AI Agents and the Future of Financial Crime: From Manual Review to Autonomous Investigation

Past event date: July 20, 2026 Available on-demand 45 Minutes
REGISTER NOW
Speakers
  • Holly Sraeel
    SVP Content and Strategy, Live Media
    American Banker
    (Moderator)
  • Marianne Yen
    Chief Compliance Officer
    CTBC Bank
    (Speaker)
  • Andrew Szabo
    Head of Industry Vertical, Financial Services
    UiPath
    (Speaker)
  • Michelle Goodsir
    Americas Head of Financial Crime Compliance
    SMBC
    (Speaker)

AI agents are emerging as the next operating layer for financial crime compliance.

Rather than simply automating tasks, these systems can investigate alerts, synthesize data across silos, generate explainable risk narratives, escalate complex cases, and continuously adapt to evolving threats.

This marks a structural shift from labor-scaled compliance operations toward intelligent, machine-assisted risk management architectures.

For bank leaders, the implications extend far beyond efficiency. AI-driven compliance has the potential to redefine workforce models and roles, improve customer experience, strengthen supervisory confidence, accelerate product innovation, and transform compliance from a cost center into a strategic enterprise capability.

LEADERS is a flagship channel that spotlights C-level executives and top experts as they discuss transformative topics for an audience of key decision-makers. We deliver thought leadership on the most pressing issues driving the future of financial services. The LEADERS series is made possible by the support from top industry collaborators including WorkFusion.

Transcription:
Transcripts are generated using a combination of speech recognition software and human transcribers, and may contain errors. Please check the corresponding audio for the authoritative record.

Holly Sraeel (00:21):
Hi, I'm Holly Sraeel, Senior Vice President of American Banker Live Media. Financial crime compliance is entering its most consequential transformation in decades, and it's being driven by artificial intelligence. The traditional model built around manual reviews, fragmented and siloed systems, and labor-intensive investigation teams is breaking under the pressure of real-time payments, instant account opening, cross-border transaction velocity, and increasingly sophisticated fraud and money laundering networks. At the same time, regulators are raising expectations around effectiveness, explainability, governance, and operational resilience. Banks are undergoing a generational shift in financial crime compliance as AI becomes the core engine for how risk is managed, investigated, and governed. Institutions that modernize can establish a long-term advantage in resilience, operational scalability, and trust through a hybrid model where AI handles high volume, repeatable work, and human experts focus on complex investigations and strategic risk management. Here to talk to me today about AI agents and the future of financial crime from manual review to autonomous investigation are Marianne Yen, Chief Compliance Officer for CTBC Bank's New York branch, Michelle Goodsir, America's Head of Financial Crime Compliance at SMBC, and Andrew Szabo, Head of Industry Vertical Financial Services for UiPath.

(01:49):
So welcome all. This is an urgent topic, so let's dig in. Maryanne, what signals tell you that financial crime compliance has reached an inflection point rather than simply another technology upgrade?

Marianne Yen (02:04):
It's more than an inflection point in my view. I think it's a sea change. I compared to researching based on a set of encyclopedia volumes to now being able to ask Claude and Gemini a question and get a really comprehensive answer. So to me, it couldn't have come at a better time because compliance for sanctions and money laundering has gotten so complex. In sanctions, we're not only screening names against a list to see who is a sanctioned entity. We are now asking to look at sanctions evasion, resales of products that are embargoed through third countries that are friendly to Russia or Iran. We are asked in money laundering to detect new typologies and they crop up every day like pig butchering and use of virtual assets to aid and event money laundering. So AI-assisted technology could not have come at a better time because we are asked to do much more as compliance professionals to keep up with the bad actors and how they are misusing our system.

Holly Sraeel (03:11):
Michelle, anything to add to that?

Michelle Goodsir (03:14):
A few thoughts actually, and I do think we are at an inflection point. One of the drivers is just the capabilities of AI. When you look at the systems that we've been using for years within the industry, they're often rule-based and are not flexible in terms of taking on new information quickly and adapting to some of the changing typologies that Marianne mentioned. And also the impact to our operating model. We're talking about a capability that can potentially replace people in the office in doing some of the work even today. So that requires us thinking about things a little bit differently. How are we going to apply this new technology and how are we going to apply it within our workforce and amongst our teams?

Holly Sraeel (03:54):
Okay. So Andrew, I'm going to come to you, move this conversation along. Where are traditional compliance models breaking down most visibly today in fraud, AML, sanctions, customer onboarding, or somewhere else?

Andrew Szabo (04:08):
Well, from what we were observing, it's anywhere where there's a tremendous amount of volume. So AML triage is one of those areas that is getting out of control a little bit. You have banks that are encountering 95% false positives and so forth. So there's a lot of work there, but I actually say that or actually think that there's another area that we don't talk about often enough, which is synthetic data generated by AI, especially around the onboarding cycles at banks where people just can't keep up with the volumes that are being generated. So what happens is you have a human model trying to counter an AI model, an adversarial AI model, and what you need is AI to the previous points made here to counter that as well. So anywhere where there's huge amounts of volume.

Holly Sraeel (05:04):
So real-time payments have compress decision windows from days to milliseconds. How does that fundamentally change the compliance operating model? Shell?

Michelle Goodsir (05:15):
Well, I think it gives us the capability to move more quickly, particularly when you are looking at real-time payments. You don't want to take the risk, particularly related to OFAC in processing a payment and then missing something because you didn't have sufficient time to review any potential matches in your system. So it enables us to be more flexible, move more quickly as a compliance department. I think traditionally compliance departments have been told we don't move very quickly. And anytime you hold up a payment, for example, clients are never happy. So it just gives us a better experience for our clients by being able to use this technology to support where the industry is going in terms of payments.

Holly Sraeel (05:55):
Marianne, you had some add-on thoughts to that question.

Marianne Yen (05:57):
Yeah. If we had the ability through AI-assisted technology to be able to ingest volumes of data and quickly identify relevance and impact to what it is that we're surveilling, like Michelle said, then we can be much quicker in our decision-making and our conclusions because the computer can do all of that in a fraction amount of time that people used to have to do it. But again, like Andrew mentioned, AI technology brings along with it, its own set of challenges like deep fakes and we've seen AI generated documentation when we are reviewing trade finance deals, phony bills of lading, phony invoices. So it's not that AI is bringing us only the good aspects of faster processing, but it also presents additional challenges that weren't present just a very short while ago.

Holly Sraeel (06:55):
Perfect lead-in. And I'm going to come to Andrew. Fraud, AML, cyber crime, identity theft are increasingly interconnected. Does the industry still organize these risks in silos because of structure regulation or culture or all of the above?

Andrew Szabo (07:10):
It's a complex question for sure. I think it's all of the above a little bit. And I think that's because of the nature of financial crime and the way it has evolved. But I think some of the ways that financial crime is evolving and how the threat actors are well ahead of banks now, you have to coalesce these capabilities into one. And I think you have to have a bit of a control layer in the middle that talks to what is this entity doing here versus this other part of the bank or the financial system? So I think what you have to have, and this is where I think AI has been a game changer for many, is that control layer in the middle that unifies those various different functions into one layer of understanding of what is your client doing, what is nefarious and what is legal?

Holly Sraeel (07:59):
Regulators are increasingly focused on effectiveness rather than process. How does that change what banks measure and prioritize?

Michelle Goodsir (08:08):
I think it's still a combination of the two. The regulators and the current administration has emphasized focusing on effectiveness. I think what we've seen in the past in prior reviews within the industry is that it was very much around the process and did you follow the steps and did you document things accordingly? And I still think that that's important. You have to be able to support any decisions that you're making. The regulators will absolutely expect that, but it's really about I think the bigger picture for the regulators now. And are you finding the right risks? Are you reporting the right risks to law enforcement, to treasury and meeting that expectation of managing suspicious activity through your organization and identifying it accordingly?

Marianne Yen (08:50):
Yeah, I just want to add that the two I think are inextricable in my mind. When regulators come in on an examination, they evaluate our process to see if has the maximum effectiveness to detect and deter what it is we're looking for. So I think process is still important, not the check the box process that I think all of us agree is 20th century thinking and not O-Quran, but the process itself has to be well enough designed that we can effectively find things and effectively report. So I don't think they're mutually exclusive.

Michelle Goodsir (09:26):
Right.

Andrew Szabo (09:27):
And if I may, I think another problem here is that we've always looked at sampling as a methodology for looking at the data that's coming in. So regulators and the government could only look at what was looked at. With AI, you can look at the entire set of data that's coming in in front of you and you can look at the outcomes of the data and your findings, which is materially different than what you could do before with humans. And I think at the end of the day, it's a math problem. You can't sort of hire your way out of a logarithmically growing volume of alerts.

Holly Sraeel (10:02):
Right. Okay. So I think we'd all agree that AI is becoming a competitive necessity, but here's my question. Is there still meaningful strategic advantage available to early movers?

Andrew Szabo (10:17):
I feel like I should answer this question last given where I sit, but if you want me to start, I would say yes for a couple of reasons. And I think I may get dissenting opinions on the panel here. But look, at the end of the day, getting a hold of and controlling models appropriately is a learned skill. It's something that you have to get comfortable with. It's something that the organization has to evolve to manage appropriately. And I think early movers are getting that chance to do that. Not only that, but you also get a material advantage from having your regulators look at larger data sets that are coming from your AI models early. That builds trust. That builds trust with your board, with your opco and various other oversight and regulatory functions so that you have the comfort of knowing that you can manage these things in production versus the later movers who may not be able to get on that train as fast.

Marianne Yen (11:19):
So I have not a dissenting view because I - Slightly different. I agree with everything Andrew said, but a different perspective, a disparate point of view as a former lawyer who's cautious by training. Recovering lawyer and a heavily regulated compliance professional taking the first step on something this revolutionary has risks. So a lot of people in my position are taking more of a look, see and conservative view of let's see how the technology plays out. Let's see how the early adopters fare with regulatory acceptance before we dive in full force and commit the firm's resources and our own resources to developing something that is still not completely known. AI has many other unintended consequences that we may not yet be aware of. So there might be advantages to early adoption, but there are also benefits to be cautious and not to be the leader in an area that is so revolutionary that it's sort of look see and not to be the pioneer and take the first risk.

Holly Sraeel (12:38):
I mean, it's true across the enterprise. It's not just with compliance. I mean, it's true in business units with what could go wrong and for all the revenue opportunities, there's still a lot of risk there. Michelle, anything to add?

Michelle Goodsir (12:47):
I would just add, I think it really depends on organizational readiness and the quality of your data. It's so important that you have good data that's reliable because it's the same whether you're using artificial intelligence or any of the current systems that are in the market, data feeding the system and quality output go hand in hand. So you just have to make sure that that's available and the quality is there I think before you jump in. It

Andrew Szabo (13:13):
Feels like we just have to spur on those early adopters.

Holly Sraeel (13:17):
Well, I mean to follow on with the unscripted question, how much time do you really have though? I mean, things are moving. So you don't want to jump in and run full throttle because you're aware of and concerned about the risks, but the bad guys are working overtime. Fraud is industrialized. So I mean my question rhetorical is there's not much weight in this game. All right, so let's move along. AI agents and the end of labor scaled compliance. We often talk about AI as automation. What's different about AI agents compared with previous generations of compliance technology?

Marianne Yen (13:58):
Well, we've never had a software or whatever you want to call a technology that could replicate what a human does from start to finish to complete a task. They've always been aids but not actually completing a task. And I'm referring to level one reviews of sanctions, alerts or transaction monitoring. There's a number of providers out there who have that available already for use and that's a big change. Not that we will ever replace a human out of the entire process, but at least on the level one review and maybe even level two reviews, the system has been proven to be able to do all that a human can do and replicate a sound conclusion as a human would.

Michelle Goodsir (14:47):
Which is a huge

Marianne Yen (14:47):
Departure.

Michelle Goodsir (14:48):
Yeah. I think there's an anticipated impact to the labor force, which makes it a very tough topic to talk about because of the impact and because of the shift of skillsets that will be needed going forward are different from the skillsets that are required today. But I do think it's going to be pretty significant and it's just kind of a matter of time for agents to be used on a regular basis and start getting into the decision-making process because the capability is already there. Within the industry and financial services as a heavily regulated institution, it has to be determined how far we're going to go and how quickly, but there will absolutely be a human impact.

Andrew Szabo (15:26):
Right. So look, in previous instances of technology in regulated areas of the bank with RPA, with ML and other technologies, you basically wrote software that did the thing that you wanted it to do. And with AI, you can ask it to complete a task and it'll look at various systems, fragments of data. It'll look at components of data that you've never even looked at before and provide a narrative that is defensible to an investigator. And I think what this allows regulated industries, especially banking to do in a substantive way, is to look at functions that they've never been able to look at before. And that kind of opens the aperture to look at a lot more capability in this area.

Holly Sraeel (16:12):
Okay. So good lead in. Hat investigative tests are most ready today for autonomous or semi-autonomous AI execution?

Andrew Szabo (16:22):
I think it was said already level one and level two. Level one especially. I mean, look, I think, and you know this better than I, but the problem with investigators is that they're a scarce resource. They're expensive and they're a little bit flighty sometimes. They like to move around. I see a smile over here, which confirms my suspicion, but essentially they move around a lot. And so most of their time is taken up by investigation or gathering documents rather than investigations. And I think what AI allows them to do is to do the investigations through an automated means and then they focus on the actual results or actual output of the work, which means that they will be less flighty because it's more important, interesting work, and they can focus on the real disposition rather than volume handling.

Marianne Yen (17:14):
And to add to that, even the best investigator does not have the wherewithal to ingest volumes of information and be able to sort and pick out the relevance in quick time. There's just no comparison between what a human's capacity is to absorb all that information than a machine's. And as Andrew said, then what the human has to do then is import the subject matter knowledge, the analytical ability to be able to look at what the system has spit out for you and make those judgments that will make the human in the loop still relevant. But at least on the collating and information digestion side, there's just no comparison what a computer can do versus a human.

Holly Sraeel (18:05):
So on the tasks that remain human led for the foreseeable future, what do they look like? How do they change?

Michelle Goodsir (18:15):
I think you'll still have people involved in decision-making for sure for transaction monitoring investigations, decisions to file suspicious activity reports, reviewing to make sure that it's complete. Yo probably might have AI filling out the form, but you need somebody really signing off on it because at the end of the day, the financial institution is accountable. So there needs to be that accountability with an individual and not just the technology. I think you also need to have people who are experienced and communicating with regulators and auditors too, to be able to explain how agents are being used. How do we know that the output that they're producing is exactly what we want to see? How are we managing them as we're managing other models? You really need people with some experience and expertise in that area too. So that's

Holly Sraeel (19:02):
A new role?

Michelle Goodsir (19:02):
We see that

Holly Sraeel (19:03):
As a

Michelle Goodsir (19:03):
New role? I think it is a new role. I think there are other roles too on the governance side as well around AI use, AI policy. Application and adherence is also a new role that will evolve within organizations.

Andrew Szabo (19:17):
And we do see that to double down on that point with a lot of our clients who are spending a tremendous amount of energy and effort on building these new roles that are model risk managers. We're dealing with some banks who are spending billions of dollars on AI right now, maybe a third of it on regulatory technology. And a lot of that investment is in the people that are going to manage these models.

Holly Sraeel (19:43):
So since we're touching on it, we might as well keep going. What entirely new roles do you see potentially emerging inside of compliance organizations because of AI?

Marianne Yen (19:54):
I think more technologists, people who are not afraid of systems and evaluation of systems. So it's a marriage between compliance knowledge and technology.

Holly Sraeel (20:06):
Do you see more engineers, for example, embedded within compliance as they understand large language models?

Andrew Szabo (20:14):
If they understand the regulatory rules and governance that's required to make those things happen absolutely.

Michelle Goodsir (20:21):
I think you'll see analytics teams embedded within compliance teams. Some organizations already have that and I think those teams will grow. But if they're not embedded within compliance, but they're maybe sitting in the technology side, I could see them moving in. That's one of the key things is that we have our investigators and our subject matter experts, but there needs to be a marriage between those people and the people who understand agents and how agents work. Because somebody again is going to have to verify, yes, this is what I want to see. This is suspicious activity.

Andrew Szabo (20:52):
Do you think reporting people as well? More reporting capabilities within your finance?

Michelle Goodsir (20:58):
In terms of metrics and KRIs. Exactly. Yeah, for sure. Because we have to measure quality. Right.

Holly Sraeel (21:04):
Does the traditional L1, L2, L3 analyst hierarchy make sense anymore in an agent enabled future or do you see that changing in a meaningful way?

Andrew Szabo (21:15):
I think only if you adopt agents to the previous points made on the stage. No, I think if you do adopt agents, L1 is likely going to disappear relatively fast. I don't think I've had a conversation in the past month with regulatory folks who have not set that as a defacto truth. I think a lot of level two will be taken up as well. And then the really high order, very specific investigations, the real meat of the work will be handled by the higher levels. I also like to just make a point, and I'm curious to hear what my panelists have to say about this. We always talk about false negatives. Oh sorry, false positives. False positives. Can we talk about false negatives for once as a metric here as well? Because I think that's where the real power of this will come. And I think when you eliminate level one and level two, those are going to be the metrics that will matter.

Holly Sraeel (22:10):
I have a follow-on to the, you said level one may go away fairly quickly. Care to put a timeframe on that because whenever we're talking about AI, people say fairly quickly, but then you really press them and it's three to five years. So do you have a sense? I mean, I know this is a prediction.

Andrew Szabo (22:30):
So my lived experience tells me that for smaller banks, it may happen a little faster than for larger banks in a way, because sometimes it's outsourced, et cetera, et cetera. But larger banks are putting a lot of energy and calories behind this as well. So I'd say 18 months is going to be a bit of an inflection point for those roles starting to go away. I'd be curious to hear what - 18

Holly Sraeel (23:00):
Months is pretty aggressive.

Michelle Goodsir (23:01):
That's fast. Yeah, I was going to go maybe two to three years where they start winding down. I think we'll be faster, and I'm seeing this already in the industry, to adopt AI for parts of the process, but not necessarily the end-to-end L1 reviews.

Marianne Yen (23:17):
I think it's difficult to predict because I've met with a lot of software developers who are trying to show me what's possible in the new world. And every time I ask a question, "Well, can you do this? Or is this a function that exists?" They said, "No, but in the next version in six months, it will be possible." And even they have said what we though was possible a year from now, we're seeing that it can be implemented much sooner. So even the developers are shocked at how quickly or exponentially the AI is teaching itself and developing. So I think it's really hard to predict.

