Innovation Theme & Use Case Map
BMC taxonomy scored for Citigroup Inc. — 63 high-relevance, 13 medium-relevance use cases identified
AIAutomationModernizationObservabilityOrchestrationRisk & Compliance
Tier 1 Themes
6
Tier 2 Categories
30
Tier 3 Use Cases
81
High Relevance
63
Medium Relevance
13
Active Pipeline
76
Taxonomy Gaps Found
7
AIExtremely high relevance. Citi has deployed AI tools to 140,000+ employees across 11 countries, launched Citi Stylus Workspaces with agentic AI, armed 30,000+ developers with GitHub Copilot, and has an AI Center of Excellence led by Dr. Prag Sharma. The bank spent $11.8B on technology in 2024 and is actively piloting Cognition's Devin agentic coding agent for 40,000 developers. AI is positioned as a core pillar of Citi's transformation programme.
AI for Data & Analytics
ML/GenAI for analytics, fraud detection, forecasting, NLP, and decision-making.
High. Citi has deployed Citi Assist (NLP knowledge assistant) and Citi Stylus (document intelligence) to 140,000 employees. Uses AI for fraud detection, transaction monitoring, risk modeling, and FX t
HIGH
AI Model Deployment in Financial Controls
Citi uses ML for predictive risk models analyzing credit risk, market volatility, and counterparty defaults. The consent order demands improved controls, making AI-driven financial controls a top prio…
HIGH
AI Readiness Framework for 150K+ Employees
Citi has deployed AI tools to 140,000 employees across 11 countries, with 2,000+ AI Champions and over 42 million AI interactions. The AI readiness programme is a stated CEO priority with formal train…
HIGH
AI/ML Assisted Change Management
Citi's consent order mandates improved change management and internal controls. With 2,000+ apps retired and ongoing platform consolidation, AI-assisted change management would reduce risk of failed c…
HIGH
AIOps
Citi operates one of the world's largest IT environments with mainframe Command Centers providing 24/7 monitoring. AIOps would reduce alert volume and improve MTTR across the hybrid estate.
HIGH
Agentic AI Workflow Orchestration
Citi launched Citi Stylus Workspaces with agentic AI in September 2025, piloting with 5,000 employees. CTO Griffiths confirmed the bank is 'developing agentic systems that can plan, execute and refine…
HIGH
Citi AI Center of Excellence Enablement
Citi has a formal Global AI Center of Excellence led by Dr. Prag Sharma, one of only 10 Citi Tech Fellows. The CoE develops best practices in AI governance, risk, controls, and tooling. Directly named…
MEDIUM
Abend Auto-diagnosis for COBOL Claims
Citi runs substantial COBOL workloads on IBM z-series mainframes. While 'claims' is insurance-specific, the abend auto-diagnosis capability is relevant for Citi's mainframe batch processing.
NOT RELEVANT
Claims Adjudication Workflow Automation
AI-Enhanced Engineering & Co-Pilots
Developer co-pilots, code insight, test generation, and agentic DevOps automation.
Very high. Citi deployed GitHub Copilot to 30,000 developers with 5-15% productivity gains. Rolling out Cognition's Devin agentic AI agent to 40,000 developers with 2x-20x speed improvements for speci
HIGH
AMI DevX for Developer Productivity Gains
Citi has 40,000+ developers and runs extensive mainframe workloads. The bank is pursuing developer productivity aggressively with GitHub Copilot (5-15% gains) and Cognition Devin (2-20x for specific t…
HIGH
Agentic AI Co-Pilots for IT Ops
Citi's Command Center team manages 24/7 global IT operations across mainframe and distributed systems. Agentic AI co-pilots for IT ops align with Citi's stated strategy of embedding AI 'in our process…
AI Risk & Governance
Model risk management, AI governance, fairness, and compliance.
High. Citi's AI CoE establishes best practices for AI governance, risk, and controls. The bank has implemented ethical AI principles and embeds governance at every stage. Consent order requirements fo
HIGH
AI-Powered Risk Ops Automation (AML/KYC)
Citi has a robust global AML programme with AI applied to detect suspicious behaviour patterns beyond rule-based systems. U.S. agencies are investigating Citi's AML policies. AI-driven AML/KYC automat…
Continuous Integration and Continuous Delivery
CI/CD pipelines for continuous integration and deployment/delivery.
High. Citi is modernizing its engineering platform, reducing application migration time from 7 weeks to 2 weeks via streamlined public cloud processes. The bank has 40,000 developers and is standardiz
AI-Augmented Software Development
AI to enhance the software development lifecycle from design through deployment.
Very high. Core initiative — Citi's CTO David Griffiths is leading the rollout of AI coding agents (Cognition Devin) and GitHub Copilot. Citi Stylus Workspaces integrates agentic AI for multi-step dev
AIOps & Intelligent Incident Response
AI anomaly detection, alert reduction, and intelligent incident response.
Medium-High. Citi's massive IT estate (mainframes, hybrid cloud, 180+ countries) generates enormous operational complexity. The Command Center operations team monitors global infrastructure including
HIGH
Predictive Incident Avoidance (AIOps)
Citi's global IT infrastructure serves clients in 180+ countries. Service outages have direct financial and reputational impact. Predictive incident avoidance is essential for maintaining the 'safety …
AutomationCritical relevance. Citi's consent order remediation demands automated controls and data governance. The bank has retired 2,000+ legacy applications over three years and is investing heavily in automation to reduce manual processes that historically contributed to control weaknesses. CEO Fraser emphasized 'investments we're making to modernize our infrastructure, streamline processes and automate controls are changing how we run the bank.'
Workflow & Process Automation
Automate business/IT workflows, approvals, and RPA-like tasks.
Very high. Citi is investing in 'automating controls' as a core consent order remediation strategy. The bank uses AI-driven intelligent document processing for tax forms and SWIFT messages. Client onb
HIGH
AMI AppDev
Citi's extensive IBM mainframe footprint running core banking applications requires modern development tools. The bank's push to modernize developer experience with AI tools needs to extend to mainfra…
HIGH
AMI DevX
Same as AMI DevX above — Citi's 40,000+ developer workforce and mainframe dependence make modern developer experience for z/OS a strategic need.
HIGH
Automated Remediation for Anomaly Detection
Citi's consent order demands improved internal controls. Automated remediation reduces the manual intervention that historically contributed to control weaknesses and the 2020 Revlon payment error.
HIGH
Automated Triage & RCA of Core Systems
Citi's core banking runs on mainframe with CICS/DB2. The Command Center provides 24/7 support. Automated triage would accelerate incident resolution for mission-critical systems.
HIGH
Batch SLA Enforcement (Subscriber Systems)
Citi processes end-of-day batch workloads for settlement, regulatory reporting, and client reconciliation across 180+ countries. Batch SLA enforcement is critical for T+1 settlement and regulatory dea…
HIGH
Client Onboarding & Product Fulfillment
Citi's KYC programme focuses on 'globally consistent standards/policies, customer risk scoring, on-boarding.' AI is being applied to document processing for client onboarding. Automation of this workf…
MEDIUM
App Dev
Citi's broad application development efforts align with general app dev automation needs, though the bank uses its own bespoke tools and platforms heavily.
Data Pipeline Management
Automate ETL/ELT, data ingestion, DataOps, and quality gates.
Critical. The OCC consent order specifically targets data governance, data quality management, and regulatory reporting. Citi has established a Virtual Enterprise Data Lake. Data pipeline automation i
HIGH
Agile DevSecOps Pipelines
Citi's 40,000-developer organization and cybersecurity investment demand DevSecOps integration. The bank's $11.8B tech spend includes cybersecurity. Automated code reviews (220,000 in Q1 2025) suggest…
HIGH
CI/CD Process Modernization at Scale
Citi is standardizing development practices across 40,000+ developers, reducing app migration time from 7 weeks to 2 weeks. CI/CD modernization is foundational to the transformation.
HIGH
Data (ETL, Big Data)
Citi has a Virtual Enterprise Data Lake and uses Snowflake for financial data cloud. ETL automation is critical for data governance compliance and AI/ML pipelines. The consent order targets data quali…
HIGH
Data Pipeline Traceability Across Systems
The OCC consent order requires Citi to improve data quality, aggregation, and management including End-User-Computing processes. Data pipeline traceability is essential for proving data lineage to reg…
HIGH
DevOps
Citi is transforming its development practices with AI-assisted coding, Kubernetes-based workloads, and container standards. DevOps enablement is central to the modernization programme.
