Anti-money laundering regulation is no longer developing through isolated changes to customer due diligence or suspicious activity reporting. The current direction of travel is broader: regulators are strengthening corporate transparency, expanding the range of regulated professions, harmonising requirements across markets, increasing organisational accountability and imposing clearer governance expectations on the technology used to make financial-crime decisions.
The changes that began to take shape in 2024 have also evolved materially. Some measures have expanded, while others have been narrowed or delayed. The United States’ beneficial ownership reporting framework, for example, no longer applies to domestic companies in the form originally anticipated. By contrast, the European Union has moved from successive directives towards a directly applicable AML rulebook and a central supervisory authority.
For financial institutions, the important question is not simply which regulation applies. It is how these reforms collectively change the evidence, governance and operating capabilities expected from a modern financial-crime programme.
Listen the podcast
Watch the video
Why the regulatory transformation matters now
Money laundering increasingly crosses the traditional boundaries between banking, professional services, corporate formation, cryptoassets, digital identity and technology governance. A criminal network may use a company registered in one jurisdiction, a trust administered in another, a payment account elsewhere and a virtual-asset service provider operating across several markets.
Regulatory frameworks are responding by widening the control perimeter and improving the ability of authorities to identify the people behind legal entities and financial transactions. The Financial Action Task Force has strengthened its standards on the beneficial ownership of companies, trusts and similar legal arrangements, requiring countries to provide competent authorities with access to adequate, accurate and current ownership information.
At the same time, regulators are moving beyond formal compliance. Institutions are increasingly expected to demonstrate that controls identify material risks, produce useful intelligence and adapt when criminal behaviour changes. A technically complete policy is not sufficient where data remains unreliable, ownership cannot be verified or suspicious activity is detected only after funds have moved.
Five regulatory developments illustrate this transition particularly clearly.
1. The United States Corporate Transparency Act: a major recalibration
The Corporate Transparency Act was originally designed to create a broad federal beneficial ownership reporting regime. Companies formed or registered in the United States were expected to provide the Financial Crimes Enforcement Network with information on the individuals who ultimately owned or controlled them.
The objective was to reduce the anonymity provided by shell companies and make beneficial ownership information available to authorised law-enforcement agencies, regulators and financial institutions under defined conditions.
However, the reporting framework changed substantially in March 2025. FinCEN issued an interim final rule exempting all entities created in the United States, together with their beneficial owners, from the federal reporting requirement. US persons were also exempted from providing beneficial ownership information under the revised framework.
The remaining obligation is focused primarily on certain foreign entities registered to conduct business in the United States. Even those entities are not required to report beneficial ownership information concerning US persons.
This change significantly reduced the scope of the original regime. Financial institutions should therefore avoid assuming that the FinCEN beneficial ownership database provides comprehensive coverage of domestic US companies.
The narrowing of the reporting requirement also does not remove existing customer due diligence responsibilities. Banks and other covered institutions must still identify and verify customers, understand ownership and control structures, assess the purpose of relationships and conduct ongoing monitoring according to applicable rules and risk.
Operationally, this means that beneficial ownership remains an investigative process rather than a simple registry lookup. Firms may need to compare customer declarations with incorporation records, tax information, corporate websites, transaction activity and evidence from connected entities.
The wider lesson is that regulatory implementation can change rapidly. Compliance programmes should distinguish between the intended direction of legislation and the obligations actually in force.
2. The EU AML package: from fragmented directives to a single rulebook
The European Union adopted a major AML and counter-terrorist financing legislative package in 2024. Its purpose is to reduce variation between member states, strengthen supervision and create a more consistent framework for regulated businesses operating across the single market.
A central component is the new Anti-Money Laundering Regulation. Unlike a directive, the regulation will apply directly across member states, reducing the extent to which core private-sector obligations differ through national implementation.
The regulation establishes harmonised requirements covering customer due diligence, beneficial ownership, internal controls, reporting and enhanced measures for higher-risk relationships. It also extends or clarifies the obligations applying to sectors including cryptoasset service providers, traders in high-value goods and certain professional service businesses.
A Union-wide cash-payment limit of €10,000 forms part of the framework, although member states may impose lower domestic limits. Professional football clubs and agents will also enter the AML perimeter, subject to a later implementation timetable and limited national flexibility for lower-risk activity.
The accompanying directive addresses the organisation of national supervisory systems, financial intelligence units and beneficial ownership mechanisms. It seeks to improve cooperation and access to information across the Union.
The institutional centre of the package is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism. AMLA began operating in Frankfurt in 2025 and is progressively building its supervisory, coordination and technical capabilities.
During 2027, AMLA is expected to select 40 significant cross-border financial-sector entities for direct supervision. Direct supervision is scheduled to begin in 2028, while AMLA will also promote convergence among national supervisors and support cooperation between financial intelligence units.
