A compliance dashboard presenting great metrics that actual misrepresent reality

AI Can Improve Monitoring. It Can’t Perform Governance.

A compliance dashboard presenting great metrics that actual misrepresent reality

Key points

  • AI can dramatically expand compliance monitoring, but more information doesn’t automatically produce better governance.
  • AI is particularly valuable for identifying patterns, concentrations and recurring deficiencies that conventional sampling may miss.
  • An AI-generated alert, classification or risk score is evidence, not a verdict. Management still needs to investigate, challenge assumptions and decide what the information means.
  • “Human in the loop” is not enough if the human simply approves the system’s output. Effective oversight requires genuine judgement and challenge.
  • Technology can improve what a licensee sees, but it can’t assume accountability for what happens next. Governance remains a human responsibility.

Better monitoring can improve decisions, but it’s not accountable for those decisions.

There are two rather different ways to worry about information. George Orwell’s dystopia imagined power being maintained partly by controlling information and constraining what people could know. Aldous Huxley’s Brave New World suggested a different danger: a society could be rendered passive not because information was unavailable, but because distraction, gratification and abundance left people with little inclination to question what was in front of them. Neil Postman later sharpened the contrast between the two authors. Orwell feared that truth would be concealed from us; Huxley feared that it could become irrelevant.

There is something uncomfortably Huxleyan about the promise of AI-enabled compliance monitoring. A licensee can potentially review far more advice, connect information sitting across different systems, identify unusual patterns and detect emerging risks that conventional file sampling might never expose. Soon enough, the problem may not be obtaining information at all. It may be deciding which of thousands of alerts, exceptions, classifications, correlations and risk scores actually matters. A business drowning in information is not necessarily better governed than one starved of it.

Derek Sivers makes essentially the same point rather more economically: “If more information was the answer, then we’d all be billionaires with perfect abs.” AI undoubtedly changes what compliance monitoring can see, and that’s valuable. But information is only an input into governance. Somebody still has to interpret it, challenge it, distinguish signal from noise and decide what the organisation should do about it.

That distinction matters because sophisticated technology can create a particularly persuasive illusion of control. A dashboard populated with risk scores, trends and automated classifications looks considerably more reassuring than an incomplete spreadsheet and a worried compliance manager. Yet neither the volume of information nor the sophistication of its presentation tells us whether management has understood the risk. Worse, information abundance can encourage passivity: another alert becomes another item to triage, another exception to close and another metric to report.

The danger, then, is not simply that AI might get something wrong. It’s that AI becomes so good at producing information that management mistakes the production of information for the exercise of governance. Technology can improve visibility, assist interpretation and direct human attention towards matters that warrant investigation. It can do quite a lot of the looking. What it can’t do is accept responsibility for what the organisation decides to do once something has been seen.

AI may solve the information problem. It doesn’t solve the attention, judgement or accountability problems. Those are governance problems.

For a licensee, that distinction isn’t just philosophical. Licensee obligations continue to require adequate risk-management and supervisory arrangements, and ASIC has specifically warned that AI adoption can outpace the governance arrangements surrounding it. AI may change the tools used to monitor risk but it doesn’t absolve management or transfer responsibility for the adequacy of the resulting controls or decisions


More monitoring doesn’t necessarily mean more assurance

Traditional compliance monitoring has always involved compromise. A licensee reviews a sample of advice, identifies deficiencies and uses those findings, together with other information, to form a view about broader conduct and compliance risk. Sampling inevitably creates uncertainty because management is drawing conclusions about a larger population from a smaller one. AI potentially changes that equation by allowing considerably larger populations of advice and other information to be assessed. That’s a substantial improvement in monitoring capability, but capability and assurance are not synonyms.

John Naisbitt anticipated part of the problem remarkably well in Megatrends in 1982: “We are drowning in information but starved for knowledge.” AI threatens to make that distinction even more important. A compliance function can have extraordinary quantities of information about advisers, clients, products and transactions without necessarily understanding the risks those data reveal. But financial services history suggests we should go one step further than Naisbitt. Knowledge is not enough either. An organisation can recognise a problem, understand its significance and still fail to act.

Although they’ll ultimately be determined by the Courts, ASIC’s current Federal Court proceedings against Interprac Financial Planning provide an uncomfortable, but as yet unproven, example for other licensees. ASIC’s case isn’t simply a story about a licensee lacking information, but an allegation that Interprac detected a significant spike in business volumes, conducted compliance reviews that identified serious advice deficiencies, imposed pre-vetting requirements and subsequently knew or ought to have known those requirements were not being followed. ASIC further alleges that senior Interprac personnel expressed significant concerns about Shield and First Guardian in July 2023, including conflicts, charges and liquidity, and directed that advisers stop putting money into the funds. ASIC’s case is that the problem wasn’t whether there were warning signs, but whether the licensee responded adequately to what it knew.

That distinction should make anyone contemplating AI-enabled monitoring slightly uncomfortable. If ASIC ultimately establishes its allegations, the lesson from Interprac won’t be that licensees need better dashboards. A dashboard might have made the spikes, concentrations and recurring deficiencies visible earlier or more dramatically, but visibility wasn’t necessarily the missing ingredient. The harder governance problem begins after the warning light comes on. Someone has to decide what the information means, challenge the explanations offered, intervene where necessary and accept responsibility for the consequences of acting, or choosing not to act.

That’s why reviewing 100 per cent of available advice documents doesn’t mean that 100 per cent of material risk has been reviewed, and why identifying 100 per cent of visible risks won’t necessarily solve the problem anyway. AI can increase the probability that a licensee sees the warning signs. It can’t ensure that management takes them seriously. The ultimate compliance failure won’t be a failure to know. It will be knowing and failing to act.


Pattern detection is where AI becomes genuinely interesting

The strongest case for AI in compliance monitoring isn’t its capacity to find more individual exceptions. Humans are already reasonably accomplished at finding things that have gone wrong when someone points us towards the right file. The more interesting capability is identifying relationships between apparently separate events, particularly across datasets too large or dispersed for conventional review.

Consider a recurring advice deficiency. One occurrence may reasonably be treated as an adviser error. The same deficiency appearing across several advisers, involving the same product and similar client circumstances, should prompt a different enquiry. Perhaps the advisers are individually making the same mistake. Perhaps the problem instead sits in training, supervision, an approved product process, an advice template, remuneration arrangements or some other feature of the licensee’s operating model. The pattern doesn’t provide the answer, but it changes the question.

That distinction is important because compliance programs have traditionally been very good at individualising problems. Find the deficient file, identify the adviser, prescribe remediation and close the incident. Pattern recognition makes that response harder to justify because it can expose the possibility that what looks like an adviser problem is actually a licensee problem. AI’s real governance value may therefore be slightly uncomfortable: not helping management find more people who made mistakes, but making it harder for management to pretend recurring mistakes are unrelated.


Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.


A pattern is evidence. It’s not a verdict.

Suppose an AI-enabled monitoring system identifies an unusual product concentration. Another model classifies a group of advice files as high risk. A dashboard shows the same deficiency recurring across several advisers. Each finding may deserve attention, but none establishes why the pattern exists, whether it is material or what management should do about it. AI can make the evidence more visible without making the conclusion certain.

This is where Annie Duke’s Thinking in Bets provides a useful discipline. Duke’s argument is essentially that consequential decisions are made under conditions of uncertainty: some information will always remain hidden, different outcomes remain possible and even a good decision can produce a bad result. The objective isn’t to manufacture certainty from incomplete information, but to become better calibrated about what we believe and how confident we should be in that belief. Instead of asking only, “What do we think is happening?”, a Responsible Manager might ask, “How confident are we, what would have to be true for us to be wrong, and what information would change our view?”

That’s more than intellectual modesty. It changes governance behaviour. If management concludes that there is a 60 per cent probability that a recurring advice deficiency reflects a systemic supervision problem, the remaining 40 per cent does not provide a reason to do nothing. It identifies uncertainty that needs to be managed. Depending on the potential consequences, a relatively uncertain risk may justify investigation precisely because the cost of being wrong is significant. Conversely, describing a conclusion as “high confidence” should invite the next question: high confidence based on what? Experience, more data and an AI-generated risk score can improve a judgement, but none converts an uncertain proposition into a fact.

The danger is that AI may encourage precisely the opposite behaviour. A classification expressed to two decimal places can make an uncertain assessment appear objective, while a sufficiently impressive dashboard can disguise assumptions beneath presentation. Management may then confuse the precision of the output with the reliability of the conclusion. Duke’s lesson is useful here: good decision-making does not require certainty. It requires being honest about uncertainty and making the best decision available despite it.

For governance purposes, that suggests a better sequence than simply identify, escalate, close. When AI identifies a material pattern, management should articulate its working hypothesis, record its level of confidence, identify plausible alternative explanations, determine what evidence would materially change that confidence and then decide what action is justified given both the probability and consequence of being wrong. The purpose isn’t to turn Responsible Managers into bookmakers. It’s to prevent an opinion from quietly becoming a fact simply because everyone in the room has stopped questioning it.


The automation paradox

There is a slightly uncomfortable realisation buried in all of this: better compliance technology can weaken governance if its sophistication discourages challenge. The more polished the dashboard, the more precise the risk score, or the more confident the automated classification appears, the easier it becomes to assume that somebody, or something, has already done the thinking. Precision can be particularly persuasive. A risk score of 87 looks considerably more scientific than somebody saying, “I’m worried about this”, even when the assumptions supporting the 87 deserve considerably more scrutiny.

This is the automation paradox. We introduce technology to improve oversight, but the authority of the technology can reduce the quality of human oversight applied to it. An organisation may therefore have more information, more alerts, more metrics and more documented review while exercising less genuine judgement. Compliance professionals have seen versions of this movie before. Changing the technology doesn’t necessarily change the plot.

The governance response is not to distrust AI, but to distrust unexamined confidence, whether it comes from a model, a spreadsheet, an adviser, a compliance manager or a board paper. Good governance has always depended upon challenge. AI simply gives management another source of information that needs to earn, rather than inherit, its credibility.


Human oversight has to involve more than a human

This is why “human in the loop” can be a misleading comfort. Putting a person at the end of an automated process doesn’t necessarily create meaningful human oversight. If that person’s function is simply to approve the conclusion produced by the system, the control may satisfy a procedural requirement while contributing very little to governance.

Effective oversight requires the reviewer to understand enough about the system and its information to challenge what it produces. What did the system see? What information was unavailable? What assumptions influenced the classification? Could another explanation reasonably account for the result? How reliable has the system been in comparable circumstances? Those questions do not require every Responsible Manager to become a data scientist, but they do require somebody within the governance framework to understand the limitations of the information being relied upon.

The useful test is therefore not “Did a human review the output?” It’s “Did somebody exercise judgement?” Those questions sound similar but describe materially different controls. One records that a person was present. The other asks whether the organisation actually governed.


Four questions Responsible Managers should be asking

Responsible Managers do not need to understand every technical detail of an AI model to ask sensible governance questions about its use. They do, however, need enough understanding to know what reliance the organisation is placing on the technology and whether that reliance is justified. A useful starting point is to ask four connected questions:

  1. What risk are we asking the system to identify?
  2. What information can it actually see?
  3. Who investigates and challenges what it identifies?
  4. Who decides what happens next?

The first two questions define the boundaries of the monitoring. If the business can’t clearly articulate the risk the system is supposed to identify, greater automation may simply produce greater quantities of data. Likewise, understanding the information available to the system is essential to understanding the limits of any conclusion drawn from it. A model assessing advice documents, for example, should not quietly become evidence that supervisory behaviour is effective unless the information being analysed can genuinely support that conclusion.

The final two questions locate accountability. Exceptions and patterns require investigation, context and challenge, while somebody with appropriate authority must determine whether the organisation needs to act, what response is proportionate and what risk is being accepted if it doesn’t. That final question is the one that matters most because it prevents technology from becoming an accountability laundering device. Someone still has to own the decision.

For material AI-supported decisions, a useful governance record should capture more than approval. It should identify the output relied upon, its known limitations, the challenge applied, the decision reached, the accountable decision-maker and any follow-up required. That turns ‘human in the loop’ from a procedural label into evidence of judgement.


Does AI change a Licensee’s governance responsibilities?

The purpose of compliance monitoring has never been to process the largest possible number of files. Nor should the success of AI-enabled monitoring be measured principally by the number of documents analysed, exceptions generated or alerts closed. Monitoring exists to help the business identify material risk early enough to understand it and respond appropriately. Coverage matters only to the extent that it improves that outcome.

AI can make an important contribution. It can increase the population being reviewed, connect information that would otherwise remain dispersed, identify relationships between events and bring emerging themes to management’s attention earlier. Those capabilities may materially improve financial services compliance and risk management. They should be embraced where the technology is appropriately designed, tested and governed.

But there’s no technological shortcut around accountability. If anything, AI makes the quality of governance more important because it increases both the amount of information available to management and the temptation to defer to apparently objective outputs. Technology may change what management can see. It doesn’t change what management is responsible for doing with what it sees.

Governance should be informed by data, not delegated to it.

AI can inform governance, but it’s a poor alternative to real governance.

If the problem isn’t detecting the issue but proving who investigated it, what was decided and whether remediation was completed, use [complye] to turn monitoring findings into assigned, trackable and reviewable compliance actions.

Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.

Further reading


Frequently Asked Questions

Does reviewing 100% of advice files mean an AFSL has effective compliance monitoring?


No. Reviewing every available advice document can materially increase coverage, but it does not establish that every material risk has been identified, understood or appropriately managed.

AI can analyse substantially larger populations than conventional sampling and expose concentrations, recurring deficiencies and unusual relationships. But monitoring effectiveness also depends on what information the system can access, what risks it has been designed to identify and what happens after an exception is detected. A system reviewing advice documents, for example, may have little visibility of conversations, supervisory conduct or information held elsewhere.

For a licensee, the better question is therefore not simply “How much did we review?” but “What risks could this monitoring detect, what could it miss, and what evidence shows that identified issues were investigated and acted upon?”

That distinction matters because AFS licensing obligations include taking reasonable steps concerning representative compliance and maintaining adequate risk-management arrangements; automation does not displace those obligations.

What does ASIC expect from licensees using AI in compliance and risk management?


ASIC’s published position is that existing obligations continue to apply when licensees adopt AI, and governance and risk-management arrangements need to keep pace with its use.

In REP 798, ASIC examined 624 AI use cases being used or developed across 23 AFS and credit licensees and warned of a potential gap between accelerating AI adoption and the governance arrangements supporting it. ASIC subsequently reiterated that licensees should ensure their governance practices keep pace with expanding AI use.

That does not establish a separate statutory requirement to use a particular AI governance framework. It means a licensee should be able to explain how its existing governance, risk, supervision and consumer-protection arrangements address the way AI is actually being used.

Practically, management should know which decisions rely on AI outputs, the information and limitations underlying those outputs, who challenges material findings and who has authority to determine the response.

When should an AI-detected compliance pattern be treated as a systemic problem?


An AI-detected pattern should trigger investigation when its recurrence, concentration or potential consequences make an isolated explanation increasingly difficult to sustain; the pattern itself does not prove that a systemic failure exists.

For example, the same advice deficiency across several advisers using the same product, template or process may point beyond individual adviser performance. Possible causes could include supervision, training, product governance, process design or another shared control. AI is particularly useful here because it can connect events dispersed across advisers and datasets.

The governance mistake is to jump from correlation to conclusion. Management should document the working hypothesis, alternative explanations, evidence required to test them and the consequence of being wrong.

That produces a more defensible record than either extreme: automatically treating every cluster as systemic, or repeatedly remediating individual files without asking why the same issue keeps returning.

What evidence should Responsible Managers retain when acting on AI-generated compliance alerts?


Responsible Managers should retain enough evidence to reconstruct both the information considered and the judgement exercised.

For a material alert or pattern, that would ordinarily include the output that triggered review; relevant source information; known data or model limitations; investigation undertaken; alternative explanations considered; the assessed likelihood and consequence of the risk; the decision made; the person or body responsible for that decision; any remediation or monitoring required; and the basis for closing or accepting the issue.

The purpose is not to create paperwork around every automated flag. It is to distinguish routine triage from decisions involving material regulatory or client risk.

A useful governance record should enable a later reviewer to answer: What did management know, what did it think that information meant, what did it do, and why?

That is particularly important where automated monitoring creates large numbers of alerts: an impressive detection system is of limited assurance value if material matters disappear into a queue without accountable resolution.

Why can a precise AI risk score create false confidence?


Because numerical precision describes the form of an output, not necessarily the reliability of the judgement behind it.

A score of 87.3 can appear more authoritative than a compliance manager saying, “This worries me”, but the score may still depend on incomplete data, assumptions, classification choices or correlations whose significance has not been established. AI can therefore make uncertainty look deceptively objective.

Management should respond to significant scores by asking what evidence generated them, what information was unavailable, how the system performs in comparable cases, and what plausible alternative explanations exist. The higher the reliance placed on the output, the more important those questions become.

This is also consistent with ASIC’s broader concern that AI governance arrangements keep pace with increasingly complex AI use. The control is not “a human looked at it”. The stronger control is evidence that somebody understood enough to challenge it and exercised judgement about what happened next.

Keep exploring

AI Can Improve Monitoring. It Can’t Perform Governance.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?