Artificial intelligence has moved from buzzword to a business reality in compliance programs – but the rush to deploy AI tools in third-party due diligence also raises important questions. Can you trust it to make even non-critical decisions? Should you? And where does human expertise fit into an increasingly automated landscape?
As organizations face pressure to assess an increasing number of third parties with constrained resources, understanding how to integrate AI into due diligence processes has become essential. The goal isn't to hand over the keys to the algorithms, but to use technology as another tool in your compliance toolbox.
The AI Moment in Compliance
We're in the midst of an AI boom that's touching nearly every industry - and compliance is no exception. The March 2024 DOJ announcement about technology's role in the evaluation of compliance programs marked an important moment, signaling that regulators now view technology use as a factor in assessing program effectiveness. This was a clear message that ignoring technology carries its own risks.
The drastic shift towards more advanced technology use since 2024 has also become increasingly evident. At compliance events around the world, AI is a major focus of debate. For due diligence specifically, the pressure to deliver faster, better, and cheaper results has made AI adoption feel inevitable. Everyone wants more thorough research, delivered quicker, and at lower price points. Technology promises to help achieve that goal, but the promise comes with warnings that organizations are still working to understand.
Where AI Adds Value Today
Speeding Up Information Gathering
AI excels at the repetitive, time-consuming tasks that have traditionally eaten up hours of research time. Database screening is a perfect example. When a common name search yields thousands of potential matches, AI can filter the results by utilizing contextual data, eliminating irrelevant categories, and pinpointing the most relevant result. If your program isn't concerned with environmental enforcement actions, AI can eliminate those hits instantly. It can further identify and remove false positives, dramatically reducing the volume of results that need human review.
Beyond screening, AI can quickly locate relevant issues across vast online information sources. Ask it to find any matters related to bribery, human rights violations, fraud, or money laundering connected to a specific company, and it can deliver results in seconds. This technology provides quick summaries covering the essential details, giving researchers a head start on understanding potential red flags, while comprehensively compiling the information that’s most useful.
Summarization and Initial Analysis
AI's ability to quickly pull together information from multiple sources can streamline the early stages of research. It can provide the who, what, when, where, and why of adverse media findings, helping analysts quickly determine whether a deeper investigation is needed. This becomes particularly valuable when dealing with high volumes of third parties and viewing initial results.
The key word, however, is "initial." While AI can provide helpful overviews, these summaries shouldn't be treated as a complete analysis. Important details may be left out based on how the AI was prompted. Names of involved individuals, dates of events, related companies, appeals that overturned judgments, or other important details can be lost when AI condenses information. This can be particularly complex when documents are in multiple languages.
Pattern Recognition at Scale
With large datasets, AI can identify patterns and connections that might go unnoticed during manual review. Cross-referencing corporate relationships, identifying unusual transaction patterns, or flagging inconsistencies across multiple data sources are tasks where AI's processing power shines. These functions don't replace human judgment, but they can uncover issues that deserve closer examination.
The Irreplaceable Human Element
Understanding Context
Some aspects of due diligence fundamentally require human insight. Understanding whether adverse findings represent genuine risk, political bias, or routine matters in a market demands baseline knowledge that AI currently lacks.
“Is this criminal investigation politically motivated?”
“Is this type of regulatory action common in this location?”
“Does this news article reflect real concerns or simply competitive market dynamics?”
“How does this finding impact my relationship with the third party?”
Analysts familiar with specific industries, countries, and regulatory environments bring expertise that technology cannot currently synthesize or replicate. They understand local business practices, political situations, and cultural factors that shape how risks should be evaluated. This knowledge helps connect dots that might appear unrelated to an algorithm working without that full contextual and experiential background.
Based on this, the process should be simple: AI gathers the information, and then a human checks it before it is taken as fact, right?
Quality Control and Verification
AI generates outputs based on available data and the prompts it receives. It doesn't inherently understand whether its conclusions make sense or whether it has missed critical information. It has also been found that many AI tools heavily leverage user-based sites, such as Reddit, when sending results as facts to users. This can be problematic as lore or anecdotes and slowly be viewed as facts over time through repeated exchange and acceptance. Human reviewers of the AI data serve as an essential reality check, ensuring that AI-generated research is accurate and hasn't been corrupted or led astray.
The need for verification becomes clear when considering how AI can miss important details. A company might be using a former name not captured by the AI's search. A parent company might be named in a lawsuit, but the subsidiary was the one responsible for the wrongdoing. Executives at companies with problems also know some tricks to reduce their negative findings online and will use them to sweep adverse information under the rug and away from the AI's eye. These details require human analysts who can recognize gaps and pursue additional research.
Critical Thinking
While AI can summarize findings, it cannot fully replicate the analytical thinking required to assess their significance.
“How serious is this legal issue?”
“What does this pattern of regulatory violations suggest about the company's compliance culture?”
“Should these adverse findings change our risk rating or recommended approach?”
These questions require judgment informed by experience, an understanding of your organization's risk appetite, and the ability to weigh multiple factors simultaneously. They're not simply data processing tasks but decisions that shape your organization's risk exposure. The question of “now what?” isn’t one that people are asking AI to answer, but it is prompting compliance professionals to ask it, and they are using AI-generated results as the basis of fact.
Implementing AI Thoughtfully
Start Small and Learn
Rather than deploying AI across multiple functions at once, consider beginning with limited applications where the stakes are lower and the results can be easily verified. Using AI to screen database hits or as a supplemental research tool allows your team to understand its capabilities and limitations without excessive risk.
This step-by-step approach provides opportunities to identify where AI performs well and where gaps exist. Has the company faced legal action? If AI says no, verify that conclusion through direct court searches. You might discover AI missed actions filed under a parent company name or involving the company's former legal name. These lessons provide guidance on how to use technology more effectively.
A possible approach would be to start with a completed, analyst-completed report and then do checks on that same entity versus AI-driven research. If the results are very different, ask why.
Apply a Risk-Based Approach
Your comfort level with AI should match the risk level of the relationship being assessed. For low-risk third parties, you may be comfortable relying more heavily on AI-generated research, particularly when human reviewers conduct spot-checks to ensure quality. For high-risk relationships, keep experienced analysts in charge, using AI as a supplemental tool rather than the primary researcher.
This risk-based approach aligns with broader compliance principles while acknowledging that AI technology continues to improve. As it gets better and your team gains confidence in its capabilities, you may rely on it more, but that evolution should happen carefully based on demonstrated performance.
Trust but Verify
Regular validation of AI-generated findings ensures the technology performs as expected and that your team catches any errors before they impact decisions. This might mean comparing AI research against traditional methods for a sample of cases, checking whether AI consistently identifies certain types of issues, or verifying that important details aren't routinely lost in summarization.
Over time, successful verification builds confidence in where AI can be trusted and where additional human oversight remains necessary. This isn't about being skeptical for its own sake but about understanding your tools well enough to use them appropriately.
Understand the Limitations
AI is only as effective as the prompts it receives and the data it can access. Like any machine it does what you tell it to do. It won't know to search for information you haven't asked about. It can't apply your organization's specific risk criteria unless those have been clearly defined and built into its instructions. And it may not recognize when information is missing or when sources are unreliable.
Being clear about these limitations doesn't diminish AI's value. It simply means understanding that AI is a tool requiring skilled operators who can recognize when its outputs need additional review or supplementation. AI can have trouble with database or news sources behind paywalls or those that require a special login such as criminal background checks.
The Evolution Continues
The capabilities of AI are expanding rapidly, and what seems beyond its reach today may be routine tomorrow. Organizations should regularly reassess where AI fits into their due diligence processes, adjusting as technology improves and internal expertise with these tools deepens. They should also check the market for new, valuable tools as the rate of improvement on existing AI tool is moving incredibly fast with large sums of investment money and new startups emerging all the time.
However, some fundamental principles will likely remain constant. Technology should handle what it does well—processing large volumes of data, identifying patterns, conducting initial screening, and summarizing information. Humans should handle what requires judgment—contextual analysis, complex risk assessment, and decisions that significantly impact the organization's risk exposure.
The most effective due diligence programs won't be the most automated or the most traditional. They'll be the ones that thoughtfully integrate AI where it adds value while preserving the human expertise that technology can enhance but not replace. Finding that balance requires understanding your organization's risk profile, your team's capabilities, and the realistic strengths and limitations of available tools.
Looking Ahead
The integration of AI into due diligence represents an opportunity to strengthen compliance programs, not by replacing human judgment but by freeing experienced professionals to focus on what matters most. When technology handles the tedious and repetitive tasks, analysts can dedicate their expertise to complex assessments, borderline cases, and high-risk relationships.
This isn't about achieving perfect automation. It's about building programs that work in the real world, where budgets are tight, regulatory expectations continue to grow, and the volume of third-party relationships keeps expanding. AI helps bridge the gap between what needs to be accomplished and available resources, but only when used thoughtfully.
The question facing compliance professionals isn't whether to adopt AI, but how to adopt it in ways that strengthen rather than weaken due diligence quality. Getting that balance right requires careful implementation, ongoing assessment, and the wisdom to recognize that even as technology advances, human judgment remains irreplaceable in areas that truly matter.
Effective third-party due diligence programs require understanding where technology adds genuine value and where human expertise cannot be substituted. The right approach to AI integration isn't universal—it depends on your organization's risk appetite, resources, and operational realities, and should evolve as both technology and your program mature.
To hear more from the source conversation, check out Beyond Legal Risks in Third-Party Risk Management
