AI for financial services
AI for financial services
Underwriting files summarized, claims and KYC prepped, client reporting that writes itself. 5x ROI in 30 days, or we work free.
- Lenders
- Credit unions
- Wealth managers
- Fintechs
- Insurance brokers
Teams we build for
- Hoyes Michalos
- Nurse Next Door
- Fedi
- UBC Sauder
- Merchant House Capital
- Picton Investments
- Campbell Froh May & Rice LLP
- Barnakl
- Hungerford
- Breez
Teams we build for
- Hoyes Michalos
- Nurse Next Door
- Fedi
- UBC Sauder
- Merchant House Capital
- Picton Investments
- Campbell Froh May & Rice LLP
- Barnakl
- Hungerford
- Breez
Teams we build for
- Hoyes Michalos
- Nurse Next Door
- Fedi
- UBC Sauder
- Merchant House Capital
- Picton Investments
- Campbell Froh May & Rice LLP
- Barnakl
- Hungerford
- Breez
Underwriters read all day and decide for minutes.
The file review is the bottleneck. The judgment was never the slow part.
KYC and onboarding drag for weeks.
Document collection and verification by email, while the client wonders whether you want the business.
Client reporting is a quarterly scramble.
Senior people assembling updates instead of advising clients.
The KYC refresh cycle never actually closes.
High-risk files get re-papered every year. By the time the sweep reaches the end of the book, the first files are stale again, and the gap is what the examiner samples.
Renewals roll over because remarketing takes hours nobody has.
The book renews as-is, the client finds the better price on their own, and the unreviewed coverage gap sits in your E&O file, not the carrier's.
Client letters age in the compliance queue.
The advisor writes it Tuesday and it goes out Friday, reviewed at speed by a two-person desk. The queue is the control your regulator cares most about, and it is the desk everyone resents.
A credit manager's Thursday
The broker calls before she opens the file
humanIt is 8:40 and the broker wants to know where his midnight submission stands. She has not read it. She does not need to have.
The package arrived parsed, not just attached
The Filogix submission was split on arrival: NOAs, T4s and bank statements extracted into the application fields, each figure linked to the page it came from. Two exceptions are flagged, a missing most-recent NOA and a deposit pattern worth one question.
She adjudicates the deal, not the paperwork
humanDebt service is her call. The exception pricing is her call. She approves in principle with two conditions and the system records which evidence she relied on. Nothing about the decision was the machine's to make.
The commitment letter drafts from her decision
Conditions listed, document requests sent to the broker, and the FINTRAC identification record prepared as the file builds instead of reconstructed at funding.
Conditions get walked down while she works the next file
The outstanding NOA is chased, the appraisal booking is confirmed, and the file's condition list shortens without her touching it. A condition that stalls for three days escalates to a person.
The over-limit file gets its second signature
humanOne afternoon deal exceeds her authority. She walks it to credit committee with the summary, the flagged exceptions and the source links. The committee reads for ten minutes and decides. Nobody spent the morning assembling the write-up.
The trail is a by-product, not a chore
Every extraction, flag, decision and approval from the day is already in the access-logged record the next file review will ask for. Nobody stays late building evidence of work that was plainly done.
Financial services, before and after
The manual path is dashed: Files read line by line, KYC chased over email, Reporting eats quarter-end. The system path replaces it, and a person approves before anything ships: Submissions summarized, KYC documents verified, Updates assemble themselves.
Before: by hand
- 01Files read line by linehuman
- 02KYC chased over emailhuman
- 03Reporting eats quarter-endhuman
After: the system
- 01Submissions summarized
- 02KYC documents verified
- 03Your approvalhuman
- 04Updates assemble themselves
The research
Klarna says its AI assistant performs the work of 853 full-time agents, handling roughly two-thirds of service chats (CX Dive, 2025).
Klarna · 2025
Who this is built for
The morning goes to adjudication
The deal goes to whoever answers first, and answering first used to mean reading fastest. Now the submission is parsed and summarized before you open it, with every figure linked to its source page. Your morning goes to adjudication, and the broker learns that your shop is the one that responds while the deal is still warm.
The examiner gets logs, not recollections
When the sweep letter arrives, the question is never whether the work was done. It is whether you can prove it without a month of reconstruction. Here every extraction, flag and approval lands in an access-logged trail as a by-product of the work. You answer the examiner from the record, and the record was never optional.
