Nestack Agent Care
Industries / Banking / Programme agent

Banking AI agent · Programme governance

AML Programme-Governance & Independent-Testing AI Agent

Assemble the programme evidence a board approves and a named independent tester opines on, reconcile the risk assessment to the controls, and track each order deliverable against the day count it carries.

4–6 weeksTypical delivery
Your stackDeployment
Minute-backedBoard approves
Agent CareAfter launch

What this agent does

Maintains the evidence, not the approval

In
01

A pillar is tested, and the agent opens one evidence set from the policy, training, monitoring and filing systems.

02

A legal-entity file is opened, and CDD at 31 CFR 1010.230 still applies — only foreign companies now file BOI.

Reason
03

A minute entry is drafted — the OCC asks for approval reflected in the minutes, the Fed and FDIC for it noted.

04

A risk is retired, and the agent shows which controls still map to it and which risks are now left uncovered.

05

A risk profile shifts, and the scope reopens — no rule sets a testing frequency, and change is the trigger.

Decide
06

A finding is raised, and it is logged against the element it hit, its owner and the evidence closure will need.

07

A training population is defined, and contractors, mid-period joiners and acquired lines are named in or out.

Out
08

An order article falls due, and the agent tracks the day count and whether no supervisory objection was sought.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The board approves and a named tester opines; if a signed opinion rested on a pack the agent mis-assembled, the next examination re-tests that period.

Example workflow

One element, evidence to opinion

AgentHuman
1Testing cycle openedBoard calendar, examination findings, order articles or a change in the risk profile
2Evidence assembledProgramme version, risk assessment, control mapping, training records and issue log, each with its source
3Pack draftedElement coverage, evidence gaps, open findings and confidence
4Controls appliedSource-currency checks, control-to-risk reconciliation, scope-coverage rules and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is approved or opined at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the BSA officer to review.

Low confidence

Adds a second compliance read first.

Officer review

The pack is held with its evidence, its gaps and the confidence.

Accept · Amend · Send to second review
Accepted — goes to the board and the tester
6Programme record updatedOnly where write access and approval policy allow it
7Outcome evaluatedGaps the tester found, officer amendments, issues reopened and examination findings
Amendments

Every officer amendment is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Approving the programme — the board's own act.
Signing the scoped, dated testing opinion.
Accepting residual risk on any element.
Closing an MRA or a consent-order article.
Automation boundaryAgent acts unaided
Assemble the programme record and stamp what was current when.
Reconcile the risk assessment to the controls mapped to it for the named owner.
Test the evidence set against the configured element rules.
Flag what the pack is missing, and hold it for the officer.
Any write happens inside the boundaries agreed at implementation, never ahead of the board.
Judging whether a tester is independent.
Setting the scope of the independent test.
Certifying an order deliverable to the OCC.
Changes to element, evidence or escalation rules.

Example output

One programme element, annotated

The examinable artefact is the minute naming the version approved — this is that layer.

Programme evidence · single elementIllustrative example
Element
Evidence assembled
Version
Rule and record
Confidence
Approval record
Internal controls
Control-to-risk mapping reconciled to the current assessment
v4.2, 12 Mar 2026
12 CFR 21.21(c)(1) · OCC
91%
Minute entry, board of directors
As receivedTaken from the programme record and the board minute — nothing on this side is written by the agent.
Evidence held Approved programme v4.2 Risk-assessment extract Training completion log
Why this recordThe minute names the version the board approved and a person still decides.
ActionAcceptAmendSend to second review
What the score decidesBelow the configured threshold the pack picks up a second compliance read first.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every elementFrom the programme record
03Assembly

Assemble from the record

Draw on the programme record, the element rules and the day counts a consent order sets.

01Approved path

The minutes are the evidence

Most programme tooling holds the document and not the minute — the half that proves nothing.

02Human review

Send review to the weak evidence

Unsupported closures and low-confidence packs are marked, so the officer's read starts where the gaps sit.

04Build an evidence trail

The element, the testing it was scoped for and the tester who opined stay on the programme.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

GRC and policyArcher · MetricStream
OneTrust · ServiceNow IRM
Audit managementAuditBoard · Workiva
TeamMate · Galvanize
AML systemsActimize · Verafin
Oracle FCCM · Hawk

Agent

AML programme governance & independent testing

Reads the record
Assembles evidence
Holds for the officer

Board and trainingDiligent · Boardvantage
Cornerstone · Docebo
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the programme

Six controls, every one holding the next. What none of them holds is named in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modePull assembly back to evidence-listing only when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, element-rule and programme-configuration changes.Track
L4TraceabilityRecord the evidence, its source system, the amendments and the acceptance time.Record
L3Officer reviewHold packs for the named officer; it governs release, not whether the board's approval is sound.Gate
L2Policy guardrailsTest packs against the configured element and evidence rules; a failure returns the pack.Restrict
L1Confidence thresholdsRoute low-confidence packs to a second compliance read before the officer sees them.Require review
Model corePack produced — element coverage, evidence gaps, open findings and confidence
L1 – L2Test whether a pack may stand
L3Puts the acceptance in an officer's hands
L4 – L5Keep the element and the testing behind it
L6Steps back to evidence listing when signals degrade

