Fintech <> AI Webinar
Say Yes to AI Without Failing an Audit
MCP gives AI access to the systems your firm runs on. In financial services that only works when you can control what customer data reaches AI, approve which servers run, and produce logs that tie every agent action to a named person.
In this webinar, VP of AI at Usercentrics, Michael Yaroshefsky, will show you:
- how to filter customer data and NPI out before it reaches the model
- how to satisfy DORA and examiner requirements with per-user audit logs
- how to approve MCP servers before anyone connects them, instead of finding out after
Thursday, October 1st at 1 PM ET
RSVP for Free. Can’t make it live? We’ll send you the recording

The Presenter
Michael “Yaro” Yaroshefsky is the VP of AI at Usercentrics. He also founded MCP Manager, which Usercentrics acquired in 2026. Yaro’s AI security and governance expertise has appeared in leading tech publishers like The New Stack, AI Journal, and CIO.com.
Trusted by companies like:
What financial regulators ask for and how MCP gateways help
Approve servers before anyone connects them
DORA third-party ICT register. Every agent connection becomes an inventoried entry in one governed gateway, with a fail-closed allowlist that blocks anything not explicitly sanctioned. You approve a server up front instead of discovering it in a log afterwards.
Keep NPI out of the model
GLBA Safeguards Rule. Gateway rules block, redact, mask, replace, or hash customer data inline, before it reaches the model. Detection runs on regex for account and card numbers, plus Presidio, Bedrock Guardrails, or Lakera for free text.
A person, not a service account
DORA and SR 11-7 oversight. The gateway brokers a specific identity on every upstream call, so each log entry names the real user even when the downstream system uses a shared account. That is what makes the record support non-repudiation.
Records an examiner can use
SEC and FINRA recordkeeping. Every call is logged with the requesting identity, the tool invoked, the request and response payloads, and the enforcement verdict. Searchable across users and timeframes, years after the decision it relates to.
Read and write, separated per tool
Least privilege and segregation of duties. Turn off an individual tool when it grants too much access, and scope servers per team so quants, engineers and front office get different gateways. An agent can be held to read-only and never handed a write tool.
Inside your existing monitoring
NYDFS Part 500 and DORA resilience. Forward logs to your SIEM over OpenTelemetry, with connectors for Datadog, Splunk, Grafana and others, or a self-hosted collector in your own region. Rules fail closed on a detector outage, and kill switches cut off a connection instantly.
AI Governance in Fintech:
How Finimize Stops MCPs from Sending Customer Data

MCP Manager’s Impact on Finimize:
5
teams safely connecting MCPs to AI, without sending PII
30
minutes from guardrail creation to verified filtering in Claude
30,000+
secure messages sent via MCP gateways in first month
MCP Manager allows us to filter out the data that we don’t want to ever hit AI. We can now connect the core tools that we use day-to-day with Claude, even if those tools have PII in them. Before, we couldn’t connect certain MCP servers at all.
Matt Dalton
CTO at Finimize
What you can put in front of an examiner
Every claim below is enforced at the gateway, and evidenced in the log:
- No agent reaches a system we did not sanction
- Customer data and NPI are stopped before the model sees them
- Every action ties back to a named person, not a service account
- Agents are scoped below the permissions their user already has
- A detector outage denies sensitive data instead of passing it
- The record lives in our SIEM, on our retention schedule
Built by a company regulators already know.
MCP Manager is built by Usercentrics, Europe’s largest consent management platform, active in more than 100 countries and processing billions of consent signals every month across millions of websites and apps.
Deciding what data is allowed to flow, and proving it afterwards, is the job Usercentrics has done since before AI made it urgent. Review the security posture at the Usercentrics trust center, and the pre-signed DPA at mcpmanager.ai/dpa.