Prompts • Skills • Connectors • Agents • Verticals & functions • Tools
AI Playbook for Financial Services Teams
A practical guide to using AI across banking, wealth, lending, insurance, markets, risk and compliance, with clear limits on advice, credit and underwriting decisions, financial-crime determinations, trading, and regulatory filings.
Start With Your Role
Banking, wealth and risk roles start in different places. Begin with preparation and review work; every advice, credit, underwriting, filing and client-contact decision stays with the qualified person accountable for it.
- Start with: client meeting preparation brief
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved CRM notes, licensed research, and prior correspondence
- First agent: meeting preparation briefer
- Measure: completeness, exceptions found, and reviewer changes
- Start with: account onboarding document checklist
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved onboarding files and policy requirements
- First agent: document completeness monitor
- Measure: completeness, exceptions found, and reviewer changes
- Start with: credit file completeness review
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved borrower financials and covenant records
- First agent: covenant and renewal watcher
- Measure: completeness, exceptions found, and reviewer changes
- Start with: portfolio concentration review questions
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved exposure reports and rating definitions
- First agent: watchlist review organizer
- Measure: completeness, exceptions found, and reviewer changes
- Start with: policy-to-procedure gap review
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved policy library and regulatory change feeds
- First agent: regulatory change digest
- Measure: completeness, exceptions found, and reviewer changes
- Start with: case file evidence index
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved case records, excluding any SAR content
- First agent: alert documentation reviewer
- Measure: completeness, exceptions found, and reviewer changes
- Start with: model documentation checklist
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved model inventory and validation reports
- First agent: model documentation monitor
- Measure: completeness, exceptions found, and reviewer changes
- Start with: cash position summary
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved bank reporting and investment policy
- First agent: liquidity assumption organizer
- Measure: completeness, exceptions found, and reviewer changes
- Start with: submission completeness review
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved submission files and coverage guidelines
- First agent: submission completeness monitor
- Measure: completeness, exceptions found, and reviewer changes
- Start with: variance explanation draft
- Save as a skill: approved inputs, output format, and stop rules
- Connect: approved ledgers, budgets, and reporting definitions
- First agent: reporting exception organizer
- Measure: completeness, exceptions found, and reviewer changes
100 AI Prompts for Financial Services Teams
Ready-to-use prompts for client work, research, lending, risk and compliance, financial crime, payments, treasury, finance, insurance, and AI governance. Copy one, add approved and permitted context, and have the accountable person review the result.
Use client & relationship work prompts with approved, permitted information and a named accountable reviewer. AI prepares the work; a qualified person makes every decision.
12 Claude-Ready Financial Services Skills
Downloadable Claude Skill packages for repeatable regulated work. Each defines inputs, output, limits, and an accountable reviewer.
Connect Your Work
Start with approved files, then add a system only after risk, compliance and data-licensing review. Two things to know up front: a data connector carries data you are already licensed for, so you still need your own entitlement with each provider; and a vendor’s own AI trust commitments usually stop at its native assistant.
Easy start
Start with a limited, low-risk connection your team can test quickly.
- Access: approved, permitted copies of reports, policies, templates and de-identified extracts
- Useful for: research summaries, policy gap reviews and reporting drafts with no integration at all
- Setup & limit: work from controlled copies with a named reviewer; do not paste client, account or case data your agreement and policy do not permit
- Access: Gmail, Drive and Calendar read and write for the signed-in user
- Useful for: pulling prior correspondence and approved documents into a preparation brief
- Setup & limit: attachment content is not read and images inside documents are skipped; on a managed domain an administrator must enable it first
- Access: retrieve agreement status, metadata and key dates, and trigger supported workflow actions
- Useful for: a document status and renewal-date worklist
- Setup & limit: Beta - confirm before you rely on it; tool coverage is uneven across environments and production use needs a paid plan
Needs an administrator
These can be useful, but someone needs to set access and permissions first.
- Access: SharePoint, OneDrive, Outlook and Teams content the signed-in user can already open; Teams is read-only
- Useful for: approved documents, meeting records and correspondence history
- Setup & limit: a Microsoft Entra Global Administrator must grant tenant-wide consent; every call is logged to your Microsoft 365 audit log, which your surveillance pipeline can capture - but run a permissions clean-up first, because AI can search everything a user is technically entitled to see
- Access: a purpose-built offering with prebuilt read connectors to major market-data and research providers
- Useful for: research, screening and analysis grounded in data you already license
- Setup & limit: the connector is the pipe, not the license - you must hold and maintain your own subscription with each provider, and an Owner enables connectors for the organization before anyone connects
- Access: read across company profiles, financial statements, market data and earnings transcripts
- Useful for: company research and peer comparison
- Setup & limit: it installs as a custom organization-level connector while the underlying license is per named user, so decide explicitly who may use it before enabling; segment and relationship data coverage varies by company
- Access: read across fundamentals, estimates, ownership, pricing, events and supply-chain data
- Useful for: grounded research and analysis
- Setup & limit: requires a FactSet client relationship and credentials; the entitlement and generative-AI license terms are not publicly documented, so confirm them in writing before enabling for a team
- Access: read across licensed LSEG market data and analytics
- Useful for: cross-asset market context in analysis work
- Setup & limit: requires active LSEG data entitlements, and usage is metered and attributable back to your license - queries may be billable and misuse is detectable
- Access: read across analyst research, market analysis and investment data
- Useful for: fund and investment research
- Setup & limit: delivered through a commercial Morningstar agreement; the entitlement model, limits and redistribution terms are not documented publicly, so confirm scope in writing - ratings and analyst research carry attribution rules when reused in client material
- Access: read across firms, deals, funds and people in private markets
- Useful for: private-market research and diligence preparation
- Setup & limit: each user authenticates with their own credentials, so the connector respects your seat licenses; bulk extraction is restricted, and an assistant that iterates queries can become an extraction tool - keep per-query approval on unless you have decided otherwise
- Access: read, and optionally write, on permitted records, honouring field-level security and sharing rules
- Useful for: relationship review and meeting preparation from approved CRM records
- Setup & limit: an administrator must create and authorize a client application; note that the vendor’s own AI trust commitments cover its native assistant, not an external one - when records leave through a connector, retention and training terms come from your AI vendor agreement instead
- Access: read-only operational telemetry - connection debugging, link conversion analytics and API usage
- Useful for: diagnosing a data-connection problem, not analyzing customer money
- Setup & limit: this carries no consumer financial data at all - no accounts, balances, transactions or identity - so do not plan a customer-analysis workflow around it; consumer data still requires your own application code
- Access: read-only, citation-grounded legal and regulatory research
- Useful for: regulatory research with sources you can follow back
- Setup & limit: requires a CoCounsel subscription and an administrator to enable it; the license prohibits using this content with another professional AI tool, including your own internal model, so results stay in the session where they were produced
- Access: search, read and write files, with metadata and collaboration tools
- Useful for: retrieving approved policy, client and deal documents
- Setup & limit: an administrator enables it, and the document question-and-answer and extraction tools are licensed separately, so the connection can be live while the useful answers stay blocked
Integration project
Plan the use case, source data, permissions, and owner before connecting.
