Financial sector · high-risk · 2 December 2027

AI Act readiness for the financial sector: credit and insurance demonstrably in order

Credit scoring and risk-based insurance pricing fall under Annex III as high-risk AI. Those obligations have moved to 2 December 2027 through the political agreement. That is no reason to wait: the evidence dossier for banks, insurers and fintech is heavy, and runs together with DORA and supervision by DNB and AFM. We set up your AI inventory, classification, gap matrix, FRIA and DPIA and roadmap so you get ahead rather than catch up.

Finance readiness

Readiness Sprint in a few weeks

From model in production to a demonstrable evidence dossier

AI inventory and classification of credit and insurance models

Gap matrix against Annex III and overlap with DORA

FRIA and DPIA for credit and insurance

Roadmap with owner and priority toward 2 December 2027

The runway to 2 December 2027 is shorter than it looks

For standalone high-risk AI under Annex III the application date has moved from 2 August 2026 to 2 December 2027 through the political agreement on the Digital Omnibus. That agreement is not yet applicable law: until publication in the Official Journal, the original text legally applies. For the financial sector, postponement is not rest. Credit scoring and insurance pricing require a full evidence dossier: inventory, risk management, data quality, human oversight, logging and a FRIA. You do not build that in a quarter. Use the runway to get ahead.

Why credit and insurance are high-risk

Annex III designates specific AI use cases in financial services as high-risk. We test your models against the core of that regime.

Credit scoring and creditworthiness

AI that assesses the creditworthiness of natural persons or determines a credit score falls under Annex III. That touches acceptance, limit setting and adjustment in retail and consumer credit.

Risk and pricing in insurance

AI for risk assessment and pricing in life and health insurance falls under the high-risk regime. Acceptance, premium setting and segmentation come into scope.

Full evidence dossier

High-risk means risk management, data quality and governance, technical documentation, logging, human oversight, accuracy and robustness, plus registration. Evidence, not only policy.

Provider versus deployer

Do you build models yourself, or deploy a vendor’s models. Your role determines which obligations rest on you and what you must arrange contractually with the vendor.

Status of the postponement: the move of standalone high-risk to 2 December 2027 follows from the political agreement on the Digital Omnibus, endorsed by the European Parliament but not yet formally adopted and published. Until publication in the Official Journal, the original AI Act text legally prevails. We plan on the runway and track the status for you.

Overlap with DORA and supervision by DNB and AFM

In the financial sector the AI Act does not stand alone. You already have a framework for risk, model governance and supervision. We connect to that rather than build a parallel stack.

DORA and ICT risk

The Digital Operational Resilience Act sets requirements for ICT risk management, third-party risk and incident reporting. AI models and their vendors fit that register; we prevent double work by linking the touchpoints.

Model risk management

Validation, monitoring and governance of models are familiar from prudential supervision. The high-risk requirements of the AI Act connect to that: data quality, accuracy, robustness and human oversight.

Supervision by DNB and AFM

Expectations around explainability, duty of care and non-discrimination in credit and insurance bear directly on the AI Act. We translate that into evidence a supervisor can follow.

FRIA for credit and insurance

The fundamental rights impact assessment under Article 27 applies among others to providers deploying high-risk AI for creditworthiness and for risk assessment in life and health insurance. We draft it together with your DPIA.

When this readiness fits

This approach is for banks, insurers and fintech that deploy AI in credit or insurance and want it demonstrably in order toward 2 December 2027.

1

You use AI in credit or acceptance

Credit scoring, acceptance models or limit setting where it is unclear whether the evidence dossier toward Annex III is complete.

2

You use AI in insurance pricing

Risk assessment, premium setting or segmentation in life or health insurance, without classification and evidence being recorded.

3

You already have DORA and model governance

You want the AI Act to connect to your existing risk and supervision frameworks, not a separate compliance stack alongside.

What the readiness delivers

AI inventory of credit and insurance models with owner, purpose and vendor

Classification per model: high-risk, transparency or out of scope

Role determination provider versus deployer per model and what belongs with the vendor contractually

Gap matrix against the high-risk requirements of Annex III with status score

Linking of the touchpoints with DORA, model risk and supervision by DNB and AFM

FRIA for credit and insurance, together with the accompanying DPIA

Roadmap with owner, priority and milestones toward 2 December 2027

Note on the status of the postponement and what it means for your planning

Approach of the Readiness Sprint

1

Scope and intake

We define which credit and insurance models, vendors and processes fall within the readiness and connect to your existing risk and supervision frameworks.

2

Inventory and classification

We map your AI models and classify them against Annex III: high-risk, transparency or out of scope, including provider or deployer role.

3

Gap matrix

We test each high-risk model against the requirements for risk management, data, documentation, logging and human oversight, and link the touchpoints with DORA.

4

FRIA and DPIA

We draft the fundamental rights impact assessment for credit and insurance, together with the DPIA, so privacy and fundamental rights sit in one dossier.

5

Roadmap

You get a concrete roadmap with owners, priority and milestones to be demonstrably in control before 2 December 2027.

Who this works for

Risk and model validation

Teams that validate credit scoring and pricing models and want to link the high-risk requirements to existing model governance.

Compliance and legal

Teams that want to translate the AI Act, DORA and supervision by DNB and AFM into a coherent evidence dossier.

Data science and engineering

Teams that must technically secure data quality, logging, accuracy and human oversight in credit and insurance models.

Board and management

Teams that want to be demonstrably in control of high-risk AI in credit and insurance toward 2 December 2027.

Afterwards you know

Which models are high-risk under Annex III

Whether you are provider or deployer per model

Which evidence is still missing for the high-risk regime

Where the AI Act, DORA and supervision overlap

Which actions must be done before 2 December 2027

Frequently asked questions

Do credit scoring and insurance pricing really fall under high-risk?

Yes. Annex III designates AI for assessing the creditworthiness and credit scoring of natural persons as high-risk, and additionally AI for risk assessment and pricing in life and health insurance. That triggers the heavy obligations around risk management, data, documentation, logging and human oversight.

When do those obligations apply?

For standalone high-risk AI under Annex III the application date has moved to 2 December 2027 through the political agreement on the Digital Omnibus. That agreement is not yet formally adopted and published: until publication in the Official Journal, the original text legally prevails. We plan on that runway and track the status.

How does this relate to DORA and supervision by DNB and AFM?

The AI Act is not separate from your existing frameworks. DORA sets requirements for ICT risk and third-party risk, and model risk management is familiar from prudential supervision. We link the high-risk requirements of the AI Act to those frameworks so you have a coherent evidence dossier rather than a parallel stack.

What is the FRIA and when do we need it?

The fundamental rights impact assessment under Article 27 applies among others to providers deploying high-risk AI for creditworthiness and for risk assessment and pricing in life and health insurance. We draft it together with your DPIA, so fundamental rights and privacy sit in one dossier.

Is this legal advice?

No. This is a practical readiness. We set up inventory, classification, gap matrix, FRIA, DPIA and roadmap so risk, compliance, data science and the board can act in a focused way. For formal legal advice, involve legal counsel.

How much internal time does this require?

Usually a few interviews with risk, model validation, data science and compliance, plus an overview of your credit and insurance models and one review moment. We do most of the drafting.

Get ahead of 2 December 2027 in credit and insurance.

Start with the finance readiness. We set up inventory, classification, gap matrix, FRIA, DPIA and roadmap, connected to DORA and supervision by DNB and AFM.

Rivium Westlaan 46, Capelle aan den IJsselCoC 90283597