Case Studies | FinTech

A framework-first path to governed AI in regulated finance

Governed AI Framework

About

A FinTech business working with Cloud Combinator on AWS. The client is anonymised at their request.

Challenge

The framework addresses three focus areas that regulated firms must resolve before adopting AI at scale.

Adopting AI without losing control

As AI systems gain agency, basic prompt and output filtering is no longer enough. The framework had to move controls toward explicit action policies, non-human identity, runtime monitoring and fail-safe mechanisms, so that autonomy could rise safely rather than uncontrollably.

Deciding what to buy and what to build

The landscape spans off-the-shelf enterprise AI, developer tooling and custom agents, each with a very different security and compliance burden. The client needed a clear, defensible way to classify each workload and set its default posture rather than treating all AI the same.

Proving control to regulators and auditors

A regulated programme must show not only that controls were designed, but that they operate, are measured and are improved. The framework had to make evidence, logging and incident reconstruction first-class concerns, mapped to recognised standards.

Solution

The engagement followed the progressive-autonomy arc that AWS recommends, delivered as a phased one, three and six-month rollout so that capability and assurance mature together.

ISO 42001

Governance backbone the framework is anchored in

6

Control lenses applied consistently across every workload

1-3-6

Month phased rollout from foundations to scale

By the numbers:

  • ISO 42001 - Governance backbone the framework is anchored in
  • 6 - Control lenses applied consistently across every workload
  • 1-3-6 - Month phased rollout from foundations to scale
Changes

Cloud Combinator delivered a coherent, customer-ready governed AI framework that gives the client a defensible way to adopt AI across regulated workloads with human accountability preserved at every step.

  • Scope before toolingA two-axis scoping matrix lets the client classify any AI workload by ownership and autonomy and set its default control posture accordingly.
  • Consistent control modelSix control lenses, from action boundaries to sensitive-data handling, are applied uniformly, making the programme easier to govern and explain.
  • Regulator-ready evidenceThe framework maps to ISO/IEC 42001, with NIST AI RMF, SOC 2 and DORA and FCA resilience expectations reinforcing logging, third-party oversight and incident handling.
  • Progressive autonomyAn one, three and six-month rollout advances only as security capability matures, so autonomy stays bounded and incidents remain reconstructable.

With the framework defined, the client has a clear path from governance foundations to controlled pilots and scaled adoption. Open decisions, such as the platform on AWS versus Claude on Bedrock for regulated data, and vendor-diligence points on retention and audit export, are called out explicitly so they can be resolved before wider rollout, leaving the client ready to move into implementation with confidence.

AWS Stack

Amazon Bedrock

For the foundation models underpinning enterprise and custom AI.

Amazon Bedrock AgentCore

For secure, policy-governed deployment of custom agents across runtime, gateway, identity and observability.

Amazon Bedrock Guardrails

For enforcing content and action boundaries.

Amazon Bedrock Knowledge Bases

For retrieval-based handling of sensitive data instead of model customisation.

Amazon CloudWatch

For OTEL-compatible telemetry, monitoring and auditability.

AWS IAM Identity Center

For identity and access governance across the stack.

AWS DevOps Agent

For a tightly bounded AI operations use case.

YOU MIGHT LIKE

Related success stories

View all case studies

Case Studies | Insights

Utilising Language Recognition, Speed, and Enhanced Security to Make Social Media a Force for Good

  • Here, we take a detailed look at how the Cloud Combinator team collaborated with another cutting-edge AI service provider that provides intelligent systems to “make social media more social” for brands and users alike.
  • Arwen AI is a UK-based startup specialising in AI solutions to manage and enhance brands’ social media interactions. Founded in 2020 by Matt McGrory, Dr. David Cole, and Joel Bailey, Arwen. AI focuses on using AI to automatically detect and remove spam, toxic comments, and other unwanted content from social media platforms.
  • The team at Arwen have three core products. ‘Moderate’ is focused on identifying and removing toxic content from social media channels. ‘Engage’ helps brands identify and engage with meaningful conversations on social media, and ‘Customize’ allows brands to apply bespoke algorithms to their channels - creating an even more effective moderation and engagement.
Read more
CONTACT US

Ready to turn AI into impact?

We'll help you spot the highest-value opportunities, reduce risk around your first AI initiative, and define a clear path to results from day one.

Why talk to us:

Outcome-driven recommendations

AWS-recognised delivery expertise

Risk-aware AI adoption

Clear next step, not a sales pitch

Start with a focused 20-minute conversation about your goals — no pressure, no commitment.

This website uses cookies to enhance user experience and to analyze performance and traffic on our website.

See our Privacy Policy for details.