The AI Operational Gap in BFSI: Why AI Strategies Are Failing To Deliver Business Value

Mark Westbrook

September 04, 2026

The AI Operational Gap in BFSI: Why AI Strategies Are Failing To Deliver Business Value

Key Takeaways

AI is no longer a future-facing ambition for payment institutions. It is already present in boardroom priorities, transformation roadmaps, vendor propositions, and risk discussions.

The evidence is moving beyond adoption. The World Economic Forum's 2026 AI Playbook for Financial Services argues that financial services firms are shifting from experimentation to scaled deployment, with the central challenge becoming how to integrate AI with both urgency and discipline.

The Financial Stability Board's 2026 consultation on responsible AI makes the same point from a risk perspective. Financial institutions are using AI to transform operations and services, but rapid adoption can also amplify risks that need to be managed through organisation-wide governance across the AI lifecycle.

The market no longer has an AI capability gap.
It has an AI operationalisation gap.

The question is not whether AI can support payments. It can. The real question is whether banks, payment schemes, PSPs, and market infrastructures can deploy AI safely, at scale, within governance frameworks, and connect it to measurable business outcomes.

ai-operational-gap-1

AI pilots are not operational AI

Most payment organisations have no shortage of AI use cases: fraud detection, alert triage, payment exception handling, reconciliation, sanctions screening, dispute management, customer service, operational risk monitoring, and liquidity forecasting.

Many of these pilots prove that AI can work in controlled conditions. But production environments are different.

Operational AI has to work with real data, legacy platforms, payment rails, compliance processes, audit requirements, human decision chains, and service-level expectations. It must be reliable enough for operations, explainable enough for risk teams, and measurable enough for executives.

A pilot proves the possibility. Operational AI has to prove resilience, control, adoption, and value every day.

Often the idea is sound. What's missing is organisational readiness to turn it into a governed, production-grade capability.

Where AI gets stuck before production

In many BFSI programmes, pilots stall because the organisation isn't ready to operationalise a perfectly good concept.

A recent banking discovery programme showed this clearly. Deep user research and rapid prototyping helped identify a genuine customer and value-proposition problem. But moving from "to-be" design into production required more than strong UX or product thinking.

ai-operational-gap-3

The blocker was operating model readiness.

Banks often work tactically, with long backlogs, siloed teams, legacy platforms, and business-led experimentation that is not fully connected to technology delivery. As long as AI remains owned by isolated business teams, it struggles to move beyond POC.

The solution is not another prototype. It is a centralised transformation: shared ownership between business, technology, risk, and operations; clear prioritisation; production funding; integration planning; and governance that makes AI part of the enterprise roadmap.

Why payments make AI harder to scale

Payments are not an easy environment for experimentation. They are fast-moving, regulated, and highly sensitive to trust.

A poor AI decision can delay settlement, increase fraud exposure, frustrate customers, create regulatory risk, or weaken confidence in the institution.

The pressure is rising. UK Finance's 2026 fraud update reported that criminals stole almost £1.3 billion through fraud in 2025, while the industry prevented £1.68 billion in unauthorised fraud. APP fraud losses also rose 19% to £576.4 million.

The European picture tells a similar story. The EBA and ECB's 2025 payment fraud report found that payment fraud in the EEA increased to €4.2 billion in 2024, up from €3.5 billion in 2023.

AI can help institutions detect patterns, prioritise risk, accelerate investigation, and improve operational response. But it also introduces practical questions around model governance, data quality, explainability, third-party dependency, cyber risk, and operational resilience.

BIS research published in 2026 makes a similar point: data privacy, data quality, data security, third-party dependencies, and provider concentration are now central barriers to wider AI adoption in financial services.

For CEOs, COOs, Heads of Payments, and transformation leaders, the challenge is not simply "Can AI work?"

It is: can AI improve payment operations without increasing operational, regulatory, or customer risk?

Fraud AI needs controlled deployment and clear accountability

ai-operational-gap-2

Fraud is a good example of where AI value and AI risk meet.

For fraud triage or SAR recommendations, AI should support investigation, not replace accountable decision-making. It can prioritise alerts, surface suspicious patterns, assemble evidence, and recommend next steps, but any case with doubt should still go to a human reviewer.

In practice, fraud AI should be deployed carefully before it influences live customer outcomes. Many institutions would first run the model in a passive mode, comparing its recommendations against existing decisions, tuning thresholds, and reducing false positives until performance is consistently strong.

Only then should it move closer to live decision-making.

That balance matters. Decline too little and fraud risk increases. Decline too much and genuine customers are blocked.

The business outcome that matters is faster investigation, fewer false positives, better control, stronger auditability, and improved customer trust.

The real gap is operating model design

For regulated payment environments, AI cannot be treated as a standalone technology layer. It needs an operating model.

