Hookshot™ Protege Agents cut high-risk findings 88% in five months — and the program grew 40%+ anyway

How a card issuance infrastructure provider replaced five senior compliance officers with two junior analysts, cut high-risk findings 88% in five months, and scaled UDAAP, FDIC, and card disclosure reviews — plus marketing change request approvals — by automating the Asana workflows it already used to track compliance, with Hookshot™ Protege Agents.

40%+

Five senior officers → two junior analysts, program grew 40%+

Five experienced compliance officers replaced by two junior analysts

88%

High-risk findings down 88% in the first five months

12,000

Unique web pages monitored for UDAAP, FDIC Part 328, and card disclosures

Across all advertising domains for the BaaS program

500K+

Content scans processed annually

Partner onboarding and card disclosures

7 figures

Saved per year versus closed-source AI LLM token usage

ShieldLlama, a finetuned open-source model, with Teach your AI feedback loops

About

A leading card issuance infrastructure provider — with 275M+ cards created for startups, software platforms, and enterprises worldwide — monitors regulatory language across its Banking as a Service program. The team ensures card disclosures, advertising language, and partner-facing materials meet UDAAP, FDIC Part 328, Regulation E, and Regulation Z requirements across all regulated marketing.

Region
Global
Company size
Enterprise

Key workflows

  • Web and regulatory compliance monitoring
  • Marketing change request approvals
  • Document pre-approvals
  • Sponsor bank program coordination

Key features

Protege AI Review, Hookshot™ Protege Agents, Automated Asana review workflows, ShieldLlama (finetuned open-source model), Teach your AI

Key integrations

Asana

Highlights

Challenges

The team already tracked its compliance work in Asana — web monitoring, marketing change requests, and document pre-approvals all moved through Asana projects — but every step still ran manually. They had relied on PerformLine for compliance monitoring, but the platform couldn't be configured for the scale and specificity their growing BaaS program demanded. Five experienced US-based risk and compliance officers spent up to 50% of their time on manual re-reads — reviewing the same disclosure categories and advertising language that an automated workflow should have handled. Every marketing change — a new landing page, an updated disclosure, a revised partner-facing asset — required a full manual pass before it could ship, and that queue backed up alongside the monitoring workload. PerformLine's false positives buried genuine risk signals under noise. The backlog grew so severe the team nearly stopped onboarding new programs altogether.

Solution

Protege helped the team configure and automate the Asana workflows they already used to track compliance — turning manual tracking boards into an automated review pipeline built on Protege AI Review and Hookshot™ Protege Agents. The agents monitor 12,000 unique web pages for UDAAP risk language, FDIC Part 328 advertising disclosures, and Reg E/Reg Z card terms — checking every crawl cycle automatically. The same agents handle marketing change requests: the program brings roughly 600 change requests each year, ranging from single-asset updates to packages of up to 25 assets at once, and every asset is checked automatically before it reaches a human reviewer — so routine changes clear faster and only genuine edge cases get escalated. Document pre-approvals flow through the same automated Asana queue, with gaps surfaced before sign-off. Web monitoring, change requests, and document queues now run as one automated pipeline — two junior analysts focus on judgment calls and escalations instead of re-reading every submission. Running this volume on closed-source AI LLMs would have cost several million dollars per year in token usage. Instead, Hookshot™ Protege Agents run on ShieldLlama, a finetuned open-source model — and Teach your AI lets reviewers feed corrections back into future cycles, so the agents improve continuously.

Outcomes

The program grew more than 40% while replacing five experienced compliance officers with two junior analysts. High-risk findings dropped 88% in the first five months — three quarters of sustained data confirm the trend has held while review volume increased. The automated Asana workflows now cover 12,000 unique web pages for UDAAP, FDIC Part 328, and card disclosure requirements, clear roughly 600 marketing change requests per year, and process over 500,000 content scans annually. Pre-approvals for sponsor bank programs representing $50B+ in card transaction volume run through the same automated pipeline. ShieldLlama kept token costs viable at this scale — closed-source AI LLM pricing would have made the program cost-prohibitive — while Teach your AI ensured agent accuracy improved with every human correction.

Scaling web and regulatory compliance for card programs

Every advertising domain gets checked for UDAAP risk language, FDIC Part 328 advertising disclosures, and Reg E/Reg Z card terms before issues reach sponsor banks or regulators.

Continuous monitoring at scale

Hookshot™ Protege Agents review 12,000 unique web pages across all advertising domains for BaaS compliance — not spot checks on a sample.

  • UDAAP risk language, FDIC Part 328 disclosures, and Reg E/Reg Z card terms checked automatically on every crawl cycle.
  • Compliance issues flagged before they reach a sponsor bank or regulator.
  • Analysts focus on exceptions instead of re-reading every page manually.

Visibility for leaders

  • Review volume and finding severity roll up for PMO and risk reporting.
  • Every step is recorded automatically in Asana, so teams can answer what changed and when.

Clearing marketing change requests without the queue backlog

Every new or updated marketing asset — landing pages, disclosures, partner-facing materials — runs through the same policy checks as ongoing monitoring, before it reaches a human reviewer.

Volume and scope

  • Roughly 600 marketing approval requests move through the queue each year, ranging from single-asset updates to packages of up to 25 assets submitted together.
  • Each asset in a multi-asset package is checked individually against current UDAAP/FDIC/Reg E/Reg Z policy.
  • Routine changes clear without a full manual pass; only flagged items reach an analyst.

Automating document pre-approvals in Asana

Over half a million content scans move through review each year — partner onboarding packages and card disclosures. Hookshot™ Protege Agents check each one automatically inside the team's Asana workflow.

An automated Asana queue

Pre-approval work runs through the team's Asana queue, now configured to check submissions against UDAAP, FDIC, and card disclosure requirements before sign-off.

  • Submissions checked automatically before analysts open each attachment.
  • Gaps and missing disclosures surfaced with citations for faster sign-off.
  • Exceptions routed automatically — routine approvals move without re-reads.

Hands-off routing

  • Every agent decision recorded with inputs, outputs, and rationale — no manual logging.
  • High-risk items escalated automatically with full context for human review.

Partner program coordination

The same automated workflows support the program's largest sponsor bank partnerships — one pipeline for pre-approvals, web monitoring, and change requests across the BaaS program.

One automated pipeline across partnerships

  • Pre-approvals, UDAAP/FDIC monitoring, change requests, and document diligence run through shared automated workflows.
  • Partner volume can grow without adding a senior FTE per new program.
  • Review operations stay consistent as domains and queues expand.

Program outcomes

Review coverage expanded across sponsor bank partnerships without adding headcount per program.

  • Sponsor bank pre-approvals for programs representing $50B+ in card transaction volume streamlined under one automated workflow.
  • One pipeline covers pre-approvals, web monitoring, change requests, and document diligence.

Cost-efficient agents at scale

Reviewing 12,000 web pages and over 500,000 content scans annually through closed-source AI LLMs would have cost several million dollars per year. Hookshot™ Protege Agents on ShieldLlama, a finetuned open-source model, made the program viable.

ShieldLlama instead of closed-source AI LLMs

Hookshot™ Protege Agents run on ShieldLlama, a finetuned open-source model, rather than paying per-token for closed-source API calls — turning a cost-prohibitive proposition into a sustainable program.

  • Token costs at this review volume would reach several million dollars annually on closed-source AI LLMs.
  • ShieldLlama delivers consistent policy-matching without per-call pricing that scales with volume.
  • Hookshot™ Protege Agents apply the same checks whether reviewing 10 pages or 12,000.

Teach your AI — human feedback improves future reviews

When human reviewers correct or override an agent decision, that feedback is incorporated into future review cycles — so the agent improves continuously.

  • Analyst corrections fed back into agent behavior for subsequent crawl cycles, change request reviews, and document reviews.
  • False positive rates dropped as the system learned from human judgment over time.
  • The agent adapts from the review queue itself — no prompt engineering cycle required.

Conclusion

Before automating its Asana compliance workflows with Protege AI Review and Hookshot™ Protege Agents, five experienced compliance officers couldn't keep up with a program they nearly had to stop growing. After, two junior analysts cover more ground — with 88% fewer high-risk findings, roughly 600 marketing change requests cleared per year, and a faster, automated review pipeline for every sponsor bank program. The program that almost froze now adds partnerships without adding headcount — and without the multi-million-dollar closed-source AI LLM bill that would have made it impossible.

"We went from five senior officers re-reading the same disclosures to two analysts handling escalations only — and 88% of our high-risk findings were addressed and remediated within the first five months. The marketing change request queue used to be the bottleneck — now it just isn't."

Product Risk Lead Banking as a Service program

Build with us

See Hookshot in your stack.

Request early access or book a live walkthrough with the team.

Request Demo
Hookshot™ setup screen — AI agent workflow configuration with model selection, trigger status, and governance controls.