Change Control and Human Oversight in Governed LLM-Assisted AML Triage: Validation Flows, Metrics, and Supervisory Readiness
Main Article Content
Abstract
The paper presents a study of change control and human oversight mechanisms for governed, non-authoritative large language model (LLM) assistance in anti-money laundering (AML) case triage. While operational monitoring frameworks enable institutions to observe production behavior, sustained regulatory defensibility additionally requires structured validation flows and controlled change management that bind model, template, and validator evolution to measurable evidence and explicit human accountability. The study proposes a governance-oriented validation lifecycle that integrates pre-deployment checks, post-deployment surveillance, and supervisory escalation paths, with human-in-the-loop controls formally embedded into each phase. Quantitative metrics are introduced to evaluate validation stability, override behavior, and post-change risk exposure. A BPMN-based process model is presented to illustrate how governed change flows support supervisory readiness in the face of regulatory scrutiny. The purpose of the work is to determine how structured change control and human oversight can be operationalized for LLM-assisted AML triage through measurable validation metrics and governed workflows, and to assess how these mechanisms contribute to sustained audit readiness. The methodology encompasses: formalizing validation stages across the LLM lifecycle, defining quantitative indicators for change impact and human intervention, modeling governed change workflows using BPMN, and analyzing their suitability for supervisory review and quality assurance. The scientific novelty. For the first time, change control and human oversight for LLM-assisted AML triage are formalized as an integrated validation lifecycle with explicit metrics for override pressure, post-change deviation, and human acceptance behavior, enabling auditable evidence of sustained governance beyond initial deployment. The practical value lies in providing compliance, QA, and engineering teams with a defensible framework for managing LLM changes in production, thereby reducing uncontrolled drift, mitigating automation bias, and strengthening institutional readiness for regulatory inspections. Conclusions. Effective governance of LLM assistance in AML triage depends not only on monitoring outputs but also on controlled validation and change processes that explicitly integrate human judgment. The results demonstrate that structured change control combined with quantitative oversight metrics significantly improves supervisory defensibility compared to ad hoc or informal update practices.
Article Details
References
Basel Committee on Banking Supervision. (2020). Sound management of risks related to money laundering and financing of terrorism. Bank for International Settlements. https://www.bis.org/bcbs/publ/d505.pdf
European Banking Authority. (2021). Guidelines on money laundering and terrorist financing risk factors. https://www.eba.europa.eu/regulation-and-policy/anti-money-laundering-and-countering-financing-terrorism/guidelines-mltf-risk-factors
European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). https://eur-lex.europa.eu/eli/reg/2016/679/oj
European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2025). From prompt injections to protocol exploits: Threats in LLM-enabled systems and mitigations. Internet of Things, 29, 101997.
https://www.sciencedirect.com/science/article/pii/S2405959525001997
Federal Financial Institutions Examination Council. (2026). Bank Secrecy Act/Anti-Money Laundering examination manual.
https://www.ffiec.gov/bsa_aml_infobase/pages_manual/manual_online.htm
Financial Action Task Force. (2012). International standards on combating money laundering and the financing of terrorism and proliferation: The FATF recommendations. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
Hinder, F., Artelt, A., Hammer, B., & Kuehl, N. (2024). One or two things we know about concept drift—A survey on unsupervised drift detection. Frontiers in Artificial Intelligence, 7, 1330257. https://www.frontiersin.org/journals/artificial-intelligence/articles/10.3389/frai.2024.1330257/full
International Organization for Standardization. (2022a). ISO/IEC 27001:2022 Information security management systems — Requirements. https://www.iso.org/standard/27001.html
International Organization for Standardization. (2022b). ISO/IEC 27002:2022 Information security controls. https://www.iso.org/standard/75652.html
Kücking, F., (et al.). (2024). Automation bias in AI decision support: Results from an empirical study. [Indexed article page]. https://pubmed.ncbi.nlm.nih.gov/39234734/
Lewis, P., Perez, E., Piktus, A., Petroni, F., Karpukhin, V.,
Goyal, N., Küttler, H., Lewis, M., Yih, W., Rocktäschel, T.,
Riedel, S., & Kiela, D. (2020). Retrieval-augmented generation for knowledge-intensive NLP tasks. Advances in Neural Information Processing Systems, 33. https://papers.nips.cc/paper/2020/hash/6b493230205f780e1bc26945df7481e5-Abstract.html
Liu, X., Yu, Z., Zhang, Y., Zhang, N., & Xiao, C. (2024). Automatic and universal prompt injection attacks against large language models. arXiv. https://arxiv.org/abs/2403.04957
National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (SP 800-53 Rev. 5). https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
National Institute of Standards and Technology. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
OWASP Foundation. (2024). OWASP Top 10 for Large Language Model Applications. https://owasp.org/www-project-top-10-for-large-language-model-applications/
Patton, C. E., (et al.). (2023). Automated assistance in a dynamic decision-making context: Human–automation teaming and transparency. Humanities and Social Sciences Communications / SpringerOpen article page. https://link.springer.com/article/10.1186/s41235-023-00519-5
Robertson, J., (et al.). (2025). Managing change when integrating artificial intelligence into organizational processes: A socio-technical perspective. Journal of Business Research.
https://www.sciencedirect.com/science/article/pii/S0148296325000219
Umar, K., (et al.). (2025). Enhancing regulatory compliance through automated retrieval-augmented generation. ACL Anthology (RegNLP).
https://aclanthology.org/2025.regnlp-1.14.pdf
Zaidan, E., (et al.). (2024). AI governance in a complex and rapidly changing environment: Legal and institutional perspectives. Humanities and Social Sciences Communications, 11. https://www.nature.com/articles/s41599-024-03560-x
