Skip to content
Regulayer™Human Control for AI
Book a live demo

Financial services · banks, payments, asset and wealth managers, lenders, fintechs

An agent drifts off procedure. The payment stops before the money moves.

An AI agent that can move money, decide credit or send an instruction needs a named person’s current authority at the moment it acts, and a record an examiner can check. Regulayer™ checks every action before it takes effect, stops the one that drifts, and seals a record of every decision.

A corridor of server racks in a data centre

Where it is put to work

Where an AI action in finance carries consequences.

Money movement and paymentsPayments inside the limit a person set.A transfer to a new beneficiary, over the limit, or after the authority is withdrawn, stops before the money moves.
Credit and lendingEvery automated credit action, on the record.Approvals, declines and limit changes, each checked against a named person’s current authority and sealed with the outcome.
Trading and order instructionsOrders inside the mandate a person set.An instruction outside the mandate goes back to the agent for correction, holds, or stops before it is sent.
Customer communications and disclosuresWhat the agent sent, and under whose authority.Notices, disclosures and replies to customers, each recorded with the named person accountable for it.
Systems of recordWrites to the ledger, the core and the customer file.A change to a record of account runs under current authority, and the record shows who held it.
KYC and AML case actionsCase decisions with a name on them.Closing an alert, clearing a match or escalating a case, each checked against the authority of the named analyst or officer, and sealed.

A sample run · a payments queue

Drift, caught at the moment of effect.

  1. 1A treasurer sets the authority once. Payments to approved beneficiaries, up to a limit, for this quarter.
  2. 2The agent works the queue. Each payment is checked before it takes effect. No one has to approve each step.
  3. 3The agent drifts off procedure. It proposes a payment to a beneficiary added an hour earlier, over the limit. Regulayer™ sends it back for correction, with the reason.
  4. 4The correction fails, so the payment holds. The money stays where it is.
  5. 5The treasurer withdraws the authority. The next payment the agent proposes stops. Every decision, allowed, held or stopped, is sealed as it happens.

The model may agree. The action still requires current human authority.

Drift, a persuasive prompt, a hidden instruction or another agent: Regulayer™ does not need to know why. It checks the authority.

At the moment of effect

Four answers, one record.

  • Allow. The action is inside a named person’s current authority, and it runs.
  • Send back for correction. Outside the authority, the action returns to the agent with the reason.
  • Hold. The action waits for the named person.
  • Stop. The authority is withdrawn or the action is out of bounds, and it does not take effect.
  • Fail closed. If the check cannot complete, the action does not run.
2 ms medianDecision time for each action.
3 ms p95Decision time for each action.

What each rule asks, and the record that answers it

From the rule to the record.

