Back to Blog

AI in Banking and Financial Services: Use Cases, Tools and the Compliance Framework

Henri Jung, Co-founder at Superkind
Henri Jung

Co-founder at Superkind

A dark metal bank vault door with an orange accent ring around its dial, representing the trust and security at the centre of AI in banking

An adviser at a Volksbank opens a client meeting having spent the previous forty minutes doing something a machine could have done: pulling the account history, reading the last three contract changes, checking the open service tickets, and skimming a product sheet. The conversation that follows is good, because the adviser is good. But the value the bank pays for is in that conversation, not in the forty minutes of gathering that came before it. Multiply that by every adviser, every compliance analyst chasing false positives, and every back-office clerk keying the same data twice, and you have the real cost base of a modern bank.

The pressure to change it is coming from two directions. The workforce that carries the institutional knowledge - the senior credit officers, the AML specialists, the risk managers who know why a rule exists - is ageing and retiring, and the specialists to replace them are scarce. At the same time the regulator has stopped treating AI as an experiment: BaFin now folds it into ICT risk management under DORA, and the EU AI Act names credit scoring a high-risk use with obligations attached10,11.

This is an honest map of where AI actually works in a bank in 2026 - the use cases across departments, the real tools and vendors that serve each one, and the BaFin, MaRisk, DORA, EU AI Act, and DSGVO frame you have to work inside. No tool wins every row. And there is one thing almost none of them keep, which is the difference between software that runs your process and a system that remembers how your institution actually decides.

TL;DR

The value is real and large - McKinsey puts gen AI at 200 to 340 billion dollars a year for the global banking sector, largely through productivity in the document-heavy back office1.

The tool market splits by job - financial crime and AML (NICE Actimize, Nasdaq Verafin, SymphonyAI, ComplyAdvantage), credit and lending (nCino, Zest AI, parcIT), digital engagement and core banking (Backbase, Temenos, Avaloq, Finastra), and the DACH sector platforms (Finanz Informatik S-KIPilot, Atruvia GenoGPT).

Compliance is on the shortlist, not the afterthought - credit scoring is high-risk under the EU AI Act, AI sits inside DORA and MaRisk, and personal data falls under DSGVO10,11,22.

Every banking tool is a process engine - it runs the account, the alert, or the credit file. What it rarely keeps is the reasoning behind your credit, compliance, and advisory decisions when the specialist who held it retires.

The durable win - a Company Brain that retains how your institution decides, plus AI employees that work the routine, regulated back-office tasks inside the systems you already use. Buy the banking tools, do not build them, and layer memory and action on top.

Where a Bank Actually Loses Time and Knowledge

A bank runs on process and on people who know the process. The cost problem is not that the work is hard; it is that skilled, expensive staff spend most of their day on routine gathering and drafting, and the knowledge that makes the hard calls right lives in a handful of heads.

  • The back office is document-bound - KYC files, credit dossiers, regulatory reports, and complaint responses are assembled by hand from data that already exists in ten systems, over and over.
  • Compliance drowns in false positives - AML transaction monitoring generates far more alerts than are real, and analysts spend their days clearing noise rather than catching the genuine risk.
  • The specialists are retiring - the senior credit officers, risk managers, and compliance leads who know why a rule exists are ageing out, and the replacements are scarce and slow to train.
  • Knowledge lives in people, not systems - why a corporate client always draws down late, which alerts your best analyst dismisses and why, how the credit committee really weighs a borderline file - none of that is written down.
  • Every decision is regulated - a lending or compliance call is not just a business choice; it carries MaRisk, EU AI Act, and DSGVO duties, so the reasoning has to be defensible and logged, not just fast.
  • The core systems do not talk - the account is in the core banking platform, the client in the CRM, the risk in a separate model, and the context in an inbox, so staff become the integration layer, copying between them.

Key Data Point

McKinsey estimates generative AI could add 200 to 340 billion dollars in value a year across the global banking sector, equal to 2.8 to 4.7 percent of total industry revenues, largely through productivity1. Yet Accenture found that while 91 percent of banking executives call AI a strategic priority, only around 23 percent have moved past pilots into production7. The prize is real; the constraint is turning it into day-to-day, compliant operations.

PressureTypical figureWhy it matters
Banking value at stake$200-340bn a year1Productivity upside is board-level
Front-office productivity+27-35% for top IBs3Skilled staff do more, not fewer
Adoption vs production91% priority, ~23% live7The gap is scaling, not technology
Staff already using AI~60% of finance staff7Shadow use runs ahead of governance
Profit pool at risk~$170bn / ~9%2Laggards fight over shrinking margins

So the question is not whether to put AI on the problem. It is which use case fits which department, which tool serves it, and whether the tool just runs the process or actually keeps the judgement your best people carry.

“We want to enable digital progress while ensuring the proper functioning, stability and integrity of the financial system.”

