By Kareem Staytieh, Senior Product Development Manager AML and KYC at Eastnets
The UK’s latest AML reforms come at an important moment for financial crime compliance.
The amendments to the Money Laundering Regulations, which took effect on 30 June 2026, are intended to make the UK’s AML regime more proportionate and risk-based. That direction is welcome. For years, financial institutions have had to manage rising compliance expectations, growing transaction volumes and increasingly complex customer structures, often while working with systems that were not designed for today’s financial crime environment.
But the success of any risk-based regime depends on the quality of the information behind it. A bank cannot accurately assess the risk of a company if it only has a partial view of who owns it, who controls it and how money moves through its accounts. As the UK puts renewed focus on targeted controls, ownership data needs to move from a static compliance record to a live part of financial crime decision-making.
AML reform is pushing firms towards more targeted compliance
The UK reforms are intended to make parts of the AML regime clearer and more focused on genuine risk. The Law Society has welcomed the move towards a more proportionate and risk-based approach, although it has also cautioned that the changes may not substantially reduce the compliance burden on firms.
The amendments to enhanced due diligence requirements illustrate this approach. Rather than treating complexity alone as a reason for greater scrutiny, the rules place more emphasis on transactions that are unusually complex or unusually large when viewed in context.

This distinction is important. Complex ownership structures and transactions are common across international trade, corporate finance and cross-border payments. Complexity may have a legitimate commercial purpose. The challenge for a bank is deciding whether the structure and activity make sense for that particular customer.
Making that judgement requires more than a checklist or a single piece of customer information. Compliance teams need to understand how different indicators relate to one another and why a particular combination of factors increases or reduces risk.
A more targeted regime may therefore place greater demands on the quality of financial crime decision-making. Institutions must be able to connect relevant risk signals, assess them consistently and provide a clear explanation for the action they have taken.
Ownership data remains too fragmented
Separately, the Economic Crime and Corporate Transparency Act 2023 is strengthening corporate transparency in the UK. Identity verification for directors and people with significant control became a legal requirement from 18 November 2025 and is being phased in over 12 months. This should improve the reliability of Companies House data, but it does not replace firms’ own customer due diligence and ongoing monitoring obligations.
The Money Laundering Regulations (MLRs) already require ongoing monitoring and customer due diligence information to be kept up to date. In practice, however, ownership information may still be operationally refreshed mainly through periodic review cycles, although some institutions are moving towards perpetual KYC models that continuously update customer data based on triggered events and ongoing monitoring, making material changes less visible between reviews.
Ownership, control and influence can change significantly during a business relationship. A company may transfer or issue shares, appoint new directors, change voting arrangements or become part of a more complex corporate structure. Criminal networks can also use nominee directors, shell companies and cross-border arrangements to obscure who ultimately owns or controls an entity.
The limitations are not always caused by a complete lack of information. In many cases, institutions hold much of the data they need, but it is spread across separate systems and workflows. Customer details may sit in a KYC platform, while corporate registry information, sanctions results, adverse media findings and transaction alerts are held elsewhere. Case investigators may then have to move between these systems to piece together the full picture.
This fragmentation makes it harder to recognise when an apparently routine customer relationship has changed. It also creates duplication, slows investigations and increases the possibility that an important connection will be overlooked. Ownership data alone does not tell the full story either. A beneficial owner may not appear high risk when assessed individually, but the company’s transaction activity, counterparties or links to other businesses may raise questions.
The question is no longer simply, who owns or controls this company? It is whether the ownership structure makes sense when viewed alongside how the money moves.
Banks must connect ownership with transaction behaviour
The future of AML compliance will depend on linking information about corporate control ongoing transaction behaviour, supported by real-time and post-transaction monitoring where appropriate. Treating ownership checks and transaction monitoring as separate exercises leaves institutions with an incomplete view of risk.
Consider a company with a straightforward stated purpose and a seemingly low-risk owner. If that company begins sending funds through unnecessarily complex routes, frequently changing counterparties or dealing with businesses in high-risk jurisdictions, its activity may no longer align with its profile.
The same principle applies when ownership changes. Updating the customer file should only be the first step. A new owner may introduce connections to sanctioned entities, politically exposed persons or companies in opaque jurisdictions. The change should prompt the institution to reassess both the customer’s risk rating and its recent transaction behaviour.
This becomes more urgent as payments accelerate. When funds move within seconds, institutions have less time to investigate unclear ownership structures after a suspicious transaction has taken place. Relevant ownership and risk information should be available to controls operating at the point of payment, where applicable, as well as to post-transaction monitoring and investigations.
Ownership data becomes far more powerful when it is connected to transaction monitoring, sanctions screening and case management. That connection turns a compliance record into an active risk signal. It can also support stronger investigations. When customer information, alerts and transaction histories are brought together, investigators can understand how a decision was reached, identify related entities and follow the movement of funds more easily. A clear audit trail can then show which risks were considered and why an alert was escalated or closed.
AML reform needs better data beneath it
The UK’s 2026 amendments to the MLRs are a useful step towards a more targeted and proportionate regime. But reform will only succeed if financial institutions have the data foundations to make risk-based compliance work in practice.
Ownership data sits at the centre of that challenge. It helps Financial Institutions understand who ultimately owns or controls an entity, but its real value comes when it is connected to how that entity behaves. Without that connection, firms may still miss the relationships, patterns and control structures that reveal genuine financial crime risk.
The next phase of AML compliance will not be defined by more data alone. It will be defined by whether institutions can bring the right data together, interpret it clearly and act on it with confidence. Better ownership data is not a side issue in AML reform. It is one of the foundations that will determine whether reform delivers real impact.


