AI is increasingly part of modern due diligence and KYC research—especially for quickly scanning large volumes of public information and surfacing potential issues early.
At the same time, AI outputs can be incomplete, outdated, or simply wrong without warning. That’s why AI works best as an efficiency tool within a disciplined research process, where trained analysts verify sources, add context, and apply judgment before any findings are relied upon or shared with clients.
Because AI creates vulnerabilities such as bias, hallucinations, and privacy risks, users must weigh its benefits, limits, and risks before changing workflows.
No one disputes that AI tools are powerful but fallible. As models evolve from simple chatbots into agents that can research, assess sources, and draft outputs from one prompt, their risks grow. Using AI without understanding its limits or verifying its work can lead to costly errors, as seen when consulting firms face scrutiny for AI-generated deliverables containing hallucinations and inaccuracies. Because AI can invent plausible citations, verification must be explicit rather than assumed.
AI tools can also be sycophantic, tailoring answers to please users instead of prioritizing accuracy. In due diligence, prompts built around a hypothesis may produce confirmation rather than challenge it, risking inaccurate work and reputational harm. The best safeguard is a human analyst who understands the tools, the research, and the need for rigorous verification.
AI Fundamentals and Why AI Can’t Replace Human Judgment
Q: What exactly is AI?
A: AI (artificial intelligence) is technology designed to help computer systems perform tasks that typically require human-like capabilities—such as recognizing patterns, learning from information, and generating answers or summaries. Unlike traditional software that follows fixed instructions, AI systems “learn” from large amounts of data to produce outputs based on patterns in that data.
Q: How does AI work, in simple terms?
A: AI systems are trained on very large datasets (text, numbers, and sometimes images). They use algorithms—rules built on math and logic—to detect patterns and relationships, and then generate predictions, summaries, or responses based on what they’ve learned. The results can be fast and helpful, but they depend heavily on the quality and coverage of the underlying data and sources the tool can access.
Q: How can AI support due diligence research?
A: Used appropriately, AI can help analysts quickly build an initial picture of a subject by scanning broad public information, identifying common risk signals, and highlighting areas that may require deeper review. It can also help reduce the chance of missing obvious adverse references by rapidly sifting through large volumes of content and returning early, high-level summaries that guide next steps.
Q: If AI is fast, why isn’t it a complete due diligence solution on its own?
A: Due diligence requires accuracy, context, and careful source evaluation—not just speed. AI tools may pull from inconsistent, incomplete, or outdated sources; confuse people with similar names; or produce “hallucinations” (definitive, confident sounding but incorrect statements). AI is also limited by what it can access, including most court databases, corporate registries, regulatory systems (e.g., SEC/FINRA and international equivalents), and certain property ownership records. For these reasons, AI outputs must be treated as leads that require verification and professional interpretation—not as final answers.
How IntegrityRisk uses AI Responsibly
Q: How does IntegrityRisk use AI in its due diligence research process?
A: IntegrityRisk uses AI as a targeted support tool within a human-led research workflow. We apply AI where it can improve efficiency and coverage—while maintaining strict safeguards to ensure findings are accurate, properly sourced, and appropriately interpreted.
Q: Where does AI provide the most value in IntegrityRisk’s workflow?
A: We primarily use AI to support:
- Scoping — helping identify subjects, relevant jurisdictions, and obvious areas of concern to guide research planning.
- Related-party discovery — generating an initial list of potentially connected individuals or entities to help analysts assess relationships and risk exposure (with verification required).
- High-level risk charts — when requested, supporting the creation of summary visuals that complement (not replace) traditional written analysis and executive summaries.
- Editing and review support — helping analysts check for consistency and reduce the risk of missing significant issues, while keeping decision-making and final conclusions with the analyst.
Q: How does IntegrityRisk manage risk when using AI tools?
A: IntegrityRisk maintains an AI-specific policy and governance framework that defines which tools are authorized, how they may be used, and what is restricted. We also have an AI Committee that vets and tests tools before implementation, monitors outcomes, and provides updated guidance to analysts to support quality and consistency. Our approach is designed to align with relevant data protection requirements and industry-specific compliance expectations, and we consider ethical implications as part of evaluating any AI-enabled tool.
Best Practices and Caution Points When using AI for Due Diligence
Q: What are best practices for using AI in due diligence research?
A: AI is most useful at the start of a project (to scope and identify potential issues) and at the end (as a cross-check to reduce the risk of obvious misses). The strongest outcomes come from combining AI speed with expert human review and judgment—especially when evaluating sources, assessing relevance, and adding context.
Q: How should AI-generated findings be validated?
A: AI outputs should be treated as pointers, not proof. Analysts should trace any meaningful statement back to the original source and corroborate it with primary or authoritative references whenever possible (e.g., official records, direct statements, reputable outlets). If a claim can’t be verified, it should not be presented as fact.
Q: What confidentiality and data-handling rules matter most?
A: AI tools should not be given proprietary, confidential, or sensitive personal information. This includes items such as dates of birth, Social Security numbers, address histories, proprietary or internal company information, or intelligence gathered through discreet on-the-ground inquiries. IntegrityRisk’s approach emphasizes strict controls to help protect privacy, confidentiality, and client trust.
Q: Why is human review still required?
A: AI tools cannot reliably judge source credibility, evaluate nuance, or explain the “why” behind a finding. They may also miss context that changes the risk interpretation or misattribute information to the wrong person or entity. Trained analysts add what AI cannot: careful verification, contextual analysis, and informed judgment about what is relevant and how it should be communicated.
Q: What are common limitations of AI for due diligence research?
A: Key limitations include:
- Public record accessibility — many AI tools largely rely on Google-indexed webpages and, as mentioned earlier, cannot directly search most court databases, corporate registries, regulatory systems (e.g., SEC/FINRA and international equivalents), or certain property ownership records. Captchas, paywalls, and subscription systems can block access. Some local, non‑US, or industry-specific reporting may not be easily searchable online, reducing AI coverage.
- Bias toward recent sources — like search engines, AI results often favor newer content. For events older than roughly five years, usefulness may decline, and older information may appear mainly through later retrospective articles rather than contemporaneous reporting.
- Foreign-language and naming challenges — AI performance can vary significantly by language and region. Tools may conflate individuals with similar names, misunderstand local naming conventions (e.g., patronymics), or struggle with non‑Roman scripts (e.g., Chinese or Japanese). Without native characters, AI may “guess” spellings or characters, increasing the risk of misidentification.
- Difficulty identifying primary sources — AI may cite secondary or tertiary reporting even when better sources exist, requiring manual follow-up to confirm accuracy and provenance.
- Other AI risks — datasets and outputs may be vulnerable to manipulation (including coordinated “poisoning” efforts that amplify biased or false narratives). In addition, effective use often requires skilled prompting and follow-up questions; initial responses may be high-level and omit critical nuance.
Balancing AI Speed with Human Expertise in Due Diligence
Although AI enhances the speed and efficiency of due diligence research— especially for early scoping and spotting potential red flags—it is not a substitute for careful, source-based analysis. IntegrityRisk uses AI with controls, governance, and rigorous human review so clients benefit from speed without compromising quality, context, or reliability.

