The following is the transcipt of a podcast episode Joseph Martin on how AI is transforming AML processes in compliance between Carmen Cracknell, GRIP senior reporter, and Kinectify founder Joseph Martin.
[INTRO]
Carmen Cracknell: Joseph, thank you so much for joining us on The GRIP Podcast. Can you please introduce yourself and your background to our listeners?
Joseph Martin: Yeah, absolutely. Thanks so much for having me. It’s really great to be here. I listened to a number of the podcast conversations and always thought that they were really thoughtful and interesting. So I’m really looking forward to this one and excited to dig into the discussion today.
I didn’t really come into AML through a conventional compliance career. I came through national security intelligence and investigations and I’ve worked in AML in some of the highest risk areas in banking and in the casino gaming industry. Throughout my career, I’ve really bounced between being in regulated institutions, doing the work as an AML professional and building regulatory technology to solve these problems.
So I started in the Marine Corps fresh out of high school and then I studied the Middle East and Arabic and eventually worked at the State Department on Middle East issues during the Arab uprisings and later doing diplomatic and humanitarian initiatives related to the war in Syria. And then when I transferred to financial crime, I went into the investigations and the enhanced due diligence side, largely due to my background in expertise in languages and intelligence related work.
So I worked with firms like Kroll and Exiger during these conflicts, enhanced due diligence and financial crime work for these larger institutions. And then I’ve also been an AML officer at a financial institution helping set up a cannabis banking program in the United States. And then I worked in casino AML at Caesars Entertainment in the gaming industry.
On the regtech side, I’ve kind of straddled the fence between being an AML practitioner in these organizations and then working on the reg tech side. And at reg tech, I worked at Kharon, a global sanctions investigations company and then hyper cannabis payments and AML company. And then like I’ve formerly mentioned Exiger, helping set up their enhanced due diligence programs, which we transitioned into technology. And then now they pivoted that into supply chain risk management and done some pretty impressive things with that technology.
So like I said, I’ve really straddled this world of being a practitioner and working on the regulatory technology side. And ultimately about five years ago I launched Kinectify to bring these worlds together, to bring all my past experience really together into a technology platform that really focuses on intelligence, financial crime technology geared towards pointed towards higher risk industries.
And we started with the most complex high risk industry in the United States, which is gaming, sports betting, casino industry. And we’ve done really well at it. It’s been an incredible journey so far.
Carmen Cracknell: Amazing. So yeah, that’s such an interesting background that you’ve come from with working at the State Department. And given that you have that national security and diplomatic background, how do you think that’s shaped the way you see financial crime risk versus someone from a more traditional compliance background?
Joseph Martin: Yeah, it’s really shaped me enormously. In national security, particularly working on something as complicated as the Middle East, you quickly learn that you rarely have perfect information. You’re trying to understand actors, you’re trying to understand relationships, motivations, behavior, and really context around these complex issues with lots of disparate pieces of information that you’re bringing together.
So you tend to start with the threat first, and then you work backwards. And you ask questions like who are the actors, what are they trying to accomplish? What vulnerabilities are they trying to exploit? What information can help us understand what is actually happening? And traditional compliance can sometimes work completely opposite. We start with the regulation, and then we build a procedure around it. And then we measure whether the procedure was followed. And we’re looking for the procedure.
And so I would say that with traditional compliance, those controls matter, and that procedural compliance is not necessarily the same thing as running an effective compliance program. And regulators are now expecting true risk detection and risk management, especially in environments like in the US gaming industry. And you see this in Europe and other environments too, where you have dual regulatory regimes.
You might have the federal government, the national government, looking from a certain perspective. And then you have local regulators, you have your control boards or your gaming commissions. And they’re wanting to protect the integrity of the industry. So you’re going to have regulations there, and people involved at that level. And they’ll even publicly say that they want to keep the national government out of their proverbial tent. They’re like, we really want to manage our industry and the integrity of our industry at a local level.
