Aug 18, 2026
Product
The Data Problem Underneath Financial Crime Compliance

The data problem underneath financial crime compliance
Financial institutions spend extraordinary sums fighting financial crime, with industry research putting the global cost of compliance operations above $200 billion a year, and the results remain stubbornly disproportionate to the effort. Transaction monitoring programs routinely report false positive rates above 90 percent and investigators drown in the resulting alert queues, while regulators keep finding the gaps anyway. Two decades of investment have gone into better detection, first through more elaborate rules and then through machine learning scores, on the theory that the discipline suffers from a shortage of analytical sophistication.
The theory deserves more skepticism than it gets, because underneath every fraud model, AML rule, sanctions screen, and conduct control sits a quieter problem that scoring cannot reach: the data being scored does not mean the same thing from one system to the next. Until fraud, AML, sanctions, and conduct risk reason over a shared picture of customers, relationships, risk, and history, the surveillance built on top of them will keep generating noise at industrial scale. It is worth walking through where the meaning breaks down, because each break is familiar to anyone who has worked a case, and together they explain most of what frustrates the discipline.
One customer, four versions of the truth
Start with the customer. The same individual exists in the KYC platform, the core banking system, the payments infrastructure, and the card processor, and in each of those systems they look like a different person. Names are transliterated differently, dates of birth were captured to different standards, addresses were updated in one system and left stale in three, and each application generated its own identifier with no authoritative link between them. Every vendor in the compliance stack then runs its own matching logic inside its own module, so the institution ends up with several competing opinions about which records are the same human being, none of them portable.
The fragmentation extends past identity into classification. Ask what a customer's risk rating is, and the answer depends on which screen you are looking at, because every system defines concepts like risk rating and customer type on its own terms. A customer rated medium risk in onboarding may be unrated in payments and high risk in the card portfolio, without any of those systems being wrong by its own lights. Investigators absorb this incoherence as a daily tax, reconciling identity and meaning across screens before the actual analysis can begin, and much of what institutions book as investigation time is really translation time.
The relationships that matter are never modeled
Financial crime is a network phenomenon, yet the systems watching for it store the world as rows. Ownership and control chains, the exact structures that layering and sanctions evasion depend on, are rarely represented explicitly anywhere. The fact that a customer directs a company that owns a company that holds the account is discoverable, in the sense that an analyst can reconstruct it from registry filings and KYC documents, and that is precisely what happens: it gets reconstructed by hand, case by case, and the reconstruction evaporates when the case closes. The next analyst who touches an adjacent entity starts over. A second category of meaning never makes it into structured form at all. Adverse media, KYC documents, onboarding files, and years of analyst narratives carry exactly the context that distinguishes a suspicious pattern from an innocent one, and it sits locked in PDFs and free-text fields that no monitoring rule can see. The institution has usually already paid, at least once, for the knowledge that would resolve an alert, and the knowledge is simply unreachable at the moment the alert fires.
Meaning moves with time and jurisdiction
Two further breaks compound the rest. The first is temporal. Ownership, addresses, risk ratings, and account states all change, but most systems store only the current state, overwriting yesterday to record today. Investigations, by their nature, ask about the past, and so analysts reconstruct historical ownership and account states from archived documents and email threads because the systems of record kept no memory. A monitoring model scoring today's transaction against today's snapshot has no way to notice that the ownership structure changed three weeks before the money started moving, which is often the single most telling fact in the case.
The second break is jurisdictional. The definition of a politically exposed person, the threshold at which ownership becomes control, the obligations that follow, and the deadlines attached to them all shift from one regulator to the next, and a global institution answers to many of them at once. When those definitions live buried inside each system's configuration, every jurisdiction effectively forks the bank's understanding of its own customers, and demonstrating consistent treatment across the group becomes an archaeology project.
Better scoring cannot fix a meaning problem
Seen against this backdrop, the limits of the detection arms race make sense. A machine learning model scores events attached to entities, and the model can only be as coherent as the entities it is given, so feeding it four fragmented versions of the same customer produces four partial risk pictures and a false positive rate no amount of retraining will cure. The sophistication is real, but it is aimed at a layer above the one where the trouble lives. The same underlying issue explains why institutions respond so slowly when criminal typologies shift. Adapting to a new pattern means re-authoring rules in one system, retraining models in another, updating screening lists in a third, and re-briefing analysts on all of it, because the meaning of the pattern has to be re-implemented separately everywhere it is enforced. Months pass between a typology emerging and the controls reflecting it, and the lag is a direct consequence of meaning being duplicated rather than shared. Explainability suffers for the same reason. When a regulator asks why an alert was raised or dismissed, a feature-importance score attached to a fragmented entity is a weak answer, and assembling the real answer means pulling threads from every system the decision touched.
What changes when the meaning is shared
The alternative is to give the entire financial crime function one semantic foundation and let every system, model, agent, and analyst reason against it. Concretely, that means persistent entity identifiers with probabilistic resolution across every source, so the institution holds one defensible view of each customer; a single canonical concept model that every system's local vocabulary maps into, so risk rating means one thing everywhere; ownership and control represented as first-class relationships in a graph rather than facts an analyst rediscovers; and extraction pipelines that lift what documents and case narratives say into the same structure. Every fact carries its history, so the question of what was true when has an answer, and each jurisdiction's definitions sit as a rules layer over the shared concepts instead of forking them. On that foundation the daily mechanics of the discipline start to move. Fraud, AML, sanctions, and conduct risk finally look at the same customer, the same network, the same history, and the same rules, so a signal raised in one domain is visible to the others instead of dying inside a module. A new typology becomes an update to the shared graph and the reasoning over it, deployable in days rather than re-implemented per system over months. Cognitive agents can take on the reconciliation and evidence-gathering that consumes most of an investigator's day, and because they reason over an explicit model, every step they take is traceable to the concepts and rules it relied on, which is an answer a regulator can actually examine. The human role shifts accordingly, away from reviewing an endless queue of half-formed alerts and toward supervising a system that arrives with the case already assembled, which is what we mean in practice when we talk about amplifying human intelligence.
Start where the meaning breaks
The practical starting point follows from the diagnosis. Before procuring another detection engine, map where meaning fractures across your existing stack, because that is where the false positives, the slow typology response, the painful audits, and the reconciliation tax all originate. Metafore approaches financial crime this way by design, building the governed semantic foundation first and deploying cognitive agents against it, so that every control the institution adds afterward inherits a coherent picture of the customer instead of a fragmented one. The institutions that fix the meaning layer will find their detection investments finally paying what they promised.
If your fraud, AML, and sanctions teams are each holding a different version of the truth, talk to our team about what a shared one would change.
Article by
Sumit More
Subscribe to Metafore blog
Get notified about new product features, customer updates, and more.
related posts



