How to know if your compliance operation is ready for AI

On this page
Banks and other financial institutions are deploying AI on top of compliance operations that were never designed to support it. That makes AI readiness essential to expanding automation across the function.
More than half of anti-financial-crime (AFC) teams already use AI in their compliance programs, according to the Association of Certified Anti-Money Laundering Specialists (ACAMS) Global Threats Report 2026. But 52% say outdated data and legacy IT systems pose a high or very high risk to those same programs.
An AI readiness assessment identifies where AI can work within existing processes and what needs to change to support it.
Why AI in compliance is different
Functions like customer support, coding, and marketing include low-risk, non-regulated tasks that are a good fit for generic AI. Errors in these tasks don’t have the financial or regulatory implications that an error in compliance would.
The European Union’s Anti-Money Laundering Authority (AMLA), for example, states in its draft guidelines on ongoing monitoring (Section 2.11, para. 90) that firms using AI must be able to explain its role, functioning, and outputs so they can be reviewed and challenged.
Compliance leaders can also face personal liability and fines for regulatory failures. AI in compliance needs clear controls around what it can decide and when a person needs to step in.
This is why financial institutions require bank-grade AI that is:
Explainable: Teams must understand and be able to explain to auditors why a specific case was flagged or accepted, and what evidence led to the decision.
Auditable: Every decision needs a record of what the AI was asked, the evidence it considered, what it returned, and how that output contributed to the decision. Teams also need to be able to revisit previous cases for an audit, or when policies change.
Repeatable: The same information evaluated under the same policy should produce the same outcome. Hard rules, such as knockout criteria, must also be applied every time.
How to assess AI readiness

1. Document current processes.
Start by identifying your compliance processes, including onboarding, customer due diligence (CDD), enhanced due diligence (EDD), legal reviews, and periodic reviews.
For each process, record the work performed at each stage and the systems and teams that support it. Specify outcomes and handovers, as well as any pain points teams experience, such as having to switch between multiple systems, doing manual reviews, or receiving incomplete applications.
Then map the same processes from the customer’s point of view to identify where they experience friction. Supplement your observations with data to create a baseline.
2. Assess policies and tooling.
Evaluate policies and tools separately and grade each dimension according to its level of AI readiness.
Policies: The goal of a policy assessment is to understand how much preparation is needed before AI can read and apply your policies.
Most compliance policies were written for analysts who know how to decipher ambiguous terms or can ask a peer for advice on how to read them. AI can’t resolve that ambiguity in the same way an experienced analyst can, so the requirements need to be broken down in a way machines can understand.
For example, an original policy might look like this:
“International transactions — For international transactions, country risk is assessed against a geographical risk list to identify increased or unacceptable risk.”
To prepare this policy for AI, compliance teams would need to answer questions like:
Does the number or frequency of transactions change the risk level?
How should risk be assessed when multiple jurisdictions are involved?
Can the reason for the transaction change the assessment?
Review the policies for each process you’ve mapped and identify which requirements need further clarification. Also, look for gaps between formal policies and the work instructions or established practices teams use to carry them out.
Tooling: Compliance teams should assess whether their current tools can support both analysts and AI.
Start with the systems identified in the process mapping step. Check for workarounds, fragmented systems, and places where analysts spend time sourcing or piecing together information manually rather than investigating risk.
Look out for legacy tools with minimal automation, or those that require teams to flip back and forth across multiple systems. Finally, identify tools that work well today and should remain in place.
Fragmentation doesn’t necessarily mean you have to replace your existing technology to use AI. The assessment should help determine where new or improved integrations are needed and what technical capabilities are missing.
3. Build a blueprint.
Map how compliance could operate with AI, including what would change across the customer lifecycle and what would stay the same. For example:
onboarding could collect missing information as the application is completed
analysts could review evidence using a single interface
new customer information could automatically trigger a review
The blueprint should also show where AI fits alongside existing technology and how the systems will work together. This shows teams what an AI-native compliance operation could look like and the work required to get there.
Put the assessment into practice
Use the blueprint to choose the first use case. Look for areas of the compliance process where people spend a lot of time on work that a machine could reasonably take on. That might be collecting information, checking evidence across different sources, or approving low-risk cases that don’t require analyst review.
Then determine how to implement that use case. The policy may already be specific enough for a machine to apply, but the data AI needs could be spread across several systems. Or the technology may be in place while the policy still isn’t machine-readable.
Long decision times and repeated requests for information can also uncover opportunities to improve the customer experience while reducing manual work.
Make your AI investment count
Adding AI to existing operations can automate individual tasks while still leaving the underlying processes unchanged. An AI readiness assessment creates a chance to rethink the compliance function itself.
That means investing in changes that reduce friction for customers while giving analysts more time for investigative work.
Learn how Duna can help assess your compliance operation’s AI readiness and create a blueprint for expanding automation across the function. Get in touch.
Banks and other financial institutions are deploying AI on top of compliance operations that were never designed to support it. That makes AI readiness essential to expanding automation across the function.
More than half of anti-financial-crime (AFC) teams already use AI in their compliance programs, according to the Association of Certified Anti-Money Laundering Specialists (ACAMS) Global Threats Report 2026. But 52% say outdated data and legacy IT systems pose a high or very high risk to those same programs.
An AI readiness assessment identifies where AI can work within existing processes and what needs to change to support it.
Why AI in compliance is different
Functions like customer support, coding, and marketing include low-risk, non-regulated tasks that are a good fit for generic AI. Errors in these tasks don’t have the financial or regulatory implications that an error in compliance would.
The European Union’s Anti-Money Laundering Authority (AMLA), for example, states in its draft guidelines on ongoing monitoring (Section 2.11, para. 90) that firms using AI must be able to explain its role, functioning, and outputs so they can be reviewed and challenged.
Compliance leaders can also face personal liability and fines for regulatory failures. AI in compliance needs clear controls around what it can decide and when a person needs to step in.
This is why financial institutions require bank-grade AI that is:
Explainable: Teams must understand and be able to explain to auditors why a specific case was flagged or accepted, and what evidence led to the decision.
Auditable: Every decision needs a record of what the AI was asked, the evidence it considered, what it returned, and how that output contributed to the decision. Teams also need to be able to revisit previous cases for an audit, or when policies change.
Repeatable: The same information evaluated under the same policy should produce the same outcome. Hard rules, such as knockout criteria, must also be applied every time.
How to assess AI readiness