The ruleWhat it asksWhat Regulayer™ supplies
US banking
Federal Reserve SR 26-2 and OCC Bulletin 2026-13Model risk management, 17 April 2026, replacing SR 11-7 · OCC textSound practice for model development and use, validation and monitoring, and clear roles and controls. The agencies state the guidance sets no enforceable standards, that non-compliance with it does not result in supervisory criticism, and that generative and agentic AI models are outside its scope. They expect it to be most relevant to banking organisations with over $30 billion in total assets. On 17 April 2026 they announced a planned request for information on AI, agentic AI included.For the agents outside its scope, evidence your own risk practices can draw on: each action, the named person whose authority covered it, and the outcome, in a signed record.
NYDFS 23 NYCRR 500.6 and 500.14Section 500.6 textSystems that can reconstruct material financial transactions, and audit trails to detect and respond to cybersecurity events, with the records kept for not fewer than five years. Controls that monitor the activity of authorized users and detect tampering.Each AI action that moves money or changes a record, with the authority it ran under and the outcome, kept on your own infrastructure.
GLBA Safeguards Rule, 16 CFR 314.4(c)(8)Financial institutions under FTC jurisdiction · eCFR textMonitor and log the activity of authorized users, and detect unauthorized access to, use of, or tampering with customer information.Every action an AI agent takes on customer information, recorded under the named person whose authority it used. The customer information stays in your environment.
US securities
FINRA Rule 3110 and Regulatory Notice 24-09Rule 3110 · Notice 24-09A system to supervise the activities of each associated person toward compliance with securities laws and FINRA rules, with reviews evidenced in writing. Notice 24-09, June 2024: FINRA’s rules are technology neutral and apply to generative AI as they apply to any other tool.The named person whose authority covered each AI action, checked before it took effect, and recorded with the outcome.
SEC Rule 17a-4(f) and FINRA Rule 4511Rule 17a-4 · Rule 4511Electronic records kept with a complete time-stamped audit trail of every creation, change and deletion, and the person who made it, or in a non-rewriteable, non-erasable format. Communications kept at least three years. FINRA records kept six years where no other period applies.A time-stamped, signed record of each AI action, made as it happens. Any change after sealing fails verification.
US consumer credit
ECOA and Regulation B, 12 CFR 1002.9eCFR textAn adverse action notice whose reasons are specific and give the principal reasons. A reason that the applicant missed a qualifying score is insufficient.For each automated credit action, what was proposed, the named person whose authority covered it, and the outcome, sealed when it happened.
FCRA, 15 U.S.C. 1681m(a)Statute textA user taking adverse action based in whole or in part on a consumer report gives the consumer notice, the credit score used, the reporting agency’s details and the consumer’s rights.A record of each notice an agent sent, under whose authority, and when.
European Union
DORA, Regulation (EU) 2022/2554, Articles 9(4)(c) and 17In application since 17 January 2025 · EUR-Lex textAccess to information and ICT assets limited to legitimate and approved functions, with controls over access rights. Every ICT-related incident recorded, with root causes identified and addressed.Each AI action checked against the authority approved for it before it runs, and every refusal recorded with the reason.
EU AI Act, Annex III point 5(b) and Article 14Applies from 2 December 2027 under Regulation (EU) 2026/1744 · EUR-Lex textAI used to evaluate the creditworthiness of natural persons or set their credit score is high-risk, fraud detection excepted. The people assigned to oversight can override or reverse the output, and interrupt the system so it comes to a halt in a safe state.A named person’s authority, checked before each action, which that person can withdraw. Withdraw it, and the next action stops.
EU AI Act, Articles 12 and 26(6)For Annex III systems, applies from 2 December 2027 · Regulation (EU) 2026/1744Automatic recording of events over the system’s lifetime. Deployers keep the logs at least six months, and financial institutions keep them with the documentation their financial services law requires.An automatic, signed record of every decision, allowed or refused, kept on your own infrastructure.
United Kingdom
FCA SYSC 9.1.1 R and 9.1.2-A RFCA HandbookOrderly records of business and internal organisation, sufficient for the FCA to monitor the firm’s compliance. For common platform firms, records that cannot be manipulated or altered, with any correction and the earlier content easy to ascertain.A tamper-evident record: any change after sealing fails verification, and anyone can check it offline.
PRA SS1/23, model risk management principles for banksBank of England textFor UK banks, building societies and PRA-designated investment firms with internal model approval: five principles for models that inform business decisions, regardless of technology, AI included. Model identification, oversight, development and use, independent validation, and risk mitigants.Where a model’s output drives an action, a record of the action and the named person whose authority covered it.

Regulayer™ supplies the evidence. Your examiner, auditor or court makes the determination.

Inside your environment

Your data stays where it is.

  • Runs on your infrastructure. On premises, on your own servers, or in a sandbox for a pilot.
  • Your data does not leave it. Customer, account and transaction data stay in your environment.
  • No Regulayer™ cloud service is required.
  • Model-agnostic. Change the model, and the check stays where it is.
  • Verify offline. Anyone holding a record can check it, with no account and no call to Regulayer™.

Read further

Related on this site.

See it

Watch an agent drift, and watch the payment stop.

Regulayer™ supplies the evidence. Your examiner, auditor or court makes the determination. Patent pending.