AI in banking and insurance, DORA-compliant and audit-defensible.
AI consulting and agent deployment for banks, insurers and fintechs. Sovereign architecture, encryption, full audit trail, MCP credential isolation, prompt injection defence. Compatible with DORA, PCI DSS, ACPR, EBA and internal cybersecurity requirements.
Colombani.ai supports banks, insurers and fintechs deploying AI agents compliant with DORA (in force since January 2025), PCI DSS and ACPR / EBA requirements. Each deployment includes sovereign or contracted EU cloud architecture, encryption at rest and in transit, complete audit trail of agent decisions, strict credential isolation via MCP, defences against user prompt injection, and documentation expected by supervisors.
Use cases
Automated KYC and AML
Structured extraction of ID documents, document consistency checks, atypical transaction alerts. Auditable trail for Tracfin and ACPR. Final decision retained by the analyst.
ACPR / EBA / AMF compliance monitoring
Weekly synthesis of ACPR, EBA, AMF, DGCCRF publications relevant to your activities. Filtered by risk type (credit, market, operational). Sourced from official texts.
Financing contract review
Rapid facility agreement analysis, covenant extraction, atypical clause alerts. Used by financing teams pre-signing.
B2B client advisor assistant
Meeting prep support, client position summary, monitoring of company life events. Without exposing card data or PSD2-covered information.
Ethics and regulatory framework
DORA — Digital Operational Resilience Act
In force since January 2025. Obligations: ICT risk management (including AI agents), resilience testing, major incident notification, governance and model risk register. Every Colombani.ai deployment includes documentation expected by the supervisor.
PCI DSS and payment data isolation
No card data must be exposed to an LLM without prior tokenization. Solutions: agent restricted via MCP to systems outside the PCI perimeter, or pre-tokenization via a dedicated service before any AI processing.
ACPR / EBA / AMF — model governance
Supervisors require documentation of models in use, continuous performance evaluation, and demonstration of effective human oversight on material decisions. Colombani.ai produces this documentation alongside the deployment.
What we don't do
- Personalized financial advice: reserved for regulated advisors.
- Algorithmic trading: other expertise and specific AMF framework, not covered.
- Automated credit scoring without human intervention: prohibited by GDPR art. 22.
- DORA certification of a third-party ICT provider: certifications are issued by accredited bodies, not us.
How we work with you
Consulting: sectoral AI compliance
AI compliance audit against DORA, PCI DSS, ACPR, EBA, AMF, GDPR art. 22.
Solutions: AI agents & security
Banking and insurance AI agent plugins, AI-assisted security audits.
Training: AI for regulated teams
Qualiopi programs, OPCO Atlas eligible for banking and insurance teams.
Frequently asked questions
How do you ensure an AI agent does not leak card data? +
Two layers. First, the agent never has direct access to card data: MCP tools are scoped to systems outside the PCI perimeter or pass through a tokenization service. Second, a post-tool hook validates every agent output against card patterns before emission (DLP). Everything is logged auditably.
How do you meet DORA resilience testing for AI agents? +
Each plugin ships with a reproducible test suite covering: degradation scenarios (LLM unavailable, hallucinated response, tool timeout), load tests, adversarial injection tests. Results are documented and versioned for presentation to supervisors in case of inspection.
Can we use cloud Claude or must we stay on-prem? +
Depends on data classification. Public or already-anonymized data: cloud Claude (Anthropic or via EU Bedrock) acceptable with subprocessor contract. Sensitive or bank-classified data: local Mistral or Claude via a dedicated EU instance. Choice made at scoping.
Discuss your project
First call is free. Straight answer on what is feasible and what is not within your ethics framework.