# What an auditor asks about AI in compliance (EU AI Act + AML)

**In short:** auditors ask about AI in anti-money-laundering work the way they ask about any control — what it does, who decided, on what evidence, and can you show it — plus three questions specific to AI: how the system is classified under the EU AI Act, whether a human meaningfully intervened in each decision, and whether every output can be traced to its inputs and explained. The rules behind those questions are the AMLR (Regulation (EU) 2024/1624, notably Art. 76(5) on automated decisions and Art. 18 on outsourcing), the GDPR (Art. 22), and the AI Act (Regulation (EU) 2024/1689, as amended in 2026), whose high-risk requirements apply to Annex III systems from 2 December 2027.

## Key takeaways

- Under the AMLR, AI may support but not replace the decision: onboarding, refusal, exit and changes in due-diligence level need **meaningful human intervention** (Art. 76(5)(b)).
- The decisions on a customer's risk profile and on entering a relationship **cannot be outsourced**, to a vendor or its model (Art. 18(3)).
- Customers can obtain an **explanation** and challenge a decision — except in relation to a suspicious transaction report (Art. 76(5)(c)).
- The AI Act's **high-risk requirements** apply to Annex III systems from **2 December 2027** (Regulation (EU) 2026/1744). Annex III does not list AML customer due diligence as such; classification depends on the intended purpose.
- **AI literacy** (AI Act Art. 4) has applied since 2 February 2025; **transparency** to people interacting with AI (Art. 50) since 2 August 2026.
- The strongest evidence is a **per-decision record**: the inputs, the AI output, the human decision, and the reasons.

## Which rules apply

| Rule | What it requires | Applies from |
|---|---|---|
| AMLR Art. 76(5) | Automated or AI-assisted decisions: data limited to due diligence data; meaningful human intervention; explanation and challenge | 10 July 2027 |
| AMLR Art. 18 | Outsourcing: supervisor notified, firm fully liable, some decisions never outsourced | 10 July 2027 |
| AMLR Arts. 20(4), 21(3), 77 | Demonstrate appropriateness; record decisions and justifications; keep five years | 10 July 2027 |
| GDPR Art. 22 | Limits on decisions based solely on automated processing | 25 May 2018 |
| GDPR Art. 35 | Data protection impact assessment for high-risk processing | 25 May 2018 |
| AI Act Art. 4 | AI literacy of staff (reworded in 2026) | 2 February 2025 |
| AI Act Art. 50 | Tell people when they interact with an AI system | 2 August 2026 |
| AI Act Chapter III, Sections 1–3 | High-risk requirements, including Arts. 12, 13, 14 and 26 | 2 December 2027 (Annex III) |

Until 10 July 2027, national rules transposing Directive (EU) 2015/849 apply instead of the AMLR, but a firm preparing for 2027 can already use the AMLR as its reference point.

## The first question: what is it, and is it high-risk?

**Is it an AI system?** The AI Act defines an AI system by its ability to infer, from its input, how to generate outputs such as predictions, recommendations or decisions (Art. 3(1)). Recital 12 states that the definition should not cover systems based on rules defined solely by natural persons to execute operations automatically. A compliance tool often contains both: fixed rules and inferring models. Document which is which.

**Is it high-risk?** Annex III lists the high-risk use cases. It does not list anti-money-laundering customer due diligence as such. Point 5(b) covers creditworthiness assessment and credit scoring of natural persons, "with the exception of AI systems used for the purpose of detecting financial fraud", and recital 58 adds that systems provided for by Union law to detect fraud in financial services should not be considered high-risk under the AI Act. Point 1(a) covers remote biometric identification but excludes biometric verification that only confirms a person is who they claim to be. The classification of a particular system depends on its intended purpose. A provider that considers an Annex III system not to be high-risk must document that assessment (Art. 6(3) and (4)).

**Who is who?** The vendor is normally the "provider" and the payment institution the "deployer" (Art. 3(3) and (4)). The AI Act duties differ accordingly; the AMLR duties stay with the institution either way.

## The questions auditors ask

### 1. Which AI do you use, where, and for what?

An inventory of every AI-assisted step: its purpose, the vendor, the version, the data it uses, and the decision it feeds. Auditors test whether the inventory matches what actually runs.

### 2. Who makes the decision?

AMLR Art. 76(5)(b) requires that any decision to enter into, refuse or maintain a relationship, or to increase or decrease due diligence, be "subject to meaningful human intervention to ensure the accuracy and appropriateness of such a decision". Auditors look for evidence that the person could assess the output, not only accept it: what they saw, what they changed, and how often they overrode the system. The AI Act's description of automation bias (Art. 14(4)(b)) is a useful yardstick even where Art. 14 does not formally apply.

