Surajeet Dev
Surajeet Dev

Financial institutions are increasingly turning to AI to manage growing regulatory complexity. Yet adoption does not automatically make compliance clearer. A 2026 Wolters Kluwer survey found that 31.8% of financial institutions had deployed AI or machine learning into production, while only 12.2% said their AI strategy was well-defined and adequately resourced.

Surajeet Dev, founder of RegiSentinel, believes the next stage of compliance technology should focus on improving that connection. RegiSentinel is a pre-revenue regulatory intelligence and compliance platform that Dev says is being developed to help financial institutions connect regulatory requirements with the policies, controls, and operational decisions they influence. Some elements of the platform's broader vision remain in development.

For Dev, one of the main challenges is what happens as regulatory information moves across an organization. A requirement may involve several departments, systems, and teams, each responsible for interpreting or implementing part of it. As information moves between them, the original regulatory intent can become less clear.

"There is a gap between understanding what the regulators want, and what the legislation initially intended, versus what the banks can implement," Dev explains.

This is where explainability becomes particularly important when AI is introduced into compliance processes. NIST's AI Risk Management Framework identifies transparency, explainability, accountability, and interpretability as important considerations when organizations manage AI-related risk.

In practice, Dev believes compliance professionals need more than an AI-generated conclusion. They should also be able to understand how that conclusion was reached and what information supports it.

He uses risk scoring as one example. "If it says the risk is high without explaining, there is a lack of trust," he says. A more useful approach, in his view, would provide supporting context, including the relevant regulatory language, the reasoning behind the assessment, and the obligations or controls that may be affected.

This emphasis on documentation also reflects broader regulatory expectations around governance. Federal Reserve guidance on model risk management highlights the importance of governance, validation, controls, and documentation when models are used within financial institutions. The Basel Committee's guidance on compliance functions similarly places compliance risk within a wider framework of governance and oversight.

The challenge, however, extends beyond interpreting a regulation. Financial institutions must also translate that interpretation into policies, controls, transaction checks, and everyday operating decisions.

Dev sees AI as one way to help different teams work from a more consistent foundation while keeping people responsible for final decisions. "The end result is still human judgment, but augmented with generative AI," he says.

According to Dev, RegiSentinel is being designed around that principle. He explains an approach that includes structured extraction, risk scoring, impact analysis, and a regulatory knowledge graph. Rather than relying mainly on a conversational AI interface, the broader aim is to make it easier to understand how regulatory requirements relate to obligations, policies, and controls.

Dev also believes there is value in looking at compliance as a connected process rather than a series of separate steps. Regulatory changes can lead to new obligations, which then influence policies and controls. Those controls affect transactions, and when exceptions occur, operational teams must investigate what happened.

In his view, connecting those stages more clearly could help institutions understand whether an exception reflects an isolated operational issue or points to something that should be reviewed further up the compliance process.

RegiSentinel
RegiSentinel

That idea remains part of RegiSentinel's longer-term direction rather than a claim of an already completed capability. Dev frames the broader goal as creating a feedback loop in which information from operational activity can be connected back to the original regulatory requirement.

He also sees potential for better alignment between financial institutions and regulators. "Once everyone is on the same page, you can go ahead and optimize," he says.

For financial institutions, this does not necessarily mean adding more automation. The more practical opportunity may be to make existing compliance processes easier to follow, review, and understand across teams.

AI may support that effort by helping organize information and identify connections, but Dev's view keeps human judgment at the center. As compliance technology develops, the most useful systems may be those that help professionals understand not only what decision was reached, but also how it connects back to the regulation that started the process.