Skip to content
· By

AML compliance software: what it covers and what it costs

Short answer: AML compliance software covers four separable jobs: screening customers against sanctions and watchlists, monitoring transactions for suspicious patterns, managing the cases that result, and filing reports with your regulator. Most firms buy the data feeds and build the decision layer, because the feeds are commodity and the rules are specific to your risk appetite.

This covers what AML compliance actually requires, where the four components sit, what drives cost, and the honest build-versus-buy line. For the customer-onboarding half of the problem, see KYC AML software, which covers identity verification and the onboarding pipeline.

What is AML compliance, in practice

Anti-money-laundering obligations require you to know who your customers are, watch what they do, investigate what looks wrong, and tell the authorities about it. That is the whole of it, and every product in the category addresses one or more of those four.

No single piece of AML compliance software does all four well, which is the first thing to accept before drawing up a shortlist. The regulatory text is deliberately outcome-based rather than prescriptive. It tells you to have a risk-based programme; it does not tell you what a suspicious transaction looks like in your business. That gap is why AML and compliance work resists off-the-shelf answers, and why two firms in the same sector can run defensibly different rule sets.

Your regulator will judge you on whether your programme is reasonable for your risk profile and whether you can evidence the decisions it produced. Not on which vendor you chose.

The four components

Screening

Checking customers and counterparties against sanctions lists, politically exposed persons registers, and adverse media. This is a data problem rather than a software problem. The lists are published, the vendors aggregate and normalise them, and what you are buying is coverage, update latency and name-matching quality.

Buy this. Nobody should be scraping sanctions lists themselves, and the matching logic for transliterated names across alphabets is a genuinely hard problem that a specialist has already solved.

The part you will still own is the threshold. Fuzzy name matching produces false positives in volume, and where you set the similarity cut-off decides how many analysts you employ. Set it loose and your team drowns in review; set it tight and you miss a real match, which is the failure that ends careers.

Transaction monitoring

Watching payment flows for patterns that do not fit the customer profile established at onboarding. Structuring, rapid movement through an account, unusual counterparties, geography that contradicts the stated business.

This is where AML compliance software gets expensive and where most of the false positives originate. Legacy systems run fixed rules and generate alert volumes that are brutal: a review rate where the overwhelming majority of alerts close as nothing is normal rather than exceptional in this category.

Case management

The workflow layer. An alert becomes a case, a case gets assigned, an analyst gathers evidence, someone decides, and the whole chain is recorded in a form that reconstructs the reasoning years later.

Unglamorous, the component firms most often underestimate, and the one where AML compliance software most often has to bend to your team rather than the reverse. It is also the piece most likely to be a poor fit off the shelf, because it has to match how your compliance team actually works.

Reporting

Filing suspicious activity reports in your jurisdiction’s format, on its schedule, with its field requirements. Mechanical, mandatory, and a place where an integration failure is a regulatory failure rather than an inconvenience.

What drives the cost of AML compliance

Four things, and licence fees are rarely the largest.

AML compliance software is quoted on licence fees, and licence fees are the part of the bill you can predict. Data feeds, priced per customer screened or per check. Predictable and scaling directly with your growth.

Platform licensing, usually banded by transaction volume or customer count.

Analyst headcount, which is the real number. A monitoring system generating alerts your team cannot clear is not a compliance programme, it is a backlog with a dashboard. Model your alert volume before you sign, because analyst salaries will exceed your software spend within a year at most volumes.

Model validation and audit, recurring rather than one-off. Whatever decides your alerts has to be explainable to an examiner, periodically revalidated, and documented.

The arithmetic worth running before any vendor conversation: expected monthly alert volume, multiplied by average minutes to disposition, divided by analyst capacity. If that number requires a team you have no intention of hiring, your problem is alert quality rather than software selection, and no procurement process will fix it.

Where AML compliance solutions fall short

False positive rates. The dominant operational complaint in the category and the one every AML compliance software buyer underestimates. Rules tuned conservatively to avoid missing anything generate enormous volumes of nothing, and the analysts reviewing them become progressively less attentive, which is precisely the failure mode conservatism was meant to prevent.

Rules that cannot express your risk. Every platform has a rule language, and every rule language has a ceiling. Teams routinely discover the pattern they most need to detect requires joining data the platform does not hold.

Static thresholds on changing behaviour. A rule calibrated on last year’s customer base misfires on this year’s. Recalibration is a scheduled activity, not a project, and few programmes treat it that way.

Explainability. A model that flags accurately but cannot say why is not usable here. An analyst has to write a narrative, and an examiner has to follow the reasoning. This constraint rules out approaches that would be perfectly acceptable elsewhere.

Where machine learning genuinely helps, and where it does not

It helps at triage. Ranking alerts by likelihood so analysts see the ones that matter first does not change what gets flagged, does not change your risk coverage, and is defensible to an examiner because the rule set is unchanged. It is the highest-value, lowest-risk application in the category.

It helps at evidence gathering. Assembling counterparty history, prior alerts and related accounts into a case file before an analyst opens it removes real minutes from every disposition.

It helps at entity resolution. Deciding whether two records describe the same person or business, across spelling variants and transliterations, is a well-shaped problem with a measurable answer.

It does not help by replacing your rules with an unexplainable model. You will not defend that to a regulator, and you should not try. Anything touching a filing decision needs a reasoning trail a human can read, which is a design constraint rather than a preference.

Build or buy

Buy the screening data, always. Buy the reporting connectors, because format compliance is mechanical work with no upside for doing it yourself. Buy the whole platform when your volumes are moderate, your product set is conventional, and the vendor’s risk model broadly matches yours.

Build the decision layer when one of four things is true. Your alert volume has made analyst headcount your dominant compliance cost and better triage has a clear payback. Your product does something the platform’s rule language cannot express. Data residency rules prevent transaction data leaving your infrastructure. Or your case workflow is specific enough that you are fighting the product’s model every week.

The usual shape that results is a bought screening feed, a bought reporting connector, and a built layer between them: your rules, your triage ranking, your case workflow, your audit trail. Firms offering AML compliance services that recommend replacing everything are usually selling a platform.

We build that middle layer as part of KYC and KYB automation, alongside the intelligent document processing services that handle the document side of onboarding.

An AML compliance checklist for evaluation

Take this AML compliance software checklist to every vendor conversation.

  • What is the alert-to-case conversion rate at a comparable institution, and how many analysts does that imply for our volume?
  • Can we express our three most important risk patterns in your rule language? Show us, during the evaluation, using our data.
  • What does an analyst see when an alert opens, and how much of the evidence is assembled automatically?
  • How is the rule set recalibrated, how often, and who signs it off?
  • What does the audit trail record, and can it reconstruct a decision made three years ago after two staff changes?
  • Which lists are covered, at what update latency, and what is the name-matching approach for non-Latin scripts?
  • What happens when the filing format changes in our jurisdiction?

The second question is the one that sorts the field. A platform that cannot express your actual risk patterns during evaluation will not learn to after the contract is signed.

What to measure once it runs

Four numbers, reviewed monthly.

Alert volume per thousand transactions, tracked as a trend. A sudden move means a rule is misfiring or your customer base has shifted.

Alert-to-case conversion. How many alerts survive first review. Low conversion is a threshold problem and it is fixable.

Time to disposition, split by alert type. This is your analyst cost in a single figure.

Case-to-filing conversion. How many investigations become reports. Trending toward zero suggests your rules have drifted away from real risk.

If you track one, track time to disposition. Everything else is a way of explaining why it is what it is.

The takeaway

AML compliance software is four separate jobs sold as one product, and the right answer is usually to buy the data and build the decisions. Cost the analyst hours before the licence fee, because alert quality determines headcount and headcount determines what the programme actually costs. Insist a vendor demonstrates your own risk patterns in their rule language during evaluation, not after.


EpochC builds the decision layer behind AML programmes: triage ranking, entity resolution, case evidence assembly and audit trails, as part of KYC and KYB automation. See the KYC OCR automation case study — EUR 40,000 a year removed at 98% field accuracy — or start a project.

More on Document intelligence, OCR & KYC