Skip to content
Hominis Agentic OS · early access program now openJoin the waitlist
RealAI

Case studiesBanking risk & compliance

Case study
Banking risk & complianceA consumer and SME banking group operating across several European markets

The design writes a fifth of the first year's money against risk and control before a single use case is chosen

A consumer and SME banking group commissioned a written design for its AI operating model, and the budget section is the part worth reading. The proposed first-year mix allocates 45 percent to the shared platform and central team, 35 percent to embedded delivery, and 20 percent to risk and control, which is named as its own line rather than absorbed into project costs. Two phase envelopes of €0.8M to €1.0M and €1.2M to €1.5M sit under a stated first-year estimate of roughly €2.2M to €2.5M, a figure €0.2M above the sum of its own phase floors. The second tranche is gated on three evidence conditions rather than the calendar, two of which are governance outputs. None of this was executed: every number is a proposal, an envelope or a target inside a design deliverable. The most instructive detail is internal. The worked example the deliverable hands its own audience allocates 15 percent to governance against a stated policy of 20, and the instructor's run-book asks the room whether fifteen is too high or too low.

20%Share of the first-year budget the design allocates to risk and control. A proposed allocation, not a spend
Client
A consumer and SME banking group operating across several European markets
Duration
Facilitated workshop and written design deliverable; nothing built in this phase
AI · RIDGE E22.7 N25ρmax 1.00
45 / 35 / 20Proposed first-year split across shared platform, embedded delivery and risk and control. Planned mix, nothing executed
€2.2M-€2.5MStated first-year estimate in the design. A planning figure, and €0.2M above the sum of its own phase floors
15%Governance share in the deliverable's own worked example, five points under the policy it proposes

Every AI programme pays for governance. Most pay late, out of a line that was meant to fund something else, and by the time the invoice lands it has acquired a name: overhead, drag, the compliance tax. The budget work described here starts from the opposite assumption. A fifth of the first year's money is written against risk and control before any use case is picked, and the other four fifths are sized around what is left.

What follows is a design, not a record. It is the resource-allocation section of a design deliverable written for a consumer and SME banking group operating across several European markets: a proposed investment mix, two phase envelopes and a set of targets the programme commits to hitting. Nothing here has been spent, and no number below is a measurement.

The challenge

The AI Act is in force, and for a lender the timing is awkward in a specific way. The prohibited-practices ban and the staff literacy obligation already apply. Full obligations for high-risk systems, covering credit scoring, human resources and insurance, arrive on a fixed August date. Detailed financial-sector guidance from the European Supervisory Authorities is still expected, and expected to keep arriving after that deadline passes, so a bank has to be compliant before the sector-specific reading of compliance is published.

The classification work in the deliverable turns that from an anxiety into a scope. Three categories of banking system sit inside Annex III as high risk: credit and lending, insurance, and human resources and employment. Anti-fraud falls outside, and the exemption is genuine: fraud detection, money-laundering transaction monitoring and identity theft prevention are not high-risk systems. Assignment runs as five ordered checks rather than as a debate, and the fraud exemption is checked fourth, after Annex III listing, after whether the system assesses a natural person, and after whether it is a product safety component. Ordering it that way stops a team claiming the exemption by putting the word fraud in a system's name.

For a consumer and SME lender the consequence is blunt. Credit scoring of natural persons, creditworthiness assessment, loan eligibility and risk-based pricing are the products, and all four sit inside the high-risk perimeter. So do CV filtering, performance monitoring, task allocation and termination decision support, which are easy to leave out of an inventory, because those systems arrive as software bought by human resources rather than as models built in house.

Governance for that perimeter is a build, not a posture: a model inventory, a risk management system that runs continuously, data governance covering training-data quality and bias provenance, automatic event logging across the system lifecycle, oversight interfaces that permit an actual human intervention, technical documentation to Annex IV, a quality management system, an internal conformity assessment, and registration in the EU database. Nine named deliverables, most of them cited on the page to a specific article of the statute. That list, rather than a principle, makes a fifth of the money a plausible number.

