The AI revolution in risk has been quiet, but it is real. Models now scan millions of transactions, surface anomalies that humans would miss, and review thousands of contracts in minutes instead of weeks. The temptation is to let them run unattended — full automation feels efficient, reads flawlessly in an audit, and promises to free people for higher work. But a model that runs the entire compliance estate with no one at the threshold is exactly the wrong kind of speed. It moves fast, uniformly and confidently, at a scale that easily outruns the careful eye of a single human rule.
Human-in-the-loop is a phrase we throw around carelessly; the loop is not a human clicking approve on results they do not understand. It is an active architecture: the model resolves the ordinary, the entire population of routine checks; a clearly described, experienced expert translates the exceptions; and a human board owns the thresholds when the edge cases bend the rule. That division of labour is a culture decision, not a technical one. Whether exceptions feel like a chance to improve or a reason to blame shapes every side of the loop.
When we design the loop, we think of three concentric rings: the model scans at scale, the human reviews the exceptions (the model's clean misses and the near-miss edges), and the expert panel owns the discretion — the borderline case, the changing threshold, the interpretation of an ambiguous scenario. Each ring produces a transparent record: what was looked at, what was decided, and who owns the decision. That transparency, ironically, is often where compliance culture changes most: the loop turns the compliance function into a visible, learning part of the business rather than a distant gate.
Culture is the friend, and the loop is the tool: it changes who is seen as responsible. When metrics, thresholds and decision chains are shared, accountability is no longer a penalty pushed down to the floor but a tension the organisation owns as a whole. In practice, the teams who close the loop — who review cases weekly, adjust thresholds with feedback, and let both human and machine learn from the same evidence — are the same teams whose people stop fearing the rulebook and start expecting it to be useful. Compliance never fully succeeds through automation alone; it succeeds when the culture wraps around the machine and the human judgement at the centre of the loop.

