Skip to main content

Looking for 360 View?

You're in the right place. 360 View is now part of Abrigo.
Read the press release

How AI helps financial institutions with AML/CFT monitoring

Terri Luttrell, CAMS-Audit, CFCS
October 9, 2026
0 min read

Artificial intelligence (AI) may feel like the newest topic in banking, but financial institutions have used forms of AI for years. Machine learning, for example, already helps institutions analyze large volumes of financial transactions and identify activity that warrants closer scrutiny.

You might also like this checklist, "6 steps for compliance with the new AML/CFT program rules."

DOWNLOAD

From machine learning to agentic AI

What is changing is the sophistication of the technology. Generative AI and agentic AI are creating new possibilities for financial crime professionals. Banks and credit unions considering AI in AML/CFT monitoring have an opportunity to make better use of data, focus investigators on higher-risk activity, and potentially create a more effective risk-based program.

AI does not remove a financial institution’s responsibility for its AML/CFT program. Human judgment, governance, testing, documentation, and risk-based oversight remain critical. But AI can help financial institutions deal more effectively with escalating AML/CFT compliance burdens, friction in workflows, and an ever-changing risk environment.

AML/CFT monitoring has always been a data challenge

AML investigators sift through enormous amounts of information. Transaction monitoring systems generate alerts based on scenarios and thresholds. Investigators gather customer information, review transaction histories and patterns, document findings, and determine whether further investigation or reporting of suspicious activity is warranted.

Financial institutions also continue to face staffing and resource challenges. According to a study by McKinsey & Company, approximately 20% of a bank’s full-time employees are dedicated to solving financial crime activities, with 60% relying on manual processes that are labor intensive. Insufficient resources can contribute to alert backlogs, inappropriate alert disposition, or monitoring that is not reasonably designed to capture the institution’s risks.

Technology can help manage this workload, but efficiency cannot be the only objective. Instead, financial institutions should also aim to use AI to improve their ability to identify and investigate potentially suspicious activity based on their unique risk profiles.

The Financial Crimes Enforcement Network (FinCEN) has encouraged responsible innovation in AML/CFT. The proposed AML/CFT program rule, published in 2026, discusses machine learning, generative AI, blockchain monitoring and analytics, digital identity, and Application Programming Interfaces (APIs) as innovative approaches that institutions may evaluate to combat financial crime more effectively.

Machine learning adds another dimension to monitoring

Traditional transaction monitoring relies heavily on rules, scenarios, and thresholds. Rules remain valuable because they are understandable, testable, and can be tied to known risks and typologies. But static rules may not identify unusual patterns outside established parameters.

Machine learning can complement rules-based monitoring by analyzing data for relationships, patterns, and anomalies that may be difficult to identify using predetermined thresholds alone. The Federal Reserve has described machine learning as a mature form of AI already used by financial institutions, including for fraud detection and prevention.

AI is not one technology, and using machine learning does not mean turning an AML program over to a black box and removing analyst judgment. Agentic AI has capabilities throughout the AML lifecycle, from identification, triage, investigation, and reporting, but human-in-the-loop must also be incorporated into these processes. Understanding the technology and being able to explain how it works to regulators is critical for the integrity of any AML program.

Machine learning can help identify unusual customer behavior, recognize patterns across large datasets, and prioritize alerts based on risk. The investigator still evaluates that information in context.

AI can help investigators focus on higher-risk activity

A typical transaction monitoring alert investigation may require an analyst to review customer information, previous alerts, account activity, counterparties, and transaction patterns. Gathering that information from multiple systems can constitute a substantial portion of an investigation.

AI can help AML investigators work more efficiently by identifying connections between customers and transactions, summarizing investigative histories, and prioritizing alerts. Machine learning can also support customer segmentation, automated scenario tuning, and alert scoring to help financial institutions focus resources on higher-risk activity.

Machine learning can also help address a longstanding monitoring challenge: false positives. A transaction may trigger an alert because it meets a scenario’s parameters even though the activity is reasonable for that customer. By considering historical behavior, customer risk, counterparties, and related activity, machine learning can provide additional context for prioritizing alerts, as well as addressing false positives.

Many financial institutions already use AI and machine learning for fraud detection, analyzing transaction patterns to identify potentially fraudulent activity. The same principle is relevant to AI in AML/CFT monitoring.

Reducing alert volume, however, should not be the primary measure of success. Institutions need to understand why alerts were reduced and whether monitoring continues to identify the risks it was designed to detect.

From generative AI to agentic AI

Generative AI and agentic AI are different technologies. Generative AI produces an output in response to a request. It might summarize a document, organize information, or draft text for human review. An example of this would be an AI-powered AML assistant that can auto-generate investigation summaries and SAR-ready draft narratives.

Agentic AI goes a step further by taking action rather than simply providing information. An AI agent can determine the steps needed to complete a task, access relevant data, and carry out multiple activities with limited human intervention. For AML departments, this could mean automating portions of the investigative process while keeping investigators responsible for reviewing findings and making decisions.

Consider an alert involving unusual wire activity. An investigator traditionally might have to retrieve the customer’s profile, review previous alerts and transactions, research counterparties, compare activity with the customer’s expected behavior, and document the findings.

