BUILD, BUY OR ASSEMBLE – A RISK-BASED APPROACH TO AI-ENHANCED COMPLIANCE SYSTEMS

For most compliance teams, the choice is not a binary decision between an internal build and a finished vendor product. The question is what combination of technology, data, controls and accountability the organisation can operate responsibly over time and what suits which use case. The answer depends on the problem it is looking to solve or the opportunity it is looking to grasp.

Corporate compliance teams are looking at artificial intelligence (AI). It may be because there is pressure within the organisation to deploy it or because we are a naturally curious profession, eager to implement systems that can improve programmes, more efficiently identify and mitigate risks, and allocate more routine or time-consuming tasks, freeing up important human capital. The conversation is seductive: faster third-party screening, better monitoring, more efficient investigation triage, smarter policy search, more targeted training and more dynamic risk assessment. The question then arises, should we build internally or buy from a reliable vendor?

Most AI-enabled compliance tools are assembled from layers. A company may license a general-purpose model, connect it to proprietary data, add retrieval and workflow components, configure rules, and place a vendor interface on top. Even a product described as an internal build may depend heavily on external models, cloud services, open-source components and consultants. Conversely, a purchased platform may be so extensively configured that the customer controls much of the system’s practical behaviour, investing time in configuration to achieve desired outcomes.

The question is therefore more complicated than build or buy. It is what to own, what to source, what to configure and even what not to automate.

Oct-Dec 2026 Issue

Sounding Board Compliance LLC