- Access: governed, role-based read against curated data models, with optional write
- Useful for: portfolio, exposure and reporting questions answered from a governed source
- Setup & limit: not available in government regions; exposing a raw query tool beside a governed model lets a client bypass your semantic layer, so keep them on separate servers; the configuration is not replicated on failover, so document it in your recovery plan
- Access: exactly the tools you choose to expose, bound by OAuth scope and your own permission model
- Useful for: one narrow, review-only recurring job before anything is allowed to write
- Setup & limit: the protocol cannot enforce approval on its own, so the real controls are which tools exist and how narrowly the token is scoped; where a platform authenticates at firm level rather than per user, rebuild entitlement filtering yourself or an assistant will surface accounts a person is not entitled to see
Good to know
Useful limits and honest gaps to keep in mind before you connect anything.
- Access: do not begin with case files, suspicious activity material, full client books, trading systems or anything that can transact
- Useful for: choosing a small, reversible first connection
- Setup & limit: never let AI advise a client, determine suitability, decide or price credit or underwriting, make an AML, sanctions or KYC determination, execute a trade, or produce a regulatory filing; and remember AI conversation logs containing client information may themselves be records you must retain
No official path
- Access: none - there is no official Bloomberg connector for any external AI assistant
- Useful for: knowing where the boundary is before someone crosses it
- Setup & limit: Bloomberg terms prohibit recirculating or redistributing the service without prior written consent, and entitlements are per user and non-transferable; tools that extract Terminal data into an external model risk contract breach and audit findings - use the in-Terminal AI instead, and treat any extraction as a contract question for Bloomberg
- Access: none for external AI assistants - the major core platforms embed AI in their own products rather than exposing core data outward
- Useful for: setting expectations before a project is scoped
- Setup & limit: vendors state that client data remains inside their controlled infrastructure, which means a connector you build yourself moves regulated core data outside that boundary and outside their governance - treat it as a full third-party risk exercise, not an integration task
- Access: none for external AI assistants; the major platforms run their own in-product agents
- Useful for: understanding a hard legal boundary before anyone prototypes
- Setup & limit: suspicious activity report content and even the existence of a report may not be disclosed to unauthorized parties, so routing case material through an external AI assistant is a potential unlawful disclosure - never prototype against live case data, and keep every filing decision with a named investigator
- Access: none outward - the AI assistant runs inside the research platform instead
- Useful for: knowing which direction the integration runs
- Setup & limit: content is licensed rather than owned and the agreements restrict extraction and systematic downloading, so a home-built connector risks the contract independently of any AI question; anything advertised as an unofficial connector is not vendor-supported
Tools
Products a financial services team may choose for the work. Evaluate each through your own risk, compliance, information-security, data-licensing and procurement process. A tool is not automatically a permitted connection.
AI Assistants & Writing 8
8Core Banking & Lending 19
19Wealth Management & Advisory 17
17Risk & Compliance 12
12Fraud Detection & Security 12
12Insurance & InsurTech 18
18Payments & Operations 16
16Capital Markets & Trading 19
19Customer Experience 10
10Data & Analytics 12
12Document & Process AI 10
10ESG & Sustainable Finance 8
812 AI Agents for Financial Services Teams
An agent prepares one recurring job from approved information for a named accountable reviewer. It never advises, decides, files, or trades.
A good first agent handles one task your team already does. Give it the information it needs, tell it when to stop, and have a person check the work.
# Meeting preparation briefer ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Document completeness monitor ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Covenant and renewal watcher ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Watchlist review organizer ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Regulatory change digest ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Alert documentation reviewer ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Model documentation monitor ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Liquidity assumption organizer ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Submission completeness monitor ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Reporting exception organizer ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Control evidence collector ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
# Third-party AI review coordinator ## Job to be done Prepare recurring accounting work for qualified human review. ## When it runs On an approved schedule or trigger. ## Approved context Only the approved systems, files, and records named by the workflow owner. ## Operating loop Gather context, apply the approved skill, prepare a work packet, and route exceptions. ## What it delivers A review-ready work packet with evidence, questions, and next steps. ## Human owner A named accounting owner reviews and approves the output. ## What it must never do Never take a consequential action without explicit human approval. ## How to measure it Measure accuracy, cycle time, exception resolution, and human override rate. ## Operating rules 1. Use only approved sources and follow the linked accounting skill. 2. Cite source records and separate facts from hypotheses. 3. Route missing evidence, threshold breaches, and material exceptions to the human owner. 4. Keep an auditable record of trigger, inputs, output, reviewer, decision, and override. 5. Stop and ask for human review when the policy, evidence, or approval authority is unclear.
Wealth Management
Prepare client, portfolio and planning work from approved records. Advice and suitability stay with the licensed advisor.
- Summarize an existing portfolio against the stated investment policy and flag where allocations, concentrations or restrictions no longer match the documented mandate
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble the account, lot and realised-gain information a tax discussion needs, and list the questions for the advisor and tax professional - never a recommended trade
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Group households by documented service model, asset level or review cadence so coverage gaps become visible for the advisor to act on
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Review an automated program’s documented rules, disclosures and exception handling, and list what a person must still confirm before a client is enrolled
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize stated goals, constraints and approved account data into a planning worksheet, marking every assumption that needs the client’s own numbers
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Compare documented questionnaire answers with the recorded objective and flag inconsistencies as questions for the advisor - not a suitability conclusion
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Wealth Management Implementation Checklist
WorkflowPre-Implementation
- Audit existing portfolio construction methodology and define performance benchmarks (Sharpe ratio, alpha, deviation from efficient frontier).
- Inventory all client data: demographics, account balances, holdings, transaction history, goals, risk questionnaires.
- Define compliance requirements: performance attribution, fiduciary sign-off workflows, audit trail retention.
- Select core data integrations: custodian feeds, market data vendors, tax data providers, CRM systems.
- Build pilot cohort (500-2,000 clients) stratified by AUM, segment, platform to test recommendations and monitor drift.
Post-Implementation
- Monitor recommendation adoption rate, client response velocity, and advisor override reasons to identify blind spots.
- Track realized returns vs. target allocation; recalibrate models quarterly based on market regime shifts.
- Measure tax efficiency impact: tax-loss harvests executed, wash sales avoided, tax-equivalent returns improvement.
- Conduct advisor retraining on interpreting AI recommendations and communicating uncertainty to clients.
- Establish feedback loop: collect client satisfaction, advisor trust scores, and performance attribution confidence intervals.
- Suitability Override: Flag any recommendation that deviates from client risk profile by >2 standard deviations; require advisor review and consent form.
- Concentration Limits: Enforce position size caps (e.g., no single holding >15% of portfolio) and sector exposure limits per regulatory guidance.
- Liquidity Guardrails: Ensure rebalancing trades maintain minimum cash buffer (2-3% for advisors' operational needs); avoid forced selling in illiquid positions.
- Tax Drag Monitoring: Alert advisors when estimated tax drag exceeds 0.5% annually; auto-suggest harvesting pairs ranked by magnitude of loss.
- Recommendation Drift Detection: If same client receives conflicting advice (e.g., increase/decrease equity allocation) within 6 months, escalate for model review.
- Advisor Discretion Threshold: Allow advisors to override AI recommendations for compelling reasons; log reason codes for continuous model improvement.
- Assumption Sensitivity: Update all forward projections (retirement, goal funding) monthly using latest market data; alert clients to material plan variance (>10%).
Lending & Credit
Assemble credit files, covenants and portfolio evidence for review. Credit decisions and pricing stay with the authorized credit officer.
- Assemble the credit file, spreads and policy requirements into a decision-ready packet showing what is missing. The credit officer makes the decision
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Check an application package against the documented checklist and produce an outstanding-items list with the owner for each
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize account status, contact history and hardship documentation into a worklist that respects communication rules and permitted contact windows
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document what data a model uses, where it came from and what it may proxy for, so fair-lending review has something concrete to test
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Show the approved rate sheet, applicable exceptions and the deviation being requested, so the authorized approver can price it
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Produce a covenant, maturity and exception worklist from approved records, with the evidence and owner attached to each item
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Lending & Credit Implementation Checklist
WorkflowPre-Implementation
- Establish model governance: define development/validation/monitoring roles; document model assumptions, data lineage, and performance targets.
- Assemble historical loan-level data: applications, approvals, fundings, payments, defaults, collections outcomes for 2-5 year lookback.
- Conduct disparate impact analysis on current lending patterns; identify and document any regulatory or reputational risks pre-implementation.
- Integrate data feeds: credit bureaus, alternative data providers, bank transaction APIs, employment verification services, document processors.
- Pilot in shadow mode: AI prepares the file while underwriters decide as usual; compare file completeness and where the reviewer disagreed.
Post-Implementation
- Monitor model performance weekly: origination rate, approval rate, average risk score, loss emergence vs. forecast by origination vintage.
- Validate fairness metrics monthly: disparate impact ratio, adverse action rates, and loan performance parity across protected classes.
- Track operational metrics: time-to-decision, cost-per-loan, document exception rates, manual review burden, and workflow bottlenecks.
- Establish retraining cadence: retrain models quarterly or after policy/product changes; validate on holdout test set before deployment.
- Publish transparency reports: disclosure of AI use in decisions, model explainability, and adverse action notice generation for regulatory compliance.
- Model Risk Review: Conduct annual independent validation of AI models by compliance/audit; document assumptions, limitations, and performance degradation scenarios.
- Explainability Requirement: Maintain audit trail of key decision factors for every approval and denial; enable applicant-level explanations for adverse actions within 30 days.
- Disparate Impact Thresholds: Flag any protected class group with approval/loss rate deviation >10%; require remediation (model retuning or policy override) before expanding.
- Manual Override Tracking: Log underwriter overrides of AI recommendations; quarantine low-performing override patterns for model feedback.
- Data Quality Gates: Reject applications with missing critical fields (income, employment, alternative data) unless explicitly approved by exception workflow.
- Collections Fairness: Ensure collection strategy respects debt-to-income thresholds; do not pursue borrowers with imminent hardship signals.
- Pricing Transparency: Disclose APR/fee rationale to borrowers; flag unusually high or low pricing for underwriter review to prevent predatory or loss-making offers.
Insurance AI
Organize submissions, claims files and coverage questions. Underwriting, pricing and claims determinations stay with the authorized person.
- Check a submission against the documented underwriting guideline and list missing information and referral triggers for the underwriter
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Summarize a claim file, index the documentation and list the outstanding items, leaving coverage and payment determinations to the adjuster
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize the indicators already recorded on a file into an evidence index for a trained investigator to evaluate
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document the rating factors, filings and approvals a pricing change depends on, so actuarial and compliance review has a complete record
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble claim history and development inputs with each source labeled, so the actuary can review the basis rather than reconstruct it
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Draft approved-template policyholder communications for review, keeping coverage statements to language already approved
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Insurance Implementation Checklist
WorkflowPre-Implementation
- Audit current underwriting and claims workflows to identify high-volume, rule-based decision points
- Establish data governance: consolidate policyholder, claims, and third-party data into unified data lakes
- Define baseline metrics: average underwriting time, claims processing duration, fraud detection rate, loss ratios
- Identify regulatory constraints: validate AI outputs against state insurance codes and anti-discrimination requirements
- Secure executive sponsorship and budget allocation for 12-18 month implementation timeline
Post-Implementation
- Monitor model drift: quarterly retraining on new claims and underwriting data to maintain accuracy
- Track review metrics: processing time reduction, fraud prevention dollars, premium accuracy, claims closure rates
- Establish human-in-the-loop reviews for edge cases, appeals, and high-value claims to maintain trust
- Audit for bias: ensure models don't inadvertently discriminate by age, location, or protected attributes
- Scale incrementally: pilot in one business line before enterprise rollout to manage change management risk
- Explainability: Maintain transparent underwriting reasons and provide claimants with clear explanations for automated denials to satisfy FCRA and state regulations
- Anti-Discrimination: Implement fairness constraints on protected attributes (age, gender, race, zip code) and monitor disparate impact metrics quarterly
- Audit Trail: Log all underwriting and claims decisions with model versions, thresholds, and decision reasoning for regulatory examination
- Human Escalation: Route unusual claims, high-value decisions, and edge cases to trained adjusters for override authority and judgment calls
- Third-Party Validation: Have external actuaries validate pricing models and reserve adequacy before deployment to new markets or risk classes
- Data Security: Encrypt all PII and medical data in transit and at rest; implement role-based access controls for AI model access
Capital Markets & Trading
Summarize research, filings and market context. Trade decisions and execution stay with the licensed desk.
- Summarize the documented execution policy, venue rules and exception log for review. AI does not route or execute orders
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Summarize filings, transcripts and licensed research with each fact traced to its source, marking anything unverified
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Aggregate what named, permitted sources said, keeping the quotation and the inference clearly separate
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize flagged activity and the documented rationale into a review packet for the surveillance analyst
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Record what a dataset covers, its license terms and its known gaps, so research and compliance can judge whether it may be used
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Restate the constraints, limits and objectives already documented, and show where a portfolio sits against them
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Capital Markets Implementation Checklist
WorkflowPre-Implementation
- Inventory trading strategies and execution workflows to identify which are rules-based vs. discretionary
- Consolidate market data: aggregate real-time quotes, order books, trade history (2-5 years) from all trading venues
- Establish baselines: measure current execution costs, alpha generation, research cycle time, and detection of market anomalies
- Secure compliance sign-off: ensure AI execution and surveillance models meet SEC, FINRA, and exchange requirements
- Define risk controls: establish maximum order size, loss limits, and circuit breakers for algorithmic strategies
Post-Implementation
- Monitor execution quality: track daily slippage vs. benchmarks, market impact, and execution consistency
- Measure alpha: benchmark portfolio returns against risk-free rate and market indices with proper attribution analysis
- Review market surveillance hits: validate AI detections with compliance team and report suspicious activity to regulators
- Retrain models quarterly: update algorithms with new market data, regime changes, and emerging trading patterns
- Expand data sources: integrate additional alternative data feeds and venue connectivity as infrastructure improves
- Circuit Breakers: Implement hard stops on algorithmic execution if daily losses exceed threshold or market volatility spikes beyond tolerance
- Order Validation: Apply pre-execution checks on all AI-generated orders to ensure size, price, and venue compliance with SEC Reg SHO and exchange rules
- Surveillance Logging: Maintain detailed audit trail of all trades, orders, and cancellations for SEC examination and FINRA reporting
- Human Oversight: Require senior trader sign-off on high-risk strategies and reserve ability to override AI execution in real-time
- Stress Testing: Run monthly scenarios on edge cases (flash crashes, liquidity crises) to validate algorithm stability under duress
- Vendor Validation: Audit third-party data providers for accuracy and verify alternative data sources are legally compliant
- Backtesting Rigor: Use out-of-sample validation and walk-forward testing to avoid overfitting and false alpha claims
Private Equity & Venture Capital
Prepare sourcing, diligence and portfolio-monitoring material. Investment decisions and LP commitments stay with the deal team.
- Build a researched target list from licensed private-market data with the source and date on every record
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Index a data room against the diligence checklist and produce an outstanding-items list by workstream and owner
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble reported KPIs and covenant positions into a monitoring pack, flagging where a company has not reported
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Lay out the comparables, assumptions and sources behind a valuation range so the deal team can test each input
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Draft an LP reporting narrative from approved figures, separating reported results from commentary that needs sign-off
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- List where private-market data licenses, confidentiality undertakings and material non-public information restrict what may be shared with any AI tool
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
PE/VC AI Readiness Checklist
ChecklistBefore You Start
- Document your investment thesis with quantitative criteria AI can pattern-match against
- Audit historical deal data, win/loss, sourcing channel, diligence timeline, to train AI models
- Assess current CRM and deal tracking systems for AI integration readiness
- Establish data room security requirements for AI diligence tools
- Get IC alignment on how AI sourcing signals feed into investment process
After Go-Live
- Track deal sourcing volume and conversion rates by channel (AI vs. network vs. inbound)
- Measure diligence cycle time reduction and analyst hour savings
- Review portfolio monitoring alert quality, false positives and lead time to performance issues
- Assess LP report quality and time savings quarterly
- Calibrate sourcing model against deals that progressed vs. those that didn’t
- Investment decisions must remain with qualified investment professionals, AI provides analysis and signals, not investment recommendations
- Data room AI tools must operate in isolated environments, cross-contamination between competing deal contexts creates fiduciary risk
- AI-generated LP communications must be reviewed by IR professionals before distribution
- Valuation models must be validated by independent professionals for fund NAV and reporting purposes
- Document AI tool usage in investment process for LP due diligence and regulatory examination
Risk & Compliance
Turn policy, control and regulatory material into review packets and evidence indexes. Risk acceptance stays with the accountable owner.
- Turn incident and issue records into a themed review pack with the evidence and remediation owner for each item
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Restate documented limits, exposures and breaches with their sources so the risk committee reviews evidence, not recollection
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Index the evidence a report depends on and list what is missing. AI does not produce or submit the filing
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Check model documentation against your own standard and list gaps in purpose, data, testing, limitations and monitoring
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document scenario definitions, assumptions and data lineage so results can be explained and reproduced
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize screening results and supporting documents into a review file. Every match determination stays with a trained analyst
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Risk & Compliance Implementation Checklist
WorkflowPre-Implementation
- Conduct compliance readiness assessment: map current processes, policies, and control gaps against regulations (BSA/AML, GDPR, CCPA, Model Risk Rules).
- Establish AI governance framework: define roles (AI governance committee, model owners, validators), approval workflows, and escalation paths.
- Integrate data infrastructure: ensure real-time access to transaction feeds, sanctions lists, entity data, and external data providers; validate data quality and latency SLAs.
- Define model performance targets and acceptable false positive/negative rates; establish monitoring dashboards and alerting thresholds.
- Pilot detection rules in parallel: run AI alerts alongside legacy rules for 30-60 days; measure sensitivity, specificity, and compliance resource impact before cutover.
Post-Implementation
- Monitor alert volume, true positive rate, and analyst closure velocity daily; tune thresholds to balance detection and workload.
- Conduct quarterly independent model validation: assess discrimination, bias, stability, and adherence to governance policies.
- Track regulatory submission accuracy and timeliness; obtain feedback from regulators on SAR quality and completeness.
- Publish model documentation: maintain records of assumptions, data lineage, performance metrics, and validation results for regulatory audit readiness.
- Retrain models monthly or after material data drift detected; capture feedback from compliance analysts to improve model interpretability and alert precision.
- Model Performance Monitoring: Track accuracy, precision, recall, and AUC weekly; alert when any metric degrades >5% vs. baseline; halt model use if performance falls below minimum thresholds.
- Bias & Fairness Testing: Measure model performance across demographic groups quarterly; document protected class parity; escalate disparities >3% for investigation.
- Data Quality Validation: Enforce completeness, timeliness, and accuracy checks on input data streams; reject transactions with missing critical fields from processing.
- Alert Escalation Rules: Route high-confidence alerts to analysts; auto-escalate unresolved alerts after 24 hours; require supervisor sign-off on case closure.
- Sanctions List Currency: Update screening lists daily from official sources (OFAC, UN, EU); flag gaps or delays in list updates for compliance approval.
- Explainability & Audit Trail: Maintain reason codes and evidence for every alert and decision; enable 100% traceable audit logs for regulatory exams and legal discovery.
- Model Versioning & Rollback: Tag all model deployments with version, date, validator approval; maintain ability to roll back to prior version within 1 hour if drift detected.
Fraud Detection
Organize alert and case documentation for an investigator. Fraud determinations and account actions stay with authorized staff.
- Summarize the activity and documented rules behind an alert so an analyst can assess it, without deciding the outcome
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- List which verification steps were completed, which failed and what evidence is outstanding for the reviewer
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble the recorded access and change history for an account into a timeline for investigation
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document what a behavioural signal measures, its known limits and its error modes, so the control can be governed and challenged
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize recorded indicators and response steps into an incident timeline for the security team
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Index case evidence and draft the factual chronology, leaving the determination and any filing to the investigator
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Fraud Detection Implementation Checklist
WorkflowPre-Implementation
- Establish baseline fraud metrics: current fraud rate by channel/product, detection rate, false positive rate, and investigation turnaround time.
- Inventory data sources: transaction logs, authentication events, device data, geolocation, merchant info, third-party threat feeds, fraud labels for model training.
- Prepare labeled dataset: manually review and label 5,000-10,000 confirmed fraud/legitimate transactions from past 12 months for model training.
- Define decision rules: establish fraud score thresholds for automatic blocking, challenge, and manual review based on loss tolerance and customer impact targets.
- Pilot shadow mode: run AI fraud detector alongside legacy system for 4-8 weeks; measure agreement, missed fraud, and false positive delta before cutover.
Post-Implementation
- Monitor fraud metrics hourly: fraud rate, detection rate, false positive rate, average fraud loss, and cost-per-fraud by channel and product.
- Track customer experience: measure authentication friction (step-up rate, decline/approval ratio), complaint volume, and customer satisfaction impact.
- Conduct weekly fraud team reviews: analyze confirmed fraud cases, identify emerging typologies, and adjust rules/thresholds based on fraud evolution.
- Retrain models bi-weekly with new fraud labels; validate on holdout test set; deploy updates with A/B testing to measure performance lift.
- Maintain threat intelligence feeds: update device fingerprint databases, IP reputation lists, and dark web monitoring to catch new attack methods early.
- Automatic Decline Threshold: Block transactions with fraud score >95th percentile automatically; flag for investigation within 24 hours; enable quick release via customer verification.
- Step-Up Authentication Trigger: Require additional auth (OTP, biometric) for scores 75-95th; personalize challenges based on customer history (rare events, new devices, unusual locations).
- Velocity Limits: Enforce transaction count, amount, and merchant category velocity limits per device/account/IP; escalate unusual patterns for review.
- Geographic Impossibility: Flag transactions from geographically impossible locations (e.g., same account used in two cities <2 hours apart); require confirmation.
- Device Fingerprint Monitoring: Track device changes and anomalies; require re-authentication after new device registration or device list tampering detection.
- Merchant Blacklist Management: Maintain dynamic merchant risk ratings; block transactions from high-risk merchant categories for new cardholders; escalate suspicious merchant patterns.
- Dispute Rate Monitoring: Track post-transaction fraud disputes and chargebacks; retrain models quarterly using confirmed fraud labels to catch emerging patterns.
KYC / AML & RegTech
Prepare due-diligence and screening documentation. Every AML, sanctions and KYC determination stays with a named investigator.
