Cases from the MBA and the Vanguard · MBA module — when AI becomes the bank's primary checker (a Southeast European bank)
Subtitle: When AI becomes the primary checker, how much human control is still enough?
For years, the final check before a loan is disbursed has looked much the same. A Credit Operations employee opens the file and starts comparing: does the contract match the approval, is the customer’s personal data identical across all documents, is the ID still valid, are all required documents there and correctly classified, is the employer confirmation valid, and are the signatures and stamps where they should be?
The work is repetitive, but the responsibility is real. Most files are correct. The challenge is finding the one detail that is not.
There is still a lot of paper involved. In this Southeast European bank, regulation requires hard-copy credit documentation to be retained, so customers still provide a substantial part of the documentation in physical form even though much of the surrounding process is already digital.
The bank is now working on a different way to perform post-approval validation. The idea is to use AI to read scanned credit documentation, classify documents, extract relevant information and compare it with the approved loan conditions and system data. It could identify missing documents, inconsistent personal data, expired identification, mismatches between the contract and approval, or missing signatures and stamps.
The obvious first step is to use AI as an assistant. It checks the file, highlights potential problems, and the employee then performs the normal control. Everyone is relatively comfortable with that model, but it also changes very little. If a person still has to repeat everything AI has already checked, the bank has added technology without really changing the process. Processing costs remain largely the same, turnaround time improves only slightly, and experienced employees continue spending much of their day checking information that is correct almost every time.
The more interesting model is also the more uncomfortable one: AI becomes the primary verifier. It checks the entire file and presents the employee only with exceptions, uncertain cases and items specifically reserved for human review. If AI checks thirty items and identifies four problems, the human looks at those four. The other twenty-six are accepted because the system concluded that nothing required human attention.
That is where the discussion inside the bank changes.
Operations sees an opportunity to move people away from repetitive work and towards cases that genuinely need judgement. Customers could be served faster, while the process could become more scalable and consistent. Risk asks who owns the error when AI gets something wrong. Compliance and Legal point out that the physical file still matters and that AI can classify a document incorrectly, read personal data wrongly or conclude that a signature exists when it does not.
Internal Audit raises a different question: if a human no longer checks every file, how does the bank prove that the automated control itself is working properly?
Under the traditional model, the answer was intuitive: someone checked the file. Under the new model, the bank would have to monitor the system that performs the checking. That could mean independent samples, error-rate monitoring, false-positive and false-negative analysis, testing changes in document formats and validating whether the AI continues to behave as expected.
Human control would therefore not disappear. It would move to a different level.
There is also a quieter concern. An experienced Credit Operations employee today knows how to review an entire credit file. If people spend the next few years seeing only exceptions selected by AI, will they still develop the same knowledge? A manual fallback can remain written in a procedure while gradually disappearing as a real organisational capability.
The COO responsible for the process therefore sees three possible models. AI can remain an assistant while humans continue checking everything. It can become the primary verifier, with people handling exceptions and performing independent quality checks. Or the bank can gradually move standard cases towards almost fully automated post-approval validation, accepting a controlled level of residual error in exchange for lower processing cost, faster service and greater scalability.
The COO already believes AI belongs in the process. That is no longer the difficult decision. The harder question is when the bank should stop asking a human to repeat the machine’s work simply because that is how control has always been defined.
If the human only approves what AI has already decided, is that still meaningful human oversight, or only the appearance of it?
Open the discussion with one ordinary credit file. Assume that a Credit Operations employee currently performs thirty checks before disbursement. Then ask the table: “If AI performs all thirty and reports four exceptions, would you still require the employee to check the other twenty-six?”
If the answer is yes, ask what value the human is adding by repeating the same control. If the answer is no, ask who has actually performed the control and who owns the twenty-six items the human never saw.
I would first ask someone responsible for Operations or process transformation, then someone from Risk, Compliance or Internal Audit. The first person should answer whether they would trust AI as the primary checker once its performance reaches an agreed level. The second should define what evidence would be necessary before humans could stop repeating the control.
The fact most likely to change the room’s answer would be a comparison of AI and human performance on real historical credit files. The key question is not simply which is more accurate, but what each one gets wrong. Does AI miss different errors than people do? Are those failures predictable? What would be the legal, financial or customer impact of those errors? The acceptable model may depend less on how often AI is wrong than on what kind of wrong it can be.
Traditional banking control was designed around people performing work and other people checking it. AI changes that relationship.
The opportunity is not simply to perform the same control faster, but to redesign the process around continuous verification and exception-based work. The human role moves from checking every document towards governing the system, investigating exceptions and challenging whether the control itself can still be trusted.
The leadership challenge is therefore not choosing between humans and AI. It is deciding where each genuinely adds value, and having the confidence to remove human activity when it provides reassurance but no longer provides additional control.
The new control model begins when the bank stops asking “Who checked the file?” and starts asking “Why do we trust the way it was checked?”
