Survey finds UK banks confident on financial crime compliance, but not ready for real-time
UK banks are reporting strong confidence in their financial crime compliance posture, yet new research suggests many are not operationally equipped for the move toward continuous, event-driven due diligence expected by regulators.
The findings, released by TransactionLink in a report titled The End of Periodic Due Diligence: How UK Banks are Navigating the Shift to Event-Driven Compliance, are based on a survey of 250 senior compliance professionals across Tier 1 and Tier 2 banks, as well as building societies. The research focuses on whether institutions have the frameworks, governance and monitoring capabilities needed to detect and respond to meaningful changes in customer risk outside of scheduled review cycles.
Confidence appears to outpace documented readiness
According to the survey results, 89% of banks say they are confident in their ongoing due diligence obligations for financial crime. However, the report points to a gap between that confidence and the systems and processes needed to act on risk changes as they occur.
A central requirement in event-driven compliance is the ability to identify so-called “trigger events”, including changes in customer behaviour, ownership, or activity that could materially alter risk. The research says less than half of banks, 43%, have a formal and documented framework for identifying those trigger events.
At the same time, nearly all respondents, 97%, believe their firms are aligned with Financial Conduct Authority (FCA) expectations. Yet only 45% say they have a clear understanding of what continuous, event-driven due diligence requires in practice. The juxtaposition suggests that some organisations may interpret expectations broadly, while lacking the operational detail needed to implement them.
Real-time monitoring still not the default
Event-driven compliance is designed to shift monitoring away from periodic reassessment toward continuous oversight, where firms can detect and respond to meaningful risk changes in a timely manner. The report indicates that many banks remain closer to scheduled cycles.
Only 39% of institutions describe their monitoring as truly continuous. The majority, 50%, are still operating on frequent periodic review cycles, while 10% rely on annual or biennial reviews.
Automation also remains uneven. The survey reports that 36% of banks are running fully automated ongoing due diligence workflows, while 54% depend on hybrid manual processes. This mix has implications for scalability and consistency, particularly where monitoring relies on manual judgement or manual escalation steps.
Governance and resourcing gaps complicate the transition
Beyond monitoring design, the report highlights planning and governance limitations that can slow implementation. Less than half of banks, 46%, say they have a fully funded transition plan for continuous monitoring. Only 38% report that they have modelled the resourcing impact of moving to event-driven compliance.
The survey also suggests limited senior-level alignment. Only 43% say there is board or executive sponsorship for the transition, which can affect budgeting decisions and the ability to sustain program delivery across technology, data, and operational teams.
The report further notes that banks recognise the resource implications. More than half, 54%, acknowledge that continuous due diligence will require significantly more resources. Yet most have not translated that acknowledgement into fully modelled operational plans.
What “event-driven” compliance changes operationally
While periodic due diligence often follows fixed review schedules, event-driven compliance requires firms to continuously assess risk indicators, define meaningful triggers, and establish workflows that can update risk assessments and controls when customer circumstances change. In practice, that can require improvements in data quality, systems integration, and rules or models that can identify when changes are significant enough to warrant reassessment.
The survey’s results point to a broader pattern seen across compliance and regulatory technology programmes, where conceptual understanding can develop faster than implementation capability. Even where institutions believe they are aligned with expectations, operational readiness depends on documented trigger criteria, continuously functioning monitoring processes, automation where appropriate, and governance that ensures ownership and funding.
Industry implications for banks and compliance teams
For banks, the report underscores a key operational challenge: aligning compliance narratives with measurable capabilities. The missing elements identified in the research, including documented trigger-event frameworks and truly continuous monitoring, may make it harder for firms to demonstrate control effectiveness, especially if regulators scrutinise how firms identify and respond to risk changes between review cycles.
From a technology perspective, the findings also suggest continued demand for platforms and data capabilities that can support continuous monitoring and event-driven workflow execution. However, the research does not evaluate specific solutions, focusing instead on readiness and implementation maturity.
Bottom line
TransactionLink’s survey suggests a widening gap in the UK between confidence in financial crime compliance and the practical ability to deliver continuous, event-driven due diligence. With only a minority reporting continuous monitoring and formal trigger-event frameworks, banks may face growing pressure to translate compliance expectations into funded programs, measurable processes, and scalable operational controls.
The report is available via TransactionLink’s website.







