Mastering financial risk and compliance with AI

Mastering financial risk and compliance with AI

AI brings new challenges, as well as opportunities. Microsoft’s Bastian Bahnemann explains how financial firms can combine transformation with resilience and trust

Jacqui Griffiths

By Jacqui Griffiths |


Ambitious and explorative – this is how analysts describe the adoption of AI across the financial services sector. Companies have been quick to see opportunities to enhance innovation, efficiency and customer experience. But to reap the rewards, they must also tackle new threats.

“For financial services firms, the question is no longer whether AI can create value, but how they can industrialise it in a controlled, explainable, resilient and auditable way,” says Bastian Bahnemann, financial services industry compliance and business development lead at Microsoft.

“AI – especially agentic AI – can increasingly influence decisions, trigger workflows, access sensitive data and interact with core systems. Unlike traditional systems, the speed of change and evolution of models is rapid and dynamic. That means the control model must evolve as well.”

Bahnemann advises organisations to structure their thinking around four compliance columns: contracts, off-cloud activities, in-cloud controls and other topics such as training, business continuity and broader regulatory readiness. However, he says, most AI risks cut across these categories.

“AI risk is not a separate category anymore,” he says. “It is part of mainstream prudential, cyber and operational risk management. Models like Claude Mythos have shown that advanced cyber capability is being compressed into multi-AI-model and AI agent powered tools which identify vulnerabilities, improve exploit paths and materially reduce the time from discovery to attack. That doesn’t just create a technology challenge; it changes expectations around patching discipline, baseline hygiene, third-party oversight and operational resilience.”

In this environment, a ‘deploy fast, govern later’ approach doesn’t work. AI maturity demands both ambition and a clear strategy for adoption and governance. 

Financial Services feature

Financial institutions need to follow a clear adoption and governance strategy to support AI maturity

“Many organisations start with technology enthusiasm and try to add governance later, but that creates friction in regulated industries like financial services,” says Bahnemann. “A better path is to scale in stages with the four-column compliance concept in mind: get the contractual and documentary side right, put the in-cloud controls in place, establish operating guardrails and keep the broader resilience and compliance topics visible from day one.”

For instance, rather than leaving AI agents scattered across individual teams or toolchains, Bahnemann recommends setting up an agent control plane such as Microsoft Agent 365, which provides a central registry, policy-based controls, observability and role-specific oversight. Robust data governance policy and AI-specific security controls are also essential in the agentic era. By bringing layers together in familiar tools, Microsoft empowers companies to build in these measures without hampering productivity and innovation.

“Productivity and protection do not have to be opposites if the platform is designed properly,” says Bahnemann. “Microsoft helps safeguard confidentiality and integrity by combining permission-aware grounding, strong identity controls, policy-driven data protection, auditability and threat protection – while still letting employees and customer-facing teams use enterprise data in productive and value-generating ways.

“In Microsoft 365 Copilot, for instance, the architecture is built around the Microsoft 365 service boundary, Microsoft Graph grounding and permission-aware access. The system only grounds on data the user is allowed to see, and Microsoft makes sure customer prompts, responses and grounding data are not used to train foundation models. That matters a lot in financial services, because confidentiality starts with identity, authorisation and trust boundaries – not with a generic promise that AI is secure.”

Further layers include Microsoft Entra with its conditional access, identity governance and agent identity concepts, and Purview, which extends data security and compliance controls into AI usage. Meanwhile Microsoft Defender adds posture management, detection, investigation and response capabilities for AI and agent environments.

“Purview can extend auditing, classification, labels, data loss prevention, insider risk, e-discovery and compliance controls to AI interactions, including prompts and responses,” explains Bahnemann. “That is exactly the type of control fabric financial institutions need before moving from experiments to production.”

Financial Services feature

Microsoft Purview provides financial institutions with advanced control over AI to help them move from experimentation to production

Knowing an application needs multi-layered security is one thing, but building those layers into an effective, compliant application can be an incredibly complex challenge. AI also raises very practical questions developers must answer: where does data go, who can access it, what is automated, and how to intervene when things go wrong. Microsoft provides the structure, as well as the building blocks, to simplify the task.

“For IT teams and developers, the biggest challenge is often getting an AI workload through security, architecture, compliance and risk approval and then running it in production without creating a new unmanaged attack surface,” says Bahnemann. “Microsoft Foundry provides a straightforward model for developer and platform teams to use, turning AI governance from an abstract policy discussion into a practical engineering pattern. It gives them a structured way to build, evaluate, monitor and improve AI systems with enterprise security and governance in mind from the start.

“In addition, as workloads become more agentic, the developer platform and the control plane need to work together. Microsoft Foundry helps build and run the AI workloads, while Agent 365 helps inventory, observe, govern and secure both Microsoft built-in and ecosystem partner agents at enterprise scale. That separation is helpful for regulated organisations because it lets innovation continue without giving up central oversight.”

Ultimately, it takes a complex weave of strategy, capabilities and governance to provide AI tools that are safe, inspiring and simple to use. Microsoft’s partner ecosystem plays a crucial role in translating financial firms’ AI vision into reality.

“Most financial institutions do not solve AI transformation with one vendor and one generic platform,” says Bahnemann. “They need domain expertise, regulatory content, integration into existing workflows, industry-specific controls and often managed implementation support. More broadly, the ecosystem matters because resilience and compliance are not solved only at the infrastructure layer. They also depend on the partner tools, implementation patterns and operational services that sit around the core platform. Our partners’ core strength lies in combining Microsoft’s control, security and governance stack with deep industry process expertise.”

With confidence in their ability to address risk and compliance, financial services firms are moving fast with AI.

Financial Services feature

KYC is a compliance process requiring financial institutions to confirm the identity of their customers

“Companies are quickly progressing from using AI for individual productivity to employing agentic systems that support entire business processes,” says Bahnemann.  

“Two examples from Germany stand out. DOMCURA, a non-life underwriting agency, used Azure OpenAI and Azure Cognitive Services to build KIM – an award-winning AI-powered virtual employee that processes claims from submission to decision in around 15 minutes. KIM has now been commercialised as a white-label product for third parties, moving from an internal efficiency gain to a new business model. Meanwhile AURA, an AI-powered underwriting assistant built jointly by HDI Global, Microsoft and Reply, supports underwriters through document-heavy intake, policy reasoning and decision support – reducing manual effort in one of the most compliance-sensitive processes in commercial insurance.

“Together, these two cases illustrate what the partner ecosystem enables in practice: claims automation on one side, underwriting intelligence on the other, both built on Microsoft’s cloud and AI governance stack with domain-specialist partners.”

Looking ahead, Bahnemann stresses the continued importance of cyber resilience, including important questions around issues like third-party dependencies, patch velocity and fallback planning.  

“In the coming months, many firms will remain focused on productivity and decision support, while cybersecurity enhancements, AI-supported vulnerability scanning and the automation of patching processes currently have the highest C-suite priority and regulatory attention,” he says. “In addition, organisations remain under pressure to modernise their data foundations because AI only works well if the data platform is secure, resilient and usable at scale.

“If advanced models like Claude Mythos can compress the timeline from vulnerability discovery to exploit, then response speed, architecture discipline and visibility matter even more. That is why the compliance conversation should not stop at policy and contracts, but extend into security posture, operating model and resilience execution. Financial firms will need to defend at AI speed, not just build AI features faster. And this is exactly what our new Microsoft multi-model agentic scanning harness (codename MDASH) is built around. It is a multi-agent vulnerability discovery and remediation system, using more than 100 agents that are injected in the right combination with the right set of models in your software delivery workflow. This works as a structured pipeline that takes the code base and emits validated, proven findings to help organisations harden their own developed software products.”

Keeping these considerations in play will enable the industry to continue its AI journey with ambition and confidence.

“In the longer term, we are moving from AI as an assistant to AI as part of the operating model,” says Bahnemann. “Financial services organisations will not move all the way to autonomy overnight, and in many areas they should not. But AI will increasingly sit inside service operations, compliance workflows, cyber defence, software engineering, customer service and control functions. The firms that win will be the ones that combine productivity gains with trust, resilience and supervisor-readiness.”

Partner perspectives 

Technology Record asked selected Microsoft partners how they use the Microsoft Azure platform to help financial services firms approach their AI strategy with confidence 

“Coretek helps financial services firms build compliant, resilient operations on Azure using AI-driven risk analytics, intelligent automation and Microsoft Purview governance,” said Brian Barnes, chief technology officer at Coretek. “We deploy agentic AI solutions that accelerate regulatory reporting, detect fraud in real time and streamline audit readiness. A large regional bank in Ohio implemented an Azure OpenAI-powered underwriting agent that automated loan decisioning workflows, reducing approval cycle times by 60 per cent while maintaining full audit-trail compliance. The result: lower operational cost, improved regulatory posture and a faster, more consistent customer experience – demonstrating that AI and compliance are complementary, not competing, priorities.”
Brian Barnes 
Chief Technology Officer, Coretek 

“In our project with TeamBank, KPMG has established a scalable Microsoft Power Platform landing zone and introduced the foundation for broad adoption of agents and apps,” said Peter Hertlein, partner in financial services at KPMG. “A standardised onboarding process for apps and agents, which is partly automated through an AI agent itself, has enabled faster, more autonomous delivery by business teams. At the same time, it has increased transparency, reusability and governance across use cases. Through this approach we have transformed the Power Platform into a manageable, bank-wide platform model. The solution embeds regulatory requirements, data protection and compliance controls by design, translating complex regulatory hurdles for financial services into a smart, scalable and compliant operating model.” 
Peter Hertlein 
Partner in financial services, KPMG 

 

“Melissa leverages the Microsoft Azure platform to help financial services firms manage risk and ensure compliant, agile and resilient operations," said Bud Walker, chief information officer at Melissa. “Our data quality, address validation and know your customer/anti-money laundering identity verification solutions integrate seamlessly with Azure Data Factory via native SQL Server Integration Services components, and with Azure Functions and Logic Apps via our REST APIs. This supports real-time verification, scalable batch processing and secure data enrichment. Powered by Azure’s global infrastructure and compliance framework, firms gain faster onboarding, reduced fraud and stronger regulatory adherence.” 
Bud Walker 
Chief Information Officer, Melissa

Discover more about AI and insights from experts at Microsoft Partner businesses including ServiceNow, LSEG and Velosio in the Summer 2026 issue of Technology Record. For more content like this, subscribe to the print edition or free digital edition of the quarterly Technology Record magazine.

 

Subscribe to the Technology Record newsletter


  • ©2026 Tudor Rose. All Rights Reserved. Technology Record is published by Tudor Rose with the support and guidance of Microsoft.