Andrew Szabo (23:56):
And I think that's what makes this answer very, very difficult. I mean, you asked me this question two or three years ago, I would've said 10 years. But this is accelerating at such a pace that it is difficult to predict. Plus there's tremendous appetite to do this, right?

Holly Sraeel (24:12):
On both sides.

Andrew Szabo (24:13):
On both sides. On both sides. I mean, we deal with clients who are hiring six, seven, 800 people seasonally to handle volumes. They don't have the appetite to manage that from a P&L and OPEX and CapEx perspective. So there's a tremendous pressure to make those roles go away. So I guess the answer I should have given earlier was it depends on size of the bank, your appetite, the pressures on your P&L, et cetera. But I would suspect that many are going to push this faster than I think we think on the stage. And I'd love to look back at this in a year, year and a half and see what happened.

Holly Sraeel (24:54):
Well, it's also going to be that they'll have to react to the acceleration by perpetrators who are using AI. So if that acceleration is dramatic, then the industry will have to follow suit.

Andrew Szabo (25:05):
Absolutely.

Michelle Goodsir (25:06):
Particularly on the fraud side. And that might be the area where you see it happening faster versus maybe other parts of compliance like the L1 sanctions reviews, or maybe that's a little bit later. But I think the counterbalance - Well,

Holly Sraeel (25:18):
You never know, right? I mean,

Michelle Goodsir (25:19):
You don't know. Yeah. But that's where you're seeing a lot of the AI use with the deep fakes on the fraud side and opening fraudulent account. But I think the counterbalance to this is also going to be regulatory comfort with your application of AI within your bank because they're always asking you, do you have enough staff? And they're very concerned about when you make drastic reductions in your staffing models. So you have to be able to demonstrate that it's a smart decision, that it's not only saving money and getting efficiencies, but you're also, again, you have quality output.

Holly Sraeel (25:55):
So following on that, do you think AI agents eventually will investigate more cases than humans? And if so, when does that become acceptable?

Michelle Goodsir (26:08):
Okay, definitely not giving a timeframe to that one. No, but I - Learning for me.

Andrew Szabo (26:13):
I

Michelle Goodsir (26:13):
Like that. Well,

Holly Sraeel (26:14):
You would think. I mean, think about it rationally. AI agents investigating more cases make sense because they can digest things so much faster, right?

Michelle Goodsir (26:22):
Well, in L1, you have more alerts than you actually have cases. So they probably will at some point definitely be processing more volume than humans will if we're keeping higher level type investigations for human review.

Marianne Yen (26:36):
And I think that's an expected outcome. So there's nothing intrinsically wrong with that.

Holly Sraeel (26:42):
It's interesting when you talk about outcomes. Depending on where the AI subject is headed, either the focus is on efficiency or it's on revenues. In this case, one would assume it's on efficiencies because you're trying to process as many cases as possible. On the other side of the fence, they're dragging on efficiencies and not looking elsewhere. Okay. Governance, explainability and supervisory trust. You guys live in this world. Is technology advancement or governance maturity the bigger challenge to scaling AI and financial crime prevention?

Marianne Yen (27:25):
Governance is definitely the bailiwick of a compliance department to introduce new technologies. Especially in the state of New York, there is a heightened sensitivity to you own your system, you have to validate that they work and they are fit for purpose. So I think the governance regime will dictate who will be on the right side of the regulators when they come into examine how you've approached the implementation. And to that end, I think new roles will be created for people who know how to service a model, model validate it, explain it and test it, backtest it until everyone is assured that the results coming out of AI mirrors what a knowledgeable human would have also come to as the way to show our regulators that the system works and is fit for purpose.

Michelle Goodsir (28:26):
I think that governance around more continuous type testing is also going to be a little bit of a shift than what the industry has done with our current models where you periodically tune. But because we know that AI can drift and hallucinate and all those things that we've read about, just being able to demonstrate that level of governance from a continuous standpoint will be critical.

Andrew Szabo (28:49):
Yeah. And I think this is a governance function. Governance will always come first. But to some of the points that were made, I think as long as you are able to backtest an AI model and if a human will arrive at the same conclusion, then I think your regulators will be happy with the outcomes because they're not going to go into the deep, dark dungeons of how an AI system works as long as the explainability and the traceability and the auditability of those cases and alerts is resolved the same way as a human would, I think. But again, there's another point that was made earlier, and I wanted to just tackle it super, super quickly. I think we were talking about the fact that adversarial actors are really at the vanguard of these attacks. And an AI model will not have that because it'll have what you train it for.

