BFSI
Share

Code generation got fast. Getting an autonomous workflow into a bank’s production control environment did not. In Banking & Financial Services (BFS), the blocker is rarely the model; it’s trust. A risk officer will not sign off on a system that cannot say why it flagged something, that does its arithmetic inside a language model, or that leaves no audit trail an examiner can open. That is exactly the gap most agentic pilots die in.

Over the last two quarters, we built a portfolio of ten BFS agentic offerings on Alti AIOS™, Altimetrik’s AI Operating System, and deployed them on two stacks: Google Cloud with Gemini and AWS with OpenAI. This piece is the architecture and design principle behind them.

The design principle: agents reason; deterministic services decide

The single most important architectural decision is what the model is not allowed to do. In every offering, the language model reasons, reads, summarizes, and drafts, but it never does the money math or interprets policy. Fees, entitlements, interest, screening thresholds, deadlines, and policy evaluation run as deterministic services outside the model: versioned, owned, and testable. Agents orchestrate and explain; the deterministic core computes and decides; a human disposes; and every step is cited and written to an append-only audit log.

The Rule of Thumb

If a wrong answer costs money or breaks a regulation, it does not belong in the model. Arithmetic can’t hallucinate, so we keep arithmetic and rules deterministic and let agents do the reading, routing, and narrative that models are genuinely good at.

The AIOS reference architecture

AIOS is a layered operating system for enterprise agents with five horizontal layers. A request flows top to bottom: Experiences, Context, Orchestration, Governance, and Substrate. Two called capabilities are drawn as insets so no detail is lost: Tool & Data Integration populates Context, and the Deterministic Core sits at the heart of Orchestration. The Governance layer carries the trust controls: evaluation, observability, security (zero-trust, CMEK / KMS), audit, and versioned policy with a governed agent registry. Human-in-the-loop lives in Experiences; AI economics lives in Substrate.

AIOS™ Five layer reference architecture 1 1

The canonical pattern: an agent mesh over a deterministic core

Across all ten workflows, the shape is the same. A request enters through the experience layer. A central orchestrator composes a mesh of specialist agents over the Agent-to-Agent (A2A) control plane: one agent for a routine corporate action, up to ten for a complex Anti-Money Laundering (AML) case. Specialists call tools and the deterministic core, grounding every claim in a real record from the knowledge layer. Nothing is committed until a human disposes, and the entire trace is written on the audit log.

The Canonical Agent Mesh Pattern

Deep dive: Agentic AML Investigation & Detection

Financial-crime investigation is the canonical case. An analyst spends nearly 40 minutes assembling a case before review can begin; roughly nine in ten alerts are nothing; threshold rules miss the customer who deliberately stays just under them; and risk teams won’t approve detection they can’t explain. The AIOS pattern puts ten agents over a deterministic detection layer. The pattern engine does the arithmetic and reads the whole transaction book while the agents resolve entities, pull ownership and adverse media, assemble cited evidence, and draft a disposition narrative. A quality-control gate routes any unevidenced write-up to a human.

Agentic AML Investigation Flow

Second deep dive: Trade Breaks & Corporate Actions

Settlement operations show the deterministic-core discipline at its sharpest. A trade fails over a fee, or a date, and the proof is a line in a chat; a split or dividend lands as a dense Swift message keyed into every account by hand. The agentic version reads the mess and drafts the fix, but every number is computed by a deterministic calculator, and nothing posts as a silent edit. The agent count fits the job: one agent for a routine corporate action, up to five for a disputed break.

Agentic Trade Breaks Corporate Actions — Flow

The Deterministic-core Pattern, in Code

In code, the split is explicit. The model proposes structured economics, deterministic services validate and compute, a versioned policy gate decides routing, and every output is cited and appended:

Illustrative pseudocode of the AIOS pattern. The same shape underlies all ten offerings

Third deep dive: Fraud & Dispute Resolution

Disputes run against the clock. A cardholder claims fraud or a billing error and the bank is immediately on a regulatory timer. Regulation E gives roughly ten business days to provisionally credit the customer, and every card network sets its own chargeback deadlines on top. Analysts race two clocks at once while the evidence is scattered across the ledger, authentication logs, device signals, and merchant data. Under time pressure, decisions drift, and policy breaches creep in.

The AIOS pattern puts five checkpointed agents over a deterministic core. The agents classify the dispute, assemble cited evidence, and draft a recommendation. The evidence spans transaction, authentication, and device signals, merchant, and prior-dispute history. The deterministic core runs the regulatory clocks and liability rules (Reg E / Reg Z windows, network timers, provisional-credit and liability math), and the tighter of the two clocks sets priority. Durable checkpoints let a case pause for a merchant or network response and resume without losing the clock; a quality gate sends anything unevidenced or policy-exception to a person, who makes the final call.

