Home › Resources › KYC Compliance in 2026

KYC Compliance in 2026: The Real Cost of Getting Verification Wrong

Between October 2016 and July 2021, one Nationwide Building Society customer ran fake furlough claims through an ordinary personal current account. Twenty-four fraudulent Covid-19 payments landed there, £27.3 million in total, with £26.01 million of it arriving inside an eight-day window. Nobody at the bank noticed. The account had cleared onboarding checks years earlier, then sat there unmonitored until HMRC came looking for its money. Most of it came back. Roughly £800,000 didn't. In December 2025, the Financial Conduct Authority fined Nationwide £44,078,500 for the gap, on top of thirteen similar penalties it has handed UK banks since 2021, worth more than £300 million combined.

That's not a story about one bad customer. It's a story about a due diligence process that worked once, at signup, and then quietly stopped working for the better part of five years. For compliance teams heading into 2026, that distinction, between checking someone once and actually keeping watch, is the whole ballgame.

A Decade-Old Account Is Still Your Onboarding Team's Problem

Most compliance programs still treat know-your-customer checks as a gate: verify identity, screen against sanctions and PEP lists, assign a risk rating, let the customer through. Once they clear it, attention moves to the next application in the queue.

That model assumes risk is fixed at the moment of onboarding. It isn't. A dormant account can turn into a mule account within a month. A low-risk retail customer can start running business volumes through a personal account, the exact pattern Nationwide missed for years running. A supplier can change ownership overnight and hand control to someone who showed up on a sanctions list nobody rechecked.

The FCA's finding wasn't that Nationwide had no controls. It had controls. They were built for a snapshot, not for a moving picture, and by the time anyone looked again, tens of millions of pounds had already moved through an account nobody was watching.

Ask a compliance analyst why a file like that doesn't get a second look and the honest answer is usually resourcing, not policy. A bank with millions of retail accounts can't manually re-underwrite every file on a fixed schedule, so teams triage by risk tier and hope the tiering held up. It rarely does for the account that mattered.

Frankfurt Just Put a Deadline on Every Bank's AML Program

Compliance teams who assume the regulatory pressure is a US or UK story are behind. The EU's new Anti-Money Laundering Authority, headquartered in Frankfurt, is now working through the mechanics of direct supervision, and it has attached real dates to the process. National supervisors have to report which entities in their jurisdiction meet the criteria for direct oversight, with a provisional list of eligible firms due by the end of September 2026. The formal selection of which institutions come under direct EU-level supervision happens in 2027. Those firms answer to AMLA starting in 2028.

For a payments company or bank operating across several EU member states, that's not an abstract policy shift sitting in a legal briefing somewhere. It means the file quality, the audit trail, and the customer risk assessments a firm has on record right now could be exactly what a Frankfurt-based supervisor pulls apart in under two years. Waiting until the selection list gets published before cleaning up onboarding records isn't a plan, it's a bet that nobody looks too closely.

The Crypto Reckoning: When KYC Verification Is an Afterthought

Nowhere did the grow-first-verify-later approach cost more in 2025 than in crypto. Regulators handed the sector more than a billion dollars in combined AML penalties over the year, anchored by a $504 million penalty against a major exchange that had onboarded millions of users without adequate identity checks or sanctions screening. Other platforms picked up fines ranging from €20 million to nearly $300 million for the same basic failure: customer acquisition outran the compliance program built underneath it.

The lesson isn't unique to digital assets, but crypto made it visible faster because volumes scaled faster than almost any other sector in financial history. A platform that treats kyc verification as a signup formality, something to clear as fast as possible so a new user can start trading within minutes, is building the exact failure mode regulators keep fining. The exchanges that avoided the worst penalties weren't the ones with the smoothest onboarding screens. They were the ones that kept checking who was actually using the platform after day one, not just on it.

Crypto exchanges weren't the only ones caught out. In January 2025, a coalition of 48 state financial regulators fined Block Inc, the company behind Cash App, roughly $80 million for Bank Secrecy Act and AML violations, pointing to insufficient policies for spotting and preventing money laundering on the platform. Different business model, different regulators, same root cause: growth that ran ahead of the controls meant to keep pace with it.

Perpetual KYC Is Replacing the Annual File Review

The old rhythm, refresh high-risk files every year, medium-risk every two to three years, low-risk every five, was never really about risk. It was about resourcing. Compliance teams could only push through so many manual file reviews in a quarter, so the calendar did the prioritizing instead of actual customer behavior.

Perpetual KYC, sometimes called continuous or always-on due diligence, flips that logic around. Instead of reviewing a file because a date on a spreadsheet arrived, teams flag a file because something about it changed.

Trigger events that should restart monitoring

  • •A change in beneficial ownership or listed company officers
  • •A new hit on a sanctions or adverse media screen that wasn't there last week
  • •A jump in transaction volume or a new counterparty jurisdiction
  • •An expired, replaced, or reported-lost identity document
  • •Account activity that no longer matches the stated purpose of the account

None of those wait for an annual review date, and none of them showed up in the Nationwide file until it was far too late. The point of perpetual KYC isn't reviewing everyone more often. It's catching the right file at the right moment, triggered by an event instead of a calendar entry.

KYB Just Got Harder, Not Easier

Verifying a business customer, the practice most people call KYB, was supposed to get simpler in the US once the Corporate Transparency Act's federal beneficial ownership registry came online. It didn't work out that way. Through 2025 and into 2026, FinCEN narrowed the reporting rule so far that most of the original registry's purpose disappeared.

Who still has to file

  • •US companies and their beneficial owners: exempt from reporting entirely
  • •Foreign entities registered to do business in a US state or tribal jurisdiction: still required to report, though they don't have to name any US persons as beneficial owners

That's a genuine regulatory retreat, and it puts the burden back where it sat before the CTA existed: on the compliance team running its own UBO verification, registry checks, and adverse media screening for domestic business customers, with no federal database to lean on as a backstop. A bank or fintech onboarding a US LLC in 2026 can't assume a government registry has already done the beneficial ownership work for them. It has to build that picture itself, or license a KYB tool that does.

Where Onboarding Friction Actually Belongs

Every added verification step costs conversions. That's real, and pretending otherwise doesn't help anyone. But the Nationwide fine, the billion-plus in crypto AML penalties, and AMLA's supervision timeline all point at the same underlying failure: institutions putting friction in the wrong place, or none at all.

A risk-based approach doesn't mean adding a document check and a liveness selfie to every signup. It means routing a student opening a low-limit account through a fast, largely automated flow, and routing a new business customer moving six-figure sums through a jurisdiction with weak ownership disclosure rules into a slower, document-heavy path with a human actually reviewing it. Step-up verification, asking for more only when an account's behavior or risk profile gives a reason to, keeps the fast lane fast without waving the risky cases through on a rubber stamp.

Synthetic identity fraud is the clearest case for why this matters. A fraud ring doesn't need a stolen identity to open an account anymore. It can blend a real Social Security number with a fabricated name and date of birth, clear a basic document check without trouble, and build a clean transaction history for months before maxing out credit lines or running mule activity through the account. Catching that isn't a one-time verification problem. It's a pattern-over-time problem, which is exactly what a point-in-time check at signup was never built to solve.

The same logic applies to document fraud, which has gotten cheap and good enough to worry about. A convincing fake passport or utility bill used to take real skill to produce. Now a generative tool can spit out a passable one in minutes, and a manual reviewer glancing at a scan on a screen isn't well positioned to catch it. Teams that lean on liveness checks, document forensics, and device or behavioral signals at onboarding, then keep watching afterward, catch far more of this than teams relying on a human eyeballing a photo once and moving on.

The Fine Is Rarely the Expensive Part

Regulators publicize fines because headlines move budgets and boards. What doesn't make the press release is the multi-year remediation program that usually follows: an external skilled-person review, a negotiated overhaul of the transaction monitoring system, months spent back-testing old files against new risk models, and a compliance team that spends the next two years explaining every decision to an auditor sitting in the room with them. Nationwide didn't just write a check. It agreed to fix the underlying control failure, which for a bank with millions of personal accounts means rebuilding monitoring logic, retraining staff, and re-underwriting a long tail of legacy files that never got a second look after onboarding.

That's the number that should worry a compliance officer more than the headline fine: the cost of proving, file by file, that a broken process actually got fixed. It's cheaper, by a wide margin, to build ongoing monitoring in the first place than to reconstruct it under supervision after a regulator has already found the gap.

2026 Is the Year the Static File Runs Out of Excuses

Every piece of this, AMLA's supervision timeline, the FinCEN rollback that puts more weight on private KYB verification, the billion-dollar run of crypto fines, lands on the same point. A customer file that was accurate on the day it was created and never touched again isn't evidence of a job done anymore. It's a liability sitting quietly on the balance sheet.

The institutions that get hurt next won't be the ones with weak onboarding forms. Plenty of onboarding forms are fine. They'll be the ones where a file passed once and everyone assumed that was permanent. Compliance teams that treat verification as running infrastructure, something checking every customer against new information as it appears, rather than a project completed at signup, are the ones that won't end up as next year's version of the Nationwide case. The account that moves £27 million in eight days doesn't announce itself in advance. It looks exactly like every other account looked on the day it opened.

Build compliance that keeps watching after onboarding

Static checks at signup aren't enough anymore. Talk to our compliance team about building ongoing KYC, KYB, and monitoring into your risk program before a regulator finds the gap for you.

Get a Compliance Assessment