We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
A credit model in a bank meets the EU AI Act, DORA, NIS2, the GDPR, and model-risk supervision at once, on different clocks, with the duties landing personally on named executives. One system, six regulators. We map it at the level of the obligation, so one body of evidence holds across all of them.
Financial services sits at the busiest regulatory crossing. These are the regimes an AI credit, pricing, or trading system meets together.
Credit scoring and insurance pricing are high-risk uses, carrying the full obligation set.
ICT risk, third-party oversight, and resilience testing, owned by the management body.
Security risk-management and 24-hour incident reporting, with board-level liability.
The validation, documentation, and monitoring discipline supervisors now expect AI to meet.
Controls, testing, and kill-switch governance for algorithmic and high-frequency trading.
Article 22 rights and disparate-impact testing wherever a model decides about a person.
DORA Article 5 makes the management body own the ICT risk framework; NIS2 Article 20 holds it personally accountable for cyber measures; and the UK Senior Managers & Certification Regime already attaches individual accountability to named executives. AI governance here is not a matter a board can leave to a function.
Capture each obligation once and satisfy the AI Act, DORA, NIS2, and the GDPR from a single, cited record.
Regulatory correspondence and posture surfaced so accountable executives can see their exposure clearly.
The SS1/23 and SR 11-7 practices your validators already run, extended to AI systems with the same rigour.