On this page

AI transformation in compliance starts with policies that machines can understand. For banks deploying AI agents, policies that rely on human interpretation will limit how much of the compliance process can be automated.

Experienced analysts can make sense of unclear instructions, refer to previous cases, or ask a colleague for guidance. AI doesn’t have that same context.

Before AI can take on more of the work, teams need to turn their policies into specific instructions that can be translated into code.

What machine-ready policies make possible

Clear instructions allow more routine compliance work to be automated without requiring an analyst to interpret every case.

When policies are subjective, analysts have to investigate every case, including those that should require little or no judgment. They spend their time determining what vague terms such as “higher-risk,” “adequate,” and “when appropriate” mean and how they impact the assessment.

Defining those criteria allows cases that don’t require an analyst to be handled automatically, saving time for those that require deeper investigation. Clear criteria also make it possible to train AI on analysts’ decisions and improve its performance.

In the longer term, banks have more control as their risk appetite changes, and can adjust their policies without having to reassess every customer.

How to prepare your policies for AI

Preparing a policy for AI means breaking it down into explicit instructions a machine can follow.

Following are three steps compliance teams can take to prepare their own policies for AI.

1. Clearly define the final decision.

Start by identifying what the policy ultimately needs to determine and the data needed to get there. If a business applies for payments and lending, for example, the policy may need to produce a separate recommendation for each product.

The policy should be an exhaustive representation of the bank’s risk model, accounting for all the factors that can affect the final decision. If the final assessment depends on something outside the individual checks, an analyst still has to review the case to supply the missing context. That also leaves AI without feedback on one of the variables influencing the outcome.

The data needs to be available across the organization’s compliance infrastructure and throughout the customer lifecycle. If that information is fragmented across systems or buried in analysts’ notes, AI won’t have the evidence it needs to apply the policy.

2. Isolate each policy check.

Break policies into individual checks that can be assessed independently. When an analyst reviews an entire case and makes an overall decision, the reasons behind that decision can be difficult to separate. That leaves AI with the final outcome rather than the results of each individual check.

For example, rather than asking an analyst to “review the ownership structure,” separate that review into checks such as prohibited legal forms, the number of ownership layers, and signs that unnecessary complexity has been deliberately introduced. Each check can then produce its own result.

Isolating the checks makes those results visible. Teams can compare how an analyst and AI handle each check and use the results as feedback for the AI. It also allows checks that can already be handled deterministically to be automated without waiting for the entire assessment to be automated.

3. Specify the criteria.

Many existing policies leave room for interpretation. An instruction such as “Where appropriate, enhanced due diligence measures are applied” leaves an analyst to determine what “appropriate” means and which measures to apply. Different analysts may reach different conclusions from the same instruction.

Turn those judgments into defined criteria wherever possible. Specify the evidence to use, the relevant values or conditions, and the action that follows.

For each clause in your policy, answer the four questions below. The examples show the difference between criteria a machine can act on and language that still leaves room for interpretation.


The goal is for the same inputs to produce the same result. That reduces differences between analysts and gives AI defined criteria to work from.

A practical example

Consider a policy that asks an analyst to classify an ownership structure as low, medium, or high risk.

  • Low risk: The ownership structure is transparent and straightforward.

  • Medium risk: The ownership structure is somewhat complex, but the ultimate owners can be identified.

  • High risk: The ownership structure is complex and not transparent.

Because these classifications are loosely defined, “complex” could mean something different depending on the case. The classification can also combine several separate checks into a single assessment. For example, complexity could depend on the number of ownership layers, the number of jurisdictions the structure spans, how ownership is distributed between entities, and the ability to confirm the ownership data through authoritative registries.

Those criteria can also determine when an analyst needs to become involved. A two-layer ownership structure confirmed by registry data might require no human review. A structure with four, five, or six layers, or one that can’t be confirmed through registry data, could be routed to an analyst. The analyst can then decide if there’s a legitimate business explanation or if the case needs further investigation.

Defining the criteria also makes policy changes easier to apply. Suppose six ownership layers previously triggered a high-risk classification, but the bank changes its risk appetite and lowers that threshold to four. 

The bank can identify and reassess only businesses affected by the new threshold rather than reviewing the entire portfolio again. The underlying evidence also shows why each business received its original risk classification.

What to watch out for when preparing policies for AI

Compliance teams typically face the following challenges when preparing their policies for automation.

Trying to automate everything at once: Teams don’t have to prepare every policy before getting started. Some checks are objective enough to automate. Others can be handled by analysts until the policy, data, or AI can support automation.

Consider a value-added tax (VAT) number. A system can confirm that the number is valid and registered to the business without an analyst visiting the registry and performing the same check manually. Assessing a business activity can involve a lot more judgment.

In both cases, teams need to isolate the check and define its outcomes. For checks that still require judgment, the analyst’s decision can be captured as a defined result, such as 0, 5, 10, or 20 risk points. AI can then run alongside the analyst and learn from those decisions.

Creating exceptions that can increase risk: Exceptions are difficult to automate when they depend on information that isn't captured as evidence. If an exception can turn an apparently low-risk case into a higher-risk one, analysts may have to review every low-risk case simply to look for the exception.

The reverse is less costly. If roughly 80% of cases are low risk and 20% require further review, analysts can examine the smaller group for exceptions that reduce the risk while the larger low-risk group continues automatically.

Omitting policy details: Policies often leave details out because analysts already know how to apply them. Those assumptions turn into problems when the policy is turned into machine instructions.

Common omissions include:

  • a named source for every data point

  • the complete list behind any category that carries a consequence (countries, legal forms, activity codes, document types)

  • the risk score for every possible value, including those that score zero

  • the decision options available to an analyst and how they impact the score or application

Compliance teams should check their policies to make sure these details are explicit rather than left to the analyst to fill in.

Putting your policies to work

Once the policy has been prepared for AI, it can become part of the compliance infrastructure rather than a document analysts have to interpret.

At Duna, the policy engine translates policy into executable code and automatically runs new evidence against that policy. It also sets the rules and guardrails for where AI agents collect and evaluate additional evidence.


Build the policy foundation for AI transformation

Machine-ready policies give compliance teams a way to expand automation without giving up control over the rules that govern it. 

When the risk model is fully represented and individual checks are isolated, more cases can be handled automatically while analysts focus on the decisions that genuinely require judgment.


Find out how Duna can help turn your policies into instructions AI can use. Get in touch.

AI transformation in compliance starts with policies that machines can understand. For banks deploying AI agents, policies that rely on human interpretation will limit how much of the compliance process can be automated.

Experienced analysts can make sense of unclear instructions, refer to previous cases, or ask a colleague for guidance. AI doesn’t have that same context.

Before AI can take on more of the work, teams need to turn their policies into specific instructions that can be translated into code.

What machine-ready policies make possible

Clear instructions allow more routine compliance work to be automated without requiring an analyst to interpret every case.

When policies are subjective, analysts have to investigate every case, including those that should require little or no judgment. They spend their time determining what vague terms such as “higher-risk,” “adequate,” and “when appropriate” mean and how they impact the assessment.

Defining those criteria allows cases that don’t require an analyst to be handled automatically, saving time for those that require deeper investigation. Clear criteria also make it possible to train AI on analysts’ decisions and improve its performance.

In the longer term, banks have more control as their risk appetite changes, and can adjust their policies without having to reassess every customer.

How to prepare your policies for AI

Preparing a policy for AI means breaking it down into explicit instructions a machine can follow.

Following are three steps compliance teams can take to prepare their own policies for AI.

1. Clearly define the final decision.

Start by identifying what the policy ultimately needs to determine and the data needed to get there. If a business applies for payments and lending, for example, the policy may need to produce a separate recommendation for each product.

The policy should be an exhaustive representation of the bank’s risk model, accounting for all the factors that can affect the final decision. If the final assessment depends on something outside the individual checks, an analyst still has to review the case to supply the missing context. That also leaves AI without feedback on one of the variables influencing the outcome.

The data needs to be available across the organization’s compliance infrastructure and throughout the customer lifecycle. If that information is fragmented across systems or buried in analysts’ notes, AI won’t have the evidence it needs to apply the policy.

2. Isolate each policy check.

Break policies into individual checks that can be assessed independently. When an analyst reviews an entire case and makes an overall decision, the reasons behind that decision can be difficult to separate. That leaves AI with the final outcome rather than the results of each individual check.

For example, rather than asking an analyst to “review the ownership structure,” separate that review into checks such as prohibited legal forms, the number of ownership layers, and signs that unnecessary complexity has been deliberately introduced. Each check can then produce its own result.

