How banks can build reliable compliance around AI

On this page
Compliance is a mix of hard rules and case-by-case assessments, which is why the systems supporting it need to handle both. A deterministic system governs how AI evaluates evidence, giving teams confidence that the bank’s rules are followed consistently.
In the 2026 Global AI in Financial Services Report, 70% of financial services firms identified model hallucinations and unreliable outputs as a top AI risk. The same percentage of regulators said the same.
Compliance leaders need a way to address that risk without asking analysts to review every AI output. The process must stay reliable despite AI’s unpredictability.
How deterministic systems work with AI
A deterministic system applies the same rules to the same information, producing the same result every time. AI is non-deterministic, which means the same information can produce different results. This poses a problem, as compliance requires consistent results.
Deterministic systems provide that consistency. If a customer crosses a defined risk threshold, for example, the system requires additional checks every time.
AI is better suited to evaluating evidence, such as assessing the relevance of adverse media. Its performance can then improve through feedback.
Combining the two provides the foundation for bank-grade AI. The deterministic side makes the process reliable, repeatable, and auditable by ensuring the required procedure is followed without fail.
For example, Duna’s deterministic policy engine controls how a bank’s policies are carried out, directing specialized AI agents across onboarding, due diligence, screening and monitoring, and perpetual Know Your Customer (KYC).
The policy engine brings in an agent when additional evidence is needed to satisfy the policy. Once the agent returns its finding, the policy engine determines whether the requirements have been met and which action to take.
Building reliability around AI
Define where AI contributes
AI works best when it has enough context to evaluate the evidence. Duna’s policy engine turns a bank’s policy into code, defining what evidence is required and when AI should be used to evaluate it.
For example, when a value-added tax (VAT) check returns a registered address that differs from the one the customer supplied, the policy engine brings in AI to evaluate the discrepancy. A company may have moved from Belgium to the Netherlands while its VAT registration still carries the old address. Or it may operate from two headquarters recorded in different sources.
Cases like these might be too rare to have their own explicit rule. AI can use the available context to determine if there’s a reasonable explanation for the discrepancy, with cases requiring human judgment passed to an analyst.
The policy engine then uses the finding to determine if the policy requirements have been met and which action to take.
Prove agents can work on their own
Banks already use training and quality assurance to make analysts more consistent. AI needs to meet the same standard before its outputs no longer require analyst review.
One way to test this is to have an AI agent and analysts perform the same task across a set of cases and compare the results. A disagreement may point to an instruction that needs refining, or expose a case where analysts themselves reach different conclusions.
Teams can then measure performance for each type of work and decide what level is acceptable. An AI agent performing sanctions screening, for example, could be tested across cases with different levels of risk to see if it meets the bank’s standard.
Compliance teams also need to test how much results vary when the facts haven't changed. Running the same case again with the same information shows how consistent the AI’s assessments are. If the result changes, the bank needs to know if the change came from new information or variation in the model.
Reduce review task by task
Once an AI agent consistently performs within the bank’s accepted range for a specific task, analysts no longer have to review every result. This approach can reduce analyst workload without removing them from the cases that require their attention.
At SeQura, Duna runs screening and verification checks against the company’s policy before a case reaches an analyst. Adverse media, politically exposed person (PEP) checks, ID verification, and watchlist hits are already included in the case file. Analysts can then focus on high-risk and edge cases. Average analyst time per case fell from 243 minutes to 14.9 minutes, making reviews 16.3 times faster.
Design for reassessment
Testing may reveal that the way AI performs an assessment needs to change after it has already been used on earlier cases. The compliance team then needs a way to apply that change to the work already completed.
Duna keeps a record of the evidence and work associated with each case. The deterministic system can identify which cases were affected by the earlier instruction and make sure the relevant work is reassessed. AI then performs the assessment again using the updated approach.
Trust AI, even with uncertainty
AI doesn’t have to be deterministic for the compliance process to be reliable. Trust comes from knowing AI is working within a system designed for consistency.
Learn how Duna can help you design reliable compliance processes for unpredictable AI. Get in touch.
Compliance is a mix of hard rules and case-by-case assessments, which is why the systems supporting it need to handle both. A deterministic system governs how AI evaluates evidence, giving teams confidence that the bank’s rules are followed consistently.
In the 2026 Global AI in Financial Services Report, 70% of financial services firms identified model hallucinations and unreliable outputs as a top AI risk. The same percentage of regulators said the same.
Compliance leaders need a way to address that risk without asking analysts to review every AI output. The process must stay reliable despite AI’s unpredictability.
How deterministic systems work with AI
A deterministic system applies the same rules to the same information, producing the same result every time. AI is non-deterministic, which means the same information can produce different results. This poses a problem, as compliance requires consistent results.
Deterministic systems provide that consistency. If a customer crosses a defined risk threshold, for example, the system requires additional checks every time.
AI is better suited to evaluating evidence, such as assessing the relevance of adverse media. Its performance can then improve through feedback.
Combining the two provides the foundation for bank-grade AI. The deterministic side makes the process reliable, repeatable, and auditable by ensuring the required procedure is followed without fail.
For example, Duna’s deterministic policy engine controls how a bank’s policies are carried out, directing specialized AI agents across onboarding, due diligence, screening and monitoring, and perpetual Know Your Customer (KYC).
The policy engine brings in an agent when additional evidence is needed to satisfy the policy. Once the agent returns its finding, the policy engine determines whether the requirements have been met and which action to take.
Building reliability around AI
Define where AI contributes
AI works best when it has enough context to evaluate the evidence. Duna’s policy engine turns a bank’s policy into code, defining what evidence is required and when AI should be used to evaluate it.
For example, when a value-added tax (VAT) check returns a registered address that differs from the one the customer supplied, the policy engine brings in AI to evaluate the discrepancy. A company may have moved from Belgium to the Netherlands while its VAT registration still carries the old address. Or it may operate from two headquarters recorded in different sources.
Cases like these might be too rare to have their own explicit rule. AI can use the available context to determine if there’s a reasonable explanation for the discrepancy, with cases requiring human judgment passed to an analyst.
The policy engine then uses the finding to determine if the policy requirements have been met and which action to take.
Prove agents can work on their own
Banks already use training and quality assurance to make analysts more consistent. AI needs to meet the same standard before its outputs no longer require analyst review.
One way to test this is to have an AI agent and analysts perform the same task across a set of cases and compare the results. A disagreement may point to an instruction that needs refining, or expose a case where analysts themselves reach different conclusions.
Teams can then measure performance for each type of work and decide what level is acceptable. An AI agent performing sanctions screening, for example, could be tested across cases with different levels of risk to see if it meets the bank’s standard.
Compliance teams also need to test how much results vary when the facts haven't changed. Running the same case again with the same information shows how consistent the AI’s assessments are. If the result changes, the bank needs to know if the change came from new information or variation in the model.
Reduce review task by task
Once an AI agent consistently performs within the bank’s accepted range for a specific task, analysts no longer have to review every result. This approach can reduce analyst workload without removing them from the cases that require their attention.
At SeQura, Duna runs screening and verification checks against the company’s policy before a case reaches an analyst. Adverse media, politically exposed person (PEP) checks, ID verification, and watchlist hits are already included in the case file. Analysts can then focus on high-risk and edge cases. Average analyst time per case fell from 243 minutes to 14.9 minutes, making reviews 16.3 times faster.
Design for reassessment
Testing may reveal that the way AI performs an assessment needs to change after it has already been used on earlier cases. The compliance team then needs a way to apply that change to the work already completed.
Duna keeps a record of the evidence and work associated with each case. The deterministic system can identify which cases were affected by the earlier instruction and make sure the relevant work is reassessed. AI then performs the assessment again using the updated approach.
Trust AI, even with uncertainty
AI doesn’t have to be deterministic for the compliance process to be reliable. Trust comes from knowing AI is working within a system designed for consistency.
Learn how Duna can help you design reliable compliance processes for unpredictable AI. Get in touch.
Continue reading
Industries
Customers
Company
Resources

Industries
Customers
Company
Resources

Industries
Customers
Company
Resources


