From Bottlenecks to Breakthroughs:
Optimizing AML/CFT Compliance with Cognitive AI — Without Ripping-and-Replacing
Executive Summary
David Shapiro
Regulatory Affairs, US
U.S. financial institutions are operating under mounting pressure. Regulatory scrutiny is intensifying, compliance costs are soaring, and criminal networks are evolving faster than the systems designed to stop them.
At the same time, a new wave of financial crime threats—synthetic opioid trafficking, virtual assets, and AI-assisted money laundering—demand a smarter, faster response. These typologies move fluidly across payment rails, exploit opaque platforms, and often evade detection by traditional rule-based systems.
Meanwhile, banks are being encouraged, if not expected, to embrace innovation, particularly AI, to improve both detection and efficiency. Yet for many institutions, immediately tearing out and replacing entrenched legacy systems presents too much operational risk, cost, and disruption.
This paper outlines a more pragmatic path forward: AML optimization through Cognitive AI. It enables institutions to improve outcomes quickly, build trust in AI, and lay the groundwork for deeper architectural transformation—without the need to rip-and-replace their existing transaction monitoring systems. Cognitive AI uncovers hidden risks, reduces false positives, and delivers explainable, regulator-aligned intelligence at scale.
For U.S. compliance teams navigating escalating expectations and shrinking resources, Cognitive AI provides a powerful solution: one that improves outcomes without disrupting operations—transforming compliance from a bottleneck into a breakthrough.
Table of Contents
-
01Executive Summary
-
02The Compliance Pressure Cooker in U.S. Banking
-
03AI Policy Momentum from the White House
-
04What Banking Leaders Are Now Saying About AI
-
05Why Rip-and-Replace Is the Wrong Move Right Now
-
06ThetaRay’s Three-Step Optimization Model
-
07Business Impact: What U.S. Institutions Gain
-
08Use Case: Mid-Sized U.S. Bank Optimization POC
-
09Why Cognitive AI Stands Apart
-
10Conclusion: Smarter Compliance Without Disruption
-
11Glossary of Terms
In today’s compliance landscape, standing still is not an option.
Over the past two years, U.S. regulators have sharpened their focus on transaction monitoring. Enforcement actions from the Office of the Comptroller of the Currency1 (OCC) and Financial Crimes Enforcement Network (FinCEN) have spotlighted institutions with outdated monitoring controls, ineffective alert triage, and narrow detection scopes.
At the same time, the nature of financial activity is undergoing a profound transformation. Real-time payments, embedded finance, and digital assets are reshaping how—and how fast—money moves. Transactions are no longer confined to bank-led channels or batch-based cycles. Instead, money flows through wallets, APIs, and instant settlement platforms, often beyond the view of legacy surveillance.
These shifts create fertile ground for newer criminal typologies. Synthetic opioid proceeds now flow through instant rails, virtual assets are laundered via decentralized mixers, and embedded platforms create new vulnerabilities around identity, velocity, and transparency. Rule-based systems simply weren’t designed for this level of complexity or speed.
Compliance teams are expected to respond, yet with fewer resources and higher stakes.
-
1
False positives still dominate alert queues, exceeding 90% in many institutions
-
2
Criminal innovation is outpacing monitoring rulebooks
-
3
Annual compliance spend exceeds $60 billion in the U.S.
-
4
Board-level oversight and personal liability for compliance leaders has intensified
-
5
Regulators are demanding explainability, risk-based prioritization, and operational agility
This is no longer just a technology problem, it’s a strategic risk issue. Compliance leaders now face personal criminal and monetary exposure for failures tied to inadequate controls, poor model governance, or weak escalation frameworks.
What’s more, regulators are signaling that explainability, auditability, and operational responsiveness are now table stakes—not optional upgrades.
In this environment, the question isn’t whether to modernize, but how to do it without introducing disruption, regulatory risk, or cost overruns. Compliance teams must find a way to adapt. But the traditional playbook—more rules, more staff, more dashboards—is no longer scalable.
AI isn’t just a buzzword in earnings reports—it’s fast becoming a strategic lever.
In Q2 2025 earnings calls, executives from Bank of America, Wells Fargo, and PNC pointed to AI as central to achieving operational efficiency, cost control, and growth enablement.
- Bank of America noted that halving consumer banking headcount and doubling revenues was “enabled by application of technology on scale.”
- Wells Fargo spoke of ongoing staff reductions supported by automation and AI.
- PNC emphasized that AI investments are key to “keeping expenses on the low end as it relates to people.”
The common thread? AI is not just about innovation—it’s about business survival. And in compliance, where cost pressure meets regulatory scrutiny, the upside is especially clear.
But to capture that upside, the AI must be explainable, adaptable, and low-disruption.
