Month: September 2023

“AI in Compliance” Webinar Summary: Emerging Trends and Technologies

On 20 September 2023, Ripjar held an AI in Compliance webinar, welcoming financial crime compliance experts to discuss the impact of emerging trends and technologies on the industry. The exclusive, live-only event was hosted by Ripjar’s Chief Product Product Officer, Gabriel Hopkins, with Michael Heller, Head of Financial Crime Compliance Proposition at Dow Jones, and guest speaker Andras Cser, VP Principal Analyst at Forrester. 

With awareness of artificial intelligence in financial crime applications higher than ever, firms around the world are exploring the technology’s potential and its limitations. Focusing on that dynamic, the AI in Compliance webinar involved a guest speaker presentation and a panel discussion, with opportunities for audience members to submit questions to the expert speakers. 

Let’s take a closer look at the key insights and discussion points from the webinar:

Introductory Presentation

Guest speaker Andras Cser opened the panel with an introductory presentation offering an industry perspective on the current role of Artificial Intelligence (AI) in compliance. 

The Role of AI

The presentation explored uses of AI in the compliance ecosystem and how the technology may help with a range of critical compliance processes – from addressing financial crimes such as money laundering and fraud, to helping enhance regulatory scrutiny, minimising customer friction, and increasing operational efficiency. 

AI and machine learning (ML) tools have recently demonstrated “unprecedented improvements” in compliance contexts. These improvements include:

  • More standardised, FATE-compliant vendor-developed models.
  • Models with fewer re-training requirements that can learn autonomously from analyst and investigator decisions. 
  • More preventative models that can identify attempts to commit fraud or launder money before they take place.  
  • Models with better governance and explainability out of the box – simplifying audit requirements
  • More cloud/SaaS-delivered fraud management and AML models.

Those advancing capabilities have clear potential for AI-powered Know Your Customer (KYC) and Watchlist Management (WLM) solutions in the following areas: 

  • Predictive methodologies
  • Adverse media and politically exposed person (PEP) screening
  • Natural language processing (NLP) and link analysis between entities 
  • Information processing, discarding irrelevant data points in large quantities of data
  • Shortening investigation times
  • Filtering and managing watchlists

Supported by AI, these applications promise a wider range of compliance benefits, such as a reduction in false positive alerts, enhanced contextual analysis and risk scoring, and a reduction in the need for employee focus. 

AI Best Practices

In order to capitalise on the promise of AI, it’s important that firms understand the best practices for its integration:

  • AI model governance needs to be able to prove that challenger models perform better than current models. 
  • Firms need to use statistical measurements and high quality SDLC processes for building AI models. This may be easier with supervised AI models which are trained and continuously tested against a set of truth data, as opposed to unsupervised models where deductions are made without that reference point. 
  • Firms must work with regulators, such as FINCEN and FINRA, in the development and application of AI models. 
  • AI models should be designed for explainability in investigative contexts. 
  • Firms should keep partial retrainings in sight in order to reduce the need to retrain models from scratch.  

The Future of AI

Casting an eye to the horizon, firms may expect the following AI compliance developments: 

  • Increased adoption of cloud-based analytics and cloud-based delivery methods for watchlist management, and adoption of new transaction monitoring tools for addressing money laundering. 
  • Increased use of AI in addressing risks in peer-to-peer payments and in cryptocurrency payments. 
  • Increasing use of NLP to analyse the textual content surrounding transactions and in adverse media stories.
  • Advanced link analysis to determine connections between transactions and other data points, such as telephone numbers or addresses. 
  • Predictive investigation of potential financial activity that exhibits criminal ‘red flags’. 

Panel Discussion

Following the presentation, Gabriel Hopkins framed the panel discussion by referencing the renewed “wave of excitement” about AI and machine learning tools in compliance and screening contexts. The discussion went on to cover the recent rise in popularity of generative AI and large language models, and the challenges that firms should expect as they seek to integrate the new technology.  

Where do you think we are in the cycle of industry attitudes to AI? 

Mike Heller suggested that AI was at a ‘midpoint’ – in the sense that, while there is excitement about its advancing capabilities, there is also concern about its risks, and a push from governments to regulate, as the technology is integrated into business functions. In the financial industry, that trend has given rise to a focus on ‘compliance-ready’ AI – meaning the introduction of tools that are explainable, auditable, and can be tested against the relevant metrics. Compliance-ready AI obviously requires a “significant amount of technical expertise” which will, in turn, require coordination with the regulatory community.  

