Question 01
How much can AI actually reduce false positives in fintech transaction monitoring?
AI-powered transaction monitoring reduces false positives by 30 to 80% depending on baseline maturity. The median at PE-backed mid-market fintechs is 40 to 55%. The biggest win is alert prioritization, not pure suppression. Experian's Transaction Forensics showed a 200% lift in actual fraud caught alongside the 80% false-positive cut. The vendor that promises 95% suppression with no impact on detection is selling a model that hasn't been backtested honestly.
Why most vendors get this wrong: they benchmark on the vendor's own customer base (which already had bad rules) and not on the portco's actual baseline. The honest comparison is rule-based versus AI on the portco's last 12 months of alerts, with a holdout sample to validate.
Right answer pattern: a pilot on the portco's actual 90-day alert history with a holdout backtest. The vendor that won't run this pilot doesn't have the confidence in their numbers.
Question 02
What does AI KYC and AML actually do, and when does it fail diligence?
AI KYC uses identity verification, document OCR, and behavioral signals to compress identity checks from days to minutes. AI AML uses graph analytics and LLM-based narrative review to triage suspicious activity. Both work cleanly when model decisions are auditable, when the vendor maintains a documented training-data lineage, and when human-in-the-loop review is preserved on high-risk cases. Both fail diligence when the audit trail is opaque, when the vendor pushes back on training-data transparency, or when the model can't explain why a specific decision was made.
Why most vendors get this wrong: they treat the audit trail as a UI feature, not a contractual obligation. The diligence team is going to ask for a 7-year retention guarantee with API access for the auditor's tooling. The vendor whose contract doesn't already permit this needs to rewrite the MSA.
Right answer pattern: a SOC 2 Type II report, a Model Card per production model, a documented training-data lineage, and an explicit 7-year audit log retained in the portco's tenant. The vendor that can produce all four in 24 hours is real. The one who needs a quarter to assemble them isn't.
Question 03
Can fintech portcos use AI for same-day underwriting decisions on commercial lending?
Yes. AI underwriting platforms deliver same-day decisions on 60 to 80% of commercial loan applications under $250K, compressed from the historical 5 to 12 day cycle. The math works when data sources are live (Plaid, Shopify, Stripe, Xero), model explainability is preserved for adverse-action notices (ECOA, Reg B), and portfolio monitoring runs continuously instead of at origination only. Real-time covenant monitoring is the under-deployed piece most fintech portcos miss.
Why most vendors get this wrong: they ship a fast origination decision and stop there. The continuous monitoring side (early-warning alerts on covenant breach, payment-pattern shift, cash-flow stress) is where the credit loss actually lives. The portfolio-monitoring AI is harder to sell because it doesn't have a clean origination metric, but it's where the portco's loss ratio gets protected.
Right answer pattern: origination AI for speed-to-decision plus portfolio-monitoring AI for continuous covenant compliance, with the same data-source plumbing serving both. Bonus points if the vendor includes ECOA/Reg B adverse-action notice generation as part of the standard product.
Question 04
What's the right way for fintech portcos to handle AI model risk under SR 11-7?
SR 11-7 model risk management applies to AI models used in regulated banking activities. The clean implementation pattern at fintech portcos: maintain a model inventory, document training data lineage, run independent validation before production deployment, and track model performance with drift detection in production. The AI vendor that can't produce a model card and a validation pack on demand will not survive a federal examination. Add the OCC's June 2024 third-party risk guidance on top: the bank or fintech remains accountable for vendor model decisions.
Why most CROs get this wrong: they treat AI as a vendor-managed line item, the way they treated SaaS in 2018. The OCC, FDIC, and Federal Reserve don't see it that way. Third-party risk is the bank's risk. The vendor's SOC 2 doesn't extend to the bank's MRM obligation.
Right answer pattern: a model inventory maintained by the portco (not the vendor), independent validation by a third party for each material AI model, and a quarterly drift-detection review with documented escalation paths. The vendor that resists any of this is a regulatory liability.
Question 05
What's the cost difference between buying RegTech AI and building it in-house?
For KYC and AML, buy almost always wins. The vendor landscape (Sardine, Persona, Alloy, Unit21, ComplyAdvantage) has the rule libraries and regulatory templates that take a 5-person team 18 to 24 months to replicate. For underwriting and risk scoring, build wins at scale: the portco's own customer data is the moat. Typical 24-month TCO: RegTech vendor at $200K to $800K per year fully loaded; in-house equivalent at $1.5M to $2.5M with a 4-person team plus infrastructure.
Why most CTOs get this wrong: the build instinct flips on the wrong side of the line. They try to build KYC (where the vendor's regulatory expertise is the moat) and they buy underwriting (where the portco's customer data is the moat). The decision pattern is opposite the instinct.
Right answer pattern: buy KYC and AML from a category leader. Build underwriting and continuous portfolio monitoring on the portco's own customer data. The 24-month math holds for portcos at $20M+ revenue.