So you’re dealing with these dual regulatory regimes. When you do that, the quality of the risk management really matters. Are you identifying the threats? Are you managing your risk? And that’s where regulators are moving to. We know the technology exists. We know you’re capable of identifying risk and managing it, where compliance people traditionally run more capacity-based programs. And they’re like, I have a certain amount of people. Here’s the regulations and writing. I’m going to write procedures. I’m going to make sure everyone follows the procedures. And so these worlds are starting to go in these opposite directions, and the gap is really widening. And you’re seeing more regulatory action because of it.
Carmen Cracknell: Yeah. So that was going to be one of my next questions, actually. Traditional compliance and AML systems are struggling to keep up with the pace of technological change in AI. Are they addressing the gaps and how?
Joseph Martin: Yeah, I think that’s a difficult one. I think one of the bigger problems is that much of compliance, like we talked about just now, is that you are processing a lot of information. And the team is really tooled around information processing. And that’s not really the fault of compliance officers and compliance teams.
Technology always promised this world where technology could handle the information processing and humans could make decisions. But technology was never able to really deliver that until now. And technology wasn’t advanced enough. So we had these 90% plus false alert rates. And you had all this noise in the system that you had to deal with. And so what humans ended up doing is getting the old trusty spreadsheet out. And they’re collecting all of this information.
And they’re putting it all together and formatting data. And you have these really big teams that turn into these assembly lines of processing information. So if you think about the typical workflow, especially around transaction monitoring, you might have an alert that gets generated by a system. It might be a rule-based alert, or it might be a machine learning model produces an alert.
And then once it’s generated, you have to review those transactions. You might open a case. And then the person is pulling information about the customer, gathering documents, looking at the formal historical activity. And they’re doing all of this analysis, pulling in all this information, formatting it all. And so when the workload has increased, if you launch new services at a bank, you’re very successful with the new type of payment processing or something, you have a lot more transactions coming in or at a casino, you launch online sports betting or whatever it is. And you have a lot more customers, a lot more transactions, you’re just adding headcount. And the headcount is being added incrementally to the volume of work that’s coming in. And sometimes you don’t get the headcount, right? So you just do less work and you’re exposed on the risk side.
But what we’re seeing now is that technology can handle almost all of this information processing now. It can collect the information. It can connect the information. It can summarize the information. It can find the patterns. It can populate the regulatory reports. And so humans are really now positioned where they can be the risk decision makers.
One of the biggest gaps, though, in problems is that’s not how the team is tooled. So it’s not how your SOPs are written. It’s not what the compliance team skill set is a lot of times. And we’re seeing this when the technology gets implemented. We’re like, here’s a bar chart of structuring. And all you have to do is decide if you think it’s structuring or not. You have the visual analytic. You have all the data gathered for you. You have the relationships all mapped out. Click one of two buttons. Is it not structuring or it is and you’re going to file a regulatory report?
Right. And is your team capable of making that decision? That’s the question. Because a lot of teams aren’t. They’re not very comfortable with that. They’re like, well, my job was to gather the information and format it. And then I passed it on to the next person who reviewed it and went to the next and went to a committee. And like, you have this whole assembly line where no one’s really individually held accountable for making a decision. They’re just following a process. And sometimes they don’t understand the process.
They don’t understand what risk actually looks like. And that’s really where things are getting choked up when you’re talking about these transitions and these gaps. Is your team tooled? Are they skilled with AML? Do they know how to look at information and make a decision and are they capable of making that decision? And we can all talk about tech companies. I mean, some are slow and some aren’t adopting the new technologies. Those tools aren’t available in every industry yet. But I guarantee you, it’s highly likely in the next coming years, they will be. Tech companies will catch up. The technology is going to get integrated into the tools that you have. And the question is, is your team ready for it?
Carmen Cracknell: Yeah. And I guess a big part of that is AI, right? And obviously, AI has been the buzz term for a while now and it’s predicted to transform all industries. What is the effect on AML processes of AI, do you think?
Joseph Martin: Yeah, that’s a really popular question. And I like to counter it with, how does the internet, how does the internet change the business? Like, how has the internet changed your business? Like, what is the impact of the internet on AML? Like, can you imagine a world of doing anti money laundering without the internet? Like, I can’t even imagine a bank operating without the internet or a casino operating without the internet.
It just like literally wouldn’t work if you went to just a paper and pen for every single thing, you didn’t have a single database or a single system. And that’s really the world we’re moving into. Most of the technology leaders today and even former technology leaders like Bill Gates, this is as foundational as internet infrastructure.
So AI runs through everything, right? And a lot of people talk about productivity, right? They’re talking about false positives on alerts and drafting narratives and doing all of that. And I think that’s the least interesting part. That’s the low hanging fruit. Of course, yeah, I can draft those things and do all those things. And those things are important. But I think it’s one of the least interesting parts. Really, change is how it enables us to continuously synthesize enormous amounts of information.
If you think about a bank, and you think about like back in the 80s, how a bank ran, compared to today, it’s all about data collection, right? And we’ve gotten really good at collecting data against account numbers and having this world in which we’ve never had access to more data on our customers than we have today. Because it’s all gathered, right?
And in the gaming industry it’s the same way. It’s like, in pretty much every industry, they’ve gotten so good. Gaming used to be – put coins into a slot machine. And nothing was tracked, right? Because you just have people on the floor putting coins into a slot machine, then they moved into digital vouchers, loyalty programs, or tracking all this information to issue loyalty programs and things that manage these programs. So they’ve collected all this information. The question is, what do you do with it?
Regulators are like, you have the information, right? But as you know, as a compliance professional, and, you know, most compliance professionals you ever talked to have a history of it, you’re like, I literally don’t have enough staff or time to go through billions or trillions of data points. And even if I did, even if you gave me an army of 1,000 people or more, we still can’t go through a trillion data points and make any sense of it, right? You’re just scratching the surface. So that’s really what’s exciting about this new technology.
It’s not just AI, but it’s things like graph databases, they can go and link all these relationships and visualize them. It’s it’s moving away from SQL databases into the new forms of databases coming out, where you can synthesize billions and trillions of transactions, AI is integrated into that process, you can make sense of it, and you can actually work from a world of intelligence, where you’re like, I’m gathering all this information, I’m bringing in enriching it with public information, all this adverse media, all this sanctions and all this other stuff.
And now I’m presenting intelligence around these players, or these customers. And I think it’s the first time where technology is at a place where it’s able to actually do that. It’s been the promise technology for a long time, and it hasn’t delivered. But now technology is at a place where it can deliver these capabilities. A lot of compliance officers always think about automation, automation, automation, and they’re like, I just wanted to do all the work for me. I think about it very differently.
I mean, humans make the decisions, and they need to be skilled, and there needs to be control and governance. But technology can do all the information processing. And when we think about AML, it’s probably 90%, 95% information processing. It’s all the stuff we’ve been talking about, gathering information, formatting information, populating forms. And you take that away, then you’re left with the important part of the job, the most important part of the job, which is that 10%, that 5-10% of making these decisions. And I think that’s the exciting future when you’re talking about AI.
Carmen Cracknell: Yeah, exactly. So you mentioned transaction monitoring. So what you think entity-based risk detection means in practice? And how is it different from transaction monitoring? And how can compliance teams adapt to that?
Joseph Martin: Yeah, that’s a really great question. You’re seeing this around the world from regulators saying we need to run risk-based AML programs. Compliance people, I don’t think they comprehend yet what that means. And the reason I say that is compliance people are so trained on capacity-based AML programs. And what I mean by that is they say, like I said earlier, they look at the regulation, and then they’re like less designed procedures. This is my head count. And this is how much work I can get done with my head count. And then they justify that work by saying it’s risk-based.
But what they’re doing is justifying their capacity, right? And regulators are like, no, no, no. What you need to do is you’re offering all your services, you need to go identify the risk and manage it. Don’t worry about the low risk and the medium risk stuff. Go concentrate your resources on high risk and manage your risk. And that’s what they’re really expecting here. And entity-based goes along with that. When you’re talking about capacity-based programs, you do things from the outside that look silly. But from the compliance perspective, they make sense because you’re dealing with limited, finite resources.
