Back to Blog

When the regulatory direction changes, your screening programme shouldn’t

Blog

Screening requirements are changing in different ways

In Europe, AML supervision is becoming more centralised. The Anti-Money Laundering Authority (AMLA) became operational in Frankfurt in July 2025 and the EU’s Anti-Money Laundering Regulation will generally apply from 10 July 2027.

From 2028, AMLA is due to directly supervise up to 40 high-risk cross-border financial institutions or groups, with powers to request information, carry out inspections and impose penalties.

In the US, a specific part of customer due diligence has been simplified. FinCEN’s February 2026 relief allows covered financial institutions to avoid repeating beneficial ownership identification and verification each time an existing legal-entity customer opens another account. Checks are still required when the customer first opens an account, when previous information is called into question and when the firm’s risk-based ongoing due diligence procedures require them. That reduces duplication. It does not remove initial verification requirements or introduce a new monitoring obligation.

Separately, the AML/CFT programme changes proposed by FinCEN and the federal banking agencies in April 2026 place greater emphasis on programmes that address an institution’s risks effectively, rather than treating compliance as a tick-box exercise.

These developments concern different parts of the AML framework, rather than directly opposing screening rules. However, they reinforce a point, which is that a change to a particular requirement does not remove the need to understand who you are dealing with or to respond when their risk changes.

What it costs to build around individual screening requirements

The instinct when requirements diverge is to build a separate process for each of them. Screen against this list here, apply that verification step there and run a different enhanced due diligence (EDD) process for each supervisor you answer to.

Some local variation is necessary but when a jurisdiction is added or a requirement changes, a programme organised too tightly around individual regulations can need substantial reworking. If your structure follows the requirements, you will have to rebuild it every time the requirements change. You should build instead around a consistent view of the customer.

Meanwhile, the combination of lists a financial institution might screen against is not determined by regulation alone. An international bank operating in the UK might screen against the UK Sanctions List alongside relevant US, EU and UN lists, depending on its legal obligations, business exposure and risk appetite.

Three things a screening baseline needs when requirements change

Entity resolution, before anything else

It is better to organise your screening programme around entities, rather than names. A screening programme organised around names only asks whether a possible match appears on a list, whereas one organised around entities resolves who you’re actually dealing with.

That means bringing customer information together in a single profile and using it to distinguish the right person or business from others with similar names. That discipline applies across sanctions, PEPs and watchlists, but it matters most in adverse media, where the material is unstructured and rarely carries the identifiers that make a match straightforward, so relevant articles can be linked to that profile rather than treated as a series of disconnected alerts.

Ripjar’s 2026 research found that 93% of financial services leaders surveyed rate adverse media screening as critical or very important and 77% say their firms carry it out. Overall, 58% still use manual internet searches as part of the process.

Those firms may also have automated tools, but manual searching remains a critical part of the work. Entity resolution helps with one part of that task: establishing whether the information found actually relates to the customer being screened. Finding a familiar name is not the same as knowing who it refers to.

Monitoring throughout the relationship

Risk can change between scheduled reviews. You might have carried out a check on a customer last year, but the results of that check probably no longer reflect what is known about that customer today. Continuous screening can help teams pick up new information between reviews and assess whether it changes their understanding of the customer or level of risk.

FinCEN’s relief leaves risk-based ongoing due diligence in place. It does not introduce a blanket requirement for real-time screening, but it does preserve the responsibility to monitor for suspicious activity and update customer information on a risk basis.

Explainability built in instead of adding it later

Your analysts need to show what was checked, when it was checked, which sources were used and why an alert was escalated or closed. The supporting evidence and reasons for the decision need to remain available when that decision is reviewed by an auditor or regulator.

We know from our research that companies are increasingly using AI in customer screening. Where AI supports screening or decisions on alerts, the same principle applies. Analysts should be able to review the evidence and understand the basis for the output, with appropriate human oversight.

It is easier to build that into the process than to reconstruct it later. A policy document cannot fill gaps in the evidence behind a decision.

The Ripjar engineering standard for screening

Ripjar was founded in 2013 by a team from GCHQ, a UK intelligence agency. They came from an environment where decisions with serious consequences depended on making sense of vast amounts of publicly available information. The systems supporting those decisions had to be explainable, handle large volumes of information and leave a record that could withstand the highest levels of scrutiny.

That is the engineering standard Ripjar applies to screening across sanctions, PEPs, watchlists and adverse media, bringing the results together in one intelligent, continuously updated view of customer risk.

It’s also why we would argue for the same starting point regardless of what any individual regulator does next. Build your programme around knowing who you’re dealing with, monitor for new risks throughout the relationship and record decisions so they can be traced back to their sources.

New requirements will still need to be assessed and some will call for changes to systems or processes but a consistent baseline gives you a foundation for that work, rather than treating every new list or rule as a separate screening problem.

Regulation should inform how you screen – it shouldn’t be the only reason you do.

The figures above come from The State of Adverse Media Screening, Ripjar’s 2026 research with financial services decision makers in the UK, US, France and Germany. Download the report.