An agentic AI system could take the process further by coordinating multiple steps with limited human intervention. For example, it could collect and verify customer data, search external sources for adverse media, evaluate results based on risk and relevance, and prioritize cases requiring investigation. It could then generate case summaries, document its actions, and incorporate investigator feedback to improve future results. This would allow AML professionals to focus on higher-risk activity while maintaining oversight of the process.

Federal Reserve officials have discussed agentic systems capable of planning and executing multistep processes, although the technology remains in its early stages.

The investigator, or human-in-the-loop, remains critical. Agentic AI may change how information is gathered and analyzed, but human judgment should remain central to investigative decisions.

 

Governance must evolve with the technology

As AI capabilities increase, so does the importance of governance. Financial institutions need to understand what the technology does, what data it accesses, how outputs are generated, how it was tested, where errors can occur, and which decisions require human approval.

In April 2026, the Federal Reserve, FDIC, and OCC revised their supervisory guidance on model risk management. Traditional statistical and quantitative models, as well as non-generative, non-agentic AI, remain within the scope of the guidance. The agencies clarified that novel and rapidly evolving generative and agentic AI models are not currently within their scope. Institutions should use their risk management and governance practices to determine appropriate controls for tools outside the guidance.

In addition, other agencies have developed or pointed to frameworks to help financial institutions understand governance requirements. The Conference of State Bank Supervisors recently released an AI Supervisory Framework that could shed light on the general approach, types of questions, and the information that a state examiner may request regarding the institution’s AI-based products, services, and tools. Abrigo also has resources, including an AI governance vendor questionnaire.

AML professionals evaluating AI in AML/CFT monitoring should consider whether investigators can understand and challenge AI output, how performance will be monitored, what happens when the technology is wrong, and what controls apply to third-party providers. Controls should reflect the use case. A tool that summarizes case notes does not pose the same risk as an agent that performs multiple tasks across customer and transaction systems.

Start with the AML problem

Many financial institution staff can get overwhelmed thinking of the possible uses of AI, but a good place to start is with the AML problem:

  • Where are investigators spending unnecessary time?
  • Which monitoring scenarios generate large numbers of alerts with little investigative value?
  • Is relevant data difficult to retrieve?
  • Are investigators repeatedly performing the same manual research?
  • Are new products or payment channels creating risks that existing processes struggle to monitor?

Once the problem is clear, the institution can determine whether rules, machine learning, generative AI, agentic AI, or a better process is the appropriate solution.

This approach also keeps the focus where it belongs. Experienced AML professionals understand customers, recognize context, connect information, and apply judgment. Technology should help them spend more time on work that requires those skills.

The future of AI in AML/CFT monitoring

AI capabilities will continue to evolve, and agentic AI could eventually change how financial crime investigations are performed. Financial institutions do not need to move directly from traditional monitoring to autonomous agents.

A deliberate approach allows institutions to identify where machine learning can strengthen monitoring, explore generative AI where it can safely assist investigators, establish appropriate governance, and evaluate agentic AI based on the risks and benefits of the tasks it would perform.

The strongest AML programs will combine experienced financial crime professionals with technology that helps them identify relevant information, recognize risk sooner, and spend their time whe

Frequently Asked Questions

How can AI help financial institutions with AML/CFT monitoring??

AI can help analyze large volumes of activity, identify patterns or connections, prioritize alerts, and organize information for investigators. Its value depends on whether it helps the institution better identify and investigate risks tied to its own customers and activities.

Can AI reduce false positives in transaction monitoring?

Machine learning can add context, such as a customer’s historical behavior, risk profile, counterparties, and related activity, to help prioritize alerts. A lower alert count alone does not show that monitoring is more effective. Institutions should understand why alerts were reduced and confirm that the system still identifies the risks it was designed to detect. 

What is the difference between generative AI and agentic AI in AML?

Generative AI can summarize information or draft text in response to a request. Agentic AI can plan and perform multiple steps toward a goal, such as retrieving customer information and organizing prior alert findings for review. Agentic AI is still developing, and investigators should remain central to decisions.

What governance should financial institutions apply to AI in AML/CFT monitoring?

Institutions should understand what a tool does, what data it accesses, how it produces results, how it was tested, and where errors may occur. They should also monitor performance, set appropriate human review requirements, and consider the risks of third-party providers. Controls should reflect the tool’s use and the decisions it can affect.

This blog was written with the assistance of ChatGPT, an AI large language model, and was reviewed and revised by the subject-matter expert.

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

 

Don't settle for out-of-the-box AML software if you want the best. BAM+ was built for your unique risk profile.

learn more about bam+
About the Author

Terri Luttrell, CAMS-Audit, CFCS

Compliance and Engagement Director
Abrigo
Terri Luttrell is a seasoned AML professional and former director and AML/OFAC officer with over 20 years in the banking industry, working both in medium and large community and commercial banks ranging from $2 billion to $330 billion in asset size.

Full Bio

About Abrigo

Abrigo enables U.S. financial institutions to support their communities through technology that fights financial crime, grows loans and deposits, and optimizes risk. Abrigo's platform centralizes the institution's data, creates a digital user experience, ensures compliance, and delivers efficiency for scale and profitable growth.

Make Big Things Happen.