Home   News   Features   Interviews   Magazine Archive   Industry Awards  
Subscribe
Securites Lending Times logo
Leading the Way

Global Asset Servicing News and Commentary
≔ Menu
Securites Lending Times logo
Leading the Way

Global Asset Servicing News and Commentary
News by section
Subscribe
⨂ Close
  1. Home
  2. Features
  3. When compliance becomes a moving target
Feature

When compliance becomes a moving target


08 Jul 2026

As sanctions regimes proliferate, private markets expand, and regulatory expectations evolve, financial crime compliance has become one of the most operationally demanding functions across asset servicing. Zarah Choudhary explores how firms are navigating a new era of financial crime risk

Image: ipopba/stock.adobe.com
Financial crime compliance has always been a moving target. Criminals evolve their methods, regulators tighten their expectations, and financial institutions adapt accordingly. Over the past five years, however, the pace of change has accelerated dramatically.

The convergence of geopolitical conflict, increasingly sophisticated financial crime, rapid technological innovation, and expanding private markets has fundamentally altered the operating environment for asset servicers. Anti-money laundering (AML) programmes, once centred on customer onboarding and transaction monitoring, are now expected to identify complex ownership structures, monitor rapidly evolving sanctions regimes, verify the source of wealth behind investments, and guard against increasingly sophisticated AI-enabled fraud.

The scale of this transformation is reflected in the numbers. According to LSEG’s Global Sanctions Index, the number of global sanctions has increased by more than 440 per cent since 2017, driven largely by geopolitical tensions including the Russia-Ukraine conflict and wider developments involving Iran, Belarus, China, and the Middle East.

For firms facilitating trillions of pounds in cross-border assets, financial crime compliance has become far more than a regulatory obligation. It now sits at the intersection of geopolitics, data governance, technology, and operational resilience.

As Sean Vickers, managing director and global head of client lifecycle management (CLM) at Delta Capita, explains, firms have experienced “a significant increase in both regulatory scrutiny and complexity” in recent years.

“Sanctions have evolved from being a relatively static compliance obligation to a rapidly changing geopolitical risk management challenge, driven by events such as the Russia-Ukraine conflict, heightened US-China tensions, and the expansion of global sanctions frameworks,” he explains.

“The biggest challenge is maintaining a holistic view of risk across increasingly complex investor, intermediary, and fund structures while controlling operational cost and client friction.”

Sanctions become a geopolitical instrument

Although sanctions have long formed part of financial crime compliance frameworks, their role has changed significantly over the last decade. Rather than functioning primarily as tools against terrorism or organised crime, sanctions have become central instruments of international diplomacy, evolving rapidly in response to geopolitical events.

Successive rounds of restrictions introduced following Russia’s invasion of Ukraine demonstrated how quickly governments can impose measures targeting individuals, financial institutions, sovereign assets, and entire sectors of an economy. At the same time, export controls and technology restrictions have expanded alongside more traditional financial sanctions, creating a regulatory environment that is increasingly dynamic and politically driven.

Jamie Rogers, partner at Hogan Lovells, believes this represents a fundamental shift.

“The sanctions landscape has changed dramatically over the last five years,” he says.

“Sanctions have moved from static to dynamic and continuously evolving regimes as legislators establish sanctions restrictions and then legislate to prevent circumvention.”

Rather than focusing solely on designated individuals and organisations, regulators are increasingly targeting attempts to evade sanctions through intermediary jurisdictions, layered ownership structures, and indirect trading relationships.

“The extraterritorial reach of sanctions has become increasingly important. Legislators are seeking to prevent sanctioned persons from accessing international markets indirectly through third countries or complex ownership arrangements”, Rogers adds.

For internationally-active asset servicers, this creates significant operational challenges. Compliance teams must not only identify clients and counterparties but also understand where capital originates, who ultimately controls investment vehicles, and whether changing geopolitical developments have altered the risk profile of an existing relationship.

Robin Cotterill, chief compliance officer at Carne Group, notes sanctions have become one of the fastest-moving areas of financial crime compliance.

He says that sanctions lists now contain almost 80,000 sanctioned individuals, entities, and organisations globally, while the overall number of sanctions has risen sharply over the last decade.

“The direction of travel is clear,” he informs. “Notwithstanding year-on-year fluctuations, the stock of sanctioned individuals, entities and organisations has expanded substantially, increasing the screening burden for firms operating cross-border.”

