The financial services landscape across the Asia-Pacific region has reached a critical inflection point in the deployment of artificial intelligence. For several years, the primary concern of boards and regulators was the pace of adoption—ensuring that regional firms remained competitive against global peers by integrating automated efficiencies. However, by mid-2026, the focus has shifted dramatically. Regulatory bodies are no longer merely asking whether a firm uses AI; they are demanding to know the "why" and "how" behind every AI-driven decision. This transition from "adoption" to "explainability" was the central theme of the Future of Compliance Asia-Pacific summit recently held in Singapore, where industry leaders gathered to address the growing gap between technological implementation and regulatory assurance.
The catalyst for this shift can be traced back to late 2025, specifically the Monetary Authority of Singapore’s (MAS) November consultation on Guidelines on AI Risk Management. These guidelines set a new high-water mark for transparency and explainability, signaling to financial institutions (FIs) that the "black box" era of machine learning is officially over. As firms move from experimental pilots to agentic AI—systems capable of making autonomous decisions in customer screening and transaction monitoring—the pressure to provide a "defensible reasoning" path has become the most significant compliance hurdle of the decade.
The Widening Gap Between Ambition and Assurance
Data from the State of Financial Crime 2026 survey highlights a concerning disparity in the region. While global figures suggest that 59% of firms have established a comprehensive AI assurance program, the Asia-Pacific region lags slightly behind at 54%. This 5% gap is particularly striking when contrasted with the region’s aggressive appetite for new technology. In the APAC market, approximately 73% of firms are currently using, piloting, or evaluating "agentic AI" for customer screening. However, only 31% of these firms have moved these systems into full production.
The hesitation to move from pilot to production is largely attributed to the "assurance gap." Financial institutions are finding that while AI can identify risks faster than human analysts, the systems often lack the audit trails required by modern regulators. The challenge is no longer about the accuracy of the model alone; it is about the ability to reconstruct a specific decision made months in prior. Regulators are now asking firms to prove which version of a model was running on a specific date, which data sets were ingested, and which human officer provided the final sign-off—even after the relevant analysts have left the firm or the model has been updated.
A Chronology of Regulatory Evolution in APAC
The regulatory environment in Asia-Pacific has evolved through three distinct phases over the last five years. Between 2021 and 2023, the period was defined by "Exploratory Engagement," where regulators like MAS and the Australian Transaction Reports and Analysis Centre (AUSTRAC) issued high-level principles such as Singapore’s FEAT (Fairness, Ethics, Accountability, and Transparency) framework. During this time, the dialogue was largely collaborative and non-punitive.
The second phase, "Framework Formalization," occurred throughout 2024 and 2025. This saw the introduction of specific discussion papers and the embedding of "responsible AI" principles into existing Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) laws. In Malaysia, Bank Negara Malaysia (BNM) began integrating explainability requirements into its financial sector discussion papers, while Australia embarked on major AML reforms that placed a premium on senior management ownership of automated systems.
By 2026, the region entered the "Operational Proof" phase. The conversation has moved from theory to practice. As Kok Chun Hou, Managing Director and Group General Counsel at DCS, noted during the Singapore summit, the primary question for legal and compliance teams today is: “If we deploy this model, how can we ensure that it’s deployed in a sensible, justifiable, and defensible manner?” This phase is characterized by active audits where "institutional opacity" is treated as a major compliance failure.
The Triple Cost of Opacity
The summit participants identified three distinct stages where "opacity"—the inability to see into or explain a system—costs a firm. The first is "Operational Opacity," which occurs during the development phase. If a team cannot understand why a model is flagging certain names, they cannot tune it effectively, leading to high false-positive rates that drain resources.
The second is "Institutional Opacity," where the organization loses the thread of accountability. This happens when a firm cannot identify the specific version of an algorithm or the data lineage that led to a specific outcome. As regional regulatory guidelines take effect, there is increasingly less excuse for an organization to be unable to identify the human analyst or the model version involved in a historic decision.
The third and most severe stage is "Regulatory Liability." Kok Chun Hou emphasized that this is when the consequences of opacity "crystallize." When a regulator audits a compliance decision from six months prior and the firm cannot reconstruct the reasoning, the firm is left defenseless. In this scenario, the lack of an explanation is often treated with the same severity as a failure to screen entirely.
Accountability: The Un-outsourceable Burden
A recurring theme among the panelists, including Thomas Chia, Chief Technology Officer at Chocolate Finance, was the misconception that third-party vendors can absorb a firm’s regulatory risk. Most financial institutions rely on AI models from external vendors, cloud providers, or open-source repositories. However, the legal consensus remains clear: while you can outsource the technology, you cannot outsource the accountability.
The practical test for firms today is ensuring that their external partners operate in strict accordance with the firm’s internal risk appetite. This requires a two-pronged control strategy. First, firms must have "Input Controls" to ensure the data being fed into the vendor’s model is accurate and relevant. Second, they must maintain "Output Validation," where the results are checked against the firm’s specific standards rather than the vendor’s generic benchmarks.
Human-in-the-Loop and the Reality of Risk Management
As firms look to cut costs, there has been a trend toward reducing headcount under the assumption that AI "agents" can replace level-one analysts. However, experts at the summit urged caution, advocating for a phased approach. The consensus suggests that AI should handle repetitive, high-volume level-one work, but a human must remain at level two to review and validate outcomes.
Christopher Liu, Chief Compliance Officer and Head of Regulatory at BIT, reminded the audience that the industry is in the business of "risk management," not "risk elimination." Expecting AI to be 100% perfect is unrealistic, just as it is unrealistic for human teams. However, the "punitive edge" of accountability changes when humans are removed. As Thomas Chia pointed out, "If you think that the accountability sits with AI or an agent or a model, they can’t be punished. At least we have not figured out how." This lack of a "punishable" entity makes regulators even more insistent on having a named human officer responsible for the AI’s output.
Data Integrity: The Foundation of Explainability
The effectiveness of any AI system—and the ability to explain its decisions—rests entirely on the underlying data. Kush Mukherjee, Managing Director of Responsible AI at Accenture, summarized the sentiment: "Your AI is only as good as your data." Assurance begins the moment a model is built, depending on the provenance, relevance, and availability of information.
A significant risk identified in agentic AI is its tendency to produce "persuasive" answers even when data is missing. Unlike a human analyst who will stop and flag a missing record, an AI agent may attempt to "hallucinate" or interpolate a conclusion to complete its task. Therefore, modern compliance teams need controls that detect "missing data" rather than just "bad outputs." If a firm cannot confirm when a sanctions list was last updated or from where a specific data point originated, the entire decision-making chain is compromised.
Strategic Implications: Core vs. Chore
As the summit concluded, Paul Kizakevich, President of GTM at ComplyAdvantage, introduced a framework for firms deciding whether to build or buy AI solutions. He suggested that firms must determine if a specific AI application is "core" to their business identity or a "chore" that simply needs to be handled efficiently.
For many, AML and customer screening have become "chores" that require high levels of precision but do not differentiate the brand. In these cases, leveraging established, transparent platforms that offer built-in explainability is often the more "defensible" path. By getting the fundamentals of transparency, data integrity, and human oversight right, financial institutions can move beyond the fear of regulatory scrutiny.
The ultimate goal for APAC firms in 2026 is to transform "control" into "confidence." When a firm can demonstrate exactly why a decision was made, it gains the trust of the board, the auditor, and the regulator. In an increasingly automated financial world, that confidence is the primary currency that allows a business to continue growing without the shadow of regulatory intervention.
Chronology of Key Events
- 2018-2021: Early adoption of machine learning in APAC for basic fraud detection.
- November 2025: MAS issues the pivotal consultation on Guidelines on AI Risk Management.
- January 2026: AUSTRAC implements new AML reforms emphasizing senior management accountability for automated systems.
- March 2026: Bank Negara Malaysia releases updated responsible-AI principles for the financial sector.
- June 2026: The State of Financial Crime 2026 report reveals the 5% gap in APAC AI assurance compared to global averages.
- July 2026: The Future of Compliance APAC summit in Singapore establishes the "Core vs. Chore" framework for AI implementation.



