This article was written in collaboration with SAS.
Deloitte
• Marit Hoegen, Partner - MHoegen@deloitte.nl
• Mitchell Verstraate, Senior Manager - mverstraate@deloitte.nl
• Robby Philips, Senior Manager - rphilips@deloitte.nl
SAS
• Olaf Passchier, PhD, CFE, BNL Customer Advisor for Fraud,
Compliance and Public Security - olaf.passchier@sas.com
The Regulation (EU) 2024/1624, or Anti-Money Laundering Regulation (hereinafter AMLR) is more than a deadline; it is a structural test of data equity across the financial ecosystem. From 10 July 2027, the Anti-Money Laundering Authority (AMLA) will centralise supervision and through the AMLR insist on machine-readable, harmonised data, near-real-time screening and group-wide reporting. For first and second line teams this is not simply a matter of updating policies: it is an architectural mandate. The question for Obliged entities is straightforward:
Will data be treated as a strategic asset or will it continue to be accepted as a recurring liability?
Fragmented Know-your-customer (hereinafter KYC) data is an immediate AML compliance risk, where unknown risks make proficient mitigation impossible. Across the whole financial system, including newly obliged entities, customer information resides in scattered silos: CRM systems, core banking ledgers, insurance platforms, commercial units, PDFs and spreadsheets.
The same customer appears in different forms for example; “John Smith” in retail banking, “J. Smith” in insurance, and “John. S.” in commercial dealings. These trivial variations break reliable entity matching, generate false positives, impede automation and obliterate auditability. The immediate effects are familiar: manual reconciliation, repeated remediation and weak audit trails, resulting in infrequent and weak batches which are unable to show which data, list or algorithms inform decisions.
Regulatory momentum makes this problem unavoidable. Key AMLR provisions with supporting Regulatory Technical Standards (hereinafter RTS), Implementing Technical Standards (hereinafter ITS) and Guidelines enhances the role of data as a core compliance requirement:
Together, these articles demand machine-readable, high-quality, harmonised data and a technology uplift to support near-real-time, auditable processes. The legal direction is clear: if your data cannot be read, verified and exchanged in standardised formats, you will struggle to demonstrate compliance.
The consequences of inaction are both immediate and strategic. Persisting with manual patchwork and occasional remediation locks firms into a permanently higher cost base: repeated reconciliations, consultant engagement and firefighting absorb budget that should fund long-term resilience and business transformation. This is not mere accounting; it skews investment decisions and shrinks future capacity for innovation.
Failure to achieve the proposed data readiness approach also becomes a commercial handicap. Inability to verify identity promptly or to complete defensible due diligence will slow or block onboarding, prolong decision times and drive clients towards competitors with cleaner, faster processes. Onboarding friction is not just a customer experience issue; it is a revenue and market-share issue.
More troubling is the systemic impact. If many institutions cannot re-screen portfolios quickly or share intelligence securely, supervisory measures lose precision and typologies go undetected. AMLR aims to create a cohesive, data-driven defence; without Data Readiness, the regulation risks amplifying unevenness across the sector and concentrating, rather than dispersing, risk
Treating Data Readiness as an optional optimisation is a strategic mistake. Organisations that act early will lower operating costs, preserve business agility and be the institutions trusted in a fair, data-driven financial ecosystem. While those that delay will face escalating costs, constrained business and a diminished role in the collective AML defence.
Our view is that the pragmatic solution to fragmented KYC is found by setting up an organised capability for data readiness, where the right data is available, in the right quality and format, precisely when AML/ CTF processes require it. This is not a one-off project but an operating model that turns a dispersed set of records into consistent, auditable, reusable assets. In effect, the proposed data readiness approach makes the “John Smith” problem disappear by converting inconsistent strings into canonical, attributable records.
The proposed data readiness approach dissolves fragmentation in the following ways:
Transitioning to Data Readiness need not be paralysis-inducing. Start with a focused assessment of data availability at the item level, establish a canonical model for critical attributes, and deploy entity resolution on a high-risk segment to prove the approach.
Embed PET where sharing is required and govern rules as code to maintain reproducibility. These are practical, deliverable steps that move firms from costly remediation cycles to a scalable, auditable operating model. AMLR’s timeline is uncompromising and its expectations are structural.
Achieving Data Equity requires a data and technology platform capable of consolidating fragmented KYC data into machine-readable, standardised formats in the different ways discussed above.
Platforms that integrates their modules for Anti-Money Laundering, Customer Due Diligence and Real-Time Watchlist screening, such as SAS Viya for Financial Crime demonstrates how this consolidation can be achieved at scale within a single governed environment. Machine-readable data export functionality ensures CDD and STR outputs align with AMLA Regulated Technical Standards removing ad hoc conversions that compromise auditability. Real-Time screening and event-driven rescreening replace batch processes, meeting Article 26’s near-real-time requirements. Integrated data sharing capabilities, supported by advanced analytics and network intelligence, enable secure and documented intelligence exchange between institutions under Article 75 safeguards.
By treating data quality, entity resolution and regulatory reporting as integrated functions rather than separate point solutions. Organisations transition from costly remediation cycles to scalable, auditable operations. That satisfy AMLR’s structural demands for harmonised, machine-readable data and transparent decision trails, as is also applicable in other data domains in financial institutions.
By automating entity resolution and maintaining perpetual KYC through integrated CDD and EDD workflows, compliance teams can accelerate customer onboarding while simultaneously reducing false positives and improving decision quality, directly addressing the speed-versus-accuracy trade-off that has long constrained KYC operations.
This unified approach transforms KYC from a fragmented, periodic process into a continuous, data-driven capability that adapts to evolving risk profiles and regulatory expectations.
We recently brought together representatives from more than 20 different organisations to address some of the sector’s most pressing AMLR challenges. The energy and insights shared were insightful– bringing together peers from banking, payments, insurance and other industries to find common challenges and approaches proved invaluable.
Three Key Takeaways
This article was written in collaboration with SAS.
Deloitte
• Marit Hoegen, Partner - MHoegen@deloitte.nl
• Mitchell Verstraate, Senior Manager - mverstraate@deloitte.nl
• Robby Philips, Senior Manager - rphilips@deloitte.nl
SAS
• Olaf Passchier, PhD, CFE, BNL Customer Advisor for Fraud,
Compliance and Public Security - olaf.passchier@sas.com