- Produce a refresh worklist showing which records are stale, which documents expired and who owns each outstanding item
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Summarize the documented pattern behind an alert for analyst review. AI does not clear, escalate or determine an alert
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble name, date and jurisdiction evidence for a potential match so a trained analyst can adjudicate it
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Check an onboarding file against the documented requirement list and produce the outstanding-items list
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Index supporting evidence and completeness gaps. Suspicious activity reporting content, and the existence of a report, stay out of any AI tool
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- State plainly what may never enter an AI assistant here: suspicious activity report content, the fact a report exists, and live case material
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
KYC/AML AI Implementation Checklist
ChecklistBefore You Start
- Map current KYC/AML workflow: volumes, alert rates, false positive %, analyst FTE cost
- Audit data completeness: transaction feeds, customer master, beneficial ownership, adverse media sources
- Confirm regulatory appetite with compliance and legal: explainability requirements for your jurisdictions
- Run parallel model testing for 60–90 days before decommissioning legacy rules
- Establish false positive and false negative SLAs with compliance leadership
After Go-Live
- Track alert volume, analyst workload, and true positive rate monthly
- Review SAR filing quality and regulatory feedback from examiners
- Monitor for model drift, set automated retraining triggers
- Measure onboarding conversion rate and time-to-approve vs. baseline
- Conduct annual model validation with independent third party
- Keep every filing decision with a named investigator. Suspicious activity report content, and the fact a report exists, stay out of any AI tool entirely
- Document model methodology and feature importance for regulatory examination readiness
- Sanctions list updates must be applied within 24 hours of publication, automate this process
- Segment AML models by customer type and channel, a retail model applied to correspondent banking will underperform
- Conduct adversarial testing to identify model blind spots before deployment
Payments & Banking Operations
Produce exception worklists and operational summaries from approved records. Payment actions stay with authorized operators.
- Summarize documented routing rules, cutoffs and exceptions so operations can review them against what the records show happened
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Produce a break and exception worklist with the supporting records attached and an owner on every line
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble the cash and funding position from approved reporting with the source and timestamp on each figure
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Group recurring exceptions into themes and show the documented handling procedure for each
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document settlement timing, breaks and their recorded causes so operations can prioritize the real problems
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize screening outcomes and documentation for review, leaving release and block decisions to authorized operators
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Payments Implementation Checklist
WorkflowPre-Implementation
- Map payment flows: document all entry points (AP, payroll, treasury), channels, and decision logic currently in place
- Consolidate data: aggregate transaction history (12-24 months), customer master files, and vendor profiles into centralized systems
- Establish baselines: measure current reconciliation time, payment failure rates, cost per transaction, and settlement delays
- Assess integrations: evaluate API capabilities of banks, payment providers, and ERP systems for real-time feeds
- Define governance: establish approval workflows for AI decisions, override thresholds, and escalation paths
Post-Implementation
- Monitor transaction velocity: track payment processing speed, settlement times, and automated vs. manual exception rates
- Audit cost savings: quantify reductions in manual reconciliation hours, payment failures, and financing costs
- Validate compliance: ensure all AML/sanctions screening maintains regulatory thresholds and generate audit reports
- Tune models monthly: adjust routing logic and exception thresholds based on new payment methods and costs
- Expand scope: roll out to international subsidiaries and integrate new payment channels as they emerge
- AML/KYC Validation: Screen beneficiaries against multiple OFAC, sanctions, and PEP databases in real-time before transaction execution
- SLA Enforcement: Ensure AI routing decisions meet agreed settlement times and payment velocity requirements with counterparties
- Audit Logging: Record all routing decisions, exceptions, and overrides with timestamp and reasoning for regulatory examination
- Manual Override Authority: Preserve treasury team's ability to override AI decisions on high-value or strategically important payments
- Cross-Border Compliance: Validate payment corridors against OFAC, FCPA, and sanctions rules in all destination countries
- Data Encryption: Encrypt all payment data in transit to payment processors and at rest in reconciliation systems
- Data Encryption: Encrypt all payment data in transit to payment processors and at rest in reconciliation systems
Customer Experience & Engagement
Draft and review client-facing material and service summaries. Approval and sending stay with the responsible person.
- Review documented intents, escalation paths and approved answers, and list where a customer would reach a dead end
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Restate the documented eligibility and consent rules behind an offer so marketing and compliance can check them together
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Map the documented onboarding journey and list where a customer must supply something and where a person must review
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Draft approved-template alert copy for review, keeping anything that could read as advice out of it
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Summarize permitted call recordings into themes with each theme traceable to the calls behind it
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document how a customer moves between channels and where context is lost, as a list of gaps to fix
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Customer Experience Implementation Checklist
WorkflowPre-Implementation
- Map customer journeys: document all touchpoints (digital, voice, branch) and identify bottlenecks and manual handoffs
- Consolidate customer data: create unified customer 360 view by combining transaction, service, and behavioral data from all systems
- Establish baselines: measure current NPS, first-call resolution, cross-sell rates, onboarding time, and churn rates by segment
- Define personalization strategy: identify highest-value use cases (product recommendations, churn prevention, activation)
- Secure infrastructure: ensure cloud or on-premise systems can handle real-time data feeds and API calls
Post-Implementation
- Monitor customer satisfaction: track NPS, CSAT, and effort scores by channel with monthly trend analysis
- Measure engagement impact: quantify cross-sell lift, onboarding conversion, and churn reduction from personalization
- Maintain conversation quality: review bot interactions weekly to improve response accuracy and identify escalation gaps
- Ensure regulatory compliance: audit AI recommendations for bias and ensure voice recording policies are documented
- Expand to new segments: migrate learnings across customer tiers and geographic markets with localized content and rules
- Consent Management: Maintain explicit opt-in consent for personalization and marketing communications; respect opt-out requests immediately
- Data Privacy: Encrypt customer data in transit and at rest; limit AI model access to PII and enforce minimum necessary data principles
- Transparency: Disclose when customers are interacting with bots and provide easy handoff to human agents on request
- Fair Lending: Audit recommendations for potential discrimination by protected attributes; monitor disparate impact in credit and product recommendations
- Recording Compliance: Obtain recorded consent before voice calls and comply with state two-party consent requirements (California, Florida, Pennsylvania, etc.)