Andras Cser raised the issue of data protection and privacy, and the need for developers to be very careful about how AI tools handle personal data. Generative AI may pose unique new compliance challenges: Cser pointed to the EU’s recent regulatory focus on the unacceptable risks of generative AI, including its potential to manipulate certain groups of people with deep fakes and voice synthesis. Essentially, Cser explained, with the benefit of generative AI, criminals may be able to automate their deception of customers, significantly increasing the scope and effectiveness of their illegal activities.   

Where do you see AI having the greatest impact in compliance?

Andras Cser pointed out that AI has been used for a long time in compliance (for example, in risk scoring models), and described its impact as “evolutionary” rather than revolutionary in these contexts. However, he suggested that generative AI might have the greatest impact in the investigative side of compliance. While investigators currently need to have an extensive understanding of the details of a particular case, generative AI has the potential to reduce that administrative burden, and provide guidance, and even assistance, to compliance teams. This trend might include AI systems answering questions or providing resources to help employees work with data and effectively remediate alerts. 

The predictive potential of AI will also be important for investigations. AI-enabled systems could be used to automatically identify patterns of behaviour indicative of money laundering or fraud – and alert investigators before the crime takes place. 

How will AI continue to improve established compliance processes?

Mike Heller highlighted the strength of AI tools in facilitating compliance screening at scale, including processing information, and analysing data from structured and unstructured sources. Heller re-emphasised the value of compliance-ready AI solutions, referencing Dow Jones’ partnership with Ripjar as a way to harness best-in-class technology for the purpose of screening vast amounts of customer risk data. He also mentioned feature engineering for existing models, with AI enhancing the explainability of certain processes in order to make them more accessible for auditors, regulators, and customers.  

How should organisations select their AI vendors and technology?

Andras Cser stressed the need for organisations to view AI models as “starting points”, seeking those with a combination of rules-based decision-making and machine learning features. He also suggested that firms should seek vendors that can provide a comparison of model efficiencies (between current champion and challenger models) in order to understand how a product will ultimately integrate within existing compliance infrastructure.  

Are there any AI tools that are white-listed by regulators?

Mike Heller pointed out that while there isn’t a current white-list of AI tools, organisations should survey their surroundings to find out which tools competitors use, how those tools have been tested, and how the systems have fared under review. Gabriel Hopkins noted that regulators have also been pushing organisations towards the integration of AI and machine learning tools as a way to enhance their screening processes. He added that while regulators “don’t want to give people carte blanche” they are nonetheless opening up to the wider use of these solutions.

Andras Cser pointed to the limitations of entirely heuristic compliance, which is particularly vulnerable to criminals that know how to exploit the rules. He characterised AI as the only known long-term strategy for dealing with evolving criminal methodologies, suggesting that regulators and institutions would need to work through initial challenges in order to optimise its use.  

How is guidance from organisations like the Wolfsberg Group helpful?

Following advances in AI and machine learning, Mike Heller noted that the Wolfsberg Group’s 2022 Negative News FAQs advised the use of technology as a means to screen against unstructured adverse media data. The move reflects a shift in the expectations of financial regulators towards firms integrating tools capable of matching the increasing sophistication of criminal methodologies – and effectively implies the use of machine learning-enabled technology.   

How should institutions approach the issue of explainability in AI models?

Mike Heller stressed the importance of AI providers being able to present documentation on how their model surfaces risk-relevant documentation. Organisations should then take that documentation through an internal review process with their compliance and legal departments to ensure alignment with their policies and risk-appetite. Andras Cser added the notion of feature extraction to that process – essentially as a means to ensure that the vendor is able to deliver an explanation for decisions taken in the AI risk scoring process. Cser went on to mention the benefit of having the vendor help with the operationality of the AI model, splitting responsibility for its management. 

Referencing the regulatory strictness of compliance and transaction monitoring requirements, Cser also suggested that AI offers a way to improve on existing models, including developing tools that boost the accuracy and efficiency of risk scoring. 

How would you recommend firms prepare for the ‘new wave’ of AI?

Looking back on years of industry experience, Mike Heller, noted a shift in the type of skills needed to manage compliance. Where once legal and regulatory expertise was required, today teams require individuals with project management, engineering, and technical backgrounds who can also be involved in the operational design and development of the tools. The next step may be to hire internal data scientists and AI experts to help bridge the gap between the regulatory and technical functions. 

