DATS is the AI consulting system from DILR.AI that maps where AI pays across UK banking: financial-crime alert triage, PRA SS1/23 and DORA evidence, routine customer-contact cost, and Consumer Duty governance. It ranks the four cost centres, shows where Dilr Voice, Cognibl and Dilr Academy fit, and names the evidence each must leave for a supervisor.
DE
Dilr.ai EngineeringEngineering team
Published Sep 28, 2026Read 15 min
Almost 2.5 million people worked in UK financial and related professional services in 2023, 377,000 of them in banking (TheCityUK). The sector has spent the past two years adding AI faster than it has learned to govern it: the Bank of England and the FCA found that 75% of UK financial services firms already use AI, yet only 34% report complete understanding of the technology they run (Bank of England and FCA, 2024). Across the wider economy the gap is the same shape: about a third of enterprises have moved AI into production and only around six per cent capture material earnings impact (McKinsey, The State of AI).
For a Chief Risk Officer measured on cost to income and on financial-crime fines avoided, and for a Chief Data and AI Officer signing off model risk, the question is no longer whether to use AI. It is where AI actually pays inside a bank, and what evidence each use has to leave behind for a supervisor. This guide maps that, cost centre by cost centre, and names which line inside DILR.AI carries each one. It is the banking view of our broader AI voice automation by industry guide, and it stays deliberately at the altitude of the map: the deep how-to for each area lives in a named post, which we link where the mechanism belongs, so this page holds the whole picture rather than repeating any one part of it.
This guide is shipped by the team behind DATS, the AI consulting system from DILR.AI that places AI where the profit and loss actually moves. Or read how we design an AI operating model, the governance, RACI and lifecycle layer a regulated bank needs before it scales anything.
Where does AI pay first in UK banking?
AI pays first in UK banking where a manual workload is large, rising and tied to a regulatory clock. Four areas fit that test: financial-crime compliance, where alert volume outruns headcount; model risk and operational-resilience evidence, which supervisors now expect continuously; the cost of routine customer contact; and the governance layer that proves any of it to a board. DATS treats these as the map, and places AI against the one where the return and the risk are largest first.
The order matters because a bank does not buy capability, it buys a reduction in a cost it can already name. The four areas below are not equal. Financial crime and customer contact carry the highest manual volume; model risk and resilience carry the highest supervisory exposure. Governance sits underneath all four, because every one of them now has to produce evidence a board and a regulator can read. The map that follows is the same one a DATS placement diagnostic produces for a specific bank, ranked to that bank's own numbers rather than to a generic sequence.
Where AI pays across UK bankingFour cost centres, and the evidence each one has to produce for a supervisor.
Why do financial-crime compliance costs keep rising?
Financial-crime compliance costs rise because the workload is structural, not discretionary. Anti-money-laundering obligations under the Money Laundering Regulations 2017 and JMLSG guidance land on the money laundering reporting officer's budget every year, whatever the quality of the alerts a rules engine produces. Adding another point tool rarely moves the number, because the real cost sits in the manual middle: the analyst hours spent clearing alerts that turn out to be noise.
The scale is set by the sector. EMEA financial institutions spent about $85 billion a year on financial-crime compliance, and those costs rose for 98% of them (LexisNexis Risk Solutions, 2023). This is the area where DATS leads, and it leads on the manual middle rather than the detection model. A privatised triage layer, run inside the bank's own perimeter, drafts the customer due diligence narrative and clears the alerts that turn out to be noise, so analyst hours move to the exposure that is real. The point is not a cleverer detection model. It is the senior-led, evidence-first delivery that a market of half-finished pilots has been missing, and it is why financial crime is the first place a diagnostic usually lands. The deeper mechanics of AI governance for a financial-services deployment sit in our FCA AI governance guide; this page holds the placement decision.
What does PRA SS1/23 expect of a bank's AI model inventory?
The PRA's supervisory statement SS1/23 sets model risk management principles: a model inventory, independent validation and ongoing outcome monitoring. It applies to the banks, building societies and PRA-designated investment firms in its scope that hold internal model approval for regulatory capital. The duty binds the PRA-regulated firm, not the vendor whose model it deploys, and a model a bank cannot explain is a supervisory finding waiting to happen.
The supervisory statement extends those expectations to AI and machine-learning models to the extent that they behave like models more generally, so a bank cannot exempt an AI system from its inventory simply because it was bought rather than built. The same 2024 survey found 75% of financial services firms use AI while only 34% report complete understanding of it. For a bank inside SS1/23's scope, that understanding gap is not a talking point but a control weakness a validation function has to close. DATS builds the evidence layer for it, the evaluation and observability our enterprise AI consulting practice treats as a first-class deliverable, so a model risk team has continuous evidence on every AI model in production rather than a point-in-time attestation. What DATS provides is the evidence; whether the firm meets SS1/23 remains the firm's own responsibility.
How does DORA change continuous resilience evidence?
DORA, the Digital Operational Resilience Act, became applicable on 17 January 2025, and it changes the tense of resilience evidence from past to present. It requires ICT risk management, incident reporting, resilience testing and third-party ICT risk management on a continuing basis. For a bank the shift is from an annual binder assembled the week before a review to evidence that is always current, which is a different operating posture rather than a heavier one.
DORA binds the EU financial entities in its scope (European Banking Authority). That catches UK banking groups with EU entities or EU-client exposure, not their purely domestic peers, who answer instead to the UK's own operational-resilience regime. That UK regime is the FCA and PRA rules on building operational resilience (PS21/3), which required firms to be able to remain within board-set impact tolerances for each important business service by no later than 31 March 2025. Both regimes ask the same thing of a bank: evidence that is current, not point-in-time. This is where DATS automates control-evidence assembly, and where the resilience area of the map turns into ongoing engineering rather than a project. The specific ICT third-party test that DORA imposes on an outsourced service, including a voice deployment, is worked through in our DORA operational resilience guide; this hub places it in the wider banking picture.
Where does Dilr Voice fit against the redress and complaints surge?
Dilr Voice, the enterprise voice AI platform from DILR.AI, fits where routine call volume is highest and still rising. Complaints across financial services are at their highest in six years, and on top of that sits the FCA's motor-finance redress scheme, a customer-contact and redress exercise now under way. Voice is secondary to DATS in banking, and its role is precise: it absorbs the routine, repeatable calls so that people stay free for the conversations that need a person.
The complaints picture is steep. The Financial Ombudsman Service received 305,726 new complaints in 2024/25, up 54% on the year before and the highest in six years.
The redress numbers are larger still. The FCA estimates that 12.1 million motor-finance agreements made between 2007 and 2024 are eligible, with about £7.5 billion in total redress if 75% of eligible consumers claim, at an average of around £830 per agreement (FCA). Under PS26/3, firms had until 30 June 2026 for loans taken from April 2014 and 31 August 2026 for earlier agreements to be ready to run the scheme; lenders then have three months from the end of that period to tell complainants whether they are owed compensation and how much, and the majority of claims are settling in 2026. That duty binds the lending firm, not the broker or dealer who introduced the agreement. Against that surge, the mean cost of a live-agent inbound call in the UK is £5.58 (ContactBabel, 2024), so every routine query answered by a person is capacity taken from a harder conversation, and absorbing those queries is what Dilr Voice is built for.
It does that narrow job well. It takes the routine balance, card-status and redress-enquiry calls, runs after-hours routing and warm transfer to a person with full context, and chases KYC-refresh follow-ups on an outbound campaign, with a full audit trail on every call. Deflecting those routine types away from that mean cost frees capacity for the financial-difficulty conversations a person should handle, and it produces a logged contact record. The collections and debt-recovery mechanics under Consumer Duty are worked through in our AI voice debt recovery guide, and the complaints and DISP handling in our complaints handling guide; Dilr Voice never makes the vulnerability judgement, it clears the queue so a person can.
What does a corporate KYC refresh cost a bank without AI?
A corporate KYC review is expensive and getting more so, and the cost lands twice: once in analyst time, and once in the client who walks before the review is finished. The refresh book falls due on a fixed regulatory clock, so a backlog compounds rather than clears on its own. For a bank with a large corporate book, that means a per-review cost that keeps rising against a volume that keeps growing.
The figures put numbers on it. UK banks spent an average of $2,613 to complete a corporate KYC review, up 19% year on year, and 39% of UK banks reported losing clients to slow or inefficient onboarding and review processes (Fenergo). This is where the map connects three lines rather than one. DATS designs the workflow and the evidence, Dilr Voice chases the outstanding documentation with an outbound campaign, the pattern our voice collections and KYC guide works through, and the case preparation itself belongs to an agent-and-human desk. AI pays here by holding the per-review cost flat while the book grows, which is a different claim from making any single review faster, and it is the kind of ranked, cost-anchored placement a diagnostic exists to produce.
When does an agent desk belong in a bank's remediation and operations?
An agent desk belongs in remediation and operations once the work is high-volume, rule-bound and audited, which describes reconciliation, complaints triage, KYC refresh and redress-case preparation exactly. Cognibl, from DILR.AI, is a candidate for that desk. It is a work-management platform where people and AI agents share one board, and where a task cannot reach a done status until a proof version is attached, because the database refuses the move without one.
