Skip to content
Back to Blog
AI in Financial CrimeAML GovernanceHuman OversightAgentic AIExplainabilityFinancial Crime Prevention

AI in Financial Crime: Governance, Human Oversight and the Future of AML

Marco Beranzoni · · 10 min read

Reading time: ~10 minutes · For AML, KYC, sanctions, fraud and compliance professionals

AI Is Changing Financial Crime. Accountability Isn’t.

How AI, automation and digital transformation are reshaping financial crime risk management, and why human judgement still matters.

I was recently interviewed by Maria Gonçalves as part of her Master’s research at ISCTE Business School into corporate governance, risk management and digital transformation in the European financial sector.

Our discussion focused on something I have been working around for several years: what happens to financial crime risk management when more of the work is performed by technology?

AI is already changing transaction monitoring, sanctions screening, KYC, fraud detection and investigations. We are now moving beyond individual AI tools towards systems capable of performing larger parts of a workflow.

There is a lot to be positive about. But there are also questions that I don’t think the industry has fully answered yet.

Who is accountable when an AI system gets something wrong? How much decision-making should we automate? How do we explain a decision years later? And if AI takes over much of the work traditionally performed by junior analysts, where will the next generation of experienced investigators come from?

These are some of the views I shared with Maria.

1. Financial crime technology is improving faster than banks are changing

Digital transformation has already changed the way financial institutions identify and manage financial crime risk, but the transformation is far from complete.

Banks don’t change at the same speed as many other industries.

There are good reasons for that. A financial institution cannot simply introduce a new technology because it performs well in a demonstration. Systems need to be tested, validated, integrated, governed and monitored. Data privacy, regulatory requirements and legacy infrastructure all come into the equation.

The result is a tension I have seen repeatedly during my career.

The technology may be available, but implementing it safely across a large regulated organisation can take years.

Meanwhile, criminals don’t have change committees.

They don’t have model validation requirements, procurement processes or regulators asking them to explain their technology strategy. They can adopt new tools quickly, test what works and change approach when something stops working.

Diagram: a financial institution must test, validate, integrate, govern and monitor before going live, while a criminal simply adopts, tests and adapts

That asymmetry matters.

AI can help financial institutions analyse larger volumes of data, identify relationships that would be difficult for a person to find manually and prioritise activity that deserves investigation. Used properly, it can make financial crime controls faster and more effective.

The challenge is getting those capabilities into production quickly enough without weakening the controls around them.

2. We started with false positives. We are now moving towards AI agents

One of the early promises of machine learning in financial crime was relatively straightforward: reduce false positives.

Anyone who has worked in transaction monitoring or sanctions screening knows the problem. Traditional systems can generate enormous numbers of alerts, many of which ultimately require no action.

Better analytics can help distinguish meaningful risk from noise and allow investigators to spend more time on cases that actually require judgement.

But the conversation has moved on.

We are now entering the agentic AI era.

Instead of AI performing one isolated task, we are beginning to see systems capable of supporting multiple stages of a workflow: gathering information, analysing documents, summarising activity, identifying inconsistencies, drafting investigation narratives and recommending the next step.

That could fundamentally change financial crime operations.

It also introduces a different risk.

At what point does the human gradually disappear from the process?

I don’t think we are ready for that.

AI can process information extremely quickly, but financial crime investigations involve context, ambiguity and judgement. A transaction that appears suspicious in isolation may make perfect sense when the customer’s circumstances are understood. The opposite can also be true.

For now, qualified humans need to remain in the loop, particularly where decisions can materially affect customers or expose an institution to regulatory risk.

There is another consequence that deserves more discussion: entry-level jobs.

Junior AML and KYC roles have traditionally been where people learn the profession. They review alerts, investigate cases, make mistakes, receive feedback and gradually develop judgement.

If AI performs an increasing proportion of that work, we may reduce the number of entry-level roles.

That makes economic sense in the short term. But it creates a longer-term question.

If people don’t get the opportunity to perform the basic investigative work, how do we develop the senior investigators, compliance officers and MLROs we will need ten years from now?

Diagram: the path from reviewing alerts and investigating cases to developing judgement and becoming an MLRO or senior investigator, with the first steps increasingly performed by AI

Automation changes the workforce as well as the workflow.

3. AI doesn’t change who is accountable

One principle should remain relatively simple.

The machine isn’t the risk owner.

Introducing AI into a financial crime control doesn’t transfer accountability to the model, the software provider or the algorithm.

The institution remains accountable.

The appropriate risk owners and senior management still need to understand whether their systems and controls are operating effectively. MLROs still need management information. Compliance teams still need assurance. Models and systems still need monitoring.

In many ways, AI makes governance more important rather than less important.

Imagine an auditor or regulator reviewing a decision five years from now.

They may ask why a particular customer was escalated, why another wasn’t, what information was available to the system, which model was operating at the time and how the resulting decision was reached.

“We used AI” isn’t an answer.

Institutions need records that allow important decisions to be reconstructed.

That means thinking about audit trails, model versions, data inputs, human interventions and changes to systems from the beginning rather than trying to reconstruct them after something has gone wrong.

Diagram: an auditor asks why a customer was escalated; the institution needs audit trails, model versions, data inputs, human interventions and system changes on record

4. Human judgement needs to move, not disappear

Keeping a human in the loop shouldn’t mean asking someone to click “approve” after an AI system has effectively made the entire decision.

That is human oversight on paper, not necessarily in practice.

The more useful question is: where does human judgement add the most value?

AI is particularly useful where there are large volumes of information to process. It can retrieve data, compare records, identify patterns, summarise documents and help investigators prioritise their attention.

Humans become more important where the problem becomes ambiguous.

Does the customer’s behaviour make sense given what we know about them? Is an unusual pattern suspicious or simply unusual? Is the information reliable? Are there plausible alternative explanations? Does the case need escalation?

Those questions require context.

Diagram: AI handles large volumes of information such as retrieving data and spotting patterns, while humans matter more where problems are ambiguous

There is also the risk of automation bias. Once a system consistently produces convincing answers, people can become less inclined to challenge them.

An investigator who is technically “in the loop” but routinely accepts an AI recommendation isn’t providing meaningful oversight.

Financial institutions therefore need people who understand both financial crime and enough about the technology to challenge its output.

That may become one of the most important skills in the profession.

5. The black-box problem isn’t going away

Explainability remains one of the biggest challenges with AI in regulated environments.

A financial crime system cannot simply produce a risk score or recommendation without the institution understanding how that output should be interpreted.

This becomes more difficult as models become more complex.

There is always a trade-off between sophistication and explainability. A technically powerful model isn’t necessarily suitable for every compliance decision.

For me, transparency needs to extend to technology providers as well.

Vendors should be able to explain what their systems are doing, what data is being used, what limitations exist and how the institution can monitor performance.

Financial institutions also need the ability to intervene.

If an outcome doesn’t make sense, there should be a mechanism for a qualified person to review it, challenge it and, where appropriate, override it.

Human intervention should also be recorded. If people constantly override the same type of recommendation, that tells you something important about the system.

Explainability isn’t only a regulatory exercise. It is part of knowing whether your control actually works.

6. Build or buy? Digital-first institutions are approaching the problem differently

One difference I see between traditional banks and digital-first financial institutions is the appetite to build technology internally.

This isn’t universal, but newer institutions often have stronger engineering cultures and technology is much closer to the core of the business. Building an internal financial crime capability can therefore seem more natural than purchasing a complete external solution.

There are advantages.

An internally developed system can be closely aligned with the institution’s products, data and risk profile. Changes may be implemented faster and the organisation isn’t completely dependent on a vendor’s roadmap.

But building the technology is only part of the job.

Someone also has to maintain it, validate it, document it, monitor its performance, manage changes and demonstrate that it remains effective.

That can become expensive very quickly.

Buying technology brings different advantages. Specialist vendors can provide capabilities developed across multiple customers and use cases, together with established implementation and support structures.

The trade-off is dependency. Institutions may have less control over development priorities, integration can still be difficult, and a vendor solution doesn’t remove the institution’s responsibility for understanding what the system does.

Neither approach automatically produces better financial crime controls.

The important question is whether the institution has the capability to govern what it deploys.

A bank can’t outsource accountability by buying a platform. Equally, a fintech doesn’t automatically understand its financial crime risk better because its engineers wrote the code.

7. The next challenge is keeping pace

If I had to reduce the future of financial crime risk governance to one challenge, it would be this:

Keeping pace without losing control.

Criminals are already using new technologies to improve scams, impersonation, document manipulation and other forms of financial crime.

Financial institutions need to respond faster.

But moving faster cannot mean deploying technology without appropriate governance. And stronger governance cannot become an excuse for moving so slowly that controls are outdated by the time they reach production.

That balance is going to become increasingly difficult.

The financial crime professional of the future will therefore need a different combination of skills.

Understanding AML, sanctions, fraud or KYC will still matter. But professionals will increasingly need to understand data, AI, automation and model limitations as well.

They won’t necessarily need to become data scientists.

They will need to know enough to ask the right questions.

Diagram: six questions to ask of any AI system, from what data it uses to who remains accountable if it gets the answer wrong

The technology will continue to change.

That last question won’t.

Want to use AI in your role, and govern it properly?

The FinCrime AI Accelerator covers practical AI prompting and an AI governance framework, built for people already working in financial crime. AI for financial crime. Done properly.

Explore the FinCrime AI Accelerator

About the author

Marco Beranzoni is a financial crime specialist with experience across banking and RegTech, covering areas including AML, sanctions, KYC/CDD, transaction monitoring, fraud prevention and financial crime technology. He is CAMS certified and the founder of FinCrime Agent, an educational platform focused on practical financial crime knowledge, career development and the application of AI within financial crime prevention.

This article expands on views shared during an interview with Maria Gonçalves, conducted as part of her Master’s research at ISCTE Business School into corporate governance, risk management and digital transformation in the European financial sector. Her research examines traditional banks, FinTechs and digital-first financial institutions, including how governance and risk-management structures are evolving in response to new technologies and regulatory requirements.

Share: