Case study · Govern · AI governance & security
From shadow AI to governed use at a Swiss financial services firm
How a regulated Swiss financial firm replaced shadow AI with a governed framework: inventory, risk tiers, controlled access and measured proof.
Anonymised case — representative example from real Numezis engagements
Starting situation
Consumer generative AI tools had spread through the teams without a single decision ever being made: drafting letters, summarising client files, preparing analyses. Nobody knew who was using what, or with which data. Until an employee pasted an end client’s data into a prompt — an incident caught just in time, and a revealing one: the risky path had become the default path.
Management’s first instinct was a total ban. Yet a ban would have solved nothing: usage would have migrated to personal devices, out of all visibility, and the firm would have lost what these tools were genuinely contributing. The board, for its part, was asking for neither a charter nor intentions: it wanted proof of control, in a business where pension data leaves no room for approximation.
The decision on the table
Ban AI and lose its useful work — or govern it, and make the safe path faster than the risky one?
Real constraints
Swiss financial regulation & nFADP
Regulated financial activities and personal data under the revised Swiss data protection act: every usage rule had to be written, traceable and defensible — not a mere internal recommendation.
Highly sensitive pension data
End clients’ pension data ranks among the most sensitive the firm holds. Its exposure to an unapproved tool was the scenario to rule out first.
A board demanding proof
The board of directors would not settle for a signed policy: it required evidence of control — inventory, controls, logs and indicators reviewed at fixed intervals.
No technology-risk culture
The firm managed its financial risks rigorously but had no formalised practice for technology risk. The framework had to be one the teams could own, not one imposed on them.
What we built
The architecture of this engagement is twofold: a governance framework and the access platform that makes it concrete. One principle held from the first day to the last: every use gets a risk tier, every tier gets proportionate controls — and the approved path must be faster than the workaround.
System components
Delivery sequence
Inventory & threat modeling 4 weeks
Team-by-team interviews and analysis of actual practice: 68 generative AI uses inventoried, the data involved mapped, leak and misjudgement scenarios modelled.
Framework, risk tiers & controls 4 weeks
Classification of all uses into four risk tiers, proportionate control matrix, usage policy drafted with external counsel, sign-off by management.
Governed access rollout 6 weeks
Approved tools deployed behind SSO with role-based permissions and usage logs; the two-speed approval process put into operation — the safe path made real.
Training & anchoring 4 weeks
Role-based training for users, approvers and management, internal publication of approval decisions, first full dashboard cycle, handover of the governance to the client.
Measured results
The starting point was a documented zero: no inventory, no controls, no approval process. The figures below measure what the framework made visible, then brought under control — including six months of operation after rollout.
Figures rounded. Anonymised case: a representative example drawn from real Numezis engagements, not a nameable reference.
What we would do differently
This section is part of our editorial standard: no case study without its lessons.
- 01
Start training before the access platform, not after it. Teams knew approved tools were coming, and the wait bred frustration; training during the rollout would have turned that delay into preparation.
- 02
Involve external counsel from the inventory phase, not only when drafting the policy. Two rounds of rework on the text would have been avoided had the legal constraints framed the classification from the start.
- 03
Publish approval decisions internally from day one. We started mid-engagement, and that transparency proved the real driver of adoption: everyone could see the process deciding quickly, and why.