Only 4.7% of financial institutions update compliance monitoring and controls continuously as risk changes, according to research from SymphonyAI and AML Intelligence. A further 56.8% have yet to adopt continuous monitoring, are exploring it or remain at the pilot stage.
The FinCrime Frontier 2026–27 Report draws on responses from more than 200 financial crime and compliance leaders. It examines how institutions are responding to changes in criminal methods, regulation and transaction volumes.
The findings indicate that periodic review cycles remain common despite the speed at which financial crime risks can change. Seven in ten respondents, or 70.8%, said no more than 5% of the alerts they investigate result in an escalation or a suspicious activity report or suspicious transaction report.
That figure points to the investigative workload created by low-conversion alert volumes, although it does not show whether the remaining alerts were unnecessary or correctly resolved. Firms may need to examine how alert quality, investigative capacity and risk coverage interact rather than treating filing rates as a standalone measure of effectiveness.
Artificial intelligence (AI) and model governance, alongside the adequacy of technology and systems, ranked as the leading regulatory concerns. Each was selected by 40.8% of respondents. Cross-border regulatory complexity had topped the previous year’s survey.
Investment has yet to produce the same degree of operational change. AI and automation ranked as the leading compliance investment priority, cited by 61.9% of respondents. However, 76.3% said their institutions still review alerts manually or with partial automation. The share relying on fully manual review fell from 21.3% to 16.5% year on year.
John Edison, president of Financial Services at SymphonyAI, said: “The next phase will be defined by how effectively institutions use AI to connect risk intelligence with institutional judgment, transforming detection, investigation and governance so that controls respond dynamically as risk changes, while maintaining appropriate human oversight and accountability.”
The report covers regulatory change, compliance economics, operational performance, AI maturity, data readiness and governance. More than half of respondents described some form of forward-looking response to regulatory change, including modernisation or operating-model reform. Reactive workload, however, remained the most common response.
Subscribe to our newsletter


