Site icon Finance Derivative

AI Is Complicating Compliance—But It Can Also Strengthen It

AI and 5G technology

By Brian Fahey, CEO of MyComplianceOffice (MCO)

Regulatory expectations for firms are continuing to increase, placing additional demands on already stretched compliance programs. When teams are at full stretch and budgets for adding staff are constrained, it puts real pressure on compliance. AI has the potential to ease some of that pressure, but it also adds new complexity. The challenge is determining where AI can improve compliance outcomes without making established processes, decisions, and controls more difficult to explain and defend.

Where AI Can Strengthen Compliance

Compliance breaks down into two core areas regulators consistently evaluate:

Compliance Program Definition: Is the compliance program appropriately designed for the activities of the firm’s business model? This is assessed by whether the firm’s policies and procedures are appropriate for its products, jurisdictions, and regulatory obligations.

Compliance Program Operations: Are the firm’s policies and procedures being effectively executed, monitored, and evidenced? Evidence of this requires monitoring, surveillance, and retained records that demonstrate those policies and procedures are consistently followed day to day.

There is no evidence that regulatory expectations for compliance will fundamentally change because AI is involved, at least in the near term. Firms will still need to demonstrate that their compliance programs are appropriately designed and effectively operated. The more relevant question is where AI can support the maintenance and operation of the compliance program while reducing risks or costs without compromising regulatory defensibility.

Maintaining the Compliance Program

In some areas, the potential value of AI is significant. Defining a compliance program requires firms to interpret laws, rules, and regulations and then translate those obligations into policies and procedures. That work happens when new products are launched, new geographies are entered, or regulatory changes affect existing activities.

The challenge is considerably more complex in larger organizations operating across multiple products, legal entities, and jurisdictions. Differing interpretations of regulatory requirements, combined with the need to align those requirements to business units, employee populations, and policies, create a level of complexity that has previously required significant legal and compliance expertise.

Traditionally, technology has played a limited role in this process because much of the underlying information existed in unstructured sources such as legislation, rulebooks, regulatory notices, and policy documents. Generative AI is changing that dynamic by making it possible to read, interpret, and process large volumes of text. As a result, firms may be able to identify regulatory changes more efficiently, assess their potential impact, and accelerate the development of policy and procedure updates. This is one area where AI could materially change how compliance programs are maintained.

Supporting Compliance Operations

The implications are different, however, when AI is applied to compliance operations. Technology has supported monitoring, surveillance, review, exception management, and retention for decades. These solutions evolved in response to regulatory demands for greater specificity and accountability and have been built around deterministic rules, workflows, and extensive audit trails.

Where compliance activities depend on highly structured data, these traditional approaches have proven effective. Trades, gifts, and other structured transactions can often be monitored through highly automated processes that are both efficient and auditable. Human review is generally required only when thresholds, rules, or controls are breached.

Improving Oversight of Unstructured Information

The compliance challenge is greater where information is largely unstructured. Electronic communications monitoring, for example, has relied on lexicon-based rules to identify potential issues across email, text, voice, instant messaging, and social media communications. While effective in some circumstances, these approaches often generate significant false positives and require substantial ongoing maintenance.

As firms evaluate AI-enabled solutions, the regulatory question should not be whether AI can replace existing controls. It is whether AI can produce better outcomes. Where technology already delivers highly automated, defensible results, the case for replacement may be limited. But where current approaches struggle with the volume, complexity, or unstructured nature of the data, AI may offer an opportunity to reduce risk, improve effectiveness, and lower operational costs.

Fragmented Oversight Increases the Risk

AI should be purpose-built into compliance processes, not bolted on or managed separately. As AI becomes more deeply integrated into compliance activities, firms need a clear understanding of where it is being used, what role it plays in regulated functions, how its outputs influence decisions, and where human review is required.

That becomes harder in fragmented compliance environments. When compliance activities are managed across multiple platforms, data sources, and disconnected workflows, visibility breaks down, and consistent oversight becomes harder to evidence. As firms introduce AI into siloed environments, the challenge of maintaining effective oversight becomes more complex.

AI Changes Compliance, Not Regulatory Expectations

AI will continue to have an evolving role in compliance. Generative AI is already driving advances in areas such as translation, speech processing, and the analysis of unstructured information that has historically been difficult for compliance technologies to process.

Some firms will move early and use AI-enabled surveillance capabilities in place of more traditional deterministic, rule-based processes. Those firms will need to show regulators that the new approach produces better compliance outcomes and reduces risk.

Given the explainability and defensibility challenges associated with replacing established controls, many financial institutions are likely to look first at how AI can support compliance officers, reduce costs, and improve activities such as issue escalation, investigations, review processes, querying, and reporting.

Firms best positioned for regulatory scrutiny will not necessarily be those using the most advanced technology. They will be the ones that can demonstrate effective oversight of how AI is used and maintain appropriate controls, governance, and evidence to support its use within the compliance program. As AI becomes more widely adopted, that is likely to remain the standard by which compliance programs are judged

Exit mobile version