AI Privacy for banking & finance

What ships out of the box

The finance preset is one of the four built-in industry presets in SOWA Privacy and covers banking and finance workflows directly. It is one click away in Settings → Detection → PII Presets, and you can compose it with other presets via Custom rules & lists.

Finance preset – accounts / transactions / loans

Covers account-level identifiers, banking products, transaction primitives, and the paper trail.

Accounts & balances

account numberbalancebank accountsort coderouting numberaccount statement

Products

loanmortgagecash loancredit lineleasingfixed depositsavings accountretirement accountISA

Transactions

transactionwire transferpaymentdepositwithdrawalPINauthorisationtokenSMS code

Documents

invoicetax returnreceiptproof of incomeannual tax declarationbank statement

The preset layers on top of the always-on regex packs – emails, phone numbers, IBAN, BIC/SWIFT, credit card numbers, national tax IDs, and a dozen others.

Why this matters for banking & finance

Banking secrecy & MiFID II

Customer financial data is subject to banking secrecy in every EU member state. Names paired with account numbers, transaction history, or product holdings are protected – exactly the data shape SOWA Privacy is built to catch. MiFID II's recordkeeping requirements also assume the bank knows where its customer data is going; uncontrolled AI prompts undermine that.

Local detection – zero data egress

Detection runs entirely in the browser. No SOWA Privacy server sees your prompt content. The optional NER model is downloaded once from HuggingFace and then runs offline; the optional WebLLM model runs on the local GPU. The only network call SOWA Privacy makes (other than the AI vendor you chose) is a sparse entitlement check that contains no PII, no prompts, and no audit data.

Tailor it to your institution or desk

  • Add institution-specific identifiers (customer numbers, securities account numbers, deal codes) to the Blacklist in Settings.
  • Add safe boilerplate (your institution's name, product names, your own BIC) to the Whitelist.
  • Add custom regex rules for instrument identifiers (e.g. ISINs, CUSIPs, internal reference codes).
  • Export the resulting preset as .sowa.json and ship it to every workstation via an IT policy.

This is a technical control, not legal advice. Each bank needs its own assessment of which AI vendors are admissible at all, and what residual risk remains after anonymisation. SOWA Privacy is one strong layer in a larger compliance stack – not a substitute for one.