sitkastack

Your regulated financial back office runs on manual work. I automate it with AI that survives an audit.

AI-powered back-office and operations automation for banks, credit unions, insurers, lenders, and fintechs. Built by an operator who has done it before. Every automation ships with an audit log, a model record, and a named owner, so it holds up when OSFI, an examiner, or your board asks. Take the manual cost out without adding risk.

Book a 20-minute back-office conversation See the track record

Track record

I have automated the regulated back office before.

  • 85% of manual onboarding automated and 61.5% annual sales growth at Refresh Financial, later acquired
  • $500M originated on a lending platform launched in 18 months
  • AML/KYC and POS modernization across 600+ retail locations

Selected work

Regulated-environment delivery.

15+ years shipping systems in fintech, financial services, and regulated industries.

85%
of manual onboarding automated

Fintech · Canada

Refresh Financial: sales and servicing automation

A call-centre-dependent sales and servicing model that couldn't scale. Led the end-to-end automation build: 85% of manual onboarding automated, 61.5% annual sales growth, and the company was later acquired.

$500M+
originated

Financial services · North America

Consumer lending platform launch

A North American financial services group with 600+ retail locations. They needed a new consumer lending product and had no platform to start from. Built the technology and the product line in 18 months, alongside AML/KYC and POS modernization across the network. It still runs the lending business today.

$200M
projected 5-year customer lifetime value

Retail · Canada

MarTech and customer data platform

A top-five Canadian grocer's $16M MarTech program. Built and integrated the customer data platform behind their marketing automation. The roadmap projects 40% higher engagement and 25% better marketing ROI.

Services

One way in. Most engagements start with the Back-office AI Opportunity Sprint.

Back-office AI Opportunity Sprint

2 to 3 weeks · fixed price

I map your manual back-office and servicing operations, rank where AI can cut cost and time, quantify the savings, and hand you a build plan that passes risk review. You leave knowing exactly what to automate, in what order, and what it is worth.

The build plan maps to your regulatory context: OSFI E-23, SOX, SOC 2, NIST AI RMF, EU AI Act, or ISO 42001. See Frameworks for the mappings.

What comes next.

90-Day AI Build

90 days fixed

I build the top workflow from your Sprint plan and ship it to production. Includes the workflow itself, governance artifacts (model card, risk assessment, audit log specification, eval set), and 30 days of post-launch support. Always preceded by the Opportunity Sprint or equivalent scoping.

Fractional AI Lead retainer

6-month minimum

I keep shipping. Weekly access to senior AI implementation judgment: roadmap delivery, vendor decision support, governance pattern reviews, and team enablement. Three tiers (Standard, Strategic, Embedded) based on engagement depth. Six-month minimum.

Also available.

E-23 Readiness Sprint

4-6 weeks

Standalone OSFI E-23 readiness for federally regulated financial institutions: model inventory, decision surface map, accountability matrix per decision class, and audit-ready evidence artifacts. Includes 30 days of post-completion advisory.

AI Policy & Risk Pack

3 weeks

Governance artifacts that live in your repository and adapt to your regulatory framework: machine-readable model cards, structured risk registers, instrumented audit logging patterns, and vendor AI risk workflows. Mapped to NIST AI RMF, EU AI Act, OSFI E-23, NAIC, or SR 11-7.

Questions about scope or fit? Email me.

Who this is for

sitkastack is built for VPs and Heads of Operations, COOs, and Servicing or Lending Ops leaders at banks, credit unions, insurers, lenders, and fintechs with expensive manual processes and pressure to adopt AI without adding risk.

You hold the budget and feel the pain; your risk or compliance partner is in the room. The work is built so they can sign off on it.

This isn't a fit if

  • You haven't deployed any AI and aren't planning to within the next 90 days.
  • You're a pure-play AI or ML platform company where AI is the entire product. You need an AI platform consultancy, not a back-office automation practice.
  • You're looking for slideware or board-deck output. sitkastack produces working code and structured documentation, not presentations.
  • You don't have at least one named human accountable for AI decisions in your organization. Without that, no governance pattern can hold.
  • You're hoping AI governance is a one-time documentation exercise. It's not. If you're building for a one-time audit pass without lifecycle commitment, this won't survive the next audit.

Automation that survives the exam.

Anyone can wire an AI model into a back-office workflow. In a bank, a credit union, or an insurer, the hard part comes later, when OSFI, an examiner, or your internal audit team asks how a specific decision was made and who owned it.

That question has a precise answer here. Every automation I ship carries its evidence with it:

  • An audit log for every automated decision, tied to the model version that made it.
  • A model record: what the model does, its limits, its evals, and when it was last reviewed.
  • A named owner for every class of automated decision, with a documented override path.
  • Controls mapped to OSFI E-23, NIST AI RMF, SOX, and SOC 2 where relevant.

This is the reason the automation is safe, not the product. The product is the manual cost coming out of your operation. The artifacts are why your risk and compliance partners sign off, and why the savings are still there after the exam.

For Canada's federally regulated financial institutions, OSFI E-23 takes effect May 1, 2027. Automation built now is built to that bar by default.

The sitkastack Framework

Proof I build governed AI in the open: sitkastack's vendor-risk-triage framework is shipped at v1.0.5, eight phases complete, open source under Apache 2.0. 1,377 tests at 100% coverage across twelve packages. The full implementation lives on GitHub, with a worked example on /demo.

The open-source framework is a free reference implementation. It is deliberately not a turnkey audit defense. Paid sitkastack engagements deliver the calibrated, client-specific, audit-ready version mapped to your regulatory context and your data.

Eight phases shipped: Discovery & Risk Classification; Data Contracts & Privacy; Architecture & Threat Model; Agent + RAG + Ingestion + Eval; Eval Depth + Retrieval Quality; Operational Hardening; Production Polish; Multi-tenancy + Schema Migration.

How sitkastack compares

vs. the status quo

Manual back-office processes do not stay cheap. Headcount scales with volume, error and rework costs compound, and every audit request turns into a scramble for evidence. That cost grows every quarter. The Opportunity Sprint quantifies it and hands you a ranked plan to take it out.

vs. Big 4 or boutique advisory

Big 4 engagements typically run 6-9 months and produce slide decks. sitkastack engagements run 2 to 3 weeks (Opportunity Sprint) or 90 days (Build) and produce working code with documentation. Lower cost, shorter timeline, working artifacts versioned in your repository instead of PDFs in a SharePoint folder.

vs. building it with an internal team

Internal teams shipping their first regulated AI workflow typically take 3-4x longer than they expect, because the governance pattern has to be invented from scratch. sitkastack ships proven patterns from an open-source reference framework, so your team builds on a known-good architecture instead of starting from a blank repo. The patterns transfer. I leave your team capable, not dependent.

Robyn is one of the very few non-engineers I've worked with who can genuinely engage in technical trade-offs while still keeping cross-functional teams aligned and moving forward.
Angela Zenner · Senior Engineering Manager, Wealthsimple. Worked with Robyn at Refresh Financial, where Angela was Director of Technology & Development.
Robyn joined Refresh and built our Enterprise PMO from scratch at a critical time in our growth. She has a rare ability to translate high-level strategy into clear execution plans without slowing down the business, particularly in an environment where we were trying to execute quickly without compromising on quality. I trusted her to manage our most complex initiatives and she delivered every time.
Michael Wendland · Founder/CEO at Refresh Financial
I reported to Robyn at Refresh Financial, first as a Project Manager and later as I transitioned into Product and Marketing roles. Robyn is the rare leader who genuinely cares about her team's long-term career path, not just the project in front of her. She supported my growth and helped me develop the strategic skills I needed to level up within the organization. I'd highly recommend her to any team looking for strong leadership.
Tyler Hinds · Product at KOHO (formerly at Refresh Financial, reported to Robyn)

Tools I built and use

The same patterns I apply to client work.

Internal tool

Executive delivery dashboard

A Python pipeline that ingests Jira, Smartsheet, and timesheet data and uses the Claude API for RAG-based program insights, margin analysis, and forecast views. An internal tool I built and use to replace manual status compilation.

Claude APIPythonJiraSmartsheet
Public demo · GitHub (personal repo)

Fintech service ops triage

AI triage tool for service-operations decisions in regulated environments. Confidence-gated routing, PII redaction, prompt-injection mitigation, and structured audit logging.

Claude APIPythonTool use
View on GitHub
Independent build

Multi-persona AI code review

Claude API pipeline running parallel code review across security, performance, readability, and architectural perspectives before commits land. Pattern testing for earlier risk detection.

Claude APIPrompt engineering
Independent build · In daily use

Daily briefing system

Runs overnight. Surfaces what changed, what's at risk, what needs a decision. Reduces inbox triage and morning context-switching.

n8nClaude API

Writing in public.

Notes from the work. Weekly LinkedIn newsletter (Wednesday), weekly Medium posts, LinkedIn posts Tuesday and Thursday.

LinkedIn newsletter and posts

A weekly LinkedIn newsletter every Wednesday on audit-ready AI for regulated mid-market operators. Shorter posts Tuesday and Thursday on patterns from the build and what's working this week.

Newsletter Wednesday · Posts Tue + ThuFollow on LinkedIn

Articles on Medium

Long-form weekly on practical AI, governance, and what's actually working for operators in regulated environments.

WeeklyRead on Medium

Follow sitkastack on LinkedIn for company updates, new builds, and case studies. linkedin.com/company/sitkastack

Robyn Toor, Founder of sitkastack

Founder

Robyn Toor

15+ years shipping systems in fintech and regulated industries, where the work has to hold up in production, not just demo well. sitkastack brings that standard to small and mid-sized operators. Founded in 2025.

MBAPMPAIGP (in progress)CSMCSPOAWS Cloud Practitioner
Full background at robyntoor.com

Let's talk.

Questions about your back office or the work? Email me at robyn@sitkastack.com. If a call is easier, you can also book a 20-minute back-office conversation.