
Ramkumar Venkataraman
CTO & Co-Founder
62 articles
Voice Cloning and the End of Voice Biometrics as a Sole Factor: A Caller-Verification Architecture for Banks
Cheap, high-fidelity voice cloning has collapsed voiceprint and knowledge-based authentication as standalone factors on bank phone channels. The NIST 800-63 level we hold caller authentication to, the phishing-resistant factors that survive a synthetic caller, and the agent-side controls we wire around them.
OFAC Sanctions Screening with AI Agents: The SDN List, Fuzzy Matching, and the 50 Percent Rule
Sanctions screening is strict-liability and the SDN list does not match cleanly. How we architect AI agents for name and identifier screening, beneficial-ownership traversal under the 50 percent rule, and hit disposition that survives an OFAC subpoena.
Prompt Injection Defense for Banking AI Agents: Threat Model, Controls, and a Red-Team Cadence
Prompt injection is the highest-impact attack against an AI agent in a bank because the agent has tools that move money. The threat model, the architectural controls, and the red-team patterns we exercise before every deployment.
Building AI Agents for Open Banking While the 1033 Rule Is Enjoined
Section 1033 was finalized in 2024, enjoined in 2025, and is now under reconsideration. How we architect AI agents for personal financial data sharing so the design survives whichever way the rewrite lands.
NYDFS Part 500 and the AI Cybersecurity Letter: What New York-Regulated Institutions Have to Build
New York's Part 500 is fully phased in and its October 2024 AI guidance tells covered entities how to apply it to AI risk. The controls that matter for an AI agent: phishing-resistant authentication, privileged access on the model store, AI vendor diligence, and data minimization.
AI Agents for BSA/AML: SAR Narratives, Transaction Monitoring Tuning, and the New Examiner Bar
How banks and credit unions can use AI agents inside BSA/AML programs — covering SAR narrative drafting, alert triage, transaction monitoring tuning, and the FinCEN and FFIEC controls examiners expect to see.
Third-Party Risk Management for AI Vendors: An Interagency TPRM Playbook for Banks
How banks should run TPRM for AI vendors under the 2023 interagency guidance (SR 23-4, OCC Bulletin 2023-17, FDIC FIL-29-2023) — covering the diligence pack, contract terms, ongoing monitoring, and concentration risk.
Model Risk Management for AI Agents: An SR 11-7 and NIST AI RMF Playbook
How banks and regulated lenders should govern AI agents under SR 11-7, OCC Bulletin 2011-12, and the NIST AI Risk Management Framework — covering inventory, validation, ongoing monitoring, and challenger models.
Preventing AI Hallucinations in Bank Customer Service: A Grounding and Citation Architecture
How regulated banks can architect AI agents that do not hallucinate — covering retrieval grounding, citation enforcement, confidence gating, and the eval harness needed to keep policy-true answers in production.
AI Claims Processing for Regulated Insurers: A Hands-On Field Guide
How regulated insurers can deploy policy-aware AI agents for FNOL, triage, documentation, fraud signaling, and subrogation — with audit trails and compliance guardrails.
From Bot to Banker: AI-to-Human Handoffs for Regulated Financial Institutions
How to build AI-to-human handoff experiences that are fast, compliant, and human-ready — for banks, lenders, servicers, credit unions, and insurers.
Building a Finance-Grade AI Assistant for Mortgage Loan Queries
How to build a policy-aware, multimodal AI assistant for mortgage queries — with consent handling, disclosure tracking, guideline-grounded answers, and audit-ready architecture.
You Ain't Seen Nothin' Yet
- Any loan type, any agency guideline or custom investor overlays.
- Every finding cited to the guideline or document it came from