AI Act-audit
for banks and insurers
Which systems in your environment fall within the scope of the EU AI Act, and in which category.
In financial services, the line between high-risk and ordinary risk management often runs through the same system. Creditworthiness assessment of natural persons falls within Annex III. So does risk assessment and pricing in life and health insurance. Fraud detection and anti-money-laundering checks fall outside that category, until the same model is also used to support decisions about individual customers.
That is where the practical difficulty lies. Most institutions run a single scoring environment that serves several purposes. The classification does not follow from the model but from how it is used.
Credit assessment
Which systems contribute to decisions on approval, limit or price for individual customers. Who in your chain is the provider and who is the deployer, including where scoring software is bought in. What documentation you would need to produce in an inspection, and what you have today.
AML en KYC
Where transaction monitoring ends and customer assessment begins. Which existing obligations under financial regulation already cover what the EU AI Act asks for, so that you do not document the same thing twice. Where the two frameworks diverge.
underwriting risk
Which pricing and underwriting systems fall within Annex III, and which sit outside the life and health classes.
How far a claims decision can be automated before the rules on solely automated decision-making apply, and what you must tell the policyholder.
What you receive
An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.
We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.
After the audit,
Automation
The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us..
If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.
That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.