Disruption starts with risk, and that is precisely why so much of what passes for “innovation” in AML is not disruption at all but careful career management dressed in strategic language. The uncomfortable truth is that industries built around compliance often reward the people least likely to unsettle them: the candidate with the right regulator on the CV, the right bank on the profile, the right “Head of Strategy,” “Innovation,” or “Chief Product Officer” title, and the right ability to reassure boards that nothing truly dangerous will happen under their watch.
This is not a moral indictment of individuals. It is a structural observation. My book Trade-Based Money Laundering Compliance and the Law makes clear that AML has evolved into a field in which symbolic compliance, professional homogeneity, and risk-averse governance reproduce the same rituals even when everyone in the room knows the rituals are not fundamentally curbing economic crimes. That is why the key question is not whether a person looks qualified to lead AML strategy or product innovation. The real question is whether they are willing to threaten the assumptions, incentives, and commercial arrangements that made them appointable in the first place.
Safe hands
The AML industry has become remarkably skilled at appointing safe hands and then wondering why nothing changes. It promotes people who “tick all the boxes,” precisely because box-ticking is the native language of the sector. The ideal hire often appears obvious: enough regulatory credibility to calm clients, enough delivery experience to satisfy investors, enough product familiarity to speak fluently about machine learning, orchestration, workflow, entity resolution, and false-positive reduction, but not so much independent thinking that anyone has to confront whether the model itself is exhausted.
There is, of course, a certain corporate elegance to this. Nobody gets criticised for appointing the low-risk candidate. Nobody gets dismissed for choosing the person with the respectable mix of bank, consultancy, regulatory, and vendor experience. This is the quiet genius of what might be called the IBM principle: nobody gets fired for buying the familiar answer. In AML, the principle survives not because it produces disruption, but because it distributes blame safely. If the new hire fails to transform the market, well, they were eminently credible. If the strategy disappoints, it was aligned with market expectations. If the product does not disrupt crime, at least it disrupted no internal power structures.
And that, diplomatically put, is the problem.
Status quo returns
What disruption should we expect from those who materially benefit from the status quo? Very little, unless they are willing to become dangerous to their own ecosystem. My book is explicit that the AML field is shaped by systemic incentives that sustain symbolic compliance, where manuals, dashboards, controls, audits, workshops, and metrics create an appearance of seriousness while the underlying criminal problem persists unchanged.
That system has many beneficiaries. Consultancies benefit from remediation cycles. Vendors benefit from selling scalable tools that are legible to regulators. Firms benefit from products that help demonstrate diligence, regardless of whether they materially improve crime disruption. Senior professionals benefit from being seen as prudent custodians of a serious domain. None of this requires conspiracy. It requires only alignment. As my book argues, the AML ecosystem is sustained by interlocking incentives and by a narrow circle of professionals whose shared backgrounds foster epistemic homogeneity and groupthink.
So when a RegTech announces its disruptive offering, the correct response is not applause. It is a respectful question: disruptive for whom? Disruptive for criminals? Disruptive for regulators? Disruptive for client operating models? Disruptive for the vendor’s own revenue logic? Or merely disruptive in the safer marketing sense, where old workflows are wrapped in newer language and presented as transformation?
The distinction matters because the industry has become proficient at confusing novelty with disruption. A new interface is not disruption. A generative AI assistant layered on top of an unchanged control philosophy is not disruption. Faster alert triage is not disruption if the system still measures success by alert handling, SAR volume, or audit readiness rather than by criminal disruption outcomes.
Appointable minds
This is where the hiring issue becomes central. The industry often hires for credibility in front of buyers rather than imagination in front of the problem. It seeks leaders who can reassure procurement, compliance, and boards that innovation will remain safely interpretable within existing regulatory expectations. That makes perfect commercial sense. It also helps explain why so many “innovation” functions produce elegant extensions of existing compliance architecture rather than genuine alternatives to it.
There is a certain irony here. The same market that claims to want bold innovation often filters candidates through criteria specifically designed to remove boldness. The ideal applicant must know the rules intimately, must have managed regulators carefully, must understand enterprise sales discipline, must speak in measured tones about responsible innovation, and must not create reputational discomfort. In other words, the person must be disruptive only in ways that do not threaten hiring committees.
Again, this should not be read as contempt for experience. Experience matters. Deep domain knowledge matters. Knowing how banks, supervisors, law enforcement, and product teams actually behave matters enormously. But experience can do two very different things. It can sharpen judgment, or it can teach professional self-preservation. It can make a leader more insightful, or more fluent in the rituals that everyone else has already agreed to protect.
The point is not that veterans cannot disrupt. Quite the opposite. In many cases, only veterans can see clearly enough where the theatre lives. But they can do so only if they are willing to stop converting that knowledge into safer versions of the same answer.
Endogeneity problem
My book’s treatment of legal endogeneity is especially important here. It shows how compliance regimes become self-referential when regulated entities and intermediaries help define the standards by which their own conduct is judged. In plain terms, the field starts to mistake what is legible, documentable, and defensible for what is effective. Over time, the artefacts of compliance become evidence of success. The manual becomes proof of integrity. The workflow becomes proof of control. The model validation pack becomes proof of innovation.
That logic extends directly into RegTech product strategy. If the market rewards products that are easy to explain to auditors and supervisors, then product leaders will build for explainability to authority rather than for disruption of criminal behaviour. If buyers want comfort, vendors will sell comfort. If regulators reward visible procedure over uncertain but potentially superior experimentation, the whole sector will converge around low-risk sameness.
This is why disruption from inside the current AML market is so difficult. The market does not merely sell technology. It sells institutional justifiability. A product is valuable not only because it detects something, but because it helps a client narrate that it is responsible, modern, and serious. That is commercially rational. It is also one reason the industry can invest billions and still struggle to demonstrate proportionate outcomes in asset recovery, criminal prosecutions, or meaningful disruption of laundering infrastructure.
Low-risk innovation
There is, then, something faintly comic in the spectacle of low-risk disruption. One can almost picture it: a strategy offsite, a declaration that the company must be bolder, a reorganisation around innovation, several carefully worded job descriptions, and eventually the appointment of highly accomplished people whose greatest qualification is that no sensible board member could object to them. Then comes the language of transformation, followed by a product roadmap that remains prudently adjacent to what clients already buy.
The mocking point, made gently, is this: no one should expect radical outcomes from a process designed to minimise career risk at every stage. If disruption is filtered through what is easiest to approve, easiest to defend, and safest to commercialise, it will reliably produce upgraded conformity.
No risk, no disruption. Real disruption means becoming comfortable with being wrong in public, uncomfortable in governance forums, and occasionally unwelcome in the very circles that once validated you. It means backing approaches that may not fit neatly into existing supervisory expectations on day one. It means challenging clients who say they want better detection but purchase mainly for regulatory reassurance. It means asking whether whole categories of current AML effort are designed more to protect institutions from regulators than to protect societies from criminals.
What real risk is
What, then, would actual disruption require from an established RegTech or from the people chosen to lead strategy, innovation, or product?
- It would require a willingness to redefine success away from alerts, throughput, and audit artefacts toward measurable investigative value and criminal disruption outcomes.
- It would require building products that do not simply optimise existing reporting rituals but challenge whether the reporting architecture itself is fit for purpose.
- It would require multidisciplinary leadership beyond the usual closed circle of lawyers, compliance officers, ex-regulators, and vendor insiders, precisely because epistemic homogeneity reproduces the same ideas in different packaging.
- It would require accepting regulatory ambiguity as part of innovation rather than using it as a permanent excuse for timidity.
- It would require commercial courage: the willingness to risk short-term sales friction by telling buyers that what is easiest to procure may not be what is most useful for disrupting economic crime.
None of this is anti-professional. It is simply anti-comfort.
Final tension
The diplomatic answer is that many highly experienced AML leaders are intelligent, conscientious, and serious people trying to work responsibly inside heavily constrained systems. The more provocative answer is that the system especially likes leaders who know exactly how not to threaten it. That is why titles, pedigrees, and low-risk hireability should not be confused with disruptive capacity.
After all, the industry already has plenty of people who can run AML functions, innovation teams, and product portfolios without alarming anyone. That is not a scarce resource. What is scarce is the leader willing to risk professional neatness in order to produce something that might genuinely unsettle the compliance marketplace, the regulatory comfort zone, and the commercial habits of buyers.
Disruption, in other words, is not a branding exercise for incumbents who feel old beside younger RegTechs. Nor is it a reward for those who have accumulated the perfect sequence of respectable roles. It is a willingness to become uncomfortable in service of results. And until the AML industry starts hiring, promoting, and buying for that kind of courage, it should not flatter itself that it is building disruption. It is building continuity with better slide decks.


Leave a comment