← All industry field guides

Applied research 05 · Financial services

Move faster without making accountability disappear.

A regulated decision is more than an answer. It is the evidence considered, policy applied, alternatives rejected, uncertainty disclosed, person accountable, and treatment the customer can understand.

Decision domainFinancial crime, credit, compliance, and customer operations
Evidence surfaceCustomer, transaction, document, policy, market, and communication data
Control boundaryInvestigate and prepare; designated human authority decides high impact

Our point of view

Explainability begins before the model.

If customer identity, policy, product, and decision authority are vague, a generated explanation only makes ambiguity sound confident. We first model the regulated decision: what evidence is permissible, which rules are binding, which judgment is discretionary, and what must be reviewable later.

Models detect patterns and retrieve context; graphs resolve parties and relationships; policy-as-code enforces non-negotiable controls; role-bound agents prepare evidence for investigation, underwriting, and compliance teams.

Design principleUse generative AI to assemble and communicate evidence—not to conceal the policy, score, or person that actually determined the outcome.

These are applied research patterns, not descriptions of completed customer engagements. Public bank and regulator signals establish context; no named institution is presented as a Zustis customer.

Applied research outputs

Three decisions that must remain reviewable.

The system accelerates evidence work while preserving maker-checker, customer protection, and regulatory accountability.

01

KYC / AML investigation

Show the network behind the alert.

This research pattern links customers, beneficial owners, counterparties, transactions, devices, jurisdictions, cases, and adverse information in an evidence graph for investigator review.

The decision

Close, request information, restrict, escalate, or prepare a regulatory report?

The evidence

KYC/CDD, UBO and corporate registry, transactions, sanctions/PEP, adverse media, device/channel, prior alerts, expected behavior, and policy.

System behavior

Resolves entities, builds flow and relationship narratives, retrieves policy, tests typologies, highlights contradictions, and drafts a cited case pack.

Human boundary

Investigators and MLRO-designated roles decide disposition and reporting. Generated text cannot create an unsupported suspicion.

02

Credit intelligence

Make the credit memo a living argument.

The reference design connects statements, cash flow, obligations, bureau, trade behavior, collateral, sector exposure, policy, and relationship context in an explainable underwriting workspace.

The decision

Approve, decline, resize, price, condition, or refer—and which evidence changes the risk view?

The evidence

Applications, verified identity, statements, financials, bureau, transaction and open-banking data, trade records, collateral, covenants, and policy.

System behavior

Extracts and reconciles figures, detects anomalies, applies eligibility and policy rules, runs sensitivities, and drafts reasons and conditions with source trace.

Human boundary

Credit authority owns high-impact decisions, overrides, pricing, and exceptions. Protected attributes and prohibited proxies are controlled and tested.

03

Regulatory change

Trace every new obligation to the control that proves it.

This research pattern transforms circulars, standards, and guidance into obligations linked to policy, process, system, control owner, evidence, test, issue, and remediation.

The decision

What changed, where are we exposed, who owns the response, and what evidence will demonstrate compliance?

The evidence

Regulation and guidance, internal policy, procedure, product, process maps, controls, risk assessments, audit findings, and prior interpretations.

System behavior

Compares versions, extracts obligations, maps likely impacts, finds gaps, proposes review tasks, and maintains a source-linked implementation record.

Human boundary

Legal and compliance interpret obligations and approve policy/control changes. The system labels suggestions, ambiguity, and jurisdiction explicitly.

Reference architecture

A governed decision fabric.

Customer and model risk controls are part of the system, not a document added after deployment.

01 · Govern data

Purpose-bound evidence

Identity, consent, lineage, minimisation, retention, entitlements, and permitted use travel with every input.

02 · Resolve context

Financial knowledge graph

Party, account, transaction, product, obligation, policy, risk, control, and case share stable identity.

03 · Decide

Models + policy-as-code

Detection and generation remain separate from eligibility, regulatory, approval, and customer-treatment rules.

04 · Assure

Human workflow & monitoring

Maker-checker, reason codes, override, appeal, drift, fairness, performance, and incident evidence are built in.

The line we do not cross.

  • High impactNo opaque autonomous adverse decision in credit, access, reporting, or customer restriction.
  • Customer reasonEvery material outcome has an accurate, specific reason grounded in the actual decision path.
  • Data purposeConsent, privacy, security, residency, minimisation, and permitted-use constraints precede model convenience.
  • Challenge rightsHuman review, override, complaint, and appeal paths remain visible and testable.

Validation before autonomy

Validate behavior, not average accuracy.

Release gates cover false negatives, fairness, stability, explanation faithfulness, privacy, security, and human reliance.

  1. 01

    Benchmark

    Create point-in-time, adjudicated cases across products, segments, languages, edge conditions, and known typologies.

  2. 02

    Red-team

    Probe prompt injection, document fraud, entity collision, data leakage, policy conflict, bias, and fabricated rationale.

  3. 03

    Shadow

    Compare evidence quality, miss rate, workload, override, and customer effect with existing decisions.

  4. 04

    Monitor

    Release bounded tasks with thresholds, maker-checker, outcome monitoring, drift triggers, rollback, and incident response.

What earns the right to scale.

Risk-weighted quality
False negatives and false positives are measured by consequence, not hidden inside one average.
Reason fidelity
The explanation reflects the actual evidence, rule, model, and human decision—not a plausible after-story.
Fair treatment
Outcomes and error rates are tested across relevant customer cohorts and accessibility needs.
Control effectiveness
Privacy, security, approval, override, monitoring, and audit controls work under normal and adversarial conditions.

Public sector signals

The UAE bar is moving from experimentation to governed scale.

  1. Emirates NBD GenAI summit and use cases

    Public examples include contact assistance, legal summarisation, ESG/customer work, governance, and guardrails.

  2. Emirates NBD 2025 results

    Public signal of more than 50 AI initiatives and AI-enabled customer operations at institutional scale.

  3. CBUAE responsible AI and consumer protection guidance

    Primary guidance on governance, transparency, bias, accountability, explainability, privacy, and high-impact decisions.

  4. CBUAE enabling technologies guidelines

    Wider regulatory context for safe adoption by licensed financial institutions.

Continue exploring

Related industry research.

Bring us the regulated decision whose evidence costs more time than its judgment.