BFSI · AI SECURITY & GOVERNANCE SIMULATION

The AI decision your people make today, made here first.

Real banking work where an AI tool sits in the workflow. Every decision is scored. Every consequence plays out.

Why it feels different

Not a course. A working bank.

Nobody watches a video. They log into what looks like their own system and do their job.

Real work, not exercises

The queue is full of legitimate items built to the same quality as the one that matters. Finding it is the work.

Evidence, or the score says so

Every artefact is a real artefact. Configs are well-formed, logs filter, agreements are full documents. Whether the critical one was opened before deciding is recorded.

Consequences, then containment

A wrong call doesn’t end the simulation. It becomes the incident the participant has to contain, escalate and report.

Rules, not reminders

Each simulation ends in one control statement the bank adopts. Every rule is tested more than once across the library.

How a simulation runs

Three screens. One decision each.

Recognition is the first screen. Handling is the other two.

01

The task

An ordinary job with a deadline. Nothing is flagged. The participant opens what they choose to open, takes a real action, and records why.

02

The consequence

The decision plays out as a system event, not as feedback text. A DLP alert. A settled payment. An audit finding with their name on it. Then they have to deal with it.

03

Report and prevent

Who gets told, within what window, what gets preserved rather than deleted, and what standing control stops it happening again.

A wrong first call caps the score. It doesn't end the simulation — handling your own mistake correctly is most of the value.

Simulation library

The simulation library.

Every one is an ordinary banking task with an AI tool inside it. None of them test the underlying discipline.

A

Customer-Facing Operations

Branch, contact centre, relationship management

  • The complaint bundle
  • The ticket that instructs the assistant
  • The client note
B

Technology, Change & IT Operations

Developers, reviewers, change and access approvers

  • The generated pull request
  • The dependency that does not exist
  • The automation that reports itself
C

Payments & Authorisation

Payment desk and payments operations

  • The instruction that came by voice and video
  • The instruction from an internal automation
D

Governance, Registration & Model Risk

Vendor risk, procurement, legal — and two from a manager's chair

  • The vendor pack
  • The renewal that quietly added AI
  • The unregistered process
  • The output nobody reviewed

Participant journey

From first click to a decision record.

1

Create your profile and function

2

Enter the console for your seat

3

Take the work item as it comes

4

Open the evidence — or don’t, and it shows

5

Act, and record why

6

Live the consequence

7

Contain, escalate, report

8

See where you stand by category

For leadership

What you hold at the end.

Not an attendance sheet.

1

A control rule set in force — written so your audit function can test against it

2

Readiness by function and category — where technology is strong and vendor risk is thin

3

Every decision with its reasoning — captured in the queue where it arose, exportable

4

A named gap list — the specific categories and cohorts to fix next

5

A reconciled, tamper-evident record — scores cross-checked, discrepancies flagged

This measures human decision capability in AI security and governance. It is one indicator. It is not a measure of your institution's overall AI risk posture.

Bring one queue.

Pick the queue where AI already touches a decision. Run your team through it and see what your record looks like.