Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
AI For Finance · CoreTrack
1AI, Automation & Digital Finance
iAI Foundations
Artificial Intelligence in FinanceAlgorithmNeural Networks and Deep LearningMachine LearningArtificial Intelligence vs Machine…Computer Vision in FinanceTraining Data and LabelsNatural Language Processing in Finance
iiGenerative AI
Generative AIGenerative AI vs Predictive AILarge Language ModelsEmbeddingsHallucinationFine TuningPrompting vs Fine TuningThe PromptThe Context WindowTool CallingGroundingVector DatabasesRetrieval Augmented GenerationRAG vs Fine Tuning
iiiAutomation and Workflow
Workflow AutomationAutomation vs AugmentationHow to Map a…Straight-Through Processing and Exception…Robotic Process AutomationRule EnginesMachine Learning vs Rule-Based…
ivDocument and Operations AI
Intelligent Document ProcessingBatch vs Real-Time vs…Document Classification vs Entity…Service Level AgreementsCase ManagementHow to Document Data…Reconciliation AutomationOptical Character Recognition and Data ExtractionConfidence Scores
vCustomer Systems, Identity and Digital Assets
Digital IdentityConsent ManagementBlockchain and Distributed LedgerChatbots and Conversational AIFrom Use Case to ProductionDigital Assets and TokenisationDigital SignaturesData Sharing in FinanceElectronic KYC and Digital Onboarding
viCredit and Fraud Systems
The Fraud AlertCredit Decisioning SystemsHuman in the Loop…Adverse ActionAnomaly DetectionThe Decision ThresholdCredit Score vs Credit DecisionAlert Triage and EscalationFraud Detection and Transaction MonitoringFraud Model vs Credit ModelHow to Build Human…
viiGovernance, Data and Vendors
AI Governance and the AI PolicyHow to Create an…Explainability and Interpretability ComparedThe AI VendorBias and Fairness in Financial AIShadow AIAccess Control and Data MinimisationCloud Computing in FinanceData Lineage and Master DataData ResidencyThe AI Use Case Register and Model InventoryThe Model Owner
viiiModel Performance, Monitoring and Resilience
Model DriftFalse Positives and False NegativesClassification MetricsAdversarial AttacksModel TestingBias, Fairness and Explainability…Stopping an Automated SystemModel ValidationAI Governance vs Model Risk ManagementPrompt InjectionHow to Create an…

Shadow AI: Tools in Use That Nobody Approved

An unapproved use is a use case running with no entry in the register, whatever it is made of and whoever set it up. Concealment almost never explains one. An unapproved use is what happens when somebody solves a real problem faster than the approval route works, and a register's completeness on the day it was signed measures how much of it a firm already has.

The whole subject turns on one asymmetry. Buying something takes a payment, and a payment leaves a line in a ledger that somebody can search. Building something inside software the firm already had takes nothing at all, and leaves nothing at all. The difference between leaving a line and leaving nothing is why a search of one kind finds a particular kind of thing, why a firm that searches one way concludes its problem is small, and why the honest answer to how much of this a firm has is always a little larger than the first search suggests.

What counts as an unapproved use, and what does not?

Start outside a bank. A household keeps a list of its standing commitments so that anybody in the house can see what money goes out every month. Somebody sets up a small monthly payment for something useful, forgets to add it to the list, and the list is now wrong. Nothing was hidden. Nobody was deceived. The list is simply not a description of the household any more, and the moment somebody needs it to be true, it will not be.

An unapproved useA use case that is running with no entry in the register, whatever it is made of. is that, at a firm. The test is one question and it has nothing to do with how the use was built: is it running, and is there an entry for it in the register. A calculation somebody assembled inside a spreadsheet and a service the firm pays a supplier to run every month are equally unapproved if neither appears in the record. So is a step that has been running quietly for two years. So is one that three people know about and nobody wrote down.

Being just as clear about what does not count is worth the same care. Four things get called an unapproved use in a meeting, and not one of them is one. Something registered but badly described is a bad entry, not an unapproved use. Something built and never switched on is not in use. Something a person does by hand once a quarter with no software involved at all is not a use case in the register's sense. And something sitting outside the firm's own scoping test is a scoping question rather than a discovery. At Sumeru Bank Limited, an invented bank, that last distinction turned out to be the whole story.

