Sector · Financial services

The one sector the Act names twice.

Creditworthiness and life-and-health insurance pricing are high-risk by listing, not by assessment. And financial institutions are the only organisations the Act gives two explicit routes to fold AI duties into governance they already run — Art. 17(4) for providers, Art. 26(5) for deployers. Both are narrower than they sound.

No card · EU-hosted · 5 minutes to a first classification
Veritome risk register — portfolio risk KPIs and a severity-by-likelihood heat-map for Article 9 risk management
The reality

What financial firms get wrong.

What we hear

“Our model risk framework already covers this.”

What the product does

It covers a great deal of the evidence and none of the classification. Art. 17(4) and Art. 26(5) let you fold specific aspects into internal governance — they do not remove the duty to say which systems are in scope and why.

What we hear

“We assumed the fraud carve-out covered the scoring model too.”

What the product does

The Annex III point 5(b) carve-out attaches to purpose. A model used for fraud detection and separately for scoring is not carved out in the second use.

What we hear

“We did the DPIA and stopped.”

What the product does

For creditworthiness and insurance pricing deployers, Art. 27 adds a fundamental-rights assessment. It may build on the DPIA under Art. 27(4) — but it asks questions the DPIA was never written to answer.

What you get

The routes the Act grants, with their conditions.

01

Art. 17(4), stated precisely

Fold the Art. 17(1) aspects into internal governance under Union financial-services law — while accounting separately for (g), (h) and (i), which the provision does not carry across.

02

Art. 26(5) for deployer monitoring

Post-deployment monitoring folded into the same internal governance arrangements, where they genuinely observe the system in operation.

03

Annex III scoping that holds

Point 5(b) creditworthiness and 5(c) insurance pricing, with the fraud-detection carve-out applied by purpose rather than by model.

04

Art. 27 pre-filled from the DPIA

The fundamental-rights assessment builds on the data-protection work, as Art. 27(4) permits — then asks what the DPIA did not.

05

You declare the reliance

A statutory route prefills a form and records that you relied on it. It never ticks the obligation, because whether your governance reaches far enough is your judgement, not the software's.

06

GDPR on the same register

Art. 22 automated decision-making sits next to the EU AI Act duties rather than in a separate programme.

In practice

Three financial deployments.

Use case 01

A lender running a bought credit-scoring model.

  • Annex III 5(b): high-risk by listing, deployer duties under Art. 26.
  • Art. 27 fundamental-rights assessment applies, pre-filled from the DPIA.
  • Art. 26(5) folds monitoring into existing internal governance, declared not assumed.
  • GDPR Art. 22 sits on the same register.
Veritome obligations register — EU AI Act and GDPR duties per system and for the organisation, with owners, dates and status
Use case 02

An insurer pricing life cover with a model it built.

  • Annex III 5(c) and the provider set — Art. 9 through Art. 49 registration.
  • Art. 17(4) folds most Art. 17(1) aspects into internal governance.
  • (g), (h) and (i) accounted for separately, because the provision stops short.
  • The reliance is recorded with the instrument it rests on named.
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
Use case 03

A bank running fraud detection and scoring on related models.

  • The fraud model sits inside the Annex III 5(b) carve-out.
  • The scoring model does not, even where the architecture is shared.
  • Classification asks about purpose, so the two separate cleanly.
  • One register carries both, with different duty sets.
Veritome systems portfolio — every AI system with its role, risk tier and journey position
Also included

What sits beside the sector duties.

Straight answers

Straight answers for financial services.

Which financial use cases are high-risk?

Annex III point 5(b) names AI used to evaluate creditworthiness or establish a credit score, other than for detecting financial fraud. Point 5(c) names risk assessment and pricing in life and health insurance. Those are high-risk by listing, which means the classification question is not whether but how you will evidence the duties.

We already run internal governance under CRD or Solvency II. Does that count?

In two specific places, yes. Article 17(4) lets a provider that is a financial institution subject to internal governance requirements under Union financial-services law include most of the Article 17(1) quality-management aspects within those arrangements — though (g), (h) and (i) must still be accounted for separately. Article 26(5) does the equivalent for deployer monitoring. Both are routes the Act itself grants; neither is a general exemption.

Does a fundamental rights impact assessment apply to us?

Article 27 binds deployers of the Annex III creditworthiness and insurance-pricing systems, alongside public bodies. Where it applies it can build on a data protection impact assessment you have already carried out — Article 27(4) permits that explicitly, and Veritome pre-fills from the DPIA rather than asking the same questions twice.

Is fraud detection caught?

Annex III point 5(b) carves out AI used for the purpose of detecting financial fraud. That carve-out is narrow and attaches to purpose, so a model used for fraud detection and separately for scoring is not covered by it in the second use. The classification asks about purpose rather than about the model.

How does this sit with DORA and existing model risk management?

Beside them. Operational resilience and model risk management are their own regimes with their own evidence, and much of that evidence is reusable as input. What the EU AI Act adds is a classification, an obligation set derived from it, and a record naming the article behind each item.