Organize the questions by the three standards. Explainable: what knowledge grounds the agent, can outputs be traced to source documents, can the bank configure its own policies. Auditable: is every action logged, can a workflow be reconstructed months later, are source citations retained, can you see where humans intervened. Governed: what can the agent access and change, which actions require approval, can permissions vary by role, can agents be stopped or escalated. Then ask whether all three exist inside the actual workflow rather than in the documentation.