Training is often one of the first areas to come under pressure when firms try to trim budgets, despite the serious risks that can arise when it falls short of regulatory expectations. The arrival of generative AI has only increased that pressure, making cheap, generic courses easier to produce and more tempting to buy. These courses may appear perfectly adequate on the surface, but they can leave firms poorly prepared to deal with the regulatory risks they face.
In a bid to cut costs and respond to the hype around AI, some financial firms are turning to cheap, generic and substandard training platforms. This is a huge mistake – and one they could soon regret.
The pressure to do more for less is nothing new. Every organisation wants to trim the fat wherever it can. Generative AI, however, has opened up a tempting new opportunity – it can quickly produce training courses that appear perfectly credible at first glance, and with lower upfront cost. For firms looking for quick savings, it can seem like an easy win, and a convenient way to show they are embracing the latest technology.
But compliance training is not a throwaway task that can simply be streamlined or automated without expert oversight. It is a critically important part of any functioning financial institution, and it demands depth, expertise and a trusted delivery partner.
When firms replace tailored training with generic courses, employees are more likely to make avoidable mistakes. This increases the risk of regulatory breaches, and with it, the risk of huge financial penalties and lasting reputational damage. This is not an idle threat: across decades of working in compliance, I’ve seen this happen time and time again when training budgets get cut.
For senior managers, this should serve as a wake up call. You will be held directly responsible for any breaches that occur on your watch – and no, you can’t simply pass the buck onto a faulty AI. Regulators will want to know what exactly your employees were taught, and why you chose to cut corners in such an important area.
They will throw the book at you, and rightly so.
Now is the time for firms to take a hard look at their training programmes and ask whether they are genuinely preparing people to manage risk. Responsible use of AI can certainly help to deliver effective training, but not at the expense of quality, expertise and rigour.
Until recently, financial firms largely viewed compliance training as a necessary evil – a precautionary measure, rather like a robust insurance policy. Not the most exciting investment, but a worthwhile expense.
The proliferation of AI has changed all that. Now that training content can be generated quickly and cheaply, the cost of traditional courses appears harder to justify. Firms are increasingly tempted to ask whether they really need to spend so much time and money equipping their employees to manage seemingly distant compliance risks.
But those risks are always much closer than they appear. Throughout my career, I’ve seen regulatory issues completely blindside firms again and again. You might think it can’t happen to you – but believe me, it can.
It often starts with a compliance breach that attracts the attention of regulators, usually due to an employee misunderstanding a regulatory requirement. What begins as a relatively routine call or visit can then develop into a thematic review, with the regulator requesting detailed evidence of how the firm is managing a particular issue – anti-bribery, for example. The review may involve weeks of examining the systems and controls you have in place.
At that point, the regulator will assess the quality of your training. They will scrutinise your courses and delivery methods and consider how detailed they are, how up to date they are and how well they address your particular problems.
This is where the decision to cut costs will come back to bite you. A cheap or AI-generated training programme may look perfectly adequate when you purchase it, but it will look very different under this kind of scrutiny. Regulators will want to see evidence that you take compliance seriously, and a 99% completion rate on a set of superficial refresher courses will not be enough to satisfy them.
Things will then escalate quickly. A failed thematic review turns into enforcement action, financial penalties, public criticism and reputational damage, as well as the cost and disruption of correcting the problems you’ve ignored. And if the regulator remains unconvinced that you can put those problems right yourself, it can get even worse: a Section 166 mandate, where an independent skilled person is brought in to examine your systems and oversee the remediation.
Suddenly, the decision to cut a few thousand pounds from the training budget no longer seems so clever. And who will have to answer for that decision? Senior management. Regulators are increasingly holding managers accountable for these kinds of failures, with the Failure to Prevent Fraud offence a notable example. You cannot simply blame a bad training provider or a defective algorithm in these situations.
So, if you’re thinking of compromising on the quality of your training, I’d urge you to think twice. Imagine sitting in front of a regulator and trying to justify that choice – you’ll soon realise that it’s not worth the risk.
“Choosing a generic, non-specialist training provider might save you a bit of cash in the short term, but what happens when you pick up a £20 million fine two years later because the course content lacked depth or regulatory precision? If your training isn’t overseen by compliance experts, standards will slip – and the resulting regulatory fines and reputational damage will far outweigh any savings you might have made upfront.”
We have quickly become used to using AI to summarise email threads, condense reports and produce basic first drafts. These are the simple administrative tasks where the technology really shines.
Compliance training is different. To be effective, it requires people to spend time with the material, think deeply about it and understand how it applies to their work. The same care is needed when deciding how that learning should be delivered and tracked – which is just as important as the content itself.
My concern is that AI makes compliance training appear insignificant and insubstantial, like the basic tasks we’re used to using it for. Quickly scanning a surface-level interaction with an AI is perfectly effective in many cases, but it is not an appropriate way to approach detailed and important regulatory requirements. The method of delivery needs to reflect the seriousness of the task.
AI tools are also designed to aggregate information to produce broad, generalised answers.
That can be useful for many things, but it is a poor fit for compliance training, where the content needs to reflect the organisation’s particular policies, circumstances and risks. The most effective training puts people into realistic scenarios, asks them to make decisions and shows them how the rules apply to their particular situation. A generic AI tool simply cannot offer that level of specificity or immersion – only synthetic content with very little judgement or human experience behind it.
Using an open AI model such as ChatGPT for regulatory information is an even bigger concern. These systems do not know whether an answer is correct – they predict the most likely response from the information available to them. They can confidently produce outdated or inaccurate information, without recognising that they have done so, and may give a different answer when asked the same question again.
For compliance teams, this raises an uncomfortable question: without input from human experts, how do you know the information your employees are being given is accurate, current and fit for purpose? With a generic AI tool, it can be difficult to establish where an answer came from or how it was reached. If you cannot properly establish the basis for the information being taught, it becomes much harder to have confidence in the training itself.
“There’s a race to adopt cheap training – a race to the bottom – and firms simply don’t understand the risks yet. They’re conflating cheap AI training packages with much more innocuous investments, such as time management software. But if your time management software doesn’t work, the worst that can happen is your team still can’t manage their time. The stakes are far higher when it comes to compliance training, but you wouldn’t know it from the way some firms are acting.”
None of this means financial services firms should avoid AI altogether. Used properly, it can make compliance training more targeted, more responsive and easier to integrate into your employees’ routines. The important distinction is between using AI to support expert-led training and handing the whole process over to a generic automated tool.
AI should always work from approved organisational policies and verified regulatory content, rather than pulling information from an unverified pool of sources. It should help people understand and apply that material, while the expertise, judgement and responsibility remain with the people who know the organisation and its risks.
There are examples of AI being used to improve compliance training without replacing the expertise behind it. Aida, Skillcast’s built-in AI assistant, is designed specifically for corporate compliance. It draws on approved organisational and regulatory content and is embedded directly into Skillcast courses, where employees can use it as a personal tutor alongside their learning.
Crucially, Aida is not being asked to decide what is compliant or invent answers from scratch. Its responses are grounded in the approved material behind the training, giving employees the benefit of an AI assistant without handing regulatory judgement over to the technology.
Skillcast’s training content is also developed and regularly reviewed by compliance professionals and subject matter experts, with regulatory changes monitored and courses updated as requirements evolve. This is the human oversight that gives the technology the context and precision it needs to be trusted.
As AI improves and becomes more integrated into our professional lives, the temptation among firms will always be to ask: how much of this process can be automated? How much money could we save? For me, these are the wrong questions to be asking. The real test is whether the training is good enough to protect the firm when things go wrong.