• Home
  • About us
    • About Compliance Champs
    • Our team
  • Our services
    • Compliance Risk Management
    • Crypto as a Service
    • Financial Economic Crime (FEC)
    • Integrity & Investigations
    • Training & Awareness
  • Sectors
    • Banking
    • Insurance companies
    • Crypto Asset Service Providers (CASPs)
    • Trust Offices
    • Football Sector
    • Investment Firms
    • Payment Service Providers (PSPs)
  • Cases & References
  • Learning & Development
  • Careers
  • Updates
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

About us

  • About Compliance Champs
  • Our team

Sectors

  • Banking
  • Insurance companies
  • Crypto Asset Service Providers (CASPs)
  • Trust Offices
  • Football Sector
  • Investment Firms
  • Payment Service Providers (PSPs)

Our Services

  • Compliance Risk Management
  • Crypto as a Service
  • Financial Economic Crime (FEC)
  • Integrity & Investigations
  • Training & Awareness

Careers

Contact

Dutch
You are here: Home1 / Articles

Stablecoins in Europe: The Race for Digital Money

Stablecoins are no longer a crypto story. With a global market capitalisation exceeding $305 billion and annual transfer volumes that surpassed Visa and Mastercard combined in 2024, they have crossed into mainstream financial infrastructure.[1] If your financial institutions hasn’t formed a clear view on what this means operationally, strategically, and from a compliance perspective, the time to do so is now.

This article covers what financial institutions need to understand: how stablecoins work and why they lead the field among digital money formats, why dollar dominance is a geopolitical issue rather than just a market fact, what banks entering this space are discovering, and how the regulatory frameworks on both sides of the Atlantic are taking shape. With USDT and USDC alone accounting for 93% of the global stablecoin market and euro-denominated alternatives representing less than 0.3%, dollar dominance in this space is hard to overstate.[2] The central question for Europe is whether a consortium of 37 banks united under the Qivalis initiative can still mount a credible answer, or whether the window has already closed.

The basics are worth getting right

Stablecoins are blockchain-based digital tokens that maintain a stable value relative to a reference asset, typically a fiat currency like the US dollar or euro. They combine the programmability and settlement speed of crypto infrastructure with the predictability of sovereign currency

To understand where stablecoins fit, it helps to look at the broader landscape of digital money. Three main formats are commonly discussed: cryptocurrencies, Central Bank Digital Currencies (CBDCs), and stablecoins. Of these, stablecoins are the most developed, in both adoption and regulatory clarity. Cryptocurrencies remain highly volatile and speculative. CBDCs are a different matter: as of mid-2025, 137 countries representing 98% of global GDP are exploring them, with 49 in active pilot, but despite that global momentum stablecoins have moved faster and are already deployed at scale in commercial applications that CBDCs are still testing.[3]

Privately issued, not sovereign money

One distinction that often gets overlooked is that stablecoins are privately issued instruments, not sovereign money. A stablecoin is only as stable as the entity behind it. Its value depends entirely on the issuer’s reserve management, governance practices, and regulatory compliance. There is no central bank backstop. If the issuer mismanages its reserves, faces a redemption run, or loses regulatory standing, the coin can suddenly lose its fixed value. The TerraUSD collapse in May 2022 illustrated this, when design flaws and a loss of confidence wiped out tens of billions of dollars in market value within days. [4] Before incorporating stablecoins into their products or processes, this is the first thing any institution should understand. CBDCs carry no such risk: they are sovereign money issued directly by central banks, and governments retain full control over their issuance. Governments can also programme features such as spending restrictions or targeted distribution directly into the currency.

The cross-border payment advantage

Cross-border payments are where the efficiency advantage becomes impossible to ignore. A traditional payment through Society for Worldwide Interbank Financial Telecommunication (SWIFT) does not travel directly from sender to receiver. It passes through a chain of correspondent banks, each adding time, cost, and friction. A single payment may cross three to five entities before reaching its destination, incurring fees up to $50 and taking one to three business days to settle.[5] A stablecoin payment eliminates that chain entirely. The token moves directly from sender to receiver on a blockchain, with no intermediaries and settlement in under five seconds at a cost below one cent.

Three ways businesses are using stablecoins

One of the three ways in which standout businesses are using stablecoins is for cross-border payments. They are cheaper and faster than traditional methods, so the benefits are clear. The second way is to protect company cash. In countries with high inflation, where the local currency quickly loses value, companies can hold stablecoins instead, since their value remains stable. The third use is for automated payments. Because stablecoins run on code, they can automate payments, eliminating manual checking and approval of each transaction and saving time while reducing errors.[6]

Dollar dominance is a geopolitical issue, not just a market fact

The dollar dominance is striking. As the gap between USDT, USDC, and euro-denominated alternatives already shows, this imbalance is not just a market preference. It reflects a structural problem with geopolitical consequences. The dollar stablecoin ecosystem is self-reinforcing: the larger it grows, the harder it becomes for alternatives to gain traction. Network effects in payments are powerful and slow to reverse.

The European Central Bank (ECB) has been direct about what this means for Europe. A July 2025 blog post warned that dollar dominance in stablecoins would give the United States strategic and economic advantages, allowing it to finance its debt more cheaply while exerting global influence, and would leave Europe with higher financing costs, reduced monetary policy autonomy, and geopolitical dependency.[7] A March 2026 ECB working paper went further, warning that widespread adoption of dollar-denominated stablecoins in the euro area could trigger retail deposit outflows, constrain European banks’ lending capacity, and in extreme cases amount to a form of partial currency substitution. [8]

For European corporates, the dependency is already real. Companies that have moved to stablecoin rails for cross-border payments are almost all doing so on dollar infrastructure. In practice, this means they are relying on US financial systems, even for payments that have nothing to do with the United States.

Case in point: Meta’s return to stablecoins

In 2019, Meta (then known as Facebook) announced Libra, a stablecoin backed by a basket of national currencies that was designed to function as a global digital currency.[9] Governments and central banks on both sides of the Atlantic pushed back hard, citing concerns about monetary sovereignty, privacy, and systemic risk. The project was progressively scaled back, rebranded as Diem, and ultimately shut down in early 2022 when its assets were sold off. At the time, the regulatory climate simply didn’t support it.

The climate has changed. Meta is planning a stablecoin comeback in the second half of 2026, this time taking a fundamentally different approach.[10] Rather than issuing its own coin, Meta is positioning itself as a distribution channel, integrating third-party stablecoin rails across Facebook, Instagram, and WhatsApp. Stripe, the payments company widely used by businesses to process online transactions, is reported to be the likely infrastructure partner.[11] Its CEO Patrick Collison joined Meta’s board in April 2025. For Europe, the implications are significant. Meta has more than 3 billion users globally. If stablecoin payments become embedded in its platforms, the adoption curve for dollar-pegged digital payments accelerates at a scale no European initiative has yet matched, and the window for euro-denominated alternatives to compete on distribution narrows further. That dynamic is exactly what European banks are now racing to get ahead of.

A new playing Field for Financial Firms

The opportunity

Major banks view stablecoins as both a risk and an opportunity. Those that do not act risk losing ground to tech companies and crypto companies, which could take over payment services, along with money and client data that come with them. However, banks that do act can update their business model, find new revenue streams and offer clients services that are not currently available.

The clearest opportunity lies in cross-border payments. Stablecoins eliminate the correspondent banking chain, reducing costs and settlement times for corporate clients. For banks, this means retaining clients who might otherwise turn to fintech alternatives, while also generating income from the reserves backing stablecoin issuance. The revenue model is straightforward and the competitive advantage is clear.[12]

JPMorgan has already taken action, expanding its JPM Coin platform to support euro-denominated payments with Siemens being its first corporate client. Additionally, in early 2025, Bank of America’s CEO indicated that the bank would launch its own stablecoin. Citigroup, PayPal, and others have signalled varying degrees of interest. The question is no longer whether banks will participate in this market. Rather, it is whether their compliance and operational infrastructure can keep up with the speed at which deployment is happening.[13]

The risk

These opportunities come with significant operational and reputational complexities.

Compliance

The biggest issue is compliance. Stablecoin payments happen all day and night, every day of the week, raising the bar on monitoring that many banks already do in real time for other payment rails. They need to continuously monitor for suspicious activity, signs that an issuer might encounter difficulties. They also need to monitor unusual account behaviour and cash-out requests on a scale that batch-based checks were never designed to handle.

The risk of regulatory scrutiny and criminal misuse is real, not just a theoretical concern. According to Chainalysis, 63% of illicit crypto transaction volume in 2024 was attributed to stablecoins, linked to money laundering, sanctions evasion, and financial crime.[14] While this reflects usage patterns more than inherent risk, it signals the intensity of scrutiny that any bank entering this space should expect. Know Your Customer (KYC) processes need to be rethought from the ground up. Both the Guiding and Establishing National Innovation for US Stablecoins (GENIUS) Act and the EU’s Markets in Crypto-Assets Regulation (MiCAR) require KYC obligations to extend to blockchain wallet addresses, something most existing programmes were not designed to handle. Leading compliance teams are responding with a triple-layer approach, monitoring simultaneously at the blockchain, transaction, and broader ecosystem levels.

Beyond compliance, three further risks run through any stablecoin strategy: security, who is backing the coin, and whether it can hold its value.

Security, backing, and value risk

Security became a serious concern after the 2025 Bybit hack, in which hackers stole $1.4 billion. [15] It showed clearly what can go wrong when companies don’t properly protect digital assets. Counterparty and issuer risk is structural: private entities, not central banks, issue stablecoins, so companies need to check each issuer’s reserves and reputation on their own. The last risk is whether the coin can keep its value. The TerraUSD collapse in 2022 showed that even a popular stablecoin can suddenly lose its value, causing panic as everyone tries to cash out at once.

Client trust and education

There is also a risk that sits one step further out but is not less consequential. Most retail and corporate clients currently have little understanding of how stablecoins work, what backs them, or how they differ from familiar payment methods. That knowledge gap directly creates a trust gap, and trust has to be there before adoption can happen. Financial institutions that move fast on deployment without investing equally in client education are likely to find their clients do not follow. Building that understanding is not a marketing problem. It is a core part of what it means to introduce a genuinely new financial instrument responsibly.

The European response: Qivalis

The dependency on dollar-denominated stablecoins, and the pressure that creates for European banks to act, has produced a concrete response. The response comes from Qivalis, a joint venture launched by a consortium of 37 European banks building a fully regulated, 1:1-backed euro stablecoin, scheduled for launch in the second half of 2026.[16] The membership includes major companies such as BBVA, BNP Paribas, ING, UniCredit, Rabobank, and CaixaBank, spanning nearly every major European market. A full list of participating banks is available on the Qivalis website.

