Financial compliance expert urges caution over AI-driven transaction monitoring

A leading compliance figure warns banks to prioritise transparency and demonstrated performance before embracing autonomous AI solutions in anti-money laundering efforts.

Banks have been told for years that artificial intelligence will trim false alerts, speed up reviews and, eventually, decide cases on its own. Aishwarya Kothapally, who leads financial crimes compliance at BHI Bank in New York, is urging caution. For her, the real test is not whether a tool can produce a lower alert count, but whether it can do so without weakening risk coverage or leaving a bank unable to explain its choices to an examiner.

Kothapally said a compliance team should already be able to reconstruct a model’s life cycle before regulators ever ask for it. That means documenting what the model is meant to detect, why it was introduced, what data it uses, who owns it, what assumptions sit behind it and how it is monitored. She also expects validation evidence, change logs, tuning decisions and approval records to be readily available, rather than assembled in a rush when an examination begins.

The promise of AI in transaction monitoring is real, but she warns against treating lower alert volumes as proof of success. Industry papers and vendor material frequently cite reductions of 30 per cent to 80 per cent, depending on the system and use case, yet Kothapally argues that such numbers can be misleading if institutions simply loosen detection thresholds. In her view, the key question is whether fewer alerts still capture the behaviour a scenario was designed to find. She said a tuning exercise she worked on initially suggested a major drop in alerts, but transaction-level testing showed that some of the removed activity still mattered from a risk perspective.

That is why she wants institutions to judge AI on more than aggregate performance. False positives, false negatives, coverage, investigator behaviour and the changing nature of production data all matter, she said. A model can look strong in a controlled test and then behave differently once customer behaviour shifts or analysts start using its output in unexpected ways. The most reliable check, in her view, is to go back to actual transactions and trace the logic from data input to final alert outcome.

Her caution extends to so-called agentic AI, which can take actions rather than merely flagging activity. Kothapally said she would only allow autonomous closure of alerts after a system had shown consistent performance on a tightly defined population, proven that its data was complete and reliable and demonstrated that every decision could be explained and replayed. She would begin with a narrow, lower-risk use case and keep a human in the loop. “Autonomy should be earned through demonstrated performance rather than granted at implementation,” she said.

Kothapally also pushed back on vendor claims that proprietary systems should be accepted on trust. In her view, banks do not need every line of code, but they do need enough detail to understand how a model works, what drives its output and how to defend its use to regulators. She said the same principle applies across jurisdictions: whether the rules come from US regulators, the EU’s AMLD6 or the UK’s FCA, the common expectation is accountability, explainability, testing and meaningful oversight. For banks building out AI in anti-money laundering, her advice is simple: start with the problem, not the technology, and keep the governance in place before scaling.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.