The approach

The proposed first-year mix runs 45 percent to the shared platform and central team, 35 percent to embedded delivery inside the business units, and 20 percent to risk and control. The 20 covers AI Act compliance work, risk frameworks, the ethics committee and audits, and it is a named line rather than a loading spread across project costs. That is the mechanism, not a presentational choice. A line item can be defended in a portfolio review. A loading hidden inside twelve project budgets is trimmed twelve times by twelve people who each believe they are trimming something small.

Money is released in two phases. Months one to six carry €0.8M to €1.0M for an interim leader, three or four first hires, two or three quick-win pilots and a basic governance framework. Months seven to twelve carry €1.2M to €1.5M for the full team, platform and data engineering, and first production deployments. The deliverable states a first-year total of roughly €2.2M to €2.5M, which is worth reading carefully: the two phase floors sum to €2.0M, so the stated floor sits €0.2M above its own arithmetic. It is a planning estimate, not a reconciliation.

The second tranche is gated on evidence rather than on the calendar. Three conditions release it: a validated value case, completed risk tiering, and data privacy sign-off. Two of the three are governance outputs. That is the quiet argument inside the design: delivery money does not move until the control work has produced something checkable, which turns stopping a programme into a routine outcome rather than a political event.

Sequencing follows the same logic. The first three hires are costed at roughly €320K combined: a leader at around €120K, a head of governance, and a lead engineer. None is a data scientist. Each is expected to take three to four months to land, so a slice of the first envelope buys calendar rather than output, and the design says as much. Ten to fifteen percent stays unallocated as contingency, because this class of project is uncertain.

The outcome

The design sets three targets for the first year: two or three scaled use cases, the compliance gap closed, and governance active across the estate. The specification written for the programme's leader carries three success metrics rather than pilots launched: return above 10 percent against baseline, a 40 percent reduction in time to production, and 80 percent of projects reaching scale. Each is a number written into a job description before the job exists, tested against nothing, and reading them as achievements would invent a result the engagement never produced.

The most instructive thing in the material is a disagreement the document has with itself. The stated policy is 20 percent to risk and control. The worked example the same deliverable hands its audience, a €900K budget, puts €135K into governance and risk, which is 15 percent. Strategy and leadership take another €135K, platforms and technology €270K, pilot delivery €270K, and €90K stays as contingency. The instructor's run-book sets the pass mark for an acceptable budget at 15 to 20 percent, and asks the room directly whether fifteen is too high or too low.

That five-point drift, between the policy and the first spreadsheet that had to balance, is the honest part. Governance is never voted down. It is the line that absorbs the rounding once everything else has become a must-have, and here it happened inside a document arguing that it should not.

The run-book names four other ways the arithmetic goes wrong, and they are the same four everywhere: a central team funded into an ivory tower with nothing left for delivery, no contingency on work that is uncertain by definition, hiring assumptions that pretend five specialists arrive in month one, and a build budget with no run costs, so cloud and licence fees arrive later as a surprise.

Two of those four are governance failures wearing a finance costume. An unfunded control layer does not stop a model shipping. It stops the model shipping lawfully, which is discovered at the point of production and paid for at the worst available moment. That is the cost most programmes book as overhead, and it is the price of being allowed to run at all.

This is where a budget line turns into something buildable. Deciding to fund control at a fifth takes an afternoon. Producing a model inventory that stays current, a risk tier on every system with the reasoning recorded beside it, a log an auditor can walk end to end, and an oversight interface where the intervention is real rather than a checkbox, is engineering work. That is where the Platform work starts, and where our Agentic OS work starts, because an agentic operation under graded autonomy has the same requirement over a much larger surface. Our Consult engagements now price that layer on its own, ahead of the use-case list, for the reason this deliverable makes plain: the number is easier to defend before the roadmap exists.

NEXT STEP

Ready to make AI real?