HIGH
Door 4: Data (Big Data, ETL, Databases)
Same rationale as Data (ETL, Big Data) — Citi's data governance crisis and consent order compliance make this a top priority.
HIGH
MLC Cost Control for COBOL Pipelines
Citi is one of the world's largest IBM mainframe customers with extensive COBOL workloads. MLC costs are a major expense category. Optimizing batch job scheduling to reduce peak MIPS usage directly re…
MEDIUM
AMI Code Insight for Secure Code Pipelines
Citi's mainframe applications handle sensitive financial data requiring secure coding practices. However, the bank's primary secure code focus is on distributed systems with GitHub Copilot and Cogniti…
IT Operations Automation
Runbooks, patching, backups, and maintenance automation.
High. Citi runs one of the world's largest IT environments with mainframe Command Centers providing 24/7 monitoring. Automated patching, backup, and maintenance are critical for security and complianc
HIGH
AMI Ops
Citi's Command Center provides 24/7 mainframe monitoring. AMI Ops directly addresses mainframe operations automation needs for z/OS, JES2, and system automation.
HIGH
Ops Excellence
CEO Fraser stated the bank is now 'beginning to realize the benefits of more standardized, automated, and digitized controls.' Operations excellence is a core transformation outcome.
HIGH
Ops excellence
Same as above — Citi's transformation programme targets operational excellence through automation and standardization.
HIGH
SecOps
Citi invested in cybersecurity as part of $11.8B tech spend. DORA compliance requires robust ICT incident detection and reporting. Mainframe security monitoring (RACF/SMF) is essential.
MEDIUM
Digital Twin for IT Ops Simulation
Citi's complex IT estate would benefit from simulation capabilities for change impact assessment and disaster recovery testing. However, no direct evidence of Citi pursuing digital twin initiatives fo…
MEDIUM
SLA Assurance for ERP Batch Ops
Citi has substantial batch processing for financial operations, though ERP-specific batch (e.g., SAP) is less prominent in public disclosures. General batch SLA assurance is highly relevant.
Dev & Platform Automation
CI/CD, Infrastructure as Code, containers, and platform engineering.
High. Citi uses Kubernetes-based workloads and container-based standards across on-prem and cloud. The Google Cloud partnership involves Vertex AI platform adoption. Platform standardization is key to
HIGH
Control M Platform
Citi's massive batch processing across mainframe and cloud requires enterprise-grade workload automation. Control-M platform deployment is a foundation use case for Broadcom CA7/AutoSys replacement.
HIGH
Cost Efficiency via Platform Reduction
Citi has retired 2,000+ legacy applications and is consolidating onto unified platforms. Reducing the number of scheduling/automation platforms aligns with the simplification strategy. Broadcom pricin…
Infrastructure Optimization
Cost/right-sizing, storage optimization, and FinOps hooks.
Medium-High. Citi has consolidated from 70 to ~20 data centers and is migrating workloads to private/public cloud to reduce costs. MLC cost optimization on mainframe is relevant given the substantial
MEDIUM
AMI Storage
Citi's extensive mainframe estate generates substantial storage management requirements. Storage optimization reduces costs and improves performance, though no specific public evidence of Citi storage…
ModernizationCore strategic priority. Citi's transformation reverses decades of underinvestment. The Google Cloud strategic partnership (October 2024) involves migrating multiple workloads. Citi has reduced data center count from 70 to ~20, retired 2,000+ apps, and runs IBM z-series mainframes as 'core processing engine of virtually every line of business.' Mainframe modernization and cloud migration are central to the multi-year transformation.
Application Development / Software Engineering
Modern application development and software engineering practices.
High. Citi employs 40,000+ developers and is building 'an end-to-end, AI-enabled tech stack.' Application rationalization (2,000+ apps retired) and modern development practices are central to transfor
Cloud Migration & Hybrid Ops
Migrate to cloud/hybrid and operate across estates.
Very high. The October 2024 Google Cloud strategic partnership is a cornerstone of Citi's modernization. The bank uses a hybrid cloud strategy with Kubernetes-based standards, has reduced application
HIGH
Cloud
Citi's Google Cloud strategic partnership, 70%+ cloud adoption, and hybrid strategy make cloud a top-tier priority. The bank reduced data center costs by migrating workloads to private cloud.
