Tracking financial crime through code and law: A review of RegTech applications in anti-money laundering and terrorism financing
Full text
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 73 TRACKING FINANCIAL CRIME THROUGH CODE AND LAW: A REVIEW OF REGTECH APPLICATIONS IN ANTI-MONEY LAUNDERING AND TERRORISM FINANCING Mariam El Harras *, My Abdelouhab Salahddine ** * Corresponding author, National School of Business and Management of Tangier, Abdelmalek Essaadi University, Tangier, Morocco Contact details: National School of Business and Management of Tangier, Abdelmalek Essaadi University, Boulevard Moulay Rchid, Airport Road, P. O. Box 1255, 90000 Tangier, Morocco ** National School of Business and Management of Tangier, Abdelmalek Essaadi University, Tangier, Morocco _______________________________________________________________________________________________________________ Abstract How to cite this paper: El Harras, M., & Salahddine, M. A. (2025). Tracking financial crime through code and law: A review of RegTech applications in anti-money laundering and terrorism financing. Corporate Law & Governance Review, 7(3), 73–85. https://doi.org/10.22495/clgrv7i3p7 Copyright © 2025 The Authors This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0). https://creativecommons.org/licenses /by/4.0 ISSN Online: 2664-1542 ISSN Print: 2707-1111 Received: 06.03.2025 Revised: 27.05.2025; 07.07.2025; 31.07.2025 Accepted: 06.08.2025 JEL Classification: E44, G28, K22, O33 DOI: 10.22495/clgrv7i3p7 Regulatory technology (RegTech) is transforming financial compliance by integrating advanced information technologies to strengthen antimoney laundering and countering the financing of terrorism (AMLCFT) frameworks. Recent literature suggests that such technologies represent more than just an efficiency tool; they mark a paradigm shift in regulation and the evolution of financial oversight (Kurum, 2023). This paper aims to provide a narrative review of recent RegTech applications in financial crime prevention, with a focus on key compliance domains. A structured literature review was conducted to examine publications between 2020 and 2024 with a thematic synthesis of findings related to customer due diligence (CDD) and know your customer (KYC), transaction monitoring, regulatory reporting and compliance automation, information sharing and crossborder cooperation, as well as cost efficiency. Findings reveal that RegTech solutions give financial institutions more responsibility for detecting and managing financial crime risks, making them more active players in compliance processes traditionally overseen by regulators. The combined use of technologies such as artificial intelligence (AI), blockchain, and big data also generates synergistic effects that improve compliance outcomes beyond what these technologies achieve individually. This demonstrates the strategic relevance of integrated RegTech approaches. Keywords: RegTech, AML-CFT, Compliance Automation, Financial Crime Detection, Systematic Narrative Literature Review Authors’ individual contribution: Conceptualization — M.E.H.; Methodology — M.E.H.; Resources — M.E.H.; Validation — M.E.H. and M.A.S.; Writing — Original Draft — M.E.H.; Writing — Review & Editing — M.A.S.; Supervision — M.A.S. Declaration of conflicting interests: The Authors declare that there is no conflict of interest. Acknowledgements: The first author sincerely acknowledges the CNRST (Centre National pour la Recherche Scientifique et Technique) in Morocco for the “PhD-Associate Scholarship — PASS” program. 1. INTRODUCTION As capitalism evolved, financial systems also underwent significant transformations. The deregulation of the 1980s, particularly under the Reagan and Thatcher administrations, facilitated the internationalization of financial flows and opened the door to the expansion of financial crimes. Indeed, concealing the proceeds of criminal activities has never been easier. Criminals can now
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 74 swiftly move money and goods between countries and international financial centers by using a number of procedures, which speed up the process of laundering illegal funds (Gilmour, 2020). The concept of money laundering first emerged in the United States during the 1920s with Al Capone, who used Laundromat chains and cash-based businesses to turn funds from illegal sales into legitimate earnings (Unger, 2013). Over time, mafia producing black money through heinous crimes and extortionist activities, including the Cosa Nostra, Colombian cartels, and Japan’s Yakuza, have refined their laundering methods and expanded internationally (Vernier, 2013). This global evolution has amplified the economic consequences of such illicit activities. Financial crimes severely impact both developed and developing economies (Hendriyetty & Grewal, 2017). In response, governments are putting more and more pressure on financial institutions to bolster their AML-CFT policies. This is reflected in the strict compliance obligations imposed on the sector, as illustrated by the $2 billion fine against Danske Bank for major AML failures in its Estonian branch (U.S. Securities and Exchange Commission, 2022). As a result, technological solutions to combat financial crimes have gained prominence, particularly through RegTech, which represents the innovative use of digital tools to enhance and automate regulatory compliance, monitoring, and reporting processes in the financial sector (Arner et al., 2017). This trend aligns with findings from a Financial Action Task Force (FATF) report on digital transformation, which examines the role of technology in AML-CFT efforts and highlights that financial institutions, tech developers, and globally regulated financial technology (FinTech) companies are leading the adoption of these innovations (FATF, 2021). According to this report, these technologies will also help to reinforce efforts in AML-CFT, notably through more precise risk detection and real-time monitoring of transactions. RegTech’s capabilities extend beyond automation to include enhanced risk detection, real-time transaction monitoring, as well as optimized customer vigilance, especially in scenarios involving substantial data volumes and complex regulatory frameworks. Recent studies also show that banks are relying more heavily on RegTech solutions to manage compliance risks more efficiently and reduce the operational workload associated with AML-CFT procedures (Bakhos Douaihy & Rowe, 2023). Although financial crime and money laundering have been extensively studied, their treatment remains largely disconnected from research on RegTech, which has often been confined to its operational and technical dimensions rather than its institutional implications (Turki et al., 2020; Utami & Septivani, 2022). In order to fill this gap, this study aims to offer a structured analysis of academic and institutional literature on RegTech applications in AML-CFT, with particular attention to how integrated digital solutions contribute to risk detection and automation, as well as the redesign of compliance ecosystems. To guide this inquiry, the study addresses the following research questions: RQ1: How is RegTech transforming the role of financial institutions in the fight against financial crime? RQ2: What are the contributions and limitations of integrated technologies in AML-CFT compliance frameworks? This study is grounded in the literature on regulatory technology and institutional accountability, which emphasizes the role of digital infrastructures in transforming how compliance is enacted (Becker et al., 2020; Campbell-Verduyn & Hütten, 2021; Khoury et al., 2024). RegTech is becoming a “bridge” between businesses and regulatory expectations, with a two-way flow of influence (Grassi & Lanfranchi, 2022). While regulators rely on industrydeveloped solutions to extend their oversight, businesses integrate regulatory logic directly into their digital systems. This mutual dependence underlines the importance of regulators not only to follow the evolution of RegTech but to actively engage with it and build internal technical expertise to respond to the sophistication of money laundering strategies (Kurum, 2023). Simultaneously, financial institutions are under growing regulatory strain in an increasingly volatile global context, which makes this study both timely and necessary. Methodologically, we followed a structured narrative literature review, based on 33 peerreviewed studies published between 2020 and 2024, selected through Boolean-based search strategies focused on AML-CFT technologies. This review led to the following insights. This work contributes to the growing literature on digital compliance by identifying overlooked conceptual areas and proposing a governance-focused interpretation of RegTech’s role in AML-CFT frameworks. Key findings indicate that these solutions improve not only operational efficiency but also reallocate compliance responsibilities and foster technological synergies while bringing new governance challenges, particularly with regard to regulatory asymmetry and institutional capacity gaps. The rest of this paper is structured as follows. Section 2 provides background context and reviews related academic and institutional works on RegTech adoption, especially its use in AML-CFT. Section 3 outlines the methodology of the literature review. Section 4 synthesizes key findings across five application areas: customer due diligence (CDD) and know your customer (KYC), transaction monitoring, compliance automation, information sharing, and cost efficiency. Section 5 discusses the implications and persistent challenges. Section 6 concludes by summarizing the main contributions, acknowledging limitations, and suggesting directions for future research. 2. LITERATURE REVIEW 2.1. RegTech: Revolutionizing compliance in the digital age Technology has become a fundamental part of modern financial regulation, with the accent now being placed not on human control, but on automated systems (Zetzsche et al., 2017). This evolution was facilitated by the widespread integration of information and communication technologies (ICT) by the banking sector, which provides essential tools to meet global economic challenges (Jakšič & Marinč, 2019; Mocetti et al., 2017; Navaretti et al., 2018). This technological shift in the banking sector has catalyzed an important regulatory innovation: RegTech, a cross between “regulatory” and “technological”, which the Institute of International Finance (IIF) refers to as the application of technology to improve
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 75 the effectiveness and efficiency of regulatory compliance (IIF, 2016). By delivering real-time data, these technologies improve market monitoring and risk detection (Anagnostopoulos, 2018). RegTech is no longer just about automating back-office processes. It is now seen as a strategic instrument that redistributes power and compliance responsibilities across different actors (Khoury et al., 2024). It also facilitates dynamic and datadriven oversight, allowing both regulators and institutions to transition from retrospective audits to near real-time supervision (Broby et al., 2022). As the focus is on compliance challenges and crossborder transactions, studies have revealed that the most popular and in-demand RegTech solutions are those that concentrate on AML-CFT, KYC, and anti-fraud compliance (Battanta et al., 2020; Kurum, 2023). Within these domains, challenges such as cyber identity privacy and financial crimes are expected to grow significantly in importance in the coming years (KPMG, 2022). The majority of studies in the newly emerging field of RegTech concentrate on technologies such as distributed ledgers, cloud computing, artificial intelligence (AI), big data analytics, application programming interfaces (APIs), cryptography, and biometrics, which are investigated for their potential to improve financial regulation and supervision, though their use in this area is still developing (Yang & Tsang, 2018). Notably, both technology providers and established financial institutions have made significant strides in regulatory compliance, improving customer identity verification processes and transaction oversight. These developments allow for a more streamlined and proactive approach to meeting regulatory demands, strengthening the security and transparency of the financial sector (De Koker et al., 2019). 