No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

‘Blame the Bot’ Won’t Cut It in Front of Regulators

Responsible automation requires human judgment, independence and evidence

by Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh
May 11, 2026
in Risk
robot fallen over

Regulators won’t simply look at your AI outputs when scrutinizing your organization’s compliance, Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh of StoneTurn write. Your decision-making is being evaluated, and relying on the defense that AI told you to make a certain decision is a recipe for disaster.  

AI is changing the speed and scale of compliance work, identifying anomalies in real time and surfacing risks that would have taken weeks to find manually.

But speed without structure creates different risks. Regulators are not evaluating your algorithms. They are evaluating your decisions — how you reached them, whether they are supported, and whether they hold up under scrutiny. Using AI isn’t the risk. In fact, neglecting the use case for AI can create a different risk entirely. Where organizations can find themselves in the hot seat is treating AI output as the defense behind every conclusion it helps produce.

The defensibility gap

Recent allegations involving a provider of AI-automated auditing and compliance reviews underscore a growing problem: the defensibility gap. Whistleblowers allege the firm bypassed authentic reviews and used “certification mills” to rubber-stamp compliance reports.

Whether those specific allegations are proved, the lesson is clear: If you cannot explain and defend the result, the process does not matter. In today’s environment, where AI missteps are scrutinized and amplified, a weak or opaque process risks not only regulatory exposure but immediate reputational damage.

The allegations also highlight a broader structural issue: Independence required for credible assurance breaks down when a single platform implements compliance measures and evaluates their effectiveness. For companies facing DOJ or SEC scrutiny, “check-the-box” automation is a liability.

What regulators expect is straightforward: a clear, auditable trail; evidence of independent judgment; and conclusions that can be explained and defended

Where AI helps and where it doesn’t

AI is powerful where scale and pattern recognition matter. This can include identifying anomalies across large datasets, canning contracts or transactions for outliers and surfacing potential misconduct signals. These capabilities are not theoretical. Many compliance teams use AI to accelerate reviews that previously took weeks. The technology works.

But uncovering the genesis of a compliance failure is rarely rooted in data alone. That requires an understanding of why people acted, whether controls were bypassed and whether leadership reinforced — or undermined — the program

AI cannot interview a whistleblower effectively. It cannot assess tone at the top. It cannot distinguish a technical failure from a cultural one. These require human judgment. That is where experienced professionals add irreplaceable value — not as a check on AI but as the judgment layer that makes AI outputs meaningful.

magritte son of man deepfake
Risk

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

by Matt Flegg
May 1, 2026

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

Read moreDetails

The shift in skillset

As AI becomes embedded in compliance, the job is changing. Less time gathering data. More time interpreting it and acting on it. Four capabilities matter most:

  • Model validation: Understanding what the AI is doing, where it is most effective and how to spot when its outputs need a closer look.
  • Data integrity: Ensuring inputs are reliable, knowing that bad data can produce confident but wrong answers.
  • Contextual judgment: Recognizing when controls exist on paper but fail in practice.
  • Defensible conclusions: Translating outputs into a clear, supportable narrative that explains why a conclusion was reached.

Questions to ask before deploying AI

AI compliance-testing products are sure to proliferate. Ask these questions from your vendor to assess whether the output will stand up to scrutiny:

  • Who is accountable if the tool flags or clears an issue?
  • What evidence supports the conclusion?
  • Does the same system design, implement and test controls?
  • Does the tool produce auditable documentation or just outputs?
  • What are the limits of the model?
  • What data is excluded?
  • How are false positives and false negatives handled?
  • Would you rely on this output in front of the DOJ or SEC?

AI will continue to transform how compliance work gets done, but it will not lower the bar. Prosecutors and regulators evaluate whether a program is adequately resourced, empowered and effective. Technology is but one piece of the puzzle.

In other words: Do not expect credit for automation alone. Every automated insight still needs a human who can stand behind it. In the end, compliance is not about what your system can detect. It is about what your organization can defend.

AI has permanently raised the bar for what defines ”defensible” compliance. The leaders of this new era will not be those who avoid AI, nor those who automate blindly. They will be the firms that pair powerful technology with the professional judgment required to explain, defend and stand behind every conclusion.

Tags: Artificial Intelligence (AI)
Previous Post

Your Next AI Risk Is Inside the Systems You Trust the Most

Next Post

Need for Speed: What DOJ’s New Approach to the CEP Means for Internal Investigations

Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh

Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh

Jonny Frank, a partner with StoneTurn in New York, brings more than 40 years of public, private and education sector experience in forensic investigations, compliance and risk management.
Nathan Gibson, a manager at StoneTurn in Washington, D.C., has more than six years of experience in forensic accounting and compliance monitoring. Specifically, he focuses on FCPA monitorships, anti-money laundering (AML) investigations and export control compliance.
Michael Costa, a partner with StoneTurn in Chicago, has deep experience in data analytics and data science, financial crime, investigations, complex litigation and compliance matters. He has worked with clients in the financial services, technology, education, life sciences and hospitality industries, as well as with public sector entities
Kashif Sheikh, a manager at StoneTurn in Chicago, is a full stack data scientist and AI engineer with over 15 years of experience assisting clients in the financial, technology, government, and legal sectors on data-oriented solutions impacting e-discovery, compliance and regulatory issues.

Related Posts

robot using calculator digital collage

When AI Writes the Number, Who Has a Reasonable Basis to Certify It?

by Shreyas Sampath
July 27, 2026

Treating AI governance as an IT deliverable leaves an officer standing at the end of a chain that doesn't reach...

news roundup data grungy

As Costs Rise & ROI Remains Elusive, Majority of Execs Say AI Agents Are Worth the Risks

by Staff and Wire Reports
July 23, 2026

30% of UK managers get specially trained on sexual harassment; Gartner IDs 5 big changes for legal functions

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

news roundup data grungy

43% of GRC Professionals Say AI Makes Their Jobs Harder

by Staff and Wire Reports
July 16, 2026

Plus: AI’s place in signing M&A deals; leaders use shadow AI more than employees

Next Post
speeding train in motion

Need for Speed: What DOJ’s New Approach to the CEP Means for Internal Investigations

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights