KYC files and periodic reviews
The agent collects documents, checks their consistency, screens watchlists and prepares the file for the compliance officer. Periodic reviews, often overdue, start from a file that is already built.
Preparing KYC files, building credit analyses, tracking regulation: Claude agents connected to your tools, within DORA and the EU AI Act, with the decisions that commit a customer left to your teams.
An AI agent for banking is a Claude agent that handles the document-heavy, repetitive work of a bank: assembling know-your-customer files, preparing credit analyses, monitoring regulation and answering first-level requests. It operates inside the institution’s DORA perimeter and leaves every decision that commits a customer to the bank’s own teams.
A bank does not deploy an agent the way an unregulated company does. Four frameworks weigh on every project, and they need reading before the first line of code.
The Digital Operational Resilience Act (EU 2022/2554), in application since 17 January 2025, governs the ICT risks of financial entities, including those coming from their providers. An agent calling an externally hosted model falls within it: contractual clauses, register of information and resilience testing, plus an exit strategy as soon as the service supports a critical or important function.
Annex III of the EU AI Act lists systems that evaluate the creditworthiness of natural persons or establish their credit score as high-risk, with financial fraud detection explicitly excluded. The corresponding obligations apply from 2 December 2027: risk management, documentation, human oversight, traceability.
AML rules require banks to know their customers, monitor transactions and report suspicions to the national financial intelligence unit. An agent can gather documents, spot an inconsistency or draft a note. Qualifying a suspicion and filing the report remain human acts, justified and logged.
Professional secrecy rules and the GDPR require full control over where data travels: chosen cloud environment, hosting region, contractual retention terms, access logging. These choices belong to the scoping phase, not to the aftermath of a pilot.
The agent collects documents, checks their consistency, screens watchlists and prepares the file for the compliance officer. Periodic reviews, often overdue, start from a file that is already built.
Tax returns, accounts, sector notes: the agent assembles the material and drafts a first reasoned analysis with its sources. The analyst reviews, completes and recommends. The credit committee decides.
EU texts, EBA guidelines, national supervisor publications: the agent flags what changes, identifies the internal procedures affected and drafts an impact note for compliance.
First-level answers, meeting preparation, customer history summaries. Customers are told they are talking to an AI, as the EU AI Act has required since 2 August 2026, and sensitive requests go to an adviser.
High-risk under the AI Act, in scope of DORA, covered by banking secrecy: classification drives the architecture, the level of control and the documentation. It happens upfront, with compliance and the CISO.
Granting credit, onboarding a customer, filing a suspicion report, handling a complaint: the agent prepares, an authorised person decides. That is also the logic of Article 22 of the GDPR, which strictly limits decisions based solely on automated processing that produce legal or similarly significant effects on a person.
Every agent action is logged with its source, the model version and the instruction version. Internal audit and the supervisor alike can reconstruct what was done, by whom and on what basis.
We start from your processes and your regulatory constraints to find the first agent worth building, and the framework that goes with it.