What Happens When Compliance Catches Up?
.png)
What is the core work of compliance?
Not the task list we know today. Not the endless review, the chasing employees down, the laborious audit preparation. All of this is work that, while it takes up much of a CCO’s time now, will be made far more efficient and easier to manage in the future, as artificial intelligence makes its way into compliance. That’s not the work we’re interested in. That’s not the work compliance will be doing in ten years.
On July 29, Hadrius and World Salon gathered three industry-leading CCOs for a discussion on the real future of compliance. “The Owner of Firm Integrity: Compliance After the Busywork” brought together Colleen Graham (AlTi Tiedemann Global), Robert Molinari (Commonwealth Financial Network), and Robert Ehrlich (Citi Private Bank) for a conversation on what compliance will be doing once the queue clears.
Below are three of the most important takeaways from a fascinating discussion, followed by a complete transcript of the session.
More automation means more compliance
The panel rejected the idea that AI means less compliance. History points the other way. Colleen Graham of AlTi Tiedemann compared it to what spreadsheets did for accounting: routine work got dramatically faster, and experienced professionals became more essential, not less.
Robert Ehrlich of Citi Private Bank pointed out that with every function at a firm adopting AI, every function is producing more material in need of oversight, faster. Compliance has to cover that growth.
Other fields are already further along the same arc. Software development was supposed to shrink as AI wrote more code; instead there’s more code in the world and more demand for people who understand how it works. Radiology was written off years ago and is now one of the fastest-growing disciplines in medicine. Exposure to AI has grown these roles, not hollowed them out.
The same will likely happen in compliance. By the time compliance lives into its true work, the department will likely be larger and more important than it is today.
From cop on the beat to strategic partner
The question at the center of the discussion was what compliance will do with the time it gets back. Graham described moving away from reviewing alerts and checking boxes toward advising senior executives on ethical and reputational risk, reading shifts in employee behavior and leadership tone, and helping shape the character of the firm. That work will always depend on human judgment. A model can flag a pattern, but it can't decide what the pattern means for the institution. Regulators will likely always expect a person to own that call.
This is the core of the “owner of firm integrity” idea. When the office catches up on its backlog, it will be able to act less like an operational function and more like an advisor to the business.
Trust as a competitive asset
Although compliance is a cost center today, a department that produces stronger client relationships, easier partnerships, lower regulatory scrutiny, and a lower cost of doing business is one that creates competitive advantage. With such an “owner of firm integrity” at the table, trust becomes something the firm competes on.
Taken together, the session pointed to a single conclusion. AI will not only increase the scope of compliance’s mandate, it will clear the way for work the CCO was always supposed to do: exercise judgment, protect the firm, and earn trust.
Session transcript
Participants
Leonard DeFranco — Editorial Lead, Hadrius (Moderator)
Robert Ehrlich — Global Head of Compliance, Citi Private Bank & Wealth at Work
Colleen Graham — Chief Legal, Compliance & Risk Officer, AlTi Tiedemann Global
Rob Molinari — Chief Regulatory Affairs Officer & RIA CCO, Commonwealth Financial Network
Leonard DeFranco
Welcome, everyone, to the webinar presented by Hadrius and World Salon, The Owner of Firm Integrity: Compliance After the Busywork.
What we're talking about today is the future of compliance. At Hadrius, we sell agentic compliance infrastructure, which means software built from first principles to use AI to help compliance do their work better. A lot of compliance work is repetitive. It involves a lot of reading, a lot of flagging things, a lot of reaching out to people. These are all things AI can massively scale and, in many ways, do better than humans — before serving it up for human review. This job function has traditionally been about catching up; about a checklist of things to do.
The question I'm posing today is: what happens if, ten years from now, compliance had double the amount of time it has today? If the catch-up mode compliance officers are constantly in were to invert, what is the busywork keeping compliance from doing?
There's a thing that happens with automation where it tends to reveal the core of the work. We see this with coding. Now that AI can write code, we still need developers, but it changes the nature of the work into more architecture than typing. So the question for this group is: what is the core of compliance that gets uncovered once you can handle the work that used to take up most of your time?
