Skip to main content

Mind the gaps: Scaling agentic AI in financial compliance

How banking risk and compliance leaders can adopt AI strategies that balance operational ambition with expanding complexities

Inside this article

Key questions addressed

Drawing on macro insights from the KPMG Managed Services Outlook Survey 2026 and qualitative research with US banking risk leaders, this article explores the realities of deploying agentic AI in financial crime compliance, answering questions in key areas:

  • Data privacy: Why does data sensitivity remain the biggest barrier to scaling AI in banking, and how are firms navigating third-party vendor risks?
  • Human-in-the-loop: How can compliance teams use AI to multiply capacity without violating strict regulatory requirements for human oversight in AML and KYC?
  • AI governance: What are the operational challenges of governing dynamic, continuous-learning AI models within a static regulatory landscape?
  • The execution gap: Why is AI support now the top area of managed services investment, and how are modern providers helping organizations build the secure architecture needed to scale AI safely?

Across the banking and capital markets industry, the C-suite is pushing for more rapid progress—and results—from AI-powered innovation. Executives are especially eager to harness agentic AI’s potential to transform operations and reduce costs.

But within compliance operations, teams are pumping the brakes. Amid the day-to-day complexities of their work, they’re asking a much more pragmatic question: How do we implement agentic AI in financial compliance without putting our organization at risk? The board has its timeline, but the “details” of managing financial crime, anti-money laundering (AML), and Know Your Customer (KYC) requirements remain anchored down by long-standing guardrails and workflows.

This gap between ambition and execution cuts across industries. In a recent survey of more than 1,200 senior leaders (KPMG Managed Services Outlook Survey 2026, with research and analysis by IDC), nearly every respondent (98 percent) cited AI implementation as a critical capability. But many of these executives also realize they lack the internal bandwidth and secure infrastructure to scale these tools safely and effectively.

Financial crime compliance is a prime example of this execution gap, where the tension between AI ambition and regulatory reality is most acute—especially amid the push to deploy AI agents. According to recent KPMG-commissioned qualitative research1, operators are struggling to help their organizations scale AI due to stubborn constraints, including rigid regulatory testing, fragmented legacy systems, and steep data-sharing barriers.

To break this deadlock, banks must build the operational plumbing to govern these tools securely. This means adopting a deployment strategy that aligns with both executive ambitions and the complex risk profile of financial crime operations. Here’s a closer look at these core challenges, and why a managed services approach is emerging as the critical path to making agentic AI a reality.

1. In Q1 and Q2 2026, KPMG conducted qualitative research with U.S. banking leaders on agentic AI in financial crime, AML and operations via a 10EQS interview series. Source: KPMG LLP, “Agentic AI in Financial Crime AML,” with qualitative research led by 10EQS, April 2026.

Why data sensitivity limits AI adoption in banking

AI adoption is driven heavily by localized experimentation, according to the qualitative research, which included in-depth interviews with 20 compliance operations leaders. Rather than waiting for top-down frameworks, many organizations are rolling out AI tools to encourage bottom-up innovation.

But as these tools hit the actual workflow, they collide with a massive barrier: data sensitivity, which remains a defining constraint for scaling AI in banking. This data friction is omnipresent for compliance teams, creating architectural limitations and workarounds, including:

01
Third-party barriers

Personally identifiable information (PII) and proprietary data remain tightly controlled behind the firewall, so getting the internal approvals to share data with a new vendor requires top-heavy reviews and significant time.

02
A bifurcated vendor strategy

Data exposure heavily dictates how firms source technology. Many are comfortable purchasing vendor platforms for low-sensitivity tasks, but feel obligated to keep high-risk decision logic tightly in-house.

03
Layering vs. replacing

Given these constraints, institutions aren’t ripping out core compliance systems. Instead, they’re layering AI onto existing technology to enhance specific workflow steps.

The result is a patchwork operating model: vendor platforms and custom in-house solutions are layered over legacy systems, creating a highly fragmented landscape. AI models expose decades of poor data management, a barrier because most legacy data was never intended for high-velocity AI training. Banks want to deploy advanced algorithms at scale, but managing this mix while locking down sensitive data raises significant governance headaches.

To navigate this safely, organizations need a clear point of view on target architecture that moves away from fragmented workarounds and toward secure, closed-loop ecosystems that protect proprietary data while still allowing models to function.

It comes down to the type of data you're putting into it. The more sensitive or customer-specific the data, the more likely the capability would need to be built or tightly controlled internally.

