Trust by design
Clear evidence.
Human responsibility.
Practical design principles for AI preparation in financial services.
These are objectives for future implementations. The portfolio demonstrates concepts; operational controls require implementation and validation.
Source-grounded outputs
Preparation should be linked to the documents and records behind each finding. A reviewer needs to inspect the evidence, check its date and understand how a figure was derived.
In practice
In the Credit Memo walkthrough, each financial indicator links to an illustrative document excerpt or calculation.
Current portfolio: Source references support verification; they do not guarantee that extraction or interpretation is correct.
Explore the credit walkthroughHuman approval
AI can analyse, prepare, flag and draft. The responsible professional reviews the output, resolves exceptions and retains the decision.
In practice
A credit officer checks the figures and recommendation before the authorised credit function makes a real approval decision.
Current portfolio: The portfolio does not make credit decisions, close AML alerts or approve client onboarding.
Explore the credit walkthroughAuditability
A deployed workflow should record the inputs, source versions, prepared output, model configuration and human review so that the process can be reconstructed.
In practice
An investigation record could connect each finding to a transaction, KYC record and reviewer action.
Current portfolio: The current public previews do not save review histories or provide an operational audit trail.
Role-based access
Permissions should be checked by the server and reflect the user’s role, assigned cases and authorised activities. Displaying or hiding a button is insufficient.
In practice
An approved visitor could see selected demo applications, while contact management would be accessible only to the owner.
Current portfolio: The current demo workspace and contact management preview are public prototypes. Authentication and restricted access are not yet active.
Client data isolation
Real client data should remain separated across users, cases and institutions throughout storage, retrieval and processing. Isolation needs to be enforced and tested.
In practice
A document search for one client must never retrieve another client’s records without explicit permission.
Current portfolio: This portfolio uses synthetic data. It has no live bank connections and does not accept real client documents.
Defined retention policies
A real implementation should define which records are kept, why, for how long and how they are deleted, including logs and generated outputs.
In practice
Uploaded material, draft outputs and review records can require different retention periods determined by the institution.
Current portfolio: There is no operational document storage in the public demos. The access preview form does not transmit or store the entered details.
Model governance
Models should be evaluated for the specific workflow, with documented limitations, version tracking and checks when models or prompts change.
In practice
Credit extraction can be evaluated against known figures, and unsupported findings should be flagged for human review.
Current portfolio: The current guided walkthrough uses prewritten results and makes no live AI calls. No model validation or certification is claimed.
Secure deployment options
Deployment choices should match the institution’s access, confidentiality, operational and residency requirements. These requirements need to be established before handling real records.
In practice
A production architecture would evaluate hosting location, encryption, secrets, access controls and monitoring against the intended use.
Current portfolio: This public portfolio is a demonstration site. It is not a certified banking system, and no bank-grade security claim is made.