HIGH
Cloud DataOps & Batch Scheduling
Citi is migrating data workloads to Google Cloud including analytics and HPC. Cloud batch scheduling for data pipelines is essential for the data governance transformation.
HIGH
Cross-Domain Observability for Cloud Migration
Citi's migration to Google Cloud while maintaining mainframe and on-prem workloads creates visibility gaps. Cross-domain observability is essential for the hybrid operating model.
HIGH
Door 6: Cloud
Same as Cloud above — Citi's multi-year Google Cloud partnership and 70%+ cloud adoption make this highly relevant.
HIGH
Hybrid Cloud Integration for Flexible Orchestration
Citi follows a 'standards-based hybrid cloud strategy' with Google Cloud, on-prem Kubernetes, and mainframe. Flexible orchestration across these environments is essential.
HIGH
Multi-Cloud Data Movement Governance
Citi's data governance consent order requirements extend to cloud environments. Data movement between mainframe, data lake, Snowflake, and Google Cloud must be governed and auditable.
MEDIUM
AMI Cloud Vault for Encrypted Storage
Citi is migrating workloads to Google Cloud and uses encryption extensively. The bank explored mainframe crypto coprocessors for encryption. Cloud-based encrypted storage for mainframe data aligns wit…
MEDIUM
Private Cloud Fabric for Sensitive Services
Citi has reduced data center costs by migrating workloads to private cloud. Most sensitive data remains on-prem. Private cloud fabric supports the hybrid strategy.
Application Modernization
Refactor/replatform applications, adopt microservices and containers.
Very high. Citi has retired 2,000+ legacy applications and continues to retire 100+ per quarter. The bank is consolidating trading/reporting platforms and moving to container-based architectures. Appl
Mainframe Modernization
Scheduler takeouts (CA7/AutoSys), mainframe-cloud integration.
Very high. Citi is one of the world's largest IBM mainframe users, running z-series as 'core processing engine of virtually every line of business.' The bank processes 150,000+ transactions/second on
HIGH
CA7/Autosys Replacement with Control-M
Citi is one of the world's largest mainframe users with CA7/AutoSys as the dominant scheduling platform for z/OS. Broadcom's pricing pressure and Citi's platform consolidation strategy create a prime …
HIGH
Cloud-Native Mainframe Interoperability
Citi's Google Cloud partnership involves migrating workloads while core banking remains on mainframe. Interoperability between z/OS and Google Cloud services is essential.
HIGH
Data Orchestration Across Cloud & Mainframe
Citi's data governance transformation requires governed data flows between mainframe (core banking, transaction data) and cloud (analytics, AI, regulatory reporting).
HIGH
Door 1: Mainframe
Citi uses IBM mainframe as 'core processing engine of virtually every line of business.' Mainframe modernization is a fundamental pillar of the transformation.
HIGH
Mainframe
Same as Door 1: Mainframe — Citi's massive mainframe footprint makes this a core use case.
HIGH
Mainframe Cost Optimization (MLC/ISV/RAA)
Citi's massive IBM z-series footprint means MLC costs are a multi-million-dollar expense. With $12B+ annual tech spend, mainframe cost optimization directly impacts profitability.
HIGH
Mainframe Job Cost Optimization
Citi processes massive batch workloads on mainframe. Individual job cost optimization complements MLC optimization for overall cost reduction.
HIGH
Mainframe Modernization via Broadcom Takeout
Citi likely uses Broadcom CA products (CA7, AutoSys, potentially CA-View, CA-Deliver). Broadcom's acquisition of CA Technologies and subsequent pricing changes create incentive for replacement. Citi's…
Platform/SRE Modernization
SRE patterns, reliability engineering, and toil reduction.
Medium-High. Citi's global scale (180+ countries) and regulatory requirements demand high reliability. The consent order requires demonstrating operational resilience. SRE patterns align with reducing
ObservabilityHigh relevance. Citi operates across 180+ countries with massive hybrid infrastructure spanning mainframes, private cloud, and Google Cloud. Real-time visibility into batch jobs, treasury settlement workflows, and cross-platform SLAs is essential. The consent order specifically requires improved data quality management and compensating controls, which demand robust observability.
