From Risk Assessment to Operating Model: Why KYC Is Now the First Line of Defense Against Fraud

KYC

June 5th, 2026

riskassessment_682_325

The 2026 U.S. National Money Laundering Risk Assessment (NMLRA) does not introduce entirely new categories of financial crime. What it clearly demonstrates, however, is that the operating model of financial crime has changed in material ways, particularly the way fraud, identity abuse and money laundering now intersect. 

What the Data Shows

The numbers reinforce this shift. In 2024, fraud generated more than $16 billion in reported losses, with actual losses likely tens of billions of dollars higher. The U.S. federal government estimates annual fraud losses of $233–$521 billion, creating a massive pipeline of illicit proceeds requiring laundering. At the same time, the median loss in money laundering cases increased by more than 150% over the past five years, with large-scale cases growing rapidly. 

Taken together, these findings point to a structural change in how financial crime is generated, scaled and monetized. For financial institutions (FIs), this shift has direct implications. KYC must now operate as a converged intelligence layer across fraud, AML and cyber-risk operations, serving as a first-line defense against identity-driven financial crime across the customer lifecycle. 

Increasingly, this requires institutions to move beyond fragmented onboarding and monitoring processes toward a continuous customer intelligence framework where onboarding, fraud prevention, screening and AML operations operate from shared risk intelligence across the lifecycle. 

Fraud as the Front Door to Laundering

The NMLRA reinforces the notion that fraud is now one of the largest generators of illicit proceeds, alongside drug trafficking, producing hundreds of billions of dollars annually. 

Investment fraud alone drove $6.57 billion in reported losses in 2024, a 44% increase year-over-year. Confidence scams added another $5.5 billion, while business email compromise schemes accounted for $2.7 billion.  Identity theft incidents exceeded one million reported cases, with identity-related suspicious activity representing 42% of filings and $212 billion in suspicious activity. Digital asset investment scams generated $5.8 billion in losses, creating additional volumes of illicit proceeds that must ultimately be moved and laundered. 

The report details how these proceeds are operationalized and moved. Professional money laundering networks and organized money mule activity facilitate the domestic and cross-border flow of fraud funds, with mule accounts often opened using stolen or synthetic identities, serving as pass-through vehicles before funds are layered or transferred internationally. These networks increasingly leverage controlled accounts and stablecoins as additional channels for moving and laundering fraud proceeds.  

Technology is accelerating identity-related financial crime. AI-generated text, voice cloning and deepfake media are increasingly used in attempts to bypass customer identification checks. Synthetic identities are created by combining stolen or fabricated personally identifiable information with AI-generated artifacts, enabling accounts that appear structurally compliant but are operationally fraudulent. 

Fraud and money laundering are no longer sequential control problems. They are structurally linked at the point of identity establishment. When an institution onboards a compromised or synthetic identity, fraud and AML exposure are created simultaneously. 

Technology Has Industrialized Identity Abuse

The NMLRA underscores how technology has transformed both the scale and effectiveness of illicit finance. AI-enabled fraud is now measurable, with over 9,000 AI-related complaints recorded in the first seven months of 2025.

At the same time, professional money laundering networks are scaling the infrastructure behind these activities. Chinese money laundering networks alone were linked to $312 billion in suspicious activity across 137,000 reports. 

These networks make financial crime increasingly resilient to traditional control strategies. Channel volume declines do not eliminate fraud risk. Criminal actors adapt to identity and control weaknesses wherever they exist. Illicit finance now scales like a platform business characterized by low marginal cost, high automation and rapid iteration. 

The Core Vulnerability: Static Identity in a Dynamic Risk Environment 

Across fraud and AML cases, one root weakness appears consistently: institutions validate identity at onboarding and then assume it remains stable. In reality, identities, ownership structures and risk profiles are volatile. Beneficial ownership can change rapidly, control parties can be inserted or layered through intermediaries, consumer accounts can transition into mule behavior within weeks and seemingly legitimate businesses can be repurposed into laundering conduits through nominee manipulation. 

The issue is not merely incomplete data. It is the failure to continuously validate who is operating the account, who controls the entity, who ultimately benefits from the activity and whether observed behavior aligns with stated purpose. Once the identity foundation is compromised, downstream transaction monitoring operates on corrupted inputs. 

This challenge is amplified when onboarding, fraud and AML functions operate through disconnected workflows. Evolving risk indicators are often assessed within individual teams rather than shared across the institution, resulting in fragmented investigations, inconsistent risk assessments and delayed responses to emerging threats.  

