Compliance & Risk 11 min read Updated August 2026

AI Governance for Finance Teams — EU AI Act, Model Inventory and Risk Tiers

How finance teams build AI governance frameworks that satisfy the EU AI Act, OCC SR 11-7 model risk guidance, and board-level oversight requirements: AI model inventory, risk tier classification, model cards, EU AI Act Annex III compliance assessment, and vendor AI procurement due diligence.

Educational content, not professional advice — AI output and figures here can be wrong. Verify before you rely on it. Full disclaimer →

Why AI Governance Is Now a Finance Function

AI governance has moved from the IT department to the boardroom. The EU AI Act (effective August 2024, most provisions applying from August 2026) creates hard legal obligations for financial services firms using high-risk AI systems. The SEC's AI disclosure guidance, the OCC's model risk management guidance, the Basel Committee's principles on operational resilience, and DORA's provisions on ICT risk all touch AI. For finance teams, this means AI governance is not an optional best practice — it's a compliance requirement with material regulatory exposure.

The challenge is that most financial institutions deployed AI faster than they built governance frameworks. There are models running in credit scoring, fraud detection, AML, and financial planning with no formal model cards, no risk tier classification, no ongoing monitoring framework, and no board-level visibility. Building that governance infrastructure is the current state of play for compliance and risk teams across the industry. Claude can help structure and accelerate it.

Building an AI Model Inventory

The foundation of AI governance is a complete inventory of all AI models in production. Without it, you can't classify risk tiers, assign owners, or comply with disclosure requirements. The inventory should capture: model purpose, data inputs, decision scope, regulatory classification, owner, deployment date, last validation date, and performance monitoring status.

  • "Help me build an AI model inventory template for a regional bank. The bank has the following known AI systems: (1) a credit scoring model for consumer loans (vendor: FICO, custom overlay built internally), (2) a fraud detection model on debit card transactions (real-time, vendor: Featurespace), (3) an AML transaction monitoring system (vendor: Actimize), (4) a chatbot for retail customer service (vendor: Salesforce Einstein), (5) an internal FP&A tool that uses LLMs for variance analysis (built internally on Claude API). Create an inventory template with the fields required by the EU AI Act Article 61 (record-keeping for high-risk AI) and OCC SR 11-7 model risk management guidance. Flag which of these systems likely qualify as high-risk under the EU AI Act."
  • "Classify these AI systems by risk tier using the EU AI Act framework: (1) Credit scoring for mortgage applications, (2) Fraud alert generation (human reviews all alerts before action), (3) Automated wire transfer blocking for OFAC name matches, (4) LLM chatbot that answers customer questions about account balances, (5) Portfolio optimization model that generates recommended trades reviewed by a human portfolio manager. For each: state the EU AI Act risk tier (Unacceptable / High / Limited / Minimal), cite the relevant Annex III provision if high-risk, and list the compliance obligations that apply."

Model Cards for Financial AI Systems

Model cards (originated by Google Research, now a standard governance tool) document an AI model's intended use, performance metrics, limitations, and known risks in a standardized one-page format. Regulators increasingly expect model cards for high-risk AI systems. The EU AI Act's Article 13 (transparency obligations) and the UK FCA's AI transparency guidance both point in the same direction. Claude can draft model cards from technical model documentation or from stakeholder interviews.

  • "Write a model card for the following AI system: System Name: Consumer Credit Scoring Overlay Model. Purpose: Augments FICO score with 14 internal behavioral features (account tenure, payment history volatility, product mix, overdraft frequency) to improve approval rate precision for borderline applicants (FICO 620–680). Model type: Gradient Boosted Trees (XGBoost). Training data: 4 years of internal loan performance data, 1.2M accounts. Performance metrics: AUC 0.81, Gini 0.62, Default rate prediction error ±0.4% at 12 months. Known limitations: underperforms on thin-file applicants (fewer than 12 months of account history); not validated for applicants outside 18–75 age range. Bias testing: no statistically significant disparate impact found in testing across race, gender, or national origin proxies. Owner: Chief Credit Officer. Last validation: Q4 2025. Format as an EU AI Act-compliant model card."
  • "Write a model card for a Large Language Model deployed for internal financial analysis. System: Claude API (claude-sonnet-5) used by the FP&A team for budget variance commentary generation. Inputs: budget vs actual data pasted by users. Outputs: draft management commentary reviewed and edited by FP&A analysts before distribution. Risk tier: Limited (human review required before any output is used). Known limitations: may hallucinate specific figures if data is not pasted directly in the prompt; performance degrades on complex multi-entity consolidations. Bias: no known bias in financial commentary generation; however, outputs reflect the framing of the input data. Monitoring: outputs are spot-checked by FP&A Manager monthly. EU AI Act classification: Limited Risk — chatbot transparency disclosure required. Draft the model card."

