Skip to main content

AI Is Accelerating Every Decision in Your Bank. And, Maybe, Every Error.

Accuracy in the new agentic era depends on one thing: who is who.

Picture an Anti-Money Laundering (AML) alert closing automatically at 2:47 a.m. An agentic system decided it was a false positive, in milliseconds, and moved on. Now picture the alert being real, and the two parties on either end of the structured transaction pattern being the same beneficial owner but the system never knew it, because nothing in the bank’s architecture resolved them as the same person.

This is becoming possible right now, as Know Your Customer (KYC), AML, fraud, and wholesale onboarding are increasingly run by AI agents making decisions faster than people can review them. The pace is real. So is the question senior leaders in financial crime, KYC, and compliance are asking in private.

Are we automating errors?

Underneath that question is an even more uncomfortable one. When an AI agent scores a new account opening, when a wire gets cleared, when an AML alert is closed, does the system actually know who it is dealing with?

Yes, you have customer numbers in your core. Yes, you have legal entity records in your Know Your Business platform. Yes, you have screening hits, transaction history, beneficial ownership filings, sanctions lists, Politically Exposed Person feeds, and adverse media. But across all of that, is there a comprehensive understanding of the actual person, legal entity, ownership chain, or counterparty network behind the wire that just hit the queue: the duplicates, the variants, the transliterations, the linkages for every unique identity touching the bank?

So where, across your systems, does an accurate picture of who is who actually live?

For most banks, the honest and uncomfortable answer is nowhere in particular. That gap, between having identity data and having identity intelligence, is the blind spot under most banks’ AI strategies. Banks that deploy AI in KYC, AML, fraud, or wholesale onboarding without first building identity intelligence underneath it are not automating financial crime detection. They are automating financial crime exposure.

The Identity Problem Underneath Financial Crime

A bank vault secured by a network of resolved identities
The numbers are stark. The UN Office on Drugs and Crime estimates that 2 to 5 percent of global GDP, between $800 billion and $2 trillion a year, is laundered through the financial system. Detection rates by financial institutions, by most credible estimates, sit well below 1 percent. Synthetic identity fraud is now the fastest-growing financial crime in the United States, with 2023 losses estimated at over $35 billion, per FiVerity, cited by the Federal Reserve.

$800B–$2T
LAUNDERED ANNUALLY (UN OFFICE ON DRUGS & CRIME)
<1%
DETECTION RATE BY FINANCIAL INSTITUTIONS
$35B+
SYNTHETIC ID FRAUD LOSSES, 2023

Most of what looks like a financial crime detection problem is actually an identity resolution problem. Consider two scenarios very likely playing out right now, both of them invisible until something goes wrong:

A new retail banking customer is being onboarded whose name is spelled slightly differently and whose identity document is different, but whose date of birth and a previously used phone number match a customer the bank exited last year following a Suspicious Activity Report for layering activity. The onboarding system has no way to see this. The compliance team will not learn about it until a regulator does, or until the new account starts repeating the same layering pattern, once again identifying risk to the bank.

A wholesale relationship manager onboards a new commercial customer through a UK subsidiary. The named entity is a clean Cayman Limited Partnership. The Ultimate Beneficial Owner, four layers up, also controls two existing commercial customers in the US and Singapore books, and one was reported in adverse media six months ago in connection with a sanctions-evasion network. Three relationships, three systems, three KYC files. But no human and no current system reconciles them.

Each of these is identity risk in action, and each represents real financial losses, real regulatory exposure, and in several cases real personal liability for senior accountable officers.

Identity intelligence is what would have made the connection visible at the speed of the business: at application, at onboarding, at wire authorization. Not forensically. Not at next year’s remediation. But immediately, and in time.

AI Is About to Magnify This Problem

A fingerprint formed from a beneficial-ownership chain of connected records
AI does not magically fix bad identity data. It accelerates decisions based on whatever foundation already exists.

KYC agents that recommend onboarding in seconds can also approve a re-onboarded bad actor in seconds. AML agents investigating at machine speed can dismiss the wrong alert at machine speed. Get the identity wrong and the rest of the chain is wrong, only faster.

Synthetic identities push this further still. A synthetic identity is a fabricated person, built from a mix of real and made-up data: a real Social Security number paired with a fictitious name and date of birth, or a fully invented individual constructed over months. For commercial banking, fully synthetic LLCs serve the same function. Because there is no real victim to raise an alarm, traditional document verification cannot catch them. Only identity intelligence, looking across many sources for telltale patterns, can.

Banks deploying AI in KYC, AML, fraud, or wholesale onboarding without identity intelligence underneath it are not automating financial crime detection. Just the opposite: they’re automating and escalating financial crime exposure.

What You’re Doing Now Is Not Enough

A reasonable question follows: do we not already have this?

Most banks point to one of three places: the Customer Information File, a master data management (MDM) platform, or the KYC vendor stack, and assume the identity work is being done. It is not.

Customer Information Files are organized around accounts, not people. The same individual can exist as multiple customers across retail, wealth, commercial, and trust businesses with no resolution between them. KYC vendor platforms typically operate point-in-time at onboarding. MDM converges on clean golden records for known internal entities. None were built to continuously resolve entities across messy, multi-source, internal and external data such as sanctions lists, Politically Exposed Persons lists, adverse media, business registries, and beneficial owner registers in real time. Identity intelligence operates from a fundamentally different premise.

Messy data is often the signal.

MASTER DATA MANAGEMENT

Misspellings, transliteration variants, aliases, conflicting dates of birth, different phone numbers across different relationships: in an MDM worldview, these are noise.

IDENTITY INTELLIGENCE

In an identity intelligence worldview, these variances are often the only clue that a sanctioned individual is hiding behind a transliteration, or that a layered ownership chain resolves to a PEP nobody intended you to see.

CASE STUDY
Verisk

This is not theoretical. Verisk, one of the largest data and analytics providers serving the financial services industry, including banks and insurers, has built an enterprise-wide entity resolution platform to do just that. The platform resolves more than 1.6 billion records into over 420 million unique identities with sub-second response, and its outputs feed into the fraud detection, underwriting, and risk decisioning that banks and carriers rely on every day. This engine resolves entities across messy, multi-source data, different name formats, address conventions, transliterations, at the scale and speed financial institutions need to act on what they discover.

1.6B
RECORDS
420M
UNIQUE IDENTITIES
Sub-second
RESPONSE

The lesson: financial crime is not being meaningfully reduced by better AML models alone. A meaningful share of the reduction comes from building identity intelligence underneath those models, because the model is only as good as the identity foundation it reasons against.

The Regulatory Picture Is Tightening, Globally

Identity intelligence is no longer a financial crime issue alone.

United States

In the US, the Financial Crimes Enforcement Network in February 2026 eased verification at every new account opening but sharpened the requirement for risk-based ongoing Customer Due Diligence, so point-in-time KYC is no longer enough.

United Kingdom

In the UK, the Financial Conduct Authority’s Consumer Duty and the Senior Managers and Certification Regime put personal accountability on demonstrating the firm understands its customers and counterparties.

European Union

In the EU, the new Anti-Money Laundering Regulation and Sixth AML Directive enter full force on 10 July 2027, with the Anti-Money Laundering Authority operational in Frankfurt since 2025 and the Financial Action Task Force tightening beneficial ownership transparency globally.

Across all three regimes, regulators now implicitly assume the bank has, or can build, an identity intelligence layer.

The Three Questions to Take Into Your Next AI Review

Banking has always been a business of resolving identity. The teller, the relationship manager, the AML analyst, the sanctions specialist: every one of these roles has always required answering the same question: who am I really dealing with?

What is new is that those decisions are increasingly being made by AI at the speed of the next click, the next wire, the next authorization, and the identity layer underneath those systems was never built for that velocity, that scale, or the regulatory expectations now being written around it.

Before your next AI initiative moves from pilot to production, put three questions on the agenda:

  1. 1
    Where is identity intelligence actually managed today, and by whom?
  2. 2
    Can we resolve who is who and who is related across our retail, wealth, commercial, payments, correspondent, and external data in real time, explainably, and under proper governance?
  3. 3
    Can our AI agents access trusted identity context when they make decisions?

What you’re asking is basically this: will our AI understand who it is dealing with?

If the answer is uncertain, your AI strategy isn’t mitigating risk, it’s multiplying it.