Sector — Banking

AI in banking, under the supervisor's watch

AI use cases in banking in Morocco: AML-CFT compliance, credit analysis, customer relations. Bank Al-Maghrib framework, Law 09-08, CNDP and a sovereign option.

In brief

A Moroccan bank can deploy generative AI across compliance, credit analysis, customer relations and the back office, provided it first addresses three matters: outsourcing and the use of cloud as framed by Bank Al-Maghrib, the protection of personal data under Law 09-08 and the CNDP, and the traceability of assisted decisions. Hunter BI designs these deployments with the audit trail as a deliverable, not an afterthought.

In a bank, the question is never 'can the model do it'. It can, often better than hoped. The question is: who answers when internal control, audit or the supervisor ask why this file was classified the way it was, where the data went, and who had the right to decide it.

That is why banking AI projects almost never fail on the technology. They fail on poorly prepared outsourcing, on customer data sent to an unqualified service, or on a pilot that cannot move to production because nothing was logged. Hunter BI works with the IT, compliance and risk departments of Moroccan banks to take these matters in the right order: the framework first, the use cases next, scaling last.

Updated 14 July 2026

Sector stakes in Morocco

What a banking AI project must face in Morocco

Bank Al-Maghrib frames the outsourcing of services and the use of cloud computing services: an AI assistant plugged into banking data is an outsourced service like any other, with its requirements for prior analysis, control of operational risk, reversibility and the right of access to information for oversight. This reading must be done before the first pilot, not after — it is what determines whether a use case can go into production as is, whether it must be confined to non-sensitive data, or whether it demands a sovereign architecture.

Added to this is Law 09-08 on the protection of individuals with regard to the processing of personal data, for which the CNDP is the authority: banking data is among the most sensitive there is, and any new processing — including the analysis of a customer file by a language model — must be declared, framed and limited to its purpose. Finally, the framework for combating money laundering and the financing of terrorism imposes a requirement of its own: an alert must remain explainable. An AI system that helps qualify an alert is a decision-support tool — the decision, the suspicious-activity report and the responsibility remain human. We design banking systems with this boundary written in black and white into the architecture.

Outsourcing and cloud

Using a hosted AI service falls under Bank Al-Maghrib's outsourcing requirements: risk analysis, reversibility, oversight access to information. This file is prepared before the pilot.

Law 09-08 and the CNDP

Any processing of customer data by a model must be declared, limited to its purpose and documented. Data classification precedes any connection to an assistant.

AML-CFT and explainability

AI can help qualify an alert or prepare a file; it does not decide. Every suggestion must be logged, reviewed and attributable to an identified analyst.

Audit trail

Prompt, sources consulted, output, validator, timestamp: without logging usable by internal audit, a pilot never makes the crossing into production.

Use cases

What AI concretely changes banking

Every use case links to the Hunter BI offer that delivers it. We claim no result figures until they are measured at your organisation.

01

Qualifying AML-CFT alerts

Gather for the analyst everything they would otherwise search for by hand — the relationship history, comparable transactions, available public information — and propose a structured summary note. The analyst decides, the audit trail keeps every step.

AI engineering 

02

Credit assessment and memos

Extract the financial statements from a file, cross-check them against internal data and prepare a draft memo in the committee's format. The gain is taken on formatting and search, never on the risk analysis itself.

Finance Agent 

03

Customer relations and the branch network

An assistant that answers advisers on products, fees and procedures, in French as in Arabic, citing the exact internal source. The answers come from your up-to-date documents, not from a model's memory.

Customer Support Agent 

04

Regulatory watch and circulars

Track the supervisor's texts and translate them into concrete impacts on your procedures: what changes, who is affected, which documents to update. Compliance saves the time of reading, not the time of judgement.

Legal Agent 

05

Complaints and customer protection

Classify, route and pre-draft responses to complaints while respecting the deadlines and the expected formalities. Sensitive cases are escalated automatically to a case handler, with the reason for the flag.

Customer Support Agent 

06

Governance and the use-case register

An AI committee, an enforceable charter, a register of use cases and rated risks: the framework that internal control and audit will demand the day AI touches customer data.

AI governance 

Sovereignty

Why sovereignty arises first in banking

Banking is the sector where data is at once the most regulated and the most coveted. A statement, a credit file, a list of counterparties: this information cannot cross a border without knowing exactly whose hands it lands in, under which law, and with what ability internal control has to go and check. The question is not ideological, it is operational: most of the blockers we encounter in Moroccan banking projects do not come from a refusal of AI, but from the impossibility of answering these three questions cleanly.

Sovereign deployment removes the obstacle by removing its cause: open models hosted in your own infrastructure or with a qualified host in Morocco, data that never leaves your perimeter, full logging under your control, up to complete isolation for the most sensitive environments. In practice, the architecture chosen is often hybrid: cloud models for general knowledge and tasks with no customer data, sovereign for everything touching the customer file. It is this boundary — not the choice of a vendor — that makes a banking project defensible before a supervisor.

Where to start

Three steps, in this order

Start with the least risky use case that produces real proof: a scope with no customer data, a metric defined in advance, and a compliance file written in parallel.

Step 01

Free diagnostic

A session with your IT department, your compliance team and a business line: data classification, use cases feasible without exposure, and an honest reading of what your outsourcing framework allows.

Step 02

Instrumented pilot

One use case, a narrow scope, an audit trail from day one. The goal: produce the evidence that internal control and audit will expect, not a demonstration that impresses a committee.

Step 03

Governed scaling

The validated pilot becomes a service: governance, seats, continuous monitoring and periodic risk review. Recurrence begins here, when the tool enters the teams' daily work.

Frequently asked

Can a Moroccan bank use ChatGPT or Claude on customer data?

Not without working through the matter. Using a hosted AI service falls under Bank Al-Maghrib's requirements on outsourcing and cloud, and Law 09-08 frames any processing of personal data. In practice, enterprise offerings bring useful contractual guarantees, but the decision depends on your data classification and your outsourcing file. That is precisely what we work through before the first pilot.

Can AI decide on a suspicious-activity report?

No, and no serious system proposes it. AI gathers, cross-checks and formats; the analyst qualifies and decides, the bank reports. Our architecture makes this boundary concrete: every suggestion is logged, reviewed and attributable to an identified person, so that the file remains defensible before audit as before the authority.

How do you justify a model-produced answer to internal control?

By making the answer verifiable. Our banking systems systematically cite the internal source used — the procedure, the circular, the contractual document — and log the question, the documents consulted, the output and the validator. An answer with no source is not an answer: it is a risk, and the system must say so rather than hide it.

Does the whole bank need a sovereign deployment?

Rarely. Most of the banks we support settle on a hybrid architecture: cloud for general knowledge, office work and tasks with no customer data; sovereign for the customer file, credit and compliance. The value of the scoping lies precisely in drawing this boundary in the right place — too high and you deprive yourself; too low and you expose yourself.

How long before a first usable result?

The diagnostic is held in a single session and the pilot is scoped in the weeks that follow. We do not promise a gain figure before we have measured it at your site: the metric is defined at the outset — processing time, rework rate, perceived quality — and measured before and after. Without a baseline measurement, no result can be demonstrated.

AI in your field: let's start with a diagnostic.

A free scoping session with a Hunter BI consultant: your data, your regulatory framework, the use cases worth launching first — and the ones better set aside.

  • Réponse sous 24 h ouvrées, par un ingénieur
  • Diagnostic gratuit, sans engagement
  • Membre des réseaux partenaires OpenAI et Anthropic