AI for Regulatory Compliance: AML Alert Triage, Regulatory Change, and Audit-Ready Controls
How compliance teams use AI for AML alert triage, regulatory change tracking, and control testing, and what the TD Bank case shows about monitoring gaps.

In October 2024, TD Bank pleaded guilty to US Bank Secrecy Act violations and agreed to pay $1.8 billion to the Justice Department; the Federal Reserve put the total across all agencies at approximately $3.09 billion. The OCC also imposed an asset cap on the bank. According to the Justice Department, the bank left 92% of its transaction volume, about $18.3 trillion between January 2018 and April 2024, out of automated monitoring, and its senior executives put holding costs flat ahead of maintaining an adequate AML program. Three money laundering networks moved more than $670 million through its accounts in the meantime.
The case is a useful corrective to how AI in compliance is usually pitched. The biggest compliance failures tend to be coverage gaps and underinvestment, not a lack of sophisticated models. AI helps most when it lets a compliance team cover more ground with the same people: triaging alerts, tracking regulatory change, and testing controls. This guide covers those uses and how to make them hold up in an exam.
For governing AI systems themselves, see our separate guide to AI governance frameworks.
AML alert triage
Rule-based transaction monitoring generates large volumes of alerts, and in most institutions the great majority turn out not to be suspicious. Investigators spend most of their time closing alerts that were never going to become SARs.
Machine learning helps by prioritizing rather than replacing the rules:
- Score each alert using the customer's history, peer group behavior, counterparties, and links to other flagged accounts.
- Route the highest-scoring alerts to experienced investigators first.
- Give the lowest-scoring alerts a lighter, faster review, with quality assurance sampling.
- Pre-assemble the case: transactions, customer profile, prior alerts, and adverse media, so the investigator starts with context.
A worked illustration. An institution gets 10,000 alerts a month, each taking 20 minutes to review, or about 3,333 investigator hours. If a validated model sends the lowest-risk 40% (4,000 alerts) to a 5-minute review with 10% QA sampling at full depth, the time for that group falls from about 1,333 hours to 333 hours plus 133 hours of QA, saving roughly 870 hours a month. Those hours can go to the complex cases and to closing monitoring gaps.
Auto-closing alerts without human review is where examiners push back. If you want to go there, expect to show extensive validation evidence first.
Validating AML models
AML models fall under model risk management expectations (SR 11-7 in the US). Examiners typically look for:
- Coverage. Every product, channel, and customer type monitored, with any exclusions documented and justified. This is the lesson from TD Bank.
- Below-the-line testing. Sampling activity just under alert thresholds to check whether suspicious cases are being missed.
- Tuning documentation. Why thresholds and model cut-offs are where they are.
- Explainability. An investigator should be able to see why an alert scored high.
- Ongoing monitoring. Alert-to-SAR conversion rates, drift in scores, and changes in customer mix.
The US federal banking agencies and FinCEN issued a joint statement in December 2018 encouraging banks to try innovative approaches, including artificial intelligence, to meet BSA/AML obligations. It adds that pilot programs should not in themselves bring supervisory criticism even if they prove unsuccessful, and that pilots which expose gaps in a program will not necessarily lead to supervisory action. That is a useful document to cite internally when proposing a pilot.
SAR timing
In the US, a suspicious activity report is generally due within 30 calendar days of initially detecting facts that may justify filing, extendable to a maximum of 60 days if no suspect has been identified (31 CFR 1020.320 for banks). Faster case assembly helps teams meet those deadlines. Language models can draft the SAR narrative from the investigator's findings, but the investigator must check every fact and remains responsible for the filing.

Regulatory change management
Keeping up with new rules, guidance, and enforcement actions across jurisdictions is labor-intensive. AI helps at three points:
- Monitoring. Pulling new documents from official sources (the Federal Register, EUR-Lex, regulator sites, enforcement releases) and filtering for relevance to your products and jurisdictions.
- Summarizing. Producing a plain-language summary with effective dates and affected entities, linked to the official text.
- Mapping. Suggesting which internal policies, procedures, and controls the change touches.
The risks are the usual ones for language models: invented details, missed exceptions, and confident summaries of rules that are not yet final. Every summary should cite the source text, and a qualified person must sign off on the interpretation before anything changes. Treat the output as a draft for a compliance analyst, not a legal opinion.
Enforcement actions deserve special attention. They show what regulators are actually prioritizing, often before guidance is updated.
Control testing and evidence
Much compliance work is collecting evidence that controls operate: access reviews completed, reconciliations signed off, training finished, vendors assessed. AI and automation help by:
- Pulling evidence from systems automatically instead of by screenshot
- Testing full populations rather than samples where data allows (every user access change, not 25 of them)
- Flagging exceptions for follow-up
- Drafting control narratives for audits such as SOC 2
Our SOC 2 Type 2 guide covers the audit side.

Privacy compliance
Classifying personal data across databases, tracking consent, and responding to access and deletion requests are well suited to automation. The details are in our AI and SaaS data privacy guide.
AML rules are changing
In the EU, the new Anti-Money Laundering Authority (AMLA), based in Frankfurt, has had legal existence since June 2024 and will directly supervise 40 of the most complex high-risk financial institutions or groups from 2028. A single EU AML rulebook, the AML Regulation (EU) 2024/1624, applies from 2027. Separately, the EU AI Act's high-risk list in Annex III covers AI used to evaluate creditworthiness of natural persons but expressly exempts AI used to detect financial fraud, and AML transaction monitoring does not appear on the list by itself. Supervisors still expect model risk controls either way. Institutions in scope should expect more consistent expectations on monitoring models across member states.
Getting started
- Map coverage first. Confirm every product, channel, and customer segment is monitored before optimizing alert quality.
- Measure the baseline: alert volume, hours per alert, alert-to-SAR rate, and backlog.
- Pilot alert prioritization in parallel with the existing process, and validate before changing workflows.
- Add regulatory change monitoring with source links and analyst sign-off.
- Automate evidence collection for your most frequently tested controls.
For the fraud side of financial crime, see AI fraud detection. For model risk expectations in detail, see AI financial risk management.
This guide is for informational purposes only and is not legal or compliance advice. Requirements differ by jurisdiction and institution type; consult qualified compliance counsel.



