
Banks Turn to AI Agents to Improve Financial Crime Compliance QA
Banks are moving from sample-based reviews of financial crime investigations toward continuous, fully auditable processes using AI agents. Flagright’s Christopher Phillips says agentic systems can standardize investigations and documentation across every case, while keeping humans responsible for consequential decisions.
From sampling to auditing every case
Traditional financial crime quality assurance often relies on sampling, with compliance and audit teams reviewing a portion of cases and extrapolating results. In an agentic setup, Phillips says banks can expand that approach to cover every case, producing outputs that are easier to audit.
He links the shift to agent behavior that does not degrade over time. “The AI doesn’t get bored. It doesn’t get fatigued. It doesn’t forget to include that link for the one search it did,” Phillips said, adding that the result can be “a robust output that is easy to audit.”
More autonomy, more visibility
As AI moves from recommending actions to executing them, the key question changes from what machines can do without approval to how to make every investigation observable and auditable. Phillips argues that properly designed autonomy can increase visibility into how decisions are reached, not reduce control.
He describes the need to rethink the investigative process end to end, including documenting workflows and clarifying where controls belong throughout.
Human oversight shifts to “effective challenge”
Phillips says machines can investigate, search, identify patterns, and assemble evidence. But when actions have consequences, such as closing an account or recommending SAR filing, a person must review the decision.
The operating principle becomes “effective challenge,” where humans understand why an agent reached its conclusion and document why they agree or disagree. “AI agents are basically employees,” Phillips said. “They need to be monitored like employees and need to have strictures like employees.”
Overrides, model retraining, and accountability
One operational signal Phillips points to is how often investigators override an agent’s recommendation. He notes that a small disagreement rate may be normal, but changes such as overrides moving from 5% toward 10% or 15% can indicate shifts in customer behavior, underlying data drift, or the need for retraining.
In this model, audit becomes part of the operating system rather than a retrospective exercise. Phillips also stresses governance: procedures must define who retrains models, when intervention is necessary, and who signs off on retrained versions.
He warns that “Every agent is a threat factor,” adding that agents can be hacked and training data can be poisoned. Responsibility remains with the institution. “Where does accountability lie? It lies to the institution,” Phillips said.
Why this matters
Agentic AI changes how banks supervise financial crime controls by enabling consistent investigation documentation across every case and faster detection of drift. The tradeoff is tighter governance, defined thresholds for intervention, and human accountability for consequential actions.