RegTech Has Solved the Easy Problems. The Hard Ones Are Still Waiting.
Pathik shah has watched RegTech develop from the perspective of a practitioner who needs to advise clients on what to buy and how to use it. She is neither a technology sceptic nor an uncritical advocate. In this interview, she gives her honest assessment of what AML technology has delivered, where it has oversold itself, and what the genuine frontier of innovation looks like.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
- Where RegTech has worked best: Sanctions screening and digital identity verification.
- Where it has underdelivered: Transaction monitoring, especially where data quality and typology design are weak.
- Is AI useful in AML? Yes, for entity resolution, adverse media and network analytics.
- Can AI replace compliance officers? No. Human accountability and oversight remain essential.
- How should firms buy AML technology? Start with the problem, define success, and test using your own data.
Where has RegTech genuinely delivered on its promise in AML compliance?
Sanctions screening and digital identity verification are complex disciplines. They are comparatively more structured, data-led and automatable than the judgement-heavy areas of AML compliance, which is what makes them more tractable for technology. Sanctions screening is the clearest success story. The automation of sanctions screening against multiple lists, in near-real-time, with intelligent name-matching that handles transliteration and alias variations: this is something that would have been practically impossible at scale twenty years ago and is now routine. The technology has genuinely solved a problem that compliance teams could not solve manually.
Customer identity verification at onboarding is another area of real delivery. Biometric verification, document scanning and authentication, digital identity frameworks: these have made the onboarding process faster, cheaper, and in some respects more rigorous than the paper-based processes they replaced. The compliance officer who remembers verifying identity documents physically understands how significant that change has been.
Where has RegTech overpromised and underdelivered?
Transaction monitoring. The promise has always been that sophisticated rules-based and then machine-learning-based monitoring would dramatically improve the detection of suspicious activity while reducing false positives. The reality is that false positive rates remain extremely high in most implementations, the alerts that require human review are often of poor quality, and the genuine detection of suspicious activity that was not already being caught by simpler means has been more limited than the vendor presentations suggested.
The reason is that the hard problem in transaction monitoring is not the technology. It is the quality of the underlying data, the clarity of the typologies being searched for, and the calibration of the rules or models to the specific risk profile of the institution. You can have the most sophisticated monitoring platform in the market and get poor outcomes if the underlying data is inconsistent, the typologies are not contextualised, and the thresholds are set to minimise alerts rather than maximise detection. Technology does not solve those problems. Human expertise does.
You can have the most sophisticated monitoring platform in the market and get poor outcomes if the underlying data is inconsistent and the thresholds are set to minimise alerts rather than maximise detection. Technology does not solve that. Human expertise does.
Jyoti Maheshwari | AML/CFT Advisory Practitioner | AML Guild Expert
What about artificial intelligence specifically? There has been enormous hype about AI in AML compliance. How much of it is justified?
Some of it, in specific applications. AI-based entity resolution, which links disparate references to the same individual or entity across different data sets, has produced genuine improvements in beneficial ownership identification and adverse media screening. Network analytics that identify suspicious relationship patterns across customer populations have surfaced connections that rules-based monitoring misses. These are real contributions.
The hype around AI-generated STRs and AI-driven compliance decisions is less justified. Regulatory frameworks generally expect firms to remain accountable for compliance decisions. An AI system that identifies a suspicious pattern still requires a human compliance officer to review, contextualise, and decide whether to file. The AI can make that human review more efficient. It cannot replace it. Vendors who imply otherwise are selling something that does not exist in a form that regulators currently accept.
How should a compliance officer approach the technology procurement process to avoid buying something that does not deliver?
Start with the problem, not the solution. Most compliance technology purchases go wrong because the institution decides it wants a particular type of technology and then builds a procurement process around finding the best version of that technology. The right approach is to identify the specific compliance weakness you are trying to address, define what success looks like in measurable terms, and then assess whether technology can contribute to addressing that weakness and, if so, how.
Also, insist on a proof of concept with your own data before committing to a purchase. Vendor demonstrations use curated data sets that make the technology look as good as possible. Your data is messier, less complete, and differently structured. Whether the technology performs adequately on your data is the only relevant test, and a vendor that will not allow a proof of concept with real data is telling you something important.
A vendor that will not allow a proof of concept with your own data before you commit to a purchase is telling you something important about their confidence in the technology.
Jyoti Maheshwari | AML/CFT Advisory Practitioner | AML Guild Expert
What does the frontier of genuine innovation in AML technology look like to you right now?
Federated learning and privacy-preserving analytics are the developments I am watching most closely. The basic idea is that financial institutions can collectively train machine learning models on their combined transaction data without sharing the underlying data with each other or with a central party. Each institution's data stays within its own environment, but the model benefits from the patterns in all of them. If this can be made to work at scale, it would transform the detection capability of individual institutions and potentially break the information silos that financial crime networks exploit.
The regulatory and privacy frameworks for this kind of collaboration are still developing, and the technical challenges are significant. But the potential is real. The compliance function of an institution that can effectively learn from the suspicious activity patterns identified across the entire sector would be fundamentally more capable than one limited to its own transaction data. That is the genuinely exciting frontier.
Final thought: for a compliance officer who is not a technologist, what is the most important thing to understand about AML technology?
That you remain accountable for the decisions the technology supports. The system does not file the STR. You do. The system does not decide the customer's risk rating. You do. Understanding what the technology is actually doing, where its limitations are, and when its outputs require sceptical review rather than acceptance is a compliance responsibility that no amount of vendor assurance can transfer. The compliance officer who treats the technology as a black box is not complying with the regulatory expectation of human oversight. They are avoiding it.
Know Where You Stand Before Questions Are Asked
The compliance questions facing accountancy firms and auditors do not have simple answers, but they do have answers. AML Guild connects you with practitioners who have worked through these exact issues across real firms in real jurisdictions. Whether you need a covered activity self-assessment, a CDD framework review, or guidance on a specific disclosure question, our expert panel is ready.