AI agents in Swiss finance: explain and prepare, never just act

Financial agents need strong walls between explaining an answer, preparing an action and executing it.

A concrete example: policy answers

A service agent answers a customer question using only the institution’s approved, versioned policy library. The response links to its source and says so when the available material cannot support an answer. Outdated and conflicting policies, missing language variants and a hidden instruction inside a retrieved file all belong in the test set.

The content owner is responsible for approved sources and retirement dates. The agent owner is responsible for retrieval settings and refusal behaviour. Compliance and legal teams decide whether the workflow needs extra review — the technical result never makes that decision for them.

Keep every customer’s data apart

We test role and customer-account boundaries across profiles, transactions, internal research and support records. Retrieval must filter before context reaches the AI. Hiding names in the final answer is too late if another customer’s data already entered the prompt or the record.

Prepare a payment — without executing it

In the draft payment workflow, the agent may collect invoice details and create a draft in a restricted system. It cannot release funds. A reviewer sees payer, payee, account, amount, currency, due date and source document — then approves those exact details through the payment service.

Verification submits the draft without approval, changes the amount after approval, reuses an old approval and attempts a second customer’s payment. All four must fail. The evidence links agent version, authorization decision, reviewed details, reviewer identity and downstream result — without exposing unnecessary customer data.

Your procurement and operations pack

Ask for the versioned workflow and policy sources, customer-separation design, tool scopes, approval and reuse tests, tamper-showing records, incident responsibilities, regression history and remaining-risk statement. Platform certificates can never replace evidence from your configured financial workflow.

The business owner owns permitted use and fallback, security owns authorization criteria, data protection reviews personal-data flows, operations owns monitoring and containment, and the accountable financial function keeps decision responsibility. Important connector, permission or policy changes trigger review before the quarterly rhythm.

Common questions

Can the assessed agent execute a payment?

No. The draft workflow allows preparation only. Execution needs a separate human approval, locked to the exact payment details and enforced by the payment service.

How is customer isolation tested?

Synthetic identities from different customer and account contexts probe retrieval, prompt context, tool authorization, caches and records for cross-boundary exposure.

Does a positive technical assessment prove regulatory compliance?

No. It documents the tested controls and their limits. Your institution still makes the legal, compliance and business decision for the specific use.