AI Agents for Investment Adviser Compliance: What to Delegate Before 2028
What a compliance AI agent actually does, which tasks to hand it, which decisions must stay with a named person, and how to evaluate and govern one at an RIA.

Short Answer
An AI agent for investment adviser compliance is software that carries a compliance task through several steps on its own: it collects documents, extracts the facts, checks them against your rules and drafts a case summary with every source cited. What it should not do is decide. Risk rating overrides, true sanctions matches, accepting a high-risk investor and filing a SAR stay with a named person. Used that way, agents give a two-person compliance team the capacity to meet the 2028 rule without hiring a department.
Key Takeaways
- An agent is not a chatbot and not a rules engine. It runs multi-step work and hands a prepared case to a human.
- The useful split is three-way: software runs it, the agent drafts and a person weighs it, or a person decides.
- Regulators accept automation but expect human ownership of decisions. The EU AMLR makes that explicit from July 10, 2027.
- Evaluate agents on evidence, not demos: cited sources, versioned rules, a complete audit trail, and QA you can sample.
- Advisers are the right place to start because their compliance teams are small and the obligations arrive on a fixed date.
What is an AI agent in compliance, and how is it different from automation?
Compliance teams have used automation for years. A rules engine screens a name against a list and returns a hit. A workflow tool sends a reminder when a document is missing. Each does one step, the same way, every time.
An agent strings steps together and handles the variation between them. Asked to prepare an onboarding file for a new LP that is a Delaware LLC, it can request the formation documents, read the operating agreement when it arrives, pull out the members and their percentages, notice that one member is itself a Cayman company, request that company's register, screen every person it finds, and produce a summary that says what it found and where each fact came from. A person would do the same sequence. The agent does it in minutes, at any hour, for every investor.
The difference from a general chatbot is just as important. A chatbot answers a question from whatever it has absorbed. A compliance agent works from your documents, your rules and your data sources, and it should show its work. If it cannot point to the page of the operating agreement that supports a 30 percent ownership figure, the figure should not be in the file.
Why do investment advisers need agents more than banks do?
Banks built their AML functions over decades with dozens or hundreds of analysts. Most registered investment advisers and exempt reporting advisers have a chief compliance officer who also covers the Advisers Act, marketing rules, code of ethics and SEC exams, often with one analyst or none.
From January 1, 2028, covered advisers must run a written, risk-based AML/CFT program with ongoing customer due diligence, suspicious activity reporting, recordkeeping, information sharing under Section 314 and independent testing. That is a bank-style obligation landing on a team sized for something else. Hiring analysts is the obvious answer and the wrong one for most firms: onboarding work arrives in bursts around closings, and analysts cost the same in the quiet months.
Agents match that shape. They absorb the volume at a fund close and the steady trickle of re-screening and refresh work between closes, while the compliance officer keeps the judgement calls.
What can an AI agent do for adviser compliance today?
Figure 1. Which adviser compliance tasks to give software, which to give an agent to draft, and which to keep with a named person.
The left column is mature and low risk. Document chasing, identity verification, list screening and file assembly are deterministic enough that software can run them with spot checks.
The middle column is where agents earn their place. Each task involves reading unstructured material and producing a draft that a person reviews:
- Alert triage. For each screening hit, the agent compares date of birth, nationality and other identifiers, and drafts a disposition note: likely false positive because the listed person is 30 years older and Russian, while the investor is a U.S. national.
- Ownership charts. The agent reads formation documents and registers and builds the chart to natural persons, with each percentage linked to its source.
- EDD memos. The agent assembles the source of wealth evidence, flags gaps and drafts the memo structure your methodology requires. See our EDD guide for private fund investors.
- SAR narratives. From a case file, the agent drafts the who, what, when, where and why. The decision to file stays human. See the SAR filing guide for RIAs.
- Periodic review packs. The agent pulls what changed since the last review and asks the investor only for what is missing.
Where must a person stay in the loop?
Figure 2. The agent prepares the case in four steps. A person reviews and decides. The audit trail is written as the work happens, and overrides feed back into a versioned rulebook.
The line is drawn in law in Europe and in expectation everywhere else.
Article 76(5) of the EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, which applies from July 10, 2027, allows firms to rely on automated processes and AI only if decisions to enter, refuse or maintain a relationship, or to change the level of due diligence, are subject to meaningful human intervention. U.S. rules contain no equivalent text, but OFAC's Framework for OFAC Compliance Commitments expects technology to be selected and calibrated to the firm's risk profile and tested, which assumes a person owns the settings. FinCEN's SAR rules make the filing decision the institution's, and an adviser cannot tell an examiner that a model decided.
Keep five decisions human: risk rating overrides, true match disposition, acceptance of high-risk investors, SAR filing, and approval of the program and its policies. Everything else can be prepared by software, provided a person can see what it did. Our article on explainable AI in KYC covers why "the algorithm said so" fails as an answer.
How should you evaluate an AI compliance agent?
A demo will always look good. Ask for evidence instead.
| Question | What a good answer looks like |
|---|---|
| Does every extracted fact cite its source? | Click any field and see the document and page it came from |
| Are rules and models versioned? | Each file records which rule set and model version produced it |
| What happens when the agent is unsure? | It flags the gap and routes to a person; it does not fill it with a guess |
| Can you sample its work? | A QA view that lets you pull a random set of files and score them |
| Who sees investor data? | Clear data processing terms, no training on your data without consent, SOC 2 Type II report |
| Can you export the file? | A complete, timestamped record you can hand an examiner without the vendor present |
| What screening data sits behind it? | A named, reputable list provider and a stated update frequency |
How do you govern an agent once it is live?
Treat the agent like any other control in the program. The banking agencies' model risk guidance is a sensible reference even though it does not bind advisers: know what the tool is for, validate it before relying on it, and monitor it after.
- Inventory. Record each agent task, its owner and the decisions it feeds.
- Validation. Before go-live, run the agent on a set of files your team has already completed and compare results.
- QA sampling. Each month, score a random sample of agent-prepared files. Track the defect rate.
- Change control. Rule changes are written, approved and versioned. No silent tuning to reduce alert volume.
- Independent testing. Include the agent in the annual independent test the 2028 rule requires.
How do you measure the value of a compliance agent?
Use your own baseline, not a vendor's. An illustrative example: a fund closing 120 LPs, where analyst time averages three hours per investor across chasing, checking, screening and file assembly, consumes 360 hours. If an agent prepares the file and the reviewer needs forty minutes per investor to check and decide, the close needs about 80 hours of human time. Your numbers will differ. Measure time to KYC-complete, first-pass completeness, QA defect rate and reviewer hours per file before and after, and keep the comparison in the program file. It is also good evidence of a program that is resourced in proportion to its risk.
What are the common mistakes?
- Letting the agent approve. Even low-risk auto-approval should be a written rule a person signed off, not model discretion.
- Rubber-stamp review. If reviewers accept 100 percent of drafts, they are not reviewing. Track override rates.
- No source citations. An extracted fact without a source cannot be defended.
- Tuning for volume. Raising match thresholds to cut alerts is a risk decision. Document it as one.
- Agents on top of scattered data. An agent cannot fix investor records spread across email, the administrator portal and a shared drive. Pick one system of record first.
Where Verifica fits
Verifica's compliance agent runs the collection, verification, ownership mapping and screening steps for each investor and drafts the case for your reviewer, with every fact linked to its source document and every action timestamped. Screening data comes from LSEG Risk Intelligence. Decisions, overrides and approvals are recorded against a named user, so the file an examiner reads shows both what the agent prepared and what your team decided. Verifica is software, not a law firm: your rules, thresholds and sign-off stay with your team.
Frequently Asked Questions
Can AI agents be used for AML compliance at investment advisers?
Yes. Nothing in the Investment Adviser AML Rule prohibits automation. What matters is that the program is risk-based, that a designated person is responsible, and that decisions and their reasons are documented.
Can an AI agent decide whether to file a SAR?
It should not. An agent can assemble the case and draft the narrative, but the filing decision belongs to the adviser's AML officer or designated reviewer, and the reasoning should be theirs.
Is an AI compliance agent different from a KYC API?
Yes. A KYC API performs one check, such as ID verification, and returns a result to your systems. An agent runs a sequence of steps across documents and data sources and hands a prepared case to a person.
What does the EU AMLR say about AI in onboarding?
Article 76(5) permits reliance on automated processes and AI systems if decisions to enter, refuse or maintain a relationship, or to change the level of due diligence, are subject to meaningful human intervention. It applies from July 10, 2027.
How should we test an AI agent before relying on it?
Run it on a set of completed files and compare its output with your team's, then sample its live work monthly and track the defect rate. Include it in the annual independent test.
Sources
- FinCEN, AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers, final rule, 89 Fed. Reg. 72156 (September 4, 2024), and postponement to January 1, 2028.
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation), Article 76(5).
- OFAC, A Framework for OFAC Compliance Commitments (May 2019).
- Board of Governors of the Federal Reserve System and OCC, Supervisory Guidance on Model Risk Management (SR 11-7).
- U.S. Department of the Treasury, 2024 Investment Adviser Risk Assessment.
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.



