RiskPulseRequest Demo

Insight

Risk Based by Design: How Agentic AI Can Supercharge Modern AML

Regulators increasingly endorse a risk-based approach (RBA) to AML, allowing AI to supercharge efficiency and effectiveness. Agentic AI can automate high-volume tasks, freeing human investigators for higher-risk work. Success hinges on robust AI governance and clear mapping of AI use cases to risk drivers, demonstrating accountability.

Risk Based by Design: How Agentic AI Can Supercharge Modern AML

One of the themes of the regulator guidance at the recent ACAMS conference in Florida was a renewed emphasis on a risk-based approach (RBA) to AML programs. While this messaging has been debated, it seems regulators are more committed to allowing financial institutions to use RBA to shape the core elements of financial crime compliance programs, including increased use of AI to improve efficiency and effectiveness.

Recent proposals from FinCEN and statements from the Wolfsberg Group explicitly promote proportionality, prioritization, and effectiveness rather than uniform, check-the-box controls. That shift creates regulatory room for banks to use advanced AI to focus efforts where risks are greatest—and to automate lower-risk, high-volume tasks in a defensible manner.

Under FinCEN's proposed 2026 program rule, AML/CFT programs "should be risk-based, with more financial institution attention and resources directed toward higher-risk customers and activities, rather than toward lower-risk customers and activities." The proposal also elevates the role of formal risk assessment processes, requiring institutions to evaluate risks across products, services, channels, customers, and geographies and to update those assessments as their risk profile changes. In parallel, the Wolfsberg Group's latest RBA statement urges firms to design financial crime controls around proportionality, prioritized resourcing, and demonstrably effective outcomes, explicitly rejecting a "zero-failure" mindset.

For AI, this has two important implications. First, agentic and generative AI should be deployed where they clearly advance the institution's risk-based objectives: for example, using agents to automate the end-to-end process, including data gathering, analysis, and risk scoring, and then allowing the human to make the final judgment. This enables the reallocation of skilled investigators to higher-impact work, exactly the kind of resource shift regulators now encourage when grounded in robust risk assessment. Second, governance must keep pace with the technology. Surveys show that agentic AI is scaling faster than guardrails in many enterprises, and most organizations still lack mature mechanisms to define agent decision boundaries, monitor behavior, and maintain audit trails.

A genuinely risk-based AML program will therefore treat agentic and generative AI as integral yet controlled components of the control framework. This means clearly mapping AI use cases to specific risk drivers, documenting why an AI-enabled approach is at least as effective as legacy methods, and demonstrating that humans remain accountable for key outcomes, such as SAR decisions and risk appetite choices. Institutions that marry this renewed RBA with disciplined AI governance will be best positioned to improve both the efficiency and effectiveness of their AML programs while staying aligned with evolving regulatory expectations.

See it in action

Bring a real case.
We’ll show you the workflow.

Share a real workflow, a sample file, or a current challenge and we’ll show you how RiskPulse works in practice.

Request Demo