The 98% Problem: Why Financial Crimes Compliance Is Drowning, and What Forticomply is Building to Fix It
Over the last decade, financial crime compliance has been transformed by real-time payments, digital onboarding, evolving sanctions regimes, and rising regulatory expectations. Transactions that used to settle in days now settle in seconds. Fintechs reset customer expectations around speed and ease, forcing banks and incumbents to catch up to a new baseline. Regulators added new requirements, new variations of existing requirements, and new jurisdictions of overlapping requirements, each one becoming costlier and more difficult to patch onto the existing stack. And underneath all of it, the volume of digital transactions kept climbing, putting pressure on compliance teams to scale review capacity fast enough to clear cases within SLA without leaving customers stuck on hold.
The patchwork that compliance organizations have built to keep up with layers of legacy systems, screening tools, expanded analyst teams, outsourced L1 operations has worked, but barely. Costs of financial crime compliance have ballooned over the last decade. And by most industry estimates, a significant majority of that spend is tied to resolving false positive alerts that require manual intervention.
Why the system generates so much noise
Compliance systems were built so that any potential name match, suspicious transfer, or hidden beneficial owner with ties to a list gets pulled aside for review. The logic is sound: anything potentially in scope must be caught, reported, blocked, or cleared so that fines and reputational risk are mitigated. Sensitivity is a feature, not a bug.
The consequence of that sensitivity is volume. Partial matches. Shared keywords. Common names. Overlapping addresses. Some of these alerts are easy to resolve in seconds. Others require a longer investigation, pulling in additional information from customer records, transaction history, public sources, and internal databases just to make a defensible decision.
Of all the alerts these systems pull aside, an estimated 98% are false positives.
Two out of every hundred are real risk. The other ninety-eight are noise that the screening engine couldn't disambiguate on its own. Names it couldn't distinguish, keywords it couldn't contextualize, signals it couldn't weigh against history. The system was never designed to make those calls. It was designed to surface anything potentially in scope and hand the decision to a human analyst.
That model held when volumes were lower. With today's transaction throughput, expanding sanctions lists, and tightening review windows, it doesn't.
The cost compliance teams are actually paying
The work of remediating that 98% is enormous, and it falls almost entirely on the people least positioned to absorb it.
Compliance teams across the world are operating under conditions that would not be tolerated in most other functions. Caseloads that grow faster than headcount. Pushes for efficiency and reduced review times that don't account for the actual complexity of the work. A talent pool that can't keep up with departmental demand, and an attrition rate that walks institutional knowledge out the door every quarter.
The component of teams and effort spent on remediating excess review is extremely labor intensive and produces little proportional benefit to the compliance organization itself. So much budget gets allocated to filtering for the real cases that there's almost nothing left to invest in becoming proactive, in setting aside the time real cases deserve, in building the kind of program that turns compliance into a value-add line of business rather than a cost center fighting to keep its head above water.
That's the situation. That's the problem the team at Forticomply has been thinking about for years.
How Forticomply approaches the problem
The team has spent over two decades in the trenches of compliance, building filters for changing requirements, optimizing screening instances, sitting with analysts who kept describing the same recurring issues. Time and again, we watched new products and features that didn't even scratch the surface of the underlying problem.
When the latest generation of AI models reached a point where their reasoning capabilities could be tested against real compliance workflows, the team began experimenting. The question wasn't whether AI could replace the analyst. The question was whether AI could replicate the context-gathering and reasoning that an experienced analyst applies to an alert, pulling all the relevant data points together, weighing them against the specific match, and making a defensible call on whether the alert can be auto-resolved or needs to move into a manual queue with enriched context already attached.
That experimentation became Forticomply.
We've built 50+ models that work together with redundancy in mind, so that decisions are accurate, precise, and safe. Every decision the system makes is paired with explainable output, the reasoning, the data considered, the path to the conclusion so that compliance teams can review or audit it the way they would any analyst's work, and so that it stands up to the regulatory tests the program will eventually face.
The product is built as an easily integrable add-on to existing screening systems. Forticomply is able to pull detections and cases from a database, message queue, or API, process the information to detect, enrich, and resolve alerts, and then update the status in whatever case management solution the organization is already using. Nothing gets ripped out. Nothing gets replaced. The investment already made stays in place.
The platform includes:
- An analysis engine and proprietary knowledge base
- Models and scenarios tuned for compliance reasoning
- Cases and flow management with full traceability
- Indexing and continuous learning from analyst decisions
- A BI layer for program-level visibility
- A safety model that every decision passes through before being committed
The result is something close to a 24/7 workforce of pre-trained and tailored models that are fully auditable, traceable, and explainable, with continuous learning and human-in-the-loop built in from the ground up.
Internally, we're tracking toward auto-resolving up to 70% of false positives and reducing investigation costs by up to 40%.
Where we are, and what comes next
We are excited about the future of compliance, about a future where teams move away from keeping their heads just above water and finally get the chance to come up for air, where the time and budget freed from clearing noise gets reinvested into the real cases, the proactive work, and the program-building that compliance leaders have been telling us for years they want.
— The Forticomply team