Verifiable AI in municipal shareholding management
How an on-premise decision-intelligence system turns real shareholding figures into auditable reports, a deterministic early-warning system and robust decision scenarios — without inventing a single number.
By Leonardo Bornhäußer (Founder, Creativate Technologies GmbH) in co-authorship with Assoc. Prof. Dr. Tuna Çakar · July 2026 · ~10 min read
- Automated, auditable report text per company — rule-based and via a local language model, both without invented numbers.
- An honest data-maturity and early-warning analysis that shows what can seriously be said at the current data depth — and what cannot.
- An assumption-driven scenario and simulation layer (best/base/worst + Monte Carlo) that solves the forecasting problem on a short history cleanly.
Guiding principle throughout: no enrichment of the actual figures, no invented values, every number traceable to source, everything local.
Context & data basis
The basis was a municipal shareholding portfolio with five companies from different sectors. All figures were delivered masked and processed 100% locally — no data outflow, no cloud.
| Item | Content |
|---|---|
| Client | Shareholding portfolio of a German municipality (participation report under §123a GO) |
| Companies (5) | Culture/museum gGmbH · project-development mbH · municipal utility · culture/exhibition gGmbH · facility-services GmbH (anonymised) |
| Metrics (8 core) | Depreciation · balance-sheet total · equity · net result · material cost · personnel cost · revenue · liabilities |
| Processing | 100% local, no data outflow; empty cell = n/a, never a number |
Method — three work streams
The PoC cleanly separates what follows arithmetically from the customer data and what a language model phrases from it. The business logic never belongs to the model.
Rule-based report text — ready to show today
From the figures, a participation-report excerpt is produced per company, bilingual. At the core is a five-level variance classification per KPI plus curated cause hypotheses — explicitly flagged as hypotheses to validate, never as fact.
Machine learning with a hallucination lock — 5/5 validated
This layer enriches nothing. A local language model (via Ollama, offline) writes the reports under a strict anti-hallucination architecture: number-token allow-listing, JSON schema, temperature = 0, deterministic fallback. Result: all 5 reports passed — 0 fallbacks, 0 unsupported statements.
Honest analytics, early warning, scenarios
The scientifically honest answer to the use cases “report” and “early warning/forecast” — a deterministic early-warning system on real KPIs plus assumption-driven scenarios.
Intelligence layer — today, on real figures
- Cross-sectional multivariate analysis across the five companies — valid even on a short time series, because it varies across companies rather than over time.
- Deterministic early-warning system on real KPIs: first-degree liquidity below threshold, negative net result, revenue > 5% below plan — each signal carries the driving actual figures.
- Scenario & simulation: a statistical forecast needs 18–36 periods; only two annual points existed — so we do not forecast. Instead, conditional modelling (best/base/worst + Monte Carlo) under openly declared assumptions.
Verifiability — what holds today, and what doesn’t
Verifiability also means naming the limits. That boundary is part of the product.
- Auditable report text from real data (live)
- Local model writes reports without inventing numbers (5/5 validated)
- Deterministic early-warning system on real KPIs
- Scenarios/Monte Carlo as conditional modelling under assumptions
- Architecture: local, GDPR, RBAC, traceable to source
- A specific forecast accuracy on a short history
- Early-warning thresholds from two data points as calibrated
- Pilot figures from other projects as a 1:1 promise
- Scenario output as a forecast
- Enrichment of the real KPIs with third-party data
Future intelligence — the ML forecast pipeline
The path to statistical forecasting is not a promise but a data-driven expansion criterion. Once the data depth is right, the same architecture activates a real ML forecast pipeline.
A serious statistical forecast becomes possible from ≥ 8 years of annual data or ≥ 20 quarters per metric — objectively checkable, and the bridge to a concrete data request to the client.
| Stage | Method | Output (artifact) |
|---|---|---|
| Forecast | Time-series model on ≥ 8 years, with conformal interval | Forecast + uncertainty band |
| Drivers | XGBoost + SHAP attribution | Explainable drivers per metric |
| Early warning | Calibrated thresholds from internal history | Signal with actual figures |
| Decision | Scenario + recommendation, the human decides | Decision memo, evidenced |
All artifacts stay traceable to source and deterministically reproducible; the language model phrases, but never computes.
Quality & compliance evidence
- No fabrication: a validation notebook recomputes every number in pure pandas (agreement to 1e-12).
- Tests: deterministic core + scenario/market = 41 tests green.
- Local-only: no data outflow, model local via Ollama, cache only public macro values.
- Explainability: deterministic-first — the model is a pure phrasing layer over precomputed facts (EU AI Act, Art. 12/13).
See it on your data.
A short test in your environment — evidenced answers and reports, on-prem. We show the PoC on your own figures.
Book a demo call →Data basis: real, masked shareholding figures of a German municipality, processed exclusively locally. Client and companies anonymised. Creativate Technologies GmbH · Frankfurt am Main.
Read the full whitepaper
Just your details — then read the complete whitepaper and download it as PDF.