Matt Mills, CEO of Ripjar: “Explainability is a hard constraint in regulated AI, not a nice-to-have”

Financial institutions have spent years strengthening their defences against financial crime, yet many still rely on surprisingly manual processes to identify emerging risks. As regulators raise expectations and enforcement activity intensifies, compliance teams are under growing pressure to move beyond periodic reviews and build a more continuous, intelligence-driven approach to customer screening.

According to Matt Mills, CEO of Ripjar, this challenge is particularly evident in adverse media screening, where many organisations continue to depend on manual internet searches despite recognising the process as a critical component of anti-money laundering (AML) and compliance programmes. Mills argues that the issue is no longer a lack of awareness or investment appetite, but a combination of trust, explainability and operational complexity that has slowed the adoption of more advanced technologies.

In this interview, Mills discusses why AI deployment continues to lag behind AI investment in financial services, how continuous monitoring can help close dangerous compliance gaps, and why the future of screening lies in unified platforms that combine sanctions, politically exposed persons (PEPs), watchlists and adverse media into a single, continuously updated view of risk.

Your research found that 58% of financial institutions still rely on manual internet searches for adverse media screening. Why has the industry been so slow to modernise such a critical process?

As our research also shows, the intent is there, with 93% of financial services leaders rating adverse media screening as critical. The execution hasn’t caught up yet, but this is really a trust and capability problem rather than an attitude problem.

Most screening stacks were built domain-by-domain over a decade or more. Sanctions came first, then PEPs, then watchlists, with adverse media bolted on later as the youngest discipline of the four. Four separate procurements with manual integration and analyst reconciliation. And until recently, the automated adverse media tools available produced too many false positives for compliance teams to trust them fully. So manual review, which is typically analysts using public search engines to look up entities, has stayed in workflows as a layered check on automated tools that haven’t yet earned full confidence.

The other piece is that manual review is defensible. An analyst can explain every decision they made and why. Legacy AI screening couldn’t always do that and the underlying name matching wasn’t always accurate enough to trust at scale either. Handling common name variants, aliases, intentional misspellings, and transliterated versions is technically demanding, and getting the permutations wrong means missing the signal entirely. Both of those things are changing now, and the next wave of investment is headed towards more automation and less manual searching.

The report highlights a major gap between AI investment plans and actual AI deployment. What’s stopping banks from turning AI ambition into operational reality?

It’s a great question; the numbers (79% of firms investing in AI for screening but only 28% fully deployed) tell you it isn’t really about access to technology. It’s more of an operational change management issue, because putting AI inside a screening process means changing how analysts triage alerts, how the audit trail works, how risk decisions get documented, and how institutions defend decisions to a regulator.

The other constraint is explainability. A compliance officer needs to be able to explain every alert decision in an enforcement conversation. So if the AI can’t explain why it surfaced a match, the alert becomes useless. Most general-purpose AI products weren’t built with that design constraint in mind, so to close the deployment gap, you need AI that is defensible and explainable. 

Ripjar says adverse media screening should act as a “first line of defence” against financial crime. What are the biggest risks institutions face when they fail to monitor continuously?

Every major AML enforcement action of the past few years has had a similar pattern, where adverse media signals existed in the open for years before action came. What separates institutions that catch it from those that don’t is the gap between scheduled reviews.

Most banks today are running adverse media screening at onboarding and then periodically, usually annually, sometimes more often. The risk rears its head in the weeks and months between those checks, when news surfaces but there’s nothing built to look at it. Continuous monitoring closes that gap where periodic review, by definition, can’t.

To your question about the risks: first of all there’s the regulatory exposure: $69 billion in AML enforcement actions globally since the financial crisis, and 522% year-on-year growth in bank penalties in 2024. Then there’s the reputational damage of being the institution that didn’t see what was already in the public domain. Both are increasingly hard to defend when the technology to monitor continuously is available and being deployed by your peers.

AML penalties jumped 522% year-on-year in 2024. Do you think regulators are becoming less tolerant of outdated compliance processes?

Yes, and the pattern in recent enforcement makes it clear. These cases aren’t about missed individual transactions or a single bad customer; the enforcement comes down hard on structural failures, where the screening system isn’t built to look at the information that is already out there and easily knowable. 

What regulators are focusing on now is the structural gap, not the specific bad outcome. A defensible process that produces a bad result on one case can still be defensible, but one that wasn’t built to surface the signal in the first place isn’t.

Underlying this is a broader shift in how regulators think. They’ve moved from being prescriptive about specific concerns to expecting institutions to demonstrate they’re doing everything reasonable to surface risk, not just what’s explicitly required. This decrease in tolerance means compliance leaders now have to ask themselves if they can demonstrate that their processes are capable of catching these signals. It’s much harder to clear that bar when you’re running manual searches and periodic reviews. 

Your findings show significant differences between the UK, US, France and Germany. Which markets are leading the way in modern screening practices, and what are others getting wrong?

Each one has a different shape of the same problem, which is the more useful way to think about it.

Germany has the lowest manual reliance at 40%, partly because BaFin wrote adverse media analysis into formal guidance in 2024. Where supervisors have been directive, institutions have followed. But Germany also reports the highest mean false positive rate at 52%. Automation doesn’t make false positives go away, it just changes how they’re managed.

Then you’ve got the UK which leads on responsiveness. 75% of UK firms use event-triggered screening, the highest rate of any market. The gap is in automation depth, not how fast institutions react when something surfaces. UK firms also have the most fragmented vendor stacks, with 41% running four or more screening providers.

Then there’s the US. 70% are still doing this manually, which sounds like a laggard story. But 53% of US firms cite regulatory scrutiny as a driver for new investment, and 50% cite high false positive volumes as their primary screening challenge. The US has been holding manual review in the workflow as a quality control on tools it didn’t fully trust. That position is starting to shift. The institutions investing in this now are doing so because the operational risk doesn’t disappear when regulatory pressure eases, and the US data shows them taking the operational case seriously regardless of where the political wind blows.

Many institutions appear to treat sanctions, PEPs, watchlists and adverse media as separate processes. Why is a unified approach becoming increasingly important?

96% of the leaders we surveyed want sanctions, PEPs, watchlists and adverse media in a single unified platform. But they’re running screening across three or four separate vendors, often integrated by hand, with manual reconciliation.

The problem with that architecture is twofold. The first is operational: when domains aren’t entity-resolved, the same low-quality match can generate alerts in three different systems, multiplying false positives and analyst time without adding any new information. The second is risk. When adverse media is separate from sanctions and PEPs, the signal that someone is becoming risky doesn’t connect to the data showing who they actually are. That’s how risk slips through.

The unified platform question is the key one facing screening teams right now. Yes, it consolidates contracts and reduces vendor cost, but the more significant value is giving the compliance function one risk picture for each customer, continuously updated, with the audit trail to defend every decision. That’s how you clear the bar as regulators keep raising it.

There’s often concern around explainability and trust when AI is used in compliance. How can financial institutions balance automation with transparency and accountability?

Explainability is a hard constraint in regulated AI, not a nice-to-have. If you use AI and it surfaces an alert, it’s non-negotiable that you need to be able to explain why it surfaced. What data drove the decision? How was the confidence score calculated? This becomes even more important with the AI is used not only to prepare but also to disposition, prioirtise and in some cases discount alerts. 

This need changes how AI products must be built. Most general-purpose AI today optimises for accuracy. AI built for compliance has to optimise for accuracy plus explainability plus auditability, which is a more demanding design constraint and a harder engineering problem.

The way I’d frame it is that your AI isn’t making the risk decision. Your analyst is. AI and your analyst are working together. The AI is doing the upstream work of entity resolution, name matching, false positive triage, and confidence scoring, with the trail of how each decision was made traceable at every step so the analyst can interrogate or override. Your analyst is spending time on the cases that actually need judgement, which will always be present. Human-in-the-loop, machine-out-of-the-noise. That’s what balance looks like in practice, and it’s about doing way more without having to invest in additional resources.

Looking ahead, what does “good” adverse media screening look like in 2026 and beyond, and how far away is the average bank from reaching that standard?

Good adverse media screening in 2026 is unified across sanctions, PEPs, watchlists and adverse media in a single view. It’s continuously monitored. It’s AI-supported for the high-volume, low-judgement part of the workflow. And every decision has an audit trail that can stand up in an enforcement conversation.

But there’s a subtler gap to be aware of: effective screening depends on entity understanding, not just name matching. Some names – mine being an example – are more common than others. Then you have aliases, intentional misspellings, transliterated version of names from other languages. If you’re going on matches alone you could miss the important signal entirely, regardless of how good everything else in the stack is. That’s where a lot of screening programmes are still falling short today, and it only becomes visible when it’s too late.

The average bank is closer to that than you’d think. The intent is there, as our research shows. The tools are there as well. What good looks like in 2026 is a programme that matches capability to intent, one that’s unified, continuous, and built on entity resolution that works at scale. To get there first, procurement decisions have to be made now.

More interviews

About The Author

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.