eCommerceNews UK - Technology news for digital commerce decision-makers
United Kingdom
Only 4.7% of institutions update compliance continuously

Only 4.7% of institutions update compliance continuously

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

SymphonyAI and AML Intelligence have published research showing that only 4.7% of financial institutions continuously update their compliance monitoring and controls as risk changes. The findings are based on responses from more than 200 financial crime and compliance leaders.

Most institutions still rely on periodic review cycles even as financial crime threats, regulation and transaction volumes change more rapidly, the report found. It also found that 56.8% have not adopted always-on compliance monitoring, are still exploring it, or remain at an early pilot stage.

The data points to a gap between investment priorities and day-to-day practice. While 61.9% of respondents said AI and automation are now their leading compliance investment priority, 76.3% said alert reviews are still carried out manually or only partly automated.

That suggests many compliance teams are increasing technology budgets without making comparable changes to their operating models. The level of manual or partly automated alert handling showed little movement from the previous year, although fully manual review fell to 16.5% from 21.3%.

Alert burden

The research also examined the efficiency of financial crime investigations. More than seven in 10 respondents, or 70.8%, said 5% or fewer of the alerts they investigate result in an escalation or a suspicious activity or transaction report filing.

As a result, compliance teams spend much of their time on alerts that do not translate into identified risk. The findings add to long-running industry concerns about false positives, investigator workload and the cost of maintaining large alert review operations.

Regulatory priorities are also shifting. AI and model governance, along with the adequacy of technology and systems, were each cited by 40.8% of respondents as their top regulatory concern, overtaking cross-border regulatory complexity, which had led the rankings a year earlier.

The change indicates that firms are increasingly focused on whether their systems can be explained, evidenced and governed, rather than only on whether formal compliance policies are in place. That issue has become more pressing as institutions expand their use of AI in surveillance, transaction monitoring and case management.

Operating tempo

More than half of respondents described their organisation's response to regulatory change as forward-leaning in some form. Those responses included accelerating modernisation, reshaping operating models, or moving towards proactive and intelligence-led compliance, although reactive workload remained the single biggest response.

Together, the findings suggest an industry in transition rather than one that has completed a broad shift in compliance practice. Investment is rising and some manual processes are declining, but institutions still appear to be operating largely within scheduled review structures.

Stephen Rae, Co-Founder and Chair of AML Intelligence, said the central problem is not intent but pace.

"This year's data draws a clear line. Most financial institutions aren't short on commitment to modernizing compliance, they're short on operating tempo. Criminal typologies shift by the week, transaction volumes keep climbing, and regulatory expectations are tightening - yet compliance functions are still largely built to reassess risk on a schedule rather than as conditions change. That gap, more than any single technology choice, is what the industry needs to close next," Rae said.

John Edison, President of Financial Services at SymphonyAI, said the sector is making progress but remains behind the pace of change in risk and regulation.

"The research shows an industry moving in the right direction, but the pace of change in financial crime compliance - across emerging threats, regulation and increasing business complexity - continues to outrun most compliance programs' ability to adapt.

"The next phase will be defined by how effectively institutions use AI to connect risk intelligence with institutional judgment, transforming detection, investigation and governance so that controls respond dynamically as risk changes, while maintaining appropriate human oversight and accountability," Edison said.