Official Anthropic PartnerNVIDIA Inception Program- MemberIoT Global Awards 2023 Winner- Cloud Big Data Analytics
Arrochar Labs
ARROCHAR
LABS
MeshFinBuilt on MeshboneIn development

Our vision for financial services

Run the bank on governed AI.Serve customers better, cut the cost of operations, keep every decision accountable to the regulator.

One governed AI platform for the operations of a bank, aligned to the BIAN Service Landscape.

1

Serve customers better

Onboarding in one sitting, requests resolved at first contact, complaints and hardship recognised wherever they are raised and answered within the statutory time. Agents carry each service end to end; the customer sees the status without ringing.

2

Cut the cost of operations

Automate the operations of the bank so the cost of running it falls, service by service, as each legacy system retires and its licence, integration and upgrade costs go with it. Savings arrive during the programme, not after it.

3

Keep every decision accountable

No credit decision, hardship decision, suspicious matter report, account closure or complaint outcome is taken by an agent alone. A named person with the delegation decides, and the evidence chain shows who, why, on what data and under which policy, in the form the regulator asks for.

Onboarding, lending, payments, complaints, hardship, financial crime, compliance and the rest of the twenty-four services a bank runs, as governed AI services on a single platform, mapped service by service to the BIAN Service Landscape. The governance rails are standard. The services are built to measure for your products, your policies and your regulator.

The consolidation case

Reduce the shelf of banking systems to one platform the regulator can read. Lower technology and operations cost over time, service by service.MeshFin runs on the AI-safe Arrochar Labs platform.

A bank buys the same system many times over. Every line of business procures its own stack: an origination system here, a complaints register there, a collections platform, a reconciliation tool, a GRC suite, a case tool for financial crime. Each one is a separate licence, a separate integration, a separate copy of the customer and a separate story told to the regulator. The cost of running the bank rises while the service to the customer does not.

The work underneath is largely the same everywhere. Identify the customer, take the request, apply the policy, decide, record the decision with its reasons, act, and prove it later. That is true of a loan, a complaint, a hardship request, a payment hold, a suspicious matter and a provision, and it is true in every market.

MeshFin treats those as one set of governed AI services on a single platform, mapped to the reference architecture your architects already use. Agents do the processing, people take the decisions that carry legal, financial or regulatory weight, and the evidence is produced as the work happens rather than reconstructed for the examiner.

The baseline

Aligned to the BIAN Service Landscape

BIAN, the Banking Industry Architecture Network, publishes a reference architecture for banking: the Service Landscape, now at version 14.0 (February 2026), with five business areas, 38 business domains and 322 service domains that large banks already use to map their estate. MeshFin takes it as the baseline. The four families follow the BIAN business areas, and every service names the BIAN service domains it covers, so your architects can lay MeshFin over your own BIAN map and see what is covered, what is partly covered and what stays.

The same map your architects use

A service domain in BIAN is a discrete business capability with a defined purpose, control record and behaviour. MeshFin's services are built so that each one covers a set of those domains in whole or in part, and says which.

Interoperability by design

Where a MeshFin service exchanges data with a system you keep, the exchange follows the BIAN Semantic APIs, published by BIAN on GitHub under the Apache 2.0 licence, and ISO 20022 where it applies, so the integration is read from the standard rather than invented per project.

What alignment is, and is not

Aligned means mapped to the published landscape and built to its vocabulary. It does not mean BIAN has reviewed, certified or endorsed MeshFin. BIAN is a trademark of its owner. Where the catalogue covers a domain partly, the service page says partly.

The claim we make

The claim we make: every MeshFin service is mapped to named BIAN service domains, and the mapping is on each service page for your architects to check. That is the whole of the claim.

MeshFin familyFollows the BIAN business area and domainsServices
Family A · Serving customersBIAN Sales and Service: Customer Management, Sales, Marketing, Servicing, Cross Channel6
Family B · Running products and operationsBIAN Operations and Execution: Loans and Deposits, Payments, Account Management, Cards, Investment Management, Trade Banking, Operational Services, Collateral Administration9
Family C · Managing risk and complianceBIAN Risk and Compliance: Regulations and Compliance, Models, Business Analysis5
Family D · Running the organisationBIAN Business Support and Reference Data: Finance, Human Resource Management, Non-IT and Non-HR Enterprise Services, Business Direction, Product Management4

Mapped to the BIAN Service Landscape 14.0 as published on bian.org (read-only, non-member access) and the BIAN Semantic APIs on GitHub (Apache 2.0). Arrochar Labs is not a BIAN member as at October 2026. BIAN is a trademark of BIAN e.V. BIAN has not reviewed, certified or endorsed MeshFin. Service domains that 14.0 marks obsolete (for example Payment Order, Payment Execution) are not used; their replacements are.

The services

The 24 services a bank runs

Each service is a governed AI service in its own right. Run one, or run the bank. The catalogue is the reusable machinery of a financial institution in four families that follow the BIAN business areas; your products, policies and regulator are the configuration.

Every service names the BIAN service domains it covers on its own page. As at October 2026 every service is scoped and none runs for a customer yet; the pattern is proven by MeshGov Regulate, which runs today.

FAMILY A

Serving customers

The front of the bank: who the customer is, what they are offered, what they ask for, and what happens when something goes wrong.

MF-01

MeshFin Onboard

Customer onboarding and identity

A customer becomes a customer once: identity verified with consent against authorised sources, the know-your-customer file built from evidence rather than a checklist, eligibility tested, and the agreement signed in plain language, on any channel, in one sitting.

BIAN: Party Authentication, Party Lifecycle Management, Party Reference Data Directory and 4 more

MF-02

MeshFin Serve

Customer servicing and requests

The front door. Every request on every channel identified with consent, classified, resolved where it can be and routed where it must be, with the status visible to the customer until it is closed.

BIAN: Servicing Order, Servicing Issue, Servicing Mandate and 4 more

MF-03

MeshFin Offer

Sales, offers and product eligibility

Offers made only to customers who are eligible and for whom the product fits, priced from the policy grid, disclosed in plain language and recorded with the suitability evidence beside them.

BIAN: Customer Offer, Sales Product Agreement, Lead and Opportunity Management and 5 more

MF-04

MeshFin Resolve

Complaints and disputes

Every complaint and transaction dispute recognised on any channel, the statutory clock started, the evidence assembled, the outcome decided by a person with reasons, and the systemic issues found that no single complaint reveals.

BIAN: Customer Case, Customer Case Management, Servicing Issue and 2 more

MF-05

MeshFin Assist

Financial hardship and vulnerable customers

A hardship notice recognised in any channel within the statutory time, the options modelled on real income and expenses with consent, the decision taken by a person with reasons and review rights, and collections stopped while the case is open.

BIAN: Customer Relationship Management, Customer Behavior Insights, Customer Case and 2 more

MF-06

MeshFin Share

Open banking, consent and data sharing

Consent granted, shown, enforced and expired exactly as the customer gave it; data served to accredited recipients only within that consent through the standard APIs; every access logged and the regulator's reports produced from the log.

BIAN: Customer Consent, Customer Access Entitlement, Party Authentication and 2 more

FAMILY B

Running products and operations

The products themselves and the operations that fulfil them: accounts, lending, payments, cards, investments, trade and the controls that reconcile them.

MF-07

MeshFin Deposit

Deposits and transaction accounts

Transaction, savings and term deposit accounts kept in real time: every posting explained, interest and fees calculated from the product rules and shown in plain language, maturities and dormancy handled before they become problems.

BIAN: Current Account, Savings Account, Term Deposit and 6 more

MF-08

MeshFin Lend

Consumer and mortgage lending

Application to settlement: the income and expenses verified from authorised data with consent, serviceability assessed against the credit policy and the responsible lending obligations with every figure cited, security checked, and the credit decision held for a person with the delegation.

BIAN: Loan, Consumer Loan, Mortgage Loan and 5 more

MF-09

MeshFin Finance

Business and corporate lending

Facilities for businesses from request to annual review: the financial statements spread and analysed with every figure cited, structure and covenants proposed within policy, covenants tested on the date, and every approval, variation and waiver held for a credit approver.

