Human-in-the-Loop Controls for AI-Initiated Payments
Tiered risk scores route payments to the right human reviewer before money moves.

Once a payment clears and reaches legal finality, undoing it ranges from difficult to impossible. That single fact makes payment initiation the sharpest edge of agentic AI in banking today. Agentic systems already execute multi-step tasks with limited human steering: approving invoices, reconciling accounts, flagging exceptions. Payments differ because the moment of execution is also the moment an error becomes permanent, so governance has to catch a problem before finality, not after it.
A toggle, either a human approves every AI-initiated payment or no human does, fails in both directions. Review everything and the review turns into theater: volume forces reviewers to click through without reading. Automate everything and the institution loses the accountability chain that regulators and auditors need to trace a decision back to a responsible party. Both failure modes share a root cause: neither asks which humans should review which decisions, or at which moment in the transaction's life. A tiered architecture answers that question. A toggle can't.
What a tiered control architecture looks like across transaction risk
Picture three lanes running parallel to each other, each handling a different band of risk. Low-risk, routine payments flow straight through, auto-approved with no human in the loop at the moment of execution. Mid-risk payments route to a human reviewer before they go out. High-risk or anomalous payments escalate further still, to a senior authority or to a dual-authorization requirement, and some get blocked outright pending that second signature. That is the shape a tiered human-in-the-loop system takes, and it's the shape the strongest emerging guidance converges on.
The IMF's 2026 note lays out the toolkit behind it: mandate-based authorization, architectural separation of decision-making from execution, agent identity frameworks, programmable payment controls, audit trails, and tiered human-in-the-loop models. None of these function alone. Each covers a gap the others leave open.
A regulatory consultation on oversight practices names six distinct oversight models. A tiered architecture doesn't pick one of these six and stop there. It spans the range, applying the strictest model to the riskiest transactions and the loosest to the safest ones.
The decision layer has to be distinct from the execution layer, and that separation carries the whole weight of the design even though it sounds almost mechanical. An agent that can both decide a payment should go out and then send it, with no seam between those two steps, collapses the only point where a control could actually intervene. Decoupled human-in-the-loop research on agentic workflows treats this separation as foundational, not optional. Review has nothing to attach to without it. By the time anyone looks, the money has already moved.
Setting the thresholds that determine which tier a payment lands in
Who decides what counts as low-risk versus high-risk? That's a policy question before it's a technical one. The answer has to be owned at the right level of the institution, configurable as conditions change, and auditable after the fact.
Dollar value is the most obvious input, but it's rarely the only one that matters. Combined with payee history, transaction pattern, and anomaly signals, these inputs produce a risk score, and that score routes a transaction into its tier, not any single factor taken alone.
The same logic applies to who is allowed to touch what. Least privilege applies to the human reviewers in this architecture just as much as it applies to the agents.
Setting the thresholds is the easy part. The real discipline starts after. The HITL governance framework describes feedback loops where AI agents learn from human decisions over time, refining future threshold calibration and cutting down on escalations that don't need to happen. The institution has to retain that control directly. A threshold that drifts on its own, shaped by the agent's own learning without a human checking the direction, stops working as a safeguard and turns into just another variable nobody is watching.
JP Morgan's framing gets at the core of it: organizations face a fundamental governance challenge in deciding what they are willing to delegate to a machine, at what thresholds, and under what conditions. High-value payment authorization is the clearest test case for that challenge, because the cost of getting the threshold wrong is most visible and least reversible there. A quieter requirement follows: the threshold decisions themselves need to be logged, along with the transactions that pass through them. A reviewable governance process requires that the calibration history itself sits inside the audit trail.
Regulators aren't leaving this to each institution's judgment indefinitely. The Revised Interagency Guidance on Model Risk Management (SR 26-2), issued by the Federal Reserve, OCC, and FDIC, supersedes the 2011 SR 11-7 and extends model risk management obligations to traditional statistical and non-generative AI models used in threshold-setting and risk scoring. Generative AI and agentic AI are explicitly excluded from that scope for now. The threshold logic behind tier assignment may fall under formal model risk management requirements well before the agents executing on those thresholds do.
Why the human review step fails when the interface is designed poorly
A human sitting in the approval chain is not the same thing as a human exercising judgment. That gap is the most underappreciated failure mode in the entire architecture, and it comes down to automation bias: the tendency to trust a system's recommendation more than the evidence actually supports.
The International AI Safety Report 2026 names this directly. An approval screen that just shows a model's recommendation and a button marked "approve" is a formality that happens to have a person attached to it.
A review surface has to give a reviewer something to actually weigh. A reviewer who sees only "approved by AI, confidence 94%" has nothing to push back against. A reviewer who sees the invoice next to the payment request, the vendor's history, and a flag that the bank account changed two weeks earlier has something to actually evaluate.
Sibos 2026 offered a glimpse of this in production. BNY, BNP Paribas, Deutsche Bank, HSBC, and Citi all showed AI agents running live in exception handling, covering payment repair, trade document checking, and process dispatch. The override rate and time-to-approve are the two numbers to watch together from that work. If the override rate falls at the same time approval time collapses, that's the early signature of reviewers clicking through faster because they've stopped actually checking.
High-risk approvals need more than a well-designed screen. They need step-up authentication and a genuine separation of duties, so the chain of authority from request to execution can be reconstructed afterward, not just logged as a timestamp and a click. A regulatory expectation shapes the whole design and doesn't bend: the institution has to be able to explain to a regulator how a model reached a given decision. A review surface that obscures that reasoning fails the regulator's test as surely as it fails the reviewer sitting in front of it.
