Feature AI Risk
If AI Writes the Memo, Who Owns the Risk? Accountability for AI-Generated Compliance Work
AI is generating risk assessments, SAR narratives, board memos, and regulatory change summaries. But 'human-in-the-loop' without documented challenge is accountability theater. Here's what genuine ownership looks like — and what regulators are starting to require.
Table of Contents
In May 2026, Standard Chartered confirmed it will cut approximately 7,000 corporate roles by 2030 — explicitly linking the reductions to AI automation of back-office and operations functions. The bank’s CEO described the plan as replacing “lower-value human capital” with AI-driven processes across 52,000 corporate staff. HSBC’s CEO, commenting separately, said the bank needs its entire workforce on the AI transition — while also acknowledging AI will reshape what those jobs look like.
Compliance functions are not immune. SAR narratives. Policy reviews. Board risk memos. Regulatory change summaries. Impact assessments. These are exactly the categories that generative AI drafts reasonably well and that compliance teams are quietly using AI to accelerate.
That raises a question most programs haven’t formally answered: when AI writes the memo, who owns the risk?
This isn’t abstract. Regulators are starting to ask it directly.
TL;DR
- Compliance teams are using AI to draft SAR narratives, risk assessments, board memos, and regulatory change summaries — and regulators are beginning to ask how those outputs are reviewed and who is accountable.
- “Human-in-the-loop” without documented challenge isn’t accountability — it’s a paper trail that fails when something goes wrong.
- The FCA’s Senior Managers Regime holds named executives personally accountable for AI outcomes. The HKMA requires human oversight for high-impact decisions. NIST AI RMF and the FS AI RMF both require documented accountability structures.
- Genuine accountability requires: a named reviewer, documented verification against source materials, a challenge record, and a sign-off that reflects professional judgment, not a rubber stamp.
The Accountability Illusion
Here’s the version of AI governance that doesn’t work: a compliance analyst uses Claude or ChatGPT to draft a regulatory change impact assessment. They read it. It looks reasonable. They add their name to it and send it to management.
That’s “human-in-the-loop.” It’s also not accountability.
Accountability requires that the person who signed off can answer the following questions:
- What source materials did you verify the analysis against?
- What did you challenge or change in the AI’s draft?
- What did you independently conclude?
- If there’s an error in this document, what review process should have caught it?
A reviewer who can’t answer those questions didn’t review the document — they reviewed the appearance of a document. That distinction matters enormously when the document is wrong, when a regulator asks about it, or when it becomes the basis for a board decision that turns out to be flawed.
What Regulators Are Already Requiring
The regulatory framework for AI accountability in compliance work is clearer than many practitioners realize.
FCA Senior Managers Regime (UK / cross-border implications): The FCA has been explicit that its Senior Managers Regime applies to AI outcomes. Named executives are personally accountable for AI systems operating in their areas — including AI that generates compliance work products. The FCA described its approach as “leaning on the SMR to hold named executives accountable for AI outcomes” rather than issuing prescriptive AI-specific rules. The practical effect: if AI generates an analysis that causes harm, the named senior manager is accountable for whether adequate oversight was in place. “We use AI tools but no one individually owned the output” is not a defense.
HKMA (AI guidance for banks): The Hong Kong Monetary Authority requires that banks maintain humans in the loop for high-impact decisions and maintain explainability for any AI model affecting customer outcomes. For compliance work, this means that AI-generated outputs that inform consequential decisions — filing decisions, regulatory disclosures, board risk positions — require documented human judgment, not just human presence.
NIST AI RMF GOVERN Function: The NIST AI Risk Management Framework’s GOVERN function specifically requires organizations to define accountability structures for AI systems: who is responsible for oversight, what their review obligations are, and how accountability is documented. For regulated financial institutions using AI in compliance functions, this translates directly to requiring accountable-reviewer designations for AI-generated work products.
FS AI RMF (U.S. Treasury, February 2026): The Financial Services AI Risk Management Framework, published by the Treasury with 230 control objectives, includes accountability structures as a core governance requirement. Institutions are expected to document who is responsible for AI outcomes — including compliance-related outputs — and demonstrate that accountability chains are operationalized, not just stated in policy.
See AI Governance Framework for Financial Services: A Practical Guide for how these frameworks apply to a working program.
The Work Products That Require Named Accountability
Not all AI-generated compliance work carries the same risk profile. Here’s how to think about accountability requirements by work type:
| Work Product | Risk if Wrong | Minimum Accountability Requirement |
|---|---|---|
| SAR narrative | Filing error, missed suspicious activity, FINRA/FinCEN scrutiny | Named BSA/AML officer; documented review against transaction data; sign-off with notes |
| Board risk memo | Misinformed board decision, governance failure, D&O exposure | Named senior risk officer; verification against KRI data and source documents; challenge record |
| Regulatory change impact assessment | Missed compliance deadline, incomplete implementation, examiner finding | Named compliance officer; cross-check against primary regulation text; documented conclusions |
| Policy draft or review | Policy with errors distributed to staff, relied upon in audit | Named policy owner; line-by-line review against regulatory requirements; approval sign-off |
| Enforcement action summary | Mischaracterized regulatory position, misinformed compliance strategy | Named reviewer; source-document verification; explicit note on what was AI-generated vs. independently verified |
| Vendor risk assessment | Incorrect risk tier, missed control gap, flawed onboarding decision | Named TPRM analyst; verification of vendor-specific claims; documented challenge on risk conclusions |
The pattern is the same across all of them: there’s a named human, that human has access to the source materials, that human documented their verification, and the sign-off reflects judgment, not approval of an appearance.
What Genuine Review Looks Like
There’s a difference between reviewing a document and reviewing what the document says.
A genuine review of an AI-generated regulatory change impact assessment looks like this:
- Pull the primary regulation text (or the official agency summary) and compare it against the AI’s characterization of the key requirements.
- Identify any claims that reference specific dates, thresholds, or enforcement actions, and verify at least a sample against primary sources.
- Note what the AI analysis included that you agreed with, what you changed or qualified, and what you added.
- Document whether there’s anything the AI analysis didn’t cover that you independently concluded should be in scope.
- Sign off with your name, role, date, and a note summarizing what your review covered.
This process takes 20-45 minutes for a typical impact assessment. It’s proportionate to the risk. It produces an evidence artifact that demonstrates the review was substantive.
Contrast that with: read through the document, it looks fine, add your name, send.
Both approaches result in a signed document. Only one of them is defensible when an examiner asks “who reviewed this and what did they verify?”
See The AI Output Review Checklist for Risk and Compliance Teams for a structured review framework you can apply across AI-generated compliance work products.
The “AI Wrote It” Defense That Doesn’t Work
Here is the accountability failure mode that’s emerging across compliance functions: a compliance deliverable is distributed, relied upon, or submitted that contains material errors. When the error surfaces, the response is “the AI generated it” — sometimes implicitly, sometimes explicitly.
This is not a defense. It is, in fact, the disclosure of an accountability gap.
When an AI tool generates a document and a compliance professional signs it, the signature represents that person’s professional judgment. The AI tool is a drafting aid — the equivalent of a junior analyst producing a first draft. The professional who signs is accountable for the final product, regardless of how it was generated.
The Baker Donelson 2026 AI Legal Forecast is explicit: regulators are shifting focus from “do you have AI controls in policy?” to “can you demonstrate that your controls are operating effectively?” For compliance work products, “operating effectively” means the review was substantive, documented, and performed by a named, accountable professional.
If your organization can’t answer “who reviewed this AI-generated document and what did they verify?” you don’t have a review process. You have a faster way of producing documents that still need a real review.
Building the Accountability Chain
A practical accountability framework for AI-generated compliance work has five components:
1. Designation: Every AI-generated work product in a compliance function should have a designated accountable reviewer before it’s distributed or relied upon. The designation should be role-specific, not generic (“the compliance team”).
2. Review protocol: For each major work product category (SAR narrative, board memo, policy review, impact assessment), define what a substantive review requires — what sources to check, what claims to verify, what challenge documentation to produce.
3. Evidence artifact: For higher-risk work products (anything going to the board, regulators, or informing material decisions), the review should produce a documented artifact: challenge notes, a sign-off memo, or a review log entry that answers the “what did you actually check” question.
4. Version control: Retain both the AI-generated draft and the final reviewed version. The delta between them tells a story about the quality of review. If the AI draft and the signed final document are identical, that’s a question a regulator will ask.
5. Escalation path: Define what happens when the reviewer identifies a material error, gap, or unsupported claim in an AI-generated draft. That’s not a “send it back to the AI” situation — it’s a human judgment moment that may require additional source research, specialist review, or escalation.
What This Means If You’re Using AI Now
Most compliance teams are using AI for drafting and research, even if that use isn’t formally governed. The accountability framework above doesn’t require stopping — it requires intentionalizing.
Start with the highest-risk work products: anything that goes to the board, regulators, or informs filing decisions. Define who is accountable for each category. Establish what the review protocol requires. Begin producing evidence artifacts that document the review.
The fintech.global 2026 AI compliance priorities survey characterized the shift clearly: 2025 was the year of AI adoption; 2026 is the year of AI accountability. Regulators are moving from asking “do you use AI responsibly?” to asking for evidence of how the governance works.
The question “who looked at this?” has a clear answer in a well-governed program. If your program can’t answer it, that’s the gap to close — before an examiner asks it on behalf of the exam team.
So What Does This Mean for Your Program?
AI tools are legitimate productivity multipliers for compliance teams under pressure. The problem isn’t using them — the problem is using them without an accountability structure that can withstand scrutiny.
The test is simple: for every AI-generated compliance work product your team distributes or relies upon, ask:
- Who is named as accountable for this output?
- What did they verify, and against what sources?
- Where is the evidence of their review?
If the answers are “unclear,” “not documented,” or “no one specifically” — you have accountability theater, not accountability. That gap is manageable if you close it now. It’s much harder to close it after an examiner finds the document that was wrong.
If your organization is building AI governance for compliance work — including model inventory, pre-deployment checklists, vendor questionnaires, and accountability frameworks mapped to 2026 regulatory requirements — the AI Risk Assessment Template & Guide covers the governance structures regulators are starting to test against. Get the AI Risk Assessment Template →
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who is accountable for AI-generated compliance work products?
What does 'human-in-the-loop' actually require regulators to see?
Does this apply to AI tools built into compliance software, not just ChatGPT?
What evidence artifacts should organizations retain for AI-generated compliance work?
What's the risk if AI-generated compliance work isn't properly attributed and reviewed?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026