Skip to Primary Navigation

Transcript: Kosta Kadas podcast

GRIP Montage: Private

At the National Bank of Canada, Kadas and his team use AI technology to facilitate communication surveillance and mitigate risk to the business.


This is a transcript of the podcast episode Kosta Kadas on how AI tech enhances electronic communication monitoring between GRIP’s North America head of regulatory content, Julie DiMauro, and Kosta Kadas, senior director and co-head of business conduct at National Bank of Canada.

[INTRO]

Julie DiMauro: Greetings, and welcome to a Global Relay Intelligence and Practice, or GRIP, podcast. I am Julie DiMauro, the head of regulatory content for North America based in New York City. I’m so pleased to have on the program today Kosta Kadas, director, co-head of business for the National Bank of Canada.

I’m going to have Kosta give us a little bit more insight into his great professional experience before we kick off the program, if you would, Kosta.

Kosta Kadas: Hey, Julie, thank you so much for the introduction and for having me on today. So yeah, as you mentioned, I am the senior director, co-head of business conduct at National Bank of Canada within our capital markets compliance team. So yeah, I’ve been with the firm for approximately the last seven and a half years. Initially, prior to joining the National Bank of Canada, I was working for a small company, a fintech company that was a lender to small, medium-sized businesses. I was working within their credit risk department, so I had some experience both on the underwriting side and by also working in their risk and analytics group.

By working on a bit of in their modeling department, prior to that, I was in school working on my, my bachelor’s of commerce with a specialization in finance. And then, yeah, in 2019, I joined National Bank of Canada. Initially, I started in a role that was conducting surveillance in our OTC derivatives space. So I was really responsible for overseeing our OTC derivatives desk within Canada.

So that transitioned into a role that expanded into the US. So within the Dodd-Frank compliance space. So I got exposure to the rules of regulations in the US and really starting to, I guess, hone my craft in that space. While I was in those roles, a lot of my part of my responsibilities were communication surveillance, performing the surveillance and helping shape our program. And then so naturally that led into my role that I took on approximately maybe three and a half years ago, which was leading our communications monitoring program.

So I’ve been responsible for that for the last three and a half years. And that’s helped me get to where I am today and having built this partnership with Global Relay. And I’m really excited that that led me to recording this here today with you, Julie.

Julie DiMauro: Thank you so much, Kosta. And we’re excited to have you here. All right. Let’s kick it off with our first question about AI-driven compliance surveillance, which can involve many different capabilities from scanning corporate data, flagging policy deviations and more. Can you tell us about how you’re using it in your compliance program?

Kosta Kadas: Yeah, absolutely, Julie. So our firm has integrated AI through the use of LLMs, large language models, right? And we’ve integrated this into our communications monitoring program. And what this does is, you know, a lot of the listeners are probably already familiar, with this, but it analyzes the context of our communications to then identify risks and flag those communications for our team.

So that’s how we’ve integrated AI. We’ve also integrated AI-powered translation models, transcription models to help our reviewers. And we’re continuing to explore any new AI technology that will help facilitate our communication surveillance. It’s an ever evolving space. New technologies are being developed daily. We’re not stopping at what I’ve listed. We’re continuing to look at how we can improve our program and what new technology is going to be available to help us there.

Julie DiMauro: That’s terrific. And through the past several months, Kosta, even just this year, what kind of changes have you noticed that have been kind of eye opening for you in these capabilities?

Kosta Kadas: Well, what I would say is that the AI has really, well, it’s made the work more interesting for my team. That I would say that for sure. I think a lot of individuals who, you know, worked, I guess, with the old methods, which were like all these predefined scenarios that, you know, very rule based and like, you know, if this happens, then, you know, I want to look at it versus like, you know, what the AI does, which is really trying to understand the context of the message. It produced a lot of, I would say, a lot of noise for compliance officers that are performing reviews and going through these alerts.

So, you know, over the last few months, what I’ve noticed is that it’s brought a bit more, I’ll say, excitement to, you know, a reviewer’s day. There’s a lot more meaningful alerts. In my experience, I’ve noticed that the AI is able to identify more relevant communications. So with more relevant communications, there are then, you know, further investigations that someone needs to perform. It’s much less of a review something and able to close it off very quickly. And so it’s added, I guess, a bit more of like a richness to my team’s day.

Julie DiMauro: Absolutely. Now, along those lines, you’ve seen it develop in these ways and, you know, it sounds like add more than exciting layer for your team’s work and more efficiency. But at the same time, can you make it more specific to your business? How has it helped you with specific challenges that your business faces?

Kosta Kadas: Yeah, well, I think, again, the risk identification, one of like our biggest challenges was, you know, with our old methods of working is really identifying relevant risks and being able to monitor them. And so the AI has brought communications that we otherwise wouldn’t be seeing to the forefront, which helps my business reduce our risk, reduce potential, you know, regulatory risks.

