Your AI systems are high-risk.

Are you ready?

Banks and financial institutions using AI for credit scoring, fraud detection, or underwriting are squarely within the EU AI Act's high-risk category. Obligations are in effect and the documentation window is closing.

The AI Act at a Glance

The EU AI Act classifies AI systems into four risk tiers. Most AI used in financial services falls into the high-risk category triggering a full suite of compliance obligations.

Prohibited

Prohibited AI tools: Social Scoring Systems, Social Profiling Engines, Subliminal Manipulation Software, Vulnerability Exploitation Systems, Sensitive Attribute Biometric Classifiers, Workplace Emotion Recognition Systems, Educational Emotion Recognition Systems, Untargeted Facial Recognition Database Builders, Predictive Policing Systems, Real-Time Remote Biometric Identification Systems.

High-risk

High-Risk AI tools: Critical Infrastructure Safety Systems, Educational Assessment Systems, Recruitment Screening Tools, CV Filtering Systems, Employee Monitoring Systems, Credit Scoring Systems, Insurance Risk Assessment Systems, Public Benefits Eligibility Systems, Evidence Assessment Systems, AML system, Fraud Detection

Limited risk

Limited-Risk AI tools: Chatbots, Virtual Assistants, Generative AI Text Systems, AI Image Generators

Minimal risk

Minimal-Risk AI tools: Spam Filters, Movie Recommendation Systems, Inventory Management Tools, Customer Analytics Tools, Predictive Maintenance Systems, Smart Search Systems, AI Productivity Assistants

A structured five-step process

We guide financial institutions through a proven end-to-end compliance programme, co-designed with PwC's regulatory specialists. Typically completed within 10–12 weeks.

Discover - Build your AI inventory

Identify and document all AI systems used across the organisation. Capture key information such as the system purpose, business owner, vendor, data sources, and potential impact on customers and operations.

Classify - Determine the AI risk level

Assess each AI system against the EU AI Act risk categories to determine whether it is prohibited, high-risk, limited-risk, or minimal-risk. Consider the specific use case and its impact on individuals and business processes.

Determine Role - Identify your responsibilities

Establish whether your organisation acts as a provider, deployer, importer, or distributor for each AI system. Understanding your role is essential for determining the compliance obligations that apply.

Govern & Implement - Establish compliance measures

For high-risk AI systems, perform a Fundamental Rights Impact Assessment (FRIA) and implement appropriate human oversight. Define internal policies, transparency measures, accountability structures, and vendor governance controls to ensure compliant use of AI.

Monitor - Maintain ongoing compliance

Continuously monitor AI systems for performance, bias, drift, incidents, and regulatory changes. Review and update assessments, controls, and governance arrangements whenever systems, data, or use cases change.

Get Started Today and Book a Demo with Samuel

Get Started Today and Book a Demo with Samuel

Book your personalized demo with Samuel and discover how AI-enhanced GRC can accelerate your risk and compliance outcomes.

Book your personalized demo with Samuel and discover how AI-enhanced GRC can accelerate your risk and compliance outcomes.

Samuel Mihalcik