One idea I'm energized by is what I'll call the Owner of Firm Integrity. The same way the SEC is the owner of systemic integrity, I wonder whether the compliance office of the future takes on the role of the office in charge of firm health. A regulator sets standards, interprets standards, monitors the market, and holds enforcement authority. It doesn't sit inside firms; it audits them and exercises prosecutorial discretion. If the compliance office becomes a strategic partner, it could do something similar for firm integrity: defining protocols, monitoring the firm with the help of AI agents, and, while it can't throw anyone in jail, exercising judgment, investigating, and stress-testing controls. That's where the name of the session comes from. So the question I want to pose is: do you think compliance will continue to exist as a discrete office? Do you think something like this is in the future?
One thing I want to say off the bat: what we're not talking about when we talk about AI and compliance is less compliance. We've already seen that jobs more exposed to AI grow in headcount. On this chart from an Indeed report, up in the right corner is software development, something people thought would be gone. It turns out there's more code in the world and more need for people who know how it works. Radiology is another good example. There were so many predictions that we wouldn't need radiologists, and it's actually the fastest-growing discipline in medicine right now. As someone who works in the AI industry, if you strip away the terror stories, AI is a tool. It's a quantum leap forward for automation, but it's a tool, and nowhere is that more true than in compliance. You wouldn't trust a machine to make judgments, and you're going to need to govern reps using AI to send marketing emails and the like, so the burden is increasing and the tools available to compliance are increasing. That means compliance is going to become more important. This report from the Bank Policy Institute shows changes in compliance full-time employees from 2016 to 2023; regulatory complexity has increased and will continue to as more AI requires governance. My prediction is that the function is going to get more important, and there will probably be more people in the department, even as each worker and each CCO is able to do more.
With that, my core questions are: what happens when the office catches up? What is the core work of compliance, what would your oversight look like, and what work would you take on if you had 95% more time? And what role should compliance play as a business partner to leadership? I'll address the first question to Ms. Graham. As someone who spans the legal and compliance worlds, could you tell me what you think is the core job of compliance, specifically as distinct from legal?
Colleen Graham
Sure. I'll focus on legal and compliance together, because the answer is largely the same. AI is changing the way legal, compliance, and risk do their work, and I think the future compliance officer, chief legal officer, or chief risk officer is going to look different than today because of that automation. As automation clears the routine work, in the right organization, and that qualifier is important, compliance can help build the firm's integrity across culture, reputation, and counterparty trust.
AI has already changed the way I work. We can review contracts and draft policies in minutes. We can stay abreast of regulatory changes, conduct investigations, and track remediation items in a fraction of the time it used to take. But that raises a real question: what does it mean for our profession? I actually think AI is the best thing that's happened to our profession. It should elevate, not diminish, the strategic importance of compliance. We now have time to understand the business and the economics, to be a partner to the business, and to shift from being a cop on the beat finding problems to a partner who helps shape the institution's character and earn the trust of key stakeholders.
Rather than spending most of the day reviewing alerts and checking boxes, we can advise senior executives on ethical and reputational risks, assess the cultural implications of strategic decisions, and make sure employees feel comfortable escalating. Those aren't things AI can do. There are things AI can't detect that we can, now that the routine work is more efficient: shifts in employee behavior, shifts in leadership tone, emerging ethical concerns. Professionals will have more time to look at the culture and integrity of the firm, making sure the firm is acting transparently, treating customers fairly, and detecting emerging risks. The role becomes less operational and more advisory.
And trust is a competitive asset. Firms with a strong compliance culture enjoy stronger client relationships, easier partnerships, lower regulatory scrutiny, and a lower cost of doing business. You mentioned software development and radiology; I'll give you another one. I think AI will have the same impact on legal and compliance that spreadsheets had on accounting. Routine work becomes dramatically faster, but experienced professionals remain essential for interpreting complex issues, exercising judgment, and making decisions that regulators and clients expect humans to own, not AI. We add measurable value by helping shape the firm's culture and reputation.
Leonard DeFranco
Thank you. I love the spreadsheet analogy. There's that famous example: if you look at a room full of actuaries with their slide rules in the 1950s, each one is basically a cell of a spreadsheet, and the building is the whole spreadsheet. If you took that away, you'd ask what they're going to do, but it turns out the thing they're hired for is the expertise, the larger thinking. So I think we probably all agree automation is a tool that makes the function more powerful. Mr. Ehrlich, you also have a legal background. Do you see any inherent work of compliance that will stay a distinct compliance department, not absorbed by legal oversight?
Robert Ehrlich
I'll start with the disclaimer that all my comments are my own and not those of my employer. With that out of the way, and I might be getting ahead of some of our later questions, the way I think about AI is that there are really three pillars for how it works in compliance. First, your own personal productivity: summarize for me, draft for me. Second, the functions doing repetitive tasks, the automation side that everybody talks about, like a testing function or a surveillance function. And third, which we'll talk about later, our role in helping the business in its own way.
What will always happen is that we'll evolve along with the business as it evolves, because we won't be the only function implementing AI. Everybody across the firm will be. As that happens, volumes increase, and we have to keep up with those volumes. If the business isn't increasing headcount at the rate it used to, because it's automated processes, we still need to cover its increase in a similar way. So you have to strike the right balance of how we use AI, how they use it, and how we keep up with their pace. I don't see it changing the massive size of the department. We may just have to move a few chairs around: this part of testing is now automated, but now we're testing thirty more things, so you can redeploy and look at something else. We're still going to be extremely value-add, and, like Colleen said, we're going to have to use our thinking hats for those higher-value tasks. That's where we'll always come into play.
Leonard DeFranco
Thank you. Mr. Molinari, to you. The question is: do you think this value-add is going to be something new that compliance isn't doing now, or more of the same at a larger scale?
Robert Molinari
I don't think it'll be new. At my firm, I wear two hats. One is very reactive, the chief compliance officer role, and the other is more proactive, the regulatory affairs role. I'll start by saying a misconception about AI and compliance is that the primary value is in reducing headcount. The more profound impact is that it's going to allow compliance professionals to spend less time answering questions and more time anticipating.
A significant portion of the compliance team's work has historically been reactive. We review communications, approve advertising, resolve exceptions, answer advisor questions, and respond to regulatory inquiries. Those activities are necessary, but they're fundamentally driven by someone else's agenda. Regulatory affairs is different. It's about looking toward the horizon, identifying emerging risks, understanding where regulators are heading, recognizing industry trends before they become exam priorities, and helping business leaders make decisions today that will hold up under scrutiny in the future. If automation takes over a significant portion of the reactive queue, compliance's future becomes increasingly concentrated in anticipatory work.
Leonard DeFranco
That brings up this idea of the Owner of Firm Integrity, which you're describing as essentially doing regulatory affairs. Can you talk about what unique insight the compliance department has in doing that proactive work, something you don't think could come from another part of the company?
Robert Molinari
A lot of it is that we have purview into almost everything at the firm. Our firm has multifaceted departments: wealth management, a trading arm, operations. Compliance does the overlay across almost all of it, and that purview helps a lot. It lets us help with predictive analytics and help business leaders make sound decisions today that will stand the test of time.
What does that require? First, a shift in the mindset of compliance professionals, moving from monitoring to predicting. A traditional compliance program is very good at detecting known issues; you build surveillance systems around risks that have already been identified. Anticipatory compliance requires scanning for risks that don't yet fit into a control framework. That means paying attention to enforcement trends, exam priorities, emerging technologies, and changes in consumer behavior. AI can help synthesize enormous amounts of information, but humans still matter, because they have to determine what it all means and apply it to the business.
That leads to my second point. It requires a much stronger partnership with the business we provide oversight for. The most valuable compliance function of the future won't show up after a product is designed. It will be sitting at the table when the product is being conceived. By the time a compliance issue appears in a surveillance report, the strategic decisions have already been made. Anticipatory compliance means getting involved earlier and helping shape those outcomes rather than evaluating them after the fact.
And that leads to where I think the compliance professional of the future adds the most value, which revolves around judgment. This is where the human element remains indispensable. AI can identify patterns, summarize regulations, compare policies, and uncover potential risks. What it cannot do is determine the firm's appetite for risk. It cannot decide how to balance innovation against customer protection, or whether a technically permissible action is nevertheless inconsistent with the firm's values or culture. These are judgment decisions, and I believe strongly that judgment remains human.
Leonard DeFranco
Absolutely. Colleen, how do you think compliance goes about winning that level of partnership so we can begin undertaking what Robert is calling anticipatory compliance? I love that term.
Colleen Graham
I feel very strongly that you need to do two things. First, you need to be at the right organization. There has to be a fundamental respect for compliance and the work that's done, because some of it is routine, whether it's more efficient through AI or not, and they don't always want the answer. So you need to be at a firm that respects and appreciates the value and welcomes the answer and the solutions that come with it. It's important that there's a culture of compliance at the organization in order to become more of a strategic partner as things get more efficient.
The other thing is that we all try hard to train our teams to become partners to the business: understanding the economics, understanding what the business person wants to accomplish through what they're asking you to advise on, and being solutions-oriented. That doesn't mean compromising to the point where someone is non-compliant, but helping them understand what it means to do good business. If you combine that, being in the right organization and being a partner, the shift as AI makes things more routine into more of a strategy role becomes really important.
The last thing I'd say is that in my last couple of roles, at a couple of banks over the last few years, it's been really important to me that compliance has a seat at the table with the most senior people. That's not a power thing. It's evidence that they want the advice and want compliance at the table, because they're very interested in doing good business. I think that's really important.
Robert Molinari
Colleen, you triggered something when you said culture of compliance. One of the things that came to mind is why the people are so important. When regulators examine the firm, they're not simply assessing whether we have controls. They're evaluating whether leadership exercised reasonable judgment. They want to know what management knew, when they knew it, what alternatives were considered, and why decisions were made. Those explanations still require people. You can't do that with algorithms.
Leonard DeFranco
Mr. Ehrlich, what insights do you think the compliance department could offer to build the partnership Colleen is talking about?
Robert Ehrlich
Being at that table, you have insights across the entire firm, and you have to develop partnerships with both the business and the other control functions. It's very hard to do compliance risk in a silo without operational risk, for example. All those partnerships together give you a unique insight into what's happening across the firm, and then you can give the recommendation and guidance early, being there at the product design stage to give that advice.
The other thing, and this is where AI is a nice enabler, is that when you're in that room, you can enable the building of the controls, the monitoring, and the output compliance needs as part of the whole build process. You should never think about compliance as its own side process; it should be embedded in the overall build. If we're building a trading platform, all the compliance rules need to be in the trading platform, and all the monitoring and testing you need, pre- and post-trade, has to be embedded into one design. If you build them in silos, an AI system for compliance over here and an AI system for the business over there, there's going to be a break and we're going to miss something.
That level of engagement with the business and senior leaders is the value-add we bring to reduce compliance risk. This is a prime example of why compliance personnel are still going to be needed. That human in the loop is always going to be in the design. We might have coders that can code faster and products that launch in months instead of years, but we're still going to need people with the expertise to guide the build. If we do it right, end-to-end, in the right partnership, it'll be a better result for everybody, including our external stakeholders, clients, and regulators.
Colleen Graham
Robert, you made me think of something. Communication is key to that partnership. If automation makes things more efficient, you can spend more time communicating. The most successful compliance people I know are the ones who can articulate things in such a way that the business partner comes to the same conclusion themselves. You don't need to advise them one way or the other; you help them understand it, and you share the same goal. It's a bit like, and maybe I shouldn't say this, the way I get my husband to clean up the backyard or take the garbage out: I get him to realize he wants to do it. Getting people to the same place through good communication and partnership, whether it's product design or otherwise.
Robert Ehrlich
That's why staying close to the latest is extremely helpful. Think about the shift that's already happened. It used to be that a problem arose, legal and compliance got together, and you might have needed an outside counsel call; there were all these steps to reach a conclusion. Now the business has already typed the problem into AI and has what the AI said. Legal and compliance, same thing. Outside counsel, if we engage them, same thing. We may have gotten an answer that was a needle in a haystack much more quickly, an exemption to something that would normally have required someone who had focused solely on that topic for thirty years, now easily accessible. Our ability to respond to inquiries and work across functions is also much quicker, and that's a change we already see.
Leonard DeFranco
I want to throw this to the group at large. What would you do if you had double the time? If you had double the bandwidth, what work do you think, a year from now, your department would be taking on?
Colleen Graham
I think it's strategic work: being at the table in product design, getting into it with the business from a strategic perspective. It's interesting, because if you look at how legal and compliance titles have evolved, Chief Legal Officer versus General Counsel, it's because there's a strategic element to it. So there's a lot more we could add with more time from a strategic perspective. That's how I see it evolving, and I love it.
Robert Molinari
I agree. The future model, with that double capacity, and I'm not sure that will ever happen, but we can wish, is going to let compliance be involved in things it needs to be in every day: product governance, technology governance, strategic planning, and, importantly, change management. Not as a reviewer, but as a participant. That's a big difference, because in compliance we're often accountable for outcomes we've had very limited influence in creating. Having the ability to shape those decisions instead of just review them will be fantastic. We've already got the respect of our peers; we just needed the capacity to be present in those rooms.
Robert Ehrlich
I also think most programs are risk-based approaches, so we'd continue going down the list as we clear some of the priorities and tackle other items. There's definitely no shortage of work.
Colleen Graham
I'll add one example of things we've started to do in my group that we didn't always have time for. We're a public company, so we have earnings calls, or the CEO may have a town hall, and we have an opportunity to strategically help shape that dialogue, what the script is, making sure the tone is right and the culture of compliance comes through. There wasn't always time to do that. It's not only more fun, it's real value-add.
Leonard DeFranco
One thing that's interesting about compliance as a strategic partner is that we don't have a lot of precedent for what it optimizes for. A revenue-generating function is always going to be a partner in strategy, and we know what they want: maximize revenue. A product-led organization is ensuring business decisions drive toward capturing market share. Compliance is something I'm not sure we have an easy proxy for, because it has always been a catch-up function, satisfying something external. So what does this group think would be the optimization goal of a compliance function that's actually able to set strategy?
Robert Molinari
Tying in what we've already covered, I'd see the compliance officer of the future spending less time on fact-finding and more time helping the organization navigate ambiguity, emerging risks, and strategic trade-offs, which might ultimately be the most valuable role compliance has ever played. The future isn't just answering regulator questions or yes-or-no questions from our business partners. It's identifying questions the industry hasn't started asking yet and helping our senior leadership peers be prepared for them before those questions come forward.
Colleen Graham
I completely agree, and I'd add that across the three, culture, helping shape the behavior at the organization is totally value-add; reputation, managing the trust premium, how we treat customers, whether we're governing AI responsibly; and, importantly, the strategic differentiator of counterparty trust. As I said earlier, trust becomes a competitive asset, so we can be more competitive in the market with a stronger compliance culture, because we have better client relationships and lower regulatory scrutiny. Those things really add value.
Leonard DeFranco
I love that answer. Trust has never been at more of a premium, and compliance has always been a guarantor of reputation, but it's more important now than ever. We mentioned the regulatory interface. We have a few minutes left, so I'd like to close by asking: in a world where there's this more strategic function, what would you like the regulatory interface to be? What would be the proper type of audit and engagement a regulator would have with you? Should they be asking the same questions, or coming in and auditing your strategy setting? What would you like to see?