You do things like separate your credit card AML. And you’re like, this is my credit card team. They just look at credit card type processing. And that’s all they do. They don’t look at anything else, and this is my other team. And they’re going to look at chargebacks or things that look like fraud and see if there’s nexus to AML or whatever it is. And you divide up your services. Here’s my depository count teams and things like that. And gaming is the same way.
They’re like, I’m going to have an alert that just looks at this one analytic on a slot machine. And I’m not going to worry about what the player did on a table games because I got another team over there looking at what’s going on the tables. And I got another team over there looking at what’s going on online. And so you have one player, though, that’s not how people transact with the business. You have a player or you have a customer like at a bank, and they’re transacting across the portfolio assets. I own a house, I have a mortgage, I have a car loan, right? I have multiple credit cards, I have multiple accounts, and I’m transacting in all of these different ways.
And if I’m doing something suspicious, I’m likely doing it across multiple channels, right? And all that information being collected. So entity based is more like looking at that person and seeing all of their activities across your portfolio across your entire business, and seeing what looks suspicious about it, and servicing that risk and running a more risk based program. And that’s a difficult thing to do. Traditionally, but technology can do that. You can bring all this data in because it’s all collected, you can format it, sometimes not a very easy exercise to get it all in and format and do the integration work.
But there are new technologies coming out to make it easier and reduce the friction in that area as well. But that’s the key is like getting a good technology partner building it in house where you’re collecting all you are, you’ve already collected information, you’re using it now, you’re feeding it into the models, you’re feeding into the system. And you’re changing your thought perspective to say, I’m going to look at the person or the person, and we’ll look at all their activities across all of my portfolio and I’m going to identify risk. And what we’re seeing is when we do this in the gaming industry, you’re seeing a huge reduction of false positives and noise.
Because I might play on a slot machine and I don’t gamble very much like I put a whole bunch of money to the slot machine. And I press the button a few times and I lose money. And I’m like – I’m not lucky on this machine. So I’m going to go play over at Blackjack. And then I’m going to have better luck and they have a little better luck. And then they leave the casino. And before, traditionally, you would have an AML alert on the slot machine.
And you would have been like – they put a bunch of money in and they didn’t gamble very much. And then it would take them a while to figure out, oh, they gambled over here on the table games, because now the team handles that or whatever. It’s another alert, it’s another area of the casino. And now when you look at the person, it doesn’t even generate an alert because you’re like, they didn’t do anything suspicious. They just switched the game that they were playing. And that’s very applicable to banking as well. Or any business that has a multi-channel environment, you really need to look at the person and then analyze from that perspective.
Carmen Cracknell: Yeah. So since you have worked across these different industries like gaming and gambling, cannabis, and now compliance, what commonalities do these industries and sectors share in terms of financial crime? Or are they just completely different in terms of risk?
Joseph Martin: Yeah, they are, when you get into the details of the actual transactions, they can look different. But the motions are the same. And so it’s very, very common. And if you talk to an AML officer at a bank and an AML officer at a casino, we’re talking about the motions and the teams they set up between enhanced due diligence and risk scoring and sanctions and all those in transaction monitoring and the workflow between alert and a case and a SAR or whatever your federal filing is, whatever country you’re in, it’s the same workflows. And it’s the same types of things you’re looking at.
But the transactions are different. The typologies are different, obviously. And one of the biggest differences that banking people struggle with when they go into some other industries is at a bank, you don’t worry about customer friction as much because you own their mortgages and stuff, right? Like you have like stable relationships. So you can add paperwork on friction on the because as a compliance person, you’re not really thinking about customer service, you’re thinking about how do I protect the financial institution?
