AIPolicyTracker

By sector · Financial services and credit

AI regulation in financial services, credit and insurance

Financial firms already run model risk management, so most AI duties land on existing controls: model inventories, validation, monitoring, explanations of adverse decisions and vendor oversight. What changes is scope and evidence: credit scoring and insurance pricing are high-risk uses in several instruments, and the explanation given to a consumer is a duty rather than a courtesy.

Recorded duties
27
25 legally binding
Jurisdictions
5
Controls
17
that meet these duties
Evidence items
52

Extend model risk management, do not duplicate it

The controls below map onto validation, monitoring and vendor-management practice a supervised firm has already. The value is in the mapping: knowing which duty a validation report already evidences, and which one still needs a fairness test or a consumer notice.

Explanations and adverse action

Several regimes require a specific, reviewable reason for an automated adverse decision. That is a transparency control with a data-governance dependency: the features have to be explainable to be explained.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
Decision explanation, human review and appeal route
Process
41Customer operations lead · once per ai system
AI interaction and use disclosure notices
Process
41Product owner · at launch and on material change
AI impact and fundamental-rights impact assessment
Process
32AI system owner · once per ai system
AI risk assessment and lifecycle risk register
Process
31AI system owner · once per ai system
AI incident management and regulatory reporting
Process
30Incident coordinator · continuous
Technical documentation, model cards and instructions for use
Process
22Product or model owner · at launch and on material change
Automatic event logging and record retention
Technical measure
21Engineering lead · continuous
AI governance policy and accountability structure
Policy
21Executive sponsor for AI · annual
Post-deployment monitoring and drift detection
Technical measure
13AI system owner · continuous
AI system inventory and classification
Process
12AI governance lead · continuous
Accuracy, robustness, fairness and security testing
Technical measure
12Quality or testing lead · at launch and on material change
Human oversight design and override procedure
Process
11AI system owner · once per ai system
Privacy and data-protection controls for AI
Process
11Data protection officer · once per ai system
Data governance and dataset documentation
Process
11Data governance lead · once per ai system
Prohibited and unacceptable-use screening gate
Process
10AI governance lead · once per ai system
Training-data provenance and copyright register
Process
01Model development lead · at launch and on material change
Conformity assessment, declaration and registration
Process
01Regulatory compliance lead · once per ai system

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

Colorado (United States) 10 duties

European Union 9 duties

South Korea 5 duties

Texas (United States) 1 duty

United Kingdom 2 duties

What evidence would a reviewer expect?

  • AI data-flow and legal-basis record Register entry
  • AI decision challenge and human review procedure Procedure or standard operating process
  • AI governance forum minutes Governance meeting record
  • AI impact assessment Impact assessment
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI intake and classification procedure Procedure or standard operating process
  • AI interaction or use notice Disclosure or notice
  • AI policy Policy document
  • AI responsibility map Register entry
  • AI system event logs Access or activity log
  • AI system register Register entry
  • AI system risk assessment Risk assessment
  • Adverse-decision explanation template Disclosure or notice
  • Board or executive approval of the AI policy Approval or sign-off record
  • Challenge and reversal log Monitoring record
  • Conformity evidence pack Technical documentation file
  • Copyright and rights-reservation policy Policy document
  • Data protection impact assessment for an AI system Data protection impact assessment
  • Data quality and bias check report Evaluation or test report
  • Dataset approval for use Approval or sign-off record
  • Dataset documentation sheet Dataset documentation
  • Declaration of conformity or certificate Conformity declaration or certificate
  • Human oversight and override procedure Procedure or standard operating process
  • Human-involvement design rationale Approval or sign-off record
  • Impact assessment approval Approval or sign-off record
  • Impact assessment procedure and template Procedure or standard operating process
  • Incident report to an authority Regulatory filing or notification
  • Independent data audit or DPO review Audit or assurance report
  • Instructions for use Disclosure or notice
  • Log integrity and retention check Audit or assurance report
  • Log schema and retention standard Procedure or standard operating process
  • Model card or deployer information pack Model documentation
  • Monitoring dashboard or periodic monitoring report Monitoring record
  • Monitoring review decision Approval or sign-off record
  • Notice catalogue Register entry
  • Notice wording approval Approval or sign-off record
  • Overseer training completion Training record
  • Per-system AI risk register Risk register
  • Post-market monitoring plan Procedure or standard operating process
  • Pre-release test report Evaluation or test report
  • Privacy notice section on AI use Disclosure or notice
  • Prohibited-use screening record Approval or sign-off record
  • Public summary of training content Disclosure or notice
  • Registration record in the relevant database Regulatory filing or notification
  • Release test sign-off Approval or sign-off record
  • Residual-risk acceptance Approval or sign-off record
  • Risk-tier classification sign-off Approval or sign-off record
  • Screening list and escalation procedure Procedure or standard operating process
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Training source register Register entry

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is credit scoring high-risk?
Under the instruments that use a risk tiering, creditworthiness assessment of natural persons is typically listed as high-risk, with fraud detection often excluded. The duty pages cite the entry.
What evidence do supervisors ask for?
The model inventory entry, the validation report, monitoring records, the fairness assessment, the consumer notice and the vendor assessment. The controls below list them.