A financial crime practitioner view of AML screening and ongoing monitoring.
The Voice of AML Compliance Professionals: what 600+ organisations told us about manual alert handling, sanctions and PEP screening, ongoing monitoring, and the architectural gap between screening and decision, with a vendor assessment checklist for live evaluations.
Cost-effective AML compliance requires more than powerful screening capabilities. AML solutions must enable compliance teams to make accurate, context-rich risk decisions throughout the customer lifecycle. The bottleneck in modern AML operations is not screening but the decision that has to follow each match.
The gap emerges after screening. The customer’s identity, verified and documented at onboarding, may not flow to the screening system, and the screening result, once a customer’s risk has changed, may not flow to transaction monitoring. Transaction alerts that point to genuine risk never flow back to update the customer’s continuous risk profile either. Each system operates as an island, answering its own narrow question over incomplete data, so the information required to turn a screening result into a sound risk decision has to be reconstructed by hand, one alert at a time. Even the data behind AI-powered AML screening is often out of date and out of step with regulatory logic, which leaves the resulting risk assessment misleading.
This is why 32% of organisations name manual alert handling as their single largest operational challenge, and why, even as agentic AI improves screening, the decisioning that depends on customer context takes longer than ever. A model that inherits the same context gap inherits the same failure, because screening without context is never a decision in itself, only a task that still has to be passed to a person.
THE HEADLINE NUMBERS
Voice of AML Compliance Professionals
32%
named manual handling their single largest difficulty
45%
of sanctions-screening organisations say clearing a match is manual and slow
50%
of PEP-screening organisations say checks are manual or ad hoc
51%
of ongoing-monitoring frictions are manual workarounds, not automated triggers
Where the findings come from
This report is based on an analysis of anonymised market intelligence derived from Shufti’s customer and prospect base, comprising more than 600 organisations across the globe actively evaluating anti-financial crime solutions, including identity verification, fraud prevention, AML compliance, and transaction monitoring technologies.
All responses were anonymised prior to analysis and reviewed using thematic analysis to identify recurring patterns and emerging trends. Findings are presented in aggregate to provide a broader view of market priorities while ensuring that no individual organisation or respondent can be identified.
Regulators are now measuring the cost of compliance itself
In September 2025 the United States Financial Crimes Enforcement Network (FinCEN) opened a formal Survey of the Costs of AML/CFT Compliance. That a regulator has judged it necessary to measure the cost of compliance at all is itself a signal. The industry responses submitted to it already describe the pattern this report examines, naming personnel and technology as the largest components of compliance cost, and manual workflows and the difficulty of integrating multiple vendor systems among the principal operational burdens.
A Federal Reserve Bank of St. Louis study of 1,091 community banks found total regulatory compliance costs near 10% of non-interest expense at the smallest banks, roughly double the largest, with the Bank Secrecy Act the single most burdensome area at about a fifth of that total.
A 2026 PwC survey of more than five hundred financial institutions across Europe, the Middle East, and Africa found AML compliance costs rising structurally, customer due diligence now the largest operational bottleneck, confidence in transaction monitoring roughly halved since 2024, and data quality the leading barrier to AI adoption at up to 89%. Those figures measure the problem from the outside. The findings that carry this report, drawn from a proprietary dataset, explain it from the inside.
Why AML compliance becomes costly and inefficient
The customer’s identity is verified once, at onboarding, and the information captured there, date of birth, nationality, document details, is exactly what is needed to resolve a screening match. Yet when a screening alert arrives at the desk of a compliance officer, that information is not there. It was collected, verified, and paid for, but it sits behind a different vendor’s interface. This is not a staffing problem. It is an architectural problem. The cost lands in four connected places, all driven by the same root cause.
01
Decision time
Every alert requires manual context gathering because the information needed to resolve it does not arrive with the alert itself. Officers search for dates of birth, nationality, document numbers, transaction history: data that exists but is not connected.
02
Analyst hours and headcount
Manual context gathering is the largest operational cost because it scales with alert volume. When alert volume outruns the team, cost increases by hiring, so spending scales with noise rather than actual risk.