The intent is clear. European companies currently lack access to a regulated, European-issued digital settlement asset that does not route through US financial infrastructure. Qivalis is designed to provide one.[17] Jan-Oliver Sell, CEO of Qivalis, has described the problem directly: with only dollar stablecoins available at scale, European companies depend on US-controlled digital rails for cross-border commerce.

The regulatory approach is MiCAR-compliant from the outset. That matters, because MiCAR is the dedicated framework the EU has built specifically for crypto-asset issuers and service providers. Qivalis is not seeking exemptions or operating in a regulatory grey zone. It is not working around the rules; it is built to operate within them.

The Competitive Landscape

The challenge ahead is real. Network effects in payments are strong and slow to shift. The clearest example is EURC: Circle, an American company, currently issues the largest euro-denominated stablecoin in circulation.[18] That is the exact problem Qivalis is meant to solve: a non-European issuer controls even the leading euro stablecoin today, leaving European companies dependent on a US company for euro-denominated digital money.

MiCAR, meanwhile, has pushed Tether’s USDT out of the EU entirely. With MiCAR’s final compliance deadline on 1 July 2026, licensed European exchanges have been delisting USDT because Tether never sought the required authorisation.[19] Reaching enough liquidity to actually be useful will not be easy for Qivalis either, but it enters a market where regulation has already excluded the largest dollar-based competitor, and the largest euro alternative remains foreign-owned.

The Trust Gap

There is also a trust dimension that should not be underestimated. Qivalis is a new instrument from companies that most retail and corporate clients will not immediately associate with digital money. Even with 37 banks behind it, client familiarity with euro stablecoins is low. The consortium will need to invest in building that understanding, not just in building the product.

The conditions for Qivalis to succeed are improving. Geopolitical fragmentation is raising European appetite for alternatives to dollar infrastructure. Regulatory clarity under MiCAR gives it a foundation that earlier euro-stablecoin efforts lacked. Whether that is enough depends on execution, and execution depends on the regulatory rules Qivalis and every other stablecoin issuer now has to operate within.

What this means in practice

The stablecoin transition is not a future scenario. It is happening now, and it is moving faster than most formal planning cycles were built to accommodate.

For banks

For banks, the question is no longer whether to engage with stablecoin infrastructure but how quickly and through which route. That means assessing whether they can issue, store, and convert stablecoins into traditional currency and back, against existing regulatory frameworks. It also means identifying partnership opportunities with issuers or infrastructure providers, and adapting compliance architecture for real-time, 24/7 monitoring before deployment decisions are made, not after.

For European companies

For European companies operating in stablecoins, the dual-licence requirement (MiCAR plus EMI) is now the compliance baseline, not a stretch goal. The EBA’s June 2025 No Action Letter and February 2026 clarifications were not ambiguous: companies supporting EMT payment flows that have not obtained a payment firm or EMI licence are operating outside the framework. The zerohash precedent, secured in May 2026 from De Nederlandsche Bank, sets the benchmark. Any European-based company looking to participate in stablecoin infrastructure, whether as an issuer, custodian, or payment processor, should treat obtaining both licences as an immediate priority, not a future-quarter agenda item.

For compliance teams

For compliance teams specifically, wallet-level screening is no longer optional. Stablecoins appear disproportionately in illicit flows relative to their market share, and that pattern will attract regulatory scrutiny across European jurisdictions. Blockchain analytics tools are baseline infrastructure, not specialist add-ons. The governance frameworks for when to freeze assets, escalate internally, and file reports need to exist before an issue arises, not during one.

The architecture of digital money is being built right now. Companies that treat stablecoins as a compliance problem to manage rather than infrastructure to understand are already operating with an incomplete picture. The decisions being made in the next 12 to 18 months will set positions that will be difficult to change.

Conclusion

Stablecoins are no longer an experiment on the edge of finance. They are becoming core infrastructure for cross-border payments, corporate treasury, and increasingly, for the platforms billions of people already use every day. The dollar’s dominance in this space did not happen by accident, and it will not reverse by accident either.

For Europe, the stakes go beyond market share. A digital financial system built almost entirely on dollar rails carries real consequences for monetary autonomy, financial stability, and strategic independence. Qivalis represents a credible, regulated attempt to close that gap, but it enters a market shaped by entrenched network effects, an American company holding the largest euro stablecoin position, and a regulatory environment that, while more developed than its US counterpart, is still finding its footing in practice.

Execution, not ambition, will decide what happens next. Three things will determine that: how quickly European banks can build trust and liquidity, how consistently EU member states apply the rules they have agreed to, and how seriously financial companies across the continent respond to a shift that is already underway. The window to act is not unlimited. The companies that move early, and move deliberately, will be the ones that shape what European digital money looks like, rather than simply adapting to a market someone else has already built.

Want to know more?

Is your organization ready for the regulations surrounding stablecoins and digital money in Europe?

Contact use at: info@compliancechamps.com

Read more articles here

[1]European Central Bank, Financial Stability Review, November 2025 (Frankfurt: European Central Bank, November 2025), https://www.ecb.europa.eu/press/financial-stability publications/fsr/html/ecb.fsr202511~263b5810d4.en.html.

[2]Crystal Foresight Team, “USDT Maintains Dominance While USDC Faces Headwinds,” Crystal Intelligence, November 13, 2025, https://crystalintelligence.com/thought-leadership/usdt-maintains-dominance-while-usdc-faces-headwinds/.

[3]Atlantic Council. (2025). Central Bank Digital Currency (CBDC) Tracker. Atlantic Council GeoEconomics Center. https://www.atlanticcouncil.org/cbdctracker/

[4]IBTimes, “Crypto Fraudster Do Kwon Gets 15 Years for $40 Billion Terra/Luna Collapse That Triggered 2022 Crash,” IBTimes, December 12, 2025, https://www.ibtimes.com/crypto-fraudster-do-kwon-gets-15-years-40-billion-terra-luna-collapse-that-triggered-2022-crash-3792451.

[5]TreasurUp, “Stablecoins for Banks in 2025: The Strategic Playbook for Banks,” TreasurUp, May 21, 2025, https://treasurup.com/stablecoins-for-banks-strategic-playbook-2025/.

[6]Olivier Truquet, “Banking on Stablecoins: How Financial Firms Can Lead the Next Wave of Digital Money?,” GFT Technologies, June 29, 2025, https://www.gft.com/int/en/blog/banking-on-stablecoins-financial-firms-lead-the-wave-of-digital-money.

[7]Reuters, “Dollar Stablecoins Threaten Europe’s Monetary Autonomy, ECB Blog Argues,” Reuters, July 28, 2025, https://www.reuters.com/business/dollar-stablecoins-threaten-europes-monetary-autonomy-ecb-blog-argues-2025-07-28/.

[8]European Central Bank. (2026). Stablecoins and monetary policy transmission (Working Paper Series No. 3199). European Central Bank. https://www.ecb.europa.eu/pub/pdf/scpwps/ecb.wp3199~ad552b59ec.en.pdf

[9]ShunSpirit. (2026). Why Libra failed: Unraveling Facebook’s troubled cryptocurrency venture. ShunSpirit. https://shunspirit.com/article/why-did-libra-fail

[10]CoinDesk. (2026, February 24). Mark Zuckerberg’s Meta is planning stablecoin comeback in the second half of this year. CoinDesk. https://www.coindesk.com/business/2026/02/24/mark-zuckerberg-s-meta-is-planning-stablecoin-comeback-in-the-second-half-of-this-year

[11]crypto.news, “Meta to Plug Stripe Stablecoins into Facebook, Instagram, WhatsApp in 2026,” crypto.news, February 25, 2026, https://crypto.news/meta-to-plug-stripe-stablecoins-into-facebook-instagram-whatsapp-in-2026/.

[12] Elliptic. (2025). How stablecoins can improve cross-border payments for banks. Elliptic Blog. https://www.elliptic.co/blog/how-stablecoins-can-improve-cross-border-payments-for-banks

[13]The Block. (2025, June 20). JPMorgan expands its JPM Coin system to include euro payments. The Block. https://www.theblock.co/post/236134/jpmorgan-jpm-coin-euro

[14]Chainalysis. (2025). 2025 Crypto Crime Report. Chainalysis. https://www.chainalysis.com/crypto-crime-report/

[15]IBTimes, “Bybit Hack: How the $1.4B Exploit Happened, Funds Recovered, and Who’s Responsible,” IBTimes, accessed June 2026, https://www.ibtimes.com/bybit-hack-how-14b-exploit-happened-funds-recovered-whos-responsible-3764817.

[16]Qivalis Consortium. (2026). Qivalis – Secure. Trusted. Future-ready. Qivalis. https://qivalis.eu/ (qivalis.eu)

[17]Payment Expert, “Qivalis CEO: Euro Stablecoin Will Challenge USD Stablecoins,” Payment Expert, March 4, 2026, https://paymentexpert.com/2026/03/04/qivalis-euro-stablecoin/.

[18]CryptoBriefing, “The Largest EUR Stablecoin Is Issued by a US-Based Company, and Europe Should Be Paying Attention,” CryptoBriefing, May 2026, https://cryptobriefing.com/largest-eur-stablecoin-us-issuer-circle/.

[19]Phemex, “Why EU Exchanges Are Delisting Tether Before the July 1 MiCA Deadline,” Phemex, accessed June 2026, https://phemex.com/academy/eu-exchanges-delist-tether-mica-deadline.

 

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/07/Stablecoins-in-Europe-the-race-for-digital-money-1-scaled.png 1440 2560 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-07-20 17:23:452026-07-21 11:39:23Stablecoins in Europe: The Race for Digital Money

Are crypto mixers becoming harder to ignore because of the AMLR?

Why crypto mixers matter for AML compliance

Crypto mixers, also known as tumblers, are tools that enhance the anonymity of users of cryptocurrencies. They do so by shuffling cryptocurrencies from multiple users to hide the original source and destination of funds. The purpose is to reduce traceability on a blockchain: by mixing the transaction with those of others, it is significantly more complicated to trace the original source or destination of the crypto-asset. But mixers have two sides of the same coin: they provide increased privacy for genuine users, while at the same time allowing bad actors to hide their finances. This is particularly relevant during the layering phase of money laundering. The main goal in this second phase of money laundering is to distance funds from their criminal source by creating multiple transaction layers that complicate audit trails. A mixer can be used as an effective tool for this specific purpose: in a single step, the transaction trails that would otherwise be visible on the blockchain are harder to trace from their original source. In practice, this means that for crypto-asset service providers (CASPs), screening customers only at onboarding is not sufficient. When a customer deposits funds that have been routed through a mixer or when a transaction is directed to an address associated with one, the customer’s identity alone is insufficient to assess the origin or destination of the funds. CASPs must therefore also assess the transaction history of both incoming and outgoing funds.  

