Why Finance Companies Still Hire Like It's 2015
Finance hires slowly because a wrong hire in a regulated role is a control failure. Why pedigree is a weak proxy and what documented evidence fixes.
Finance companies still screen the way they screened in 2015 — institution, certification, years served — because a wrong hire in a regulated function is not a wasted salary, it is a control failure. Something an internal auditor, a supervisor or a client can point at afterwards. Pedigree is the only screening-stage risk control most firms have ever had, so it survives every reorganisation and every new system. It is also a weak one: it filters out capable people while doing almost nothing about the risk it was bought to cover.
I ran a recruitment agency before I built Pickr, and banking and insurance clients were the slowest part of the desk by a wide margin. Not because the people in them were slow. Because nobody in the approval chain had a personal incentive to be the one who said yes to an unusual profile.
Why financial services hiring takes 60 to 90 days
Watch how a compliance officer or an anti-money-laundering lead actually gets hired. Business head, risk, compliance, HR: 4 sign-offs, 4 inboxes, 4 formats of feedback arriving at 4 different speeds. On the agency side I never saw a senior control-function mandate close in under 60 days, and 90 was ordinary. Comparable seniority outside a regulated function closed in 30 to 45 days.
The usual explanation is bureaucracy. That is lazy. Those sign-offs exist because the failure mode is real: a bad hire in a control function can produce an audit finding, a remediation programme and a personal accountability question for whoever approved them. Measured against that, 10 more days of delay looks cheap to everyone in the room except the recruiter and the candidate.
The problem is not that finance is careful. It is that the care goes to the approval process, which is visible, and not to the evidence the approvers are handed, which is not.
Why pedigree screening does not reduce risk
The unstated screen in most financial services hiring is: which institution, which certification, how many years. Three failure modes, all of which I saw repeatedly on the agency side.
It confuses proximity with responsibility. "Built the transaction monitoring function" and "worked in the team that ran the transaction monitoring function" generate nearly identical CVs. A pedigree screen cannot separate them, because both people worked somewhere recognisable. The interview usually cannot separate them either, unless someone asks for a specific decision the candidate personally made and what it cost.
It filters out people who did the work somewhere unfashionable. Someone who stood up a monitoring and reporting function from nothing at a 60-person payments firm has often designed more controls than the equivalent hire at a large bank, where the function already existed and the job was to operate it. The first CV rarely reaches the hiring manager, because the institution name does not do the work the screen expects of it.
It does not price the risk it claims to price. The commonly cited figure for a bad hire is around 30% of first-year salary, and in a control function that is the uninteresting part. The real exposure is the control gap nobody noticed for a year. Nothing about a prestigious former employer predicts whether this particular person will notice a gap.
One narrow case where pedigree screening is genuinely correct: where a regulator requires a named qualification or an approved-person status. That is a hard requirement, and it belongs in the filter. Everything else on the pedigree list is a guess wearing the clothes of prudence. The general case against CV-shaped proxies is set out in why keyword screening is dead.
| Pedigree screen | Evidence screen | |
|---|---|---|
| What it reads | Employer, title, certification, years | What the person did, decided and owned |
| Separates builder from bystander | No, both CVs look the same | Yes, if the evidence is specific |
| Adjacent experience | Filtered out | Surfaced and explained |
| What audit gets afterwards | A status field | The reasoning, dated |
| Where it is genuinely right | Regulator-mandated qualifications | Everything else |
What evidence-based matching changes for a regulated role
Pickr is an AI-native recruiting platform that scores every candidate on evidence of skills rather than keyword matches, including adjacent and transferable skills, with that evidence attached to the score. For hiring into banking, insurance and fintech, two things change.
First, the shortlist becomes arguable. A number with no explanation is worse than no number, because it launders a guess into something that looks like a measurement. When the score carries the evidence behind it, a recruiter or a compliance lead can disagree with a specific claim rather than with a ranking. That is the point of evidence-based candidate matching in a regulated function: not that the machine is right, but that it shows its work well enough for a human to be right.
Second, adjacent experience stops being invisible. A treasury analyst who has run liquidity stress scenarios has done a version of the thinking a risk role needs, without the exact noun on the CV. When the qualified population for a senior control role is small and every firm in the city is fishing in the same pond, the ability to look one pond over is not a nice-to-have.
Then the loop closes. What happened to the people a firm actually hired feeds back into how the next candidates are evaluated. After 20 or 30 hires into the same role family, a firm is working from its own record of what a good compliance hire looks like rather than the sector's shared assumptions.
What a bank should document about a hiring decision
The objection I hear from hiring managers is that writing down a reason for every rejection is overhead. In a regulated firm it is the cheapest insurance available, and it is only cheap if you buy it at the moment of the decision.
Three situations where the record pays for itself. Internal audit asks why a control role sat open for 5 months. A rejected candidate raises a discrimination complaint and the firm has to show the decision was made on job-related grounds. The hiring manager who made every call leaves, and someone has to run the same role again next quarter.
In each case the reconstructed version is worthless. Ask anyone in March why they rejected a candidate in January and you get a fluent, confident, largely invented story. Two sentences written at the moment of rejection, tied to something the candidate actually said, beat a page written 6 weeks later.