Meeting prep shrinks to a read-through
The review file assembles from the custodian feed and the CRM before the client sits down: positions, what changed, the KYC fields going stale, the notes from last time. You read it in ten minutes and spend the hour advising. The suitability record is drafted from what was actually discussed, and it waits for your sign-off.
Renewals get remarketed, not rolled over
Ninety days out, the renewal surfaces with its claims history, the expiring terms and the markets worth approaching. The remarketing package is assembled, not improvised at the deadline. Your producers have the conversation about coverage instead of apologizing for the rollover, and the E&O file shows the gap was reviewed.
What stays human
- The broker calls before she opens the file
- She adjudicates the deal, not the paperwork
- The over-limit file gets its second signature
The steps the day below leaves to a person, by design.
Proof from the pattern
Our closest published work is an outbound and research engine for a private capital firm. The mechanics transfer to carriers and lenders, and the numbers we publish will be yours, measured against a baseline you sign.
We guarantee 5x ROI inside 30 days of deployment, in writing, measured against a baseline you sign before we build. If the system misses the bar, we keep working for free until it clears.
The numbers in financial services
Klarna says its AI assistant performs the work of 853 full-time agents, handling roughly two-thirds of service chats (CX Dive, 2025).
Klarna · 2025
82% of insurance executives plan to integrate AI agents within three years (Capgemini, 2025).
Capgemini · 2025
Only about 1 in 5 companies has a mature governance model for autonomous AI agents (Deloitte, 2026).
Deloitte · 2026
Built around your rules
| Regime | What it demands here | How the system complies |
|---|---|---|
| FINTRAC and the PCMLTFA | Reporting entities, banks, credit unions, securities dealers, life insurers, MSBs and payment providers among them, owe client identification, record keeping and reporting duties, with a designated compliance officer accountable for them. | Identification records are prepared as the file builds and gaps are flagged instead of discovered. Every reporting decision stays with your compliance officer. Nothing files itself. |
| OSFI B-13, technology and cyber risk | Federally regulated institutions must govern technology risk with named accountability, keep a current technology asset inventory, and hold controls they can evidence across operations, resilience and cyber security. | The build lands inside your accounts as a documented asset with named owners, access control at the database layer and logs on access. It enters your B-13 inventory as governed technology, which is the opposite of the shadow AI it replaces. |
| OSFI B-10, third-party risk | Third-party arrangements assessed for criticality, with documented data flows, subcontracting transparency and a credible exit plan. | The materiality call is yours. We arrive with the data-flow map, the subcontractor list and the exit path, and the exit path is real because the data never left your accounts. |
| OSFI E-23, model risk management | From May 2027, AI and machine learning models at federally regulated institutions belong in the model inventory with lifecycle governance, validation and monitoring proportional to risk. | Shipped as a validatable package: documented scope and data lineage, eval results that stand as monitoring evidence, and interpretable classifiers where a flag must survive a validator's why. |
| Provincial regulators, BCFSA and FSRA | Credit unions, provincially incorporated insurers and mortgage brokers sit outside OSFI's perimeter and answer to provincial regulators whose information-security and outsourcing expectations track the federal guidelines. | The same artifacts serve both perimeters: data flows, access logs, residency answers and human approval gates, documented as part of the deliverable rather than assembled for the exam. |
| CIRO and CSA obligations | Registrants owe suitability and KYP under the Client Focused Reforms, marketing review before anything client-facing ships, and books and records producible on request. | Client-facing output is a draft until it clears your existing review workflow, approvals are logged where the work happened, and the records the regime demands accumulate where your records already live. |
| PIPEDA and BC PIPA | The personal information in play here is the client file itself: SINs on tax slips, account statements, health details on insurance applications. Both statutes reach it, with consent, purpose limits and access rights. | That file stays in your accounts, handled to respect both statutes, with residency scoped per engagement and access logged and reviewable. |
| CASL | Commercial electronic messages require consent, sender identification and a working unsubscribe. | Outreach is consent-based, identified and unsubscribable, with consent state enforced in the data layer so an agent cannot message a client who opted out. |
The regimes that govern financial services, what each demands, and how the system complies
Regime
- FINTRAC and the PCMLTFA
What it demands here
Reporting entities, banks, credit unions, securities dealers, life insurers, MSBs and payment providers among them, owe client identification, record keeping and reporting duties, with a designated compliance officer accountable for them.
How the system complies
Identification records are prepared as the file builds and gaps are flagged instead of discovered. Every reporting decision stays with your compliance officer. Nothing files itself.
