
Nicola Magennis
Financial Crime Practice Lead, First Derivative
WALKING around the recent European Anti-Financial Crime Summit in Dublin you could hear one word more than any other: effectiveness.
Not “compliance.” Not “controls.” Effectiveness – can you actually prove your financial crime programme works, at scale, under scrutiny and not just on the day the auditor visits.
That word choice isn’t an accident. It reflects where regulatory thinking is heading right across Europe and not only inside the EU. AMLA is the clearest, most concrete example of the pattern, but the FCA in the UK and FINMA in Switzerland are moving in broadly the same direction on their own timelines: less tolerance for policy that exists only on paper, more expectation that firms can evidence a control actually works.
It’s also a useful lens for a second, quieter shift running through almost every session at this year’s Summit: the arrival of agentic AI into financial crime. Taken together, these two forces of supervisors that increasingly judge outcomes, not paperwork, and a technology that finally has the maturity to help produce those outcomes are going to define how financial crime teams are built over the next several years.
As someone who spends most of my working life talking to heads of financial crime about exactly this tension, I want to unpack both, and what they mean for the direction compliance functions need to be moving in.
AMLA is no longer theoretical
For a few years now, AMLA has been something compliance leaders nodded along to in conference sessions without quite feeling the deadline pressure.
AMLA has taken on its AML/CFT mandate from the EBA and is steadily finalising the regulatory technical standards that will define what “good” looks like across the single rulebook.
AMLA represents a structural shift from a patchwork of national regulators interpreting AML rules with varying degrees of rigour, to a single supervisor applying one rulebook consistently across the EU.
It matters beyond the institutions directly in scope, too. Countries like the UK and Switzerland sit outside AMLA’s remit, but few operate in isolation from it – group entities, correspondent relationships and cross-border business all mean EU standards have a way of becoming the de facto benchmark and both the FCA and FINMA are independently pushing their own regulated populations toward the same evidence-based standard.
The institutions that treat the intervening period as a runway to shape their operating model to where the standards are clearly heading, whichever regulator ultimately asks the question, will be in a fundamentally different position than those that wait for a formal supervisory letter to arrive.
What “effectiveness” means in practice under that model is a harmonised, evidentiary bar: not “we have a policy for that” but “we can demonstrate this control performs, at the volumes we actually see, consistently across the group.” Sampling a handful of alerts a quarter and calling it assurance won’t satisfy a supervisor. Firms increasingly need to be able to show how controls perform over time. They must be able to demonstrate where they fail and what happens when weaknesses are identified.
For financial crime leaders, that’s an operating model problem before it’s a technology problem. It’s why we spend so much of our own work with clients on capability maturity assessment and benchmarking before anything else. You cannot demonstrate effectiveness in a framework you haven’t first measured honestly. Institutions still running fragmented, case-led approaches are going to find that model increasingly expensive to defend as harmonised supervision becomes the norm, regardless of whether AMLA itself is the one asking the questions.
Where agentic AI actually fits
The second theme threading through this year’s Summit was AI – inevitably. But the conversation has matured. Not long ago, AI panels at events like this were largely about whether generative AI could summarise a SAR. Now the conversation is about agentic AI systems that don’t just draft or predict but that plan, execute and adapt across a multi-step workflow running a KYC review end-to-end, orchestrating a set of checks across CDD, screening and transaction monitoring and escalating what genuinely needs a human judgement call.
It’s worth being precise about what’s real here versus what’s still marketing. Most agentic AI deployments in financial crime today are workflow augmentation, not autonomous decisioning. That’s not a limitation, it’s the correct design and it’s likely to remain the correct design for some time yet.
The institutions getting real value are the ones using agentic systems to compress the mechanical parts of a case like gathering data, cross-referencing sources, drafting a rationale, flagging inconsistencies so that a human analyst spends their time on judgement rather than assembly. It’s the shift we talk to clients about most: moving the analyst from administrator to investigator, away from the manual, repetitive groundwork of a case and toward the higher-value analysis only a person can do. The ones getting AI wrong are the ones trying to skip straight to autonomous decisioning without first proving explainability, audit trail integrity and how data quality can support it.
That distinction matters enormously as supervision harmonises across Europe, because “AI decided” is not an answer any credible supervisor is going to accept. Every agentic workflow needs a clear, inspectable trail: what data it used, what logic it applied, what it escalated and why, and where a human made the final call. Explainability isn’t a nice-to-have layered on afterwards and it has to be designed into the workflow from the start, or the efficiency gain becomes a supervisory liability the first time it’s tested.
This is exactly the principle we’ve built into KYX, our own AI-enabled client intelligence approach: using AI to remove manual friction from onboarding and due diligence, while keeping the evidentiary trail intact and auditable throughout. The goal isn’t automation for its own sake. It’s turning a slow, inconsistent, manually-assembled case file into a fast, consistent, defensible one.
Three things worth prioritising
Based on what came out of the Summit and the general direction both regulation and technology are travelling in, three things are worth acting on now rather than waiting for a formal deadline to force the issue:
Get an honest baseline first. Before investing further in tooling, run a proper capability maturity assessment against where the emerging regulatory technical standards are heading. Most institutions are stronger in some areas (screening) and materially weaker in others (ongoing due diligence consistency) than their own internal reporting suggests.
Treat data quality as the AI project. Every agentic AI initiative that stalls, stalls on data — inconsistent entity resolution, incomplete customer records, disconnected systems across fraud, AML, sanctions and KYC. In practice, that means investing in the data pipelines first: making sure the information an investigator or an AI agent needs is available, clean and ready to act on, rather than scattered across systems and reassembled by hand every time a case is opened. Fixing that is unglamorous and it’s also the actual prerequisite for anything more ambitious.
Build the audit trail in, not on. Whatever you deploy design the explainability and evidence layer as a first-class part of the workflow and not a reporting layer bolted on afterward. One of the more effective ways we’ve seen institutions do this is by treating policy as code: standardised, codified sets of rules that don’t just drive consistent decisions but leave a step-by-step trail of exactly what happened, when and why. It’s the difference between a control you can defend and one you’re hoping never gets tested.
The shift is already underway
None of this is a distant prediction. The standards that will define harmonised EU supervision are being written now toward the same evidence-based bar, even without a shared rulebook to point to. Agentic AI, similarly, isn’t an emerging technology anymore in financial crime it’s being deployed today by institutions that have done the unglamorous work of getting their data and AI governance right first regardless of which regulator they answer to.
The through-line from this year’s Summit is that “effective” is becoming the only word that matters. Not effective compared to where you were five years ago, but effective against an evidence-based standard. That’s a genuinely different bar than most financial crime programmes across Europe were originally built to meet, and it’s not one that arrives on a single date – it arrives gradually, then all at once, for whoever hasn’t started moving.
First Derivative works with financial institutions on exactly this transition from fragmented, case-led financial crime operations to scalable, evidence-based ones, using AI where it genuinely earns its place in the workflow rather than where it’s fashionable to put it. If any of this resonates with where your own programme is headed, we’d welcome the conversation.
First Derivative was a proud sponsor of the European Anti-Financial Crime Summit 2026, hosted by AML Intelligence in Dublin. Learn more about First Derivative’s Financial Crime capabilities at firstderivative.com/financial-crime.