The same pattern, ten workflows

OfferingDomainWhat it does & signature control
01 AML Investigation
Financial crime

Alert or raw transaction book -> finished, cited case to sign off; signature factory for new patterns (CRO-approved).
02 Trade Breaks & Corporate Actions
Trade operations

Failed trade or dense Swift message -> a ledger update a person can stand behind; entitlements calculated, cancel-and-replace (42->3 min/break).
03 Fraud & Dispute Resolution
Fraud & disputes

Five checkpointed agents assemble evidence, apply policy, produce a review-ready recommendation (85% agreement target).
04 Customer & Merchant Onboarding
Know Your Customer (KYC)/ Know Your Business (KYB)

Governed onboarding with maker + checker sign-off; versioned policy, immutable log, governed agent registry.
05 Intelligent Advisor Platform
Wealth

Household planning questions -> advisor-approved recommendations; deterministic router picks the specialist.
06 Executive Deck Review
Capital formation

Six specialists review a deck in parallel -> a cited readiness decision with a graph evidence store.
07 Payment Completion
Payments

Completes a purchase inside the conversation under an AP2 mandate and a human threshold.
08 Booking Waitlist & Re-engagement
Property/booking

Turns a cancellation into a booking for the buyer who was waiting, completed under mandate.
09 Individual Investor Intelligence
Investor intel

Explainable next-best action with forecast, evidence and advisor approval.
10 Institutional Intelligence
Institutional

Ranks institutions by readiness and service risk, evidence attached.

The trust fabric

What makes these deployable in a bank is not the agents but the controls wrapped around them. Four govern every offering:

  • Maker & checker: Two authenticated humans on sensitive cases; neither step closes by itself.
  • Versioned policy rules: Policy runs as deterministic code with a version, an owner, and a result ledger; only the Chief Risk Officer (CRO) switches a rule on.
  • Immutable audit log: Every action, policy version, tool call, retrieval lineage, and human decision is append-only and point-in-time reproducible.
  • Governed agent registry: Only approved agents are reachable; every task routed and traced through the A2A gateway, a zero-trust boundary for non-human actors.
Why This Clears the Bar?

Evidence citation means every number points to the message or document it came from, including the records that clear a subject. That is the difference between a demo and something a second line of defense and an examiner will accept.

An Audit-trace Entry: What One Appended Record Looks Like

Every step emits one immutable, hash-chained record that ties the action to its policy version, its evidence, the human who signed it, and the cost:

APPENDED RECORD LOOKS LIKE

Write once, deploy on your stack

The AIOS capability layers are the stable contract; the cloud and model services underneath are swappable. The same ten offerings run on Google Cloud with Gemini and on AWS with OpenAI today, with Anthropic supported. So, a bank deploys on the platform it has already certified, without rearchitecting.

One ArchitecturePortable Across Model Platforms

From pilot to production

The reason these ship is that AIOS treats production as the design target, not a later phase. Context makes bank data agent-ready and case-scoped. Orchestration gives durable, checkpointed, resumable workflows. Governance, including maker/checker, versioned rules, immutable audit, and a zero-trust agent registry, is what a risk officer signs. Economics keeps the unit economics honest at volume. And the deterministic core keeps the money math and the regulation out of the model entirely.

In regulated banking, the winning architecture isn’t the smartest model. It’s the one that lets a human stay accountable, an auditor reconstruct every decision, and the arithmetic stay provably correct. Agents make the work faster; the operating system makes it trustworthy enough to deploy.

Author Bio

Author Bio
Niraj Nagrani
Niraj Nagrani
Chief Data & AI Officer, Altimetrik
Niraj Nagrani is a C-suite transformation leader with a track record of scaling AI-native platforms, growing ARR (multi-$B), and leading engineering, data science, and product organizations across Altimetrik, Google, Wayfair, American Express, Microsoft, SnapLogic (A16Z), and iManage (IPO). He specializes in Enterprise AI and Cloud transformations, agentic AI, knowledge graphs, cloud-native data platforms, and turning enterprise data into governed, production-scale intelligence.
More Industry Insights

Harnessing Altimetrik’s Expertise

Blog

From Evidence to Governed Execution: Unlocking Life Sciences Value with Snowflake and ALTi AIOS™ 

Here is something most life sciences organizations already know but rarely say out loud: Snowflake did its job. The data lake is full. Batch records, deviation logs, CAPA histories, COA repositories, clinical trial evidence, it is all there, unified, queryable, and beautifully governed. And yet the quality director is still chasing approvals through email threads. The compliance team is still manually cross-referencing batch records against specifications before a release decision. The CAPA cycle is still measured in weeks, not hours.

Data centralization was never the finish line. It was the foundation. The question now is whether that foundation does work or just sits there.

Read More

Contact Us

We'd love to hear from you.
Contact Us