Effectiveness Is the New Compliance: AMLA, Agentic AI & the Next Phase of Financial Crime Compliance in Capital Markets
Across global capital markets, one word has quietly displaced "compliance" in regulatory conversations: effectiveness. The distinction matters. Effectiveness asks not whether a policy exists, but whether a control demonstrably performs at scale, under scrutiny and consistently across the group. That's a genuinely higher bar than most financial crime programs were originally built to meet and one capital markets firms feel more acutely than most, given the volume, velocity and cross-border complexity of the business they run.
Two forces are converging to make that bar unavoidable. First, regulators across Europe are moving in a clear direction: less tolerance for compliance frameworks that exist only on paper, more expectation that firms can produce evidence their controls actually work.
Second, agentic AI has matured to the point where capital markets firms can deploy it to help meet exactly that standard. Understanding both forces, and how they interact, is where compliance leaders now need to focus their thinking.
How AMLA, the FCA & FINMA Are Raising the Evidentiary Bar
The EU's Anti-Money Laundering Authority (AMLA) represents the most concrete structural shift in AML/CFT supervision in a generation. Having taken on its mandate from the European Banking Authority (EBA), AMLA is finalizing the regulatory technical standards that will define what "good" looks like across a single EU rulebook. Standards that apply as fully to capital markets firms, broker-dealers and their custody, clearing and prime brokerage arrangements as they do to retail and commercial banks.
Direct supervision of an initial cohort of roughly 40 cross-border credit and financial institutions is expected to begin within the next two years, but the standards those institutions are measured against are being written now and will shape supervisory expectations well beyond whichever firms end up directly in scope.
That has particular teeth for capital markets. The structures that make capital markets business efficient across group entities, correspondent relationships and cross-border settlements show how EU standards have a way of becoming the de facto benchmark. The FCA in the UK and FINMA in Switzerland are independently driving their own regulated populations toward the same evidence-based standard, each on their own timelines.
What that means in practice is a harmonized evidentiary bar: not "we have a policy for that" but "we can demonstrate this control performs, at the volumes we actually see, consistently across the group." Sampling a handful of alerts per quarter and calling it assurance won't satisfy a supervisor built around consistency and comparability across multiple institutions and jurisdictions. For firms managing complex transaction flows, high-velocity data and multi-jurisdictional exposure, the operational implications are significant.
The Expanding Role of Agentic AI
The AI conversation in financial crime has matured considerably. Not long ago, discussions centered on whether generative AI could summarize a suspicious activity report. Today, the focus has shifted to agentic AI systems that don't just draft or predict, but plan, execute and adapt across multi-step workflows: running a know-your-customer (KYC) review end-to-end, orchestrating checks across customer due diligence, screening and transaction monitoring, and escalating only what genuinely requires human judgment.
Precision matters here and it matters more in capital markets than almost anywhere else in financial services. For example, transaction monitoring in equities, fixed income or derivatives environments produces high volumes of alerts with complex interdependencies. The capital markets firms generating real value are those using agentic systems to compress the mechanical parts of a case: gathering data, cross-referencing sources, drafting a rationale, flagging inconsistencies. The result is that human analysts spend their time on judgment rather than assembly, moving from administrator to investigator.
The institutions getting AI wrong are those trying to skip straight to autonomous decisioning without first establishing explainability, audit trail integrity and data quality. In a capital markets context, where the underlying ownership and settlement chains are often several layers deep and the cost of a control failure is material, "the AI decided" is not an answer any credible supervisor will accept. Every agentic workflow needs a clear, inspectable trail: what data it used, what logic it applied across which entities in the chain, what it escalated and why, and where a human made the final call.
Improving Compliance Effectiveness
The pathway to scalable, evidence-based programs that meet the standard regulators are increasingly applying starts with an unbiased understanding of your baseline capability. Before investing further in technology, conduct a rigorous capability maturity assessment against where regulatory technical standards are heading. Most institutions are stronger in some areas, such as sanctions screening, and materially weaker in others, such as ongoing due diligence consistency, than their internal reporting suggests. Without an accurate baseline, any AI investment risks optimizing the wrong part of the process.
This assessment typically surfaces structural gaps in governance and operating model design. Firms that undertake it seriously often restructure their financial crime operating model before any technology is deployed, consolidating fragmented functions and clarifying accountability between first and second lines.
Next, firms must address their data quality. The most effective approaches treat data quality as an AI project. Every agentic AI initiative that stalls does so on data: inconsistent entity resolution, incomplete customer records, disconnected systems across fraud, AML, sanctions and KYC. In capital markets environments, where data flows from trading systems, prime brokerage platforms, custody chains and multiple counterparty sources, this challenge is acute. Investing in data pipelines before deploying AI agents isn't a precursor to the real work; it is the real work.
Firms that make this investment typically consolidate data ownership across functions that have historically operated in silos. That means clearer accountability between technology, compliance and operations teams, and often a new or elevated data governance function with direct reporting lines to the chief compliance officer or chief data officer.
Finally, firms need to design explainability directly into their agentic workflow. Explainability can't be a reporting layer added after deployment. It has to be designed into the workflow from the start, or efficiency gains become a supervisory liability the first time they're tested.
One effective approach is treating policy as code: standardized, codified rule sets that don't just drive consistent decisions but leave a step-by-step trail of exactly what happened, when and why. That's the difference between a control a firm can defend and one it's hoping won't be tested.
Firms that build explainability-first workflows often discover that the process forces greater alignment between legal, compliance and technology teams on what a defensible decision actually looks like. That cross-functional alignment tends to reduce control failures over time by ensuring that policy intent and system behavior stay in sync.
The Path Forward for Capital Markets Compliance Functions
The regulatory shift toward evidence-based supervision isn't a distant deadline. The standards being written now will shape supervisory expectations across the EU and influence regulators beyond it. Agentic AI, similarly, isn't an emerging technology in financial crime; it's being deployed today by firms that have done the foundational work of getting their data and AI governance right first.
The firms that will be best positioned are those treating the current period as a runway, not a waiting room. That means starting with an honest assessment of where controls actually perform, investing in the data infrastructure that makes AI agents effective and building explainability into workflows as a design principle rather than an afterthought.