This is a workflow problem more than a discipline problem. In Pickr, interviews are transcribed and scorecards arrive pre-filled with evidence mapped to each criterion, so the interviewer edits a draft instead of confronting an empty form days later, when the memory has already decayed. Interviewer and hiring-manager seats are free, which sounds like a discount and is a design decision: risk, compliance and the business head are exactly the people a per-seat budget quietly excludes, and their judgement then lives in hallway conversations no audit can read.
Is AI allowed in regulated hiring?
The compliance question I get asked first is whether AI in hiring is permitted at all. It is, and the timeline moved in a way most firms have not caught up with. Recruitment is still classified high-risk under Annex III of the EU AI Act, but the obligations that classification carries — risk management, human oversight, technical documentation — were deferred from August 2026 to December 2027 by the AI Digital Omnibus that entered into force in July 2026. What binds you today is narrower: the transparency rules that did take effect in August 2026, so a candidate talking to an AI system has to be told that is what it is, and Article 22 of the GDPR, which has not moved and gives a candidate the right not to be subject to a decision based solely on automated processing.
The deadline slipped 16 months. The design it implies did not: software proposes and evidences, a named person decides, and the decision plus its reasoning lands in the record. Treating December 2027 as a start date is the trap, because the evidence you will need then is the evidence nobody can reconstruct afterwards. The detail is in what the EU AI Act requires of recruiters.
The other question is where the data sits. Pickr hosts candidate data in Frankfurt, Germany, is built in Austria, is GDPR compliant with a data processing agreement included, and redacts personally identifying information from AI prompts by default. In this sector that conversation happens before the product demo, not after it.
What better evidence does not fix
Software does not shorten a 4-party sign-off chain. Only the firm's own governance can do that, and in many cases it should not. It does nothing for a firm that wants pedigree as social proof for a board or a client rather than as a predictor — that is a positioning decision, not a screening one. And the compounding part is slow: the first quarter gives you a cleaner record and very little else, and anyone promising that your hiring gets measurably smarter next month is selling something else.
If you want the diagnosis before the purchase, Pickr can connect to your current ATS read-only and audit your real hiring history rather than a demo dataset. If that audit says your bottleneck is an unowned approval stage rather than your screening, no software fixes it and you have saved yourself a migration.
The takeaway
Finance is not slow because it is old-fashioned. It is slow because the downside of a wrong hire is genuinely asymmetric, and the control it reaches for at the screening stage is the wrong tool for the job. Pedigree rejects the people who did the work in the wrong postcode, admits the people who stood near it in the right one, and leaves nothing behind for the auditor who asks why.
The replacement is not faster hiring. It is better evidence, captured while it is fresh, with a human name against every decision. Slower to set up, and considerably faster to defend.
Frequently Asked Questions
Why is hiring in financial services so slow?
Because a wrong hire in a regulated function is a control failure rather than a wasted salary, so banks and insurers add sign-offs from the business, risk, compliance and HR. A senior control-function hire commonly takes 60 to 90 days from brief to signed contract, against roughly 30 to 45 days for comparable seniority elsewhere. The delay is a risk response rather than simple bureaucracy, which is why telling people to move faster never works.
Does hiring for pedigree actually reduce risk in regulated roles?
Rarely. A recognised former employer, a certification and a number of years tell you where someone was, not what they were responsible for. Someone who built an anti-money-laundering programme and someone who attended its steering meetings produce almost identical CVs. The one defensible exception is a qualification or approved-person status a regulator genuinely requires, which is a hard requirement rather than a proxy for competence.
How can AI be used in financial services recruitment under the EU AI Act?
Recruitment is still classified high-risk under Annex III of the EU AI Act, but the obligations that classification carries were deferred from August 2026 to December 2027 by the AI Digital Omnibus that entered into force in July 2026. What applies today is narrower: the transparency rules that took effect in August 2026, and Article 22 of the GDPR, which gives a candidate the right not to be subject to a decision based solely on automated processing. The workable shape either way is software that proposes and evidences while a named person decides, with the decision and its reasoning recorded at the time.
What should a bank document about a hiring decision to survive an audit?
For every advance and every rejection, record who decided, when, and the specific evidence behind it, captured at the moment of the decision rather than reconstructed months later. Structured interview scorecards tied to the published role criteria, plus 2 or 3 sentences of reasoning on each rejection, are normally enough to answer internal audit, a supervisory question or a discrimination claim without a reconstruction exercise.
Where is candidate data stored if a regulated firm uses Pickr?
Candidate data is hosted in Frankfurt, Germany, and Pickr is built in Austria. It is GDPR compliant, a data processing agreement is included, and personally identifying information is redacted from AI prompts by default. In banking and insurance this is usually the first question procurement and the data protection officer ask, well before anyone looks at the product itself.
Free recruiting audit · 2 minutes
Find out what your hiring process is actually costing you.
Answer eight questions, or connect your current system read-only, and get a report on where your funnel loses candidates and which changes are worth making. No signup, no API key stored, data stays in the EU.
Written by Andreas Amann
Founder of Pickr. Former operator at startups in Berlin and Silicon Valley, where he helped scale companies from 40 to 200+ people. Built Pickr after years of using every major ATS as a recruitment agency owner at ScalingPPL.