BIAN: Corporate Loan, Credit Facility, Syndicated Loan and 6 more

MF-10

MeshFin Pay

Payments, clearing and settlement

Every payment validated, confirmed against the payee and the mandate, screened, routed to the right rail, repaired where it can be and settled, with the status explained to the customer and the exceptions held for a person.

BIAN: Payment Order Initiation, Payment Orchestration, Payment Confirmation and 7 more

MF-11

MeshFin Card

Cards issuing, authorisation and disputes

Cards issued, controlled and replaced; authorisations decided in real time by rule against the balance and the fraud score; disputes run to the scheme's reason codes and timetable; scheme files reconciled.

BIAN: Credit Card, Corporate Card Service, Card Authorization and 5 more

MF-12

MeshFin Collect

Collections and recoveries

Early, respectful contact with the options; arrangements set and monitored within policy; every statutory notice prepared in the right form at the right time and held for approval; and no enforcement step without a person deciding it.

BIAN: Collections, Delinquent Account Handling, Customer Behavior Insights and 1 more

MF-13

MeshFin Invest

Investment and wealth account servicing

Investment accounts and portfolios serviced without the paper: orders validated against the mandate, corporate actions processed and explained, statements and fee disclosures written in plain language, and drift from the mandate flagged before a review finds it.

BIAN: Investment Account, Investment Portfolio Management, Custody Administration and 3 more

MF-14

MeshFin Trade

Trade finance and guarantees

Letters of credit, guarantees and trade loans issued from the facility; presented documents examined against the credit and the ICC rules with every discrepancy cited to its clause; amendments, expiries and claims tracked; and every acceptance, refusal and payment held for a person.

BIAN: Letter of Credit, Bank Guarantee, Credit Facility and 1 more

MF-15

MeshFin Reconcile

Reconciliation, positions and operations control

Every rail, scheme, custodian and ledger matched as the files arrive, breaks investigated from the source records with the adjustment drafted and evidenced, and the control attestation produced from the system rather than from a sign-off form.

BIAN: Account Reconciliation, Position Keeping, Transaction Engine and 3 more

FAMILY C

Managing risk and compliance

The second-line machinery a regulated institution runs every day: fraud, financial crime, obligations, credit risk and operational resilience.

MF-16

MeshFin Detect

Fraud and scam detection and response

Every transaction and session scored in real time with an explanation, alerts assembled with the history and the similar cases, customers contacted and funds held or recovered through the rails, and the models watched for drift, bias and false positives.

BIAN: Fraud Evaluation, Fraud Diagnosis, Fraud Resolution and 2 more

MF-17

MeshFin Screen

AML/CTF, sanctions and ongoing due diligence

Parties and payments screened against sanctions and politically exposed person lists with false matches resolved from the record; unusual patterns detected against the customer's own profile and the typologies; cases assembled with the report drafted; and the suspicious matter report lodged only by the compliance officer.

BIAN: Regulatory Compliance, Guideline Compliance, Compliance Reporting and 4 more

MF-18

MeshFin Comply

Regulatory obligations, reporting and breaches

Every new rule and piece of guidance mapped to the obligations register and the controls; regulatory returns compiled from the ledger and the registers and reconciled; incidents assessed against the reportable tests with the clock started; and attestations assembled from evidence.

BIAN: Regulatory Reporting, Regulatory Compliance, Guideline Compliance and 4 more

MF-19

MeshFin Assess

Credit risk, models and portfolio monitoring

Exposures, concentrations, grades and arrears watched daily with the movements explained; expected credit loss stages and overlays run from the policy and reconciled to the ledger; the model inventory kept with validation evidence; and provisions, models and limits decided by the people the policy names.

BIAN: Credit Risk Models, Economic Capital, Customer Credit Rating and 3 more

MF-20

MeshFin Assure

Operational risk, resilience and controls

Incidents captured and assessed against tolerances with the notification drafted; controls tested from system evidence rather than attestations; critical operations mapped to the systems, people and third parties that run them; and audit and regulator findings tracked to closure.

BIAN: Operational Risk Models, Internal Audit, Continuity Planning and 3 more

FAMILY D

Running the organisation

The corporate machinery behind the products: the ledger, the product catalogue, the people and the third parties.

