An AI portfolio the board can govern

Year:

2026

Service:

AI Strategy & Adoption

Industry:

Banking

Team:

4 specialists, 8 weeks

Reference scenario: a mid-sized Polish bank turns 43 scattered AI ideas into a governed portfolio of six funded bets, an operating model and a 90-day backlog, with risk classes and stop decisions the board can defend.

Introduction

In this scenario a mid-sized Polish bank has no shortage of AI activity. Operations run two document pilots, the contact centre is testing an assistant, IT has bought coding assistant licences, and risk is asking who approved any of it. A workshop count finds 43 ideas. Eleven of them are already spending money, and none has an agreed measure of value.

The management board asks a plain question: which of these do we fund, which do we stop, and what do we owe the supervisor? Keter AI runs the Boardroom Simulator, our accelerator for exactly this decision. Over eight weeks it turns the list into a governed portfolio, an operating model and a 90-day backlog that the board can read in one sitting and defend in front of the supervisory board.

Challenge

The bank's problem is not a lack of ideas. It is that nobody can compare them.

  • Value is counted in the wrong unit. Pilots report licences and prompts, not cycle time, cost or risk. Survey data shows why this matters: in McKinsey's 2026 survey, as reported in a secondary summary, 37 percent of respondents attributed any positive EBIT impact to AI.

  • Regulation arrives in layers. Under DORA, which has applied since 17 January 2025, the bank's AI systems and AI vendors fall within ICT and third-party risk management. The AI Act's high-risk obligations for Annex III uses, which include creditworthiness assessment, apply from 2 December 2027 after the 2026 postponement. Poland's own act on AI systems has been in force since 11 August 2026.

  • Data residency is discussed last. Three pilots send customer data to services nobody has classified.

  • No one owns the stop decision. Every idea has a sponsor; none has an exit criterion.

Without a common scale, the board can only approve everything or nothing.

Solution

The engagement follows our four layers: strategy, architecture, delivery, governance. Three decisions shape it.

One scoring model for every idea. Each of the 43 ideas is scored per workflow on value, feasibility, data readiness and regulatory class, using baseline cycle-time and cost measurements rather than sponsors' estimates.

Buy before build. For each candidate we test whether a bought product or one of our accelerators covers it before proposing bespoke work.

A sovereignty tier per workload. Every workload gets a data class and a placement: managed model API, EU sovereign cloud region, or on-prem open-weight serving. The draft EU Cloud and AI Development Act is used as a reference only, because it is still a proposal.

What the bank receives:

  • Portfolio board pack - six funded bets, 14 ideas parked with conditions, 23 stopped, each with a one-page rationale.

  • AI inventory - every system and pilot with owner, vendor, data class and a preliminary AI Act risk class; credit scoring is flagged for high-risk preparation.

  • Operating model - a central platform team, domain product owners and an AI committee with a stage-gate calendar.

  • Reference architecture - a model gateway with per-team keys, tool access for agents through MCP servers with scoped permissions, tracing and an evaluation harness in MLflow, and open-weight options such as Mistral Small 4, with Bielik for Polish-language workloads.

  • 90-day backlog - sequenced work items with owners, budgets and stage gates tied to P&L metrics.

Risk and compliance sit in every scoring session, so classification is decided with the people who will later have to defend it.

Result

Because this is a reference scenario, the outcomes below are design targets and acceptance criteria, not audited results.

  • Board decision in one meeting - acceptance criterion: the board approves or rejects each of the six bets on the basis of the pack alone.

  • Two or three workflows to measured impact - target for the first twelve months, measured in cycle time and cost per case, not in usage.

  • Complete inventory - acceptance criterion: no AI system or pilot in the bank without an owner, a data class and a risk class.

  • Stop decisions that hold - every stopped idea has a written reason and a condition for reopening.

At the end the bank owns the scoring model, the inventory, the operating model and the backlog as working documents, not slides. It can rerun the portfolio review each quarter without us. From 28 October 2026 it can also ask KRiBSI, Poland's AI supervisor, for an individual opinion where a classification remains uncertain.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.

Book a readiness call.

Bring one process, product or function where AI should help. We will suggest the most practical next step.