What problem does it solve?
In a bank or insurer the knowledge that staff need to do their job correctly is scattered across credit and risk policies, operating procedures, product manuals, compliance guidance and internal research: many documents in several systems, each with versions. Keyword search returns a list of PDFs. Staff ask a colleague, use an outdated copy, or give a customer a wrong answer.
Retrieval augmented assistants change the interaction: ask a question, get an answer with the paragraphs it came from. The hard problems are not the model. They are permissions (an answer must never come from a document the person may not see), currency (the answer must come from the version in force), and trust (people must be able to check the source quickly). Done well, one governed retrieval layer can serve the service desk, HR, frontline and specialist assistants instead of each building its own.
How does it work?
- Ingest and index approved sources. Policies, procedures and research are ingested from the document management system, intranet and knowledge base, with owner, version and access rights kept as metadata.
- Retrieve with permissions. When an employee asks, retrieval runs only over documents their role and entitlements allow, combining semantic and keyword search.
- Answer with citations. The model answers only from the retrieved passages and cites each document and section, so the employee can open the source.
- Refuse when unsure. If retrieval finds nothing relevant or sources conflict, the assistant says so and points to the owner, rather than guessing.
- Learn from gaps. Unanswered and badly rated questions go to content owners, who fix or write the missing document.
- Audience
- Employee facing
- Autonomy
- Assist
- Adoption
- Mainstream
- Channels
- Internal tools, Microsoft Teams, Agent desktop
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| Interactions handled | Not pooled | at least 23 million | 1 | 1 organization |
Value drivers: Employee productivity, Speed and cycle time, Compliance quality, Customer experience.
Indicative value
A bank with 5,000 employees who regularly look up policies and procedures
USD 2.3 million to USD 18 million
Employee time released per year
How this is calculated
Formula: employees * searchHoursPerWeek * workingWeeks * timeSaved * hourlyCost. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Employees who search internal knowledge regularly employees, employees | 5,000 | 5,000 | The reference organization. |
| Hours per week each spends finding and reading internal information searchHoursPerWeek, hours per employee per week | 2 | 4 | Editorial assumption. Replace with a time study of your own staff. |
| Share of that time saved timeSaved, fraction of search time | 0.1 | 0.25 | Editorial assumption, replace with a time study of your own. No source on this page reports a measured share of search time saved. For comparison, Google Cloud reports that information searches by less experienced SIGNAL IDUNA agents are 30% faster (read as speed, that is about 23% less time per search, since 1 / 1.3 is about 0.77), and that Wells Fargo's tool reduced the workflow for query resolution by about 20%, without saying whether that is time. |
| Working weeks per year workingWeeks, weeks | 45 | 45 | Editorial assumption. |
| Fully loaded cost per hour hourlyCost, USD per hour | 50 | 80 | Editorial assumption. Replace with your own blended cost. |
What it leaves out: Released time, not cash. It leaves out the value of fewer wrong answers to customers and fewer policy breaches, which is often larger, and the cost of cleaning up and maintaining the content.
Who already uses it?
4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Bank of America
United States · Wealth and asset management · 2024
Merrill and Bank of America Private Bank teams use ask MERRILL and ask PRIVATE BANK, built on the technology behind Erica, to curate the information they need for clients. For more complex requests, the chat can connect teams with experts at the bank. The bank reports more than 23 million interactions with the two tools in 2024.
- Interactions handled: at least 23 million, calendar year 2024
"In 2024, there were more than 23 million interactions with ask MERRILL and ask PRIVATE BANK, an increase of 1 million over 2023, helping employees more proactively connect with clients about timely and relevant opportunities."
Claimed by: organization
Morgan Stanley
United States · Wealth and asset management · 2023
Morgan Stanley Wealth Management fully rolled out the AI @ Morgan Stanley Assistant in September 2023, a generative AI chatbot that gives Financial Advisors quick access to the firm's intellectual capital. The rollout followed the firm's March 2023 announcement of OpenAI as its strategic partner. In its June 2024 release the firm said that 98% of Financial Advisor teams had adopted it. It was followed by AI @ Morgan Stanley Debrief, which drafts meeting notes and follow up emails with client consent.
No outcome disclosed.
SIGNAL IDUNA
Germany · Insurance · 2025
SIGNAL IDUNA, a German insurer, built Co SI with Google Cloud, BCG and Deloitte: a knowledge assistant that helps customer service agents answer complex health insurance questions. Google Cloud reports that for less experienced agents, information searches are 30% faster and inquiries that previously needed further escalation dropped from 27% to 3%.
No outcome disclosed.