- OSFI B-13, technology and cyber risk
What it demands here
Federally regulated institutions must govern technology risk with named accountability, keep a current technology asset inventory, and hold controls they can evidence across operations, resilience and cyber security.
How the system complies
The build lands inside your accounts as a documented asset with named owners, access control at the database layer and logs on access. It enters your B-13 inventory as governed technology, which is the opposite of the shadow AI it replaces.
- OSFI B-10, third-party risk
What it demands here
Third-party arrangements assessed for criticality, with documented data flows, subcontracting transparency and a credible exit plan.
How the system complies
The materiality call is yours. We arrive with the data-flow map, the subcontractor list and the exit path, and the exit path is real because the data never left your accounts.
- OSFI E-23, model risk management
What it demands here
From May 2027, AI and machine learning models at federally regulated institutions belong in the model inventory with lifecycle governance, validation and monitoring proportional to risk.
How the system complies
Shipped as a validatable package: documented scope and data lineage, eval results that stand as monitoring evidence, and interpretable classifiers where a flag must survive a validator's why.
- Provincial regulators, BCFSA and FSRA
What it demands here
Credit unions, provincially incorporated insurers and mortgage brokers sit outside OSFI's perimeter and answer to provincial regulators whose information-security and outsourcing expectations track the federal guidelines.
How the system complies
The same artifacts serve both perimeters: data flows, access logs, residency answers and human approval gates, documented as part of the deliverable rather than assembled for the exam.
- CIRO and CSA obligations
What it demands here
Registrants owe suitability and KYP under the Client Focused Reforms, marketing review before anything client-facing ships, and books and records producible on request.
How the system complies
Client-facing output is a draft until it clears your existing review workflow, approvals are logged where the work happened, and the records the regime demands accumulate where your records already live.
- PIPEDA and BC PIPA
What it demands here
The personal information in play here is the client file itself: SINs on tax slips, account statements, health details on insurance applications. Both statutes reach it, with consent, purpose limits and access rights.
How the system complies
That file stays in your accounts, handled to respect both statutes, with residency scoped per engagement and access logged and reviewable.
- CASL
What it demands here
Commercial electronic messages require consent, sender identification and a working unsubscribe.
How the system complies
Outreach is consent-based, identified and unsubscribable, with consent state enforced in the data layer so an agent cannot message a client who opted out.
Client and policy data stays inside your accounts under no-training API terms, with per-team access control and the audit logs your regulator will ask about.
Policy admin, CRM, Custodian feeds and the system run inside a boundary labeled your accounts. The only path that crosses the boundary is the audited egress to the model API, under no-training terms. The boundary is what answers FINTRAC and the PCMLTFA and OSFI B-13, technology and cyber risk.
Inside your accounts
- 01Policy admin
- 02CRM
- 03Custodian feeds
- 04System in your cloud
- 05Audit log
Outside, through the audited port
- 01Model API
Where the data comes from
Policy admin
The system of record for the book, whether that is Applied Epic or Policy Works at a brokerage or Guidewire on the carrier side. Policies, endorsements, claims history and the renewal list live here, and the remarketing and triage work reads from it so the ninety-day renewal surfaces with its history attached.
Where it stops. Read in place. Nothing binds, endorses or cancels from this system. A licensed person binds coverage, and the only writes are activity notes a person routed.
CRM
Salesforce Financial Services Cloud or Maximizer holds the households, the KYC records, the review schedule and the consent state. Onboarding starts here, the KYC refresh sweep runs against it, and meeting prep draws the client history from it.
Where it stops. Consent state is checked in the data layer before any client is messaged, and suitability-relevant records are drafts until an advisor signs them. One household's file never renders in another advisor's context.
Custodian feeds
The daily position, transaction and fee files from NBIN, Fidelity Clearing Canada or the carrier's own downloads. Client and investor reporting assembles from these feeds with every number traced to its feed line, which is what lets an advisor review a letter instead of rebuilding it.
Where it stops. Read only, one direction. Nothing writes back toward a custodian, and performance figures are calculated deterministically from the feed rather than generated. A number that cannot be traced to a feed line does not ship.
What we build for financial services
The underwriting desk
Underwriting copilots.
Submission files summarized, risk factors surfaced with sources cited. The underwriter decides; the reading compresses.
Claims intake and first-pass triage.
FNOL documents structured on arrival, routine claims prepped for adjuster sign-off, complex ones routed to people fast.
The client book
KYC and onboarding automation.
Identification documents chased, verified and filed, with FINTRAC records prepared as the file builds.
KYC refresh sweeps.
The book is cycled continuously instead of annually in a panic. Stale fields surface with the document request drafted, and the compliance officer decides what escalates.
Renewal remarketing prep.
Ninety days out, the expiring terms, claims history and candidate markets are assembled into a remarketing package a producer takes to carriers. Binding stays licensed and human.
Fraud and anomaly flagging.
Patterns surfaced for your team's review. Flags, never verdicts.
The reviewed channel
Client and investor reporting.
Updates assembled from your systems on schedule. Advisors review instead of write.
Compliance-reviewed outbound.
Advisor communications drafted inside your existing review workflow, so speed never skips approval.
The economics
Before and after economics
Line
- Long-file review
Before
Submissions, statements and committee packages read line by line by the most senior person in the room
After
A cited summary arrives first and the senior reader checks lines instead of finding them. Qualitative by design, no number claimed
- The senior reader's week
Before
Assembly hours on file prep, write-ups and client letters
After
The same hours back on clients and deals
- Manual hours in scope, modelled
Before
At the page defaults, 7 people spending 10 hours a week on file prep, KYC chasing and reporting is 70 hours, $6,650 a week at $95 loaded cost
After
The calculator below prices your own baseline, and the 5x ROI guarantee is measured against a baseline you sign before we build
- KYC and onboarding drag
Before
Document collection by email across weeks, while the client wonders whether you want the business
After
The chase runs on a schedule and the records build with the file. Qualitative by design, no number claimed
The first two rows and the KYC row are qualitative and carry no figure on purpose. Our closest published work is an outbound and research engine for a private capital firm, which is finance but not a lender or a carrier, so no number from it is offered here as a financial-services result. The modelled row multiplies this page's calculator defaults, 7 people at 10 manual hours a week each at a $95 loaded hourly cost.
The objections
Our core systems are locked down. The LOS and the BMS barely have APIs.
The first phase does not ask them to. It reads the documents and the extracts your team already pulls, and its outputs are drafts and summaries a person acts on inside the systems you keep. Where a system offers a clean read path we use it. Where it does not, nothing is forced into it, and no build waits on a core integration project.
Under B-10, every new vendor is a six-month onboarding. We do not have the appetite.
The materiality assessment is yours to make, and we show up with the file it needs: the data-flow map, the subcontractor list, the access model and the exit plan. Exit is the easy question here, because the data never left your accounts. There is nothing to migrate back and nothing held hostage.
One hallucinated number in a client statement would end us.
Client-facing numbers are never generated. They are pulled from the source record and traced to it, and the language drafted around them is graded in the eval harness against files your team already decided before anything reaches a live book. A wrong figure is a failed eval in the build phase, not a discovery in a client meeting.
Our model risk team will treat this as another model to validate under E-23.
They should, and it is built to be validated. OSFI's E-23 reaches AI and machine learning models at federally regulated institutions when it comes into force in May 2027, and the build ships as a validatable package: documented scope and data lineage, eval results that serve as ongoing monitoring evidence, and interpretable classifiers wherever a flag needs an explanation a validator can test.
Compliance is two people. They cannot absorb an AI program on top of the day job.
The build is pointed at their queue first, not added to it. Records prepared as files build, gaps flagged instead of discovered, client-facing drafts arriving pre-checked against the rules the desk enforces. The two people keep every decision they have today and lose most of the assembly around it.
How we build it for financial services
Ground the system in your own positions.
Policy wordings, underwriting guidelines and past decisions get indexed first, so answers are the firm's position rather than a model's impression of the market.
Measure agreement against decided files.
Extraction and flagging accuracy is graded against files your team has already decided, before anything touches a live book.
Automate the packet, never the adverse decision.
Submissions and KYC packets assemble themselves. Every adverse or client-facing decision arrives as a proposal with the evidence attached.
What we will not automate
Advice, adverse decisions and anything a regulator would ask you to justify. Risk flagging uses interpretable classifiers precisely so the answer to why is a real answer.
How the system is built for financial services
See the full capability mapRetrieval
Policy wordings, underwriting guidelines and past decisions indexed so the answer to a coverage question is the firm's own position, cited to the document it came from, not a model's impression of the market.
- pgvector
- Full-text BM25
- Reciprocal rank fusion
Agents and orchestration
Agents prepare submissions, assemble KYC packets and run monitoring sweeps on a schedule. Every adverse or client-facing decision is a proposal with the evidence attached. A licensed person decides.
- agent-worker
- Autonomy guard
- Proposal queue
Evaluation
Graded against files your team has already decided, so extraction and flagging accuracy are known before anything touches a live book. Regulated work is where an unmeasured system is most expensive.
- Eval graders
- Decision agreement rate
- quality-worker
Models
Document models for submissions, statements and claims packets. Frontier models for long-file synthesis. Interpretable classifiers for risk flagging, because a regulator asking why will not accept an embedding as an answer.
- Document layout extraction
- Frontier models, one gateway, routed per task
- Interpretable classifiers
Data boundary
Per-book and per-team access control at the database layer with audit logs on access. Client financial data never leaves your accounts, and no-training terms apply to every model call.
- Supabase row-level security
- Access audit logs
- No-training API terms
Policy admin, CRM, Custodian feeds feed a hybrid index. The agent runtime works from that index, and every consequential action passes a human approval before it reaches Ask your brain, Approval queue, Workflow builder.
Your systems
- 01Policy admin
- 02CRM
- 03Custodian feeds
The system
- 01Hybrid index
- 02Agent runtime
- 03Your approvalhuman
Where your team works
- 01Ask your brain
- 02Approval queue
- 03Workflow builder
What that means in practice
Retrieval and RAG
Connecting AI to your actual documents so it answers from your knowledge, accurately and with citations, instead of making things up.
Where we stop. A dedicated vector database is justified by scale, not by default. Most of RAG quality is won or lost in chunking and indexing strategy, not in the model choice, and we have walked clients back from RAG to plain search when that was the honest answer.
Security, privacy and governance
Keeping your data yours, and your AI safe to put in front of customers.
Where we stop. We do not claim certifications we do not hold, and we will not ship a customer-facing agent without a human gate and an eval suite. If a vendor cannot offer no-training terms, it does not get into the stack.
Evaluation and observability
How we prove the AI actually works: measured, monitored and regression-tested like real software, not vibes.
Where we stop. There is no engagement where we skip this. The honest variable is depth: a document pipeline gets faithfulness and extraction suites, an outbound agent gets human review sampling, a classifier gets a held-out test set. We size the harness to the risk, never to zero.
Where your team works
Tour the platformAsk your brain
Ask a question. Get the answer and where it came from.
Every answer cites the document behind it, so you can check the source yourself. When the brain does not have the answer, it says so instead of guessing.
Approval queue
The AI proposes. You approve. Nothing sends itself.
Every consequential action arrives as a proposal with the risk, reversibility, and expiry spelled out before you say yes. Control stays in the room.
Workflow builder
Describe the workflow. Watch it assemble.
Say what should happen in plain language and the builder assembles the automation on a canvas you can read, run, and change.
Cost per outcome
Every dollar of spend traced to the work behind it.
Outcomes delivered, cost per outcome, value attributed, return on spend. The same measurement the guarantee is settled against, live on one page.
By team
The same system, seen from the desk that runs it.
- SalesBrokerages and asset managers run relationship pipelines where every send needs sign-off.
- Customer supportRegulated replies need citations and an approval trail.
- MarketingMarketing there ships through compliance review, which is what the approvals queue is built for.
- FinanceThe compliance-heavy version of this page, for firms where finance is the product.
- Engineering and ITLean IT under heavy compliance, which is what the gated approval pattern is for.
- Legal and complianceThe same obligations and evidence discipline, at regulator grade.
Run your numbers.
Your operations
Savings use the low end of our hours-reclaimed range. The math is conservative on purpose.
The math
Calculated at the low end of every range.
Every first build is covered in writing: 5x ROI in 30 days. Or we work for free.
The hard questions
The systems behind this
Operations hub→
Your numbers, one place, no Friday scramble.
Custom agents→
For the jobs only your business has.
Client onboarding→
Documents chased until they arrive.
Knowledge brain→
Cited answers from your own documents.
Intelligence engine→
Who to call next, scored into your CRM.
Governance→
Autonomy rules your lawyer can read.
Quality lab→
Proof it works, measured every week.
Free · 3-5 days
Know your number in five days.
We map your operations, find the highest-ROI automations, and hand you a ranked plan with the payback math attached. Yours to keep, whoever builds it.
Prefer to talk first? Book 15 minutes with James. No pitch deck.