EU AI Act Compliance for Banks, Insurers and Financial Services AI
Financial services AI, especially consumer credit scoring and life/health insurance underwriting, is Annex III Point 5. Together with the mandatory private-sector FRIA under Article 27, supervisory oversight from the ECB, EBA and EIOPA, and DORA operational-resilience obligations, the compliance stack for financial institutions is dense.
Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.
Financial services faces one of the heaviest AI Act obligation surfaces. Annex III Point 5(b) (creditworthiness of natural persons, excluding fraud detection) and Point 5(c) (life and health insurance risk assessment and pricing) are the two domains where even private-sector deployers are bound by a mandatory Article 27 FRIA.
On top of the AI Act: DORA (Regulation (EU) 2022/2554) imposes ICT risk-management, testing, and incident-reporting duties on financial entities with substantial overlap with AI Act Article 15. ECB guidance on AI in prudential decisions, EBA guidelines on ML model governance, and EIOPA supervisory statements on AI in insurance all add supervisory expectations that are not in the Regulation text but are enforced in practice.
Consumer Credit, The Most Scrutinised Use Case
Consumer credit scoring AI is the highest-profile Annex III Point 5 application. The SCHUFA judgment (CJEU, 2023) established that automated credit scoring can trigger GDPR Article 22 even where a human formally signs off. The AI Act layers on top:
- Article 9 risk management with specific attention to disparate-impact analysis across protected groups.
- Article 10 data governance, the canonical bias-examination area. Training data must be representative and tested for fairness.
- Article 14 human oversight, meaningful review, not rubber-stamping, at least at the appeal stage.
- Article 27 FRIA, mandatory for private deployers of Point 5(b). The FRIA must cover groups affected, specific risks, governance measures, and mitigation.
- Article 86 right to explanation, individuals refused credit can demand a clear and meaningful explanation of the AI's contribution to the decision.
The combined Consumer Credit Directive II (Directive (EU) 2023/2225, applying from November 2026), GDPR, and AI Act create a three-layer regime. Dual-path reviews in credit-risk functions are increasingly common.
Insurance, Life and Health Pricing
Point 5(c) covers AI in risk assessment and pricing only for life and health insurance. Non-life insurance (motor, property, commercial) is not in scope of Point 5(c), though it may still be caught by other regulatory regimes.
EIOPA's June 2021 report on AI in insurance and its subsequent supervisory statements set out expectations on: fairness across protected characteristics, explainability, human oversight, and ongoing model monitoring. These are soft law, but insurance supervisors across Member States have aligned on them. The AI Act Article 27 FRIA effectively codifies the fairness and explainability expectations already in supervisory guidance.
DORA + AI Act, Operational Resilience
DORA (Regulation (EU) 2022/2554, applying from 17 January 2025) imposes ICT risk-management, resilience-testing, incident-reporting, and third-party risk obligations on financial entities. Several DORA duties overlap materially with AI Act Article 15 (accuracy, robustness, cybersecurity) and Article 72 (post-market monitoring).
Financial institutions that have mature DORA programmes have a head start on AI Act Article 15 and 72, but the two regimes have distinct scope. DORA covers all ICT systems; the AI Act covers the behaviour of AI systems specifically. Mapped controls, distinct reporting lines.
What to Do Before 2 December 2027
Concrete actions for Financial Services compliance teams.
Inventory AI systems by Annex III point
Point 5(b) credit, Point 5(c) insurance, Point 4 HR, Point 6 fraud-detection-plus-credit. Fraud-only systems are carved out of 5(b), but pure fraud is rarely deployed.
Trigger FRIA for Point 5(b) and 5(c)
Private-sector FRIA obligation under Article 27. Most financial institutions do not yet have a FRIA workflow, build it.
Map DORA controls to AI Act Article 15
ICT risk-management, testing, and resilience duties under DORA substantially cover Article 15 requirements. Document the mapping.
Integrate with GDPR Article 22 workflow
Automated-decision requests and explanation requests must be handled in a unified workflow, duplicate processes confuse customers and auditors.
Document Article 86 explanation procedures
Customers refused credit or priced out of insurance have a right to meaningful explanation. Pre-drafted explanation templates with model-card-derived content are the emerging practice.
Align with ECB, EBA, EIOPA guidance
Supervisory expectations go beyond the Regulation text. Senior governance sign-off on model use is now standard.
Register with the competent market surveillance authority
Member State designations are finalising. Financial-services competent authority is often the prudential supervisor acting under the AI Act.
Built for Financial Services Compliance Teams
The Full Readiness Bundle gives you 11 documents covering the full Annex III obligation set, including the exact templates Financial Services compliance teams need to operationalise the Regulation.
one-time · instant download
Get the Full Bundle →Also available: Checklist Pack $149 · White-Label $999/yr