Podcast: AI, Due Diligence, and the Limits of Machine Judgment
A conversation with Michael Volkov on how AI is changing due diligence, where it works well, and where human judgment still matters.
Threat.Digital founder Christian Focacci joins Michael Volkov on the Corruption, Crime and Compliance podcast to discuss how AI use in due diligence has changed, where it works well, and where human judgment still matters.
Michael Volkov recently invited Threat.Digital founder Christian Focacci back to the Corruption, Crime and Compliance podcast for their annual conversation about AI, due diligence, and compliance.
A lot has changed since their earlier discussions (2020, 2024, and 2025). Companies have moved beyond the initial rush to add general-purpose chatbots to everything, and the more useful applications of AI are becoming narrower and more specific. In due diligence, that includes reviewing large volumes of information, resolving entities, identifying relevant adverse media, triaging sanctions results, and helping researchers focus their attention where it is most useful.
The conversation also covered some of the problems that have become clearer as adoption has increased.
AI still needs something reliable underneath it
Large language models have improved substantially, but they still produce incorrect information. That creates an obvious problem in due diligence, where a plausible answer is not enough.
One of the points discussed in the episode is the difference between using an LLM as a source of information and using it to analyze information that can be independently verified.
For due diligence work, we strongly prefer the latter. AI can read, classify, compare, and summarize source material, but material findings should remain traceable to the documents and data behind them.
That approach also makes human review more useful. An investigator can evaluate the underlying evidence, consider the credibility of the source, and decide whether the information actually matters to the investigation rather than being asked to trust an unsupported model response.
Governance is starting to catch up with adoption
Another topic was "shadow AI": employees using AI tools on their own before an organization has established policies around how those tools should be used.
This creates practical questions about confidential information, data handling, documentation, and accountability. It also becomes more consequential when AI moves from helping someone complete a task to influencing decisions about employees, customers, vendors, or other third parties.
The same issue now extends into third-party risk. Organizations increasingly need to understand not only whether a vendor uses AI, but where it is used, what information it processes, how outputs are reviewed, and whether an AI-generated result can directly affect an important decision.
Those are more useful questions than simply asking whether a company "uses AI."
The technology is getting better, but judgment still has a job
Michael and Christian also discussed the rapidly changing model market, including open-weight models, the growth of models developed outside the United States, and the regulatory approaches beginning to develop around different AI use cases.
Despite the pace of change, the basic principle for due diligence remains fairly stable.
AI is very good at processing more information than a person could reasonably review, identifying patterns, filtering large result sets, and handling repetitive research tasks. Experienced investigators are still needed to evaluate sources, understand context, resolve ambiguity, and determine what findings actually mean.
As the technology improves, the boundary between those responsibilities will continue to move. Due diligence teams should be testing that boundary rather than assuming either that everything can be automated or that the way research was done five years ago should remain unchanged.
The full conversation is about 40 minutes and covers considerably more, including sanctions screening, third-party AI risk, regulation, model development, and where AI is likely to fit into compliance programs next.