AI in Compliance: Where RegTech Is Actually Working and Where It Quietly Isn't
- TrustSphere Network

- Jun 9
- 4 min read
Updated: Jul 2

The RegTech narrative of 'AI will transform compliance' has matured into a more nuanced picture. Some use cases are delivering real effectiveness gains; others have quietly underperformed and are being unwound behind closed doors. Cost overruns, explainability challenges, and disappointing effectiveness have taught the industry that AI is neither a silver bullet nor a failed technology — it is a set of tools that work well when deployed thoughtfully and poorly when deployed reflexively.
For Tier 1 banks, the strategic question is no longer whether to use AI in financial crime compliance — it is how to distinguish the genuinely high-value applications from the expensive experiments, and how to govern the resulting models responsibly. The winners have usually been those institutions that invested in data, governance, and measurement discipline before scaling their AI use cases; the losers are usually those that tried to do it the other way around.
Supervisors are watching closely, and they are no longer impressed by novelty alone. Effectiveness, explainability, and model governance are the benchmarks against which deployed AI is being judged. That insight is now shaping procurement decisions, vendor selection, and the shape of new model-risk frameworks across the industry.
Regulatory, Enforcement, and Market Context
The FCA, MAS, HKMA, and APRA have all published commentary on AI in financial crime compliance, stressing model risk management, explainability, and outcome monitoring. The BIS and FSB have issued similar messages at the international level. Regulators are specifically focused on how institutions test for drift, bias, and adversarial manipulation in production models, rather than on whether AI is being used at all.
The FATF has explicitly supported responsible use of technology to enhance AML effectiveness, and the Wolfsberg Group has published principles on effective transaction monitoring that implicitly endorse well-governed AI approaches. The Wolfsberg Group's work on effectiveness has been widely cited as the practical benchmark for how AI should be evaluated within a financial-crime programme.
Enforcement actions have not yet focused on AI-specific failures, but the direction of travel in supervisory communication suggests this is only a matter of time. Institutions that can evidence explicit, continuous testing of these risks will find far more latitude in deploying new AI capabilities than institutions relying on pre-deployment validation alone.
What the Data Is Showing
Internal benchmarks from several large institutions suggest that AI-assisted alert triage can reduce investigator time per case by 30–50% without loss of detection quality. Conversely, pilots of AI-driven alert generation often produce modest or no net effectiveness gains when measured rigorously. However, the productivity gains only translate into genuine effectiveness gains when coupled with continuous model tuning and investigator feedback loops, which many institutions underestimate during initial deployment.
Sumsub and other vendor data show that identity-fraud detection is an area where AI is consistently outperforming rule-based systems — but also one where adversaries are adapting fastest. On the adversary side, attackers are now iterating on AI-defended controls in days rather than months, which means that any effectiveness gain that is not actively maintained tends to decay quickly.
Implications for Financial Institutions
AI works best where data is rich, outcomes are measurable, and human judgement remains in the loop. Alert triage, narrative drafting, entity resolution, and identity fraud detection all fit that profile. Institutions should also think carefully about where AI fits in the customer experience; automation of back-office processes is far less contentious than automation of customer-facing decisioning.
AI works least well when applied to areas where training data is sparse, labels are ambiguous, or regulators expect full explainability. Pushing AI into these areas without discipline creates model risk that can dwarf any efficiency gain. Model risk management should explicitly cover third-party AI components, not just in-house models, because the supervisory expectation is that the institution is accountable for every model in the chain.
Governance is the core asset. Institutions with a credible model risk framework will be better placed to deploy — and defend — the next generation of AI-assisted compliance tools. Finally, AI programmes should be reported to boards with the same rigour as traditional financial crime metrics — and boards should expect to see evidence of both wins and losses over time.
Conclusion
AI is no longer the future of compliance; it is already shaping daily operations. The winners will be the institutions that deploy it with discipline, measure its outcomes honestly, and govern the models as rigorously as they govern the humans who review the alerts. This is the moment for institutions to consolidate AI experiments into a disciplined, measured programme — and to let honest measurement decide which capabilities scale next.
Suggested Next Steps
Prioritise AI use cases with measurable outcomes and clear human oversight.
Strengthen model risk management around every deployed financial crime model.
Measure AI-enabled programmes against effectiveness, not just productivity.
Engage supervisors early on novel AI deployments to build shared understanding.
Sources: FATF technology statements, Wolfsberg Group principles, FCA, MAS, HKMA, APRA notices, BIS, FSB reports, Sumsub, Reuters.
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments