
As Australia's financial services businesses prepare for the AML/CTF reforms, the conversation has shifted from whether to adopt AI and risk-based approaches to how to implement them effectively. This operational challenge, moving from strategy to execution, was a central focus of our recent webinar with industry leaders from Deloitte, AMP, and SymphonyAI.
The consensus? Technology alone won't deliver transformation. Success requires the right combination of AI deployment, robust governance, risk-based thinking, and stakeholder engagement that turns compliance obligations into competitive advantages.
When it comes to deploying AI across the financial crime lifecycle, not all applications deliver equal value. Craig Robertson, Financial Crime and Compliance SME - APAC at SymphonyAI, identified the highest-impact areas through a clear lens: "Detection. Why do I say that? We have this framework for anti-money laundering, counter-terrorism financing, counter proliferation, and complementary anti-scam frameworks because at the end of the day they're about implementing a framework that stops harm."
If organisations can't detect harm effectively, Robertson argued, they remain "caught in a loop of process and data and things and alerts that don't make a difference." Detection must be the priority, with automation serving as the gateway that makes transformation possible.
Across the Australian financial services sector, AI is being deployed in four key areas:
Robertson emphasised that the real value comes from integrated AI: "Those layers of data, the orchestration piece and how you use that data, how it interacts with your detections and ultimately gives you risk insights—that's the thing that hopefully fits with what we're talking about today."
Deploying AI into regulated financial crime processes raises critical questions about explainability and governance—questions that regulators are watching closely. AUSTRAC has been explicit about explainability and governance in its AI Transparency Statement. The regulator recognises that AI and emerging technologies are changing service delivery and that criminals are becoming more sophisticated. In meeting Australian Government requirements, AUSTRAC declares its own use of AI to identify money laundering indicators and support financial intelligence production, while maintaining strict governance standards.
For reporting entities, several governance principles have emerged as essential:
Dobbin noted that organisations approaching this thoughtfully are building AI deployment into their broader program transformation. Rather than bolting technology onto existing processes, they're redesigning end-to-end workflows around what intelligent systems enable.
From a business user perspective, AI adoption must solve problems without creating new ones. Michelle Reinisch, Director of Small Business/Personal Banking at AMP, stressed this point: "What's critical to ensuring AI adoption actually reduces friction and doesn't add new complexity?"
AMP's experience with their digital banking platform, AMP Bank Go, offers instructive lessons. The bank embedded new regulatory requirements and technology from the ground up, thinking about customer experience, compliance, and operational efficiency together rather than sequentially.
"We look at ways to invest in capabilities that reduce effort, improving detection, have faster responses, but also build trust," Reinisch explained. "We can't keep just throwing people at our problems. We need to think about it in a much smarter way."
For AI to reduce rather than increase complexity, several factors matter:
Reinisch emphasised that AMP's approach focuses on "automation lens and data-driven intelligence" that allows controls to be intelligent rather than merely reactive. "Right now, a lot of us tend to have more reactive controls rather than proactive controls, particularly in this space."
The shift to outcomes-based regulation makes risk-based approaches not just good practice but a regulatory expectation. As Dobbin explained when asked what clients should consider: "What are the key things you're advising clients to consider when building a genuinely risk-based approach under the new reforms?"
The foundation is comprehensive risk assessment across four dimensions:
The reforms make clear that risk assessments must be current, reviewed at least every three years, and approved by senior management. Importantly, each outdated risk assessment could constitute a separate compliance breach.
But Dobbin cautioned that risk assessment alone isn't enough. "It's not just about identifying risks—it's about evaluating their likelihood and impact and documenting how they're managed."
This means:
The goal, as AUSTRAC has signalled, is moving from regulation that primarily checks for compliance to regulation focused on substantive risks and harms. AUSTRAC will look at risk and behaviour at an industry and sector level, not just individual entities.
As technology providers evolve their products, businesses like SymphonyAI evolve in-built governance to align with regulators' expectations. Robertson described three key shifts:
From Detection to Prevention: "I always go to the E-Safety Commissioner talking about safety by design. A lot more financial crime controls can live what I'd call upstream of where they might live today." This upstream approach means embedding controls earlier in the customer journey—during onboarding, transaction initiation, and relationship management—rather than solely at the detection stage.
From Alerts to Explainability & Audit: Building Governance into AI Systems.
Rather than simply generating alerts without context, next-generation AI systems are being designed with explainability and auditability at their core. This shift reflects regulators' increasing focus on how decisions are made, not just what decisions are made.
Why governance matters:
Practical governance elements:
This is a fundamental shift from "black box" decision-making to governance-by-design—where explainability isn't an afterthought but embedded throughout the system architecture.
From process to decision support:
"The bad version of this is detect and report. The good version is I understand something's changed, I can see there's a cohort here who are doing something that might be misusing a product or service I'm providing. Now that I have that insight, I can do something about it."
Regulators won't just ask "Did you catch this?" They'll ask "How did you catch it? Why didn't you catch it earlier? Can you prove your system is working as intended?"
Institutions that embed governance into their AI systems now will find it far easier to demonstrate compliance confidence by 2026, while those treating it as an afterthought will face audits, remediation, and potential enforcement action.
As technology providers evolve their products, businesses like SymphonyAI evolve in-built governance to align with regulators' expectations."
Coming Next: In Part 3 of this series, we'll explore leadership strategies for navigating change, what success looks like, and the defining characteristics of next-generation financial crime capabilities.
Leading through change: Success strategies and the future of financial crime (part 3)
Webinar: Modernizing Compliance without Disrupting the Business: The Always-on Compliance Approach
This blog series is based on the webinar "Australia's Regulatory Reforms: Gateway to the Next Generation of Financial CrimePrevention," hosted by SymphonyAI featuring Michelle Reinisch (AMP), Lisa Dobbin (Deloitte), and Craig Robertson (SymphonyAI).