2.2. Know your customer: Beyond identity to intelligence As indicated earlier, under financial regulation, compliance within financial institutions has become increasingly important to safeguard their reputation and the integrity of their activities. As part of this, the evolution of the banking sector has brought to the fore the urgent need for sophisticated and reliable digital identity verification systems. At the heart of this is KYC, a process that requires institutions to check the identity of their customers and collect the information needed to facilitate legitimate financial transactions (Arasa & Ottichilo, 2015). In line with FATF Recommendation 10, financial institutions must verify the identities of their clients, identify beneficial owners, and gain a clear understanding of the purpose and nature of their business relationships (FATF, 2012/2025). As a result, different onboarding procedures, identity standards, and authentication techniques result from the various KYC needs (Arner et al., 2019). Under AML-CFT regulations, institutions must conduct KYC screening on individuals entering into a business relationship, as well as the beneficial owner, while ensuring that they are not included on blacklists, since it is strictly forbidden to maintain business relationships with them. Research indicates that technological advancements are increasingly simplifying KYC procedures. These include the deployment of remote onboarding systems, the use of biometric technologies for secure and efficient authentication, and the integration of Blockchain solutions to accelerate and enhance the reliability of specific customer due diligence processes. (Gaviyau & Sibindi, 2023; Teichmann et al., 2023). However, effective integration of these technologies, such as blockchain, depends a lot on how ready institutions are, how clear the rules are, and what digital infrastructure is already in place (Al-Smadi et al., 2023). Building on these foundations, enhanced KYC systems are now evolving further by incorporating machine learning (ML) and big data analytics, which enable the creation of adaptive and risk-based profiles that update in real time based on client behavior (Alhajeri & Alhashem, 2023; Gandhi et al., 2024). This change means that organizations can not only verify identity, but also predict and stop any suspicious activity. 2.3. Real-time vigilance: The rise of automated monitoring Transaction monitoring is a critical component of AML-CFT initiatives. It leverages information systems to detect suspicious financial activities, acting as a filter by flagging potentially fraudulent actions based on limited datasets. Nevertheless, it depends on human analysts such as compliance officers to examine the warnings and decide if the transactions that have been reported pose a danger of money laundering and terrorist financing (Chau & van Dijck Nemcsik, 2020). A local financial intelligence unit, which ensures liaison between financial institutions and regulators, must be notified when such practices are discovered and cannot be justified following a comprehensive study or inquiry. Transaction monitoring faces a key challenge: reducing false positives. While ML is seen as a promising solution to replace traditional rulebased approaches, this technological shift is still more of an aspiration than a current reality (Oztas et al., 2024). Nevertheless, the traditional software and systems used to monitor financial transactions and to verify details of the originator and beneficiary against blacklisted entries are not sufficiently effective to either unblock or block transactions from the historical database (Alkhalili et al., 2021). In response to these limitations, the recent literature emphasizes that real-time and automated transaction monitoring is now a foundation of modern AML-CFT compliance (Gupta et al., 2023; Garcia-Segura, 2024). Rather than conducting audits after the fact, banks are recently deploying AI tools that continuously monitor transactions and flag suspicious activities as they occur. 3. RESEARCH METHODOLOGY 3.1. Search strategy and data sources In addition to providing empirical evidence of specific effects, a literature review can facilitate the establishment of guidelines for policy and practice, contribute to the advancement of knowledge, and, when rigorously conducted, stimulate novel ideas and potential research trajectories within a particular domain (Snyder, 2019). In the context of AML-CFT technologies, it can be particularly instrumental by offering insights that may catalyze
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 76 innovation, inform policymaking, and shape future scholarly inquiries in this pivotal area. The purpose is to provide a summary of the main findings, to evaluate current knowledge, to identify gaps, and to address any ambiguities in existing research (Knopf, 2006). A structured methodology was adopted for this literature review, with data gathered from the Scopus database. Selection was based on title, abstract, and keywords to ensure reliability and accuracy in our findings. A Boolean search was conducted using AND and OR operators to explore the literature on emerging technologies in AML-CFT. Given the high number of results, the search was limited to the following keywords (Table 1). Table 1. Themes, keyword pool, and final list of selected keywords used in the systematic literature review Category Keyword pool Selected keywords Financial crime and identity threats Money laundering, financial crime, terrorism financing, KYC, digital identity “Money laundering” OR “Financial crime*” OR “Terrorism financing” Technological solutions for compliance RegTech, FinTech, artificial intelligence, machine learning, blockchain, data mining “RegTech” OR “FinTech” OR “Artificial Intelligence” OR “Machine Learning” OR “Blockchain” OR “Data mining” In order to maintain relevance, our review focuses on articles and conference papers published between 2020 and 2024. Also, only publications written in English were considered for inclusion. To uphold alignment with our review’s objectives, we excluded publications that did not meet these criteria to ensure the final selection was relevant and aligned with the review’s objectives. Book chapters, editorials, notes, and quick polls were all excluded since they were not pertinent to the review’s focus. Additionally, studies that were off-topic or that concentrated on criminal technology rather than AML-CFT were also not included. Other methods, such as bibliometric analysis, case studies, or field research, would have provided valuable insights by enabling trends to be mapped or the practical implementation of RegTech to be examined. These approaches, however, were less suitable for capturing the broader conceptual and governance issues addressed in this study. Therefore, a structured narrative review was considered the most appropriate. 