This informal CPD article ‘The Compliance Skills That Matter in a Generative AI World’ was provided by ChatKYC, an AI-powered compliance advisor, strategist, and assistant built for risk and compliance practitioners.
Generative AI has arrived in the compliance function whether or not any firm has formally decided to adopt it. Analysts are drafting risk assessments with it, MLROs are using it to interrogate regulation, and consultants are producing policy at a pace that would have been implausible two years ago. The question for the profession is whether compliance practitioners using them have the skills to do so defensibly.
That is a more demanding question than it first appears, because the skills involved are not the ones the profession has historically selected for. They are also not, for the most part, technical skills. You do not need to understand how a model is trained to use one responsibly, in the same way you do not need to understand database architecture to be good with a spreadsheet. What you need is a specific set of practitioner competencies, and they are learnable. The compliance professionals who will be trusted with this technology are the ones who treat it as a discipline rather than a novelty.
Understanding what the tool actually is
The first competency is conceptual. A large language model is a prediction engine. It produces the statistically likely next words given your input; it does not retrieve verified knowledge and it does not reason from first principles, even when its output reads as though it does. This has direct consequences. The model can produce a fluent, authoritative, and entirely incorrect answer, and its confidence tells you nothing about its accuracy. A practitioner who internalises this treats every output as a draft to be tested rather than an answer to be trusted, and is immediately harder to mislead. Alongside this sits an awareness of the recognisable ways these tools fail: inventing sources, drifting from their instructions across a long task, and quietly importing assumptions from the wrong jurisdiction.
Prompting as a professional craft
The quality of the output tracks the quality of the input more closely than most first-time users expect. A vague request produces generic content; a well-constructed one produces something you can actually work with. The skill here is learning to give the tool the context it needs, to specify the role it should adopt, to direct it to the sources it should rely on, to define the format you require, and to set the constraints that keep it honest. Just as important is iteration: reading a first output critically, identifying what was inadequate, and rewriting the instruction rather than accepting what you were given. This is a craft, and like any craft it rewards practice.
Verification and source discipline
If there is a single non-negotiable skill in this new world, it is verification. Generative AI's most dangerous habit for regulated work is the fabricated citation: the confident reference to a rule, a case, or a figure that does not exist or has been superseded. The 2023 United States matter Mata v. Avianca, in which lawyers filed a brief containing fictitious case citations produced by a public AI tool and were sanctioned for it, is the cautionary tale the whole profession should know. The competent practitioner treats every specific entity, every citation, date, and number, as wrong until independently confirmed, and grades sources by reliability, placing the primary text of a regulator or standard-setter above industry commentary, and industry commentary above a consultancy's analysis. This is not new to compliance. It is the evidential discipline the profession already values, applied to a new source of claims.
Judgement: knowing where the human must stay
The genuinely strategic skill is knowing which parts of the work can be accelerated and which cannot be delegated at all. AI can structure a risk assessment, draft a policy section, and surface considerations you might have missed. It cannot own your firm's risk appetite, it cannot decide what is proportionate in your context, and it cannot take responsibility for a decision. The practitioner who understands this uses the tool to compress the mechanical parts of the work and reinvests the time saved into the judgement layer, which is where their professional value has always lived.
Governance and risk awareness around the tool itself
Using AI in a regulated firm introduces its own risks, distinct from the compliance risks the tool is helping to address. Pasting customer information into a consumer product raises data protection issues. Relying on a model without understanding its limitations raises model risk. Producing customer-facing outcomes with an unmonitored system raises conduct concerns. A competent practitioner in this world can recognise these risks and knows the rules that govern the use of the technology, not only the rules the technology helps them apply.
Supervising and signing off AI-assisted work
Finally, and increasingly, this is a supervisory skill. Heads of compliance and MLROs are being asked to review and approve work produced with AI assistance, often by people more fluent with the tools than they are. The ability to interrogate someone else's AI-assisted output, to ask how it was produced, what was verified, and why it can be relied upon, and then to make a defensible sign-off decision, is fast becoming a senior competency in its own right.
None of these skills is exotic, and none requires a background in technology. What they require is deliberate development, because they are not acquired simply by using the tools. The profession has been here before. When spreadsheets, and later dedicated compliance systems, entered the function, the practitioners who invested in the skill to use them well pulled ahead of those who treated them as a curiosity. Generative AI is the same shift at a larger scale, and the same logic applies. The advantage will go to the practitioners who intentionally build these competencies.
We hope this article was helpful. For more information from ChatKYC, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
References
- Financial Action Task Force (FATF), International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation (The FATF Recommendations).
- National Institute of Standards and Technology (NIST), AI Risk Management Framework (AI RMF 1.0), 2023.
- International Organization for Standardization, ISO/IEC 42001:2023, Artificial intelligence management system.
- OECD, Recommendation of the Council on Artificial Intelligence (OECD AI Principles), 2019, updated 2024.
- Mata v. Avianca, Inc., United States District Court for the Southern District of New York, 2023.