### 3. Can you trace each output to its inputs?

The AMLR requires records of due diligence actions, decisions and their justifications (Art. 21(3)), kept for five years (Art. 77). For high-risk systems the AI Act adds automatic logging (Art. 12) and, for deployers, log retention of at least six months; financial institutions keep those logs as part of their financial-services documentation (Art. 26(6)). The practical test: pick a decision from last year and reconstruct which sources went in, what the system produced, and who decided.

### 4. Can you explain a decision — and when must you not?

Under AMLR Art. 76(5)(c), a customer may obtain an explanation of an automated or AI-assisted decision and challenge it, except in relation to a suspicious transaction report, where the prohibition of disclosure applies (Art. 73). Under the GDPR, Art. 22 limits decisions based solely on automated processing; in Case C-634/21 (*SCHUFA*, 7 December 2023) the Court of Justice held that a credit agency's automatically established credit score is itself such a decision where a third party to which it is transmitted "draws strongly" on it to establish, implement or terminate a contractual relationship. For high-risk systems, AI Act Art. 86 adds a right to an explanation, but only to the extent that Union law does not already provide one (Art. 86(3)) — and AMLR Art. 76(5)(c) does.

### 5. What data does the AI use?

AMLR Art. 76(5)(a) limits automated decision-making to data obtained through customer due diligence. Art. 76(2) and (3) set conditions for special categories and criminal-offence data, including procedures that distinguish allegations, investigations, proceedings and convictions. Art. 76(4) prohibits processing for commercial purposes.

### 6. How do you control bias and error?

AMLR Art. 76(2)(c) prohibits decisions leading to biased and discriminatory outcomes on the basis of special-category data. Auditors ask how the firm tests for false negatives (missed risk) and false positives (unfair refusals), and how changes to the system are approved.

### 7. Who is the vendor, and what have you outsourced?

AMLR Art. 18 requires prior notification of outsourcing to the supervisor, leaves the firm fully liable, and requires it to demonstrate that it understands the rationale behind the provider's activities (Art. 18(2)). It requires a written agreement and regular controls (Art. 18(4)). The decision on a customer's risk profile and the decision to enter into a relationship can never be outsourced (Art. 18(3)(c) and (d)).

### 8. Are your people trained?

AI Act Art. 4, as reworded by Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the AI literacy of their staff; it does not require any particular level to be reached by each individual.

### 9. Do people know when they are dealing with AI?

AI Act Art. 50(1): systems that interact directly with people must be designed so that they are informed they are interacting with an AI system, unless that is obvious. This applies, for example, to an assistant in a customer portal.

## An evidence pack that answers them

1. An AI inventory with intended purpose, role (provider or deployer) and classification reasoning.
2. Per decision: sources and inputs, the AI output, the human decision-maker, the decision and the reasons.
3. Override and escalation statistics, reviewed by the compliance officer.
4. The vendor agreement, its instructions for use, and your controls over it.
5. The data protection impact assessment and the Art. 76 conditions for sensitive data.
6. Training records for staff who use or oversee the system.
7. The customer explanation process, and its exception for suspicious transaction reports.

## Frequently asked questions

### Is our KYB or AML tool a high-risk AI system?

Not automatically. Annex III does not list AML customer due diligence as such, but the answer depends on the system's intended purpose — for example, whether it evaluates the creditworthiness of natural persons or performs remote biometric identification. Take the provider's documented assessment and your counsel's view.

### Do the AI Act's high-risk rules apply now?

No. After Regulation (EU) 2026/1744, they apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. AI literacy and the prohibitions already apply (two prohibitions added in 2026 apply from 2 December 2026), and Art. 50 transparency applies from 2 August 2026.

### Is "a human in the loop" enough for the AMLR?

Only if the intervention is meaningful — able "to ensure the accuracy and appropriateness" of the decision (Art. 76(5)(b)). A reviewer who cannot see the evidence, or who approves everything, does not meet that test.

### Is a rules engine an AI system?

Rules defined solely by people to execute operations automatically are outside the definition, according to recital 12. Models that infer their outputs are inside it. Many tools combine both.

## Where ProofVolt fits

In ProofVolt, every AI-assisted output is traceable to its inputs, and an officer decides. Website checks follow fixed rules, not a model's judgement. No later document, round or AI output can quietly clear a risk. Every conclusion appears on the case's receipt with its source, every source, step and decision is kept in an append-only trail, and approvals can require a second pair of eyes where the risk requires it. These are product capabilities that help you answer the questions above; they are not a statement about how ProofVolt is classified under the AI Act.

## Related

- [EU AI Act](/glossary/eu-ai-act/)
- [Four-eyes principle](/glossary/four-eyes-principle/)
- [Tipping-off](/glossary/tipping-off/)
- [AMLR](/glossary/amlr/)

Canonical: https://proofvolt.eu/guides/auditor-questions-ai-in-compliance/
