AI in Financial Services
Fraud and AML analytics, credit decisioning on alternative data, IFRS 9 ECL with machine-learning overlays, agentic operations, and supervisory technology — engineered for institutions whose models must answer to risk committees, auditors, and regulators.
In finance, a model that cannot explain itself is not an asset. It is an unbooked liability.
- Fraud & AML Analytics
- Alternative-Data Credit Scoring
- IFRS 9 ECL Modelling
- PD / LGD / EAD
- Model Risk Management
- Explainable AI (SHAP)
- Agentic Operations
- Suptech & Regtech
- Open-Weight LLMs
- Mobile-Money Data
- Dynamics 365 Finance
02 — The Reality
The Hard Part Is No Longer the Model
AI in African banking has crossed the line from pilot to core infrastructure. The Central Bank of Kenya’s own survey work shows the pattern clearly: a majority of institutions already run AI in credit risk assessment and fraud detection, and most of the rest plan to. But the same surveys expose the gap that decides who gets hurt — only a minority of adopters have a formal data strategy or an AI policy behind the models they have put into production.
That gap is where we work. A fraud model is a few weeks of data science and years of pipeline, monitoring, threshold governance, and false-positive economics. An ECL model is a few notebooks of PD/LGD/EAD estimation and a permanent argument with auditors about staging logic and overlays. An agent that drafts customer responses is a demo in a day and a supervised, logged, permission-bounded system in a quarter. The differentiating skill in 2026 is not training models — it is building the surrounding system that lets a regulated institution defend them.
We come at this from an unusual angle: two decades inside the infrastructure of East and Central African financial institutions — connectivity, systems, and uptime engineering for banks and central banks — now combined with current, formally trained data-science and LLM practice. We know what core-banking integration actually looks like at 2 a.m., and we build AI systems that respect it.
03 — Three Lenses
Three Institutions, Three Different AI Problems
A commercial bank, a development finance institution, and a central bank all say "AI" — and mean three different engineering disciplines
Commercial Banking
High demandWhere AI is now table stakes — and where governance debt is accumulating fastest
What We Build
- Fraud and AML detection — anomaly models over transaction streams, alert triage that respects investigator capacity, and false-positive economics treated as a first-class metric
- Credit decisioning on alternative data — mobile-money, telco, and behavioural signals, with consent, data-protection, and adverse-action explainability designed in from day one
- IFRS 9 ECL with ML overlays — PD/LGD/EAD estimation, staging logic, forward-looking macroeconomic scenarios, and management overlays documented tightly enough to survive auditor and supervisor challenge
- Agentic customer and back-office operations — LLM agents for service, reconciliation, and reporting workflows, permission-bounded, logged, and never authorised to move money alone
- Core-banking integration realities — batch windows, flat-file interfaces, Dynamics 365 Finance and payment-rail integration, and the data-quality remediation nobody budgets for
- Model monitoring in production — drift detection, challenger models, and retraining governance with an audit trail
Why It Matters
Fraud and credit models now sit on the critical path of revenue and provisioning. The institutions that win are not the ones with the cleverest models — they are the ones whose models a risk committee can interrogate and an auditor can trace.
Developmental Finance
Where the data is thinnest, the consumer-protection stakes are highest, and the field realities are least forgiving
What We Build
- Financial-inclusion credit scoring — models for thin-file and no-file borrowers built on alternative data, with fairness testing and the humility to say where the data cannot support a decision
- Mobile-money data pipelines — M-Pesa-class transaction data put to work under explicit consent and Kenya Data Protection Act discipline, not scraped and hoped for
- DFI portfolio monitoring — ML-assisted early-warning signals across lending portfolios, aggregating partner-institution reporting that arrives late, inconsistent, and in spreadsheets
- Impact measurement that survives scrutiny — indicator pipelines and analytics that distinguish measured outcomes from narrative, for boards and funders who increasingly know the difference
- Low-connectivity field design — scoring and data-capture systems that tolerate intermittent links and offline operation, informed by decades of building networks in exactly those environments
- Capacity building — data and AI literacy for partner institutions, so models are operated, not merely delivered
Why It Matters
Inclusion lending fails in two directions: models that exclude the creditworthy poor, and models that lend recklessly to them. Disciplined data consent, fairness testing, and honest model limits are what separate developmental AI from predatory automation with better branding.
Central Banking
Where the governance bar is highest — and where sovereignty questions decide the architecture
What We Build
- Suptech — AI-assisted analysis of prudential returns and supervisory reporting, flagging anomalies for human examiners rather than replacing their judgment
- Payment-system oversight analytics — pattern and concentration analysis over RTGS and fast-payment-system data, at national-rail transaction volumes
- Research and nowcasting — ML models over high-frequency payment and mobile-money data as leading indicators, alongside — never instead of — established statistical practice
- CBDC data architecture questions — what a retail CBDC ledger reveals, who may analyse it, and how privacy, AML, and monetary analysis are separated by design
- Regulatory sandbox and licensing analytics — structured evaluation of AI-using licensees, informed by having built the systems being evaluated
- Sovereign deployment — open-weight models run on infrastructure the institution controls, because supervisory data and deliberations should not transit a foreign API
Why It Matters
A central bank cannot outsource its judgment or leak its deliberations. Explainability, auditability, and data sovereignty are not features here — they are constitutional requirements, and they usually point to private, open-weight deployment rather than public AI services.