Hybrid/Cloud Visibility
APM/logs/traces/SLOs across hybrid environments.
High. Citi's hybrid environment spans mainframes, private cloud, Google Cloud, and on-prem data centers across 20+ locations. Cross-estate visibility is critical for compliance, SLA management, and in
HIGH
AMI Ops for Observability Modernization
Citi's Command Center provides 24/7 mainframe monitoring. Modernizing observability with AMI Ops improves visibility and supports the overall transformation.
HIGH
Real-Time Treasury Visibility
Citi TTS serves 120+ countries with cash management, payments, and settlement. T+1 settlement and Citi Token Services for real-time liquidity management demand real-time treasury visibility.
HIGH
SLA & Resiliency Monitoring
DORA requires robust operational resilience monitoring for EU operations. The consent order demands demonstrating effective controls. SLA monitoring is critical for batch and real-time processing.
HIGH
Security & Access Monitoring (RACF/SMF)
Citi's mainframe runs core banking with strict security requirements. RACF/SMF monitoring is essential for access control compliance and detecting unauthorized activity on z/OS.
HIGH
Security Monitoring for Legacy Systems
Despite retiring 2,000+ apps, Citi still operates legacy systems including mainframe applications dating back decades. Security monitoring for these systems is essential for compliance.
Mainframe Monitoring
z/OS, CICS, IMS, DB2 performance and health monitoring.
High. Citi runs IBM z-series with CICS, DB2, and MQ Series workloads. The Command Center team provides 24/7 mainframe monitoring. Performance visibility is critical for batch processing windows and re
Data Observability
Data quality, lineage, and freshness telemetry.
Critical. The consent order specifically mandates improved data quality management. CEO Fraser stated 'We fell behind in data, particularly regarding regulatory reporting.' Data observability is essen
SLO/Cost (FinOps) Observability
SLO tracking with cost/FinOps telemetry.
Medium-High. Citi's $12B annual tech spend and cloud migration demand FinOps visibility. CTO Griffiths tracks AI spend per employee through the Citi AI platform. Cost optimization is important given t
OrchestrationVery high relevance. Citi processes 150,000+ transactions per second on mainframe, runs massive batch workloads for end-of-day processing, treasury settlement, and regulatory reporting across 180+ countries. The migration to Google Cloud and hybrid architecture demands cross-platform workload orchestration. The T+1 settlement transition requires tighter batch windows and automated workflow coordination.
IT Systems Orchestration
Batch/workload orchestration using tools like Control-M.
Very high. Citi's mainframe-centric batch processing for end-of-day settlement, regulatory reporting, and treasury operations across 180+ countries requires enterprise-grade workload orchestration. Th
HIGH
App Rationalization Automation
Citi has retired 2,000+ legacy applications since 2022 and continues to retire 100+ per quarter. Application rationalization automation is directly relevant to the transformation programme.
HIGH
Automation to Optimize IT Spend
Citi spends $12B+ annually on technology. CFO Fraser highlighted achieving 2% expense reduction through simplification. Optimizing IT spend through automation is a stated priority.
HIGH
Control M Workload Change Manager
Citi's massive batch environment requires careful change management for workload modifications. The consent order demands improved change controls.
HIGH
Control-M
Control-M is the primary BMC product for Citi's batch processing, workload orchestration, and scheduler replacement needs. Direct fit for mainframe and cloud orchestration.
HIGH
Control-M Workload Change Manager Adoption
Same as Control M Workload Change Manager — Citi's consent order demands improved change controls and this use case drives broader adoption.
HIGH
DBA - Control-M Implementation and Upgrade Services - Consulting
A CA7/AutoSys to Control-M migration at Citi's scale would require significant professional services for planning, migration, testing, and cutover.
MEDIUM
Control-M SaaS
While Citi is moving to cloud, a Tier 1 GSIB bank may prefer on-prem or private cloud deployment for control and compliance. SaaS could be relevant for non-sensitive workloads.
NOT RELEVANT
Connected Vehicle Data Pipeline Scheduling
Cross-Functional Orchestration
End-to-end process orchestration spanning IT and business.
High. Treasury and Trade Solutions (TTS) spans 120+ countries, requiring orchestration across payments, trade, custody, and settlement. T+1 settlement demands tighter end-to-end process coordination.
