Illicit money moves through ecosystems, not sectors. Is AML finally catching up? It's tempting to read the latest wave of UK and European financial crime regulation as more of the same: more supervision, more consultations and more acronyms, but that misses the real story. What matters most isn't the expanded AML perimeter; it's the shift in how controls are supervised, challenged and evidenced.
Regulation Is Moving Across Sectors
In the UK, HM Treasury (the UK's finance ministry) has confirmed that the Financial Conduct Authority (FCA) will become the AML supervisor for legal service providers, accountancy firms and trust and company service providers, replacing a fragmented, long-criticized supervisory landscape.
The FCA has also finalised rules and guidance for the UK's future cryptoasset regime, bringing in-scope cryptoasset activities within a Financial Services and Markets Act (FSMA)-style authorization framework from October 2027. Across Europe, the Anti-Money Laundering Authority (AMLA) and Anti-Money Laundering Regulation (AMLR) package is driving an equally significant shift away from years of uneven implementation, in which member states transposed the same directives differently, toward a directly applicable rulebook and more centralised supervision.
Viewed individually, each development matters, but viewed together, they point to something considerably bigger. For financial institutions (FIs), the practical challenge is demonstrating that they understand risk across increasingly connected ecosystems.
For years, financial crime controls have been designed within organisational boundaries: banks looked at banking risk, professional services firms at their own risk and crypto firms at crypto risk. Supervisors followed the same logic. Criminal networks never respected those boundaries; they treat each sector as another link in a criminal supply chain.
Illicit money moves through ecosystems, not sectors. This is why a professional intermediary, a company formation agent, a crypto exchange, a nominee director and an offshore structure are rarely separate stories, but chapters in the same one. The problem is that those chapters sit in different systems, reviewed by different teams and overseen by different regulators. Regulators are now increasingly trying to close that gap.
More Rules Aren't the Point
A surface-level reading is that regulators are increasing scrutiny and firms must comply. While this may be true, it’s not a particularly useful perspective. The more pertinent question is whether firms can prove their controls work under such scrutiny. That is where regulatory expectations are heading: the conversation is shifting from “Do you have an AML framework?” to “Show me why it works.”
FIs will need to think harder about their exposure to law firms, accountancy practices, trust and company service providers and other intermediaries. Those businesses are not automatically high risk, but because persistent laundering schemes often use these channels to create ambiguity around beneficial ownership and source of funds.
That scrutiny cuts both ways. As oversight increases, alert volumes may rise, and firms that simply generate more alerts will drown in noise, not risk. The firms that get ahead will invest in analytics that separate genuine signals from routine activity, so rising scrutiny doesn't necessitate additional headcount.
Crypto Is Following a Familiar Path
Despite claims that crypto is a wholly new regulatory challenge, the pattern is familiar. Markets start outside formal supervision, then regulators expand their focus from financial crime controls to conduct, governance and accountability as the market matures. The FCA's new regime follows that trajectory, applying a more established financial-services regulatory model to in-scope cryptoasset activities.
For FIs, the implications are already taking shape. Fiat-to-crypto flows, wallet activity, mule accounts, sanctions exposure and layering typologies are becoming mainstream financial crime risks. By the time the new regime is fully operational, regulators are unlikely to be persuaded by institutions that are still assessing whether crypto exposure is relevant to their business.
More Output Doesn't Equal Better Outcomes
There's a real counterargument worth taking seriously: more supervision doesn't automatically mean less financial crime. The Law Society has cautioned that FCA supervision must remain proportionate and mindful of legal privilege and access to justice. More oversight can mean more cost and complexity, and it's fair to ask whether every requirement improves outcomes.
The industry has an uncomfortable history here: firms pour money into compliance programmes and generate huge volumes of alerts, yet the link to actually disrupting criminal finance is often hard to prove. Regulators can easily measure outputs such as policies and alerts. Effectiveness, however, is harder to quantif, particularly when hidden ownership, proxy actors and fragmented data don't show up cleanly in a management report.
This creates a real risk that firms respond to new expectations by simply doing more: more documentation, more attestations and more dashboards, spending significantly more while changing very little. A better response is to build a shared intelligence capability that connects data, alerts and risk signals across products and jurisdictions, so effectiveness can be shown, not just claimed.
Avoid a Patchwork Compliance Response
Every major regulatory shift creates winners and losers. Regulators gain clearer powers and greater consistency. Consulting firms gain transformation opportunities; legal advisers see greater demand for interpretation and implementation guidance, and technology providers benefit from renewed investment cycles. Larger institutions may even gain competitive advantages as barriers to entry increase for smaller firms.
The real risk is responding with disconnected initiatives: one programme for AMLR, another for crypto, another for intermediary risk and another for model governance. That's expensive and rarely builds lasting capability. The better question is whether firms can meet through shared, reusable infrastructure: common customer intelligence, reusable risk indicators, consistent case management and analytics that can be evidenced across multiple obligations. That's where long-term operating leverage gets built.
Preparing for Greater Regulatory Scrutiny
This is unlikely to be the last shift. The trajectory is clear: more scrutiny of enablers, tighter oversight of crypto, more transparency around beneficial ownership and growing expectations that firms can evidence control effectiveness on demand.
The organisations that navigate this best will be the ones that connect risk across silos, explain decisions clearly and stay agile enough to respond when regulators challenge them. The centre of gravity is shifting away from compliance for compliance's sake and towards demonstrable outcomes. That's the conversation regulators want to have and it's the one every obligated firm should be preparing for now.
For more information on changing regulations in the UK and Europe, visit the NICE Actimize
AMLA resource hub.
For an overview of NICE Actimize AML capabilities, explore the
AML Solutions Portfolio.