Scale decides the headcount. Automation just decides how close to the floor you get.
The regulatory floor and the control architecture establish who has to exist. This page converts that into illustrative headcount across three customer scales and three automation levels, a genuinely different question from "what's the legal minimum," and one this investigation hasn't verified yet. Every figure below is a modelling assumption, not a regulatory minimum, not yet independently verified.
Last reviewed: 2026-07-24
Locked, per the hub's phase-one scope, plus two larger ones to show scaling.
The small scenario is this investigation's actual baseline (see the hub's "The Frame" section). Medium and large exist to show how the floor scales with customer count. They're not alternative baselines this investigation is adopting.
| Scenario | Customers | Product complexity | Operating assumption |
|---|---|---|---|
| Small challenger | 50,000 | Narrow | Digital-only current account, savings, debit card, simple unsecured lending, sponsor-based payments access. |
| Medium retail bank | 500,000 | Moderate | Same as the small scenario, plus broader lending and more in-house first/second-line capability. |
| Large retail bank | 5,000,000 | Broad | Full retail-bank control environment, direct infrastructure dependencies, materially larger support, fraud, and resilience capability. |
Seven components added together, not one number pulled from the air.
Each component maps to something the regulatory floor or the control architecture already establishes: this formula doesn't introduce new obligations, it structures how existing ones convert into headcount.
Total FTE
= named-accountability floor
+ control-function floor
+ volume-driven operations
+ customer-support and complaints capacity
+ technology/resilience/security capacity
+ third-party oversight capacity
+ change-the-bank buffer
Twelve functions, three scenarios, "frontier automation" throughout.
Illustrative FTE at high/frontier automation, not a regulatory minimum, not yet independently verified. See "What's Still Open" below for a known arithmetic discrepancy in the small-scenario total.
| Function | Why a human remains | Small | Medium | Large |
|---|---|---|---|---|
| Board and governance | Independent challenge, committees, strategic decisions. | 1.5 | 2 | 3 |
| Executive management and regulator interface | CEO, finance leadership, ops leadership, accountable sign-offs. | 4 | 6 | 8 |
| Risk management | Risk appetite, limit frameworks, model/change challenge. | 2 | 8 | 30 |
| Compliance and AML leadership | SMF16, SMF17, policy ownership, escalations, SAR governance. | 3 | 15 | 80 |
| Internal audit | Required assurance function; can be outsourced in non-significant firms. | 0.5 | 3 | 20 |
| Finance, treasury, and regulatory reporting | Prudential reporting, liquidity, capital planning, accounts. | 4 | 12 | 70 |
| Payments and reconciliations | Exceptions, breaks, safeguarding of integrity, settlement oversight. | 3 | 15 | 120 |
| Lending and collections | Exceptions, hardship handling, complex arrears, governance. | 2 | 20 | 250 |
| KYC, sanctions, fraud, AML operations | EDD, investigations, alert handling, casework. | 6 | 45 | 350 |
| Technology, SRE, cyber, data | Change control, resilience, security operations, production support. | 10 | 45 | 300 |
| Customer support, complaints, vulnerable-customer handling | Consumer Duty, complaints, tailored support. | 8 | 60 | 900 |
| Legal, privacy, company secretariat | Contracting, board process, privacy rights, contentious issues. | 2 | 6 | 25 |
| Illustrative total | 46.5 | 237 | 2,156 |
Automation compresses each scenario by about the same proportion.
Each group below is scaled to its own maximum, not a shared axis, so read bar length within a group, not across groups. The pattern is the actual finding: moderate → high → frontier automation shrinks every scenario by roughly the same fraction. What makes small, medium, and large different from each other is customer scale, not how automated they are.
This is a model to test, not a finished answer.
- The small-scenario total doesn't foot. Summing the twelve function rows above gives 46, but the source research states the total as 46.5. That half-FTE discrepancy is unresolved here. Flagged rather than silently corrected in either direction.
- None of the twelve function-level FTE figures have been checked against real workload data, recruiter benchmarks, or a working bank's actual headcount. They're the source report's reasoned estimates, not measurements.
- "Moderate" and "High" automation levels are given only as scenario-level totals in the source material, not broken down function-by-function the way "Frontier" is above.
- This model hasn't been challenged by the people who'd actually know: a former regulator, a working MLRO/CRO/COO, an internal auditor. That red-team pass is still open.
This is illustrative modelling, not verified fact.
The regulatory floor and control architecture pages establish who has to exist; this page estimates how many more join them. All three still need the same primary-source and workload-data verification pass.