A live case: every round can be improved, and the author's feedback is the next one.
The same two questions, answered twice: first without the mentor's corpus, then from it — the second volume's task map and HAI5, his Vanguard AI project, VIS, the first volume and his receipt design.
Without the mentor's corpus
1. When the bank can show, check by check, that the machine misses no more than the person it replaces, and that what it misses the bank can afford. Start with the human baseline the bank has never measured. This control is a textbook vigilance task: thirty items a file, on files that are correct almost every time. Norman Mackworth showed in 1948 that on such tasks people's detection falls within the first half hour. So run both on real historical files, the AI and the people, and count misses by type, not in total, as the moderator asks. Then stop the repetition class by class:
So the residual error is not one number for the bank. It is a price for each class: how often a miss may happen, multiplied by what it costs. Ask yourself: do I know how often my people miss today?
2. Three things must stay human, and repetition is not one of them.
Ask yourself: which of my controls could prove that it still works, and which only that it ran?
Sources: N. H. Mackworth, "The breakdown of vigilance during prolonged visual search", Quarterly Journal of Experimental Psychology, 1948; The Institute of Internal Auditors, "The IIA's Three Lines Model", 2020; R. Parasuraman and D. H. Manzey, "Complacency and Bias in Human Use of Automation: An Attentional Integration", Human Factors 52(3), 2010.
From the mentor's corpus
1. The mentor's second volume sorts this work before the bank does. Its task map puts low-context, high-repetition work in the Grind and says: move it to HAI5 Level 4, AI executes with human exceptions, "once the agent has earned the autonomy". Comparing thirty fields against the approval is the Grind. So the question is not whether, but how the autonomy is earned, and the mentor's Vanguard AI project, described in chapter 55, gives the path:
The residual error the bank accepts is written into that threshold, class by class, before anyone sees the numbers. One condition then decides which checks stay with a person: whether a miss can be undone. Where it can be corrected after the money is out, the machine may accept; where it cannot, a person still signs. Ask yourself: has my AI earned its level, or been given it?
2. The mentor's HAI5 framework was written for the case's last question. Teams that deploy AI without declared levels, his second volume says, drift into over-automation without noticing, and "errors of omission become un-assignable". Those are the twenty-six items nobody saw. So what stays human is declared, not assumed:
His first volume adds the rule for audit: "traceability requires capturing the trace at the moment of action, not reconstructing it from logs neither party independently trusts." So every automated check writes its trace as it happens. Ask yourself: if the supervisor asked tomorrow who checked a given file, could I answer with a record rather than a belief?
On the NEO Turn. The case's closing line asks why the bank should trust the way a file was checked. The mentor's receipt design for agents' actions answers with five questions: who acted, under what authority, on which policy, on which evidence, with what later verifiability. For a credit file:
Chapter 17 of this book states the principle behind it: the core attests; it never decides. The COO still decides. The receipt makes the decision provable.
Sources: Vanguard Leadership, vol. 2, the task map (the Grind; HAI5 Level 4 once the agent has earned the autonomy) and HAI5 (declared levels; errors of omission); the mentor's Vanguard AI project, Horizon Europe proposal (retrospective validation, shadow mode, an active pilot, GO/NO-GO); VIS in the mentor's doctrine for intelligence officers (kill indicators); Vanguard Leadership, vol. 1, p. 424 (the trace at the moment of action); the mentor's receipt design for agents' actions (Beautiful Mind); chapters 17 and 55 of this book.
Swedish breast screening has a four-eyes rule of its own: standard double reading, in which two radiologists read every mammogram. The MASAI trial asked this case's question of it. More than a hundred thousand women at four Swedish screening sites were randomised between standard double reading and a model in which an AI system reads first, sending low-risk examinations to one radiologist and high-risk ones to two. The final results, published in The Lancet in January 2026:
Three lessons carry to the bank.
The machine decides where attention goes, not whether there is any. Every examination was still read by at least one radiologist, and the authors say plainly that the study does not support replacing professionals. For the bank, the equivalent is not a person on four exceptions and nobody on the rest. It is a person on the exceptions and a lighter, blind check on a sample of the rest.
Safety first, then efficiency, each proven. MASAI published its safety analysis first, and the result on missed cancers only once the women had been followed long enough to know. The bank's switch should wait for the same kind of evidence: misses measured on files whose outcome is known.
Monitoring does not end. The authors' own condition is tested tools and continuous monitoring. In the bank, that is the blind sample every month, the error rates by class, and a retest whenever the document formats change.
Ask yourself: what would my bank's MASAI look like, and who would sign its protocol?
Sources: the MASAI trial in Sweden: K. Lång et al., the clinical safety analysis, The Lancet Oncology, 2023, and the final results on interval cancers, The Lancet, 29 January 2026.
A question for the table, a disagreement, what you would have done. The case lead reads every comment; the ones the table takes up enter the chapter as questions from the room, with your name.