Skip to main content

Looking for 360 View?

You're in the right place. 360 View is now part of Abrigo.
Read the press release

Human-in-the-loop: Enhancing AI in AML/CFT software for competent case management

Terri Luttrell, CAMS-Audit, CFCS
September 24, 2024
0 min read

Banks can balance AI automation with human oversight by automating repeatable analytical tasks while establishing review points for consequential decisions.

Effective oversight includes clearly defined escalation thresholds, qualified human reviewers, documented overrides, audit trails, assigned accountability, and ongoing testing of AI performance. 

You might also like this checklist, "6 steps for compliance with the new AML/CFT program rules."

DOWNLOAD

Why human oversight matters for AI in AML/CFT

FinCEN’s evolving AML/CFT program framework emphasizes risk-based, reasonably designed programs that allow financial institutions to focus resources on higher-risk activity. FinCEN 's latest guidance is a new proposed rule that encourages financial institutions to consider innovative tools—including machine learning, generative AI, digital identity, blockchain monitoring, and application programming interfaces—when they may help combat financial crime. Human expertise remains essential for determining how these tools fit within an institution’s program and for reviewing complex cases. As institutions introduce AI into AML/CFT workflows, governance is especially important: institutions need to understand where automation is appropriate, where human judgment is necessary, and how decisions are documented. 

What human-in-the-loop means for AI in banking

Human-in-the-loop refers to the collaboration between AI systems and human experts, ensuring that machines do not operate in isolation. While AI can process vast amounts of data quickly, detect patterns, and even reduce false positives in suspicious activity monitoring, it lacks the contextual understanding and decision-making capabilities that experienced AML professionals provide. As AML/CFT investigators understand, the BSA world is not black and white. While some alerts are simple and can easily be handled by AI, many are complex and require extensive analysis. 

Why human-in-the-loop matters in AI-powered AML/CFT case management

The approach that keeps a human in the loop is essential in alert and case management for several reasons.

1. Human judgment adds context to AI-generated AML alerts 

AI excels at spotting unusual patterns, but not all anomalies indicate fraud or money laundering. Human experts use contextual judgment to differentiate between normal behavior and illicit activities. AI can help reduce false positives for simple alerts that can drain resources and leave the complexities to human analysis.

2. Human review supports complex AML/CFT investigations 

Certain AML/CFT cases involve complex data layers or require an understanding of industry-specific regulations. A purely AI-driven approach may miss these nuances. Human investigators ensure the broader picture is considered, especially in high-risk cases that demand more than just data-based conclusions.

3. Human oversight helps institutions respond to changing financial crime risks 

Financial crime evolves quickly, with fraudsters continuously finding new ways to exploit systems. AI models need regular updates and supervision to adapt to these new threats. By integrating human expertise, institutions can ensure AI is monitoring emerging threats and regulatory changes, preventing outdated models from leaving blind spots and improving risk management.

4. Audit trails support explainability and regulatory review 

AML/CFT regulations require institutions to justify their actions and decisions during audits or examinations. HITL ensures that AI recommendations are backed by human review and documentation, providing an additional layer of validation that supports defensible oversight and documentation.

5. Testing and validation build confidence in AI-assisted decisions 

Financial institutions that are new to AI may hesitate to rely entirely on machines for critical tasks like AML/CFT compliance. Human oversight builds confidence in AI systems by assuring that machine-generated results align with professional standards and regulatory expectations. Testing of any model is critical to the success of any AML/CFT program.

 A framework for human oversight of AI in banking 

Human-in-the-loop oversight is most effective when it is built into a financial institution’s processes before technology is deployed. For AML/CFT teams, that means defining where investigator review is needed, when an automated process should escalate an issue, how decisions are documented, and who remains accountable. These conversations can help financial institutions gain efficiencies from AI while preserving staff involvement in decisions that require context, judgment, or additional scrutiny. 

Define human review points 

Financial institutions should determine in advance which AI-supported activities can move through routine workflows and which require review by qualified personnel. Not every automated output will require the same level of scrutiny. Compliance team review may be required when activity involves higher-risk customers, unusual or complex transaction patterns, contradictory information, potentially consequential decisions, or outputs that do not provide sufficient confidence for the next step in a workflow. 

Establish escalation thresholds 

Human-in-the-loop oversight should not undermine many of the efficiencies the technology is intended to provide. Rather than requiring manual review of every AI-supported action, institutions can establish triggers that identify a need for review. Those triggers might include unusually high-risk scores, significant departures from expected customer behavior, unresolved data conflicts, repeated alerts, higher-risk customer categories, policy exceptions, or outputs that fall outside established confidence or quality parameters. 

Escalation thresholds should reflect the institution’s risk profile, policies, and intended use of the technology. They should also be reviewed periodically as customer behavior, financial crime risks, data, and technology change. 

Maintain an audit trail 

A financial institution should be able to understand how an AI-supported decision progressed from initial analysis to final disposition. Maintaining an audit trail can help management, auditors, and examiners evaluate how automated processes and human judgment interact. Depending on the technology and use case, documentation could include the AI-generated output or recommendation, relevant information available to the reviewer, the employee responsible for the review, any changes or overrides, the rationale for significant decisions, timestamps, required approvals, and the final disposition. 

Institutions should also document changes to configurations, thresholds, or workflows that could affect how the technology produces or routes results. Clear records can help demonstrate that human oversight is a defined part of the process rather than an informal safeguard. 

Assign accountability

AI can assist AML/CFT professionals with tasks such as analyzing information, prioritizing work, identifying patterns, or drafting portions of case documentation. However, technology does not assume responsibility for the institution’s AML/CFT program, or the decisions made within it. 

Financial institutions should assign clear ownership for reviewing AI-supported outputs, investigating escalated activity, approving significant decisions, monitoring system performance, and overseeing the controls surrounding the technology. This will help institutions avoid ambiguity when multiple teams, systems, or third-party providers are involved.  

Test and monitor performance 

Human oversight should continue after an AI-enabled process is implemented. Financial institutions should periodically evaluate whether the technology and related controls continue to operate as intended. 

Monitoring may include reviewing system performance, validation results, employee overrides, escalation patterns, and false-positive or false-negative trends when they can be reasonably measured. Institutions should also consider whether changes in data, customer behavior, products, transaction patterns, or financial crime risks could affect performance. 

Patterns in manual intervention can provide useful information as well. Frequent overrides or unexpected escalation volumes, for example, may indicate that thresholds, workflows, data inputs, or other controls warrant further review. 

How banks should evaluate human oversight in AML/CFT software

When evaluating an AML/CFT monitoring solution, financial institutions should carefully consider how much HITL is necessary for their compliance program. Here are some key considerations:

  • Institutions should assess their risk-based AML/CFT program to determine what degree of HITL is needed to avoid regulatory criticism. If the institution operates in high-risk markets, such as money services businesses or cannabis, or deals with complex customer profiles, human involvement can provide the additional scrutiny needed to ensure that suspicious activity is not missed.
  • Once the level of human intervention is determined based on the institution’s risk profile, ask the right questions during AML software due diligence:
    • How does the system incorporate human oversight into AI decision-making?
    • Does the case management feature allow for humans to intervene in high-risk cases or flagged alerts?
    • What roles do AML/CFT experts play in adjusting AI models and improving accuracy?
    • How easy is it to review, override, or update AI-generated recommendations?

Balancing AI automation and human oversight in banking

AI is a powerful tool and is very useful in streamlining AML/CFT suspicious activity monitoring, but its effectiveness is strengthened with the involvement of human experts. HITL ensures that technology complements human decision-making rather than replacing it. For financial institutions, this collaborative approach leads to program confidence, more accurate alert management, better resource allocation, and more robust compliance outcomes. By balancing the strengths of AI and human expertise, institutions can enhance their fight against financial crime while maintaining the confidence and soundness of their AML/CFT program.

Frequently Asked Questions

How do banks balance AI automation with human oversight?

Banks can balance automation with human oversight by using AI for tasks where it can improve efficiency and consistency while establishing clear points where qualified employees review, challenge, or act on its output. A risk-based approach to AI in banking can include defined review responsibilities, escalation thresholds, documented overrides, audit trails, and ongoing testing and monitoring. 

Do banking regulators require human oversight of AI?

There is no single U.S. banking regulation requiring a person to review every output produced by AI. However, regulators and government frameworks increasingly emphasize risk-based governance, controls, testing, monitoring, transparency, and accountability when financial institutions use AI. 

Importantly, the level of oversight should reflect the technology and risk involved. Updated interagency model risk management guidance issued in April 2026 takes a risk-based rather than prescriptive approach, and generative and agentic AI are specifically outside the scope of that guidance. Institutions should therefore determine appropriate governance and controls based on how the technology is being used and the risks it presents

What AI decisions in AML/CFT should receive human review?

Human review is particularly important when an AI-supported process involves higher-risk, complex, ambiguous, or consequential activity. Examples can include alerts involving unusual customer behavior, conflicting information, higher-risk customers or products, complex transaction patterns, potential suspicious activity, or situations where available information does not clearly support an automated recommendation. 

Rather than requiring investigators to manually review every automated step, financial institutions can establish risk-based review points. This allows AI in banking to support routine analysis while directing employees’ expertise toward cases where judgment and context are most valuable. FinCEN’s current proposed AML/CFT framework similarly emphasizes allowing institutions to focus resources on higher-risk activity based on their own risk assessments. 

What should trigger escalation from AI to an AML investigator?

Escalation criteria should reflect the institution’s risk profile, policies, technology, and specific AI use case. Potential triggers could include unusually high risk scores, significant departures from expected customer activity, inconsistent or incomplete information, involvement of higher-risk customers or products, repeated alerts, policy exceptions, or outputs that do not meet predetermined confidence or quality thresholds. Institutions should document these escalation criteria and periodically evaluate whether those thresholds continue to direct attention to the risks. 

What should an AI audit trail include?

An audit trail should provide enough information to understand how an AI-supported AML/CFT decision moved from initial analysis to final disposition. Depending on the system and use case, records may include the AI-generated output or recommendation, relevant supporting information, the employee who reviewed the matter, actions or overrides taken, the rationale for significant decisions, timestamps, required approvals, and the final disposition. 

Institutions should also consider documenting changes to workflows, thresholds, configurations, or other controls that could affect results. Maintaining this information can make AI in banking more transparent and help management, auditors, validators, and examiners understand how technology and human judgment work together. 

Who is accountable for AI-assisted AML/CFT decisions?

Using AI does not transfer responsibility for an institution’s AML/CFT program to the technology or its vendor. Financial institutions should establish clear roles and responsibilities for employees who govern the technology, review its output, investigate cases, approve significant decisions, monitor performance, and oversee the broader AML/CFT program. 

FinCEN’s April 2026 proposed AML/CFT program rule continues to contemplate a designated individual responsible for establishing and implementing the program and coordinating and monitoring day-to-day compliance. Clear accountability is therefore an important component of AI in banking: technology can assist employees with analysis and workflow, but the institution remains responsible for its program, controls, and decisions. 

This blog was written with the assistance of ChatGPT, an AI large language model, and was reviewed and revised by the subject-matter expert.

Don't settle for out-of-the-box AML software if you want the best. BAM+ was built for your unique risk profile.

learn more about bam+
About the Author

Terri Luttrell, CAMS-Audit, CFCS

Compliance and Engagement Director
Abrigo
Terri Luttrell is a seasoned AML professional and former director and AML/OFAC officer with over 20 years in the banking industry, working both in medium and large community and commercial banks ranging from $2 billion to $330 billion in asset size.

Full Bio

About Abrigo

Abrigo enables U.S. financial institutions to support their communities through technology that fights financial crime, grows loans and deposits, and optimizes risk. Abrigo's platform centralizes the institution's data, creates a digital user experience, ensures compliance, and delivers efficiency for scale and profitable growth.

Make Big Things Happen.