ClickCease

Something we said? Don’t leave just yet!

For more information about latest events, news and insights, leave us your email address below.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form
Dismiss

Who owns compliance decisions in automated systems?

As AI transforms AML operations, accountability remains human. Explore ownership, explainability, oversight, and responsible AI in compliance.

Janet Bastiman
July 23, 2026

The question of ownership in automated compliance systems is not simply a technical one it is foundational to how financial institutions operationalise trust. As AI becomes increasingly embedded in anti-money laundering (AML) workflows, the industry is being forced to confront a fundamental tension: how to harness automation at scale without diluting accountability.

Automation can enhance, accelerate, and augment decision-making but it does not replace responsibility. Accountability remains firmly with the human-in-the-loop.

Automation does not transfer accountability

Despite the growing sophistication of AI models, regulators have been unequivocal: responsibility for compliance decisions cannot be delegated to machines. Whether alerts are prioritised using risk scoring, recommendations are generated by machine learning models, or narratives are drafted using natural language processing, the ultimate decision to escalate, discount, or report sits with a human analyst.

This is not a limitation of AI; it is a design principle. Financial crime compliance is not just a data problem, but a regulatory obligation. AI can synthesise vast volumes of behavioural, transactional, and contextual data far more efficiently than any human analyst. It can highlight anomalies, recommend actions, and even explain its reasoning in natural language. But these outputs must operate under human oversight, because the regulatory framework demands it.

A human-in-the-loop approach is therefore not an interim compromise it is the only viable model for responsible AI adoption in AML.

Decisioning vs. decision support

One of the most important distinctions firms must make is between automating decisions and supporting decisions with automation.

Consider alert handling. It may be tempting to automatically discount alerts below a certain risk threshold, especially where historical data suggests a low likelihood of suspicious activity. However, this approach risks conflating statistical inference with regulatory judgement. An alert should only be discounted if the underlying rationale is both risk-based and clearly documented and crucially, if it has been subject to prior human validation.

In practice, this means that AI should be used to identify patterns in historical human decisions, not to bypass them. Clear uses cases include AI-recommended rules derived from patterns identified in consistent past-discounting decisions from trained analysts. When automation is introduced must be explainable, traceable, and anchored in a well-defined risk framework.

This is where many institutions encounter difficulty. If AI operates as a “black box,” analysts cannot meaningfully challenge or defend its outputs. And if decisions cannot be clearly explained, they cannot be justified to regulators.

Transparency is not optional, it is operationally essential.

The regulatory test: Explainability

Regulatory expectations around explainability have not changed with the introduction of AI. If anything, they have become more stringent.

Every compliance decision must be defensible.That means institutions must be able to articulate not only what decision was made, but why. This applies equally when AI contributes to the process.

Encouragingly, AI can play a valuable role here. Modern systems can generate natural-language explanations that summarise the data points influencing a recommendation; accelerating the creation of Suspicious Activity Reports (SARs) and improving consistency in documentation. But these explanations must be intelligible to a human reviewer, and sufficiently transparent to stand up to regulatory scrutiny.

Critically, the analyst must be able to understand the AI’s reasoning, not just accept it.

This requires a shift in how models are designed and deployed. Explainability cannot be retrofitted; it must be embedded from the outset.

Oversight is not a metric

A common question we hear is: how much human oversight is enough?

The answer is that oversight is not something that can be reduced to a numeric threshold. It is not about reviewing a fixed percentage of decisions or inserting manual checks at predefined intervals. Such approaches risk recreating the “tick-box compliance” mentality that regulators are actively moving away from.

Instead, oversight should be outcomes-driven. Can the institution demonstrate that its automated processes are transparent, explainable, and auditable? Can analysts clearly articulate how decisions are made? Are risk-based assessments documented, operationalised, and consistently applied?

If the answer to these questions is yes, then oversight is functioning as intended.

Governance must catch up. But not at the expense of innovation

Historically, governance frameworks have struggled to keep pace with operational change. The introduction of AI into AML workflows has only amplified this challenge.

However, the broader regulatory shift towards outcomes-based supervision particularly from bodies such as the Financial Conduct Authority signals a more collaborative approach. Rather than prescribing rigid controls, regulators are increasingly focused on whether firms can demonstrate effective risk management and decision integrity.

This creates an opportunity, but also a responsibility.

Institutions must ensure that governance evolves alongside their technology. This includes clear documentation of risk models, robust audit trails for automated processes, and defined accountability at every stage of the decision lifecycle.

For many firms, the complexity of governing AI models in-house can be a barrier to adoption. This is where the choice of technology partner becomes critical. A compliance-first approach to AI (where explainability, auditability, and regulatory alignment are built into the solution) can significantly reduce governance overhead, while ensuring that innovation does not come at the cost of control.

The future of ownership in AI-driven AML

As automation continues to reshape financial crime compliance, the question of ownership will only become more important. The answer, however, is unlikely to change.

AI will continue to evolve as a powerful decision-support tool one that enhances detection, reduces false positives, and improves operational efficiency. But ownership of compliance decisions will remain with the human, because accountability cannot be outsourced.

The institutions that succeed will be those that embrace this reality not as a constraint, but as a framework for building more transparent, more effective, and ultimately more trustworthy AML systems.

In the end, responsible AI is not about removing humans from the loop. It is about ensuring they remain firmly at the centre of it.

Chair of the Royal Statistical Society’s Data Science and AI Section and member of FCA’s Synthetic Data group, Janet started coding in 1984 and discovered a passion for technology. She holds degrees in both Molecular Biochemistry and Mathematics and has a Masters in Finance and a PhD in Computational Neuroscience. Janet has helped both start-ups and established businesses implement and improve their AI offering prior to applying her expertise as Chief Data Scientist at Napier AI. Janet regularly speaks at conferences on topics in AI including explainability, testing, efficiency, and ethics. In 2026, Janet was named to the Computing AI Leadership Index, presented Project Theseus as part of the FCA Supercharged Sandbox, and is shortlisted for the British Data Awards- Data Leader of the Year.