That means defining:

  • where AI can recommend;
  • where AI can act;
  • where human approval is required;
  • who owns model performance;
  • how risks are escalated;
  • how decisions are logged;
  • how value is measured.

This is no longer optional. FCA operational resilience rules required in-scope firms to remain within impact tolerances for important business services by 31 March 2025. In the EU, DORA has applied since 17 January 2025, strengthening expectations around ICT risk management, resilience testing, incident response, and third-party risk.

AI operationalisation sits directly inside that agenda.

If AI supports payment operations, fraud monitoring, compliance workflows, customer communications, or exception handling, it must be designed with resilience, auditability, and governance from the start.

Third-party AI still needs bank-owned control

When AI sits on a third-party or vendor model, accountability does not move outside the institution.

The bank, processor, or scheme deploying it into production remains responsible for how it behaves. That means governance has to focus on data ownership, controllership, testing, monitoring, and operational override.

Banks should not need to expose raw customer PII to prove an AI use case. A safer route is to use anonymised or aggregated behavioural data, such as digital activity patterns, while keeping sensitive customer data inside the bank's own environment.

The key is orchestration. AI needs to work with existing data environments and operating processes without creating unnecessary data movement or unclear accountability.

That requires clear controls around:

  • what data is used, shared, anonymised, or restricted;
  • who is the controller under GDPR principles;
  • who can approve, challenge, or override AI recommendations;
  • how recommendations and decisions are logged;
  • how incidents are investigated if the model makes a bad call.

If something goes wrong in production, it is still the institution's incident to govern, investigate, and resolve.

What operational AI should deliver

The value of AI in payments should not be measured by the sophistication of the model alone. It should be measured by tangible business outcomes.

Operational AI should help institutions:

  • reduce manual workload in high-volume operations;
  • improve fraud and scam detection;
  • accelerate payment exception handling;
  • strengthen compliance and risk monitoring;
  • improve investigation quality;
  • reduce customer friction;
  • increase operational visibility;
  • support faster, better-informed decision-making.

AI shouldn't stop at identifying a potential issue. It should route it, prioritise it, explain it, trigger the right workflow, and provide the evidence needed for audit and review.

That is the point where technology enables transformation without becoming the story itself.

What matters is whether payment operations become safer, faster, more resilient, and more efficient.

When the idea is right but the operating model is wrong

A common pattern in large banking environments is not a shortage of AI ideas, but too many disconnected experiments. One major bank, for example, has run dozens of AI experiments across back-office and customer operations, yet struggled to convert them into production-grade value because the core problem, success metric, and ownership model were not clearly defined. The result is experimentation without orchestration.

This is consistent with McKinsey's 2025 State of AI research, which found that nearly two-thirds of organisations have not yet begun scaling AI enterprise-wide, while only 39% report enterprise-level EBIT impact from AI. It also notes that high performers are more likely to redesign workflows, not just deploy tools.

What is usually missing is:

Problem clarity: what exact operational issue is AI solving?
Boundary design: where does AI automate, assist, escalate, or stop?
Technology alignment: can the prototype run inside the real enterprise stack?
Central orchestration: who governs tools, agents, workflows, metrics, and risk?
Human-in-the-loop design: where does supervision start and autonomy end?

HFS Research's 2026 study makes a similar point: fewer than 20% of enterprises have scaled AI, and 55% cite fragmented data across systems as a blocker to embedding AI in core workflows.

Moving from AI strategy to AI value

For many payment institutions, the next phase is not about writing another AI strategy. It is about closing the gap between strategy and execution.

ai-operational-gap-4

That shift needs governance first. For example, fraud AI may start by triaging alerts and recommending next steps, while humans approve every decision. It should only move closer to live action once thresholds, audit logs, override routes, role-based approvals, escalation rules, and model monitoring are in place.

The trigger is evidence: stable passive-mode performance, fewer false positives, compliance sign-off, and reviewer confidence in the output.

Ciklum helps turn that progress into board-level metrics by defining baselines, instrumenting workflows, tracking overrides, linking AI activity to outcomes, and reporting measurable value such as faster investigations, reduced exceptions, and improved operational control.

The market has moved beyond asking whether AI has potential.

In my view, the institutions that succeed will be the ones that stop treating AI as a standalone innovation programme and start treating it as an operating capability. The real question now is whether payment institutions can embed AI safely, deeply, and measurably into governed workflows, accountable decision-making, and day-to-day operations to turn potential into business value.

That is the AI operationalisation gap.

And closing it will define the next phase of payments transformation.

 

 

Mark Westbrook
By Mark Westbrook
Author posts
Global Head of Architecture
18+ Exp

Mark brings 18+ years of payments expertise, spanning POS, Open Banking, and Core Payment Rails. As Global Solutioning Director, he crafts innovative strategies that drive operational excellence across payments and banking.