Public and non-confidential work
Approved public information, general drafting and low-risk productivity tasks.
- Enterprise identity
- Approved tools
- Usage monitoring
AI platform thesis
A practical operating model for moving from promising technology to governed capabilities, adopted workflows and measurable value.
An independent point of view—not the architecture of any employer or bankThe objective is not to maximise the number of AI experiments. It is to repeatedly turn the right opportunities into safe, adopted and measurable outcomes.
Start with the bank’s strategy
An AI strategy should begin with the institution’s priorities, the jobs its people perform and the outcomes its clients experience. The model is a design choice later.
BCG argues that banks should anchor AI in business strategy and move beyond disconnected pilots.[Boston Consulting Group, 21 May 2025]
A good strategy narrows the field. It gives the portfolio a clear reason to say yes, wait or stop.
Treat AI as a platform product
Domain products should feel specific to the user. Underneath, they should reuse enterprise capabilities for identity, retrieval, models, tools, evaluation and operations.
I would build the platform through real use cases, hardening each shared capability as more products reuse it.
Illustrative enterprise architecture—not the architecture of any specific bank.
Selected layer
Where work happens: relationship-manager tools, operations workbenches, research experiences and specialist applications.
Provide differentiated access
Access should depend on user role, business domain, client-data access, data sensitivity, approved tools, deployment environment, permitted actions and required human approval.
The model below is illustrative. A bank would adapt tiers to its classifications, policies and architecture.
Approved public information, general drafting and low-risk productivity tasks.
Internal knowledge and workflows, with domain-based access and stronger data controls.
Strictly bounded use cases in controlled environments with explicit permissions and oversight.
Run a transparent use-case portfolio
A less impressive use case may create more value when it is easier to adopt, safer to operate or builds capabilities the organisation can reuse.
Scores should expose assumptions. They should never replace accountable judgement.
Change the weights. Use cases move as the portfolio's priorities change. All scores are illustrative.
A score is a decision aid, not a decision. Portfolio review still needs evidence, judgement and accountable owners.
Build governance into delivery
Governance that appears only at final approval is both late and inefficient. Important decisions about data, models and actions have already been made.
FINMA’s supervisory guidance points to model, data, IT, cyber, third-party, legal and reputational risks and a materiality-based control approach.[FINMA, 18 December 2024]
Agentic AI makes runtime controls more important. The system needs to know not only what a user can see, but what an agent may do, which tools it may invoke and when a human must approve.
BIS research highlights governance, skills, model risk, data governance and third-party providers as priority areas.[Bank for International Settlements, 12 December 2024]Treat adoption as part of the product
Teams need to understand the existing workflow, design the new one, equip users and stay accountable after release.
“Deploying an AI tool is not the same as changing how work gets done.”
Measure and scale
A use case needs a baseline before launch, product and operational measures after launch, and a clear review rhythm.
The decision is explicit: stop, improve or scale. Platform reuse and evaluation performance matter alongside business outcomes.
The evidence does not support further investment.
The problem is valid; the product or control needs work.
Outcome, adoption and operations are ready to expand.
Evidence base
Selected primary and institutional sources. The full bibliography is available on the sources page.
A useful conversation
I am always interested in difficult product, platform and transformation mandates—especially where trust matters as much as speed.
Start a conversation