For multinational institutions, this changes the supervisory landscape. Group programmes will need to demonstrate consistent risk assessment, data quality and control performance across legal entities rather than relying on materially different local interpretations.
The EU package is therefore not simply another AML directive. It represents a shift towards centralised standards, comparable supervision and more direct accountability for cross-border control weaknesses.
3. The United Kingdom: corporate transparency and organisational fraud accountability
The Economic Crime and Corporate Transparency Act 2023 has continued to reshape the UK financial-crime framework through phased implementation.
One of its principal objectives is to improve the integrity of the companies register. Companies House has moved from a largely passive recipient of information towards a more active gatekeeper with powers to query, reject, annotate and remove information and to take action against companies created or used for unlawful purposes.
Mandatory identity verification began on 18 November 2025 for new directors and people with significant control. A transition period was also introduced for millions of existing directors and beneficial owners to complete verification through their companies’ confirmation-statement processes.
These reforms are intended to make it more difficult to create companies using false identities, nominee arrangements or fabricated addresses. However, identity verification does not establish that a business is legitimate or that its transactions have a lawful purpose.
Financial institutions must still assess who exercises effective control, whether the ownership structure is economically credible and whether the company’s activity is consistent with its stated purpose.
The Act also introduced the corporate offence of failure to prevent fraud, which came into force on 1 September 2025. A large organisation may be criminally liable where an associated person commits a specified fraud offence intending to benefit the organisation or certain connected parties, and the organisation did not have reasonable fraud-prevention procedures.
This development is broader than conventional AML compliance. It connects financial-crime governance with corporate culture, employee conduct, third-party risk, sales incentives and the design of preventative controls.
The practical implication is that fraud risk cannot remain confined to customer-facing detection teams. Organisations need documented risk assessments, senior ownership, proportionate prevention procedures, training, due diligence and monitoring capable of addressing fraud committed for the organisation’s benefit.
The UK reforms therefore combine greater transparency over corporate actors with greater accountability for corporate behaviour.
4. Australia’s Tranche 2 reforms: widening the regulated perimeter
Australia’s AML and counter-terrorist financing regime historically applied to financial institutions, gambling businesses, remittance providers and certain digital-currency services while leaving several professional sectors outside the full regulatory perimeter.
The AML/CTF Amendment Act 2024 addressed this longstanding gap. Reforms for existing reporting entities commenced on 31 March 2026, while obligations for newly regulated sectors began on 1 July 2026.
The expanded regime covers designated services provided by legal professionals, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals, stones and related products. Certain additional virtual-asset services are also brought within scope.
These sectors can play legitimate and essential roles in corporate formation, property transactions, wealth management and asset transfers. They can also be exploited to create legal structures, move ownership, purchase high-value assets or provide a professional appearance to criminal activity.
Newly regulated businesses must determine whether they provide designated services, enrol with AUSTRAC, appoint an AML/CTF compliance officer and establish a risk-based programme. They must conduct customer due diligence, monitor relationships and report suspicious matters where legal thresholds are met.
Implementation is particularly challenging for smaller professional practices that have limited previous exposure to formal financial-crime regulation. A generic policy or outsourced customer-verification tool will not be sufficient. Firms need to understand how their particular services could facilitate laundering, terrorism financing or proliferation financing.
Financial institutions should also review their reliance on professional intermediaries. The introduction of regulation does not mean that every lawyer, accountant or property professional immediately presents lower risk. Banks need to understand whether counterparties are within scope, whether their controls are operational and how information can be exchanged lawfully.
Australia’s reforms demonstrate the global movement towards regulating the professional gatekeepers who enable companies, trusts and high-value transactions.
5. AI governance: financial-crime innovation enters the regulatory perimeter
Artificial intelligence is becoming increasingly important to AML operations. Institutions use machine learning, graph analytics, natural-language processing and generative systems to identify suspicious behaviour, resolve entities, prioritise alerts and support investigations.
The regulatory question is no longer whether firms may use AI. It is whether they can demonstrate that the technology is governed, explainable, secure and appropriate for the decision it supports.
The EU AI Act entered into force in August 2024 and has applied through a phased timetable. AI-literacy requirements and prohibited-practice rules began applying in February 2025, followed by governance requirements for general-purpose AI models. Further transparency obligations take effect in August 2026.
Whether an AML application is classified as a high-risk AI system depends on its specific purpose, deployment and relationship to the categories defined in the legislation. However, even systems outside the formal high-risk classification remain subject to wider expectations under data protection, financial-services governance, operational resilience and model-risk frameworks.
For FinCrime teams, the relevant risks include biased alert prioritisation, unsupported generative outputs, poor data lineage, model drift and excessive reliance on third-party systems. An AI model may produce a plausible explanation without accurately representing the transactions or evidence from which it was derived.
Institutions should therefore maintain inventories of AI use cases, define accountable owners and validate performance against the relevant financial-crime objective. Generated conclusions should remain traceable to source evidence, while material decisions require meaningful human oversight.
AI regulation should not be interpreted as a barrier to innovation. Proper governance can make advanced analytics more defensible by clarifying data boundaries, testing requirements, escalation routes and individual accountability.
Why the five developments converge
Although these reforms arise in different jurisdictions, they point towards a common regulatory model.
Authorities want greater visibility over the natural persons behind companies, trusts and transactions. They are extending obligations to professional intermediaries and digital businesses that sit outside traditional banking. They are increasing accountability for organisational conduct and strengthening oversight of automated decision-making.
The resulting compliance challenge is not solved by maintaining separate projects for beneficial ownership, transaction monitoring, fraud prevention and AI governance. The same customer or transaction may engage all of them.
A corporate customer may be verified through a national registry, introduced by a newly regulated professional adviser, monitored using an AI-enabled model and investigated under rules shaped by multiple jurisdictions.
Institutions therefore need an integrated financial-crime architecture capable of preserving evidence and accountability across the full lifecycle.
What a resilient control stack looks like
The first layer is regulatory intelligence. Firms should maintain a structured inventory of obligations, implementation dates, affected entities and dependencies rather than relying on high-level summaries of proposed legislation.
The second layer is reliable ownership data. Beneficial ownership should be collected, independently verified and refreshed when risk events occur. Registry information should inform due diligence but not replace it.
The third layer is enterprise risk assessment. New sectors, products, technologies and jurisdictions should be reflected in customer, product and delivery-channel assessments. The programme should explain how regulatory change alters the institution’s actual exposure.
The fourth layer is control traceability. Institutions should be able to demonstrate which data, rule, model or judgement produced a decision. This is particularly important where AI influences onboarding, monitoring or investigation.
The fifth layer is cross-functional governance. AML, fraud, sanctions, legal, data protection, technology and model-risk teams need shared escalation and decision protocols. Regulatory convergence makes isolated ownership increasingly ineffective.
Finally, firms need continuous effectiveness testing. Success should be measured through risk coverage, quality of investigations, intelligence value and prevention outcomes—not only through policy completion or alert volumes.

What this means for financial crime leaders
The regulatory changes that emerged in 2024 have not followed a straight or uniform path. The US beneficial ownership regime narrowed, the EU moved towards a centralised framework, the UK strengthened corporate transparency and fraud accountability, and Australia expanded its AML perimeter to professional gatekeepers.
At the same time, AI has moved from an experimental compliance tool into a regulated governance issue.
Financial crime leaders should therefore avoid treating regulatory change as a sequence of implementation deadlines. Each reform changes the information institutions must obtain, the parties they must assess and the evidence they must preserve.
The strongest programmes will translate legal obligations into connected operational capabilities: accurate ownership identification, risk-sensitive due diligence, intelligence-led monitoring, accountable technology and rapid information sharing.
Regulations will continue to evolve, and some will change materially between enactment and implementation. Institutions that monitor only the written rule will remain reactive. Those that understand the policy direction—greater transparency, broader accountability and demonstrable effectiveness—will be better positioned to adapt before regulatory change becomes a control failure.




The AML reforms that have emerged since 2024 demonstrate that financial-crime regulation is moving towards greater transparency, broader accountability and more rigorous evidence of control effectiveness.
The direction is not uniform. Some frameworks, such as the United States’ beneficial ownership reporting regime, have been materially narrowed. Others, including the European Union’s single AML rulebook, the United Kingdom’s corporate-transparency reforms and Australia’s expanded regulatory perimeter, are increasing the obligations placed on institutions, professional intermediaries and corporate actors.
For financial institutions, the challenge is therefore more complex than meeting a series of implementation deadlines. Regulatory change affects how firms identify beneficial owners, assess professional gatekeepers, monitor customer activity, govern artificial intelligence and demonstrate that financial-crime controls work in practice.
A resilient programme requires accurate regulatory intelligence, reliable ownership data, risk-sensitive due diligence, cross-functional governance and clear traceability from source information to final decision. Registry checks, automated models and third-party verification tools can support this process, but none should replace independent assessment or accountable human judgement.
Ultimately, the strongest institutions will be those that understand the policy direction behind the rules. Greater corporate transparency, expanded institutional responsibility and closer scrutiny of technology are becoming central features of the global AML framework. Organisations that translate those principles into connected operational capabilities will be better positioned to manage future regulatory change before it becomes a compliance failure.