As AI becomes embedded in compliance workflows, supervisors are no longer satisfied with outcomes alone. They want to see exactly how a decision was reached. According to Duna, the challenge for many institutions is that analysts are left trying to build an audit file from sprawling change logs, where separating what matters from what doesn’t is far from straightforward.
The regulatory pressure is sharpening. Duna points to the draft guidelines on ongoing monitoring from the EU’s Anti-Money Laundering Authority (AMLA), which state that firms should be able to explain how AI is used and what it produces, so that supervisors can understand and challenge it. For compliance teams, Duna argues, meeting that bar begins with knowing what an effective audit file should contain.
Beyond core business details such as ownership and activities, Duna says a complete record should start with the AI model itself: the provider, model family and exact version. If a supervisor finds that an outdated version was used, they may conclude it was not fit for the task, potentially forcing the bank to revisit affected cases.
The prompt matters too. It shows what the AI was asked to investigate and how it was instructed to weigh the evidence. This is particularly important where judgement is involved, such as assessing whether a company address in a residential area is plausible.
Evidence must also be preserved. Duna’s evidence model allows outdated findings to be dismissed rather than deleted, keeping the current view clean while retaining history. This narrows remediation if a flawed prompt is discovered after being used on thousands of cases, as teams can identify affected results, rerun them with a corrected prompt and pinpoint which cases need attention.
Provenance gives supervisors context when sources conflict. If a customer declares a 40% ownership stake while the company registry shows 30%, provenance reveals where each figure originated. Duna attaches provenance to each individual piece of evidence so findings can be traced back to their source.
The raw AI response should be retained before the system converts it into a finding. Duna notes that an AI might correctly extract a registration number, only for the application to misread it and flag a mismatch. Keeping the original shows whether the fault lies with the model or the software.
Finally, human judgement must be clearly recorded. If AI flags “Duna BV” against “Duna” as a mismatch, an analyst may recognise the omitted legal form and dismiss it. The file should capture that decision and the reasoning, just as it should record when an analyst accepts an AI finding.
Duna recommends building the record as work happens, tying each action to its supporting evidence and policy. Its audit log records every action within the case, removing the need to reconstruct events from notes and emails. The firm also advises separating case history from the decision record, storing decisions as structured data that can be rendered into a report on demand and rerun against new policies later.
The payoff, Duna says, is a focused audit file that gives supervisors what they need without burying it in case history, and one that can be generated whenever it is requested.
For more, read the full story here.
Copyright © 2026 FinTech Global
Copyright © 2026 RegTech Analyst





