
Banks embedding artificial intelligence into core banking systems will need to strengthen model governance, adversarial testing and operational resilience as automated decisions become more closely integrated with lending, pricing and fraud controls, according to McKinsey.
The consultancy’s analysis, published last week, argues that ageing core platforms are restricting banks’ ability to deploy AI and respond to growing supervisory expectations for timely risk information.
For quality assurance teams, the proposed transformation brings decision quality, data traceability and recovery performance into sharper focus alongside transaction processing accuracy.
“Because legacy cores are complex and difficult to modify, they also struggle to meet rising regulatory expectations about real-time visibility,” wrote Henning Soller, a partner in McKinsey’s Frankfurt office, in the analysis co-authored with Riyadh partner Chandrasekhar Panda.
The authors describe a shift towards core platforms that combine transaction processing with AI embedded in everyday banking decisions. Their recommendations connect that transition directly to explainability, continuous monitoring, automated compliance checks and resilience testing.
Governance
For banks, the governance challenge grows as AI moves beyond supporting analysis and starts influencing customer outcomes within operational systems.
McKinsey described pricing engines that can propose overdraft limits or fee waivers using transaction histories, behavioural signals and other indicators. Similar integration across underwriting, fraud management and collections makes the behaviour of these systems increasingly consequential.
“At the same time, as AI increasingly influences credit, pricing, and collections decisions, institutions must ensure explainability and strong model governance,” Soller and Panda stated. “This includes adversarial testing and monitoring to guard against AI-related risks.”
The implication is a broader assurance remit: assessing the decisions generated within a banking workflow as well as whether the underlying software processes a transaction correctly.
“Legacy cores struggle to meet rising regulatory expectations about real-time visibility.”
– Henning Soller
The analysis places testing and monitoring within the governance of AI-enabled banking operations, rather than treating them solely as activities undertaken before deployment.
McKinsey distinguished between banks using AI outside core workflows, institutions embedding it in selected processes, and more advanced operations integrating AI across products, servicing, risk management and technology delivery. Relatively few institutions have reached that final stage at scale, the authors say.
That distinction matters for assurance planning. A model supporting an analyst and a model influencing a live credit decision occupy different positions within the bank’s operations, even if both are described as AI adoption.
Regulatory reporting
The analysis also linked modernisation to the quality and timeliness of information available for risk management and regulatory reporting.
Legacy systems can leave customer, transaction and risk information fragmented across separate platforms. Overnight processing can delay updated balances and risk assessments, restricting the usefulness of otherwise sophisticated analytical capabilities.
McKinsey cited an unnamed large universal bank where overnight reconciliation delayed credit-line adjustments and fraud interventions by up to 24 hours.
Following the introduction of an event-driven modernisation layer and machine-learning decisioning, credit decisions fell from hours to seconds. The consultancy reported a 12 percent increase in approved lending volume in targeted segments and an 18 percent reduction in fraud losses within the first year.
The regulatory opportunity extends to more granular intraday liquidity monitoring and reporting that can be traced back to originating transactions.
“In practice, data and AI architecture must be co-designed with the core from day one,” Soller wrote in the joint analysis.
The authors recommended consistent data models across core banking entities, alongside governed data platforms with lineage, quality checks and privacy controls. They also called for banks to decide early which AI applications will operate within real-time workflows and which will remain outside them.
For testing teams, this puts the connections between source transactions, data transformations and reported information firmly within the modernisation agenda. Faster reporting depends on the integrity of that chain.
Resilience
Operational resilience is another central element of McKinsey’s proposed architecture. The authors identified automated recovery, continuous monitoring and chaos testing among the capabilities needed to support increasingly intelligent core platforms.

“They use active–active or active–standby architectures, automated recovery, and chaos testing to meet rising resilience expectations,” Soller and Panda wrote of these systems.
The analysis describes an unnamed systemically important bank that introduced active–active deployment across multiple regions and automated failover.
According to McKinsey, the design allowed critical services to continue during regional outages while meeting data residency requirements.
Combining chaos testing, AI-driven anomaly detection and zero-trust controls helped the bank reduce mean time to recovery by more than 60 percent, the consultancy reported. It said the bank also met enhanced supervisory expectations for operational resilience without materially increasing running costs.
The example gives QA and resilience teams a concrete performance measure: recovery time under a redesigned operating architecture. The reported improvement resulted from a combination of architectural changes and controls; the analysis does not isolate the contribution of chaos testing alone.
Migration
McKinsey favours progressive modernisation for large institutions, with banks moving selected products or businesses onto new platforms, surrounding legacy systems with modern interfaces, or separating pricing and product engines from existing cores.
“The right pattern is context-specific to the regulatory environment, scale, vendor landscape, and risk appetite,” Soller pointed out in the co-authored analysis.
AI can support that transition through code analysis, refactoring, automated test generation, data mapping and reconciliation, the authors say. Configurable product platforms also allow pricing and feature changes to be simulated before rollout.
The consultancy recommended treating each migration wave as a product release, with explicit measures covering business outcomes, costs and resilience. Platform engineering, site reliability engineering and capabilities for operating data and machine-learning systems should be established during the first wave.
The central implication was that core modernisation connects software assurance more closely with model governance and regulatory evidence. As banks introduced AI into live decision flows, the scope of validation expands from transaction accuracy to the quality, traceability and resilience of the decisions those transactions trigger.
THIS MONTH



REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Goldman puts AI coding to the test
- How to test AI models that banks do not control
- OpenAI, Filigran and SunTec: the latest vendor and product news
- Sygnum: Testing AI is ‘a measurement problem’
- Banks’ ‘code for all’ push raises testing risks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