- Mark Branson, President, BaFin9

Why 2026 Is Different for Banks

Banks have used models for decades, from credit scoring to fraud rules. What changed is that language models can now read and draft the unstructured documents that fill a bank, agents can act across systems rather than answer in a chat window, and the regulator has set a clear frame, so the technology and the rules arrived at the same time.

  1. Language models handle the documents - KYC files, contracts, complaints, and reports are unstructured text, and AI can now read, summarise, and draft them, which is where most of a bank’s manual load sits1.
  2. Agentic AI moved from chat to action - early frontline pilots report a two to threefold increase in qualified leads, because an agent gathers, drafts, and acts rather than just answering a question20.
  3. The regulator set the frame - the EU AI Act classifies credit scoring as high-risk, and BaFin folded AI into ICT risk management under DORA in December 2025, so the rules are now concrete rather than pending10,11,22.
  4. The sector data centres shipped AI - Finanz Informatik built the S-KIPilot into OSPlus toward roughly 200,000 Sparkassen workplaces, and Atruvia offers GenoGPT to the cooperative banks, so AI is arriving through the platforms banks already run14,15.
  5. The workforce cliff is here - the specialists who hold credit, risk, and compliance knowledge are retiring, so capturing what they know is now urgent, not aspirational.
  6. The honest caveat - most banks have not yet turned AI into scaled revenue or efficiency, and slower adopters risk what McKinsey calls pilot purgatory, so the winners pair the technology with governance and real integration, not demos21.

The Productivity vs Judgement Trap

An assistant that drafts a credit memo in seconds feels like the work is done. It is not the same as deciding well. The value is only realised when the right risk weighting is applied, the borderline file is judged the way your credit committee actually judges it, the alert that matters is separated from the noise, and the reasoning is remembered so the next analyst does not relearn it. A tool that drafts is only half the job in a regulated business.

With that lens in place, here is the honest read on where AI works across the bank.

AI Use Cases Across the Bank

AI does not arrive as one project; it arrives department by department. Here is where it earns its keep across a bank or financial-services firm, from the front line to the back office, with the honest note on what stays human.

Advisory and the front office

  • Meeting preparation - an assistant pulls the account, contracts, past contacts, and open tickets into a briefing, so the adviser walks in ready instead of spending forty minutes gathering, as the Sparkassen S-KIPilot is built to do14.
  • Next-best-product suggestions - grounded in the customer’s real position, not a generic campaign, with the adviser deciding what to actually recommend.
  • Call and meeting documentation - the routine write-up and CRM update drafted automatically, so the record is complete without the adviser keying it.

Credit, lending and underwriting

  • Credit file assembly - gathering financials, collateral, and history into a structured dossier, the slow part of every lending decision, with platforms like nCino built around this workflow18.
  • First-pass analysis - drafting the credit memo and flagging the risks, so the officer starts from a reviewed draft rather than a blank page.
  • Decisioning models - Zest AI and the German cooperative sector’s parcIT run credit and risk models, which sit squarely in the EU AI Act high-risk class and need the governance to match16,22.

Compliance, KYC and AML

  • Onboarding and KYC - reading identity documents, checking sanctions and PEP lists, and assembling the file, the highest-volume routine work in compliance.
  • Transaction monitoring and alert triage - NICE Actimize, Nasdaq Verafin, SymphonyAI, and ComplyAdvantage use AI to cut false positives and prioritise the alerts that matter17.
  • Suspicious-activity drafting - AI assembles the case and drafts the report, but a qualified human owns the filing decision, as the rules require.

Fraud, risk and reporting

  • Real-time fraud detection - AI scores transactions for fraud far faster than static rules, a mature category with vendors like Featurespace and FICO alongside the AML leaders19.
  • Regulatory reporting - drafting and reconciling the returns that consume the risk and finance functions, with a human checking the numbers that carry capital and MaRisk weight.
  • Model monitoring - watching deployed models for drift, which is not optional in a bank, because a model that quietly goes wrong is a real financial and regulatory risk16.

Operations, IT and service

  • Customer service and requests - answering routine queries and drafting responses, with escalation to a human for anything that affects an account or a complaint.
  • Legacy code modernisation - documenting and refactoring the old core-banking code that no one who wrote it still works there, a use case half the leading banks are pursuing.
  • Back-office automation - the reconciliations, data entry, and inter-system copying that turn skilled staff into an integration layer.

Where AI leads vs where the human stays

AI takes the routine

  • ✓ Gathering - assembling files, briefings, and dossiers from many systems
  • ✓ Summarising - condensing documents, transactions, and history
  • ✓ Drafting - memos, reports, replies, and case files
  • ✓ Triage - separating the alerts and requests that matter from the noise

The human owns the decision

  • ✗ Lending calls - approving, pricing, or declining credit
  • ✗ Compliance filings - the suspicious-activity decision and account actions
  • ✗ Regulated numbers - the capital and risk figures MaRisk governs
  • ✗ The relationship - the advice and trust a client pays for

The AI Tool Landscape for Banks in 2026

Here is the honest read on the categories that matter, grouped by the job each does best, what it is genuinely good at, and where it stops. Pricing is quote-only for almost all of these, because they are sold on modules, users, and volume.

Financial crime, AML and fraud

1. NICE Actimize

  • What it is - A leading financial-crime platform covering AML, fraud detection, and market surveillance, with AI-driven transaction monitoring and case management17.
  • Best for - Banks that want an established, broad enterprise platform for the whole financial-crime stack.
  • Where it stops - It monitors and flags; the investigation judgement and the filing decision still sit with your analysts.

2. Nasdaq Verafin

  • What it is - A cloud financial-crime platform strong in AML and fraud, using consortium data and AI to sharpen detection17.
  • Best for - Institutions that value cross-institution data to reduce false positives.
  • Where it stops - Powerful for detection; the compliance reasoning and case ownership remain human.

3. SymphonyAI and ComplyAdvantage

  • What they are - AI-native financial-crime tools; SymphonyAI (Sensa) focuses on AML detection and investigation, ComplyAdvantage on real-time AML and sanctions risk data17.
  • Best for - Firms wanting modern, AI-first detection, including fintechs and mid-size banks.
  • Where they stop - They score and surface risk; the SAR decision and the audit trail stay yours to own.

Credit, lending and decisioning

4. nCino

  • What it is - A cloud banking platform strong in commercial lending, with AI-assisted credit decisioning and workflow across the loan lifecycle18.
  • Best for - Banks wanting to digitise and speed the commercial credit process end to end.
  • Where it stops - It runs the lending workflow; the final credit decision and its EU AI Act duties stay with the bank.

5. Zest AI

  • What it is - An AI credit-decisioning specialist that builds and runs underwriting models aimed at more accurate, more inclusive lending18.
  • Best for - Lenders wanting to modernise the scorecard itself, especially in consumer credit.
  • Where it stops - Credit scoring is high-risk under the EU AI Act, so the model needs conformity, validation, and human oversight22.

6. parcIT (Atruvia)

  • What it is - The credit and risk methodology provider inside the German cooperative group, supplying the models the Volksbanken and Raiffeisenbanken rely on16.
  • Best for - Cooperative banks whose risk and credit models must fit the sector’s standards.
  • Where it stops - As one public case showed, a model error can strain a bank’s risk limit, which is exactly why MaRisk validation and monitoring matter16.

Digital engagement and core banking

7. Backbase

  • What it is - An engagement banking platform folding AI across onboarding, service, and the customer journey on top of the core18.
  • Best for - Banks modernising the digital front end without replacing the core all at once.
  • Where it stops - It owns the engagement layer; the risk, compliance, and credit judgement live elsewhere.

8. Temenos, Avaloq and Finastra

  • What they are - Established core and wealth banking platforms embedding AI features into the systems of record European banks already run.
  • Best for - Institutions extending AI inside their existing core rather than adding a separate tool.
  • Where they stop - The AI is bounded by the platform; it does not reach the email, the past cases, and the tacit knowledge outside it.

DACH sector platforms and assistants

9. Finanz Informatik - S-KIPilot and SparkasseGPT

  • What it is - The Sparkassen data centre’s AI, with the S-KIPilot built into OSPlus for advisers and SparkasseGPT developed with OpenAI, rolled out toward roughly 200,000 workplaces13,14.
  • Best for - Sparkassen using the standard advisory and service workflows inside OSPlus.
  • Where it stops - It is a sector-wide assistant; the workflows and knowledge specific to one Sparkasse still need something on top.

10. Atruvia - GenoGPT

  • What it is - The cooperative group’s AI knowledge platform, bundling bank knowledge and making it available context-specifically for the Volksbanken and Raiffeisenbanken on agree2115.
  • Best for - Cooperative banks wanting sector-standard AI inside their core environment.
  • Where it stops - It is a shared platform; a single bank’s own processes and institutional memory are not its focus.

11. General assistants (ChatGPT, Microsoft Copilot) as a baseline

  • What they are - General-purpose assistants that draft text, summarise a document, or answer a question.
  • Best for - One-off drafting and analysis alongside the real banking systems.
  • Where they stop - They are not a banking system. They do not hold your accounts, do not connect to your core, and used without governance they create a shadow-AI and DSGVO problem. Use them as a co-pilot, not the system.
Tool / categoryPrimary jobBest forEU AI Act risk
NICE ActimizeAML, fraud, surveillanceBroad enterprise financial crimeMostly limited / minimal
Nasdaq VerafinAML and fraud, consortium dataCross-institution detectionMostly limited / minimal
SymphonyAI / ComplyAdvantageAI-first AML and sanctionsModern, AI-native detectionMostly limited / minimal
nCinoCommercial lending workflowEnd-to-end credit processHigh if it scores people
Zest AICredit decisioning modelsModernising the scorecardHigh-risk (credit scoring)
parcIT (Atruvia)Credit and risk methodologyCooperative-sector modelsHigh-risk (credit / risk)
BackbaseDigital engagement layerFront-end modernisationMostly limited / minimal
Temenos / Avaloq / FinastraCore and wealth platformsAI inside the existing coreDepends on the feature
Finanz Informatik S-KIPilotSparkassen adviser assistantOSPlus advisory and serviceMostly limited / minimal
Atruvia GenoGPTCooperative knowledge platformagree21 banksMostly limited / minimal

Do more with the specialists you have

Book a 30-minute call. We will find the routine, regulated work worth automating and the credit and compliance knowledge worth keeping.