While the limitations of legacy transaction monitoring systems are widely acknowledged, replacing them outright is often neither practical nor strategic. These systems are deeply embedded within a bank’s broader technology ecosystem, connected to core banking platforms, KYC infrastructure, sanctions screening, and case management workflows. Unwinding them introduces considerable complexity, not just from a technical perspective but also from a regulatory and operational standpoint.
For many institutions, the risk of operational downtime, compliance gaps, and potential business disruption far outweighs the theoretical benefits of a full system overhaul. Replacing a transaction monitoring engine often requires revalidating data flows, reconfiguring thresholds, retraining teams, and coordinating across multiple vendors. It can take months—if not years—to fully transition, during which time exposure to both regulatory scrutiny and financial crime may increase.
There’s also the cost to consider. Beyond licensing and implementation fees, there’s the hidden burden of parallel testing, audit readiness, and change management. In today’s resource-constrained environment, few compliance programs can afford that kind of upheaval.
That’s why many institutions are choosing a more pragmatic path: optimization. Instead of tearing out existing infrastructure, they are augmenting it, layering in Cognitive AI to elevate detection precision, reduce false positives, and prioritize high-risk alerts. This delivers immediate impact without disturbing the systems already in place.
There’s no downtime, no retraining of staff, and no expensive ongoing maintenance contracts, just better performance from day one. For many banks, this optimization strategy becomes the ideal first step toward responsible AI adoption: low-risk, high-impact, and fully auditable.
Just as importantly, it lays the groundwork for more transformative change. Institutions that begin by enhancing legacy systems often discover that they’re better prepared—strategically, culturally, and operationally—for a future in which AI becomes the core detection engine. In this way, optimization isn’t the end of the journey. It’s the on-ramp to a full modernization roadmap, future-proofing compliance without destabilizing the present.
ThetaRay offers a gradual, low-risk transition that enables banks to enhance compliance while maintaining operational stability.
Step 1: Optimize & Enhance Existing Compliance Operations
(AI augmentation over the incumbent system)
- Overlay ThetaRay’s AI alongside your existing rules-based system—no need to rip and replace.
- Reduce false positives by up to 90%, cutting down investigation time and compliance costs.
- Prioritizes True Positive Alerts – intelligently filter and prioritize true positive alerts, focus on the most critical threats while reducing noise from false positives.
- Provide explainable, risk-based alerts, enriching investigations with actionable intelligence.
- Improve SAR productivity by helping analysts focus on real threats.
Outcome: Immediate efficiency gains without disrupting current workflows.
Step 2: Parallel Testing & AI-Driven Optimization
(Replacing rule-based detection while running in parallel)
- Run ThetaRay’s AI-driven risk models in parallel with existing transaction monitoring rules.
- Gradually phase out legacy rules, reducing dependency on static logic.
- Monitor AI-generated alerts side-by-side with the incumbent system for performance validation.
- Fine-tune risk thresholds dynamically to align with regulatory expectations.
- Enhance regulatory confidence with explainable AI-driven insights.
Outcome: Demonstrate AI’s superior accuracy, lower operational costs, and improved detection capabilities—all while ensuring regulatory alignment.
Step 3: Final Option – A Full Conversion to Cognitive AI Core Detection
(ThetaRay becomes the bank’s primary transaction monitoring system)
- Decommission legacy rule-based monitoring, eliminating costly maintenance and manual tuning.
- Leverage ThetaRay’s Cognitive AI as the core detection engine for effective, dynamic financial crime detection.
- Maintain full transparency & auditability, ensuring compliance teams and regulators have clear visibility into risk coverage and risk mitigation decisions.
- Continuously improve detection accuracy through ongoing AI learning and refinement.
- Reduce total cost of ownership (TCO) by eliminating expensive professional services and system upkeep.
Outcome: A future-proof, AI-powered compliance system that scales with business growth, enhances efficiency, and delivers proactive financial crime detection.
This approach isn’t theoretical. Institutions using Cognitive AI for transaction monitoring optimization report:
| Impact Area | Measured Benefit |
|---|---|
| Operational Costs | Up to 50% reduction in investigation time per analyst |
| Alert Quality | SAR conversion rates increase on average by 30-40% due to smarter alert prioritization |
| Alert Prioritization | High-risk cases identified and prioritized for investigation with clear reasoning behind alerts that have a high probability of producing false positives; saving time, improving accuracy, and ensuring regulatory transparency. |
| Scalability | Able to onboard new payment products or expand jurisdictions all while supporting real-time payments, virtual assets, and multi-entity operations |
| Audit Readiness | Alerts include full audit trail, AI explainability, documentation and risk model validation |
| IT Load | No changes required to existing rule-engines or core platforms, minimizing resource requirement for implementation and ongoing maintenance |
In a recent deployment with a U.S. mid-sized bank:
- Alerts processed dropped by 67%
- False positives decreased from 95% to 28%
- Monthlyminvestigation hours reduced by over 2,700 hours
- Projected annual savings exceeded $570,000
Importantly, the deployment took less than four weeks—without modifying the existing system or delaying BAU operations—as ThetaRay ran in parallel with their existing platform.
