Cian Fernando, CEO of Aqua Global, explains why as increased sanctions expand, the ability to evidence compliance at the transaction level will soon become a baseline expectation for banks

From 2028, the top 40 EU banks will face direct scrutiny under the Anti-Money Laundering Authority (AMLA). This development has been a long time coming. Cross-border flows are accelerating, and financial crime is evolving just as fast. The European Banking Authority found in 2025 that 70% of competent authorities report high or rising money-laundering and terrorist-financing risk in the financial sector.

While the AMLA’s direct supervision will only initially cover 40 banks, the move sends an industry-wide signal. The bar is rising on how banks are judged, how controls are evidenced, and how financial crime frameworks stand up under pressure. These expectations won’t just stop at the largest institutions, but will increasingly shape expectations across the wider market.

For banks relying on translation tools to bridge the gap between legacy infrastructure and new messaging standards, the clock is ticking. Many legacy systems weren’t designed to store structured AML data or provide end-to-end traceability. When regulators come knocking, fragmented records leave banks exposed to fines, remediation, and reputational damage. Those who wait risk reacting under pressure rather than staying ahead of the curve.

From Screening to Structured Evidence

The AMLA was established in 2024 to strengthen and harmonise anti-money laundering and counter-terrorist financing (AML/CFT) supervision across the EU. For years, oversight has been national, creating inconsistencies in assessment and enforcement. AMLA’s mandate is to create greater consistency, convergence and accountability, reducing gaps that financial crime can exploit.

To support this, European authorities developed a first package of Regulatory Technical Standards (RTS). The RTS specifies standardised data points and criteria that national supervisors will use to assess money-laundering and terrorist financing risk. This involves a three-step process: assess inherent risk, evaluate AML/CFT controls, and determine a residual risk score.

The decision to directly supervise 40 of the EU’s highest-risk cross-border banks from 2028 marks the next phase. It signals that this harmonised methodology will not remain theoretical, but will be brought into direct EU-level application. The direction of travel is clear. Scrutiny is becoming more centralised, more consistent and more exacting, with less room for interpretation or inconsistency.

Supervisors will now assess not only the presence of controls but also how effectively those controls are applied and how risk assessments translate into action. Banks must be able to show precisely how decisions were made, who approved them, and what follow-up steps were taken. Without a complete, end-to-end record, it is impossible to demonstrate that controls are effective or that residual risks are properly managed in a defensible way.

Meeting AMLA’s expectations will be challenging for many banks. Translation tools – used to convert payment message formats to meet evolving requirements – were never designed to capture structured AML verification data or link compliance decisions to individual transactions. They can reformat messages, but they do not embed verification records into the core systems. As a result, critical AML information ends up sat across multiple platforms. Some data remains in the originating platform, some in separate AML systems, whilst workflow decisions may be recorded elsewhere entirely.

The result is fragmentation. Data is split across systems, teams, and workflows. Critical AML information is scattered, making it difficult – if not impossible – to create a single, coherent view of a payment and its associated AML checks. Under AMLA’s new standards, this kind of disconnected record-keeping will be a major liability.

Recent enforcement action shows how quickly these weaknesses can translate into real consequences. In July 2025, the Financial Conduct Authority fined Barclays £42 million for weaknesses in financial crime controls, citing failures in customer due diligence and ongoing monitoring. The AMLA can impose similarly strong penalties – up to €10 million or 10% of a company’s annual turnover. Banks that delay upgrading their AML frameworks not only risk steep fines, but lasting damage to client trust should they fall victim to control failures they cannot clearly explain.

Modernising Payments to Meet AML Demands

As regulatory expectations tighten, banks face a choice. They can continue layering temporary fixes onto legacy infrastructure, or rethink how compliance is built into payments altogether. Stop-gap solutions may appear cost-effective in the short-term, but they often add complexity, increase operational risk and make evidencing compliance harder over time.

A more sustainable path is to embed compliance directly into the transaction lifecycle. That means ensuring AML evidence – screening results, verification references and workflow decisions – sits within the payment record itself, creating a clear and defensible audit trail. Payments platforms that integrate seamlessly with AML and sanctions providers can capture responses in real time, reducing delays and manual intervention. They also standardise data across message formats, allowing banks to build transparency into everyday operations. Banks that take this approach will be better placed to meet rising supervisory expectations; those that delay may find short-term workarounds turning into long-term constraints.

