Financial Services & Fintech

Responsible AI adoption for financial services and fintech

Build institutional trust in AI without slowing down the business.

Responsible AI adoption for financial services and fintech

Financial institutions and the fintechs building for them are using AI across customer service, operations, fraud detection, underwriting, research, employee productivity, software development, and other consequential workflows.

The challenge is no longer deciding whether AI will be used. It's determining which uses are appropriate, what oversight they require, and how you can demonstrate to your board, your clients, your partners, or your own leadership that important decisions were deliberate rather than improvised.

I help financial-services and fintech organizations align AI use with real workflows, stakeholder needs, business goals, and proportionate safeguards.

Discuss your AI adoption needs →

When existing risk processes don't fully account for AI

Larger institutions already have substantial risk, compliance, model-management, privacy, security, vendor, and audit capabilities. Smaller and growth-stage companies are often building these capabilities for the first time, under real time pressure. Either way, generative and agentic AI don't always fit neatly inside the structures you already have.

You may be seeing signs such as:

  • Employees using generative AI faster than policies and approved-tool processes can adapt
  • AI capabilities appearing inside vendor products without a consistent review path
  • Staff applying different definitions and assumptions to how they use AI
  • Low-risk productivity uses becoming trapped in the same process as consequential customer-facing applications
  • Unclear human-approval requirements for systems that recommend, initiate, or execute actions
  • Difficulty documenting why an AI use was approved, what safeguards apply, and when it must be reconsidered
  • If you're a fintech selling into banks or insurers: AI governance questions showing up in a vendor security review or partner diligence process that no one on your team can answer with full confidence

The answer isn't to force every AI use through the most rigorous review. It's to create enough shared structure to efficiently distinguish among uses, apply proportionate oversight, and make accountability clear at whatever scale your organization operates.

Regulation is being rewritten in real time — and it still won't answer your hardest questions

In April 2026, federal banking regulators issued SR 26-2, revised guidance on model risk management that supersedes a framework that had stood for fifteen years. It's aimed at large banking organizations, so it may not apply directly to your institution. But it's worth paying attention to for what it reveals about the broader pattern every organization in this space is living through right now: even the most established, heavily precedented guidance in financial services is being actively rewritten. The new version explicitly places generative and agentic AI outside its scope, because regulators consider the technology too novel and fast-moving to govern the same way as traditional models.

That exclusion doesn't make these systems risk-free or governance-free. It means every institution, regardless of size, has to decide for itself how its broader risk-management practices apply to AI because no one is going to hand you a settled rulebook. This raises practical questions:

  • Where should generative and agentic AI enter your existing risk structure?
  • Which uses require close review and documentation?
  • How should controls differ between an assistant that drafts content and an agent that can take actions?
  • What human approvals, activity records, testing, monitoring, and escalation paths are appropriate for your scale?
  • How should third-party AI capabilities be inventoried and challenged when vendors provide limited visibility?
  • What evidence will leadership need to explain that oversight is operating in practice?

If you're a fintech selling into larger regulated institutions, being able to answer these questions with confidence is increasingly part of how you pass a partner's vendor risk review and close the deal.

I don't provide regulatory interpretations or model validation. I help you investigate these operating questions and translate responsible AI expectations into usable processes, responsibilities, safeguards, and documentation.

Methodology & Capabilities

How I can help

I use a method called REAL (Rooted, Embedded, Actionable, and Legible) to systematically guide recommendations that encompass a robust view of critical decision points.

Step 1

Establish the ground truth

The REAL Diagnostic identifies how AI is actually entering your organization, where uncertainty or friction is concentrated, and what to address first.

Depending on scope, this may include:

  • Stakeholder interviews with people directly impacted by your AI strategy
  • An inventory of employee, operational, vendor, and product AI uses
  • Preliminary risk tiers based on context and potential consequences
  • Ownership and review-path recommendations
  • Risks mapped to relevant NIST AI RMF considerations
  • A prioritized action plan and executive working session
Step 2

Build a workable responsible AI approach

The REAL Blueprint translates sufficiently clear findings and priorities into an operating structure that can be tested against real use cases.

This can include:

  • Principles translated into practical boundaries and safeguards
  • A process for proposing, reviewing, approving, documenting, and reconsidering AI uses
  • Risk-based routing and escalation criteria
  • Defined roles for leadership and participating functions
  • A governance working-group launch kit
  • Leadership reporting and decision-tracking tools
  • A NIST-aligned profile and pilot plan
Step 3

Prepare leaders and teams to make better decisions

A customized Get REAL Workshop helps executives, committees, risk partners, product teams, or employees build shared language and practice applying responsible AI expectations to realistic financial-services scenarios.

See full services overview →

Grounded in financial-services realities

I combine two decades of human-centered research and strategy with direct, ongoing work inside financial services.

I’ve served Fortune 500 banks and issuers in reimagining their digital checking and banking service suites through in-depth market research and product strategy engagements. I currently serve as the Responsible AI Program Director for The American College's Cary M. Maguire Center for Ethics in Financial Services. Here, I work with global insurers and wealth management firms to help them build their RAI decision-making capacity.

As always, my goal is never to create cumbersome processes that slow you down or static documentation that sits unused. I design nimble responsible AI practices that people can authentically operate, and leadership can readily explain.

See where your AI approach may need attention

The REAL Readiness Snapshot offers a quick, directional view of whether your current approach is rooted in evidence, embedded in real work, actionable when decisions arise, and legible to the people who use and oversee it.

You’ll see an instant picture of where you stand, and can request a full report and field guide.

Take the free REAL Readiness Snapshot →

GroundSpring provides responsible AI research, strategy, and governance design. It does not provide legal advice, regulatory conclusions, model validation, compliance certification, or technical implementation.