The customer-facing assistant is the pattern supervisors have looked at hardest, and their findings are specific: wrong answers about rights and fees, customers unable to reach a person, and systems that hide what they are. The design is routing: classify the intent, answer knowledge questions from the governed document set with citations, answer account questions through tools to the live system, hand transactions above a threshold to a person, and make the route to a human one step away at all times.
Customer-facing chatbots: The model prepares and may act within limits; a person approves anything that reaches a customer or cannot be undone. Several model calls orchestrated by your code, in a sequence or a graph you designed. Material but recoverable. The model may prepare and, within limits, act, with a person approving anything that leaves the bank or touches a customer.
Which steps belong to a person, the model and a system?
| # | Step | Owner | Note |
|---|---|---|---|
| 1 | Identify the customer and the intent | A system | Authentication in the channel; intent classification with a confidence. |
| 2 | Answer a knowledge question | The model | Retrieval over product terms and policies, with the source shown. |
| 3 | Answer an account question | A system | A tool call to the system of record; the model formats, never invents. |
| 4 | Execute a low-value task | A system | Within an envelope, by rule, confirmed with the customer. |
| 5 | Escalate | A person | Complaints, disputes, hardship and anything the classifier is unsure about. |
Which control layers carry the weight?
Each layer is described, with its controls and documents, on the control plane page.
- Governance and accountability: core for this design.
- Identity and entitlements: core for this design.
- Action gateway: core for this design.
- Data and knowledge: core for this design.
- Models and vendors: core for this design.
- Human oversight and escalation: core for this design.
Which rules and guidance does this design answer to?
| Document | Authority | Why it applies here | Status |
|---|---|---|---|
| CFPB Chatbots in Consumer Finance (issue spotlight, 2023) | CFPB | Inaccurate answers and blocked access to a person can violate consumer law. | Final |
| Regulation (EU) 2024/1689 | EU AI Act | Article 50: people must be told they are talking to an AI system. | In force |
| NIST AI 600-1 (Generative AI Profile) | NIST | Confabulation named as a generative-AI risk, with suggested actions. | In force |
| DFS Virtual Currency Customer Service Guidance (May 2024) | NY DFS | New York's expectations for customer service, including a route to a human. | In force |
| SR 26-2 | Federal Reserve | US model risk management as revised in April 2026. | In force |
| SR 23-4 | Federal Reserve | US third-party risk management, including the model provider. | In force |
| SB 26-189 | Colorado AI Act | Colorado: notice, explanation and human review for consequential automated decisions from Jan 1, 2027. | Final |
| BCBS Third-Party Risk Principles (Dec 2025) | Basel Committee | Nth-party supply chains and concentration on cloud providers. | In force |
| BCBS ICT Risk Management Report (June 2026) | Basel Committee | How supervisors look at ICT and cloud dependencies. | Final |
| OCC Bulletin 2026-13 | OCC | For a national bank, the OCC's copy of the 2026 model-risk guidance. | In force |
| NIST AI RMF 1.0 | NIST | The voluntary Govern, Map, Measure, Manage frame for everything model-risk guidance leaves out. | In force |
How will you know it works, before and after launch?
- A golden dataset of at least 150 real cases with expected outputs, including adversarial inputs: wrong documents, unusual formats, prompts that try to change the task.
- A judge model scoring against a written rubric (accuracy, completeness, tone, citation present), calibrated against a human-scored sample every month. Threshold set from the human sample, not guessed.
- Citation checks: every factual claim resolves to a passage in the governed set; unsupported claims below 2% of answers.
- Escalation evals: the cases that must reach a person do, on a held-out set, with precision and recall both reported.
- Trace evals per step, not only end to end: which step fails, how often, at what cost, so a prompt or model change can be judged step by step.
- The same suite reruns on every prompt change, model version change and retrieval change; a regression blocks the release. That is what ongoing monitoring and outcomes analysis mean in model-risk terms.
Where must a person be in the loop?
- Per-action approval by a competent reviewer for anything customer-facing or irreversible; sampled review for the rest.
- Validation proportionate to materiality, with monitoring for drift on inputs and outputs.
- An escalation route to a person that the customer can reach in one step.
- Monthly review of the evals and the exception log by the accountable owner.
- The customer is told they are dealing with an AI system and can reach a person in one step.
- Retrieval used for live state, producing confident wrong balances.
- No disclosure that the customer is talking to an AI system.
- Escalation buried behind repeated attempts to keep the customer in the bot.
What will a validator or an examiner ask?
- Where is this system in your inventory, what tier did you assign, and who signed it off?
- What counts as a model here, and what does your validation cover for the parts that are not?
- Show me the data lineage behind the retrieval set and the training or tuning data.
- What can the system do without a person, and where is that written down?
- How do you know it is still working: which evals run, how often, and what happened the last time one failed?
- What did you do about the vendor: due diligence, contract, exit plan, concentration?
- Walk me through one wrong output from production and what the customer, if any, saw.
- Who can switch it off, and has that been tested?
- Show me how a customer reaches a person, and how long it took the last ten who tried.
What it does: answers customers' questions and completes simple tasks in a chat or voice channel; the model prepares and may act within limits; a person approves anything that reaches a customer or cannot be undone.
Pattern: workflow (routing, evaluator and optimizer); tier 2: act with approval.
Rules it answers to: 4 documents across US, each linked in the brief.
How we know it works: a golden dataset, automated checks on every release, and human review at the level the tier demands.
What could go wrong and who answers: the accountable owner, the kill switch, the escalation route.
Which of the 100 largest US banks have put this use case on the record?
Every rule this brief cites, the morning it changes.
agent deployments, regulator positions and the day's six stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning