Supporting AI in Finance: Compliance, Implementation, and the Gaps Nobody Tells You About

calendar_today
person Manish Thakor
schedule 7 Min Read
label Automation Implementation
Supporting AI in Finance Compliance, Implementation, and the Gaps Nobody Tells You About

Blog Summary

Financial services has the highest density of named high-risk AI use cases under the EU AI Act, and existing model-risk rules already apply to AI. The compliance load is real, layered, and moving.

This guide walks the gaps nobody warns you about: explainability, the model inventory, audit-grade documentation, and logged human oversight. Each is a place a system that passed the demo fails the examination.

Most finance AI guides hand you a checklist. The checklist is not where projects fail. They fail in the gap between what a vendor demonstrates and what an examiner later requires.

This piece is organised around those gaps. Each one surfaces after the contract is signed, when a system that sailed through the demo cannot survive an examination.

The regulatory floor most teams underestimate

AI in finance gets no compliance pass. Existing model-risk rules already apply to it, and the EU AI Act layers fresh obligations on top of them rather than replacing anything. The result is a stack of overlapping regimes, each with its own evidentiary standard, all applying to the same model at the same time.

RegimeWhat it requires of AIWhere teams get caught
SR 11-7 (Fed and OCC)Model inventory, validation, monitoring, outcome analysisTreating it as credit-only; leaving bought AI tools off the inventory
EU AI Act (from Aug 2026)Conformity assessment, technical docs, logged human oversight for high-risk usesAssuming it is a lighter model-risk regime; it is additive
DORA and NYDFS Part 500Operational resilience and security controls for systems and vendorsVendor architecture that cannot evidence either on request


One moving part is worth flagging now. High-risk obligations are set to apply from
2 August 2026, though a Digital Omnibus deferral to December 2027 has provisional political agreement and may shift the date. Until that amendment is formally adopted, August 2026 is the date to plan against, not the one to bet against. Banking on a delay that has not become law is exactly the kind of risk a compliance function exists to avoid.

By The Numbers

Finance carries a heavier, and more time-sensitive, AI compliance load than any other sector.

Aug 2026
EU AI Act high-risk obligations are set to apply, covering credit scoring and insurance pricing. A deferral to Dec 2027 is proposed but not yet law.
€35M / 7%
the upper tier of penalties under the AI Act, against global annual turnover (lower tiers apply to most high-risk breaches).
67% vs 33%
vendor-built AI succeeds about twice as often as internal builds, a warning for finance’s proprietary-build habit.


What makes finance distinct is density. Of every sector the AI Act touches, financial services has the most named high-risk uses, credit scoring and insurance pricing among them, with fraud detection one of the few carve-outs. So for most of what a bank or insurer actually does with AI, the high-risk obligations are the default rather than the edge case.

The explainability that falls apart at the adverse-action notice

Vendors say the model is explainable. A regulator asks you to justify one declined application to one named customer. Those are not the same standard, and the difference is where audits go sideways.

Picture a declined mortgage. The applicant is entitled to a specific reason. A chart showing that income and credit history are globally important features does not answer why this person, with these numbers, was declined. That is the gap between model-level explainability and decision-level explainability, and only the second one satisfies an examiner or a court.

A global feature-importance chart does not explain a single decision. Tools like SHAP and LIME help, but they carry known limits in precision and stability, and they do not by themselves produce a defensible adverse-action explanation. Treat explainability as a per-decision obligation, not a property the model either has or lacks.

The model inventory nobody owns

Examiners increasingly want a complete AI model inventory on request. The gap is that bought tools, the general assistants and copilots scattered across teams, quietly fall outside it. An incomplete inventory is itself a finding, before anyone looks at a single model.

The risk is rarely the model the bank built on purpose. It is the copilot an underwriting team adopted informally, or the assistant a call centre uses to draft customer responses. Each one may be touching a regulated decision, and none of them appears on the official list. When an examiner asks for the inventory and finds the omissions, the conversation stops being about model quality and starts being about governance maturity.

Every model that touches a regulated decision belongs on the list, third-party ones included. If you cannot name them, you cannot govern them, and an examiner will assume the latter follows from the former.

Vendor documentation that is not audit-grade

A security questionnaire is not model documentation. The gap shows the moment a vendor cannot produce what your model-risk program actually consumes.

What vendors usually hand overWhat SR 11-7 and the AI Act expect
A security and SOC 2 questionnaireConceptual-soundness documentation for the model
Uptime and SLA commitmentsValidation evidence and outcome back-testing
A short model cardLogged, exportable human-oversight records


The items on the left are not worthless. They answer a different question, one about software risk rather than model risk. SR 11-7 and the AI Act both expect the right column, and a vendor who cannot supply it has effectively handed you their compliance gap to carry. The time to discover that is before signing, not during an examination.

Human oversight that is documented, not assumed

Everyone agrees a human is in the loop. The gap is whether that oversight is logged, structured, and meaningful. The AI Act expects recorded human oversight, with automated logs retained, not a person who could in theory intervene if they happened to be watching.

Meaningful oversight has teeth. The reviewer can see why the model reached its output, has the authority and the time to overrule it, and leaves a record when they do. A reviewer who rubber-stamps a queue of model decisions under time pressure is oversight on paper and nothing in practice, which is exactly the distinction an examiner is trained to probe.

Implementation in finance therefore front-loads governance and documentation in a way other sectors can defer. Our broader treatment of AI ethics consulting covers the principles. In finance, those principles harden into examinable controls with retention requirements attached.

Watch Out

Be wary of “compliance-ready” as a marketing phrase. Compliance-ready in a brochure is not the same as auditable inside your regime, under your examiners.

Demand model documentation at SR 11-7 grade, plus logged human oversight. If a vendor answers with a security checklist, the gap is theirs and the liability becomes yours.

Close the gaps before an examination opens one

Four questions, asked before you sign, close most of the distance.

  • Can you give us model documentation sufficient for our SR 11-7 program, rather than a security questionnaire?
  • Where is human oversight logged, and can we export those records for an examiner?
  • Which of our use cases do you classify as high-risk under the EU AI Act, and on what basis?
  • What is in, and deliberately out of, the model inventory you hand us at go-live?

The same buyer discipline we set out for leading AI implementation firms applies here with extra weight. In finance, the system that cannot be audited is, in practice, the system that cannot ship. The compliance work is not a tax on the implementation. In this sector, it is most of the implementation.