How Nestack evaluates it

Evaluate the evidence workflow — not only the pack the board reads.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the pack the board and the tester read
Depth of coverage ▼
E1Final-output evaluationDid every item in the pack match its source system?
E2Step-level evaluationDid the agent use the right programme version and element rules?
E3Tool evaluationDid it read the correct element and the correct source system?
E4Confidence calibrationDo low-confidence packs actually attract more officer amendments?
E5Slice evaluationHow does performance change across specific programme elements?
E6Business outcomeHow many packs needed an officer amendment or a later correction?
Floor — the outcome the bank answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
OP-03

Superseded version used

Evidence pulled from a version the board never approved.

Stage gathersProgramme versions, risk assessment, training, issues
02 · Reasoning2 modes
OP-04

Orphaned control mapping

A control still maps to a risk the assessment retired.

OP-06

Scope inherited unchanged

Testing scope carries over though the bank's risk moved.

Stage proposesElement coverage, evidence gaps and confidence
03 · Tool / write2 modes
OP-02

Closure without evidence

An issue closes on an attested date with nothing attached.

OP-05

Population left undefined

Training completion is reported over an unstated group.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
OP-01

Approval not minuted

A version reaches the board with no minute entry drafted.

Stage returnsThe pack the officer accepts and the board approves
05 · Change / Version1 mode
OP-07

Silent element drift

A model or rule change narrows what the agent flags.

Stage tracksModel, prompt, element rules and programme config
Sev-1 · pack relied on outside the boundary Sev-2 · a stale version reaches the board Sev-3 · source degrades, pack routes to review

Affected slices

An evidence gap is never evenly spread

A programme-wide evidence figure is carried by the pillars that hold the most documents, while the thin ones set the examination. Nestack reports the evidence-gap rate by pillar, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Board minute record7.6%3.6× Review
Issue and MRA closure5.5%2.6× Review
Risk-assessment currency3.7%1.8× Watch
Internal-controls testing1.6%0.8× Normal
Bar: evidence-gap-rate lift vs. internal-controls baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

Each cycle closes with a new evidence case

A cycle is done when the undocumented approval has become a case the next release must close. That suite is what the next test scoped is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Evidence gaps rise in one programme element.

02Diagnose

The programme approval nobody could find in a board minute is traced back to one cause — a version number the corporate secretary was never given.

03Improve

The fix gets a number, and the findings that raised it are held against it.

04Verify

No release while a touched evidence case is outstanding; it reruns until green.

05Learn

The case stays for good, and the elements it spans are recorded against it.

Learn → DetectThe return edge. The next detection runs against a suite one evidence case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Programme workflow discovery and boundary setting.
02GRC, audit and training-source assessment.
03Element, evidence and escalation-rule mapping.
04Programme-record ingestion and mapping.
05Control-to-risk reconciliation logic.
06Confidence scoring and escalation routing.
07Officer review workflow.
08GRC and audit-platform integration.
09Evidence and remediation cases.
10Guardrails and opinion controls.
11Programme-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne charter, one programme ProductionProduction GRC systems AdvancedMultiple charters / entities
Introduced at Pilot
Assembly to your record and elements
Officer review
Evidence-coverage baseline
Introduced at Production
Reporting by pillar
Review workflow in your systems
Approved write-back
GRC-platform integration
Introduced at Advanced
Multi-agency element rules
Multi-stage board approvals
High issue volume
Multi-charter programme controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your programme document and element structure Programme-record ingestion and evidence mappingWeek 1
02Representative past testing cycles Evidence baseline, source binding and coverage mappingWeek 2
03Your risk assessment and control inventory Element, evidence and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports GRC, audit and training-source assessment, then integration setupWeek 2
05Programmes you would not want tested Finding cases and failure-mode testingWeek 4
06What no opinion may cover Confidence scoring, escalation routing, guardrails and approval controlsWeek 3
07Named officers, and a tester reporting to the board Officer review workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The weeks are taken from the board calendar, so the fifth band carries evaluation and the pilot.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Programme workflow discovery, element mapping and the automation boundary W2Source integration and the evidence baseline W3Evidence workflow, reconciliation logic and review controls W4Evaluation suite, coverage checks and failure-mode testing W5GRC integration, pilot elements and targeted corrections W6One testing cycle run under the AML officer, then Agent Care handover
Reading the bandA bar covers the weeks its work is named in, and nothing else. The week 5 overlap is real, not padding.
At the end of W6Once the cycle validates, monitoring transfers to Agent Care.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Banking AI agent

Build a programme-governance agent around the minute that proves approval.

Show us your programme and your issue log. Your corporate secretary holds the minute an examiner asks for first, and we build to the rule in force — the 2024 NPRM is withdrawn, no successor final.

Nestack Agents · AML programme governanceAGT-BK-19 · Agent Care available after launch