A faster document request is no achievement if the bank never needed the document. Before funding automation, banks should decide which steps matter and which can go. KYC shows why cutting paperwork and improving judgement can be part of the same job.

Imagine a bank announcing an automation success. Documents arrive faster. Approvals move quicker. The dashboard turns green. There is one awkward question: If we built this bank today, would we introduce this process at all? My view is that management should answer it before signing the technology budget. Otherwise, the bank may be paying to preserve work it could have removed.

Every step needs a reason

A legal requirement can be necessary while the workflow around it remains open to improvement. The bank needs to separate three things: what it must achieve, how it checks the result and how it organises the work.

That distinction matters. A required assessment does not automatically justify every form, handoff and approval attached to it.

Take a hypothetical customer asked to submit information the bank already holds in a verified, current form. Before building an automated reminder, establish whether the bank can reuse that information under the applicable requirements. If it can, there may be no request to automate.

The same applies to repeated data entry and serial approvals. Each deserves examination. Some provide an independent check. Others may exist because two systems do not connect or because an old division of responsibilities has survived.

Those possibilities need evidence. A step should survive because it does something necessary. Its place in the existing workflow is insufficient justification.

The practical starting point is simple: identify what each activity establishes, who uses its result and what would be lost if it disappeared. An unclear answer is a reason to investigate before commissioning automation.

KYC needs understanding, not a thicker file

Periodic KYC review provides a useful example. Imagine a customer receiving proceeds from selling a company. The purchase agreement is available. The payment is documented. An automated workflow prepares the case for approval.

But the payer differs from the buyer named in the agreement.

That may be perfectly legitimate. Another company in the group could have made the payment. Yet a possible explanation remains a possibility until adequate evidence supports it.

The employee’s real task is to assess whether the story makes sense and whether anything important is missing. The right questions change with the situation. So does the point at which further paperwork adds little.

FATF Recommendation 10 requires understanding the relationship and checking transactions against knowledge of the customer, their business and risk profile, including the source of funds where necessary.1 A collection of documents supports that work. It cannot establish that the work is complete.

Periodic checks also have a regulatory foundation. FINMA’s explanation of the rules introduced in January 2023 specifies risk-based periodic checks to ensure that client data remain current.2 Banks cannot simply abandon a required check because nothing appears to have changed.

They can examine how they perform it. Reuse suitable evidence where permitted. Investigate meaningful gaps. Challenge requests and handoffs that add no necessary value.

The aim is less avoidable administration and more relevant scrutiny.

A polished answer can hide an open issue

A language model could flag the payer mismatch and suggest the next enquiry. It could also write a convincing summary that leaves the mismatch unexplained.

Both answers might sound professional.

NIST describes the risk that generative models confidently present false or erroneous content, which it calls confabulation.3 Good writing therefore cannot establish good assessment.

That does not mean models cannot judge content. Research by Dell’Acqua and colleagues found that assistance improved consultants’ performance on some tasks and worsened it on others.4 The study concerned consulting and an earlier model. It does not validate current banking systems.

Its lesson is useful: test the actual job. Summarising a contract, spotting a discrepancy and deciding whether an explanation is sufficient are different tasks.

The bank must also agree on what a sufficient answer looks like. Where experienced employees disagree, management should establish whether the difference reflects legitimate discretion or a rule the bank has yet to settle. Giving that disagreement to a machine does not resolve responsibility for it.

Cutting steps can send the bill elsewhere

The strongest defence of standard procedures is consistency. They make minimum requirements visible, help less experienced employees and leave records for others to inspect.

Removing a step can weaken those protections. It can also move work.

An early check disappears. Another team receives more exceptions. One department celebrates faster processing while another spends longer repairing the result. In that hypothetical situation, the dashboard tells only part of the story.

That is why redesign needs a test across the whole process.

Choose one clearly defined result. Identify the requirements. Map what each step contributes. Propose which activities should remain, change or disappear, with a reason for each decision.

Then compare three versions: the existing process, a redesign without model assistance and the same redesign with it. This proposed comparison would show what comes from better organisation and what the technology adds.

Measure missed issues, unsupported conclusions, customer effort, rework and total time across teams. Include ordinary cases, exceptions and missing information.

FINMA Guidance 08/2024 discusses expert-defined tests, expected results, monitoring and independent review.5 Those disciplines can help establish whether the new approach works. Speed should be assessed alongside the quality of the required controls.

Bank Automation Strategy: Make every Process earn its Budget

Governance. Make someone responsible for the overall result. Define who owns the rules, who checks the system and who decides individual cases. Give employees clear grounds for accepting a case, seeking more evidence or escalating it. Closing one KYC enquiry does not end ongoing due diligence.1

Customer experience. Give every request a purpose. Assess whether it was justified by the information available when it was made. Allow adequate evidence to close an enquiry, while recognising that new information may require another look. More paperwork is an activity measure; its contribution still needs to be established.

Strategy. Select one process now. Bring together the people who perform it, depend on it and challenge it. Require them to explain which steps stay, which go and why. Test the redesigned process before funding its automation. Then put the uncomfortable question to the executive approving the budget: If we built this bank today, would we introduce this process at all?

Sources

  1. FATF: The FATF Recommendations, updated June 2026. Recommendation 10 and its Interpretive Note.
  2. FINMA: Money Laundering Supervision (2022), Annual Report 2022, published 2023.
  3. NIST: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (July 2024), section 2.2.
  4. Dell’Acqua et al.: Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of Artificial Intelligence on Knowledge Worker Productivity and Quality, Organization Science 37(2), 403–423 (2026).
  5. FINMA: Guidance 08/2024: Governance and Risk Management When Using Artificial Intelligence (18 December 2024).