Skip to content
GUIDES

Where should human validation sit in AI workflows for independent asset managers?

A practical control architecture for placing human validation across AI workflows used by Swiss independent asset managers.

By Cytria Research9 min read

Standfirst. Human validation is not one approval box at the end of an AI process. It is a set of control points placed where information enters, sources are selected, content is produced, professional judgement is exercised and an external action becomes possible.

Direct operational answer

Place human validation before each material change in authority or consequence. A person should confirm that inputs are permitted, sources are authorised and current, extracted facts are accurate, professional conclusions remain the adviser’s, and client-facing or transactional actions are appropriate. The intensity should follow the workflow’s risk, not the novelty of the model. Low-consequence formatting can be automated with monitoring. Suitability conclusions, investment decisions, client communications, orders, regulatory submissions and exceptions require named owners and explicit checkpoints. Logs should show what the system did, which evidence was available, who decided and which version was released.

Who this applies to

This article addresses Swiss independent portfolio managers and the governance, compliance, technology and relationship-management functions supporting them. Portfolio managers operating commercially require FINMA authorisation and ongoing supervision through a supervisory organisation. Their exact obligations depend on activities, clients, mandate, organisation and applicable law. The framework is also useful to firms not directly subject to every FINMA observation, but it does not extend a rule beyond its legal scope.

Why one final review is insufficient

A fluent output can conceal an earlier failure. The wrong client file may have entered the workflow; retrieval may have excluded a mandate amendment; a stale research note may have been treated as authoritative; an extraction error may have propagated into a recommendation; or an agent may already have sent a message before the reviewer sees a summary.

FINMA’s Guidance 08/2024 identifies model risks including correctness, robustness, explainability and bias; data risks; IT and cyber risks; third-party dependency; and legal and reputational risks. It describes governance measures observed in supervision, including inventories, classification, testing, monitoring and clear responsibilities. Human review is useful only when the reviewer has authority, time, competence, source access and a genuine ability to stop the process.

Classify workflow risk first

Use consequence and reversibility to determine control intensity.

  • Tier 1, assistive: formatting, translation of approved internal text, meeting logistics. No professional conclusion or external execution.
  • Tier 2, analytical: summarisation, extraction, comparison and briefing. Errors can influence work but a qualified person verifies against sources.
  • Tier 3, advisory: drafts or analysis that may shape suitability, recommendations, client understanding or regulatory duties. Specialist approval is mandatory.
  • Tier 4, consequential: orders, payments, mandate changes, client commitments, filings or access changes. AI may prepare information, but autonomous execution should normally be disabled unless a separately governed, deterministic control framework supports it.

Risk can rise because of sensitive data, vulnerable clients, scale, weak explainability, time pressure, market impact, an unfamiliar instrument, conflicts, cross-border issues or inability to reverse an action.

Validation at input selection

The first checkpoint asks whether the system may receive the proposed material. Confirm client and mandate, purpose, classification, minimum necessary fields, permissions and any restriction on outsourcing or cross-border processing. Do not make the reviewer infer this from a prompt after the data have already been disclosed. Enforce it through approved repositories, access rules, redaction and data-loss controls.

Validation of authorised sources

Define a source hierarchy for each workflow. Mandates, signed client records and current internal policy should not be displaced by model memory or an unverified web result. Retrieval should expose document title, owner, version and effective date. A human owner approves additions to the source set and resolves conflicts. Where freshness matters, stale documents should fail closed or be visibly flagged.

Validation of generated or extracted content

Review facts against the cited source, not against plausibility. For extraction, use field-level checks, reconciliation and exception thresholds. For generation, test attribution, omissions, arithmetic, dates, client identity and unsupported inference. Sampling can be appropriate for low-consequence high-volume work; material client or regulatory content calls for complete review. The system should preserve uncertainty rather than convert missing evidence into confident prose.

Before professional judgement

AI may organise evidence or propose questions. It should not silently become the decision-maker. The adviser must consider the mandate, client profile, objectives, risk capacity, portfolio context, conflicts and current conditions using the firm’s approved process. A checkpoint is meaningful only if the reviewer sees the underlying evidence and can depart from the output without friction or penalty.

Before client-facing or external action

Separate “draft” from “send”, and “propose” from “execute”, through permissions and interfaces. Require an authenticated person with the appropriate role to approve client communications, orders, payments, regulatory submissions or records that create commitments. High-impact actions should show a concise evidence panel and material exceptions at the moment of approval.

Exceptions and escalation

Escalate missing or contradictory sources, low-confidence extraction, mandate ambiguity, unusual instruments, potential conflicts, client complaints, suspected manipulation, prompt injection, material model changes and any request outside the approved purpose. An exception queue needs an owner, service level, evidence requirements and a prohibition on silent fallback. Repeated overrides are a control signal and should trigger workflow review.

Logging, traceability and evidence

Keep a proportionate record of workflow version, model/service version where available, source identifiers, material inputs and outputs, validation results, reviewer, timestamp, decision and exception. Do not create an indiscriminate prompt archive that increases confidentiality risk. Logs must be access-controlled, retained for a defined purpose, searchable for investigation and linked to the business record when appropriate.

Decision table

Workflow AI-supported action Possible failure Mandatory human checkpoint Decision owner Prohibited autonomous action
Meeting briefing Summarise portfolio and interactions Wrong client; stale mandate Confirm identity, sources and material facts Relationship manager Send briefing externally
Client email Draft explanation Unsupported promise or unsuitable framing Approve final wording and attachments Relationship manager Send to client
Portfolio monitoring Flag deviations False alert or missed breach Review evidence and mandate thresholds Portfolio manager Trade to cure deviation
Investment research Compare instruments Invented facts; stale data; bias Verify primary data and analysis Investment professional Adopt recommendation
Suitability support Organise client and product evidence Missing constraint or false inference Complete professional assessment Adviser/compliance as defined Decide suitability
Order preparation Populate order fields Instrument, quantity or account error Dual or role-appropriate confirmation Authorised dealer/adviser Transmit order
Compliance monitoring Prioritise cases False negative; opaque score Review alerts and sampled negatives Compliance Close material case
Regulatory filing Draft or extract fields Incomplete or inaccurate disclosure Reconcile and sign off Responsible officer Submit filing

Illustrative workflow: relationship-manager briefing

This is an illustrative internal workflow, not a client case.

  1. The relationship manager selects a meeting and confirms the client identity and purpose.
  2. The system retrieves only authorised sources: current mandate, approved profile, holdings snapshot, prior meeting notes and open actions.
  3. Retrieval displays source dates and flags missing or conflicting records.
  4. The model drafts a briefing with sections for facts, open questions and possible discussion points. It cannot label a product suitable or create an order.
  5. Deterministic checks reconcile holdings, currency, dates and open actions with source systems.
  6. The relationship manager verifies the cited evidence, removes irrelevant personal detail and records approval.
  7. Any profile conflict, complaint, restricted instrument or mandate ambiguity moves to the defined specialist queue.
  8. The approved briefing remains internal. A separate, explicit action is required to create client communication.

The controls sit at selection, retrieval, generation, professional interpretation and release. A final read-through alone would not detect every upstream error.

Roles and accountability

Management defines risk appetite and accepts material residual risk. The business owner defines purpose and outcome. The adviser retains professional judgement. Compliance interprets conduct and escalation requirements within its remit. Data protection assesses personal-data risks. Security governs identities, integrations and incidents. Model or technology owners test and monitor the service. Internal control or audit evaluates whether the design and evidence operate as stated. A vendor can support these roles but cannot own the institution’s decision.

What can be automated safely

Automation is most defensible where the action is bounded, reversible, observable and does not itself make a professional or external decision. Examples include document routing, formatting, duplicate detection, calculation checked against deterministic rules, retrieval from an approved corpus, and drafting clearly marked for review. “Safe” remains contextual: even formatting can expose confidential data if the service posture is wrong.

What remains under human responsibility

Client acceptance, mandate interpretation, suitability or appropriateness judgements, investment decisions, conflicts, exceptions, material communications, complaints, regulatory assertions and authority to execute should remain with the appropriately qualified and authorised person or body. AI may support the evidence, but responsibility must not become ambiguous.

Cytria’s operational interpretation

Cytria models human validation as an architecture of gates. Each gate has an object to validate, evidence the reviewer can inspect, an authorised role, an escalation path and a recorded outcome. Controls should become stricter as a workflow moves from information to judgement to action. The decisive question is not “Was a human involved?” but “Could the right person detect this failure before its consequence?”

Limitations

This article is general operational and legal information reviewed on 14 July 2026, not legal, investment or regulatory advice. FINMA materials have different scopes; an observation addressed to supervised institutions should not be represented as a universal legal rule. Firms must assess their licence, supervisory organisation, mandate, activities, clients and technology.

Recommended next step

Take one existing AI-assisted workflow and draw its evidence-to-action path. Mark every point where data enter, authority changes or an external consequence becomes possible. For each point, name the reviewer, evidence, stop mechanism, record and escalation path. Test the design with wrong-client, stale-source and unsupported-output scenarios.

Primary sources and review dates

Recommended next step

Evaluate the most practical path to deploy controlled AI inside your business operations.

Start free diagnostic