New MCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master KeyMCP Server: Your Agents Get a Badge, Not a Master Key
Read More
Five Considerations for Anti-Financial Crime Leaders
Kimberly Lacey, Chief Anti-Money Laundering Officer (retired), 2026

As financial institutions continue to evaluate how artificial intelligence fits into their financial crime programs, I believe there are several questions every financial crime executive should be asking.

Figure 1: Five questions that sit behind a single readiness test - are we ready to scale AI? Each one moves the discussion away from tooling and toward the data foundation underneath it.
Much of today's conversation around AI quite rightly focuses on improving efficiency. That opportunity is real. However, financial crime leaders should also ask whether today's investments will improve the institution's ability to identify and mitigate its highest-risk threats. The greatest long-term value comes from building capabilities that support both objectives.
AI should only evaluate the information it is given. If customer, transaction and relationship data remain fragmented across systems, without clear relationships, AI will inherit the same limitations investigators face today in reconciling conflicting data. Before expecting AI to improve decision making, institutions should consider whether they have provided it with a sufficiently complete understanding of the activity being assessed.
Connecting systems is only part of the challenge. Institutions should also consider whether customers, entities, transactions and relationships are being interpreted consistently across the organization. Context depends not only on bringing information together, but on ensuring it means the same thing wherever it is used.
Regulatory priorities evolve alongside technology. As AI capabilities continue to mature, it is reasonable to expect that supervisory expectations will evolve as well. Institutions that invest now in creating trusted, connected and contextual data will be better positioned to adapt to those changes while continuing to meet their long-standing obligations to detect and report financial crime.
The greatest value may not come from any single AI use case. It may come from creating a foundation that supports investigations, improves analytical capabilities and enables future innovation across the financial crime program. Building that foundation today positions institutions to respond more effectively to whatever changes come next.
Financial institutions have an opportunity today that may not come again soon. They can build the data infrastructure required to deploy AI responsibly while simultaneously strengthening the effectiveness of their financial crime compliance programs.
The opportunity, therefore, is not simply to automate existing processes. It is to build the underlying data foundation that enables AI to operate at scale while improving the institution's ability to identify increasingly sophisticated financial crime. The challenge is no longer collecting more data. It is providing the context needed to turn that data into reliable intelligence.
By Kimberly Lacey
Former Chief AML Officer at KeyBank and SunTrust
This brings me to the next area of change the industry is buzzing about: artificial intelligence.
The pace of new consent orders has slowed in the United States as the government encourages banks to innovate in addressing financial crime risks. Significant focus has been placed on the potential efficiency benefits of deploying AI agents to perform repetitive tasks. This makes perfect sense. Humans would still perform the higher-level thinking. Humans would check the AI agent's work.
AI's capabilities extend beyond performing repetitive tasks, though.
AI can truly help us see the unseen. It can pull disparate pieces of data together to form a coherent picture. Those pesky little highly complex, program-threatening risks? AI can help us identify them through pattern recognition found in mountains of data that exceed human capabilities. This is tremendously exciting.
Regulatory changes are also on the horizon. On April 7, 2026, the Financial Crimes Enforcement Network (FinCEN) published its proposed rules to “fundamentally reform financial institution programs designed to fight illicit finance” (source). The proposed rules are intended to empower “financial institutions to devote more attention and resources toward higher risks than toward lower risks”.
The highly publicized shift in regulatory focus from "box checking" to "effectiveness" carries its own challenges. While the proposed rules create an expectation that a one-off miss will not result in a consent order, they clearly state that a program must focus on, and effectively mitigate, high-risk threats to be considered effective. Often, the highest-risk threats are also the most complex to identify.
It raises an important question about how institutions will be judged down the road if they repeatedly fail to identify material financial crime despite the availability of increasingly sophisticated analytical capabilities. As artificial intelligence advances, regulatory expectations will likely evolve to match the new technological capabilities.
We have spent some time on what is changing. I will now shift and focus a bit on what is not changing.
The legal framework remains the same. Financial institutions are still charged with identifying and reporting financial crime. Transaction data associated with criminal networks remains fragmented across institutions. There is still no single place into which all of this data feeds. Financial institutions are still charged with trying to put the puzzle pieces together with the limited information each of them has. But are they really fully leveraging the potential of the data they already have across business lines and crime fighting functions?
As I pull out my crystal ball, I see two areas of potential failure in the future. Mind you, my crystal ball is not magic; it is simply replaying a movie I have already seen.
The first area of failure will be financial institutions that do not evolve their programs to properly incorporate current technological capabilities. We saw this movie in the early 2000s when the first major consent orders came out. Financial institutions that relied on spreadsheets and manual monitoring, and that were grossly understaffed, were hit first.
The next area of failure will be financial institutions that actually incorporate current technological capabilities, but they do it poorly using shortcuts. This movie has been playing out over the past decade or so. Financial institutions that failed to ensure all their data fed properly into their systems, did not incorporate the risks associated with new products into their programs, failed to properly capture customer information at onboarding or update it as needed, and lacked appropriate controls to self-identify and correct these problems, will be hit next.
The regulatory framework to penalize institutions that fail to comply remains in place. Although a temporary reprieve from regulatory orders appears to be in effect, the statute of limitations remains unchanged and exceeds the duration of a single administration. In the coming years, it will be interesting to observe which institutions effectively use the current opportunity to evolve their programs, and which ones fail—and how.
Learn how Ally applied graph analytics and contextual investigation tools to uncover complex fraud networks and strengthen fraud prevention.
Read Case StudySo, how does an institution avoid these failures? How does it design and successfully implement a program that appropriately leverages current technological capabilities to focus resources on addressing the highest-risk threats, particularly in an environment that is currently more heavily focused on achieving efficiencies?
The answer is to use the current environment to create a reusable foundation that can be leveraged to solve both effectiveness and efficiency challenges.
The foundation begins with connecting fragmented data that resides in multiple applications and ensuring that those connections use a common language to interpret the data. In today's world, that interpretation must move beyond converting data into information; it must convert information into intelligence. For that intelligence to be reliable, the disparate pieces of data residing in multiple internal and external systems must be pulled together to create an accurate, holistic picture.
When creating that picture, unstructured data has historically posed particular problems, as has information stored in paper form. When created, this data was not designed to be analyzed by a machine; it was intended solely for human consumption. Given free reign to describe something, one never knows how it will be answered.
If Mary Smith is a conductor who decides to describe her occupation as “drug kingpin” on her CTR Form, it is up to the customer service representative to question her regarding her answer. Failure to do so would result in an investigation that would need to pull in all of the relevant information regarding the customer to determine whether “drug kingpin” was an honest answer, or an unfunny pharmacist joke.
In other words, the data must be used to create the context for the activity.
I will provide another quick, easy example that I think will resonate with most in the anti-financial crimes industry.
At some point, someone identified that sending money in round amounts could be indicative of illicit activity. For this example, let's take Mary Smith, who uses a payment network like Zelle or PayPal to transfer $20,000 to David Jones in July. Ding, ding, ding!
We have a round amount alert, which would result in an analyst determining whether the activity could potentially be suspicious. If the analyst cannot explain the activity, it would go to an investigator, who would then investigate the activity, possibly conducting an outreach to Mary to ask her who David Jones is and why she is sending him money.
All of this is resource intensive. It also is not a great customer experience. And it could be avoided if the data residing in the trust system was easily accessible to provide context for the activity in an automated way.
Contextualized data would have shown that Mary Smith had remarried, that her previous name was Jones, and that David Jones was actually her son who was enrolled in college. Suddenly, that round amount no longer looks suspicious because the use of the funds becomes quite clear: David is paying his tuition and buying books, deodorant, shampoo and beer (not necessarily in that order).
The transaction itself never changed. What changed was the context surrounding it. That context transformed what initially appeared to be suspicious activity into an explainable event without requiring additional investigation.

