ComplyAI · AI Governance for UK Financial Services

ComplyAI. The governance layer for AI-assisted financial decisions.

Four compliance layers, built to make AI-assisted credit, risk, and compliance decisions traceable, explainable, and accountable under UK financial regulation.

Two-minute self-check

Could your AI-assisted decisions survive being questioned?

Four questions, one per governance layer below. Answer honestly, see your score out of 8, and exactly where the gaps sit.

The problem

Deployment is outrunning governance.

UK banks are deploying AI faster than they can govern it. The Bank of England's February 2026 summary of its 2025 roundtables with UK banks found firms saying traditional model risk management does not scale to agentic AI.

Most deployments cannot answer a simple question: when the FCA asks how a specific AI-assisted decision was made, what is the evidence?

The four layers

Every decision traceable.
Every gap accounted for.

Each layer answers a different regulatory question, and each one is independently tested.

01 /

Source Tracing

Every figure in an AI-assisted decision verified against source documents, not just plausibility-checked. Fabricated or unverifiable citations are rejected, not flagged and forgotten.

02 /

Immutable Audit Log

A hash-chained record of every decision processed. Tampering with any historical entry breaks the chain and is cryptographically detectable, not just procedurally discouraged.

03 /

Explainability Record

A plain-language explanation of every decision, written for a borrower or an FCA examiner, not an engineer. Limitations are stated honestly. Nothing found by the source tracing layer is silently omitted or softened.

04 /

SMCR Accountability Gate

A named individual reviews and signs off before any consequential decision is finalised. Once signed off, a decision cannot be silently overwritten by a second reviewer.

Track record

Built and proven,
not just designed.

Every layer is independently tested. The system has been audited twice, by two separate review processes, and each finding was fixed and verified before being considered closed.

One story worth telling directly

The governance layer caught its first fabrication in our own code.

During development, an automated citation-verification check was added specifically to catch AI-fabricated source references. On its first run, it found a fabricated citation already sitting inside an internal test fixture from an earlier stage of development, a stated figure that did not match what the source document actually said.

This is exactly the failure mode the layer exists to catch, and it caught it in our own code before any client ever saw it.

The system has also been validated against live model behaviour twice, not just automated tests, confirming the governance logic holds under real conditions, not only scripted ones.

HONEST SCOPE

We do not claim this is finished.

The current build has a documented, bounded list of production-readiness items: a database backend for high-volume deployment, external anchoring for the audit chain, and multi-instance concurrency testing. Nothing is hidden. Every gap is known and scoped.

How this deploys

Two ways to work with ComplyAI.

Governance layer proof

For banks with an existing AI platform

ComplyAI can run as an independent, parallel system on the same source documents for a bounded trial period, at no cost, producing a direct comparison of accuracy, audit completeness, and cost against your current system.

Governance-first platform

For banks building AI capability

ComplyAI deploys as a complete governance-first platform from day one, or one workflow at a time as your team builds confidence.

How we work

Three tiers. No retainers.
You own everything.

Both deployment models above are delivered through the same Tier 0 to Tier 3 engagement. Tier 0 is a free discovery call. Tier 1 scores your governance gap. Tier 2 deploys ComplyAI. Tier 3 keeps it running. Start at Tier 0. Stop whenever the case is not proven.

TIER 0 · FREE

45-Minute Discovery Call

A free video call on Zoom or Teams with your risk and engineering leads. We talk through your current AI-assisted decision workflows, identify where the governance gap actually sits, and tell you honestly whether a ComplyAI assessment is the right next step.

  • Video call on Zoom or Teams, whichever you prefer
  • Your current governance posture mapped at a high level
  • Immediate FCA/SMCR risk points identified
  • Clear, honest recommendation on next steps
Book your free call
TIER 1

ComplyAI Governance Readiness Assessment

A 2-3 week paid engagement scoring your current AI-assisted decisions against the four questions ComplyAI answers. Deliverables include:

  • Governance Gap Register scored across provenance, audit, explainability, and accountability
  • The reconstruction drill: timed evidence trail reconstruction for one historical decision
  • Draft policy configuration ready for deployment
  • Fixed-price roadmap for closing the gaps found

Your CRO, CCO, and CTO leave with a document they can act on.

From £5,000. Fully credited against your Tier 2 deployment if you proceed within 30 days.
TIER 2

ComplyAI Deployment Sprint

Deployment, integration, and pilot of the built, tested, four-layer ComplyAI system, scoped at the assessment stage. This is not a build from scratch, ComplyAI already exists. Deliverables include:

  • One decision traced end to end from day one, not week six
  • Policy configuration workshop and data integration
  • Prediction-first parallel trial rounds on your own decisions
  • Reviewer onboarding and production storage setup
  • Integrity operations wired into your monitoring, including scheduled chain verification and off-host anchoring

No black boxes. No vendor dependency.

Scoped and priced at assessment stage.
TIER 3

Sustained Governance Programme

Once ComplyAI is in production, ongoing operation and assurance. Deliverables include:

  • Monthly governance review sessions
  • Retention, redaction, and incident response support
  • Config and model version fingerprint monitoring
  • Quarterly model risk review against FCA/PRA guidance

Full IP transfer at handover. You retain complete control.

Ongoing retainer. Priced per engagement.

Common questions

Straight answers on how this actually works.

How ComplyAI works

During the Tier 1 assessment, we pick one real historical AI-assisted decision from your records and time how long it takes your team to produce a complete evidence trail for it, which documents were used, what figures were relied on, who reviewed it, and why it was approved. Most teams have never measured this. The result becomes the baseline the rest of the engagement is measured against.
It is marked as one of two honest states, either genuinely unsupported by any document provided, or reliant on a data source outside what we were given access to. Either way, the finding is surfaced in the explainability record and automatically routed for human review, never silently approved.
No. For banks running an existing platform, ComplyAI operates independently, on the same source documents you supply, without requiring any access to your platform's internals, prompts, or proprietary data. It runs alongside your system, not inside it.
For every decision, a tamper-evident record of the source documents referenced, the verification outcome for every figure traced, the plain-language explanation generated, the configuration and model version in force at the time, and the named individual who reviewed and signed off. Any attempt to alter a historical entry breaks the chain and is detectable.
Yes. The system has been validated across four separate recorded live runs against real Claude API behaviour, each with predicted outcomes stated before the run and the actual results compared and documented afterwards, not just a passing automated test suite.
The current build is a tested, audited reference architecture, not yet a production deployment. Before any client goes live, a production database backend, scheduled off-host anchoring for the audit chain, and a reviewer-facing interface are built as part of the Tier 2 deployment sprint, scoped to that specific engagement.
Logging records that something happened. ComplyAI verifies what happened. Source Tracing checks every figure against source documents and rejects fabricated citations, not just logs them. The Immutable Audit Log is hash-chained, so tampering with a historical entry is cryptographically detectable, not just discouraged by access controls. Standard logging cannot make either claim.
A named individual, not a department. The SMCR Accountability Gate requires a specific person to review and sign off before a consequential decision is finalised, and once signed off, that decision cannot be silently overwritten by a second reviewer. This is designed specifically to answer the SMCR accountability question regulators are asking UK banks directly.

Security, architecture and data

No. The system runs on your own Anthropic API account and your own infrastructure, not ours, so ShiftAi never holds your data at all. Under Anthropic's standard commercial terms, API inputs and outputs are not used to train its models. Where your organisation requires a Zero Data Retention agreement with Anthropic directly, we can build to that requirement and confirm it as part of the ComplyAI Governance Readiness Assessment.
We use a strict DevSecAI architecture. The AI operates in a sandboxed environment where read and write permissions are physically separated. Any action that alters a database, sends an email to a client, or approves a credit line requires a deterministic Human-in-the-Loop (HITL) interrupt. The AI can draft the decision, but a human must click approve.
Because we build using abstracted frameworks like the Model Context Protocol (MCP), your system architecture is completely decoupled from the underlying LLM. If a model is deprecated, we update the API pointer, run your automated evaluation suite (LLM-as-a-judge) to ensure output quality remains identical, and push the update seamlessly.
Yes. Our reference architectures are built on the Anthropic API and Model Context Protocol (MCP), documented on our Our Work page. The patterns are stack-agnostic, including MCP adapters for legacy core banking APIs. If your systems expose an API, we can build a governed, auditable agentic layer on top of them.

Engagement and ownership

The ComplyAI Governance Readiness Assessment is a written report, so it does not depend on ongoing availability once delivered. For a ComplyAI Deployment Sprint, all code, architecture decisions, and documentation live in a shared GitHub repository from week one, with your engineering team given read access immediately, not just at handover. Every Friday you receive a written progress update. The project is never dependent on information that exists only in one person's head.
Yes. Every build engagement ends with a complete handover: the GitHub repository transferred to your organisation, production-ready code, Architecture Decision Records for every design choice, an operating runbook, and a knowledge transfer session with your engineering team. You own the code, the architecture, and the IP outright. We do not operate a SaaS model and there is no ongoing licence fee for the system itself.

Start here

One free call to find out
where your governance gap is.

Book a free 45-minute discovery call to discuss whether ComplyAI fits your current AI governance gap.

Book your free call Free. 45 minutes. No obligation. hello@shiftaiconsulting.co.uk