For Banks & Financial Services

Where banks are stuck, and the moves.

The substrate is the differentiator now. Core modernisation, GenAI in customer journeys, supply-chain attestation, EU DORA operational resilience — the work is no longer about picking vendors. It’s about whether identity, observability, policy-as-code and audit are encoded properties of the platform, or theatre.

The regulatory floor — banking

  • APRA CPS 230 (operational risk management) · live in AU FS
  • APRA CPS 234 (information security) · auditable today
  • EU DORA (digital operational resilience) · enforced 17 Jan 2025
  • EU AI Act · high-risk obligations from 2 Aug 2026 (credit scoring → Annex III)
  • BCBS 239 (risk data aggregation) · the perennial benchmark
  • SLSA v1.0 + SSDF (SP 800-218) · the supply-chain attestation floor for vendor integrations

Working on this in Banks & Financial Services?

These are field notes on the patterns that recur in banking — standing up GenAI under the EU AI Act, hardening the supply chain for CPS 234, rebuilding the platform under DORA. If they’re useful, or you’d push back on them, I’m glad to compare notes.

   [email protected]
Also on this site