Industries · Financial services
Annex III duties for credit scoring apply from 2 December 2027A bank's AI answers to four supervisors at once
Each one holds its own legal basis, its own document requests, and its own clock.
What you need to know
- Four desks can examine the same AI system. The financial supervisor under DORA, the ECB for internal models, the data protection authority under the GDPR, and the market surveillance authority under the EU AI Act, which for high-risk AI in regulated financial services is the financial supervisor holding a second mandate under Article 74(6).
- Credit scoring and insurance pricing are named high risk. Annex III points 5(b) and 5(c) cover creditworthiness assessment of natural persons and risk assessment and pricing in life and health insurance; under the Digital Omnibus these duties apply from 2 December 2027.
- DORA has applied since 17 January 2025. Suppliers of cloud-hosted LLMs and ML platforms count as ICT third-party providers. Classifying an incident as major starts a 4-hour initial-notification clock, within 24 hours of awareness at the latest.
- GDPR Article 22 already restricts automated decisions. The CJEU held in SCHUFA (C-634/21) that producing a credit score can itself be such a decision, and Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher.
- The evidence overlaps almost entirely. The AI inventory, validation artefacts, oversight logs, third-party records, and incident history form the evidence base every desk draws on once they live in one governance graph.
The use-case docket
The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a fraud model with no AI Act gate still answers to desks one and three.
Manipulative nudging in retail finance
Article 5(1)(a) and 5(1)(b) prohibit techniques that materially distort behaviour or exploit vulnerability.
Retail credit scoring for natural persons
Named high risk in Annex III point 5(b).
Life and health insurance pricing
Named high risk in Annex III point 5(c).
Fraud detection and transaction monitoring
Carved out of the 5(b) credit clause. GDPR Article 22 applies in full.
Generative AI customer service
Article 50: customers must be told they are interacting with AI.
Internal analytics and reporting
No gate when outputs do not drive customer decisions. DORA still applies.
Who can knock, and with what
The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.
01DORAYour financial supervisor
The national competent authority that already supervises you: BaFin, the ACPR, DNB, the Central Bank of Ireland, or their peer in your member state.
ICT risk and operational resilience under Regulation (EU) 2022/2554 (DORA), fully applicable since 17 January 2025. Suppliers of cloud-hosted LLMs and third-party ML platforms count as ICT third-party providers, so every production AI dependency sits inside this mandate.
What they can ask for
- The ICT risk management framework and its approval by the management body
- The register of information covering every ICT third-party provider, AI and ML vendors included
- Resilience testing results and exit strategies for material providers
- Major-incident reports on the DORA timeline
- 4h
- initial notification after an incident is classified as major
- 72h
- intermediate report
- 1 month
- final report
02SSMThe ECB, for significant institutions
The European Central Bank through the Single Supervisory Mechanism, direct supervisor of significant institutions in the euro area.
Internal models under the CRR, with expectations set out in the ECB Guide to Internal Models: IRB credit risk, market risk, and counterparty credit risk. An ML model used as an internal model meets the same validation, data quality, and documentation bar as a traditional statistical model. The ECB is not an AI Act authority; its lane is prudential model risk.
What they can ask for
- Model development and model change documentation
- Independent validation reports and data quality evidence
- An on-site internal model investigation, announced in advance
- Before use
- material model changes wait for supervisory approval
- Weeks
- typical on-site phase of an internal model investigation
03GDPRThe data protection authority
Your lead supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.
Automated decision-making under Article 22, which restricts solely automated decisions with legal or similarly significant effects. The CJEU held in SCHUFA (C-634/21, December 2023) that producing a credit score can itself be such a decision. Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher, and fines in the hundreds of millions of euros already exist in adjacent consumer sectors.
What they can ask for
- Data protection impact assessments under Article 35
- Records of processing under Article 30
- The human review path behind automated credit and insurance decisions
- 72h
- personal data breach notification under Article 33
- 1 month
- response to a data subject request under Article 12(3)
04AI ActThe market surveillance authority
Under Article 74(6), for banks and insurers regulated under EU financial services law this is your financial supervisor again, holding a second mandate.
High-risk AI under Regulation (EU) 2024/1689. Annex III point 5(b) names creditworthiness assessment and credit scoring of natural persons; point 5(c) names risk assessment and pricing in life and health insurance. Under the Digital Omnibus, now in force, these duties apply from 2 December 2027.
What they can ask for
- The technical file, on request under Article 74
- Data governance and training data documentation
- Automatically generated logs and human oversight records
- The conformity assessment behind the CE marking
- 2 Dec 2027
- Annex III obligations apply
- 15 days
- serious incident report under Article 73, from awareness
The regimes overlap where the controls live
The financial-services stack in the framework library: the EU AI Act, DORA, the GDPR, and ISO/IEC 42001 map onto shared controls, so a control written once is reused by every framework that shares it. The desks above each read from that shared record.
Framework library v1.0.32
Frequently asked questions
Are credit scoring models really high risk under the EU AI Act?
Yes. Annex III Part 5(b) explicitly classifies AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score as high risk. The only carve-out is AI systems used for the purpose of detecting financial fraud. High-risk classification triggers conformity assessment, technical documentation, data governance, human oversight, logging, and post-market monitoring.
How does the EU AI Act interact with DORA?
DORA is lex specialis for ICT risk management in financial services, so its incident reporting and third-party register rules take precedence on those topics. The AI Act conformity assessment, data governance, and fundamental rights impact assessment obligations still apply to high-risk AI systems. Most firms run a combined programme to avoid duplicate control documentation.
Do we need ISO/IEC 42001 certification?
Not yet legally required, but increasingly expected. Supervisors across the EU and Middle East reference ISO/IEC 42001 as the governance baseline, and certification is becoming a commercial expectation in RFPs for regulated AI vendors. For financial firms that already run ISO/IEC 27001, adding 42001 is typically a six to nine month effort on top of existing controls.
How should we treat third-party LLMs and cloud-hosted AI?
DORA designates critical ICT third-party service providers on a service-based test under Article 31 and the related Delegated Regulation. Cloud platforms hosting AI services for financial entities qualify where they meet the criticality criteria, and fall under direct oversight by a Lead Overseer from one of the ESAs. Include them in the ICT third-party register, document exit strategies, run concentration risk analysis, and cover them in resilience testing where material.
What does "personal board accountability" mean in practice?
Article 5 of DORA places ultimate responsibility for ICT risk management on the management body. Combined with SMCR in the UK and Article 20 of NIS2 for cybersecurity, this means board members can face personal fines, suspension from managerial functions, and in some jurisdictions criminal liability for governance failures linked to AI or ICT incidents.
How does Modulos help with EU AI Act readiness?
Modulos gives you a structured backbone: a live AI inventory with risk classification, traceable technical documentation, conformity assessment workflows, human oversight logs, post-market monitoring, and a fundamental rights impact assessment template aligned to Commission guidance. All of it shares evidence with your existing model risk, DORA, and ISO 27001 programmes so you do the work once.
See the governance graph on one of your models
Talk to an expert
A demo walks through the four desks with a credit or insurance use case, on the governance graph your evidence would live in.
Request a demo →Keep exploring on your own
The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on each desk's legal basis.