MF-21

MeshFin Ledger

Financial accounting, ledger and close

The general ledger kept from the sub-ledgers as they post; the close run from a checklist with accruals prepared and reconciled; statements and management accounts produced with the narrative; and no journal approved by the person who prepared it.

BIAN: Financial Accounting, Financial Statements, Financial Control and 1 more

MF-22

MeshFin Product

Product design, pricing and governance

Products designed from the template with terms, fees and the target market determination tested against the conduct rules; pricing modelled and proposed within policy; and product performance watched for customers the product was never meant to reach.

BIAN: Product Design, Product Deployment, Product Directory and 3 more

MF-23

MeshFin People

People, accountability and conduct

The accountability map and statements kept current under the accountability regime; access and delegations provisioned from the role and the instrument and removed on change; conduct events assessed against the policy; and training due before it is overdue.

BIAN: Employee Data Management, Recruitment, Employee Payroll And Incentives and 2 more

MF-24

MeshFin Procure

Procurement and third-party management

Sourcing and contracts run to policy; every material service provider assessed against the resilience and security requirements on schedule and from evidence; performance watched against the contract; and exits planned before they are needed.

BIAN: Procurement, Partner Agreement, Partner Management and 2 more

Read about each service in detail

The MeshFin rule

Agents prepare. People decide. Every time.

No decision with legal or financial effect on a customer, on the institution's balance sheet or on a regulatory obligation is taken by an agent alone. A credit decision, a hardship decision, a suspicious matter report, an account exit, a complaint outcome, a provision, a breach report: each is held for a named person with the delegation, with the agent's evidence and recommendation attached, and the record shows who decided, why, on what data and under which policy.

What the platform refuses

  • A credit approval by an officer without the delegation for the amount
  • A payment released from a sanctions hold without a sanctions officer
  • A suspicious matter report lodged by anyone but the compliance officer
  • A default notice issued while a hardship case is open
  • A journal approved by the person who prepared it
  • A disclosure outside a valid consent

Enforced in code, tested on every build and evidenced on a tamper-evident chain, not written in a policy document. A guardrail stops an agent; it does not replace a lawful decision-maker. We will run the test suite in front of you.

The experience

Software people can actually use, on both sides of the counter

Banking software has a reputation: a dozen screens for one customer, a credit file assembled by hand, and a training course to explain a system that should have explained itself. MeshFin is built the other way round, for the people who run the bank and the customers who deal with it.

One workspace, not a dozen systems

A banker works across every service in one interface, with the same navigation, the same search and the same sign-on. No swivelling between the origination system, the core and the case tool, and no re-keying the same customer into all three.

Work arrives prepared, not assembled

The credit file, the complaint file or the AML case is built before the officer opens it: the history, the evidence, the policy that applies and the options, each cited back to its source. The officer spends their time on judgement rather than on assembly.

A bank customers can finish with

Customer-facing services are short, mobile-first and written in plain language, with progress saved as people go and status visible without ringing anyone. An account opens in one sitting. A hardship request is acknowledged the moment it is made.

Ask once, not every time

Nothing is requested that the bank already holds and is entitled to use. Details carry across services with consent recorded, so a customer is not asked for the same payslip by three different teams.

Accessibility designed in, not bolted on

Interfaces are designed against WCAG 2.2 AA, built to work with a keyboard and a screen reader, and written at a reading level the whole population can use. Conformance is assessed and evidenced for your deployment rather than asserted once and left.

One design system across every service

A service switched on next quarter looks and behaves like the ones already in use, so staff do not relearn the software and improvements land everywhere at once.

How MeshFin helps your institution

One platform, every line of business

Retail, business, wealth, payments and the second line run as services on the same platform, on one identity model and one evidence chain, instead of a shelf of unconnected systems that each need integrating and each tell the regulator a different story.

Automate the process, keep the decision accountable

Agents do the intake, the verification, the analysis and the paperwork. People take the decisions that carry legal, financial or regulatory weight, and every decision is recorded with the evidence that supported it and the delegation it was taken under.

Efficiencies that compound with every service

Each new service reuses the identity, evidence chain, integrations and design system already paid for. The custom share is kept small by design and measured on every build. The second service is the test.

