Talk

AI in Financial Services: Authority and Evidence

An evidence-led talk on deploying AI in regulated financial services: action tiers, human approval, replayable evidence, and the limits of what controls prove.

Direct answer

Direct answer: AI in financial services

This talk is for financial-services audiences who need to deploy AI in controlled environments. It explains how to bound what an AI system or agent may do, where human approval belongs, and what evidence must exist for review, using experience from regulated banking AI at Aveni and public reference systems. It is an engineering and governance discussion, not a regulatory assurance claim.

The question

“Our audience needs an evidence-led discussion of deploying AI in controlled environments, not a regulatory assurance claim.”

Who it is for

Fintech and banking conferences, risk and compliance events, regulated-industry meetups, and internal sessions for financial institutions.

Abstract

What the talk covers

Financial-services firms want the productivity of AI assistants and agents without handing them authority nobody can review. The difficulty is that a guardrail on what a model says does not control what a connected agent can do: change a customer record, propose a payment, or send a message. This talk moves the control boundary to the action. It sets out an action-tier model that classifies tool effects by consequence, shows where segregation of duties and human approval belong, and describes the evidence a firm needs to review and replay a decision later. The material draws on regulated banking AI work at Aveni, where Dipankar was part of the team in the first FCA Supercharged Sandbox cohort, and on the public reference systems CloseGate and Regulus. It is also explicit about limits: mapping controls to a framework is not certification, sandbox participation is not endorsement, and no talk replaces a firm’s own regulatory judgement.

The audience leaves able to

  • →Why AI control in financial services belongs around actions, not only model output
  • →An action-tier model for deciding which effects need approval, segregation, or refusal
  • →What evidence a firm should retain to review and replay an AI-assisted decision
  • →What controls and sandbox participation do and do not demonstrate

Audiences

Fintech Banking Risk and compliance Agent security

Formats

  • Conference talk
  • Keynote
  • Panel
  • Webinar
  • Podcast
  • Workshop variant

What you leave with

Talk brief connecting technical controls, human authority, and evidence boundaries.

  • 01 An abstract tailored to the audience: technology, risk, compliance, or mixed
  • 02 An action-tier model and approval-boundary pattern attendees can adapt
  • 03 An outline evidence schema for AI decisions and tool actions
  • 04 Short and long speaker biographies from the speaker kit

How it runs

Structure and format

Duration
30–45 minutes as a talk; 60 minutes with discussion; panel contribution on request
Delivery
In person in the UK, travel by agreement, or remote
Participants
Technology, risk, compliance, and product leaders in banks, insurers, wealth firms, and fintechs
01

Why the control belongs around the action

Guardrails on model text are not enough when an agent can change a record, propose a payment, or contact a customer.

02

Action tiers and approval

Classifying tool effects by consequence, segregating duties, and requiring approval for material or irreversible actions.

03

Evidence that survives review

What to retain so a decision can be reviewed and replayed: identity, purpose, policy version, approval, request, receipt, and outcome.

04

What controls do not prove

Why mapping controls to a framework is not certification, and why sandbox participation is not endorsement.

Audience assumptions

  • →A general understanding of how AI assistants or agents are being used in the audience’s organisations
  • →No legal or engineering specialism is assumed

Evidence

What this draws on

Delivery experience

Regulated banking AI at Aveni

Architected enterprise banking AI with conduct-risk workflows, evidence generation, human review, escalation, evaluation, versioning, and release controls. Part of the Aveni team in the first FCA Supercharged Sandbox cohort; the FCA lists Aveni as an accepted firm, which is not an FCA endorsement or certification.

Inspect the source ↗
Public reference system

CloseGate

A Python and MCP policy layer with action tiers, segregation of duties, materiality routing, mandatory approval for irreversible actions, and hash-chained replayable audit. No published independent certification or customer deployment.

Inspect the source ↗
Public reference system

Regulus

A runtime-governance architecture covering agent identity and purpose, policy, PII, residency, model-risk tiers, kill switches, human oversight, and evidence export. Controls are mapped to NIST AI RMF and ISO/IEC 42001; mapping is not certification.

Inspect the source ↗

Scope and limits

What this is not

  • —The talk is not legal or regulatory advice and does not state what any regulator requires of a particular firm.
  • —Participation in the FCA Supercharged Sandbox as part of the Aveni team is not an FCA endorsement or certification.
  • —CloseGate and Regulus are public reference systems without published independent certification or customer deployment; confidential delivery detail is not disclosed.

If the need is different

Common questions

Answers before you commission

Is this a talk about AI regulation?+

It is about engineering and governance practice: how to bound authority, place approval, and retain evidence. It does not interpret regulation for a particular firm.

What experience does it draw on?+

Regulated banking AI architected at Aveni, including conduct-risk workflows, human review, escalation, evaluation, and release controls, plus the public reference systems CloseGate and Regulus.

Can it suit a risk and compliance audience?+

Yes. The material can be weighted towards decision rights, evidence, and escalation rather than implementation detail.

Will the talk discuss confidential client work?+

No. Confidential architectures stay confidential; examples use public systems and general patterns.

Related

Next step

Invite Dipankar

A short written brief is enough to establish fit. I reply personally, and say plainly when the work belongs elsewhere or is not worth commissioning.

Talk, panel, or event workshop: what to include

  • →Event name, organiser, and website
  • →Audience: size, roles, and technical depth
  • →Preferred topic or the problem the audience faces
  • →Format and length (keynote, talk, panel, podcast, workshop)
  • →Date, time zone, and location or remote
  • →Fee, travel, and accommodation arrangements
  • →Recording, publication, and reuse terms
  • →AV and lab environment, if a workshop