Event-Driven Scheduling
Kafka/events/webhooks as triggers for workload execution.
Medium-High. Citi's real-time treasury services, tokenized deposits (Citi Token Services), and streaming analytics require event-driven scheduling capabilities beyond traditional time-based batch wind
Multi-Cloud Workload Orchestration
Coordinate workloads across multiple cloud providers.
High. Citi follows a 'standards-based hybrid cloud strategy' with Google Cloud as primary partner, plus references to AWS and Azure compatibility. Kubernetes-based workloads need cross-cloud orchestra
API/Webhook Orchestration
Expose/consume APIs/webhooks to control flows.
Medium-High. Citi's TTS platform, Citi Token Services, and client-facing APIs require integration with internal orchestration. The bank is adopting API-first architectures for real-time data flow.
Risk & ComplianceParamount relevance. Citi operates under active OCC and Fed consent orders (2020) for deficiencies in data governance, risk management, and internal controls. Fined $400M in 2020 and additional $136M in 2024. The bank spent ~$3.5B on risk-management improvements in 2024 alone. DORA compliance is mandatory for EU operations from January 2025. AML investigations are ongoing. This is Citi's #1 transformation priority.
Regulatory Reporting & Evidence
Automate data/controls/evidence for CCAR/DFAST/Basel regulatory reporting.
Critical. The consent order explicitly targets regulatory reporting deficiencies. Citi must demonstrate improved data quality and reporting accuracy. CCAR/DFAST stress testing, Basel III compliance, a
HIGH
Proactive Risk Reporting to Regulators
The consent order requires Citi to demonstrate progress through regular regulatory submissions. CFO Mason stated the bank will continue to 'improve its data quality management' for regulatory reportin…
HIGH
Regulatory Reporting Pipelines
The OCC consent order explicitly targets regulatory reporting deficiencies. CEO Fraser stated 'We fell behind in data, particularly regarding regulatory reporting.' This is a critical compliance use c…
HIGH
Unified Data Governance for Regulatory Compliance
The consent order's primary focus is data governance. The OCC identified 'serious and longstanding deficiencies' in data governance. Citi has been investing heavily in data governance since 2020.
MEDIUM
Audit-Ready ESG Reporting
Citi TTS highlights ESG as a strategic initiative and publishes ESG reports. However, ESG reporting automation is secondary to the more pressing consent order and regulatory reporting requirements.
LOW
Compliance & Actuarial Reporting
Cyber Resilience & Compliance (incl. Security)
Zero Trust, PAM, DR/BCP, and policy enforcement.
Very high. DORA compliance is mandatory for Citi's EU operations from January 2025. Citi invested in cybersecurity as part of the $11.8B tech spend. Zero Trust architecture and fraud detection are act
HIGH
Threat Detection & Incident Response (DORA)
DORA is mandatory for Citi's EU operations from January 2025. Citi published its own DORA analysis document. DORA requires ICT incident detection and reporting within 24 hours. Citibank Europe plc in …
HIGH
Zero Trust and Fraud Detection Tools
Citi uses AI for real-time fraud detection and has invested in cybersecurity as part of $11.8B tech spend. The bank's mainframe crypto coprocessors and Google Cloud Confidential Computing support Zero…
Consent Order Remediation & Audit Readiness
Remediate findings, enforce controls, and prove regulatory adherence.
Paramount. Citi's #1 priority. Active OCC and Fed consent orders (2020) remain in force. The bank spent ~$3.5B on risk-management improvements in 2024. Transformation is explicitly aimed at satisfying
HIGH
RACF/SMF Real-Time Access Auditing
The consent order demands improved internal controls. Real-time RACF/SMF auditing provides evidence of access control effectiveness on mainframe systems processing core banking transactions.
Data Security & Governance
Data protection, masking, and governance policies.
Critical. The consent order's primary focus is data governance. The 2023 Federal Reserve exam found 'ongoing deficiencies in data quality management.' Data security is paramount given the global footp
Operational Risk & Controls
SLA/change/operational risk controls and reporting.
Very high. The consent order requires demonstrating effective internal controls and operational risk management. Citi must prove that 'standardized, automated, and digitized controls' are functioning
HIGH
AMI Security
Citi's mainframe processes core banking transactions and stores sensitive data. Mainframe security is critical for consent order compliance and cyber resilience.
