CFOtech India - Technology news for CFOs & financial decision-makers
India
Why AI governance is the key to unlocking APAC's compliance backlog

Why AI governance is the key to unlocking APAC's compliance backlog

Thu, 13th Aug 2026 (Today)
Bryan Keasberry
BRYAN KEASBERRY APAC Head of Market Development Fenergo

If you were to take a figurative snapshot of the compliance landscape today, you will see a picture of backlogged compliance teams across Asia-Pacific. We ran a survey with 600 risk, fincrime and compliance specialists at banks and asset managers across the UK, US and Asia Pacific, and discovered that about two-thirds in APAC are being burdened by heavy manual workload. More than half are sitting on backlogs of periodic reviews and 45 percent flagged false-positive rates as a persistent drag on resources.

The false-positive problem tells us something specific about this region. In parts of Asia, common surnames and non-Roman scripts make accurate name matching difficult. Markets like Singapore and Malaysia generate enormous volumes of near-identical screening hits, every one of which must be reviewed. Right now, that review is being done manually by people who could be focusing on genuine risk instead.

The trouble is that the regulatory environment across APAC is also evolving while compliance teams try to clear their desks. Meanwhile, every compliance officer employed takes headcount away from teams generating revenue elsewhere in the business.

Enforcement is intensifying across the region

Our annual fines report released in January 2026 found that AML-related fines in Singapore rose 579 percent last year. In July 2025, the Monetary Authority of Singapore (MAS) imposed S$27.45 million in penalties on nine financial institutions for weaknesses in customer due diligence, screening and wire transfer controls. MAS has also explicitly stated that AML enforcement is a priority for 2026 with a review of penalty frameworks to ensure they remain dissuasive. Initiatives including proliferation financing as a mandatory component of risk assessments, source of wealth verification and the COSMIC suspicious transactions initiative are clear indicators that MAS is tightening its regulatory framework.

In Australia, the country's most substantial AML overhaul in over a decade takes effect from mid-2026, bringing potentially tens of thousands of new entities, including lawyers, accountants and real estate professionals, under AUSTRAC's regulation for the first time. Existing reporting entities, meanwhile, are still transitioning to updated requirements.

In short, regulations are changing, the workload is growing, the talent pool is tight, while regulators will not accept staffing shortages as an excuse for backlogs.

Switching from periodic compliance to an always-on model

Most compliance functions still operate periodically, responding to obligations as and when they arise. This disconnect creates risk and the downtime between a client's onboarding and when their file is next reviewed is exactly where threats could slip through.

Most institutions recognise they need technology to close that gap. The survey found that 54 percent in APAC are evaluating AI options and a third have begun implementing solutions, but 13 percent are not using AI at all, and two-thirds say they are only comfortable with partial automation.

However, companies are looking to leverage agentic AI's ability to continuously maintain client due diligence profiles, run real-time screening and flag anomalies without manual initiation of each step. Forty-four percent of respondents are considering agentic AI for end-to-end process execution in transaction monitoring, fraud detection and sanctions screening. Close to 50 percent also expect annual savings of between US$2-3 million (between SGD2.5 – 3.8 million).

However, over 80 percent describe themselves as only somewhat or not at all familiar with the technology. This is a readiness gap that needs to close.

Refining the role of human oversight

To capture the agentic AI advantage, compliance leaders must move focus from tasks and individuals, toward orchestrating agentic AI systems by managing intent, boundaries and outcomes.

Humans ultimately remain accountable, but their role evolves from executing tasks to providing oversight, judgement and decision-making. Compliance leaders define the objectives and guardrails within which AI agents operate and maintain clear lines of review and escalation. AI agents would then assume the burden of routine and repetitive tasks currently creating backlogs for compliance teams.

Essentially, the shift means refocusing compliance teams where they add the most value: their discernment on genuine risk, exceptions and decision-making that comes from experience and context. There is positive research that suggests this model will work: according to McKinsey, a single human can typically supervise 20 or more AI agents operating concurrently, which can lead to productivity gains of 200 to 2,000 percent in the fight against financial crime.

Autonomy is optional, governance is not

Success with agentic AI means controls must be engineered into the AI lifecycle. Best practice begins with a risk-based framework. Not every AI use case carries the same regulatory or customer impact, so it's important to classify risk use cases and align governance requirements to the assigned risk level. High-risk use cases require stronger traceability, explainability and oversight, while lower-risk use cases can move faster with lighter controls to drive efficiencies.

Every decision an AI agent makes must also be explainable, with clear audit trails and defined reasoning behind the actions of AI agents. MAS has made this explicit in its consultation paper on responsible AI. Although Singapore's principles-based approach gives institutions some flexibility, accountability remains non-negotiable.

This means that every AI action must be captured and logged, including which agent triggered the action, when it occurred and under what conditions. Teams overseeing AI agents should also review historical activity and decision paths to track the rationale behind specific outputs in context.

Guardrails that protect against data leakage are integral to maintaining trust. Human oversight should incorporate privacy-preserving techniques like ensuring client data is not used to train or fine-tune models.

The survey tells us that respondents are moving towards this. Fifty-five percent of firms plan to take a hybrid approach to agentic AI, blending vendor solutions with in-house customisation that provides governance, auditable systems that can be explained and defensible.