Book a Demo →
A grid of dark metal safe-deposit boxes with one framed in orange, representing institutional knowledge and records kept secure across a bank

What Every Banking Tool Misses

Run the tools above side by side and a pattern appears. They differ on price, on breadth, and on how much they automate. They agree on one blind spot: each is a process engine for one part of the bank, and none of them keeps the reasoning that makes a decision right when the specialist who held it retires.

  • They run the process, not the judgement - the AML tool flags an alert. It does not know that this pattern, for this client, is the same false positive your best analyst cleared last quarter and why.
  • The context walks out the door - when a senior credit officer retires, the platform keeps the files but loses the sense of which borrowers to trust, which sectors are turning, and how the committee really weighs a borderline case. The next hire relearns it.
  • Each tool sees only its own box - the core banking platform, the AML tool, the lending system, and the CRM each hold a slice, so no single tool has the cross-department view a real decision needs.
  • Drafting is not deciding - a perfect credit memo still needs someone to weigh the risk and own the number, and a regulator expects that human to be accountable, not the model.
  • Reach stops at the system edge - the reason a decision should move often lives in an email, a past case note, or a conversation the tool never sees.
  • Governance is left to you - the EU AI Act, MaRisk, and DORA duties around a model are the bank’s to carry, and a point tool rarely gives you the logging and oversight the supervisor wants across everything.

The Real Constraint

The best AML or lending tool cannot tell you why a client that looks risky on paper is one your relationship manager would back, remember which alert patterns are noise for your book, or know how your credit committee actually decides. In 2026 the differentiator is not the point tool - it is whether your credit, compliance, and advisory reasoning is captured and reusable, and whether something actually works the routine, regulated tasks across your core, your CRM, and your inbox. That is a knowledge-and-execution problem the banking software market mostly leaves to you.

This is the gap a Company Brain, plus AI employees, is built to close.

The Company Brain Approach

A Company Brain is company memory: the people-knowledge, processes, and decisions that make your bank work, captured so they survive turnover and can be acted on. It is the layer above your banking tools, and it is what turns a process engine into an AI employee that works the task and answers the questions - inside your compliance frame, not around it.

What it keeps

  • How your credit really decides - the way your committee weighs a borderline file, the sectors you are cautious on, and the borrowers you know, so analysis reflects your risk appetite, not a generic model.
  • Which alerts are noise - the transaction patterns your best analysts clear as false positives and why, so triage improves instead of repeating the same investigations.
  • The client patterns - who draws down late, who is worth the exception, and the relationship history, so advice and credit reflect who you are really serving.
  • Why you decided - the reasoning behind past credit, compliance, and pricing calls, kept and logged, so the next decision learns from the last and is defensible to the supervisor.
  • Feedback as it happens - the Company Brain learns from your specialists’ corrections every day, so it stays accurate as markets, rules, and clients change, rather than going stale.

The AI employees on top

Grounded in that memory, AI employees do the routine work end to end and stay connected to the systems where your accounts and their context actually live - the core platform, the CRM, email, Teams, and SharePoint.

  • Assemble the file - pull the KYC, credit, or complaint file together from every system and flag what needs a human eye.
  • Draft the analysis - produce the credit memo, the case summary, or the regulatory draft in your format, ready for review.
  • Triage the alerts - separate the AML and fraud noise from the genuine risk, using your own history of what turned out to matter.
  • Prepare the adviser - build the meeting briefing and the next-best-action from the client’s real position.
  • Improve daily - every correction and every closed case feeds back into the Company Brain, so you get more output without more headcount.
DimensionBanking tool with AICompany Brain + AI employees
What it holdsAccounts, alerts, files, modelsThe reasoning behind each decision
What it doesRuns one process wellWorks the task and supports the call
ReachStrong inside its own systemAcross core, CRM, email, Teams, SharePoint
When your specialist retiresData stays, judgement is lostThe reasoning is retained and reused
Over timeRules go stale unless maintainedImproves daily from real feedback

A Company Brain does not replace your core banking platform or your AML tool. It sits above them and keeps the thing they never captured: how your institution actually decides, and who works the follow-through.

“Model risk management is developing from a reactive gatekeeper into a proactive enabler of responsible innovation.”

- Dr. Philipp Schröder, Partner, Financial Services, PwC Germany5

Build vs Buy vs Layer: The Verdict

The instinct with banking AI is to frame it as build versus buy. That is the wrong question. The right frame has three parts, and for most banks the answer is all three, in order.