Wells Fargo
United States · Banking · 2025
Wells Fargo deployed a retrieval augmented tool for branch bankers that finds the relevant policies and procedures during customer interactions. Google Cloud reports that it reduced the workflow for query resolution by about 20%, without saying whether that means time, steps or effort. The bank uses reusable APIs on Apigee to scale generative AI across teams.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- An inventory of authoritative sources with an owner and review date per document
- Access rights per document or collection that can be carried into the index
- A set of real questions per domain with expected answers, for evaluation
Systems to integrate
- Document management and intranet (for example SharePoint or Confluence)
- Identity provider and entitlement data for permission aware retrieval
- The channels where employees work (Teams, the agent desktop, the intranet)
- Feedback routing to content owners
Complexity: Medium
A prototype over a folder of PDFs is quick to build. Production takes longer: connecting several document systems, carrying access rights into the index, handling versions and retirement, and building evaluation sets per domain so answer quality can be measured.
- 1
Start with one domain and its owners
Pick a domain with heavy lookup volume and willing owners, such as operations procedures or product terms. Clean its documents before indexing anything.
- 2
Carry permissions into retrieval
Index access rights with every chunk and filter at query time. Test with accounts of different roles that restricted content never appears.
- 3
Build the evaluation set
Collect a few hundred real questions with expected answers and sources, and run them on every change to content, retrieval settings or model.
- 4
Make citations the product
Show the source passage next to the answer with a link. Staff trust and adopt tools whose answers they can check in seconds.
- 5
Close the loop with content owners
Send unanswered questions and negative feedback to owners weekly, and retire documents that are superseded.
- 6
Offer it as a shared layer
Expose the same governed retrieval to the other assistants (service desk, HR, contact centre) so permissions, residency and versions are enforced in one place.
Guardrails
- Permission aware retrieval, tested with role based test accounts
- Answers only from retrieved passages, with citations, and refusal when nothing relevant is found
- Only the version in force is indexed; superseded documents are removed
- Prompt injection defences for content from shared or external sources
- Query logs protected and retained according to policy
KPIs to instrument
- Answer accuracy and citation correctness on the evaluation set, per domain
- Share of questions answered versus refused
- Weekly active users among target employees
- Time to find information in a time study, before and after
- Negative feedback and content gaps closed per month
Human in the loop
Content owners are accountable for their documents and review flagged answers. Employees remain responsible for decisions they take on the basis of an answer, and high impact decisions (credit, compliance, customer remediation) still follow their documented approval steps.
Common failure modes
- Oversharing through search
- The assistant surfaces documents that were technically accessible but never meant to be widely read. Review permissions before indexing, not after an incident.
- Confident answers from old versions
- Superseded policies stay in the index. Index only the version in force and track effective dates.
- Answers without sources
- Staff cannot verify and either distrust the tool or trust it blindly. Always show the cited passage.
- Many point solutions
- Every department builds its own index with its own permissions. Build one governed layer and reuse it.
What are the risks and rules?
EU AI Act
Limited risk (transparency)
Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant. The system would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)) or making decisions on or evaluating workers (point 4(b)).
Rules that apply
Guidance
- Artificial Intelligence (AI) Model Risk Management, information paper (Monetary Authority of Singapore, Asia Pacific). Good practices for AI and generative AI model risk management observed in a thematic review of banks in mid 2024, covering governance and oversight, risk management systems and processes, and development and deployment.
- OWASP Top 10 for LLM Applications (OWASP Gen AI Security Project, Global). The 2025 list covers prompt injection (including through retrieved content), sensitive information disclosure and vector and embedding weaknesses, the main security risks of retrieval assistants.
- Article 50, transparency obligations for providers and deployers of certain AI systems (European Union, Europe). Providers must design AI systems that interact directly with people so that those people are informed they are interacting with AI, unless this is obvious from the context. Applies from 2 August 2026.
Controls to put in place
- Inventory entry with an accountable owner and the list of indexed sources
- Permission tests per role before each new source is added
- Evaluation set runs on every change to content, retrieval or model
- Document ownership and review dates enforced for indexed content
- Monitoring of refusals, negative feedback and unusual query patterns
When it went wrong elsewhere
- CVE-2025-32711: AI command injection in Microsoft 365 Copilot. A vulnerability recorded by NVD in June 2025, not a reported breach: AI command injection in Microsoft 365 Copilot allowed an unauthorized attacker to disclose information over a network. It shows that an enterprise assistant can be made to disclose information through injected instructions.
Frequently asked questions
- How is this different from the search we already have?
- Search returns documents; the assistant returns an answer with the paragraphs it came from. Google Cloud reports that Wells Fargo's retrieval tool for branch bankers reduced the workflow for query resolution by about 20%, and that information searches by less experienced SIGNAL IDUNA service agents are 30% faster.
- Will employees actually use it?
- Two wealth managers have published usage figures. Morgan Stanley said in June 2024 that 98% of its Financial Advisor teams had adopted its AI @ Morgan Stanley Assistant. Bank of America reports more than 23 million interactions in 2024 with ask MERRILL and ask PRIVATE BANK, a volume figure that does not say what share of employees use the tools.
- How do we stop it from showing confidential documents?
- Carry each document's access rights into the index and filter at query time, then test with accounts of different roles. Review what is technically accessible before you index it, because an assistant makes forgotten oversharing easy to find.
How to cite this page
Blits.ai AI Use Case Library, "AI enterprise knowledge search for employees", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/enterprise-knowledge-search. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published