Where Human Oversight Reaches Its Operational Limits
What happens when the agent is initiating thousands of actions a day and no human can look at each one? The architecture has to change shape at that point. Oversight doesn't disappear, but it has to move.
Continuous human review of every individual decision becomes operationally impossible past a certain scale. Human attention has to move up a level, from approving individual actions to governing the boundaries within which the agent is allowed to act.
The FSB's June 2026 consultation states this directly. For agentic deployments operating at scale, it recommends a human-in-command model centered on oversight of autonomy boundaries and guardrails. It expects AI-in-the-loop monitoring to become warranted as the number of agents grows, with the AI systems themselves alerting humans when accuracy metrics are breached, or when a human asks to be alerted.
The consultation includes a live case that makes this concrete. A large internationally active bank built an agentic fraud detection system that monitors more than 80 million signals every day. The agent proposes new detection rules, but the fraud analytics team reviews and approves every single rule before it goes live. Human approval still happens, applied at the rule level. The review point moves from each transaction to the policy governing all of them, and that shift is the mechanism by which human oversight scales without quietly disappearing.
None of this loosens who answers when something goes wrong. The FSB is explicit that institutions and individuals retain ultimate accountability even where the monitoring itself is mostly machine-led. Shifting toward AI-assisted monitoring changes where human attention gets spent. Who answers for the outcome stays fixed.
The security attack surface that tiered controls must account for
A tiered control built to catch honest mistakes is only half a defense. The agent also has to withstand someone trying to manipulate it on purpose.
A human-in-the-loop control is only as trustworthy as the information the agent puts in front of the reviewer. If an attacker compromises the agent through a prompt injection or a similar manipulation, the reviewer may see a clean, convincing approval screen while the agent executes something else underneath it. An injection attack slips past a reviewer who's already clicking through on autopilot far more easily than it slips past one actually checking the evidence on screen.
The FSB's recommended mitigations target this directly. Adopt dynamic identity and access management: grant, change, or revoke permissions in real time based on behavior and context, rather than relying on a static profile set once and left alone.
The IMF's 2026 toolkit puts agent identity frameworks in the same category of necessity. A reviewer approving a payment needs proof that the agent initiating it is actually the agent it claims to be.
For the architecture to hold up under this kind of pressure, the audit trail has to capture more than the final payment instruction. It needs the tool calls the agent made, the data sources it referenced, and the intermediate steps along the way. A review surface with that full chain gives a human something real to evaluate in the moment, and it gives an investigator, after the fact, the ability to reconstruct how the agent was manipulated.
The regulatory layer's requirements for tiered HITL implementation
Regulators aren't waiting for the industry to settle best practice before writing their own rules. The Revised Interagency Guidance on Model Risk Management (SR 26-2), issued by the Federal Reserve, OCC, and FDIC, supersedes the 2011 SR 11-7 and extends model risk management obligations to traditional statistical and non-generative AI models. It explicitly excludes generative AI and agentic AI from its scope. Institutions should read that exclusion as a signal of where the next round of guidance is headed.
A supervisory standard is blunt: a bank that cannot explain why an AI model behaves the way it does cannot truly control that model. An institution unable to demonstrate control cannot satisfy its supervisor, no matter how sophisticated the underlying system is.
Broader AI governance frameworks turn that principle into specific architectural obligations. The institution has to be able to trace any decision back to its source data and the model logic that produced it.
For agents handling financial transactions involving customer funds, the FSB's June 2026 consultation sets a higher bar still: human approval or dual authorization above a defined threshold value, restricted agent access to payment systems, and audit trails covering every agent transaction. These form the floor the FSB expects a responsible institution to already have in place.
SOC 2 certification and broader compliance-readiness work matter here for a practical reason. Every requirement in this section, from immutable records to traceable decisions to dual authorization, converges on the same artifact: a complete audit trail ties the tiered architecture to the regulatory obligation that makes it mandatory.
Voice and Text Interfaces and Control Design for Payment Initiation
The underlying risk tiers don't change, but the mechanics of confirming and reviewing a transaction have to be rebuilt for a channel that doesn't leave behind the equivalent of an unsigned form.
Research on language-centric AI in retail banking shows that voice and text interfaces are already capable of executing real banking operations on existing infrastructure. That capability is why the confirmation step has to carry real weight by design, not by default. A voice flow needs an explicit confirmation step with a full read-back of the payee and the amount before anything executes. It needs a clear, unambiguous way to cancel or undo before the payment reaches finality. And it needs to tell the user which actions the agent can take on its own and which ones require something more.
The tiering logic carries over without needing to be reinvented. A recurring payment to a payee the system already knows can confirm and execute off a simple verbal yes. A first-time payee, or an amount that crosses the relevant threshold, has to route to a stronger confirmation method, the same way it would if the payment had been initiated through a structured form or an API call. The channel a payment comes through doesn't change its risk tier.
The real design challenge voice and text interfaces raise is continuity: making sure the confirmation steps and the audit trail the tiered architecture requires travel with the transaction no matter how it started. A payment initiated by voice still needs the same payee history, the same policy checks, and the same reconstructable chain of authority as one initiated through a dashboard. The interface changes. What the architecture demands of it stays the same.


