Aml Consortium Data Monopoly Risk

AML Consortium Data Monopoly Risks

Introduction

An AML Consortium Data Monopoly arises where banks, fintech companies, payment institutions, insurers, credit institutions, or other regulated entities create a common platform or consortium to collect, pool, analyse, and distribute information for anti-money laundering (AML), counter-terrorist-financing (CFT), sanctions screening, fraud detection, or suspicious-transaction monitoring.

Such cooperation can have legitimate public-interest objectives. AML information sharing can improve detection of financial crime, reduce duplicated compliance costs, and address information asymmetry. Current regulatory developments expressly contemplate such information sharing—for example, UK legislation permits AML-regulated firms to share relevant information for preventing, detecting, or investigating economic crime, while EU authorities are developing guidance on AML information-sharing partnerships.

The competition-law problem arises when a consortium moves from necessary compliance cooperation to control over an indispensable data infrastructure. The resulting risks include:

  • exclusion of non-members;
  • collective control over commercially valuable customer information;
  • discriminatory access;
  • excessive data concentration;
  • foreclosure of competing AML providers;
  • coordinated behaviour between participating competitors;
  • creation of common customer-risk profiles that competitors cannot independently reproduce;
  • refusal to provide data on reasonable terms;
  • exploitation of a dominant data intermediary; and
  • using AML information as a mechanism for broader commercial coordination.

The OECD's 2026 work confirms that information exchange can itself become a competition concern, particularly where data intermediaries or digital systems make competitor information more frequent, granular, automated, and actionable.

1. Meaning of AML Consortium Data Monopoly

An AML consortium generally has several participants contributing information to a common system.

For example:

Bank A + Bank B + Bank C + Fintech D → AML Data Consortium → Shared Risk Database → AML Screening/Scoring

The consortium may aggregate:

  • customer identification information;
  • beneficial ownership information;
  • suspicious transaction indicators;
  • sanctions-screening results;
  • transaction patterns;
  • fraud indicators;
  • account-risk information;
  • adverse-media information;
  • high-risk jurisdiction indicators;
  • corporate ownership relationships;
  • cryptocurrency transaction information;
  • behavioural risk indicators; and
  • historical suspicious-activity information.

The competition problem becomes particularly serious where the consortium becomes the only commercially meaningful repository of particular AML-related information.

A data consortium can therefore evolve from:

compliance infrastructure

into:

essential data infrastructure

and eventually:

a gatekeeper controlling access to an important competitive input.

2. Why AML Data Can Create Market Power

Data has several characteristics that can make a consortium powerful.

A. Network effects

The more financial institutions participating in the consortium, the more information the consortium possesses.

More data → better detection → more valuable service → more participants → still more data.

This creates a self-reinforcing cycle.

B. Data accumulation

Historical AML information can be extremely difficult for a new entrant to reproduce.

A new AML provider may have sophisticated software but lack:

  • historical transaction information;
  • cross-institutional patterns;
  • historical risk indicators;
  • network relationships; and
  • accumulated false-positive/false-negative information.

C. Switching costs

Financial institutions may become technologically dependent upon the consortium's:

  • APIs;
  • risk scores;
  • databases;
  • screening tools;
  • customer identifiers;
  • reporting systems; and
  • compliance workflows.

Switching therefore becomes expensive.

D. Information asymmetry

A consortium may know considerably more about participating institutions' customers and transactions than a competing AML service provider.

This can create a substantial competitive advantage.

3. Competition-Law Theories of Harm

A. Cartel and information-exchange risk

Where competing banks contribute commercially sensitive information to the same consortium, the arrangement may reduce strategic uncertainty between competitors.

The information could reveal:

  • customer acquisition strategies;
  • transaction volumes;
  • geographic expansion;
  • risk appetite;
  • customer categories;
  • pricing-related information;
  • lending activity;
  • merchant relationships; or
  • future business strategies.

The AML objective does not automatically immunise unrelated competitive information sharing.

The CJEU's Portuguese Banks judgment is particularly important because it confirmed that an exchange of confidential strategic information between competing banks can constitute a restriction of competition by object.

4. Data Pooling and Competition

Data pooling is not inherently unlawful.

EU competition guidance recognises that data pools can have legitimate procompetitive effects where they address information asymmetry and generate consumer benefits, particularly where commercially sensitive information is:

  • aggregated;
  • historical;
  • necessary;
  • proportionate;
  • access-controlled; and
  • exchanged at an appropriate frequency. 

Therefore, the legal distinction is not:

AML data sharing = unlawful

but rather:

necessary AML cooperation versus unnecessary or competitively harmful data concentration.

5. Exclusion of Non-Members

A major monopoly risk occurs when the consortium refuses access to competing institutions.

Suppose five major banks establish the only effective AML database and then refuse access to:

  • smaller banks;
  • fintechs;
  • payment institutions;
  • foreign entrants;
  • independent AML technology providers.

The consortium could potentially become an input bottleneck.

The legal analysis may involve:

  • refusal to deal;
  • discriminatory access;
  • exclusionary abuse;
  • essential-facility-type theories;
  • tying;
  • leveraging;
  • interoperability restrictions; and
  • foreclosure of downstream competitors.

The critical question would be whether the data resource is genuinely indispensable and whether alternative sources exist.

6. Discriminatory Access

Even where access is technically available, discrimination may produce monopoly effects.

For example:

Consortium memberAccess
Founding banksReal-time access
New membersDelayed access
Non-member fintechsLimited API
Independent AML providersNo access
Smaller institutionsHigh fees

This can disadvantage smaller competitors.

Competition authorities may examine:

  • price discrimination;
  • discriminatory technical standards;
  • API restrictions;
  • different data quality;
  • latency differences;
  • eligibility conditions; and
  • membership requirements.

7. AML Consortium as a Data Gatekeeper

A consortium can become a data gatekeeper when financial institutions cannot realistically compete without access to the consortium's information.

This is particularly problematic where:

  1. the consortium covers most major market participants;
  2. participation produces substantial network effects;
  3. the database contains unique historical information;
  4. alternative data sources are insufficient;
  5. switching is technically difficult;
  6. the consortium controls API access; and
  7. downstream AML competitors depend upon its data.

The existence of a large database alone, however, does not establish dominance. Market definition, substitutability, access alternatives, barriers to entry, and actual competitive effects remain important.

8. Six Important Case Laws

1. Banco BPN v BIC Português and Others — CJEU, Case C-298/22 (2024)

This is one of the most directly relevant authorities.

Fourteen Portuguese banks exchanged information relating to:

  • credit spreads;
  • risk variables;
  • production volumes; and
  • current and future commercial conditions.

The CJEU confirmed that a comprehensive exchange of competitively sensitive information between competing credit institutions can constitute a restriction of competition by object, particularly in concentrated markets with barriers to entry.

AML relevance

An AML consortium involving competing banks should therefore ensure that its data architecture does not become a vehicle for exchanging unrelated strategic information.

2. T-Mobile Netherlands and Others — C-8/08

The CJEU recognised that even a single exchange of information can potentially remove uncertainty regarding competitors' future conduct.

The important principle is that frequency alone does not determine legality.

AML relevance

A consortium cannot necessarily argue:

"We only share the information occasionally."

The substantive character and competitive sensitivity of the information remain important.

3. Todd v Exxon Corp., 275 F.3d 191 (2d Cir. 2001)

The Second Circuit considered an alleged information exchange involving major petroleum companies.

The exchanged information concerned employee compensation and included current and future salary information.

The court emphasised characteristics such as:

  • specificity;
  • timing;
  • whether information was publicly available; and
  • the market's susceptibility to coordination.

The complaint was sufficient to proceed under Section 1 of the Sherman Act.

AML relevance

The case demonstrates why an AML consortium should distinguish:

aggregated AML-risk statistics

from:

individualised, current, commercially sensitive information concerning competitors.

4. United States v. Agri Stats — U.S. Department of Justice, 2026

The DOJ's 2026 Agri Stats enforcement concerned a data-sharing intermediary that collected detailed information from competing meat processors and redistributed granular information concerning:

  • prices;
  • output;
  • costs; and
  • labour data.

The DOJ alleged that the arrangement enabled competitors to obtain extensive visibility into one another's operations. The proposed settlement required major restrictions on the distribution of non-public pricing and company/facility-level information and sought broader access to much of the information on reasonable, non-discriminatory terms.

