Blog Summary
Financial services has the highest density of named high-risk AI use cases under the EU AI Act, and existing model-risk rules already apply to AI. The compliance load is real, layered, and moving.
This guide walks the gaps nobody warns you about: explainability, the model inventory, audit-grade documentation, and logged human oversight. Each is a place a system that passed the demo fails the examination.
Most finance AI guides hand you a checklist. The checklist is not where projects fail. They fail in the gap between what a vendor demonstrates and what an examiner later requires.
This piece is organised around those gaps. Each one surfaces after the contract is signed, when a system that sailed through the demo cannot survive an examination.
The regulatory floor most teams underestimate
AI in finance gets no compliance pass. Existing model-risk rules already apply to it, and the EU AI Act layers fresh obligations on top of them rather than replacing anything. The result is a stack of overlapping regimes, each with its own evidentiary standard, all applying to the same model at the same time.
| Regime | What it requires of AI | Where teams get caught |
| SR 11-7 (Fed and OCC) | Model inventory, validation, monitoring, outcome analysis | Treating it as credit-only; leaving bought AI tools off the inventory |
| EU AI Act (from Aug 2026) | Conformity assessment, technical docs, logged human oversight for high-risk uses | Assuming it is a lighter model-risk regime; it is additive |
| DORA and NYDFS Part 500 | Operational resilience and security controls for systems and vendors | Vendor architecture that cannot evidence either on request |
One moving part is worth flagging now. High-risk obligations are set to apply from
2 August 2026, though a Digital Omnibus deferral to December 2027 has provisional political agreement and may shift the date. Until that amendment is formally adopted, August 2026 is the date to plan against, not the one to bet against. Banking on a delay that has not become law is exactly the kind of risk a compliance function exists to avoid.
By The Numbers
Finance carries a heavier, and more time-sensitive, AI compliance load than any other sector.
What makes finance distinct is density. Of every sector the AI Act touches, financial services has the most named high-risk uses, credit scoring and insurance pricing among them, with fraud detection one of the few carve-outs. So for most of what a bank or insurer actually does with AI, the high-risk obligations are the default rather than the edge case.
The explainability that falls apart at the adverse-action notice
Vendors say the model is explainable. A regulator asks you to justify one declined application to one named customer. Those are not the same standard, and the difference is where audits go sideways.
Picture a declined mortgage. The applicant is entitled to a specific reason. A chart showing that income and credit history are globally important features does not answer why this person, with these numbers, was declined. That is the gap between model-level explainability and decision-level explainability, and only the second one satisfies an examiner or a court.
A global feature-importance chart does not explain a single decision. Tools like SHAP and LIME help, but they carry known limits in precision and stability, and they do not by themselves produce a defensible adverse-action explanation. Treat explainability as a per-decision obligation, not a property the model either has or lacks.
The model inventory nobody owns
Examiners increasingly want a complete AI model inventory on request. The gap is that bought tools, the general assistants and copilots scattered across teams, quietly fall outside it. An incomplete inventory is itself a finding, before anyone looks at a single model.
The risk is rarely the model the bank built on purpose. It is the copilot an underwriting team adopted informally, or the assistant a call centre uses to draft customer responses. Each one may be touching a regulated decision, and none of them appears on the official list. When an examiner asks for the inventory and finds the omissions, the conversation stops being about model quality and starts being about governance maturity.
Every model that touches a regulated decision belongs on the list, third-party ones included. If you cannot name them, you cannot govern them, and an examiner will assume the latter follows from the former.
Vendor documentation that is not audit-grade
A security questionnaire is not model documentation. The gap shows the moment a vendor cannot produce what your model-risk program actually consumes.
| What vendors usually hand over | What SR 11-7 and the AI Act expect |
| A security and SOC 2 questionnaire | Conceptual-soundness documentation for the model |
| Uptime and SLA commitments | Validation evidence and outcome back-testing |
| A short model card | Logged, exportable human-oversight records |
The items on the left are not worthless. They answer a different question, one about software risk rather than model risk. SR 11-7 and the AI Act both expect the right column, and a vendor who cannot supply it has effectively handed you their compliance gap to carry. The time to discover that is before signing, not during an examination.
Human oversight that is documented, not assumed
Everyone agrees a human is in the loop. The gap is whether that oversight is logged, structured, and meaningful. The AI Act expects recorded human oversight, with automated logs retained, not a person who could in theory intervene if they happened to be watching.
Meaningful oversight has teeth. The reviewer can see why the model reached its output, has the authority and the time to overrule it, and leaves a record when they do. A reviewer who rubber-stamps a queue of model decisions under time pressure is oversight on paper and nothing in practice, which is exactly the distinction an examiner is trained to probe.
Implementation in finance therefore front-loads governance and documentation in a way other sectors can defer. Our broader treatment of AI ethics consulting covers the principles. In finance, those principles harden into examinable controls with retention requirements attached.
Watch Out
Be wary of “compliance-ready” as a marketing phrase. Compliance-ready in a brochure is not the same as auditable inside your regime, under your examiners.
Demand model documentation at SR 11-7 grade, plus logged human oversight. If a vendor answers with a security checklist, the gap is theirs and the liability becomes yours.
Close the gaps before an examination opens one
Four questions, asked before you sign, close most of the distance.
- Can you give us model documentation sufficient for our SR 11-7 program, rather than a security questionnaire?
- Where is human oversight logged, and can we export those records for an examiner?
- Which of our use cases do you classify as high-risk under the EU AI Act, and on what basis?
- What is in, and deliberately out of, the model inventory you hand us at go-live?
The same buyer discipline we set out for leading AI implementation firms applies here with extra weight. In finance, the system that cannot be audited is, in practice, the system that cannot ship. The compliance work is not a tax on the implementation. In this sector, it is most of the implementation.