What AML Compliance Actually Costs: A Budget Model for 2026
Most AML budget conversations start with a vendor quote and work backwards. That is the wrong direction — and it is why so many programmes are simultaneously over-licensed and under-staffed. This guide builds the cost from its real drivers so you can defend the number to a board, and test any quote against it.
The five cost centres
An AML programme costs money in five places. Any budget that does not name all five is incomplete, and the gap is almost always number four.
1. Onboarding operations
The analysts who clear KYC cases that automation could not. This scales with new customer volume and with your straight-through-processing rate — not with your total customer base.
2. Alert handling
Transaction monitoring and screening alerts, from triage through investigation to escalation. Scales with transaction volume and, brutally, with your false-positive rate.
3. Periodic review and remediation
Refreshing existing customer files. Scales with your total customer base divided by your review cycle. This is the cost centre that a move to event-driven rescreening most directly attacks.
4. Governance and assurance
The MLRO function, policy, training, risk assessment, second-line quality assurance, third-line internal audit, regulatory reporting, and examination response. This is fixed-ish cost that does not scale with volume — and it is the line most often missing from a budget built bottom-up from a vendor quote.
5. Technology
Licences, data feeds, implementation, integration, tuning, and the internal engineering time to keep it all running. Data feeds — sanctions lists, PEP data, adverse media, corporate registry access — are frequently a larger line than the platform licence itself, and are frequently forgotten.
Building the number
Work in analyst-hours, then convert. Hours are comparable across jurisdictions in a way that currency is not, and they survive a salary revision.
Step one: alert cost
Take your monthly alert volume. Split it by disposition tier — auto-closed, level-one triage, level-two investigation, escalated to SAR. Attach an average handling time to each tier from your own case management data, not from a vendor's slide.
The arithmetic is unforgiving. A programme generating 10,000 monthly alerts at a 96% false-positive rate, where level-one triage averages twelve minutes, spends roughly 1,920 analyst-hours a year on alerts that were never going anywhere. That is a headcount line you can put a name to. It is also the single clearest business case for rule tuning.
Step two: onboarding cost
New customers per month, multiplied by the proportion requiring manual intervention, multiplied by average handling time. Then add the cost of the ones you lost: if abandonment during verification runs at a meaningful rate, the revenue forgone belongs in this model even though it never appears in a compliance cost line. Most firms discover the drop-off cost exceeds the review cost.
Step three: periodic review cost
Customer base, divided by review cycle in years, multiplied by hours per review — weighted by risk tier, because a high-risk refresh with enhanced due diligence is not a twenty-minute job.
Step four: fixed governance
Headcount for MLRO, deputy, policy, QA, training, and audit support. In a small firm these are fractions of roles rather than whole ones, and saying so explicitly is better than pretending the function is free.
Step five: technology and data
Licence, plus implementation amortised over the contract term, plus data feeds, plus the internal engineering allocation. Amortising implementation matters: a three-year deal with heavy year-one professional services looks very different in year one than averaged.
The three metrics worth tracking
Once the model exists, three derived figures tell you more than the total ever will.
- Cost per alert disposed. Total alert-handling cost divided by alerts closed. Track it monthly. If it rises while volume is flat, your tuning has drifted or your mix has shifted toward harder cases.
- Cost per customer onboarded. Total onboarding cost divided by customers successfully onboarded — successfully, so abandonment correctly inflates it. This is the number your commercial colleagues understand.
- Compliance cost as a share of revenue. Crude, but it is the figure a board will ask for, so calculate it yourself before someone else calculates it badly.
Tracked over time, these three turn compliance from a cost centre that only ever grows into a function with a demonstrable efficiency curve. That is a materially different conversation.
Build versus buy, honestly
The build case usually rests on licence avoidance. It rarely survives contact with the full model, because building means owning five things the licence quietly included: the data feeds and their contractual terms, list-update latency, model documentation an examiner will ask for, the tuning function, and an audit trail that stands up under review.
Build tends to make sense where monitoring logic is genuinely idiosyncratic to a product no vendor serves, and where engineering capacity is already in place. It tends not to make sense for sanctions screening, where the data licensing and update-latency obligations dominate and are largely non-negotiable.
The honest middle path — buy the screening and monitoring engine, build the orchestration and case management around it — is what most mature programmes converge on. See how to choose transaction monitoring software for the evaluation criteria that matter once you have decided to buy.
What to do with the number
A model built this way does three jobs a vendor quote cannot. It lets you show the board which cost line moves when volume grows, so growth conversations stop being a surprise. It lets you price a tuning project against the analyst-hours it returns. And when an examiner asks whether your programme is adequately resourced, it lets you answer with arithmetic rather than assertion.
Start with alert cost. It is the largest variable line in most programmes, the easiest to measure from data you already hold, and the one where improvement is fastest.
Related reading: the cost of AML non-compliance covers the other side of this equation — what happens when the programme is under-resourced.
What the Model Does Not Capture
Three costs sit outside the five centres and are routinely left out of the budget, which is why programmes so often look cheaper on paper than they turn out to be.
The cost of friction on good customers
Every false positive that reaches a customer — a held payment, a request for documents already provided, an account restriction pending review — carries a commercial cost that never appears in a compliance line. In a retail or payments business this is frequently larger than the analyst time spent on the alert itself. It is worth estimating even crudely, because it changes the economics of tuning: a threshold change that removes ten thousand alerts a year is saving analyst hours and avoiding ten thousand customer interruptions.
Regulatory change
Every material change in obligation — a new jurisdiction, an amended notice, a new product in scope — consumes policy, engineering, testing and training effort. Firms operating in several regimes should treat this as a standing annual allocation rather than a series of surprises. A programme with no change budget absorbs the work by deferring something else, usually testing.
Turnover and the competence curve
Alert investigation quality is experience-dependent. A team with high turnover pays twice: once in recruitment and onboarding, and again in the months during which a new analyst disposes of cases more slowly and less accurately. Where turnover is high, the effective cost per alert is materially above the figure the model produces from average handling time.
Know What Your Programme Actually Costs
One Constellation attacks the largest variable line in most AML budgets — alert handling — through tuned monitoring, automated triage and straight-through onboarding.