(29:42):
And I think going back to that, what are the new rules that are going to be relevant here? It's going to be folks who are flagging those capabilities and putting them into the model because the AI model will know what it knows and will act within those guardrails. But if there's a new type of attack, like People selling, my favorite one is children's coloring books for millions of dollars online and they're the only ones buying it back because it's a way to launder money. You can put that mode of attack into an AI model and then it will know it, but you will need humans for that as well.

Marianne Yen (30:18):
Well, I wonder if you put all your millions of transactions into a database, AI could spot new patterns and typologies. Yeah, absolutely. So that we can train it because we've identified or hopefully the AI is smart enough to look at the millions of transactions that we've loaded up and say, I see a pattern here that I hadn't seen before and be able to help us identify.

Andrew Szabo (30:45):
But that's a much different model than the reactive model. And then you're asking AI to say, give me all the frightening potential topologies that could happen versus let me react to what just happened.

Holly Sraeel (30:56):
But that's where the industry needs to go.

Andrew Szabo (30:58):
Absolutely. Right.

Michelle Goodsir (31:00):
And it helps break down those silos that we talked about earlier across information security and fraud in AML. If you have one repository where everything is held and it's looking for all of these different types of patterns and activity, it helps to bridge those silos for us as an organization.

Holly Sraeel (31:16):
So relatedly, what does explainability mean when an AI agent has reviewed hundreds of data points and generated a recommendation?

Marianne Yen (31:27):
Well, again, it's just demonstrating that the process the system went through is quite logical and similar to what a human would go through. What information did it rely on? What conclusions was reached based on that information? And the human is the checker in the process to make sure that it's all logical and comports with how we would've done it if we were doing it. Except AI would do it much quicker and take much more information in a shorter time to arrive at the conclusion than we would have.

Michelle Goodsir (32:03):
I think it'll identify new typologies for us as well. Yeah.

Holly Sraeel (32:08):
So looking down the line, how much transparency will regulators ultimately require before they're comfortable with agent-driven investigations?

Andrew Szabo (32:18):
Thank you for not asking for a timeline there.

(32:21):
Look, I think the answer is lots, right? I think you have to build comfort. And I think AI in this setting needs to build a huge backlog of decisions so that the organizations and the regulators are comfortable with the decisions it's making based on the models that you built. And again, the point was made earlier and I think of a very apt point, you own the AI, you are responsible for the outcome of that AI. But at the end of the day, it will have to be explainable. And once you build that backlog, I think regulators will become more and more comfortable with AI handling a vastly larger portion of AML and sanctions and fraud and everything else that's in this world to a greater extent.

Michelle Goodsir (33:10):
Yeah, I agree. I think documentation is key. Showing that the output is as you expected, having your metrics in place to demonstrate what was substantiated as much as you can substantiate some of these things and just having documentation on your methodology and your testing. That's something that they'll absolutely look for as a model.

Marianne Yen (33:30):
Right. Well, you mentioned the output is as you expect it, but there could be a scenario where the AI output is vastly different because it's much more sophisticated. It saw more things. It was able to synthesize things that a human wouldn't have because it couldn't ingest millions of data points as AI would. So there could come a time when the AI results are actually more effective, better, fewer, more false positives. Yeah. But identifying different things that a human would have because the premise is that AI can do it much better than we can in terms of collating information and dissecting it. So if that's the case, I wouldn't be surprised if the AI results are even better than what humans could have done without it.

Michelle Goodsir (34:19):
For sure. I think you'll get output that demonstrates that, but you also have to validate it. There has to be some form of validation in order to prove to a regulator that it makes sense. You can't just take it for what it says. We'll have to find some way to determine that, particularly with new output that you're not expecting. You still have to find some way to say, yes, this is true.

Holly Sraeel (34:41):
And when an AI agent misses suspicious activity, where does the accountability reside?

Michelle Goodsir (34:49):
Unfortunately, it's still with the financial institution because whether it's a person or a tool. Absolutely. And whoever approved it sign up. That's right. That's right.

Holly Sraeel (34:58):
Okay. So regulators presumably will always require at some point human review of every high risk decision or will they ever become comfortable with autonomous decision-making outside of a human?

Michelle Goodsir (35:16):
I think the key there is high risk.

Holly Sraeel (35:18):
Yeah.

Michelle Goodsir (35:19):
So

Holly Sraeel (35:19):
How would we define high risk in this scenario? In this question, how would you define high risk?

Michelle Goodsir (35:23):
Well, I mean, if you're looking at a client with certain high risk triggers, they operate out of a high risk jurisdiction, they're a PEP. Anything that you have as a high risk flag to make the relationship higher risk. I don't think we're close to that. I think that there will need to be some decision-making autonomy within the organization, with people within the organization to review those higher risk relationships and make decisions around, do we maintain that relationship? Do we not maintain that relationship? Is this reportable? Are we going to increase our monitoring of this relationship and transactional activity? I don't think that would be something that a regulator, at least not in the foreseeable future that I see, would be comfortable not having a human involved in that process because of the high risk element.

