Software and AI for banks and fintechs
We do fintech software development and applied AI for banks, lenders and payment companies that have to move fast inside strict supervision. Our work ranges from customer onboarding and alert handling to the integrations around your core banking platform, with analysts approving every regulated decision.
Where the work gets stuck.
Onboarding stalls on document checks
Passports, company extracts, UBO statements and bank statements are still checked by hand. Each missing or unclear document adds days to onboarding and costs customers.
Alert backlogs in transaction monitoring
Monitoring systems produce many alerts, most of which turn out to be explainable. Analysts spend their time gathering data from several systems before they can even judge a case.
Old cores, new obligations
Legacy core systems and batch interfaces make every new product, API or reporting duty slow to deliver. DORA adds testing, incident and third-party requirements on top.
How we improve banking and fintech.
Each one is scoped around your systems and rules, and each one keeps a person in charge of the decisions that matter.
KYC and KYB document checks
Identity documents, Chamber of Commerce extracts, UBO registers and bank statements are read, cross-checked and summarised with discrepancies flagged. A compliance officer approves or requests more information.
Transaction monitoring alert investigation
An agent collects account history, counterparties and customer profile data for each alert and drafts an investigation note with the evidence attached. The analyst decides whether to close the alert or report it to FIU-Nederland.
Compliance policy copilot
Staff ask questions about internal policies, product rules and regulatory guidance and get cited answers from the approved versions. Compliance owns the sources and sees which questions come up most.
Fintech product engineering
We build lending, payments and wealth products as web and mobile platforms with ledgers, audit logs and role-based access. Your team owns the code and the architecture decisions.
Open banking and payment APIs
We connect account information and payment initiation services under PSD2, plus payment providers and ISO 20022 flows. Consent, error handling and reconciliation are built in from the start.
Core banking modernisation
We wrap legacy core and batch systems with APIs and move functions to platforms such as Mambu step by step. Existing processes keep running while each part is replaced.
Built around the rules.
What we design for from the first week. Your legal and compliance people keep the final word.
DORA
We design for DORA's requirements on ICT risk, incident logging, resilience testing and third-party arrangements. That includes documented exit plans and contract terms your register of information needs.
Wwft and EU anti-money laundering rules
KYC and monitoring tools keep a full record of what was checked, by whom and why, so files hold up under Wwft reviews and the incoming EU AML regulation. Reporting decisions remain with your analysts.
PSD2
Payment and account access flows are built around strong customer authentication, explicit consent and secure API access. We work with licensed providers where your own licence does not cover a service.
EU AI Act for credit decisions
AI used to assess the creditworthiness of individuals is high-risk under the AI Act. Where a build touches credit, we design for human oversight, logging and documentation, and keep the decision with your credit staff.
Works with what you run.
If a system has an API, a database, an export or an inbox, we can build on it. These are the ones we meet most.
- Mambu
- Temenos
- Thought Machine
- Ohpen
- Backbase
- Fenergo
- Salesforce Financial Services Cloud
- Adyen and Stripe
- SEPA and ISO 20022 payment formats
Where to start.
Alert investigation assistant for one scenario
An assistant that prepares investigation notes for a single transaction monitoring scenario with high alert volume. Analysts keep deciding every alert while the time spent gathering data goes down.
Talk it throughWhat it includes
- Read-only connectors to monitoring and core data
- Drafted investigation notes with evidence
- Analyst review and decision screen
- Eval set built from closed alerts
Related work.
Guides.
AI vendor security questionnaire: what to ask before you buy or build
The questions to ask an AI vendor, or your own team, about data, model providers, access, logging, quality, incidents, GDPR and exit, and how to score the answers.
8 min read
Build vs buy software: a decision guide for operations and product teams
A practical guide to choosing between off-the-shelf and custom software, with a cost comparison, a decision matrix and a checklist for your team.
10 min read
Further reading.
Human-in-the-loop AI agents: design patterns for production
The patterns we use to run AI agents safely in production: approval checkpoints, confidence thresholds, tool permissions, audit trails and fallbacks.
4 min read
Document parsing with LLMs: extracting data from invoices and forms
How to turn invoices and forms into reliable structured data with LLMs, schemas, validation and a review queue for the cases that need a person.
4 min read
Build vs buy software: when custom development pays off
A practical way to decide between off-the-shelf software and custom development, covering total cost of ownership, integrations and risk.
5 min read
Common questions.
When we build or run software that supports your services, you should treat us as one. We provide the contract terms, security information and exit arrangements your DORA register and risk assessment need.
In our builds it does not. The software gathers data, drafts notes and highlights risk indicators, and a trained analyst or credit officer makes and records the decision.
Yes. Modern cores have APIs we build against, and for in-house or older systems we work with database access, batch files or middleware. We assess the options in discovery because they shape the plan.
In the EU, either with EU-hosted model providers or entirely inside your own cloud. Customer identifiers can be masked before any text reaches a model.
We document intended use, data sources, eval results and the human decision points for each build. That gives your risk and compliance teams material to explain the process to supervisors.