New: the Kontor regulatory map, with UK, EU and US obligations mapped to controls and evidence. Read it

[ Blog / Product ]

Agent Operating Procedures: how we make servicing agents auditable

The Kontor team·1 October 2026

Every lender already knows how to govern human servicing teams: you write standard operating procedures, train people on them, and audit against them. The problem with AI agents has never been capability — it's that nobody could point to the procedure the agent was following.

Agent Operating Procedures are our answer. An AOP defines one piece of servicing work — a hardship plan, a billing dispute, a payoff quote — in plain language, the way you'd train a person. Kontor compiles it into policy checks and executes it with the consistency of code.

What an AOP looks like

An AOP has four parts:

  • A procedure, written in plain language by your operations team. Not pseudo-code, not a flowchart tool — sentences.
  • Steps and conditions, including explicit branch points: if there are signs of vulnerability, hand over to a trained specialist.
  • Limits, stating what the agent may do alone, what it may only propose, and what is never its decision.
  • Guardrails that hold regardless of the procedure: never issue a default notice, never change interest, never promise an outcome.

Written like prose, governed like code

The plain-language form is the source of truth, but it goes through the same lifecycle as credit policy:

  1. Versioned. Every change produces a new version; the old one stays, because past actions reference it.
  2. Replayed. Before a version goes live, it runs against your historical cases, so you see what the agent would have done differently before any customer does.
  3. Approved. Four-eyes sign-off in Console, by named people.
  4. Recorded. Every action an agent takes carries the AOP version it followed.

When a regulator asks why the agent did something, the answer isn't a model card or a prompt log. It's a numbered procedure, a version, and the approval trail behind it.

Why not just prompts?

Prompts are instructions; they aren't controls. They don't version cleanly, they don't compile to checks the platform can enforce, and they can't make guarantees about what the agent will never do. An AOP is enforced outside the model: the runtime refuses actions the procedure doesn't grant, whatever the model generates.

That's the line we think the industry will converge on: agents that are flexible in conversation and deterministic in consequence.

[ More from the blog ]

Run your credit book on Kontor.

Bring a product spec or a portfolio extract. We'll show you how the ledger, decisions and agents would run it, and what your regulator would see.