How to build an MCP for your industry
By Dorian Chávez · founder of Hábil and integration architect ·
What an MCP is, which controls it needs in a regulated industry, and how it applies to banking, insurance, ERP-run companies and retail. A guide for executives, with sources.
Your AI rarely fails because of the model alone
Models make mistakes, especially when they lack the real context of your company. More than 90% of data users at banks say they don't get the information they need in time, and 81% name data quality as their main challenge (Deloitte, 2025). In life insurance, 52% say legacy technology is the main obstacle (Capgemini, 2025). AI inherits the problems of your architecture: if your team can't get reliable data in time, neither can the model.
MCP (Model Context Protocol) is an open standard for connecting AI to your company's tools and data. It has become a widely adopted interface, and its governance moved to an open foundation. But the protocol on its own brings no permissions, no audit log and no data protection: those are designed and built around the connection, and that is where it's decided whether an MCP passes an audit.
How it's done, without the jargon
An MCP server is a layer between the AI and your systems. It is designed around four questions:
- Which system is opened, and only that part of it.
- Which actions are allowed: read first; anything that writes, with human approval.
- Under which identity: where it applies, that of the person the AI is acting for; when a service identity is used, with least privilege, tied to the request that triggered it and audited.
- What trail is left: who asked for what, with which data, and what the system answered.
MCP server
- Identity and permissions
- Human approval
- Audit log✓
- Minimal data
Returns with the answer
This snippet shows the shape of an MCP tool; it doesn't show the controls a live deployment needs:
# Illustrative, based on the official MCP documentation: a read-only tool.
from mcp.server.fastmcp import FastMCP
mcp = FastMCP("estatus-de-poliza")
@mcp.tool()
def estatus_poliza(numero: str) -> str:
"""Returns the status of a policy. Read-only."""
return consultar_core(numero)In a regulated environment, that same call runs with delegated identity, scope validation, minimal data and an auditable record. What you don't see in the example is what decides whether it passes an audit.
What a regulated industry requires
The risks are already documented: instructions hidden in the data the AI reads, tools that promise one thing and do another, permissions that grow without anyone noticing. That's why, from day one:
- Read-only first, and writes with human approval.
- Acting on someone's behalf: the log should say “the AI looked this up on behalf of this person”, not “someone logged in at 3 a.m.”.
- Minimal data, protected according to its classification: before exposing information to a model, you define the purpose, the allowed fields, retention and processing by third parties.
- Usage limits and a searchable log for the auditor.
Can your AI prove today on whose behalf it acted? DevSecOps
Different capabilities for each audience
The costly mistake is giving the AI a single access for everyone. Capabilities and policies are designed per audience; there may be one or several MCP servers, depending on isolation, risk and regulation.
| Audience | What it can do | What your company is after |
|---|---|---|
| Customers | see what's theirs —policy, loan, order—, start a request | broader service and fewer repeat inquiries |
| Employees | look up their area's files according to their role | less double data entry and faster answers |
| Suppliers | see their invoices, their payments and their file | fewer calls to accounts payable |
| Intermediaries (agents, brokers, distributors) | quote, check their portfolio and their commissions | a more agile sales channel |
| Auditors | look up evidence, for a limited time | preparing evidence in less time |
| Third-party AI agents | query your public catalog | being where AIs already shop |
On channels like WhatsApp, sensitive queries require linking identity in a way that matches the risk, consent where applicable, limits on the information shown and a secure path for higher-impact operations.
What it looks like in your industry
Insurance: the agent asks “has the premium on this policy been paid?” and the answer comes from the policy system, without calling collections. Up to 65% of underwriting hours can be automated or supported with AI (Accenture).
MCP server
- Identity and permissions
- Human approval
- Audit log✓
- Minimal data
Premium status, without calling collections
Banking and fintech: the customer checks the status of their loan after verifying their identity; compliance reviews its alerts with a reinforced audit log. At banks that already apply it, verifying new customers' identity cost 20% less and false money-laundering alerts fell 30% (BCG, 2025).
MCP server
- Identity and permissions
- Human approval
- Audit log✓
- Minimal data
Loan status
ERP-run companies: “why doesn't this invoice reconcile?”, answered from the ERP. Some ERPs already expose their functions through MCP, respecting each role's permissions; for the rest, we build the MCP server on top of their current APIs.
MCP server
- Identity and permissions
- Human approval
- Audit log✓
- Minimal data
Why the invoice doesn't reconcile
Retail: stock by channel, order status and returns with human confirmation; plus an open catalog for shopping agents. Customers who use a large retailer's AI assistant spend around 35% more per order (Modern Retail, 2026).
MCP server
- Identity and permissions
- Human approval
- Audit log✓
- Minimal data
Stock by channel and order status
These figures describe studies or cases from specific organizations; they are not a promise of results. To estimate the impact on your operation, we start from your volume, the time per request, the error rate and the current cost.
Which of your systems would come first? Integration and APIs
How we build it for you
- On top of what you already have: we build the MCP server to consume the current interfaces of your core, your ERP or your sales platform, with minimal changes to your systems.
- And, if you already run on Retícula, the platform connects through the same MCP: quoting, issuance, collection and reconciliation within the AI's reach, under your rules.
- Nova, Hábil's AI, serves customers on WhatsApp with the same capabilities as your internal team.
Sources
- Deloitte, 2026 Banking and Capital Markets Outlook (oct-2025)
- Capgemini, World Life Insurance Report 2025
- BCG, “A Faster Path to Scaling GenAI in Banking Compliance” (Nov 2025)
- Accenture, “Underwriting Rewritten”
- Modern Retail (Feb 2026)
- Microsoft Learn, MCP in Dynamics 365
- Official MCP specification
- OWASP MCP Top 10
At Hábil we design and build MCP servers for your core, your ERP and your channels, with the permissions and the trail your regulator requires.
Send us on WhatsApp the name of one system and one process that today causes waiting, double data entry or risk. In the first conversation we'll tell you whether an MCP makes sense, which controls it would require and what's missing to estimate it.
Prefer email? Write to us at hola@habil.mx