Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries · Financial services

Annex III duties for credit scoring apply from 2 December 2027

A bank's AI answers to four supervisors at once

Each one holds its own legal basis, its own document requests, and its own clock.

What you need to know

  1. Four desks can examine the same AI system. The financial supervisor under DORA, the ECB for internal models, the data protection authority under the GDPR, and the market surveillance authority under the EU AI Act, which for high-risk AI in regulated financial services is the financial supervisor holding a second mandate under Article 74(6).
  2. Credit scoring and insurance pricing are named high risk. Annex III points 5(b) and 5(c) cover creditworthiness assessment of natural persons and risk assessment and pricing in life and health insurance; under the Digital Omnibus these duties apply from 2 December 2027.
  3. DORA has applied since 17 January 2025. Suppliers of cloud-hosted LLMs and ML platforms count as ICT third-party providers. Classifying an incident as major starts a 4-hour initial-notification clock, within 24 hours of awareness at the latest.
  4. GDPR Article 22 already restricts automated decisions. The CJEU held in SCHUFA (C-634/21) that producing a credit score can itself be such a decision, and Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher.
  5. The evidence overlaps almost entirely. The AI inventory, validation artefacts, oversight logs, third-party records, and incident history form the evidence base every desk draws on once they live in one governance graph.
Owners: CRO, Head of Model Risk, DPO, Head of ComplianceRead the framework docs →
01

The use-case docket

The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a fraud model with no AI Act gate still answers to desks one and three.

Manipulative nudging in retail finance

Article 5(1)(a) and 5(1)(b) prohibit techniques that materially distort behaviour or exploit vulnerability.

Prohibited (Art. 5)

Retail credit scoring for natural persons

Named high risk in Annex III point 5(b).

High-risk (Annex III)

Life and health insurance pricing

Named high risk in Annex III point 5(c).

High-risk (Annex III)

Fraud detection and transaction monitoring

Carved out of the 5(b) credit clause. GDPR Article 22 applies in full.

No AI Act gate

Generative AI customer service

Article 50: customers must be told they are interacting with AI.

Transparency (Art. 50)

Internal analytics and reporting

No gate when outputs do not drive customer decisions. DORA still applies.

No AI Act gate
02

Who can knock, and with what

The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.

01DORAYour financial supervisor

The national competent authority that already supervises you: BaFin, the ACPR, DNB, the Central Bank of Ireland, or their peer in your member state.

ICT risk and operational resilience under Regulation (EU) 2022/2554 (DORA), fully applicable since 17 January 2025. Suppliers of cloud-hosted LLMs and third-party ML platforms count as ICT third-party providers, so every production AI dependency sits inside this mandate.

What they can ask for

  • The ICT risk management framework and its approval by the management body
  • The register of information covering every ICT third-party provider, AI and ML vendors included
  • Resilience testing results and exit strategies for material providers
  • Major-incident reports on the DORA timeline
4h
initial notification after an incident is classified as major
72h
intermediate report
1 month
final report
02SSMThe ECB, for significant institutions

The European Central Bank through the Single Supervisory Mechanism, direct supervisor of significant institutions in the euro area.

Internal models under the CRR, with expectations set out in the ECB Guide to Internal Models: IRB credit risk, market risk, and counterparty credit risk. An ML model used as an internal model meets the same validation, data quality, and documentation bar as a traditional statistical model. The ECB is not an AI Act authority; its lane is prudential model risk.

What they can ask for

  • Model development and model change documentation
  • Independent validation reports and data quality evidence
  • An on-site internal model investigation, announced in advance
Before use
material model changes wait for supervisory approval
Weeks
typical on-site phase of an internal model investigation
03GDPRThe data protection authority

Your lead supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.

Automated decision-making under Article 22, which restricts solely automated decisions with legal or similarly significant effects. The CJEU held in SCHUFA (C-634/21, December 2023) that producing a credit score can itself be such a decision. Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher, and fines in the hundreds of millions of euros already exist in adjacent consumer sectors.

What they can ask for

  • Data protection impact assessments under Article 35
  • Records of processing under Article 30
  • The human review path behind automated credit and insurance decisions
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
04AI ActThe market surveillance authority

Under Article 74(6), for banks and insurers regulated under EU financial services law this is your financial supervisor again, holding a second mandate.

High-risk AI under Regulation (EU) 2024/1689. Annex III point 5(b) names creditworthiness assessment and credit scoring of natural persons; point 5(c) names risk assessment and pricing in life and health insurance. Under the Digital Omnibus, now in force, these duties apply from 2 December 2027.

What they can ask for

  • The technical file, on request under Article 74
  • Data governance and training data documentation
  • Automatically generated logs and human oversight records
  • The conformity assessment behind the CE marking
2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness
EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189CCPA ADMTNYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

The financial-services stack in the framework library: the EU AI Act, DORA, the GDPR, and ISO/IEC 42001 map onto shared controls, so a control written once is reused by every framework that shares it. The desks above each read from that shared record.

454 / 958controls in the library serve more than one framework
45controls shared by at least two of these four frameworks

Framework library v1.0.32

03

Frequently asked questions

Are credit scoring models really high risk under the EU AI Act?

Yes. Annex III Part 5(b) explicitly classifies AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score as high risk. The only carve-out is AI systems used for the purpose of detecting financial fraud. High-risk classification triggers conformity assessment, technical documentation, data governance, human oversight, logging, and post-market monitoring.

How does the EU AI Act interact with DORA?

DORA is lex specialis for ICT risk management in financial services, so its incident reporting and third-party register rules take precedence on those topics. The AI Act conformity assessment, data governance, and fundamental rights impact assessment obligations still apply to high-risk AI systems. Most firms run a combined programme to avoid duplicate control documentation.

Do we need ISO/IEC 42001 certification?

Not yet legally required, but increasingly expected. Supervisors across the EU and Middle East reference ISO/IEC 42001 as the governance baseline, and certification is becoming a commercial expectation in RFPs for regulated AI vendors. For financial firms that already run ISO/IEC 27001, adding 42001 is typically a six to nine month effort on top of existing controls.

How should we treat third-party LLMs and cloud-hosted AI?

DORA designates critical ICT third-party service providers on a service-based test under Article 31 and the related Delegated Regulation. Cloud platforms hosting AI services for financial entities qualify where they meet the criticality criteria, and fall under direct oversight by a Lead Overseer from one of the ESAs. Include them in the ICT third-party register, document exit strategies, run concentration risk analysis, and cover them in resilience testing where material.

What does "personal board accountability" mean in practice?

Article 5 of DORA places ultimate responsibility for ICT risk management on the management body. Combined with SMCR in the UK and Article 20 of NIS2 for cybersecurity, this means board members can face personal fines, suspension from managerial functions, and in some jurisdictions criminal liability for governance failures linked to AI or ICT incidents.

How does Modulos help with EU AI Act readiness?

Modulos gives you a structured backbone: a live AI inventory with risk classification, traceable technical documentation, conformity assessment workflows, human oversight logs, post-market monitoring, and a fundamental rights impact assessment template aligned to Commission guidance. All of it shares evidence with your existing model risk, DORA, and ISO 27001 programmes so you do the work once.

See the governance graph on one of your models

Talk to an expert

A demo walks through the four desks with a credit or insurance use case, on the governance graph your evidence would live in.

Request a demo

Keep exploring on your own

The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on each desk's legal basis.