AI & Banking

When AI Reviews AI: A New Control Layer for Banks

How banks can control AI outputs before delivery with an independent evaluator, policy gate, human escalation and robust evidence.

acceleraid Redaktion

4 min read

Bank AI reviewed by an independent digital control layer before delivery

Banks increasingly use generative AI where answers must be produced quickly: customer service, document review and decision preparation. This creates a new control problem. A response can sound professionally credible while being wrong, incomplete or outside policy. Sampling outputs after delivery is no longer enough.

Hang Seng Bank is therefore testing a practical principle in Hong Kong’s GenA.I. Sandbox++: AI reviewing AI. An independent evaluator does not replace rules or people. Properly embedded, however, it can identify defects before a response reaches a customer or an employee relies on a faulty summary.

Two pilots, one control principle

In retail banking, an “AI Judge” is intended to review responses from a generative service chatbot before content is delivered. According to the description of Hang Seng’s two pilots, the control is designed to support more accurate, appropriately toned and compliant answers. One AI system reviews, challenges and validates another system’s output.

The second pilot covers commercial onboarding and due diligence. Generative AI will check business information across several dimensions, identify early warning signs and produce an auditable summary. Humans retain control of final decisions. In both cases, the objective is not maximum autonomy but an additional control layer between generation and consequence.

The institutional setting matters. Hong Kong’s financial regulators launched Sandbox++ jointly. Participating firms receive targeted supervisory guidance, technical support and access to computing resources in a controlled environment, as the Hong Kong Monetary Authority explains. A pilot does not prove production readiness, but it creates a setting in which value and control limits can be tested together.

A practical four-layer pattern

A robust design separates four functions:

  1. Generator: The first model drafts an answer, extracts information or prepares a case summary. It receives only the data and tools required for that task.

  2. Independent evaluator: A second system assesses the output against defined criteria such as factual accuracy, completeness, permitted claims, tone and supporting evidence. It returns reasons and confidence, not merely a pass or fail.

  3. Deterministic policy gate: Hard rules determine whether the output is released, blocked or escalated. Mandatory wording, prohibited claims, permissions, thresholds and data classifications belong in inspectable code, not in a language model’s discretion.

  4. Human escalation: Ambiguous, conflicting or consequential cases go to qualified employees with context. The reviewer sees the generated output, evaluation, applied rule and relevant evidence instead of rebuilding the case.

This separation prevents one model from producing content, grading itself and authorising release. It also reflects the direction described by the Financial Stability Board. As Reuters reported, the global standard setter called for clear boundaries, embedded safeguards and human approval for high-risk actions, including financial transactions above defined thresholds.

The evaluator is not an oracle

A second model can share the first model’s error. That risk is pronounced when both use the same model family, similar data or similarly written prompts. An evaluator may also reward confidently expressed mistakes, miss rare customer situations or be influenced by manipulated inputs. A green result is evidence that a check occurred, not a guarantee that the answer is correct.

Independence therefore needs an operational definition: separate roles and prompts, independent versioning, preferably different failure profiles, and no generator access to the evaluation logic. Calibration should compare evaluator judgements with a reference set labelled by subject-matter experts. False releases and unnecessary escalations should be measured separately; an evaluator that blocks everything may be safe but has little operational value.


Four control layers for AI outputs in banking

Evidence turns checks into a control system

Each run should record the model and prompt versions, available sources, criteria applied, policy decision and any human intervention. Sensitive content requires proportionate retention, access controls and data minimisation. Auditability does not mean storing every prompt indefinitely.

Before production, banks should test the combined system adversarially: conflicting documents, omitted facts, prompt injection, misleadingly confident language, language changes, and edge cases from complaints or onboarding. After launch, monitoring and drift detection become essential. Release rates, false releases, escalation reasons, handling time and disagreement between evaluator and human show whether the control continues to work.

The second line shifts human effort from broad checking to focused judgement. That is an improvement only when escalations arrive in time, employees have real authority and their corrections flow back into tests and calibration. AI-versus-AI is therefore not a substitute for accountability. It is a scalable way to prepare the decisions for which people remain accountable.

Five takeaways

  1. AI outputs that affect customers or decisions need a control layer before delivery.

  2. The generator, independent evaluator, deterministic policy gate and human escalation should remain technically distinct.

  3. An AI Judge can be wrong, making independence, calibration and different failure profiles essential.

  4. Versions, criteria, rules, evidence and human decisions must be logged in a reconstructable form.

  5. Adversarial testing and continuous monitoring determine whether the control remains reliable as systems change.

Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.

We use cookies 🍪

Strictly necessary cookies, such as for Pipedrive forms, remain active. With your consent, we also use Google Analytics for analysis and Leadfeeder for visitor identification. You can find further information in our privacy policy.

Decline

Accept all