As AI continues to evolve, there are unprecedented opportunities to strengthen global defences against financial crime. AI is already helping organisations bring fragmented customer information together, identify relationships and patterns during onboarding, and direct investigators towards higher-risk activity.
However, without the right strategy, data foundations and system design, supported by a coordinated approach across legal, risk management, compliance, data and technology teams, valuable opportunities may be missed, and new risks may become embedded in the financial crime control environment.
In this latest article, we explore:
- three practical AI use cases already strengthening financial crime controls;
- the risk of ‘cognitive erosion’ and overreliance on machine-generated conclusions; and
- the key questions senior leaders should be asking to inform their FCC AI strategy prior to deployment.
In increasingly pressured and resource constrained environments, the central governance challenge is to ensure that AI supports professional judgment rather than becomes a substitute for it.
Have a read below for some practical considerations on assessing your FCC AI readiness and deploying AI in a way that strengthens the effectiveness of your financial crime compliance team.
Three ways AI is reshaping financial crime compliance
The use of AI in financial crime compliance is now moving beyond workflow management and documentation, and extending to more reliable screening measures on customers, insightful data on ML/TF/PF customer risk profile, diligent monitoring of transactions and more useful and comprehensive intelligence on suspicious activity to inform suspicious activity reports.
Across the three lines of defence, teams are shifting away from just following instructions and process, to becoming more curious, more analytical and more investigative and collaborative as they continue to review AI generated output and exercise judgment to ensure fairness of outcomes, particularly when onboarding new customers. This could have a profound positive impact on customers, communities and the economy, provided the important role of human judgment is preserved.
Three key FCC AI use cases are driving momentum in strengthening financial crime compliance and risk management more broadly:
- Bringing previously fragmented information together to assess customer behaviour and risk: In the HKMA’s global-bank case study, a cloud-based AI platform combined transaction data, customer profiles, KYC information, previous suspicious activity and the bank’s own financial crime typologies to identify abnormal behaviour and rapid movements of funds across more than one billion transactions each month. The results included a reduction in false positives by 60%, an increase in detection of suspicious activity by two to four times, and case investigations were completed approximately 50% faster. Investigators were then able to focus on higher-risk activity while reducing the compliance burden created by large volumes of low value alerts.
- Identifying relationships and patterns when onboarding a customer: In the HKMA’s digital-bank case study, AI models analysed customer information, facial images and behavioural indicators to identify possible impersonation, mule-account activity and recurring connections that may not have been apparent through traditional onboarding checks. The results included a 30% increase in the detection of suspected mule accounts, while screening times were reduced to seconds. Investigators were then able to focus on customers displaying the strongest indicators of financial crime risk while supporting faster and more seamless onboarding for lower-risk customers.
- Directing human attention to the highest risk areas when investigating financial crime risks: In another HKMA case study, a large bank combined human-defined risk indicators with a machine-learning model to prioritise customers displaying potential money-mule activity. The model reclassified 42% of customers previously assessed as medium risk as high risk, with 70% of those customers escalated for investigation and 40% ultimately exited because of financial crime concerns. Investigators were then able to direct their attention to the cases presenting the greatest potential risk, rather than working through alerts in chronological order or treating all alerts as equally significant.
Risks – when the human in the loop stops thinking
There is an exciting shift ahead as we start to see AI being used as not only a compliance productivity tool but a strategic financial crime intelligence partner, enabling risk and compliance teams to be more curious, investigative and analytical, and build their careers beyond due diligence. On the flipside, if not appropriately governed, this shift may lead to overreliance on an AI system, risks of non-compliance and potentially a financial crime function that has gradually pushed away its true value, its unique ability to think independently.
The FCA’s Mills Review described the concept of ‘cognitive erosion’ as the reduction over time in a person’s knowledge, judgment, confidence or decision-making capability associated with sustained reliance on AI-enabled systems. Without deliberate safeguards, the use of FCC AI could encourage cognitive offloading, automation bias and an over-reliance on machine-generated conclusions, ultimately leading to weakened professional capability to challenge AI output.