Less sprawl, less regulatory risk

A stack of unconnected systems is a risk register in its own right: duplicated customer records, integrations nobody owns, controls tested by attestation, and findings that stay open because no single system can answer them. Consolidating onto one governed platform removes the sprawl those findings live in.

Efficient and compliant, not one at the cost of the other

Cost comes out because the processing is automated, not because service or control levels drop. Decisions become consistent because the same policy is applied to everyone, and the evidence is produced as the work happens rather than reconstructed for the regulator.

Adopt one service at a time

Start with the service under the most pressure: complaints, hardship, collections or onboarding. Run it alongside what you have, then add the next. No bank has to replace its core to get value from the first service.

Built for any jurisdiction

The products, policies, delegations, thresholds and regulatory forms are configuration, not code. A bank in Australia, the United Kingdom, Singapore or the United States runs the same platform against its own rules and its own regulator.

The core bank stays, if you want it to

MeshFin is not a core banking replacement. It runs the operations around the core, through the BIAN-aligned interfaces, and retires the systems around it one at a time. Whether the core itself moves is a later decision, taken with the evidence.

How it is delivered

Standard rails, made to measure for your institution

The governance platform is ready-made and identical for every institution, so its assurance is reused rather than rebuilt, while each service is still assessed on its own. The services that run on it start from the catalogue and are built to fit your products, your policies and the way your institution actually works. Every build runs on the platform, in four layers.

1

Rails first

AIG Sentinel and Meshbone go in unchanged. They are the same for every institution, which is why the security architecture below is assessed once and that assessment reused, read in your regulator's language. Each service still carries its own assessment; the rails make it smaller.

Platform subscription
2

Templates from the catalogue

Each of the services above starts from a template that already runs on the rails and is mapped to its BIAN service domains: intake, verification, assessment, decision, record. A bank switches on the ones it needs, in the order that suits it.

Subscription per service
3

Made to measure for the bank

Your products, your credit policy, your delegations, your thresholds, your regulatory forms and your data model, configured and coded onto the template. This is where the hard part lives, the policy exceptions, the legacy core and the regulator's own forms, so the custom share is scoped in three columns before the build and reported after it. Anything another institution could use goes back into the template.

Fixed-scope build
4

Run, and hand over the controls

The service runs on the platform in your region, with monitoring, re-attestation and upgrades included. After go-live your own staff change a threshold or a form within guardrails, without raising a change request to us.

Subscription

The rule

No made-to-measure build without the platform underneath it. It is the rule that keeps a custom service governed, upgradeable and provable, instead of a fork that has to be maintained by hand forever.

Prudential and conduct regulators increasingly expect exactly this arrangement to be documented: the institution remains accountable for the service, the provider's controls are assessed as a material service, and the evidence of both is available on request. MeshFin is built to be bought that way.

Deployment and ownership

Runs in your account. You own the instance.

MeshFin deploys into the tenancy your institution already controls, in the region you choose. The running instance, the database, the evidence chain and the AI credentials are yours to operate, back up and audit. Nothing in a MeshFin instance calls back to Arrochar Labs.

Your cloud, your region

Delivered as a container image with infrastructure code, so the same build runs on AWS, Google Cloud, Microsoft Azure or in your own data centre. One instance per institution: its own database, its own records, its own tamper-evident evidence chain. All the services share the rails inside that one instance.

Your identity, your delegations

Staff sign in through your directory with multi-factor authentication. Roles map to your delegations instrument and your accountability map, so the gate checks that the person deciding holds the delegation, and every attempt, allowed or refused, is on the record.

Your model route, in region

Claude runs under your own agreement with Anthropic, or through Amazon Bedrock or Google Cloud Vertex AI in your region, pinned so prompts and customer data never leave it. Every agent has a deterministic path and runs fully without a model, so a model outage never stops a lawful decision.

Your data, your exit

Outbound traffic is read-only to the payment rails, the schemes, the bureaus and the model route you chose. Records, agent runs and the evidence chain export in open formats. At exit the data is returned and deleted on a certified schedule.

What Arrochar Labs keeps, and what it provides

The software stays ours under licence, delivered as the container image and infrastructure code you can rebuild from, with source escrow where you require it. We provide the deployment automation, the assurance evidence for your security and outsourcing assessments, the operating runbooks, the monthly release train and support under a service agreement. The platform subscription attaches to every instance; the services on it are built to measure for your products and policies.

