The Asian Bankers Association (ABA) and Fintelekt Advisory Services, an ABA Knowledge Partner, held a very informative webinar entitled "Balancing AML Compliance and Data Privacy: Navigating Competing Regulatory Expectations" on 15th July 2026.
The webinar was moderated by Shirish Pathak, Managing Director, Fintelekt Advisory Services with panelists Sheila Ricca Dioso, Chief Compliance Officer, RCBC Philippines; Thilani Punyawansa, Chief Compliance Officer, DFCC Bank PLC, Sri Lanka; and Joseph Muvombo, Head of Training and Professional Development, Compliance Institute of Zambia.
The one-hour session attracted participation from close to 900 compliance professionals, AML officers, risk managers, data privacy practitioners and banking executives from 43 countries, generating active engagement through live polling and audience questions.
Highlights of the discussions covered the following:
(1) Competing or Complementary?
Financial institutions today operate within an increasingly complex regulatory environment. On one hand, AML/CFT frameworks require institutions to collect, analyse and monitor significant amounts of customer information to identify suspicious activity and manage financial crime risks. On the other hand, data protection laws emphasise purpose limitation, proportionality and data minimisation, creating operational challenges for institutions attempting to comply with both obligations simultaneously.
A central theme that emerged throughout the discussion was that AML compliance and data privacy should not be viewed as competing objectives. Rather, both frameworks ultimately seek to protect customers, preserve trust in the financial system and support sound governance. The challenge lies less in conflicting legislation and more in establishing governance frameworks that enable institutions to meet both sets of requirements effectively.
(2) Regulatory Developments and Supervisory Expectations
The Philippines has recently introduced legislative reforms that strengthen cooperation between financial institutions in combating fraud and money laundering while providing greater clarity regarding the lawful sharing of information. These developments demonstrate an increasingly coordinated approach between AML and privacy regulators.
In Zambia and Sri Lanka, participants noted that data protection frameworks are still evolving, with institutions continuing to navigate practical implementation challenges, particularly around cross-border data transfers, regulatory interpretation and supervisory expectations.
Despite differences across jurisdictions, the panel agreed that regulators are increasingly recognising the importance of balancing financial crime prevention with the protection of personal information. Continued dialogue between regulators and industry was identified as essential to achieving greater consistency and providing clearer operational guidance.
(3) Information Sharing and Public-Private Collaboration
The discussion emphasised that timely information sharing remains fundamental to effective financial crime prevention. Excessive restrictions on the movement of information could inadvertently weaken AML controls by delaying investigations or limiting institutions' ability to identify suspicious activity across multiple entities. At the same time, data protection laws should not be viewed as barriers to collaboration, but rather as mechanisms that promote responsible, purpose-driven information sharing while discouraging unnecessary or uncontrolled disclosure of customer information.
Public-private partnerships and collaboration between financial institutions were recognised as increasingly important components of modern AML frameworks, particularly in combating rapidly evolving fraud and financial crime typologies.
(4) Building Customer Trust
As public awareness of data privacy continues to increase, customers are becoming more conscious of how financial institutions collect, use and retain their personal information. Frontline staff play a critical role in addressing customer concerns by clearly explaining why information is required, how it supports regulatory obligations and how customer data will be protected. Transparency and effective communication were identified as essential in building customer confidence while reducing resistance during customer onboarding and ongoing due diligence processes.
The discussion highlighted that customer trust should be viewed as an important outcome of both effective AML compliance and robust data privacy practices.
(5) Artificial Intelligence and Responsible Innovation
The increasing adoption of artificial intelligence and advanced analytics within AML programmes formed another important area of discussion. AI has significant potential to strengthen transaction monitoring, behavioural analytics and financial crime detection. However, effective AI deployment depends upon high-quality data, robust governance frameworks and appropriate safeguards around privacy and security.
Emerging challenges associated with data localisation requirements, cross-border data availability and explainability of AI-driven decision making were highlighted. Institutions need to adopt responsible AI practices that balance innovation with accountability, transparency and ethical use of customer information.
(6) Governance as the Common Foundation
Rather than managing AML compliance and data privacy as separate programmes, panelists advocated for a unified governance framework involving compliance, risk management, legal, information technology, cybersecurity, audit and data protection teams.
Key governance priorities include:
- Developing integrated policies that address both AML and data protection requirements.
- Establishing robust information security controls and secure data management practices.
- Providing continuous training for frontline staff and compliance personnel.
- Strengthening cross-functional collaboration across business units.
- Embedding privacy considerations into AML processes through governance-by-design.
- Institutions with strong governance frameworks are better positioned to meet regulatory expectations while maintaining operational effectiveness.
(7) Looking Ahead
Several common priorities emerged, including greater international harmonisation of regulatory standards, trusted mechanisms for customer information sharing, wider adoption of common KYC infrastructure, stronger public-private collaboration and increased use of AI to combat increasingly sophisticated financial crime.
While approaches may differ across jurisdictions, the discussion reinforced the need for globally coordinated solutions that enable institutions to respond effectively to evolving criminal threats while maintaining appropriate safeguards for personal information.
As financial institutions continue to modernise their compliance frameworks, success will increasingly depend on their ability to combine effective financial crime controls with responsible data governance, transparent customer communication and ethical use of technology.
The video recording of the session is available at the ABA YouTube channel.