  1. Buy the banking tools - core platforms, AML engines, and lending systems are solved problems built by vendors with years of data and compliance work. Building your own is a false economy; pick the tools that fit your sector and connect them.
  2. Do not build the platform - a homegrown AML or core system competes with specialists and carries the regulatory burden alone. You will spend more and see less.
  3. Layer memory and action on top - the part no banking tool gives you, the retained credit and compliance reasoning and the AI employees that work the routine tasks across your core, CRM, and inbox, is where a custom layer earns its place, because it is specific to how your bank decides.
Your situationSensible shortlistWhy
Financial crime is the bottleneckNICE Actimize, Nasdaq Verafin, SymphonyAIMature AML and fraud detection at scale
Modernising the credit processnCino, Zest AI, parcIT (DACH)Lending workflow and decisioning
Fixing the digital front endBackbase, core platform AIEngagement without replacing the core
Sparkasse or cooperative bankFinanz Informatik, AtruviaSector-fit AI inside OSPlus or agree21
Knowledge walks out when people retireCompany Brain + AI employeesKeeps the reasoning and works the routine task

Buyer’s Checklist

  • Classify each use case under the EU AI Act before you buy, especially anything touching credit scoring
  • Confirm the tool fits your core, whether OSPlus, agree21, Temenos, or Avaloq
  • Check EU and German data residency and DSGVO handling of personal data
  • Treat the AI provider as a third party under DORA and register it in your ICT risk framework
  • Require explainable, logged model outputs for MaRisk and supervisory review
  • Confirm a human owns every decision that affects a customer or a regulatory obligation
  • Model total cost including licence, integration, validation, and ongoing monitoring
  • Ask what happens to your credit and compliance reasoning when the specialist retires

Single broad platform vs specialist plus a layer

Single broad platform

  • ✓ One vendor - core, service, and analytics in one place
  • ✓ Consistent data - one system of record
  • ✓ Enterprise depth - strong for large, regulated work
  • ✗ Heavy and costly - long rollout, enterprise pricing
  • ✗ Still an engine - it does not keep your reasoning

Specialist plus a layer

  • ✓ Right tool per job - best-fit AML, credit, or engagement
  • ✓ Faster to value - quick wins on the biggest bottleneck
  • ✓ Memory and action - a layer keeps judgement and works the process
  • ✗ More integrations - more systems to connect
  • ✗ Needs discipline - only pays off if you capture and act

The 90-Day Deployment Playbook

Most banking AI projects stall because they try to boil the ocean, or because they start with a high-risk use case and get stuck in governance. A focused 90-day plan takes one lower-risk, high-volume back-office process from baseline to a working, measurable loop, with the compliance frame in place, then expands. Here is the shape.

Phase 1: Baseline and capture (Weeks 1-4)

  1. Week 1: Pick a lower-risk, high-volume process - KYC file assembly, complaint drafting, or meeting prep, not credit decisioning, so you get value without the full high-risk conformity burden first.
  2. Week 2: Baseline the numbers - measure handling time, volume per staff member, error and rework rate, and backlog. This is your before picture.
  3. Week 3: Capture the reasoning - sit with your best specialist and document how the process really runs and where the judgement lives. This seeds the Company Brain.
  4. Week 4: Set the guardrails - define what the AI may do automatically, what needs review, and what always goes to a human, plus the logging DORA and MaRisk expect.

Phase 2: Build and test (Weeks 5-8)

  1. Week 5-6: Connect and ground - wire the AI employee to the core, CRM, and document stores, and ground it in the captured reasoning. It runs alongside the team, not on live cases yet.
  2. Week 7: Shadow mode - the AI assembles files and drafts on real cases, and your specialists review and correct. Every correction feeds the Company Brain.
  3. Week 8: Refine - tune the edge cases, finalise the review checkpoints, confirm the audit trail, and set the go-live scope.

Phase 3: Run and measure (Weeks 9-12)

  1. Week 9: Soft launch - let the AI run the process for one team, with a human owning every decision and the log capturing every step.
  2. Week 10-11: Full rollout - expand to the wider function, and only then plan the move toward a higher-risk use case with the governance already proven.
  3. Week 12: Measure and expand - compare handling time, volume, and rework against the week-1 baseline, review the audit trail, then pick the next process.

Banking AI Readiness Checklist

  • You can name the one lower-risk process where manual effort and backlog hurt most
  • Your core, CRM, and document data are in a form an AI employee can read
  • You have classified the use case under the EU AI Act and confirmed its risk class
  • Your best specialist can spend time capturing how the process really runs
  • The AI provider is registered as a third party under your DORA ICT framework
  • Model outputs are explainable and logged for MaRisk and supervisory review
  • A human owns every decision that affects a customer or a regulatory obligation
  • DSGVO, EU data residency, and any works-council involvement are cleared before go-live

How Superkind Fits

Superkind builds AI employees grounded in a Company Brain. In a bank, that means AI employees that work the routine, regulated back-office tasks - file assembly, drafting, alert triage, meeting prep - connected to the systems you already use, and a company memory that keeps how your institution decides even when specialists retire.

  • Works on top of your banking tools - it sits alongside OSPlus, agree21, Temenos, nCino, or your AML platform, no rip-and-replace of the systems you already run.
  • Grounded in your Company Brain - analysis reflects your real credit appetite, your known clients, and your false-positive history, not a generic model.
  • Connected to your real systems - it acts across the core, CRM, email, Teams, and SharePoint through API connections, so it works where the context lives.
  • Works the task, not just a chat - it assembles the file, drafts the memo, triages the alerts, and prepares the adviser, with a human owning every decision that affects a customer or a regulatory obligation.
  • Built for the compliance frame - human-in-the-loop by design, logged actions, EU data residency, and provider governance that fits DORA and MaRisk, not a consumer chatbot bolted on.
  • Keeps the knowledge - the credit, compliance, and advisory judgement your specialists hold is captured as the work happens, so it survives retirements and turnover.
  • Improves every day - your team’s feedback and every closed case make it more accurate over time, so you get more output without more headcount.
  • Live in weeks - a first lower-risk process typically reaches supervised production in 8 to 12 weeks, running one workflow before it expands.
ApproachTypical banking toolSuperkind
Primary jobRun one process wellWork the task and support the calls
GroundingIts own data and rulesCompany Brain kept current by daily feedback
ReachStrong inside its own systemAcross core, CRM, email, Teams, SharePoint
Knowledge retentionData kept, judgement lostCredit and compliance reasoning retained
ModelPer-user or module licensingAI employees tied to outcomes

Superkind

Pros

  • ✓ Works the process - file assembly, drafting, and triage, not just a chat
  • ✓ Grounded in your knowledge - not a generic assistant
  • ✓ Acts across real systems - core, CRM, email, Teams, SharePoint
  • ✓ Built for compliance - human-in-the-loop, logged, EU-resident
  • ✓ No rip-and-replace - works on top of your existing banking tools

Cons

  • ✗ Not a self-serve product - it is built with your team
  • ✗ Needs process access - we map how you really decide
  • ✗ Not a system of record - it complements your core, not replaces it
  • ✗ Not the model itself - a high-risk scoring model still needs its own conformity work

BaFin, MaRisk, DORA, the EU AI Act and DSGVO

For a bank or financial-services firm, compliance is the first line of the AI shortlist, not the last. The good news is that most back-office AI is lower risk, but credit scoring is high-risk, AI now sits inside DORA and MaRisk, and personal data falls under DSGVO, so the frame has to be part of the design.

EU AI Act

  • Credit scoring is high-risk - Annex III names creditworthiness assessment and credit scoring of natural persons as high-risk, bringing risk management, data governance, documentation, logging, human oversight, and a conformity assessment22.
  • Most back-office AI is lower risk - assembling files, summarising documents, and drafting internal text generally sit outside the high-risk categories, so the heavy duties usually do not apply.
  • Article 50 transparency - where an AI system interacts with a person, that should be clear, so disclose the AI in customer-facing messages23.
  • Enforcement is real - breaches of the AI Act can draw fines up to 15 million euros or 3 percent of worldwide annual turnover, so classification is not a formality11.

DORA, MaRisk and BaFin

  • AI is ICT risk under DORA - BaFin’s December 2025 guidance treats AI as part of ICT risk management under DORA, so the model and its provider fall inside your resilience framework10.
  • Model risk under MaRisk - any model feeding a risk or capital number needs validation, monitoring, and clear ownership, and a public case where a provider model error strained a bank’s risk limit shows why16.
  • Third-party governance - an external AI provider is a third party to register, assess for concentration risk, and oversee, exactly as DORA requires for critical ICT services.
  • Human oversight and logging - keep a qualified human on every regulated decision and log what the AI does, which satisfies the supervisor and is simply good banking governance.

DSGVO and the DACH fit

  • Customer data is personal data - account, transaction, and identity data are covered by DSGVO, so process them lawfully, minimally, and with a clear purpose and legal basis.
  • Keep data in the EU - prefer tools that process within your infrastructure or a compliant EU boundary, a point sharpened by the sovereignty debate around US cloud providers12.
  • Works council involvement - where AI changes how staff work, the Betriebsrat is typically involved in German institutions. Bring them in early, not after the pilot.
  • Sector fit - a tool that cannot work inside OSPlus or agree21, or that ignores German reporting conventions, will not fit a Sparkasse or Volksbank however good its AI.

Practical Compliance Stance

Classify each use case under the EU AI Act, keep a qualified human on every regulated decision, register the AI provider under DORA, validate and monitor any model that feeds a risk number for MaRisk, prefer EU data residency for DSGVO, disclose the AI where it communicates, involve the works council early, and log every action. That posture respects the AI Act, satisfies DORA and MaRisk, and happens to be good banking governance regardless of the regulation.

