£38.3bn
UK financial crime compliance spend in 2023. Up 33% since 2021. An estimated 90 to 95% of AML alerts turn out to be false positives.
LexisNexis Risk Solutions and Oxford Economics, 2024. [1]
For challenger banks, building societies, and smaller financial institutions. We design the agent, build it, and run it on your behalf. Every output goes through model checks your second line can defend, an audit trail your regulator can inspect, and a sign-off workflow your operations team controls. You only pay when the agent delivers.
Compliance costs are rising. KYC reviews are taking longer. Complaint volumes are at six-year highs. Most of the spend is going on work that does not need a human, but that humans are still doing because the alternatives have not been trustworthy enough to put live.
UK financial crime compliance spend in 2023. Up 33% since 2021. An estimated 90 to 95% of AML alerts turn out to be false positives.
LexisNexis Risk Solutions and Oxford Economics, 2024. [1]
How long UK corporate KYC reviews now take on average. 70% of financial institutions globally lost clients to onboarding delays in 2024/25, the highest rate on record.
Fenergo Global KYC Trends, 2025. [2]
Complaints to the Financial Ombudsman Service in 2024/25. A 54% jump on the prior year and the highest volume in six years. Fraud and scams drove most of the banking increase.
Financial Ombudsman Service Annual Report, 2024/25. [3]
The pattern is familiar. Alerts that take hours to investigate and almost always turn out to be nothing. Onboarding queues that lose clients while files sit waiting for the next free analyst. Complaint inboxes growing faster than headcount. Most of it is repeatable, rules-based, and well-suited to delegation. The problem has been finding a way to delegate it that the second line can actually sign off.
The workflow areas below are illustrative. The exact steps, checks, and outputs are designed around your firm's specific process during a Discovery session. We do not deploy off-the-shelf workflows.
These four areas come up most often when we scope agents with banking firms, but they are not a fixed menu. Most banks have one or two processes consuming a disproportionate share of operational headcount. Discovery is where we find out which one, for you, would actually move the needle.
This could look like an agent that takes a fresh AML alert through to a triaged investigation pack, ready for a compliance analyst to act on.
A structured investigation pack with a recommended disposition, sat in the analyst's queue, with the time-consuming groundwork already done.
We might build this as an agent that runs a corporate or individual onboarding case from intake through to a complete review file.
A populated KYC file with a draft risk rating, all checks evidenced, and every exception flagged to a human reviewer with the reason stated.
An agent at this stage could take an inbound complaint through to a classified case with a draft response and an escalation flag where one is needed.
A triaged complaint case with a draft response ready for review, a confidence rating, and a clear escalation flag where vulnerability or regulatory risk is in play.
Or an agent that takes a borrower's submitted documents through to a structured affordability pack for the underwriter.
A structured affordability pack with a recommended decision band, sat in the underwriter's queue, with every figure traced back to the source document.
Most providers stop at the build. We design, build, and run the agent for as long as it is in production.
Free 30-minute Discovery session. We walk through the workflow with you, identify where an agent fits, and decide together whether it is the right call. If it isn't, we tell you.
Senior engineers, isolated Azure tenancy. Prompts engineered against your standards, evaluation criteria written before a single output goes live, outputs formatted to your team's existing workflow. A refundable commitment per agent covers the build phase. Refunded in full if we don't deliver to spec.
Live monitoring. Continuous evaluation. Retraining as your processes, products, and regulation change. Output guarantee against the agreed standards. Failed outputs not billed. 36-month contract with monthly billing throughout.
There's no rate card for banking. We scope each agent individually because the workflow drives the cost, not the headcount. The model is the same across every agent we build.
A refundable commitment per agent, taken at the start of the build. It's a prepayment toward the work, not a deposit. If we don't deliver to specification, we refund it in full.
Once the agent is live, billing is per output. The unit price scales with the complexity of the workflow. A failed output, one that doesn't meet the agreed standard, is not billed. The output guarantee sits behind every workflow. It's commercial, not legal.
The contract runs for 36 months with monthly billing throughout. Caps available where volume forecasting is uncertain.
The scenario below is hypothetical. It's included to make the pattern concrete, not to claim a specific outcome. Real performance is dependent on your existing systems, your alert volumes, and your firm's typology profile.
An analyst opens an alert generated by the transaction monitoring system. They cross-reference the customer's account history. They run sanctions and adverse media checks in three or four separate systems. They write up a note on whether the activity is consistent with the customer's baseline. They make a recommendation. They file it. Most of the alerts they investigate turn out to be false positives. The work is repetitive, the volume is constant, and the analyst is the bottleneck.
The agent triages each alert on intake. It pulls together the cross-references, the screening checks, the historical context, and the recommended disposition. It produces a structured investigation pack sat in the analyst's queue, every check evidenced, every reason cited. The analyst reviews, agrees or overrides, and signs off. They spend their time on the cases that need judgement. The clear-cut false positives close quickly. The complex cases get the attention they deserve.
This is what an output-focused agent looks like in banking. Designed for the work, built where it has to stand up, and reviewed by a human before anything leaves your firm.
Banking is governance-led. Every output your firm produces sits inside one of several frameworks, and so does every agent we build. We do not claim to certify your firm's compliance. We design our work so that yours is easier.
The frameworks we design against: PRA SS1/23 on model risk management, with AI and ML explicitly in scope. FCA Consumer Duty (PS22/9), the outcomes-based obligation for retail customers. UK GDPR Article 22 and the rights around solely automated decisions. PRA SS2/21 on outsourcing and third-party risk, which applies to managed AI services. JMLSG guidance, the HM Treasury-approved operational reference for AML procedures. And the Financial Ombudsman Service, the complaint redress framework agents need to be built around.
Agents built for banking need to be designed with these frameworks in mind from the first sketch. Ours are. Independent model checks, version-controlled model inventory, override tracking, generation testing where generative models are used, and an audit trail tailored to the controls your second line already runs.
We are part of Synextra, a UK Microsoft Azure managed service provider with many years of experience running production cloud infrastructure for governance-led firms. Every agent runs in an isolated Azure tenancy. ISO 27001 certified, ICO registered, UK GDPR compliant.
The accountability stays with you. SS1/23 puts the obligation on the firm, not the supplier. What we provide is the infrastructure to make compliance practical: a versioned model inventory, independent validation documentation, override tracking, generation testing for any generative components, and ongoing performance monitoring that your model risk function can inspect at any time. We design every agent so the documentation your second line needs is produced as a by-product of the work, not as an afterthought.
You own your data: every input, every output, and the audit log, all exportable on request. The agent is ours — the engineering, the prompts, the infrastructure. That's why there's no licence and no seats: we run the machine, you pay per output. At the end of the term you get a full export, all outputs, and a documented handover. No lock-in. No exit fees.
By default, no. UK GDPR Article 22 puts a high bar on solely automated decisions with legal or significant effect, and Consumer Duty adds an outcomes obligation on top. Our agents are designed to produce a recommended decision and the evidence behind it. A human in your team makes the call. Where you want a different model, for example fully automated for low-risk cases with human review for everything else, we scope that during Discovery.
The four outcome rules apply whether the work is done by a person or an agent. We design agents to produce evidence of outcomes, not just process compliance. Every customer interaction produces a logged record of the checks run, the alternatives considered, the vulnerable customer indicators surfaced, and the decision logic applied. Your conduct team has the evidence base to demonstrate good outcomes to the FCA.
Most likely not at the firm size we typically work with. The Critical Third Party regime is aimed at suppliers whose failure would cause systemic risk across the sector. We would still be a material outsourcing arrangement under SS2/21, which means full due diligence, contractual protections, concentration risk assessment, and an exit plan. We provide the documentation pack as standard.
Vulnerable customer indicators are surfaced for human review before any response is drafted. The agent does not close, dismiss, or auto-respond to any case where a vulnerability indicator is present. Indicators include recent bereavement, financial difficulty, indications of poor mental health, and patterns we agree with you during Discovery based on your customer base. Consumer Duty is explicit on this point and so are we.
We retrain. Regulatory change is part of the run phase. When supervisory expectations move, we update the agent's checks, evaluation criteria, and documentation accordingly. No additional charge for routine regulatory updates. Major reworks, for example responding to a new regime that did not exist when the agent was built, are scoped separately.
Build typically takes between four and twelve weeks depending on the workflow complexity, your existing systems, and the depth of evaluation we run before go-live. Most of the time is spent on the design and evaluation work, not the code. Smaller, well-scoped workflows can be live in under a month. Cross-system workflows with multiple integrations can run longer. We give you a calendar plan during Discovery.
30 minutes. No commitment. If we do not think an agent is the right call for your workflow, we will say so.