And I need to gather this information and do this work to be able to meet our regulatory requirements and expectations, right? But when you go into the entertainment industry, and a lot of other businesses, the insurance industry, maybe has a little bit more stability, but a lot of other industries like, especially the gambling industry, sports betting, online gaming, brick and mortar gaming, casinos, all that, it’s an entertainment environment. People don’t have to gamble there.
And so if you start adding friction to the experience, they’ll just leave and they’ll go gamble somewhere else, right? And so there is differences in culture where it’s really important, technology is even more important in some of those areas to say, are we gathering the right information? Are we doing the right investigative work? Do we have the right tools? Do we understand the right typologies? Because if we have a 90% false alert rate, and I’m asking follow up questions to 90% of my customers that are doing nothing wrong, and I’m asking for their source of funds and their tax filings, all this other stuff, they’re just going to leave, and they’re going to go to the next casino down the street or go online to another online gaming operator that’s very competitive.
So you know, you get more of that executive pressure and the executive pressure compliance people are tempted to be like, oh, we have a poor culture of compliance. You’re like, you don’t, you’re in a customer service environment, you’re in an entertainment environment, so 90% false alert rate is actually very bad for the business, and you can lose significant revenue. And so that’s, I think that’s kind of an interesting thing is like, they’re very similar in so many ways.
But then when you get into the nitty gritty of the typologies and how the work is conducted, they can be quite different. I guess one other thing I would say is also the human intelligence is really interesting. In certain types of industries like the gambling industry, they spend their money at the business, like at the casino, and you don’t get that at the bank. So you get to watch them spend their money. So you have this added element of human intelligence, which I think is fascinating, and it really informs the risk and how you manage it.
Carmen Cracknell: That makes sense. Yeah. How effective do you think public private collaboration on financial crime is? And are businesses getting what they need from law enforcement and vice versa?
Joseph Martin: Yeah, I think that’s always a complaint is law enforcement sometimes isn’t as transparent with what they need and how they’re using the information. And sometimes I could feel like you’re putting these reports into a black hole and they’re not being used. There’s more initiatives around the world now. They’re trying to give percentages of when we investigate something, how many end up in a successful prosecution, and it’s a really high percentage usually when these federal filings for these financial institutions are involved.
And so that’s encouraging, but at the same time, you know, that feedback loop is something that I think compliance people really value, because they want to know that they’re doing something that means something with all of this, all this work, all this risk management work that they’re doing. So I think that can always be worked on and improved. I do think that like, uh, that, yeah, I just think that the collaboration is incredibly important. And sometimes it can feel a little bit asymmetrical, like we’re submitting reports to the government, and then we don’t really know where those reports really go.
But I do think that there are a lot of countries, especially in the United States, we do have frameworks for more information sharing. Like we have the three 314(b) regulation, US Patriot Act that allows information sharing amongst financial institutions. And that’s really a government supported program. And I think some of those programs can be underutilized, like you submit an information request, and then there’s a really high chance you’re not going to get a response back. And so people quote percentages that are like 80, 90% or more that you don’t get a response back.
And I think some of that stuff is unfortunate. It’s an area where collaboration is extremely important, where information sharing could be is underutilized. And it could be used because you can pick up a lot of risk signals from these information sharing programs that the government set up. So you can share information on customers across industries and things like that. And I think local regulators have a huge opportunity where AML is typically a federal government or a national level issue, where the regulations are coming out of the central governments often.
And then sometimes local regulators will get out of the game and just be like, well, I’m not going to really collaborate or be that involved. But then bad things happen and you know, the federal government come down, like we talked about before, and the local regulators get embarrassed, or I don’t know the right word. They’re like, well, we’re supposed to be the ones regulating this industry and protecting the integrity of it. And you’re seeing some of them get more involved now. And in that collaboration is really incredibly important between the public private sector, even on the local level, it’s very important.
