VIRTICUSDiscuss your situation

AI & Automation

AI and automation that takes work off your team and holds up at audit

For the operations, risk, or technology lead at a UK regulated firm who wants manual decisions taken off a team without losing the record of how each one was made. We build AI, agents, and automation that run in your own environment, live in weeks. Every run is traceable and reproducible, with a named owner and a person who can override it, so the record is already there when an auditor, a regulator, or a customer asks how a decision was reached. A first sprint is one to two weeks at £6,000–£25,000 + VAT, fixed.

Built by practitioners who have done this work inside banks and regulated firms.

If getting an AI or automated decision wrong would be expensive, regulated or not, this applies.

Decision Pipeline

Running

Decision requested

Input received & logged

Pending

Agent reasoning

Steps recorded, not hidden

Pending

Policy & control check

Checked against the rules

Pending

Human oversight

Overridable checkpoint

Pending

Immutable decision log

Reproducible, audit-ready

Pending

Every automated decision leaves a reproducible trail — reasoned, policy-checked, and human-overridable — so it is evidence prepared for regulatory, audit or litigation scrutiny.

The shift

AI is in the decision now, not beside it

Agents and automation increasingly make or shape decisions that used to need a person. When one goes wrong, the cost — and the question of who was accountable — lands on the business.

The gap

Speed outran the evidence

Teams ship AI that works in the demo but cannot show how a given decision was reached, who owned it, or that a person could override it. The evidence a regulator or customer later asks for was never captured.

The standard

Built the same way, every time

Every workflow is built the same way: traceable, reproducible, and human-overridable, so each decision leaves a record you can show. The record is not a document written afterwards; it is what the build leaves behind.

What we build

One method, two ways to start

Every engagement is built the same way: working automation, traceable from input to decision, documented as it is built. Start small and fixed, or move to ongoing embedded delivery.

Sprint · fixed scope

Audit-Ready Automation Sprint

One real workflow live in weeks, taking a manual step off your team. Every run is logged, with a person on the oversight checkpoint, so it stands up to internal audit, a regulator, or a customer challenge. For any regulated or high-stakes team; FCA regulation is not required.

  • One workflow, connected to one system, up to three decision points
  • Deterministic, reproducible decision log
  • One-page control note

One to two weeks · £6,000–£25,000 + VAT, fixed

View the sprint scope

Retainer · recurring

Embedded AI Build & Governance

An embedded build team that moves more of your workflows onto agents and automation, and keeps them in good order as they change — ownership, review, escalation, human-oversight design, and the documentation an auditor asks for.

  • Ongoing build embedded alongside in-house teams
  • Maintained governance & control pack
  • Mapped to the UK regime

Ongoing · £5,000–£15,000 a month + VAT, embedded

Discuss your situation

Financial Crime is a separate service for the Head of Fraud or MLRO.

For legal and investigation teams: evidence analysis, fraud and forensic expertise, loss modelling, and legal AI and automation are on Legal & Forensic.

How we deliver

We design, build, deploy, and test it — not just document it

This is implementation, not paperwork. The documentation is what the build leaves behind — the work is a working system, delivered into your environment and tested against real cases. Every engagement runs the same five steps.

01

Discovery

We scope the decision rather than the task: the workflow, where it decides something, the scrutiny it has to survive, and the regime that binds it.

You receive: A fixed scope and the standard of evidence it must meet, agreed before any build starts.

02

Design

We design the decision path before we write it: inputs, the reasoning steps, the human-oversight checkpoint, and the record each run leaves.

You receive: A decision design a reviewer can read and sign off.

03

Build

We build the automation or agent workflow in your environment, connected to one system, with deterministic, reproducible logging baked in from the first line.

You receive: Working automation running on your data, not a slide deck.

04

Deploy & test

We deploy behind a human-oversight checkpoint and test it against real cases. The same inputs produce the same decision every time, with a person able to override.

You receive: A live workflow with a tested, reproducible decision log.

05

Assure & hand over

We leave the evidence and hand it across: the decision and audit log, a plain-language control write-up, and a working session with the people who will run it, so your team owns it and can change it without us.

You receive: A record built to the standard an auditor, a regulator, or a customer challenge asks for.

Built to the UK regime

Built to the obligation that actually applies to the decision

We do not certify the whole organisation — we build and deliver a single workflow that is traceable and built to the record an auditor asks for, mapped to the obligation that actually reaches it. UK firms today; work elsewhere is done with partners where a client needs it.

Financial conduct

FCA expectations where an automated decision reaches a customer — Consumer Duty outcomes, Senior Managers and Certification Regime (SM&CR) accountability for who owns the decision, and the record that shows what a model actually decided.

Data and automated decisions

UK GDPR as it now stands: significant decisions taken with no meaningful human involvement carry information, representations, human intervention and the right to contest. Whether a deployment is solely automated is a fact about the process, and we establish it rather than assume it.

Prudential and model risk

PRA SS1/23, the supervisory statement on model risk, where it binds — identification and tiering, governance, development and use, independent validation, and the mitigants a model runs under. Firms outside its scope get the same discipline as a standard they chose, which changes who signs.

See the method run

This one can be shown to you, running

Everything above is a claim about how automated decisions should be built. This one is built, and it can be shown to you running. On the case we walk through, it declines to reach a conclusion, because the evidence in front of it will not support one. That refusal is the product working, not failing.

POCA 2002 Part 7

SAR Assessment and Escalation

The failure-to-disclose clock starts at knowledge or suspicion, not at the point someone gets to it.

What you would watch

The case it refuses to conclude.

Ask to see it run →

The automation behind it is a financial-regulation check — what it demonstrates is the mechanism above, running on a real rulebook. It is shown by invitation and walked through with you, because the cases inside it are constructed for the demonstration. Illustrative cases are here.

Start here

Pick one workflow; we automate it and show it holds up

A short call is enough to scope a fixed-price sprint. Or run the free decision-rule check first: up to ten questions about one automated rule, and where its record is thin.