Speakers
Shlomit Labin
VP, Data Science, Shield
Oliver Bradford
Senior Director, Strategic Accounts, Shield
David Aaronson
Senior Product Marketing Manager, Shield
In this Insiders in-focus webinar we delve into the world of AI in financial compliance. Discover the latest trends, perspectives, and strategies shared by industry leaders Oliver Bradford and Shomit Labin. Explore how AI adoption is reshaping the compliance landscape, improving efficiency, and driving meaningful value at scale. Don’t miss this opportunity to gain expert insights and stay ahead in the evolving world of AI and compliance.
Shlomit Labin
VP, Data Science, Shield
Oliver Bradford
Senior Director, Strategic Accounts, Shield
David Aaronson
Senior Product Marketing Manager, Shield
Shield Insiders In-Focus
Speakers
David:Welcome to Insiders In-Focus, where the Shield insiders like to share a little bit of information with you that maybe you don’t know. Not so scary. But really, the purpose here is not to talk about things for about an hour and a half — because who has time for that — but to get really straight to the point in about fifteen, twenty minutes.
Today’s topic: well, no topic has made more noise in recent days and months than artificial intelligence. It’s been well adopted in many industries for years, but with the rise of ChatGPT and other products, we’re seeing massive adoption and integration of its use across every sector, and even by private individuals. It’s been a hot topic in compliance at financial institutions for some time, with strong opinions all around.
So for this conversation, I’m excited to have some of the brightest minds in the industry share their perspectives on the market, on ways to approach AI, and how to get meaningful value from AI at scale.
Let me welcome Oliver Bradford — we’re going to call him Olly, just because we like him that much — Senior Director, Strategic Accounts at Shield. I can tell you, few people know the market and the people in it like Olly. If you haven’t had a chat with him yet, I’d recommend you reach out to him on LinkedIn and just say hi.
Shlomit Labin, VP, Data Science at Shield, brings with her not one but two PhDs and a very shiny new Cloud Innovator of the Year award from the Cloud Awards — so congratulations on that. Shlomit is probably the smartest person I know, and the smartest person that anyone I know has known. So we’ll get a chance to hear some of her very smart things to say, and hopefully we’ll be smart enough to understand what she’s trying to teach us. So we’ll get to that. I’m very excited.
David:So, Olly, let’s kick it off with you. There are a lot of solutions out there marketed to the financial compliance sector as AI, machine learning, NLP. What are you hearing about the adoption of AI in the market?
Oliver:That’s a really good question, David. I’d say, first of all, that there’s a huge amount of interest — from the market, from banks, energy and commodity trading firms, asset managers — about AI and how it can be used and how it can benefit them. And there are a lot of vendors providing this in the marketplace at the moment.
Overall, I’d say we’re pretty early on the adoption curve. Institutions in the financial sector started rolling this out probably 2016, 2017, and really then it was strictly within the tier-one and tier-two global investment banks. They rolled out both vendor solutions and in-house solutions, and it’s been mixed results so far. There have been some very good results, but there have also been some very, very long deployments. We’re seeing quite a lot of skepticism from the people who initially rolled it out, coming around to maybe relooking at what they’re doing and improving things.
And things like ChatGPT — you mentioned it — I really feel like we’re at a tipping point in terms of AI at the moment. That’s what I hear from the market. It’s accelerated the interest even further, and people wanting those better results. The whole compliance function is ripe for automation and ripe for AI being used, because there are loads of manual processes. So that’s what I’m seeing and hearing at the moment.
David:Thank you, Olly. And you speak to a very important point about how every organization is coming to compliance from a different perspective, coming to AI from a different perspective, and vendors come in with their own “this is how to do it, that’s how to do it.” Obviously we’re sitting here talking from the Shield perspective, but taking a step back from the vendor side of things — it is a challenge of how do we, as a financial institution, get started with this? How do we adapt from where we’re starting? I think you really nailed it there.
Shlomit, what are some of the limitations with these AI products that people need to know about and look out for?
Shlomit:Okay, so maybe we’ll start from the evolution of AI in the financial industry. This is a relatively traditional industry. It started originally when the need came to process large amounts of data, and humans were not sufficient anymore. The initial solutions were what we call lexicon-based — a manual collection of phrases or rules — to try to detect them in conversations and highlight the risky conversations, or the ones that should be manually reviewed. These solutions obviously did not always produce the best results, and the ongoing manual collection of examples is very tedious.
For a few years there were attempts to use AI in this industry. The initial attempts of using classical machine learning, on one hand, promised to show good results and the ability to better generalize. On the other hand — and this refers to what Olly was mentioning about the long deployment processes — it required a vast amount of investment in data collection. Namely, machine learning starts from being able to learn from examples, and the problem was to collect those examples out of large amounts of data and corpora. Companies sat for months, and sometimes even years, trying to collect enough data to create their own models.
So this was a challenge, and it created some frustration in the industry, leading people to hold on to the more traditional list solutions. They’re easier to adopt, quicker to change and maintain. We know this industry is in a place of changing regulations and changing use cases, where the banks need to constantly adapt. Providing AI models that cannot be easily customized is a challenge for those institutions. So the first attempts of using AI in this industry were met with mixed emotions.
I think that was the case until about a year ago, or a few months ago. Again, the sentiment in the industry — the same as the sentiment in the entire modern world — is changing due to the visibility of ChatGPT, and we’re at a new place right now. The technology has been available to some extent in the past one, two years, but now it’s being exposed to the public, and now everybody knows what it can achieve and do. We’re facing a breakthrough in the capabilities that we can deliver.
David:Thank you, Shlomit. The fact is that with the vast amount of data constantly being generated, we’re seeing more and more adoption of AI. There just doesn’t seem to be a good way to monitor all this data and identify risks at scale without it. There just isn’t a way.
So, question back to you, Shlomit: are there better, more practical ways to leverage AI that really can make an impact on how firms identify risk? What are the ways to take advantage of AI?
Shlomit:Okay, so let’s go back again to the evolution of AI. As we said, the initial attempts were classical machine learning and a lot of work in creating models that then get frozen. The new generation of AI — the ones that also serve models like ChatGPT — are based on large language models. These models already learn a lot of human knowledge and a lot of human language from huge amounts of corpora, even prior to being adapted to specific tasks.
In the case of compliance teams, we need to solve the problem of identifying specific financial risks. We have a very specific target. It’s a within-domain expertise, and we need to address it. But when we’re able to use the more advanced language models, we can already start to train them from a much higher, more knowledgeable starting point, and quickly adapt them to our own specific solutions.
So this is a technology that is already available — also available in some of the more advanced compliance technologies — and it’s starting to create a real breakthrough in this industry. The next phase, of using actual generative models, is creating a lot of interest in this domain, especially in the ability to customize to specific questions or to the ongoing investigation of a specific use case. This, I think, is something we’re facing as a game-changer, a deal-changer in this industry. It will sweep us all toward the future.
David:Thank you so much, Shlomit. There have been tons of advances. Anybody who’s even maybe heard of ChatGPT knows the world is not the same, and what we can do is not the same.
So, Olly, let me ask you: when it comes to the actual impact these technologies have on a business, can you give us some details of what that impact is, and what kind of approach firms can take in order to take advantage of this?
Oliver:Sure, David. I’ll probably summarize three main points.
The first is a big time-to-value impact, which is really the overall deployment of these types of solutions. Using the techniques Shlomit mentioned, we can get live deployments in three or four months — even two months to get data into the system, and then four months for the alerting side. This is all through the pre-training of models, out-of-the-box behaviors, and the built-in AI that we use. So you can really get that alerting through to compliance quicker, and get value where otherwise it might take up to two years sometimes.
The second one is around actually finding more escalations. It’s one thing using AI to reduce the false positives — I’ll talk about that in a second — but what our clients want to be doing is actually finding instances which are interesting, worth escalating: what we call true positives. Using techniques like semantic detection and NLP, we can really accelerate and increase that.
And the last one is probably the biggest impact, and that’s all around the operational side and efficiency. If you’re moving from a non-AI-based solution — even ones with AI — we see a lot more efficiency. Often when we talk to a new client that isn’t using AI, they’re maybe having false-positive rates of 99% — that is, 99% of the alerts they see are just noise. It might be out-of-office replies, disclaimers, that sort of thing. It’s just a waste of everyone’s time and money. What value are people adding in a process if 99% of what they look at is noise? We see that rate coming down by 90, 95%, and what that allows these compliance teams to do is really focus on the things which are true positives. We can get alerting rates of less than 1% of total communications, and that’s all done through AI, NLP, and different sorts of AI techniques.
Also — not sure I’ve got time to cover this — but it’s very important: the EU is really hot on AI, how it’s used, and transparency, and we’ve seen this filter down to regulators as well. It’s knowing why something is alerted. It’s very important, when you see these alerts, for the person reviewing them and for internal audit teams to be able to know exactly what was alerted, to explain this internally and externally, and also to record it.
David:Thank you, Olly. Those are all really important. I think what it ultimately comes down to for an organization is: are you focusing on risk? A lot of the time there are just the activities you need to do to support a regime, but is the focus on what you need to do to support it, or actually what you get out of it — which is focusing on risk? And what does it mean for your review quality if the vast majority of what you’re looking at isn’t relevant anyway? What does that do for your… I don’t know what the word is — it’s like going by rote.
Oliver:Agreed. Yeah, it’s not a great way of managing this, is it? If you’re showing a regulator, “these are all processes,” but 99% of what we look at isn’t really any risk. So, yeah.
David:Thank you for sharing those. That is very important — for an organization to be able to make that shift from “how are we managing all this work” into actually getting proactive: seeing what you need to see, analyzing it, getting those insights. So thank you very much.
David:I want to move to the part of the conversation that we like to call “five and five.” We’re going to try to get some quick questions and quick answers out the door. So, guys, take a quick deep breath and run through as fast as you can.
So, Shlomit — we spoke about modern advancements and maturity in AI methodologies over the years. What are some of the historical innovations in AI that we saw before this new era?
Shlomit:Okay, so again, the first attempts at AI were to use classical machine learning — collect, again, a lot of examples in order to train your own models. This seemed to be very tedious work, and to some extent did not even converge. The challenge in financial risk is that we’re trying to detect a needle in a haystack. We’re not trying to differentiate between black and white, or two very clear classes of a domain — we’re trying to find the rare cases. In this case, the ability to collect large amounts of examples seemed really challenging.
Another challenge of this industry, in the early adoption of language models as well, is that financial talk is a very unique talk. It’s not straight English — a lot of internal terminology, a lot of shortcuts that to the layman are sometimes not understandable at all. So even the models that were trained on pure or classical English would not fully fit to perform these tasks, because the conversations are completely different. So it became a challenge to create advanced technology that already leverages vast amounts of what we call unsupervised data, but that also fits the financial domain. And this is where we are today.
David:Back to you, Shlomit. Where are we going to be in, let’s say, five years? It feels like an eternity in this field — but maybe the next couple of years. Where do you see the next advancements coming from?
Shlomit:Yes. I think we cannot avoid adopting newer technologies, as everybody is seeing in their day-to-day or reading about in the paper. The future is already here, and the ability to communicate with models is already accessible and feasible. So if in the past we needed to very carefully curate the questions we’re trying to collect answers on, in the future I think compliance teams will be able to do their work more in a conversational way with models. We are not there yet — it will take us a little bit of time — but definitely we’ll be there in a year or two, definitely less than five years.
David:Thank you, Shlomit. Olly, let’s do a mythbuster here. Can you reflect on the AI solutions out there in the market — are they worth the investment?
Oliver:It depends. I’d say normally, for sure. We’ve talked about some of the advantages — finding more true positives, reducing those false positives, and generally improving the efficiency and effectiveness of surveillance. You’ve got to think about how you’d manage it without AI, and really it isn’t as effective. I’ve talked to tons of people in the market who are not using it, and, to not create an operational issue, they scale back the lexicons to reduce the noise, use samples, do random sampling, manually listen to phone calls, and that sort of thing. That’s generally not a great approach to risk.
Generally, regtech firms offering AI are going to be more future-ready and definitely worth talking to. But I’d say do your due diligence. There are different scales of firms having experience in this, having implemented it. You need to see more than just a slideshow. And it’s not just AI that makes your surveillance effective — you need perhaps better search, better case management, better data management, and that sort of thing. So you need to look at the bigger picture, the holistic view, and not just focus on AI.
David:Yeah, thanks. That’s a good call-out, Olly. Following up on that: what advice do you have for people who are in talks with vendors, or thinking about reaching out to some of these vendors, looking for AI solutions? What questions should they be asking?
Oliver:So, Shlomit and I have gone through this many, many times with different financial institutions, different customers, and so on. I’d say the top ones are: what technology powers your AI, and what is the goal of using it — why do you want to use it? From there, AI is really an umbrella term — a catchall for “we’re a futuristic vendor because we have AI.” But do they use named entity recognition? Do they use large language models? Do they use NLP? And if so, how is the data trained and labeled? What datasets are they using? Do we need to label our own data, or do you label it?
A big one is around effectiveness. For us, we need to prove how we measure the performance of the models, how precise they are — quality, accuracy, that sort of thing. From the client side, you want to know these things too, to measure the effectiveness. And seeing some real results from the field as well — what results do you see from your clients, what improvements can we see?
And then, finally, what is the roadmap? It’s a fast-changing space. Are you incorporating ChatGPT? What other sorts of AI are you bringing into your solution in the future? That’s also really important. So, yeah, just a few things that we’ve picked up along the way.
David:Thank you, Olly. Shlomit, how can regulators leverage this newer approach so that they can better understand the risk models being adopted by banks?
Shlomit:I don’t think regulators limit the usage of AI at all. But the constraints they give financial institutions — in terms of model governance and the ability to explain how you cover the risks — to some extent deter some customers from shifting toward new AI technologies that really need different methodologies of governance and evaluation.
