Why spot-checking case files can no longer be a compliance strategy – Kotur
The financial services industry has long treated compliance as a capacity problem, as there simply aren’t enough hours in the day to review every single file, so we review a sample, typically around 10%, and call it a ‘risk-based approach’.
Let’s be honest, nobody ever sat down and determined that 10% was the mathematically perfect number to guarantee safety. It became the industry standard for a simple reason: a manual file review routinely runs from under an hour to the best part of two, and at that rate, checking 100% of your cases is financially and operationally impossible. Spot-checking was never a true strategy, it was a workaround dressed up as one.
I recently spoke with a compliance director who told me something that perfectly captures this reality: “We’ve been playing compliance theatre for 20 years. We check the ones we check, everyone knows the game, and somehow we all sleep at night.” Spot checking became the industry standard for a simple reason: a manual file review routinely runs from under an hour to the best part of two, and at that rate, checking 100% of your cases is financially and operationally impossible.
However, artificial intelligence (AI) means this game is ending, and ending fast. Not because UK regulators suddenly decided to get tough, nor because we are staring down the barrel of another financial crisis. It is ending because the fundamental math of compliance has changed.
The new compliance baseline
Moving away from spot-checking isn’t about achieving a flawless, zero-error business overnight. It’s about eliminating blind spots. Checking 100% of your files with an intelligent, assisted framework ensures that systemic issues, outliers, and vulnerable customers are surfaced immediately and not left to chance in the unreviewed 90%.
EPC planning: act now or risk the rush later
Sponsored by BM Solutions
While the next major regulatory shift will take time to fully mature, technology is moving at a pace that could force the industry’s hand faster than many think. Once the market demonstrates that total book oversight is operationally viable, the regulatory expectation will inevitably catch up.
Changing the maths of the file review process
Under regulatory regimes like the Financial Conduct Authority’s (FCA’s) Consumer Duty, the goalposts have fundamentally shifted. You can no longer just point to a clean process, shrug your shoulders at the remaining 90% of unchecked files, and consider the matter closed. Regulators demand that you actively monitor and demonstrate positive, consistent customer outcomes across your entire business.
Historically, manual checking was an expensive, linear resource curve. If you wanted to check more files, you had to hire more people or squeeze your existing team. But when comprehensive checking becomes cheaper, faster, and more reliable than selective checking, the old compromise completely dissolves. This is where AI enters the room, but perhaps not in the way the hype suggests.
The truth is, not everything should or will be automated and it isn’t making broad, sweeping human inferences or subjective judgements. Instead, it works within highly defined parameters to find, surface, and connect information across thousands of pages of data in seconds.
Instead of a compliance officer spending an hour hunting through a file just to verify whether a piece of advice was properly documented, AI discovers and connects that specific context instantly. The compliance team can then shift their energy away from the needle-in-a-haystack search and focus entirely on the human element, judging whether the outcome was right for the client.
AI can identify a vulnerability flag that’s buried in a call transcript that never made it into the suitability assessment, or a document missing from the packaging that a time-pressured sampler would never have reached. It can also check for falsified identity documents and bank statements using advanced tools that analyse microscopic patterns and metadata, ensuring a level of oversight that manual review alone cannot achieve.
We’re also significantly widening the library of checks that run on our core engine, both in the products we cover and the risks we catch. Alongside mortgages, users can expect protection compliance, plus a growing suite of financial crime checks such as adverse media screening, politically exposed person (PEP) and sanctions checks, and appointed representative (AR) checks that give principal firms genuine oversight of their networks. We’re extending into more specialised areas too including vulnerability assessments, offer checks, and social media monitoring.
Rejecting the ‘black box’
If you are going to change how you audit your files, the most critical requirement is transparency, as there is a growing temptation to buy into ‘black-box’ AI solutions, tools where you feed a file into a system, and it spits out a green checkmark or a red flag without explaining why. In a regulated environment, that is an incredibly risky situation. If you use technology in a way where you cannot explain exactly what happened or show your work, you are exposed.
Regulators will not accept ‘the algorithm said so’ as a defence. They will demand to see the underlying reasoning. Any technology integrated into a compliance workflow must be built defensively, providing clear audit trails that point directly back to the source text within the case files. An output nobody can verify isn’t evidence, it’s a second opinion with no audit trail. Curvestone is built to pass it, as the platform displays findings with the reasoning and source evidence attached, a human reviewer approves or overrides, and every step lands in the audit trail. The machine does the reading; the accountable person does the judging. AI should empower human auditors to defend their conclusions, not replace their oversight.
Preparation and anticipation remain the best strategies. The transition from compliance theatre to data-driven assurance is already underway. The firms that recognise this shift early and trade random sampling for comprehensive visibility are the ones that will truly sleep soundly at night.