Infosys manager calls for tighter controls over agentic AI in banking
Rajeew Vishvakarma says banks need audit trails for AI systems that act across tools, records and workflows, not only controls over model outputs.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
Banks adopting agentic artificial intelligence will need governance that records full sequences of machine-assisted activity, not just the output of a model, according to Rajeew Vishvakarma, a project manager at Infosys. In an external Finextra opinion, Vishvakarma said the shift could affect customer service, fraud work, compliance investigations, payment exceptions and internal operations, while raising new accountability risks for regulated institutions.
Agentic AI refers to systems that can do more than score a transaction or recommend a response. As described by Vishvakarma, these tools may retrieve information, interpret instructions, call software tools, start workflow steps, draft communications, update records and support multi-step operational decisions.
That capability changes the control problem for banks. A conventional model might produce a fraud score or classify a compliance alert. An agentic system could gather case history, compare policy material, draft an investigator note, open a task and send the case to a reviewer. Vishvakarma argued that banks must be able to show what the system did at each point, which data it used and whether the action was permitted.
From output checks to workflow evidence
Vishvakarma said existing AI governance in banking has focused on questions such as model validation, data quality, explainability, performance monitoring, fairness and drift. Those controls remain relevant, he wrote, but they do not fully cover systems that operate across business processes.
The proposed governance approach, which Vishvakarma called action-chain governance, would preserve evidence from the original user request or system trigger through to the final recommendation or action. The aim is to give banks a durable record that can be reviewed by risk, compliance, audit or supervisory teams after the event.
In practice, that record may include the original instruction, sources retrieved by the system, tool calls, workflow steps, guardrail results, approval checkpoints, human edits, final action, timestamps, lineage metadata and access logs. Vishvakarma said the goal is not to capture every token or internal computation, but to retain enough evidence to reconstruct and govern the chain of activity.
Human review needs clearer definition
Vishvakarma also argued that broad references to a human being in the process are insufficient for agentic AI. Banks would need to specify where review is mandatory, what evidence a reviewer receives, which actions can be approved and how that decision is logged.
Different workflows may need different controls. Vishvakarma said some AI systems may prepare recommendations that require human approval before any action, while lower-risk steps may be automated with exceptions escalated. Customer communications may need review before release, and compliance work may allow automated evidence gathering while keeping final judgment with staff.
The governance burden is higher where AI touches customer accounts, regulatory evidence, fraud investigations, case management or external communications. Vishvakarma said errors in agentic systems may involve wrong information retrieval, incorrect policy application, inappropriate tool use, missed approvals, faulty record updates or responses that appear authoritative without sufficient grounding.
Existing frameworks may need extension
Vishvakarma pointed to established references including the NIST Artificial Intelligence Risk Management Framework, ISO/IEC 42001:2023, the European Union AI Act and the Federal Reserve’s SR 11-7 model risk guidance as foundations for AI oversight. His view is that these frameworks need to be extended for workflow execution, tool permissions, prompt instructions, source validation, logging and post-action review.
For banking leaders, Vishvakarma framed the readiness test around concrete questions: which workflows an AI agent can influence, which actions create customer or regulatory impact, which systems the agent may access, which steps need approval and whether the full action chain can be reconstructed months later.
This story draws on original reporting from Finextra Research.