Build or buy is the first real decision in any AI initiative, and for a FINMA-regulated institution it is also the one with the longest shadow. The choice of custom AI vs off-the-shelf is usually presented as a cost question — licence a SaaS product or commission a bespoke build — but in regulated finance the deciding factors are data sensitivity and auditability, not the sticker price. Get the decision right and the system survives an internal audit for years. Get it wrong and you inherit either a tool you cannot account for or a build you cannot maintain.
Five questions decide it, and they are worth answering in order. How sensitive is the data the workflow touches — client identities, NAV files, board papers? How unique is the workflow to your institution, or is it a commodity that every fund runs the same way? What is the scale — one report a quarter, or thousands of documents a month? What internal capability do you have to own what you choose? And how much time pressure are you under? Each answer pulls the decision toward one of three archetypes; the trap is letting a single answer — usually time pressure — override the rest.
The first archetype is buy off-the-shelf, and it fits more cases than vendors of bespoke work like to admit. For a commodity workflow on low-sensitivity data — calendar coordination, meeting summaries, internal knowledge search — a mature SaaS product is the right answer. You are not differentiated by how you schedule meetings, and building a custom tool for it is a vanity project. The one caveat that is non-negotiable in regulated finance: confirm where the data goes. A product that routes prompts through an endpoint outside your control turns an innocuous workflow into an outsourcing and data-residency question the moment it touches anything confidential.
The second archetype is buy and integrate — take a capable platform you already license and configure the workflow inside your own environment. This is the pragmatic middle for mid-complexity workflows: the calculation logic is yours, the document store is yours, but you are not writing a model from scratch. Most institutions already own more of this than they realise; the Microsoft stack most Swiss finance teams license can carry a surprising amount of automation before a custom build is justified. The work here is integration and process design, not algorithm research — which is exactly where most of the value sits anyway.
The third archetype is build custom, and it is rarer than the market implies. It earns its keep in exactly three situations: the data is too sensitive to leave your environment, the workflow is genuinely specific to how your institution operates, or the capability is a competitive edge you do not want to rent. Regulated reporting is the textbook case. When reporting across 39+ funds at a leading Zurich investment foundation was automated, an off-the-shelf platform could not have carried it — the calculation had to stay deterministic and auditable, the data had to stay in their environment, and the format had to bend to investor and regulatory demands on their schedule, not a vendor's roadmap. Custom was not a preference; it was the only configuration that passed.
The decision tree, then, is not custom AI vs off-the-shelf as a matter of taste. Start from the workflow and its control points. If the data is low-sensitivity and the process is a commodity, buy. If the logic is yours but the engine need not be, buy and integrate. Only when sensitivity, specificity, and strategic value all point the same way should you build — and then build where compliance can audit it. The institutions that waste the most money are the ones that build commodities and buy their crown jewels. The discipline is knowing which workflow is which before the first contract is signed.
