Divya Iyer — Practice Leader, HFS Research[00:00]
Hello everyone, and welcome to another HFS videocast. I’m Divya, Practice Leader for Banking, Financial Services, and Insurance at HFS Research. Today I’m delighted to be joined by Tom, who leads the Global Financial Crime Managed Services at EY. Tom, before we begin, congratulations to you and the entire EY team on being recognized as a market leader in the HFS Horizons: Financial Crime Compliance (FCC) in Financial Services, 2026 report. It’s a tremendous achievement and reflects EY’s continuous commitment and investment in its global FCC capabilities. Congratulations to you and the team. Tom, it’s a pleasure to have you with us today. Before we jump into the discussion, why don’t you introduce yourself to our audience and tell us a little bit about your role at EY?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[00:51]
First, thank you, Divya, for having me. It’s great to be a part of the conversation, and I really appreciate the recognition from HFS as well. By way of background, I lead our EY Global Financial Crime Managed Services business. So my focus is really helping financial institutions rethink how they operate their financial crime programs, moving from some of these reactive, cost-heavy compliance program models, really towards a more intelligence-led, technology-enabled operation. I’ve spent the majority of my career in financial services, really in consulting, working closely with large banks and fintechs across KYC, transaction monitoring, sanctions, and fraud. Over the last several years, my role has really centered on bringing together the regulatory expertise of EY, the advanced analytics and AI that are coming out in the industry, and our global delivery centers to really help clients solve problems at scale, not just from a compliance standpoint, but more in a way that’s sustainable and future-ready. What’s exciting for me right now is that it’s an inflection point in our industry where institutions are no longer asking, “How do I keep up?” Now they’re asking, “How do I fundamentally redesign for what’s next?”
Divya Iyer — Practice Leader, HFS Research[02:09]
Brilliant. Fantastic. Tom, organizations have been investing heavily in financial compliance programs for well over a decade. We’ve seen significant investment in technology, operations, and talent, yet enforcement actions haven’t meaningfully declined. Where do you believe the real problem is?
Tom Scazzafavo — Global Financial Crimes Managed Services Leader, EY[02:25]
So I think the key issue is that most firms have invested heavily, as you’ve said, but they’ve invested incrementally. It’s not been transformational. They’ve layered technology on top of fragmented processes, legacy systems, and inconsistent data. So while the spending has gone up, the operating model really hasn’t fundamentally changed. So the real problem, in my view, comes down to three things. There’s data fragmentation, so those critical insights are still trapped across silos in these firms. There are inefficient processes, so too much manual triage and duplication of effort. And then there are misaligned incentives. Success is often measured by throughput and regulatory response, not so much in risk reduction. So when you combine all of those things, enforcement actions persist because firms are still largely reacting to symptoms. They’re not addressing the root causes like customer risk segmentation, the network-level visibility that’s out there, and then using real-time intelligence.
Divya Iyer — Practice Leader, HFS Research[03:26]
So, Tom, over the past 12 months, have you seen your clients’ priorities change? What conversations are you having today that simply weren’t happening a year ago?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[03:37]
Yeah, there’s been a notable shift over the past 12 months. Historically, clients were very focused on cost takeout and remediation. So really in the whole mindset of, “How do I clear backlogs? How do I reduce false positives? How do I respond to some of these regulatory findings?” Today, the conversation’s much more strategic. So we get questions on, “How do I build an intelligence-led financial crime program? How do I embed AI safely and at scale? How do I modernize my end-to-end operating model, not just some of the individual processes?” We’re also seeing increased demand around platform-led transformation, and then the combination of managed services on top of that. So this is where clients are really asking us to take on full operational accountability, not just advisory. So it’s shifted really from point solutions to more enterprise transformation. And I think the advent of the new technologies that are coming out, and then the operating models that are changing, has really led to this shift over the last 12 months.
Divya Iyer — Practice Leader, HFS Research[04:46]
So let’s talk about AI. Where are you seeing AI genuinely improve client compliance outcomes today, and where do you think the industry is still getting a little ahead of itself, if it is?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[05:00]
Okay, yeah. So AI is absolutely delivering impact, but it’s very selective where that’s happening. So, where is it working well today? First, if you look at alert reduction and prioritization, there’s improving signal-to-noise in transaction monitoring that’s happening today, and that’s seeing a lot of improvement in use cases in the industry. Second is around entity resolution and network analytics. That’s identifying hidden relationships across customers and transactions. AI is just able to see things a lot more clearly than an analyst would. The third thing we really see is the increase in productivity in cases. So this is where we’re starting to see the use of generative AI to accelerate investigations. That’s summarizing data, improving SAR quality, and producing narratives as well. So those things are happening today and they’re pretty effective. These are the use cases where AI is really augmenting human decision-making, and that’s driving the measurable outcomes. We’re looking at better detection and lower cost. So that’s what’s working well.
So then we get to where we still have some more ambition than reality in some of the talk that’s happening around AI. A few areas: fully autonomous decisioning. In some of the high-risk regulatory areas, we’re not quite there to where we can do straight-through processing. I think a lot of our clients are uncomfortable because they don’t know the regulatory reaction behind it. The second piece is around end-to-end AI-driven compliance programs that don’t have human oversight. I think that goes to the same problem as before: we don’t know how the regulators are going to react, and I think there’s still a lot of testing and inference that needs to happen throughout the AI process to really get comfortable that human oversight isn’t there. I think we’re going to be in a process of human-in-the-loop for a while. And then the last piece is around being able to scale AI consistently across jurisdictions that have different regulatory expectations. We’re finding a little bit of challenge there as you look at some of our big global clients. AI is great, but there’s a challenge in scaling it across different countries.
So I think the reality is AI is very powerful, but it’s not a silver bullet. It still requires very strong data foundations, there needs to be governance in place, and it’s got to be integrated into the operating model for it all to work well together.
Divya Iyer — Practice Leader, HFS Research[07:41]
So, in your point of view, what’s the time frame you see it reaching that autonomous state, or the end-to-end autonomous state, for financial crime compliance through AI?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[07:52]
Yeah, I still think we’re a couple of years out from taking humans out of the loop and where there’s fully straight-through processing. Now, I do think that there are parts of the equation that are more ripe for straight-through processing. If you look at some of the transaction monitoring level-one triage processes, there is an ability, and I think a push from the industry, to try to get that to be as much straight-through processing as possible. Really doing some of the risk decisioning that happens, especially for things that are very low quality or low probability of being a true match or a true alert of some suspicious activity. I think that is probably closer to reality than some of the more complex processes down the road, like if you think about enhanced due diligence in the KYC process. So I think we’re a couple of years from something like that. But the industry is pushing there, and I think when there’s some regulatory comfort around it as well, we’ll get to a point where AI is being much more powerful in doing some of that straight-through processing, where the analysts are really looking at the risk rather than going through the process.
Divya Iyer — Practice Leader, HFS Research[09:14]
How difficult is it to strike a balance between innovation and regulatory confidence when deploying AI in an FCC environment?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[09:22]
Yeah, this is one of the biggest challenges, and frankly I think it’s one of the biggest opportunities for differentiation as well. The regulators have been very clear: they’re not anti-AI, but they do expect transparency, governance, and accountability. So I think at EY we approach this in a few ways. We have explainability by design. So that’s where we’re selecting or engineering models that can provide traceability into decisions. We have hybrid approaches, so that’s where we’re combining AI models with rules-based overlays where needed. And then strong governance frameworks: model validations, auditability, and ongoing monitoring of the AI itself. So for us, the balance is really about being innovative but responsible.
We look at it as an AI trust and governance plane. This is where we treat agents like they would be a customer in a KYC process. So we verify the agent’s identity: who owns the agent, what model version it’s on, what’s the refresh state behind it. But we also risk-rate that agent based on its role, the process it’s undertaking, and the data it’s exposed to. And then we do some monitoring on that agent to make sure it’s behaving properly. For me, I think the firms that get this right are going to be the ones that treat AI not just as a technology play, but really as a risk-managed capability embedded into their compliance frameworks.
Divya Iyer — Practice Leader, HFS Research[10:55]
So, EY speaks a lot about helping clients evolve towards intelligent operations. How will your investments in FCC assets, AI and delivery capabilities help turn that strategy into operational intelligence? How do you bring this to life? And in your experience, what separates a successful FCC transformation from those that fail to deliver lasting change?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[11:17]
Yeah, so where we see real success is when clients are moving beyond the strategy decks that they create and really putting it into operational execution at scale. So like you mentioned, we’ve invested very heavily in three areas to enable that. First is around FCC platforms and accelerators. So that’s really where we’re trying to standardize and industrialize the processes, both from an operations but also a technology capability. The second area we’ve heavily invested in is our AI and analytics capabilities. So we’re embedding these directly into workflows, not just sitting on the side of somebody’s desk to use ad hoc. And then the third place we’re investing very heavily is around our global delivery model. So this is around leveraging the combination of our offshore global delivery services network and our local jurisdiction domain expertise. That’s really going to drive that consistency and scale for us.
So to answer your question about what separates successful transformations from those that fail: for me it’s a couple of things. One, there needs to be a clear target operating model that’s tied to the business outcomes. Second, I think you need to have end-to-end redesign, not just incremental fixes, because that’s just kicking the can down the road. Very important to me is having strong data and technology alignment into the processes. And then, critically, having change management and adoption across the enterprise. So when a transformation fails, it’s really when an organization underestimates the operational and cultural shift that’s required. It’s not just about deploying tools. And we’ve seen a lot of firms struggle at this over the last few months. It’s really about changing how decisions get made.
Divya Iyer — Practice Leader, HFS Research[13:09]
No, I couldn’t agree more with the importance of change management. I know EY has a really big cross-functional team of FCC experts. So how have you built this team that combines regulatory, data, AI and transformation experts? And how are you leveraging this global knowledge-sharing model to stay ahead of the evolving regulatory expectations and the emerging financial crime risks across jurisdictions?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[13:34]
Yeah, so I think this is an area where EY has a real advantage, because of the breadth of our services and our reach globally. Financial crime today is inherently cross-functional. You need to have regulatory and compliance expertise, you need to have deep technology and risk knowledge, you need to have the data and AI capabilities, and then you need to have that transformation and operations expertise. So what we do is we bring those teams together through an integrated global model that’s really supported by a few things. One, we have a global knowledge-sharing model where insights from one market can be rapidly applied to another. We’re continuously developing typologies and regulatory tracking. And then we also have that really close alignment that needs to happen between our advisory teams, our technology teams, and our managed service teams. So this is what’s really allowed us to stay ahead of both the regulatory expectations and the emerging threats, which I think we could all agree are evolving faster than ever given the advent of AI these days.
Divya Iyer — Practice Leader, HFS Research[14:46]
Yeah, that’s how you’re more proactive than reactive to any situation.
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[14:50]
Exactly.
Divya Iyer — Practice Leader, HFS Research[14:50]
So just looking ahead, where do you believe financial crime is migrating over the next two to five years that compliance leaders aren’t watching closely enough today? What do they need to look out for?
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[15:04]
Yeah, I think there are a few areas that aren’t getting enough attention yet. First, I would say there’s this risk around ecosystems. So if you think about it, financial services are becoming more embedded across fintechs, they’re embedded across platforms now, third parties, non-traditional financial institutions. So what it’s really showing us is that this risk is no longer contained within a financial institution or a singular entity. It’s across the whole ecosystem as a whole. And I think there’s got to be a little bit better collaboration, and I think we’re starting to see some of that migration happen.
Second is around AI-enabled financial crime. We’ve talked a lot about AI in the compliance aspect of it, but we haven’t talked about the fact that criminals are also adopting AI just as quickly as institutions. So whether it’s synthetic identities, deepfakes, or more sophisticated fraud schemes, the criminals are continuing to evolve. We’re going to have to continue to meet that evolving nature that they have right now.
The third area where we’re going to see some migration, and what’s not getting enough attention right now, is really around the continued growth of real-time payments and digital assets. Digital assets is one of the biggest sectors that’s growing for us right now. These typically are areas where traditional controls that we’re used to simply don’t apply anymore. They’re not being used in the same way that we’re used to with traditional financial institutions. So it’s really causing us to challenge our approaches.
Finally, I think the last thing that gets overlooked a little bit, but maybe given recent events is becoming more and more highlighted, is really this cross-border regulatory complexity. So jurisdictions are going to start to take different approaches, and global institutions are going to struggle to maintain consistency. We’ve seen bigger divergence in the last 12 months than we’ve seen in a long time, especially when it comes to regulatory drive here. The US is operating very differently than it has in the past, while the EU is maybe becoming a little bit more stringent on their application of some of the regulations.
So I think the common thread is that financial crime is really becoming a faster, more and more technology-driven enterprise. So leaders in the space are going to be the ones who move towards real-time, intelligence-led, highly adaptive compliance models to really meet the needs against those criminals that are moving at machine speed these days.
Divya Iyer — Practice Leader, HFS Research[17:50]
Tom, thank you. This has been a fantastic conversation. One message comes out really clearly: that to succeed in financial crime compliance is no longer just about simply meeting regulatory obligations. It’s about building that intelligent operating model that combines technology, AI, domain expertise and human judgment to stay ahead against this increasingly sophisticated financial crime. And once again, congratulations to you and the EY team on your recognition, and thank you for sharing your insights with us today. Thank you.
Tom Scazzafavo — Global Financial Crime Managed Services Leader, EY[18:22]
Thank you, Divya. It’s been a great conversation.