The hardest part of any automation programme is not the technology; it is the sequencing. For a FINMA-regulated institution, the instinct to automate a business process with AI in one ambitious push is exactly what produces a stalled flagship and a nervous board. Ninety days is enough time to take a single workflow from a messy manual routine to a measured, audited process in production — but only if the ninety days are structured. The structure that works is four phases, each two to four weeks, and each ending not in a status update but in a decision gate that is allowed to say stop. A phase that cannot be halted is not a gate; it is a slope.
Days 1 to 14 are the process audit, and they are the phase most teams skip to their cost. The work here is not choosing a tool — it is mapping the workflow exactly as it runs today, naming every control point and the person who owns it, and capturing the baseline: the cycle time, the exception rate, the count of manual touches between the data and the investor. Do it during a parallel observation, while the current process runs, so the numbers are real rather than remembered. The deliverable is a documented current-state process with a measured baseline. The gate is a single question: can we prove this baseline? If the workflow has no measurable starting point, it goes back into discovery until it has one — because without a baseline you can never prove the return, detect a regression, or answer the first question an internal auditor will ask.
Days 15 to 30 are for the approach decision and a proof of concept. First, decide build versus buy on the terms that matter in regulated finance — data sensitivity and auditability, not the sticker price — and confirm where the data goes before anything touches it. Then build a deliberately narrow proof of concept against representative data, with three success criteria and, just as important, the kill criteria defined in advance. A proof of concept validates feasibility; it is not a pilot and not a commitment. The deliverable is a POC verdict measured against those pre-set criteria. The gate: did it clear the bar you set on day fifteen? If it did not, you have spent two weeks to avoid spending six months on a workflow that was never going to pay — a good trade, not a failure.
Days 31 to 60 are the build and integration, and this is where discipline separates a durable process from a demo. Build inside your own environment, on the stack you already license, with the calculation kept deterministic and auditable and the model sitting around it rather than inside it. Design the parallel run first: the new workflow produces its output alongside the old one, not instead of it. Wire in the three things a compliance officer will actually ask for — a review checkpoint above a confidence threshold, logging that lets the process reconstruct itself after the fact, and a rollback that a human can trigger without a scramble. The deliverable is a working workflow running in parallel. The gate is reconciliation: does the automated output match the manual process within tolerance, run after run? Until it does, nothing goes live.
Days 61 to 90 are rollout, measurement, and iteration — done gradually, never as a single switch. Expand from one reviewer to the team in steps, keep the parallel run until the reconciliation holds, and measure the result against the day-zero baseline rather than against a feeling. Budget honestly for the second-month dip: there is a predictable stretch where the parallel run and the added review cost more than they save, before the curve turns, and a board that has been warned reads it as expected rather than as failure. The deliverable is the workflow in production, owned by a named senior, with a measured improvement over the baseline. The final gate: does the proven result beat the baseline, and would it survive an audit unassisted? Only a yes to both ends the ninety days.
The decision gates are not bureaucracy bolted onto the plan; they are the plan. Each one gives the institution a clean, defensible place to stop — after the audit, after the proof of concept, after reconciliation — before the spend compounds. That is precisely how reporting across 39+ funds at a leading Zurich investment foundation was built: not as a single transformation, but as one narrow workflow taken through exactly these gates, its compressed cycle time measured against a real baseline, and only then extended to the next. The gates are what let a regulated institution move quickly without moving recklessly.
None of this is glamorous, and that is the point. To automate a business process with AI in regulated finance is not a technology project with a governance afterthought; it is a governance discipline that happens to use technology. Start with the one workflow whose baseline you can prove, run it through the four phases, and let each gate earn the next. When the ninety days close on a measured, audited process in production, you have not just automated a workflow — you have a template, and a proven case that funds the one after it. That is the same discipline that runs through everything we build.
