The Meter Is Running: Financial Crime Technology Commercial Models in 2026 and What They Do to the Buyer


For most of the past decade the commercial question in financial crime technology was straightforward enough to delegate. Screening was priced per named user, monitoring against transaction volume bands, onboarding against cases opened, case management per investigator seat. Buyers argued about discount, term and uplift caps. The unit of charge itself was rarely contested, because it was intuitive and the number in year three was knowable in year one.
That has changed, and faster than most procurement functions have adapted. Consumption-based pricing, API-call-based pricing, per-alert, per-decision and per-enquiry units, and a growing minority of outcome-linked structures now appear in the majority of proposals TrustSphere reviews. The headline rate has become the least interesting figure in the commercial schedule. The interesting figure is the definition of the thing being counted, and that definition is normally drafted by the vendor, in a schedule the buyer's procurement team reads last and its risk function never reads at all.
The timing compounds the problem. The shift has arrived at precisely the moment when vendors have begun to pass through the cost of AI inference as a separate and explicitly variable line, on the reasonable basis that it is a genuine marginal cost rather than an accounting fiction. The buyer is therefore being asked to accept variable pricing on a variable neither party can forecast, in a category where it cannot reduce demand without creating a supervisory question.
Regulatory and Market Context
Supervisors do not price technology, but they do constrain the buyer's ability to respond to price, and that constraint is the whole negotiation. Screening a payment against a sanctions list is not discretionary. Neither is rescreening a customer book after a list update, reviewing an alert that has been raised, or retaining the record of the decision. In almost every other consumption market a customer facing an unexpected bill can moderate demand. In financial crime, demand is set by payment flows, the customer base and the obligations, and a firm that cut its screening calls in response to a unit price would be making a risk decision disguised as a cost decision. Vendors know this, which is why the consumption model migrated into this category at all.
The market forces pushing in the same direction are ordinary rather than sinister. Automation is reducing the number of analysts a platform must support, so a per-seat model in a category that is automating is a shrinking model. Vendors under private equity ownership need expansion revenue that does not depend on new logos, and consumption pricing supplies it mechanically. The resilience frameworks add a twist: the Digital Operational Resilience Act, European Banking Authority outsourcing guidance and United Kingdom operational resilience policy all expect firms to document their material third party arrangements, including exit and continuity planning, yet a consumption-priced contract makes committed volumes, cost of exit and cost of parallel running much harder to state with confidence. Firms are asked to evidence control over an arrangement whose economics are, by design, undetermined at signature.
What the Data Is Showing
TrustSphere's engagement data on commercial terms, drawn from the selections, renewals and contract reviews the firm has supported, shows the shift clearly. Fixed-fee and per-seat structures are now a minority of proposals in screening, identity and onboarding, and are increasingly rare in anything with an API-delivered component. More striking is the divergence between business case and outturn. On consumption-priced arrangements reviewed after their first full year, spend against the modelled figure varies widely in both directions, and by more than anything we observed under the volume-band contracts these models replaced. The point is not that consumption pricing is more expensive, because sometimes it is cheaper. It is that the cost is not forecastable at signature, which is awkward for a regulated firm that must set a budget and defend it.
The second and more important finding is that commercial disputes in this category are almost never about the rate. They are about what counts. The recurring flashpoints are consistent enough to list in advance: retried calls after a timeout, the same party screened twice because two internal systems each call the service, batch rescreening triggered by a list refresh rather than by any customer action, alerts closed automatically by a rule before a human sees them, cases reopened after quality assurance, traffic from test and disaster recovery environments, and enquiries on parties who turn out not to be customers. Every one is arguable both ways, and every one is worth more over a five-year term than the discount the buyer spent three months negotiating.
Per-alert and per-decision units deserve particular attention because they invert the incentives on both sides. A vendor paid per alert has no commercial reason to help the buyer tune the estate down, and while most vendors behave better than that model predicts, the buyer should not have to rely on it. The buyer, meanwhile, acquires a direct financial incentive to suppress alerts, which is exactly the incentive a supervisor would least like to see in the second line. The institutions that handle per-alert pricing well separate the commercial unit from the risk decision: the threshold is owned by the money laundering reporting officer and documented as a risk judgement, and the schedule is drafted so that a tuning change produces a windfall for neither party.
Outcome-linked and gain-share pricing performs worst of all in the data, not because the idea is unsound but because attribution defeats it. A structure that pays the vendor a share of fraud losses avoided, or of alert volume reduced, requires an agreed counterfactual, and there is no such thing. Losses fall because the vendor's model improved, because the firm changed its payment limits, because a mule network was disrupted by someone else, or because a large customer left. Of the gain-share arrangements TrustSphere has seen reach a second review point, most have been renegotiated to a fixed or hybrid structure, usually at the buyer's instigation once it discovers that the measurement dispute costs more management time than the mechanism saves. Where outcome pricing survives, the metric was narrow, mechanical and directly observable in the vendor's own system, and sat on top of a fixed floor rather than replacing it. Inference pass-through deserves a final word: the vendor chooses the model, the context size and the retrieval strategy, and each choice moves the buyer's bill. Very few contracts we have reviewed give the buyer any right of notice or price protection when the vendor changes the underlying model.
Implications for Financial Institutions
The first implication is that the unit definition is the contract. A rate schedule without a rigorous definition of the billable event is not a price, it is an intention. Buyers should require a closed list of what generates a charge, with named exclusions for retries, duplicate calls originating inside the buyer's own architecture, system-initiated rescreening, non-production environments, and any event the platform creates without a human or customer trigger. If the vendor will not enumerate exclusions, the buyer should assume the ambiguity has been priced in the vendor's favour, because it has.
The second is that per-transaction and per-enquiry pricing punishes exactly the institutions growing fastest, and produces no operating leverage at all. A firm whose payment volumes double sees its financial crime technology cost double, while the fixed cost of the compliance function it was supposed to be automating does not fall by anything like as much. Growing institutions should treat volume-linked pricing as a strategic question rather than a procurement one, and negotiate step-down tiers that bite at realistic growth rates. A tier that only becomes attractive at three times current volume is designed never to be reached.
The third is that unforecastable total cost of ownership needs structural mitigation rather than better forecasting. The instruments that work are collars rather than caps alone: a committed minimum that buys a materially better unit rate, an annual ceiling above which the rate falls sharply, a right to convert to a fixed structure at a defined point on defined mechanics, and a burst allowance for the spikes everyone knows are coming, such as a list update, a remediation exercise or an onboarding campaign. Buyers should also insist on usable billing transparency: exportable event-level data with enough attribution to reconcile the invoice against their own logs. An invoice that cannot be independently reconciled is not auditable, and in a regulated firm that is a control weakness as well as a commercial one.
The fourth is that outcome-linked pricing deserves real scepticism and, where used, should be confined to metrics the buyer can observe directly. Ask who owns the baseline, how it is refreshed, what happens when the firm changes its risk appetite mid-term, and what the dispute mechanism is. If the answer to any of those is that the parties will discuss it in good faith, the structure will end in a renegotiation conducted from a weaker position than the buyer holds today.
The fifth concerns the finance function, and it is the implication most often missed. Consumption pricing converts a predictable annual licence into a volatile operating expense, changing how the cost is budgeted, allocated to business lines and treated for planning purposes. It also changes the politics: a business line watching a monthly financial crime charge rise with its own growth will start asking questions about screening thresholds, and those questions must be routed to risk governance rather than answered in a cost review. Institutions should agree in advance, in writing, that unit economics never determine control coverage. That sounds obvious. It is not, once the meter is running and someone has to explain a variance.
Conclusion
The migration away from per-seat and simple per-transaction licensing is not a scandal and will not reverse. It reflects real changes in how these products are built and delivered, and in some cases it gives smaller institutions access to capability they could not previously afford. The problem is that the risk transfer embedded in the new models has been almost entirely one-directional, and buyers have continued to negotiate as though the rate were the exposure.
It is not. The exposure is definitional. A buyer who wins ten per cent on the unit price and loses the argument about whether a system-initiated rescreen is billable has lost the negotiation, and will not find out for eighteen months. The institutions that come out of this well will put a financial crime subject matter expert, not only a procurement lead, into the drafting of the commercial schedule, model three volume scenarios rather than one, reconcile invoices against their own event logs from the first month, and keep the threshold decision permanently outside the commercial conversation. One further point is worth holding alongside all of this: consolidation determines who you will be renegotiating these units with in three years, and it will not necessarily be the counterparty who signed.
Suggested Next Steps
Require every proposal with a variable component to define the billable event exhaustively, with named exclusions for retries, internally duplicated calls, system-initiated rescreening, non-production traffic and vendor-generated events, and treat refusal to enumerate exclusions as a pricing signal.
Model at least three volume scenarios for every consumption-priced arrangement, including a stress case covering a large list update, a remediation exercise and an acquisition, and negotiate collars, ceilings, burst allowances and a defined right to convert to a fixed structure.
Build invoice reconciliation into the implementation from day one, requiring event-level billing data matchable against the institution's own logs, and treat an unreconcilable invoice as a control deficiency.
Document formally that alert thresholds, screening scope and rescreening frequency are owned by risk governance and never adjusted for commercial reasons, and route business line challenges through that governance rather than through cost review.
Sources: Financial Conduct Authority and Prudential Regulation Authority operational resilience policy and supervisory publications on outsourcing and third party risk; European Union Digital Operational Resilience Act requirements on contractual content and exit strategies; European Banking Authority guidelines on outsourcing arrangements; Financial Action Task Force recommendations on risk based measures and record keeping; Wolfsberg Group statements on effectiveness; TrustSphere Risk Index, April 2026.
Companion vendor assessment: today's TrustSphere Risk Index post assesses Fenergo against this problem. Read it at www.trustsphere.ai
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments