Transforming decades-old banking systems takes more than upgrades; it takes trust – trust in people and in technology. We spoke to Sanjida Gafur, CIO Technical Lead at TSB, at WSO2’s Oxygenate event, whose approach blends transparency, upskilling and AI innovation to modernise its services without missing a beat.

Banking has so much legacy technology. What has been the biggest challenge in modernising TSB’s systems?
The biggest challenge is keeping the business running at the same time as upgrading the systems and modernising them. We cannot afford to be down for 24 hours. Downtime impacts the customers, and we are committed to the customers. Our ultimate goal is to serve them as we are a service. So, the biggest challenge has not been about implementing new technology but about maintaining our systems while we upgrade.
How does AI impact you and your team on a day-to-day basis?
We use AI to inform and accelerate our organisation. We’re modernising our old system and re-platforming it. The old system consists of SOA services, which are almost obsolete right now. To migrate those SOA services to the newer technology, we are assessing and analysing those services and generating reports on them using AI. We are using Claude 3 AI engine for safety and alignment with financial industry compliance.
In terms of challenges we’re facing with AI, one important thing is that Amazon Bedrock runs in US territory, but we hold UK data. Therefore, we cannot actually run any analysis on our data which cannot go beyond this geolocation. But our teams are using GitHub Copilot for the conversion of code in their day-to-day activities to counter this.
What does open-source technology bring to TSB?
I’m a huge fan of open-source technology and have evangelised for it since I am from a Java background. Companies in the financial sector are accountable and responsible for every single action and every single step they’re taking in any area of their service; therefore, they are wary of using open-source technology.
But to do that, we have some governance processes, and we do our own due diligence when using open-source technology. We also have a wide range of tech experts who can help and guide our use of this technology, including the CISO, the CISO’s team and engineers who assist with the evaluation of the products we use. Technology teams set up the scanning and filtration process using industry-standard tools.
I’m confident in open-source technology because I know the product inside out, which always attracts me to FOSS. With other licensed products, they’re not as sleek and clean as they seem to be, whereas with an open-source product, you can actually customise them according to your needs.
When going through a tech transformation, how do you make sure your team is buying in to the new technologies?
My main technique is engaging them from day one and being open and transparent with them from the beginning. Of course, we test various products that are on the market, so we can explain our reasoning behind the transformation.
I think laying it all out as simply as possible and clearly explaining it is an often-overlooked method. Not treating them like children but engaging with them about the basics. For example, we often say: ‘We are going to introduce this new technology. Please familiarise yourself with it.’
Then the next stage is asking the team what their confidence level is in using it. If they are not comfortable, then we try to bring some SMEs in to give us some professional services, and then that allows the team to upskill in those areas.
But I help them and guide them in the development process. They know I am there to help them level up and get the best out of them.
What excites you the most about recent innovations in the financial sector?
Open banking, which is a huge arena, and how security in that field is developing, is exciting. Banks are exposing public APIs and third-party providers integrate with our APIS by adhering to OBIE security standards. Before Brexit, we were using PSD2, which is a European regulation. Now, Open Banking UK has embraced and implemented those regulations as well, and we need to adhere to them. Security, like SSA (software statement assertion), which is technically complex, is one innovative and exciting implementation that we are using right now.
What is the biggest shift you’re expecting to see in banking?
The biggest shift is going to be the use of AI. Any mundane work that was previously undertaken by a human will be passed to AI. The routine works, such as customer verification (aka KYC) and static policy verification, will be delegated to AI-backed tools. Leveraging AI technology for these functions is the biggest shift I expect to see in the banking sector.