As financial institutions explore the potential of artificial intelligence in transaction monitoring, the market is flooded with solutions that promise innovation—but often fall short of real operational or regulatory readiness. Many systems labeled “AI” still rely on supervised machine learning models that demand large volumes of fully labeled historical data, require frequent re-tuning, and often operate as opaque black boxes, leaving compliance teams with limited visibility and regulators with limited patience.
Cognitive AI takes a fundamentally different approach. Built on semi-supervised machine learning, it doesn’t require predefined rules or labeled typologies to detect risk. Instead, it continuously analyzes transactional behavior to identify behavioral anomalies, hidden relationships, and emerging threat patterns—even those the system has never encountered before. This makes it especially well-suited for today’s high-velocity, high-complexity environments, where criminal tactics shift faster than rulebooks can be updated.
Beyond detection power, what sets Cognitive AI apart is its ability to meet the rising expectations of both operational teams and regulators. It is designed with explainability, traceability, and auditability at its core, offering:
- Clear rationale for every alert, including behavioral insights and clear explanations around scoring
- Feature attribution and decision path transparency, ensuring models are readable and transparent for investigators, supervisors, and regulators
- Integrated model governance and audit logs, support defensibility and documentation, and simplify auditing reviews and internal risk management
Critically, it also delivers on the need to be future-ready. Cognitive AI aligns with global AML/CFT guidance from FATF, the Wolfsberg Group, and the European Banking Authority, as well as emerging U.S. policy directives such as OMB Memoranda M-25-21 and M-25-22. Institutions can be confident that their AI-enhanced compliance programs are not only effective but fully in line with evolving supervisory expectations.
And perhaps most important of all: none of this requires a system overhaul. Cognitive AI can layer directly onto existing infrastructure, amplifying what already works while reducing false positives, boosting efficiency, and improving the quality of suspicious activity reports, enabling institutions to upgrade performance, accuracy, and auditability, without downtime, retraining, or disruption to BAU workflows—just measurable results, delivered fast.
This ability to optimize from within, rather than replace from the outside, is central to the theme of this paper. In a climate where speed, scale, and regulatory alignment are critical, Cognitive AI enables financial institutions to move decisively. Institutions can modernize at their own pace, without sacrificing control or compliance, it offers a path to smarter, leaner, and more resilient compliance—not years from now, but immediately.
For U.S. banks navigating the dual demands of innovation and regulatory accountability, Cognitive AI doesn’t just stand apart. It stands ready.
Across the U.S. banking landscape, compliance teams are being pulled in two directions; called to innovate, but required to reduce risk, legacy infrastructure, and rising operational costs. As financial crime evolves and regulatory expectations increase, embarking on a full rip-and-replace journey is neither realistic nor necessary.
This white paper has outlined a third path: optimization through Cognitive AI. Rather than replacing existing systems, banks can enhance them, instantly improving detection, reducing false positives, and regaining control of overwhelmed investigative functions. This approach is pragmatic, scalable, and aligned with both institutional realities and global supervisory momentum.
By layering onto existing infrastructure, institutions don’t need to choose between innovation and stability; optimization with Cognitive AI allows them to achieve both. Compliance leaders can deliver meaningful results without business disruption:
- No downtime – preserves business-as-usual operations
- No staff retraining – reducing alert fatigue and investigative burden
- No prolonged implementation – delivering meaningful gains in detection and efficiency
- No trade-off between innovation and control – setting a strategic foundation for Cognitive AI transaction monitoring at scale
In short, this isn’t just a technological shift. It’s a mindset shift. From compliance as a cost center to compliance as a growth enabler. From static controls to intelligent detection. From keeping up to moving ahead.
Financial institutions don’t need to rip and replace. They need to start smart—by making what they already have stronger, faster, and smarter.
In a landscape where the cost of delay is rising and regulatory tolerance is thinning, optimization isn’t a stopgap. It’s a strategic leap forward.
Glossary
AI (Artificial Intelligence)
Technology that simulates human intelligence processes using algorithms, including learning, pattern recognition, and decision-making. In AML, AI helps identify suspicious behaviors beyond static rule sets.
Alert Prioritization
Alert prioritization is the process of ranking compliance alerts based on their estimated risk or urgency to focus analyst attention where it matters most. Instead of treating all alerts equally, prioritization uses contextual factors—such as customer risk scores, transaction anomalies, or typology matches—to triage cases. This improves investigative efficiency, reduces alert fatigue, and accelerates response to high-risk activity.
AML (Anti-Money Laundering)
A legal and regulatory framework designed to prevent the use of financial systems to disguise the origins of illegally obtained money.
AMLA (Anti-Money Laundering Authority)
A forthcoming European Union supervisory body tasked with coordinating AML supervision across EU member states and directly supervising high-risk institutions.
API (Application Programming Interface)
A software interface that allows applications to communicate with each other. In finance, APIs support embedded services and real-time integrations between platforms.
BAU (Business As Usual)
The standard operational status of systems and processes within a business. Maintaining BAU is critical during technology upgrades or optimization efforts.
CFT (Countering the Financing of Terrorism)
Policies and controls designed to detect and prevent the movement of funds intended to support terrorism.
Cognitive AI
An AI model based on unsupervised learning that identifies previously unseen patterns in data without relying on predefined rules. In AML, it enables more adaptive, dynamic risk detection.
Digital Assets
Digital representations of value, such as cryptocurrencies, that can be used for exchange, investment, or payment. They present unique risks for AML compliance due to their speed, anonymity, and global reach.
EBA (European Banking Authority)
An EU financial regulatory agency that sets guidelines and standards for banking supervision, including those for AML/CFT and responsible use of AI in financial services.
Embedded Finance
The integration of financial services like lending, payments, or insurance into non-financial platforms, increasing transactional touchpoints and AML oversight complexity.
FATF (Financial Action Task Force)
An intergovernmental body that develops global standards and promotes effective implementation of AML and CFT measures worldwide.
FedNow
A real-time payments service launched by the Federal Reserve to enable instant fund transfers between U.S. banks 24/7.
FinCEN (Financial Crimes Enforcement Network)
A bureau of the U.S. Treasury responsible for enforcing AML laws, analyzing suspicious activity reports (SARs), and coordinating financial crime intelligence across institutions.
KYC (Know Your Customer)
The process by which financial institutions verify a customer’s identity and assess their risk profile before and during the relationship to comply with AML/CFT regulations.
OCC (Office of the Comptroller of the Currency)
A U.S. financial regulatory agency that supervises and regulates national banks and federal savings associations, including their AML compliance.
OMB (Office of Management and Budget)
A U.S. federal office that, in 2024–2025, issued guidance (M-25-21 and M-25-22) outlining requirements for government AI use—highlighting explainability, auditability, and fairness.
Real-Time Payments
Payment systems that enable funds to be transferred instantly between bank accounts at any time of day. These increase transaction velocity and reduce review timeframes for AML teams.
SAR (Suspicious Activity Report)
A regulatory report that financial institutions must file with authorities (e.g., FinCEN) when transactions appear unusual or indicative of money laundering or terrorism financing.
Semi-Supervised Machine Learning
Semi-supervised machine learning combines a small amount of labeled data with a large volume of unlabeled data to improve model training and prediction. In financial crime detection, it helps systems learn from a limited set of confirmed suspicious cases while still capturing broader patterns from raw transaction behavior. This approach bridges the gap between rule-based systems and fully unsupervised AI, offering more adaptable and context-aware risk detection.
Supervised Machine Learning
Supervised machine learning is an approach where models are trained on labeled historical datasets—that is, data that includes both the inputs and the correct outputs (e.g., known suspicious vs. non-suspicious transactions). The model learns patterns from this labeled data to make predictions on new, unseen inputs. In AML, supervised learning can help identify previously flagged behaviors but may struggle to detect emerging or unknown typologies, as its performance depends heavily on the quality and scope of historical labeling.
TCO (Total Cost of Ownership)
The full cost of operating a technology solution, including implementation, training, maintenance, and vendor services—used to evaluate long-term efficiency.
Unsupervised Machine Learning
A form of AI that learns from unstructured data without labeled outcomes, making it well suited to detect unknown risks or novel financial crime typologies.
Virtual Assets
A type of digital asset used as a medium of exchange, including cryptocurrencies. Virtual assets pose AML risks due to their pseudonymous and decentralized nature.
Wolfsberg Group
An association of global banks that issues guidance on best practices in AML and financial crime risk management, including transaction monitoring standards.
Sources:
- OCC and Fed examiner guidance
- FinCEN enforcement actions archive
- LexisNexis Risk Solutions, “True Cost of Financial Crime Compliance” (2023)
- White House Office of Management and Budget (2025)
- DLA Piper summary of federal AI guidance (2025)
- Evident Insights, “The Brief – CEOs Preview AI Layoffs” (July 2025)
- Chartis Research, “AML Technology Market Update” (2023)