Situation
A Swiss private bank engaged TSG on an internal-controls modernization programme. The written procedures existed but were partially outdated. The real operating knowledge lived in the heads of a small number of senior operators. Any AI initiative built on top of the documented process would automate a version of the work that had not existed in practice for years - and would inherit its blind spots.
- Regulated environment with strong controls expectations.
- Written SOPs partially disconnected from actual execution.
- Key operational knowledge concentrated in a few senior people.
Friction
The core friction was not technical. It was that no one could show, on paper, how each process actually ran end-to-end - with its exceptions, its escalation paths, and the controls that were being enforced in practice versus those that were only documented. Without that ground truth, no AI use case could be defensibly scoped and no risk owner would sign off on deployment.
- Gap between as-documented and as-run process.
- No single source-of-truth for controls actually enforced.
- Second-line functions unable to challenge deployments without that source of truth.
Intervention
TSG reconstructed the target processes from the documented sources - policies, procedures, control catalogs - rather than from interviews. Each activity, gateway and control was linked back to the source that justified it. A double human-in-the-loop review was applied: TSG validated internal consistency; the bank validated business truth. Only once this sourced ground truth existed were AI agents scoped on top of specific process segments.
- Process reconstruction from sources, not anecdotes.
- Each element traceable to a policy or a control.
- Double HITL: TSG-side technical review, bank-side business validation.
- Agent scoping only after ground truth was accepted.
Operating model
The resulting operating model has clear boundaries. Every BPMN version is immutable once approved. Any change requires a new version with its own approval trail. Agents may act only on segments explicitly whitelisted, with hard-enforced boundaries at runtime. Second-line functions have a direct read on the whole audit trail. Retirement of a component is as designed-in as its deployment.
Evidence
The evidence we track is not model accuracy. It is whether the second-line function can sign off on a deployment without a special exception, and whether new joiners can be onboarded on the sourced process rather than on tribal knowledge. Both of these were previously not achievable. Both now are. Quantified client outcomes are intentionally not disclosed in this brief.
Cas d’usage et impact
No sourced ground truth on how regulated processes actually run, blocking any defensible AI deployment.
Solution: Forensic BPMN reconstruction from documented sources with double HITL, followed by scoped agent deployment on segments with explicit runtime boundaries.
- Sourced ground truth: Partial
- Second-line sign-off on AI initiatives: Blocked
- Onboarding on written process: Not viable
- Sourced ground truth: Complete on pilot processes
- Second-line sign-off on AI initiatives: Standard workflow
- Onboarding on written process: Viable
FAQ
Why not just interview senior operators?
Interviews capture what people remember. A sourced reconstruction captures what the policies and controls actually require. The gap between the two is exactly where the value of the exercise is.
How is this different from a classic process mapping exercise?
A classic mapping produces a diagram. A forensic reconstruction produces a diagram whose every element is traceable to a source, and which is designed from the start to be the substrate for governed AI agents.
What is the board-level question this answers?
Can we deploy AI on our regulated processes without inheriting years of implicit drift? The answer is only defensible when the ground truth of those processes has been rebuilt from the sources first.
Conclusion
Any AI initiative in a regulated environment starts, or should start, with the same discipline: reconstruct the work from the sources, expose the gaps, and only then decide where an agent can safely act. It is slower than a demo. It is what survives an internal audit.