This informal CPD article ‘Output, Not Model: What Regulators Expect When Compliance Work Is AI-Assisted’, was provided by ChatKYC, an AI-powered compliance advisor, strategist, and assistant built for risk and compliance practitioners.
There is a persistent worry among compliance professionals that using generative AI in regulated work is somehow risky in the eyes of a regulator, as though the involvement of a machine is itself the problem. It is worth stating plainly that this is not, in general, how regulators approach the question. Very few expect firms to abstain from AI. What they expect is that the standard of the work is unaffected by how it was produced, and that a named human being can stand behind the result. The operative principle, and the one worth building everything else around, is simple: you are accountable for the output, not the model.
The shift from tool anxiety to output accountability
This reframes the question that actually matters. A regulator examining an AI-assisted risk assessment, policy, or customer file is not primarily interested in which tool you used. They are interested in whether the output is correct, whether it is appropriate to your firm and your jurisdiction, and whether you can explain and defend the process by which you arrived at it. The substantive test is defensibility, and it is the same test that has always applied to compliance work. "The AI produced it" carries no more weight as a defence than "a junior drafted it" or "we copied it from a template." Accountability does not transfer to the tool.
Matching oversight to consequence
Because accountability stays with the human, the real design question is how much human oversight a given piece of AI-assisted work requires, and the answer should turn on consequence. Where an action is irreversible or directly affects a customer, a person should review and approve every output before it takes effect; the human sits firmly in the loop. Where the work is partially reversible and lower in stakes, a person can oversee the process and retain the right to intervene without approving each item individually; the human is on the loop, typically supported by sampling and review. Only where an action is fully reversible, and where monitoring and defined stop conditions are in place, is it defensible to let a system operate with limited direct oversight. Calibrating this well, rather than applying a single blanket posture to everything, is what a thoughtful regulator expects to see.
The record is the difference
The mechanism that turns "we used AI" into "we used AI defensibly" is the record. If you cannot reconstruct how a piece of work was produced, you cannot defend it, and an examiner has no reason to take your assurance on trust. A defensible record answers a predictable set of questions: which tool and version was used, what you actually asked it to do, which sources were relied upon and confirmed as current, what you changed and why, and the basis on which you were confident enough to sign it off. This is not bureaucracy for its own sake. It is the difference between an output that survives scrutiny and one that unravels under the first pointed question, and it is entirely within the practitioner's control to produce.
Accountability stays human
Underpinning all of this is a feature of most regulatory regimes that AI does not change: accountability attaches to people, not processes. Senior management accountability frameworks exist precisely so that a named individual is answerable for the work of the function, and that individual cannot delegate their responsibility to a piece of software. The person who signs off an AI-assisted output owns it in exactly the same way they would own the work of a member of their team. This is not a reason to avoid the technology. It is the reason to use it with the discipline described above, so that when the sign-off is questioned, there is a defensible answer.
The standards already point this way
Practitioners looking for external reference points will find the direction of travel consistent. International guidance such as the OECD AI Principles, the NIST AI Risk Management Framework, the ISO/IEC 42001 management-system standard, the Monetary Authority of Singapore's principles on fairness, ethics, accountability, and transparency, and the risk-based structure of the European Union's AI Act all converge on the same expectations: human accountability, transparency about how outputs are produced, proportionate oversight matched to risk, and a documented basis for reliance. None of these frameworks asks firms to stop using AI. They ask firms to be able to explain and defend how they do.
The reassuring conclusion for compliance professionals is that this is manageable, and that the discipline required is familiar. The profession already knows how to verify, how to match control to risk, how to document, and how to stand behind a decision. Applied to AI-assisted work, these habits are precisely what regulators expect. The firms that formalise them will be the ones able to adopt this technology at scale without anxiety, because for them the answer to "can you defend it" will always be yes.
We hope this article was helpful. For more information from ChatKYC, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
References
- Financial Conduct Authority, Senior Managers and Certification Regime (SM&CR).
- Monetary Authority of Singapore, Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics, 2018.
- OECD, Recommendation of the Council on Artificial Intelligence (OECD AI Principles), 2019, updated 2024.
- National Institute of Standards and Technology (NIST), AI Risk Management Framework (AI RMF 1.0), 2023.
- International Organization for Standardization, ISO/IEC 42001:2023, Artificial intelligence management system.
- Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act).