Klavius was recently featured in the Fall 2026 edition of FinTech BoostUP. In the founder interview, we discussed a problem familiar to many management companies: regulatory obligations continue to grow, while much of the work used to evidence them still moves through spreadsheets, shared drives, emails and documents prepared for the next committee.
The phrase “from Excel to AI” can sound like a technology story. For a Luxembourg AIFM or ManCo, it is really an operating-model question. Which work can a system prepare safely? Which decisions must remain with the second line of defence? And what should exist in the record when a conducting officer, board member, auditor or supervisor asks how a conclusion was reached?
Excel is not the problem. The missing connections are.
Spreadsheets are flexible, familiar and quick to adapt. That is why they remain useful. The difficulty begins when one workbook becomes the risk assessment, another becomes the monitoring plan, evidence is stored elsewhere and findings are followed in a fourth file. Each document may be accurate on its own. The control environment becomes fragile in the spaces between them.
A regulatory change may be reviewed without updating the relevant risk. A completed test may have no direct link to the supporting evidence. A finding may be closed in the action tracker while the residual-risk assessment remains unchanged. Reporting then becomes a reconstruction exercise: several people have to explain how one decision travelled across several files.
This is the boundary worth addressing. The objective is not to eliminate every spreadsheet. It is to stop relying on manual reconciliation as the main control connecting regulation, risk, monitoring and remediation.
What AI should do for the second line of defence
The most useful applications of AI in compliance are often less dramatic than the market suggests. They reduce reading, classification and drafting time, but they do not turn a probabilistic output into an approved conclusion.
- Filter regulatory information to the entity. A system can collect updates from the CSSF, ESMA, EBA and EUR-Lex, identify likely relevance and prepare a concise explanation. The compliance officer still decides whether the change applies and what action follows.
- Prepare links between obligations, risks and controls. AI can suggest which parts of the compliance risk assessment may be affected and which controls deserve review. It should show the source and reasoning rather than silently changing an approved assessment.
- Structure evidence already produced by the firm. Reports, minutes, attestations and test results can be classified and attached to the relevant review. The value lies in making evidence retrievable, not in generating evidence that never existed.
- Draft from the live record. Committee and board reporting can be prepared from approved assessments, completed tests, open findings and overdue actions. A draft is helpful only if every statement can be traced back to the underlying record.
These use cases have something in common: AI proposes, organises and explains. A named person reviews, adjusts and signs off.
What an AIFM should not delegate to AI
Some decisions remain inherently accountable. The system should not determine the firm’s regulatory perimeter, accept residual risk, conclude that a control is effective or close a material finding without human approval. Nor should an unreviewed summary become the basis of a board paper simply because it was generated quickly.
That is not an argument against AI. It is the design condition that makes AI usable in a regulated function. A reliable workflow needs visible sourcing, clear status labels and approval points. Users should be able to distinguish:
- information collected from an external source;
- content proposed by the system;
- evidence supplied by the firm;
- a conclusion reviewed by the compliance function; and
- a decision approved by the appropriate officer or governing body.
If those states are blurred, faster production can create more ambiguity rather than better oversight.
The evidence-ready operating model
An evidence-ready compliance record does not begin with the annual report. It begins when a source enters the process. The source is linked to the obligation; the obligation informs a risk; the risk supports a control; the control becomes a test in the compliance monitoring plan; and the result either supports the assessment or creates a finding and action.
The chain should be reviewable in both directions. From a board-level conclusion, an officer should be able to reach the tests and evidence beneath it. From a new CSSF publication, the team should be able to see the affected risk, responsible owner and resulting action. Our article on building a CRA that drives the CMP describes the same principle at launch: the plan should be the operational expression of the assessment, not a separate annual spreadsheet.
This model changes the role of reporting. Instead of rebuilding a narrative from disconnected files, the team reviews a narrative assembled from the live record. The efficiency gain matters, but the more important result is consistency: the same approved facts appear in the working file, the committee view and the board pack.
How to move beyond spreadsheets without a big-bang project
The transition does not require every compliance process to move at once. A narrower sequence is easier to govern and easier to test.
- Choose one recurring decision. Start with a process such as the CRA-to-CMP cycle, delegate oversight or regulatory change assessment, where the hand-offs are visible and the owners are known.
- Map the current evidence. Identify the source documents, approvals, dates and exceptions that support the decision today. Do not automate a process whose evidence standard has not been agreed.
- Separate preparation from approval. Define what the system may collect or propose and where a person must intervene. Make those states visible in the workflow.
- Run one cycle in parallel. Compare the structured record with the existing process. Missing links and unclear responsibilities will become apparent before the old file is retired.
- Measure traceability, not generated volume. The meaningful questions are whether the team can find the source, explain the conclusion and show who approved it. The number of AI-written summaries is not a control metric.
Once that chain works, adjacent processes can reuse the same entities, owners and evidence rather than creating another standalone register.
Where Klavius fits
Klavius is being built around this distinction between assistance and accountability. Regulatory Watch prepares relevant developments with their sources. The Compliance Risk module connects the control library, compliance risk assessment, monitoring plan, findings and action plans. Delegate Oversight and DORA extend the same record to third-party and ICT risk.
The platform can prepare, connect and draft. Your officers remain responsible for the perimeter, the judgement and the sign-off. That is the practical meaning of the line we use to describe the product: read by AI, signed by your officers.
If your compliance cycle still depends on reconciling several spreadsheets before each committee, a 30-minute working session can start with the process you already have and identify the first connection worth making explicit.
Source
- FinTech BoostUP, Fall Issue 2026, “From Excel to AI: Reinventing the Second Line of Defence”, Founder’s Insight, p. 29. This article develops the themes of that interview with additional analysis by Klavius.
