
Large language models are the most impressive software tools I have encountered in fifteen years of building technology companies. They can read an unstructured document and extract structured facts from it. They can reconcile conflicting information across multiple sources. They can identify an inconsistency buried in a KYB file that a tired analyst would have missed on a Friday afternoon. These are capabilities that directly address some of the hardest operational problems in compliance.
The power of these tools is precisely what makes their deployment such a serious engineering challenge. Compliance requires that every decision be traceable, every action be auditable and every output be reproducible.
Harnessing these technologies in a regulated context means building the right infrastructure around them.
At Ondorse, we have spent three years thinking about what that infrastructure looks like. This article explains the architecture choices we have made and why we believe they are the right ones.
AI without a system of record is guesswork
The first question to ask before deploying any AI in compliance is not “which model should I use ?” It is: what system of record do I have for my KYB/KYC data?
Most regulated entities run their compliance on a CRM (Salesforce, HubSpot) or a homemade back-office. The problem is that these tools were built to represent sales relationships, not risk. Their data model is built around commercial interactions. Their world view is the pipeline, not the case.
AI agents, just like human analysts, need a clear representation of the world to work well : what objects am I manipulating ? What is the expected output ? What tools do I have access to ? A CRM cannot answer these questions in compliance terms.
This is what Ondorse is : a system of record built around a risk-centric view of each client. What risk does this entity pose ? What data and events have led me to revise that assessment ? What actions have I taken as a result ? This is the world view an AI agent needs to be useful in a compliance context.
Without this layer, you are pointing an LLM at a spreadsheet and asking it to understand your compliance posture. That is guesswork and regulators will notice.
Sequential workflows break compliance automation
The second prerequisite for AI in compliance is the right workflow architecture.
Most compliance tools, and most AI-on-top-of-compliance tools, are built around sequential workflows. Step 1, then Step 2, then Step 3. They are clean, predictable, and easy to draw on a whiteboard.
The problem is that they do not work in compliance.
Compliance is a conditional checklist, not a linear process. The underlying data of a case changes constantly, especially now that perpetual KYC is standard practice. A new transaction flag, a public data alert, a document expiry, a questionnaire update : all of these can trigger new tasks at any point in a case’s life. Sequential workflows cannot handle this without being rebuilt from scratch every time.
Ondorse is built around what we call condition-native workflows : a cloud of tasks where every task is triggered by conditions evaluated continuously, not by position in a sequence. Millions of conditions are evaluated every day on our platform. This architecture has been running since 2022, before the LLM era.
This matters for AI because AI needs to slot into a well-defined state space. If your workflow is a rigid sequence, AI cannot be inserted intelligently. If your workflow is condition-native, AI can act at exactly the right moment, when a specific condition is met on a specific case.
State machines : the scaffolding that makes AI reliable
LLMs are probabilistic. They guess. This is what makes them powerful at language tasks and dangerous at operational tasks without guardrails. Without structure, an AI agent can loop indefinitely on a failing tool call, hallucinate missing information or skip a step that the regulator will ask about.
The compliance-grade solution is state machines.
Instead of asking an LLM “what should you do next ?”, a state machine poses precise, scoped questions inside a controlled flow. The agent can only advance according to defined transitions. Each state is auditable. Each transition is logged. The behavior is reproducible.
State machines are not a new AI concept. They are not even a software engineering concept. They are a mathematical concept, much older than LLMs. But they are exactly the right answer to the problem of deploying AI reliably in regulated environments. Ondorse’s architecture is built around state machines at both the task level and the case level. It was designed this way before LLMs existed. As it turns out, that was the right foundation for the AI era.
Two categories of AI tasks and why the distinction matters
Not all compliance AI tasks are the same. We have found it essential to separate two categories:
Single-context tasks are tasks where the data inside Ondorse, the case record, is sufficient to resolve the task. Document verification, consistency checking, flagging anomalies in a KYB questionnaire, ensuring a shareholder structure is coherent with declared information : all of these are solvable with the data Ondorse already holds. These tasks represent the biggest productivity gains available today. We are building AI directly into the platform for these tasks. It is traceable, auditable, with deterministic guardrails where compliance demands it.
Multi-context tasks are tasks that require pulling in data from other systems : a CRM, a transaction monitoring platform, a CSM tool. The resolution of these tasks requires crossing information from multiple systems. For these, the right architecture is not a compliance-platform copilot. It is an AI agent with rights across multiple platforms : Ondorse, Zendesk, your internal CRM. With the agent acting on behalf of a compliance team member. Ondorse’s API is built to be the compliance “skill” layer for these agents : a well-documented, structured set of tools that tell an agent what it can and cannot do in the compliance domain, safely.
The distinction matters because conflating the two leads to bad architecture. Trying to solve multi-context problems with a single-platform copilot leads to hallucinations and scope creep. Trying to solve single-context problems with a complex multi-agent setup leads to unnecessary cost and fragility.
One more angle : AI for configuration, not just execution
There is a third use of AI in compliance that is often overlooked : configuring the compliance workflow itself.
The ability to adapt your KYC/KYB policy quickly is critical. When regulation changes, or when your compliance team decides to add a new document requirement for a specific type of entity, the time between the decision and the actual deployment in your workflow should be days, not months.
Historically, flexible compliance tools were configurable only by technical teams. This created a bottleneck : the compliance officer cannot modify the process without a developer. AI changes this. At Ondorse, compliance operators can configure workflows in natural language, describing a new rule, and having it translate into a live condition in the platform. This is going from no-code to prompt. It removes the technical intermediary and dramatically reduces the time-to-market for new compliance models.
The cost of AI is real, use it where it matters
There is an axiom in software that marginal costs approach zero. This does not hold for frontier LLMs.
Running a large model call on every compliance task, regardless of whether it adds value over deterministic logic, is expensive and wasteful. At Ondorse, we are deliberate about this : we do not use an LLM where a rule-engine evaluation does the job. String comparisons, date validations, threshold checks : all of this runs with traditional software, at near-zero cost.
We use AI where it genuinely outperforms pre-AI approaches : document understanding, nuanced information extraction, natural language analysis of unstructured data and configuration in natural language. These are the tasks where LLMs earn their cost.
Human after all
AI will not automate everything and it should not.
There will always be cases where human judgment is not just preferable, it is required. A CFO sign-off on a sensitive account. A compliance officer’s call on an ambiguous PEP situation. A manual review triggered by an unusual ownership structure with multiple layers of holding companies.
Our goal at Ondorse is not to eliminate human work in compliance. It is to eliminate the unnecessary human work : the repetitive, low-judgment tasks that slow teams down without adding meaningful compliance value. The more of that we automate, the more time compliance professionals have for the decisions that actually require them.
We are building this with state machines rather than chaos, with a proper system of record rather than a chatbot wrapper and with AI occupying its right place: a powerful assistant to human judgment, not a replacement for it.
Discover our latest guide
Everything you need to know about this subject
Heading
Subtextt


.avif)