How the AMLR affects mixer-related risks  

The Anti-Money Laundering Regulation (AMLR), which will apply from 10 July 2027, introduces obligations aimed at reducing the risks associated with crypto mixers. More broadly, the AMLR will require CASPs to conduct ongoing monitoring of business relationships, including scrutiny of transactions throughout the relationship to ensure that they are consistent with the CASP’s knowledge of the customer and their risk profile.[1] This is particularly relevant to mixer exposure, which may only become apparent after onboarding.  

Anonymous accounts

First, mixers can be used to obscure the origin or destination of crypto-assets and frustrate attempts to trace transaction flows, for example until the assets can be transferred, exchanged or cashed out. An anonymous crypto-asset account at a CASP could further facilitate this process by providing access to the regulated financial system without a clearly identifiable account holder. The AMLR will address this risk by prohibiting CASPs from maintaining anonymous accounts or accounts that otherwise enable the anonymisation of the account holder or the masking of transactions.[2]

Self-hosted addresses

Second, transfers to or from self-hosted addresses may expose CASPs to mixer-related risks. Standard KYC alone does not provide sufficient insight into the transaction history of the crypto-assets involved. The AMLR will therefore require CASPs to identify and assess the money laundering and terrorist financing risks associated with such transfers and to have appropriate internal policies, procedures and controls in place.[3] Where blockchain monitoring or other risk indicators point to mixer exposure, CASPs may need to apply proportionate mitigating measures, such as obtaining additional information on the origin and destination of the crypto-assets or conducting enhanced ongoing monitoring. 

Customer due diligence

Third, mixer exposure not only affects how funds move but also raises questions about their origin and purpose. As part of customer due diligence, CASPs will have to assess and, where appropriate, obtain information on and understand the purpose and intended nature of the business relationship or occasional transaction. Where funds appear to have passed through a mixer, this may require the CASP to obtain further explanation and documentation regarding the origin or the destination of those funds before proceeding. [4]

Enhanced due diligence

Finally, where mixer exposure or other suspicious indicators point to a higher-risk transaction, CASPs may be required to apply enhanced due diligence. This includes examining the origin and destination of the funds and the purpose of transactions that are complex, unusually large, conducted in an unusual pattern or lack an apparent economic or lawful purpose.[5]

In practical terms, funds that have passed through a mixer can represent a higher-risk indicator that may oblige CASPs to conduct enhanced due diligence and may, depending on the circumstances, give rise to a suspicious transaction report.  Risk-based monitoring must cover incoming as well as outgoing activity, an aspect that can be overlooked in practice. CASPs must assess not only where crypto-assets are being sent but also the origin of incoming deposits where relevant. Incoming deposits should therefore be included in the CASP’s transaction-monitoring framework. 

Practical consequences for CASPs 

In practice, this will have a significant operational impact on CASPs. Key implications include: 

  • Blockchain analytics: Blockchain analytics tools can support the mapping of transaction chains and the identification of mixer exposure and other risk factors. 
  • Risk-scoring: Risk-based rules and scoring mechanisms can help CASPs prioritise alerts and determine the appropriate follow-up action. 
  • Customer profiling and ongoing monitoring: CASPs should establish the customer’s expected transaction profile, including relevant use of self-hosted wallets, and monitor subsequent activity for inconsistencies or mixer exposure. 
  • Escalation procedures for suspicious activity: Clear internal procedures must be in place for reporting and following up on suspicious activity.  
  • Staff training: Compliance and operational staff must be equipped to recognise mixers and related transaction patterns as part of internal controls. 
  • Better documentation: Risk assessment and monitoring decisions must be demonstrably recorded. 
  • Higher compliance costs: The required technology, staffing and process changes are likely to increase compliance costs for CASPs. 

 

Conclusion

Crypto mixers illustrate why the AMLR will require CASPs to look beyond customer onboarding. The Regulation does not impose a general prohibition on mixers, nor does exposure to a mixer automatically make a transaction suspicious. It will, however, require CASPs to assess the risks associated with crypto-asset flows throughout the business relationship and to take proportionate action where relevant risk indicators arise. 

The key question is therefore not whether CASPs can eliminate mixer exposure, but whether they can identify, assess, document and escalate it effectively. This requires more than blockchain analytics alone. Customer risk profiles, transaction-monitoring controls, internal procedures, reporting lines and staff knowledge must operate as one coherent framework. 

Compliance Champs supports CASPs in translating regulatory requirements into practical and proportionate controls. Through risk assessments, reviews of policies and procedures, compliance monitoring and reporting, training and implementation support, we help organisations identify gaps and strengthen their AML framework. Contact Compliance Champs to assess whether your current framework is ready for the AMLR. 

Do you seek support and assistance in enhancing your Crypto Compliance Framework?

Please reach out to us on: info@compliancechamps.com

Read more articles here.

[1] Article 26, Regulation (EU) 2024/1624

[2]  Article 79, Regulation (EU) 2024/1624 

[3] Article 40, Regulation (EU) 2024/1624 

[4] Article 20 and 25, Regulation (EU) 2024/1624 

[5] Article 34, Regulation (EU) 2024/1624 

 

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/07/Are-crypto-mixers-becoming-harder-to-ignore-because-of-the-AMLR-1-scaled.png 1440 2560 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-07-16 14:13:592026-07-16 17:05:24Are crypto mixers becoming harder to ignore because of the AMLR?

EU Pay Transparency Directive

The EU Pay Transparency Directive is coming, and for many organisations, the work required is bigger than it looks.

Directive (EU) 2023/970 introduces binding obligations that go well beyond publishing salary ranges. Think gender-neutral job evaluations, written pay criteria, employee rights to comparative pay information, and mandatory gender pay gap reporting.

That is exactly why we built our new compliance service offering at Compliance Champs.

We guide organisations through every step: from an initial training and compliance gap assessment, through job evaluation and policies and procedures, to reporting setup and ongoing support. Whether you are starting from scratch or closing specific gaps, we will help you build a programme that is practical, documented, and audit-ready.

We have put together a one-pager that outlines exactly what the Directive requires and how our services map to it.

Download here

Read more updates here.

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/04/ComplianceChamps-66.jpg 550 825 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-07-13 15:23:432026-07-13 15:29:24EU Pay Transparency Directive

Compliance audits: from incident to system

This is the final article in the series ‘The landscape of compliance investigations’. The earlier articles in this series focused on individual files and relationships. Integrity investigations, due diligence, IDD and AML/KYC each centred on specific parties, transactions or client relationships. The core question was tangible: what happened here, with this client, this deal or this signal?

With compliance audits, the perspective shifts fundamentally. The focus is no longer on the individual case, but on the machinery surrounding it: policies, processes, controls, culture and reporting lines. The question is no longer “is this specific file in order?”, but “does our compliance framework as a whole function as intended, and where are the blind spots?”

While this series focuses on the broad landscape of investigations within a single organisation, the parallel series AML/CFT internal audits – The invisible battle zooms in specifically on the dynamics of AML/CFT audits. There, we discuss why so many audits devolve into a paper reality, and what it takes to achieve truly risk-driven testing.

1. What do we mean by a compliance audit?

The term ‘compliance audit’ is elastic. In practice, scope ranges from a focused spot check on a single topic (such as sanctions screening or conflicts of interest) to a comprehensive review of the entire compliance management system.

A thorough audit analyses the organisation at three levels:

  • Design: Are the policies, procedures, roles and systems theoretically structured in a way that makes compliance possible at all?
  • Existence: Have those elements actually been implemented, or do they exist on paper only?
  • Operation: Do the controls function in practice as intended, and are deviations identified and corrected in a timely manner?

Where a forensic investigation primarily looks backwards (“what went wrong?”), a compliance audit looks forward: “if we continue on this path, where will the next incidents occur?” The AML/CFT audit series returns to this sharply as the difference between tick-box exercises and audits that genuinely uncover hidden risks.

2. The audit as a mirror of the system

Integrity and compliance issues rarely stand alone. An incident, a red flag in IDD, a client with elevated sanctions risk or a difficult KYC file is almost always a symptom of a deeper systemic problem. Think of:

  • An unclear or poorly embedded risk appetite.
  • Policies designed behind a desk that bear no relation to operational reality.
  • Poor data quality or failing tooling.
  • Vague boundaries between business, legal, compliance and audit.
  • A culture in which critical questions are seen as obstructive or time-consuming.

Compliance audits expose these patterns without mercy. They reveal why the same types of errors or omissions recur across different files, teams or countries. In this way, the audit forms the logical conclusion of this series: it shifts the focus definitively from the incident to the system.

3. Three flavours in practice

Although the boundaries are fluid in practice, we can conceptually distinguish three types of compliance audits.

3.1 Theme-based audits

These audits focus sharply on a single specific topic. Common examples include:

  • Sanctions and export controls
  • Conflicts of interest and secondary roles
  • Whistleblower arrangements and speak-up culture
  • Gifts and hospitality
  • Third-party due diligence
  • Data privacy and information security

The aim is to test whether the processes and file management around that theme hold up against internal and external standards, and whether day-to-day pressures have quietly overtaken best practice.

For more serious topics such as sanctions and transaction monitoring, such a theme audit closely borders on regular monitoring. The AML/CFT internal audits series examines the specific pitfalls of this: the temptation of checklist thinking, blind spots in data, and the subtle pressure to soften sharp findings.

3.2 Process and chain audits

Here the focus is not on the standard, but on the flow. We examine the end-to-end chain, such as:

  • The full client onboarding and KYC process.
  • The procurement and supplier chain.
  • M&A and integration trajectories.
  • Trade and export processes.

The central question is: where in the chain do risks accumulate, where do we rely too heavily on a single vulnerable control point, and where is there no clear owner? Often the errors seen in individual files reappear here at scale: structural backlogs, poor file management or critical controls simply skipped under time pressure.

3.3 Framework or system audits

This is the helicopter view. These audits examine the complete compliance framework:

  • The governance surrounding integrity and compliance.
  • The actual structure and effectiveness of the three lines of defence.
  • The methodology behind risk identification and monitoring.
  • Training, awareness and overall compliance culture.
  • Escalation and reporting to the board, audit committee and regulator.

This type of audit aligns with external standards (such as international guidance on effective compliance programmes or corporate governance codes). It determines whether the organisation’s foundations are solid enough that the other investigations in this series can do their work at all.

4. From finding to improvement plan

Stating the obvious, perhaps, but practice is stubborn: a compliance audit only has value if its findings lead to real change. Too often, an audit results in a thick document that goes straight into a drawer: a long list of observations, but no sharp action plan.

An effective audit report follows a clear three-part structure:

  • Finding: What has been factually and objectively observed?
  • Risk: What could concretely go wrong if this is left as is?
  • Recommendation: What is needed to close the gap structurally?

The report must also provide a realistic assessment of impact and feasibility. The goal is for executives and line managers to immediately understand what is on their plate. It must not become a technical compliance exercise. In the AML/CFT series, we address this under “from report to action”: how do you get management to genuinely move? Being right on paper is one thing. Delivering real change within the organisation is what counts.

5. Roles and responsibilities: the playing field between compliance and audit

As with the other investigations in this series, a compliance audit involves multiple key players. This requires clear coordination.

  • Compliance is the owner of the framework and the substantive standard-setting. In that role, compliance often conducts its own reviews or thematic assessments, or prepares the areas into which internal audit will later dig deeper.
  • Internal Audit maintains the independent perspective on the design and operation of controls, often with compliance as a substantive sparring partner.
  • External specialists join when specific in-depth expertise is required (such as complex sanctions legislation, FCPA/UKBA or IT security), or when maximum independence is required vis-à-vis the regulator or the supervisory board.

Nothing is more damaging to effectiveness, or to internal relationships, than audit and compliance inadvertently fishing in the same pond or duplicating each other’s work. Clear demarcation upfront is not a luxury, but a hard necessity. In the AML/CFT articles, we challenge this further in the context of the “myth of independence”: how internal politics and pressure from above can colour audit outcomes, and how auditors can push back against this.

6. Learning from practice: the root cause approach

Incidents, integrity reports, due diligence findings and KYC issues are all windows onto underlying risks. A mature compliance audit uses that data systematically through:

  • Case analysis: Which types of incidents recur, and what does that reveal about gaps in our policies?
  • Trend analysis: What patterns emerge when we look at data across different countries, business lines or product groups?
  • Root cause investigation: If the same error is made in three different departments, what is the common underlying cause?

The organisation thereby learns to stop mopping the floor and actually turn off the tap. The AML/CFT audit series builds on this by looking specifically at the blind spots in data and culture that mean red flags are in practice still missed or ignored.

7. Compliance audits and the limits of the reasonable

In compliance audits, the inevitable question arises sooner or later: “when is enough, enough?” An auditor can always find more: one additional control, a tightened policy, an extra reporting layer. Without a clearly defined risk appetite, you risk building a top-heavy compliance apparatus that completely paralyses the organisation.

A mature audit approach is willing to make choices:

  • It benchmarks findings directly against the established risk appetite.
  • It not only identifies where practice deviates from the manual, but also acknowledges where the risks are negligible.
  • It facilitates the healthy conversation between board, business and compliance about the balance between safety, workability and cost.

This discussion is directly mirrored in AML/CFT audits: stricter monitoring and generating more alerts may always look better on paper, until the system becomes clogged and the real risks are drowned out by noise.

8. Final note: the circle is complete

With the compliance audit, the circle of this series is closed. Where we began in the capillaries of the organisation, at the concrete incident, the difficult KYC file or the integrity report, we end at the nervous system.

The dynamic is clear: incidents expose the acute wounds, due diligence and KYC keep the back door closed, but the compliance audit checks whether the foundations of the entire house can withstand the storm. It shifts the focus definitively from firefighting to structural fire safety. The ultimate question for the board is not whether the rules happened to be followed today, but whether the organisation is structured in such a way that it can still do so tomorrow and a year from now.

Invitation to Consult

If this article has raised questions or topics you would like to discuss further, we welcome you to reach out. If you have a specific case you would like to explore, we are happy to arrange an informal introductory conversation. Our contact details can be found here.

Read more updates and articles here.

Get in touch

Dennis van der Meer | +31618948848 | dennis.van.der.meer@compliancechamps.com

Boy Custers | +31649935735 | boy.custers@compliancechamps.com

 

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/04/Afbeeldingen-Sectoren-pagina-website-1-1.png 938 938 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-06-29 14:47:352026-07-16 14:16:02Compliance audits: from incident to system

FIU-NL gets a pause button, but crypto keeps moving

From 1 July 2026, Financial Intelligence Unit Nederland (FIU-NL) will receive a new power: the power to postpone transactions. Under the new Article 17a Wwft, FIU-NL may require reporting institutions to temporarily postpone one or more transactions if there are signs of money laundering, related criminal activity or terrorist financing. 

The word temporarily is important. 

This is not a general freezing power. A postponement may last for up to five working days. If the request is made on behalf of a foreign FIU, it may last for up to ten working days. The aim is to create a short period in which suspicious value can be stopped before it disappears. 

The Anti Money Laundering Centre, the knowledge and expertise centre of the FIOD, has described the new power in similar terms. It is a temporary tool with clear limits. It is not an open-ended freeze. 

Why crypto makes this more complex

For crypto, this distinction matters. 

FIU-NL’s new power does not extend to stopping a blockchain network in its entirety. Unlike a bank transfer that may sometimes be recalled, or a payment instruction that may still be intercepted, on-chain transactions are settled by the network itself. Once crypto assets have been broadcast to and confirmed on a blockchain network, the transaction is generally final in practice. It cannot usually be reversed by a regulated platform or by a government authority. 

There is one practical point to keep in mind. A crypto withdrawal request is not always the same as a completed blockchain transaction. Before confirmation, a transaction may still be pending. It may still be inside the platform’s own systems, or it may be waiting for confirmation by the network. At that stage, it may still be possible to stop it. 

Once the transaction has been confirmed on chain, the original transfer is effectively out of reach. 

Where the pause button can still work

This makes exchanges, brokers and custody providers important control points. They may still be able to stop a pending withdrawal, restrict crypto assets held in custody, or block a customer’s balance before value leaves the platform. 

FIU-NL’s new power can therefore help in two practical situations: where crypto assets are still held in a custodial account at a regulated platform, and where fiat proceeds or other customer balances remain available. 

However, the new power does not solve the crypto’s speed and finality problem. If the relevant transaction has already been confirmed on chain, the pause button comes too late for that transaction. 

Why this matters for regulated platforms and their customers

For regulated platforms, such as exchanges and custody providers, FIU-NL’s new power has direct operational consequences. When a platform receives a postponement request from FIU-NL, it must act immediately. It must also be able to document its response afterwards. 

This means the issue is not only legal. Platforms need clear internal procedures. These procedures should explain how FIU-NL requests are received, escalated, and handled. They should also make clear who is authorized to act on such requests, how the relevant assets or balances are identified, and how each step is recorded. 

The effectiveness of the new power will also depend heavily on the quality and speed of the platform’s transaction monitoring. Suspicious activity that is only identified after a withdrawal has been confirmed on chain cannot be postponed or reversed. Platforms should therefore assess whether their monitoring, alert handling and withdrawal controls are fast enough. 

This also matters for customers. A delayed withdrawal or temporarily restricted balance should be handled quickly, consistently and in line with the legal requirements. If the platform is allowed or required to communicate with the customer, it should be able to explain the situation clearly without harming the legal process. 

There is also a risk that bad actors will adapt. They may try to move assets away from regulated platforms more quickly, because those platforms are the main point where transactions can still be stopped. This makes fast monitoring, clear escalation and effective withdrawal controls even more important. 

Part of a broader AML trend

The Dutch change should not be seen on its own. Similar intervention tools already exist in other European AML frameworks. FIU-NL has also noted that many foreign FIUs already have comparable powers, and that the Dutch addition should support international cooperation. 

The direction is clear. AML is moving beyond reporting suspicion after the event. Increasingly, the focus is on stopping suspicious value flows before they disappear. 

Crypto tests the limits of this approach. 

The legal power to pause a transaction only matters where there is still practical control. Platforms can freeze, delay, or block. Blockchains do not rewind. 

Conclusion

FIU-NL’s new power is useful, but it is not a full solution for crypto. It can help stop suspicious asset while that asset is still inside a regulated platform. The same applies where related fiat proceeds or other customer balances remain available.

A confirmed blockchain transaction, however, generally cannot be reversed.

For regulated platforms, the main compliance challenge is speed. They need fast monitoring, clear escalation routes, practical procedures and strong withdrawal controls 

Invitation to Consult

If this article has raised questions or topics you would like to discuss further, we welcome you to reach out. If you have a specific case you would like to explore, we are happy to arrange an informal introductory conversation. Our contact details can be found here.

Read more updates and articles here.

 

https://en.compliancechamps.com/wp-content/uploads/sites/2/2025/11/Afbeeldingen-Sectoren-pagina-website-1.png 938 938 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-06-04 13:21:232026-06-04 17:08:05FIU-NL gets a pause button, but crypto keeps moving

AMLA Update 

What recent AMLA developments mean for firms 

Since the end of March, AMLA has continued to expand its consultation activities and lay the groundwork for its future supervisory role. While many organisations are focused on upcoming AML Regulation deadlines, AMLA’s recent work provides an early indication of future supervisory expectations.

Focus on governance and risk assessments 

During the past months, AMLA has consulted on group wide AML/CFT policies, procedures and controls, as well as business wide risk assessments. Both topics are fundamental building blocks of the future EU AML framework. 

The message is clear: AMLA expects firms to demonstrate a well documented and risk based approach to AML/CFT compliance, supported by effective governance arrangements and consistent implementation across the organisation. 

For cross-border firms, expectations are increasing around harmonised AML/CFT frameworks and effective group-level oversight.

Supervisory cooperation is becoming more important 

AMLA has also consulted on standards governing cooperation between home and host supervisors for cross border groups. While these proposals primarily address supervisory authorities, they signal a broader move towards greater consistency and coordination across the European Union. 

For firms, this could mean more consistent supervision, greater information sharing and increased scrutiny of cross-border activities.

Preparing for AMLA’s future supervisory role 

AMLA has also published a reporting package to support the future identification of entities subject to direct supervision.

Although direct supervision is not expected until 2028, AMLA is already preparing its supervisory model. This demonstrates that the Authority’s focus is increasingly shifting from institution building towards operational readiness. 

What firms should consider now 

While many organisations are understandably focused on upcoming AML Regulation implementation deadlines, AMLA’s recent work offers an early indication of future supervisory expectations. 

In our view, firms should pay particular attention to the following areas: 

  • Reviewing the quality and documentation of business wide risk assessments.
  • Assessing whether group wide AML/CFT policies and controls are applied consistently across legal entities andjurisdictions.
  • Evaluating governance structures and oversight arrangements to ensure clear accountability for AML/CFT risks.
  • Monitoring AMLA consultations and technical standards to identify future implementation requirements at an early stage.