3.2. Screening and selection process After eliminating duplicates to ensure the chosen studies were unique, a preliminary filtering was performed by screening the article abstracts, which allowed the elimination of studies that were not related to the main scope of the review, in particular studies that focused principally on AML-CFT for virtual currencies using blockchain technology, as they did not correspond to our main topic. Only those papers that provided significant insight into the technologies used to combat financial crime were to be considered. The second phase involved a detailed assessment, in full text, of the selected publications, to determine their relevance and contribution to the field. This allowed us to determine the most significant and relevant research results. After careful review of the content of each publication, 33 studies were selected for inclusion in the final dataset based on their compliance with the selection criteria (Figure 1). Figure 1. PRISMA Diagram illustrating the screening and inclusion process 3.3. Epistemological and methodological approaches Knowledge management paradigms provide structured approaches to analyzing organizational knowledge, offering both practical tools and theoretical foundations for research (Turyahikayo, 2021). Understanding these paradigms clarifies the epistemological stances and methodological choices that are likely to transform scholarly work in this field. Records identified through database searching based on a specific keyword combination within 2020–2024. Scopus (n = 759) Records screened (title & abstract) (n = 676) Excluded before screening (n = 83): •Non-English studies •Document types other than (articles, conference papers, book chapters) Records excluded via abstracts assessment (n = 416) Full-text articles excluded (n = 126): •Out of scope/off-topic •Focused on tech but not AML-CFT •Not empirical/irrelevant format Full-text articles assessed for eligibility (n = 159) Studies included in the systematic review (n = 33) Identification Screening Eligibility Included
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 77 The positivist paradigm, which assumes that reality can be objectively measured through scientific methods and empirical evidence (Park et al., 2020), underpins most of the studies reviewed. Among the 33 articles, 64% adopt a positivist stance, employing quantitative methods such as statistical modeling, algorithmic evaluation, and performance metrics (Antwi & Hamza, 2015). For example, Al-Ababneh et al. (2024) and Sharma et al. (2024) assess the accuracy and efficiency of AI and ML tools in AML-CFT contexts. In parallel, the interpretivist paradigm focuses on understanding meaning and experience within specific social or organizational contexts (Alharahsheh & Pius, 2020). Approximately 27% of the studies follow this approach, using qualitative methods to explore ethical concerns, implementation challenges, and user perceptions of RegTech systems. Studies by Daugaard et al. (2024) and Pavlidis (2023) show how technologies like blockchain and AI are integrated into real-world institutions. In addition, qualitative techniques such as the Delphi method, which involves iterative rounds of expert feedback to reach consensus on complex issues, are used in some studies, such as that of Kurum (2023). Others use literature review methods to synthesize existing knowledge on technologies such as Blockchain and AI, as well as to identify research gaps and suggest future research directions (Bozorgi, 2024; Smith & Tiwari, 2024; Swain & Gochhait, 2022). This distribution (see Appendix, Table A.1) reflects a dominant orientation toward measurable outcomes, while still incorporating contextual and interpretive insights. 4. RESULTS 4.1. Publication trends The analysis of selected publications from 2020 to 2024 reveals a clear evolution in both the volume and focus of research on RegTech technologies (see Appendix, Table A.1). This growth reflects the increasing role of these technologies in combating financial crime and ensuring regulatory compliance (see Figure 2). Early publications (2020–2021) primarily focused on establishing foundational frameworks and exploring initial applications of AI and ML in AML-CFT (Chitimira & Ncube, 2021; Couchoro et al., 2021), while more recent research (2023–2024) emphasizes practical implementations and integrated solutions, reflecting a maturing field (Lokanan, 2024a; Meiryani et al., 2023; Sharma et al., 2024; Usman et al., 2023). This progression exemplifies how academic attention has moved from theoretical potential to operational integration, and underlines the strategic relevance of RegTech in the field of financial compliance. Figure 2. Evolution of the number of documents analyzed per year (2020–2024) 4.2. Technologies identified in the literature A thorough analysis of the technologies presented in the literature uncovers the emergence of several trends that are transforming the financial compliance landscape (see Figure 3 and Appendix, Table A.1): • AI and ML have emerged as the predominant technological solutions, with their presence in publications jumping from 70% in 2020 to 91.7% in 2024, a remarkable 21.7 percentage point increase. Applications range from neural networks (Lokanan, 2024a, 2024b; M. Raj et al., 2024) to various learning algorithms (Beketnova, 2021; Kumar et al., 2022; Mohammed et