AI Act readiness for the financial sector: credit and insurance demonstrably in order
Credit scoring and risk-based insurance pricing fall under Annex III as high-risk AI. Those obligations have moved to 2 December 2027 through the political agreement. That is no reason to wait: the evidence dossier for banks, insurers and fintech is heavy, and runs together with DORA and supervision by DNB and AFM. We set up your AI inventory, classification, gap matrix, FRIA and DPIA and roadmap so you get ahead rather than catch up.
Finance readiness
Readiness Sprint in a few weeks
From model in production to a demonstrable evidence dossier
AI inventory and classification of credit and insurance models
Gap matrix against Annex III and overlap with DORA
FRIA and DPIA for credit and insurance
Roadmap with owner and priority toward 2 December 2027
The runway to 2 December 2027 is shorter than it looks
For standalone high-risk AI under Annex III the application date has moved from 2 August 2026 to 2 December 2027 through the political agreement on the Digital Omnibus. That agreement is not yet applicable law: until publication in the Official Journal, the original text legally applies. For the financial sector, postponement is not rest. Credit scoring and insurance pricing require a full evidence dossier: inventory, risk management, data quality, human oversight, logging and a FRIA. You do not build that in a quarter. Use the runway to get ahead.
Why credit and insurance are high-risk
Annex III designates specific AI use cases in financial services as high-risk. We test your models against the core of that regime.
Credit scoring and creditworthiness
AI that assesses the creditworthiness of natural persons or determines a credit score falls under Annex III. That touches acceptance, limit setting and adjustment in retail and consumer credit.
Risk and pricing in insurance
AI for risk assessment and pricing in life and health insurance falls under the high-risk regime. Acceptance, premium setting and segmentation come into scope.
Full evidence dossier
High-risk means risk management, data quality and governance, technical documentation, logging, human oversight, accuracy and robustness, plus registration. Evidence, not only policy.
Provider versus deployer
Do you build models yourself, or deploy a vendor’s models. Your role determines which obligations rest on you and what you must arrange contractually with the vendor.
Status of the postponement: the move of standalone high-risk to 2 December 2027 follows from the political agreement on the Digital Omnibus, endorsed by the European Parliament but not yet formally adopted and published. Until publication in the Official Journal, the original AI Act text legally prevails. We plan on the runway and track the status for you.
Overlap with DORA and supervision by DNB and AFM
In the financial sector the AI Act does not stand alone. You already have a framework for risk, model governance and supervision. We connect to that rather than build a parallel stack.
DORA and ICT risk
The Digital Operational Resilience Act sets requirements for ICT risk management, third-party risk and incident reporting. AI models and their vendors fit that register; we prevent double work by linking the touchpoints.
Model risk management
Validation, monitoring and governance of models are familiar from prudential supervision. The high-risk requirements of the AI Act connect to that: data quality, accuracy, robustness and human oversight.
Supervision by DNB and AFM
Expectations around explainability, duty of care and non-discrimination in credit and insurance bear directly on the AI Act. We translate that into evidence a supervisor can follow.
FRIA for credit and insurance
The fundamental rights impact assessment under Article 27 applies among others to providers deploying high-risk AI for creditworthiness and for risk assessment in life and health insurance. We draft it together with your DPIA.
When this readiness fits
This approach is for banks, insurers and fintech that deploy AI in credit or insurance and want it demonstrably in order toward 2 December 2027.
You use AI in credit or acceptance
Credit scoring, acceptance models or limit setting where it is unclear whether the evidence dossier toward Annex III is complete.
You use AI in insurance pricing
Risk assessment, premium setting or segmentation in life or health insurance, without classification and evidence being recorded.
You already have DORA and model governance
You want the AI Act to connect to your existing risk and supervision frameworks, not a separate compliance stack alongside.
What the readiness delivers
AI inventory of credit and insurance models with owner, purpose and vendor
Classification per model: high-risk, transparency or out of scope
Role determination provider versus deployer per model and what belongs with the vendor contractually
Gap matrix against the high-risk requirements of Annex III with status score
Linking of the touchpoints with DORA, model risk and supervision by DNB and AFM
FRIA for credit and insurance, together with the accompanying DPIA
Roadmap with owner, priority and milestones toward 2 December 2027
Note on the status of the postponement and what it means for your planning
Approach of the Readiness Sprint
Scope and intake
We define which credit and insurance models, vendors and processes fall within the readiness and connect to your existing risk and supervision frameworks.
