By sector · Financial services and credit
AI regulation in financial services, credit and insurance
Financial firms already run model risk management, so most AI duties land on existing controls: model inventories, validation, monitoring, explanations of adverse decisions and vendor oversight. What changes is scope and evidence: credit scoring and insurance pricing are high-risk uses in several instruments, and the explanation given to a consumer is a duty rather than a courtesy.
- Jurisdictions
- 5
- Evidence items
- 52
Extend model risk management, do not duplicate it
The controls below map onto validation, monitoring and vendor-management practice a supervised firm has already. The value is in the mapping: knowing which duty a validation report already evidences, and which one still needs a fairness test or a consumer notice.
Explanations and adverse action
Several regimes require a specific, reviewable reason for an automated adverse decision. That is a transparency control with a data-governance dependency: the features have to be explainable to be explained.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| Decision explanation, human review and appeal route Process | 4 | 1 | Customer operations lead · once per ai system |
| AI interaction and use disclosure notices Process | 4 | 1 | Product owner · at launch and on material change |
| AI impact and fundamental-rights impact assessment Process | 3 | 2 | AI system owner · once per ai system |
| AI risk assessment and lifecycle risk register Process | 3 | 1 | AI system owner · once per ai system |
| AI incident management and regulatory reporting Process | 3 | 0 | Incident coordinator · continuous |
| Technical documentation, model cards and instructions for use Process | 2 | 2 | Product or model owner · at launch and on material change |
| Automatic event logging and record retention Technical measure | 2 | 1 | Engineering lead · continuous |
| AI governance policy and accountability structure Policy | 2 | 1 | Executive sponsor for AI · annual |
| Post-deployment monitoring and drift detection Technical measure | 1 | 3 | AI system owner · continuous |
| AI system inventory and classification Process | 1 | 2 | AI governance lead · continuous |
| Accuracy, robustness, fairness and security testing Technical measure | 1 | 2 | Quality or testing lead · at launch and on material change |
| Human oversight design and override procedure Process | 1 | 1 | AI system owner · once per ai system |
| Privacy and data-protection controls for AI Process | 1 | 1 | Data protection officer · once per ai system |
| Data governance and dataset documentation Process | 1 | 1 | Data governance lead · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 1 | 0 | AI governance lead · once per ai system |
| Training-data provenance and copyright register Process | 0 | 1 | Model development lead · at launch and on material change |
| Conformity assessment, declaration and registration Process | 0 | 1 | Regulatory compliance lead · once per ai system |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
Colorado (United States) 10 duties
-
Legal requirementColorado AI Act · C.R.S. 6-1-1704applies from 30 Jun 2026Deployers and developers must disclose to consumers that they are interacting with an AI system
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(3)applies from 30 Jun 2026Deployers must complete impact assessments for high-risk AI
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(2)applies from 30 Jun 2026Deployers must implement a risk management policy and programme
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(7)applies from 30 Jun 2026Deployers must notify the Attorney General of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(5)applies from 30 Jun 2026Deployers must publish a statement about the high-risk AI systems they use
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(1)applies from 30 Jun 2026Deployers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702applies from 30 Jun 2026Developers must document high-risk systems and disclose known risks
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(5)applies from 30 Jun 2026Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(1)applies from 30 Jun 2026Developers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(4)applies from 30 Jun 2026Notify consumers and explain adverse consequential decisions
European Union 9 duties
-
Legal requirementEU AI Act · Article 27applies from 2 Aug 2026Carry out a fundamental rights impact assessment before deployment
-
Legal requirementEU AI Act · Article 26(4)applies from 2 Aug 2026Deployers must ensure input data they control is relevant and representative
-
Legal requirementEU AI Act · Article 86applies from 2 Aug 2026Deployers must explain individual decisions taken with high-risk AI on request
-
Legal requirementEU AI Act · Article 26(5)applies from 2 Aug 2026Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
-
Legal requirementEU AI Act · Article 26(11)applies from 2 Aug 2026Deployers must tell natural persons that a high-risk AI system is used in decisions about them
-
Legal requirementEU AI Act · Article 26(9)applies from 2 Aug 2026Deployers must use the provider's transparency information in their data protection impact assessment
-
Legal requirementEU AI Act · Article 6(4); Article 49(2)applies from 2 Aug 2026Providers must document and register a conclusion that an Annex III system is not high-risk
-
Legal requirementEU AI Act · Article 18applies from 2 Aug 2026Providers must keep high-risk AI documentation for ten years
-
Legal requirementEU AI Act · Article 19applies from 2 Aug 2026Providers must retain automatically generated logs under their control
South Korea 5 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must be able to explain outputs and the main criteria behind them
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must ensure human management and supervision
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
-
VoluntaryFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35applies from 22 Jan 2026Operators of high-impact AI should assess its impact on fundamental rights before use
Texas (United States) 1 duty
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.056applies from 1 Jan 2026Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
United Kingdom 2 duties
-
Legal requirementICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025Apply safeguards to solely automated decisions with significant effects
-
VoluntaryUK AI regulation framework · Principle 3, Part 3Use AI in ways that are fair and do not discriminate unlawfully
What evidence would a reviewer expect?
- AI data-flow and legal-basis record Register entry
- AI decision challenge and human review procedure Procedure or standard operating process
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI responsibility map Register entry
- AI system event logs Access or activity log
- AI system register Register entry
- AI system risk assessment Risk assessment
- Adverse-decision explanation template Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Challenge and reversal log Monitoring record
- Conformity evidence pack Technical documentation file
- Copyright and rights-reservation policy Policy document
- Data protection impact assessment for an AI system Data protection impact assessment
- Data quality and bias check report Evaluation or test report
- Dataset approval for use Approval or sign-off record
- Dataset documentation sheet Dataset documentation
- Declaration of conformity or certificate Conformity declaration or certificate
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Log integrity and retention check Audit or assurance report
- Log schema and retention standard Procedure or standard operating process
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public summary of training content Disclosure or notice
- Registration record in the relevant database Regulatory filing or notification
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Screening list and escalation procedure Procedure or standard operating process
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
Latest changes to these instruments
Texas TRAIGA takes effect
European Commission proposes Digital Omnibus adjustments to AI Act timelines
Colorado delays the AI Act effective date to 30 June 2026
EU AI Act general-purpose AI, governance and penalty provisions start to apply
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is credit scoring high-risk?
- Under the instruments that use a risk tiering, creditworthiness assessment of natural persons is typically listed as high-risk, with fraud detection often excluded. The duty pages cite the entry.
- What evidence do supervisors ask for?
- The model inventory entry, the validation report, monitoring records, the fairness assessment, the consumer notice and the vendor assessment. The controls below list them.