Skip to content
Sectors
Sectors · Finance

AI in banking and insurance, DORA-compliant and audit-defensible.

AI consulting and agent deployment for banks, insurers and fintechs. Sovereign architecture, encryption, full audit trail, MCP credential isolation, prompt injection defence. Compatible with DORA, PCI DSS, ACPR, EBA and internal cybersecurity requirements.

Executive desk with amber financial terminal, brass paperweight and leather-bound reports on black marble
In 3 sentences

Colombani.ai supports banks, insurers and fintechs deploying AI agents compliant with DORA (in force since January 2025), PCI DSS and ACPR / EBA requirements. Each deployment includes sovereign or contracted EU cloud architecture, encryption at rest and in transit, complete audit trail of agent decisions, strict credential isolation via MCP, defences against user prompt injection, and documentation expected by supervisors.

Use cases

Automated KYC and AML

Structured extraction of ID documents, document consistency checks, atypical transaction alerts. Auditable trail for Tracfin and ACPR. Final decision retained by the analyst.

ACPR / EBA / AMF compliance monitoring

Weekly synthesis of ACPR, EBA, AMF, DGCCRF publications relevant to your activities. Filtered by risk type (credit, market, operational). Sourced from official texts.

Financing contract review

Rapid facility agreement analysis, covenant extraction, atypical clause alerts. Used by financing teams pre-signing.

B2B client advisor assistant

Meeting prep support, client position summary, monitoring of company life events. Without exposing card data or PSD2-covered information.

Ethics and regulatory framework

DORA — Digital Operational Resilience Act

In force since January 2025. Obligations: ICT risk management (including AI agents), resilience testing, major incident notification, governance and model risk register. Every Colombani.ai deployment includes documentation expected by the supervisor.

PCI DSS and payment data isolation

No card data must be exposed to an LLM without prior tokenization. Solutions: agent restricted via MCP to systems outside the PCI perimeter, or pre-tokenization via a dedicated service before any AI processing.

ACPR / EBA / AMF — model governance

Supervisors require documentation of models in use, continuous performance evaluation, and demonstration of effective human oversight on material decisions. Colombani.ai produces this documentation alongside the deployment.

What we don't do

  • Personalized financial advice: reserved for regulated advisors.
  • Algorithmic trading: other expertise and specific AMF framework, not covered.
  • Automated credit scoring without human intervention: prohibited by GDPR art. 22.
  • DORA certification of a third-party ICT provider: certifications are issued by accredited bodies, not us.

Frequently asked questions

How do you ensure an AI agent does not leak card data? +

Two layers. First, the agent never has direct access to card data: MCP tools are scoped to systems outside the PCI perimeter or pass through a tokenization service. Second, a post-tool hook validates every agent output against card patterns before emission (DLP). Everything is logged auditably.

How do you meet DORA resilience testing for AI agents? +

Each plugin ships with a reproducible test suite covering: degradation scenarios (LLM unavailable, hallucinated response, tool timeout), load tests, adversarial injection tests. Results are documented and versioned for presentation to supervisors in case of inspection.

Can we use cloud Claude or must we stay on-prem? +

Depends on data classification. Public or already-anonymized data: cloud Claude (Anthropic or via EU Bedrock) acceptable with subprocessor contract. Sensitive or bank-classified data: local Mistral or Claude via a dedicated EU instance. Choice made at scoping.

Discuss your project

First call is free. Straight answer on what is feasible and what is not within your ethics framework.