AI / ML

The ESG-Compliance-AI Convergence: Why Your Next Risk Model Needs an Engineering Team, Not Just a Data Team

Agentic AI in Dutch banking is reshaping how financial institutions approach ESG, compliance and AI governance. Discover why AI engineering is becoming the critical capability for building resilient, future-ready banking systems.

The ESG-Compliance-AI Convergence. Human oversight lead points out discrepancies comparing AI generated report data.

Dutch banks are facing three major shifts at once. Yet many financial institutions still manage them as three separate challenges.

CSRD is reshaping ESG reporting, demanding sustainability data with the same rigour as financial data. At the same time, the EU AI Act and DORA are introducing new requirements for how AI systems must be governed, explained and kept operationally resilient. Alongside these regulatory changes, banks are beginning to deploy agentic risk and compliance systems. 

Each of these developments would represent a significant programme of work on its own. 

Together, they expose something many organisations have not fully recognised. ESG teams, compliance teams and AI or data teams often work independently, even though they rely on the same underlying capabilities.

In reality, these are not three separate challenges. They are one connected capability challenge. Most internal teams are still structured as if they were not.

Three Regulatory Waves, One Data Problem

CSRD requires companies, including banks and the businesses they finance, to report on sustainability performance with the same rigour as financial reporting. The EU AI Act requires that AI systems, particularly higher-risk ones, be explainable, monitored, and auditable. DORA requires financial institutions to demonstrate operational resilience across their technology estate, including third-party and AI-driven systems.

Although CSRD, the EU AI Act and DORA address different regulatory priorities, they all depend on the same underlying capability.

That capability consists of clean, traceable data, auditable decision logic and real-time monitoring that can withstand regulatory scrutiny.

Yet many organisations continue to build these foundations separately, creating unnecessary duplication across ESG, compliance and AI initiatives.

What Happens When AI Outpaces Governance: Rabobank’s Lesson

Rabobank’s own journey into AI offers a useful example of the governance challenges many financial institutions face.

The bank’s IT and risk departments introduced a temporary moratorium on AI initiatives while they assessed the technology. Rabobank then established a steering committee to define AI categories, identify potential use cases and set clear experimentation boundaries within the bank’s risk appetite.

Vincent Kolijn, Head of Strategy & Transformation, has since highlighted the tension facing regulated banks: while fintechs, neobanks and fraudsters can often move faster, established financial institutions must innovate within strict regulatory and risk-management frameworks. This illustrates the balancing act facing many financial institutions: accelerating AI adoption while meeting increasingly demanding regulatory and governance requirements. Few banks can afford to prioritise one at the expense of the other. 

The Infrastructure Is Already Being Built, Just Not in Public View 

Much of the public conversation still presents agentic AI in banking as a future ambition. The engineering work, however, is already underway. 

Rabobank, for instance, is actively building dedicated agentic infrastructure within its Data & Analytics organisation. The bank is hiring specialist platform engineers to design and maintain the cloud infrastructure required for agentic AI, including containerised environments and agent orchestration frameworks that will support future autonomous risk and compliance capabilities. 

Rabobank is not alone. Across Dutch banking, organisations are investing in the engineering foundations needed to support agentic AI. Industry-wide, development is moving towards automated risk alignment, dynamic control calibration and real-time typology detection, banks have not yet deployed these capabilities at scale across the sector. What is already taking shape is the infrastructure that will enable them.

That distinction matters for two reasons. First, it shows that the gap between agentic AI as a concept and agentic AI as deployed infrastructure is closing faster than public announcements suggest. Second, it highlights how banks are choosing to build these systems. Banks are adopting orchestration tooling built around explicit, structured control flows rather than unrestricted autonomy. Even at the infrastructure level, banks are prioritising traceable, governable agent behaviour.

This reflects what is already emerging at the customer-facing level, where autonomous systems operate within clearly defined and auditable boundaries rather than without oversight.

For banks planning the next phase of AI adoption, these infrastructure decisions carry long-term consequences. For risk and compliance leaders, the takeaway is clear: the platform engineering decisions being made today will determine whether future ESG-aware risk models and compliance monitoring systems are defensible to regulators or become difficult to justify during an audit.

The Talent Gap Behind Autonomous Banking

Dutch banks are building engineering foundations that require a different mix of expertise than banks have traditionally needed. As AI, ESG and regulatory compliance become more closely connected, so do the skills needed to deliver them.

Building this kind of infrastructure requires specialists who understand ESG data and reporting requirements, regulatory compliance, and hands-on AI and platform engineering. Individually, these skills already exist within many organisations. Bringing them together in the same teams, however, remains far less common.

That combination is becoming increasingly important as banks move from experimenting with AI to deploying governed, production-ready systems. Success no longer depends solely on building accurate models. It also depends on designing engineering platforms that are transparent, resilient and capable of meeting regulatory expectations.

This is precisely the challenge Levy helps organisations address. By connecting clients with professionals who combine technical expertise and regulatory understanding, Levy supports the delivery of AI systems that support both innovation and long-term resilience.

The opportunity extends beyond organisational strategy. Roles such as platform engineer, AI engineer and data engineer are already evolving as banks invest in the infrastructure that will underpin agentic AI. The work is no longer limited to developing models. Increasingly, it involves designing systems that satisfy both technical and regulatory requirements.

These are the capabilities shaping the next generation of AI engineering in financial services. Explore opportunities at Levy. 

One Challenge, Not Three 

Dutch banking is where ESG, compliance, and AI are converging most rapidly, and the banks getting ahead of it aren’t doing it with three separate teams working in silos. The winners will be the ones who treat ESG reporting, AI governance, and compliance automation as one connected capability challenge rather than three separate projects competing for the same budget and the same data.

Key Takeaways

  • CSRD-driven ESG reporting demands are growing at the same time as EU AI Act obligations phase in — same data, same pressure, disconnected teams
  • Agentic AI is already being explored industry-wide for automated risk alignment, dynamic control calibration, and compliance prioritization
  • Rabobank’s own experience shows what happens when AI, risk, and compliance aren’t aligned early: a bank-wide moratorium to reset
  • The infrastructure for self-updating, ESG-informed risk models is already being built industry-wide, and it’s being built around structured, traceable agent behaviour, reinforcing that “agentic” in banking means governed, not unchecked
  • Closing the ESG-compliance-AI gap requires specialists fluent in all three domains simultaneously, a rare and specific hiring challenge

Ready to discuss your delivery challenge?

We help teams build the specialist capability needed for complex programs. Tell us what you are working on.

Contact us