Schedule a meeting

Financial services

DORA, supervisory scrutiny and the protection of client data.

Context

Banks, insurers and asset managers operate under the strictest ICT-risk regime in Europe. Supervisors now expect a credible answer to where AI runs, who can access client data and how the institution would exit a provider.

Key regulation

Framework Relevance
DORA ICT third-party risk management, contract requirements and exit strategies, applicable since 17 January 2025.
EU AI Act Creditworthiness assessment and life and health insurance pricing are high-risk uses, with obligations from 2 December 2027.
GDPR Client data processed by AI systems remains subject to full data protection obligations.

Challenges and opportunities

Challenges

  • Provider concentration AWS, Google Cloud and Microsoft are among the 19 providers designated as critical to the EU financial sector.
  • Exit planning Every material AI dependency requires a tested exit strategy.
  • Model risk AI models fall under existing model risk management and validation expectations.

Opportunities

  • Client due diligence Document review and case preparation on confidential client files, inside the institution.
  • Knowledge assistants Internal search across policies, procedures and regulatory correspondence.
  • Supervisory reporting Faster preparation of reporting and audit evidence, with full traceability.

Discuss the priorities in financial services.

Schedule an introductory meeting with our team.

Schedule a meeting