Figure 2: The same $20,000 payment from Mary Smith to David Jones, read two ways. Without context it generates review work, noise and a poor customer experience. With context it resolves into an explainable event.
Now, let's assume that the bank in the example above decided to deploy an AI agent to work all of those annoying (almost completely useless) round amount alerts. Can it do so reliably?
When the AI Agent pulls in the information, will it pull in the information around the correct Mary Smith? Will it pull in all of Mary Smith’s information? If Mary Smith entered the retail bank through a branch 20 years ago, as Mary Jones, at a different address, and then entered the private bank at her new address, with her new name, after remarrying, will the AI Agent pull all of her accounts in? Will it know that she is also a signor on a commercial account in the name of her employer, and will that business’s accounts get pulled in? If Mary Smith moved $20,000 out of her employer’s account and into her personal, retail account a week before she moved it to her son, that might be material.
Deploying AI agents requires proper infrastructure. The systems and applications the AI agent gathers information from must have a consistent way of defining things. A "customer" in one system might have a different meaning as "customer" in another system. AI agents can navigate differences between systems, but they should not be left to guess which differences matter, otherwise they may encounter issues such as hallucinations.
Without a meaningful data infrastructure and appropriate controls to support its AI agents, an institution will simply miss risks and make wrong decisions faster.
This is an important distinction. AI does not eliminate the need for organizing data around its context; it increases it. The more responsibility institutions ask AI to assume, the more important it becomes that the underlying data presents a complete and consistent picture of the people, entities and transactions being evaluated.

