NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights11 min read· July 24, 2026

KYC and AML Compliance for Banks: Automating Due Diligence at Scale

Banks carry the heaviest KYC/AML burden of any intermediary. Here is how automation cuts onboarding, screening and review at scale in 2026.

by Wecan

No financial intermediary carries a heavier KYC and AML burden than a bank. A private or universal bank onboards and monitors tens of thousands of relationships spanning individuals, operating companies, holding structures, trusts and foundations — many of them cross-border, many exposed to politically exposed persons (PEPs), all of them running on core banking systems that were never designed for the pace and granularity of modern due diligence. As supervisory expectations shift from documented procedures to demonstrable effectiveness, the gap between what regulators expect and what manual processes can deliver is widening.

This article looks at why the burden is structurally heaviest for banks, what the 2026 regulatory tightening actually requires, why the External Asset Manager relationship creates a shared-data obligation under revised art. 37 AMLO-FINMA, and where automation delivers the most measurable return across onboarding, screening, and perpetual monitoring.

1. Why banks carry the heaviest KYC/AML burden

The scale of a bank's obligation is not a matter of degree — it is a difference in kind. Volume, entity complexity, and legacy infrastructure compound each other.

Volume and entity complexity

A mid-sized Swiss bank may hold 20,000 to 100,000 active relationships, each requiring identification, beneficial-ownership determination, a documented risk profile, ongoing monitoring, and periodic review. A large share of those relationships are not natural persons but legal entities: operating companies with layered shareholders, holding structures spanning several jurisdictions, trusts and foundations whose beneficial owners are not visible on any single register. Establishing the ultimate beneficial owner behind a five-layer cross-border structure is not a form-filling exercise; done manually it consumes two to four hours per file and depends on the analyst's ability to read registry extracts across languages and legal systems.

Correspondent relationships, PEPs, and cross-border exposure

Banks also carry exposure that smaller intermediaries do not. Correspondent banking relationships require due diligence on the respondent institution and, indirectly, on its clients. A single international client base multiplies sanctions and PEP exposure across dozens of watchlists that update daily. And every cross-border relationship layers a second regulatory regime on top of the Swiss one. The result is a screening problem measured not in hundreds of alerts but in tens of thousands per month — with a false-positive rate that, on rules-based systems, runs between 90% and 99%.

Legacy core systems

The final aggravating factor is infrastructure. KYC data typically lives in a core banking platform, one or more CRM systems, a document repository, and a stand-alone screening tool — none of which was built to share a single, current client record. Analysts re-key the same data across systems, reconcile conflicting versions, and assemble review files by hand. The burden is not only the work itself; it is the work of moving information between systems that do not talk to each other.

2. FINMA scrutiny and the 2026 regulatory tightening

Three converging developments make 2026 the year the manual model stops being defensible for banks.

Revised AMLO-FINMA

In its partial revision of the Anti-Money Laundering Ordinance-FINMA — consulted on between 12 May and 9 June 2026 — the regulator reinforced several due-diligence expectations, including the treatment of payable-through accounts (discussed in section 3). The direction of travel is consistent: more granular verification of beneficial ownership, tighter documentation of the rationale behind risk classifications, and less tolerance for files that are formally complete but substantively stale.

The LETA beneficial-ownership register

From 1 October 2026, the Legal Entities Transparency Act (LETA) alongside the revised Anti-Money Laundering Act introduces a federal beneficial-ownership register and obliges intermediaries to identify the natural person who ultimately controls a legal entity — regardless of how many layered or offshore structures sit in between — with lowered thresholds and expanded capture. For a bank with tens of thousands of corporate relationships, re-establishing and cross-checking beneficial ownership against a new register is a project that manual teams cannot absorb without either backlog or headcount.

From tick-box to demonstrable effectiveness

The deepest shift is not any single article. It is the supervisory move from asking whether controls exist to asking whether they work. The 2026 expectation is demonstrable effectiveness: decisions that are traceable, timely, evidence-based, and applied consistently across the entire book. A bank cannot demonstrate consistency across 50,000 relationships reviewed by dozens of analysts using judgement and spreadsheets. It can demonstrate it with a single record per client, a full audit trail, and a monitoring engine that applies the same logic every time.

