Your AI systems are high-risk.
Are you ready?
Banks and financial institutions using AI for credit scoring, fraud detection, or underwriting are squarely within the EU AI Act's high-risk category. Obligations are in effect and the documentation window is closing.
The AI Act at a Glance
The EU AI Act classifies AI systems into four risk tiers. Most AI used in financial services falls into the high-risk category triggering a full suite of compliance obligations.
Prohibited
Prohibited AI tools: Social Scoring Systems, Social Profiling Engines, Subliminal Manipulation Software, Vulnerability Exploitation Systems, Sensitive Attribute Biometric Classifiers, Workplace Emotion Recognition Systems, Educational Emotion Recognition Systems, Untargeted Facial Recognition Database Builders, Predictive Policing Systems, Real-Time Remote Biometric Identification Systems.
High-risk
High-Risk AI tools: Critical Infrastructure Safety Systems, Educational Assessment Systems, Recruitment Screening Tools, CV Filtering Systems, Employee Monitoring Systems, Credit Scoring Systems, Insurance Risk Assessment Systems, Public Benefits Eligibility Systems, Evidence Assessment Systems, AML system, Fraud Detection
Limited risk
Limited-Risk AI tools: Chatbots, Virtual Assistants, Generative AI Text Systems, AI Image Generators
Minimal risk
Minimal-Risk AI tools: Spam Filters, Movie Recommendation Systems, Inventory Management Tools, Customer Analytics Tools, Predictive Maintenance Systems, Smart Search Systems, AI Productivity Assistants
A structured five-step process
We guide financial institutions through a proven end-to-end compliance programme, co-designed with PwC's regulatory specialists. Typically completed within 10–12 weeks.

Discover - Build your AI inventory
Identify and document all AI systems used across the organisation. Capture key information such as the system purpose, business owner, vendor, data sources, and potential impact on customers and operations.

Classify - Determine the AI risk level
Assess each AI system against the EU AI Act risk categories to determine whether it is prohibited, high-risk, limited-risk, or minimal-risk. Consider the specific use case and its impact on individuals and business processes.

Determine Role - Identify your responsibilities
Establish whether your organisation acts as a provider, deployer, importer, or distributor for each AI system. Understanding your role is essential for determining the compliance obligations that apply.

Govern & Implement - Establish compliance measures
For high-risk AI systems, perform a Fundamental Rights Impact Assessment (FRIA) and implement appropriate human oversight. Define internal policies, transparency measures, accountability structures, and vendor governance controls to ensure compliant use of AI.

Monitor - Maintain ongoing compliance
Continuously monitor AI systems for performance, bias, drift, incidents, and regulatory changes. Review and update assessments, controls, and governance arrangements whenever systems, data, or use cases change.
