| TL;DR: When a bank tests a security control, the result shows that it worked at that point in time. But the system can keep changing before the next review. Finzly’s new Assure product is designed to keep monitoring and testing controls as BankOS operates, while also collecting evidence along the way. We looked at what changes when banks do not have to wait for the next review to get a more current picture of whether their controls are working. |
Security evidence in banking always carries a date. A control gets tested, the result gets written down, and that record describes the system as it stood at that point.
But what happens after the test?
Software gets updated. Permissions change. New services can be connected. And increasingly, AI is beginning to take on work inside banking infrastructure. The evidence may still be perfectly valid, but the system it describes has already started moving on.
On September 3, Finzly launched Assure, an AI-powered security and assurance layer inside its BankOS platform. Assure watches for risk and investigates anomalies while the system operates, testing controls and gathering compliance evidence as it goes.
Finzly calls this a move from point-in-time review toward continuous assurance. It also raises a simpler question: how long does security evidence keep telling you enough about the system you have now?
Monitoring and Review Were Never Meant to Do the Same Job
Finzly builds banking infrastructure that lets financial institutions deploy capabilities such as payments and digital banking without replacing the core systems underneath. Assure is the newest addition to that platform.
Continuous monitoring and periodic review already coexist in banking risk management. Federal guidance on third-party relationships says ongoing monitoring can run periodically or continuously, depending on the risk involved. The same guidance separately calls for periodic independent reviews of a bank’s third-party risk-management processes.
Seeing more of what happens between reviews does not make the review pointless. It changes how much the review has to carry on its own.
And that is roughly where Assure fits. Finzly says the product can continuously monitor attack-surface risk and surface anomalies, then speed up investigation and triage. It also tests security controls across traditional and AI-assisted development and collects compliance evidence automatically.
A bank can still stop at intervals to have its controls independently assessed. Assure is aimed at the stretch in between, while the system keeps running toward the next formal review point.
Finzly Has Been Pushing AI Deeper Into BankOS
Last October, Finzly introduced Agentic Galaxy and brought deployable AI agents into payment processing and banking operations. The company described agents helping operations teams resolve exceptions and make decisions, with humans still involved for compliance and control.
In the Assure announcement, Finzly says its use of agentic AI has since expanded across BankOS into software development, testing and customer experiences.
That chronology tells you something about the shape of the platform. Finzly first pushed AI into the work its banking infrastructure performs. It is now pushing AI further into the security surrounding that work. Ordinary changes such as software releases and new API connections keep changing the environment too.
Attackers are not slowing down either. TrendAI surveyed 46 financial-sector CISOs in June 2026 for its Modern Bank Heists in 2026 report. It recorded an 89% year-over-year rise in AI-enabled attacks. Sixty-seven percent of the institutions surveyed experienced “counter incident response,” where attackers interfered with security teams during live investigations.
Watching more closely solves only part of this. An alert can tell a bank that something unusual happened. It cannot tell the bank whether the controls built to stop it actually held.
Spotting an Anomaly and Proving a Control Held Are Different Questions
This is where Assure starts to look like more than a monitoring product.
Finzly is pulling several activities into the same loop. The system watches for risk, and AI helps with investigation and triage. Controls get tested, and evidence of those tests accumulates while the platform keeps operating.
The principle behind this is established. NIST’s guidance on information security continuous monitoring describes it as maintaining visibility into assets, threats, and vulnerabilities. It also covers seeing whether deployed security controls remain effective. Finzly is applying that idea inside banking infrastructure, with AI carrying more of the load.
That changes the question a bank can put to its own system. Not only “did something suspicious happen?” but “when it happened, did the controls around it behave the way we expected?”
Ask that question continuously, and the age of the evidence starts to matter.
Security Evidence Has a Shelf Life
Take a control tested on a Monday. The test is run properly, and the control passes. Tuesday does not somehow make that result false.
But a new software version may have gone live since. Permissions may have moved, or another service may now be connected. Monday’s test is describing an environment that no longer quite matches the one the bank is running.
Monday’s test still tells the truth about Monday. It just tells you less about Tuesday than it once did.
That matters because the same evidence can be asked to do two different jobs. It shows what was true at a point in time, and it may also be used to understand whether a control is working now. The further the system moves from the one that produced the proof, the harder it is for that proof to do both.
This is why Assure’s automated evidence collection is more than an efficiency feature. Finzly points to the manual effort saved when compliance evidence no longer has to be assembled later. The larger change is timing. Evidence produced alongside the activity ends up closer to the thing it is supposed to describe.
Two clocks are running here. One is the system, changing whenever someone ships or reconfigures something. The other is the evidence, refreshing at whatever interval the process allows.
Assure is an attempt to bring those two clocks closer together.
Finzly Is Making Assurance Continuous Before Making It Autonomous
One line in the Assure announcement sets the boundary. A human remains in the loop while Finzly refines and tunes the system, and fully automated actions sit on the roadmap.
Continuous, in other words, is not the same as autonomous. Assure keeps watching, and AI helps investigate what it finds. Controls get tested without waiting for the next review cycle. A person still sits on the other side of that process today.
For banking, that boundary is doing real work. In April, the OCC, Federal Reserve and FDIC revised their model-risk guidance and left generative and agentic AI outside its scope. The agencies called the technologies novel and rapidly evolving. They said banks should still apply appropriate risk-management and governance practices, and that further work examining banks’ use of AI is planned.
Finzly’s sequencing reads more clearly against that backdrop. The system can keep watching and testing, but a person remains part of what happens next.
That changes once the system starts acting on what it finds. A system that detects a problem and documents it is handing information to a person. A system that acts on its own conclusion is doing something with that information. At that point, everything upstream becomes more consequential, from how an event was interpreted to the evidence available to explain the decision.
Finzly’s Bigger Bet Is on Fresher Evidence
Periodic independent review does not have to disappear for Assure to matter. A review can still tell a bank something real about its controls. The system simply does not stop changing when the review ends.
Assure is built around what happens next. Systems change, and permissions move while software takes on more of the work. Finzly’s bet is that banks should be able to keep testing what is happening during that time, rather than wait for the next formal checkpoint.
If it works as intended, yesterday’s proof stops carrying quite so much responsibility for explaining today’s system.
That gives Finzly a different way to frame continuous assurance. Detection asks how quickly a problem can be seen. Assure asks a second question alongside it: how recently can the bank show that the controls around the system were still working?
For infrastructure that runs in real time, that second question is the one Finzly is building to answer.