03
Backlog and delay
Unresolved alerts pile up because context gathering is slow. Approvals and transaction clearance wait for manual resolution of alerts that should resolve automatically if context were preserved.
04
Regulatory risk
Under pressure to clear a growing backlog, teams clear faster, which weakens the control. Because decisions are made by individuals with access to fragmented context, those decisions are inconsistent, undocumented, and unapproved.
The bottleneck in AML Compliance is resolution of alerts not just screening
Practitioners describe officers spending time manually gathering context because the information required to resolve a screening match is not present when the alert arrives. That context, verified identity data from onboarding, transaction history, previous risk assessments, exists within the organisation’s systems but does not flow to the point where decisions must be made.
45%
of Sanctions screening
Clearing an individual match is manual and slow because decision context does not arrive with the alert.
50%
of PEP screening
Exposure is established by hand because the system cannot close the check against a verified record.
51%
of Ongoing monitoring
Work meant to run continuously runs as scheduled re-screening instead because false alerts are not resolved.
20%
of Transaction monitoring
Practitioners cited lack of vendor consolidation as a risk-assessment challenge, leaving officers to merge three risk views by hand.
46%
of Lack of context
Common-name noise drives false positives, which points to the context available at the point of matching.
27%
of Regulatory pressure
Obligation is rising faster than the capacity absorbing it.
Why solving AML alerts becomes manual work
01
The data going into the match is weak
A record built from a verified document carries the name as printed, a date of birth, a nationality, and machine-readable data, while one built from a sign-up form carries whatever the customer typed.
02
The matching logic is a blunt trade-off
Matching narrowly misses the genuine hit whose name was spelled differently, while matching loosely returns a flood of alerts.
03
The alert arrives without the context to resolve it
The system hands the officer a possible match, not an answer. When the identifiers needed to decide do not arrive with the alert, the officer searches for them manually, which is why AML screening became manual work.
04
The systems do not share what they know
Most businesses verify identity with one supplier, screen with a second, monitor transactions with a third, and check company ownership with a fourth. None shares a record with the others.
05
The system only answers when asked
A screening query is a one-off, and nothing watches the customer or the lists. When a customer becomes a PEP or adverse media appears, no alert follows.
How the five compound
That is not five separate problems but one architectural problem with five manifestations. The solution is not to hire more analysts. It is to preserve customer context across the AML lifecycle so that screening flows directly to decision.
AML Screening needs a decisioning layer
The question that decides whether a programme can meet the standard regulators have already set is not which lists it screens against, but whether the system that establishes who the customer is and the system that decides what that customer’s name signifies are the same system. Where they are, the customer’s context is preserved across the whole AML lifecycle, and that is what makes an assessment accurate, explainable, and aligned with the institution’s own risk appetite.
Ask one question of every vendor: is the verifying system and the deciding system the same system?
Use this in a live evaluation
Each question surfaces a specific operational weakness found common in deployed systems. The full report carries the complete checklist across these areas.
01
On alignment to risk exposure and appetite
Can thresholds be configured and evidenced by risk tier, rather than to a fixed vendor default? Can screening sensitivity be tuned without a vendor change request, with every change logged for audit?
02
On data quality entering screening
Are identifiers (date of birth, nationality, document number) drawn from the same platform that verified the customer’s identity? How does the solution handle transliteration and name variants for non-Latin scripts?
03
On context delivered with alerts
Does an alert deliver the source of the listing, identifiers behind the match, and a rationale? What proportion of alerts can be resolved from the information delivered in the alert itself?
04
On explainability and consolidation
Can the solution produce a documented rationale for each decision showing why a match was cleared or escalated? How many separate suppliers underlie identity, screening, monitoring, and corporate-structure functions?
05
On continuity between screening and transactions
Does the solution assess identity screening and transaction activity against a single, shared understanding of customer risk? When a customer newly appears on a list, does the system automatically re-evaluate risk?
06
On AI-based alert triage
Does the solution offer Agentic-AI alert triage and own the AML risk data layer? Does it immediately update risk data when a customer’s sanctions or PEP status changes?
Use this in a live evaluation
Each question surfaces a specific operational weakness found common in deployed systems. The full report carries the complete checklist across these areas.
01 - 04
Certifications
Independently audited and certified for enterprise-grade security and data protection.
Frequently asked questions (FAQs)
The context gap is the structural disconnect between the system that verifies a customer’s identity and the systems that screen and monitor that customer. The identity data captured and verified at onboarding, date of birth, nationality, document details, does not flow to the screening system, so when an alert arrives, a compliance officer must manually reconstruct context the organisation already holds. The gap also widens when the data and risk logic are not tuned to the organisation’s own risk exposure and the alert does not explain its own relevance, which pushes decisioning time up further. Screening works well enough, and it is the decision-making that has to follow which becomes the real bottleneck.
Was this content helpful?
32% of organisations name manual alert handling their single largest operational challenge, and that manual context gathering is where most of the cost sits. Because the work scales with alert volume, adding analysts only makes spending scale with noise rather than actual risk.
Was this content helpful?
Accuracy depends on context, and in most stacks context is fragmented across separate vendors for identity, screening, monitoring, and corporate structure, none of which shares a record with the others. The verified identifiers needed to resolve a match sit behind a different interface from the one raising it, so the assessment is made over incomplete data. The report also notes that the data behind AI-powered screening is often out of date and out of step with regulatory logic, which leaves even automated assessments misleading.
Was this content helpful?
Transaction monitoring is where fragmentation between suppliers becomes most visible: 20% of organisations named it their principal operational difficulty, with officers manually reconciling three vendors’ separate risk views of the same customer. When identity screening and transaction activity are not assessed against one shared understanding of customer risk, genuinely high-risk behaviour is diluted across systems that each answer only their own narrow question.
Was this content helpful?
Context is what turns a screening result into a decision. The identity captured and verified at onboarding, date of birth, nationality, and document identifiers, is exactly what is needed to resolve a match, yet it does not travel with the alert. Without it, an officer cannot tell whether a matched name is the sanctioned individual or an unrelated customer who happens to share it, which is why 46% of false positives trace back to common-name noise, a context problem rather than a detection one.
Was this content helpful?
The report finds 50% of PEP-screening organisations resolve checks manually or ad hoc because the system cannot close them against a verified record. False positives fall when the verified date of birth, nationality, and document identifiers from onboarding are matched against the listing inside a single system, so a non-PEP customer sharing a name with a politically exposed person is separated automatically rather than sent to an officer for open-source research.
Was this content helpful?
In the findings, 51% of ongoing-monitoring friction is manual workaround, with work meant to run continuously performed as scheduled re-screening because false alerts are never truly resolved. False alerts happen for several reasons, which can include poor-quality AML data that even treats low-risk customers as high-risk.
Was this content helpful?
Because automation has solved screening and not the decisioning. Screening reliably raises a possible match, but the alert arrives without the identifiers, sanctions or PEP context, and rationale needed to close it, so AML compliance officers may manually investigate those alerts. Until the verifying system and the deciding system are the same system, automated screening simply hands a task to a person, which is how screening became manual work.
Was this content helpful?
Form submitted successfully!
Thank you for your interest — your report is
loading now.
Resolve AML alerts with context, save on decision time
The information required to decide already exists, captured and verified at onboarding. The question is whether your architecture lets it reach the system that needs it. Find out why your AML decisioning is taking longer than it should, or start with a short conversation about your own alert queue.
Product Guide
Customizable KYC Solution for KYC Product Owners
Product Guide
Docless KYC Verification in APAC to Onboard More Genuine Users
Product Guide
EU AMLR Guide 2027: Requirements, Scope, Deadlines | Shufti
Product Guide
APAC Child Safety Age Verification Regulations
Product Guide
Docless Identity Verification in the Middle East
Product Guide
The Future of Docless Verification in Europe
Product Guide
Cyprus 2026 KYC Operators Guide to Improve First Pass Rate