Skip to main content Skip to navigation

The case for defensible AI in APAC compliance

Regulators and boards across the Asia-Pacific have stopped asking whether firms use artificial intelligence (AI). Instead, they started asking about the reasoning behind the AI-made decisions. In November 2025, the Monetary Authority of Singapore (MAS) issued its consultation on Guidelines on AI Risk Management for financial institutions, setting expectations on transparency and explainability. 

Yet the gap between adoption and assurance is wide: our State of Financial Crime 2026 survey found that 59% of firms globally have a fully established AI assurance program in place, with only half of the firms (54%) in the Asia-Pacific region.

Appetite is running ahead of production, too – in Asia-Pacific, 73% of firms are using, piloting, or evaluating agentic AI for customer screening, while 31% have it in production.

For years, regulators asked whether controls were in place. Nowadays, a reasonable question to ask is whether a firm can reconstruct and defend a decision a model made months ago – the version, the data, the human who signed off – long after both the analysts and the model have moved on.

That theme set the agenda for the third and final session of our Future of Compliance Asia-Pacific summit in Singapore, hosted by Heather Tan, Managing Director and Head of APAC at ComplyAdvantage. She was joined by:

  • Kok Chun Hou, Managing Director and Group General Counsel at DCS.
  • Kush Mukherjee, Managing Director, Responsible AI at Accenture.
  • Christopher Liu, Chief Compliance Officer and Head of Regulatory at BIT.
  • Thomas Chia, Chief Technology Officer at Chocolate Finance.

From assurance to proof

Two years ago, the conversation with regulators was exploratory. That test is now in full swing: whether a model is deployed responsibly and can be justified, and whether a policy has been operationalized rather than filed away.

“If we deploy this model, how can we ensure that it’s deployed in a sensible, justifiable, and defensible manner?”

– Kok Chun Hou, Managing Director and Group General Counsel, DCS

Across the region, MAS has doubled down on transparency, the Australian Transaction Reports and Analysis Centre (AUSTRAC) is focused on defensible reasoning and senior-management ownership midway through major AML reforms, and Bank Negara Malaysia (BNM) has embedded explainability in its responsible-AI principles. The requirement to explain why a name-screening match scored 80% rather than 100% predates the current wave of AI by a decade. What has changed is the pressure to prove it.

“Once you’ve put the AI to work, what can we do to prove what it’s done?” 

– Heather Tan, Managing Director and Head of APAC, ComplyAdvantage

Where the “black box” hurts

Opacity costs a firm in three stages: 

  • At the point of decision: When a human who cannot see why a case was escalated either reconstructs it by hand or becomes a rubber stamp.
  • During maintenance: When a team that cannot tell model drift from a versioning change cannot manage the model over its lifecycle.
  • In front of the auditor: When a decision has to be defended.

“The last stage, and arguably the most impactful stage at which an institution can be impacted by opacity, is when your regulatory liability actually crystallizes.”

– Kok Chun Hou, Managing Director and Group General Counsel, DCS

When regulators audit a compliance decision made six months prior, a firm that cannot reconstruct the reasoning behind it is left defenseless. This highlights the critical difference between model opacity – where an AI or system’s complexity makes it difficult to dissect – and institutional opacity, where an organization simply cannot identify the model, version, or human analyst involved. As new regional regulatory guidelines take effect, there is increasingly less excuse for the latter. 

Accountability can’t be outsourced

Most firms rely on models from a vendor, a cloud provider, or an open-source base, which raises the question of what to demand of a partner. The premise itself needs to be reframed, as outsourcing the model does not outsource the responsibility.

“Accountability in general can’t be outsourced – that’s not a new problem, that’s not an AI problem.”

– Thomas Chia, Chief Technology Officer, Chocolate Finance

The practical test is whether a partner operates in accordance with the firm’s standards. The controls are split into two: 

  • Build-time controls: Such as choosing the right model and testing in a safe sandbox before deployment.
  • Runtime controls: What a system does in production, because a team needs both the discipline to reduce hallucinations and the means to detect one when it happens.

Keep the human in the loop, and be realistic about risk

Firms are cutting headcount on the claim that AI agents have made teams more effective, often before sustainability has been assessed. 

A more durable answer is a phased approach: AI handles repetitive level-one work, a human reviews at level two, and the balance shifts only once level-one confidence is consistently high. Validation has its own limits – a bank model regulators expected to be validated in a 300-page report is a burden a lean engineering team may not be equipped to meet.

“All of us here are in the business of risk management. We are not in the business of eliminating risk.” 

– Christopher Liu, Chief Compliance Officer and Head of Regulatory, BIT

An auditor who treats a single error in a million transactions as failure is applying a standard no team of humans would meet, either. Removing the human raises a harder question, because accountability has always carried a punitive edge.

“If you think that the accountability sits with AI or an agent or a model, they can’t be punished. At least we have not figured out how.”

– Thomas Chia, Chief Technology Officer, Chocolate Finance

Your AI is only as good as your data

If explainability is the visible layer, data is the foundation beneath it. Assurance begins when the model is built and depends on where it sources its information and whether its thresholds align with the institution’s risk appetite. Availability, provenance, relevance, and the conflicting versions of a record scattered across an organization all determine whether a decision can be explained at all.

“Your AI is only as good as your data.”

– Kush Mukherjee, Managing Director, Responsible AI, Accenture

Unlike a human analyst who will flag a missing record and stop, an agentic workload tends to press on and produce a persuasive answer even when it lacks what it needs, so teams need controls that detect missing data, not only bad outputs. 

Garbage in, garbage out still holds. If a firm cannot say when a sanctions list was last updated for a name it cleared, that gap can discredit the rest of the work.

A framework to take home

  1. Start with governance and clear ownership, held across the organization rather than left with the data scientists.
  2. Build explainability in at the point of decision rather than bolting it on afterward as a reporting layer.
  3. Get the underlying data right from day one – metadata, entity resolution, customer risk profiles, and detection models – because no decision is defensible without sound inputs.

A fourth question is worth sitting with as firms decide what to build themselves.

“There becomes a point around materiality where you have to determine: is this core or a chore for my business?”

– Paul Kizakevich, President, GTM, ComplyAdvantage

Get the first three right, and control you can demonstrate becomes confidence – with the board, the auditor, and the regulator – which is what gives a business the room to keep growing.

Transform your AML compliance with AI-native solutions

A cloud-based compliance platform, ComplyAdvantage Mesh combines AML risk intelligence with actionable risk signals to screen customers and monitor their behavior in near real-time.

Get a demo

Originally published 24 July 2026, updated 24 July 2026

Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.

Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).