AML for banking is the transaction-monitoring, sanctions-screening, correspondent-banking-due-diligence, and SAR filing layer that retail banks, private banks, wealth managers, and correspondent banks operate to satisfy BSA/AML, MLR 2017, AMLD6, and AMLA obligations. It runs in real time, links alerts to verified identity, re-screens perpetually, and produces case files reproducible per-decision under regulator audit.
What does banking AML actually have to do?
The AML for banking category covers the broadest customer surface of any AML category. Retail individuals across hundreds of millions of accounts. Corporate customers with multi-jurisdictional ownership trees. High-net-worth and ultra-high-net-worth clients with documented EDD. Counterparty institutions in correspondent relationships where the originating bank inherits the correspondent’s compliance posture.
For the broader transaction-monitoring architecture, see our AML transaction monitoring 2026 piece. For the underlying KYC pattern, see our KYC for banking page.
What are the regulatory baselines for banking AML across US, EU, and UK?
United States: BSA, FinCEN, OCC, Federal Reserve, FDIC, state regulators
The Bank Secrecy Act is the foundational US AML statute. Obligations include the Customer Identification Program (CIP), Customer Due Diligence (CDD) Rule covering beneficial ownership at 25%, Currency Transaction Reports above USD 10,000, SAR filing within 30 days, and a documented five-pillar AML program. The “reasonably designed and risk-based” standard is already statutory, at 31 U.S.C. 5318(h)(2)(B)(iv) as amended by the Anti-Money Laundering Act of 2020. What is still open is the FinCEN regulation that implements it. FinCEN proposed that rewrite on April 7, 2026, withdrawing its July 2024 proposal, closed comments on June 9, 2026, and proposed a 12-month implementation period after any final rule. It is a proposal, so nothing new binds today, but the direction it sets is the one to build against.
European Union: AMLR, AMLD6, AMLA direct supervision
The 2024-2025 EU package replaced the directive-based framework with a single rulebook regulation (AMLR), a new directive (AMLD6 in the new numbering), and the Anti-Money Laundering Authority (AMLA) operational from 2025 in Frankfurt. AMLA has direct supervisory authority over approximately 40 EU banks. Per-decision defensibility is the operating standard.
United Kingdom: FCA, PRA, MLR 2017, Senior Managers Regime
The UK splits prudential supervision (PRA) and conduct supervision (FCA) for the largest banks. Obligations sit under the Money Laundering Regulations 2017, the FCA Handbook (SYSC 6.1, SYSC 6.3), and SMCR.
Side-by-side: banking AML obligations
| Dimension | US | EU | UK |
|---|---|---|---|
| Primary statute | BSA + AML Act of 2020, program rule still proposed | AMLR + AMLD6, AMLA Regulation | MLR 2017, FCA Handbook SYSC, SMCR |
| BO threshold | 25% (CDD Rule) | 25% (AMLD6) | 25% (MLR 2017) |
| CDD timing standard | At onboarding + perpetual | At onboarding + perpetual | At onboarding + perpetual |
| Audit standard | Reasonably designed + risk-based | Per-decision defensibility | Proportionate to risk + SMCR accountability |
| Direct supervisor | OCC / Fed / FDIC + FinCEN | AMLA (top 40 banks) + national | FCA + PRA |
| Recent enforcement | TD Bank USD 1.3B (Oct 2024) | Revolut UAB EUR 3.5M (Apr 2025) | Starling GBP 29M, Monzo GBP 21M |
Where do bank AML programs fail, and what does it cost?
Five reproducible failure modes show up in every recent megabank Final Notice.
Periodic re-KYC missing or stale
Banks running annual or three-year re-KYC cycles inherit the TD Bank pattern: customer status changed, internal records did not. Perpetual KYC at the credential layer is the regulatory expectation now.
Sanctions screening at customer level only
Banks that screen customers at onboarding and forget to screen counterparties at every transaction get the Binance USD 4.3 billion / Standard Chartered / BNP Paribas pattern.
KYB depth shortfall on corporate customers
Corporate customer onboarding stops at the registered entity, with no UBO trace and no operating-entity verification. Wirecard EUR 1.9 billion (2020) is the canonical example. See our Zyphe KYB software.
Correspondent banking due diligence gaps
The originating bank inherits the correspondent bank’s KYC failures. Most banks know this. Few document it well enough to satisfy a regulator.
Audit-trail reproducibility
When the regulator pulls the case file 18 months later, the closure rationale does not reproduce. The TD Bank, Starling, Monzo, Revolut UAB, and Cash App / Block penalties all cited reproducibility gaps as core findings.
Recent enforcement timeline
| Date | Action | Penalty | Why it matters for banking AML |
|---|---|---|---|
| 2018 | Danske Bank Estonia | ~EUR 200B suspicious flows | UBO trace stopped at corporate-name match |
| 2020 | Wirecard collapse | EUR 1.9B missing | Operating-entity verification fictional |
| 2023 | Binance settlement | USD 4.3B | Sanctions screening gaps at transaction layer |
| Oct 2024 | TD Bank | USD 1.3B FinCEN, USD 3.1B combined | Five-pillar program failures |
| Oct 2024 | Starling Bank | GBP 29M FCA | Sanctions screening + control framework |
| Apr 2025 | Revolut Bank UAB | EUR 3.5M Bank of Lithuania | Per-decision defensibility under AMLA |
| Jul 2025 | Monzo | GBP 21M FCA | High-risk customer onboarding gaps |
How does Zyphe deliver banking AML at the post-TD Bank audit bar?
Zyphe ships four primitives.
Perpetual KYC at the credential layer. Customer credentials carry expiry, revocation pointers, and continuous re-screening status. Sanctions, PEP, and adverse media re-screening run on a defined cadence.
KYB depth across 190+ corporate registries. Zyphe KYB walks the corporate customer’s ownership tree to natural persons or regulated parents. Wirecard-style operating-entity verification, BVI/Cayman opacity flagging, and recursive UBO trace are built in.
Identity-linked AML monitoring. Every alert in the Zyphe AML transaction monitoring stack carries the verified credential, the KYC tier, and the perpetual re-screening status. Mule indicators fire at the rule level. Sanctions screening at the transaction-counterparty layer is automatic.
Per-decision triage records and audit-export readiness. AMLA per-decision defensibility, FCA SYSC SMCR personal accountability, FinCEN reasonably-designed standard. Case files exportable in regulator-ready formats on demand.
A senior head of financial crime at a Tier-1 European bank framed the post-TD Bank operational reality on a customer call in March 2026: “the FinCEN consent order against TD changed how our board reads our quarterly compliance report. The ‘we have controls in place’ language stopped landing. They want to see per-decision evidence, and the AML for banking architecture decision is whether the AML for banking system produces that evidence as a side effect or whether your team has to assemble it.”
How do you implement banking AML across retail, private, and correspondent banking?
Three patterns covering the most common bank deployment shapes.
Retail banking
Real-time transaction monitoring at authorisation, identity-linked alerts, sanctions screening at customer and transaction-counterparty layer, perpetual KYC re-screening at the credential layer. CTR filing pipeline (US), SAR filing pipeline. Standard onboarding flow lands in 5 to 10 minutes.
Private banking and wealth management
Standard obligations plus elevated EDD: source of funds, source of wealth, PEP screening with adverse media depth, multi-jurisdictional UBO trace where the customer is a corporate entity or trust, ongoing monitoring at elevated cadence. Case file carries every piece of evidence with timestamps and policy versions.
Correspondent banking
KYB on the correspondent bank itself (licensing, ownership, sanctions exposure, regulator standing), credential-based verification of the underlying customers where permitted under the correspondent agreement, continuous monitoring of the relationship. Where the correspondent bank uses Zyphe credentials, the originating bank reads the same credentials.
What are the real edge cases banking AML still struggles with?
Five edge cases worth flagging.
Trust structures terminating in opaque jurisdictions. BVI, Cayman, certain Liechtenstein vehicles. Recursive UBO trace flags the opacity rather than blanket-rejecting.
PEP status changes mid-relationship. Newly elected officials, family-member designations, post-office cooling periods.
Wealth-management cross-border source-of-wealth opacity. A UHNW client whose wealth originated in a third jurisdiction with regulatory opacity around the underlying business.
Correspondent banking with smaller counterparts. A correspondent relationship with a Tier-2 bank in a higher-risk jurisdiction inherits the counterpart’s KYC standards.
Legacy core-banking integration. Most banks’ KYC layers are wired into core-banking systems built before reusable credentials existed. Migration path matters as much as greenfield architecture.
How do you evaluate banking AML in the next 30 days?
Five concrete moves for a head of financial crime, MLRO, or CRO.
- Audit re-KYC cadence. Annual or three-year for any non-low-risk customer is operating below the post-TD Bank bar.
- Map KYB depth. Corporate customers with multi-jurisdictional ownership trees need recursive UBO trace.
- Pressure-test AML monitoring identity linkage. Every alert should carry the verified credential.
- Run audit-export drill. Pull a SAR filed 18 months ago and trace the evidence chain.
- Update SMCR responsibility map (UK), risk-based program documentation under the AML Act of 2020 (US), or AMLA per-decision defensibility documentation (EU).