Compliance becomes the control layer, scams get blocked pre-transfer, and AI moves to execution

By DripPublished

The gist

This week, compliance and fraud tooling moved closer to the transaction and decision layer, while regulation and agentic automation began reshaping who can compete and how value is captured.

This week’s developments

DORA and AMLA Push Compliance Platforms Into the Control Layer

DORA is now forcing the operating-model shift: critical incidents must be classified and disclosed within four hours, outsourced ICT dependencies tracked in a Register of Information, and remediation kept open until supervisors are satisfied. AMLA’s draft guidelines add the same pressure on the financial-crime side, making ongoing monitoring a supervisory expectation and requiring customer data, transaction monitoring, and risk reviews to stay current as conditions change.

This week’s product moves show where the market is heading next. Napier AI and Delta Capita integrated compliance platforms; DataShyre launched an automated consent governance suite; and Alation with PwC Canada introduced an AI compliance accelerator designed to turn regulatory requirements into executable controls. The boundary is shifting from separate AML, privacy, ICT resilience, and AI governance tools toward a single control layer that can monitor, escalate, document, and report across jurisdictions.

For operators, the test is no longer whether controls exist, but how quickly they escalate, how well vendor models are overseen, and whether audit trails hold up under scrutiny. For vendors and investors, the opportunity is increasingly in integrated platforms that compress time-to-control and generate evidence continuously, extending the continuous-supervision model from last week into day-to-day execution.

What control-plane capabilities will win under DORA and AMLA?

If you operate in this industry

  • Compliance is becoming a live control layer, not a periodic check.
  • Build or buy systems that escalate, evidence, and report continuously; point tools that can't prove oversight will be a liability.

Sources

If you sell into this industry

  • Buyers want one platform that turns rules into auditable controls.
  • Shift roadmap and messaging toward integrated monitoring, workflow, and evidence across AML, privacy, ICT, and AI governance.

Sources

If you invest in this industry

  • Value is moving to platforms that own the control plane.
  • Favor vendors that compress time-to-control and generate evidence; standalone point solutions face bundling and margin pressure.

Sources

Hana Bank Shows the Interdiction Layer Can Stop Scams Before Funds Move

Hana Bank says it prevented 18.5 billion won, or about $13 million, in KReSIM scam losses by using a Fraud Detection System scenario built in February 2026 to flag 1,450 suspicious transactions and stop them before funds left customer accounts. The trigger was blunt—a transfer to a KReSIM-related corporate account—but the response extended well beyond payment rejection: Hana blocked mobile banking app installation and login, sent automated emergency alerts including via KakaoTalk, and followed with 1:1 staff outreach.

That makes the next step in the control stack harder to miss. After workflow-owned case handling, real-time mule detection, and pre-settlement prompts, fraud programs are now proving they can orchestrate interdiction, customer communication, and containment in one operating layer. The market backdrop reinforces the point: AFP’s 2026 survey found 76% of organizations experienced attempted or actual payments fraud in 2025, while Federal Reserve survey results showed rising losses across social-engineering, account-takeover, debit-card, wire, ACH, and check channels.

Vendors are responding by consolidating onboarding, screening, monitoring, and compliance into fewer systems of record, while crypto players push real-time AML alerts across custody workflows. For operators, the buying center is shifting toward platforms that can act in-line; for vendors and investors, value is moving to workflow ownership, integration depth, and measurable loss prevention.

How do we monetize prevention workflows before settlement becomes standard?

If you operate in this industry

  • Interdiction is now a measurable loss-prevention layer, not just detection.
  • Prioritize in-line controls that can block, alert, and route cases in one flow—or risk losing budget to platforms that can.

Sources

If you sell into this industry

  • Buyers want systems that stop fraud before settlement, not after.
  • Shift roadmap and GTM toward real-time orchestration, customer comms, and workflow ownership; point tools look weaker.

Sources

If you invest in this industry

  • Value is moving to platforms that own the prevention workflow end to end.
  • Favor vendors with deep integrations and provable loss reduction; standalone detection tools face bundling and margin pressure.

Sources

EDGE, Socure, nCino, and D&B Push Risk Checks to the Front Door

EDGE and Socure have integrated cashflow bureau data with identity, device, and behavior signals into a single top-of-funnel screen for onboarding, authentication, and account takeover prevention, before bank authentication or account reconnection. Socure says the layered decisioning returns in under 150 ms and can cut manual review below 5%, turning identity infrastructure into a pre-credential risk gate rather than a downstream workflow. In parallel, nCino and D&B are embedding Commercial Graph, D‑U‑N‑S entity data, UBO visibility, AML screening, and continuous monitoring into onboarding, a move that matters more as FinCEN’s rollback of domestic BOI reporting pushes beneficial ownership verification back to first-party collection, institution-level entity resolution, and manual reconciliation. After last week’s shift toward unified financial crime platforms, this is the next step: the first risk decision is moving even earlier, closer to the moment a customer or business enters the funnel. For practitioners, that means onboarding, authentication, and ownership checks are converging into one control point, and vendors that can fuse identity, entity, and monitoring data without adding latency will be the ones that reduce friction while tightening first-pass risk decisions.

Where will value accrue as risk checks move upstream?

If you operate in this industry

  • Risk is moving to the front door; downstream checks lose leverage.
  • Re-architect onboarding and auth as one control plane, or get boxed out by faster first-pass decisions and lower manual review.

Sources

If you sell into this industry

  • Buyers want one low-latency gate for identity, entity, and AML.
  • Shift roadmap to fused decisioning and sub-150ms latency; point tools without unified data and monitoring will be harder to sell.

Sources

If you invest in this industry

  • Value is shifting to platforms that own the first risk decision.
  • Favor vendors that combine identity, entity, and monitoring; standalone checks face margin and multiple pressure as bundling expands.

Sources

Governed Autonomy Becomes the New Control Plane

RegTech and FraudTech vendors this week moved agentic AI from pilot rhetoric into operational casework. FIS advanced its 2026 Financial Crimes AI Agent, which builds evidence packages at case open, tests activity against typologies, and routes high-risk cases, with BMO and Amalgamated Bank named as early deployers. Unit21 is pushing agentic fraud and AML workflows from detection through investigation with a human-readable audit trail, while Greenlite and Hawk AI are extending AI into alert prioritization and draft investigative outputs.

The common design pattern is clear: human-in-the-loop review, traceability to underlying evidence, predefined policy bounds, and controlled pilots before live use. That matters because the bottleneck has shifted from model capability to governance execution. Research cited this week says 72% of enterprises deploy agentic systems without a formal oversight model, 81% lack documented governance for machine-to-machine interactions, and only 9% have proper Agentic Access Management, with none in the sample running a complete AAM system.

For operators, the winning architecture is narrower autonomy plus stronger approvals and audit trails. For vendors and investors, value is moving toward platforms that can prove compliant autonomy in production, not just generate better outputs.

How do governed AI workflows reshape buying, build, and investment priorities?

If you operate in this industry

  • Autonomy now competes on governance, not model novelty.
  • Build narrower AI workflows with hard approvals, evidence trails, and policy bounds—or risk losing trust and renewals to governed platforms.

Sources

If you sell into this industry

  • Compliant autonomy is becoming the new enterprise buying criterion.
  • Shift roadmap and GTM toward auditability, human-in-loop controls, and production proof; pilots without governance will stall.

Sources

If you invest in this industry

  • Governed AI is separating real platforms from demoware.
  • Favor vendors that can ship compliant autonomy in production; governance execution is now the moat, and weak controls will cap multiples.

Sources

MiCA Authorization Starts Reordering Crypto Market Access

More than 1,000 crypto firms are reportedly at risk of EU exclusion as MiCA replaces national VASP registrations with mandatory CASP authorization, and the pressure is hitting firms that failed to convert legacy permissions. One report said only about 210 of more than 1,200 pre-MiCA VASPs had converted by the reported July 1, 2026 deadline. The bottleneck is also geographic: ten jurisdictions reportedly still show zero public CASP authorizations in ESMA’s register, including Italy, Poland, Portugal, and Romania, with Poland flagged for delayed local implementation as of March 2026.

This is now showing up as a distribution and product-access problem, not just a licensing one. ESMA’s register added Dinaro as an e-money token issuer, while Ripple’s Luxembourg CASP approval creates a route to scale regulated services across the EEA through passporting. ESMA guidance is also pushing CASPs to remove non-compliant ARTs and EMTs, accelerating delistings such as USDT on EU-facing venues and concentrating liquidity around MiCA-compliant issuers and products.

For operators, the window to localize licensing, token governance, and evidence trails is closing before market access and listings erode. For vendors and investors, the value pool is shifting further toward recurring authorization management, token classification, and cross-border permissioning infrastructure embedded in revenue-critical distribution workflows.

Where will MiCA authorization create the biggest commercial opportunities?

If you operate in this industry

  • EU market access now hinges on MiCA proof, not legacy registrations.
  • Localize licensing, token governance, and audit trails fast or lose listings, passporting, and distribution in core EU markets.

Sources

If you sell into this industry

  • Authorization workflow is becoming a revenue-critical product category.
  • Build for CASP conversion, token classification, and cross-border permissioning; budget is shifting to embedded compliance infrastructure.

If you invest in this industry

  • MiCA is creating winners in compliance infrastructure and passporting.
  • Favor vendors tied to recurring authorization, classification, and distribution controls; legacy VASP-dependent models look exposed.

Stay ahead in RegTech & FraudTech

Get the weekly RegTech & FraudTech brief in your inbox — the developments, what they mean by vantage, and what to do next.