Scale decides the headcount. Automation just decides how close to the floor you get.

The regulatory floor and the control architecture establish who has to exist. This page converts that into illustrative headcount across three customer scales and three automation levels, a genuinely different question from "what's the legal minimum," and one this investigation hasn't verified yet. Every figure below is a modelling assumption, not a regulatory minimum, not yet independently verified.

Last reviewed: 2026-07-24

Locked, per the hub's phase-one scope, plus two larger ones to show scaling.

The small scenario is this investigation's actual baseline (see the hub's "The Frame" section). Medium and large exist to show how the floor scales with customer count. They're not alternative baselines this investigation is adopting.

ScenarioCustomersProduct complexityOperating assumption
Small challenger50,000NarrowDigital-only current account, savings, debit card, simple unsecured lending, sponsor-based payments access.
Medium retail bank500,000ModerateSame as the small scenario, plus broader lending and more in-house first/second-line capability.
Large retail bank5,000,000BroadFull retail-bank control environment, direct infrastructure dependencies, materially larger support, fraud, and resilience capability.

Seven components added together, not one number pulled from the air.

Each component maps to something the regulatory floor or the control architecture already establishes: this formula doesn't introduce new obligations, it structures how existing ones convert into headcount.

Total FTE
= named-accountability floor
+ control-function floor
+ volume-driven operations
+ customer-support and complaints capacity
+ technology/resilience/security capacity
+ third-party oversight capacity
+ change-the-bank buffer

Twelve functions, three scenarios, "frontier automation" throughout.

Illustrative FTE at high/frontier automation, not a regulatory minimum, not yet independently verified. See "What's Still Open" below for a known arithmetic discrepancy in the small-scenario total.

FunctionWhy a human remainsSmallMediumLarge
Board and governanceIndependent challenge, committees, strategic decisions.1.523
Executive management and regulator interfaceCEO, finance leadership, ops leadership, accountable sign-offs.468
Risk managementRisk appetite, limit frameworks, model/change challenge.2830
Compliance and AML leadershipSMF16, SMF17, policy ownership, escalations, SAR governance.31580
Internal auditRequired assurance function; can be outsourced in non-significant firms.0.5320
Finance, treasury, and regulatory reportingPrudential reporting, liquidity, capital planning, accounts.41270
Payments and reconciliationsExceptions, breaks, safeguarding of integrity, settlement oversight.315120
Lending and collectionsExceptions, hardship handling, complex arrears, governance.220250
KYC, sanctions, fraud, AML operationsEDD, investigations, alert handling, casework.645350
Technology, SRE, cyber, dataChange control, resilience, security operations, production support.1045300
Customer support, complaints, vulnerable-customer handlingConsumer Duty, complaints, tailored support.860900
Legal, privacy, company secretariatContracting, board process, privacy rights, contentious issues.2625
Illustrative total46.52372,156

Automation compresses each scenario by about the same proportion.

Each group below is scaled to its own maximum, not a shared axis, so read bar length within a group, not across groups. The pattern is the actual finding: moderate → high → frontier automation shrinks every scenario by roughly the same fraction. What makes small, medium, and large different from each other is customer scale, not how automated they are.

Small challenger, 50,000 customers, narrowModerate70 FTEHigh56 FTEFrontier46.5 FTEMedium retail bank, 500,000 customers, moderateModerate360 FTEHigh285 FTEFrontier237 FTELarge retail bank, 5,000,000 customers, broadModerate3,200 FTEHigh2,500 FTEFrontier2,156 FTE

This is a model to test, not a finished answer.

  • The small-scenario total doesn't foot. Summing the twelve function rows above gives 46, but the source research states the total as 46.5. That half-FTE discrepancy is unresolved here. Flagged rather than silently corrected in either direction.
  • None of the twelve function-level FTE figures have been checked against real workload data, recruiter benchmarks, or a working bank's actual headcount. They're the source report's reasoned estimates, not measurements.
  • "Moderate" and "High" automation levels are given only as scenario-level totals in the source material, not broken down function-by-function the way "Frontier" is above.
  • This model hasn't been challenged by the people who'd actually know: a former regulator, a working MLRO/CRO/COO, an internal auditor. That red-team pass is still open.

This is illustrative modelling, not verified fact.

The regulatory floor and control architecture pages establish who has to exist; this page estimates how many more join them. All three still need the same primary-source and workload-data verification pass.