Most screening programs in EU payment institutions were not designed. They accreted. A vendor list here, a rules engine there, a spreadsheet of exceptions someone maintains by hand. It worked when volumes were low. It does not work when an EMI processes millions of transactions a month and a supervisor asks why an alert sat untouched for three weeks.
The rulebook is about to converge
The EU AML package became law in 2024, and the pieces matter for how you build. The Anti-Money Laundering Authority (AMLA) became operational in summer 2025 from Frankfurt, and per PwC it is scaling toward roughly 450 staff by the end of 2027. The Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) applies directly across all 27 member states from 10 July 2027. Directly applicable means no national transposition, no local flavor to hide behind. The same rulebook for a Lithuanian EMI and a German bank.
Two changes will hit operations hardest. First, the customer due diligence threshold for occasional transactions drops from EUR 15,000 to EUR 10,000, with limited CDD now required on occasional cash transactions of EUR 3,000 or more, according to AMLWatcher. More customers in scope means more screening events, not fewer. Second, the PEP regime is now harmonized EU-wide. The old member-state divergence on who counts is gone, enhanced due diligence extends at least 12 months after a person leaves a prominent public function, and it reaches family members and known close associates. If your PEP logic was tuned to one country's interpretation, it needs rebuilding.
Your alert queue is mostly noise
Most of the manual work your team does today produces nothing. The Wolfsberg Group has reported false-positive rates above 90 percent in sanctions alert queues, and industry figures put 95 to 98 percent of rule-based AML alerts in the false-positive bucket. That is analysts clearing noise, night after night. The noise is not random either. It comes from broad matching logic, transliteration across alphabets, and common names. Mohamed Ali matches dozens of list entries. A human applies a wide net because a missed true hit is a career event, so the queue fills with garbage and the real signal drowns.
What automation actually fixes
Automation is not about replacing analysts. It is about pointing them at the small fraction of alerts that deserve a human. In my years running operations at Solaris Bank, the lesson that stuck was that screening quality is a data problem before it is a tooling problem. Fuzzy matching tuned to your actual customer base, secondary identifiers like date of birth and jurisdiction to break ties, and clean sanctions and PEP list ingestion do more to cut false positives than any single vendor logo. Per figures cited by sanctions.io, 62 percent of institutions that adopted AI reported cutting false positives by more than 40 percent.
Where to spend effort before 2027
Screen against current lists, in real time. EU and OFSI lists change with events. A batch job that runs overnight is a gap a regulator will find. Screening at onboarding and before each outbound payment, on lists refreshed automatically, is the baseline now.
Make PEP status a monitored state, not a one-time check. Someone becomes a PEP after onboarding, and the 12-month tail after they leave office means you cannot close the file the day they resign. Rescreen your book on a schedule.
Instrument the alert lifecycle. Every alert needs a timestamp, an owner, a decision, and a reason recorded automatically. When a supervisor asks why an alert waited three weeks, the answer should be a query, not an archaeology project.
Keep a human on the edge cases and write down why. Auto-clearing obvious noise is fine. Auto-clearing a fuzzy PEP match is not. The trail of who decided what, and on what basis, is what turns a good decision into a defensible one.
Tune, then tune again. A system set once and left alone drifts. Review false-positive rates and true-hit outcomes monthly, and adjust thresholds against real results, not vendor defaults.
None of this requires a rip-and-replace of your stack. Most EMIs already own the tools. What they lack is the plumbing between them and the discipline to measure what the plumbing produces. Getting that right before July 2027 is cheaper than explaining to AMLA why you did not.
Where Novafin fits
Novafin builds AML, KYC, and sanctions screening automation for EU payment institutions and EMIs, wiring your existing tools into one measurable pipeline that stands up to supervision. If you are mapping your path to AMLR 2027, we should talk.