Go Back
On-demand

Beyond Words: AI, Local Languages and the Next Frontier of Communications Surveillance

Financial institutions across APAC are under increasing pressure to effectively monitor communications for misconduct, with regulators like MAS, HKMA, and ASIC placing greater emphasis on culture and conduct risk.

This is compounded by significant operational challenges: the explosion of communication channels (voice, chat, mobile), the complexity of multilingual content, and the nuances of slang, emojis, and coded language. Traditional, keyword-based surveillance systems, often generating high volumes of false positives, are struggling to keep pace, making it difficult to pinpoint genuine risks.

This session examines these core challenges, exploring practical strategies and modern technologies, including AI, that can help firms enhance their surveillance frameworks. The panelists discuss how to move beyond simple keyword matching to better understand context and intent, reduce operational noise, and build a more effective and efficient surveillance function that satisfies regulatory expectations.

Watch this on-demand webinar, hosted by Regulation Asia, to learn tactics on how to:

  • Meet evolving regulatory expectations around conduct risk, culture, and effective supervision
  • Tackle operational challenges by reducing surveillance noise and false positives across voice, chat, and mobile communications
  • Enhance risk detection by better interpreting multilingual conversations, regional slang, non-textual cues like emojis, and coded behaviours to uncover true intent
  • Build a robust governance and operational framework to support the adoption of new technologies including AI with clear human-in-the-loop oversight.

 

Speakers

Chris Lee, APAC Head of Communication Surveillance, BNP Paribas

Chris Lee

APAC Head of Communication Surveillance, BNP Paribas

Deepanvita Upadhyay, Executive Director, Head of Control Office, International Wealth Management, Nomura

Deepanvita Upadhyay

Executive Director, Head of Control Office, International Wealth Management, Nomura

Lawrence Choo Head, Global Banking and Corporate Functions Compliance, Maybank

Lawrence Choo

Head, Global Banking and Corporate Functions Compliance, Maybank

Alex de Lucena

Alex de Lucena

Director of Product and Governance Strategy, Shield

Manesh Samtani Editor, Regulation Asia, Moderator

Manesh Samtani

Editor, Regulation Asia, Moderator

  • Transcript

    Beyond Words: AI, Local Languages and the Next Frontier of Communications Surveillance

    A Regulation Asia webinar, supported by Shield
    Speakers

    • Manesh Samtani, Editor, Regulation Asia (Moderator)
    • Chris Lee, APAC Head of Communication Surveillance, BNP Paribas
    • Deepanvita Upadhyay, Executive Director, Head of Control Office, International Wealth Management, Nomura
    • Lawrence Choo, Head, Global Banking and Corporate Functions Compliance, Maybank
    • Alex de Lucena, Director of Product and Governance Strategy, Shield

     

    Introduction

    Manesh:Good morning, everyone. A warm welcome to our Regulation Asia webinar, Beyond Words: AI, Local Languages, and the Next Frontier of Communications Surveillance in 2026, supported by our friends at Shield. My name is Manesh Samtani, editor for Regulation Asia, based in Hong Kong. We’re here today to talk about communication surveillance — regulatory expectations, industry challenges, and how technology is being used to address these issues.
    Let me introduce our panellists. First, Deepanvita Upadhyay, Executive Director and Head of the Control Office for International Wealth Management at Nomura. She brings a first-line perspective, focusing on how surveillance and monitoring connect to broader objectives like culture, conduct, and risk management in wealth management. Then Lawrence Choo, Head of Global Banking and Corporate Functions Compliance at Maybank. Lawrence started his career as a commercial crime investigator in the Singapore Police Force, then moved into enforcement roles at the Competition Commission and SGX, and has since built global surveillance functions at major banks. We have Alex de Lucena, Director of Surveillance and Governance Strategy at Shield, coming from a background that includes criminal defense investigations and leading comm surveillance at a major bank, with a deep technology focus at the forefront of AI-driven solutions. And Chris Lee, APAC Head of Communications Surveillance at BNP Paribas, who has over two decades of experience in investigations and surveillance, including twelve years in comm surveillance at major global banks like JP Morgan and DBS. A reminder to send questions through the chat box. Without further ado, let’s go ahead.

    Regulatory Expectations: Wealth Management Risks

    Manesh:I want to start with the regulatory expectations driving the need for more robust monitoring. Deep, can you talk about the primary risks you’re trying to manage in the wealth management space?
    Deepanvita:Thanks, Manesh. In wealth management, surveillance and monitoring are very key in the eyes of regulators — seen as a means to embed a culture of compliance, which is important in the wealth sector. From a risk perspective, the top three most private banks are grappling with are money laundering and tax evasion; mis-selling, which is very much at the heart of it; and investment suitability — treating customers fairly. These are the areas where we’re exploring AI-based solutions to strengthen our monitoring. From a first-line perspective, our approach in private banking has traditionally been more manual, sample-based monitoring. With the advent of AI, the opportunity to make that monitoring far more robust is the big draw. Added to the complexity is how we communicate with clients today — most prefer to be engaged on chat channels, so how do we expand monitoring into WhatsApp and WeChat, and make sure they’re properly auditable with proper record keeping?

    Twenty Years of Surveillance: How the Goalposts Moved

    Manesh:Speaking of WhatsApp and WeChat — Lawrence, you’ve been in this space for a twenty-year journey. Can you talk about how the regulatory goalposts have moved, and how you see APAC comparing to the EU, UK, and US?
    Lawrence:Let me give a bit of the historical journey. When I first started, market surveillance always originated from trade surveillance — I started in exchange enforcement, analyzing transaction patterns to form an opinion on whether traders were doing something against market conduct. You hardly talked about getting evidence from the communication side. When I moved to a global bank, they were hiring for trade surveillance analysts, looking at transaction patterns. At that point there was hardly any surveillance software for e-communications — on emails, Yahoo Chats, Bloomberg Chats, people used the vault or keyword search. To extract evidence, you’d download based on time, date stamp, and person involved, put in a few simple boolean keywords on a sample basis, and it would throw out a lot of alerts you had no choice but to sample.
    Around 2013 or 2014, there was more demand to use keywords for e-comms monitoring. Voice still had to be done on a sample basis, because transcribers or translators were rare. So we did e-comms with a lexicon — a bit more complicated than a single keyword search, stringing thousands of keywords or key phrases, but you couldn’t use anything more complex, and you couldn’t use AI; it just didn’t exist. Then, maybe six or seven years ago, communication vendors started putting in more AI functions and risk-scoring logic — de-duplicating, adding structure to how they read and decrypt messages so they didn’t throw out so much duplicated information. That’s where we really saw communication surveillance develop, and with transcription engines using AI for context, we saw the requirement come for voice monitoring to be included in e-comms.
    On the EU comparison: anyone involved in European regulation remembers the Market Abuse Regulation put in by the European Union — it went live, if my memory serves, in 2016, with the technical specifications drawn up around 2014. To understand a trading pattern, you need the communication evidence to look at things holistically. Then around 2019 we started to see MAS, Bank Negara, and other Asian regulators asking firms to put trade surveillance in place, and it slowly evolved to the understanding that without comms surveillance, the trade alone doesn’t give you a good picture — it’s very difficult to get a full smoking gun in the FICC, OTC world. So communication surveillance evolved alongside, with transcription and translation, and they’re expecting more of it even for voice. A lot of it originated from the 2016 EU Market Abuse Regulation.

    Lessons from the Off-Channel Fines

    Manesh:Alex, the last few years we’ve all been covering the penalties in the US — about $3.5 billion in fines for unapproved channel usage. What do you see as the key lessons from those penalty actions for firms, particularly in APAC? (And thanks for dialing in from New York, twelve hours behind.)
    Alex:Stepping back and listening to Lawrence, the story is one of the increasing complexity of channels and regulators’ efforts to put frameworks and controls around them. The SEC and CFTC fines around off-channel comms were — putting aside the merits or the pushback we see now in the US — really an effort to force financial institutions to come up with governance frameworks for how they manage channels. Channels today are so much more complex: even within this Zoom, we have Q&A, chat, the fact that we’re talking, how we map that to each of us and verify who’s talking, and when we take it into Teams we have reactions and likes — there’s a new feature every day.
    One of the better outcomes of the fines is that the fined firms brought in independent compliance consultancies, and out of it they all came up with frameworks for data governance — being able to measure all the channels people use to conduct business, and validate that all of them make it into the platform, both for record keeping and surveillance. Now some wonder, with the administration changed and less emphasis on those fines, whether this goes away. My view is these controls are here to stay — you don’t undo them once they’re here, and the statute of limitations for record keeping is longer than a presidential term. And the last, important thing: this is the bridge to AI. The first step for anyone wanting to use AI is being able to validate all the communications are there, because from a model-risk-management perspective, you can point to those controls and say my model is working or not working — and if there are dips, it’s not because channels are missing. So firms looking to start their AI journey typically develop strong data-governance capabilities first, or look to vendors to help build them.

    Data Completeness and Regulatory Inspections

    Manesh:Chris, thanks for joining us. A lot of what Alex and Lawrence said speaks to your experience with regulatory inquiries. How does this focus on data integrity and governance play out when regulators come into a firm?
    Chris:Thanks, Manesh. I was involved in regulatory inspections in the region, mainly with MAS in Singapore, SFC and HKMA in Hong Kong, and a couple based out of the US. To simplify, there are two components. One is data completeness — ensuring all the channels authorized for users are properly captured, not just the content but all the metadata, because metadata is really important in the surveillance tool to identify the identity of individuals, who said what and when. The other component is the surveillance tool itself — whatever alert-flagging mechanism you have, whether AI or lexicon-based, working according to what you expect. It may be an industry-wide issue that the current technology generates really high numbers of false alerts. There are alert-minimization or optimization mechanisms you can deploy in a risk-acceptable way, but they’re still a bit primitive, so there’s still a lot of human intervention.
    From the inspections I was involved in, there’s increasing expectation that proper documentation is maintained end to end, from a litigation-hold position through to case management. In one set of inspections, there were talks that the inspectors wanted to reach out to the analysts themselves to understand how they closed an alert — bypassing senior managers and team leads — because that demonstrates how strong your framework is. In a couple of exercises, we even had to submit our analysts’ CVs to the regulators before the inspection, so they could understand the type of people doing the job. This ties back to your end-to-end surveillance framework: how do you document every alert closure? For trade it’s maybe easier, but for comms, because communication is so contextual and high-volume, ensuring proper documentation for the huge amount of volume is a challenge.

    Hard vs. Soft Surveillance Requirements: Buy Side vs. Sell Side

    Manesh:A listener asks: what is the panel seeing from regulators in terms of hard surveillance requirements for buy side versus sell side?
    Lawrence:I can speak to sell side, since I work for a bank. In terms of hard requirements, they’ve started — on a principles basis from MAS, and in written regulation from Bank Negara Malaysia, specifying communication and trade surveillance for wholesale financial markets monitoring. So it’s getting a bit more prescriptive. But they always say you don’t want a one-size-fits-all where you take a template other banks use. They want you to do a market risk assessment — what’s the risk in the instruments, the communication channels, how you could potentially be mis-selling to clients — to understand your risk profile, and from there put in the relevant surveillance tools and keywords. Don’t think that what works in Singapore will work perfectly if you just copy and paste it in Malaysia. When they inspect, they’ll challenge you: “You’ve set similar thresholds and keywords — why? Did you consider the context, the culture, the language spoken here?” So it must be very jurisdictional- and business-focused.
    Alex:For anyone with a global program, when it comes to e-comms, any culturally or regionally specific coverage should be in addition to a program that’s global. Typically, if you have something for EMEA using AI or lots of lexicon, you don’t want to be in a place where you say, “We use that for these people, but we don’t look for risk to the same degree for those.” What you’re more likely to see is a program that cuts across everyone, and then if there’s a Vietnamese, Cambodian, or Thai presence, language coverage layered on — but applied globally, because even if the Vietnamese speakers are only in one region, most of your hits happen there, and if someone happens to speak it elsewhere, you catch it. It’s always better to layer on than to pare back, because paring back is hard to justify without a real risk-based reason. Buy side is squishier — you see more variability, sometimes completely siloed regional surveillance on different platforms. There’s more focus there now, especially as private markets have gotten attention, but it’s comparatively a little behind.

    The Three Pillars: Technology, People, Governance

    Manesh:Chris, you’ve described this in terms of a three-pillar framework. What do you see as the essential components for an effective and defensible surveillance framework?
    Chris:The three components are: technology — a huge, ever-evolving word as we branch into a new era of surveillance technology; the people using the technology — do they know how to use it, do they know the objective, do they have the knowledge and capabilities to perform the task; and governance, which is the glue that ties everything together. Governance concerns not only the technology and people within the surveillance framework, but as a control function branching outside surveillance too. For example, the use of unauthorized communication channels isn’t new — it was already there when I entered this field more than ten years ago; it just didn’t get the attention it did a few years ago. That slew of regulatory fines sent a message to all the banks, especially in APAC. I’m part of the ASIFMA organization, and it resulted in a number of meetings and even a survey among members about the use of unauthorized communication channels. Governance needs to capture those types of events after detection.

    Day-to-Day Challenges: Talent, Language, and False Positives

    Manesh:I want to hear about the day-to-day difficulties. Lawrence, then Deep from the wealth space, then Chris.
    Lawrence:Currently, surveillance is a bit easier because technology has made false positives less prevalent — the number of alerts is greatly reduced, from hundreds of thousands to a manageable few thousand. But one permanent challenge is the lack of talent. Using Chris’s three pillars — people — finding the right people to do surveillance is very difficult, because traders speak in their own lingo. When I first came in and heard them shouting “fifty, sixty,” I wondered what the hell “fifty, sixty” was and what instrument that referred to. Compliance officers can interpret rules and regulations, but they’re not from the trading floor, so they can’t always decipher how a trick is done. And if you keep asking them to clear false positives day to day, fatigue sets in, and people leave — they get experience, then take twenty or thirty percent more pay and off they go. So it’s permanently difficult to find people who understand the context of what traders say.
    On APAC specifically, technology is still developing in one area: when I speak with my friends, I can string three or four dialects into one sentence, and I have not yet come across a comprehensive transcription product that can switch language that quickly and accurately reflect what I’m saying. So voice surveillance remains challenging.
    Chris:I echo a lot of what Lawrence said. I don’t see surveillance as a stand-alone function — we partner with other control functions like advisory, product compliance, and control room. The mission of surveillance is to pick up potential issues, but to know what the issues are, you need to know the policies — what I call “know your policies,” KYP, part of our training. In many firms there are hundreds of policies. We partner a lot with advisory, who are close to the business, to fill the knowledge gap Lawrence mentioned. It’s a symbiotic relationship: surveillance has all the data but might not have all the business knowledge; advisory has the business knowledge but not the data.
    Deepanvita:It resonates quite a bit. More broadly in wealth, the key challenges are, first, the complexity of the landscape — policies are built on regulations, which are getting more complex, especially on topics like mis-selling. For teams like mine monitoring thousands of trades, how do you pick the right hundred samples? So risk-based application is crucial: if you’re tackling mis-selling risk, you want to look at trades carrying higher risk — some degree of solicitation, or solicitation of a product beyond the client’s noted risk profile. It’ll never be a hundred percent foolproof, but you get higher assurance when you’re more risk-based. The second point is cost efficiency — the wealth sector has traditionally been very manually intensive, with large teams monitoring trades and conversations. As we embrace technology, the language complexity Lawrence mentioned, particularly non-English, and getting that accuracy, continues to be a challenge — slang, different tonalities, Chinese with multiple speakers, and identifying who said what. So it’s important to focus on the longer-term, sustainable benefit as we move away from manually intensive monitoring.
    Chris:To echo Deep and Lawrence on languages: we cover Asian languages like Thai, Vietnamese, Bahasa Indonesia, and Bahasa Malaysia, but there are very few native speakers in the surveillance team. Until the end of last year, we relied heavily on human assistance, reaching out to appropriate native speakers — not business native speakers, because we need to understand the alert — which depended on their capacity and availability. With the use of AI, in particular LLM models, we’ve been able to minimize the human intervention in foreign-language translation. We have AI as a 24/7 partner, and surprisingly, the translation is pretty accurate — we did some comparison, not on a huge dataset, but it’s more than ninety percent accurate, even with some of the trader lingo. So that’s probably the direction of travel, and it’s taking a lot of liking at BNP at the moment.

    AI, NLP, and Local Languages

    Manesh:Alex, how are new technology approaches — AI, NLP — being used to tackle these issues?
    Alex:Chris gave a great segue. The use cases speak to both existing and emerging capabilities. Transcription is an easy one: not long ago you’d typically only have English-language transcription, and if you wanted a second language — usually Chinese or Spanish — a firm would have to replay those communications or target specific speakers. Now the LLMs are multilingual out of the box; that’s how they were built. We’re still learning to what degree — they’re mostly trained on English, but on massive corpuses. Whisper, OpenAI’s transcription tool, was trained on roughly six hundred thousand hours of communication, through which it can understand upwards of ninety-nine languages. Is every transcript good? No. But is there now a transcript where before you couldn’t have imagined one — for some tangential but business-important language? Yes.
    Taking it a step further is a question of design and use cases. To Lawrence’s point about switching between four languages in a sentence, there are tools that first identify those languages before transcribing, so the LLM doesn’t get tripped up — it can say “this is Singlish, this is English, this is pure Chinese” and switch between them, at the sentence or word level. For any bank interested, you start with the use cases and measure them.
    The real emerging one is workflow automation, or automated review. This comes up a lot as people get exhausted by false positives. What about the things auditors and regulators focus on — consistency of comments, how do you know this person escalated this but not that? Having an LLM do some of the triage can bring consistency, auditability, and logic to the process, incorporating policies and regulations. We’re in early days, but I’m seeing a lot of velocity among curious banks, and it’s global — we’re all using these tools as consumers already, so people are almost more fatigued by false positives, because they go home and have ChatGPT help with an email, then go into their surveillance platform and feel like they’re living in the past.

    Governance of People and Technology

    Manesh:I want to talk about governance. Chris and Deep on the people side, then Alex on the technology side.
    Chris:On finding the right people — keeping them interested is something I can do; keeping them satisfied on pay is something I cannot always do; empowering them and allowing opportunities for growth is something I can do.
    Deepanvita:I’ll pick on resourcing. I’ve worked at banks with hundred-member monitoring teams; we’re evolving from that. We don’t need huge manpower now, but a combination of skills. If I have two roles, I’d pick one with more traditional monitoring experience and a second who brings a technology edge — we’re open to backgrounds like data science. That does two things: the nature of the work becomes more interesting, creating opportunities for people who want to straddle traditional and new ways of doing things; and teams become more lean, but more skills-based and multidimensional. That’s the trend I’m seeing across private banks.
    Chris:To supplement Deep — every time I have an opportunity to work on a case, I try to help connect the whole surveillance chain, from alert identification through case escalation to case conclusion. More often than not, once an alert is escalated, the analyst who detected it isn’t involved in what happens after. I try to make the conclusion available to the person who detected it, because it demonstrates their value-add — it’s not just the finishing line, it’s where they started from. That helps address analyst fatigue and, from a people perspective, binds and strengthens the overall governance.
    Manesh:Alex, talk about the governance element, bringing in AI and how technology should be managed.
    Alex:Some general principles. Anything you bring in has to be measurable and auditable, and the use case has to be understood. It starts at the beginning: what use cases, what software best practices, what data did a vendor or your own data-science team use to build a solution. It goes to deployment or POCs, where you see it in live data — what controls and reports do you have, how do you measure it’s working? Then into production, where you measure it on an ongoing basis, tweak it, and keep iterating.
    To Chris’s fatigued reviewer: what can AI do for them? Maybe add summarization or something that explains the risk and points them to the policy. Sounds like a good idea — but put it in and see if it actually helps the review or adds to it. Is it well designed? If it’s going to close out messages, is it closing the right ones, acknowledging ambiguous ones and giving those to a human, and doing a better job on noise than the day-to-day reviewer? The biggest mindset shift is going from a world where people understood inputs and logic to get their outputs, to LLMs, where we measure them based on their outputs — the input is the use case you’re solving for, the output is what it does, and the logic sits in between. Those three pieces need to tie together to make a convincing case that AI is worth the return on investment, worth replacing people, worth bringing a new vendor in. It’s not just plugging it in or asking it to plan your Italian vacation and being okay with the answers — for a regulator or auditor, you need a data-driven use case that holds water over time.

    Cost and ROI in AI Adoption

    Manesh:Lawrence, any comments on the decision-making when moving to a more AI-driven approach?
    Lawrence:To be blunt, it all boils down to cost. Management will look at whether implementing new technology saves x cost or costs more. Someone once told me, “If I can put five percent of people to do the same thing cheaper than buying the system, why should I buy the system?” That’s the brutal fact. AI is the “in thing” now, and it’s been demonstrated to bring better efficiency, so we should explore it and do POCs — and once you can demonstrate the cost savings, the change will be supported by whoever provides the budget. On governance and people: with all these AIs, the analyst’s role should transition — from a reviewer of communications to validating that the AI is doing it correctly, training the AI, ensuring it analyzed correctly. They become the expert who can feed back and validate — effectively moving from a level-one to a level-three type of role.
    Alex:Cost is a really important factor in the design of AI solutions — it’s quite costly to run these in production across all accounts or the whole bank. So when looking at solutions, it’s important to understand how people are actually using GenAI, or classifiers they’ve built, or NLP techniques, and to partner with data scientists and tech teams to make sure — whether you’re building internally or getting it from a vendor — that it’s done in the right way, satisfying the use cases and controlling for cost.

    Vendor vs. Client: Language Training and Coverage

    Manesh:A listener asks: how much do banks rely on vendors to provide the language skill set in the product, and how much do vendors rely on clients to provide real data to train the product, particularly for Asian languages?
    Lawrence:When building a new system, we hope the vendor provides as comprehensive a suite as possible, because it saves us development time. But the reality is it differs bank to bank and country to country, so it’s always good to invest some time yourself, as a bank, to make sure they can train their models to what’s specific to you — sometimes even the quality of the voice provided impacts the transcription outcome. So it’s worth telling the vendor, “I want an opportunity to provide my data to help train your model,” and that model has to be ring-fenced to you — which comes down to negotiation in the contract.
    Alex:One thing I’ve seen is a global regulator issuing findings I’d call “the new off-channel comms,” but for language: you cover these languages, but how do you know what else people are speaking, and what coverage do you have? Firms were expected to remediate that, similar to off-channel comms — looking for the languages they don’t have coverage for being spoken. Suddenly there’s a lot of pressure on vendors to provide identification, the ability to random-sample outside what they already monitor, extra tools. Many institutions say, “The finding is on me — if you can’t do it, I will, because these tools exist.” Ultimately, the firms own the risk coverage; vendors provide the tools but have to validate and prove they work, and if they don’t, the onus is on them to step it up.

    Emojis in Surveillance

    Manesh:An email question about regulatory expectations and internal processes for handling emojis in comm surveillance. Chris?
    Chris:I can share personal experience. As we onboarded new channels, one feature — not just one channel, Bloomberg channels have it too — allowed people to use different forms of emojis. In our testing, we noticed an emoji is like a symbol, not really a word; it doesn’t mean one thing or another, it just infers something. So at the time the team decided that, from a professional conduct standpoint, maybe we should not ask people to use it — and I faced a lot of headwind from the business, because the importance wasn’t recognized at the time. Then there was a court case in Canada involving a seller and a buyer where a thumbs-up emoji was ruled to be a legally binding communication. I think the SEC in the US has also mentioned something about this.
    Alex:Absolutely, we’ve seen it in social media compliance — people making guarantees on social media, and someone gives it a thumbs-up. This speaks to Deep’s wealth-side world: someone pushing a product, maybe using language they shouldn’t, and someone endorses it with a thumbs-up — I use “endorse” because that’s how it’s viewed legally. Emojis can be alerted on; most, in Teams and similar, are brought in as Unicode, so they appear as text — something like a “zipper-face,” which someone might use to indicate secrecy, can be a valuable signal you alert on. The question is how much you open this up. Is every thumbs-up problematic? My view is that a thumbs-up needs to be analyzed within further context — someone promising something they shouldn’t, and the thumbs-up supporting it — as opposed to alerting on it in and of itself. It’s also true for GIFs and reactions. It’s one more element reviewers need to be conscious of, and where technology offers some stopgap.

    Targeted Review as a Supplement

    Chris:One more thing from the surveillance standpoint. We talked about lexicons and alert-flagging logic — those are a risk-based approach, where the system is asked to identify a certain portion of messages for a second view. What I’ve found useful is, depending on the situation, implementing a targeted review program — not as a stand-alone solution, but to supplement the lexicon program. The targeted review looks at all the non-alert messages with a specific theme — a generic theme or a targeted theme. In some regulatory inspections, the regulators didn’t expect it, but they were happy to see that you have a risk-based approach and, in case certain things fall through the net, you have something to catch them.

    Closing

    Manesh:We’re over time, and we still have questions from listeners and loads more I’d like to ask — we’ll have to continue another time. Thank you for joining me on this session, a special thanks to Alex and our partners at Shield for making this discussion possible, and thank you, Deep, Lawrence, and Chris. A final thank you to our listeners for joining and for the engaging questions. The recording will be available afterwards. From all of us at Regulation Asia, thanks for your time — have a great rest of your day.
    Deepanvita:Thank you. Take care, everybody.
    Lawrence:Thanks. Bye.
    Chris:Thanks, everyone. Bye.

Q&A

What risks matter most for surveillance in wealth management?

The three risks that private banks grapple with most: money laundering and tax evasion, mis-selling, and investment suitability — essentially treating customers fairly. Historically, first-line monitoring in private banking has been manual and sample-based, so the big draw of AI is making that monitoring far more robust and risk-based, letting teams focus their samples on the higher-risk trades, such as solicited products beyond a client’s recorded risk profile.

How is surveillance in APAC different from the US and EU?

It arrived later and evolved from trade surveillance first, with e-comms monitoring maturing only as lexicons, then AI scoring, came in. The EU’s Market Abuse Regulation went live around 2016, while APAC regulators like MAS and Bank Negara began requiring trade and comms surveillance around 2019. Crucially, APAC regulators expect a jurisdiction- and culture-specific risk assessment — they’ll challenge you if you copy-paste thresholds and keywords from another market.

Do the US off-channel fines matter for firms in APAC?

Yes. The roughly $3.5 billion in US fines for unapproved channel usage pushed fined firms to build data-governance frameworks — mapping every channel used for business and validating it reaches the platform. Those controls are here to stay (record-keeping statutes of limitations outlast any administration), and they matter globally because they’re the bridge to AI: you can’t trust a model until you can prove your communications are complete.

What do regulators actually check in a surveillance inspection?

Two things, per panelists who’ve been through APAC inspections: data completeness — that authorized channels are captured, including the metadata needed to identify who said what and when — and that the surveillance tool works as expected. Increasingly they want end-to-end documentation of every alert closure, and inspectors have asked to interview analysts directly, even requesting analysts’ CVs before an inspection begins.

Should we build region-specific surveillance or one global program?

For e-comms, layer local language and cultural coverage on top of a global program rather than running siloed regional ones. If you have AI or lexicon coverage for EMEA, you don’t want to argue you look for less risk elsewhere — it’s easier to manage and defend a program that cuts across everyone, with Vietnamese, Thai, or other coverage added on. The buy side tends to be more siloed and a little behind the sell side here.

Can AI handle local Asian languages and dialect-switching?

It’s improving fast. Traders may string several dialects into one sentence, which older tools couldn’t follow — but LLM-based transcription is multilingual by design (OpenAI’s Whisper was trained on roughly 600,000 hours and understands upwards of 99 languages). One panelist reported over 90% translation accuracy at their bank, even with trader lingo. A key technique is identifying the language first, so the model doesn’t get tripped up switching mid-conversation.

How do we get AI surveillance past governance and prove ROI?

Make it measurable, auditable, and tied to a specific use case. The mindset shift with LLMs is that you validate them by their outputs, not just their inputs and logic — those three pieces have to connect. And be honest that cost is decisive: run POCs to demonstrate savings, and remember these models are expensive to run at scale, so design and partnering with your data-science and tech teams matter as much as accuracy.

Are emojis a compliance risk we need to monitor?

Increasingly, yes. A Canadian court ruled a thumbs-up emoji was legally binding as part of a contract, and US regulators have flagged the issue, especially around social-media endorsements. Most emojis arrive as Unicode, so they appear as text and can be alerted on — a “zipper-face” signalling secrecy, for example. But the panel’s view is to analyze most of them in context rather than alerting on every thumbs-up.