Share with your CISO
Financial services compliance teams are getting the AI investment sequence badly wrong, and a Vixio webinar on AI compliance pilots put a number on it. Nilesh Khatri, head of technology at regulated FinTech and financial services, proposes the 60-25-15 rule: 60% of any AI compliance budget on data hygiene in a narrow domain, 25% on governance and controls, 15% on the AI tooling itself. Most failed pilots invert this entirely. Andrew Dawson, CRCO at Yeepay UK, demonstrated the upside when the ratio holds, collapsing a five-hour SAR filing process to near-instant.
What this means for your business
The firms most exposed here aren’t the ones that haven’t started AI compliance pilots. They’re the ones that already have, because the failed-pilot pattern is almost always the same: a vendor demo gets funded, the data preparation work gets squeezed into whatever’s left, and governance gets treated as a post-launch audit concern rather than a build requirement. If your pilot produced a proof of concept that never scaled, the 60-25-15 ratio is probably a diagnosis, not a prescription.
The SAR filing example from Yeepay deserves more attention than it gets as a model. Dawson’s team didn’t deploy a general-purpose LLM and hope for accuracy. They ran it in a proprietary environment, anonymized customer data, and deliberately suppressed the model’s “temperature,” the setting that controls how creative or exploratory the AI’s outputs are. High temperature produces fluent, varied text; in a legal filing it produces hallucinations that a regulator will treat as fabrications. The architecture choice to strip creativity out entirely is the design decision most compliance teams skip because vendors don’t sell it as a feature.
Personal liability regimes change the calculus in a way that budget conversations often miss. Under the UK’s Senior Managers and Certification Regime, accountability for a compliance failure doesn’t transfer to the vendor when the AI makes a bad recommendation, it stays with the named individual who signed off on the system. That means the CISO or CRCO defending an AI-assisted compliance workflow needs runtime audit trails, explainable outputs, and documented human sign-off at every interpretive step, not because the regulator asked for a demo, but because the alternative is a personal enforcement action. The firms that treat explainability as a nice-to-have are building liability, not reducing it.
Concept deep-dive: LLM temperature
Temperature is the dial that controls how predictable or creative a large language model’s outputs are, think of it as the difference between a calculator and a brainstorming partner. At low temperature the model consistently picks the most statistically likely next word; at high temperature it ranges further, producing more varied and sometimes surprising text. For consumer chatbots, higher temperature feels more natural. For regulatory filings where a fabricated detail is a legal liability, it’s a defect, not a feature, which is why Dawson’s team set it to the minimum.
Based on reporting from The 60-25-15 rule reshaping AI compliance pilots, originally published 2026-07-30 07:58:00.

