The Budget Was Already Spent: Where Financial Crime Technology Money Actually Goes in 2026


There is a moment in every January planning round when the financial crime technology budget stops being a number and becomes a negotiation. The headline figure arrives with a percentage increase attached and a sentence about the institution's commitment to fighting economic crime, and for a short period the function believes it has capacity to do something new. Then the commitments are laid against it: contracted licence uplifts, data subscriptions indexed to volume or inflation, remediation work already promised to a supervisor, cloud consumption that grew faster than anyone modelled, and the support cost of platforms bought three planning cycles ago. What remains is the real budget, and it bears little resemblance to the one announced.
The gap between the headline and the residual is the least discussed fact in this market. Vendors build pipeline against the headline, boards approve strategy against it, and programme plans are written to it. The people holding the cost centre work with the residual, and are often the only ones who know how small it is. Much of what later reads as indecision, deferred procurement or an abandoned business case is simply a budget allocated before the year began.
The argument here is that financial crime technology spend in 2026 should be read as three distinct pools rather than one line: the cost of keeping the existing estate alive, the cost of obligations already entered into, and a genuinely discretionary residual that is smaller than almost anyone outside the function assumes. Reading the budget that way changes what a firm buys, how it negotiates, and whether the phrase "we have funded artificial intelligence this year" means anything at all.
Regulatory and Market Context
Nothing in the rulebook obliges a firm to spend a particular amount on financial crime technology. What the regime does is generate cost on a timetable the firm does not control. The Financial Conduct Authority's financial crime guide sets an expectation of effective systems and controls rather than merely present ones, and effectiveness findings arrive with remediation commitments that must be funded from somewhere. Operational resilience requirements drive investment in mapping, testing and third party oversight, and the Digital Operational Resilience Act has made the register of information and communication technology arrangements, exit planning and testing a recurring cost line rather than a one-off project. The European Union's anti-money laundering package and the arrival of the Anti-Money Laundering Authority push firms with cross-border footprints towards harmonisation work whose cost lands in the same cost centre as detection.
The commercial environment compounds this. Data is the part of the stack that has repriced hardest. Sanctions and politically exposed person lists, corporate registry and ownership data, adverse media feeds, device and identity signals and payee verification services are all licensed rather than owned, and most are priced against volumes that rise with payment growth rather than with the compliance budget. Cloud consumption behaves the same way. A firm can hold headcount flat, sign no new contracts, and still face a materially higher bill than in the previous January, purely because it processed more payments and screened more names. That is how a nominal increase becomes a real reduction, and it operates quietly.
What the Data Is Showing
The first pattern in TrustSphere's proprietary engagement data, drawn from budget and estate reviews conducted with institutions across retail, commercial and payments businesses, concerns how much of the year is committed before it starts. When we decompose a financial crime technology budget into contracted obligations, run costs that cannot be switched off without an executive decision, and genuinely discretionary spend, the discretionary pool is consistently a small minority of the headline. In several reviews it was small enough that a single unplanned remediation commitment or one adverse data repricing would have consumed it entirely. Firms are rarely surprised by the direction of that finding, and frequently surprised by the magnitude, because nobody had previously drawn the line in a single view.
The second pattern concerns the split between keeping the estate alive and building anything new. Across the engagements where we have reconstructed it, the majority of financial crime technology spend goes to running, supporting, patching, upgrading, integrating and tuning systems the institution already owns. The proportion is higher where platform estates are long-lived and legacy monitoring engines have accumulated, and higher again where an acquisition left duplicate capability nobody has been funded to retire. The consequence is that much of the increase a board approves in the name of new capability is absorbed by maintaining capability bought years ago, and the reporting rarely shows it.
The third pattern is a genuine shift in where discretionary money goes when it is spent. For most of the last decade the marginal pound went to detection: a better monitoring engine, a better screening algorithm, a new scoring model. In the budgets we have reviewed over the past two planning cycles it increasingly goes to the quality of the customer, counterparty and payment data that detection depends on, to orchestration, meaning the layer that routes a case and makes the estate behave as one system rather than several, and to investigation productivity, the tooling that reduces the handling time of the person working the alert. The reallocation is rational. Detection quality is now constrained more by the data going into the engine and the time taken to dispose of what comes out than by the engine itself.
The fourth pattern concerns artificial intelligence line items, and it is the one most often misread from outside. In the majority of the budgets we have examined that carry a visible AI allocation, the allocation is not incremental money. It is a reallocation from an existing line, most often a deferred platform upgrade, a postponed tuning programme, a reduced professional services envelope or headcount held vacant. The institution has not increased its spend; it has changed what the existing spend buys. That matters when the AI investment underdelivers, because there is no fallback: the thing defunded to pay for it is still not funded, and the year has gone. We now treat an unexplained AI line as a question rather than a fact, and the question is which line shrank.
Implications for Financial Institutions
The first implication is that the budget should be presented in three pools, every year, to the same audience: contracted and unavoidable obligations, run cost of the existing estate, and discretionary capacity. Each needs a named owner and a forward view of at least three years, because the obligations that crush next January's discretionary pool were signed in this one. A board that sees three pools asks the better question, which is not how much the firm spends but how much of it the firm can still direct.
The second implication is that run cost must be attributed to individual platforms and published. Most institutions can state a total run cost for the financial crime estate and cannot state the run cost of any single component within it. Without that attribution there is no rational retirement decision, no basis on which to challenge a maintenance uplift, and no answer to the question that follows a refused business case: what would we stop doing to fund this. The exercise is unglamorous and usually the highest value analytical work available in a constrained year.
The third implication is that data quality and orchestration should be funded explicitly rather than smuggled into detection business cases. Both are difficult to sell because neither produces a demonstration, and nobody has ever been promoted for improving the completeness of a counterparty reference field. The way to make them fundable is to express them as the constraint they are: state which detection outcomes are unachievable because of a named data defect, quantify the alert volume attributable to poor matching or duplicated records, and present the work as the enabling condition for capability the institution has already bought and cannot fully use. That converts a cost into the unlock for a sunk investment, a much easier argument in a year where new money is scarce.
The fourth implication concerns AI line items, and it is a governance point rather than a technology one. Any AI allocation should be accompanied in the budget paper by a plain statement of what was reduced or deferred to create it and what the consequence of that deferral is. Institutions that do this make better decisions, not because they refuse AI investment but because they stop treating it as free.
The fifth implication belongs to procurement. A buyer entering a negotiation in 2028 is not buying a product in isolation; it is buying a future claim on a discretionary pool that is already thin. The terms that decide whether the purchase is affordable in year three are the uplift mechanism, the volume corridor, the data licensing terms and the treatment of consumption growth, not the year one price. Price the contract across the full term against realistic volume growth, cap indexation, negotiate the data element separately where the vendor is reselling somebody else's list or registry, and secure the right to reduce scope without penalty. A vendor that will not discuss uplift caps is telling the buyer how the next three January conversations will go.
Conclusion
The honest description of a financial crime technology budget in 2026 is that it is mostly a maintenance settlement with a small strategic fringe attached. That is not a failure of ambition or advocacy but the arithmetic of an estate accumulated over two decades, licensed data priced against growing volumes, and an obligation stream the firm does not control. Functions that present the budget as though the whole figure were available are setting themselves up to explain, in October, why nothing on the strategy was delivered.
The functions that do best with a constrained residual share one habit. They know what the estate costs to run, line by line, and can therefore fund something new by stopping something old rather than by waiting for an increase. That capability is built from unfashionable work: cost attribution, contract inventory, a three-year view of committed obligations and an honest register of what was deferred to pay for whatever is fashionable this year. It is easier to do in January than in the middle of a cost programme.
Suggested Next Steps
Rebuild the financial crime technology budget as three explicit pools, covering contracted and unavoidable obligations, run cost of the existing estate and genuinely discretionary capacity, with a named owner and a three-year forward view for each, and present all three to the same governance forum.
Attribute run cost to individual platforms and services rather than reporting a single estate total, and use the attribution to identify duplicate capability that no business case has ever been funded to retire.
Fund data quality and orchestration as named line items justified by the detection outcomes they unlock, quantifying the alert volume and investigation time currently attributable to matching, duplication and reference data defects.
Require every artificial intelligence allocation in the budget paper to state what was deferred or reduced to create it, and negotiate all new contracts on full-term cost, with capped indexation, an agreed volume corridor, separately priced data licensing and a right to reduce scope.
Sources: Financial Conduct Authority financial crime guide and expectations on the effectiveness of systems and controls; Financial Conduct Authority and Prudential Regulation Authority operational resilience policy on important business services, impact tolerances and mapping; Digital Operational Resilience Act requirements on the register of information and communication technology arrangements, testing and exit planning; European Banking Authority guidelines on outsourcing arrangements and on money laundering and terrorist financing risk factors; European Union anti-money laundering package and the establishment of the Anti-Money Laundering Authority; His Majesty's Treasury economic crime plan and associated policy statements; Bank for International Settlements publications on technology adoption and operational risk in banking; Joint Money Laundering Steering Group guidance on systems and controls; Wolfsberg Group statements on effectiveness in financial crime programmes; TrustSphere Risk Index, April 2026.
Companion vendor assessment: today's TrustSphere Risk Index post assesses Finastra against this problem. Read it at www.trustsphere.ai
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments