Banking AI | EU Regulatory Compliance
Every credit decision, fraud alert, and KYC verdict ships a constraint trace your auditors can read and your regulator can replay. Built for EU banking.
A regulator names one declined credit decision and asks why. The clock starts. Nobody owns the answer yet.
The score lives in the credit engine, the rule in the policy wiki, the override in case notes, the context in an email thread.
A team rebuilds the decision and hopes the policy version they found is the one that was actually in force that day.
The decision has to come back the way it went out, with the rule, the version, and the customer factor in front of the inspector.
A generative model will confidently cite a regulation that does not exist. An auditor needs the rule that actually fired.
A risk score is not an explanation. The right-to-explanation question cannot be answered by a confidence number after the fact.
EU customer data on a US-hosted endpoint falls under foreign jurisdiction. The outsourcing and resilience rules block it.
When the supervisor asks for replay, a generative pipeline hands back a transcript. The same decision will not come back twice.
Credit, KYC, AML, fraud, trade surveillance, complaints. One record per decision.
Fabric for the risk team. Credit, policies, case notes, and audit requests in one workspace.
Debt-to-income ratio above the policy threshold on the application date. The full record is assembled and ready to replay for the inspector.
Why did we decline the revolving credit limit increase on case 4f9e?
The same decision comes back the way it went out, with the customer factor intact.
The reviewer confirmed the decline and recorded a lower limit as available.
Reviewing officer, signed and timestamped
The policy version in force on the date of the application, not the one current today.
Applicant file and the exact document version the decision used.
The risk workspace with one supervisory request open
One decision, and the reason that goes with it.
Evidence is in the trace, not in the slide.
No customer record crosses a boundary you did not approve. Processing and operation follow the access model you choose.
Source, rule, owner, and replay attach as the decision is made. The supervisory answer is a retrieval.
Decisions trace back to the rules your bank authored, with the policy version pinned to the decision date.
Completely isolated for environments that cannot tolerate any external connection.
Run the full platform on your own servers. Same capabilities, same trace, fully under your control.
Managed Fabric on the public Mesh, operated by Dweve within the agreed processing perimeter. Direct product operation is not included.
No new integration project, no proprietary wrapper. Trace on the bus you already run.
One artefact, two destinations. The same trace lands in audit storage and the analytic warehouse at once, signed locally and verifiable offline, with no double write to keep in sync.
Isolated for environments that cannot tolerate any external connection.
The full platform on standard CPUs, no GPU mandate. Same trace, fully under your control.
Managed Fabric on the public Mesh, operated from the Netherlands under its declared European processing boundary. No customer infrastructure project to start.
The same answer can be shown again, years from now, the same way.
The reviewer sees what the system saw, in the order it saw it.
The plain words above are the explanation, not a score or a code.
The reason and the rule are saved with your decision.
Your card was held by a safety check. Here is exactly why, and you can fix it in one tap.
My card was declined at the till this morning. Why?
It matched a known card-testing pattern, so the bank paused it.
Three payments came from a place far from where you usually pay.
A safety check held the card. No money left your account.
One written reason, the rule named, and a person you can reach.
The record is independently verifiable by the supervisor
Explanation answers come back in days, not months
If your data-protection authority later asks how the decision was made, the bank shows the same reasoning you saw, with the same data, against the same policy version. The record is preserved cryptographically and reads the same way years later.
No clause trains a model on your customer data
Hosting is at the bank or in EU sovereign cloud
Your statements, transactions, and identity documents are processed on hardware inside the European Economic Area. No transatlantic transfer. No US-hosted endpoint. No third party trains a foreign model on your finances.
The override is signed and dated, not a chat note
The reviewer sees the same evidence the system saw
Every automated decision carries a path to a person that does not depend on a phone tree. The reviewer sees what the system saw, in the order it saw it, and can confirm or overturn it with the same transparency. The appeal travels with the original decision.
No, the algorithm decided, with nothing behind it
The right to explanation, answered in writing
When the system flags your transaction, declines your loan, or holds your transfer, you get a written reason. It names the rule, the threshold, and the specific factor that fired. Not a probability score. Not a confidence number. The actual reasoning, in language a customer can read.
A written reason, a person to ask, your data in Europe, and a replay if the regulator asks.
Which rule fired, on which policy version, and who signed it off.
Whether the policy itself is the right policy for the case.
Card, loan, transfer, or account hold. A reason for every one.
From the moment it stops to the moment a person can look again.
You can ask a real person to review it. They see exactly what the system saw, and sign off.
The decision names the rule, the limit, and the one thing that set it off, in words you can read.
European law gives you the right to a plain explanation of an automated decision about you.
You tap to pay and it declines. Today, the bank can rarely tell you which rule fired or why.
Four counts of the record, weighed side by side
The same four counts, whatever the case.
Four fields on every decision. Source, rule, owner, replay.
The platform runs EU-pinned or on the bank's own hardware. Decisions and traces ride the event bus the bank already maintains. No customer record crosses an unapproved border.
Each decision emits a witness sealed into a hash chain. The witness replays bit-identical for any past decision and can be verified offline.
Policy and regulation are stored as versioned, provenanced nodes. A decision at a given date sees the rule version in force on that date, not the one current today.
domain specialists selected: credit, fraud subset
A mixture of domain specialists routes each decision through a small, named set of banking domain specialists. The inference records which domain specialists and which constraints fired, so the decision path is explicit rather than implicit.
The chain segment verifies without contacting us.
Pick one workflow, credit, KYC, AML, fraud, trade surveillance, or complaint resolution. Run it with your own sources and watch the review packet assemble as the work moves. Managed through Fabric on the public Dweve Mesh, on your own hardware, or air-gapped. No re-platforming between tiers.
It invents a rule instead of citing the one that fired.
A score is not a reason an inspector can read.
Foreign-hosted data fails the outsourcing rules.
A chat log will not replay the same way twice.
No more chasing the score, the rule, the override, and the context across four systems.
The policy in force on the day is the one attached to the decision, not the one current today.
The reviewer who signed off, the timestamp, and the decision state sit in the same view.
The supervisory answer is a retrieval, ready before Friday instead of rebuilt on Wednesday.
Why was the revolving credit limit increase on case 4f9e declined?
Choose the credit, KYC, AML, fraud, or complaint case the supervisor named.
Attach the applicant file and the policy version the decision used.
Source, rule, owner, and decision state are recorded as the work moves.
The same decision comes back bit-identical, in under a minute.
Netherlands base, EU-only data paths. Ready on day one, no infrastructure project required.
Think about how an inspector accepts a decision.
A risk score is not an answer you can read.
No clear way to reach a human who can look again.
Your financial data leaves the EU quietly.
Your statements feed a model built for someone else.
The bank writes its policies, following EU and national rules.
Your transaction or application is evaluated against those policies.
The decision and its reason reach you, and an officer reviews it.
It is kept for years and can be appealed on request.
Every output is a recommendation a person approves. You can ask why, you can appeal, and you can require a human review. The reason you get names the rule that was applied and the policy version behind it, not a score. Your appeal is logged like every other step in the case, your financial data stays inside Europe, and no model is trained on your finances.
The exact document and version the decision used.
The policy version in force on the decision date.