Skip to main content
News and Insights

How compliance teams use data, analytics, and AI for third-party risk management

How compliance teams use data, analytics, and AI for third-party risk management

By SCCE & HCCA in partnership with Moody’s

AI, changing regulations, and new business models are reshaping compliance programs, data analytics, and third-party risk management. More than half of the compliance professionals responding to Moody’s 2025 survey, “From reactive to proactive: How AI is transforming risk and compliance,” are actively using or conducting trials with AI, up from 30% in 2023.1 Nearly two-thirds (62%) expected widespread adoption of AI within three years.

In March 2026, several dozen SCCE members participated in a Thinkscape Swarm session as part of the organization’s Data Analytics for Compliance Programs conference. Thinkscape, an AI-powered platform, brings large groups together to hold conversations that optimize collective insights and amplify intelligence.

During the session, participants shared how they use data analytics and AI within their programs to support compliance monitoring and strengthen third-party risk assessments. The responses provide insight into some prevailing thinking and practices among compliance professionals.

Swarm questions

  • Q1: Across industries, what are the most important elements of a viable analytics stack for a compliance program, and why?
  • Q2: When analytics point to a potential issue, what makes organizations treat it as a true signal rather than “ noise,” and why?
  • Q3: What are the most important types of data to leverage when an organization conducts due diligence on third parties, and why?
  • Q4: What are the most effective analyses to evaluate risk on those third parties, and why?
  • Q5: What are the best uses of AI in current compliance programs, and why?
  • Q6: Where does AI feel most risky in compliance and why?

Data quality as a key element of an effective analytics stack

The first question in the Thinkscape session asked participants to identify the most important elements of a viable analytics stack for compliance programs and explain their reasoning. Data cleanliness and quality stood out as the leading themes, raised by around one-third of participants. Contributors emphasized that the effectiveness of analytics is closely tied to the quality of underlying data, with cleaner data supporting more consistent interpretation and analysis.

Many compliance functions appear to still be developing their approach to data analytics. In a global survey conducted by White & Case and KPMG, 69% of respondents reported having a basic or developing data analytics strategy, while 21% said they do not use data analytics for compliance and ethics at all.2 Among organizations using data analytics, the most common applications included enhancing risk assessments (58%), reporting (58%), and managing training and certification (55%), indicating a focus on core compliance monitoring and oversight activities.

Separating true risk signals from noise

Next in the Thinkscape session, SCCE members identified the reasons they believed organizations tend to treat potential issues identified through their analytics functions as meaningful indicators, rather than noise.

Topping the list of reasons was monetary or long-term financial implications. Then was validating the issue by investigating potential causes and corroborating with other data sources, such as hotline reports. Together, these accounted for about 43% of responses.

Some participants cautioned that a sole focus on monetary aspects could mean overlooking non-monetary risks. They noted that financial measures might not effectively capture early risk signals, as the financial impact of a risk often occurs after an issue has arisen.

For example, technology might help organizations focus on the data they want to prioritize by setting thresholds to filter out less relevant information, and solutions for conducting due diligence on third parties can be configured to surface publicly reported information related to bribery convictions. Contributors felt that by focusing on more relevant data, a compliance department could better hone in on and understand potentially meaningful signals.

Participants also noticed that the criteria for identifying the data organizations want to focus on may vary by industry and size. Very large enterprises with hundreds of thousands of third-party partnerships might typically set more stringent thresholds, as they’re generally working with larger datasets.

Assessing third-party risk

The next two questions in the Thinkscape session focused on risks related to third-party partnerships. This was an area of concern for many compliance professionals. One likely reason is the prevalence of such relationships.  KPMG research found that 83% of executives plan to expand their partner networks over the next one to three years, raising the significance of understanding possible risk exposure.3

Third-party relationships can present heightened compliance risks; for example, approximately 90% of Foreign Corrupt Practices Act (FCPA) enforcement matters between 1978 and 2023 identified a third-party intermediary—such as a sales agent, consultant, or distributor—as part of the bribery scheme, according to the 2023 Global Survey on Global Compliance by White & Case and KPMG.4

In the Thinkscape session, participants ranked the most critical types of data organizations should leverage when conducting due diligence on third parties. 40% said the regulatory and legal histories of the third parties were considered important for due diligence, noting that this data would show documented past violations, enforcement, or litigation, all of which could help in informing risk assessments.

Some participants countered that not all companies—especially smaller ones—have such records, and that reputational risks can go beyond a company’s legal history.

The next most common response, mentioned by 10% of respondents, was third party identity-related information, sanctions listings, adverse media, and relationship-specific risk data. In supporting this position, respondents indicated that adverse media mentions could help surface allegations or reports of potentially criminal or unethical conduct on the part of a third party. In addition, respondents said that considering this information helped support investor and regulator confidence.

The U.S. Department of Justice (DOJ) has also weighed in on compliance’s role with respect to third-party relationships. “A well-designed compliance program should apply risk-based due diligence to its third-party relationships,” DOJ states.5 This includes assessing the extent to which the company has developed an understanding of the qualifications and associations of its third-party partners.

Other factors to evaluate include whether the company knows the business rationale for including a third party in a transaction, and the risks posed by third-party partners, including relevant reputational considerations and disclosed relationships with foreign officials.

To help manage risks associated with third-party engagements, 87% of respondents to the White & Case survey said they had developed written policies for employee interactions with third parties. More than 90% used anti-corruption provisions in their written agreements with third parties.

The next question in the Thinkscape session looked at the analyses participants viewed as among the more effective approaches for evaluating risk involving third parties and the reasons for using them. One-third of respondents ranked data protection/privacy assessments first. They said assessing the strength of data protection and privacy measures helps develop compliance with global and industry-specific privacy laws. In healthcare, for instance, the Health Insurance Portability and Accountability Act of 1996 established national standards for the protection of some health information. Respondents thought a focus on data protection and privacy could also help in safeguarding against cybersecurity and privacy breaches.

The most common argument against this response came from those who countered that it addresses only one dimension of risk, missing governance, behavioral, and integrity issues.

Slightly fewer participants (29%) said developing a risk-scoring algorithm for third parties was the most effective way to evaluate third-party risk. By developing such an algorithm, companies believed they were better able to weigh multiple factors to create a more comprehensive assessment. They also indicated this approach could support prioritization and targeted oversight of high-risk vendors.

How AI is being used

The use of AI in the workplace is growing rapidly, as reflected in findings from a recent Moody’s report.6 More than four in five respondents—84%—agreed AI offered significant advantages within the risk and compliance functions, including automating processes, simplifying workloads, and augmenting decisions.

Participants in the Thinkscape session were asked to identify the best ways to use AI in current compliance programs and their reasoning. Many responses were similar to those in Moody’s survey. Several pointed to its use in summarizing data, noting that AI can rapidly analyze large volumes of data and documents, helping surface patterns or information that may warrant further human review.

Half of those who argued against this response said the approach is less valuable than automation and analysis. One-quarter said it’s too vague to be useful, and another quarter said humans can provide summarizations.

The next most popular response during the Swarm, at 14%, was “to research general compliance or regulatory questions.” These respondents noted that AI can offer quick, accessible briefs on new or complex regulations. In the healthcare sector, for instance, AI can help nonexperts understand some of the basics of healthcare compliance.

Around two-thirds of those who rejected this reasoning countered that it provides little added value versus a web search. One-third said humans are still required to validate responses.

The term “AI” can encompass a wide range of applications, making it imperative to clarify the specific use case in a given context. In practice, AI is often applied to support aspects of third-party due diligence, such as organizing and synthesizing information and helping reduce manual effort.

Along with identifying ways AI could enhance certain aspects of compliance programs, compliance professionals discussed how monitoring other functions’ use of the technology could help assess potential risks that might be introduced across the whole business.

Lastly, Thinkscape participants were asked to identify the areas in compliance that AI felt “most risky.” Just under one-quarter said AI bias. Among their reasons were the potential for biased responses to cause unfair, discriminatory, or unsafe outcomes, and the ways in which biased responses could create legal and regulatory risks.

One-third of those who disagreed said that bias is manageable with mitigation techniques. Another third indicated that bias in statistics is historically understood, and some participants pointed out that humans can introduce their own biases.

The risk of individuals accepting AI output without verification was noted by 18% of session participants, who said that some might quickly accept AI results due either to convenience or their awe of the system. Those who disagreed said they felt people usually verify AI outputs.

These responses were similar to those in Moody’s survey, where the top concerns included an overreliance on AI, along with a corresponding reduction in human judgment, as well as concerns around data privacy, sovereignty, and confidentiality risks, which were each noted by nearly half of respondents in Moody’s study.

While AI can accelerate certain process steps, such as aspects of third-party due diligence, organizations typically retain a final human review step, with compliance professionals responsible for decision-making. Although there may be a perception that AI could replace aspects of compliance work, in practice, it is more often used to support existing workflows rather than substitute for professional judgment.

Moody’ s survey: Key statistics

  • More than half of compliance professionals are actively using or conducting trials with AI, up from 30% in 2023.
  • 62% expect widespread AI adoption within three years.
  • 84% agreed AI offers significant advantages for risk and compliance functions.
  • Nearly half cited overreliance on AI, reduced human judgment, and data privacy, sovereignty, and confidentiality risks as top concerns.

AI governance and oversight in risk and compliance

A large majority of respondents to Moody’s survey (84%) indicated they felt that AI could deliver significant benefits. However, as use of technology expands, compliance professionals are likely to continue considering how it is applied and overseen, with clearly defined guidelines on use and deployment, and with safeguards such as training, governance frameworks, transparency, and regular audits.

References

1 Moody’s, “From reactive to proactive: How AI is transforming risk and compliance,” September 9, 2025, https://www.moodys.com/web/en/us/kyc/resources/insights/from-reactive-to-proactive-how-ai-is-transforming-risk-and-compliance.html.

2 White & Case LLP, “Engagement with third parties seen as the greatest anti-corruption risk,” news release, June 15, 2023, https://www.whitecase.com/news/press-release/engagement-third-parties-seen-greatest-anti-corruption-risk?s=third%20party%20compliance%20management.

3 KPMG, “The 2026 KPMG Global Third-Party Risk Management Survey,” February 19, 2026, https://kpmg.com/xx/en/our-insights/risk-and-regulation/the-2026-kpmg-global-third-party-risk-management-survey.html.

4 White & Case LLP and KPMG LLP, “Global compliance risk benchmarking survey: Third-party management,” June 13, 2023, https://www.whitecase.com/insight-our-thinking/2023-global-compliance-third-party-management.

5 U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs, updated September 2024, https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl.

6  Moody’s Analytics, “From reactive to proactive: How AI is transforming risk and compliance.”