The AMLA Wake-Up Call

AMLA’s supervision of 40 institutions is a starting gun for banks. As increased sanctions expand, the ability to evidence compliance at the transaction level will soon become a baseline expectation. Banks need to move now to get their ducks in a row and ensure their systems are fit for purpose. Those that embed verification, real-time monitoring, and structured workflows into their core processes will navigate scrutiny with confidence. Those that delay risk chaos – scrambling to trace transactions, facing fines, and suffering reputational damage when the rules inevitably tighten across the board.

Learn more at aquaglobal.co.uk

  • Cybersecurity in FinTech
  • Digital Payments

New research from Aqua Global shows banks are struggling to keep up with compliance, as legacy tech drags them down

Aqua Global, the financial messaging hub built for payments, treasury and securities processing, today revealed research showing European banks are prioritising compliance over customer experience as legacy infrastructure struggles to keep pace.

The survey of 150 European IT banking leaders, with half based in the UK, showed that:

  • Regulation is putting a drag on innovation:
    • 77% of respondents say regulatory demands outweigh customer demands when it comes to payment modernisation.
    • 67% spend more effort adapting systems to new standards than improving customer experience.
  • Banks fear missing milestones – but can’t keep up:
    • 77% say missing a key regulatory milestone would cause significant operational and reputational damage.
    • But 60% admit their existing infrastructure struggles to keep pace with evolving standards.
  • Richer data requirements expose structural weaknesses:
    • 72% admit richer data requirements (e.g. AML, sanctions, fraud) have exposed gaps in their current infrastructure.
    • Structured addresses, AML/sanctions-related data and counterparty identifiers (BIC/LEI) are the most difficult piece of data to capture.

“The challenge with richer payment data isn’t availability, it’s fragmentation. Information sits across multiple systems and formats, making it hard to build a complete, trusted view of a transaction. The ability to manage, govern and validate data at scale is quickly becoming a defining factor in payments resilience. This is why 81% of respondents believe a unified messaging hub across multiple channels will be essential to remain compliant and competitive in the future.” Elliot Wood, Chief Technology Officer at Aqua Global.

ISO 20022 and T+1: Regulatory Compression Exposes Legacy Fragility

One in five respondents experienced downtime and/or payment disruption during migration to the new ISO 20022 standard. Almost all respondents (97%) experienced challenges, with the top three cited as:

  1. Legacy systems unable to handle structured ISO 20022 data.
  2. Poor underlying data quality for enriched ISO 20022 fields.
  3. Integrating challenges with other third-party systems, such as AML, sanctions and fraud systems.

As a result, 65% still rely, at least in part, on translation tools to remain compliant, even though 83% believe such short-term fixes will prove more costly in the long run.

The same structural weaknesses are now surfacing in preparation for T+1 settlement. While 21% of banks have taken action to prepare, almost a quarter (23%) have no plans in place. Legacy systems incapable of supporting compressed settlement windows without significant investment remain the most cited barrier.

Together, ISO 20022 and T+1 highlight a broader issue: regulatory timelines are accelerating faster than banks’ infrastructure can adapt.

“The migration challenges we’re seeing aren’t isolated incidents – they expose the structural limits of legacy payment architecture,” says Cian Fernando, CEO of Aqua Global. “Treating regulatory change as a tick-box exercise encourages short-term fixes that increase complexity. Banks that modernise natively reduce cost, operational risk and friction over time. As regulatory deadlines tighten and data requirements grow richer, banks relying on fragmented systems face rising operational risk and mounting cost pressures, with less capacity left to compete on customer experience.”

To learn more download the full From Compliance Burden to Competitive Advantage report

About Aqua Global

For over 43 years, Aqua Global has delivered a robust suite of financial messaging and transaction automation solutions for payments, treasury, and securities processing that integrate internal systems to external services. Trusted by leading banks across 22+ countries, our Aquila orchestration and integration framework offers exceptional performance, control, and scalability.

Learn more at aquaglobal.co.uk

  • Cybersecurity in FinTech
  • Neobanking