Skip to content

Field guide

AI governance & compliance in finance

The EU AI Act, model risk management and supervisory expectations, turned into engineering you can ship.

All insights

From August 2026 the EU AI Act’s high-risk obligations bite, and credit scoring, insurance pricing and fraud detection sit squarely inside them. In the US, model risk management has moved on from SR 11-7. In Germany, BaFin now treats AI as an ICT risk under DORA. None of this is abstract policy: it lands as concrete requirements on systems you are building now.

This guide turns that regulatory weight into engineering: what high-risk classification actually demands, how to validate and monitor a model so it survives an examiner, and the documentation and human-oversight that has to exist before go-live, not after.

EU AI Act financial servicesmodel risk managementSR 11-7BaFin AIAI governance fintechDORA

Current signals

As of June 2026
  • The EU Digital Omnibus (provisional, May 2026) moves Annex III high-risk obligations, credit scoring included, to 2 December 2027, pending Council adoption.
  • SR 26-2 supersedes SR 11-7 with materiality-based oversight and drops blanket annual revalidation, while leaving generative and agentic AI out of scope.
  • DORA has applied since January 2025; BaFin now frames AI inside critical ICT, with dependency mapping, third-party contracts and incident reporting.
  • The CFPB holds that AI credit decisions still owe specific ECOA reason codes and documented disparate-impact testing, however complex the model.

In this guide

#governance

Running AI incident postmortems in finance

A model incident without a postmortem is an incident you will repeat. Here is the blameless postmortem process we run for finance AI failures.

Read
#governance

Consumer Duty and AI in UK financial services

The FCA's Consumer Duty reshapes what an AI-driven decision must be able to show. Here is how we engineer for good outcomes and fair value.

#governance

An AI governance operating model for a finance team

Governance fails when it is a committee with no wiring. Here is the operating model, roles and gates we help finance teams put around AI.

#gdpr

GDPR and automated decisions in finance AI

Article 22 and the right to an explanation shape what a finance model may decide alone. Here is how we engineer for it without stalling the workflow.

#procurement

AI vendor due diligence: the questions that matter

Buying an AI vendor imports their model risk into your firm. Here is the due-diligence checklist we use before a finance team signs.

#human-oversight

Designing human oversight for high-risk AI

The EU AI Act demands effective human oversight, not a rubber stamp. Here is how we design review points a person can actually exercise.

#fair-lending

A bias audit workflow for lending models

Disparate-impact testing, the less-discriminatory-alternative search, and production monitoring: the fairness workflow we run for credit models.

#governance

Writing EU AI Act technical documentation that holds up

High-risk classification means a documentation package, not a slide. Here is what Annex IV actually asks for and how we assemble it as engineering evidence.

#governance

Model cards that actually help finance governance

A model card is documentation a reviewer can act on, not marketing. Here is what we put on one for a finance model, and why each field earns its place.

#red-teaming

Red-teaming AI systems in financial services

Adversaries probe finance AI for jailbreaks, data leaks and biased outputs. Here is how we red-team a system before an attacker or an examiner does.

#audit-trail

Audit trails that make finance AI reproducible

When an examiner asks why the model said that, you need to reconstruct it exactly. Here is the logging and versioning that makes a decision reproducible.

#shadow-ai

Shadow AI: governing the tools staff already use

Your team is pasting data into chatbots whether you approved it or not. Here is the usage policy and controls we help finance firms put around it.

#governance

Continuous model monitoring that satisfies a regulator

Annual revalidation is not enough for a model that drifts weekly. Here is the monitoring, alerting and evidence trail we build for supervised finance models.

#dora

DORA incident response when AI is the ICT risk

Under DORA, an AI outage is an ICT incident with reporting clocks. Here is the detection, classification and reporting workflow we build for AI systems.

#governance

Standing up an AI model inventory and registry

You cannot govern what you cannot list. Here is the model inventory, registry and metadata we build so risk and audit can see every model in production.

#governance

BaFin now reads AI as ICT risk: what DORA asks of your models

BaFin's December 2025 guidance files AI inside DORA's ICT risk regime, not a separate ethics box. Here is what that means for registers, incidents and testing.

#governance

When the model is someone else's: third-party AI and vendor model risk

A hosted model API is an ICT service, not a feature. Here is how we treat vendor model risk, concentration, and silent updates under DORA-style scrutiny.

#governance

What the EU AI Act's August 2026 deadline asks you to build

Credit scoring and insurance-pricing systems are headed into the high-risk regime, and the date is now in flux. Here is what that means for the system you are building.

#governance

MiCA for stablecoins and crypto payments: what engineering teams must build

MiCA turns crypto-asset rules into concrete controls for issuers and payment firms. Here is the monitoring, reporting and data-lineage engineering it actually requires.

#governance

If your credit model can't explain a denial, you can't use it for that denial

ECOA Regulation B requires specific reasons within 30 days of a credit denial. Here is what that demands from the model that made the decision, not the paperwork around it.

#governance

How to actually test a credit or pricing model for fairness

Dropping a protected attribute does not make a model fair. Here is how we test credit and pricing models for disparate impact and proxy discrimination, and keep the evidence.

#governance

Model risk management when the model is an LLM

SR 11-7 was written for deterministic models. Its 2026 replacement, SR 26-2, modernised model risk management but left generative AI out of scope. Here is how to extend it to an LLM.

#governance

Explainability methods that survive a model validation review

Most explainability work satisfies the data scientist who built the model and nobody else. Here is how we make it hold up for a validator, a regulator and the customer who got declined.

Working on something similar?

Tell us about your data and the workflow around it, and we will give you a straight read.

Book a 30-min intro call