Inventory and classification
We map your AI models and classify them against Annex III: high-risk, transparency or out of scope, including provider or deployer role.
Gap matrix
We test each high-risk model against the requirements for risk management, data, documentation, logging and human oversight, and link the touchpoints with DORA.
FRIA and DPIA
We draft the fundamental rights impact assessment for credit and insurance, together with the DPIA, so privacy and fundamental rights sit in one dossier.
Roadmap
You get a concrete roadmap with owners, priority and milestones to be demonstrably in control before 2 December 2027.
Who this works for
Risk and model validation
Teams that validate credit scoring and pricing models and want to link the high-risk requirements to existing model governance.
Compliance and legal
Teams that want to translate the AI Act, DORA and supervision by DNB and AFM into a coherent evidence dossier.
Data science and engineering
Teams that must technically secure data quality, logging, accuracy and human oversight in credit and insurance models.
Board and management
Teams that want to be demonstrably in control of high-risk AI in credit and insurance toward 2 December 2027.
Afterwards you know
Which models are high-risk under Annex III
Whether you are provider or deployer per model
Which evidence is still missing for the high-risk regime
Where the AI Act, DORA and supervision overlap
Which actions must be done before 2 December 2027
Logical next steps
AI Act readiness and gap analysis
For a broader view of AI systems, roles, risks and evidence in one roadmap.
View routeFRIA and DPIA for AI systems
For the fundamental rights impact assessment and privacy test as a separate, in-depth track.
View routeAI inventory setup
For a compact inventory of AI systems with owner, purpose and evidence status.
View routeAI literacy and legal depth
Readiness is execution. Two adjacent layers we handle via our sister platforms.
AI literacy per role via LearnWize
Article 4 applies since 2 February 2025 and remains in force. For risk, acceptance and data science, literacy is part of human oversight under the high-risk regime. LearnWize delivers the evidence per role.
Visit LearnWizeLegal explanation on the Responsible AI Platform
For neutral depth on Annex III, FRIA and the status of the Digital Omnibus we refer to the Responsible AI Platform.
Read on the Responsible AI PlatformFrequently asked questions
Do credit scoring and insurance pricing really fall under high-risk?
Yes. Annex III designates AI for assessing the creditworthiness and credit scoring of natural persons as high-risk, and additionally AI for risk assessment and pricing in life and health insurance. That triggers the heavy obligations around risk management, data, documentation, logging and human oversight.
When do those obligations apply?
For standalone high-risk AI under Annex III the application date has moved to 2 December 2027 through the political agreement on the Digital Omnibus. That agreement is not yet formally adopted and published: until publication in the Official Journal, the original text legally prevails. We plan on that runway and track the status.
How does this relate to DORA and supervision by DNB and AFM?
The AI Act is not separate from your existing frameworks. DORA sets requirements for ICT risk and third-party risk, and model risk management is familiar from prudential supervision. We link the high-risk requirements of the AI Act to those frameworks so you have a coherent evidence dossier rather than a parallel stack.
What is the FRIA and when do we need it?
The fundamental rights impact assessment under Article 27 applies among others to providers deploying high-risk AI for creditworthiness and for risk assessment and pricing in life and health insurance. We draft it together with your DPIA, so fundamental rights and privacy sit in one dossier.
Is this legal advice?
No. This is a practical readiness. We set up inventory, classification, gap matrix, FRIA, DPIA and roadmap so risk, compliance, data science and the board can act in a focused way. For formal legal advice, involve legal counsel.
How much internal time does this require?
Usually a few interviews with risk, model validation, data science and compliance, plus an overview of your credit and insurance models and one review moment. We do most of the drafting.
Get ahead of 2 December 2027 in credit and insurance.
Start with the finance readiness. We set up inventory, classification, gap matrix, FRIA, DPIA and roadmap, connected to DORA and supervision by DNB and AFM.