The mechanism is what makes it defensible rather than the label. In the Cognibl work-management platform, every write is written by the gateway, append-only and hash-chained, and agents reach any tool through a gateway that is deny by default, so a capability that has not been enabled is refused rather than silently missing. The proof itself is a structured record of the run, referencing the artefact and its evidence, and the same rule applies to a person and to an agent. For a remediation programme that a supervisor will later inspect, an agent team whose every action leaves attached, ordered proof is the difference between an efficiency and a liability. Whether such a desk is ready to adopt at all is a question the operating model has to answer before the tool does.
How does Consumer Duty change what counts as evidence in banking?
Consumer Duty changes what counts as evidence because it moves the test from process to outcome, and it asks for that evidence continuously. A firm now has to show good customer outcomes and fair value on a continuing basis, with an annual board report, and the duty binds FCA-regulated firms, not the technology vendors they use. Under it, an efficient process that produces a poor outcome is no longer a defence a bank can rely on.
The FCA's wording is direct. As PRIN 2A.5.3R(2) puts it, "A firm must communicate information to retail customers in a way which is clear, fair and not misleading." That is why every area on this map has an evidence column: a redress campaign has to prove the contact was clear and timely, a collections call has to prove the customer was treated fairly, and a model that prices or decides has to prove it was understood and monitored. This is the governance area, and it is where DATS and Dilr Academy meet. DATS assembles the control evidence, and Dilr Academy raises the AI literacy of the compliance, risk and operations teams who have to run and govern what was deployed. Evidence that a person cannot interpret is not evidence a board can rely on.
The same senior-led delivery runs through our AI execution office, embedded delivery where the production placements are ones the bank owns rather than rents.
Where each DILR line pays in UK banking
The six lines inside DILR.AI do not all apply to a bank, and saying so plainly is part of an honest map. One line leads, three support it to different degrees, and two do not fit this case at all. What follows is where each one pays, and where it does not.
DATS leads. The AI consulting system is the lead line in banking: privatised financial-crime alert triage, the SS1/23 model-evidence layer that rescues a stalled AI pilot, and continuous control-evidence for Consumer Duty and operational resilience. It is delivered by senior practitioners who ship code rather than decks, with a ranked roadmap from the placement diagnostic and a named owner on every placement.
Dilr Voice supports. The enterprise voice AI platform is secondary, and it earns its place on the highest-volume routine call types: balance, card-status and redress-enquiry lines, plus KYC-refresh chasing, each deflected from the mean cost of a live-agent call and each leaving a logged contact record. It clears the routine queue so people stay free for the financial-difficulty conversations that need them. Try Dilr Voice against a single call queue before it goes near the book.
Cognibl is a candidate. Cognibl, from DILR.AI, is a candidate for the agent-and-human desk that runs reconciliation, complaints triage and redress-case preparation, precisely because a task cannot close without attached, hash-chained proof. Its proof-of-done work-management model is built for exactly the audited, high-volume queues a bank runs.
Dilr Academy supports. Dilr Academy is secondary in banking as the upskilling step that follows a build: an AI tutor that builds interactive, multilingual courses on demand, with mastery tracking, used here to raise AI literacy and governance understanding across compliance, risk and operations. The AI teacher approach is the same one it uses in schools and universities.
Dilr Mira does not apply. Dilr Mira is a class of private clinical small language models from DILR.AI, and it does not apply to this build: banking's case here is framed on financial-crime and control evidence, not the regulated document extraction Mira is built for, which is covered in our clinical document extraction guide.
DILR Studio does not apply.DILR Studio, the promptless AI content creation platform from DILR.AI, does not apply either: the banking case names no self-serve content-generation use, and Studio's promptless content model sits with marketing and brand teams rather than a risk function. Naming the misses honestly is what keeps the map trustworthy.
Is AI mandatory for UK banks under any regulation?
No. No UK regulation makes AI mandatory for a bank. Consumer Duty, PRA SS1/23, DORA and the operational-resilience rules under PS21/3 set outcomes and evidence standards, and AI is one way to meet them faster, not a requirement in itself. Each of those duties binds the regulated firm, not the vendor behind any tool, so a bank stays accountable for the evidence whether the work is done by people, by AI, or by both together under supervision.
What is the best AI approach for a UK bank in 2026?
The best AI approach for a UK bank in 2026 is a ranked, evidence-first placement rather than a platform purchase. Large integrators such as Accenture, Deloitte or a Big Four firm win where a bank wants a multi-year programme with scale and brand cover. DATS wins the narrower brief: senior practitioners who place AI against a named cost, ship it into production and leave audit-ready evidence, with a deliberate limit of a few placements a year, not a headcount pitch.
A specialist such as Faculty or Palantir wins on a single, deep data problem, and there are banks whose first move should be one of those rather than a consulting engagement at all. The honest answer depends on where the bank is stuck. Where the blocker is a stalled portfolio of pilots that no one can govern, evidence-first placement is the approach that turns them into production, and that is the ground DATS is built for.
How do the regulators divide up an AI banking deployment?
The regulators divide by outcome, not by technology. The FCA owns conduct and Consumer Duty, the PRA owns prudential and model risk through SS1/23, the Bank of England and the FCA jointly survey AI adoption, and the Financial Ombudsman Service adjudicates the complaints that result. DORA and the UK operational-resilience rules govern whether the systems behind all of it stay within tolerance. A bank has to satisfy each of them with current evidence.
Where should a bank start if pilots are stalling?
A bank should start where the manual cost is largest and the regulatory clock is fixed, which in practice usually means financial-crime triage or the model-evidence backlog. A four-to-six-week placement diagnostic produces a ranked roadmap of where AI belongs and where it does not, with a named owner per ship, so the first placement is chosen on cost and risk rather than on which vendor demonstrated best. That is how a stalled pilot becomes a production placement a bank owns.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
AI for banking UKbankingAI in UK bankingbank AI governancefinancial crime compliance AIai consulting redditbest ai consultancy uk 2026dats
Questions this article answers
Where does AI pay first in UK banking?
AI pays first in UK banking where a manual workload is large, rising and tied to a regulatory clock. Four areas fit that test: financial-crime compliance, where alert volume outruns headcount; model risk and operational-resilience evidence, which supervisors now expect continuously; the cost of routine customer contact; and the governance layer that proves any of it to a board. DATS treats these as the map, and places AI against the one where the return and the risk are largest first.
Why do financial-crime compliance costs keep rising?
Financial-crime compliance costs rise because the workload is structural, not discretionary. Anti-money-laundering obligations under the Money Laundering Regulations 2017 and JMLSG guidance land on the money laundering reporting officer's budget every year, whatever the quality of the alerts a rules engine produces. Adding another point tool rarely moves the number, because the real cost sits in the manual middle: the analyst hours spent clearing alerts that turn out to be noise.
What does PRA SS1/23 expect of a bank's AI model inventory?
The PRA's supervisory statement SS1/23 sets model risk management principles: a model inventory, independent validation and ongoing outcome monitoring. It applies to the banks, building societies and PRA-designated investment firms in its scope that hold internal model approval for regulatory capital. The duty binds the PRA-regulated firm, not the vendor whose model it deploys, and a model a bank cannot explain is a supervisory finding waiting to happen.
How does DORA change continuous resilience evidence?
DORA, the Digital Operational Resilience Act, became applicable on 17 January 2025, and it changes the tense of resilience evidence from past to present. It requires ICT risk management, incident reporting, resilience testing and third-party ICT risk management on a continuing basis. For a bank the shift is from an annual binder assembled the week before a review to evidence that is always current, which is a different operating posture rather than a heavier one.
Where does Dilr Voice fit against the redress and complaints surge?
Dilr Voice, the enterprise voice AI platform from DILR.AI, fits where routine call volume is highest and still rising. Complaints across financial services are at their highest in six years, and on top of that sits the FCA's motor-finance redress scheme, a customer-contact and redress exercise now under way. Voice is secondary to DATS in banking, and its role is precise: it absorbs the routine, repeatable calls so that people stay free for the conversations that need a person.
What does a corporate KYC refresh cost a bank without AI?
A corporate KYC review is expensive and getting more so, and the cost lands twice: once in analyst time, and once in the client who walks before the review is finished. The refresh book falls due on a fixed regulatory clock, so a backlog compounds rather than clears on its own. For a bank with a large corporate book, that means a per-review cost that keeps rising against a volume that keeps growing.
When does an agent desk belong in a bank's remediation and operations?
An agent desk belongs in remediation and operations once the work is high-volume, rule-bound and audited, which describes reconciliation, complaints triage, KYC refresh and redress-case preparation exactly. Cognibl, from DILR.AI, is a candidate for that desk. It is a work-management platform where people and AI agents share one board, and where a task cannot reach a done status until a proof version is attached, because the database refuses the move without one.
How does Consumer Duty change what counts as evidence in banking?
Consumer Duty changes what counts as evidence because it moves the test from process to outcome, and it asks for that evidence continuously. A firm now has to show good customer outcomes and fair value on a continuing basis, with an annual board report, and the duty binds FCA-regulated firms, not the technology vendors they use. Under it, an efficient process that produces a poor outcome is no longer a defence a bank can rely on.
DE
Dilr.ai Engineering
Engineering team
Dilr Voice
Voice AI built for your sector
Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.