Isolating the checks makes those results visible. Teams can compare how an analyst and AI handle each check and use the results as feedback for the AI. It also allows checks that can already be handled deterministically to be automated without waiting for the entire assessment to be automated.

3. Specify the criteria.

Many existing policies leave room for interpretation. An instruction such as “Where appropriate, enhanced due diligence measures are applied” leaves an analyst to determine what “appropriate” means and which measures to apply. Different analysts may reach different conclusions from the same instruction.

Turn those judgments into defined criteria wherever possible. Specify the evidence to use, the relevant values or conditions, and the action that follows.

For each clause in your policy, answer the four questions below. The examples show the difference between criteria a machine can act on and language that still leaves room for interpretation.


The goal is for the same inputs to produce the same result. That reduces differences between analysts and gives AI defined criteria to work from.

A practical example

Consider a policy that asks an analyst to classify an ownership structure as low, medium, or high risk.

  • Low risk: The ownership structure is transparent and straightforward.

  • Medium risk: The ownership structure is somewhat complex, but the ultimate owners can be identified.

  • High risk: The ownership structure is complex and not transparent.

Because these classifications are loosely defined, “complex” could mean something different depending on the case. The classification can also combine several separate checks into a single assessment. For example, complexity could depend on the number of ownership layers, the number of jurisdictions the structure spans, how ownership is distributed between entities, and the ability to confirm the ownership data through authoritative registries.

Those criteria can also determine when an analyst needs to become involved. A two-layer ownership structure confirmed by registry data might require no human review. A structure with four, five, or six layers, or one that can’t be confirmed through registry data, could be routed to an analyst. The analyst can then decide if there’s a legitimate business explanation or if the case needs further investigation.

Defining the criteria also makes policy changes easier to apply. Suppose six ownership layers previously triggered a high-risk classification, but the bank changes its risk appetite and lowers that threshold to four. 

The bank can identify and reassess only businesses affected by the new threshold rather than reviewing the entire portfolio again. The underlying evidence also shows why each business received its original risk classification.

What to watch out for when preparing policies for AI

Compliance teams typically face the following challenges when preparing their policies for automation.

Trying to automate everything at once: Teams don’t have to prepare every policy before getting started. Some checks are objective enough to automate. Others can be handled by analysts until the policy, data, or AI can support automation.

Consider a value-added tax (VAT) number. A system can confirm that the number is valid and registered to the business without an analyst visiting the registry and performing the same check manually. Assessing a business activity can involve a lot more judgment.

In both cases, teams need to isolate the check and define its outcomes. For checks that still require judgment, the analyst’s decision can be captured as a defined result, such as 0, 5, 10, or 20 risk points. AI can then run alongside the analyst and learn from those decisions.

Creating exceptions that can increase risk: Exceptions are difficult to automate when they depend on information that isn't captured as evidence. If an exception can turn an apparently low-risk case into a higher-risk one, analysts may have to review every low-risk case simply to look for the exception.

The reverse is less costly. If roughly 80% of cases are low risk and 20% require further review, analysts can examine the smaller group for exceptions that reduce the risk while the larger low-risk group continues automatically.

Omitting policy details: Policies often leave details out because analysts already know how to apply them. Those assumptions turn into problems when the policy is turned into machine instructions.

Common omissions include:

  • a named source for every data point

  • the complete list behind any category that carries a consequence (countries, legal forms, activity codes, document types)

  • the risk score for every possible value, including those that score zero

  • the decision options available to an analyst and how they impact the score or application

Compliance teams should check their policies to make sure these details are explicit rather than left to the analyst to fill in.

Putting your policies to work

Once the policy has been prepared for AI, it can become part of the compliance infrastructure rather than a document analysts have to interpret.

At Duna, the policy engine translates policy into executable code and automatically runs new evidence against that policy. It also sets the rules and guardrails for where AI agents collect and evaluate additional evidence.


Build the policy foundation for AI transformation

Machine-ready policies give compliance teams a way to expand automation without giving up control over the rules that govern it. 

When the risk model is fully represented and individual checks are isolated, more cases can be handled automatically while analysts focus on the decisions that genuinely require judgment.


Find out how Duna can help turn your policies into instructions AI can use. Get in touch.