PAYMENT FIRMS

AI is drafting your SARs. But can you explain it?

The sales demo begins. The vendor shares their screen, and the live AI model flags a transaction as high-risk. The MLRO on the call nods. Good catch, she says. Then she asks how it got there.

The vendor walks through the interface. Risk score, contributing factors, a short paragraph of reasoning, written in plain language, drawing on the customer's history. It looks thorough. It reads like an answer. The vendor mentions, in passing, that the same engine can draft the SAR narrative too, trained on years of the firm's own historic filings.

The MLRO asks a second question: is the reasoning generated after the score, to explain it, or does the model reach the score through that reasoning. A pause. The vendor says they will need to check with engineering.

She has seen this before. A model that scores first and provides the rationale afterwards is unlikely to meet regulatory expectations for explainability.

If a SAR goes out on the back of this alert, it is the financial crime team using the third-party tool who is responsible. The MLRO needs to be able to explain the software’s decision.

She asks for the model validation report. The document that shows how the model was tested, how often it is recalibrated, what happens when it drifts.

IMG_5521

 

What We Are Seeing

Firms are no longer just trialling these tools. Three-quarters of payment firms plan to increase AI investment, and many are already running live risk decisions through them, and expecting them to transform SAR drafting.

Yet less than one in five firms say they are confident they could pass an independent review of their AI controls within 90 days, according to Grant Thornton’s 2026 AI Impact Survey.

Firms can train models on historic data to disposition alerts and draft SAR narratives, but doing so responsibly requires rigorous validation of both data and models, since unvalidated or biased data can lead to false positives, missed threats, or discriminatory outcomes. In other words, your assurance model must grow up alongside the technology.

The discussion around using AI for risk-based decisions, at our recent Payments Roundtable, centred on two core areas in need of attention:

Explainability. Your compliance team needs an output they can challenge and justify. Can your team understand why the tool produced a certain score, alert or recommendation, not just whether it works statistically?

AI Governance. What is your firm's broader framework around ownership, approval, testing, monitoring, vendor oversight, and accountability for how all tools are used? Does this need updating inline with the AI tools currently available on the market?

The Solution

The starting point is treating the model validation report as a non-negotiable, not a follow-up request. This is the main piece of evidence that shows the system has been independently tested, challenged, and documented.

Before any AI tool touches a live risk decision, firms should be able to see (and understand) how it was tested, how often it is recalibrated, and what happens when it drifts, not just what it produced last quarter.

The whole approach to assurance needs to become a critical part of your control framework. That means the MLRO isn't just a sign-off at the end of the process. They need line of sight into the model from the point it's selected, so the explanation behind a decision is something they helped build, not something they're handed afterwards. The exact same principle applies to internal models.

BeyondFS have a clear view on AI governance and how to move from pilot to production. If this is something your firm is less than confident about, get in touch.

 

Let's make change happen.

We help Financial Institutions accelerate digital transformation – delivering improved efficiencies, better risk controls and enhanced customer experiences.