Skip to Content
architectural photography of brown building
green plant in clear glass cup
two people sitting during day
10 euro on brown wooden table
person sitting in a chair in front of a man

AI Act-audit 

for banks and insurers

Which systems in your environment fall within the scope of the EU AI Act, and in which category.

In financial services, the line between high-risk and ordinary risk management often runs through the same system. Creditworthiness assessment of natural persons falls within Annex III. So does risk assessment and pricing in life and health insurance. Fraud detection and anti-money-laundering checks fall outside that category, until the same model is also used to support decisions about individual customers.

That is where the practical difficulty lies. Most institutions run a single scoring environment that serves several purposes. The classification does not follow from the model but from how it is used.



1

Credit assessment

Which systems contribute to decisions on approval, limit or price for individual customers. Who in your chain is the provider and who is the deployer, including where scoring software is bought in. What documentation you would need to produce in an inspection, and what you have today.

2

AML en KYC

Where transaction monitoring ends and customer assessment begins. Which existing obligations under financial regulation already cover what the EU AI Act asks for, so that you do not document the same thing twice. Where the two frameworks diverge.

3

underwriting risk

Which pricing and underwriting systems fall within Annex III, and which sit outside the life and health classes.

How far a claims decision can be automated before the rules on solely automated decision-making apply, and what you must tell the policyholder.

What you receive


An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.

We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.

After the audit,

Automation


The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us..

If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.

That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.


The development timeline →