The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members. 

Building a more proactive, data-led compliance function

As regulatory expectations continue to evolve, compliance functions are under increasing pressure to provide more than just assurance. Boards, senior management and regulators now expect a clear, consolidated view of compliance and financial crime risk across an organisation. The challenge is no longer simply collecting data but turning that data into meaningful intelligence.

Moving beyond traditional compliance assessments

Many firms recognise that traditional compliance risk assessment methodologies can become static over time and struggle to keep pace with changing business models, regulatory requirements and emerging risks.

The challenge is bringing together multiple measures of risk into a single view of the control environment while retaining visibility of underlying issues and emerging risks. For many firms, the answer lies in a more dynamic, data-driven approach to compliance risk management.

Creating a unified view of risk

Firms are developing more holistic approaches to compliance risk using Key Indicators (KIs), identified through collaboration with subject matter experts and tailored through business-specific risk appetite thresholds and weightings.

The result is a dynamic dashboard that provides leadership with a clear view of compliance risk and links directly to governance, escalation and remediation processes. Back-testing, model validation and stakeholder training remain critical to ensuring users can understand and act on the information presented.

The value of data-led compliance

A key advantage of data-driven compliance is its ability to quantify risks that have traditionally been assessed qualitatively. By aggregating data from multiple sources, firms can identify patterns and trends that might otherwise remain hidden, making this an increasingly important differentiator for high-performing compliance functions.

Exploring AI in compliance

Firms are actively exploring AI use cases across the compliance lifecycle, including horizon scanning, regulatory change management, policy mapping, policy drafting, document validation, whistleblowing case management, background screening, breach analysis and compliance monitoring optimisation.

Early experiences have been particularly positive in regulatory horizon scanning, where AI helps compliance teams improve coverage and responsiveness. However, there is broad agreement that AI currently works best as an enhancement to compliance professionals rather than a replacement. Human judgement, experience and contextual understanding remain essential, although greater automation can increase workloads by uncovering more issues requiring investigation and remediation.

Separating AI hype from reality

There is a need for realism when evaluating technology solutions.  Firms have highlighted the importance of thorough testing and validation, noting a disconnect between some vendor claims and practical capabilities.

Ultimately, organisations should focus on measurable outcomes and business value rather than technology for its own sake.

The human skills that still matter

The future compliance professional will require a blend of technical and traditional skills. Data literacy, technology awareness and AI understanding are becoming increasingly important, but they do not replace the foundations of effective compliance.

Critical thinking, communication, professional judgement and collaboration remain essential. The most successful compliance functions will combine analytical capability with sound judgement and effective stakeholder engagement.

Data governance: the foundation for success

Successful compliance monitoring and AI adoption depend on high-quality data. Data quality and lineage are critical foundations for effective oversight, while firms relying on third-party providers face additional challenges in obtaining assurance over data integrity.

Without confidence in underlying data, even the most sophisticated monitoring tools and AI solutions will struggle to deliver reliable outcomes.

Looking ahead

Compliance functions must evolve from reactive oversight to proactive, intelligence-led capabilities. Data, analytics and AI are creating new opportunities to improve visibility, decision-making and risk management.

However, technology alone is not the answer. Success will depend on combining innovative tools with robust governance, high-quality data and skilled compliance professionals who can translate insights into action. For firms looking to build a truly proactive compliance function, getting the data foundations right may be the most important step of all. 

To discuss any of the above topics further please contact Claire.Simm@Kroll.com or Paul.Jennings@Kroll.com

Tags: