Feature Compliance Strategy
The Compliance Professional's AI Practice Plan: 10 Exercises to Build Fluency Before Your Job Changes
Standard Chartered is cutting 7,800 compliance and risk jobs by 2030. Fluency with AI isn't optional—it's the skill that determines whether you're the person directing AI or the one being replaced by it. Here are 10 exercises to build it.
Table of Contents
TL;DR
- Standard Chartered announced it will cut more than 7,800 compliance, risk, and HR jobs by 2030, citing AI automation. HSBC is evaluating cuts of approximately 20,000 roles.
- The compliance professionals who keep their seats are the ones who can direct, verify, and challenge AI—not the ones who only perform the tasks it can replicate.
- Passive training (watching videos, reading AI explainers) builds vocabulary. Practice builds skill. These 10 exercises build the second thing.
- Each exercise is designed to fit into your existing work in 20–60 minutes—you’re practicing on real tasks, not hypotheticals.
- The NIST AI RMF GOVERN function treats staff AI training as a documented governance requirement, not an optional competency development activity.
In May 2026, Standard Chartered made it official: the bank will eliminate more than 7,800 back-office positions in risk, compliance, and HR by 2030—the first major global bank to attach a specific headcount number and deadline to AI automation. The announcement named exactly the roles at risk: compliance reviewers who apply fixed criteria to transaction data, risk-reporting analysts who compile regulatory submissions, and policy specialists who summarize regulatory requirements.
HSBC followed the news cycle with its own restructuring discussions, reportedly evaluating cuts that could affect 20,000 roles as part of a multiyear AI-driven transformation. Morgan Stanley has estimated that AI could eliminate more than 200,000 European banking jobs by 2030—approximately 10 percent of the sector’s workforce.
None of this means compliance as a function is disappearing. It means the compliance function is being restructured around what humans actually need to do, versus what rules-based automation and generative AI can replicate. The distinction matters: the work AI replaces is high-volume, rules-based, and process-intensive. The work that remains is judgment-intensive, context-dependent, and requires accountability.
Fluency with AI is how you stay on the right side of that line.
Why Courses Aren’t Enough
The natural response to AI disruption is to take a course. Georgetown offers an AI Governance & Compliance certificate. SCCE runs AI & Compliance conference tracks. There are certifications aligned to NIST AI RMF and the EU AI Act proliferating across every professional training platform.
All of these are valuable. None of them build the specific skill that compliance work requires: the ability to use AI on your actual tasks, identify where it’s failing, verify what it produces, and maintain accountability for the output you submit.
That skill is built through practice—and practice means doing real work with AI tools, not learning about AI in the abstract.
See the AI Compliance Training Plan for the 30/60/90-day curriculum context. This post is the practice half: the 10 exercises that turn training into capability.
The 10 Exercises
Exercise 1: Summarize an Enforcement Action and Verify Every Citation
What you do: Pull a recent CFPB, OCC, NYDFS, or FTC enforcement action from the past 12 months. Feed it to your approved AI tool and ask for a 300-word summary of the key violations, regulatory basis, and required remediation. Then open every regulatory reference the summary cites—specific rule sections, guidance documents, examination findings—and verify that the citation is accurate, that the cited text says what the summary claims, and that no citations are invented.
What you learn: AI hallucination in regulatory contexts often looks accurate. The tool will cite real regulations, real rule sections, and real agency guidance—but may mischaracterize what those sources say, cite provisions that don’t exist at the stated location, or blend two separate enforcement actions into one narrative. Compliance professionals catch this because they know what the actual rule says. Start here so you internalize that checking is non-negotiable, not optional.
Time: 30–45 minutes.
Exercise 2: Convert a Policy Into a Checklist
What you do: Take a policy your organization has recently updated or is reviewing—an information security policy, a KYC policy, or a data retention policy. Ask your AI tool to extract every obligation, requirement, and control from the policy and format it as a numbered checklist. Then review the checklist against the policy yourself, identifying: (1) items the AI missed, (2) items it combined incorrectly, and (3) items where it implied an obligation the policy doesn’t actually establish.
What you learn: AI policy-to-checklist conversion is genuinely useful as a first draft. It surfaces structure faster than manual extraction. The errors are usually in scope and nuance: the AI tends to flatten conditional requirements (“when applicable”) into absolute ones, and to miss obligations nested in definitions sections. Knowing the error pattern makes you faster and more accurate when directing this work.
Time: 45–60 minutes.
Exercise 3: Draft a Regulatory Change Impact Assessment—Then Challenge It
What you do: Choose a regulatory change from the past six months—a CFPB rule, a revised examination guidance document, a state privacy law update. Ask your AI tool to draft a preliminary impact assessment: which business functions are affected, what current controls need to be reviewed, what gaps likely exist, and what the implementation timeline requires. Once you have the draft, challenge it systematically: what did it miss? What did it overstate? What regulatory provisions does it reference without verifying the effective date?
What you learn: AI-assisted regulatory change management dramatically compresses the initial research phase. The challenge discipline—treating the draft as a starting point, not a conclusion—is what makes the output defensible. Practice this until challenging AI output feels as natural as reviewing a junior analyst’s first draft.
Time: 60 minutes.
Exercise 4: Run a Hallucination Test on Regulatory Guidance
What you do: Ask your AI tool a series of specific regulatory questions: “What does NYDFS Part 500 Section 500.14 require for multi-factor authentication?” “What does OCC Bulletin 2023-17 say about subcontractor oversight?” “What is the EU AI Act’s fine structure for prohibited AI systems?” Collect the answers. Then verify each answer against the primary source. Document every discrepancy—wrong section number, incorrect threshold, a provision that doesn’t exist where the AI placed it.
What you learn: This is pattern recognition training. AI regulatory hallucinations have identifiable signatures: confident specificity about provisions that don’t exist at that location, accurate frameworks with incorrect numerical thresholds, real guidance documents with invented subsections. Once you’ve seen the pattern a few times, you’ll catch it reflexively. You’ll also discover which regulatory areas your AI tool handles more reliably than others.
Time: 30–45 minutes.
Exercise 5: Draft an AI Use Log for One Work Week
What you do: For one week, every time you use an AI tool for a work-related task, log it: the tool used, the task, the input (general description, no confidential data), the output type (draft, summary, analysis, checklist), whether you verified the output and how, and any corrections you made before relying on it. At the end of the week, review the log and assess: where was AI most useful? Where did you spend more time verifying than the draft was worth? What patterns emerge?
What you learn: The use log does two things. First, it builds the habit of intentional AI use—treating each interaction as a documented work product rather than an informal search. Second, it produces the kind of evidence artifact your AI governance policy and the NIST AI RMF GOVERN function expect to exist at the organizational level. Individual use logs, reviewed by managers, are how institutions demonstrate that human oversight of AI outputs is happening.
Time: 5 minutes per use throughout the week; 30 minutes for end-of-week review.
Exercise 6: Build an Obligation Inventory for One Regulation
What you do: Choose a regulation your institution is subject to—GLBA, CCPA, the FFIEC IT Examination Handbook, DORA if applicable. Ask your AI tool to generate an obligation inventory: a list of every specific obligation the regulation creates, organized by topic or by function. Verify the inventory against the actual regulatory text, noting what was missed and what was mischaracterized. Then extend the exercise: for each obligation, note which internal policy, procedure, or control addresses it.
What you learn: Obligation inventories are foundational to compliance program design, and AI can genuinely accelerate the initial extraction. The exercise builds the verification discipline and gives you a realistic sense of where AI assistance has leverage (structuring and formatting obligations) versus where it creates risk (missing conditional obligations, mischaracterizing scope, confusing final rules with proposed rules).
Time: 60–90 minutes.
Exercise 7: Review an AI Output for Prohibited Data
What you do: Take a draft produced by an AI tool—your own from a previous exercise, or a sanitized example—and audit it against your institution’s prohibited data categories. Is there any content that could only have been generated if the user had input confidential customer information? Any regulatory specificity that suggests exam materials were used? Any proprietary pricing or model details embedded in an analysis? This exercise works best after your institution has published its AI governance policy so you have a specific prohibited-data list to work against.
What you learn: Data handling is the first failure mode in compliance AI use. The exercise builds the habit of reviewing AI outputs not just for accuracy but for data provenance—whether the output implies unauthorized input. This is a reviewable skill for compliance managers who need to spot-check their teams’ AI use.
Time: 20–30 minutes per output review.
Exercise 8: Analyze a Complaint Sample for Risk Patterns
What you do: Pull 10–20 anonymized customer complaints from your complaints log (or from publicly available CFPB Consumer Complaint Database entries in your product category). Feed them to your AI tool and ask for: the most common issue types, any language suggesting potential UDAAP exposure, any patterns indicating a systemic product problem versus isolated user errors, and a recommended prioritization for compliance review. Then evaluate the analysis: what did it surface that you would have categorized differently? What did it miss?
What you learn: Complaint analysis is one of the highest-value AI compliance use cases—it scales pattern detection across volume that would take a human analyst days to review. The evaluation discipline—checking whether the AI’s categorization matches your own regulatory judgment—trains you to use AI as a first-pass classifier that surfaces candidates for your review, rather than as an independent decision-maker.
Time: 45–60 minutes.
Exercise 9: Draft a Board-Level Risk Summary and Challenge the Framing
What you do: Choose an open risk or issue in your portfolio. Ask your AI tool to draft a board-level risk summary: executive framing, risk description, current status, management response, and recommended action. Review the draft for: accuracy, appropriate tone (board-level summaries are different from management reports), missing context, overstatement of certainty, and any framing that would be misleading to a board member who doesn’t have the underlying detail. Revise it.
What you learn: AI board-memo drafting saves significant time on formatting and structure. The challenge exercise builds the skill of translating AI output into communications that meet board-level standards—accurate, concise, appropriately hedged, and defensible. This is a judgment skill that belongs to the compliance professional, not the AI.
Time: 30–45 minutes.
Exercise 10: Read the AI Output Review Checklist—Then Apply It to Your Own Work
What you do: Work through the AI Output Review Checklist with a piece of AI-generated work you produced this week—a draft, a summary, an analysis. Apply each checkpoint: Did you verify the sources cited? Did you check the scope for what’s missing? Did you assess whether the output could create customer harm if acted on without modification? Is the output defensible to an examiner? Document your review.
What you learn: The checklist is a tool; working through it manually on your own outputs makes the standard internalized rather than procedural. After three or four applications, you’ll be running the checklist mentally before you submit anything AI-generated. That’s the goal.
Time: 20–30 minutes.
Sequencing These Exercises
Don’t try to do all 10 in a week. The exercises that build foundational habits—Exercise 1 (citation verification), Exercise 4 (hallucination testing), Exercise 5 (use log)—should come first. These establish the verification discipline that makes everything else more reliable.
Exercises 2, 3, and 6 (policy conversion, regulatory change assessment, obligation inventory) are good Month 1 mid-point exercises once you’ve built the verification reflex.
Exercises 7, 8, 9, and 10 are Month 2 exercises—they require more AI fluency to execute well and produce higher-value outputs when you’re already comfortable directing AI and challenging what it returns.
So What?
Standard Chartered and HSBC’s job announcements weren’t warnings about what might happen to compliance. They were announcements about what is happening—at a specific pace, with a specific organizational rationale. The roles being eliminated share a profile: rules-based, high-volume, process-intensive. The work being retained requires judgment, accountability, and the ability to verify.
Compliance professionals who build AI fluency now aren’t chasing a trend. They’re positioning to be the people who direct the AI, verify the output, own the decision, and answer to the examiner—not the people who were performing the tasks the AI can now replicate.
The AI Risk Assessment Template & Guide gives compliance and risk teams the governance framework to operationalize AI use across their organization—inventory, risk assessment, vendor questionnaire, and board reporting structure. Get it at buy.stripe.com/3cI7sE4kX7tF23jcTk6J200.
Sources:
- Standard Chartered to Cut 7,800 Jobs, Replacing ‘Lower-Value Human Capital’ with AI — AML Intelligence
- Standard Chartered Job Cuts Put Spotlight on HSBC’s AI Transformation Plans — People Matters
- NIST AI Risk Management Framework
- 2025 AI & Compliance Conference Series — SCCE
- AI Governance Frameworks in 2026: What Compliance Actually Requires — ToxSec
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
How long should a compliance professional spend on AI skill-building each week?
What AI tool should compliance professionals start with?
Will AI replace compliance jobs?
What's the single biggest skill gap for compliance professionals trying to use AI effectively?
How does the NIST AI RMF treat compliance staff training?
Should compliance professionals use AI for regulatory interpretation?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026