The 60-25-15 rule reshaping AI compliance pilots

AI

Compliance teams across banks and payment providers are being squeezed from both directions. Boards and C-suites are pressing for rapid AI adoption to slash operational costs, while the volume and cross-border complexity of regulatory change continues to surge, and personal liability for failures remains very real.

The challenge of turning boardroom enthusiasm into defensible, regulatory-grade practice was the subject of a recent Vixio webinar, hosted by the firm’s payments and banking industry lead Luke Baker.

He was joined by Nilesh Khatri, head of technology, regulated FinTech and financial services, and Andrew Dawson, chief risk and compliance officer and MLRO at Yeepay UK.

Baker set the scene starkly. Vixio payments and banking industry lead Luke Baker said, “Most teams are caught in a bit of a vice. On one side, you have boards demanding immediate AI adoption. On the other, you have the sheer volume of regulatory change—and 85% of compliance leaders say managing cross-border complexity is their biggest headache.”

The panel agreed that while consumer-facing large language models are capable, their hallucination rates make them unsuitable for high-stakes regulatory decisions. Firms must deliberately strip out the machine’s creativity to make AI regulatory-grade. Dawson pointed to his experience at LHV, where a proprietary LLM was built to support analysts with suspicious activity report (SAR) filings.

Yeepay UK chief risk and compliance officer Andrew Dawson said, “We placed this model in a proprietary environment so the data wasn’t used to train public models, anonymized the customer data, and – most importantly – turned the ‘heat settings’ down to the absolute minimum. You don’t want any sort of creativity or imagination when you’re writing a SAR.” The outcome was dramatic: a five-hour analytical process became near-instantaneous, freeing analysts to focus on high-value human verification.

Khatri, meanwhile, urged firms to sidestep the “utopian” trap of waiting for multi-year enterprise data transformation projects. Instead, he proposed a 60-25-15 budgeting framework for AI compliance pilots: 60% on data hygiene for a narrow, targeted domain, 25% on governance and control, and just 15% on the AI tooling itself.

Nilesh Khatri, head of technology, regulated FinTech and financial services, said, “In many failed pilots, this ratio is completely inverted. Teams spend all their budget on the shiny new AI tool, and squeeze the data and governance pieces. To show momentum, pick a single jurisdiction or a specific product taxomony, get it right, and replicate that success.”

On agentic AI, the panel concluded that while systems excel at bookending the compliance lifecycle, through horizon scanning and administrative tasks such as populating KYC questionnaires, the interpretive middle phase must stay human.

When the UK introduced new safeguarding rules for EMIs, understanding their interaction with a firm’s localised treasury systems demanded contextual knowledge no AI possesses. Khatri also cautioned that compressing scanning time without expanding human interpretation capacity simply creates a larger backlog.

With regulators ruthless on explainability, the panel’s consensus was to design for failure rather than the happy path: AI should recommend, not decide; audit trails must be captured at runtime; and vendors must be pressed to avoid black-box systems.

As personal liability regimes such as the UK’s SMCR expand, the verdict was clear. Baker said, “You can outsource the execution of a system, but you can never outsource the accountability.”

Watch the full Vixio webinar here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.