Holly Sraeel (36:16):
It'd be interesting to see over the next couple of years whether with high risk relationships or potentially high risk relationships, whether the human override to continue that relationship can continue to exist. Anyway, that's a thought for another conversation, but it will be interesting to watch because relationship management at the end of the day matters greatly to institutions. So that'll be something for us to pay attention to. All right, let's talk about the new economics of compliance. Historically, compliance has been measured as a cost center. How does AI change that equation?

Michelle Goodsir (37:04):
I think we're still a cost center, but maybe we'll cost less because we will rely more heavily on technology and AI does not have the price tag that our current tools have. So I think we'll always cost the organization. I don't know that we'll necessarily be revenue generating, but I think it will definitely be less of an impact.

Holly Sraeel (37:31):
Could redirect capital.

Michelle Goodsir (37:33):
Absolutely. But you still cost as a function. Yeah. Yeah.

Andrew Szabo (37:37):
And I agree with that. I think it's going to be a cost center for a while, but I think there's still a lot of myopia about what AI could do in this space. I mean,

(37:47):
The richness of data that you will get once you start to adopt these technologies across your client base, across their transactions in almost real time, across what works, what doesn't the false positives and false negatives we talked about earlier. I think what you'll come out with is a richness of data that the AI teams that are just managing like how do we segment customers? How do we price our products? How do we build new products? They will eat that up so fast and will allow you to introduce better, faster, stronger products with less friction to your customers. And I think we haven't talked about that long enough or enough at all, but I think there's a nice and new level of richness and value there that AI systems will provide to the bank in general, which could offset your cost.

Holly Sraeel (38:36):
That's totally, totally true. All right. How does improved financial crime prevention translate into a better customer experience?

Marianne Yen (38:48):
Well, hopefully there'll be less consumer fraud, which is the top priority for all our regulators to protect the general public from fraud and scams and financial crimes. So if AI can assist in detecting and deterring financial fraud, I think that's a big win with every regulatory agency that is supervising the financial system and thus benefit the consumer as well.

Holly Sraeel (39:17):
Well, here's another interesting sort of tie-in. Can AI-driven compliance accelerate innovation by making institutions more comfortable launching new products and entering new markets?

Michelle Goodsir (39:29):
I think that's really interesting because compliance is typically involved in any new product review or a new business initiative. And so I think just the efficiency that it would bring in terms of collating information would be helpful and provide value by compliance to the business. But I also think it would help us in identifying risks faster rather than potentially hypothesizing just the ability to process a large amount of information and data would help us be able to really, I think, refine what risks we think would exist and what controls we need to put in place. So we again, would move faster.

Holly Sraeel (40:07):
How should banks think about ROI when many of the benefits, trust, resilience reputation are difficult to quantify? This is a question I think is very important when people in your positions think about this new technology. Thoughts

Andrew Szabo (40:25):
On that? I mean, I'll start off and you can add to it. I mean I think, look, right now ROI in this space is purely on FTEs or mostly on FTEs in terms of benefits. How much have you saved in hours? How many people can you ad? How many seasonal hirings can you defer? Et cetera, et cetera. I think there's a lot more here that we haven't unpacked because again, we've always looked at this function as a cost center. It's a necessary thing that we need to operate. You can't have a banking license without a risk function kind of deal. And I think there are avenues that you can open up with AI that you've never had before to turn this into something a little more meaningful for the organization that's not just about saving money or saving FTEs, but I'd be curious to hear what others have to say about that.

Marianne Yen (41:19):
I think most banks now have learned the lesson that compliance might be a cost center, but it's so necessary because without it, you could be paying billions dollars in fines and penalties and reputation risk. So I think all the management of banks have come to that realization are not pushing back as hard as they might've been back in the day when people were getting away with non-compliance without much penalty. I think the last couple of decades with all the myriad fines that have been meted out has really brought that home, that compliance is your business partner if you want to save on fines and other losses that are intangible. So I don't see it just on a return on investment as in revenue, but the savings too has to be a part of the equation.

Holly Sraeel (42:12):
Well, so this is how I think about it. Tell me if you agree. Compliance data could become one of the most valuable intelligence assets within the enterprise because it's going to feed everything, reduce losses, drive potential new product development, open up new markets, et cetera. All right, let's look a little bit toward 2030. We'll do some casting of our predictions. By 2030, what percentage of compliance investigations do you believe will be handled primarily by AI agents? What percentage off of today's base?