AML relevance

This is particularly instructive for a consortium model because it demonstrates the competition-law danger of a third-party data intermediary becoming the mechanism through which competitors acquire detailed information about one another.

5. CMA Nortriptyline — Case 50507.2 (2020)

The UK Competition and Markets Authority addressed exchanges involving commercially sensitive information concerning:

  • prices;
  • volumes;
  • supply timing; and
  • market-entry plans.

The CMA considered the exchange capable of reducing strategic uncertainty and restricting competition.

AML relevance

If AML consortium information includes data that enables participants to anticipate competitors' commercial behaviour, the consortium may move beyond legitimate compliance cooperation.

6. Hugo Boss / Kaufmann and Hugo Boss / Ginsborg — Danish Competition Council (2020)

Retailers exchanged information concerning future:

  • prices;
  • discounts; and
  • quantities.

The Danish authority considered that the information reduced uncertainty concerning future sales and facilitated coordination.

AML relevance

The case illustrates a broader principle: competitor information becomes more problematic as it becomes current, forward-looking, granular, and actionable.

9. Additional Relevant Authority: M. Venugopal Reddy v TransUnion CIBIL

Indian competition law provides an especially useful illustration in the credit-information context.

In M. Venugopal Reddy v TransUnion CIBIL Ltd., CCI examined the market for services provided by credit information companies and recognised the distinctive nature of credit-information services. The case concerned the competitive significance of credit-information databases and the services supplied by credit information companies.

AML relevance

AML consortium databases can similarly become economically significant because the underlying information may constitute an important input for downstream financial services.

This raises questions concerning:

  • access;
  • interoperability;
  • data portability;
  • exclusivity;
  • discriminatory conditions; and
  • dominance.

10. Essential-Facility-Type Risk

An AML consortium could potentially attract an essential-facility-type argument where its database is:

  1. genuinely indispensable;
  2. controlled by a dominant entity or consortium;
  3. practically impossible to reproduce;
  4. unavailable through reasonable alternatives; and
  5. capable of supporting competition in a downstream market.

However, courts and competition authorities generally treat essential-facility theories cautiously.

A mere statement that:

"The consortium has a very large database"

would not ordinarily establish an essential facility.

There must be evidence concerning indispensability and competitive foreclosure.

11. Data Hoarding

Data hoarding occurs where a consortium accumulates information but prevents others from obtaining comparable datasets.

For example:

AML Consortium

→ 95% of participating banks
→ millions of customer profiles
→ years of transaction patterns
→ proprietary risk scores
→ exclusive historical database
→ no meaningful access for competing providers.

The result can be a substantial data-entry barrier.

Data collaboration scholarship similarly identifies the dual character of data pooling: it can generate efficiencies while also potentially enabling collusion, exclusion, or increased market power.

12. Tying and Bundling

A dominant AML consortium might require:

"If you want access to the AML database, you must also purchase our AML software."

This creates a potential tying/bundling issue.

The analysis would examine:

  • whether the products are distinct;
  • whether the consortium has dominance in the tying product;
  • whether customers are coerced;
  • whether competition in the tied market is foreclosed; and
  • whether legitimate efficiencies justify the arrangement.

13. Algorithmic AML Risk Scoring

Modern AML consortia increasingly use algorithms to transform shared information into risk scores.

For example:

Shared data → algorithm → customer risk score → bank action

The competition concern increases if the algorithm:

  • is jointly controlled by competitors;
  • uses commercially sensitive data;
  • produces uniform commercial recommendations;
  • prevents independent model development;
  • restricts access to training data; or
  • causes participating institutions to behave similarly.

Thus, the competition issue may shift from simple data sharing to algorithm-mediated coordination.

The OECD has specifically noted that platforms, data intermediaries, and algorithms can make information exchanges more frequent, granular, automated, and actionable.

14. Privacy and Competition-Law Interaction

AML databases also contain highly sensitive personal and financial information.

Consequently, the consortium must simultaneously consider:

  • AML legislation;
  • competition law;
  • privacy/data-protection law;
  • banking secrecy;
  • cybersecurity;
  • consumer protection;
  • confidentiality obligations; and
  • sectoral financial regulation.

