Financial services · AI governance & EU AI Act

AI governance for financial institutions, from supervisory expectation to audit-ready evidence

Banks, insurers and asset managers use AI for credit scoring, fraud detection, robo-advisory and anti-money-laundering monitoring. FINMA expects clear governance, accountability, robustness, transparency and data quality for it, while the EU AI Act classifies individual finance use cases as high-risk. We build the AI inventory, classify the obligations per use case and keep the evidence so it withstands a review.

legal + security + AI from one partner DE · FR · EN independent, no in-house SOC business
AI governance and EU AI Act for Swiss financial institutions

For banks, insurers, securities firms, FinTechs and asset managers using AI

FINMA expectation governance & accountability
EU AI Act classification per use case
AI inventory kept audit-ready
Human oversight model documentation
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

AI in the financial sector is under twofold scrutiny

As soon as a financial institution uses AI in production, two sets of expectations meet: the supervisory one from FINMA and the regulatory one from the EU AI Act. Both require you to know where AI is in use and to be able to govern it.

FINMA has clearly placed AI on the supervisory agenda. At the centre are governance and accountability, that is clear responsibilities for every model, further the robustness and reliability of outputs, transparency and explainability towards clients and the supervisor, and the quality and representativeness of training and input data. FINMA does not issue its own AI certification, but it expects an institution to master these points on a risk basis and to be able to demonstrate them. What is required in a given case depends on the function, materiality and risk exposure of your applications and must be assessed case by case.

In parallel, the EU AI Act classifies AI systems by risk. Several use cases are relevant for the financial sector: creditworthiness assessment and credit scoring of natural persons count as high-risk, as do risk assessment and pricing in life and health insurance. Other uses such as fraud detection, robo-advisory, AI-assisted anti-money-laundering monitoring or generative assistants fall, depending on their design, into other classes, for instance with transparency obligations or as minimal risk. The EU AI Act applies in phases and is under revision (Digital Omnibus), so the precise classification and timing must be verified per use case.

For Swiss institutions the EU AI Act does not apply automatically. It can still bite, however, when you operate through EU branches or subsidiaries or when the outputs of your AI systems are used in the EU. Whether directly or indirectly, we check this per institution and per use case. Regardless, the nFADP rules on automated individual decisions and FINMA's expectations on governance and data quality remain decisive in Switzerland.

  • A complete AI inventory: which models are in use where, with which data and for which decisions
  • Clear governance and accountability for every model, from sign-off to ongoing monitoring
  • Robustness, explainability and human oversight for decisions that affect clients
  • Data quality and representativeness of training and input data, documented and verifiable
  • An EU AI Act classification per use case, with the resulting transparency or high-risk obligations
  • Model documentation and evidence that withstand a FINMA review or a supervisory request

AI obligations in the financial sector at a glance

Orientation, not legal advice. What actually applies depends on your use case, your supervision and your data flows. We verify scope and classification case by case, and some timelines are still moving in the regulatory process.

RequirementWhat it means for AI in financeTimingStatus
FINMA expectations on AIGovernance, accountability, robustness, transparency and data quality for every model, mastered on a risk basis and demonstrableongoing supervisory practicerelevant for supervised institutions
EU AI Act, credit scoringCreditworthiness assessment and credit scoring of natural persons count as high-risk, with duties on risk management, data governance, documentation and oversightphased, under revision (Digital Omnibus)verify case by case
EU AI Act, insuranceRisk assessment and pricing in life and health insurance can be classified as high-risk, depending on the designphased, under revision (Digital Omnibus)verify case by case
EU AI Act, further use casesFraud detection, robo-advisory, anti-money-laundering monitoring and generative assistants fall into other classes depending on design, often with transparency dutiesphased, under revision (Digital Omnibus)classify per use case
nFADP, automated decisionsInformation and right-to-comment duties for automated individual decisions with significant effects on data subjectsin forcemandatory in Switzerland
Scope for CH institutionsThe EU AI Act usually reaches Swiss institutions indirectly, via EU branches, subsidiaries or the use of AI outputs in the EUdepending on structure and data flowverify direct or indirect

How we make your AI governance audit-ready

We start with the inventory, classify every use case and build on it a governance framework that maps FINMA expectations and the relevant EU AI Act obligations in one system.

First we build your AI inventory. We capture every productive and planned AI application with its purpose, the data used, the type of decisions made and the providers involved. Many institutions underestimate how much AI is already in the house via third-party systems and generative tools. The inventory creates the basis on which every further obligation can be judged.

Then we classify per use case under the EU AI Act and map the FINMA expectations to it. We treat credit scoring and certain insurance applications as potentially high-risk and derive the corresponding duties on risk management, data governance, documentation and oversight. For fraud detection, robo-advisory or anti-money-laundering monitoring we clarify which transparency and governance duties apply. The classification is soft-framed and verified per use case, because the EU AI Act applies in phases and is under revision.

On that basis we set up a FINMA-aligned AI governance framework: roles and responsibilities for every model, a sign-off and review process, requirements on robustness and explainability, a concept for human oversight on decisions that affect clients, and data-quality requirements. For every high-risk model we produce the model documentation a review expects and set up ongoing monitoring. We keep the AI inventory, the classifications, the model documentation and the measures in the Priverion Platform, the Swiss compliance-management software, so the evidence is maintained and exportable.

Where the deeper AI-specific work is needed, we draw on our dedicated AI services. The AI Officer takes on ongoing AI governance as a mandate, the AI Governance Check delivers the well-founded baseline, and AI Security addresses the technical security of your models, for instance against manipulation and data leakage. So you get the finance view and the AI depth from the same partner.

Why SIDD for your AI governance

AI governance in finance combines supervisory law, data protection and technical security. We cover exactly that combination from one partner.

Legal, security and AI from one partner

The EU AI Act classification and the FINMA governance are led by doctorate-level lawyers, the technical model review and AI security by an in-house technical team under an ISO 27001 Lead Auditor. So legal classification and technical evidence fit together.

Three dedicated AI services

With AI Officer, AI Governance Check and AI Security we bring specialised AI depth into the mandate. We classify the EU AI Act obligations for your finance use cases and secure the models technically, instead of treating AI as a side topic.

Audit-ready evidence in tooling

We maintain the AI inventory, classifications, model documentation and measures in the Priverion Platform. If FINMA or internal audit asks, the evidence is ready, maintained and exportable, instead of being painfully assembled first.

Governance that holds in operation

We do not only build a framework on paper, we anchor responsibilities, sign-offs, human oversight and ongoing monitoring in day-to-day operations. So every model stays attributable and governable, even as new AI tools are added.

Soft-framed and case-based

The EU AI Act applies in phases and is under revision. We classify deliberately cautiously, verify applicability per use case and per institution and distinguish clearly between direct and indirect application. So you build on robust assumptions instead of provisional figures.

Multilingual & independent

We advise in German, French and English, fitting institutions across Switzerland and with EU exposure. Because we do not sell an in-house SOC, our recommendations on models, providers and measures stay independent.

Two routes to audit-ready AI governance

AI Officer

on request retainer, on request

The ongoing operation: someone who runs AI governance, classifies new use cases, maintains the model documentation and is your point of contact towards the supervisor.

  • External AI Officer who runs AI governance as a mandate and anchors it in operations
  • Ongoing classification of new use cases under the EU AI Act and FINMA expectations
  • Maintenance of the AI inventory, model documentation and measures in the Priverion Platform
  • Concept and support for human oversight and ongoing model monitoring
  • Point of contact for AI questions towards FINMA, internal audit and management, in DE, FR or EN

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your AI governance in the financial sector, concretely: LexCommand backs every risk classification of your financial AI use cases with the exact provision in the EU AI Act and FINMA supervisory practice, and maps overlapping duties across the AI Act, ISO/IEC 42001 and the FADP/GDPR, so your roadmap rests on retrievable sources rather than judgement calls.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does the EU AI Act even apply to our Swiss institution?

Not automatically. For Swiss institutions the EU AI Act usually bites indirectly, for instance when you operate through EU branches or subsidiaries or when the outputs of your AI systems are used in the EU. Whether directly or indirectly, we check this per institution and per use case. Regardless, the FINMA expectations and the nFADP remain decisive in Switzerland. The EU AI Act also applies in phases and is under revision (Digital Omnibus), so we frame the classification cautiously.

Is our credit scoring automatically a high-risk system?

Creditworthiness assessment and credit scoring of natural persons are designated as high-risk in the EU AI Act, which triggers duties on risk management, data governance, documentation and human oversight. Whether your specific system falls under it, and in which form, depends on the use and is assessed case by case. We classify per use case and derive the applicable duties, instead of assuming the strictest regime across the board.

Does FINMA issue an AI certification?

No. FINMA does not issue its own AI certification. It does expect a supervised institution to master AI on a risk basis, that is to be able to demonstrate governance, accountability, robustness, transparency and data quality. We build exactly this evidence and keep it so it withstands a supervisory request. We advise and prepare, we do not issue certificates.

What does human oversight mean in practice?

Human oversight means that a responsible person can understand, question and, if necessary, override a model's outputs for decisions that affect clients. In practice we define who reviews which decisions, when a manual sign-off is required and how anomalous or poorly explainable outputs are escalated. We anchor this in the governance framework and the model documentation.

We use third-party generative AI tools, do we have to capture those too?

Yes. Generative tools and AI features in third-party systems in particular often enter operations unnoticed and belong in the AI inventory. We capture them with purpose, data flow and provider, clarify transparency and confidentiality questions and review the provider side as part of your third-party risk management. So bought-in AI also stays attributable and governable.

Do you work in French and English?

Yes. We advise throughout in German, French and English and keep the inventory, classification and model documentation in your institution's language, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and with EU exposure.

Matching next steps

Your AI governance builds on our dedicated AI services:

Ready to make your AI audit-ready?

We build your AI inventory, classify per use case under the EU AI Act, set up a FINMA-aligned governance framework and keep model documentation and oversight audit-ready.