The AI model isn't the hard part anymore. Keeping everything around it trustworthy is. This new report from BCG and SCBX lays out a reference architecture for agentic banking: an AI core that can reason, talk, and make proposals, wrapped inside a deterministic boundary that actually decides what's allowed, approves what gets committed, checks the results, and keeps a record of it all.
Across seven sections, the authors work through the choices that actually matter once you're trying to run this in production, not a pilot. That means figuring out where the AI's judgment should end and hard rules should take over - mapping out the full architecture, tracing what happens on a single customer call from start to finish, and building scale-up so the agent proposes but the system commits.
It also means keeping routine tasks off expensive models to protect the economics, nailing down five key management calls: who owns what, what has to stay deterministic, what to build versus buy, what to centralize versus leave local, and how fresh your data needs to be. All of this, before scaling up, and planning for the messy cases: failed writes, hardship situations, the stuff that doesn't show up in a demo.