Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

If AI Writes the Memo, Who Owns the Risk? Accountability for AI-Generated Compliance Work

AI is generating risk assessments, SAR narratives, board memos, and regulatory change summaries. But 'human-in-the-loop' without documented challenge is accountability theater. Here's what genuine ownership looks like — and what regulators are starting to require.

By Rebecca Leung · May 31, 2026 ·
Table of Contents

In May 2026, Standard Chartered confirmed it will cut approximately 7,000 corporate roles by 2030 — explicitly linking the reductions to AI automation of back-office and operations functions. The bank’s CEO described the plan as replacing “lower-value human capital” with AI-driven processes across 52,000 corporate staff. HSBC’s CEO, commenting separately, said the bank needs its entire workforce on the AI transition — while also acknowledging AI will reshape what those jobs look like.

Compliance functions are not immune. SAR narratives. Policy reviews. Board risk memos. Regulatory change summaries. Impact assessments. These are exactly the categories that generative AI drafts reasonably well and that compliance teams are quietly using AI to accelerate.

That raises a question most programs haven’t formally answered: when AI writes the memo, who owns the risk?

This isn’t abstract. Regulators are starting to ask it directly.

TL;DR

  • Compliance teams are using AI to draft SAR narratives, risk assessments, board memos, and regulatory change summaries — and regulators are beginning to ask how those outputs are reviewed and who is accountable.
  • “Human-in-the-loop” without documented challenge isn’t accountability — it’s a paper trail that fails when something goes wrong.
  • The FCA’s Senior Managers Regime holds named executives personally accountable for AI outcomes. The HKMA requires human oversight for high-impact decisions. NIST AI RMF and the FS AI RMF both require documented accountability structures.
  • Genuine accountability requires: a named reviewer, documented verification against source materials, a challenge record, and a sign-off that reflects professional judgment, not a rubber stamp.

The Accountability Illusion

Here’s the version of AI governance that doesn’t work: a compliance analyst uses Claude or ChatGPT to draft a regulatory change impact assessment. They read it. It looks reasonable. They add their name to it and send it to management.

That’s “human-in-the-loop.” It’s also not accountability.

Accountability requires that the person who signed off can answer the following questions:

  • What source materials did you verify the analysis against?
  • What did you challenge or change in the AI’s draft?
  • What did you independently conclude?
  • If there’s an error in this document, what review process should have caught it?

A reviewer who can’t answer those questions didn’t review the document — they reviewed the appearance of a document. That distinction matters enormously when the document is wrong, when a regulator asks about it, or when it becomes the basis for a board decision that turns out to be flawed.

What Regulators Are Already Requiring

The regulatory framework for AI accountability in compliance work is clearer than many practitioners realize.

FCA Senior Managers Regime (UK / cross-border implications): The FCA has been explicit that its Senior Managers Regime applies to AI outcomes. Named executives are personally accountable for AI systems operating in their areas — including AI that generates compliance work products. The FCA described its approach as “leaning on the SMR to hold named executives accountable for AI outcomes” rather than issuing prescriptive AI-specific rules. The practical effect: if AI generates an analysis that causes harm, the named senior manager is accountable for whether adequate oversight was in place. “We use AI tools but no one individually owned the output” is not a defense.

HKMA (AI guidance for banks): The Hong Kong Monetary Authority requires that banks maintain humans in the loop for high-impact decisions and maintain explainability for any AI model affecting customer outcomes. For compliance work, this means that AI-generated outputs that inform consequential decisions — filing decisions, regulatory disclosures, board risk positions — require documented human judgment, not just human presence.

NIST AI RMF GOVERN Function: The NIST AI Risk Management Framework’s GOVERN function specifically requires organizations to define accountability structures for AI systems: who is responsible for oversight, what their review obligations are, and how accountability is documented. For regulated financial institutions using AI in compliance functions, this translates directly to requiring accountable-reviewer designations for AI-generated work products.

FS AI RMF (U.S. Treasury, February 2026): The Financial Services AI Risk Management Framework, published by the Treasury with 230 control objectives, includes accountability structures as a core governance requirement. Institutions are expected to document who is responsible for AI outcomes — including compliance-related outputs — and demonstrate that accountability chains are operationalized, not just stated in policy.

See AI Governance Framework for Financial Services: A Practical Guide for how these frameworks apply to a working program.

