top of page

Alerts Are Not Evidence: AMLA Redraws the Monitoring Obligation

Writer: Elizabeth Travis
Elizabeth Travis
11 minutes ago
7 min read

Three weathered white industrial storage tanks with railings under a blue cloudy sky, viewed from below.

On 3 June 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) opened a consultation on how firms should watch a customer relationship once it has begun. It reads, at first, like housekeeping: guidance issued under Article 26(5) of the Anti-Money Laundering Regulation (AMLR), horizontal in scope, technologically neutral, insistently proportionate. More than 1,200 people joined the public hearing on 2 July, which is not the audience an administrative clarification attracts. Yet the importance of the draft lies not in what it adds to the obligation but in what it does to the unit of assessment. Monitoring ceases to be a system a firm operates and becomes a framework a firm must defend.


The timing gives that shift teeth. The AMLR applies directly across the Union from 10 July 2027, and AMLA expects to issue the final text in the fourth quarter of 2026. The draft states that competent authorities should have regard to it when assessing whether a firm's ongoing monitoring is effective. Consultation closed on 3 September. The text is no longer open to argument and not yet final, which makes this the moment firms discover what they will be living with rather than the moment they can shape it.


Ongoing monitoring is not transaction monitoring


The opening principles settle a question the industry has argued over for a decade. Ongoing monitoring, AMLA states, should not be confined to transaction monitoring; it should reach the activities, behaviours and events that arise across the whole life of a relationship. The background section explains the drafting choice. AMLA introduced the language of activities to reflect the diversity of business models the AMLR now covers, including those in which nothing resembling a payment ever passes through the firm.


Those models are no longer marginal. Football clubs and agents, investment migration operators, traders in high-value goods, crowdfunding platforms and credit intermediaries are all obliged entities, many of them applying customer due diligence for the first time and holding no transactional data to interrogate. A scenario engine calibrated to payment velocity has nothing useful to say about any of them.


Yet a large bank that reads the draft as a document about the non-financial sector will have misread it. The guidelines are deliberately horizontal, and the principle applies without adjustment to institutions that hold rich transactional data. AMLA expects the framework to detect risks that appear only when transactions and activities are read together over time: linked or aggregated behaviour across accounts, customers, devices and wallets; network relationships that obscure ownership or economic purpose; individually unremarkable transactions that form a pattern once value is accumulated, split or moved on. That is not a tuning exercise. It is a different question put to a different set of data.


The AMLA framework already crosses regimes


More striking is how far the draft reaches into systems built for other purposes. A monitoring framework, AMLA says, should build on the systems and processes required by other Union legislation, and it names two. The first is the Transfer of Funds Regulation, which carries originator and beneficiary information alongside payments and certain crypto-asset transfers. The second is the Payment Services Regulation, still a proposal when AMLA drafted, whose fraud detection requirements sit outside the anti-money laundering perimeter altogether. It adds, for good measure, any other existing system intended to detect unusual customer behaviour.


Sanctions occupy stranger ground. The background section states plainly that sanctions compliance falls outside these guidelines. The draft then requires the monitoring framework to be capable of identifying patterns, behaviours or linkages indicating the evasion or non-implementation of targeted financial sanctions, whether through intermediaries, ownership and control structures, counterparties, assets or transaction patterns. The disclaimer governs what AMLA is regulating in this instrument. It does not govern what the framework must be able to see.


For firms that run screening, fraud, payment transparency and monitoring as separate estates with separate owners, budgets and vendors, that combination is uncomfortable. Nothing in the draft demands a single system or a single team. But the obligation is now expressed at a level above the individual control, and no individual control discharges it.


The industry drafted this first


None of this thinking originates with AMLA. In July 2024 the Wolfsberg Group published its Statement on Effective Monitoring for Suspicious Activity. Transaction monitoring, it argued, is properly understood as a subset of a wider discipline taking in customer behaviour, customer attributes and ongoing customer due diligence, and capable of extending to employees, vendors and counterparties. Its second statement, in August 2025, addressed the transition to innovation through three concerns: transition and validation, the balance between model risk and financial crime risk, and explainability.


The draft guidelines echo all three, and closely. Where a firm materially changes its detection logic or analytical method, AMLA expects a documented transition and validation framework, and states that validation must go further than comparing outputs against the legacy system. On model risk, the draft asks firms to weigh inaccuracy, bias and opacity against the opposite danger of delaying improvements in detection, cautioning against constraints that do not materially improve outcomes. On explainability, it requires a firm to demonstrate the role, functioning and outputs of a tool to a supervisor without requiring full technical interpretability of the model beneath it.