Frequently Asked Questions

There is no single best tool, because the right choice depends on the job. For financial crime, AML, and fraud, NICE Actimize, Nasdaq Verafin, SymphonyAI, and ComplyAdvantage lead. For credit and lending, nCino and Zest AI are strong on decisioning, with parcIT the reference in the German cooperative sector. For digital engagement and service, Backbase and the core banking vendors Temenos, Avaloq, and Finastra fold in AI. In the DACH market, the sector data centres shape reality: Finanz Informatik with the S-KIPilot in OSPlus for the Sparkassen, and Atruvia with GenoGPT for the Volksbanken and Raiffeisenbanken. The more useful question is not which tool you buy, but whether your credit, compliance, and advisory knowledge survives when a senior specialist retires, and whether something actually works the routine, regulated back-office tasks across the systems you already run.

The biggest early gains are in the document-heavy, rules-bound back office: KYC and onboarding, AML transaction monitoring and alert triage, credit file preparation, regulatory reporting, and complaint and request handling. Front-office advisory benefits too, where an assistant prepares a client meeting from account and contract data. The pattern is consistent: AI takes the routine data-gathering, summarising, and drafting off skilled staff, and a human keeps the decision. McKinsey estimates gen AI could add 200 to 340 billion dollars a year to the global banking sector, largely through this kind of productivity.

Yes. Annex III of the EU AI Act names creditworthiness assessment and credit scoring of natural persons as a high-risk use, which brings the full set of obligations: risk management, data governance, technical documentation, logging, human oversight, transparency, and a conformity assessment. Risk assessment and pricing in life and health insurance are treated the same way. That does not mean you cannot use AI in lending; it means a credit-decisioning model carries duties that a document-summarising assistant does not, so classify each use case before you deploy it, not after.

DORA governs digital operational resilience, and BaFin has made clear that AI is part of ICT risk management under DORA, not a separate ethics topic. In practice that means an AI system and the third-party providers behind it fall under your ICT risk framework: register the provider, assess concentration risk, test resilience, and keep oversight of the model in production. BaFin published guidance in December 2025 setting this tone. The upshot is that AI governance in a bank is not optional documentation; it is part of the resilience regime the supervisor already examines.

A banking tool is a system of record and workflow: the core banking platform holds the accounts, the AML tool monitors transactions, the lending platform runs the credit process. A Company Brain keeps the reasoning that makes those systems produce the right answer: why this corporate client always draws down late, which alert patterns your best analyst dismisses as false positives and why, how your credit committee really weighs a borderline file, and the tacit knowledge a retiring risk manager carries. The tool runs the process; the Company Brain remembers how your institution actually decides, and an AI employee acts on both.

For parts of the work, increasingly yes, within guardrails, but the decision that affects a customer or a regulatory obligation should stay human-owned. AI can assemble the credit file, draft the analysis, run first-pass AML triage, and prepare the reporting. What it should not do unsupervised is decline a loan, close an account, or file a suspicious-activity report, because those are decisions the EU AI Act, MaRisk, and basic fairness expect a person to own. The safe pattern is AI does the gathering and drafting, a qualified human reviews and owns the outcome, and every step is logged.

The German sector runs largely on its own IT service providers, so the AI arrives through them. Finanz Informatik built the S-KIPilot into OSPlus and rolled it out toward roughly 200,000 Sparkassen workplaces through 2025, supporting advisors with customer-data analysis, document summaries, and product suggestions, with SparkasseGPT developed in cooperation with OpenAI. On the cooperative side, Atruvia offers GenoGPT, a knowledge platform that bundles bank knowledge for the Volksbanken and Raiffeisenbanken on agree21. For an individual Sparkasse or Volksbank, the practical question is what to add on top of these sector tools for the workflows they do not fully cover.

The value is real but unevenly captured. McKinsey puts the banking prize at 200 to 340 billion dollars a year, Deloitte projects front-office productivity gains of 27 to 35 percent for the largest investment banks, and Gartner reported that three quarters of banking leaders had deployed or were deploying gen AI. Yet Accenture found that while 91 percent of banking executives call AI a strategic priority, only around 23 percent had moved beyond pilots into production. The gap between potential and captured value is the story of 2026: the technology works, but scaling it into regulated, day-to-day operations is where most institutions are still stuck.

Model risk is the risk that a model produces wrong outputs, or right outputs used wrongly, and it is a regulated discipline in banking under MaRisk and supervisory expectations. It matters for AI because a credit or risk model that drifts, is trained on biased data, or is misapplied can cause real financial and regulatory harm. A public example: a German Volksbank breached a risk limit and attributed it to a methodology error at a provider model. The lesson is that AI in a bank is not just a productivity tool; any model that feeds a risk or capital number needs validation, monitoring, and clear ownership, exactly as MaRisk requires.

It depends on the use case and the risk class. A low-risk internal assistant that summarises documents or drafts replies can be in supervised use within weeks. A high-risk system such as credit decisioning takes longer, because it needs the EU AI Act conformity work, model validation under MaRisk, and DORA-aligned provider governance before it goes live. A focused approach that automates one lower-risk, high-volume back-office process first, then extends into the regulated ones with the governance in place, reaches value faster and de-risks the rollout compared with a bank-wide big-bang programme.

The honest framing is leverage, not headcount. Banks face a retiring workforce and a shortage of specialists in compliance, risk, and IT, so the gain from AI is that each skilled person handles more of the routine load while spending their time on judgement, relationships, and edge cases. AI employees take the repetitive gathering, summarising, and drafting; people keep the decisions, the customer relationships, and the regulatory accountability. The institutions that treat AI as a way to do more with the team they have, rather than a pure cost cut, are the ones capturing durable value.

Classify the use case under the EU AI Act first, because a high-risk credit or scoring system carries obligations a low-risk assistant does not. Confirm the tool fits your core banking environment, whether that is OSPlus, agree21, Temenos, or Avaloq, and how it handles German and EU data residency under DSGVO. Check that it fits DORA as a third-party ICT provider, that model outputs are explainable and logged for MaRisk, and that a human owns every decision that affects a customer. Then ask the question the tool rarely answers: what happens to your credit, compliance, and advisory reasoning when the specialist who holds it retires.

Related Articles

Sources

  1. McKinsey - The Economic Potential of Generative AI: The Next Productivity Frontier (banking value ~$200-340bn a year, 2.8-4.7% of revenues)
  2. McKinsey - Agentic AI Will Shake Up Banking, Shrinking Global Profit Pools (~$170bn / ~9% at-risk scenario)
  3. Deloitte - Unleashing a New Era of Productivity in Investment Banking Through Generative AI (front-office productivity +27-35%)
  4. Gartner - AI and Generative AI Use Cases in Banking and Investment Services
  5. PwC Deutschland - Modellrisikomanagement wird zum Schlüssel für sichere KI-Innovation in Banken (Dr. Philipp Schröder quote)
  6. KPMG - Generative KI in der deutschen Wirtschaft 2026, Branchenreport Banking
  7. LexisNexis - Generative KI im Investment Banking (Future of Work 2026: ~60% of finance staff use AI, ~63% of firms deploy AI agents)
  8. Der Bank Blog - Wie KI das Sparkassen-Banking 2026 neu definiert
  9. BaFin - BaFinTech 2025 Speech: We Want to Enable Digital Progress (Mark Branson quote)
  10. BDO - KI unter DORA: BaFin-Orientierungshilfe für die Finanzbranche (December 2025)
  11. SIGS - Der EU AI Act: Neue Regeln für die KI-basierte Kreditwürdigkeitsprüfung (credit scoring as high-risk)
  12. IT-Finanzmagazin - Die IT-Transformation der Finanzbranche 2026: DORA, AI Act und technologische Souveränität
  13. IT-Finanzmagazin - SparkasseGPT und mehr: Warum die Sparkassen bei KI auf OpenAI setzen
  14. IT-Finanzmagazin - Jahresbericht 2025: Finanz Informatik baut KI weiter aus (S-KIPilot in OSPlus, ~200,000 workplaces)
  15. Atruvia - GenoGPT Use Cases: 4 Praxisbeispiele für Volksbanken und Raiffeisenbanken
  16. Finanz-Szene - Volksbank reißt Risikolimit und sieht Schuld bei Modell-Fehler von Atruvia-Tochter (model risk example)
  17. SymphonyAI - Top 10 AML Software for Banks in 2026
  18. Backbase - Leading AI Banking Platforms and Providers 2026
  19. Emburse - AI Fraud Detection in Banking 2026 Guide
  20. McKinsey - Agentic AI Is Here: Is Your Bank’s Frontline Team Ready? (2-3x qualified leads in pilots)
  21. McKinsey - Scaling Gen AI in Banking: Choosing the Best Operating Model (pilot purgatory)
  22. EU AI Act - Annex III: High-Risk AI Systems (creditworthiness and credit scoring)
  23. EU AI Act - Article 50: Transparency Obligations
  24. PwC Deutschland - Einblicke zur Künstlichen Intelligenz im Finanzsektor (two-thirds of financial-services firms use AI)
Henri Jung, Co-founder at Superkind
Henri Jung

Co-founder of Superkind, where he helps SMEs and enterprises deploy custom AI employees that actually fit how their teams work. Henri is passionate about closing the gap between what AI can do and the value it creates in real companies. He believes the Mittelstand has everything it needs to lead in AI - it just needs the right approach.

Ready to put AI to work in your bank without losing the judgement?

Book a 30-minute call with Henri. We will find the routine, regulated work worth automating and the credit and compliance knowledge worth keeping - no commitment, no sales pitch.

Book a Demo →