Hookshot™ Protege Agents cut high-risk findings 88% in five months — and the program grew 40%+ anyway
How a card issuance infrastructure provider replaced five senior compliance officers with two junior analysts, cut high-risk findings 88% in five months, and scaled UDAAP, FDIC, and card disclosure reviews — plus marketing change request approvals — by automating the Asana workflows it already used to track compliance, with Hookshot™ Protege Agents.
40%+
Five senior officers → two junior analysts, program grew 40%+
Five experienced compliance officers replaced by two junior analysts
88%
High-risk findings down 88% in the first five months
12,000
Unique web pages monitored for UDAAP, FDIC Part 328, and card disclosures
Across all advertising domains for the BaaS program
500K+
Content scans processed annually
Partner onboarding and card disclosures
7 figures
Saved per year versus closed-source AI LLM token usage
ShieldLlama, a finetuned open-source model, with Teach your AI feedback loops
About
A leading card issuance infrastructure provider — with 275M+ cards created for startups, software platforms, and enterprises worldwide — monitors regulatory language across its Banking as a Service program. The team ensures card disclosures, advertising language, and partner-facing materials meet UDAAP, FDIC Part 328, Regulation E, and Regulation Z requirements across all regulated marketing.
Key workflows
- Web and regulatory compliance monitoring
- Marketing change request approvals
- Document pre-approvals
- Sponsor bank program coordination
Key features
Protege AI Review, Hookshot™ Protege Agents, Automated Asana review workflows, ShieldLlama (finetuned open-source model), Teach your AI
Key integrations
Asana
Highlights
Challenges
The team already tracked its compliance work in Asana — web monitoring, marketing change requests, and document pre-approvals all moved through Asana projects — but every step still ran manually. They had relied on PerformLine for compliance monitoring, but the platform couldn't be configured for the scale and specificity their growing BaaS program demanded. Five experienced US-based risk and compliance officers spent up to 50% of their time on manual re-reads — reviewing the same disclosure categories and advertising language that an automated workflow should have handled. Every marketing change — a new landing page, an updated disclosure, a revised partner-facing asset — required a full manual pass before it could ship, and that queue backed up alongside the monitoring workload. PerformLine's false positives buried genuine risk signals under noise. The backlog grew so severe the team nearly stopped onboarding new programs altogether.
Solution
Protege helped the team configure and automate the Asana workflows they already used to track compliance — turning manual tracking boards into an automated review pipeline built on Protege AI Review and Hookshot™ Protege Agents. The agents monitor 12,000 unique web pages for UDAAP risk language, FDIC Part 328 advertising disclosures, and Reg E/Reg Z card terms — checking every crawl cycle automatically. The same agents handle marketing change requests: the program brings roughly 600 change requests each year, ranging from single-asset updates to packages of up to 25 assets at once, and every asset is checked automatically before it reaches a human reviewer — so routine changes clear faster and only genuine edge cases get escalated. Document pre-approvals flow through the same automated Asana queue, with gaps surfaced before sign-off. Web monitoring, change requests, and document queues now run as one automated pipeline — two junior analysts focus on judgment calls and escalations instead of re-reading every submission. Running this volume on closed-source AI LLMs would have cost several million dollars per year in token usage. Instead, Hookshot™ Protege Agents run on ShieldLlama, a finetuned open-source model — and Teach your AI lets reviewers feed corrections back into future cycles, so the agents improve continuously.
Outcomes
The program grew more than 40% while replacing five experienced compliance officers with two junior analysts. High-risk findings dropped 88% in the first five months — three quarters of sustained data confirm the trend has held while review volume increased. The automated Asana workflows now cover 12,000 unique web pages for UDAAP, FDIC Part 328, and card disclosure requirements, clear roughly 600 marketing change requests per year, and process over 500,000 content scans annually. Pre-approvals for sponsor bank programs representing $50B+ in card transaction volume run through the same automated pipeline. ShieldLlama kept token costs viable at this scale — closed-source AI LLM pricing would have made the program cost-prohibitive — while Teach your AI ensured agent accuracy improved with every human correction.
Scaling web and regulatory compliance for card programs
Every advertising domain gets checked for UDAAP risk language, FDIC Part 328 advertising disclosures, and Reg E/Reg Z card terms before issues reach sponsor banks or regulators.
Continuous monitoring at scale
Hookshot™ Protege Agents review 12,000 unique web pages across all advertising domains for BaaS compliance — not spot checks on a sample.
- UDAAP risk language, FDIC Part 328 disclosures, and Reg E/Reg Z card terms checked automatically on every crawl cycle.
- Compliance issues flagged before they reach a sponsor bank or regulator.
- Analysts focus on exceptions instead of re-reading every page manually.
Visibility for leaders
- Review volume and finding severity roll up for PMO and risk reporting.
- Every step is recorded automatically in Asana, so teams can answer what changed and when.
Clearing marketing change requests without the queue backlog
Every new or updated marketing asset — landing pages, disclosures, partner-facing materials — runs through the same policy checks as ongoing monitoring, before it reaches a human reviewer.
Volume and scope
- Roughly 600 marketing approval requests move through the queue each year, ranging from single-asset updates to packages of up to 25 assets submitted together.
- Each asset in a multi-asset package is checked individually against current UDAAP/FDIC/Reg E/Reg Z policy.
- Routine changes clear without a full manual pass; only flagged items reach an analyst.
Automating document pre-approvals in Asana
Over half a million content scans move through review each year — partner onboarding packages and card disclosures. Hookshot™ Protege Agents check each one automatically inside the team's Asana workflow.
An automated Asana queue
Pre-approval work runs through the team's Asana queue, now configured to check submissions against UDAAP, FDIC, and card disclosure requirements before sign-off.
- Submissions checked automatically before analysts open each attachment.
- Gaps and missing disclosures surfaced with citations for faster sign-off.
- Exceptions routed automatically — routine approvals move without re-reads.
Hands-off routing
- Every agent decision recorded with inputs, outputs, and rationale — no manual logging.
- High-risk items escalated automatically with full context for human review.
Partner program coordination
The same automated workflows support the program's largest sponsor bank partnerships — one pipeline for pre-approvals, web monitoring, and change requests across the BaaS program.
One automated pipeline across partnerships
- Pre-approvals, UDAAP/FDIC monitoring, change requests, and document diligence run through shared automated workflows.
- Partner volume can grow without adding a senior FTE per new program.
- Review operations stay consistent as domains and queues expand.
Program outcomes
Review coverage expanded across sponsor bank partnerships without adding headcount per program.
- Sponsor bank pre-approvals for programs representing $50B+ in card transaction volume streamlined under one automated workflow.
- One pipeline covers pre-approvals, web monitoring, change requests, and document diligence.
Cost-efficient agents at scale
Reviewing 12,000 web pages and over 500,000 content scans annually through closed-source AI LLMs would have cost several million dollars per year. Hookshot™ Protege Agents on ShieldLlama, a finetuned open-source model, made the program viable.
ShieldLlama instead of closed-source AI LLMs
Hookshot™ Protege Agents run on ShieldLlama, a finetuned open-source model, rather than paying per-token for closed-source API calls — turning a cost-prohibitive proposition into a sustainable program.
- Token costs at this review volume would reach several million dollars annually on closed-source AI LLMs.
- ShieldLlama delivers consistent policy-matching without per-call pricing that scales with volume.
- Hookshot™ Protege Agents apply the same checks whether reviewing 10 pages or 12,000.
Teach your AI — human feedback improves future reviews
When human reviewers correct or override an agent decision, that feedback is incorporated into future review cycles — so the agent improves continuously.
- Analyst corrections fed back into agent behavior for subsequent crawl cycles, change request reviews, and document reviews.
- False positive rates dropped as the system learned from human judgment over time.
- The agent adapts from the review queue itself — no prompt engineering cycle required.
Conclusion
Before automating its Asana compliance workflows with Protege AI Review and Hookshot™ Protege Agents, five experienced compliance officers couldn't keep up with a program they nearly had to stop growing. After, two junior analysts cover more ground — with 88% fewer high-risk findings, roughly 600 marketing change requests cleared per year, and a faster, automated review pipeline for every sponsor bank program. The program that almost froze now adds partnerships without adding headcount — and without the multi-million-dollar closed-source AI LLM bill that would have made it impossible.
"We went from five senior officers re-reading the same disclosures to two analysts handling escalations only — and 88% of our high-risk findings were addressed and remediated within the first five months. The marketing change request queue used to be the bottleneck — now it just isn't."