The five questions your board will ask about agentic financial crime

Strong answers name a mechanism, a person, and a date. Weak answers name an intention. The five questions are predictable, so predict them.

Detcord
Detcord
The five questions your board will ask about agentic financial crime

The meeting is already on the calendar. It got there in January 2025, when IBM announced a predictive AML and fraud suite. It got there again in March 2025, when Oracle added AI agents to its Investigation Hub Cloud Service. It got there a third time in April 2026, when Verafin's survey of more than 500 financial crime professionals found 90% reporting an increase in AI-driven attacks over the past two years. The board noticed.

Two more dates moved the topic upstairs. Treasury released its Financial Services AI Risk Management Framework in February 2026. The EU AI Act's enforcement provisions take effect August 2, 2026.

The questions are predictable. So predict them.

We found no published list that covers agentic financial crime specifically. The five below are built from Grant Thornton's 2026 board questions, the NACD director question bank from March 2025, and the threat numbers. Every figure carries its source and its weight.

The standard every answer has to meet comes from Dawiso's governance guide, updated 2026. A good answer sounds like this. The figure is illustrative: "Fraud detection has cut confirmed fraudulent transactions by 20 percent year on year, measured by the risk function."

An intention starts with "we plan to." A mechanism names who does what by when. That is the whole test.

The first question: "How big is this, really?"

The FBI counted 21,832 business email compromise instances in 2022, with $2.7 billion in losses. Deloitte's Center for Financial Services put AI-related fraud losses at $12.3 billion in 2023 and projects $40 billion in the U.S. by 2027. The citation is secondhand, another accounting firm's summary of Deloitte's work. The $40 billion is a projection, not an audited loss figure. Say so if you use it.

The number everyone quotes is $4.4 trillion in illicit funds flowing through the global financial system in 2025. Label it. It comes from Verafin's Global Financial Crime Report, a vendor-produced figure, widely cited and not independently audited. Saying that out loud is the answer.

The follow-up this answer survives: "Where did that come from?"

The cost question: "What is this costing us?"

The soft numbers come first. Globally, banks spend an estimated $274 billion a year on financial crime compliance. It traces to no named study. Call it an industry estimate. The claim that banks detect about 2% of illicit flows traces to a personal Substack post. Name the provenance and drop the number. The 60 to 80% reduction in investigation costs has no named study behind it either. None of these survive a CFO with an analyst.

Here is the answer that survives. "We don't have a defensible number yet. Here is the mechanism that will produce one, the person who owns it, and the date." By that standard, it is a strong answer. A borrowed number is not.

"Is anyone else doing this?" The question usually comes with a competitor's name attached.

Statista's early 2026 aggregation of industry surveys: 16% of banking executives are actively deploying agentic AI, 52% are piloting. Fintechs lead, 57% at or beyond active adoption against 45% of traditional institutions.

The follow-up: "Compared to whom, and where do we sit?"

The permission question: "Are we even allowed to?"

The EU AI Act starts enforcing August 2, 2026. The high-risk obligations in Annex III moved to December 2, 2027, after the simplification vote. The Council of the EU approved the change June 29, 2026. One vendor source still says August 2026. The primary-sourced date wins. Confirm it against EUR-Lex before it goes in the board pack.

Penalties run to €35 million or 7% of worldwide turnover under Article 99. Fraud detection sits outside the high-risk creditworthiness category, a carve-out two independent secondary sources agree on. Article 26(2) assigns human oversight to natural persons with competence, training, and authority. The assignment lands on a person, not a committee.

FATF Recommendation 15 requires human oversight and auditability of automated decision-making. SEC Rule 17a-4 and FINRA Rule 4511 require tamper-evident, auditable records — agent-generated ones included. The Treasury framework from February 2026 gives you the governance structure.

The follow-up this answer survives: "Show me the date and the file."

"When the agent does something, who answers for it?" That one gets asked last.

Everest Group draws the boundary. Agents gather, structure, and explain evidence. Humans keep alert closure, SAR and STR filing, onboarding denial, and final sanctions blocking. Their warning, verbatim: "avoid equating agent adoption with decision automation."

Article 26(2) is the accountability hook. Dawiso's sample answer names an owner who can suspend a system without escalation. The example: a pricing model pulled within the hour when drift crossed its threshold.

Run the drill. Pick one agent-touched decision, produce the complete trail on demand, and time it. Four hours end-to-end is the sample benchmark.

The surviving answer is one sentence. Which calls the agent makes, which a named human makes, who that human is. If drafting that sentence takes a committee, the institution is not ready to deploy. Say so.

Verafin's April 2026 report makes a point that is factually uncontroversial even though it is vendor-produced. Criminals operate as networks across institutions, payment rails and borders, testing controls until a gap opens. Sumsub reports agents already working user verification at volume. Unquantified. Say so.

Here is the sentence you can say to the board. "Our monitoring stops at our edge. The pattern that crosses institutions is the one we cannot see alone."

That is the honest answer. It is also the one no single institution can give alone.

Detcord is the network that sees across the seam no single institution can see, with a verifiable audit trail regulators can rely on.

Five answers, one sentence each, each with a mechanism, a person, and a date. Write them down before the meeting, not during it.

The sixth sentence is the honest one about the seam. It is also the one that starts a real conversation.

The question arrives whether or not there is a strategy. It lands this quarter. There are only two positions in the room: answers written down, or the hope that the question doesn't come.

Let's connect

Financial crime is going machine speed. We're building the network that sees it. Tell us what you're facing.

No newsletter. No email campaign. A founder will reply.