As flagged in the FCA’s Mills Review there is a need to retain control over investigation, escalation and consequential decisions. In a financial crime compliance context, preserving meaningful human control is therefore likely to include:
- Maintaining active and meaningful human judgment throughout the process (as opposed to just having a human present in the process). There is a material difference between a human making a decision with the assistance of AI and a human approving a decision that the AI has already made;
- Understanding the difference between historical investigation data and actual proof that a financial crime has occurred and training the system accordingly;
- Preserving a function’s capacity to identify when the AI is wrong, not merely its capacity to explain how the AI reached an answer. Explainability is important but it is not enough. An organisation also needs sufficient financial crime, risk management and compliance expertise to challenge the system’s assumptions, test vendor claims, interrogate external datasets, identify, assess and manage the data privacy risks and identify when apparently coherent outputs are unsupported by the underlying evidence; and
- Measuring whether AI improves financial crime outcomes rather than merely operational metrics. A reduction in alerts or investigation time does not necessarily demonstrate improved effectiveness. Clearly articulating the value of AI enabled controls in detecting financial crime risk and strengthening financial crime compliance will help in sustaining buy-in and investment while supporting more credible and constructive regulatory engagement.
The governance question is not simply whether a human remains somewhere in the process. It is whether that human has the information, capability, authority, time and genuine independence required to challenge the system and whether the organisation can demonstrate that this happens in practice.
Assessing FCC AI-readiness
The key question for senior leaders is not how quickly AI can be deployed across the full AML/CTF lifecycle but:
- where in your existing financial crime framework can AI materially improve outcomes, including fair and seamless access to products and services for consumers; and
- whether your organisation is ready – do you have the right culture and capabilities to prevent overreliance? Do you have lawful grounds to process the personal data of your customers using an AI system? Does your organisation have the right data, governance and operating discipline to trust the outcomes and is it data privacy compliant?
The successful deployment of FCC AI and cost effectiveness comes down to proper preparation. As referenced by the FCA’s Mills Review, accurate, complete, timely consistent and traceable data is foundational to reliable AI outcomes. As systems become more autonomous, tolerance for error reduces and the need for data precision, lineage and governance increases.
Time being well spent upfront to resolve issues with your FCC data and IT infrastructure, design a robust strategy and operating model and set reliable governance foundations will enable seamless and efficient deployment. It may also prevent the organisation from having to address avoidable privacy issues, reconstruct unreliable decisions or untangle a flawed AI-enabled control after a regulatory breach or poor customer outcome has occurred.
Moving towards a more intelligent control environment
As the technology landscape continues to rapidly evolve, we may start to see AI being used in the financial crime risk management context as not only a productivity tool but as a strategic intelligence partner. Roles and responsibilities will start to dramatically shift to:
- human leaders defining the risk, risk appetite, judgement thresholds and escalation pathways;
- AI agents continuously interrogating data, revealing unseen connections and challenging established risk assumptions, and
- robust governance surrounding the arrangement to ensure transparency, explainability, auditability and clear accountability.
The goal is not to place a human somewhere in the loop. It is to build an intelligent control environment in which people remain capable of seeing what the system cannot, confident enough to disagree with it and accountable for the decisions ultimately made.
Six questions to inform your FCC AI strategy
Here are the top six strategic questions to consider prior to deploying AI to help strengthen financial crime controls:
- Do you have lawful grounds to process their personal data using an AI system and are you protecting the privacy of your customers when using the AI system? Processing personal data to assess financial crime risk is not just a free for all in cases where the data is not in fact relevant to combatting financial crime risk -specific conditions that must be present in order to do this lawfully.
- Is the AI recommending, materially influencing or effectively making decisions about a customer’s risk classification, onboarding, account restriction or continued access to products? What makes the human involvement meaningful rather than a rubber stamp?
- Can every material output from your AI system be traced back to sufficiently accurate source data?
- How are you going to shift the mindset of your team from control to curiosity to analyse, critique and oversee AI generated output, particularly when investigating high risk cases.
- Who has the knowledge, authority and accountability to challenge the model when it is wrong? How are overrides, disagreements, false negatives and below-threshold cases analysed and reported?
- How are you going to explain to a regulator your use of AI, in line with the ‘show me, don’t tell me’ approach, and who is going to deliver that explanation?
Need assistance in taking your first practical step towards AI readiness? Contact us here to access our FCC AI Readiness template.
