Insights

07 Oct 2026

Five FinCrime Challenges. One Operating Model Under Pressure.

Five FinCrime Challenges. One Operating Model Under Pressure.

On 3 September, more than 300 financial crime leaders came together in Frankfurt for the 6th Annual FinCrime Leaders Summit DACH. 

Across three stages, the discussions moved from AMLA and AMLR to AI, fraud, sanctions, KYC and KYB, intelligence sharing, crypto and the changing relationship between technology and human judgement. 

But across topics ranging from regulation to technology and emerging threats, the same challenge kept resurfacing: implementation. 

European financial crime teams are no longer preparing for transformation at some distant point. New regulatory structures are taking shape, AI is moving closer to operational use and criminal threats continue to evolve alongside them. 

The question running through Frankfurt was increasingly practical: how do institutions make all of this work inside financial crime operations? 

Five pressures stood out: 

AMLR → From rules to implementation 
AI → From experimentation to governed deployment 
Fraud → From isolated events to connected intelligence 
Sanctions → From static controls to changing external risk 
Digital assets → From separate risk to investigative continuity 

AMLR: The Challenge Is No Longer Understanding the Rules 

AMLR and AMLA formed an important backdrop to the discussions in Frankfurt, but attention is moving beyond understanding the European framework towards what implementation will require across financial crime operations. 

Greater harmonisation reaches much further than policy. The challenge is how greater consistency at EU level translates into controls that may have been designed around different national requirements, risk methodologies, data structures, and existing processes. Customer risk assessment, KYC and KYB, monitoring, investigations and governance all sit within that implementation challenge. 

That makes implementation an operating model question as much as a regulatory one. The test is whether new requirements can be translated consistently into the controls, processes, and decisions they affect. And as institutions reconsider those processes, another transformation is happening alongside them: technology is changing how the work itself can be performed. 

Frankfurt AMLR Panel
 
AI: The Question Is Shifting from Capability to Control 

AI discussions in Frankfurt reflected that transition. The question is increasingly shifting from where AI could support financial crime operations towards what happens when it begins influencing investigations, decisions and actions within live workflows. 

As AI-driven and increasingly agentic approaches move closer to financial crime operations, institutions have to consider more than model capability. What systems and data can AI access? What actions can it take? Where does human approval remain necessary? Can its decisions and actions be traced? And who remains accountable for the outcome? 

Greater autonomy therefore creates a governance question alongside a technology opportunity. Accountability, explainability, escalation, data quality and human intervention have to be considered as part of the operating model, not after deployment. The question is no longer only what AI can do, but what institutions are prepared to allow it to do, and under what controls. 

Frankfurt AI Panel

Fraud: The Intelligence Exists. Can Institutions Connect It? 

Fraud and scams increasingly expose the limitations of looking at financial crime through isolated transactions. Individual institutions may see different parts of the same activity, from customer behaviour and beneficiary accounts to subsequent fund movements and links to wider criminal networks. 

The operational challenge is what happens to those signals once they exist. A fraud team may understand how a victim was manipulated, while AML or investigations teams may hold information about the beneficiary, connected accounts or subsequent movement of funds. The investigative picture changes when those separate views can be connected. 

For operating models built around separate fraud, AML and investigation workflows, the question is whether intelligence can move between those functions quickly enough to expose the wider network rather than only the individual event. Once the activity crosses institutional or national boundaries, the gap between what the financial system collectively knows and what one institution can see becomes even more significant. 

Frankfurt Fraud Panel

Sanctions: External Risk Is Moving Faster Than Internal Controls 

Sanctions and geopolitical discussions in Frankfurt reinforced how quickly external developments can change the risk institutions are expected to identify and manage. 

The challenge is the gap between a changing external risk environment and the information already held within an institution. New sanctions exposure, changes in ownership or control, counterparties and geopolitical developments can alter the context around an existing relationship without the underlying customer or transaction data necessarily changing. 

That puts pressure on how quickly new external intelligence can influence internal risk assessment, screening, escalation, and investigative decisions rather than waiting for the next established review cycle. The operational question is how quickly a change outside the institution can change a decision inside it. That same challenge of maintaining context becomes particularly relevant when funds move between traditional and digital financial systems. 

Frankfurt Sanctions Panel

Digital Assets: Can the Investigation Follow the Money? 

Crypto and DeFi discussions increasingly sit within the wider financial crime architecture rather than alongside it. The more significant investigative challenge emerges when activity moves between traditional accounts, payment providers, digital assets and jurisdictions within the same financial trail. 

At each transition, different institutions, data sources and investigative capabilities may hold another part of the picture. The question is whether the context already established around the customer, transaction or counterparty can follow the funds as they move into another financial environment. 

This makes continuity of investigation more important than treating digital assets as an isolated risk category. If the financial trail crosses different infrastructures, but the investigative context does not move with it, visibility can fragment precisely when the wider movement of funds becomes most relevant. 

Frankfurt AMLR Panel

Five Pressures. One Operating Model. 

AMLR, AI, fraud, sanctions and digital assets create different requirements, but they increasingly converge inside the same financial crime operation. 

Each creates a different operational test. AMLR tests consistency of implementation. AI tests the boundaries between autonomy and accountability. Fraud tests whether intelligence can move across functions. Sanctions test how quickly changing external risk reaches internal controls. Digital assets test whether investigative context survives across financial environments. 

Across all five discussions, the pressure ultimately reaches the same chain: 

Regulation → Data → Intelligence → Investigation → Intervention 

A regulatory requirement only changes outcomes when it reaches controls. Data only creates value when it becomes usable intelligence. Intelligence only matters when it changes an investigation or decision. And an investigation only disrupts financial crime when it leads to effective intervention. 

The question coming out of Frankfurt is whether existing operating models can keep that chain connected as each part becomes more complex. 

One Day in Frankfurt. Five Challenges to Take Forward. 

More than 300 financial crime leaders came together in Frankfurt with different priorities, operating models and areas of expertise. Across the day, however, the discussions repeatedly returned to implementation. 

How do institutions turn regulatory change into workable controls? Introduce AI without losing accountability? Connect fraud intelligence across functions? Bring changing geopolitical risk into existing decisions? And maintain investigative visibility as money moves across financial environments? 

Frankfurt did not produce one answer to those questions. It showed how increasingly difficult it is to solve in isolation. 

Stay ahead of the developments shaping financial crime through FinCrime Fighters, with insider insights, expert analysis and industry updates delivered straight to your inbox. 
 
Become a FinCrime Fighter. Subscribe now!

Loading