HSBC
This is an illustrative blueprint, built only from public information, for how a global bank of HSBC's scale could run the Mickai sovereign stack on its own infrastructure. It walks the Finance vertical pack across the bank: anti-money-laundering and transaction monitoring at scale, model-risk-registered underwriting and analytics, and board-level reporting, with every piece of transaction and customer data staying inside the bank's own perimeter. No firm named here is a Mickai customer. The point is to show the shape of a deployment, where the studios sit, and which regulatory obligations the architecture is designed to ease, not to claim any engagement.
This page is an illustrative analysis built only from public information. HSBC is not a Mickai customer and has no relationship, engagement, trial, or endorsement with Mickai. Nothing here implies that HSBC uses, has trialled, or has engaged the Mickai SIOS. It is a sector blueprint showing how a global bank of this scale could deploy the sovereign stack.
HSBC is publicly reported as one of the world's largest banks, with revenue in the tens of billions of US dollars, a workforce of around 220,000 people, and operations spanning roughly 60 countries and territories. These are approximate, published figures used here for sizing the illustration only. Treat them as indicative rather than exact, and defer to HSBC's own filings for precise numbers.
These architectural choices support control over the workflows in your deployment. Their benefits depend on configuration, integrations and operating practices. Review external connections, physical security, access and compliance responsibilities together.
Scope inference, extraction, retrieval and storage on infrastructure you control. Document and test any external connector, support channel or transfer before describing a workflow as zero-egress.
Workflows with local models, data and supporting services can continue offline. Live external email, calendars and other services need an approved connection or controlled import, with clear unavailable and pending states.
Map prompts, documents, indexes, logs and backups to their processing and storage locations. Local hosting supports control of location; access, retention and any transfers still need review.
Prepare and classify source records, preserve permissions and evaluate answers against the originals. Retrieval and model training are separate choices; agree data use and licences for each.
Compare hardware and licences alongside integration, power, administration, support, updates, evaluation and recovery. Measure cost at the required workload and quality before claiming savings.
Define who holds keys, who can administer the system and which actions need approval. Test denied requests, revoked access and audit records. Physical security, insider risk and incident response remain operational responsibilities.
Agree version selection, signed update procedures, rollback, data export and licence rights. Reassess requirements as software and obligations change; owning hardware does not remove maintenance or compliance work.
Review the requirements relevant to your organisation, jurisdiction and intended use with your responsible teams. Cloud services can be appropriate subject to applicable safeguards; on-premise deployment alone does not establish compliance or remove supplier responsibilities.
The enterprise studios that lead in this sector, drawn from the eighteen that sit on the one sovereign substrate. Scope their local processing, operator-held keys and Open Audit Record coverage for the proposed deployment. Confirm availability and any external integrations before relying on a workflow.
Fraud and Anomaly Detection
Runs AML and transaction-monitoring workloads at bank scale, scoring payment flows and surfacing suspicious patterns and anomalies for investigation, with the underlying transaction and customer data never leaving the bank's own perimeter.
Underwriting and Actuarial
Hosts credit and underwriting analytics as model-risk-registered assets, so each model carries its validation evidence, version history, and monitoring trail in line with SR 11-7 and OCC expectations.
Compliance and Regulator Mode
Provides a regulator-facing mode that maps controls and evidence to SR 11-7, NYDFS Part 500, DORA, and FCA SYSC obligations. The bank keeps its own regulatory obligations, while the friction of assembling and presenting evidence is reduced.
Audit
Maintains immutable, queryable audit trails across model decisions, data access, and analyst actions, giving internal audit and examiners a single defensible record without exporting data to an external platform.
Executive BI
Rolls AML, model-risk, and underwriting metrics into board-level and divisional reporting, so risk, compliance, and executive committees see the same governed numbers drawn from data that stays in-house.
See all eighteen on the sovereign services catalogue.
At this scale the surface is enormous: billions of transactions to monitor across roughly 60 jurisdictions, a large estate of credit and analytics models each carrying its own validation and monitoring burden, and a compliance function answering to several regulators at once. The illustrative opportunity is to consolidate AML, model-risk-registered underwriting, audit, and executive reporting onto one sovereign substrate the bank runs itself, rather than spreading sensitive transaction and customer data across multiple external vendors and cloud regions. This is a qualitative picture of scale, not a quantified forecast.
Measure value, cost and risk on hardware you control.
A buyer evaluating the Finance pack would see AML and transaction monitoring, underwriting analytics, audit, compliance evidence, and executive BI running as connected studios on infrastructure the bank controls. Transaction and customer data stays inside the bank's own perimeter rather than being exported to an external platform. The architecture removes the third-party cloud-exposure vector and eases the cross-border-transfer and third-party-processing friction, while physical, insider, and regulatory controls remain the bank's own. Models stay registered and auditable to support SR 11-7, OCC, NYDFS Part 500, DORA, and FCA SYSC work, and the whole stack runs independent of the public internet and cloud vendors.
Map the sovereign stack to your organisation estate.
Briefings are for organisations weighing a sovereign, on-premises deployment. Tell us about your estate and we will walk the pack, the regulatory crosswalk, and the deployment that fits your estate.
Note: This page is an illustrative analysis built only from public information. HSBC is not a Mickai customer and has no relationship, engagement, trial, or endorsement with Mickai. Nothing here implies that HSBC uses, has trialled, or has engaged the Mickai SIOS. It is a sector blueprint showing how a global bank of this scale could deploy the sovereign stack.