An auditor cannot approve what a model cannot explain — and a regulator will not wait while you find out.
05 — Model Risk
Model Risk Management as an Engineering Discipline
The frameworks are converging — SR 11-7-class supervisory guidance, the EU AI Act, CBK expectations — and they all reward the same thing: models built like systems, not experiments
Model Governance & Documentation
- Model inventory, tiering, and ownership — knowing what is in production before the supervisor asks
- Development documentation to SR 11-7-class standards: assumptions, limitations, and intended use in writing
- Independent validation — conceptual soundness, outcomes analysis, and challenger benchmarking
- Change management with approvals and rollback, so a retrained model is a governed event, not a quiet deploy
Explainability for Regulators
- Feature-attribution methods (SHAP-class) wired into decisioning, not bolted on for the audit
- Adverse-action reasoning — every declined borrower gets an explanation the law and the customer can accept
- Inherently interpretable models where the use case demands it — accepting accuracy trade-offs honestly
- EU AI Act readiness — credit scoring of natural persons is high-risk under Annex III, with obligations applying from August 2026; institutions serving European counterparties inherit the bar
Data Pipelines That Survive Audit
- Lineage from source system to model input — every feature traceable to its origin and transformation
- Point-in-time correctness — training data that reflects what was knowable then, not what is known now
- Reconciliation to the general ledger for ECL and finance-adjacent models — Dynamics 365-class ERP discipline applied to model data
- Retention, access control, and consent records treated as pipeline outputs, not afterthoughts
Where AI Must Not Decide Alone
- Human-in-the-loop by design for credit declines, account closures, SAR filings, and any action a customer cannot easily reverse
- Agent permission boundaries — LLM agents draft, summarise, and prepare; humans authorise anything that moves money or files with a regulator
- Kill switches and fallback procedures — the institution must be able to operate with the model switched off
- Overlay governance for ECL — management judgment documented with observable triggers and expected reversal conditions, because supervisors now read overlays first
A model risk framework is not paperwork around a model. It is the engineering that makes the model deployable at all.
06 — Regulatory Landscape
The 2026 Regulatory Reality
Four currents every financial-services AI programme in this region now swims in
The CBK Governance Gap
The Central Bank of Kenya’s AI survey work found adoption running well ahead of governance — most institutions using AI in credit and fraud, far fewer with formal data strategies or AI policies. Supervisory attention follows gaps like that. Closing it before it is closed for you is cheaper.
IFRS 9 Under the Microscope
Supervisors and standard-setters have sharpened their language on ECL: overlays with too much room for self-serving judgment, provisions that flatter the balance sheet, and ML components that validation teams cannot interrogate. ML in ECL is welcome — but only inside a governance envelope that makes its behaviour reviewable.
The EU AI Act Shadow
Credit scoring of natural persons is a high-risk AI system under the EU AI Act, with obligations in force from August 2026 — conformity assessment, technical documentation, logged human oversight, post-market monitoring. African institutions with European parents, partners, or funding lines will find the bar applied to them contractually even where it does not apply legally.
Supervisors Adopting AI Themselves
Central banks are deploying suptech — AI-assisted review of returns, anomaly flagging, adaptive stress testing — which means the institution’s reporting is increasingly read by machines with tireless attention to inconsistency. The honest response is to build reporting pipelines at least as rigorous as the systems reading them.
07 — Track Record
Where This Experience Comes From
We have served financial institutions for two decades — from the infrastructure layer up. That history is why our AI work starts from how banks actually run, not from a conference demo.
- Migrated all major Kenyan banks from satellite to fibre connectivity during the KDN years — the network layer every core-banking and payments flow in the country came to depend on
- Central-bank environment experience: Central Bank of Burundi connectivity via the CBINET project
- Cross-border banking operations in hard environments — Stanbic and KCB connectivity in South Sudan, where uptime engineering is not optional
- FinTech competency spanning AI in financial systems and IFRS 9 ECL modelling — PD/LGD/EAD estimation, staging logic, and forward-looking overlays
- Microsoft Dynamics 365 Enterprise: Finance — chart-of-accounts design, consolidation, and integration with core banking and payment rails
- M-Pesa and mobile-money integration capability — the transaction rails that carry most of Kenyan financial life
- Current, formal data-science and ML training — ALX (2025–2026) and IBM (2025) — covering Python, ML pipelines, and applied model development
- LLM, NLP, and agentic-systems practice, including open-weight model deployment for institutions that cannot send data to public APIs
We will not invent case studies for this page. The infrastructure record is verifiable; the AI practice is current; the combination is the point.
The regulatory ground shifted under financial AI this year: the EU AI Act’s high-risk obligations for credit scoring bite from August 2026, US model-risk guidance was rewritten with generative and agentic AI explicitly in view, and the IMF put supervisors on notice about self-serving judgment in IFRS 9 overlays — while the CBK’s own survey shows African adoption running well ahead of governance. Our read: fraud and alternative-data scoring are now table stakes, agentic operations are real but must stay on a permission leash, and the scarce capability in 2026 is not modelling talent but audit-grade data lineage, explainability wired into decisioning, and — for central banks especially — sovereign open-weight deployment.
Put Your Financial AI on Defensible Foundations
Start with a focused review of your models, data pipelines, and governance posture — before your auditor or supervisor starts it for you.