Banks and financial institutions are rushing to layer AI onto compliance operations that were never built to support it, according to identity verification and compliance firm Duna, which argues that a structured readiness assessment is now essential before automation can scale safely across the function.
The adoption gap is already visible. Duna points to the Association of Certified Anti-Money Laundering Specialists (ACAMS) Global Threats Report 2026, which found that more than half of anti-financial-crime (AFC) teams are using AI in their compliance programmes. Yet 52% of those teams say outdated data and legacy IT systems pose a high or very high risk to the very same programmes.
Duna stresses that compliance cannot be treated like customer support, coding or marketing, where generic AI can handle low-risk, unregulated tasks. Mistakes in compliance carry financial and regulatory consequences, and compliance leaders may face personal liability and fines. Regulators are also raising the bar. The EU’s Anti-Money Laundering Authority (AMLA) states in its draft guidelines on ongoing monitoring that firms using AI must be able to explain its role, functioning and outputs so they can be reviewed and challenged.
As a result, Duna argues that institutions need bank-grade AI that is explainable, auditable and repeatable. Teams must be able to show auditors why a case was flagged or accepted, keep a full record of what the AI was asked and what evidence it weighed, and ensure identical inputs under the same policy always produce the same outcome, with hard rules such as knockout criteria applied every time.
To get there, Duna sets out a three-stage assessment. The first step is documenting current processes, from onboarding and customer due diligence (CDD) through to enhanced due diligence (EDD), legal reviews and periodic reviews. Firms should record the systems, teams, handovers and pain points involved, then map the same journeys from the customer’s perspective to build a data-backed baseline.
The second stage evaluates policies and tooling separately. Most policies were written for experienced analysts who can interpret ambiguity, something AI cannot do in the same way. Duna gives the example of a policy stating: “International transactions — For international transactions, country risk is assessed against a geographical risk list to identify increased or unacceptable risk.” Making that machine-ready means resolving questions such as whether transaction frequency changes the risk level, how multiple jurisdictions should be handled, and whether the purpose of a transaction matters. On tooling, firms should identify workarounds, fragmented systems and manual information gathering, while recognising that fragmentation does not automatically mean replacing existing technology.
Finally, institutions should build a blueprint showing how compliance could operate with AI, from onboarding that collects missing information in real time to analysts reviewing evidence through a single interface.
Duna recommends using that blueprint to select a first use case where staff spend heavy time on work a machine could reasonably handle, such as gathering information or approving low-risk cases. Ultimately, Duna argues, a readiness assessment is a chance to rethink the compliance function itself rather than simply automating broken processes.
For more, read the full story here.
Copyright © 2026 FinTech Global
Copyright © 2026 RegTech Analyst




