Case Study · Regulated Financial Services

A company-wide AI platform for a regulated wealth and trust firm.

How an SEC-regulated firm puts a secure AI assistant in front of every employee, connected to the systems they already use, with the governance its examiners expect. The client is anonymized; the platform and the results are real.

200+
Employees with access, company-wide
4
Finished file formats: Word, PDF, PowerPoint, Excel
0
Network access from the code sandbox
100%
Of conversations logged for cost, model and timing
The Challenge

Everyone wants AI. Compliance needs control.

Staff at a 200-person wealth management and trust organization want AI help with drafting, analysis and research every day. Consumer chat tools aren’t an option for a firm that handles client financial data under SEC, GLBA and FFIEC expectations.

So the platform has to run inside the firm’s own cloud, respect who can see what, work with real operational data, produce finished work rather than chat transcripts, and leave an audit trail leadership and examiners can stand behind. It does all of that today.

The Architecture

One platform, wired into the firm’s own systems.

Employees
In the browser, with no install
Microsoft Entra ID sign-in
Conditional Access · three roles via security groups
The AI platform
Web portal and API in the firm's own Azure tenant · staging and production
Claude models
Zero data retention · right-sized per request
Live business systems
Service desk · network management · CRM performance · web
Isolated sandbox
Disposable container, no network · Word, PDF, PowerPoint, Excel
Telemetry and reporting
Every turn: who, which model, cost, time · usage and cost dashboards
What We Built

Designed, built and operated end to end.

Secure access, no new passwords

Staff sign in with their existing Microsoft Entra ID accounts under the firm's Conditional Access policies. Security groups map people to three roles, so sensitive data sources and admin reporting appear only for the people entitled to them. Administrative functions require a verified identity token.

Answers grounded in live systems

The assistant can reach the firm's service desk, network management platform and CRM performance warehouse, plus the web for time-sensitive questions. Staff ask in plain language and get answers from current data, with links that go straight to the underlying ticket.

Finished documents in minutes

Ask for a proposal, a policy draft, a board deck or a spreadsheet and the platform builds a real Word, PDF, PowerPoint or Excel file with a live preview in the browser. An automated review pass checks layout and content before anything is delivered.

Safe execution of AI-written code

Files are produced by code the model writes, so that code runs in a disposable container created for each request, on an isolated network with no internet access and no cloud identity. Only the validated file comes back. The design went through a formal security review before launch.

Measured from day one

Every turn is logged with who asked, which model answered, tokens used, cost, time to first word and total duration. Leadership gets usage and cost by person and by model, and the team can spot a slow or failing build before a user reports it.

A release process built for 200 users

Separate staging and production environments, automated tests that must pass before a deploy, and version stamps that confirm the front end and back end match. User feedback flows into the service desk as tickets, and every production release publishes plain-language release notes inside the app.

Governance

Built so compliance could say yes.

The controls come first, not as an afterthought. That’s what keeps the platform running company-wide instead of stalled in review.

A NIST CSF 2.0-aligned IT risk assessment and a formal change control process
A two-lane AI framework: frontier models for most work, self-hosted models reserved for the most sensitive data
Twenty-one catalogued AI use cases, each assigned to a lane before it is built
Role-based access to sensitive data sources and administrative reporting
The platform, its data stores and its logs run in the firm's own Azure tenant
A zero data retention agreement with the model provider: prompts and responses are not kept after each reply
A written security architecture that InfoSec and examiners can review
The Outcome

In production, not stuck in a pilot.

Running company-wide

In production for every employee, not parked as a pilot.

Finished files, not chat transcripts

First drafts of documents, decks and spreadsheets arrive as real files, typically in a few minutes.

Questions answered from live data

Questions about tickets, network health and CRM performance can be answered without anyone pulling a report.

Cost and quality in plain view

Leadership sees exactly what the platform costs and how it performs, by person and by model.

Want something like this for your firm?

Most engagements start with a readiness assessment: which use cases are worth building, what your data allows, and what your compliance team needs to see. Book a free 30-minute call to talk it through.

Start a ConversationSee More Work