1. Document current processes.
Start by identifying your compliance processes, including onboarding, customer due diligence (CDD), enhanced due diligence (EDD), legal reviews, and periodic reviews.
For each process, record the work performed at each stage and the systems and teams that support it. Specify outcomes and handovers, as well as any pain points teams experience, such as having to switch between multiple systems, doing manual reviews, or receiving incomplete applications.
Then map the same processes from the customer’s point of view to identify where they experience friction. Supplement your observations with data to create a baseline.
2. Assess policies and tooling.
Evaluate policies and tools separately and grade each dimension according to its level of AI readiness.
Policies: The goal of a policy assessment is to understand how much preparation is needed before AI can read and apply your policies.
Most compliance policies were written for analysts who know how to decipher ambiguous terms or can ask a peer for advice on how to read them. AI can’t resolve that ambiguity in the same way an experienced analyst can, so the requirements need to be broken down in a way machines can understand.
For example, an original policy might look like this:
“International transactions — For international transactions, country risk is assessed against a geographical risk list to identify increased or unacceptable risk.”
To prepare this policy for AI, compliance teams would need to answer questions like:
Does the number or frequency of transactions change the risk level?
How should risk be assessed when multiple jurisdictions are involved?
Can the reason for the transaction change the assessment?
Review the policies for each process you’ve mapped and identify which requirements need further clarification. Also, look for gaps between formal policies and the work instructions or established practices teams use to carry them out.
Tooling: Compliance teams should assess whether their current tools can support both analysts and AI.
Start with the systems identified in the process mapping step. Check for workarounds, fragmented systems, and places where analysts spend time sourcing or piecing together information manually rather than investigating risk.
Look out for legacy tools with minimal automation, or those that require teams to flip back and forth across multiple systems. Finally, identify tools that work well today and should remain in place.
Fragmentation doesn’t necessarily mean you have to replace your existing technology to use AI. The assessment should help determine where new or improved integrations are needed and what technical capabilities are missing.
3. Build a blueprint.
Map how compliance could operate with AI, including what would change across the customer lifecycle and what would stay the same. For example:
onboarding could collect missing information as the application is completed
analysts could review evidence using a single interface
new customer information could automatically trigger a review
The blueprint should also show where AI fits alongside existing technology and how the systems will work together. This shows teams what an AI-native compliance operation could look like and the work required to get there.
Put the assessment into practice
Use the blueprint to choose the first use case. Look for areas of the compliance process where people spend a lot of time on work that a machine could reasonably take on. That might be collecting information, checking evidence across different sources, or approving low-risk cases that don’t require analyst review.
Then determine how to implement that use case. The policy may already be specific enough for a machine to apply, but the data AI needs could be spread across several systems. Or the technology may be in place while the policy still isn’t machine-readable.
Long decision times and repeated requests for information can also uncover opportunities to improve the customer experience while reducing manual work.
Make your AI investment count
Adding AI to existing operations can automate individual tasks while still leaving the underlying processes unchanged. An AI readiness assessment creates a chance to rethink the compliance function itself.
That means investing in changes that reduce friction for customers while giving analysts more time for investigative work.
Learn how Duna can help assess your compliance operation’s AI readiness and create a blueprint for expanding automation across the function. Get in touch.
Continue reading
Industries
Customers
Company
Resources

Industries
Customers
Company
Resources

Industries
Customers
Company
Resources


