Just 4% of Financial Institutions Continuously Update Their Compliance Controls Despite Risks
A new SymphonyAI and AML Intelligence report reveals under 5% of financial firms use continuous compliance monitoring despite soaring AI investment.
5 October 2026 · 3 min read

SymphonyAI, a global leader in vertical AI product platforms, and AML Intelligence, the leading source of news and insight for the financial crime compliance community, today released the FinCrime Frontier 2026–27 Report. The report finds that most financial institutions still rely on periodic review cycles to manage financial crime risk, even as the threats and regulations they are meant to track continue to evolve dynamically.
Based on the perspectives of more than 200 financial crime and compliance leaders, including senior executives from major global financial institutions, the research finds that just 4.7% of financial institutions continuously update their compliance monitoring and controls as risk changes. Meanwhile, 56.8% have not adopted "always-on" compliance monitoring at all, are only exploring it, or remain at an early pilot stage. The findings point to a structural gap: financial crime typologies, payment ecosystems, and regulatory expectations are evolving continuously, while most compliance programs are still built around scheduled review cycles.
The Operational Burden of False Positives and Manual Review
The research highlights the practical cost of that gap. Without the ability to continuously recalibrate what warrants attention, investigators are left sorting through volume rather than focusing on real risk. Seven in ten respondents (70.8%) report that 5% or fewer of the alerts they investigate result in an escalation or SAR/STR filing—meaning the vast majority of investigative effort never translates into identified risk.
The regulatory environment is intensifying the challenge. AI and model governance, along with the adequacy of technology and systems, have jointly become the most frequently cited regulatory concerns, each selected by 40.8% of respondents. This has overtaken cross-border regulatory complexity, which topped the list a year ago. The shift suggests regulators are moving from evaluating whether firms have a policy to evaluating whether the technology behind it performs as expected and can be evidenced.
The research also finds that operating models have changed less than investment levels might suggest. AI and automation are now the leading compliance investment priorities, cited by 61.9% of respondents, yet 76.3% of institutions still review alerts manually or with only partial automation—a figure that has changed little from the prior year. The result is a widening gap between how much institutions are investing in AI and how much their day-to-day operations have actually changed.
There are signs of progress. Fully manual alert reviews have declined from 21.3% to 16.5% year-over-year. Additionally, more than half of the respondents describe their organization’s response to regulatory change as forward-leaning—whether by accelerating modernization, reshaping their operating model, or enabling a shift to proactive, intelligence-led compliance—even though reactive workloads remain the single largest response. Taken together, the findings suggest an industry that is beginning to move, but not yet at the pace its risk and regulatory environment now demands.
Closing the Operational Tempo Gap in Compliance
"This year's data draws a clear line," said Stephen Rae, Co-Founder and Chair of AML Intelligence. "Most financial institutions aren't short on commitment to modernizing compliance; they're short on operating tempo. Criminal typologies shift by the week, transaction volumes keep climbing, and regulatory expectations are tightening—yet compliance functions are still largely built to reassess risk on a schedule rather than as conditions change. That gap, more than any single technology choice, is what the industry needs to close next."
"The research shows an industry moving in the right direction, but the pace of change in financial crime compliance—across emerging threats, regulation, and increasing business complexity—continues to outrun most compliance programs' ability to adapt," said John Edison, President of Financial Services at SymphonyAI. "The next phase will be defined by how effectively institutions use AI to connect risk intelligence with institutional judgment, transforming detection, investigation, and governance so that controls respond dynamically as risk changes, while maintaining appropriate human oversight and accountability."
The FinCrime Frontier 2026–27 Report examines regulatory change, the economics of compliance, operational performance, AI and automation maturity, data and governance readiness, and the future of financial crime compliance.
Contributor at The London News