EU AI Act Compliance for Financial Services

The EU AI Act creates a tiered obligations framework. For financial services, the most significant category is High-Risk AI Systems under Annex III, which includes AI used for: credit scoring, evaluation of natural persons for insurance, and AI used in critical infrastructure (which includes financial market infrastructure). High-risk systems require: conformity assessment, technical documentation, registration in the EU AI Act database, human oversight, accuracy and robustness standards, and data governance compliance.

  • "Produce a gap analysis for EU AI Act compliance for a bank's credit scoring system (high-risk, Annex III point 5). Map the following obligations to our current state: (1) Risk management system (Article 9) — we have SR 11-7 model validation but no specific AI risk management system. (2) Data governance (Article 10) — we have data lineage documentation but no AI-specific dataset documentation. (3) Technical documentation (Article 11) — we have model validation reports but no standardized technical documentation per Annex IV. (4) Transparency (Article 13) — we disclose to loan applicants that a credit scoring model is used but not its logic. (5) Human oversight (Article 14) — credit underwriters review model decisions for borderline cases. (6) Accuracy/Robustness (Article 15) — we track Gini and AUC quarterly. Produce a gap analysis table: Obligation | Current State | Gap | Priority | Remediation."
  • "Draft the AI system registration entry for the EU AI Act database for a high-risk credit scoring system. Required fields under Article 49: provider name, address, system name and version, purpose, input data description, output description, geographic scope, deployment date, conformity assessment procedure followed, contact information. Fill in each field for a regional bank's consumer mortgage credit scoring model."

Board-Level AI Risk Reporting

Boards and audit committees increasingly need to oversee AI risk as a distinct category — separate from general technology risk. The SEC's AI disclosure guidance, the UK FCA's supervisory expectations, and the EU AI Act's Article 26 obligations on deployers all point toward formal board-level AI governance. Claude can help structure the reporting format that bridges technical AI risk and board-level governance.

  • "Draft a quarterly AI Risk Report for the Board Risk Committee. The report should cover: (1) AI model inventory summary (12 models in production: 3 high-risk under EU AI Act, 8 limited-risk, 1 minimal-risk), (2) Model performance monitoring summary (all 3 high-risk models within performance thresholds; 1 fraud model showing 3% AUC degradation — monitoring triggered, retraining scheduled), (3) AI incidents in the quarter (0 model failures; 1 prompt injection attempt detected and blocked on customer chatbot), (4) Regulatory update (EU AI Act implementation — we are on track for August 2026 compliance for 2 of 3 high-risk models; the credit scoring model conformity assessment is 60% complete), (5) Top AI risks: hallucination risk in FP&A LLM tools, model drift risk in fraud detection. Format as a 1-page executive summary with a risk heat map."

AI Procurement Due Diligence

Under the EU AI Act, deployers (companies using AI systems built by third-party providers) retain compliance obligations for high-risk AI. This means vendor AI procurement now requires structured due diligence. Finance teams need to understand what obligations their AI vendors are meeting and what they're leaving to the deployer.

  • "Create an AI vendor due diligence questionnaire for a financial services firm procuring a high-risk AI system (credit scoring). The questionnaire should cover: (1) EU AI Act compliance status (conformity assessment, technical documentation, registration), (2) Model performance documentation (accuracy metrics, bias testing results, known limitations), (3) Data governance (training data sources, data quality, data rights), (4) Human oversight provisions (what override capabilities does the deployer have?), (5) Incident notification (SLAs for notifying deployer of material model issues), (6) Model update governance (how are changes managed, validated, and communicated?), (7) Data security (SOC 2 Type II, data processing agreement, data residency). Format as a 20-question questionnaire with rating scale (Fully Met / Partially Met / Not Met)."

Where to Start

For most finance teams, AI governance starts with inventory — you can't govern what you don't know you have. Start by prompting Claude to build your inventory template, then run a stakeholder survey across business lines to populate it. Once you have an inventory, the risk tier classification is the next step: identify your high-risk AI systems under EU AI Act Annex III and assess which ones need conformity assessments before August 2026. The SR 11-7 model risk management guidance from the OCC provides the parallel US framework for model validation requirements. The Model Risk Management guide on ClaudeFinanceLab covers SR 11-7 in detail.

Independently verified: Financial calculations on ClaudeFinanceLab are tested against analytically computed ground truth. See the financial accuracy eval results →
Using Claude at your firm?

Connect Claude to live financial data via MCP — EDGAR, FDIC, BIS, CME and 18 more.

New guides & tools — free

Get notified when we add new MCP servers, finance AI guides, and eval results.

Try These Skills

Browse all Compliance & Risk tools →
FEEDBACK