al., 2022). • Advanced analytics also grew in significance over the period, from 22% to 33.3%. This reflects the adoption of complex data analysis methods such as pattern recognition (Canhoto, 2021; Prisznyák, 2022) as well as graphical analysis (Garcia-Bedoya et al., 2021). • Blockchain and distributed technologies rose from 15% to 27.8%, illustrating a move toward decentralized systems (Campbell-Verduyn & Hütten, 2021; A. Raj et al., 2023). • In parallel, specialized technical solutions, including natural language processing (Pavlidis, 2023) and biometrics (Kurum, 2023), increased from 12% to 19.4%, addressing targeted operational needs. The above analysis highlights a clear trend toward a multi-technology approach rather than isolated, single-technology tools. In particular, researchers are interested in technological synergetic effects that will create more comprehensive regulatory solutions. The powerful combination of AI, blockchain, and advanced analytics has considerably improved the detection of suspicious activity and the effectiveness of regulatory compliance (Daugaard et al., 2024). 0 2 4 6 8 10 12 14 2020 2021 2022 2023 2024
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 78 Figure 3. Evolution of technology coverage in RegTech literature (2020–2024) in percentage 4.3. Main application areas of RegTech The reviewed literature identifies five main areas where RegTech is most applied in the AML-CFT framework: CDD and KYC, transaction monitoring, regulatory reporting and compliance automation, information sharing and cross-border cooperation, and cost and time efficiency (see Appendix, Table A.2 and Figure 4). These categories reflect how RegTech integrates advanced technologies to improve compliance processes and enhance the detection of financial crime. 4.3.1. Customer due diligence and know your customer Our analysis reveals that RegTech is transforming the way financial institutions approach CDD and KYC processes by leveraging advanced technologies such as Blockchain, ML, and biometric verification (Lokanan, 2019; Canhoto, 2021; Thommandru & Chakka, 2023; Bhumikapala et al., 2024). A qualitative study has demonstrated that Blockchain enables secure and reusable digital identities, which reduce redundant verifications and onboarding time (Daugaard et al., 2024). Another qualitative study based on data derived from simulated real-life transactions flagged as suspicious for money laundering in Middle Eastern banks showed that ML and artificial neural networks (ANN) algorithms assess customer risk through behavioral data and detect anomalies such as sudden spikes or irregular transactions (Kumar et al., 2022; Lokanan, 2024b). It was also demonstrated that the use of big data analytics and ML while incorporating KYC data and contextual information proves to be a highly effective strategy for identifying money laundering activities, especially with support vector machines (SVMs) (Usman et al., 2023). Figure 4. Main application areas of RegTech in the AML-CFT framework 4.3.2. Detection of suspicious transactions and anomaly detection Many of the articles we reviewed highlighted the significant role of RegTech in enhancing transaction monitoring. Advanced technologies capable of processing massive amounts of data are essential for the effectiveness of these systems, such as ML (Lokanan, 2024b; Mbiva & Correa, 2024; Sharma et al., 2024), AI (Garcia-Bedoya et al., 2021; Chitimira et al., 2024), and graph-based technologies (Kurshan & Shen, 2020; Huong et al., 2024). These technologies enable real-time analysis of large datasets, allowing for the detection of suspicious activities and fraud patterns. It has been shown that reducing false alerts was one of the main contributions of emergent technologies. While traditional systems rely on rulebased scenarios that generate a large percentage of false alerts, creating a huge workload for compliance officers, those traditional rule-based manual methods have become inefficient and subject to false alarms. A study by Al-Ababneh et al. (2024) reports a 30% reduction in false positives and 25% improvement in high-risk detection using AI models over traditional rules. A ML model tested at DNB Bank in Norway has also contributed to the reduction of manual reviews by 51% and detected 80% of suspicious cases (Jullum et al., 2020), while similar research highlighted isolation forest for its real 0 10 20 30 40 50 60 70 80 90 100 2020 2021 2022 2023 2024 IA & Machine Learning Advanced Analytics Blockchain & DLT Specialized Technical Solutions RegTech in the AML-CFT framework CDD and KYC Transaction monitoring and anomaly detection Regulatory reporting and compliance automation Information sharing and cross-border cooperation Cost and time efficiency
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 79 efficiency in identifying global transaction anomalies and rapidly processing suspicious activities which makes it particularly valuable for large scale financial monitoring applications (Oztas et al., 2022). Hybrid locality outlier factor-isolation forest (LOF-IF) algorithm models identify both global and local anomalies (Mbiva & Correa, 2024). In addition to cognitive and analytical technologies, blockchain provides traceable, immutable records, reducing review time (Daugaard et al., 2024). 4.3.3. Regulatory reporting and compliance automation Regulatory reporting, as a fundamental part of financial institutions’ obligations in AML-CFT, involves submitting financial data to regulatory authorities in order to ensure compliance with laws and regulations. In the Indonesian banking sector, for example, a survey of 160 professionals across eight banks measured three key dimensions: e-KYC systems, transaction monitoring capabilities, and operational efficiency. Results show banking professionals strongly endorse RegTech’s effectiveness in enhancing risk identification and streamlining regulatory processes (Meiryani et al., 2023). ML accelerates the process of uncovering illegal activities and non-compliant practices, and enables regulators to catch financial institutions that are under suspicion at an early stage. As a result, reactivity is improved, surveillance is strengthened, and more effective application of financial regulations is achieved (Beketnova, 2021). This shift supports a broader trend; Institutions increasingly rely on RegTech for interpreting AML-CFT policies (Kurum, 2023), with AI models being regularly retrained in order to adapt to new and evolving financial crime typologies (Al-Ababneh et al., 2024). 4.3.4. Information sharing and cross-border cooperation With the complexity of international financial movements and the growing level of sophistication of criminal activity continuing to increase, a unilateral approach on the part of individual states is no longer adequate. In this context, as highlighted by Pavlidis (2023), there is a need for national and international cooperation to ensure the effective use of AI in AML-CFT, with collaboration between local authorities and global alignment of regulations and standards across sectors. Building on this, a qualitative study demonstrated that RegTech solutions enhance transparency and efficiency in cross-border operations. These tools, institutionalized under international regulatory pressure, improve AML-CFT efforts while facilitating global transactions (Bakhos Douaihy & Rowe, 2023). In parallel, Blockchain technology is highly valued for its role in compliance, as blockchainbased networks simplify international flows, enhance traceability, and reduce fraud risks (A. Raj et al., 2023; Thommandru & Chakka, 2023). It was empirically demonstrated that a multichain distributed P2P Network improves transparency and reduces delays in cross-border transactions (A. Raj et al., 2023). 4.3.5. Cost and time efficiency The literature we reviewed illustrated that the financial sector has witnessed a transformative shift in compliance operations through RegTech implementation. Institutions report major savings through automation of onboarding and transaction monitoring (Pavlidis, 2023; Prisznyák, 2022). A study conducted by Gupta et al. (2022) showed how mathematical optimization in threshold fine-tuning can generate millions in savings for financial institutions while maintaining robust monitoring capabilities. This cost-effectiveness is further reinforced by a study of Daugaard et al. (2024) showing that shared blockchain-based networks lower costs for banks working within the same compliance system. RegTech is seen as a costeffective strategy that combines accuracy with speed (Al-Ababneh et al., 2024; Kurum, 2023). 5. DISCUSSION The findings of this review reveal a profound transformation in how compliance is conceived and operationalized in the financial sector. The adoption of RegTech in AML-CFT is a reflection of more than a technological evolution; it points to a change in the institutional fabric of financial compliance. As Anagnostopoulos (2018) suggests, regulatory innovation today is no longer a matter of competing interests but of co-constructed ecosystems, where banks, FinTechs, and regulators share overlapping responsibilities. RegTech operates at the center of this convergence, not as a technical layer, but as a force that changes the balance between risk management, control, and adaptability. One of the most notable evolutions lies in the individualization of risk detection. Thanks to AI and ML, more nuanced profiling is now possible. This enables institutions to move beyond static rulebased systems. Unlike earlier frameworks, where the detection logic was imposed from outside by regulators, current RegTech tools facilitate adaptive compliance systems that learn from behavior and adjust thresholds accordingly. This shift aligns with the conceptual reframing noted by (Khoury et al., 2024), but our synthesis goes further by anchoring it in operational realities and documenting reductions of 30% in false positives (Al-Ababneh et al., 2024) and over 50% in manual verification workloads through specific algorithmic architectures. Another key insight is the functional convergence of technologies across AML-CFT stages. While previous literature often discusses ML, blockchain, or big data in isolation, our findings show that their true potential emerges through complementary use. For instance, blockchain addresses trust and data immutability in KYC and cross-border flows, while AI ensures dynamic transaction surveillance. Together, these tools form multi-layered compliance architectures, where identity verification, anomaly detection, and regulatory reporting are interconnected as described by Pavlidis (2023). This perspective also complements the work of Firmansyah and Arman (2022), whose architectural mapping highlights how technologies like AI and blockchain can support distinct compliance functions. From these observations, our findings show that these technologies do not operate in isolation, but rather as interdependent layers within AML-CFT workflows. A third transformation relates to institutional responsibility. As technologies evolve, so does the distribution of compliance duties. Whereas the traditional model placed the regulator at the center, RegTech tools empower institutions to self-regulate in real time and faster than supervisory bodies can
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 80 react. This evolution raises concerns about regulatory asymmetry, where the tools and expertise lie more with the private sector than with public oversight bodies. While Rafiq and Sohail (2023) touch on this by pointing to the challenges regulators face in keeping pace with innovation, our review illustrates how institutions not only adopt technology but also dynamically transform the logic of compliance through tool design, data control, and internal rule calibration. The growing autonomy of RegTech systems raises governance and oversight challenges, especially in contexts where regulatory frameworks lag behind technological capabilities (Kurum, 2023) warns of such gaps, and our review reinforces this concern: the speed at which AI models evolve often exceeds that of policy cycles, which creates a risk of regulatory mismatch. This is particularly problematic in smaller institutions or jurisdictions where the resources to implement, audit, and adapt these systems remain limited. Finally, the promise of cost and time efficiency must be approached critically. While the literature reports substantial savings (Daugaard et al., 2024; Gupta et al., 2022), these benefits are not uniformly distributed. Smaller institutions may face barriers to adoption due to resource constraints, while the integration of RegTech requires not just financial investment but also factors often underexamined in current research, namely, genuine organizational change, talent development, as well as cultural adaptation. 6. CONCLUSION While criminals consistently exploit weaknesses in traditional financial systems and stay one step ahead of conventional compliance measures (Kurum, 2023), our findings lead to three central conclusions regarding the evolving role of RegTech in financial crime prevention. First, the progressive incorporation of advanced technologies, including AI, ML, and big data, into core AML-CFT compliance functions is changing the status of financial institutions from passive rule-followers into active risk managers. This transformation is particularly evident in areas like KYC and transaction monitoring where dynamic systems are replacing static rule-based models. In fact, these technologies do not merely support compliance processes but they are redefining which transforms financial institutions into major participants in the detection and management of financial crime risks, traditionally the domain of regulatory authorities. Second, the integration of multiple technologies produces stronger results than isolated implementations. AI improves detection accuracy and reduces false alerts, while blockchain enhances secure identity verification and enables cross-border cooperation. However, realizing these synergies requires institutional capacity and strategic coordination, which suggests a future model based on ecosystem thinking rather than fragmented tools. This transformation raises important ethical and governance challenges. While RegTech enhances monitoring capabilities, it also redistributes responsibility across actors and systems which creates ambiguity around accountability. Many institutions lack adequate regulatory oversight mechanisms for algorithmic decisions. This becomes even more critical when technologies are deployed across borders which is challenging the coherence of international regulatory frameworks and data governance standards. In addition, smaller establishments may find it difficult to access and implement these advanced systems, which in turn exacerbates asymmetries between jurisdictions in terms of regulatory capacity and technological readiness. The study also recognizes an important limitation, namely that while it draws on 33 recent studies to map functional impacts and trends, it is limited by the lack of direct empirical evaluation of real-world implementations. Much of the available data remains theoretical or simulation-based, especially concerning algorithmic performance and interoperability across systems. Additional investigation is needed to assess the institutional and regulatory consequences of RegTech adoption in practice. Studies focusing on institutional adaptation, regulatory capacity development, and the embedding of ethical considerations into system design will be of paramount importance. In parallel, the evolving nature of financial crime threats must also be considered. Cryptocurrencies, in particular, have become a growing concern. The literature underscores the central role that crypto-assets play in facilitating money laundering activities and highlights how their decentralized and often unregulated nature undermines the effectiveness of current compliance systems (Guidara, 2022; Leuprecht et al., 2023). As noted by Prendi et al. (2023, p. 90), “electronic money is the future of currencies”, but its growth must be accompanied by proper infrastructure and oversight. These findings carry both theoretical and practical implications. The paper’s theoretical perspective calls for a rethinking of traditional compliance and regulatory frameworks. RegTech is more than just a toolkit; it represents a new ecosystem that merges technology, regulation, and governance. For example, blockchain solutions question the central role of regulators by shifting the compliance paradigm toward distributed decision-making. This evolution calls for updated frameworks that account for the convergence of regulation and technological innovation. From a practical standpoint, RegTech has become indispensable for institutions operating in increasingly complex and rapidly changing regulatory environments. Tailored solutions are needed for different compliance functions, alongside safeguards to ensure data security, avoid algorithmic bias, and manage integration with legacy systems (M. Raj et al., 2024). For regulators, RegTech enhances control through real-time monitoring and information sharing, improving the detection of suspicious activities and international cooperation. As adoption grows, recruiting technical specialists becomes as critical as the technology itself, enabling regulators to effectively manage the transformation revolutionizing AML-CFT compliance processes (Kurum, 2023). Establishing harmonized standards and universal data formats would support interoperability, while regulatory sandboxes could foster innovation (Grassi & Lanfranchi, 2022). To support future research directions, this study suggests several priority areas. To expand current knowledge, deepen understanding of financial crime prevention and compliance, respond effectively to the fast-evolving challenges in these areas, and harness the full transformative potential of RegTech to foster more secure, transparent, and effective financial systems, future research should address the following critical questions:
Corporate Law & Governance Review / Volume 7, Issue 3, 2025 81 • How can collaboration between regulators, financial institutions, and technology providers be strengthened? What models of partnership and incentive structures are most effective? • What ethical considerations should guide the use of decentralized identity systems? How can blockchain innovations be aligned with privacy and data protection principles? • How should RegTech evolve to address emerging financial crime threats such as those related to cryptocurrencies? Which technological adaptations are most promising? • What role can RegTech play in supporting SDG 16? How can it help combat corruption and reduce illicit financial flows at scale? These questions highlight persistent gaps in the literature and offer a concrete agenda for advancing research on RegTech’s evolving role in AML-CFT. REFERENCES Al-Ababneh, H. A., Nuralieva, C., Usmanalieva, G., Kovalenko, M., & Fedorovych, B. (2024). The use of artificial intelligence to detect suspicious transactions in the anti-money laundering system. Theoretical and Practical Research in Economic Fields, 15(4), 1039–1050. https://doi.org/10.14505/tpref.v15.4(32).19 Alhajeri, R., & Alhashem, A. (2023). Using artificial intelligence to combat money laundering. Intelligent Information Management, 15(4), 284–315. https://doi.org/10.4236/iim.2023.154014 Alharahsheh, H. H., & Pius, A. (2020). A review of key paradigms: Positivism VS interpretivism. Global Academic Journal of Humanities and Social Sciences, 2(3), 39–43. https://gajrc.com/media/articles/GAJHSS_23_3943_VMGJbOK.pdf Alkhalili, M., Qutqut, M. H., & Almasalha, F. (2021). Investigation of applying machine learning for watch-list filtering in anti-money laundering. IEEE Access, 9, 18481–18496. https://doi.org/10.1109/ACCESS.2021.3052313 Al-Smadi, A. W., Ali, O. A., Malkawi, A., Al-Hammoury, A. M., Kalbouneh, N. Y., & Alsakarneh, A. (2023). The extent of commercial banks’ readiness to implement blockchain technology [Special issue]. Journal of Governance and Regulation, 12(1), 282–293. https://doi.org/10.22495/jgrv12i1siart8 Anagnostopoulos, I. (2018). Fintech and regtech: Impact on regulators and banks. Journal of Economics and Business, 100, 7–25. https://doi.org/10.1016/j.jeconbus.2018.07.003 Antwi, S. K., & Hamza, K. (2015). Qualitative and quantitative research paradigms in business research: A philosophical reflection. European Journal of Business and Management, 7(3), 217–225. https://www.researchgate.net/publication/295087782_Qualitative_and_Quantitative_Research_Paradigms_ in_Business_Research_A_Philosophical_Reflection Arasa, R., & Ottichilo, L. (2015). Determinants of know your customer (KYC) compliance among commercial banks in Kenya. Journal of Economics and Behavioral Studies, 7(2), 162–175. https://doi.org/10.22610/jebs.v7i2(J).574 Arner, D. W., Barberis, J., & Buckey, R. P. (2017). FinTech, RegTech, and the reconceptualization of financial regulation. Northwestern Journal of International Law & Business, 37(3), 371–413. https://scholarlycommons.law.northwestern.edu/njilb/vol37/iss3/2/ Arner, D. W., Zetzsche, D. A., Buckley, R. P., & Barberis, J. N. (2019). The identity challenge in finance: From analogue identity to digitized identification to digital KYC utilities. European Business Organization Law Review, 20(1), 55–80. https://doi.org/10.1007/s40804-019-00135-1 Bakhos Douaihy, H., & Rowe, F. (2023). Institutional pressures and RegTech challenges for banking: The case of money laundering and terrorist financing in Lebanon. Journal of Information Technology, 38(3), 304–318. https://doi.org/10.1177/02683962231152968 Battanta, L., Giorgino, M., Grassi, L., & Lanfranchi, D. (2020). Regtech: Case studies of cooperation with banks in Italy. In the Proceedings of the 15th European Conference on Innovation and Entrepreneurship, ECIE 2020 (pp. 112–119). Academic Conferences and Publishing International Limited. https://boa.unimib.it /handle/10281/536122?mode=simple Becker, M., Merz, K., & Buchkremer, R. (2020). RegTech — The application of modern information technology in regulatory affairs: Areas of interest in research and practice. Intelligent Systems in Accounting, Finance and Management, 27(4), 161–167. https://doi.org/10.1002/isaf.1479 Beketnova, Y. M. (2021). Comparative analysis of machine learning methods to identify signs of suspicious transactions of credit institutions and their clients. Finance: Theory and Practice, 25(4), 186. https://doi.org/10.26794/2587-5671-2020-25-5-186-199 Bhumikapala, A. S., Randiko, A. S., & Adrianto, B. (2024). Applying machine learning for suspected terrorists watchlist filtering. In the Proceedings of the 2024 International Conference on ICT for Smart Society (ICISS) (pp. 1–5). IEEE. https://doi.org/10.1109/ICISS62896.2024.10751540 Bozorgi, M. (2024). Exploring the role of fintech in terrorism financing: Legal frameworks. In N. Mansour & L. M. Bujosa Vadell (Eds.), Sustainability and financial services in the digital age (pp. 9–20). https://doi.org/10.1007/978-3-031-67511-9_2 Broby, D., Daly, A., & Legg, D. (2022). Towards secure and intelligent regulatory technology (Regtech): A research agenda. Technology And Regulation, 2022, 88–99. https://doi.org/10.71265/cb65xb64 Campbell-Verduyn, M., & Hütten, M. (2021). The formal, financial and fraught route to global digital identity governance. Frontiers in Blockchain, 4. https://doi.org/10.3389/fbloc.2021.627641 Canhoto, A. I. (2021). Leveraging machine learning in the global fight against money laundering and terrorism financing: An affordances perspective. Journal of Business Research, 131, 441–452. https://doi.org/10.1016/j.jbusres.2020.10.012 Chau, D., & van Dijck Nemcsik, M. (2020). Anti-money laundering transaction monitoring systems implementation: Finding anomalies. John Wiley & Sons. https://doi.org/10.1002/9781119381877 Chitimira, H., & Ncube, P. (2021). The regulation and use of artificial intelligence and 5G technology to combat cybercrime and financial crime in South African banks. Potchefstroom Electronic Law Journal, 24(1), 1–33. https://doi.org/10.17159/1727-3781/2021/v24i0a10742 Chitimira, H., Torerai, E., & Jana, V. L. M. (2024). Leveraging artificial intelligence to combat money laundering and related crimes in the South African banking sector. Potchefstroom Electronic Law Journal, 27(1), 1–30. https://doi.org/10.17159/1727-3781/2024/v27i0a18024 Couchoro, M. K., Sodokin, K., & Koriko, M. (2021). Information and communication technologies, artificial intelligence, and the fight against money laundering in Africa. Strategic Change, 30(3), 281–291. https://doi.org/10.1002/jsc.2410