“At the heart of this transformation is our world-leading proprietary Risk Management Framework (RMF)… Our AI-enabled RMF allows us to peer review advice documents and files in real time, over 11,000 in the past year alone, embedding quality assurance into every part of the advice process.”
WT Financial Group
A Credible Ambition, But With Blind Spots
“I had a marvellous time ruining everything.”
The Last Great American Dynasty
WT Financial Group’s narrative is powerful: scale, speed, and a data-enabled quality loop. Their RMF claims are backed by impressive numbers, 11,000 reviews, 7,125 improvements, and a sub-two-day turnaround.
But when positioned as the “operational backbone,” I think we’re sitting at the “Peak of Inflated Expectations,” expecting that AI-driven surveillance and file reviews will solve all compliance and conduct risks. In reality, we’ll plunge into Gartner’s “Trough of Disillusionment” once the limitations, blind spots, and cultural implications of AI-driven compliance become clear.
This may seem to be a bleak and brutal assessment, but it’s not a rejection of RegTech; it’s simply a rejection of wishful thinking. AI can improve consistency and detect issues at scale. But despite the tremendous opportunities technology may provide to licensees, advisers and consumers, it cannot replace judgment, supervision, or culture.
AI is not a silver bullet.
As Dr H. Gilbert Welch observed in Overdiagnosed: Making People Sick in the Pursuit of Health (2011), technological advances often create new harms by overdiagnosing superficial issues while overlooking what matters most. In financial services, the same risk applies: AI-driven compliance frameworks may detect technical defects while missing the deeper conduct failures that truly harm clients.
Worse still, prioritising checklists and quantitative data over culture, conduct, character, and competence risks measuring the wrong things and providing false assurances. At scale, without indemnities or effective oversight, the regulatory, reputational, and financial consequences could be catastrophic.
On paper, AI-driven compliance looks like rigour. In reality, it may be regulatory theatre: compliance by impression.
Limited Sight, Limited Scope
AI reviews are strong at spotting what is missing on the page—forms not completed, disclosures absent, numbers misstated. But misconduct rarely announces itself in templates. It emerges in the behaviours and drivers that sit behind the paperwork: sales targets that incentivise product bias, cultural pressure to meet volume metrics, or advisers gaming the system by presenting “clean-skin” applications that omit inconvenient facts.
History offers a warning. During the Royal Commission, thousands of apparently compliant files were found to conceal systemic misconduct. The files passed tests of form, but failed the test of substance. The same dynamic applies today: if success is measured by volume of files reviewed, speed of turnaround and absence of issues, adviser behaviour can be misread, ignored, or even rewarded for its efficiency in avoiding scrutiny.
In our experience, Licensees’ reliance on these AI systems often undermines their moral leadership by entrenching a “tick-the-box culture”. Advisers learn what the model tests for and adjust their paperwork to satisfy it, without necessarily changing their approach or modifying their behaviour. This is compliance theatre where procedural neatness masks an absence of professionalism. Commissioner Hayne observed that the “safe harbour” steps practically reduced a profound professional obligation to a checklist of prescriptive processes. The risk is that AI-driven RMFs may now replicate that flawed strategy at scale.
Some of these limitations are structural, rather than strategic. AI can only interrogate the data provided against pre-set models. It cannot ask what was left unsaid, what pressures shaped the advice, or how the adviser treated the client in real interaction. File reviews alone, manual or AI-driven, can miss misconduct that surfaces only in conversation, complaint handling, or by subtly testing conduct that technically satisfies compliance, but falls short of ethical expectations and genuine best interests.
An effective compliance framework requires more than formalism. It requires a systematic and consistent assessment of adviser competence, character, conduct, and culture. These elements defy pattern recognition. They require judgment, qualitative oversight, and cultural evaluation. Without these dimensions, the AI-driven compliance risks mistaking carefully curated client files for ethical advice, and reassurance metrics for genuine consumer protection.
New Tech, Old Failures (at scale)
AI can accelerate detection, and at scale, it can provide broader insights by analysing larger samples and running more consistent testing. It can also be significantly cheaper and faster than purely human or hybrid approaches, but it introduces model risk, privacy risk, explainability issues, and service-provider risk. Without bias testing, oversight, and clear accountability, AI tools may create blind spots bigger than the problems they are designed to solve.
