EY · Tech Consulting · Hard · 35-45 min

Modern Data & AI Platform for a KSA Bank

Modern Data & AI Platform for a KSA Bank is a hard EY tech consulting case interview that runs 35-45 min. A mid-tier Saudi retail bank — ~3M customers, four legacy core systems, monthly regulatory reporting that takes ten days — wants a 12-month build of a modern data and AI platform. A strong answer works through 5 phases: Clarify business outcomes and the as-is data estate before architecting; Defend the platform choice; Handle SAMA CSF directly; Sequence GenAI use cases; Make the commercial case fit.

Last updated 2026-09-05

The brief

A mid-tier Saudi retail bank — ~3M customers, four legacy core systems, monthly regulatory reporting that takes ten days — wants a 12-month build of a modern data and AI platform. Budget is SAR 3.5–5M. SAMA Cyber Security Framework applies. The CIO wants Azure, the head of risk wants on-prem, and the new Chief Data Officer wants a GenAI pilot live in six months. You are defending the platform proposal in front of the steering committee.

How to approach it

  1. Clarify business outcomes and the as-is data estate before architecting — what value pool justifies the SAR 3.5–5M
  2. Defend the platform choice — Azure region(s), Medallion lakehouse, Kafka + Debezium CDC, Purview for catalog/lineage
  3. Handle SAMA CSF directly — data residency, tokenization vs masking, model hosting, key management
  4. Sequence GenAI use cases — RAG vs fine-tuning, MVP selection, what goes live in month 6 vs month 12
  5. Make the commercial case fit — SAR 3.5–5M split across build/run/license, FinOps from day one, who owns what at go-live

What a strong answer does

  • Anchors the architecture to a specific P&L impact (fraud loss reduction, time-to-report, conversion uplift) before drawing the platform
  • Picks Medallion + CDC with concrete reasoning — latency targets, idempotency, replay needs — not just because it is current best practice
  • Differentiates tokenization (irreversible, vault-backed, used for PII at rest) from masking (reversible, used in non-prod) by zone
  • Defaults to RAG for the first two GenAI use cases and reserves fine-tuning for genuine domain-language gaps; explains why
  • Calls out the org change — who runs the platform after go-live, where the data product owners sit, what the CDO actually owns

Red flags interviewers score down

  • Designs the platform without a value pool — picks Medallion because it is fashionable rather than because it solves the reporting SLA
  • Treats SAMA CSF as a checkbox at the end rather than a constraint that shapes region, key custody, and model hosting
  • Says 'fine-tune everything' or 'RAG everything' without naming a use case where the other approach would be better
  • Promises GenAI in production in month 6 without addressing model risk, hallucination controls, or who signs off

Cases are written in each firm's style, written and reviewed by working consultants; they are not the firms' own published cases.

Common questions

What does this EY data and AI case test?
Whether you can defend a platform proposal to a steering committee: the value pool that justifies the budget, the architecture (including SAMA cyber constraints), GenAI sequencing, and who owns the platform after go-live.
Is this a real EY or bank case?
No. It is written in EY's technology-consulting style for practice. It is not a published EY case and it is not a real client engagement.
How long does the case take?
About 35–45 minutes live with the AI interviewer, then a scored report on structure, business acumen, quantitative reasoning, and communication.

More EY cases