Figure 3: The same sequence of steps run on two different foundations. Without connected data, an identity error compounds through the process. With it, each step narrows toward an explainable, controlled decision.
Once this infrastructure is in place, it should be reused to address the primary compliance concern: identifying patterns across the institution that would otherwise remain hidden. What if the bank never lacked the information, but it was missing the connections that nobody knew how to follow?
Institutions with more complex business models typically have multiple customer onboarding systems, as well as many systems that process transactions. They may also have customers and business partners who act as intermediaries between the ultimate payor and payee. Their more sophisticated customers may have a tremendous number of related business entities, each with multitudes of counterparties conducting what can seem like an infinite number of transactions. Many of those counterparties may themselves be entities, with beneficial owners and other related parties.
All of this creates challenges in confirming actor identity across data sources and following the transaction from beginning to end.
This is the complexity I mentioned earlier, and it is often associated with the highest-risk threats. With this, let's return to our Mary Smith example.
If, instead of being Mary's son, it turns out that David Jones is actually a member of the City Council of Jonestown, then the transaction between Mary and David starts to look different. If Jonestown is also in the process of accepting bids for a new multi-million-dollar media campaign, the picture changes further.
If it also turns out that Mary Smith is the Vice President of Business Development for Bad Guy Media Company, and that Bad Guy Media Company moved $25,000 to a related entity, Bad Guy Shell Company, at another bank on Tuesday of last week, it looks stranger still.
And if Bad Guy Shell Company moved $25,000 into Mary's personal account on Wednesday of last week, well, now it looks suspicious.
If Bad Guy Media Company also happens to be a commercial client of the bank seeking to increase its working capital loan to fund business expansion, including work associated with governmental entities, the bank suddenly has a much bigger problem on its hands.
The bank has constructive knowledge of all the data and information contained within its systems. The fact that those systems are not appropriately talking with one another, using a consistent language to connect dots between customers, is unlikely to matter in hindsight if it is later discovered that Bad Guy Media Company obtained its business by paying off public officials.

Figure 4: Above, the payment as it appears in isolation. Below, the same payment inside its network of employment, ownership, government and lending relationships, where a potential bribery pattern becomes visible.
While — as mentioned at the start — the current drivers for change are understandably focused on efficiency, it is important not to lose sight of the effectiveness requirements. The infrastructure required to support AI agents directly connects to the infrastructure needed to improve Anti-Money Laundering (AML) effectiveness.
Responsible institutions have an opportunity to use the current environment to create a reusable framework that supports both objectives. The same connected, contextual view of customers, counterparties and transactions that enables AI to operate responsibly also strengthens an institution's ability to identify complex patterns of activity that would otherwise remain hidden in oceans of data.
Technology will continue to evolve. AI models will become more capable. Regulatory expectations will almost certainly evolve alongside them.
What is much less likely to change is the responsibility placed on financial institutions to identify and report financial crime. Investigators will continue trying to distinguish legitimate activity from suspicious activity. Institutions will continue trying to connect fragmented pieces of information into an accurate understanding of what is actually taking place.
AML is a natural area in which to deploy artificial intelligence because the work involves large volumes of fragmented data, repeated investigative tasks, weak signals spread across many transactions, and patterns that are difficult for humans to find at scale. AI agents must operate on a shared understanding of data; they cannot be left to determine on their own what things mean or which differences matter.
In short, AI alone cannot replace the need for accurate, connected and contextual data.
The institutions that benefit most from AI will not necessarily be those that deploy it first. They will be those that use this moment to build a stronger foundation for both AI and more effective financial crime programs.

