AML & Compliance

AML Frameworks for Regulated Industries in 2026: What Has Changed

The AML landscape is shifting faster than compliance teams can adapt. New risk typologies, beneficial ownership requirements, and digital asset obligations demand a rethink of legacy frameworks.

AML & Compliance 10 min read

The Financial Action Task Force's 2023–2024 mutual evaluation cycle produced some of the most candid assessments of AML framework effectiveness seen in over a decade. The pattern across jurisdictions was consistent: technical compliance was common; effective implementation was rare. Policies existed. Risk assessments had been conducted. Transaction monitoring was in place. But the systems were not working in the way their architects intended — and regulators knew it.

For regulated industries heading into 2026, the question is no longer whether an AML framework exists. It is whether the framework actually reduces the probability of money laundering, is capable of detecting it when it occurs, and can demonstrate both of those things to a regulator who is no longer satisfied with documentation alone.

FATF Updates: What Actually Matters in Practice

FATF's fourth-round mutual evaluations introduced a dual assessment methodology that scores both technical compliance (does the legal and regulatory framework exist?) and effectiveness (does it actually work?). The shift matters because it changes what regulators look for during inspections — and what they expect to find documented in supervised firms.

The immediate practical implications for regulated businesses include:

68% of FATF mutual evaluation reports in the 2023–24 cycle cited transaction monitoring effectiveness as a key deficiency
£573M in AML-related fines issued to UK regulated businesses in 2024, up 41% year-on-year
3.2× increase in casino-sector AML enforcement actions in the EU since 2021

Beneficial Ownership: Beyond Register Checks

The gap between beneficial ownership register data and beneficial ownership reality has been well documented. Nominee directors, layered corporate structures, discretionary trust arrangements, and jurisdictions with weak verification requirements all create conditions where the registered beneficial owner is not the actual controller of funds.

For regulated firms, the obligation to identify the beneficial owner is not discharged by checking a register and accepting the result. Where the corporate structure is complex, where the jurisdiction of incorporation has known beneficial ownership transparency concerns, or where there is any inconsistency between the presented ownership structure and other risk signals, additional verification is required. This is not new law — it is existing CDD obligation applied to a reality that register-dependent processes routinely fail to capture.

"A beneficial ownership register tells you who someone says owns the company. Your obligation is to form a reasonable belief about who actually does. In complex structures, those are often different answers."

Practical approaches to meaningful beneficial ownership verification include:

Virtual Asset Service Providers: The Compliance Overlap

The FATF Travel Rule, requiring VASPs to pass originator and beneficiary information with virtual asset transfers above threshold, is now law in most major jurisdictions. For regulated businesses that accept funds from or transact with VASPs — including gaming operators who accept crypto payments or whose high-value customers hold significant crypto wealth — this creates obligations that many have not yet fully integrated into their AML frameworks.

The specific risks that regulated non-VASP businesses need to manage in relation to virtual assets include:

Compliance Gap Alert

Most legacy transaction monitoring systems were designed for fiat bank transfer patterns. They are not configured to assess crypto-origin fund flows, chain-hop patterns, or VASP counterparty risk. If your system does not have dedicated crypto risk rules, you have a monitoring gap that a regulator will identify.

Risk-Based Approach Maturity: Moving Beyond Tick-Box

The risk-based approach has been the foundation of AML frameworks since FATF Recommendation 1 established it as the central methodology. In practice, many organisations have implemented a form of the risk-based approach that satisfies the documentation requirement without achieving the underlying purpose.

A genuinely mature risk-based approach has specific characteristics that distinguish it from checkbox compliance:

🎯
Dynamic Risk Assessment
Risk assessments updated as the risk environment changes, not as a fixed annual exercise. Trigger events — new products, new markets, typology alerts — drive updates.
📊
Resource Allocation Alignment
Compliance resource actually concentrated on highest-risk relationships and transactions — not distributed proportionally across the customer base regardless of risk.
🔍
Control Effectiveness Testing
Regular testing of whether controls actually detect the risks they are designed to address. Not just confirmation that controls exist.
📝
Decision Documentation
Documented rationale for risk ratings, CDD decisions, and monitoring calibration — sufficient to reconstruct the decision basis under regulatory scrutiny.

Source of Funds vs Source of Wealth: The Distinction That Matters

The conflation of source of funds and source of wealth is one of the most persistent practical errors in casino and high-value dealer CDD processes. They are different questions, they require different evidence, and confusing them creates compliance gaps that regulators consistently identify.

Source of funds is the answer to: where did the specific money used in this transaction come from? It is a question about the immediate provenance of the funds being deposited, wagered, or transferred. The answer should be specific and verifiable: salary payment from a named employer, dividend from a named company, property sale proceeds from a named transaction.

Source of wealth is the answer to: how did this person accumulate their overall wealth? It is a question about the origin of the total wealth base that funds the customer relationship. The answer requires understanding of career history, business interests, inheritance, or investment activity over time — and for high-value customers, that understanding needs to be supported by evidence, not just declaration.

For gaming operators with high-value customers, both questions are relevant and neither substitutes for the other. A customer who can demonstrate that their stake came from a specific bank transfer has answered the source of funds question. They have not answered the source of wealth question. In an enhanced due diligence context, both need answers.

Casino-Specific AML Obligations: The 2026 Landscape

Gaming operators face AML obligations that are both general (applying to all regulated sectors) and sector-specific (reflecting the particular vulnerabilities of the casino environment). The sector-specific obligations — cash transaction reporting thresholds, chip purchase monitoring, suspicious activity in play — sit alongside the general framework and create an overlapping compliance requirement that is not always well-integrated in operational practice.

The areas where casino AML frameworks most commonly fall short in regulatory inspection:

AML framework review and gap analysis

Wise Key Solutions conducts structured AML framework reviews for regulated businesses, identifying gaps against current regulatory expectations and producing prioritised remediation recommendations. Contact us to discuss your requirements.

Speak to our team →

This article reflects the operational perspective of the Wise Key Solutions founding team, drawing on experience across regulated industries in the UK and Europe. It does not constitute legal or regulatory advice. Operators should assess their specific obligations with qualified legal counsel.