OmniRisk

FX repatriation for lean middle-office desks.

I designed a desk tool for the lean middle office at small hedge funds and fintech treasuries, where the analyst is the integration layer between prime broker files, Bloomberg data, and internal systems that don't talk. Fund-strategy rules trigger each recommendation, the AI explains why, and every action logs to an audit trail. A workflow I ran by hand for over a decade.

Role

Product Design

Tools

Figma · Maze

Type

Self-iniated

Status

Interactive Prototype · Concept

Timeline

Sep - Nov 2025

Context

Every week, funds with foreign-currency exposure convert back to base currency — a cycle that passes from middle office to trader to systems team. The analyst pulls prime broker files, reconciles across systems that don't integrate, and times conversion against rates that may already be stale.

Bloomberg, Aladdin, Enfusion — the platforms built for this space assume enterprise IT that lean desks don't have. There's no integrations engineer at a small fund; the analyst absorbs that role. And a failed cycle isn't accounting noise: mistimed conversion locks in worse rates, breaks delay settlement, and small rate misses compound into real PnL.

The Problem

Three things make this hard to solve well:

∙ The workflow has no home. Every system lives on its own— rates, allocations, execution — but none sits inside the repatriation cycle itself. The analyst is the connective tissue, and that's not a UI problem.

∙ The users are sophisticated skeptics. They've spent years building workarounds that function, and they know exactly where the workflow breaks. Anything that can't explain itself, audit itself, and defer to their judgment gets rejected.

∙ AI makes it harder before it makes it easier. The features most likely to help — automated reconciliation, rate forecasting, AI-timed execution — are the ones most likely to trigger resistance without transparency.

Research

I interviewed four people across the handoff: two middle-office analysts, an FX trader, and a head of IT at a custodian bank.

Four findings shaped every decision that followed.

1. The workflow lives in the seams. Every operator described the same pattern: Bloomberg for rates, Excel for reconciliation, an OMS for execution, prime broker files by email. None of it connects. The analyst is the integration layer, and the tools that could help assume infrastructure a lean desk doesn't have.

"Bloomberg is great for real-time market data, but it doesn't integrate with our internal systems. Excel is our primary tool for reconciliation, but it's slow, error-prone, and doesn't scale."

Middle-Office Coordinator, Hedge Fund

2. Trade timing is the highest-stakes, least-supported decision. The problem isn't judgment versus data — it's that the data runs on a delay. FCM rates arrive on negotiated weekly schedules, get cross-referenced against Bloomberg in Excel, and reconciled T+1. The result is narrow execution windows where the rate you're acting on may already be stale. Insight and action live in separate tools, on different clocks.

3. AI is acceptable if it's explainable and controllable. All four converged here. The trader would use AI rate forecasts only if she could verify each one; the head of IT required audit trails and traceable outputs; both analysts wanted transparency and override. These weren't feature requests — they were conditions for adoption.

4. Audit trails aren't paperwork — they're the license to act. The head of IT framed audit and traceability as prerequisites, not deliverables. Without a defensible record of what fired each recommendation and who approved each override, a lean desk can't run this workflow under compliance scrutiny at all.

The AI Layer

Every operator interviewed drew the same line: the AI could recommend, but it could never decide. Fund-strategy rules — set upstream by committee, deterministic, auditable — decide each position's badge: repatriate, monitor, or hold. The AI's only job is generating the rationale and confidence score that appear when the operator opens the recommendation modal. It sees the rule that fired and the position data. It never sets the badge, never triggers execution, never sees market data it could be wrong about.

What I designed wasn't the model. It was where the model doesn't get to go.

Three decisions carry that weight.

Three Decisions Where the AI Doesn't Get to Go

01) Confidence in the Modal, Not the Table
Put AI confidence and reasoning inside the recommendation modal — not as columns in the trade table.

The badge is a trigger to act, not something to second-guess. Granular reasoning belongs one layer down: when the operator clicks Execute, the modal opens with confidence and rationale before they commit. The table stays fast for triage; the modal goes deep for the decision.

02) Enforce the Sequence
Fetch FCM → AI processing → Run analysis → View insights. Each step locks until the prior completes.

The order reflects real dependencies across the disconnected systems the workflow spans. Enforcing it prevents out-of-sequence actions that produce wrong-but-believable output — the failure mode that's hardest to catch after the fact. It also surfaces the AI recommendation at the decision moment, the one step the manual workflow never had.

03) Override Sits Beside Accept, Not Behind It
Manual Override and Accept AI Recommendation appear as two equal buttons in the modal. Every override routes through manager approval and compliance sign-off before execution — logged, traceable, defensible.

Catching errors is the job. A spot trade can post in error, and it's on the middle office to catch it, so override has to sit at the decision moment. Equal placement states the assumption plainly: the AI recommends, the operator decides. The audit trail makes that decision defensible after the fact.

How It Works

OmniRisk runs the repatriation cycle as one sequenced pipeline: Fetch FCM → AI Processing → Run Analysis → View Insights. One environment, one audit trail, one place where the recommendation and the decision happen.

Around that spine, two choices shape the working surface:

  • Widget-based dashboard — drag-and-drop layout over fixed tabs, so a middle-office analyst and a trader can each configure their own view. Every participant asked for this.

  • In-table AI highlighting — recommendations flagged inside the full data table, not siloed in a separate panel, so the operator sees flagged positions in the context of everything else on the desk.

Testing

Three operators who run this workflow ran the interactive prototype in moderated think-aloud sessions, plus a post-task survey. Small sample — directional, not proof.

Two things stood out.

What held up

  • Sequential flow. All three navigated it without instruction; disabled states read correctly.

  • Loading states. Read as the system working, not stalling — a contrast they drew unprompted against tools that give no feedback.

  • In-table highlighting. Identified as AI recommendations with no legend needed.

  • The recommendation modal. Trust rated 4.3/5 on the post-task survey. Participants named the reasoning behind each badge as the reason.

What didn't

  • Disabled states alone didn't orient users mid-sequence. Two of three hesitated at the intermediate step, unsure whether processing had finished.

  • Confidence scores weren't interpretable on sight. The same 78% read as "high" to one participant and "moderate" to another.

  • "More Details" didn't pull users in. Only one of three opened it.

Each of those three became a direct fix. Outcomes below.

Outcomes

Three fixes came directly out of testing.

  • Step X of 4 indicator on the CTA group. Position in the sequence is now explicit — not just which button is active. Addresses the mid-sequence hesitation.

  • Confidence legend — low / medium / high bands with ranges. The same score now reads consistently across operators. Addresses the 78%-reads-differently problem.

  • "More Details" relabeled to "See AI reasoning." Names the value instead of the mechanic. Addresses the one-of-three open rate.

The prototype validated the architecture. What it didn't validate is durability — whether trust holds after the tenth cycle, not the first. That's the next test.

Reflection

∙ Trust is a design material, not a user-education problem. It's built in the moment the operator decides whether to act. A confidence score that reads as useful rather than noise isn't about how much information it carries — it's whether it answers the question being asked.

∙ Test the trust layer earlier. I validated the AI presentation late in the flow; the confidence-score problem would have surfaced weeks sooner on a low-fidelity modal. Trust patterns don't need high fidelity to fail.

∙ Sequential workflows need explicit position markers. "Step 2 of 4" is a tiny addition with an outsized effect on confidence. Disabled states alone don't orient people.

∙ Compliance is a research gap, not a design blind spot. Audit, AML, and FATCA requirements came secondhand through the head of IT. A working build would need direct interviews with a compliance officer before shipping — a scope call I made deliberately at concept stage, and one I'd close early on the next iteration.

Explore Further