About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Smarsh and AWS Target the Governance Gap in AI-Powered Surveillance

Subscribe to our newsletter

Smarsh recently reported what it describes as breakthrough results from its collaboration with Amazon Web Services (AWS), including a 77% reduction in compliance review workload at one global investment bank. The three-month deployment analysed millions of alerts and, according to Smarsh, produced a 2% decline in true positives.

The results provide an early test of the collaboration’s wider objective: helping financial institutions deploy artificial intelligence in communications surveillance while retaining the governance, explanations and audit evidence required by regulators.

The collaboration began in October 2025 and is built on Amazon Bedrock and Amazon Bedrock AgentCore. Smarsh says it has since applied the technology at financial institutions seeking to move AI models from controlled trials into production.

Kamesh Tumsi, Chief Product Officer at Smarsh, explained for RegTech Insight that the result came from a champion-challenger test using the same base population. The champion comprised the bank’s existing surveillance scenario. The challenger applied the Intelligent Agent Filter to that scenario and compared the change in false-positive volumes with the loss of true positives. “The measurement was a controlled comparison rather than an estimate,” he said.

Smarsh recommends that each institution repeat the champion-challenger test against its own communications, surveillance scenarios and reviewer decisions before using the filter in production.

Building governance into model development

AWS supplies the underlying infrastructure, while Smarsh applies its surveillance models and governance controls. The collaboration has produced a model-development framework intended to reduce the manual work involved in preparing, testing and documenting models.

The framework versions each run from end to end and retains the supporting data. This allows development teams and model validators to recreate an experiment and trace the evidence that supported it. Shared components can also be reused for bias and fairness assessments or adapted for adversarial testing.

Tumsi said each experiment is “fully traceable and can be recreated exactly”. The outputs can feed into the model risk management reports that regulated institutions require before approving production models. Smarsh is extending the framework to support agentic capabilities.

The approach responds to a common weakness in enterprise AI programmes. A model may perform well during development but still face resistance from compliance, model-risk and internal-audit teams if the firm cannot explain its classifications, reproduce earlier results or document changes between versions.

Smarsh seeks to make that evidence visible within the surveillance workflow. When a communication generates an alert, the reviewer sees the policy or regulation associated with it and the text that triggered the detection. “The reviewer sees both what and the why simultaneously,” Tumsi said.

Supporting methods include token attribution, which identifies the parts of a message that influenced an individual classification. Broader explainability methods examine model behaviour across groups of inputs and its relationship with the training data.

Smarsh favours small, discriminative language models trained on domain-specific data for its Filter and Detect agents. Tumsi said this makes individual predictions easier to reproduce and link to the policy definitions and data behind them. This reduces dependence on larger general-purpose models for alert detection.

Keeping people in the decision chain

The Intelligent Agent does not suppress, escalate or prioritise communications without human oversight. Its Filter agent identifies material considered noise, including non-conversational content and disclaimers. The Detect agent identifies potential policy breaches and generates alerts. A qualified reviewer examines the result and records the disposition.

“Smarsh’s Intelligent Agent capability always operates with a human in the loop,” Tumsi said.

The audit record captures the agent’s classification score and model version, alongside the reviewer’s decision. Compliance teams can sample any message, inspect the alert rationale and reconstruct how the final disposition was reached. This creates an evidence chain covering the model output and the human response.

Responsibility is divided across AWS, Smarsh and the institution using the service. AWS is responsible for infrastructure availability and platform security. Smarsh develops and validates the models and manages deployment, application controls, encryption keys and audit trails.

The financial institution configures its scenarios, conducts its own testing and decides whether to approve production use. It remains responsible for human review and the resulting supervisory outcome. Tumsi said this division is intentional because “regulators expect financial firms to retain ultimate accountability for compliance decisions”.

Smarsh has reported a second result from K1 Investment Management, which says AI Noise Reduction has cut its false positives by 50%. That result points to the same operational goal: reducing low-value review work while retaining evidence that shows how the system and its reviewers handled each communication.

Smarsh also offers Discovery Agent for legal case assessment and a Noise Reduction Agent for smaller compliance teams. The products are available through AWS Marketplace, giving firms a route to deploy them within existing AWS arrangements.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party dependencies, its implications extend deep into core operational processes that are critical to market integrity, investor...

BLOG

Regulatory Developments 2026, a Cross-Jurisdictional Outlook

2026 regulatory themes are converging around the theme of continuous evidence – data quality, control effectiveness, and operational resilience demonstrated through repeatable artefacts rather than narrative attestations. In Europe, that direction is most explicit in ESMA’s data platform and supervisory tooling agenda, alongside the ESAs’ DORA-related coordination and oversight planning – see ESMA 2026 Annual...

EVENT

AI in Capital Markets Summit London

Now in its 3rd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...