HIGH
AMI Security for Cyber Resilience Initiatives
DORA compliance and consent order remediation both require demonstrating cyber resilience. Mainframe security is a critical component of Citi's overall cyber resilience posture.
HIGH
BFSI Visibility Enhancement via Compliance Use Cases
Citi's consent order remediation requires enhanced visibility into controls, data quality, and operational processes. Compliance-driven monitoring directly supports regulatory requirements.
HIGH
Compliance Automation & Validation Dashboards
The consent order requires Citi to demonstrate compliance progress to regulators quarterly. Automated compliance dashboards support board-level oversight and regulatory reporting.
HIGH
Finance & Credit Risk Data Flows
Citi's consent order targets risk management deficiencies. Credit risk data flows feed regulatory stress testing (CCAR/DFAST). The bank uses ML for predictive credit risk models.
HIGH
Jobs-as-Code for Data Compliance Pipelines
Citi's DevOps transformation and consent order compliance would benefit from version-controlled, auditable pipeline definitions. Jobs-as-Code supports CI/CD integration and compliance audit trails.
HIGH
Platform-Level Compliance Alignment
Citi's platform consolidation and cloud migration must align with regulatory requirements across jurisdictions. The consent order demands compliance alignment at the infrastructure level.
HIGH
Resilience Dashboards for Compliance Officers
DORA requires operational resilience monitoring. The consent order demands board-level oversight of remediation. Resilience dashboards support both regulatory requirements.

Taxonomy Gaps — Suggested Additions 7

Suggested Use CaseTier 1Tier 2Rationale
T+1/T+0 Settlement Batch Window CompressionOrchestrationIT Systems OrchestrationCiti is a major custodian and broker-dealer directly impacted by T+1 settlement (live May 2024 in US) and upcoming UK/EU T+1 transitions. Citi's head of Securities Services cited the need for 'substantial changes to operating, treasury and client service models.' Batch window compression is critical for settlement and requires advanced workload orchestration.
Consent Order Data Quality AutomationRisk & ComplianceConsent Order Remediation & Audit ReadinessCiti's 2020 consent order specifically requires a Data Governance Programme addressing data quality, aggregation, and management. The 2024 $136M fine was for insufficient progress. CEO Fraser stated 'We fell behind in data, particularly regarding regulatory reporting.' This is the bank's #1 compliance priority with no direct use case in the taxonomy.
Global Regulatory Reporting Orchestration (BCBS 239/CCAR/DFAST)OrchestrationCross-Functional OrchestrationCiti's consent order explicitly targets regulatory reporting. BCBS 239 requires risk data aggregation capabilities that Citi's OCC exam found deficient. CCAR/DFAST stress testing involves complex batch workflows spanning mainframe and distributed systems. No specific use case in taxonomy addresses cross-functional regulatory reporting orchestration.
Legacy Application Retirement Pipeline AutomationModernizationApplication ModernizationCiti has retired 2,000+ legacy applications since 2022, with 384 in 2025 alone. This is a multi-year programme requiring automated dependency analysis, data migration orchestration, and decommissioning workflows. Control-M's workload dependency visibility directly supports this effort.
AI/ML Data Pipeline Orchestration for Financial ServicesAIAI for Data & AnalyticsCiti's AI CoE is deploying ML models across fraud detection, credit risk, AML/KYC, and trading analytics. These models require automated data pipelines for training and inference that span mainframe (transaction data) and cloud (analytics platforms). Control-M can orchestrate these ML pipelines.
Cross-Border Payment & Treasury Workflow OrchestrationOrchestrationCross-Functional OrchestrationCiti TTS is described as the 'technological crown jewel' of the bank, serving clients in 120+ countries. Cross-border payments involve complex multi-timezone batch processing, FX settlements, and regulatory compliance across jurisdictions. Real-Time Funding expansion and Single Event Processing initiatives demand sophisticated orchestration.
Google Cloud Migration Workload OrchestrationModernizationCloud Migration & Hybrid OpsCiti's October 2024 strategic partnership with Google Cloud involves migrating 'multiple workloads and applications.' The bank reduced application migration time from 7 weeks to 2 weeks. Orchestrating this at enterprise scale with dependency management is a direct Control-M capability.