Andrew Szabo (42:48):
I don't want to go first on predictions. Yeah. I

Holly Sraeel (42:52):
Mean, you can go

Michelle Goodsir (42:53):
Conservatively. I think there will be some form of AI in all investigations by 2030 for something. Narrative generation, reviewing adverse news, collating information for our investigative memorandums, different areas. Even sanctions, KYC, we've talked a lot about investigations. I think end to end, I mean maybe 20%, 30% to be relatively conservative.

Holly Sraeel (43:25):
We're halfway through 2026, so 2030 is not that far off. So if you say 20%, that's a pretty good number.

Michelle Goodsir (43:31):
Pretty significant.

Holly Sraeel (43:34):
Sounds significant to me as a data girl.

Andrew Szabo (43:36):
And for my answer, I'll push the envelope a little more on it because I feel like that's my role here today. But look, I look back at my previous role as an executive at a top 30 bank and for the past decade we've deployed in that space hundreds of automations in AML, in fraud, in all of the risk functions. And they have made a material difference in the way that bank does its work. And so I would actually say that with the advent of AI and the use of AI broadly, I'd double yours. I have a 40%.

Holly Sraeel (44:16):
Not 2030. Demand is on the record. Okay. I decline to engage in the predictions

Marianne Yen (44:27):
Market.

Holly Sraeel (44:29):
Yeah. Well, we'll see. I mean, this will be in a prediction market tomorrow, right? We should check polymarket and see what's going on. What's one investment every bank should make over the next 12 months to prepare for this future?

Marianne Yen (44:45):
Well, I can start with that. I'm a strong believer in the people who run the bank should not be changing the bank. So if you are committed to developing, researching, implementing eventually AI, you need to have a dedicated team to study your institution's needs against what is available out there and then assess all the risks of implementation. So you need a dedicated core group of people who have that skill and that knowledge to help the research and implementation of AI. Don't just have it be a side job for your existing workforce because the irony is you might be asking them to research something that may one day replace them. So the incentive is not great for the people who are running the bank at the moment. It's better to have a dedicated team to help change the bank.

Michelle Goodsir (45:38):
Okay.

Andrew Szabo (45:40):
Fully agree. I think model governance; I think that's where we need to spend your money. Okay. Michelle?

Michelle Goodsir (45:47):
I think both actually. I think you need the AI experts in - house to help build the capability, understand the clientele and the risks faced by the organization. You need to have that in - house and the governance piece critical as well. And then one other thing I'll add is investing in training for your workforce because I don't think AI can be built in a silo. The people who use it and are on the receiving end of it need to understand it.

Holly Sraeel (46:17):
Okay. My lightning round, last question before we close out this panel. So I need each of you to answer this. What assumption about AI and compliance does the industry currently have wrong?

Michelle Goodsir (46:31):
We've been talking about percentage predictions. I think how quickly some of the efficiencies will be identified, and we talked 20%, 40%. But I do think the technology's moving fast, but the way we use it has been a little slower. So I think that the impact to the labor force and 50% reductions, which I've heard people tell me they think is what's happening, I think that might be a little too fast.

Marianne Yen (47:00):
Okay. I echo that. It's over-reliance on AI that hasn't been tried and true and replacing people prematurely thinking that AI is going to be a silver bullet for cost efficiencies before it's really ready to be rolled out in business as usual fashion.

Holly Sraeel (47:17):
Okay, Andrew.

Andrew Szabo (47:19):
So hello. I'm not going to make a prediction, but look, I think this is not a technology question. This is a model question at the end of the day. AI is here. It works. That's a foregone conclusion in my mind. I think what we get wrong about AI right now is that more technology begets more technology. I don't think that's what we need to do. I think we need to train people. I think we need to have model governance. I think we need to have capabilities that surround AI that make it powerful. It's like a tree and it's various branches and we have to put leaves on it kind of deal. So I don't think it's about the technology itself because it's proven to work and it has performed as advertised. I think it's about all the things that you put around it that make it work in the future.

Holly Sraeel (48:10):
So let me ask, this is my final question now. Where in this assumption that the industry executives often get wrong, don't you think organizational structure is an impediment to getting to where the industry needs to go? Because you've got to integrate your various organizations. If that doesn't happen, then the best technology in the world. Compliance can do its job brilliantly with AI, but you have colleagues in other organizational areas that need to also fit in with you. Well,

Marianne Yen (48:45):
I think that's why Andrew mentioned that it might happen quicker at smaller institutions because they're just more resilient and more agile. In the larger corporations, global institutions, integrating different siloed departments is a big bear to tackle.

Holly Sraeel (49:06):
Well, you heard it here. I'm Holly Sraeel, Senior Vice President of American Banker Life Media. I'd like to thank Marianne, Andrew, and Michelle for joining us today to share their insights on the impact of AI in the compliance world in financial services. And I look forward to hosting another American Banker Leaders Live soon. Thank you.

Michelle Goodsir (49:26):
Thank you.