Gains:
- Ability to distinguish where artificial intelligence saves real time in the banking workflow (pre-assessment, decision support, operation, reporting) and where regulated and trust-critical decisions (credit allocation, fraud/compliance provision) are left to humans, according to task risk level
- Ability to apply a discipline that verifies each AI output through the steps of connecting it to the source, recalculating it and passing it through policy/legislation filtering.
- Anonymizing customer and financial data within the scope of KVKK, customer secret and bank confidentiality rules and gaining the habit of choosing safe vehicles
A banker's day is filled with numbers, decisions and confidence. A loan application is evaluated, a transaction is examined to see if it is a fraud, which product is considered suitable for a customer, a compliance check is carried out and a report is signed at the end of the day. What these jobs have in common is that they all require quick work and, when done incorrectly, directly harm a person's money, reputation or the legal status of the bank. This is exactly where artificial intelligence falls into this tension. When used correctly, it reduces hours of work to minutes; When used incorrectly, it accelerates error, produces discrimination and results in uncontrollable decisions.
Throughout this module we will position AI as an assistant, pre-screener and draft generator. Artificial intelligence helps read the file for you, writes drafts, looks for inconsistencies, and summarizes. But the decision is yours. Whether to grant credit, whether to consider a transaction suspicious, what to say to a customer—all these are the judgments of an empowered human being. In this unit, we will fundamentally establish this distinction, that is, where artificial intelligence saves time and where the decision is left to humans, verification discipline and privacy rules.
Why banking is a 'trust-critical' and 'regulated' area
If a pun design tool works incorrectly, no one gets hurt. But a malfunctioning model in a bank can deprive a family of the credit it deserves, victimize a legitimate customer by labeling it a fraudster, or overlook money laundering and expose the bank to heavy penalties. Therefore, banking is defined by two features:
- Trust-critical: Decisions affect people's money and future. Even if the mistake is reversible, the damage is real.
- Regulated: Banking; It is surrounded by regulations such as BDDK (Banking Regulation and Supervision Agency, the public authority that supervises banks), MASAK (Financial Crimes Investigation Board, the institution fighting money laundering) and KVKK (Personal Data Protection Law). You can't explain a decision by saying "the AI said so"; You must be able to justify the decision.
These two features establish the basic rule of using AI: AI output is not a substitute for approval from a competent expert. The decision is up to the person. We will repeat this sentence many times throughout the module, because the most expensive mistakes in banking occur when this rule is forgotten.
Attention: Saying "the model works very accurately" does not mean "we can leave the decision to the model". Even a model that is 99 percent correct presents its 1 percent error with the same confidence. In banking, that 1 percent is a person's loan or a bank's penalty.
Where does artificial intelligence come in handy in banking?
Thinking of the banking business in three layers makes it clear where to put AI:
- Pre-evaluation and preparation (low risk, high gain): Document reading, missing document control, file summary, data consistency scanning. Here, even if the artificial intelligence makes a mistake, the risk can be managed because there is human review behind it; The gain is large.
- Decision support (medium risk): Credit justification draft, risk profile summary, financial commentary, suspicious transaction draft. Here, artificial intelligence produces suggestions, but the decision belongs to the human. Verification is essential.
- Final decision and judgment (high risk, human): Credit allocation, fraud verdict, suspicious transaction reporting, decision reflected on the customer. This is the layer where artificial intelligence cannot make decisions; offers the most drafts.
The following table places typical banking tasks by risk level:
Quest
layer
AI role
Who decides?
Credit file missing document check
preliminary evaluation
Scan, summary
Expert reviews
Reason for credit rejection/approval
decision support
Draft justification
competent expert
Transaction anomaly alert
decision support
Pre-qualifying signal
fraud analyst
Suspicious transaction reporting (STR)
final judgment
draft
compliance officer
Credit allocation decision
final judgment
draft/summary
Authority/committee
Draft customer correspondence
preliminary evaluation
draft text
Employee approves
Validation discipline: three-step filter
Take the AI output through these three steps every time. This will be the basic reflex we will repeat throughout the module:
- Connect it to the source. Which document, which account transaction, and which rule is each number, claim, and justification in the output based on? An output whose source cannot be cited is a "claim" until verified, not "information".
- Recalculate/check. If an odds, a total, a score summary is given, confirm it yourself. AI may misrepresent or make up numbers (this is called “hallucination”: when the model produces false information that appears to be real).
- Pass it through the filter of policy and legislation. Does the output comply with your bank's internal policies and legal rules (prohibition of discrimination, customer confidentiality, KVKK)? An output that does not fit will be rejected, no matter how "smart" it seems.
Tip: Ask yourself this question with each output: "Can I defend this to an auditor without just saying 'AI produced it'?" If the answer is no, the output is not yet ready for use.
Privacy: customer secret and KVKK
In banking, data is doubly protected. A customer's account information is both personal data (within the scope of KVKK) and customer secret (within the scope of the Banking Law; the bank's obligation to protect the information it has learned about its customer). Therefore, uploading customer data to any AI tool could be a serious breach.
Basic rules:
- Anonymize. Remove identifying information such as name, TR ID number, account/IBAN number, phone. For example, instead of "Ahmet Yılmaz, TC 123..., account 456..." write "45 years old, X segment customer".
- Minimum data. Share the minimum amount of data that is truly necessary for the task. Not the entire dump, but the relevant lines.
- Use an approved vehicle. Use contracted and secure tools approved by your bank. Do not enter customer data into a public tool if it is not clear where the data is going.
- Leave a record. You must be able to show, when necessary, what data you used, for what purpose, and which tool you used (audit trail).
Four copyable templates
1) Framework that determines roles and boundaries:
Your role: banking assistant. DECISION MAKING; Produce drafts, summaries, or consistency checks only. Do not use identification information (name, TR ID, IBAN). Mark every point you are not sure of as "[confirmation required]". I will take the final decision and responsibility. Task: [job description]
2) Three-step verification request:
Self-audit and report the following output from three aspects: (1) What source/data are each of your claims based on? (2) Which numbers need to be recalculated? (3) Is there a risky aspect in terms of internal policy or legislation (discrimination, customer secret, KVKK)? List uncertainties clearly.
3) Anonymization control:
Before giving this text to a tool, identify all the information that makes the person identifiable (name, TR ID, IBAN, phone, address, rare feature combination) and suggest how to mask it. Also specify the minimum data required for the task.Text: [data]
4) Layer classification assistant:
Determine which layer the following task falls into: preliminary evaluation (accelerated by trust) / decision support (verified) / final judgment (human). Write your rationale and state what the AI's limit is on this task. Task: [task]
three mini cases
Case 1 — Correct use. A credit specialist will check a stack of 40 files for missing documents. Gives each file to the artificial intelligence with an anonymized summary; The artificial intelligence marks "In summary number 3, the income certificate date is older than 6 months, and in number 7, there is no signature page." The expert confirms these signs one by one in the file. Manual scanning, which takes 2 hours, is reduced to 25 minutes and each alert is humanly verified.
Case 2 — Authentication-free trust failure. Another expert forwards a loan rejection reason generated by artificial intelligence to the customer without reading it. In the justification, artificial intelligence misread the customer's income and said "income is insufficient"; However, the document is correct. The customer objects, the file is reopened, and the bank loses both time and reputation. Lesson: any data on which the justification was based had to be checked at source.
Case 3 — Breach of confidentiality. For speed, an employee pastes a customer's full name and account statement into an unapproved, publicly available tool and asks, "Is this customer at risk?" With this single action, customer confidentiality and KVKK have been violated; Even where the data goes is unclear. Lesson: data is first anonymised, then processed only in the approved tool.
Weak prompt / Strong prompt
Weak prompt:
Ahmet Yılmaz's account statement is attached. Decide whether we should give credit to this customer.
This request includes personally identifiable information (breach of privacy), asks the AI for a decision directly (not leaving the decision up to the human), and puts no verification framework in place.
Powerful prompt:
Your role: assistant to the credit specialist checking file PREPARATION and CONSISTENCY.Decision making; Just mark the missing/inconsistent points and state what you are based on. Do not use identification information.Customer (anonymous): 45 years old, segment Mark "[confirmation required]" any points that appear to be missing or contradictory in the information provided. I will make the credit decision.
A strong will does not contain identity, limits the role, leaves the decision authority to the person, and marks every claim clearly for confirmation.
Common mistakes
- Leaving the decision to artificial intelligence. Making the model say provisions such as "give / do not give credit", "fraud / not". These are human decisions; the model offers the most drafts.
- Trusting without verification. Mistaking a fluent and confident text as "correct". Fluency is not accuracy.
- Sharing credentials. Entering the vehicle without anonymizing your name, TR ID and account number.
- Bypassing the audit trail. Failure to document the rationale for the decision and the data used; Not being able to answer the question "why was this decision made?"
- Driving without approval. Entering customer data into public tools where it is not clear where the data goes.
Caution: In banking, the cost of a mistake is often not immediately visible; The objection, inspection or punishment comes months later. Therefore, verification and recording discipline cannot be postponed just because "there is no need unless problems arise"; It should be a habit from the very beginning.
In summary
Banking is a trust-critical and regulated area; So AI is used here as an assistant, pre-screener and draft generator, not as a decision maker. Think of the work in three layers: preliminary evaluation (accelerated by trust), decision support (verified), and final judgment (human). Link each output to the source, recalculate, filter through policy/legislation. Anonymize data, share minimally, use approved tools and leave an audit trail. In one sentence: AI produces drafts; Competent people take the decision and responsibility.
Application task
Select three typical tasks from your own business (or as an example): one for preliminary evaluation (e.g. document check), one for decision support (e.g. justification draft), one for final judgment (e.g. credit decision). For each, (1) write the role of AI in one sentence, (2) indicate which verification step you will apply, (3) note which data should be anonymized. Then create a prompt for the “file preparation” task with the powerful prompt template above and three-step filter the output.
checklist
- [ ] I determined the layer of the task (preliminary evaluation / decision support / final judgment).
- [ ] I gave the artificial intelligence a draft/control task, not a decision.
- [ ] I connected the output to the source and rechecked the critical numbers.
- [ ] I filtered the output in terms of internal policy and legislation (discrimination, customer secret, KVKK).
- [ ] I anonymized the data, shared it minimally and used approved tools.
- [ ] I have recorded the decision and its justification; I took ultimate responsibility.