Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries / Financial services

A bank's AI answers to four supervisors at once

Each one holds its own legal basis, its own document requests, and its own clock.

01DORA

Your financial supervisor

4h initial notification after an incident is classified as major

02SSM

The ECB, for significant institutions

Before use material model changes wait for supervisory approval

03GDPR

The data protection authority

72h personal data breach notification under Article 33

04AI Act

The market surveillance authority

2 Dec 2027 Annex III obligations apply

The desk

Who can knock, and with what

Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.

Desk 01DORA

Your financial supervisor

The national competent authority that already supervises you: BaFin, the ACPR, DNB, the Central Bank of Ireland, or their peer in your member state.

ICT risk and operational resilience under Regulation (EU) 2022/2554 (DORA), fully applicable since 17 January 2025. Cloud-hosted LLMs and third-party ML platforms count as ICT third-party providers, so every production AI dependency sits inside this mandate.

What they can ask for

  • The ICT risk management framework and its approval by the management body
  • The register of information covering every ICT third-party provider, AI and ML vendors included
  • Resilience testing results and exit strategies for material providers
  • Major-incident reports on the DORA timeline

The clock

4h
initial notification after an incident is classified as major
72h
intermediate report
1 month
final report
Desk 02SSM

The ECB, for significant institutions

The European Central Bank through the Single Supervisory Mechanism, direct supervisor of significant institutions in the euro area.

Internal models under the CRR, with expectations set out in the ECB Guide to Internal Models: IRB credit risk, market risk, and counterparty credit risk. An ML model used as an internal model meets the same validation, data quality, and documentation bar as a traditional statistical model. The ECB is not an AI Act authority; its lane is prudential model risk.

What they can ask for

  • Model development and model change documentation
  • Independent validation reports and data quality evidence
  • An on-site internal model investigation, announced in advance

The clock

Before use
material model changes wait for supervisory approval
Weeks
typical on-site phase of an internal model investigation
Desk 03GDPR

The data protection authority

Your lead supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.

Automated decision-making under Article 22, which restricts solely automated decisions with legal or similarly significant effects. The CJEU held in SCHUFA (C-634/21, December 2023) that producing a credit score can itself be such a decision. Article 83(5) caps fines at 4% of worldwide annual turnover, and fines in the hundreds of millions of euros already exist in adjacent consumer sectors.

What they can ask for

  • Data protection impact assessments under Article 35
  • Records of processing under Article 30
  • The human review path behind automated credit and insurance decisions

The clock

72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act

The market surveillance authority

Under Article 74(6), for banks and insurers regulated under EU financial services law this is your financial supervisor again, holding a second mandate.

High-risk AI under Regulation (EU) 2024/1689. Annex III point 5(b) names creditworthiness assessment and credit scoring of natural persons; point 5(c) names risk assessment and pricing in life and health insurance. Under the adopted Digital Omnibus, these duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • Data governance and training data documentation
  • Automatically generated logs and human oversight records
  • The conformity assessment behind the CE marking

The clock

2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness

Every desk reads from the same record

Each desk asks a different question on a different legal basis, but the evidence behind the answers overlaps almost entirely: the AI inventory, validation artefacts, oversight logs, third-party records, and incident history. Modulos keeps that evidence as one governance graph, where a control written once earns credit across every framework it satisfies. Supervisors do not coordinate their requests; the record is ready for whichever desk asks first.

01 DORA02 SSM03 GDPR04 AI ActOne evidence record

Dates that matter

2 Aug 2026

General application of the EU AI Act and the start of GPAI enforcement

2 Dec 2027

Annex III duties for credit scoring and life and health insurance pricing, per the adopted Digital Omnibus

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a fraud model with no AI Act gate still answers to desks one and three.

Manipulative nudging in retail finance

Article 5(1)(a) and 5(1)(b) prohibit techniques that materially distort behaviour or exploit vulnerability.

Prohibited (Art. 5)

Retail credit scoring for natural persons

Named high risk in Annex III point 5(b).

High-risk (Annex III)

Life and health insurance pricing

Named high risk in Annex III point 5(c).

High-risk (Annex III)

Fraud detection and transaction monitoring

Carved out of the 5(b) credit clause. GDPR Article 22 applies in full.

No AI Act gate

Generative AI customer service

Article 50: customers must be told they are interacting with AI.

Transparency (Art. 50)

Internal analytics and reporting

No gate when outputs do not drive customer decisions. DORA still applies.

No AI Act gate

Related regulations

Go deeper on the regimes that apply to this sector:

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Frequently asked questions

Are credit scoring models really high risk under the EU AI Act?

Yes. Annex III Part 5(b) explicitly classifies AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score as high risk. The only carve-out is AI systems used for the purpose of detecting financial fraud. High-risk classification triggers conformity assessment, technical documentation, data governance, human oversight, logging, and post-market monitoring.

How does the EU AI Act interact with DORA?

DORA is lex specialis for ICT risk management in financial services, so its incident reporting and third-party register rules take precedence on those topics. The AI Act conformity assessment, data governance, and fundamental rights impact assessment obligations still apply to high-risk AI systems. Most firms run a combined programme to avoid duplicate control documentation.

Do we need ISO/IEC 42001 certification?

Not yet legally required, but increasingly expected. Supervisors across the EU and Middle East reference ISO/IEC 42001 as the governance baseline, and certification is becoming a commercial expectation in RFPs for regulated AI vendors. For financial firms that already run ISO/IEC 27001, adding 42001 is typically a six to nine month effort on top of existing controls.

How should we treat third-party LLMs and cloud-hosted AI?

DORA designates critical ICT third-party service providers on a service-based test under Article 31 and the related Delegated Regulation. Cloud platforms hosting AI services for financial entities qualify where they meet the criticality criteria, and fall under direct oversight by a Lead Overseer from one of the ESAs. Include them in the ICT third-party register, document exit strategies, run concentration risk analysis, and cover them in resilience testing where material.

What does "personal board accountability" mean in practice?

Article 5 of DORA places ultimate responsibility for ICT risk management on the management body. Combined with SMCR in the UK and Article 20 of NIS2 for cybersecurity, this means board members can face personal fines, suspension from managerial functions, and in some jurisdictions criminal liability for governance failures linked to AI or ICT incidents.

How does Modulos help with EU AI Act readiness?

Modulos gives you a structured backbone: a live AI inventory with risk classification, traceable technical documentation, conformity assessment workflows, human oversight logs, post-market monitoring, and a fundamental rights impact assessment template aligned to Commission guidance. All of it shares evidence with your existing model risk, DORA, and ISO 27001 programmes so you do the work once.

See the governance graph on one of your models

A demo walks through the four desks with a credit or insurance use case. The quiz classifies your role and risk exposure in about three minutes.