A small language model that profiles every business borrower and watches for what changes.
A bank's credit risk team was assembling business risk profiles by hand from financials, ownership records, internal exposure, and external signals, then not looking again until the next annual review. We trained a small language model that reads those sources inside the bank and keeps an evidence-backed profile and monitoring alerts on every borrower.
- Client
- Bank with commercial and SME lending across several regions
- Engagement
- Discovery sprint, then a 10-week build
- Team
- Three CoServe engineers and a strategist with the head of credit risk
- Deployment
- On-premise, two GPUs in the bank's data centre
A borrower profile built by hand at onboarding, then left alone until the next annual review.
For every business borrower, a credit analyst assembled a risk profile from financial statements, ownership and group structure, the bank's own exposure to the business across products, and whatever external signals they could find: filings, legal notices, rating actions, news. It took days per review, and the review happened once a year.
Between reviews, the picture went stale. A director change, a group company in default, a deteriorating set of accounts filed mid-year, a supplier dispute in the courts: all of it sat unnoticed until the next cycle, or until the account was already in trouble. The team knew they were finding problems late and had no capacity to look more often.
Hosted AI tools were ruled out early. Borrower financials and the personal data of directors could not leave the bank, and the regulator expected every statement in a profile to be explainable and traceable to its source.
A narrow model trained on the bank's own analysts, running on the bank's own hardware, graded before it was trusted.
Discovery began with the credit risk team and three years of past profiles. We worked out what a complete profile contains, which sources carry signal, how analysts weigh them, and what evidence a credit committee expects behind each statement. That became the verifier: a written standard for a correct profile, agreed before any training started.
We then trained a small language model on the bank's historical documents and the analysts' past profiles. It reads each borrower's financials, ownership records, internal exposure, and external signals, extracts the facts that matter, links every one back to the passage it came from, and assembles the profile. When a new document or signal arrives, it compares against the last profile and raises a monitoring alert on what changed. The verifier scores every extraction; anything below the bar goes to an analyst with the model's reasoning attached, so the queue is review rather than rediscovery.
The model runs on two GPUs in the bank's own data centre. No document leaves the network, there is no per-token bill, and the bank owns the weights. Alongside the model we delivered a model inventory, evaluation records, and decision logs mapped to the bank's model-risk policy, so the system passed internal model validation before it touched a live portfolio.
What changed once it was running.
Five components, one system the client owns.
- 01
Source intake
Connectors for financial statements, ownership and group registries, the bank's exposure systems, and external filings and news feeds, normalised into one stream the model reads.
- 02
Profile extraction model
A small language model post-trained on the bank's documents and past analyst profiles, producing structured profiles with cited passages for every statement.
- 03
Verifier and review queue
An independent checker that scores every extraction against the agreed standard, and a queue where low-confidence items reach an analyst with the model's reasoning alongside.
- 04
Monitoring alerts
Continuous comparison of new documents and signals against each borrower's last profile, raising an alert with evidence when something material changes.
- 05
Governance pack
Model inventory, evaluation history, and decision logs mapped to the bank's model-risk policy and the guidance its regulators reference.
Business risk profiling does not need a frontier model reading your borrowers' financials over the internet. A narrow model trained on your analysts' own judgement, running on your own hardware, and graded against a standard you wrote, keeps every profile current and every claim traceable, without the data ever leaving the bank.