Each one holds its own legal basis, its own document requests, and its own clock.
01DORA
Your financial supervisor
4h initial notification after an incident is classified as major
02SSM
The ECB, for significant institutions
Before use material model changes wait for supervisory approval
03GDPR
The data protection authority
72h personal data breach notification under Article 33
04AI Act
The market surveillance authority
2 Dec 2027 Annex III obligations apply
The desk
Who can knock, and with what
Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.
Desk 01DORA
Your financial supervisor
The national competent authority that already supervises you: BaFin, the ACPR, DNB, the Central Bank of Ireland, or their peer in your member state.
ICT risk and operational resilience under Regulation (EU) 2022/2554 (DORA), fully applicable since 17 January 2025. Cloud-hosted LLMs and third-party ML platforms count as ICT third-party providers, so every production AI dependency sits inside this mandate.
What they can ask for
The ICT risk management framework and its approval by the management body
The register of information covering every ICT third-party provider, AI and ML vendors included
Resilience testing results and exit strategies for material providers
Major-incident reports on the DORA timeline
The clock
4h
initial notification after an incident is classified as major
72h
intermediate report
1 month
final report
Desk 02SSM
The ECB, for significant institutions
The European Central Bank through the Single Supervisory Mechanism, direct supervisor of significant institutions in the euro area.
Internal models under the CRR, with expectations set out in the ECB Guide to Internal Models: IRB credit risk, market risk, and counterparty credit risk. An ML model used as an internal model meets the same validation, data quality, and documentation bar as a traditional statistical model. The ECB is not an AI Act authority; its lane is prudential model risk.
What they can ask for
Model development and model change documentation
Independent validation reports and data quality evidence
An on-site internal model investigation, announced in advance
The clock
Before use
material model changes wait for supervisory approval
Weeks
typical on-site phase of an internal model investigation
Desk 03GDPR
The data protection authority
Your lead supervisory authority under the GDPR, applicable since 25 May 2018. It does not wait for the AI Act.
Automated decision-making under Article 22, which restricts solely automated decisions with legal or similarly significant effects. The CJEU held in SCHUFA (C-634/21, December 2023) that producing a credit score can itself be such a decision. Article 83(5) caps fines at 4% of worldwide annual turnover, and fines in the hundreds of millions of euros already exist in adjacent consumer sectors.
What they can ask for
Data protection impact assessments under Article 35
Records of processing under Article 30
The human review path behind automated credit and insurance decisions
The clock
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Desk 04AI Act
The market surveillance authority
Under Article 74(6), for banks and insurers regulated under EU financial services law this is your financial supervisor again, holding a second mandate.
High-risk AI under Regulation (EU) 2024/1689. Annex III point 5(b) names creditworthiness assessment and credit scoring of natural persons; point 5(c) names risk assessment and pricing in life and health insurance. Under the adopted Digital Omnibus, these duties apply from 2 December 2027.
What they can ask for
The technical file, on request under Article 74
Data governance and training data documentation
Automatically generated logs and human oversight records
The conformity assessment behind the CE marking
The clock
2 Dec 2027
Annex III obligations apply
15 days
serious incident report under Article 73, from awareness
Every desk reads from the same record
Each desk asks a different question on a different legal basis, but the evidence behind the answers overlaps almost entirely: the AI inventory, validation artefacts, oversight logs, third-party records, and incident history. Modulos keeps that evidence as one governance graph, where a control written once earns credit across every framework it satisfies. Supervisors do not coordinate their requests; the record is ready for whichever desk asks first.
01 DORA02 SSM03 GDPR04 AI Act→One evidence record
Dates that matter
2 Aug 2026
General application of the EU AI Act and the start of GPAI enforcement
2 Dec 2027
Annex III duties for credit scoring and life and health insurance pricing, per the adopted Digital Omnibus
The use-case docket
The sector's six recurring use cases, compressed to their EU AI Act gates. Duties stack, and a fraud model with no AI Act gate still answers to desks one and three.
Manipulative nudging in retail finance
Article 5(1)(a) and 5(1)(b) prohibit techniques that materially distort behaviour or exploit vulnerability.
Prohibited (Art. 5)
Retail credit scoring for natural persons
Named high risk in Annex III point 5(b).
High-risk (Annex III)
Life and health insurance pricing
Named high risk in Annex III point 5(c).
High-risk (Annex III)
Fraud detection and transaction monitoring
Carved out of the 5(b) credit clause. GDPR Article 22 applies in full.
No AI Act gate
Generative AI customer service
Article 50: customers must be told they are interacting with AI.
Transparency (Art. 50)
Internal analytics and reporting
No gate when outputs do not drive customer decisions. DORA still applies.
No AI Act gate
Related regulations
Go deeper on the regimes that apply to this sector:
Are credit scoring models really high risk under the EU AI Act?
Yes. Annex III Part 5(b) explicitly classifies AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score as high risk. The only carve-out is AI systems used for the purpose of detecting financial fraud. High-risk classification triggers conformity assessment, technical documentation, data governance, human oversight, logging, and post-market monitoring.
How does the EU AI Act interact with DORA?
DORA is lex specialis for ICT risk management in financial services, so its incident reporting and third-party register rules take precedence on those topics. The AI Act conformity assessment, data governance, and fundamental rights impact assessment obligations still apply to high-risk AI systems. Most firms run a combined programme to avoid duplicate control documentation.
Do we need ISO/IEC 42001 certification?
Not yet legally required, but increasingly expected. Supervisors across the EU and Middle East reference ISO/IEC 42001 as the governance baseline, and certification is becoming a commercial expectation in RFPs for regulated AI vendors. For financial firms that already run ISO/IEC 27001, adding 42001 is typically a six to nine month effort on top of existing controls.
How should we treat third-party LLMs and cloud-hosted AI?
DORA designates critical ICT third-party service providers on a service-based test under Article 31 and the related Delegated Regulation. Cloud platforms hosting AI services for financial entities qualify where they meet the criticality criteria, and fall under direct oversight by a Lead Overseer from one of the ESAs. Include them in the ICT third-party register, document exit strategies, run concentration risk analysis, and cover them in resilience testing where material.
What does "personal board accountability" mean in practice?
Article 5 of DORA places ultimate responsibility for ICT risk management on the management body. Combined with SMCR in the UK and Article 20 of NIS2 for cybersecurity, this means board members can face personal fines, suspension from managerial functions, and in some jurisdictions criminal liability for governance failures linked to AI or ICT incidents.
How does Modulos help with EU AI Act readiness?
Modulos gives you a structured backbone: a live AI inventory with risk classification, traceable technical documentation, conformity assessment workflows, human oversight logs, post-market monitoring, and a fundamental rights impact assessment template aligned to Commission guidance. All of it shares evidence with your existing model risk, DORA, and ISO 27001 programmes so you do the work once.
See the governance graph on one of your models
A demo walks through the four desks with a credit or insurance use case. The quiz classifies your role and risk exposure in about three minutes.