Andras Cser emphasised the need for firms to move slowly in the implementation of new tools, and in understanding what exactly is being integrated. He highlighted the value of data scientists in the new AI landscape, who can assess the compatibility of vendors’ models, and provide a way of governing the development of the technology to ensure challenger models are better than champions. Ultimately, firms should seek to ensure that the basics of their models function as intended, and that their integration aligns with an organisation’s risk appetite.  

How are firms handling AI governance?

From a vendor’s perspective, Gabriel Hopkins noted the introduction of centralised model management committees, especially in global banks, as a way for firms to keep boards updated on the implementation of AI models. Expanding on that point, Mike Heller suggested that boards have been scrambling to understand how generative AI tools, such as ChatGPT, will impact their business operations, particularly in terms of compliance. He suggested that institutions that appoint compliance experts at the highest level will be better placed to handle AI integration and to address the challenges that may emerge in the future.  

Do you think regulators will expect a level of human input in the regulation of AI?

Taking a vendor’s perspective once again, Gabriel Hopkins suggested that regulators would “absolutely” expect human involvement in the implementation and execution of AI technology, and recommended that firms frame the integration of new AI tools as supporting the efforts of analysts in making compliance decisions.  

Echoing that point, Mike Heller remarked that the integration of AI technology will not make compliance easier, but rather make the process faster. The most important, critical decisions will continue to be made by analysts, who will, with the benefit of AI, be empowered to keep pace with criminal methodologies. Heller compared the evolution of AI tools with the history of sanctions compliance, where new technologies previously allowed financial institutions to scale-up their compliance response significantly. 

What’s the ‘number one’ takeaway that you’d share about the use of AI in compliance?

Stressing the importance of careful adoption, Mike Heller emphasised the need to keep pace with competitors while bridging the gap between technical and data expertise, and regulatory expectation. Andras Cser returned to the question of explainability, stressing that “explainable AI is always better than inexplicable AI”.   


To learn more about Ripjar’s AI compliance and screening technology, get in touch today

Luxembourg’s AML Regulations: An Overview 

Luxembourg is a small western European country with a global reputation for banking services and favourable tax laws. That reputation draws investment to the country, but also makes it a target for those who seek to use its financial system to launder money and commit other crimes. In 2021, a joint investigation by German and French journalists found that Luxembourg was being used to conceal funds linked to organised crime gangs from around the world. The report characterised Luxembourg as part of an “axis of tax avoidance” in Europe.   

Luxembourg’s government has pushed back strongly against the notion that it is not doing enough to address financial crime, and has made significant recent efforts to bolster the country’s anti-money laundering (AML) and counter-financing of terrorism (CFT) regulations. Those efforts have led to increased regulatory scrutiny, and a need for firms operating within Luxembourg to ensure they understand their risk environment, and achieve regulatory compliance. 

Given the importance of AML/CFT compliance in Europe and around the world, let’s take a closer look at Luxembourg’s AML regulations. 

Luxembourg’s AML Regulator: The CSSF

Luxembourg’s primary AML regulator is the Commission de Surveillance du Secteur Financier (CSSF). Established in 1998, the CSSF is responsible for “ensuring that all the persons subject to its supervision, authorisation or registration comply with the professional AML/CFT obligations”. In this capacity, the CSSF provides oversight for all banks, investment firms, and other types of financial institutions operating in Luxembourg. 

The CSSF’s duties and responsibilities include: 

  • Supervising and investigating financial institutions to ensure compliance with Luxembourg’s AML/CFT laws. 
  • Obtaining documents and other financial intelligence from persons under its supervision. 
  • Issuing sanctions against firms that do not comply with AML/CFT regulations. Sanctions may include warnings, fines, or occupational prohibitions. 

Luxembourg is a member of the Financial Action Task Force (FATF), the Wolfsberg Group, and the EU, and so the CSSF actively participates in international efforts to combat financial crime. The CSSF shares information with international counterparts and participates in the European System of Financial Supervision (ESFS) with the objective of enhancing and harmonising AML/CFT standards across the EU. 

Key Luxembourg AML Regulations

Luxembourg’s primary AML/CFT law is the Law of 12 November 2004 on the fight against money laundering and terrorist financing, also known as the AML/CFT Law. The law defines the offence of money laundering in Luxembourg and gives the CSSF its supervisory powers. 

In alignment with FATF recommendations and EU objectives, the AML/CFT Law requires that firms in Luxembourg take a risk-based approach to compliance. In practice, this means that firms must conduct risk assessments to gauge the level of criminal risk that their customers present, and then deploy proportionate compliance measures, with higher risk customers subject to a greater degree of AML/CFT scrutiny. 

