The picture banking compliance inherited without noticing
Air traffic control did not begin as a data problem. It began as a spacing problem: aircraft became faster than the interval between observations, and the interval killed people. The fix was not more information in general. It was a specific discipline — a continuously held, provenance-tagged belief about every aircraft's position, revised as fast as new evidence arrived, with separation minima priced directly off how fast that revision could happen. Ten minutes of procedural spacing on the North Atlantic became fourteen nautical miles once satellite tracking closed the gap. The buffer was never really about distance. It was about how much uncertainty the system was still carrying.
Banking compliance runs the identical problem under a different name. A customer, a counterparty, a payment corridor is not a static file. It is a moving object: its sanctions exposure, its adverse-media profile, its ownership structure and its transaction pattern all change while the bank is not looking. The question a screening system answers — will this instruction pass through a designated party or jurisdiction — is a separation question. Get the belief stale and the "collision" is a payment to a sanctioned entity, a fine, a correspondent bank relationship pulled. The instinct to treat a customer record as a file that was checked once, at onboarding, and trusted thereafter, is the see-and-be-seen era of aviation: filed intentions, periodic reports, no continuous belief, and a disaster that eventually forces the redesign.
What arrives
Four streams run into a compliance function continuously, at different rates and with different trust levels.
Transaction flow arrives in near real time — thousands of payment instructions a day at a mid-sized bank, each one a candidate for interdiction before settlement. Sanctions list updates arrive from OFAC, the UN, the EU and OFSI on no fixed schedule at all; OFAC alone issued over 40 designation actions in a single recent year, some same-day. Adverse-media feeds arrive continuously from newswire aggregators, surfacing a director's fraud indictment or a shell company's exposure in a leak, hours or days before any official list catches up. Rule changes — a new typology bulletin from FinCEN, an updated FATF grey list, an internal policy revision following a regulatory finding — arrive on a legislative rather than a market clock, but they change what "match" and "risk" mean retroactively.
None of these four streams stop. None of them agree on format, latency, or authority. A sanctions hit from OFAC's SDN list carries different legal weight than a name flagged by an adverse-media crawler using fuzzy matching on a foreign transliteration.
What is held
What the system holds is not a customer file. It is a track: a belief about a customer, a counterparty and a corridor, updated as evidence arrives, tagged by where each element of that belief came from and how old it is. A well-built version of this looks like an air traffic track file — name, entity ID, beneficial-ownership chain, most recent screening result, source and timestamp of every match or non-match, confidence score, decay clock. A poorly built version, which is still the common case, looks like a static customer risk rating set at onboarding and refreshed on a fixed cycle: every twelve months for low risk, every six for medium, every three for high. That cycle is the procedural buffer aviation used before radar — a fixed interval sized to institutional ignorance, not to the actual rate at which the underlying entity changes.
What triggers revision
This is where the loop either behaves like an air traffic system or fails like one. A properly continuous system revises the belief on event, not on calendar: a new OFAC designation should re-screen every open customer and counterparty against that name within hours, not at the next periodic review. An adverse-media hit on a director should downgrade the confidence of the whole beneficial-ownership chain immediately, flagging it for a human look rather than waiting for the annual refresh. A rule change that redefines what counts as a sanctioned jurisdiction should retroactively re-run every transaction in the affected corridor for the lookback period the regulator will ask about.
The characteristic failure is the opposite of this, and it is not hypothetical. A screening rule set is built and validated against a sanctions list as it stood on a given date, then left running for a calendar quarter while the underlying list is updated daily. Every day the rule runs, it is answering yesterday's question with growing confidence. The transactions it clears are not wrong on their face — they simply were never re-asked against the list as it now exists. When the quarterly refresh finally happens, the bank discovers a population of transactions that cleared against a stale belief, and has to explain to a regulator, transaction by transaction, why a system that looked continuously active was in fact working from a snapshot with a label that said "live."
What the compliance officer sees
The person who answers for this — typically the MLRO, the money-laundering reporting officer, or a sanctions compliance lead sitting under them — does not see raw feeds. They see, or should see, something closer to a controller's screen: a dashboard of open alerts, each one tagged with its trigger (transaction, list update, media hit, rule change), its source, its age and its current disposition. A well-instrumented desk shows which alerts are still fresh against today's lists and which are running against a belief older than the update cycle of the list that generated them — the compliance equivalent of a track whose transponder has dropped out and is coasting on the last known position.
What most desks actually see is worse: a queue of alerts ranked by score, with no visible answer to the question "as of which list version was this cleared." The officer cannot tell, from the screen, whether a name that cleared did so against last week's SDN list or last night's. That distinction is exactly what separation minima measure in aviation — not whether a track exists, but how much staleness is baked into it.
What it costs, and what it buys back
| held belief | typical revision trigger | consequence of staleness | |
|---|---|---|---|
| onboarding-only KYC | static risk rating | annual/periodic review | dormant account laundering undetected for a full cycle |
| batch screening | list snapshot loaded at build | quarterly re-run | transactions cleared against an outdated list, discovered retrospectively |
| continuous screening | per-entity track with provenance | any list update, media hit, transaction | narrower window of exposure, priced in re-screening compute rather than fines |
The trade is the same one aviation made. Ten-minute oceanic separation was not conservative for its own sake; it was the price of not knowing where an aircraft actually was between reports. A quarterly refresh cycle in compliance is not conservative either — it is the price, paid in tail-risk fines and enforcement actions, of not knowing what a customer's exposure actually is between reviews. Real-time re-screening against every list update is expensive in compute and in false-positive triage, exactly as narrower separation is expensive in surveillance infrastructure. The return is the same shape too: not more matches, but a system that stops charging you for uncertainty it no longer has.
Two objections worth taking seriously
Banking compliance can never be like air traffic control, because aircraft cooperate — they carry transponders because the law requires it — and the entities banks screen do not. Shell companies, nominee directors and sanctioned parties are actively engineered to be unobservable. Continuous intake assumes an instrumented world that mostly does not exist here.
Conceded, and it is the sharper half of the analogy, not the weaker one. Mode S and ADS-B were regulatory mandates, not discoveries; the same is true of beneficial-ownership registries and the FATF Travel Rule, which exist because voluntary disclosure failed. The claim was never that the entities being screened are cooperative by nature. It is that where cooperation can be legislated, it is, and where it cannot, the belief about a given customer degrades gracefully — held with a lower confidence score and an explicit gap, rather than defaulting silently to "clean." A shell company that goes quiet for eighteen months and resurfaces with a different beneficial owner is not evidence the model failed. It is exactly the kind of provenance-tagged silence an AIS-style analyst uses on a vessel that goes dark: the absence is recorded, not erased.
Most compliance decisions do not need per-second updates. Sanctions lists change slowly relative to daily transaction volume; a review cycle measured in months captured the vast majority of real risk for years without incident.
The record for slow cycles is real, and the marginal value of faster revision on any single account probably is falling. But the economics, as in aviation, run the other way once you count the buffer being purchased. A quarterly refresh is not efficient; it is a fixed-size hedge against not knowing, sized to the worst plausible gap rather than the actual rate of change. The gain from continuous revision was never speed for its own sake. It was the chance to stop paying, in fines and remediation, for a buffer the bank no longer needs.