
.png)
Talk to the COO of almost any UK or European mid-market bank, payments business or wealth manager this year, and you'll hear a version of the same complaint. Compliance headcount is growing faster than revenue, because the volume of financial-crime alerts, onboarding checks and regulatory reporting has outpaced what a lean team can absorb by hand.
That's the real starting point for the AI conversation in financial services. Not "what tool should we buy," but "how do we stop hiring our way out of a scaling problem we could engineer our way out of instead."
I've spent 25 years across EMEA helping engineering, product and business leaders turn ambition into results that actually land, not slideware that stops mattering the moment the project closes. The pattern I keep seeing this year in financial services holds up across the 70-plus documented cases we've run and the 800-odd people at Forte doing this work day to day: the mid-market firms making genuine progress with AI treat it as an operating problem across the whole business.
Three pressures tend to show up together on the desk of a financial services leader right now, and they rarely get solved by the same team.
The first is compliance and risk: alert volumes rising while review quality falls, onboarding still taking days in a market that increasingly expects minutes, and regulatory reporting assembled by hand every month. The second is commercial: onboarding and quote journeys leaking revenue before it's ever booked, partner and embedded distribution that's genuinely hard to onboard, and pricing logic so hardcoded that a change takes a quarter instead of a day. The third is engineering: delivery velocity that stays flat despite growing spend, a legacy core that constrains every new product, and UK engineering hiring that's competitive and slow at exactly the level firms need.
None of these are solved by a single tool. They're solved by rebuilding how work moves through the business, with AI, CRM and delivery discipline embedded in the process rather than layered on top of it.
The firms getting ahead treat all three of those pressures as one problem, and it shows in a consistent set of moves.
On compliance and risk: agentic triage on financial-crime alerts, with human reviewers spending their time on the exceptions that actually need judgment; document and identity extraction automated end to end at onboarding, so "days" becomes "minutes" without loosening the controls a regulator will ask about; and a baseline captured before AI touches a process, with the delta reported to the board every quarter, so "AI ROI" is a number, not a slide about tool adoption.
On the commercial side: pricing and product configuration that ships changes in days, not quarters; partner onboarding turned into a self-serve portal instead of a manual process that gates every new distribution relationship; and one customer record across sales, service and compliance, so those three functions stop working from different versions of the truth.
On engineering: delivery baselined, then AI embedded phase by phase across the lifecycle, rather than dropped in all at once; and compliance and reporting work automated specifically so it stops consuming roadmap capacity that should be going to product.
None of that happens by buying a platform and hoping the org adapts around it, which is why I'd rather talk about how we actually work with clients than leave this as a list of good intentions.
Every Forte Group engagement starts with a current-state baseline, typically two to three weeks, before a line of code changes. That's what makes the board conversation possible later: you can't report a delta you never measured. From there, whatever we build, whether it's the alert triage, the onboarding automation, or the CRM and CPQ work behind the commercial fixes above, runs on the architecture it will use in production from day one. No throwaway proof of concept, no separate rebuild once it works. Agentic components carry human-in-the-loop supervision and a full audit trail by default, because in a regulated environment that's the difference between a system that survives an FCA conversation and one that doesn't. And you own what gets built: source code delivered, data stays in your environment, any underlying model swappable without a rearchitecture.
The engineering-capacity side of this works the same way. Rather than a fixed team you either have or don't, delivery scales from two engineers to a hundred as the plan changes, with genuine UK and EMEA timezone overlap rather than a handoff to a different shift. Where a Build-Operate-Transfer model fits better than a permanent team, that's on the table too, with a proper transition plan rather than a vague promise to hand things back eventually. On the commercial side, that same discipline runs through ForteNext, which is our Salesforce practice: 60 implementations and 54 long-term B2B partnerships, so the CPQ and partner-portal work sits inside the same delivery model as the AI and data work, not a separate vendor relationship with its own risk profile.
I'd rather be candid about where this breaks than pretend it's risk-free, because the failure modes are specific and avoidable if you design for them up front.
Model decisions that can't be explained when a regulator asks. Whether it's the FCA in the UK or a national regulator working from EBA guidance across the EU, "the model said so" isn't an answer, and firms that bolt AI onto legacy decisioning without an explainability layer tend to find that out at the worst possible moment.
Customer data leaving the estate through tools nobody approved, or regulated data landing in a CRM without the controls that should have gone in at design time. Both are entirely preventable with governance built into delivery from the start, not audited in afterwards.
Token and inference cost scaling with transaction volume rather than margin. This is a genuinely new cost category. Firms that don't model it before scaling an AI workflow tend to discover it's quietly eating the efficiency gain they were chasing.
Test coverage falling as AI-generated code volume rises, or proofs of concept built on architecture that was never going to reach production. AI can accelerate a delivery system, but it accelerates whatever is already there, including the parts that were already broken.
Mid-market financial firms across the UK and EU are navigating this under a heavier regulatory load than most US peers, and with a fraction of the compliance budget of a tier-one bank. DORA is now live for EU financial entities and treats AI-driven operational processes as part of resilience testing, not a side conversation. The EU AI Act classifies credit scoring and several fraud and AML use cases as high risk, with real obligations attached. The FCA's Consumer Duty already expects UK firms to be able to explain outcomes that affect customers, model-driven or not. The same logic applies to PE-backed fintech and payments platforms carrying a value-creation plan that assumes AI benefits nobody has actually priced yet.
None of that is a reason to slow down. It's a reason to build governance into the engineering from the start rather than retrofitting it after something goes wrong.
At Xceptor, embedding AI across the full engineering lifecycle took requirement rework from 30% down to under 10%, and cut the time from requirement to production to a day and a half. At OppFi, a pre-IPO fintech under real delivery pressure, the same discipline shipped five independently valuable products in nine months at a 100% sprint commit rate, and drove a 400% improvement in DevOps velocity.
At BMO, business continuity reviews now run 40% faster. On the commerce and CRM side, Jifiti runs BNPL and payments orchestration at 99.99% uptime, and Discover worked with us to build a genuine product-ownership operating model rather than a one-off delivery. None of these were pilots. They were production changes, measured.
If you're leading a financial services or fintech business in the UK or wider EMEA and this sounds familiar, three questions are worth asking this quarter:
I’d be interested in hearing about the specific challenges you’re working through. If any of this aligns with what your board is looking to see, let's talk.