EU AMLD: The EU issues periodic updates to its AML/CFT regulations, known as Anti-Money Laundering Directives (AMLD), which members must implement in domestic legislation. 

Accordingly, Luxembourg amends its AML/CFT Law to incorporate details of new AMLDs. The Sixth Anti-Money Laundering Directive (6AMLD) came into effect across the EU on 3 June 2021, introducing a range of new AML/CFT compliance obligations including new AML predicate offences, expanded criminal liability for money laundering, and increased minimum penalties. 

How to Comply with Luxembourg’s AML Regulations

Firms in Luxembourg must implement a risk-based compliance programme to meet their obligations under the AML/CFT Law. Effective AML compliance programmes in Luxembourg should include the following measures and controls: 

  • Customer due diligence: In order to assess risk accurately, firms in Luxembourg must perform suitable customer due diligence (CDD) to identify their customers. The CDD process should involve the collection and verification of names, addresses, dates of birth, and other identifying information. Higher risk customers should be subject to enhanced due diligence (EDD) measures.
  • Beneficial Ownership: To prevent financial criminals concealing their identities with shell companies or corporate infrastructure, firms should also establish the ultimate beneficial ownership (UBO) of customer entities with which they do business. 
  • Transaction screening: Firms in Luxembourg should screen customer transactions for signs of money laundering. These might include unusually high transaction amounts, transactions with high risk counter-parties, or transactions that involve jurisdictions with inadequate AML controls. 
  • Watchlist screening: Firms should identify high risk customers, such as politically exposed persons (PEPs), by screening them against the relevant international watchlists. 
  • Sanctions screening: Customers that are subject to international sanctions pose a high AML/CFT risk. With that in mind, firms in Luxembourg should implement a sanctions screening solution to capture designations on the relevant lists, such as the EU’s Consolidated sanctions list

Adverse media screening: News stories, and other media, often reveal changes in customer risk before any confirmation by official sources. Given the potential for news media (and other forms of media) to capture that information, firms in Luxembourg should integrate adverse media screening as part of their AML/CFT solution. 

Adverse media screening (or negative news screening) requires firms to search for customer names across a range of domestic and  international media sources, including traditional news outlets, blogs, social media platforms, and forum posts. Adverse media solutions should be capable of searching in multiple languages, and account for regional variations in spelling, non-Western characters, and other complicating language factors. 

Recent AML Initiatives in Luxembourg

In 2022, Luxembourg made a series of amendments to the AML/CFT Law in order to clarify certain regulatory details. The amendments, introduced under the Act of July 2022, clarified: 

  • The limits of applying customer due diligence under the risk-based approach.
  • The obligation to retain documents collected as part of the CDD process – rather than just listing references to those documents. 
  • The obligation to apply enhanced CDD measures for persons acting behalf of a client, or for PEPs. 
  • The obligation to compare collected beneficial ownership data to available beneficial ownership registers. 

As an EU member, Luxembourg will also implement the upcoming Markets in Crypto Assets (MiCA) regulation. MiCA is a landmark regulation that will introduce new AML measures for the treatment of virtual assets, in particular stablecoins, and will introduce new licensing and registration requirements for cryptocurrency service providers. MiCA will be introduced across the EU in 2024. 

Next Generation Screening in Luxembourg

To keep pace with Luxembourg’s AML regulations and manage emerging threats, firms must implement an agile, flexible screening solution capable of managing vast amounts of structured and unstructured data. The increasing complexity of AML regulations, and the sophistication of criminal methodologies, mean that manual AML solutions are no longer adequate – and risk not only negative customer experiences, but human error and costly compliance penalties. 

Ripjar’s Labyrinth Screening platform is built to address modern screening challenges, with fast, flexible, accurate screening tools tailored to individual companies’ needs. Labyrinth Screening gives firms the power to search customer names against thousands of adverse media sources, watchlists, and sanctions lists in real time, in over 21 langues, and delivers actionable financial intelligence in seconds. 

Powered by next generation machine learning technology, Ripjar has also deployed AI Risk Profiles as part of the Labyrinth Screening platform. AI Risk Profiles enable compliance teams to identify and extract the most relevant risk data on their customers, minimising false positive alerts while building detailed risk profiles for stronger, more accurate decision making. 


Contact us to discuss how Ripjar can support your AML compliance in Luxembourg