The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

The AML AI Readiness Gap in North America
Most North American firms do not have an AI adoption problem. They have an architecture problem.
In The State of Financial Crime 2026: North America edition, ComplyAdvantage reports that 99% of surveyed firms allocate funds to AI for financial crime detection and prevention. The same report finds that 54% use between eight and ten separate systems for customer screening. AI is being added quickly, but the compliance infrastructure around it remains fragmented.
That distinction matters. Adding intelligent document review or alert triage to a disconnected process may improve one task, but it does not create an effective AML control. If customer evidence, ownership data, screening results, risk decisions and reviewer actions remain in separate systems, the firm still cannot see or explain the case as a whole.
AI Adoption Is Not Operational Readiness
The North American findings draw on 200 senior compliance decision-makers, including 140 in the United States and 60 in Canada. Respondents work in payments, banking and insurance organisations with at least 50 employees and more than $50 million in assets. This is not a survey of investment services alone, but its operational warning applies directly to investment advisers, fund administrators and firms onboarding complex investors.
Consider a family office investing through an SPV owned by an offshore trust. The onboarding file may include constitutional documents, registers, tax forms, an ownership chart and declarations for trustees, protectors, directors and ultimate beneficial owners. A fund-of-funds or partnership introduces further relationships. PEP, sanctions and adverse-media screening may produce alerts across several individuals and entities.
Now split that case across an intake portal, shared drive, document-reading tool, company registry provider, screening system, spreadsheet and ticketing queue. Each tool may work as designed. The operating model still fails because no part of it holds the complete line from source evidence to final decision.
An AI project can make this fragmentation less visible without resolving it. A generated summary may pull together several fields, while the underlying documents remain disconnected. An alert-triage model may prioritise a match, while the verified date of birth or associated entity needed to resolve it sits elsewhere. The output appears intelligent, but the analyst still has to reconstruct the context manually.
This is why AI-first compliance cannot mean adding AI features to every point solution. It means redesigning the process around a coherent case record and applying automation to defined tasks within it.
Fragmentation Starves AI of Context
AML decisions depend on relationships between facts. A name has limited value without a date of birth, nationality, address, company appointment or connected entity. An ownership percentage means little unless the system can follow the chain through each intermediate company. A source-of-funds statement must be assessed against the investor, transaction and supporting evidence.
Fragmented systems break those relationships into separate records. One tool knows the investor's identity. Another knows the corporate structure. A third sees a possible sanctions match. A fourth records the analyst's conclusion. The same party may appear under different spellings or identifiers, and changes may not reach every system at the same time.
This creates three operational problems.
First, automation works with incomplete inputs. A screening system cannot use the full KYC context if verified identifiers remain in the intake platform. This is precisely why context reduces false positives without weakening AML screening. A possible match becomes easier to assess when the reviewer can compare names, dates, locations and related entities in one place.
Second, every hand-off introduces reconciliation work. Analysts copy values between systems, download reports, update spreadsheets and create notes explaining what another tool could not see. Automation may save time inside one step while the wider process continues to consume effort at each boundary.
Third, fragmented records weaken decision evidence. An auditor or regulator does not only need the final risk rating. They need to understand which sources were used, how conflicting information was resolved, why an alert was dismissed and who accepted the residual risk. Rebuilding that account from several systems is one reason AML compliance remains structurally broken.
Manual Remediation Is a Workflow Problem
The report finds that 81% of North American respondents take more than five minutes to clear a single sanctions alert during customer onboarding. Five minutes sounds modest until the queue contains repeated name matches across investors, directors, trustees and beneficial owners.
The time is rarely spent looking at the alert alone. The analyst has to locate the relevant KYC file, confirm which identifiers were verified, check whether the person is connected to another entity, compare dates and locations, record a rationale and update the case. When those facts are distributed across several tools, remediation becomes a search-and-reconstruction exercise.
Adding an AI-generated alert summary does not solve that workflow if the system cannot access the evidence needed to support the conclusion. It may simply create another item for the analyst to verify. Effective automation must bring the source data, comparison logic and disposition into the same controlled sequence.
That principle applies beyond onboarding. When a sanctions list changes, a director is appointed, or an ownership structure is updated, the firm needs to identify the affected cases and reassess them with the existing context intact. Otherwise, every event begins another manual remediation cycle. The same weakness appears at scale when firms use AI to clear a KYC remediation backlog without first addressing the process that allowed the backlog to form.
Build the Case Record Before Adding More Automation
A mature AI-first AML operating model begins with the case, not the model.
The firm needs one end-to-end record connecting the investor, related parties, documents, extracted facts, layered ownership, screening results, risk assessment, exceptions and decisions. Different providers may supply data or specialist capabilities, but the compliance team should not have to reconstruct the customer from their outputs.
Automation can then be applied to specific work: classifying documents, extracting ownership information, calculating indirect holdings, comparing identifiers, prioritising alerts and drafting case summaries. Each task should feed the same record. Conflicts, missing evidence and low-confidence conclusions should move to human review with the relevant context already assembled.
This is where AI assurance belongs. It is not a large parallel programme or an abstract governance exercise. It is the proportionate set of controls that shows whether each automated task works as intended: approved use cases, tested performance, permissions, data handling, versioning, exception routes, human oversight and a reproducible decision trail. Assurance should be embedded in the operating model, not added as another disconnected workstream.
This approach also matches the regulatory shift towards effectiveness. In April 2026, FinCEN proposed reforms to AML/CFT programme requirements that would emphasise risk-based, reasonably designed programmes and how they operate in practice. An inventory of AI tools does not demonstrate effectiveness. A coherent record of evidence, controls and outcomes does.
Steward applies this model to investment services through a purpose-built, end-to-end AML/KYC workflow. Document review, layered ownership analysis, onboarding decisions, screening and ongoing monitoring share one case record, with human review and supporting evidence preserved throughout. Across the client base, 80.2% of cases achieve straight-through processing. That outcome comes from removing unnecessary hand-offs while keeping exceptions and decisions visible.
The report's lesson is not that compliance teams need more AI. It is that AI can only be as effective as the operating model around it. Firms that continue adding intelligence to fragmented systems will automate individual tasks. Firms that unify evidence, workflow and decision-making will improve the control itself.
Related Insights

AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses

FCA Increases Scrutiny of Annex 1 Firms
What the FCA's August 2026 intervention means for Annex 1 registration, governance and AML controls