|
Credit unions and vendors move beyond using artificial intelligence as a research tool and into operational compliance management. By Marc Rapport Contributing Editor Key Points
As artificial intelligence (AI) adoption accelerates across financial services, credit unions are beginning to test where the technology can provide practical value inside governance, risk and compliance (GRC) operations. Much of the early focus has centered on reducing the burden of monitoring hundreds of regulatory updates at a time by creating more structured workflows for documenting decisions and assigning accountability. For many institutions, the challenge is not simply understanding a new rule, but determining whether it applies to their charter, product mix and operational structure. Ogie Sheehy “We are currently leveraging AI in a targeted and controlled way to help monitor and filter regulatory updates across multiple sources,” said Pamela Buttles, vice president of enterprise risk management at $2.8 billion Capital Credit Union in Green Bay, WI. “Importantly, AI is used in initial filtering and research, not as a final decision-maker.” Building Structure Around Regulatory Noise The pressure on compliance teams has intensified as regulatory expectations continue shifting while staffing and budgets remain constrained. ViClarity Global CEO Ogie Sheehy said that reality helped shape his company’s AI-focused Reg Monitor platform. Sheehy founded ViClarity in 2008. Based in Kerry, Ireland, the company also has offices in Boston, MA, and West Des Moines, IA, and provides GRC management solutions to a global list of clients in highly regulated industries such as financial services, health care and insurance. The challenges are many. “GRC leaders are asked to do more with less – less budget, fewer human resources and in some cases, a smaller amount of institutional knowledge and experience caused by constant turnover,” Sheehy said. He added that deregulation has also complicated compliance work because institutions still must document decisions even when rules are rolled back. The software is designed to scan regulatory sources and narrow updates based on factors established by ViClarity consultants and clients. According to Sheehy, the system can be configured around charter type, field of membership, asset size and activities such as member business lending or CUSO involvement. Buttles described using AI in a similar way at her Wisconsin shop. The 128,000-member cooperatives uses AI tools to aggregate updates from regulators and industry groups and to gather outside interpretations and examples of how peer institutions are responding to regulatory changes. Pamela Buttles From there, compliance staff still make the final determination. “Human review is built into how we use AI by design,” said Buttles, who has been in her post for four years. “We treat AI as a tool within our compliance framework, not as a substitute for judgment, experience or institutional knowledge.” Turning Regulatory Updates Into Workflows While many AI products focus on summarizing information, Sheehy and Buttles both emphasized execution and accountability as the larger operational challenge. The goal is not simply identifying a regulatory change but translating it into concrete tasks that move through the organization. Sheehy said Reg Monitor provides a summary of the change and then generates more detailed analysis, including actionable takeaways and items credit unions should evaluate. “From there, the ViClarity user would set up a workflow to include who needs to do what and by when,” he said. The platform can then route responsibilities across business lines, legal, lending and member experience teams while documenting progress through completion. Sheehy said workflows are configurable based on the size and experience level of the institution’s staff and board. Buttles described a comparable process after AI flags a potential regulatory change for Capital. Compliance and risk teams review the AI-generated summary, determine applicability and assign ownership to the appropriate department or subject matter expert. “The individual or team responsible for that regulatory area takes ownership of the change,” Buttles said. “They are accountable for validating the requirement and its applicability to our size, charter and product mix, and for communicating the change to relevant stakeholders.” The enterprise risk manager said that AI helps organize and surface information more quickly, but policy updates, procedural changes, training requirements and implementation decisions still remain people-driven. That distinction has become increasingly important as regulators continue scrutinizing AI governance and oversight practices. Audit Trails, Oversight And Human Review Another major focus area for AI adoption involves audit readiness and documentation. Compliance departments often face pressure to demonstrate not only what decisions were made, but why they were made and how follow-up actions were completed. Buttles said AI has strengthened documentation processes by helping identify risks, summarize impacts and organize decision records. “AI improves visibility and structure, and human review ensures the audit trail remains accurate, defensible, and actionable,” she said. ViClarity’s platform similarly emphasizes traceability throughout the workflow. Sheehy said audit-ready workflows involve measurable questions aligned with specific regulations and business processes, with evidence collection built into the process. “Areas of non-compliance are identified by the software and clearly flagged with a full audit trail to show the details,” Sheehy said. “The software fully tracks and monitors action from outset to closure.” Both organizations stressed that governance controls around AI use remain critical. Capital said it evaluates AI vendors through existing third-party risk frameworks and incorporates AI usage into cybersecurity audits and risk assessments. The credit union also limits approved tools and requires employees to verify outputs before using them operationally. That oversight extends to preventing overreliance on automated outputs. “Professional judgment remains key,” Buttles said. “Our team uses AI for added context, factoring in history, risk appetite, member base and past situations.” A Growing Role In Compliance Operations AI’s role in compliance management is expected to expand significantly during the next several years, though neither Buttles nor Sheehy see the technology replacing experienced compliance professionals. Instead, they anticipate more automation around monitoring, task management and workflow coordination while human reviewers remain central to interpretation and governance. Buttles also expects AI tools to become more tailored over time as systems learn more about organizational structure, product offerings and prior compliance decisions. Even so, staff education and responsible use standards will remain essential as adoption expands. People will be watching. “Demonstrating responsible AI use with proper oversight and governance will be an important aspect of our approach to AI utilization,” Buttles said. “We have to be able to clearly explain our methodologies and decisions to leadership and regulators.” Sheehy, meanwhile, said the pace of change around AI already has accelerated dramatically. “Even a year ago, the conversation was about whether to use AI at all,” he said. “Now, we’re seeing rapid escalation of implementation projects and a lot of promise for the technology when it’s implemented with good security and people-centered responsibility.” ViClarity expects AI to continue evolving across governance, risk and compliance operations, particularly in areas where automation can reduce operational burden without creating additional risk exposure. Still, Sheehy said his company believes experienced compliance professionals must remain at the center of decision-making. “There’s a lot of chatter about having a ‘human in the loop,’” Sheehy said. “We think it’s critical not just to keep experienced compliance professionals ‘in the loop,’ but to allow them to lead, bringing their knowledge and human intellect to the forefront of anything AI will do to optimize GRC talent.” Buttles concluded, “If we keep AI positioned as one tool within our broader compliance framework, supported by strong processes, trained staff, and clear accountability, we can improve efficiency without losing the oversight and rigor our environment requires.”
0 Comments
Leave a Reply. |
Archives
July 2026
Categories |


RSS Feed