Equally, service-provider oversight matters. If proprietary systems rely on third-party vendors or cloud-based AI engines, licensees must actively manage vendor risk by testing resilience, availability, and data security.
Regulators and privacy authorities increasingly expect structured AI governance. This includes model registers, regular bias and drift testing, clear escalation channels, and privacy impact assessments. Without these, reliance on AI embeds opaque decision-making and creates dependency without accountability. Unless advisers and compliance staff understand why a file is flagged or cleared, it undermines trust in the system.
At scale, AI doesn’t just scale insight; it can scale ignorance. Failures become systemic, not incidental. Key risks include:
- Model Risk: AI trained on outdated or narrow datasets may replicate systemic blind spots. If product or conduct risks shift, the model won’t see them until it’s too late.
- Explainability Failure: Advisers may not know why their file was flagged, or worse, why it wasn’t. That undermines both trust and accountability.
- Privacy and Consent: AI reviews often mean broad data access. Without proper consent or minimisation, this can breach APPs and trigger significant OAIC enforcement.
- Vendor Dependency: Licensees relying on third-party AI must oversee availability, bias testing, security, and failure protocols. Otherwise, they inherit outsourced risk with no indemnity worth enforcing.
When AI becomes the dominant assurance tool, its failures are no longer minor. They are systemic control failures. The illusion of control becomes a vector for deep, embedded misconduct.
Beyond Standards: Closing the Gaps in AI-Driven RMFs
Not all AI adoption is superficial. We’re convinced that AI can enhance, rather than erode, compliance when it’s properly managed. For licensees adopting AI-driven RMFs, it’s critical to align your RMF with regulatory and risk management standards. Any successful rollout will explicitly consider:
- Corporations Act Obligations (s912A): AI reviews support efficiency but cannot ensure fairness or address cultural drivers of misconduct.
- ASIC Expectations: While ASIC welcomes RegTech, it stresses that remuneration, culture, and conflicts cannot be solved through file audits alone.
- APRA CPS 230 (from July 2025): Requires operational resilience, third-party oversight, and conduct risk monitoring. “World-leading” frameworks must meet these higher benchmarks.
- OAIC Privacy Principles: AI frameworks must embed transparency, accountability, and privacy-by-design.
- ISO 31000: Risk management should be integrated, human-centric, and culturally aware—over-reliance on quantifiable file data risks misdiagnosis.
- AFCA Risk Exposure: Clients harmed by technically compliant but ethically deficient advice may succeed in external dispute resolution. Where AI frameworks are used as compliance evidence but fail to detect or prevent client harm, this exposes licensees to systemic remediation risk and reputational blowback.
But compliance is not achieved by aligning to standards alone; it must be embedded in daily practice:
- Add Conduct-Centric Metrics: Track switching rates, product concentration, and vulnerable client interactions.
- Demonstrate “Efficiently, Honestly, Fairly”: Publish client outcome data, complaints upheld, adviser discipline actions, and remediation.
- Audit Vendor Claims: Demand evidence of false positives/negatives and model drift testing.
- Strengthen AI Governance: Maintain model registers, human-in-the-loop escalation, and vendor due diligence aligned to CPS 230.
- Integrate With Breach Systems: Ensure AI-detected issues feed into RG 78 breach assessments and s912DAA obligations.
- Shift from Document-Centric to Human-Centric Risk Models: Redesign compliance frameworks to evaluate advisor behaviour, intention, and ethical reasoning, not just paperwork accuracy. Incorporate role-play, interview-based assessments, and peer evaluations.
- Reframe AI as an Advisor, Not an Arbiter: Position AI tools as decision-support systems rather than authorities. Create layered assurance models where human judgment moderates and interprets AI findings, preserving accountability. Some firms are already striking the right balance. Platforms like [complye] demonstrate how AI can support rather than replace human expertise. By combining scalable machine learning with consistent human oversight, they keep the focus on client outcomes, adviser conduct and cultural indicators; strengthening compliance without surrendering professional responsibility.