And, you know, it’s also helped in the sense of, you know, our efficiency. There’s far less alerts from an AI perspective. And as I mentioned, because they’re more meaningful, there’s a lot less false positives as well. So a lot less noise to have to filter through. And so it’s just made the process much more efficient.

Julie DiMauro: That makes sense. And is this something that specifically the executive leadership and board is looking for and has asked you about?

Kosta Kadas: Well, look, our executive leadership encouraged us to explore AI and making our work more efficient. And obviously, in terms of like moving forward with these technologies, they definitely want to understand how it’s improving our processes, what’s the effect on the number of full time employees required. And, you know, it was definitely part of the reasoning used to convince them to move forward with the technology.

Julie DiMauro: For sure. Now, let’s think about the challenges that you need to balance here, because when you’re talking about innovation of any kind, you’re always talking about kind of efficiency, but also challenges in terms of privacy, surveillance, it just brings up these expectations of privacy and the obligations that you have to be mindful of them. How do you balance these things at your organization?

Kosta Kadas: You know, it’s a good point. There’s obviously a lot of positives that come with introducing new technologies. And there’s a lot of challenges with regards to the governance. So whenever you’re introducing a technology like that, that involves some AI, there’s a lot more risk assessments, having a lot of teams internally validate this technology. So that’s that’s obviously one of the bigger challenges is being able to explain, you know, the model, some model explainability to all of these other internal stakeholders that, you know, you need to get internal approvals for ensuring that you have solutions in place to continuously test your AI to ensure that it remains fit for purpose, you know, because you’d want to be in a situation where you’re introducing something today that might work today.

And then, you know, you don’t have a process in place to ensure that when you’re down the line, it’s still performing as it should be. And part of those risk assessments and those approvals comes a big discussion from a privacy perspective. And so it’s being able to explain one how your data is being handled by your vendor, explaining how the data is used and whether the model is using your data. Does it have access? Is it learning from it? So all of this, you know, it goes into like the challenges of being able to get everything approved, getting all internal stakeholders comfortable with the technology.

Julie DiMauro: Absolutely. When you talk about internal stakeholders, who in your business are you mostly working with?

Kosta Kadas: Well, there’s many different departments ranging a lot on the IT side. We have, you know, different teams that are from a cybersecurity perspective, our legal teams, then we have our privacy team, you know, we have a model risk management team. There is with the introduction of AI, it’s also created new positions within the firm that are AI specific and, you know, different committees and different approval processes. So there’s literally like over a dozen different departments that are involved in, you know, reviewing.

And it’s not just AI specific, it’s many different products, new products or activities. There are a range of departments, primarily, like I said, there’s cybersecurity, even compliance, as we have a seat at around the table for these. And so these are the kind of partners that we’re dealing with when, you know, we’re trying to get this new technology on board.

Julie DiMauro: Absolutely. Now you did mention using the technology well and having your people do so. What does effective training look like within your organization, if you can answer that. And I want to address how there are some AI skeptics within organizations afraid on a number of levels to use AI, uncomfortable about getting an output that they might not trust, or they even thinking that it might take over their jobs. How do you convince people to use it more effectively? So the training component and to be a little less scared in using it?

Kosta Kadas: Yeah, absolutely. So look, to me effective training, like I’ve always personally, I’ve learned that I and I feel like people become very comfortable with technology by using it and not through, you know, some presentations or, you know, having a meeting to explain to them what it does. I feel like having individuals form hands on reviews and using the tool helps them see like its practical value. With my team, the effective training is it wasn’t just like, Oh, I’ll tell you about how the AI works and what it does. It was using like real life data of, you know, our own data and actual alerts that were produced to help them understand, okay, look, this is what it does. This is the outcome, the alert that’s being produced. And this is the problem that it’s solving. So we have a problem where we’re trying to identify X. This is a prime example of X being identified.

So, for me, effective training was really, you know, really just diving into the tool for myself. I really thought it was important to thoroughly test. And I think this goes beyond just AI, but with any technology is to thoroughly test it against, you know, real production data to compare it and benchmark it against, you know, the previous ways of working, you know, to really ensure that you’re, you’re achieving what you’re trying to achieve. So if, if, you know, you’re trying to identify this specific risk and your old models are not or your old models are meant to identify it, well, it’s comparing both and seeing what did my previous model do? What is the AI do?

From a skeptics perspective, I would have to say like, one, I understand people that are that have some skepticism, and I think it’s healthy to have a bit of skepticism, especially as like compliance professionals, because we’re like there to like challenge and challenge assumptions. And so I think for like skeptics, it shouldn’t be like, you shouldn’t be having a conversation trying to tell them, hey, you should be trusting the AI, it’s really helping them understand what is the AI doing, showing them like, hey, where does it help? And also explaining to them that like, it’s really more so a tool to help support the human expertise, the human expertise is going to remain essential, you know, in this space, communications monitoring, and AI is really just a tool that is there to help us. And so once you help skeptics, the discussion becomes much more productive with them.