Built to be assessed as a material service under the prudential standards for operational risk, information security and outsourcing in your market. The assurance pack supports your assessment; your assessor decides.

Security architecture

Built to the standard a regulated balance sheet demands

MeshFin handles the records a bank holds on its customers: identities, accounts, credit files, complaints, suspicious matters. It is built to the highest security standard we hold any product to, and the controls are architectural rather than configured on afterwards.

Zero trust, tenant isolated

Every request is authenticated and authorised on its own merits. Each institution's tenant is isolated at the data, compute and key layer, with phishing-resistant multi-factor authentication on all administrative access.

Encrypted, with keys you hold

Data is encrypted in transit and at rest, with customer-managed keys so the platform operator cannot read a tenant's records.

Aligned to the baselines you are examined against

Built to align with ISO/IEC 27001, SOC 2, the NIST Cybersecurity Framework, PCI DSS where cards are in scope, the OWASP LLM Top 10 and ISO/IEC 42001, and mapped to the prudential standards for information security, operational risk and outsourcing in each market we serve. Aligned where aligned; certified only where a certificate exists.

Tamper-evident by default

Every agent action, approval, override and data access is written to an evidence trail that cannot be altered after the fact, which is what turns an automated process into a defensible one in front of a regulator or a court.

Read the full security architecture
Questions

What banks ask about MeshFin

What is MeshFin?
MeshFin is a governed AI platform for the operations of a bank, a mutual or a non-bank lender, built by Arrochar Labs on the Meshbone control plane. It runs the twenty-four services an institution needs to run itself, from onboarding, lending, payments and cards to complaints, hardship, financial crime, compliance and the ledger, as AI services on one platform, mapped to the BIAN Service Landscape. Run the bank on governed AI. Serve customers better, cut the cost of operations, keep every decision accountable to the regulator.
What does aligned to BIAN mean?
BIAN, the Banking Industry Architecture Network, publishes the Service Landscape: a reference architecture of business areas, business domains and service domains that large banks use to map their estate. MeshFin's four families follow the BIAN business areas, and every MeshFin service names the BIAN service domains it covers in whole or in part, on its own page. Aligned means mapped to the published landscape and built to its vocabulary. It does not mean BIAN has reviewed, certified or endorsed MeshFin. BIAN is a trademark of its owner.
How does MeshFin keep people in charge of decisions?
By the MeshFin rule: no decision with legal or financial effect on a customer, on the institution's balance sheet or on a regulatory obligation is taken by an agent alone. A credit decision, a hardship decision, a suspicious matter report, an account exit, a complaint outcome, a provision or a breach report is held for a named person with the delegation. Agents prepare the evidence, options and a recommendation; the person decides, and the record shows who, what, why, which data, which policy and which human.
What are the twenty-four MeshFin services?
Four families that follow the BIAN business areas. Serving customers: Customer onboarding and identity; Customer servicing and requests; Sales, offers and product eligibility; Complaints and disputes; Financial hardship and vulnerable customers; Open banking, consent and data sharing. Running products and operations: Deposits and transaction accounts; Consumer and mortgage lending; Business and corporate lending; Payments, clearing and settlement; Cards issuing, authorisation and disputes; Collections and recoveries; Investment and wealth account servicing; Trade finance and guarantees; Reconciliation, positions and operations control. Managing risk and compliance: Fraud and scam detection and response; AML/CTF, sanctions and ongoing due diligence; Regulatory obligations, reporting and breaches; Credit risk, models and portfolio monitoring; Operational risk, resilience and controls. Running the organisation: Financial accounting, ledger and close; Product design, pricing and governance; People, accountability and conduct; Procurement and third-party management.
Is MeshFin a core banking system?
No. MeshFin runs the operations around the core, through BIAN-aligned interfaces, and retires the systems around the core one service at a time: the origination tool, the complaints register, the collections system, the reconciliation tool, the GRC platform. Whether the core itself moves is a later decision, taken with the evidence from the services already running.
Is any MeshFin service running today?
No. As at October 2026 every MeshFin service is scoped: its BIAN mapping, events, agents, gates and records are defined, and none runs for a customer yet. The pattern is proven by MeshGov Regulate, the government regulation service from the same rails and the same formula, which runs today. The first MeshFin services are proposed in order of regulatory pressure: complaints, hardship, collections and onboarding.
Is customer data sovereign on MeshFin?
Yes. Data is hosted in the institution's own region and boundary, on in-region cloud or customer-hosted infrastructure, encrypted in transit and at rest with customer-managed keys. Customer data is never used to train models, and models run inside the institution's boundary through the model route it chose.
Which security and AI governance frameworks does MeshFin align with?
Built to align with ISO/IEC 27001, SOC 2, the NIST Cybersecurity Framework, PCI DSS where cards are in scope, the OWASP LLM Top 10 and ISO/IEC 42001, and mapped to the prudential standards for information security, operational risk and outsourcing in each market. For AI, the bar is ISO/IEC 42001, the EU AI Act high-risk obligations, the NIST AI RMF and Australia's ten AI safety guardrails, with model risk management treated as a first-class control. Arrochar Labs says aligned where it is aligned and certified only where a certificate exists.
How is MeshFin delivered and priced?
Standard rails, made to measure. The governance platform (AIG Sentinel and Meshbone) is identical for every institution and sold as a platform subscription. Each service starts from a catalogue template on a per-service subscription and is built to measure for the institution's products, policies, delegations and regulator as a fixed-scope build, scoped and reported in three columns: standard, configured, coded. No made-to-measure build runs without the platform underneath it.
Can MeshFin run in our own cloud account so we own it?
Yes. MeshFin deploys as a container image with infrastructure code into the tenancy you control, on AWS, Google Cloud, Microsoft Azure or your own data centre, in your region. You own the instance, the database, the evidence chain and the model credentials, and nothing in the instance calls back to Arrochar Labs. The software stays under licence, with source escrow where you require it.
AgentGUARD™