Executive Director, Consumer Lending BSA/AML/Sanctions, Tier-1 bank

How human oversight anchors AI capacity in financial crime

Insight
Orchestrating AI‑driven transformation with managed services
KPMG Managed Services Outlook 2026: Get in-depth insights and data from our full global survey report on accelerating AI transformation with managed services.

The C-suite wants to see a direct return on AI investment, often through headcount reductions. Indeed, cost savings through AI-enhanced managed services was the top goal cited by the executives in the Outlook Survey. But cutting staff in financial crime compliance can introduce significant regulatory risk. Instead, the objective for many compliance leaders is to drive higher throughput with existing resources.

AI can deliver this by automating the routine drudgery. The qualitative research found that targeted use cases are already auto-populating 50 to 70 percent of suspicious activity report (SAR) narratives. In sanctions screening, AI agents are eliminating 80 to 90 percent of false-positive alerts. And case summarization tools are cutting investigative prep time from 45 minutes down to seconds.

But there’s a hard limit to this automation. Regulators simply won’t accept AI as the final actor on a case disposition. Because of this, human-in-the-loop oversight is a mandatory, non-negotiable requirement. AI can handle the speed and volume of data ingestion, freeing human analysts to apply the judgment necessary for regulatory defensibility. By automating the “what”—the routine data ingestion and analysis—AI elevates human analysts to be “on the loop,” not just in it, shifting their focus from manual processes to applying the critical judgment, contextual interpretation, and ethical reasoning that regulators demand and machines struggle to replicate. Banks can empower their investigators with AI, not replace them.

Achieving this requires a sustainable adoption model. By utilizing managed services to handle the complex “design and run” execution of these AI-enabled workflows, compliance teams can scale their capacity while keeping their human experts focused on final risk determinations.

A computer cannot be the last actor on an audit log for an SAR decision. This is a regulatory reality, not cultural preference.

VP, senior global financial crime specialist, Tier-1 bank

How banks can govern dynamic AI models in a static regulatory landscape

Integrating agentic AI into financial crime workflows is exposing a fundamental tension, even as the exact regulatory roadmap for agentic is still taking shape. Traditional regulatory frameworks demand static, reproducible validation. Before a new system goes live, it typically undergoes rigorous parallel testing against legacy processes to ensure the outputs are entirely predictable.

But agentic AI doesn’t operate like a legacy rules engine. These advanced models are inherently dynamic and continuously learning.

This creates a deep structural conflict between how regulators test compliance systems and how the technology actually functions. If a model adapts its behavior based on new data, its outputs can become inconsistent, making it incredibly difficult to build rigid policies and controls around it.

To break this deadlock, leading banks are reframing governance from a compliance hurdle into an innovation engine. They are moving beyond periodic, static testing and embedding continuous, automated validation directly into the technology stack. This approach doesn't just satisfy regulators; it provides the confidence to deploy AI into production faster, turning trust into a velocity driver. Recognizing this complexity, many organizations are turning to managed services to accelerate progress. Nine in 10 leaders in the Outlook Survey view managed services as critical for agentic AI delivery as they look for help in areas like integration complexity, cross-functional data governance, and securely scaling AI across operations.

Not anyone can just build an AI and run with it — it has to be validated and have the right amount of testing and governance to ensure accuracy.

Former Executive Director & SVP, Global AML Compliance

How enhanced managed services can help solve the AI execution gap

As organizations turn to outside providers to navigate these data and governance hurdles, managed services are now seen as a critical, if often underestimated, AI accelerator. Traditional outsourcing—often focused on lifting and shifting manual processes to lower-cost labor—does not solve the complex architectural and regulatory challenges of agentic AI. Per the Outlook Survey, 82 percent of respondents say there is a clear distinction between modern managed services and all other service delivery; and they rated expanded AI support as their No. 1 area of managed services investment over the next two years.

For financial crime compliance, this distinction is critical. Based on the qualitative findings, banking leaders expect providers to go far beyond basic staff augmentation, delivering on several critical fronts:

1

Secure, closed-loop environments: Providers must deliver the “always-on” monitoring and security architecture required to handle institutional data safely, with strict safeguards against breaches.

2

Domain-aware talent: Beyond technical skills, banks need specialized talent fluent in financial crime regulations, cross-jurisdictional considerations, and emerging risk typologies.

3

Embedded and continuous governance: Institutions require a full governance suite—from intake and monitoring to post-implementation controls. Governance is eventually automated and incorporates ongoing AI testing that delivers transparent, dynamic records of AI model behavior, guardrails, and performance along with an AI asset inventory required to build trust with both internal stakeholders and regulators.