FOURTEEN USES, CUT TWO WAYS, AND ONLY ONE CUT DEFINES THE WORD Sumeru Bank Limited, invented. Each tile is one use case, numbered 1 to 14. IN THE REGISTER, 9 NOT IN THE REGISTER, 5 BUILT INSIDE THE BANK, 10 Leaves no payment record anywhere, so it is hard to find BOUGHT FROM A SUPPLIER, 4 Leaves a recurring charge, so it is easy 1 2 3 4 5 7 8 9 6 11 14 10 12 13 THIS LINE DEFINES THE WORD this line only decides how hard each one is to find
Nine of Sumeru Bank Limited's fourteen uses had a register entry and five did not, and the built or bought split runs across that line rather than along it: two unregistered uses were built and three were bought, so no search that looks for one kind can see the other.
Try it out

What makes a use unapproved?

AI For Finance Bootcamp — Fin Maverick

How does something start running without anybody approving it?

Nobody sets out to run something unapproved. The sequence that produces one is so ordinary that it can be watched happening in any office in an afternoon, and every step in it is a step a reasonable person would take.

Somebody has a real problem: a queue that keeps growing, a set of letters that all have to be written by Thursday, a pile of documents that has to be sorted before anyone can start work on it. Something already within reach solves it, either a service costing a few thousand rupees a month or a calculation put together in a spreadsheet in an afternoon. The approval routeThe path by which a use case is meant to be permitted before it starts running. exists, but at Sumeru Bank Limited first-time documentation on one item ran at about three working days, and the person with the growing queue does not have three working days. And at the end of it there is no named place to tell, so the person mentions it to whoever seems closest and gets on with the week.

Every one of those four steps is defensible on its own, and the four of them together produce a use case nobody approved. The four steps together make this a design finding about the approval route rather than a conduct finding about people, and a firm that responds with a warning changes nothing at all.

FOUR REASONABLE STEPS, AND A FIFTH THAT NOBODY CHOSE STEP 1 A real problem appears: a queue that keeps growing STEP 2 Something within reach solves it, bought cheaply or built in an afternoon STEP 3 The approval route costs about 3 working days of writing, per item STEP 4 There is no named place to tell, so it is mentioned to whoever is nearest THE RESULT It runs, it works, and it is now one of the five nobody registered NOT ONE OF THESE FIVE STEPS BREAKS A RULE Which is why a warning fixes nothing: the person it is aimed at did nothing they would have done differently.
An unapproved use arrives through four steps a reasonable person would take, and the cost of the approval route sits in the middle of them, so the finding points at the route rather than at the person who went around it.
Try it out

In that sequence, which step is the one a firm can actually change?

Is this concealment, and what does treating it as concealment cost?

Most firms read the finding wrong at exactly this point, and the evidence that they are wrong is sitting inside the finding itself.

At Sumeru Bank Limited, not one of the five unregistered uses was concealed. Every one had been set up by somebody solving a real problem in front of them, and four of the five, being 80.0 per cent, had told somebody about it before it started running. The policy did not say who to tell, so telling somebody was not the same as telling anybody in particular, and four honest disclosures landed nowhere. The fifth was not hidden either. Nobody had ever thought to raise it.

Now watch what follows if the firm reads that as indiscipline. Three things happen, and all three make the next sweep worse. The four people who told somebody learn that telling somebody was the mistake. Quiet has just become the cheaper option, so the next five uses are set up more quietly. And the firm loses the only signal it had about where its own approval route is too slow to use. The slow route, not the count of five, was the actual finding.

FOUR OF THE FIVE TOLD SOMEBODY, AND THE TELLING HAD NOWHERE TO LAND 10 11 12 13 14 Green: told somebody, 4 of 5 Grey: never came up, 1 of 5 told somebody NO NAMED DESTINATION the policy named nobody to tell WHAT READING IT AS INDISCIPLINE COSTS 1. THE FOUR WHO SPOKE LEARN THE LESSON They told somebody and were treated as the problem, so speaking up is now the expensive choice. 2. THE NEXT FIVE ARRIVE MORE QUIETLY The problems do not stop, so the same solutions appear and this time nobody mentions them at all. 3. THE SIGNAL IS LOST The count was the firm's only measure of where its own approval route is too slow to be worth using.
Four of the five unregistered uses at this invented bank had been mentioned to somebody before they started running, and the policy named nobody to tell, so the finding is about a missing destination rather than about people going around a rule.
Try it out

Four of the five had told somebody. What does that say about the fix?

Financial Analyst Program Bootcamp — Fin Maverick

What does route 1, the payments ledger, actually find?

In month 10, Ashok Pillai in technology risk ran a deliberate sweepA search for uses already running, done on purpose rather than waiting for one to surface on its own. at Sumeru Bank Limited. He did not wait for anything to surface. He picked four places where a running use might have left a mark and searched each of them in turn. Every route is blind in a way that is entirely predictable from what it searches, so the four are worth walking through slowly.

The first search routeOne method of finding a use that is already running. Each method finds a particular kind and misses the rest. is the payments ledger, read with one question in mind: is the bank paying anybody, every month, for software services. The ledger found 3 of the 5, being every bought serviceA component the firm pays somebody else to run, which therefore turns up in a payments record. among them and not one built one. Uses 10, 12 and 13 all sat in that ledger as small recurring charges. A calculation assembled in a spreadsheet raises no invoice, so uses 11 and 14 were invisible to the ledger and would have stayed invisible however carefully it was read.

The artefact itself is strikingly ordinary. A bought unapproved use does not announce itself in the ledger. The charge appears as a modest recurring line with a flat description, small enough to sit under the bank's own approval limit for a standing charge, sitting between the courier account and the stationery account. Nobody reading that ledger for any other purpose would stop at it.

THE ARTEFACT: ONE LINE IN A PAYMENTS LEDGER Sumeru Bank Limited, invented. Amounts illustrative and the bank's own. CYCLE DESCRIPTION AS WRITTEN AMOUNT RAISED BY Monthly Stationery account, branch operations Rs 12,600/- Standing instruction Monthly Courier services, document movement Rs 31,200/- Standing instruction Monthly Software services subscription Rs 18,400/- Standing instruction Quarterly Office plants and maintenance Rs 4,900/- Standing instruction THAT ONE LINE IS THE ENTIRE TRACE OF USE CASE 10 It says nothing about what the service does, what it reads, or who decided to buy it. Uses 11 and 14 left no line at all.
A bought unapproved use appears in a firm's own records as an unremarkable recurring charge with a flat description, which is why the payments ledger found three of the five while the two built inside software the bank already had left no trace in it whatsoever.
Investment Banking Analyst Bootcamp — Fin Maverick

What do the other three routes find?

Route 2 was a question, put in person to the head of every business area: what is running in this area that decides something or writes something. Route 2 found 3 of the 5, being uses 10, 11 and 14, and that set contains both of the ones built inside an existing toolA component assembled in software the firm already had, so it turns up in no payments record at all.. The person answering a question does not care whether a component raised an invoice, so a question reaches what no record holds. Asking takes somebody sitting with a dozen people and listening properly. Route 2 is therefore the slowest of the four to run and the one most likely to be skipped.

Route 3 was the network record of which outside services the bank's own systems had connected to. Route 3 found 3 of the 5, and they were exactly uses 10, 12 and 13: the same three the ledger found, arrived at by a completely different search. Both routes can only see something that was bought, so two routes that look convincingly different turn out to be structurally identical. A firm that runs those two and calls it a thorough search has done twice the work for none of the coverage.

Route 4 was the change record of systems the bank already had, read for changes nobody could explain. Route 4 found 1 of the 5, being use 14. Route 4 is the thinnest by count, and it was also the route that turned up the unrecorded change to the workflow router set out below.

FOUR ROUTES AGAINST FIVE USES, AND NO ROUTE FINDS MORE THAN THREE 10 bought 11 built 12 bought 13 bought 14 built FOUND ROUTE 1 The payments ledger 10 12 13 3 ROUTE 2 Ask every business area 10 11 14 3 ROUTE 3 The network record 10 12 13 3 ROUTE 4 The change record 14 1 DARK ROWS SEE ONLY WHAT WAS BOUGHT. GREEN ROWS SEE WHAT WAS BUILT. Routes 1 and 3 return the identical set. Route 2 is the only one that reaches uses 11 and 14 without help.
Each route is blind in a way that follows from what it searches, and routes 1 and 3 return the identical three uses, so a firm that runs both has doubled its effort without adding a single find.
Try it out

Before the control below is moved: a search of the payments ledger for recurring charges to software suppliers. How many of the five does it find?

Play with it

Switch search routes on and off, and watch which of the five stay dark

Four toggles, one for each route Ashok Pillai ran, and five blocks, one for each unregistered use at Sumeru Bank Limited. A block lights when a route that has been switched on would have found it. The default is the payments ledger on its own. A firm runs that search first, and it is the reason a firm concludes the problem is small: 3 of 5 found, being uses 10, 12 and 13, every bought one, and both built ones missed. Now switch route 2 on beside it and the coverage bar fills completely. One catches what was bought and the other catches what was built, so the payments ledger and the question together find all five. Try route 3 beside route 1 instead and watch nothing at all happen.

THE FIVE UNREGISTERED USES, AND WHICH OF THEM THE SEARCH REACHES 10 BOUGHT a drafting step in credit write-ups 11 BUILT a scoring calculation in a spreadsheet 12 BOUGHT a translation step in correspondence 13 BOUGHT a summarising step at the complaints desk 14 BUILT a document sorting step in trade operations COVERAGE OF THE FIVE 3 of 5
Routes running
1
Found, of 5
3
Bought found, of 3
3
Built found, of 2
0

The payments ledger on its own finds 3 of the 5, being every bought one, and misses both built ones.

Educational illustration. One invented bank, one sweep, five unapproved uses. Each route searches a record rather than a product, so a firm with different systems would find the same kinds of thing through different records. Figures are Sumeru Bank Limited's own.

Why does no single route find them all, and which two do?

Put the four results side by side and the shape of the answer is immediate. Route 1 finds 3, route 2 finds 3, route 3 finds 3 and route 4 finds 1. No single route found more than 3 of the 5, and the reason is not that any route was run badly: each one can only see the kind of thing it searches for. A ledger sees payments. A network record sees connections out. A change record sees changes to systems the firm already had. A question sees whatever the person answering it knows about. Only that fourth kind of search is not restricted by construction.

So the useful question is not how many routes to run but which two. The payments ledger comes first, being the cheapest and fastest route and the one that clears every bought use in an afternoon. The question comes second, as the only route that reaches what was built. Together the two cover uses 10, 11, 12, 13 and 14, all five of them. Adding routes 3 and 4 after those two finds nothing that is not already found. Running the pair the other way round gives the same answer. The question paired with either record of buying closes the same gap.

The wrong pair is instructive too. Routes 1 and 3 together still find 3. Both of them see only what was bought. Adding route 4 to those two reaches 4. Only when the question arrives fourth does the count reach 5, four searches spent to arrive where two would have arrived.

COVERAGE AGAINST ROUTES RUN, IN TWO ORDERS 0 1 2 3 4 5 1 ROUTE 2 ROUTES 3 ROUTES 4 ROUTES LEDGER THEN QUESTION: DONE AT TWO LEDGER, NETWORK, CHANGE, THEN QUESTION two searches spent finding nothing new Sumeru Bank Limited, invented. Cumulative distinct uses found, out of five.
Coverage rises steeply when the second route is chosen to see a different kind of thing and barely moves when it is not, so two well chosen routes are most of the answer and the third and fourth add almost nothing.
Try it out

Where only two search routes can be run: which two, and why?

Hypothesis Testing — free micro-course from Fin Maverick

What did the bank find, and where were the finds concentrated?

The headline is a single line: the register held 9 entries and the sweep found 14 uses in fact running, so 5 were unregistered. All five had been running on the day the register was signed off in month 6. The gap is a shortfall against day one rather than growth since. Sumeru Bank Limited's register was 64.3 per cent complete on the day somebody signed it, and that is an ordinary finding rather than a scandal. Any firm that has never swept has a number like it and simply does not know what it is.

The more useful part of the finding is where the five sat. Across all fourteen uses, 4 were bought from a supplier rather than built inside the bank, being 28.6 per cent. Among the five unregistered ones, 3 of 5 were bought, being 60.0 per cent. Unapproved use was more than twice as concentrated in bought services as the overall mix would suggest, and the reason is the asymmetry set out at the start. Buying is easy, and it leaves a trace. Building inside a tool the firm already had is easier still, and leaves none. So a firm sees the bought ones first, fixes those, and has to go looking on purpose for the rest.

BOUGHT RATHER THAN BUILT, IN THE WHOLE LIST AND IN THE MISSING FIVE ALL 14 USES 4 of 14 bought 28.6% THE 5 UNREGISTERED 3 of 5 bought 60.0% 31.4 points more concentrated Buying takes a payment and a payment leaves a line. Building inside a tool the bank already had takes nothing and leaves nothing.
Bought services made up 28.6 per cent of all fourteen uses but 60.0 per cent of the five nobody had registered, so unapproved use was more than twice as concentrated in what the bank had paid somebody else to run.
Try it out

Where was unapproved use concentrated at this bank?

Hypothesis Testing teaches you to run a test, say what it can and cannot support, and recognise a manufactured result.

How much of the shortfall matters under the bank's own scoping test?

Two numbers are now available and they are both true. Confusing one for the other is the commonest way a completeness figure gets misread. Register completenessEntries held against uses found, measured on a stated day. measured against everything running is 9 of 14, being 64.3 per cent. But this bank had settled on a consequence testScoping by what an output does to somebody rather than by how the thing was built. for what its policy covers: an output reaching a customer or a reported figure without a person deciding. On that test, 11 of the 14 uses are in scope. The register held 9 of those 11, being 81.8 per cent.

Three of the fourteen fall outside the test, and the reasons are worth stating because none of them is a loophole. Use 10 produces a draft that a person signs every time. Use 13 produces something a person reads before deciding anything. Use 14 produces an output that never leaves the system it runs in. The two numbers answer different questions: 64.3 per cent measures the register against everything running, and 81.8 per cent measures it against everything the bank said it would govern. A firm that reports only the second is flattering itself, and a firm that reports only the first is measuring against a promise it never made. Report both, in that order, and say which test produced the second.

THE SAME NINE ENTRIES, MEASURED AGAINST TWO DIFFERENT DENOMINATORS AGAINST EVERYTHING RUNNING: 9 OF 14 64.3% 3 REMOVED AGAINST WHAT THE BANK SAID IT WOULD GOVERN: 9 OF 11 81.8% Three uses drop out of the lower denominator: an output a person signs, an output a person reads, and one that never leaves the system it runs in. The nine filled tiles never move: only the length of the row changes, and with it the number a board hears.
The numerator is the same nine entries in both rows and only the denominator changes, so the register reads 64.3 per cent against everything running and 81.8 per cent against everything the bank said it would govern.
Try it out

The register was 64.3 per cent complete against everything in use. What is it against the bank's own scoping test?

Reading an Annual Report Fast — free micro-course from Fin Maverick

What else did the same sweep find, and why was it the more serious of the two?

Route 4, the change record, had found only one unregistered use and looked like the weakest of the four. Route 4 also found something that was not an unregistered use at all, and that find matters more than all five put together.

Component 9 of the intake chain is the workflow router: a set of rules somebody wrote that decides where every file goes. The router touched every one of the month's 8,600 decided files, more than any other component in the chain. In month 7 its waiting time before escalation was changed. There was no approval for that change and no record of it anywhere. And here is the part that matters most: the change broke no policy at all. The policy's scoping test at that time was written around what a thing is made of rather than what its output does, and a set of rules somebody wrote was not in scope.

Read that carefully. Nobody in the story was careless. The person who changed the waiting time was changing a written rule inside a system, exactly as they were entitled to do, in a component the policy had never claimed. The five unregistered uses sat outside the chain and were plainly things somebody should have listed. The router sat inside the chain, inside a registered entry, in the component with the widest reach in the whole system, and it was outside the policy because of a wording. The bank later settled on the consequence test set out above, under which that router is in scope. How a firm chooses between those wordings, and what each costs to run, is set out under the AI governance framework.

ONE COMPONENT, TWO SCOPES, AND A CHANGE THAT BROKE NEITHER THE SCOPE IN FORCE AT MONTH 7 Written around what a thing is made of. 5 items in scope, all of them components that learn from data. 2 3 4 6 8 Component 9 is not here. It is a rule somebody wrote. THE SCOPE THE BANK SETTLED ON Written around what an output does. 7 of the 9 components in scope, whether they learn or were written by hand. 1 2 4 5 6 7 9 Component 9 is here, because of what its output does. COMPONENT 9, THE WORKFLOW ROUTER A rule set that decides where every file goes. It touched all 8,600 decided files in a steady month. MONTH 7: THE WAITING TIME BEFORE ESCALATION WAS CHANGED. NO APPROVAL. NO RECORD. And no rule was broken, because the scope in force that month had been written around the wrong question.
The month 7 change to the router's waiting time had no approval and no record and still broke no policy, because the scoping test in force was written around how a component is built rather than around what its output does.

The error that gets made, and what it costs

The wrong reading of this sweep is that five people went round the rules. Nobody did. Not one of the five uses was concealed, four of the five had told somebody, and the fifth simply never came up. Treating the finding as a discipline matter costs the firm the four honest disclosures it had, the quiet arrival of the next five, and the signal about its own approval route.

The discipline reading costs one thing more, and that last cost is the expensive one. While everybody argues about the five unregistered uses outside the chain, the unrecorded change inside it goes unattended, and that change sat in the component that touched every one of the month's 8,600 decided files. The count of five is the finding that gets a slide. The change of one is the finding that matters.

The weakest route found something nobody had registered. See what the sweep turned up.

What follows a find, and in what order?

The instinct on finding an unapproved use is to switch it off. The instinct is wrong twice over: switching off is the wrong first step, and at this bank it would have been the wrong step entirely for three of the five.

Start with one question about the output, the same question the bank's own test asks: does what this thing produces reach a customer or a reported figure without a person deciding. At Sumeru Bank Limited, 2 of the 5 answered yes, being uses 11 and 12. Uses 11 and 12 needed an entry, a named person and a decision about whether they should continue at all. The other three answered no, and needed an entry and a named person just the same. A register that lists only the frightening things is not a register.

ONE QUESTION ABOUT THE OUTPUT, AND TWO BRANCHES THAT START THE SAME WAY Does its output reach a customer or a reported figure without a person deciding? YES NO 2 OF THE 5: USES 11 AND 12 1. Register it 2. Name somebody accountable for it 3. Apply the test and record the answer 4. Decide whether it should continue An entry and a name, not a shutdown by reflex. 3 OF THE 5: USES 10, 13 AND 14 1. Register it 2. Name somebody accountable for it 3. Apply the test and record the answer 4. It carries on, now visible A register that lists only the frightening things is not one. Both branches open with the same two steps. Neither of them opens with switching anything off.
One question about the output splits the five finds two ways, and both branches start with registering it and naming somebody, so only two of the five ever reached a question about whether they should continue.

The two branches give the order, and the order is the opposite of the instinct. Register it, name somebody against it, apply the test, decide whether it should continue, and only then stop anything. Stopping comes last for a practical reason as well as a cultural one: something that has been running for months is load bearing, and switching it off before anybody has written down what it does creates a second problem on top of the first. Stopping comes last for a cultural reason too. A firm that switches off whatever it finds is a firm nobody tells about the next one.

THE ORDER, AND WHERE THE INSTINCT JUMPS TO THE INSTINCT GOES STRAIGHT HERE 1 Register it it exists on paper now 2 Name somebody one person, not a team 3 Apply the test and write the answer down 4 Should it continue? a decision, with a name on it 5 Stop it only where step 4 said no Something that has run for months is load bearing. Switching it off before anybody has written down what it does creates a second problem, and it teaches everyone watching that the safe move is to say nothing next time.
The response runs in a fixed order with stopping last rather than first, which is the opposite of the instinct and the reason a sweep can be run twice without the second one going quiet.
Try it out

An unapproved use has been found whose output is signed by a person every time. What comes first?

How are the next five stopped from arriving?

The next five are not stopped, entirely. Sumeru Bank Limited observed about one new use case a month, and a firm that is solving problems will keep producing them. The number of them that arrive unregistered can be changed, and three things do that work while a warning does none of it.

The first is a named destination. Four of the five had told somebody and the telling landed nowhere, so name the person or the mailbox in the policy itself and make the act of telling take five minutes rather than three working days. The second is an approval route people can afford to use. If the route costs three working days of writing for a small use, people will keep going around it, and a lighter first pass for small things is not a weakening of the control but the change that makes it reachable. The third is a sweep on a stated interval. The arrival rate is not zero, and any register drifts from the day it is signed. The rate at which unregistered uses appear is set by the cost of doing it properly, so lowering that cost is the only intervention that touches the rate at all.

Try it out

What actually reduces the rate at which unapproved uses appear?

Who runs a sweep in practice, and what does it cost them?

Whether any of that ever happens is decided by what a sweep costs the person who has to run it. A sweep is not a project. At Sumeru Bank Limited it was one person in technology risk with access to the payments ledger and permission to ask questions, and the two routes that mattered are a ledger extract read in an afternoon and a dozen conversations of twenty minutes each.

The searching is the cheap half. The expensive half is what follows a find, and it is worth pricing before the sweep starts so that nobody is surprised into abandoning the exercise. At this bank first-time documentation ran at about three working days an item, and 2 of the 5 finds fell inside the scoping test, so bringing those two properly into scope cost about 6 working days of writing. Against that sits the chain the register was built around, at Rs 2,40,00,000/- to build once and Rs 65,00,000/- a year to run. The governance work that closes the gap is small money next to the thing it governs, and it is nearly always the half that gets cut.

Two other readers use the same output for different purposes. Somebody doing an independent review reads the sweep as evidence of whether the firm can state what it is running. The question is about the search rather than about the count. And an outside reader with a legitimate interest, a supervisor or an auditor, is generally not asking for the number to be perfect. The three things asked for are when it was last checked, by whom, and by which routes. A firm that can answer those three has a process, and a firm quoting a flawless count without them has a document.

India

Where the expectations sit

Where an unapproved use handles customer data or feeds a reported figure, the expectations on a regulated lender covering outsourcing, digital lending, data and consent are published by the Reserve Bank of India at rbi.org.in, and the equivalent for a market intermediary by the Securities and Exchange Board of India at sebi.gov.in. The accountability of a board and its officers for the records a firm keeps sits with the Ministry of Corporate Affairs at mca.gov.in. Requirements, thresholds, intervals and effective dates are stated in the current text at each issuing body's own site.

Discovery is the whole of the subject above: what an unapproved use is, how it arrives, how a sweep finds one, and what to do with a find. The register itself, what each entry carries and what is checked after a use goes live are set out under AI governance and the AI policy. How a register is built, how a firm chooses its scoping test and what each wording costs are set out under the AI governance framework for finance. How a supplier is assessed before anything is bought is set out under the AI vendor.
Breaking Into Quants Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Reserve Bank of IndiaPublished expectations on a regulated lender covering outsourcing, digital lending, data, consent and record keeping, the source of any expectation about what a lender must be able to say it is runningrbi.org.in
Securities and Exchange Board of IndiaThe equivalent published position where the deployer of a chain of this kind is a market intermediary rather than a banksebi.gov.in
Ministry of Corporate AffairsThe accountability of a board and of its officers for the records a firm keeps, the layer any internal search of this kind ultimately reports intomca.gov.in
Bank for International SettlementsThe international standard on governance of deployed systems at a bank, the origin of the expectation rather than the position in force in Indiabis.org

Sumeru Bank Limited, its intake chain and Ashok Pillai are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.