Enterprise / high-volume plans available on request.
Anonymous users get 10 free calls/day without a key.
Free resource
EU AI Act Financial Services Readiness Checklist
High-risk AI in financial services — credit scoring, creditworthiness assessment, insurance risk pricing and
underwriting — must meet EU AI Act obligations. The Annex III deadline was extended by the EU's Digital
Omnibus (Regulation (EU) 2026/1744, in force July 2026) from August 2, 2026 to December 2, 2027 —
a 16-month extension reflecting standards-readiness gaps, not a reduction in what's required. Most
financial-services use cases go through internal-control self-assessment rather than third-party review, which
raises the bar on your own documentation, not lowers it. This checklist maps the Annex III/IV requirements to
what you actually need to have written down — worth having in place well before the extension runs out. Enter
your work email to unlock it; it prints cleanly to PDF.
Enter your work email to unlock the full checklist
Unlock above to view all 24 checklist items across 4 sections.
1 · Risk Classification & Scope
Annex III classification check — is this system used for creditworthiness assessment/credit scoring, or life/health insurance risk pricing and underwriting? Both are explicitly named high-risk use cases.
Provider vs. deployer determination — did your firm build the system (provider obligations) or are you using a vendor's system in production (deployer obligations)? The two roles carry different duties.
Conformity assessment route — most standalone financial-services high-risk systems use the internal-control (self-assessment) procedure, not third-party notified-body review. Document which route applies and why.
EU database registration — providers of high-risk AI systems must register the system in the EU's public database before placing it on the market.
Deadline tracking — standalone high-risk systems (Annex III): compliant by December 2, 2027, per the 2026 Digital Omnibus extension. Article 50 transparency/labeling duties and GPAI provider obligations were not extended and remain live on their original schedule — don't let the Annex III relief create false comfort on those.
Stacking with existing frameworks — EU AI Act obligations apply on top of BaFin, MiFID II, or your local prudential regulator's rules, not instead of them.
2 · Technical Documentation & Risk Management
Risk management system (Article 9) — a documented, continuous, iterative process run across the system's full lifecycle, not a one-time assessment at launch.
Data governance documentation (Article 10) — training, validation, and testing data quality; examination for possible biases affecting protected groups in credit or insurance decisions.
Annex IV technical documentation file — system description, intended purpose, development process, and performance metrics, kept current as the system changes.
Accuracy, robustness & cybersecurity (Article 15) — documented accuracy metrics, resilience to errors and adversarial input, and cybersecurity measures appropriate to the system's role in a credit or underwriting decision.
Instructions for use (Article 13) — if you're a provider, documentation given to deployers explaining the system's capabilities, limitations, and appropriate use.
Change log — version history of model, prompt, or tool changes, each dated and tied to a re-assessment decision.
3 · Human Oversight & Live Controls
Human oversight design (Article 14) — the system must be built so a natural person can understand its output, intervene in real time, and override a decision. Documentation alone does not satisfy this — it has to operate as a live control.
Named accountable overseer — a specific person who can describe, concretely, how they would intervene in an AI-driven credit or underwriting decision. "The team" is not an answer an examiner accepts.
Automation bias mitigation — documented measures against staff rubber-stamping AI output without genuine review, especially under volume or time pressure.
Override record-keeping — every time a human overrides the system's output, the override and its rationale should be logged, not just the AI's original recommendation.
Escalation path — a defined process for what happens when oversight staff flag a system behaving unexpectedly, and who has authority to pause its use.
Board/senior-management awareness — evidence that someone above the model-owner level understands the system's role and the firm's oversight controls for it.
4 · Post-Market Monitoring & Governance
Post-market monitoring plan (Article 72) — a systematic, documented process for collecting and reviewing the system's real-world performance after deployment, not just at validation time.
Automatic logging (Article 12) — the system must be technically capable of logging events across its lifetime, sufficient to reconstruct how a given output was produced.
Serious incident reporting (Article 73) — a defined process and named owner for reporting a serious incident to the relevant market surveillance authority within the required timeframe.
System inventory — a documented, current inventory of every AI system touching credit, underwriting, or fraud decisions. If this doesn't exist yet, it is the first gap to close.
Vendor/third-party disclosure — if using a vendor's model or MCP server, documentation of what your firm independently validated versus what you're relying on the vendor's own claims for.
Re-assessment trigger policy — what changes (model upgrade, retraining, new deployment context) require re-running the conformity assessment before continued use.
Need this filled in, not just outlined?
We build the ground-truth test suite, run the validation, and write the report your self-assessment file can cite — sections 2 and 3 above, done for your specific system.
This checklist is educational, not legal advice — EU AI Act obligations depend on your specific system,
deployment context, and jurisdiction. Confirm your classification and conformity route with qualified counsel.
See our disclaimer for more.