top of page

The Fragmentation Tax: Why AI Alone Cannot Fix a Disconnected Compliance Stack

The Fragmentation Tax: Why AI Alone Cannot Fix a Disconnected Compliance Stack

By Baran Ozkan, Co-Founder & CEO at Flagright


As the first half of 2026 closes, the AI debate in compliance is entering a harder phase. The question is no longer whether AI can improve individual tasks, but whether those improvements can survive the fragmented architecture beneath them.


Many institutions are applying AI to a compliance stack built for a different era. Transaction monitoring sits in one system. Watchlist screening, customer risk, case management and regulatory reporting sit in others. Yet investigators still have to reconstruct a customer's risk story by moving between queues, spreadsheets and data sources.


This is the fragmentation tax. It appears as duplicated alerts, inconsistent risk scores, broken handoffs, repeated evidence gathering and slow decisions. It also creates a governance problem: when data, rules, models and human judgement are scattered across separate systems, the institution struggles to explain how a decision was reached from beginning to end.


AI can make parts of this environment faster. It can rank alerts, summarise case files, identify patterns and help draft narratives. But speed within a silo is not the same as effectiveness across a programme. A transaction-monitoring model does not automatically know that a customer's ownership structure changed, a screening match was cleared elsewhere, or an investigator previously identified a related entity. Without shared context, AI can automate fragments while leaving the overall control framework disconnected.


Fragmentation also weakens learning. When one system cannot see the outcome of another, feedback loops break. Screening decisions do not improve monitoring; investigation outcomes do not refine risk scoring; regulatory filings do not reliably inform future detection. Institutions then tune each control independently, often against local metrics, while the real objective - understanding and interrupting suspicious behaviour - remains distributed across the stack.


From transaction monitoring to suspicious activity monitoring


The industry's direction is already shifting. The Wolfsberg Group has urged financial institutions to look beyond automated transaction monitoring and adopt broader monitoring for suspicious activity, combining transactions with customer behaviour and customer attributes. FATF has likewise recognised that new technology can improve the speed, quality and efficiency of AML/CFT controls, while stressing responsible implementation, data protection and informed oversight.


The implication is clear: the unit of design should no longer be the individual alert or tool. It should be the full risk decision. Every signal, investigation, escalation, clearance and filing should contribute to one connected record of what the institution knew, when it knew it and why it acted.


Three tests for an AI-ready compliance architecture


First, shared risk context. Monitoring, screening, risk assessment and investigations should work from a consistent view of the customer, transaction history, connected parties and prior decisions. New information should update that context across the control environment, rather than remain trapped in the system where it first appeared.


Second, traceable decisioning. Institutions should be able to reconstruct which data was used, which rule or model produced an output, which version was active, how a person reviewed it and why the final decision was made. Explainability is not a technical appendix. It is part of the operating workflow.


Third, governability. AI-enabled controls need defined ownership, validation, access controls, change management, performance monitoring and human escalation paths. The Wolfsberg Group's responsible innovation framework highlights transition and validation, balancing model risk with financial crime risk, and explainability. Those principles must shape the architecture from the start.


Keep humans accountable, but give them better work


A connected system should not remove human judgement. It should remove the mechanical work that prevents people from using it. Investigators need a complete risk narrative, not another recommendation delivered without context. They must be able to challenge an AI output, document their reasoning and see how their decision affects future monitoring.


This also changes how success should be measured. Alert volumes, false-positive rates and handling times matter, but they are operational indicators. They do not prove that a programme identifies meaningful risk. Leaders should also examine coverage, the quality and consistency of escalations, the time required to detect material changes and the institution's ability to provide defensible information to authorities.


The next phase of compliance innovation will not be won by the institution that buys the most AI features. It will be won by the one that can connect risk context, decisions and evidence without losing accountability. Before adding another model, leaders should ask a harder question: will this capability strengthen the whole control system, or simply make one silo move faster?


AI is valuable, but it is not structural glue. Applied to a coherent architecture, it can help compliance teams detect risk earlier, investigate more intelligently and adapt faster. Applied to a disconnected stack, it may only make the fragmentation tax arrive sooner.

 
 
bottom of page