- CCPA/GDPR: Honor customer data access, deletion, and portability requests within regulatory timelines
Treasury Management & Liquidity
Assemble cash, liquidity and exposure evidence with the assumptions stated. Funding and hedging decisions stay with treasury.
- Assemble forecast inputs with each source and assumption labeled, so treasury reviews the basis rather than the output
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Summarize the documented position against policy limits and show where a buffer is being approached
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Restate recorded exposures and the documented hedging policy, and list the questions for treasury - never a hedge recommendation
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Organize payment timing, fees and terms from approved records into a review worksheet
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Index facilities, maturities and covenant requirements with their source documents attached
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Note where investment policy, counterparty limits and delegated authority mean an AI-prepared worksheet may not become an instruction
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
Treasury AI Readiness Checklist
ChecklistBefore You Start
- Map all bank accounts and establish real-time balance visibility across entities
- Assess AR/AP data quality, completeness and timeliness determine forecast accuracy
- Document current hedging policy and FX exposure methodology
- Identify top 3 treasury pain points by cost and time impact
- Get treasury management system (TMS) integration specs from IT
After Go-Live
- Track forecast accuracy (MAPE) at 4-week, 8-week, and 13-week horizons
- Measure working capital improvement and idle cash reduction
- Review hedging effectiveness and hedge accounting compliance quarterly
- Monitor bank fee savings from AI-optimized payment routing
- Report treasury KPIs to CFO monthly, before/after comparison
- Require dual human approval for payment executions above a defined threshold. AI prepares the payment file for review and never executes it
- Investment decisions must stay within board-approved Investment Policy Statement (IPS) parameters, AI cannot override policy constraints
- Cash forecast models should be validated quarterly against actuals and recalibrated if MAPE exceeds 15%
- FX hedge recommendations require treasurer review and sign-off, never fully automate hedging execution
- Maintain audit trail for all AI-generated treasury recommendations and decisions
FP&A & the CFO Office
Prepare forecasts, variances and reporting narratives from approved ledgers. Numbers are owned by finance, not the model.
- Organize forecast drivers and assumptions from approved ledgers, marking which inputs are actuals and which are estimates
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Lay out scenario definitions and their inputs side by side so reviewers can compare the assumptions behind each, not only the outcomes
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Draft variance explanations from approved ledger detail, separating confirmed drivers from ones still to be investigated
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Check budget submissions against the documented template and produce a completeness and consistency worklist
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Assemble the evidence behind a decision paper with each figure sourced, leaving the recommendation to the accountable executive
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Flag where a figure has been carried between systems without reconciliation, and where a reported number needs an owner before it is circulated
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
FP&A AI Readiness Checklist
ChecklistBefore You Start
- Audit chart of accounts consistency across business units and legal entities
- Document your current forecast methodology, cycle timeline, and known accuracy issues
- Identify your top 5 operational drivers most predictive of revenue and cost
- Assess current EPM/planning tool capabilities and integration gaps
- Set baseline forecast accuracy metrics to measure AI improvement
After Go-Live
- Track forecast accuracy improvement (MAPE) by business unit and time horizon
- Measure analyst time savings in budget cycle and monthly close
- Collect CFO and board feedback on narrative quality and decision utility
- Review scenario model usage and adoption by business partners
- Recalibrate models after major business events (acquisitions, restructurings)
- AI forecasts must be reviewed and approved by a qualified finance professional before being presented to board or external parties
- Document all material assumptions in AI-generated forecasts for audit and governance purposes
- Maintain human override capability, AI forecast is an input, not a mandate
- Ensure AI-generated financial narratives are reviewed for accuracy before inclusion in investor communications or regulatory filings
- Validate models against out-of-sample data before production deployment
ESG & Sustainable Finance
Organize sustainability data, disclosures and climate material for review. Reporting sign-off stays with the accountable owner.
- Index which disclosures exist, which are missing and where a figure was estimated rather than reported
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Document scenario sources, assumptions and coverage limits so the analysis can be explained and challenged
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Map disclosure requirements to the evidence that supports each one, and list the gaps with owners
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Compare public claims with the underlying documented evidence and list unsupported statements as questions for review
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Check a file against the documented sustainability criteria and list what evidence is still outstanding
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
- Note where an ESG claim becomes a regulated statement, and where an estimated figure must be labeled as estimated
- What to review: Confirm the source of each fact, what a document states on its face, and what is still an assumption
- Control: The accountable qualified person makes every advice, credit, underwriting, filing, trading and client-contact decision
ESG AI Implementation Checklist
ChecklistBefore You Start
- Identify which reporting frameworks apply: CSRD, TCFD, ISSB, SEC climate rules, GRI
- Audit current ESG data sources and gaps, especially Scope 3 supply chain data
- Assign ESG data ownership across functions (Finance, Operations, Procurement, HR)
- Assess climate risk exposure of loan book or investment portfolio
- Establish materiality assessment to prioritize disclosure topics
After Go-Live
- Track data completeness and quality scores across ESG metrics
- Review AI-generated sustainability report narratives before publication
- Monitor regulatory changes in target jurisdictions quarterly
- Measure Scope 3 data coverage improvement from supplier engagement
- Assess third-party assurance readiness annually
- All AI-generated ESG disclosures must be reviewed and approved by qualified sustainability professionals before publication
- Maintain complete audit trail of data sources, calculation methodologies, and assumptions for assurance and regulatory examination
- Do not use AI-generated estimates to replace supplier-specific emissions data where material, regulators and assurers will scrutinize estimation methodologies
- ESG claims in marketing and client communications must be substantiated before release, legal review required
- Climate scenario models are projections, not predictions, communicate uncertainty ranges in all disclosures
Set Up & Get Running
Begin with one low-risk preparation workflow using approved files. Add a connection only after risk, compliance, information security and data-licensing review.
