
There is something different about discussing the future of financial crime compliance in Brazil.
At FEBRABAN TECH in São Paulo, we had the opportunity to sit down with banking and financial crime leaders to talk about where AML is heading, what is actually changing inside financial institutions, and, perhaps more importantly, what still needs to change.
The conversation moved quickly beyond AI itself.
Because the real question facing banks today is no longer: How do we introduce more advanced technology into AML?
It is: How do we build a financial crime program that can prove its controls are effective, scale as risks evolve, and still stand up to regulatory scrutiny?
Across the discussion, four themes kept coming back.
1. Regulators Want Evidence That Controls Actually Work
For years, financial institutions have invested enormous effort in demonstrating that regulatory requirements are reflected in their policies, procedures and systems.
But having a control in place is not the same as proving that it works.
That distinction is becoming increasingly important. The conversation at FEBRABAN TECH reflected a broader shift from control existence to control effectiveness. Regulators across the region, including Banco Central do Brasil (BCB), increasingly need banks to demonstrate not only that monitoring happens, but that their controls identify the right risks, are calibrated appropriately, produce measurable outcomes and can be audited.
This changes how we need to think about detection models.
In a market like Brazil, where the explosive growth of instant payment rails like Pix has fundamentally altered customer behavior almost overnight, a transaction monitoring model cannot simply be implemented and left untouched for years. Customer behavior changes. Criminal typologies change. Products change. Regulations change.
The controls need to evolve with them.
That means continuous testing, calibration, simulation and reassessment need to become part of the operating model rather than an occasional compliance exercise.
It also makes independent model validation increasingly important. Champion/challenger approaches give institutions a practical way to test whether an alternative model can identify risks the existing model is missing, improve detection quality or reduce unnecessary false positives.
The question becomes less “Is our model running as designed?” and more “Can we demonstrate that this is still the best way to detect the risk?”
2. The Future of Detection Cannot Be Built in Silos
CDD knows one part of the customer. Screening knows another. Transaction monitoring sees another.
But financial crime does not happen in separate systems.
One of the strongest themes from our conversations in São Paulo was the need to move toward a 360-degree view of the customer and their risk. In Brazil’s rapidly evolving financial landscape, where new digital banking platforms and instant payment ecosystems are frequently layered alongside legacy banking infrastructure, these silos create blind spots that sophisticated criminal networks actively exploit.
A suspicious transaction may look relatively harmless when viewed in isolation. Add customer information, counterparties, screening results, behavioral history and network relationships, and the risk picture can change completely.
That is where the evolution from rigid rules toward more intelligent, AI-enabled detection becomes particularly important.
Traditional rules remain valuable, but by design they tend to look for scenarios that institutions already know how to define. AI gives institutions another layer: the ability to identify more complex patterns and relationships across much larger volumes of information.
But there is an important caveat.
Better detection cannot simply mean more alerts.
If a more sophisticated system identifies significantly more risk signals but sends all of them to investigators, the bank has not solved its operational problem. It may have made it worse.
The objective has to be better prioritization, alert quality and context, so institutions can expand their detection capabilities without creating an unmanageable investigation queue.

3. AI Changes the Analyst’s Job, Not Just the Technology
This may be one of the most important changes ahead.
For a long time, much of an AML analyst’s day has been defined by alerts: open an alert, collect information, review transactions, move between systems, document the findings and make a decision.
AI gives us an opportunity to rethink that model.
The goal should not be to turn analysts into faster alert reviewers.
It should be to help them become risk investigators.
That means using technology to bring together relevant context, prioritize cases, identify relationships and reduce the repetitive work surrounding an investigation, while keeping people responsible for the decisions that require judgment and accountability.
This is not only a technology transformation. It requires training, new workflows and, ultimately, a cultural shift inside compliance organizations.
It also raises one of the biggest questions institutions have about AI: How do we govern it?
Banks need to understand why a model generated an alert or contributed to a decision. Internal governance teams, model validation functions and regulators need visibility into the variables, features and scenarios influencing those outcomes.
If an AI system improves detection but its reasoning cannot be understood, challenged or audited, it creates a new risk while trying to solve another one.
Explainability therefore cannot be something added after deployment.
It has to be part of the architecture from the beginning.
4. Global Scale Still Has to Work Locally
This conversation is particularly relevant in markets like Latin America, where large financial institutions often operate across multiple jurisdictions while facing distinct local regulatory expectations.
Banks naturally want common platforms, methodologies and governance structures. Fragmenting financial crime operations country by country makes technology harder to manage and transformation harder to scale.
But global standardization cannot mean ignoring local risk.
The challenge is to build a common financial crime architecture with enough flexibility to adapt to jurisdiction-specific requirements, typologies and regulatory expectations.
That balance between global scale and local control will become even more important as institutions introduce AI across multiple markets.
A model may be technically scalable. Governance must be scalable too.
And this need to combine regulatory requirements, operational effectiveness and the ability to scale is already shaping technology decisions inside financial institutions.
As Ricardo from Banco BV shared during our conversations at FEBRABAN TECH:
“ThetaRay delivered a very robust sanctions solution that met our requirements efficiently, while also addressing regulatory requirements. Today, we have a high level of confidence that the solution meets our needs and will allow us to evolve and scale.”
— Ricardo, Banco BV
The Bigger Transformation
We left FEBRABAN TECH thinking about one point in particular.
The next stage of AML transformation will not be defined by which bank adopts the most AI.
It will be defined by how effectively institutions connect technology, architecture, governance, people and culture.
AI is an important enabler of that transformation, but it is not the transformation itself.
The institutions that move ahead will be those that can bring together customer risk across the financial crime lifecycle, continuously prove that their controls remain effective, give investigators better tools and context, and introduce AI in a way that remains explainable and governable at scale.
For us, that was the most important takeaway from São Paulo.
The conversation has moved beyond “Should we use AI in financial crime compliance?”
The more interesting question now is:
How do we redesign financial crime compliance around what AI finally makes possible?
And after the conversations we had at FEBRABAN TECH, it is clear that many of the region’s largest institutions are already beginning to answer it.