UK AI studio · Regulated operations

AI for the work
off-the-shelf software
won't touch.

DOCUMENT PROCESSING/CLAIMS REVIEW/ONBOARDING/REGULATORY REPORTING/INBOX TRIAGE/LEGACY-SYSTEM OPS/RECONCILIATION/CASE MANAGEMENT/DOCUMENT PROCESSING/CLAIMS REVIEW/ONBOARDING/REGULATORY REPORTING/INBOX TRIAGE/LEGACY-SYSTEM OPS/RECONCILIATION/CASE MANAGEMENT/
Built by people fromUK PARLIAMENTLLOYDSHSBCASSOC. OF BRITISH INSURERS
[ 01 ] The thing most people get wrong[ NS · 01 ]

The model was neverthe hard part.

The point of view

Every vendor sells you a model. But the model is the cheap, solved part. The expensive part, the part that drains your operation, is the work trapped in systems no model can reach: the insurer portal behind MFA (multi-factor authentication), the legacy core with no API, the shared inbox, the quarterly return assembled by hand. That's where the cost sits. It's the exact work horizontal tools, big consultancies and "AI consultants" route around, because it's hard, it's regulated, and it doesn't demo well.

We go there on purpose. We map the operation, score every workflow, and build only what pays back. That includes supervised agents that operate those closed systems the way a trained member of staff would, with a person approving every critical action and a full audit trail. It's the highest-value, most-stuck work in a regulated business. It's where we work.

"If a £50-a-month tool could already do it, we'd tell you to go and buy it. We exist for the work it can't."

[ 02 ] What you're really choosing between[ NS · 02 ]

Be honest aboutthe alternatives.

Five real options. Four are reasonable some of the time. Here's where each one takes you, and where it stops.

01

Horizontal AI tools & SaaS point solutions

Good for

Clean, common, well-defined problems with a clean API.

Where it stops

Built to avoid the messy, closed, regulated systems on purpose. The moment the work hits an MFA-gated portal, a legacy platform with no API, or documents that change format every quarter, the tool routes around it. That untouched work is usually most of your cost.

02

Big consultancies & systems integrators

Good for

Large, multi-year transformation with a board mandate and a budget to match.

Where it stops

A strategy deck and a pilot, billed by the partner-hour, with a team that rotates off before production. You pay for the slide that says “automate the portal”, not the working agent that does.

03

Generic ‘AI consultants’

Good for

A team that needs awareness, a chatbot demo, or training to get started.

Where it stops

Training and prompt tips don't change your operation. You end up with a more AI-literate team doing the same manual work in the same closed systems. It feels like progress and moves no numbers.

04

Hiring an internal AI team

Good for

Organisations with the scale and pipeline to keep senior AI engineers busy for years.

Where it stops

12 to 18 months and several senior salaries to find out whether the first build pays back. Most regulated SMEs don't have the volume to keep that talent busy once it does, so you carry the fixed cost regardless.

05

Doing nothing

Good for

Workflows that genuinely aren't worth automating. We'll tell you which ones those are.

Where it stops

The re-keying, the swivel-chair portal work, and the quarterly scramble compound out of sight. One client was losing 900 operational minutes a day (roughly £120,000 a year) to work a reviewed pipeline now does. Doing nothing has a number too; it's just not on an invoice.

So the real question is who will go into the closed-system last mile, prove the hard part before you pay, and leave you with a working system rather than a deck. That's the job we took.

[ 03 ] What we doOPERATIONS / 03

Where AI deliversthe fastest results.

Not experiments. Not prototypes. Real systems that change how regulated businesses operate.

01

Operational automation

Automating repetitive workflows such as document processing, onboarding, claims review, CRM updates and reporting.

02

Operational visibility

Real-time dashboards so leadership sees pipeline performance, bottlenecks and risk in one place.

03

Decision support

Systems that surface risk, anomalies and opportunities in your operational data, so teams decide faster.

04

Compliance-aware systems

Regulatory requirements built in from the start: audit trails, data governance, regulatory reporting.

[ 05 ] Where we workSECTORS / 05

Built for regulated,operationally complex industries.

01

Financial Services

Document-heavy workflows automated across lending, deal flow and compliance reporting.

02

Insurance

Optimise claims, underwriting and customer operations: parse change requests, capture underwriting data, produce clean portal files.

03

Logistics

Tame inbound document chaos, keep operational data in agreement, and give leadership real-time visibility.

04

Legal

Automate workflows on existing practice-management or case systems: intake, document processing, case analysis and knowledge management.

05

Government

AI for high-accountability environments: regulatory reporting, operational dashboards, decision support.

06

Construction

Automate bid management and estimating, unify field reporting, and give leadership real-time oversight of timelines and compliance.

[ 06 ] About North Stack[ NS · 06 ]

Built on real-worldtransformation experience.

Most SMEs don't have an AI problem. They have a workflow problem: manual handoffs, re-keyed data, reporting that takes days, compliance living in spreadsheets. AI only earns its place when it fixes that.

We build operational AI for regulated, process-heavy organisations. We find the workflows that drain time, money and control, then rebuild them to run faster, cleaner and in full view.

0 mins/day
Operational time returned to one client
0%
Less manual effort at PMD Finance
0%
Less document-review time at Marshall Peters
[ 07 ] Built for the regulator in the room[ NS · 07 ]

Governance is the reasonthis is safe to run.

In a regulated operation, "the AI did it" is not an answer you can give a regulator, a client, or a court. So a person can explain, audit and overrule every system we build. That's the whole reason it can be trusted near your operation.

The red lines, permanent
  • 01

    We never automate payments.

  • 02

    We never automate bank-detail changes.

  • 03

    Every regulator submission sits behind a hard, pre-submission human gate. Nothing leaves without explicit sign-off.

How control is built inCONTROLS / 06
01

Human-in-the-loop on anything high-stakes

The pipeline does the reading and typing; a person approves before anything is committed or actioned.

02

Per-action approval for agents

Supervised agents pause for explicit human approval on every critical step in a closed system. Nothing high-stakes is autonomous.

03

Confidence scores

Every extracted field carries a confidence score; low-confidence items are flagged for a human, not silently guessed.

04

Complete audit trail

Every extraction, edit, approval, rejection and agent action is logged and exportable. You can reconstruct exactly what happened and who approved it.

05

Role-based access control

People retrieve and approve only what they're cleared to see, mirroring your existing permissions.

06

A failure & incident playbook

When an agent hits a stuck or unexpected state, it escalates safely to a human. It doesn't improvise.

"We design for the regulator in the room, because in your business there always is one."

[ 08 ] Questions a serious buyer asks[ NS · 08 ]

The questions that actually matter.

The things a COO, operations director or compliance lead needs answered before they'd let us near the operation.

01What does North Stack actually do, in one sentence?

We map a regulated operation, build reviewed AI pipelines on top of the systems you already run, and operate the closed, MFA-gated systems you can't integrate with using supervised agents, with a person approving every critical action.

02How are you different from a horizontal AI tool or a big consultancy?

Horizontal tools are built to avoid the messy, closed, regulated systems where your cost actually sits. Big consultancies hand you a strategy deck and a pilot and rotate off before production. We go into the last mile on purpose and leave you with a working system and an audit trail, not a slide.

03You keep saying ‘supervised agents’. What does that actually mean?

A supervised agent operates a system the way a trained member of your staff would: it logs in, navigates, reads and enters data, but pauses for explicit human approval on every critical action. Nothing high-stakes is autonomous, and payments, bank-detail changes and regulator submissions are hard-gated or never automated at all.

04How do you make sure this is safe in a regulated environment?

Human-in-the-loop on anything high-stakes, field-level confidence scores, role-based access, a complete exportable audit trail, permanent red lines (no automated payments or bank-detail changes), and a hard human gate before any regulator submission. We design for the regulator in the room.

05How does an engagement start, and how do you price it?

It starts with a fixed-fee operations audit: we map the operation, score every workflow on six axes, and hand you a costed, sequenced plan that includes the workflows we'd advise you not to touch. No build is ever priced before we've proven the hard part works on your real data. If the proof fails, you don't pay for a build, and we'll say so.

06How long until we see something working?

The audit is fast. Where a build follows, our first deployments have gone live in around six weeks (PMD Finance). We sequence quick, high-payback wins first so the early work funds the climb.

07Will you rip out our core system?

No. We build on top of what you already run: your CRM, case system, policy or claims platform. Marshall Peters kept their insolvency CRM; PMD kept theirs. Where a system has no usable API, that's the boundary where supervised portal agents take over, rather than a rip-and-replace.

08What if AI isn't the right answer for a workflow?

Then we'll tell you, in writing. Anything scoring below our threshold gets a documented ‘do not automate’ recommendation. Telling you not to build is a successful audit. It's also how you know to trust us when we say a build will pay back.

09Who actually builds this, and what's the regulatory pedigree?

A small senior team with backgrounds at Lloyds, HSBC, the Association of British Insurers, UK Parliament and the University of Toronto, plus an award-winning technical delivery partner. Regulatory and operational experience sits on the team, not in a sub-contractor.

10Where are you based?

We're a UK studio, remote-first across the UK and Europe. Engagements are delivered remotely with no drop in responsiveness. Contact: [email protected].

Newsletter

Field notes from the last mile

What we're building, what we're learning, and what actually works when you automate regulated operations. No hype.

No spam, unsubscribe anytime. We respect your privacy.

[ → ] Next step[ NS · 10 ]

Start with the audit,not the build.

A fixed-fee operations review: we map the workflows draining time and control, score each one, and hand you a costed plan that includes the work we'd tell you not to automate. No build is priced before the hard part is proven.

Remote-first · United Kingdom · [email protected]