When the OCC Said Yes: What a §17f-1 Fix Taught Me About AI in Regulated Finance

Regulators do not applaud. They document, they question, they reserve judgement, and occasionally-very occasionally-they express satisfaction. That last phrase, in OCC examination language, is roughly equivalent to a standing ovation from a Scandinavian audience. Last year, when I heard it, I did not celebrate immediately. I went back through the file to check whether we had missed something.

We had not. But the reason we had not is more instructive than the outcome itself.

The Situation

The custody bank came to me with a §17f-1 problem that had quietly compounded for longer than anyone wanted to admit. Fourteen custodial accounts. Manual reconciliation spread across three jurisdictions-the US, Luxembourg, and a Cayman structure that generated its own particular brand of administrative joy. The average lag between identifying a securities fail and reporting it to the OCC examiner’s desk was eleven days.

Eleven days is not a compliance gap. It is a liability with a bow on it.

Here is the moment I do not enjoy recounting. In the first working session with the internal operations team, I asked to see the reconciliation workflow. What I expected was a documented process with some inefficiencies. What I found was a spreadsheet. A colour-coded, lovingly maintained, deeply human spreadsheet-owned by one person, checked on her schedule, dependent entirely on her being in the office on a Friday afternoon and not having a migraine.

She was excellent at her job. She was also the single point of failure for a regulated function that the OCC takes seriously enough to have its own numbered rule.

I had seen versions of this before-in Bahrain, in Mumbai, in London-but something about seeing it at a US custody bank in 2024 still caught me. The gap between what institutions tell regulators about their controls and what actually runs their controls is, in my experience, almost always a person with a spreadsheet and good intentions.

We needed to close that gap with something more durable than intention.

The Build

The surveillance layer we constructed pulled directly from the core custody ledger-integrated via structured API connections into the bank’s existing custody management infrastructure, which in this case sat on a platform familiar to most mid-tier US custodians. The exception logic ran continuously, not on a schedule. Every identified fail triggered an automated escalation path, timestamped at the moment of detection. SAR-adjacent flagging narratives were auto-drafted and queued for human review before anyone had to open a ticket or send a message.

The tooling itself was not exotic. Structured data pipelines, rule-based exception engines layered with a classification model, and a reporting stack that wrote directly to the audit trail in a format the OCC’s examination teams could read without interpretation. Platforms like Nasdaq’s Surveillance infrastructure, Broadridge’s reconciliation and regulatory reporting suite, and AxiomSL (now part of Adenza / Nasdaq) exist precisely for this class of problem. The architecture principles are well understood. What is less understood is why so many institutions still do not implement them until an examiner forces the question.

When the OCC review team arrived, they saw real-time audit trails. Timestamped escalation paths. Zero documentation gaps between identification and reporting. The eleven-day lag was gone. The process was no longer dependent on a person remembering to check something.

They expressed satisfaction.

Three Things That Were Actually True

**First:** the technology was not the differentiator. Every vendor in that room had technology. The differentiator was that the bank finally had a single source of truth-one that did not require a human to remember, to be available, or to interpret ambiguous data under time pressure. The OCC was not impressed by AI. They were impressed by accuracy. AI made accuracy repeatable. That is a meaningfully different claim, and most sales decks in this space get it backwards.

**Second:** the eleven-day lag was a symptom, not the disease. The real problem was that no one had priced the exposure correctly. Eleven days of unreported lost or stolen securities is eleven days of regulatory, reputational, and counterparty risk sitting off the risk register. Until you can see the gap in real time, you cannot price it. Until you cannot price it, you will not fix it. Visibility is not a compliance nicety-it is the precondition for every risk decision that follows. This connects to something I wrote about separately: the structural danger hiding inside AI-native clearing approvals, where boards are signing off on automated systems they do not fully understand, compounding the very exposures they believe they are managing.

**Third-and this is the one most organisations get wrong-the examiner is not your adversary.** Build for the examiner who assumes the worst. Give them audit trails so clean they have nothing left to question. The institutions that treat regulatory examination as an adversarial event spend enormous energy managing the optics of their controls. The institutions that treat it as a transparency exercise spend that same energy making their controls actually work. One of those strategies scales. The other one ends badly in year three.

What This Means for Your Organisation

If your reconciliation workflow depends on a person, a schedule, or a spreadsheet-however capable the person, however reliable the schedule-you are one absence, one error, or one examiner visit away from an eleven-day problem of your own. The technology to close that gap is not emerging. It is available, it is implementable, and in most custody environments it is not even particularly expensive relative to the exposure it eliminates. The question is not whether you can afford to build the surveillance layer. The question is whether you can afford to keep explaining to an examiner why you have not.

I have written before about what it looks like when a team holds together under that kind of pressure-the thirty-six-hour stretches, the decisions made at 3am that determine whether the morning looks manageable. None of that replaces the upstream work of building systems that do not create those nights in the first place.

The Close

The regulator does not care how sophisticated your AI is.

They care whether the record is complete, the timeline is accurate, and the gap between what happened and what was reported is measured in hours-not days.

Build the thing that makes that true without depending on anyone’s memory.

That is the whole brief.

Accuracy is not a technology problem. It is a design decision-and most institutions are still choosing wrong.