- Rebuild Governance Around Cultural Competence: Integrate conduct-centric metrics into board reporting to track ethical decision-making patterns, cultural red flags, and advisor self-reflection practices, moving beyond reactive file reviews.
- Break AI out of the Server Room: Require governance boards that include ethics, legal, operations, and frontline staff, not just data scientists, to ensure alignment with professional values, not just technical performance.
- Design “False Negative” Stress Tests: Introduce mechanisms that deliberately test for undetectable misconduct by simulating edge cases and “gaming” AI review systems. This reveals both the model’s limitations and human behaviour under surveillance.
By embedding these practices, licensees can move beyond regulatory theatre to meaningful compliance that integrates both technology and judgment.
Quick Reference: What AI Frameworks Miss
- Conduct Risk: Harmful behaviour that hides behind technical compliance.
- Model Risk: Inaccurate outputs due to poor data or assumptions.
- Explainability Gaps: Users can’t understand how decisions are made.
- Vendor Risk: Third-party providers may be unaccountable or insecure.
- Privacy Breaches: Overcollection, poor consent, or inadequate safeguards.
- Measurement Myopia: Optimising for what’s measurable, not what matters.
- Over-Reliance: Assuming automation replaces critical thought or challenge.
- Data Bias: Legacy data can embed inequality or blind spots.
Dispel the Illusion of Control
AI-driven risk frameworks offer clear benefits in scale, speed, and consistency. They can reduce manual workload, lower costs, and spot issues more quickly than traditional reviews. When implemented thoughtfully, AI can be a valuable partner in compliance. By automating routine checks, surfacing anomalies, and providing timely insights, it frees compliance staff to focus on higher-order risks that require demonstrated expertise and professional judgment.
But AI-driven RMF are not a complete, or even adequate, solution. We’ve seen numerous failures overlooked by “industry-leading” AI and undetected by Licensees who are overly confident about the capability of the technology. Licensees should pursue better solutions, but also appreciate that over-reliance on AI risks misdiagnosing problems, mistaking procedural neatness for ethical conduct, and embedding blind spots at scale.
Remember that AI-enabled risk frameworks are not a silver bullet. They are tools, powerful, but limited. Used poorly, they create blind spots. Used alone, they embed risk. Used at scale, they create systemic issues.
If your RMF can’t detect how your advisers think, act, and treat their clients, then it isn’t managing conduct risk. It’s managing documents. That’s a profoundly limited approach, but the greater risk is not that AI only manages documents, but that leaders mistake this for managing culture and conduct.
If your organisation is relying on AI to manage compliance, it’s time to look beyond the dashboard.
At Assured Support, we provide independent compliance reviews, AFSL audit support, and bespoke risk management solutions that blend innovative technology with sharper judgment. Don’t let regulatory theatre undermine real risk management. Let’s design a framework that sees what matters.
If you enjoyed this read, you might also like:
- The Laws of Compliance
- Navigating Grey Zones in Compliance
- Risk Management 2.0 for a Small AFSL: Practical, Adaptive, and Intent-Led
Frequently Asked Questions
AI frameworks can review documents quickly and at scale, but they lack the ability to assess adviser intent, ethical reasoning, and cultural drivers. This creates blind spots where technically compliant but ethically deficient conduct goes undetected.
Over-reliance can lead to a “tick-the-box” culture, where advisers optimise for what the AI tests rather than improving real behaviour. This results in procedural compliance masking deeper conduct risks, undermining genuine consumer protection.
Licensees should treat AI as a decision-support tool, not a decision-maker. Embedding AI within layered assurance models, incorporating conduct-centric metrics, and maintaining strong human oversight are key to effective implementation.
They must ensure operational resilience, manage third-party risk, conduct regular model testing, and align AI governance with privacy and fairness standards. Sole reliance on AI does not satisfy expectations under s912A, CPS 230, or ASIC guidance.
AI can miss red flags hidden in adviser behaviour, client conversations, cultural pressures, and ethical failures not visible in documents. Key risks include model bias, explainability gaps, privacy breaches, and failure to assess intent.