Controls at Scale
2026 FinTech Summit case competition
1stplace
A hybrid AI and human framework for validating a bank's internal controls when more and more of its systems are AI. First of 15 teams from universities across the GTA.

- Active controls at the case bank
- 10,400+Active controls at the case bank
- Missing an owner, frequency, or evidence
- 41%Missing an owner, frequency, or evidence
- Of its GenAI systems with no mapped controls
- 77%Of its GenAI systems with no mapped controls
- Control testing coverage at the start
- 8%Control testing coverage at the start
Thousands of controls, and no way to see which ones worked.
The case bank, Northfield Bank, had thousands of controls but no reliable way to know which were complete, which were tested, and which covered its new AI systems.
A seven-step pipeline where AI scores and humans decide.
We designed a Control Intelligence Layer: ingest and normalize control data, score each control on a five-part rubric, triage into pass, remediate, or escalate, rewrite weak controls with AI while keeping the originals, route them through tiered human review, map every AI system against its controls to find gaps, and keep re-scoring continuously instead of auditing once a year.
Humans stay responsible for judgment. The review step includes a check that reviewers are actually evaluating rather than approving by default.
A prototype on cloud infrastructure.
The prototype ran the pipeline with AI models: simulated large-scale ingestion, automated scoring, AI-drafted remediation, and a feedback loop. Against the case data, the model projected testing coverage rising from 8% to 30% and data completeness from 59% to about 95%.

