Skip to main content

Governed AI in Banking Starts with Defining What Agents Can Do

By Tracy Julian · · 4 min read
Three Colleagues Working On Laptops For Governed Ai In Banking

Agentic AI Needs an Operating Model Before It Reaches Systems of Record 

AI is moving into the systems where banking work happens. That shift creates a new operating requirement for financial institutions: define what an AI agent can access, what it can do, and how every action will be governed. 

Model Context Protocol, or MCP, is part of that shift. Anthropic introduced MCP in November 2024 as an open standard for connecting AI assistants to systems where data lives, including business tools, development environments, and content repositories. Its purpose is to replace fragmented custom integrations with a consistent protocol for connecting AI systems to data sources and tools. 

For financial services, governed AI in banking cannot stop at drafts, summaries, and recommendations. AI needs a secure way to retrieve customer context, interact with workflows, and operate inside systems of record. MCP can serve as a standardized execution layer that allows AI agents to retrieve context, invoke actions, and execute workflows within established policies and audit trails.

Before execution scales, banks need to define control.

Governed AI in Banking Starts with Execution Boundaries 

A banking agent may need account context for a service interaction. That does not mean it should update customer data, initiate a loan workflow, trigger a fraud review, or close a complaint. Each action has a different risk profile. 

Before an AI agent acts inside a system of record, a bank should define six boundaries: 

  • Data access: What customer, account, transaction, case, or relationship data can the agent retrieve? 
  • Workflow rights: What approved processes can the agent invoke? 
  • Human approval: What actions require review before execution? 
  • Decision limits: What tasks remain advisory because they involve credit, compliance, fraud, or customer harm risk? 
  • Exception handling: What happens when data is incomplete, conflicting, stale, or high-risk? 
  • Evidence capture: What gets logged for audit, compliance, model governance, and operational review?

These boundaries define the operating model for governed AI in banking. MCP can standardize how agents connect to enterprise capabilities, but the institution must decide what those agents are authorized to do. 

Where Execution Boundaries Become Enforceable 

Execution boundaries only matter if they can be enforced inside daily workflows. For banks using Salesforce, the platform can serve as part of the control plane for agentic banking work, connecting identity, permissions, customer context, workflow logic, action history, and human review.

Salesforce can serve as an API-first foundation for modern banking delivery, providing a secure, auditable execution layer built for governance, guardrails, and human oversight.

MCP extends that foundation by standardizing how agents connect to approved tools and resources. With Agentforce, organizations can register and manage MCP servers so agents can securely access approved tools and data. For banks, the server boundary is the control point: the agent should only see the capabilities its role is permitted to use. 

Governed MCP Requires Production-Level Discipline 

Once execution boundaries are defined, banks need to translate them into controls that work inside daily operations. 

  • Make agent identity explicit. Define whether the agent acts for a service representative, advisor, operations team, compliance function, or automated process. Do not let it operate as a generic system user. 
  • Scope permissions to the workflow. A servicing agent may retrieve account context. A lending agent may prepare a document checklist. A compliance agent may flag missing evidence. Each agent should access only what its role requires. 
  • Set enforceable decision thresholds. Credit decisioning, fraud escalation, KYC and AML screening, complaint handling, and exception processing need clear stop points. Some actions can run automatically. Others should route to a person. 
  • Capture evidence during execution. MCP-connected AI can generate change logs or audit trail entries as part of the action, reducing the need to reconstruct documentation later. 
  • Monitor after launch. Banks need visibility into agent performance, failures, overrides, and exception patterns so governance improves with real operating data. 

Regulatory Expectations Make Evidence Central 

Financial institutions remain accountable for AI-enabled decisions and workflows. The Consumer Financial Protection Bureau (CFPB) has stated that creditors using complex algorithms, including AI-driven credit models, must provide specific and accurate reasons for adverse action. Vague explanations that obscure the actual basis for a decision do not meet that standard.  

In April 2026, the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) issued revised model risk management guidance that replaced SR 11-7 and emphasized risk-based governance, validation, monitoring, controls, and third-party considerations. The guidance notes that generative and agentic AI are still evolving, and it is expected to be most relevant to banking organizations with more than $30 billion in total assets. 

For banks, the regulatory signal points back to the same operating requirement:  

  • Agentic AI in banking must be explainable, constrained, monitored, and auditable. 
  • MCP creates a cleaner connection layer between AI and enterprise systems. 
  • Salesforce provides the governed foundation for access, workflow, identity, and action history. 
  • AI-First Engineering brings the delivery discipline to connect architecture, integration, testing, security, compliance, and adoption. 

The institutions that get value from MCP will define safe execution before they scale governed AI in banking.

Cropped Tracy Julian.png

Tracy Julian

Financial Services Go-To-Market Lead & Architect, Salesforce Practice Tracy brings more than 20 years of financial services experience in retail banking, wealth management, capital markets, and fintech, spanning both industry and consulting roles with firms including the Big 4 across the U.S. and EMEA. She leads Perficient’s financial services industry efforts within the Salesforce practice, partnering with clients to define the vision and goals behind their transformation. She then uses that foundation to build smarter, future-ready solutions that deliver business first, scalable solutions across strategy, cloud migration, and innovation in marketing, sales, and service. A systems architect by trade, Tracy is known for aligning teams around a shared vision and solving complex problems with measurable impact.