Days 1-30: Foundation
- Audit current state: Identify existing AI/ML initiatives, data assets, and skill gaps
- Set governance framework: Create AI steering committee, compliance checklist, vendor risk template
- Identify quick wins: 2-3 high-value, low-risk use cases (e.g., document automation, chatbot)
- Set up data pipeline: Assess data quality, establish security controls, document data lineage
- Pilot one use case: Launch proof-of-concept with 1-2 vendors or internal models, measure baseline
Days 31-60: Expansion
- Scale pilot: Move POC to staging environment, validate business impact, document lessons learned
- Integrate with core systems: Connect AI to loan origination, claims, or trading systems; test data pipelines
- Train teams: Upskill business users on AI tools, educate leadership on review and risks
- Measure review: Track cost savings, cycle time reduction, accuracy improvements vs. baseline
- Refine governance: Update model risk framework based on pilot insights, document decisions
Days 61-90: Scale
- Production deployment: Move pilot to production with monitoring, logging, and rollback procedures
- Governance framework: Implement model governance, compliance monitoring, audit trails
- Expand to second use case: Launch second AI initiative based on learnings from first pilot
- Report results: Executive summary of impact, review, lessons learned, and next phase roadmap
- Build AI CoE: Establish AI Center of Excellence for scaling models across the organization
Implementation Success Metrics
Goals30-Day Targets
- 5-10 team members trained & actively using AI tools
- Baseline KPIs established (processing time, error rates, compliance metrics)
- AI usage guidelines documented with regulatory considerations
- Daily feedback collected from pilot group
60-Day Targets
- Full team deployed with AI tools across pilot workflows
- 10-15 proven prompts in shared library
- 2nd tool integrated & live (risk scoring OR fraud detection)
- KPI improvement measured vs. baseline (e.g., 30% faster processing)
90-Day Targets
- 3 workflows operationalized with SOPs and compliance documentation
- AI usage policy formalized with legal & compliance sign-off
- Team cross-trained (no single points of knowledge failure)
- Total review calculated: processing time saved, error reduction, compliance improvement
- Next wave planned (e.g., customer analytics, automated reporting)
- Week 1: Announce AI pilot to business unit leadership. Share vision, timeline, and compliance framework.
- Week 2-3: Train pilot group on tools & prompts. Go live with document processing or research synthesis.
- Week 4: Collect feedback. Share early wins. Brief compliance team on governance adherence.
- Week 5-8: Expand to full team. Add 2nd tool. Publish prompt library. Weekly tips in team meetings.
- Week 9: Formalize policy with legal review. Document SOPs. Cross-train backups.
- Week 10-12: Measure impact. Present to leadership. Celebrate wins. Plan next wave.
How the Pieces Fit Together
A prompt helps with one task now. A skill saves how your team does it. A connector brings approved, licensed context in. An agent runs one recurring job for a named accountable owner.
- Research synthesis and report generation
- Regulatory document analysis
- Client communication drafting
- AI-powered loan origination and decisioning
- Automated underwriting and credit scoring
- Digital account opening and KYC
- AML/KYC screening and monitoring
- Regulatory reporting automation
- Model governance and explainability
- Portfolio optimization and rebalancing
- Tax-loss harvesting automation
- Goal-based financial planning
- Real-time transaction fraud scoring
- Biometric identity verification
- Cyber threat detection and response
- Algorithmic trading and execution
- Alternative data and sentiment analysis
- Research automation and market intelligence
Where AI Can Help a Financial Services Team
AI can prepare, organize and review regulated work. It does not advise clients, decide credit or underwriting, make a financial-crime determination, trade, or produce a filing.
- Assemble licensed research, filings and approved records into a brief
- Show the source and date behind every fact
- The qualified person confirms the facts and forms the view
- Check a credit, onboarding, claim or control file against the documented requirement list
- Produce an outstanding-items worklist with an owner on each line
- The accountable owner decides, approves and signs
- Draft reporting narratives and approved-template communications
- Separate what a document states from what is still an assumption
- A reviewer approves anything that reaches a client or a regulator
- Investment advice, suitability, and any client recommendation
- Credit, underwriting, pricing and claims determinations
- AML, sanctions and KYC determinations, regulatory filings, and trade execution
Controls, Compliance & Guardrails
Financial services AI touches client data, licensed market data, credit and underwriting files, and financial-crime material. Set these controls before the first pilot.
- SR 11-7 and SS1/23 compliance frameworks
- Model inventory and version control
- Independent model validation and backtesting
- Performance monitoring and retraining triggers
- EU AI Act classification and compliance
- SEC guidance on AI disclosure and risk
- OCC bulletin on AI risk management
- CFPB guidance on fair lending and AI
- Fair lending compliance (ECOA, FHA, FCRA)
- Disparate impact testing and auditing
- Adverse action explanations and appeals
- Training data bias detection and mitigation
- GLBA Safeguards Rule and Privacy Rule
- CCPA/CPRA and state privacy laws
- PCI DSS and payment data protection
- Encryption, access controls, and data residency
- AI vendor due diligence and contracting
- Concentration risk and dependency management
- SLA monitoring and performance tracking
- Contingency planning and business continuity
- Model interpretability and feature importance
- Customer-facing decision explanations
- Regulatory disclosure and audit trails
- Bias assessment and fairness metrics
- AI does not decide, price or deny credit; it prepares the file for an authorized officer
- Document what data any model uses and what it may proxy for, so fair-lending testing has something concrete to examine
- Adverse action reasons must be explainable from documented factors, not from a model nobody can interpret
- A connector gives you the pipe, not the license - you still need your own entitlement with each data provider
- Market data licenses are per named user while connectors are enabled organization-wide; decide explicitly who may use each one
- AI output containing licensed data is usually derived data - check your agreement before circulating it externally
- Suspicious activity report content, and the fact that a report exists, must not be disclosed to unauthorized parties
- Never prototype an AI workflow against live financial-crime case data
- Every alert disposition and filing decision stays with a named investigator
- AI conversation logs containing client or account information may themselves be records you must retain
- Where a platform authenticates at firm level rather than per user, rebuild entitlement filtering or an assistant will surface accounts a person may not see
- Supervision expects to see who asked, what was returned, and who approved the result