Julie DiMauro: Absolutely. That makes sense. Now, you talked about working with vendors. And that’s a relationship that needs to be really carefully monitored and fine tuned. And there’s a lot of vetting of different competitors out there. What are you looking for in a vendor that is providing surveillance technology?

Kosta Kadas: Well, look, I would say vendor relationships, I think I touched on this earlier, I may have mentioned it, but they should be really viewed as as partnerships more than that. But like, from a vendor perspective, I think that the greatest relationships where you know, that usually lead to the most successful implementations and then continued success are the ones where it’s truly like a two way street. And the relationship is really a partnership as opposed to it being viewed as you know, vendor and client. That’s one area that I would, you know, say is an important area for firms to be focusing on when they’re exploring vendors.

And then another area is, you know, when you’re going to be assessing a tool, technology, whatever it is that you’re looking for, I think it’s very important that, you know, as a firm, first, you clearly define, you know, what’s the problem that you’re trying to solve. And then once you’ve defined that problem, then you could then evaluate the solution to say, does it seem to be responding to, to, to, you know, my needs for this? And then, you know, you need to ask yourself, you know, questions about the solution itself. Like one, can it be explained?

I keep talking about explainability, but that’s, you know, really big, you know, you’re going to be asked both internally within your organization and from regulators to be able to explain the solution. So that’s really important that you need to be able to do. Can it be governed? So like governance is really huge. Can it be independently validated? You know, does it fit within your firm’s risk appetite? You know, and also how does it integrate within your firm’s processes and workflow? So these are questions you should be asking yourself, keeping in mind when you’re exploring vendors and solutions. And then to me, that partnership piece is just really, really, really important as well.

Julie DiMauro: How important is it to have a plan for when technology fails? Something baked into your business continuity planning?

Kosta Kadas: Oh, yeah, it’s super important. And, you know, again, that we have business continuity plans at the firm, multiple departments that are responsible for these scenarios. You mentioned that now in one of the internal stakeholders that, you know, is involved within our risk assessment part process is our business continuity team and ensuring that, you know, there are steps in place to be able to for the business to go on and, you know, not suffer any critical losses during any periods of downtime.

Julie DiMauro: Absolutely. Kosta, I want to end with asking you about what you at the National Bank of Canada and the surveillance technology side, you’re most excited about in the final quarter of this year?

Kosta Kadas: Well, what I would say is I would extend it beyond the final quarter of the year and just, you know, into the future. And what I’m really most excited about is over the past many years, you know, my firm and other firms have been collecting large volumes of data. You know, we’re all slowly introducing, you know, different technologies. But what I’m really excited about is leveraging all of this, you know, this data that firm has accumulated and being able to use AI to kind of gain insights from it and create kind of more proactive surveillance, you know, surveillance was previously kind of very reactive involved many reactive scenarios.

And it’s so it’s using AI technologies to gain insights from, you know, our large data set that we now have, and just create like meaningful insights. There’s lots of like, I would think like, are talking about scenario based surveillance when it comes to like comms monitoring. And with that, I was really more specifically talking about like, you know, keywords and lexicons. But when you’re looking at like metadata, and trying to like, gain insights on trends, I think that’s what I’m really most excited to try to leverage AI for and, you know, see what kind of kind of information we find in there.

Julie DiMauro: Trends and patterns analysis that will help you prepare for the future for the bank and maybe monitoring risk and preparing for risk?

Kosta Kadas: I think the way it would help us is that there’s first there’s definitely trends and insights that we’re not privy to in our regular monitoring process, it would take it takes some level of automation to be able to identify patterns or trends or, you know, repeat offenders in certain scenarios and to gain those types of insights. And so to me, I think it would help identify like I was saying, risk that’s not maybe identifiable on a day to day basis through regular monitoring, or it’s not identifiable on a single alert basis.

But when viewed over, you know, certain period, whether it’s over a week, a month, a quarter, and you gain insights on individuals behavior over time, then we’ll be able to start seeing, be able to hopefully identify, you know, potential bad actors or instances of non compliance, where, you know, you just can’t see it on like a snapshot of a specific day.

Julie DiMauro: Makes total sense. Kosta Kadas is the senior director and co-head of business conduct capital markets compliance for the National Bank of Canada.

Thank you so much for joining us on the GRIP program today, Kosta.

Kosta Kadas: Thank you so much, Julie, really happy to have been on.

Listen to the audio.


Get full access, free for a month

This is a free article. Try Premium free for 28 days to get every article on GRIP and more – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience