AI Privacy for banking & finance
What ships out of the box
The finance preset is one of the four built-in industry presets in SOWA Privacy and covers banking and finance workflows directly. It is one click away in Settings → Detection → PII Presets, and you can compose it with other presets via Custom rules & lists.
Finance preset – accounts / transactions / loans
Covers account-level identifiers, banking products, transaction primitives, and the paper trail.
Accounts & balances
Products
Transactions
Documents
The preset layers on top of the always-on regex packs – emails, phone numbers, IBAN, BIC/SWIFT, credit card numbers, national tax IDs, and a dozen others.
Why this matters for banking & finance
Banking secrecy & MiFID II
Customer financial data is subject to banking secrecy in every EU member state. Names paired with account numbers, transaction history, or product holdings are protected – exactly the data shape SOWA Privacy is built to catch. MiFID II's recordkeeping requirements also assume the bank knows where its customer data is going; uncontrolled AI prompts undermine that.
Local detection – zero data egress
Detection runs entirely in the browser. No SOWA Privacy server sees your prompt content. The optional NER model is downloaded once from HuggingFace and then runs offline; the optional WebLLM model runs on the local GPU. The only network call SOWA Privacy makes (other than the AI vendor you chose) is a sparse entitlement check that contains no PII, no prompts, and no audit data.
Tailor it to your institution or desk
- Add institution-specific identifiers (customer numbers, securities account numbers, deal codes) to the Blacklist in Settings.
- Add safe boilerplate (your institution's name, product names, your own BIC) to the Whitelist.
- Add custom regex rules for instrument identifiers (e.g. ISINs, CUSIPs, internal reference codes).
- Export the resulting preset as
.sowa.jsonand ship it to every workstation via an IT policy.
This is a technical control, not legal advice. Each bank needs its own assessment of which AI vendors are admissible at all, and what residual risk remains after anonymisation. SOWA Privacy is one strong layer in a larger compliance stack – not a substitute for one.