
As AI enters communications, surveillance and investigations, firms face a wider record-keeping question: what evidence will explain how a regulated outcome arose?
This was the focus for recent webinar hosted by A-Team Group’s RegTech Insight and sponsored by NICE Actimize, The Next Compliance Frontier: Monitoring GenAI and Unstructured Comms Data.
Generative AI extends the evidence trail across prompts, retrieved sources, model responses and agent logs before a regulated communication or decision reaches its outcome. Compliance teams need a record that supports reconstruction of the evidence trail for internal audit and external examiners. “The regulators will expect to have access to them,” a panellist said when asked whether firms should retain prompts entered into large language models.Record Boundaries
A grammar tool doesn’t create the same evidentiary demand as an agent with authority to review evidence, recommend an investigative outcome or initiate regulated action.
One panellist separated communications capture from decision support and trade reconstruction. Communications records show what employees and external parties said through regulated channels. Decision-support records may need to show which information shaped an action: the prompt, sources retrieved, model output, human intervention and final disposition.
For a structured trade, an investigator could need to connect an order with a call, a chat, an AI query and a pricing recommendation. That reconstruction must identify who acted, what informed the action and when each event occurred.
Reasonable Design
When asked whether any large firm could prove complete capture across every employee, system and channel, “the answer in my view is, you can’t …” observed one panellist.
HR records, system permissions, recording duties and surveillance coverage provide the starting points for reconciliation. A role change should prompt a review of access and capture obligations. References to off-channel contact can reveal an unmonitored route. Application inventories should include AI functions within approved software. Each exception needs an owner, an assessment, a remediation record and a closure date. Testing should run on a cycle and after changes to roles, applications or vendors.The regulatory test rests on control design. As another panellist put it: “The systems and controls have to be reasonably designed.”
Shadow AI
Employees may route around controls when approved tools fail to support their work. Firms can reduce that pressure by providing sanctioned services and a route for proposing use cases. Before deployment, governance teams can assess data access, retention, model risk and record requirements. Permissions should confine each user and agent to defined data, functions and actions.
“The best way to beat shadow AI is to let people use AI in a governed way and support it across your business,” said a panellist.
Timestamps and Identifiers
The panel considered a scenario at a firm where trades used Coordinated Universal Time while communications used the time zone recorded when traders joined the firm. A trader who had joined in Hong Kong and moved to London carried the Hong Kong time setting, forcing investigators to add eight hours when matching messages to trades. Daylight-saving changes created another source of breaks.
Investigators expect consistency across timestamps and identifiers—people, accounts, instruments and counterparties, backed by lineage that shows where each record originated and how systems transformed it. A message may name a security by a desk nickname while the trade system uses an instrument code. Inconsistent mapping will result in incomplete audit trails and regulatory exposure.
Human Judgement
A human approval step offers little protection if the reviewer accepts the recommendation without challenge. The audit trail should record the evidence each reviewer received, any changes or rejection, and the grounds for the decision. Human oversight fails as a control when the reviewer does little more than approve the system’s recommendation.
Reviewers need the expertise and authority to stop the process. The panel compared that role with the kill switch used in algorithmic trading: the person overseeing the system must recognise a harmful direction and be able to hold or terminate the action. Start with the regulated outcome, trace every input and intervention that shaped it, and identify the systems that hold those records.
Panellist Take-aways
AI has changed surveillance tools more than the regulatory obligations that govern them. Firms should focus on reasonably designed controls, supported by review and change processes that respond to new systems, channels and regulatory expectations. Firms can govern AI through their existing policies, control frameworks, working groups and review boards. AI should enter the same governance process as other systems rather than sit outside established oversight.
Human owners retain accountability for AI-supported outcomes and must have the expertise and authority to intervene. Breaking down silos between compliance, technology and the business will require strong communication as well as technical controls. Surveillance teams need close working relationships with technology colleagues who control the firm’s data and systems. One panellist urged compliance leaders to invest time in those relationships, “Your tech teams are your best friends,” he said.
Subscribe to our newsletter


