On June 3, 2026, AMLA opened the public consultation on its guidelines on ongoing monitoring of the business relationship, which closed on September 3, 2026. The final text is expected by the fourth quarter of 2026 and will become the operational reference for Article 26 of Regulation (EU) 2024/1624 (AMLR), applicable from July 10, 2027. That document contains a passage that directly affects anyone using technology in anti-money laundering controls: the outputs produced by automated systems must be explainable and verifiable, and responsibility for the decision remains with the obliged entity.
That is why false positives stop being a matter of internal efficiency and become a supervisory issue.
Why false positives are a compliance problem
A false positive is an alert that looks relevant but is not: a namesake of a sanctioned party, a different transliteration of the same name, a similar company name, a threshold set too conservatively. The typical causes are almost always the same: incomplete identity data, rigid matching criteria, monitoring scenarios built on the entire portfolio instead of by risk segment.
The obvious cost is the team’s time. The real risk lies elsewhere: when the volume of noise exceeds processing capacity, the alerts that really matter get closed late or superficially. A structural backlog in alert handling is not an operational inconvenience, it is an inspection finding.
What AMLA expects from those who automate monitoring
The draft guidelines take a cross-sector approach, applicable to both financial and non-financial entities, and make clear that proportionality does not mean lower standards: manual or semi-automated processes remain acceptable for less complex organizations, provided they are effective in practice. On automation, the guidance is clear-cut:
- the outputs of automated systems and AI tools must be explainable and verifiable;
- responsibility for the decision remains with the obliged entity, which cannot simply accept the algorithm’s output;
- for third-party solutions, default settings should not be adopted without validation, and an external tool whose workings are not understood should not be used for significant decisions;
- automated closure of alerts is possible, but it requires effective human oversight and is not permitted when high-risk indicators are present;
- monitoring governance must be documented in internal procedures, including the decision logic, known limitations and the mitigation measures adopted;
- the staff involved must be trained to critically assess outcomes and activate escalation channels.
In other words: you can automate, and in many contexts you should. What you cannot do is be unable to explain why an alert was closed.
How to reduce false positives in AML screening
Reducing false positives in AML screening does not mean raising thresholds until the alerts disappear. It means giving the matching engine more information and better criteria to decide.
- Input data quality. Date and place of birth, country, tax code or VAT number, legal form: a name without supporting attributes produces noise by definition.
- Language-aware matching. Transliterations, reversed first and last names, corporate abbreviations and non-Latin characters must be handled with dedicated rules, not with a single similarity threshold.
- Calibration by segment. Thresholds and scenarios differentiated by customer type, geographic area and channel, consistent with the business-wide risk assessment.
- Disambiguation before the alert. If secondary attributes rule out the match, the analyst should not even see it.
- Whitelists with an expiry date and a rationale. A permanent, undocumented exclusion is a gap in your controls, not an optimization.
- Continuous measurement. False positive rate by scenario, average handling time, share of alerts closed automatically: without numbers there is no tuning you can defend before an authority.
What to do now
- Map which controls are automated, which are semi-automated and which are manual.
- Ask your vendor for documentation on matching logic, parameters and tuning criteria: if it is not available, that is already a red flag.
- Formally record who set the thresholds, when and based on what evidence.
- Keep a complete audit trail of closures, including automatic ones.
- Update staff training on the limitations of the tools in use.
How AegisX helps you
With Monitus, screening against sanctions lists, PEP lists and adverse media works with disambiguation on identity attributes and thresholds that can be calibrated by segment, so the team sees less noise and more real cases. Every outcome is recorded with the source, date and rationale for the decision, which is exactly the documentation required when an inspection comes. For list screening specifically, Sanction Screening covers EU, OFAC, UN and UK lists with continuous updates. If your concern is the quality of reputational risk sources, we covered the topic in depth in our article on adverse media screening.
Want to find out how much noise your screening produces today and where to act? Talk to our team: we turn compliance into a strategic advantage, not a backlog to clear.
This article is for informational purposes only and does not constitute legal or compliance advice. For more on the consultation text, see the official AMLA page and Regulation (EU) 2024/1624.