4

Seamless integration: Providers must prove their tools can seamlessly integrate and adapt within the bank’s existing, often highly fragmented, technical ecosystem.

5

Predictable, outcome-based deployment: New approaches move away from open-ended consulting and toward outcome-based models that align costs directly with operational throughput and value.

This managed services support model can act as a safe sandbox and the operational vehicle for building the mature risk capabilities that unlock disproportionate value. It gives banks the engine they need to scale AI innovation and multiply their capacity, while allowing them to maintain absolute control over their proprietary risk data.

At a glance: A practical roadmap for AI-enabled financial compliance with KPMG Managed Services

As banking leaders work to scale AI in financial crimes compliance, they face distinct operational challenges that cannot be solved by technology alone. Below are practical recommendations for navigating the complexities of AI adoption, and how a modern managed services approach can help accelerate and de-risk the journey.

Strategic imperatives for scaling AI safely:

Operationalizing with KPMG Managed Services
Our services deliver the "always-on" monitoring and security architecture required for banks to handle proprietary institutional data safely. By providing a secure sandbox with strict safeguards, we help organizations maintain control of their data as they scale AI innovation.

 

1 | Build secure, closed-loop environments to manage data sensitivity and vendor risk.

To overcome the architectural limitations of fragmented legacy systems, banks must establish secure ecosystems that protect proprietary data while still allowing AI models to function effectively.

Operationalizing with KPMG Managed Services
We offer the operational foundation to help banks scale their compliance efforts both quickly and safely. By merging advanced technology with experienced financial crime investigators, we provide the human oversight necessary for regulatory defensibility, while utilizing AI to streamline routine processes like SAR narrative generation.

 

2 | Augment human oversight with AI-powered workflows to scale capacity.

Regulators require human-in-the-loop oversight for final case dispositions. To meet this mandate while increasing throughput, organizations can use AI to automate routine data collection and analysis, freeing human experts to focus on judgment-based decisions.

Operationalizing with KPMG Managed Services
We bring established AI governance frameworks validated through regulatory engagement. Our methodologies for continuous model validation and real-time monitoring provide governance structures and process that regulators can trust, helping banks transition from static testing to a dynamic oversight model without having to build these complex capabilities internally.

 

3 | Establish dynamic governance and continuous model monitoring.

To resolve the conflict between dynamic AI models and static regulatory testing frameworks, organizations must shift from one-off parallel testing to a continuous, real-time model monitoring capability. This helps ensure that AI agents operate safely within the bank’s established risk appetite.

Operationalizing with KPMG Managed Services
We move away from traditional consulting toward an outcome-based relationship. Service level agreements tie directly to value metrics like quality scores and efficiency gains, helping AI investments translate into measurable improvements in throughput and cost-effectiveness.

 

4 | Align AI investment with measurable outcomes.

To bridge the gap between AI ambition and execution, leaders must move beyond open-ended technology projects and adopt an outcome-based model. This aligns costs directly with operational goals like risk reduction, false positive reduction, and improved decision quality.

How KPMG LLP can help

Moving agentic AI from localized experimentation to full-scale production requires a fundamental shift in how financial crime and compliance operations are governed and executed. Traditional in-house builds can move too slowly, and legacy outsourcing is too rigid. Instead, organizations need an elastic execution layer.

KPMG Managed Services professionals bring deep industry experience, domain-aware talent, and technical capabilities required to help you accelerate the value of AI safely. We take the burden of design and run off your plate, allowing your internal teams to focus on strategic risk management while we deliver ongoing support and outcome-based results.

Our team accelerates your AI journey through:

Service
KPMG Managed Services
Make the difference with KPMG Managed Services: Optimize operations, improve costs, and deliver value-creating transformations.
  • Targeted architecture and secure environments: We help organizations build the critical closed-loop data “plumbing” and Trusted AI governance frameworks required to protect sensitive data and ensure models remain explainable to regulators.
  • Continuous model validation: We help institutions transition from static parallel testing to dynamic, real-time model monitoring—helping ensure continuously learning AI agents operate safely within your established risk appetite.
  • Outcome-based managed services: We provide the operational engine. By combining advanced technology with specialized financial crime investigators, we deliver the human-in-the-loop oversight needed to scale your compliance capacity rapidly and securely.
  • Accelerated value realization: Through outcome-based pricing models, we align our service delivery directly with your operational goals, helping ensure your AI investments translate into measurable throughput and cost efficiency.

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline