Skip to content
Banking

Gresham launches AI tool to configure bank reconciliation rules

Gresham's new Control Studio lets staff describe reconciliation needs in plain language while deterministic engines still do the matching, leaving open questions about approval and audit evidence for UK firms.

By

Published
A large rubber stamp rests on an open ledger, having pressed a single neat grid square onto the page while the rest of the sheet remains blank.

Gresham, the London-based reconciliation software provider, made its new Control Studio application available on 1 October 2026. The company describes it as an AI-enabled, self-service add-on to its existing Control reconciliation product, built to let operations staff configure complex matching rules without writing code. For UK regulated firms that use, or are considering, Control to reconcile trading, settlement and clearing data, the launch raises a familiar question in a new form: who checks the machine's work, and can a firm prove it did so, before a rule touches real money.

What Gresham says Control Studio does

According to Gresham's launch announcement, Control Studio lets business users configure data sources, matching rules, validations and exception workflows, including multi-way reconciliations that pull together multiple data sources, without coding or specialist configuration skills. The company says its generative AI component translates a user's description of trading, settlement and clearing requirements into configuration that runs on Gresham's existing deterministic rules engines.

Gresham also says the tool can identify correlations between datasets and suggest matching keys and validation checks, and that natural-language assistants inside the product can help build search expressions and enrichment rules. Users can, Gresham says, build a control against sample data and inspect what a change would do before it goes live.

None of this has been independently tested or benchmarked as far as this publication has established. The figures that would normally anchor a product claim — implementation time, matching accuracy, false-match rates, processing volumes, customer numbers or cost savings — do not appear in Gresham's public material. What follows should be read as Gresham's own description of its product, not as independently verified performance.

Where the AI stops

The distinction that matters most for a reconciliation control is between the system that drafts a rule and the system that runs it in production. Gresham's own description keeps these separate: generative AI assists with configuration — turning a description of a reconciliation requirement into rule parameters, suggesting matching keys, drafting search expressions — while the actual matching, in production, runs on Gresham's deterministic rules engines. The announcement does not describe a generative model performing live reconciliation decisions itself.

That matters because a deterministic engine behaves the same way every time it is given the same inputs and rule. A generative system that drafted an unsound rule — say, a matching key too loose to catch a genuine break, or an enrichment rule that masks a mismatch rather than resolving it — would still produce that error deterministically and repeatedly once deployed. A key risk point in Control Studio's design is therefore where a rule is created and approved; Gresham has not published a technical architecture, so this should not be read as ruling out other risks once a rule is running in production.

What is not stated about human review

Gresham's announcement refers to business users building and testing controls against sample data before changes go live, and it says governance and auditability are retained in production. It does not state, in the material located for this article, that every AI-generated rule or configuration must be approved by a named human reviewer before it reaches production. Nor does it describe segregation of duties between the person who drafts a rule and the person who approves it, how regression or edge-case testing works, what happens when production data differs from the sample data used in testing, or how the system flags a rule it cannot generate reliably.

This is a gap in the public record, not an allegation that the controls are absent. A firm considering Control Studio would reasonably want Gresham to set out, in contractual or technical documentation rather than marketing copy, whether human approval is mandatory, what roles and permissions exist, and how a failed test blocks deployment.

Gresham's announcement also does not identify the underlying generative-AI model or provider, where data is processed, whether prompts and sample financial data are retained, or whether customer data is used to improve the model. Firms handling trading, settlement and clearing data would normally need this detail to carry out their own data-protection and third-party risk assessment.

Gresham says the system retains "governance and auditability" in production. The announcement attributes this to the company but does not specify what an audit log contains — whether it captures prompts, AI-suggested rules, human edits, approvals, deployment timestamps, identities, model versions or a rollback path. A reader should treat "auditability" as a claim made by the vendor, pending fuller technical disclosure.

The UK rules that apply regardless of the tool

None of this changes what UK-regulated firms already have to do. The Financial Conduct Authority's (FCA) operational-resilience rules and guidance came into force on 31 March 2022, and firms in scope had until 31 March 2025 to be able to remain within impact tolerances for their important business services. FCA Handbook SYSC 15A requires an in-scope firm to identify its important business services, set impact tolerances for each, map the people, processes, technology, facilities and information supporting them, carry out scenario testing, and keep a written self-assessment.

Two provisions bear directly on a firm that adopts a tool like Control Studio for a reconciliation process supporting an important business service. Under SYSC 15A.5.5G, a firm remains ultimately responsible for the quality and accuracy of relevant operational-resilience testing carried out by a third party. That provision is relevant where a firm has Gresham, or another third party, carry out such testing on its behalf; trying out a rule using Control Studio's own sample-data feature is not necessarily the same as outsourced operational-resilience testing, and a firm should be clear which is which when it documents what was tested and by whom. Under SYSC 15A.6.2R, each version of the specified operational-resilience self-assessment records must be retained for at least six years; this is a defined retention duty for those specific records, not a general six-year rule for every audit log a product generates.

RequirementSourceEffective date
Operational-resilience rules in forceFCA Handbook, SYSC 15A31 March 2022
Deadline to remain within impact tolerancesFCA operational-resilience policy31 March 2025
Third-party testing remains firm's responsibilitySYSC 15A.5.5G31 March 2022
Six-year retention of specified self-assessment recordsSYSC 15A.6.2R31 March 2022

On AI specifically, the FCA has said it does not currently plan additional AI-specific rules. Instead it expects firms to apply its existing outcomes-based framework, including the accountability and governance requirements that attach to senior managers. In practice, that means adopting Control Studio does not remove a firm's own accountability, or that of its relevant senior managers, under applicable FCA requirements, whatever role AI played in drafting a rule.

DORA is not a UK rule

Gresham's wider market context for operational controls sometimes invokes the EU's Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, which applies from 17 January 2025 to the EU financial entities within its scope. DORA is EU law. It does not apply as a domestic UK rule simply because a firm operates in the UK or processes UK financial data. EU law stopped applying generally in the UK when the post-Brexit transition period ended at 11pm on 31 December 2020, and DORA itself was adopted later, on 14 December 2022.

A UK-headquartered group may still have DORA obligations, but whether it does depends on its EU entities, activities and contractual relationships, not simply on where the group is headquartered. The European Insurance and Occupational Pensions Authority (EIOPA), the EU authority for insurance and occupational pensions, has said that a non-EU subsidiary of an EU financial entity is not itself a DORA financial entity, because it is established outside the EU — a point specific to insurance-sector entities within EIOPA's remit, though it illustrates the entity-by-entity approach that applies under DORA more generally. UK firms in banking, investment or other non-insurance sectors should not rely on EIOPA's guidance to determine their own group's DORA status; they should consult the official EU text of DORA directly and, for domestic requirements, treat FCA and Prudential Regulation Authority (PRA) rules as their primary framework.

The company behind the product

Gresham Technologies Limited is recorded by Companies House as an active private limited company, company number 01072032, with a registered office at Aldermary House, 10–15 Queen Street, London EC4N 1TX. The launch announcement uses the shorter brand name Gresham throughout, and the public record does not establish which group entity contracts for or operates Control Studio.

What remains unproven

Whether Control Studio was generally available to every Control customer on 1 October 2026, or rolled out by edition, region or contract, is not stated in the announcement. Firms considering the product, and firms that have already adopted it, would need to seek this detail directly from Gresham rather than rely on the launch material.

What to watch next

The questions most likely to be answered next are whether Gresham publishes a workflow specification showing mandatory approval steps and role-based access, whether it discloses which model and hosting providers it uses and how customer data is handled, and whether any customer comes forward with a named deployment. Firms using Control Studio, or evaluating it, remain subject to FCA accountability and, where in scope, SYSC 15A operational-resilience rules regardless of what the product itself can demonstrate. The FCA's operational-resilience pages and the SYSC 15A Handbook text are the primary places to check current UK requirements.

Sources

  1. Operational resilience (opens in a new tab)

    Financial Conduct Authority · · Accessed

  2. SYSC 15A Operational resilience (opens in a new tab)

    Financial Conduct Authority · Accessed

  3. AI and the FCA: our approach (opens in a new tab)

    Financial Conduct Authority · · Accessed

  4. DORA 137: Scope and territorial applicability of DORA (opens in a new tab)

    European Insurance and Occupational Pensions Authority · Accessed

  5. Financial Services Contracts Regime (opens in a new tab)

    Bank of England · Accessed