The Work Products That Require Named Accountability

Not all AI-generated compliance work carries the same risk profile. Here’s how to think about accountability requirements by work type:

Work ProductRisk if WrongMinimum Accountability Requirement
SAR narrativeFiling error, missed suspicious activity, FINRA/FinCEN scrutinyNamed BSA/AML officer; documented review against transaction data; sign-off with notes
Board risk memoMisinformed board decision, governance failure, D&O exposureNamed senior risk officer; verification against KRI data and source documents; challenge record
Regulatory change impact assessmentMissed compliance deadline, incomplete implementation, examiner findingNamed compliance officer; cross-check against primary regulation text; documented conclusions
Policy draft or reviewPolicy with errors distributed to staff, relied upon in auditNamed policy owner; line-by-line review against regulatory requirements; approval sign-off
Enforcement action summaryMischaracterized regulatory position, misinformed compliance strategyNamed reviewer; source-document verification; explicit note on what was AI-generated vs. independently verified
Vendor risk assessmentIncorrect risk tier, missed control gap, flawed onboarding decisionNamed TPRM analyst; verification of vendor-specific claims; documented challenge on risk conclusions

The pattern is the same across all of them: there’s a named human, that human has access to the source materials, that human documented their verification, and the sign-off reflects judgment, not approval of an appearance.

What Genuine Review Looks Like

There’s a difference between reviewing a document and reviewing what the document says.

A genuine review of an AI-generated regulatory change impact assessment looks like this:

  1. Pull the primary regulation text (or the official agency summary) and compare it against the AI’s characterization of the key requirements.
  2. Identify any claims that reference specific dates, thresholds, or enforcement actions, and verify at least a sample against primary sources.
  3. Note what the AI analysis included that you agreed with, what you changed or qualified, and what you added.
  4. Document whether there’s anything the AI analysis didn’t cover that you independently concluded should be in scope.
  5. Sign off with your name, role, date, and a note summarizing what your review covered.

This process takes 20-45 minutes for a typical impact assessment. It’s proportionate to the risk. It produces an evidence artifact that demonstrates the review was substantive.

Contrast that with: read through the document, it looks fine, add your name, send.

Both approaches result in a signed document. Only one of them is defensible when an examiner asks “who reviewed this and what did they verify?”

See The AI Output Review Checklist for Risk and Compliance Teams for a structured review framework you can apply across AI-generated compliance work products.

The “AI Wrote It” Defense That Doesn’t Work

Here is the accountability failure mode that’s emerging across compliance functions: a compliance deliverable is distributed, relied upon, or submitted that contains material errors. When the error surfaces, the response is “the AI generated it” — sometimes implicitly, sometimes explicitly.

This is not a defense. It is, in fact, the disclosure of an accountability gap.

When an AI tool generates a document and a compliance professional signs it, the signature represents that person’s professional judgment. The AI tool is a drafting aid — the equivalent of a junior analyst producing a first draft. The professional who signs is accountable for the final product, regardless of how it was generated.

The Baker Donelson 2026 AI Legal Forecast is explicit: regulators are shifting focus from “do you have AI controls in policy?” to “can you demonstrate that your controls are operating effectively?” For compliance work products, “operating effectively” means the review was substantive, documented, and performed by a named, accountable professional.

If your organization can’t answer “who reviewed this AI-generated document and what did they verify?” you don’t have a review process. You have a faster way of producing documents that still need a real review.

Building the Accountability Chain

A practical accountability framework for AI-generated compliance work has five components:

1. Designation: Every AI-generated work product in a compliance function should have a designated accountable reviewer before it’s distributed or relied upon. The designation should be role-specific, not generic (“the compliance team”).

2. Review protocol: For each major work product category (SAR narrative, board memo, policy review, impact assessment), define what a substantive review requires — what sources to check, what claims to verify, what challenge documentation to produce.

3. Evidence artifact: For higher-risk work products (anything going to the board, regulators, or informing material decisions), the review should produce a documented artifact: challenge notes, a sign-off memo, or a review log entry that answers the “what did you actually check” question.

4. Version control: Retain both the AI-generated draft and the final reviewed version. The delta between them tells a story about the quality of review. If the AI draft and the signed final document are identical, that’s a question a regulator will ask.

5. Escalation path: Define what happens when the reviewer identifies a material error, gap, or unsupported claim in an AI-generated draft. That’s not a “send it back to the AI” situation — it’s a human judgment moment that may require additional source research, specialist review, or escalation.

What This Means If You’re Using AI Now

Most compliance teams are using AI for drafting and research, even if that use isn’t formally governed. The accountability framework above doesn’t require stopping — it requires intentionalizing.

Start with the highest-risk work products: anything that goes to the board, regulators, or informs filing decisions. Define who is accountable for each category. Establish what the review protocol requires. Begin producing evidence artifacts that document the review.

The fintech.global 2026 AI compliance priorities survey characterized the shift clearly: 2025 was the year of AI adoption; 2026 is the year of AI accountability. Regulators are moving from asking “do you use AI responsibly?” to asking for evidence of how the governance works.

The question “who looked at this?” has a clear answer in a well-governed program. If your program can’t answer it, that’s the gap to close — before an examiner asks it on behalf of the exam team.

So What Does This Mean for Your Program?

AI tools are legitimate productivity multipliers for compliance teams under pressure. The problem isn’t using them — the problem is using them without an accountability structure that can withstand scrutiny.

The test is simple: for every AI-generated compliance work product your team distributes or relies upon, ask:

  • Who is named as accountable for this output?
  • What did they verify, and against what sources?
  • Where is the evidence of their review?

If the answers are “unclear,” “not documented,” or “no one specifically” — you have accountability theater, not accountability. That gap is manageable if you close it now. It’s much harder to close it after an examiner finds the document that was wrong.


If your organization is building AI governance for compliance work — including model inventory, pre-deployment checklists, vendor questionnaires, and accountability frameworks mapped to 2026 regulatory requirements — the AI Risk Assessment Template & Guide covers the governance structures regulators are starting to test against. Get the AI Risk Assessment Template →

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Who is accountable for AI-generated compliance work products?
The named human who reviews, challenges, and signs off on the work product — not the AI tool, and not 'the team.' Accountability requires a specific person who can explain what they reviewed, what they verified against source materials, what they changed or challenged, and what they concluded independently. Under the FCA's Senior Managers Regime, named executives are personally accountable for AI outcomes in their area of responsibility. A sign-off without a documented review trail is not accountability — it's liability without defense.
What does 'human-in-the-loop' actually require regulators to see?
Regulators — including the FCA, HKMA, and increasingly the OCC — want evidence that human review was substantive, not performative. That means: the reviewer had access to the source materials the AI used, the reviewer tested at least a sample of claims or conclusions against those sources, the reviewer documented what they verified and what they changed, and the sign-off reflects a professional judgment — not just clicking 'approve.' A log entry that says 'Reviewed and approved' with a timestamp is not sufficient if there's no evidence of what the review actually involved.
Does this apply to AI tools built into compliance software, not just ChatGPT?
Yes. Whether the AI is embedded in your GRC platform, your AML monitoring system, your document review tool, or a consumer chatbot, the accountability question is the same: who reviewed the output before it was relied upon, what did they verify, and how was that documented? The fact that AI is embedded in a vendor product doesn't shift accountability to the vendor. Your organization relied on the output. Your organization owns the accountability for that reliance.
What evidence artifacts should organizations retain for AI-generated compliance work?
At minimum: (1) a record of which AI tool was used and what version or configuration, (2) a description of what the AI was asked to do (the prompt or task input), (3) the reviewer's documented challenge notes — what they verified, what they changed, what they accepted, (4) the final signed-off version, and (5) the name and role of the accountable reviewer. For high-risk work products — board risk memos, SAR narratives, material disclosure drafts — this evidence should be retained for the same period as the work product itself.
What's the risk if AI-generated compliance work isn't properly attributed and reviewed?
Several risks converge. First, regulatory: examiners at the OCC, FCA, and HKMA are asking how AI is used in compliance processes. An inability to demonstrate substantive human review for a board memo or SAR narrative invites scrutiny on the quality of the work and the maturity of the governance program. Second, professional: when an AI-generated risk assessment contains an error — a misread regulation, a hallucinated enforcement action, a missed exception — the question isn't whether the AI made the mistake. The question is why the human reviewer didn't catch it. Third, reputational: distributing AI-generated work that's materially wrong to a regulator or board damages credibility in ways that are hard to recover from.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.