Brazil does not just need to regulate AI. It needs to create it.

Brasília, November 4–6, 2026. The gathering that begins to change that.

Brazil does not just need to regulate AI. It needs to create it.

three women posing

Unexplained Risk Scores: What the Regulator Is Signaling and How Your Institution Needs to Prepare

Unexplained Risk Scores: What the Regulator Is Signaling and How Your Institution Needs to Prepare

NeoLabsAI

In risk management, generating scores is not enough: decisions must be explained with evidence, traceability, and regulatory compliance.

For years, anti-money laundering, fraud prevention, and risk management systems have evolved around the same objective: identifying suspicious events with increasing speed.

Statistical models, machine learning, and decision engines began producing thousands of classifications per day, assigning risk scores to customers, transactions, and companies. But one question is beginning to carry as much weight as the ability to detect risk:

Who can explain how that score was produced?

The answer is no longer merely a technical matter. It is becoming a matter of governance, auditing, and regulatory compliance.

The problem is not the score. It is the inability to defend it

In many current systems, the result arrives before the explanation. A customer receives a high-risk classification. A transaction is blocked. An investigation is opened.

But when Audit, Compliance, the regulator, or the customer themselves asks “why?”, the answer often boils down to a number produced by a model whose logic no one in the room can reconstruct.

This is the real risk of a black-box score: not the use of Artificial Intelligence or advanced models, but the difficulty of demonstrating the data, criteria, relationships, and evidence that supported the decision.

What BACEN, COAF, SUSEP, and the LGPD already require in practice

None of these regulators requires every institution to use models technically classified as “explainable.” The regulations, however, already establish something broader: risk processes need to be documented, monitored, assessed, and subject to verification.

In the financial system, BCB Circular No. 3,978/2020 requires institutions to adopt a Risk-Based Approach and conduct a documented Internal Risk Assessment, approved by the responsible director and reviewed periodically. The regulation also requires procedures for monitoring, selecting, and analyzing transactions, in addition to assessing the effectiveness of the controls adopted.

This does not mean that the Central Bank requires access to the source code of every model. It does mean, however, that an institution must be able to demonstrate why a given situation was classified as riskier, which information was considered, and which procedures resulted in that decision.

Within COAF, the logic is similar. Regulated entities must analyze transactions, document in a substantiated manner the decisions to report or not report a suspicious situation, and retain the elements that supported that analysis. A report should not merely reproduce an alert: it must provide enough context for the suspicion to be understood.

In the insurance market, SUSEP Circular No. 612/2020 also establishes obligations related to anti-money laundering policies, internal risk assessment, monitoring, transaction analysis, and the maintenance of controls and records.

Even without a circular dedicated exclusively to the explainability of Artificial Intelligence models, insurers already need to demonstrate that their risk identification and treatment processes have verifiable criteria, governance, and evidence.

The LGPD adds another layer to this discussion. Article 20 guarantees data subjects the right to request a review of decisions made solely on the basis of automated processing of personal data that affect their interests.

The law also provides, upon request, for the supply of clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrets. Depending on how they are carried out, automated underwriting, pricing, credit-granting, or service-restriction decisions may be subject to these rules.

The exact scope of this right is still in the process of being regulated by the ANPD. But the direction is already clear: the greater the impact of an automated decision on a person, the greater the need for governance, documentation, and accountability.

Taken together, these different areas point to the same conclusion: it is not enough to identify the risk. It is necessary to demonstrate how it was identified and how the decision was made.

The new frontier is not just accuracy. It is auditability.

For a long time, the market evaluated risk solutions primarily through indicators such as accuracy, sensitivity, and the reduction of false positives. These indicators remain relevant, but they are no longer sufficient on their own.

What now makes a difference is the ability to produce an evidence-based risk narrative: not merely reporting that a customer presents elevated risk, but showing which facts, documents, behaviors, relationships, or connections support that conclusion.

An institution may have a statistically accurate model and still face a governance problem if it cannot reconstruct:

  • which data was available at the time of the decision;

  • which factors increased or reduced the risk;

  • which relationships among individuals, companies, and transactions were considered;

  • which rules and models were triggered;

  • who validated the decision;

  • and which evidence was preserved for a future audit.

Discover how NeoLabsAI can help you

The case that shows why the nature of risk has changed

Operation Hidden Flow, conducted by the Brazilian Federal Revenue Service and the São Paulo Public Prosecutor’s Office, revealed the activities of six fintechs that allegedly moved more than R$26 billion between 2022 and 2025.

The investigations identified the use of structures such as pooled accounts, shell companies, and different layers of financial movement.

More than the amount involved, the case highlights a structural transformation: the most sophisticated financial crimes no longer occur only as isolated events. They are organized into networks, connecting people, companies, accounts, intermediaries, and behaviors over time.

Tools based solely on rules and isolated alerts see fragments of this reality. Reconstructing the entire network—and subsequently demonstrating how it was reconstructed—requires a different analytical architecture.

The question every institution should ask tomorrow

If the Central Bank, COAF, SUSEP, the ANPD, or the Audit department itself asked today to understand exactly why a specific risk decision was made—for that customer, on that date, and with that data—would your institution be able to reconstruct the answer in minutes? Or would it take weeks of joint work among Technology, Compliance, Audit, and Legal?

If the answer depends solely on a score, the greatest risk may not lie with the customer being analyzed. It may lie in the decision-making process itself.

This was the problem that guided the design of NeoLabsAI: a multi-agent system in which different specialist agents investigate specific dimensions of risk and record the evidence used during the analysis.

Instead of delivering only a number, the system seeks to present the human decision-maker with the facts, connections, and signals that support the conclusion, preserving the traceability required for audits, reviews, and interactions with supervisory authorities.

In regulated environments, trust does not come from a score. It comes from the ability to defend, with evidence, the decision that score helped produce.

//

Últimas postagens

//

Last posts

//

Contact

SPECIALISTAIFORDECISIONSTHATNEEDTOBEEXPLAINED

Generic scores are not defensible under BACEN Circular 3,978. We built what is.


Each alert comes with a legal citation, statistical proof, and recommended action. If you are evaluating an AML stack and care about defensibility, let’s talk.