Skip to content
Amula AI
AI16 August 20266 min read

Is your institution ready for AI? A readiness assessment for regulated finance

An AI readiness assessment for a regulated institution comes down to five dimensions — each with the failure mode that tells you you're not ready yet.

By Rinor Recica

Before an institution automates anything, there is a question worth more than any vendor pitch: is it actually ready? Most AI initiatives that stall in regulated finance do not fail on the technology — they fail because the organisation was not prepared to absorb it, and no one asked the question honestly before the budget was committed. An AI readiness assessment is that honest question, made systematic. For a FINMA-regulated institution it comes down to five dimensions — governed data, documented workflows, senior sponsorship, a measurable target, and the capacity to absorb change — each with a failure mode that tells you plainly you are not ready yet. Score yourself against all five before you score a single vendor.

The first dimension is governed data. AI does not fix a broken data foundation; it inherits it, and in a regulated process it inherits the audit exposure too. The question is not whether you have data — every institution does — but whether it is clean, current, and traceable to a source you can defend. You are not ready if the numbers that feed a report live in a spreadsheet no one fully trusts, if the same figure carries two values in two systems, or if you cannot say where a data point came from without asking three people. Fix the lineage first; an automation built on unreliable inputs simply produces unreliable outputs faster, and does so with the appearance of authority.

The second is documented workflows. You cannot automate a process you cannot describe, and the act of writing one down end to end — every input, every control point, every sign-off, and the person who owns each — is where most of the real work turns out to live. You are not ready if the workflow exists only in the head of one senior person who has run it for years, if "how the reporting actually gets done" has never been mapped, or if the exceptions are handled by tacit judgment no document captures. The institutions that automate well are usually the ones that were already close to documenting the process anyway; the discipline of description is the discipline the automation depends on.

The third dimension is senior sponsorship with named accountability. A regulated automation touches a controlled process, so it needs an owner senior enough to sign off on the change and to answer for it afterwards — not a working group, and not enthusiasm scattered across three departments. You are not ready if the initiative is a bottom-up experiment no one at the top has staked their name to, if the sponsor cannot articulate the specific outcome they are accountable for, or if the person who would own the automation after go-live has not yet been named. In regulated finance an unowned process is a finding waiting to be written; sponsorship is what turns an experiment into an accountable programme.

The fourth is a measurable target — a baseline you can prove and an outcome you can name. An AI readiness assessment is impossible without a starting point, because a workflow with no measurable baseline can never demonstrate its return, detect a regression, or answer the first question an internal auditor asks. You are not ready if the goal is "become more efficient" rather than a specific number — the multi-day cycle time you intend to compress, the exception rate you intend to lower, the manual touches you intend to remove. Pick the one workflow whose baseline you can measure today, and you have found not just a target but the right place to start.

The fifth dimension is the capacity to absorb change — the one most institutions overestimate. Automating a regulated workflow is not a single switch; it is a parallel run where the new process operates alongside the old until reconciliation holds, a stretch of added review before the saving arrives, and a gradual expansion from one reviewer to the team. You are not ready if the team has no slack to run two processes side by side for a season, if the culture carries a history of cancelled roll-outs, or if "go live" is imagined as a date rather than a controlled transition. Budget honestly for the period where the parallel run costs more than it saves before the curve turns — an institution that has planned for it reads the dip as expected rather than as failure.

None of this requires a perfect score. Readiness is rarely uniform — one workflow will be well-governed, well-documented, and owned, while another is none of those things — and the assessment's real value is telling you where to begin, not whether to begin at all. Start where you score highest: the single workflow with clean data, a mapped process, a named owner, and a provable baseline. That is exactly how reporting across 39+ funds at a leading Zurich investment foundation began — not as an institution-wide transformation, but as the one process that was most ready, measured and proven before the next was attempted. If you want that read done rigorously rather than by instinct, an AI Audit is where it starts. It is the same discipline that runs through everything we build: begin where the baseline is provable, measure it, and let the proven case fund the next one.

See what your reporting could look like automated.