Robert Ehrlich
I'd like to have the same tools they use. If we know they're looking at a particular thing in a particular way, having the ability to do the same thing live helps. Think about how SEC audits have evolved. A lot of firms engage consulting firms as external auditors for a period of time to test themselves, because there can be a gap between the last audit and the next. Exam readiness has always been a key topic at large firms and registered investment advisers. In the AI world it'll be the same, and the difference is that both we and the regulators will be able to look at larger bodies of data and find those nuances a lot more easily. It's very important that we're using similar tools and have the ability to do that. That's part of the design I mentioned earlier: when we build products and platforms, we embed a lot of that in there, so we're looking at what regulators care about, what clients care about, and what the rules say as it happens, rather than thinking about it two or three years down the line.
Colleen Graham
I completely agree with everything Robert said, and I'd add to it. I'd like more time and opportunity to become, and I have to be careful saying partners to the regulators, because it's an independent function and they have to be independent, but there's a lot more time we could spend together, and that helps build trust. Some of that is having opportunities with regulators so we can educate each other: them educating us, as Robert mentioned, but also us educating them on how we see things, what we're seeing, and what we're trying to drive toward in the business. With automation and more free time, you can really build that relationship with the regulators, and that is powerful.
Robert Molinari
I agree, and Robert nailed it. How many hours do we waste at the beginning of every exam when they ask a question and we're not sure why, because they're seeing a different data set than we are? They finally get comfortable enough to explain it, we show them what we have, and we translate everything together. A lot of time wasted. I'll say that over the years, and I've been doing regulatory work for about two decades, there's been a convergence of respect. It's less adversarial. People come to the table with more of an open mind, whether that's the SEC, FINRA, or the states, and they want to understand the why behind something. That goes both ways. We want to understand why they're asking for certain things. If it's in the exam priorities, that paints its own picture. But if something comes out of left field, we want to understand where they're seeing it: should we enhance our controls, did we miss something, is there a gap? We're getting to a mutual respect as the years have gone on. Individuals come into play, and some people are easier to work with than others, but that's just personalities.
Leonard DeFranco
It's funny, I was thinking the biggest change would be going from bad guy to good guy. I like the idea Colleen mentioned earlier, going from a traffic cop to something more elevated, a legislator, or a DA, or some equivalent. Understanding around the firm why you're doing it would hopefully lead to less retaliation and a brighter future for the entire department.
I'd like to wrap it up there; this has been a really good discussion. Let me throw it to each of you for any last words about what you hope this department becomes in a future of greater agentic bandwidth.
Colleen Graham
I just hope we become the profession that's welcomed at every table, the partner every senior business person wants, because they feel like they can't live without us sitting next to them.
Robert Molinari
My wish is that compliance ceases to be the function that just finds issues and increasingly becomes the function that helps organizations avoid creating them in the first place. As for how automation will impact our jobs, the most automation-resistant part, as I said before, is exercising judgment under uncertainty. That's where we, as human beings, will remain essential.
Robert Ehrlich
The thing that comes to mind is opportunity. There is immense opportunity for both our work and the business's work to really engage here. If people are a little afraid, what I always tell them is to use it in their personal life: instead of going to Google, try it. Once you get into it, you'll start connecting the dots and it'll make a lot of sense. There's immense opportunity, as people embrace it, to change the way our firms and the industry operate.
Leonard DeFranco
You're referring to AI in general, right?
Robert Ehrlich
AI in general.
Leonard DeFranco
One thing we like to emphasize is that AI can mean a lot of different things. There's generative AI, the kind that can make up facts. Working with it directly helps you realize what it can't do, which is quite a lot. But specifically in the compliance function, what Hadrius sells is much more deterministic. It takes that computational power and puts it in specific places so it's transparent and leaves an audit trail, so you know what it's doing.
This has been a great discussion. I really appreciate the time from each of you: Robert Molinari, Robert Ehrlich, and Colleen Graham. Thank you for joining me, and we'll hopefully continue this discussion going forward. Thank you.
Insights that Move Compliance Forward
Explore new ideas, proven strategies, and technology that’s transforming how firms stay compliant.
We are Hadrius.
Hadrius is built for financial services compliance teams that demand more from their technology. Our privacy-first, policy-aware AI compresses review cycles, eliminates noise, and produces regulator-grade evidence on demand.
One vendor. One system of record.