Because we can really improve the services. I think one thing I hear repeatedly when you go to ACAMS and other types of events is law enforcement repeatedly saying, we wish we had more color in the reports, we wish you wrote more, we wish you gave us more information. It complies people, we’re like, there’s only so many hours in the day. And I think we talked about AI and information processing, I think that’s really changing things too, where now we can give them a lot more color that they’ve been wanting, because there is time that the systems can do the information processing and draft a lot of that narrative writing. And I think that’s been something cool that we’ve seen at Kinektify, is the feedback that we’ve gotten from, they can’t say too much, but they can be appreciative to say, hey, these stars are really good, this information is really good, it’s a lot more robust than we’ve seen before. And a lot of that’s just due to the automation that’s in place.
Carmen Cracknell: There’s evidence that regulators are moving towards real time jurisdiction-wide data sharing rather than siloed monitoring. How do you see the balance between a centralized oversight and operator autonomy? And what does it mean for how compliance teams will be structured in five years, do you think?
Joseph Martin: Yeah, sure. I think it’s really fascinating and interesting. And I don’t see it as giving up the time. I think there’s a massive opportunity with it. Like I keep talking about the local regulators, they have local and federal. In the US, I don’t think there’s much appetite for the federal government to get involved in that aspect of it. But there is on a local level, you have these control boards overseeing cannabis, you have control boards overseeing gambling.
These are very high risk industries, and it’s really hard to regulate stuff you can’t see. And so in Nevada, we recently had that happen, you had an illegal bookie come in and conduct transactions for years. And each casino started raising suspicion over time, but they didn’t really act on it. And there’s probably a lot of reasons why. I can’t really, I can’t really assign intent for why it went on for a while, and it was known.
But it resulted in some enforcement actions. And the local regulators started getting more involved in AML after that happened. And but I think the with that, and it’s not just in Nevada, it’s like every state that has these high risk industries where there’s a local control board or regulator, it’s really hard to manage what you can’t see. And activity like that could have been caught so much earlier, if you had a jurisdiction wide view. Because if I’m one casino and I only see a pattern at my single site, then it might take me years to figure out that pattern and to reach a threshold where I’m like concerned.
But if I was a regulator, and I was centrally, and I was collecting information across my whole jurisdiction, then you can see those patterns very quickly. This guy’s bouncing here and bouncing there, bouncing here, and you see these patterns. And then you communicate with the operators and, and you know, you have appropriate government, governance and protocols and things like that. You also have more buying power.
Like if you’re approaching a technology company, and you’re like, we have 2800 entities in our jurisdiction, and we want a unified system for AML, you have a lot more buying power than if you’re selling individual casino sites on technology. So I think there’s a lot of exciting things. In terms of autonomy, I think, regardless of what the jurisdiction does, I think that’s in parallel to what the organization does.
The organization will probably always want the autonomy to say, like, what is my risk appetite, not just for AML, but that crosses into fraud, and a lot of different areas in gaming, it crosses into what they call responsible gaming, like player addiction. And it’s the same types of engines, you’re looking at transactions, transactional patterns, you’re making calls, whether it’s AML fraud, addicted game behavior, they call it responsible gaming.
And so you’re, you’re likely going to your business to manage your risk locally. But if a regulator is looking at it across the jurisdiction, you move out of the situation where you’re punitively getting in trouble from a regulator for something that happened years past. Now it’s more real time collaboration, the regulators, hey, I’m seeing these risk signals happening, wants to be aware of it, you’re working together collaboratively, I think it’s a much more positive environment, technology is there to do it, regulators get nervous about monopolization of like a single tech company serving an entire jurisdiction.
And that’s where we’ve seen it, where we’ve presented it and talked about it. And sometimes there’s apprehension around that. But I think, you know, there’s RFP processes, procurement processes, there’s a lot of different processes where I don’t think that should stop the evolution, that it probably is inevitable and should happen have jurisdictional wide view of risk and be able to manage that. But then also have businesses have their own autonomy to do their own risk management, however they see fit.
And I think it just adds to the it just adds to the richness of the environment. And it doesn’t add to the labor in the headcount anymore. Because if you get the technology right, and you get the information processing right, then you’re not you’re not it’s not a linear process where you’re stacking on headcount, you’re stacking on the work, it’s it’s that it really changes the economics.