Again, the future is already here, and we will all be required to use the advanced technologies simply because they provide a much better solution. And it will become a regulatory requirement as well. I can give an example from voice surveillance regulations: only last year, the FCA gave a large fine to a big brokers’ company that did not use full evaluation of the voice recordings, simply because they said they didn’t have good enough transcription technology. This is no longer the case. AI-based solutions are already here, and the regulator will eventually force you to use them because they perform better.
However — and this comes back to the question you asked earlier — when you come to evaluate a vendor, you must make sure that this vendor has the ability, first, to cover the real issues being looked at by the regulator; that they have the experts in the industry that enable the model to answer the correct questions; and that they have the governance methodologies in place that will enable you to give the regulator the right reports and explanations on why your models are performing well — not only the most advanced technologies. So, in essence, you’ll need both.
David:Thank you, Shlomit. This sounds like the opposite of the advice I give my kids, which is: just because you can doesn’t mean you should. But when you get to this place of technology where you can, then, yeah, you’re going to have to — because otherwise you’re just not doing enough. What you’re able to do becomes what you need to do. That’s just the trajectory. Thank you, that’s very good insight.
Just to wrap up here: as data piles up faster and faster, I think it’s worth noting that some of the key benefits of AI we talked about today are actually dependent on embracing a wider view of what we can do with the data generated by our organizations. We see more and more firms understand the power of the data they’re sitting on — not just in terms of the potential risk sitting in there, which is important, but the opportunity available by unlocking the real meaning behind that data.
From the Shield perspective, we’re always talking about “reading between the lines” — how a data platform can capture that data, enrich that data, and make it available in more and more meaningful ways that can really unleash that value, so you can read between the lines in these unstructured conversations and better understand what the intent is. What are they trying to say? What’s the context here? I think that’s why it’s becoming more and more of a natural conversation to have about data: what can my data tell me? What analysis can you run on this data? What can this data reveal to me? We hear these questions all the time now, but a few years ago this was more aspirational, maybe.
So compliance has traditionally been more of an art than a science, I think. But with the right environment for our data, we can actually blur the lines a bit, and maybe bring more science into that art.
So thank you, Shlomit and Olly, for sharing your insights on AI and financial compliance. This was an awesome conversation. Let’s keep the conversation going — hit up our website, and let’s have a chat. This is Shield Insiders In-Focus. Thank you for watching.
Most are still early on the curve. Tier-one and tier-two investment banks began rolling out AI surveillance around 2016 and 2017, with mixed results and some deployments dragging on for up to two years. The arrival of large language models like ChatGPT has become a tipping point, sharply accelerating interest across banks, trading firms, and asset managers.
Because the first approaches were high-effort and low-flexibility. Lexicon-based rules gave way to classical machine learning that needed vast amounts of labeled examples, and collecting that data took months or years. Models couldn’t be easily customized as regulations shifted, so many firms gave up and held on to traditional list-based detection instead.
They remove the cold start. Large language models arrive already trained on huge volumes of text, so they begin from a far more knowledgeable baseline than models built from scratch. That lets compliance teams adapt them to specific financial risks in months rather than the year or two it used to take to collect and label training data.
Dramatically. Firms without AI often see false-positive rates near 99%, where almost every alert is noise like out-of-office replies or disclaimers. Using semantic detection and NLP, that noise can drop by roughly 90 to 95%, bringing alerting rates below 1% of total communications so teams can focus on true positives worth escalating.
With pre-trained, out-of-the-box models, live deployments can happen in three to four months — roughly two months to bring data into the system and about four for alerting. That compares with up to two years for approaches that require building and training models from scratch, so time-to-value is one of the biggest gains.
Generally, yes. The alternative is scaling back detection lexicons or relying on random sampling and manually listening to calls to keep noise manageable — a weak approach to risk. AI isn’t the whole story, though: effective surveillance also depends on strong search, case management, and data management, so evaluate the full platform, not just the model.
Start with what technology actually powers the AI and why. Ask whether they use named entity recognition, large language models, or NLP, how data is trained and labeled, and whether you must label your own. Then probe how they measure model precision and accuracy, what results clients see in the field, and what’s on the roadmap.
Regulators don’t restrict AI, but they expect model governance and explainability — you must be able to show why an alert was raised. Expectations are tightening: the FCA has fined firms for inadequate voice-recording evaluation, citing weak transcription. AI-based solutions are increasingly the standard regulators expect, so you need both advanced technology and defensible governance.
Gain access to exclusive insights, industry influencers, and thought leaders in
Digital Communications Governance and Archiving (DCGA).