The emerging theme across AMLA’s recent publications is consistency. AMLA’s recent work reflects a clear focus on consistency. The goal is a more harmonised AML/CFT framework across the EU.

As AMLA releases further standards throughout 2026, firms that assess their readiness now will be better prepared for regulatory change.

Compliance Champs will continue to monitor AMLA developments and share practical insights on how firms can prepare for the future EU AML/CFT framework. 

Invitation to Consult

If this article has raised questions or topics you would like to discuss further, we welcome you to reach out. If you have a specific case you would like to explore, we are happy to arrange an informal introductory conversation. Our contact details can be found here.

Read more updates and articles here.

 

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/06/EU-picture.webp 534 800 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-06-03 13:46:092026-06-03 13:46:09AMLA Update 

Everyone Wants Compliance… Until It Conflicts with the Business

Almost every organisation says the same thing: 

“Compliance is important.” “We take AML/CFT seriously.” “We want to manage our risks.” 

Investments are made in policies, monitoring tools, awareness training, and periodic audits. On paper, things often look solid: processes exist, controls are in place, and reports are neatly discussed in governance meetings. Yet in practice, we continue to see the same problems resurface. Large files in which money laundering risks go undetected for years, transactions that were never critically reviewed, or organisations caught entirely off guard when a regulator concludes that their controls fall seriously short. 

That rarely happens because no one knew what the rules were. Far more often, the problem has a different root cause: the tension between Internal Audit and the business. 

That tension is usually not openly visible. No one explicitly says that risks are unimportant or that compliance gets in the way. But as soon as audit findings touch on commercial objectives, client relationships, capacity, or revenue, the dynamic often shifts quickly. Findings get nuanced, priorities change, and discussions suddenly revolve less around risk and more around feasibility, timing, or “the reality of the business.” 

And that is precisely where a vulnerability arises that many organisations underestimate. 

When Internal Audit and the business end up on opposing sides, risks do not disappear. They simply become less visible. This dynamic is not limited to internal audit departments. It also surfaces regularly in external internal audit engagements, where independence can come under pressure the moment conclusions become commercially or organisationally uncomfortable. 

In this article, we explore that tension. We look at why it is so persistent, and how organisations can prevent audit from becoming a process in which everyone participates but no one truly listens. 

 

The Core of the Problem: Audit and Business Often Speak a Different Language 

On paper, Internal Audit and the business share the same objective: a commercially sound, safe, and sustainable organisation. In practice, however, the two functions are often evaluated against entirely different interests. 

Internal Audit is expected to make risks visible, critically assess processes, and independently evaluate whether controls are genuinely effective. The business, by contrast, is primarily driven by growth, client satisfaction, speed, and commercial results. As long as those interests remain balanced, audit and the business complement each other well. The problem arises when risk management directly conflicts with commercial reality. 

An audit finding rarely represents just a theoretical risk. In practice, it often means additional work, stricter controls, delays in onboarding, difficult client conversations, or higher operational costs. And that is precisely why resistance emerges. 

That resistance is not always conscious. In fact, many business managers are genuinely convinced they take risks seriously. At the same time, they feel pressure to keep processes workable, meet targets, and stay ahead of competitors. This gradually creates a situation in which risks are not actively ignored, but are systematically downplayed or relativised. 

This tends to manifest in three recurring tensions. 

 

Three Areas of Tension Between Internal Audit and the Business 

The Gap Between Theory and Practice

One of the biggest frustrations from the business side is the feeling that audit does not sufficiently understand how processes work in practice. Auditors examine files, procedures, and regulations, while commercial teams deal daily with client pressure, deadlines, revenue targets, and operational constraints. As a result, audit findings are regularly experienced as theoretical or difficult to implement. 

That frustration is sometimes understandable. An audit recommendation may be entirely logical on paper but lead to longer onboarding trajectories, more escalations, or additional workload for operational teams. The risk, however, arises when feasibility is consistently placed above risk management. 

When that happens, organisations begin to make concessions, whether consciously or not. Findings are “reprioritised,” deadlines are pushed back, or shortcomings are framed with arguments such as “we’ll lose clients if we do this” or “this is operationally not feasible.” In the short term, that may feel pragmatic. In the longer term, it creates precisely the conditions in which risks can grow without anyone truly intervening. 

Audit as Police Officer Rather Than Partner

A second area of tension emerges when audit is primarily seen as a function that comes to point out mistakes. Many organisations claim that audit is a “business partner,” but in practice employees still frequently experience it as a controller, police officer, or box-ticking machine. 

That perception tends to develop when audits are heavily focused on deviations, shortcomings, and reporting, without sufficient attention to the underlying causes of behaviour or process issues. As a result, employees feel assessed rather than supported. 

The consequences often show up subtly in behaviour. Doubts are raised less readily, escalations are withheld, and risks are resolved internally rather than formally reported. Not because employees are deliberately hiding risks, but because people naturally become more defensive in an environment where mistakes appear to carry primarily negative consequences. 

Within AML/CFT, this is a serious problem. Many major incidents do not arise because signals were entirely absent, but because employees no longer felt safe raising concerns or gradually came to see irregularities as normal. When audit is exclusively associated with control and accountability, the very openness needed to surface risks in time begins to disappear. 

Overconfidence and the Belief That “It’s Fine Here”

The third area of tension may be the most insidious: organisational overconfidence. Many organisations that later face serious AML/CFT deficiencies were convinced for years that their controls were essentially in good order. 

That perception is most common in organisations that have never received a significant fine, have relied on the same processes for years, or place their trust in existing monitoring tools and experienced staff. Over time, a conviction forms that the organisation understands its risks and that serious incidents are something that happens to others. 

That is precisely where the danger lies. 

Risks typically develop gradually. Temporary workarounds become permanent, alerts become routine, exceptions become normal, and systems slowly become outdated. Because incidents do not occur, it feels as though the controls must be effective. That feeling persists until a regulator, enforcement agency, or internal investigation reveals that certain signals were missed for years. 

In hindsight, it often turns out that the signals were there all along. Audit findings had been flagged earlier, employees had raised concerns, or systems had been underperforming for some time. Yet no one felt sufficient urgency to look at the situation critically. 

And that is precisely why overconfidence is so dangerous within AML/CFT. It causes organisations not to actively ignore risks, but simply to take them less and less seriously. 

 

External Internal Audit: Independence Remains Complex 

Some organisations use external parties for their internal audit function. In those cases, these tensions often become even more complex. An external party must operate independently, while simultaneously remaining dependent on the client for budget, contract renewals, and the commercial relationship. 

This does not mean that external auditors consciously report more leniently, but it does create a tension that is difficult to fully ignore in practice. Particularly where organisations are sensitive to critical conclusions, pressure can emerge to soften formulations, reprioritise findings, or direct audits toward “safer” topics. 

It is also not uncommon for organisations to seek auditors that better align with their expectations or culture. That need not be problematic in itself, but it can lead to situations where independence gradually shifts from critical assessment to relationship management. 

That is precisely why effective external internal audit requires more than technical expertise. It also requires the willingness to keep naming uncomfortable conclusions, even when those conclusions are commercially or organisationally sensitive. 

 

How to Prevent Audit and Business from Remaining at Odds 

The solution does not lie in less audit or softer findings. The problem does not disappear by framing risks more gently. Organisations become stronger when audit and the business understand each other better without losing sight of their respective roles. 

That starts with auditors who have a genuine feel for the practical realities of the business. An audit that fails to account for operational context quickly loses credibility, however strong the substantive findings may be. At the same time, the business must accept that risk management is sometimes uncomfortable, time-consuming, or commercially inconvenient. 

It also helps when audit conversations focus less on blame and more on underlying causes. The question “what went wrong?” is valuable, but asking “why does this behaviour occur?” and “what incentives drive these choices?” often yields far more actionable insights. 

Finally, effective collaboration requires a culture in which employees feel safe raising doubts. The most vulnerable organisations are usually not those where mistakes are made, but those where no one feels able to name them. 

 

Conclusion: The Real Struggle Is Not Between Audit and Business 

Ultimately, the real struggle is not between Internal Audit and the business. It is between short-term and long-term thinking, between commercial pressure and risk awareness, and between comfort and confrontation. 

That is precisely why audit plays a difficult but important role. Not as a police officer or a box-ticking machine, but as a function that makes visible where organisations are becoming vulnerable. That matters most at the moments when commercial interests, time pressure, or organisational sensitivities are at their greatest. 

Because ultimately, the largest problems rarely arise because organisations lack rules. They arise when organisations gradually convince themselves that the risks will probably turn out to be manageable after all. 

And that is precisely where good audit needs to cut through. 

 

Next Article

In the next article, we examine an uncomfortable truth: Internal Audit versus Business. Why audit teams are so often seen as a brake on progress, and how to change that. 

 

Get in touch

Dennis van der Meer | +31618948848 | dennis.van.der.meer@compliancechamps.com

Boy Custers | +31649935735 | boy.custers@compliancechamps.com

https://en.compliancechamps.com/wp-content/uploads/sites/2/2025/11/Afbeeldingen-Sectoren-pagina-website-6.png 938 938 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-06-01 17:14:182026-06-01 17:14:40Everyone Wants Compliance… Until It Conflicts with the Business
Compliance Champs - Case Sourcing

Crypto and Sanctions in 2026: When Geopolitics Moves On-Chain

Sanctions evasion is no longer a niche compliance issue, and if your institution still treats it as one, you’re already behind.

The numbers from 2025 make this hard to ignore. The value received by sanctioned entities surged by 694%, pushing illicit on-chain transaction volume to a record $154 billion.[1] In our work with compliance teams across financial institutions and CASP, the biggest gap isn’t awareness of crypto risk in the abstract, it’s understanding what that risk actually looks like in practice, and what to do about it.

Iran: The Most Urgent Compliance Risk Right Now

Of all the current sanctions and crypto stories, Iran demands the most immediate attention.

The Islamic Revolutionary Guard Corps (IRGC) and its proxy networks accounted for over 50% of value received by Iranian crypto addresses in Q4 2025 alone, totalling more than $3 billion across the year.[2] This is not opportunistic misuse by bad actors exploiting a gap, its state-directed financial infrastructure, which means the scale and sophistication of evasion will only grow.

OFAC’s enforcement response reflects this shift. In January 2026, the U.S. Treasury sanctioned two crypto exchanges, Zedcex and Zedxion, for facilitating transactions linked to Iran’s financial sector and IRGC-connected actors. Critically, the designation included specific USDT wallets on the Tron network. Sanctions enforcement now explicitly targets on-chain identifiers alongside traditional legal entities.[3] For compliance professionals, the implication is direct: name-based screening alone is no longer sufficient. Wallet-level screening is now an expected control.

The urgency sharpened in late February 2026, when U.S. and Israeli airstrikes on Iranian targets were followed within minutes by a 700% spike in outflows from Iranian crypto, $10.3 million moving within 48 hours.[4] Think about what that means operationally: crypto functioning as a real-time financial crisis management tool for a sanctioned jurisdiction, moving faster than most compliance teams can respond.

The Binance situation adds another dimension worth watching. The Wall Street Journal reported in early 2026 that the world’s largest crypto exchange had processed over $1 billion in transactions tied to sanctioned Iranian entities- which Binance disputes. Regardless of the outcome, the case illustrates how quickly Iran-related exposure can translate into reputational and regulatory risks.

Russia: From Evasion to Financial Infrastructure

Iran shows how crypto can absorb sanctions pressure in real time. Russia shows something more structural, and in some ways more concerning for long-term compliance exposure.

Russia isn’t just evading sanctions through crypto; it’s building parallel financial infrastructure designed to operate outside Western financial rails entirely.[5] The clearest example is the A7A5 stablecoin; a Ruble-backed token, processed through a dedicated decentralised exchange. A7A5 processed an extraordinary $93.3 billion in less than a year. That’s not a workaround. That’s an alternative system.

At the same time, Russia is leveraging its subsidised energy sector to capture roughly 16% of the global Bitcoin hash rate, effectively minting new, “clean” Bitcoin with no on-chain link to any sanctioned entity or jurisdiction.[6] This is crypto mining as a strategic economic bypass, not a retail activity.

The Regulatory Response: Closing the Gaps

Regulators aren’t just responding, they are accelerating. The developments of the pas weeks along illustrate how quickly this space is moving.

In the EU, MiCAR and the revised Transfer of Funds Regulation (the Crypto Travel Rule) significantly expand the supervisory framework for CASPs.  But just a couple of week ago, the EU adopted its 20th sanction package against Russia, introducing a sweeping ban on all crypto asset transactions with Russian and Belarusian providers.[7] The digital Ruble and RUBx have been added to the EU’s banned crypto-assets lists, with the digital Ruble ban explicitly designed to close a circumvention channel ahead of Russia’s planned Central Bank Digital Currency (CBDC) rollout in September 2026.

In the United States, the GENIUS Act brings payment stablecoin issuers into the scope of the Bank Secrecy Act and sanctions obligations. Just two days ago, FinCEN and OFAC published new proposals that would require digital asset firms to embed sanctions enforcement directly into their code, making compliance automatic and continuous.[8] If adopted, this would represent a fundamental shift in how sanctions compliance is architected across the industry.

The message is consistent on both sides of the Atlantic: the regulatory perimeter around crypto is closing, and the expectation that compliance teams understand this space is rising accordingly.

What This Means in Practice

From a compliance perspective, a few things consistently get underestimated.

Wallet-level screening is still treated as option in too many programs, but it isn’t. Stablecoins, particularly USDT on the Tron network, appear disproportionately in sanctioned and illicit flows relative to their overall market share, and deserve heightened scrutiny. Blockchain analytics tools like Chainalysis, TRM Labs, and Elliptic are no longer specialist add-ons; they are baseline infrastructure for any institution with crypto exposure. And importantly, crypto sanctions risks isn’t only a CASP problem. Banks with no crypto products are still exposed through payment flows, PSP relationships, and clients whose activity connects to crypto rails.

Finally, governance and escalation procedures need to exist before an issue arises, not during one. Knowing when to freeze assets, file reports with supervisors, and escalate internally is as critical as detection itself.

Deepen Your Knowledge with Compliance Champs

The risks in this article are no longer theoretical, they are showing up in transaction monitoring queues, client reviews and regulatory examinations right now. For compliance teams looking for practical, structured guidance on how crypto sanctions exposure actually appears in day-to-day work, Compliance Champs has developed a dedicated e-learning course: Crypto & Sanctions Awareness.

Explore the course here: Training Crypto & Sanctions Awareness

 


Do you seek support and assistance in enhancing your Crypto Compliance Framework?

Please reach out to us on: info@compliancechamps.com

Read more articles here.

 



[1] Chainalysis. (2026, March 5). Crypto crime in 2025 was primarily driven by 694% surge in state-driven sanctions evasion volume. Chainalysis Blog. https://www.chainalysis.com/blog/crypto-sanctions-2026.

[2] Ibid.

[3] Elliptic. (2026). OFAC sanctions exchanges Zedcex and Zedxion for assisting in Iranian sanctions evasion and IRGC operations. Elliptic Blog. https://www.elliptic.co/blog/ofac-sanctions-exchanges-zedcex-and-zedxion-for-assisting-in-iranian-sanctions-evasion-and-irgc-operations.

[4] Elliptic. (2026). Iranian crypto asset outflows surge 700% following airstrikes. Elliptic Blog. https://www.elliptic.co/blog/iranian-cryptoasset-outflows-surge-700-percent-following-attacks

[5] Chainalysis. (2026, March 5). Crypto crime in 2025 was primarily driven by 694% surge in state-driven sanctions evasion volume. Chainalysis Blog. https://www.chainalysis.com/blog/crypto-sanctions-2026.

[6] Elliptic. (2026). Russia-linked cryptocurrency services and sanctions evasion. Elliptic Blog. https://www.elliptic.co/blog/russia-linked-cryptocurrency-services-and-sanctions-evasion.

[7] TRM Labs. (2026, April 23). EU Adopts 20th sanctions package on Russia. TRM Labs Blog. https://www.trmlabs.com/resources/blog/eu-adopts-20th-sanctions-package-on-russia—-including-a-sweeping-ban-on-all-crypto-asset-transactions-with-russian-and-belarusian-providers

[8] PYMTNS. (2026, April 22). Treasury calls for programmable financial enforcement across crypto. PYMNTS.com. https://www.pymnts.com/cryptocurrency/2026/treasury-calls-for-programmable-financial-enforcement-across-crypto/.

https://en.compliancechamps.com/wp-content/uploads/sites/2/2024/07/compliance-champs-case-sourcing.jpg 799 1920 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-05-20 17:29:122026-05-20 17:29:12Crypto and Sanctions in 2026: When Geopolitics Moves On-Chain

AML and KYC Investigations: From Customer Onboarding to Ongoing Due Dilligence

Introduction

Where previous articles in this series primarily focused on investigations into incidents, reports, or specific transactions, AML and KYC investigations are centred on the front end of the relationship. The objective is not primarily to determine after the fact what went wrong, but to assess — before and during the relationship — who the organisation is doing business with, what risks are involved, and whether its services could be misused for money laundering, terrorist financing, or sanctions evasion. In a world where armed conflicts and geopolitical tensions directly impact trade flows, payment systems, and ownership structures, that is more relevant than ever. 

That makes AML and KYC investigations fundamentally different from many other compliance investigations. They are not one-off exercises, but ongoing in nature. Client due diligence starts during onboarding, but it does not end there. The relationship, transactions, and risk profile must be monitored throughout the entire client lifecycle and reassessed where necessary. 

 

Why AML and KYC Investigations Are About More Than Onboarding

In practice, KYC is still often treated as a mandatory part of client onboarding: collect identification documents, establish the UBO, screen sanctions lists, and close the file. That approach does not do justice to the structure and intent of anti-money laundering legislation. The law requires regulated institutions to apply a risk-based approach, looking not only at who the client is, but also at the purpose of the relationship, the nature of the services provided, the origin of funds, and the expected transaction profile. 

As a result, the focus of the investigation shifts. The question is no longer simply: “Who is this client?” but rather: “Does this client — with this structure, these activities, and these financial flows — fit within the organisation’s integrity and risk framework?” 

That requires analysis, interpretation, and periodic reassessment, not just document collection.

 

The Foundation: AML, CDD, and KYC 

AML is the broader anti-money laundering framework. KYC sits within that framework as the process of “knowing your customer,” while CDD — customer due diligence — is the practical investigation through which that process is carried out. In the Netherlands, this is legally embedded in anti-money laundering legislation. Regulated entities are required, among other things, to identify and verify clients, establish ultimate beneficial owners, understand the purpose and intended nature of the business relationship, monitor transactions, and report unusual transactions. 

On paper, that may sound straightforward. In practice, however, the real investigation often only begins once the structure behind the client turns out to be more complex than initially visible. Behind a corporate entity may sit foreign holding companies, foundations, nominee arrangements, trusts, or UBOs that are only indirectly visible. It is precisely in these types of files that AML and KYC reveal themselves as more than administrative processes and become investigative disciplines in their own right. 

 

KYC Beyond Regulated Sectors: The Shifted Compliance Pressure from Banks 

The importance of KYC is not always fully recognised by non-regulated businesses. In international trade especially, there is still sometimes an assumption that KYC is primarily a matter for banks, payment service providers, and other regulated institutions. Formally, that distinction may be correct, but in practice the reality has changed significantly. Banks increasingly shift part of their compliance pressure onto their clients. They are held accountable for the risks within their own portfolios.

As a result, even non-regulated companies are increasingly confronted with questions about their customer base, trade flows, UBO structures, source of funds, involved jurisdictions, and internal controls. This is particularly visible in internationally operating trading companies, import-export structures, and businesses with complex supply chains. In those cases, banks may request additional information or expect the company itself to have implemented at least a basic compliance or KYC framework. 

For many organisations, the urgency only becomes real once the bank starts asking difficult questions and signals that the existing documentation is insufficient. At that point, KYC shifts from an abstract compliance topic to an operational issue with immediate consequences. Banks may impose additional requirements, insist on the implementation of a compliance framework, apply stricter transaction monitoring, or in the most severe cases put the relationship under pressure through de-risking or offboarding. 

That is precisely why non-regulated businesses should not wait until a bank forces the issue, but should proactively consider how they assess and document their customers, trade flows, and counterparties. 

 

Source Selection: Data Providers Versus Local Registrers 

An important — but often underestimated — aspect of AML and KYC investigations is the question of where client information originates. In practice, many organisations rely on international commercial data providers such as Dun & Bradstreet or Bureau van Dijk/Moody’s because they offer fast, scalable, and user-friendly access to information on companies, shareholder structures, and group relationships. Especially in international investigations, these tools are valuable because they consolidate data from multiple jurisdictions into one environment. 

At the same time, there is an important consideration here. In many cases, these databases are derived from underlying primary sources such as local trade registers, publication registers, or other official records. This means there may be a delay between a change in the local register and its appearance in a commercial database. That difference can become highly relevant in cases involving changes in management, ownership structures, registered offices, or ultimate beneficial ownership. 

For institutions with a higher risk appetite, relying on a data provider may be a defensible choice. This is especially true in low-risk and large-scale onboarding environments with many new clients. In these cases, speed, scalability, and operational efficiency often carry significant weight. However, as risk levels increase, organisations should rely more on primary sources. These sources include local trade registers or other official registries in the relevant jurisdiction. Those sources often contain the most current and legally authoritative information, even if they are less user-friendly to access. 

The core question is not whether data providers are “good” or “bad.” The key issue is whether the chosen source fits the client’s risk profile and the organisation’s risk appetite. In low-risk processes, relying on a reliable data provider may be entirely proportionate. In complex, international, or high-risk files, additional verification is often advisable. In some cases, it may even be necessary to verify commercial data against local registers or other primary documentation.

 

From Identification to Risk Assessment 

A proper AML or KYC investigation does not consist of a single action, but of a sequence of investigative steps. First, the client is identified and verified. After that, the organisation assesses who acts on behalf of the client, who the ultimate beneficial owners are, whether PEPs, sanctions risks, or heightened geographical risks are involved, and how the services are expected to be used. 

Ultimately, this results in a risk assessment. Not every client requires the same level of scrutiny. A local company with a straightforward structure and predictable activities presents a very different profile from an internationally active group with layered ownership structures, cross-border financial flows, and exposure to high-risk jurisdictions. That is precisely why AML and KYC operate on a risk-based approach: the higher the risk, the deeper the investigation and the stronger the justification required. 

In practice, however, the question from clients or internal stakeholders rarely stops there. They do not only want to know whether a party should be classified as green, orange, or red; they primarily want to understand what that classification means for the business decision itself. In other words: can — or should — we still do business with this party? That is an understandable question, but not a purely technical exercise. 

A risk classification is not an automatic go/no-go decision. It forms the basis for a broader assessment in which compliance, business teams, legal, and sometimes senior management must determine whether a risk is acceptable, under what conditions, and which mitigating measures may be required.

This is often where a strong KYC investigation provides its greatest value. Not merely by identifying elevated risks, but by helping organisations understand the practical consequences. In some cases, this may lead to enhanced monitoring, additional documentation, or stricter contractual safeguards. In others, the conclusion may be that the relationship falls outside the organisation’s risk appetite or creates too much pressure on its banking relationships, licences, or reputation to proceed responsibly.

 

Ongoing Monitoring and Transactions 

One of the biggest misconceptions in KYC is that the process ends after onboarding. In reality, that is only the beginning of the second phase. Anti-money laundering legislation requires organisations to continuously monitor both the business relationship and transactions against the profile established during onboarding. If a client suddenly begins operating in different jurisdictions, processing unusual transaction volumes, or carrying out activities inconsistent with its known business profile, that should trigger reassessment.

Within AML and KYC investigations, sanctions screening now deserves particular attention. Due to current geopolitical tensions and armed conflicts, sanctions regimes are changing more rapidly, sanctions lists are updated more frequently, and attention for circumvention structures involving third countries, intermediaries, and complex trade chains has increased significantly. As a result, it is no longer sufficient to perform a one-time sanctions screening during onboarding. Particularly where international clients, trade flows, or payments involving high-risk jurisdictions are concerned, organisations must remain continuously alert to changes involving counterparties, countries, goods flows, and ultimate beneficial ownership. 

Sanctions screening therefore extends beyond the question of whether a name appears on a sanctions list. Increasingly, the issue is whether transactions, counterparties, or structures indicate an elevated risk of sanctions evasion. In sectors involving international trade, logistics, commodities, or complex supply chains, this can have major implications for both transaction assessments and overall client acceptance.

That makes AML and KYC investigations inherently dynamic. New directors, changes in ownership structures, amended sanctions regimes, or adverse media can all justify reopening a file. A client initially classified as low risk may present a completely different profile a year later.

At that point, client due diligence begins to overlap with transaction monitoring and, in some cases, reporting obligations. Where irregularities cannot be adequately explained, or where transactions qualify as unusual, the investigation may shift from routine compliance management into a more in-depth integrity or AML investigation.

 

Common Challenges in Practice

In many organisations, the greatest challenge lies not in the rules themselves, but in their execution. Files are incomplete, information from different systems does not align, commercial pressure conflicts with compliance requirements, and periodic reviews are postponed. Clients themselves frequently experience questions about source of wealth, ownership structures, or foreign entities as burdensome or difficult to understand. This is especially true when additional information is requested repeatedly.

Another recurring issue is that KYC is sometimes designed too much as an administrative process. As a result, the investigation deteriorates into document collection, while the real value should lie in the analysis itself. A file is only truly robust if it demonstrates not merely that documents are present, but also why a client was considered acceptable or unacceptable and how that conclusion aligns with the identified risks. 

Source usage also plays an important role here. Organisations that rely blindly on a single data provider or screening tool risk incorporating outdated or incomplete information into their files. Particularly in international investigations, the difference between a commercial database and a local register may determine whether a file remains sufficiently current and reliable.

The Role of Compliance, Business, and External Parties 

AML and KYC investigations are not owned exclusively by compliance departments. The business understands the client, sales teams and relationship managers often identify irregularities first, compliance establishes the framework and second-line controls, and onboarding or operations teams process and verify documentation. 

In complex investigations, organisations increasingly rely on external data providers, screening tools, legal specialists, and investigative firms. This is particularly common in cases involving international structures, sanctions risks, or escalations surrounding account closures.

Because AML and KYC continue throughout the entire client relationship, collaboration is essential. A strong file is not created through one successful onboarding exercise, but through consistent documentation, periodic reassessment, and timely escalation whenever signals no longer fit the client profile. That applies not only to regulated institutions, but increasingly also to companies confronted with indirect compliance pressure from banks, financiers, or commercial partners.

 

Conclusion

and Looking Ahead: From Client Investigations to Compliance Audits 

In many ways, AML and KYC investigations represent the operational day-to-day equivalent of the due diligence and integrity investigations discussed earlier in this series. At their core, they revolve around the same fundamental question: who are we doing business with, and what risks does that create? The objective is to prevent the organisation from becoming part of a larger integrity issue.

Where due diligence often focuses on a one-time decision-making moment, AML and KYC are about continuous vigilance. This places AML and KYC at the intersection of prevention and detection: from client acceptance to transaction monitoring, from file management to potential reporting obligations, and sometimes ultimately to more in-depth internal investigations. 

In the next — and final — article in this series, the focus shifts to compliance audits. AML and KYC investigations focus on individual clients, files, and transactions. Compliance audits assess the design, operation, and effectiveness of the overall compliance framework. That final article therefore forms the logical conclusion of this series: from incidents and files to systems and control. 

 

Invitation to Consult

If this article has raised questions or topics you would like to discuss further, we welcome you to reach out. If you have a specific case you would like to explore, we are happy to arrange an informal introductory conversation. Our contact details can be found on our website.

Next Article

In the next article, we examine an uncomfortable truth: Internal Audit versus Business. Why audit teams are so often seen as a brake on progress — and how to change that. 

 

Get in touch

Dennis van der Meer | +31618948848 | dennis.van.der.meer@compliancechamps.com

Boy Custers | +31649935735 | boy.custers@compliancechamps.com

https://en.compliancechamps.com/wp-content/uploads/sites/2/2026/05/afbeelding-artikel-7-1-scaled.png 1440 2560 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-05-18 09:01:252026-05-18 09:14:22AML and KYC Investigations: From Customer Onboarding to Ongoing Due Dilligence
(Senior) Transaction Monitoring Analyst

The Three Biggest Blind Spots in AML/CFT Audits (and How They Can Ruin Your Organisation)

Introduction: Why Your AML/CFT Audit May Fall Short 

The AML/CFT audit is complete. The report looks good. Compliance has finished its annual reviews, and collectively the conclusion is: we’re in control. 

And yet… several clients turn out to be part of a money laundering network worth hundreds of millions of euros. Your monitoring tool missed transactions that a competitor did flag. An employee has been approving PEP transactions for years without any enhanced due diligence measures in place. 

How is that possible? 

In practice, AML/CFT audits are frequently vulnerable to a number of fundamental blind spots: organizational culture, human behaviour under pressure, and the way data is used and interpreted. 

In this article we unpack: 

  • Blind spot 1 – Culture: Why a “compliance tick-box culture” masks real risk. 
  • Blind spot 2 – People: The psychology behind ignoring red flags. 
  • Blind spot 3 – Data: Why your monitoring tools miss more than they catch. 

 

Blind Spot 1: The “Compliance Tick-Box Culture” – Why Your Organization Thinks It’s Compliant When It Isn’t 

In many organizations, AML/CFT compliance has gradually shifted from a risk-driven discipline to an administrative process. What was once designed to make risks visible and manageable has in practice often been reduced to following steps and ticking checklists. Employees do what is asked of them but rarely pause to consider what it means — for risks, for the organization, or for overall effectiveness. The result? 

  • Reports full of confirmations that processes exist and have been implemented, but with little concrete evidence that they work. 
  • Audits that focus on the “easy” components (such as client onboarding and policy checks), while complex risks (such as transaction monitoring and culture) are ignored. 
  • A false sense of security: “We’re compliant because we follow the rules.” 

Real-world example:

In 2025, de Volksbank was fined €20 million by the DNB because their compliance system was not up to date and risks were not being effectively mitigated. The problem? The bank had processes in place, but they were never critically assessed for effectiveness. Employees followed the rules but didn’t understand why — and so they missed signals that pointed to potential money laundering.

 

Why is this a blind spot?

Culture determines the depth of compliance

In organizations where compliance is seen as an obligation, a minimal approach quickly takes hold: “do just enough to get through the check.” Employees follow processes but don’t feel responsible for the underlying goal. Identifying risks requires curiosity, ownership, and often courage. When those elements are absent, deviations go unnoticed — not because they don’t exist, but because no one is actively looking, raising concerns, or speaking up. 

No personal accountability

When compliance is positioned as a separate department, an implicit divide emerges: “they handle the rules, we handle the business.” In theory, everyone remains responsible, but in practice that accountability erodes. Risk management becomes something you can pass along rather than something that is an integral part of daily work. The result is that signals get lost between teams or simply aren’t acted on because no one truly feels ownership. 

Fear of conflict

Asking critical questions about clients, transactions, or internal processes requires space and psychological safety. In many organizations, employees feel that space is limited. Those who push back questions are sometimes seen as difficult, causing delays, or “not commercial enough.” In high-pressure environments with a strong focus on targets, this effect can be amplified. The rational choice then becomes to stay within the lines and avoid discussion — even when there is doubt. 

How to address this: 

✔ Make compliance everyone’s responsibility: Explain why rules exist and why they matter to the organization (e.g. “This prevents us from being used for money laundering”) and what each person’s role should be. In your next audit, examine the sense of accountability across different teams.

✔ Create a compliance KPI: Encourage employees to report red flags, even when it’s uncomfortable. Compliance training is essential to help them recognize those flags. As an auditor, it is also important to investigate how compliance is incentivized.

✔ Test the culture: Run anonymous employee surveys: Do employees feel comfortable voicing criticism? Do they feel safe reporting irregularities?

✔ Let senior management set the tone: If management ignores compliance, the rest will too. As an auditor, be willing to address the impact of management’s tone. 

 

Blind Spot 2: Human Behavior – The Psychology Behind Ignoring Red Flags

We are not rational — including in compliance. Even if systems and processes are perfect, people make mistakes. And those mistakes are often caused by psychological pitfalls: 

 

Psychological Bias

How It Works

Example

Confirmation bias We seek information that confirms our existing beliefs. An auditor sees that a client looks fine “on paper” and ignores signals that suggest otherwise.
Overconfidence bias We overestimate our own ability to recognise risks. “We know our clients, so we know which transactions are safe.”
Groupthink Group pressure suppresses dissenting opinions. A team ignores a red flag because “everyone agrees there’s no risk here.”
Alert fatigue Too many false alarms lead to all signals being ignored. Employees automatically click “safe” because 99% of alerts turn out to be nothing.
Authority bias We blindly trust authority figures (e.g. senior management).  An employee doubts a transaction but does nothing because the manager says: “This is fine.” 

This vulnerability — these biases — doesn’t reside in systems or procedures, but in human behavior. And that is precisely what makes it so persistent. 

People are not machines

Even the most experienced auditors and compliance officers are constantly making judgements based on incomplete information. Unconscious assumptions and cognitive biases play a larger role than is often acknowledged — think of confirmation bias, but also “normalization of deviance” (deviations that occur often enough start to feel normal). In an audit context, this means signals that don’t immediately fit the expected pattern are more likely to be filtered out or rationalized away. 

Culture amplifies biases

This natural tendency is reinforced by the environment in which people work. Culture — the first blind spot — is a key factor here. In organizations where mistakes are primarily seen as something to be punished, hesitancy sets in. Employees become more cautious about asking critical questions or escalating uncertain cases. Not because they don’t see the risks, but because the personal or organizational cost of “being difficult” feels higher than the potential benefit. The result is that risks may be noticed but not always voiced. 

Pressure to deliver results

On top of this, incentives within organizations are not always aligned with risk management. When speed, commercial targets, or customer satisfaction carry more weight in assessments and rewards, tension arises. Employees who are evaluated throughput times or volumes will — consciously or unconsciously — tend to be less rigorous in their assessments. Not necessarily out of bad intent, but because the system nudges them in that direction. A compliance KPI could help to rebalance this. 

Together, these factors create an environment where risks don’t necessarily disappear but do become less visible. And that makes this one of the most insidious blind spots: everyone is doing their job, and yet a structural underestimation of what is really happening emerges. 

 

How to address this: 

✔ Train on behavior, not just rules: Teach employees to think critically and challenge assumptions. When auditing, review training materials with this theme in mind.

✔ Use red teaming: Have a team deliberately try to circumvent your systems. What works? Where do they hit obstacles? As an auditor, explore how an organization can guard against biases.

✔ Reward reporting mistakes: Build a culture where reporting errors is rewarded, not punished. Always worth probing this in interviews and walkthroughs.

✔ Automate where possible: Replace human judgement with objective criteria where feasible (e.g. “If a transaction has characteristics X, Y, and Z, always escalate”).

✔ Measure the quality of decisions: Analyze retrospectively how often human assessments were wrong and learn from them. 

 

Question for you:

What psychological pitfalls do you recognize in your own team? And how do you ensure that employees feel comfortable expressing their doubts?

 

Blind Spot 3: Data – Why Your Monitoring Tools Miss More Than They Find

Organizations rely on sophisticated monitoring tools to detect suspicious transactions. But what if those tools are not calibrated to the actual risks of your organization? Or if the data fed into the system is incomplete, outdated, or even misinterpreted? 

Real-world examples:

  • Bunq (Dutch neobank) was fined €2.6 million by the DNB in 2025 because their AML controls repeatedly fell short. One of the problems: monitoring tools missed patterns that were suspicious because they had not been calibrated to the specific risks of a fintech.
  • De Volksbank was unable to properly monitor customer activity between 2020 and 2023 because their systems did not keep pace with new money laundering methods (for example, structuring via small amounts).

On paper, data-driven monitoring appears to be one of the strongest lines of defense in AML/CFT. In practice, this is precisely where a fundamental vulnerability lies — not because there is too little data, but because the way we use that data has limitations that are often underestimated. 

 

False Negatives

A first problem lies in what is not seen: so-called false negatives. Monitoring tools are by definition based on models, scenarios, and historical patterns. They recognize what has previously been identified as a risk. But money laundering and fraud evolve constantly. New methods often fall outside existing parameters and therefore remain invisible. The system generates no alert, even though something is genuinely happening. And because “no alert” is often interpreted as “no risk,” a dangerous form of false assurance emerges. 

False Positives

On the other side is the opposite problem: false positives. Many systems generate large volumes of alerts, a considerable portion of which ultimately prove irrelevant. This creates an operational reality where employees must assess enormous volumes daily. Inevitably, alert fatigue sets in. Signals that were initially investigated carefully are increasingly dismissed as “probably nothing again.” Not out of negligence, but out of efficiency. The risk is clear: the one genuine signal can get lost in the noise. 

Data Silos

On top of this, data rarely forms a coherent whole. In many organizations, information is spread across different systems: client data in one platform, transaction data in another, risk assessments somewhere else. These silos make it difficult to connect the dots. A transaction may appear harmless on its own, as may a client profile. But in combination — across time and systems — a pattern may well become visible. If those puzzle pieces never come together, the bigger picture remains hidden. 

 

How to address this: 

✔ Validate your data: Ensure your monitoring tools detect the risks that are relevant to your organization. Test regularly with realistic scenarios. In an audit, dig deeper into how the rules (and their associated scenarios) were developed.

✔ Combine humans and machines: AI and data analysis are powerful, but human judgement is needed to add context (e.g. “This director is a PEP, but their assets are unrelated to the client organization”).

✔ Monitor effectiveness: Measure how many real risks your tool identifies and how many it misses. As an auditor, examine the monitoring tool’s statistics.

✔ Integrate data: Ensure that client data, transaction data, and risk data are connected, so that patterns can surface. Include data types in your audit scope.

 

Conclusion: From Blind Spots to Clear Vision

The three blind spots — culture, human behavior, and data — do not exist in isolation. They reinforce each other. An organization with a tick-box culture will be less critical about the effectiveness of its monitoring. People under pressure or driven by speed will be quicker to trust systems without questioning them. And systems that don’t work effectively but are still used in turn to feed the conviction that “everything is under control.” This creates a closed loop of false assurance. 

The uncomfortable reality is that many audits do not break this dynamic. They confirm that processes exist, that controls have been performed, and that reporting is accurate. But they rarely ask the sharp question: Does this system actually work when it really matters? 

An effective AML/CFT audit therefore looks not only at what has been set up, but above all at how it functions in practice — under pressure, when in doubt, and at the moments when it counts. That demands something different from auditors: 

  • Not just testing, but asking deeper questions 
  • Not just checking, but understanding 
  • Not just reporting, but also confronting 

Because ultimately the difference does not lie in even better policies or even more data. It lies in the willingness to see what you’d rather not see. The question, therefore, is not whether your organization has blind spots. 

 The question is: do you dare to truly make them visible? 

If you ignore these blind spots, you remain reactive rather than proactive. Your organization is not badly protected — but it is vulnerable in places where you least expect it. The 20% that truly makes an impact understands that a good AML/CFT audit is not about ticking regulatory boxes, but about exposing vulnerabilities before they can be exploited. 

 

Invitation to Consult

If this article has raised questions or prompted topics you would like to discuss further — or if you have a specific case, you would like to explore — we welcome you to reach out for an informal introductory conversation. Our contact details can be found on our website. 

 

Next Article

In the next article, we examine an uncomfortable truth: Internal Audit versus Business. Why audit teams are so often seen as a brake on progress — and how to change that. 

 

Get in touch

Dennis van der Meer | +31618948848 | dennis.van.der.meer@compliancechamps.com

Boy Custers | +31649935735 | boy.custers@compliancechamps.com

https://en.compliancechamps.com/wp-content/uploads/sites/2/2024/11/Compliance-Champs-beeldbank-fotografie-154-of-156.jpg 596 1500 liekeinnemee https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg liekeinnemee2026-05-01 15:44:532026-05-01 16:04:04The Three Biggest Blind Spots in AML/CFT Audits (and How They Can Ruin Your Organisation)
Page 1 of 512345

Recent articles

  • Stablecoins in Europe: The Race for Digital Money20 July 2026
  • Are crypto mixers becoming harder to ignore because of the AMLR?16 July 2026
  • EU Pay Transparency Directive13 July 2026

Curious about the possibilities?

Contact one of our consultants

T: +31 6 25 21 22 87
E: info@compliancechamps.com

Logo Compliance Champs
LinkedIn

Contact details

COOLS Urban Office Lofts

Coolsingel 6
3011 AD Rotterdam

T: +31 6 25 21 22 87
E: info@compliancechamps.com

Compliance Champs
Chamber of Commerce number: 84800844
VAT number: NL863377464B01
IBAN: NL44 ABNA 0106 9436 26

Compliance Champs Integrity & Investigations
Chamber of Commerce number: 98134388
VAT number: NL8683.70.289.B.01
IBAN: NL47 ABNA 0149 4612 91

Football Compliance Champs B.V.
Chamber of Commerce number: 42072727
VAT number: NL869582100B01
IBAN: NL60 ABNA 0155 3508 97

Over Compliance Champs

How we work
Our team
Working at
Cases & references
Learning & development
Updates & knowledge
Contact

Services

Compliance Risk Management
Crypto as a Service
Financial Economic Crime (FEC)
Integrity and Investigations
Training & Awareness

© Copyright Compliance Champs | Kwaaijongens, rebels in oplossingen
  • Terms and Conditions
  • Privacy Statements
Scroll to top Scroll to top Scroll to top