Importantly, privacy compliance does not automatically resolve competition concerns, and competition compliance does not eliminate privacy obligations.

The EU's current work on AML information-sharing partnerships expressly reflects the need to reconcile financial-crime information sharing with personal-data protection.

15. Legitimate AML Consortium vs Data Monopoly

FeatureLegitimate consortiumMonopoly-risk consortium
PurposeAML/CFT complianceAML + commercial intelligence
DataNecessary AML indicatorsBroad commercial datasets
InformationAggregated/minimisedIndividualised/granular
TimingHistorical/necessaryCurrent/future
AccessObjective criteriaClosed membership
PricingReasonableDiscriminatory
GovernanceIndependent controlsMember-controlled
APIInteroperableProprietary lock-in
CompetitionPreservedCompetitors foreclosed
AlgorithmAML detectionCommercial coordination
Data retentionPurpose-limitedIndefinite accumulation

16. Competition-Compliant Safeguards

An AML consortium should consider the following safeguards.

1. Purpose limitation

Information should be collected and used only for legitimate AML/CFT purposes.

2. Data minimisation

Only information genuinely necessary for AML objectives should be shared.

3. Aggregation

Where possible, use aggregated rather than institution-specific data.

4. Historical information

Avoid unnecessary sharing of current or forward-looking commercial information.

5. Independent governance

The consortium should have independent compliance and competition-law governance rather than allowing participating competitors unrestricted control.

6. Access neutrality

Eligibility requirements should be transparent and objectively justified.

7. Non-discriminatory access

Comparable institutions should receive comparable access on reasonable terms where access is commercially offered.

8. Firewalls

Separate AML information from commercially sensitive competitive information.

9. API interoperability

Avoid unnecessary technical restrictions designed to prevent competing AML providers from interoperating.

10. Audit mechanisms

Regularly audit:

  • data fields;
  • access logs;
  • algorithms;
  • membership rules;
  • pricing;
  • API access;
  • data-retention periods; and
  • competitive effects.

17. A Useful Legal Test

Competition authorities can examine an AML consortium through five sequential questions:

1. What is the legitimate AML objective?

↓

2. What information is actually necessary to achieve that objective?

↓

3. Does the consortium control a unique or difficult-to-replicate dataset?

↓

4. Does that control exclude, disadvantage, or discipline competitors?

↓

5. Does the arrangement facilitate coordination between participating competitors?

The greater the divergence between the legitimate AML purpose and the commercial use of the database, the greater the potential competition concern.

18. Key Competition-Law Issues

The principal legal issues can therefore be summarised as:

  1. Horizontal information exchange — competitors may obtain strategically sensitive information from one another.
  2. Collective dominance — several major institutions may collectively control an indispensable data resource.
  3. Refusal of access — non-members may be excluded from an important AML data input.
  4. Discriminatory access — smaller competitors may receive inferior data or technical access.
  5. Data hoarding — accumulated historical information may create barriers to entry.
  6. Foreclosure — competing AML technology providers may be unable to reproduce the consortium's service.
  7. Tying — database access may be conditioned on purchasing other services.
  8. Algorithmic coordination — shared datasets may produce similar competitive decisions.
  9. Excessive data concentration — one consortium may become a market-wide data gatekeeper.
  10. Privacy/competition intersection — legitimate AML data sharing must remain proportionate and purpose-specific.

Conclusion

AML consortium data sharing is not inherently anti-competitive. Indeed, properly structured information sharing can substantially improve AML/CFT enforcement and reduce information asymmetry.

The competition-law risk emerges when a consortium transforms from a limited compliance mechanism into a market-wide data infrastructure controlled by competitors.

The most important warning signs are:

unique data + competitor participation + granular information + exclusionary access + network effects + commercial use = heightened competition risk.

The Portuguese Banks case demonstrates that information exchange between competing financial institutions can itself constitute a competition restriction. Todd v Exxon illustrates the importance of specificity, timing, and confidentiality of exchanged information. Agri Stats demonstrates the risks associated with a third-party data intermediary distributing granular information among competitors. Together with the Danish, UK, and other information-exchange authorities, these cases provide a framework for analysing AML consortium structures.

LEAVE A COMMENT