3. The EAM dimension: a shared-data obligation under art. 37 AMLO-FINMA

Banks do not only onboard their own direct clients. They serve External Asset Managers (EAM) — independent portfolio managers who custody their clients' assets at the bank and instruct transactions on those clients' behalf. This relationship sits at the centre of the revised art. 37 AMLO-FINMA on payable-through accounts.

The shared-data problem

Under revised art. 37, a bank may only execute payments on behalf of a counterparty's clients where the counterparty supplies the necessary client due-diligence information, including the KYC profile of the end clients. In practice this means a bank serving External Asset Managers must obtain, hold, and be able to evidence the underlying due diligence for clients it does not itself onboard. The information exists — it sits in the EAM's files — but in the EAM's format, on the EAM's timeline. The bank needs it in its own format, current, and audit-ready.

This converts a soft expectation into a hard gate. Where the EAM cannot hand over a complete, current dossier, the bank must either refuse or restrict the relationship, or rebuild the file itself — spending weeks re-documenting a client the EAM already knows. Multiplied across every EAM a bank serves, this is a structural drag on onboarding capacity and a recurring audit exposure. A shared compliance layer, where the EAM maintains one authoritative record and shares it in the bank's required form, is precisely what art. 37 makes operationally necessary — a dynamic examined in detail in our companion piece on KYC/AML for EAMs.

4. Where automation delivers most for banks

Automation does not replace the compliance officer's judgement; it removes the manual work that surrounds it. For a bank, the highest-return targets are the highest-volume, most repetitive tasks.

Onboarding and UBO resolution

Digital onboarding flows collect and certify client documents once; OCR and NLP extract and structure the data; beneficial-ownership chains are reconstructed automatically from registry data. A standard onboarding that runs 15 to 21 days manually — and up to six weeks for complex corporate structures — compresses to two to three hours. UBO identification drops from two to four hours to minutes.

Sanctions and PEP screening and triage

The single largest efficiency lever for a bank is false-positive reduction. Contextual, AI-assisted scoring reads the full entity context rather than matching strings, cutting the false-positive rate from 90–99% to 20–25%. Because each false positive consumes 30 to 60 minutes of analyst time, and because banks generate the highest alert volumes of any intermediary, this reduction alone reclaims a substantial share of the compliance team's capacity — as detailed in our note on reducing sanctions and PEP false positives.

Perpetual KYC and periodic reviews

The most transformative shift is from scheduled reviews to perpetual KYC (pKYC): continuous, event-driven due diligence that updates the file as circumstances change rather than on a calendar. Early adopters remove 70–90% of manual periodic-review work, because files are never allowed to drift out of date and reviews become exception-driven rather than exhaustive.

Process Manual Automated (Wecan Comply) Improvement
Standard KYC onboarding 15–21 days 2–3 hours −97%
Complex corporate onboarding Up to 6 weeks Hours to a few days −90%
UBO identification 2–4 hours Minutes −95%
Sanctions/PEP false-positive rate 90–99% 20–25% ≈ −75 pts
Periodic review per file 2–4 hours 20–45 min −70%
Cost per onboarded client CHF 300–800 CHF 50–150 ≈ −75%
Clients per analyst per month 15–25 80–120 ~4–5×

5. Integration reality and change management

For a bank, the hard question is never whether automation works in the abstract — it is whether it fits the existing estate without a two-year replacement programme.

Sitting alongside core banking and CRM

A workable compliance layer integrates with, rather than replaces, the core banking platform, the CRM, and existing screening tools. It reads client data where it lives, writes back structured due-diligence records and decisions, and becomes the single source of truth for KYC without forcing a rip-and-replace of systems the bank has spent years configuring. Security and data residency are threshold requirements, not features — Swiss hosting, granular access control, and a complete audit trail are prerequisites for any regulated deployment.

Change management

The larger risk is organisational. Analysts trained to build files by hand must learn to supervise a system that builds them automatically — reviewing exceptions and edge cases rather than every field. The transition works best when automation is introduced function by function: false-positive triage first, where the win is immediate and uncontroversial, then onboarding, then the shift to perpetual monitoring. Governance must be explicit about which decisions remain with a human and which are delegated to the system, so the audit trail reflects genuine oversight rather than rubber-stamping.

Integration dimension Legacy reality With an automated compliance layer
Client data Re-keyed across core banking, CRM, screening tool Read once, single source of truth, written back
Screening Stand-alone tool, 90–99% false positives Contextual scoring, integrated triage
Periodic reviews Calendar-driven, exhaustive, manual Event-driven, exception-based (pKYC)
Audit trail Reconstructed from several systems Complete, on a single record
Deployment Multi-year core replacement Layer alongside existing estate

6. The ROI case for a bank

The business case for a bank is a function of volume: the same per-file gains that matter to a small firm compound across tens of thousands of relationships.

Consider a bank running a compliance team of 20 KYC analysts, each loaded at CHF 80,000–110,000 per year, handling onboarding and periodic reviews across a large book. Under the manual model, each analyst manages 15–25 clients per month; false-positive triage alone consumes a substantial fraction of the working week, and periodic reviews arrive in calendar waves that create recurring backlogs. Recruiting an additional analyst takes 6–12 weeks and adds fixed cost.

Automation changes the arithmetic on three fronts at once. Per-analyst throughput rises from 15–25 to 80–120 clients per month — a four- to five-fold gain — as false positives fall by roughly three-quarters and onboarding compresses from weeks to hours. Cost per onboarded file drops from CHF 300–800 to CHF 50–150. And the shift to perpetual KYC removes 70–90% of periodic-review work, which is where backlogs accumulate. The combined effect is not marginal: teams typically report year-one ROI of around 200–260% with a payback period of three to four months, and — often more valuable than the cash figure — the elimination of the review backlog that exposes a bank to supervisory criticism.

ROI driver Manual baseline With automation Effect for the bank
Clients per analyst / month 15–25 80–120 ~4–5× throughput
Cost per onboarded file CHF 300–800 CHF 50–150 ≈ −75% unit cost
False-positive triage 90–99% of alerts 20–25% Analyst hours reclaimed
Periodic-review workload Full manual load −70–90% (pKYC) Backlog eliminated
Year-1 ROI / payback ~200–260% / 3–4 months Fast, measurable return

The full ROI methodology breaks these drivers down file by file, but the headline is straightforward: at a bank's volume, even modest per-file savings aggregate into recovered capacity worth several full-time equivalents — capacity that can be redeployed to genuine risk work rather than re-documentation.

7. How Wecan Comply helps banks

Wecan Comply is built for the scale and complexity a bank actually faces. It gives a bank a single, authoritative, continuously maintained due-diligence record per client — collected once, structured automatically, and screened with contextual scoring that keeps false positives low enough for a large team to handle exceptions rather than drown in alerts. It resolves beneficial ownership from registry data, maintains a complete audit trail for every decision, and supports the shift from calendar-based reviews to perpetual, event-driven monitoring.

Crucially for banks serving External Asset Managers, Wecan sits between the institution and the EAMs it works with. The EAM maintains one authoritative record and shares it with the bank in the form the bank requires, giving the institution the end-client due-diligence information it now needs under revised art. 37 AMLO-FINMA before it executes on the client's behalf — and removing the weeks of re-documentation that shared-data gaps otherwise create.

For a Chief Compliance Officer or Head of KYC, the choice in 2026 is not whether to automate but where to start. At a bank's volume, the manual model does not scale to meet demonstrable-effectiveness expectations without unsustainable headcount. A shared, automated compliance layer turns due diligence from a growing backlog into a controlled, evidenced, and defensible process — at the scale a bank requires.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.