  • Onboarding: Cut false-positive reviews on adverse media hits during initial customer due diligence and surface confirmed risk faster on high-priority cases. 
  • Periodic review and pKYC: Apply standardized scoring, summarization and risk categorization across every refresh cycle, every region and analyst tiers. 
  • Investigations and escalation: Hand off enriched entity profiles and structured documentation downstream, not raw article stacks. 

As part of X-Sight DataIQ, screening intelligence integrates with broader data, entity resolution and case context, strengthening investigative workflows without introducing additional operational complexity. 

The Structural Shift: Identity Intelligence as a Shared Service

What must change is not simply the controls, but the operating model itself. Most institutions still manage onboarding, fraud and AML monitoring as parallel control stacks with limited signal propagation across them and risk reconciled only after exposure has materialized. The required shift is to treat identity intelligence as a shared, continuously updated service that operates across onboarding, fraud and AML, rather than as siloed control functions that engage sequentially. 

In practice, this means onboarding, fraud and AML teams operating from shared customer and entity intelligence rather than manually reconstructing fragmented profiles across disconnected systems every time risk changes or investigations escalate.  

This includes:  

  • Entity resolution and graph analytics linking customers, counterparties, devices and behavioral signals  
  • Dynamic identity confidence scoring that recalculates whenever behavior, ownership or network exposure changes  
  • Real-time signal propagation directly into transaction monitoring models rather than running in parallel  
  • Integrated governance with shared models, shared thresholds and consistent audit logic across functions 

This reflects a move from static identity verification to continuously evaluated identity assurance. The ability to unify customer, counterparty and related-entity intelligence into a shared operational framework helps institutions identify hidden relationships, coordinated mule activity, nominee structures and network-based financial crime patterns that isolated customer records often fail to expose. 

Technology as Defensive Parity 

If criminal actors are using AI to fabricate identity artifacts, institutions must deploy AI to detect manipulation, identify synthetic identity patterns, surface coordinated mule networks and distinguish authentic from fabricated signals. Capabilities such as entity resolution, network analytics and graph modeling become foundational rather than advanced enhancements. 

Critically, these capabilities must remain explainable and auditable, as regulatory expectations continue to rise. The objective is not fully autonomous decisioning, but scalable operational intelligence where risk signals, prioritization logic and workflow recommendations remain explainable and reviewable by investigators and compliance teams. 

This includes clear visibility into: 

  • Why alerts escalated  
  • Which signals influenced risk scoring or identity confidence  
  • How policies and thresholds were applied  
  • What changes triggered reassessment workflows  
  • Where analyst intervention occurred throughout the lifecycle 

Technology is no longer an overlay on KYC. It is the mechanism that enables institutions to continuously assess identity risk as conditions change. 

Strategic Imperative: Identity as Core Risk Infrastructure 

For financial crime leaders, treating identity as core risk infrastructure is becoming a strategic imperative. Key priorities include: 

  • Breaking silos between onboarding, fraud and AML teams 
  • Maintaining a unified view of customers, counterparties and related entities 
  • Embedding identity intelligence into transaction monitoring models 
  • Designing for real-time reassessment rather than periodic review 
  • Ensuring auditability of AI-driven decisions 
  • Measuring identity integrity as a strategic risk metric 

Institutions that unify typologies, signals and risk models across the customer lifecycle will be better positioned to detect coordinated crime networks before losses scale. 

Bottom Line

The 2026 NMLRA confirms a measurable shift. Fraud is generating billions in annual losses. FIs are filing SARs representing tens of billions in suspicious activity. AI is accelerating identity manipulation. Criminal actors are successfully opening accounts using synthetic or AI-fabricated identities. 

 As fraud, money laundering and identity abuse become increasingly interconnected, KYC can no longer function solely as a front-end compliance requirement. It must operate as a continuous risk discipline spanning the entire customer relationship. 

Organizations investing in integrated onboarding and fraud decisioning, enterprise-wide entity resolution, network analytics, embedded identity confidence scoring within transaction monitoring and explainable AI governance are already moving toward this model. Solutions that unify these capabilities, such as NICE Actimize’s integrated financial crime suite, enable identity intelligence to operate as a shared control layer rather than disconnected systems. 

By unifying customer, counterparty and related entity intelligence into a shared operational framework, institutions can improve detection accuracy, reduce investigative fragmentation and respond to emerging threats with greater speed, consistency and resilience. 

View 4 Steps to Streamline & Simplify KYC Data Practices

    Speak to an Expert