Yet the convergence matters less than the change in status. A Wolfsberg statement is an argument advanced by an industry group about what effective practice should look like; a guideline issued under Article 26(5) is what a supervisor will hold a firm to. What a firm could once cite as ambition it will shortly have to evidence as practice.


Volume stops being the evidence


The most consequential sentence in the draft is not about scope at all. Effectiveness, AMLA says, should not be judged solely by alert volumes, reporting volumes or the breadth of typology coverage where these do not produce meaningful detection or escalation. What should be weighed instead is the timeliness of escalation, the appropriateness of outcomes, recurring deficiencies and whether the framework still addresses the risks the firm has identified in its business-wide risk assessment.


Most board reporting is built on the measures that sentence sets aside. A pack showing alerts generated, alerts closed, reports filed and scenarios live answers a question the supervisor has now said it is not principally asking. Backlogs get the same treatment: firms are asked to maintain mechanisms that identify, monitor and address any accumulation of unresolved monitoring outputs, which turns a familiar operational embarrassment into a named question about whether the framework works.


Automated closure survives, with limits. It may be applied only where analysis discloses no suspicion, no unusual activity and no material risk indicator; never to higher-risk customers or situations requiring enhanced scrutiny; and only under human oversight that includes sampling and the review of cases where suspicion was not identified. Reviewing what a system did not flag is a harder assurance exercise than reviewing what it did, and few firms perform it at scale.


Design cannot defeat detection


The guidelines are generous about structural limitations and unyielding about their source. A firm with no access to transaction data, or which does not execute transactions at all, may build its monitoring around documentation, mandates, instructions and event-driven review; such constraints are not in themselves deficiencies, provided they are understood, documented and mitigated. That is a sensible accommodation for lawyers, estate agents and corporate service providers.


But the sting sits a few paragraphs later. Such limitations, the text says, should not "arise from, or be reinforced by, the design" of a firm's products, services or business practices, and legal or technical constraints cannot excuse the absence of monitoring where the firm was in a position to intervene. Monitorability becomes a constraint on product design rather than a consequence of it. Nor are the approaches interchangeable: a firm able to assess a payment before it leaves cannot substitute a post-transaction review and call the outcome equivalent.


Procurement inherits its own version of the rule. Default settings in a purchased tool may not be used without a documented assessment of whether they suit the firm's risks. Where a third-party provider will not supply enough information for the firm to explain the tool to a supervisor, the draft's answer is not mitigation but abstention: the tool should not be relied upon for functions that materially influence monitoring outcomes. Explainability stops being a preference recorded in a model risk policy and becomes a term a firm must extract from a supplier.


Ownership is the open question


The work this creates is not principally technical. The guidelines require the governance of the monitoring framework to be documented, its outputs to inform customer risk classification and the business-wide risk assessment, and responsibility for overseeing its effectiveness to be clearly assigned. It does not say to whom. That silence is where the difficulty lives, because most institutions have assigned ownership of systems rather than of the outcome those systems exist to produce.


Four questions follow. First, whether the perimeter of the framework as the draft describes it matches the perimeter of any function on the organisation chart, and if it does not, who signs for the difference. Second, whether management information can be rebuilt around the quality and timeliness of escalation rather than around volume, since the measures a firm chooses to report are the measures it will be asked to defend. Third, whether decisions about product and service design pass through any test of whether the resulting activity can be monitored at all. Fourth, whether existing supplier contracts confer the explanation rights the draft assumes, a question far cheaper to ask at renewal than during an inspection.


The alert answered a smaller question


The alert was never a mistake, but a rational answer to a narrower question, asked in a period when the signal worth reading was a payment and the proof worth holding was a queue someone had worked. AMLA has now asked a larger question, and the industry asked it first. The achievement of the draft is to state, in language a supervisor can test, that the obligation is not discharged by any system a firm owns; it is discharged, or not, by what the whole of its arrangements can see, escalate and explain. An alert is a record that something was noticed. It is not, on its own, evidence that a firm was looking in the right place.


Does your firm know who owns the whole of its monitoring framework, rather than the part that produces alerts?


If the answer is a system rather than a name, we can help you establish the position, evidence it and defend it before a supervisor asks the question; contact us.


At OpusDatum, we test monitoring frameworks against the evidence a supervisor will ask for rather than the documentation a firm happens to hold. Our work runs across detection logic, data quality, escalation and the governance binding them together, in anti-money laundering, sanctions and payment controls alike. Our focus is control effectiveness rather than control existence.


bottom of page