Understanding the Role of Humans in AI-Driven Compliance
Questions about AI's role in compliance arise frequently in professional discussions. Your organization might have introduced an AI-powered policy search tool, or perhaps someone is using ChatGPT to draft case summaries. The risk committee is curious if AI can reduce case closure times. You're left questioning when to trust AI outputs, when to verify them, and the implications of errors.
The pressure is evident. Median case closure time increased from 21 to 28 days in 2025, yet your team size remains unchanged. AI offers potential relief, but the real challenge is determining when AI is effective and understanding your evolving role in AI-assisted workflows.
Here's what compliance teams are asking and how these questions shape the integration of human oversight in AI-driven processes.
Reviewing AI-Generated Policy Updates
"Our policy team wants to use AI to draft updates. Do I still need to review every line, or can I just spot-check?"
AI changes the nature of your review, not its necessity. AI tools can retrieve relevant wording and generate summaries of changes between document versions. However, you're still accountable for ensuring the proposed changes are accurate, complete, and appropriate for your jurisdiction and risk profile.
AI assists in organizing material, but you must determine if it answers the relevant questions. For instance, if your policy references local employment law and AI pulls language from another jurisdiction, it might apply the wrong standard. Your role is to identify these discrepancies and escalate when guidance is insufficient.
Avoid spot-checking. Review the substance and confirm AI's source selection.
Summarizing Investigation Reports with AI
"Can I use ChatGPT to summarize investigation reports to expedite my queue?"
Using general-purpose AI tools for investigations poses risks. Entering sensitive information into unapproved services can breach data protection and confidentiality obligations. AI outputs may not preserve original submissions or show how conclusions were reached, undermining your ability to support findings if challenged. Additionally, general-purpose AI lacks compliance-specific context, potentially mischaracterizing issues.
Purpose-built compliance platforms mitigate these risks by summarizing reports within established workflows, retaining original submissions, and ensuring data remains in approved environments. If your organization lacks such tools, manual summarization is necessary.
The NIST AI Risk Management Framework advises defining where human oversight is required and understanding the data and AI systems' provenance and quality. For investigations, use tools designed for the task and compare AI-generated summaries with original submissions before acting.
AI in Compliance Training
"AI use in compliance training is at 42%. What's my role if the system delivers most of the content?"
Your responsibility is to ensure training reflects current policy, targets the right audience, and addresses your program's risks. AI can personalize delivery and adapt content, but it can't verify the material's accuracy, alignment with regulatory changes, or relevance to your organization's specific risks.
If your anti-corruption training uses a global template and your operations have shifted to higher-risk areas, AI will deliver the template efficiently, but you must recognize its insufficiency.
Review AI-delivered content, ensure it aligns with current policies and risk assessments, and update materials as needed. AI scales delivery; you ensure accuracy.
Concerns About AI-Drafted Reports
"I'm seeing reports that sound like they were drafted by AI. Should I be concerned?"
Yes, if AI alters wording, omits details, or exposes personal information. Employees using public AI tools for drafting reports can inadvertently change the substance, affecting investigations. If AI "cleans up" submissions, you might miss specific details crucial for assessing credibility or identifying witnesses.
Encourage reporters to explain concerns in their own words, provide detailed information, and use in-language reporting options your program supports. Compare summaries with original submissions, and if wording seems generic or key details are missing, contact the reporter for clarification.
You can't prevent AI use in drafting reports, but you can design your intake process to identify and gather necessary details.
Evaluating AI Feedback in Compliance Reviews
"A recent study found GPT-4 feedback overlapped with human reviewers by 30-35%. Does that mean I can rely on it for compliance reviews?"
Not without understanding the AI's training data, source approval, and task suitability. The study focused on scientific publishing, where reliable sources underpin the review process. While AI can help organize relevant points, its performance varies by task. For instance, in one experiment, GPT-4 users completed more work faster, but in another involving financial data, AI users were less accurate.
The lesson: AI's reliability varies by context. For compliance reviews, test AI outputs against evidence, confirm source approval, and recognize when tasks require human judgment.
Screening Third Parties with AI
"We're using AI to screen third parties. How do I know if it's missing something important?"
You must confirm the correct entity, assess source reliability and currency, and determine if findings affect your relationship assessment. AI can screen large information volumes and prioritize records, but it can't confirm identities, assess source reliability, or determine materiality to due diligence decisions. Training cutoffs may exclude recent events, risking missed developments.
Review flagged records, verify matches, and apply your organization's risk tolerance and due diligence standards to decide on proceeding with relationships. AI supports screening; you make the final decision.
Next Steps
Begin with your organization's AI governance policy. If absent, the U.S. Department of Justice expects you to understand AI use, assess introduced risks, and apply compliance disciplines like policies, training, due diligence, testing, and monitoring.
The NIST AI Risk Management Framework offers guidance on defining human oversight, documenting AI controls, and understanding data provenance and quality.
Continue asking these questions. While tools evolve, the principle remains: AI prepares information for review, but you decide if the evidence supports the finding and if further action is needed.



