DEV Community

Lawrence
Lawrence

Posted on

Building the Bank from the Top Down, Appendix C4–C7: Product lines, guardrails and roadmap

Part 6 of 8 of Building the Bank from the Top Down. The main paper makes the argument; this part holds the detail.

C4. Beyond the PFA: a North Star for every product line

The PFA is one worked case, not the only one. Every classic banking and insurance product was designed around what an institution could deliver at the time: a branch visit, a form, an annual statement. AI changes what can be delivered, so every product line should face the same question: what job does the customer really hire this product for, and what could AI let us promise?

C4.1 Products become primitives

Legacy products will not disappear. Their core functions persist: storing value, pooling risk, financing a home, funding retirement. But they are becoming regulated, trusted primitives inside larger AI-run services, and customers may meet them only through an agent. The real question is not whether the product survives, but who owns the promise wrapped around it.

Four questions to ask of every product:

  1. What fundamental promise does this product make?
  2. Which parts of its delivery are just historical administration?
  3. Which trust guarantees must stay human and institutional?
  4. Which customer decisions could safely be delegated to an agent?

C4.2 Retail and household products

Product today The customer's real job AI-unlocked North Star (to test) The incumbent belief it challenges
Current account and payments Pay and get paid without thinking about it "Bills and transfers run themselves within limits I set, and my balance never surprises me." The account is a place customers come to check
Savings Have enough, when I need it "Every saver has a goal-based plan that moves money to the best safe home for it, even at another provider." We win by holding the deposit and quoting a rate
Consumer credit and overdrafts Smooth out uneven cash flow "No customer pays for high-cost credit or fees they could have avoided." Penalty fees and revolving balances are a revenue line
Mortgages Own a home, safely "From 'can I afford it?' to an offer in days, assembled from verified claims, then re-checked for the customer every year." A mortgage is a one-off sale followed by 25 years of silence
Property and casualty insurance Avoid loss, and recover fast when it happens "We help prevent, contain, document and compensate loss; most claims are settled in hours." Insurance pays out after things go wrong
Life and protection Know my family is covered "Every household can see its protection gap, and cover adjusts as life changes." Protection is sold once, at a life event, by an adviser
Pensions and retirement Retire with enough, on time "Every customer sees one retirement income figure across all their pensions, with a monthly nudge that keeps it on track." A pension is a statement once a year
Wealth and investment management Grow wealth and pass it on "Private-banking-quality advice for the mass affluent, explained and suitable." "Every family has a plan for passing wealth to the next generation." Personal advice only pays above a minimum portfolio

C4.3 Business and corporate products

Product today The customer's real job AI-unlocked North Star (to test) The incumbent belief it challenges
SME cash management Never run short of cash "Every SME has a 13-week cash forecast, and financing is arranged before the gap appears." Lending reacts to an overdraft request
SME lending Fund growth quickly "Credit decisions in minutes from verified turnover and invoices, with a limit that follows the business." Lending needs annual accounts and a relationship manager
Corporate treasury and cash management Keep liquidity, currency risk and payments within policy "Treasury runs itself within the board's policy; people handle only the exceptions." Treasury is a dashboard plus spreadsheets
Trade finance Trade across borders without paper risk "Documents are verified as claims, not checked by hand; funding is released when the evidence is complete." Trade finance is document processing

C4.4 Reading the tables

  • The promise moves up the pyramid. Most North Stars shift a product from functional value (rate, fee, speed) towards emotional or life-changing value: reduces anxiety, provides hope, heirloom.
  • Several challenge today's revenue. Penalty fees, deposit margin and mortgage inertia all depend on customers not optimising. If the bank will not make the promise, an outside agent using open finance may make it instead.
  • Many are skills of one agent. Savings, credit, protection and pension goals all run on the same context graph and consent router. Build one AI-native platform, with product skills on the bank's agent (market A) and claims on the trust layer (market B), not ten separate programmes.
  • Some sit mainly in market B (Appendix C1). Verified turnover for SME lending and verified documents in trade finance can win even when another agent owns the interface.
  • Each row is a hypothesis. Test it with its own first release, using the method in Appendix C2.

C4.5 Feasibility in large groups

Large networked groups such as BNP Paribas, Crédit Agricole, BPCE, Société Générale and KBC face four technical problems that a single-entity bank meets in milder form. The strategy does not solve them; each has a design answer to test in the first release.

Problem Why it is hard in a group Design answer Detail
A semantic control plane over different cores Mainframes and several vendors' cores, each with its own data model Map only high-risk fields; read through change-data capture or APIs with provenance; no new central warehouse C3.3; Technical annex T6, T7
Purpose-bound consent across entities and countries Each entity is a separate GDPR controller, and rules differ by country Consent records per controller; one permission dashboard for the customer Technical annex T1, T7
Agent identity and delegated authority under SCA Payment authentication needs a known amount and payee; PSR technical standards on delegation are not final One group registry for agent identity and delegation; confirmation by deep link into the entity's app; rung 7 out of scope for payments C3.3; Technical annex T3
Model risk and explainability for two sets of rules The AI Act (from December 2027, planning assumption) and supervisors' model-risk expectations both apply Evidence behind every answer, maths verifiers and one audit trail, built on existing model risk management C5.1; Technical annex T1, T5

A fifth problem is organisational rather than technical, and probably the hardest: protecting the outcome-led team from the core programme (C5.3).

C5. Guardrails: regulation, risk and the window

The strategy, the method and the cases all operate inside rules that are still being written. This section separates what regulation requires from what it enables and from how this paper reads it, sets out the timing window, and names the new risks.

C5.1 What regulation requires, what it enables, and how we read it

Rule Regulation requires Regulation enables Interpretation
EU AI Act AI used for creditworthiness and credit scoring is high-risk: risk management, data governance, human oversight and logging, from 2 December 2027 (planning assumption) (Regulation-AI.eu) Reuse of existing model risk management Explained answers and graduated autonomy double as compliance evidence
DORA ICT third-party risk management: a register, testing and exit plans for critical providers Governing model providers like other critical ICT vendors Renting models is viable if exit plans exist
GDPR Purpose limitation, data minimisation, a lawful basis Narrow, purpose-specific data sharing The consent router turns these principles into product features
PSR Dedicated interfaces with performance parity, no listed obstacles, permission dashboards, payee-name verification, reimbursement for certain impersonation frauds (Morrison Foerster) A regulated surface where customers manage who acts for them The dashboard is a product surface; liability experience is a trust advantage

C5.2 The window: December 2027 to 2028, on current planning assumptions

On current planning assumptions, the AI Act's high-risk rules apply from December 2027 and the PSR's core obligations around H1 2028: 15 to 21 months from September 2026. Both dates can move, and some obligations depend on technical standards that are not yet final, so re-check them at each roadmap gate. A bank that ships a PFA with purpose-bound consent, explained answers and graduated autonomy by then turns compliance into the product. A bank that arrives late complies anyway, and may pay for an interface its customers use through someone else.

C5.3 New risks to manage

Outcome-led delivery does not remove risk; it moves it. Model errors, answers that cannot be explained, and liability for actions an agent takes are the risks to manage. The PFA design answers each: deterministic maths verifiers for any number the agent quotes, evidence behind every answer, and autonomy that grows only as risk, reversibility and confidence allow. The Technical annex sets out a liability matrix and failure scenarios.

The largest execution risk is probably organisational (interpretation): the core programme absorbs the outcome-led team's people, budget and release slots. Protect the team explicitly: its own budget line tied to the North Star, its own release cadence, a sponsor on the executive committee, and a rule that core-programme priorities cannot reassign its engineers. Dependencies on the core go through the semantic control plane under agreed service levels, not through the core programme's backlog.

C6. What would prove us wrong

This paper is a strategic hypothesis, not a forecast. Appendix D4 lists each load-bearing claim with its status and the test that would check it. The thesis weakens if the signals below appear, and each has a leading indicator a bank can track from its first release.

The thesis weakens if… Leading indicator to track
Customers do not adopt financial agents Monthly active use and repeat use among pilot customers
Customers prefer general-purpose assistants to financial ones Share of agent traffic reaching the bank via outside assistants rather than its own; the PFA against a general assistant on the C3.1 kill criteria at month 9
Open-finance usage stays low Consented connections per customer; third-party API calls per month
Agent liability proves too expensive Error, dispute and reimbursement cost per thousand actions
Regulators restrict autonomous financial actions Final PSR technical standards on authentication for delegated payments
Banks keep strong control of the interface Share of customer interactions in bank-owned channels
AI economics do not support a mass-market agent Cost per active user against revenue per user
AI guidance produces no measurable customer value Buffer, debt and savings outcomes against a control group
Verified claims become a commodity anyone can issue, so a bank's liability backing earns no premium Share of relying parties that accept non-bank claims on equal terms; price per verified claim; claims issued per consented customer

If several indicators move the wrong way, the right response is to shift weight from market A (the bank's own agent) to market B (trusted infrastructure for other agents), not to abandon the outcome-led approach.

C7. Roadmap, board resolutions and metrics

The first 90 days set how the bank competes: with its own agent at the apex, as the trusted layer beneath other agents, or both. The roadmap lands the first PFA releases, and the trust layer beneath them, as the AI Act high-risk rules (December 2027) and the PSR (around H1 2028) are expected to take effect; both dates are planning assumptions.

Roadmap · three phases and two gates · phase widths not to scale · regulatory dates are planning assumptions
Roadmap · three phases and two gates · phase widths not to scale · regulatory dates are planning assumptions

The two gates condense the five gates of the author's Enterprise Digital Office framework. "North Star signed off" corresponds to its G1, where the C-suite ratifies the opportunity and success measures. "Usage and consent targets met" corresponds to G3, customer validation of the first release. A hard condition also sits between them: no release that can move money or prepare a regulated application ships until the board has approved the autonomy policy and liability matrix (C7.1).

C7.1 Board resolutions

The resolutions land in sequence over the first 90 days (the days are working targets). The North Star comes by day 45. The PFA envelope and a protected team for a 90-day read-only pilot follow by day 60, and the consent and trust layer starts in parallel. The portfolio is relabelled by day 90, aiming for at least 40% of change spend on apex components within 12 months. The Risk resolution is a gate rather than a date: it must pass before any release that can move money or prepare a regulated application. The AI Act and PSR dates are re-checked at every gate.

Decision The board approves Evidence required
North Star The customer outcome Baseline and target for the outcome metric
PFA An investment envelope for three releases The economics template in C3.7, filled with pilot data; kill thresholds for the month-9 decision (C3.1)
Consent and trust layer Product strategy for the dashboard and verified claims Regulatory and legal assessment (PSR, GDPR)
Architecture Build, buy, rent and contain boundaries Wardley map with evidence per component
Core Core investment tied to named needs: resilience, regulation, economics or an outcome Dependency map from apex components to core systems; business case for economic core work
Risk An autonomy policy: which rungs of the ladder, for which actions, approved before any release that can move money or prepare a regulated application Risk appetite statement; liability matrix
Data The context and evidence model Data architecture for the semantic control plane
AI Model strategy and exit plans Vendor and open-model analysis under DORA

C7.2 Measure customer outcomes, not foundations laid

Category KPIs
Customer Active agent users; task completion; customer effort; trust score; retention
Agent Task success rate; error rate; escalation rate; share completed autonomously; explanation quality; numeric-hallucination rate (numbers the maths verifiers reject)
Financial Revenue per customer; products per customer; share of wallet; servicing cost; lifetime value
Risk Incorrect-action rate; fraud; policy violations; model incidents; liability events; consent-revocation latency; share of executed actions that are reversible; kill-switch activations
Transformation Time to first customer value; apex share of change spend; run-versus-change split (from ~70%); legacy dependencies removed; API reuse

C7.3 The call to action

Core systems will always need investment, and regulation will make sure they get it. The question for every board in France and Benelux is what the rest of the change budget builds. If it goes mainly to rebuilding foundations, an outside agent may use open finance to reach the bank's customers on top of them. If it goes to the trust layer and an agent customers choose, the bank increases its ability to remain in the customer relationship as AI changes the interface, whichever agent the customer uses.


Previous: Appendix C3: The Personal Finance Agent · Next: Appendix D: Glossary, sources and claims register

Top comments (0)