All case studies

Case study · Govern · AI governance & security

From shadow AI to governed use at a Swiss financial services firm

How a regulated Swiss financial firm replaced shadow AI with a governed framework: inventory, risk tiers, controlled access and measured proof.

Anonymised case — representative example from real Numezis engagements

Consumer generative AI tools had spread through the teams without a single decision ever being made: drafting letters, summarising client files, preparing analyses. Nobody knew who was using what, or with which data. Until an employee pasted an end client’s data into a prompt — an incident caught just in time, and a revealing one: the risky path had become the default path.

Management’s first instinct was a total ban. Yet a ban would have solved nothing: usage would have migrated to personal devices, out of all visibility, and the firm would have lost what these tools were genuinely contributing. The board, for its part, was asking for neither a charter nor intentions: it wanted proof of control, in a business where pension data leaves no room for approximation.

The decision on the table

Ban AI and lose its useful work — or govern it, and make the safe path faster than the risky one?
01

Swiss financial regulation & nFADP

Regulated financial activities and personal data under the revised Swiss data protection act: every usage rule had to be written, traceable and defensible — not a mere internal recommendation.

02

Highly sensitive pension data

End clients’ pension data ranks among the most sensitive the firm holds. Its exposure to an unapproved tool was the scenario to rule out first.

03

A board demanding proof

The board of directors would not settle for a signed policy: it required evidence of control — inventory, controls, logs and indicators reviewed at fixed intervals.

04

No technology-risk culture

The firm managed its financial risks rigorously but had no formalised practice for technology risk. The framework had to be one the teams could own, not one imposed on them.

What we built

The architecture of this engagement is twofold: a governance framework and the access platform that makes it concrete. One principle held from the first day to the last: every use gets a risk tier, every tier gets proportionate controls — and the approved path must be faster than the workaround.

System components

Four-tier risk classificationEach of the 68 inventoried uses classified by the data it touches and the impact of an error or a leak
Proportionate control matrixControls matched to each risk tier — from awareness to strict prohibition, without over-controlling low risk
Signed usage policyShort, concrete rules signed by every employee — what is allowed, with which data, in which tools
Two-speed approval processFast-track under 48 hours for low-risk uses, deeper review for the rest — speed as the incentive to declare
Governed AI accessApproved tools behind SSO, with role-based permissions and usage logs — the safe path, without added friction
Governance dashboardMonthly indicators for management: uses, approvals, incidents, deviations — the proof of control the board asked for
01

Inventory & threat modeling 4 weeks

Team-by-team interviews and analysis of actual practice: 68 generative AI uses inventoried, the data involved mapped, leak and misjudgement scenarios modelled.

02

Framework, risk tiers & controls 4 weeks

Classification of all uses into four risk tiers, proportionate control matrix, usage policy drafted with external counsel, sign-off by management.

03

Governed access rollout 6 weeks

Approved tools deployed behind SSO with role-based permissions and usage logs; the two-speed approval process put into operation — the safe path made real.

04

Training & anchoring 4 weeks

Role-based training for users, approvers and management, internal publication of approval decisions, first full dashboard cycle, handover of the governance to the client.

Measured results

The starting point was a documented zero: no inventory, no controls, no approval process. The figures below measure what the framework made visible, then brought under control — including six months of operation after rollout.

BeforeAfter
AI uses inventoried068
Uses covered by a proportionate control0%100%
Approval time for a new low-risk useno process< 48 h
Data incidents since rollout0 in 6 monthswith active detection in place, not mere absence of reports
Estimated ungoverned usebaseline−80%anonymous internal survey

Figures rounded. Anonymised case: a representative example drawn from real Numezis engagements, not a nameable reference.

This section is part of our editorial standard: no case study without its lessons.

  1. 01

    Start training before the access platform, not after it. Teams knew approved tools were coming, and the wait bred frustration; training during the rollout would have turned that delay into preparation.

  2. 02

    Involve external counsel from the inventory phase, not only when drafting the policy. Two rounds of rework on the text would have been avoided had the legal constraints framed the classification from the start.

  3. 03

    Publish approval decisions internally from day one. We started mid-engagement, and that transparency proved the real driver of adoption: everyone could see the process deciding quickly, and why.