Open Banking Gave AML Teams More Data. It Did Not Give Them More Understanding.

What does open banking change for AML investigation?
Open banking gives transaction monitoring systems access to richer payment data: account aggregation, payment initiation records, and cross-institution counterparty patterns that were previously invisible. That richer input generates more alerts. It does not, on its own, generate better AML investigations, because the investigation layer that would contextualise those alerts has not been built out to match.

The argument for open banking’s compliance upside was straightforward: more data visibility means better risk detection. If transaction monitoring systems could access richer payment flows, they would generate better-quality alerts, investigators would have more to work with, and decisions would improve.

That argument was partially right, and precisely where it was wrong is where most regulated firms are now feeling the pressure. More data fed into detection systems does not produce better investigations. It produces more alerts from richer signals, with the same fragmented investigation experience waiting on the other side.

Does more payment data automatically mean better AML decisions?

No. More data improves detection, the system’s ability to flag something worth looking at. It does not improve investigation unless that data is assembled into a coherent picture before the investigator opens the case. Without that step, richer data just means more alerts to manually piece together.

What Open Banking Actually Made Available

The FCA’s open banking regulatory framework, implemented through the UK’s post-Brexit adaptation of PSD2 and overseen through the Open Banking Implementation Entity, created a structured mechanism for account information and payment initiation services to access consented financial data across institutions. This opened up three categories of information previously opaque to monitoring systems: payment initiation data, showing payment instructions across institutions rather than just within a firm’s own ledger; account aggregation data, revealing counterparty relationships and multi-account structuring invisible to any single institution; and counterparty flow patterns, showing the full network of payment relationships in ways single-institution data cannot.

These are genuinely useful inputs for financial crime risk assessment, and the UK is not alone in building this kind of infrastructure. The EU runs PSD2 in its own right across member states. The US has moved toward an equivalent model through the CFPB’s Section 1033 personal financial data rights framework, and open banking or open finance regimes are now live or under active build in Saudi Arabia and the UAE. Wherever this kind of data-sharing infrastructure exists, the same gap between richer detection and unchanged investigation shows up.

Stats callout: Industry compliance cost research found that financial institutions accessing open banking data streams reported an increase in alert volumes, not a reduction, as new data signals generated additional monitoring triggers without a commensurate improvement in investigation context at the point of review.

The Problem the Richer Data Created

Additional data inputs to a transaction monitoring system do not automatically become investigative intelligence. They become monitoring signals, and monitoring signals that are not contextualised at the point of investigation produce alerts. A firm that upgraded its monitoring to incorporate open banking data flows will, absent investigation infrastructure designed to handle the richer input, see more alerts generated from more signals, reviewed by the same investigators using the same manual retrieval process, with the same fragmented access to customer context that existed before the data enrichment began.

The investigative drag compounds because open banking data is inherently multi-source. When an investigator receives an alert generated by a cross-institution payment pattern, the customer context they need is distributed across the firm’s internal transaction records, the aggregated account data accessed via open banking, CDD files in the onboarding system, prior case records in case management, and any counterparty risk information held elsewhere. Assembling that manually, tab by tab, system by system, is not investigation. It is context friction in its most labour-intensive form. Industry benchmarking research notes that AML investigation friction is most pronounced at the point of multi-source alert review, precisely the scenario open banking data enrichment creates.

Detection Enrichment vs. Investigation Readiness

Open banking inputWhat it improves in detectionWhat it requires from investigation
Payment initiation dataCross-institution visibility on payment instructionsAssembled alongside internal transaction history, not a separate lookup
Account aggregation dataReveals multi-account structuringPresented as part of one customer profile, not multiple tabs
Counterparty flow patternsSurfaces cross-institution relationshipsContextualised against typology frameworks at review, not after

What Good Looks Like: Investigation Intelligence, Not Additional Detection

Cross-institution data visibility does make certain financial crime patterns more detectable. But detectable and investigated are not the same thing. A pattern that triggers an alert has been flagged, not assessed. The shift from detection to decision requires what open banking data alone cannot provide: a customer-first investigation view that integrates the richer data into a coherent picture before the investigator opens the case, alongside internal transaction history, CDD data, risk trajectory, and prior case reasoning.

JMLSG Part II guidance on payment services and electronic money institutions specifically addresses the obligation to assess customer risk in light of all available information. That standard is practically meaningful only when the information is accessible to the investigator at the point of review, not theoretically available somewhere in the system architecture. The data quality and consent obligations embedded in the FCA’s open banking framework, and their equivalents elsewhere, also require that data accessed through these schemes is used consistently with the consent framework, documented, and auditable, an operational requirement investigation infrastructure needs to accommodate directly.

Why does the cold-start problem get worse with open banking data?

Because the inputs are more complex. Experienced analysts can navigate simple monitoring inputs through years of pattern recognition. When inputs include cross-institution counterparty flows and payment initiation sequences spanning firms, a new investigator without surfaced institutional context is not starting from blank. They are starting from complex blank.

A concrete picture: An investigator at a regulated EMI receives an alert generated by an unusual cross-institution payment initiation pattern, a customer using a third-party payment initiation provider to move funds to a counterparty account that has appeared in two prior cases at the firm. Without institutional memory surfaced in the workflow, the investigator has no visibility of those prior cases. The pattern recurs, and whether it gets acted on consistently depends on which analyst opened the case and what they happened to recall. That is an AML investigation infrastructure failure, and open banking data enrichment makes it more consequential.

Making Open Banking Data Work for Investigations

The firms that will extract genuine compliance value from open banking are not the ones that plugged the data feed into their monitoring engine. They are the ones that designed their AML investigation layer to contextualise the richer input: surfacing account aggregation data as part of the assembled customer profile rather than a separate retrieval task, contextualising cross-institution counterparty patterns against typology frameworks at the point of review, making institutional memory from prior cases available to every investigator, and generating traceable investigative rationale that reflects the data considered.

Open banking data is an asset. Without investigation intelligence infrastructure, it is an expensive asset that produces more work without producing better decisions.

At TechnoXander, our AML Investigation Intelligence Platform integrates open banking data into the investigation layer, assembling the enriched customer picture before the case opens and surfacing institutional memory from prior patterns. Speak to our team to see how open banking data becomes investigative intelligence rather than additional detection noise.

About Author:

Sonal Bomb, CEO of TechnoXander, professional portrait highlighting leadership, innovation, and company vision.

Sonal Bomb

Sonal Bomb specialises in payments regulation, fraud prevention, and compliance frameworks across the UK and EU. She works closely with banks and PSPs on implementing Verification of Payee (VoP), Confirmation of Payee (CoP), and Open Banking requirements, translating evolving regulatory mandates into practical payment infrastructure.

VoP • CoP • Open Banking • PSD2/PSD3 • Payment Fraud Prevention • FiDA

LinkedIn Profile
Tags :
Social Share with Tooltip

Related Post

The Next Phase of AML Is Not Better Detection. It Is Better Decisions.

The Next Phase of AML Is Not Better Detection. It Is Better Decisions.

What is the next phase of AML maturity? It is the…

The AML Vendor Landscape Is Crowded. The Investigation Quality Gap Is Not Being Filled.

The AML Vendor Landscape Is Crowded. The Investigation Quality Gap Is Not Being Filled.

What is the investigation quality gap in the AML vendor market?…

Crypto, Digital Assets, and AML: The Investigation Gap That Keeps Getting Wider

Crypto, Digital Assets, and AML: The Investigation Gap That Keeps Getting Wider

What is the investigation gap in crypto AML? On-chain analytics can…