Guarded by AgentGUARD™

Every agent, ours or yours, under the same four classes of control

Directive, preventive, detective and corrective. Written in AIG Sentinel, enforced at the gateway in front of the model, carried in every Nanolitte template, evidenced on one chain.

See the controls
1

Directive

What the agent is allowed to do, as data.

2

Preventive

What stops it before it acts.

3

Detective

How we know when it goes wrong.

4

Corrective

How it is stopped, reversed and fixed.

How it fits together

Not just AI agents. An architecture for accountable ones.

Each part of ASP™ does one job, in order, and hands the next part something it can check. That is the difference between building AI agents and running them so an auditor, a regulator or a minister can see what happened.

Before the first build, Orbit Roadmaps finds where AI creates value and profiles the risk.

After it, Execdive turns what the chain recorded into plain-language insight for executives.

Policy, enforcement, templates, data, controls, evidence. Then services.

This describes the architecture, not what every deployment runs today: 5 of the 27 AgentGUARD™ controls are still in development.

  1. AIG Sentineldefines policy
  2. Meshboneenforces policy at run time
  3. Nanolittecarries the controls into reusable service templates
  4. Databallastcontrols what data the agent may access
  5. AgentGUARD™is the cross-platform control set
  6. Evidence chainrecords what happened
  7. MeshGovuses the whole thing for government services
  8. MeshFinuses the whole thing for banking and financial services

One architecture, every product

A full AI-agentic experience

Every Arrochar Labs product is built the same way: agentic, event-driven, and governed with human-in-the-loop controls, so AI does the work while your people stay in control.

Agentic

AI agents do the work, end to end. Every product runs on autonomous agents that take action across your processes, not just a chat box, but software that actually gets the job done.

Event-driven

It reacts in real time. Products respond to what's actually happening (new data, a policy breach, an incoming request, a change in your estate) instead of waiting on a batch run or a person to press go.

Human-in-the-loop

Your people stay in control. Approval gates, oversight and a tamper-evident audit trail keep every agent accountable, so automation never runs unchecked.

Start with one service

Tell us which service is under the most pressure in your institution, complaints, hardship, collections or onboarding, and we will show you what it looks like running on MeshFin, mapped to your BIAN landscape.