With sanctions programmes frequently updated in response to geopolitical developments, firms are increasingly required to reassess risks in real time rather than relying on static compliance frameworks. As Cotterill puts it, the industry is moving “from a world of consensus and correlation to one of navigation” — a shift that demands greater agility as well as a deeper understanding of increasingly interconnected global risks.

Can the AMLA deliver consistency?

While sanctions regimes continue to evolve globally, Europe is pursuing a different objective: harmonisation.

The creation of the Anti-Money Laundering Authority (AMLA) marks the most significant overhaul of the EU’s financial crime framework in decades.

Alongside the new Anti-Money Laundering Regulation (AMLR), the AMLA is intended to reduce regulatory fragmentation through a single rulebook, harmonised supervisory standards, and closer coordination between national supervisors and Financial Intelligence Units (FIUs). For firms operating across multiple European markets, the long-term ambition is clear: greater consistency, clearer supervisory expectations, and fewer differences in how AML rules are applied.

Vickers describes the AMLA as “the most significant reform of the European AML framework in decades”.

“Its objective is to reduce regulatory fragmentation through a single rulebook, harmonised supervisory standards, and greater coordination across member states,” he says.

“In the longer term, firms should benefit from greater consistency and predictability across Europe.”

However, harmonisation will not necessarily simplify compliance overnight. During implementation, firms will need to review governance frameworks, customer due diligence procedures, risk assessment methodologies, and reporting arrangements to ensure they align with the new regime, while continuing to meet requirements in jurisdictions outside the EU.

Claire Lipworth, partner at Hogan Lovells, believes the AMLA should improve consistency for firms operating across multiple member states, but notes that organisations will still need to balance EU-wide expectations with national requirements and wider international obligations.

Cotterill agrees that the long-term direction is positive but warns the transition could initially increase operational complexity.

“The development of a common rulebook has been designed to harmonise and simplify AML regulation,” she explains, “but firms may find they are facing another layer of supervision alongside existing national competent authorities rather than a straightforward replacement.”

While Europe is working towards harmonisation internally, firms with global operations must continue navigating increasingly divergent regulatory expectations elsewhere — a balancing act likely to define compliance strategies for years to come.

Looking beyond the customer

If sanctions have reshaped the external risk landscape, the rapid expansion of private markets has transformed how firms assess risks within their own client base.

Private equity, private credit, infrastructure, and real estate continue to attract significant investment, but they also introduce increasingly complex ownership structures involving trusts, holding companies, special purpose vehicles (SPVs), and multiple cross-border entities.

For compliance teams, identifying the legal owner of an asset is no longer enough.

Regulators increasingly expect firms to identify the ultimate beneficial owner (UBO), understand who exercises control, verify the source of wealth and funds, and continuously reassess those risks as ownership structures evolve.

Sean Vickers believes private markets have significantly increased the depth of due diligence required.

“Unlike many public market investments, private assets often involve layered legal structures, trusts, holding companies and cross-border ownership arrangements that require significantly deeper investigation,” he says.

As a result, firms are moving away from treating onboarding as a one-off exercise towards maintaining a continuous understanding of ownership and risk throughout the client lifecycle.

Claire Lipworth says this reflects a broader shift in regulatory expectations.“KYC remains foundational,” she notes, “but it is no longer sufficient on its own.”

“As private markets expand, increasingly complex fund structures, and layered ownership chains are placing greater pressure on firms to understand not just their direct clients but the full spectrum of underlying investors and assets.”

This has also accelerated interest in Know Your Asset (KYA), which complements traditional Know Your Customer (KYC) processes by examining the asset itself, its ownership history, and any associated financial crime risks alongside the customer.

Robin Cotterill says the growth of private markets is placing increasing pressure on compliance functions.

“AML teams are being asked to do ever more complex work to ensure that new private asset transactions are cleared from an AML point of view, often without the requisite increase in resources,” he explains.

For asset servicers, the challenge is balancing increasingly detailed due diligence with clients’ expectations for faster onboarding and seamless service. As private markets continue to expand, maintaining that balance is likely to become one of the defining operational challenges facing compliance teams.

Technology meets human judgement

As financial crime obligations continue to grow in both volume and complexity, technology has become indispensable. AI and automation are increasingly being used across sanctions screening, transaction monitoring, customer due diligence, and adverse media searches, helping firms process vast amounts of information more efficiently while reducing false positives and allowing investigators to focus on genuinely higher-risk cases.

Yet contributors consistently stress that technology should enhance — not replace — human expertise.

Adam McLaughlin, director of financial crime product at Fenergo, believes firms are moving beyond simply monitoring transactions to understanding customer behaviour over time.

“What that means is not just simply detecting sanctions breaches,” he informs, “but demonstrating that firms can identify behaviour that is genuinely abnormal or suspicious.”

Analysing behavioural patterns can reveal risks that traditional rules-based monitoring may overlook, from unusual transaction activity to indirect links with sanctioned entities. AI enables firms to process these increasingly complex datasets at scale, but McLaughlin argues that human judgement remains central.

“AI can detect those signs rapidly,” he says, “but it can’t make the final judgement. That still requires human expertise.”

Steve Hyland, strategic adviser at Complia, agrees that AI’s greatest value lies in supporting experienced investigators rather than replacing them.

“It can cover millions and millions of transactions,” he says. “People can’t do that. It’s not manually possible.”

By automating repetitive screening tasks, compliance teams are able to spend more time investigating genuinely complex cases where context and professional judgement are essential.

However, the same technologies are also being adopted by criminals.

Silvija Krupena, director of the Financial Intelligence Unit at RedCompass Labs, warns that AI is enabling increasingly sophisticated forms of financial crime.

“Deepfake video and cloned voices now defeat identity verification. Synthetic identities pass onboarding checks. AI-generated scripts allow a single operator to run multiple social engineering campaigns simultaneously,” she says.

Rather than viewing AML, sanctions, fraud, and cybercrime as separate disciplines, Krupena believes firms must recognise what she describes as “convergence crime”.

“The same jurisdictions, the same layering techniques, and the same intermediary chains appear across every crime type,” she explains.

As both financial institutions and criminals embrace AI, firms will increasingly need to combine technological capability with experienced human oversight to remain effective.

The foundations of effective compliance

While AI continues to attract investment, contributors consistently point to a more fundamental challenge: data.

Incomplete customer records, fragmented ownership information, and inconsistent internal systems can undermine sanctions screening, customer due diligence, and transaction monitoring regardless of how sophisticated the underlying technology may be.

As a result, regulators are placing increasing emphasis not only on controls themselves, but on firms’ ability to demonstrate how decisions are made, how risks are assessed and how governance frameworks operate in practice.

Krupena believes improving data quality should be the industry’s starting point.

“Every financial crime control depends on it,” she adds. “If customer data is fragmented, inconsistent or poorly standardised, then every model, every alert, and every investigation built on top of it is compromised.”

For Vickers, the organisations best placed to respond will be those that integrate policy, process, technology, and data into a single financial crime framework capable of adapting as regulatory expectations evolve.

Ultimately, financial crime compliance is no longer simply about satisfying regulatory requirements. Increasingly, it underpins firms’ ability to respond to geopolitical change, identify emerging risks and maintain operational resilience across the investment lifecycle.

From obligation to operational capability

Although initiatives such as the AMLA promise greater consistency across Europe, the broader direction of travel remains one of increasing complexity. Sanctions will continue to evolve alongside geopolitical developments.

Private markets will become larger and more interconnected.

Criminals will increasingly exploit emerging technologies, while regulators continue demanding greater transparency around ownership, governance, and operational effectiveness.

For asset servicers, compliance can no longer be viewed as a standalone regulatory function. It is becoming embedded across onboarding, custody, fund administration, transfer agency, payments, and client lifecycle management.

Meeting tomorrow’s expectations will require more than keeping pace with new regulations.

Firms must combine robust governance with high-quality data, invest in technology without becoming dependent on it, and recognise that automation and human expertise are complementary rather than competing capabilities.

As Cotterill observes, organisations must first understand the jurisdictions in which they operate before determining the controls they require. In an increasingly interconnected financial system, understanding where risk begins — and where responsibility ends — is becoming progressively more difficult.

Financial crime compliance has evolved beyond a regulatory obligation. For asset servicers, it is becoming a core operational capability — one that increasingly underpins trust, resilience, and confidence across global investment markets.
← Previous feature

Corporate actions modernisation
NO FEE, NO RISK
100% ON RETURNS If you invest in only one asset servicing news source this year, make sure it is your free subscription to Asset Servicing Times
Advertisement
Subscribe today