INTELLIGENCE BRIEF
firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session
vol VII . ISSUE 24 . 24 JUN 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.
Breaking . AML

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Insight . Intelligence . Accountability

32 Views
0 Comments
News & Analysis 04 Aug, 2026

A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Dr Foluso Amusa, PhD — Founder & President, IGRCFP

3 August 2026

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

There is a seductive logic to RegTech procurement that goes roughly as follows: our transaction monitoring generates too many false positives, or our KYC process is too slow, or our sanctions screening misses context a human would catch — therefore we need an AI-powered tool to fix it. The logic is not wrong, exactly. It is incomplete. A tool that automates a poorly governed process does not fix the process. It removes the friction that was, however inefficiently, forcing a human to notice when something looked wrong.

I have watched this play out inside institutions that were, on paper, sophisticated adopters of financial crime technology. A machine-learning transaction monitoring model was deployed to replace a rules-based system that generated too much noise. Alert volumes dropped, analyst productivity metrics improved, and the project was declared a success in the quarterly steering committee. Eighteen months later, a regulator asked a simple question during an examination: can you explain, in terms a customer could understand, why this specific transaction was or was not flagged? The institution could not answer with any confidence, because nobody had built the explainability and model validation layer that would have made the answer possible. The tool worked. The governance around the tool did not exist yet.

Explainability Is Not Optional, and It Is Not the Vendor's Job

If your model risk framework cannot explain a decision, you don't have an AI capability. You have a black box with a service level agreement.

This is the uncomfortable part of AI adoption in financial crime and compliance functions: the accountability for a model's output sits with the institution deploying it, not with the vendor who built it, and regulators globally are converging on that position regardless of how the underlying technology is licensed. A model inventory that does not include third-party and embedded AI tools is incomplete. A validation process that treats a vendor's own testing as sufficient evidence of soundness is inadequate. And a governance committee that cannot articulate, in plain language, how a high-stakes model reaches its conclusions has not actually solved the problem it set out to solve — it has simply moved the point of failure from a human analyst to a system nobody in the room can fully interrogate.

A Simple Test Before You Deploy

Institutions considering AI or RegTech adoption in financial crime, KYC or compliance functions would do well to apply a simple test before signing a contract: could you explain this tool's decision-making to a regulator, in an examination, without the vendor in the room? If the honest answer is no, the gap is not technological. It is governance — the same discipline of clear accountability, documented process and board-level oversight that has always separated institutions that manage risk well from institutions that simply generate the paperwork suggesting they do. Technology changes the speed and scale of that discipline. It does not change the discipline itself.

This article reflects the author's professional view and is intended for general awareness. It does not constitute regulatory or legal advice.

Leave a comment

Your email address will not be published. Required fields are marked with *

Similar Articles
A network that laundered more than four million euros from scams by sending the money to Nigeria falls

A network that laundered more than four million euros from scams by sending the money to Nigeria falls

Spanish Police Bust €4 Million International Money Laundering Ring Bound for Nigeria. The Spanish Civil Guard has dismantled a criminal network responsible for laundering over €4 million generated through cyber fraud, CEO scams, and identity theft across Europe. The organization utilized "smurfing"—splitting large illicit funds into more than 9,200 small-wire transfers using falsified passports and stolen identities—to bypass anti-money laundering controls and funnel cash into Nigeria. The two-phase operation led to 20 arrests, investigations into 11 others, and raids targeting key leaders in Bilbao as well as several complicit money transfer agencies.

Read Full Brief
07 Aug 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish.

Read Full Brief
04 Aug 2026
FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

The Financial Action Task Force closed its June 2026 plenary by removing Algeria and Namibia from its list of jurisdictions under increased monitoring, while adding Bosnia and Herzegovina and Iraq. For African compliance functions, the headline delisting matters less than what it confirms about the direction of travel.

Read Full Brief
04 Aug 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

Read Full Brief
04 Aug 2026
The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

High-risk AI obligations for financial services have been pushed back sixteen months. Transparency rules for chatbots and synthetic media have not moved at all — and enforcement power against general-purpose AI providers switches on this week.

Read Full Brief
04 Aug 2026
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.

Read Full Brief
04 Aug 2026
Recommended Articles
See all

No recommended articles found.