AI governance for financial institutions, from supervisory expectation to audit-ready evidence
Banks, insurers and asset managers use AI for credit scoring, fraud detection, robo-advisory and anti-money-laundering monitoring. FINMA expects clear governance, accountability, robustness, transparency and data quality for it, while the EU AI Act classifies individual finance use cases as high-risk. We build the AI inventory, classify the obligations per use case and keep the evidence so it withstands a review.
legal + security + AI from one partnerDE · FR · ENindependent, no in-house SOC business
AI in the financial sector is under twofold scrutiny
As soon as a financial institution uses AI in production, two sets of expectations meet: the supervisory one from FINMA and the regulatory one from the EU AI Act. Both require you to know where AI is in use and to be able to govern it.
FINMA has clearly placed AI on the supervisory agenda. At the centre are governance and accountability, that is clear responsibilities for every model, further the robustness and reliability of outputs, transparency and explainability towards clients and the supervisor, and the quality and representativeness of training and input data. FINMA does not issue its own AI certification, but it expects an institution to master these points on a risk basis and to be able to demonstrate them. What is required in a given case depends on the function, materiality and risk exposure of your applications and must be assessed case by case.
In parallel, the EU AI Act classifies AI systems by risk. Several use cases are relevant for the financial sector: creditworthiness assessment and credit scoring of natural persons count as high-risk, as do risk assessment and pricing in life and health insurance. Other uses such as fraud detection, robo-advisory, AI-assisted anti-money-laundering monitoring or generative assistants fall, depending on their design, into other classes, for instance with transparency obligations or as minimal risk. The EU AI Act applies in phases and is under revision (Digital Omnibus), so the precise classification and timing must be verified per use case.
For Swiss institutions the EU AI Act does not apply automatically. It can still bite, however, when you operate through EU branches or subsidiaries or when the outputs of your AI systems are used in the EU. Whether directly or indirectly, we check this per institution and per use case. Regardless, the nFADP rules on automated individual decisions and FINMA's expectations on governance and data quality remain decisive in Switzerland.
A complete AI inventory: which models are in use where, with which data and for which decisions
Clear governance and accountability for every model, from sign-off to ongoing monitoring
Robustness, explainability and human oversight for decisions that affect clients
Data quality and representativeness of training and input data, documented and verifiable
An EU AI Act classification per use case, with the resulting transparency or high-risk obligations
Model documentation and evidence that withstand a FINMA review or a supervisory request
AI obligations in the financial sector at a glance
Orientation, not legal advice. What actually applies depends on your use case, your supervision and your data flows. We verify scope and classification case by case, and some timelines are still moving in the regulatory process.
Requirement
What it means for AI in finance
Timing
Status
FINMA expectations on AI
Governance, accountability, robustness, transparency and data quality for every model, mastered on a risk basis and demonstrable
ongoing supervisory practice
relevant for supervised institutions
EU AI Act, credit scoring
Creditworthiness assessment and credit scoring of natural persons count as high-risk, with duties on risk management, data governance, documentation and oversight
phased, under revision (Digital Omnibus)
verify case by case
EU AI Act, insurance
Risk assessment and pricing in life and health insurance can be classified as high-risk, depending on the design
phased, under revision (Digital Omnibus)
verify case by case
EU AI Act, further use cases
Fraud detection, robo-advisory, anti-money-laundering monitoring and generative assistants fall into other classes depending on design, often with transparency duties
phased, under revision (Digital Omnibus)
classify per use case
nFADP, automated decisions
Information and right-to-comment duties for automated individual decisions with significant effects on data subjects
in force
mandatory in Switzerland
Scope for CH institutions
The EU AI Act usually reaches Swiss institutions indirectly, via EU branches, subsidiaries or the use of AI outputs in the EU
depending on structure and data flow
verify direct or indirect
How we make your AI governance audit-ready
We start with the inventory, classify every use case and build on it a governance framework that maps FINMA expectations and the relevant EU AI Act obligations in one system.
First we build your AI inventory. We capture every productive and planned AI application with its purpose, the data used, the type of decisions made and the providers involved. Many institutions underestimate how much AI is already in the house via third-party systems and generative tools. The inventory creates the basis on which every further obligation can be judged.
Then we classify per use case under the EU AI Act and map the FINMA expectations to it. We treat credit scoring and certain insurance applications as potentially high-risk and derive the corresponding duties on risk management, data governance, documentation and oversight. For fraud detection, robo-advisory or anti-money-laundering monitoring we clarify which transparency and governance duties apply. The classification is soft-framed and verified per use case, because the EU AI Act applies in phases and is under revision.
On that basis we set up a FINMA-aligned AI governance framework: roles and responsibilities for every model, a sign-off and review process, requirements on robustness and explainability, a concept for human oversight on decisions that affect clients, and data-quality requirements. For every high-risk model we produce the model documentation a review expects and set up ongoing monitoring. We keep the AI inventory, the classifications, the model documentation and the measures in the Priverion Platform, the Swiss compliance-management software, so the evidence is maintained and exportable.
Where the deeper AI-specific work is needed, we draw on our dedicated AI services. The AI Officer takes on ongoing AI governance as a mandate, the AI Governance Check delivers the well-founded baseline, and AI Security addresses the technical security of your models, for instance against manipulation and data leakage. So you get the finance view and the AI depth from the same partner.
Why SIDD for your AI governance
AI governance in finance combines supervisory law, data protection and technical security. We cover exactly that combination from one partner.
Legal, security and AI from one partner
The EU AI Act classification and the FINMA governance are led by doctorate-level lawyers, the technical model review and AI security by an in-house technical team under an ISO 27001 Lead Auditor. So legal classification and technical evidence fit together.
Three dedicated AI services
With AI Officer, AI Governance Check and AI Security we bring specialised AI depth into the mandate. We classify the EU AI Act obligations for your finance use cases and secure the models technically, instead of treating AI as a side topic.
Audit-ready evidence in tooling
We maintain the AI inventory, classifications, model documentation and measures in the Priverion Platform. If FINMA or internal audit asks, the evidence is ready, maintained and exportable, instead of being painfully assembled first.
Governance that holds in operation
We do not only build a framework on paper, we anchor responsibilities, sign-offs, human oversight and ongoing monitoring in day-to-day operations. So every model stays attributable and governable, even as new AI tools are added.
Soft-framed and case-based
The EU AI Act applies in phases and is under revision. We classify deliberately cautiously, verify applicability per use case and per institution and distinguish clearly between direct and indirect application. So you build on robust assumptions instead of provisional figures.
Multilingual & independent
We advise in German, French and English, fitting institutions across Switzerland and with EU exposure. Because we do not sell an in-house SOC, our recommendations on models, providers and measures stay independent.
Two routes to audit-ready AI governance
AI Governance Check (financial sector)
Fixed fee
The one-off baseline of your AI landscape against FINMA expectations and the EU AI Act, with inventory, classification and a prioritised roadmap.
AI inventory of all productive and planned applications with purpose, data and providers
EU AI Act classification per use case, soft-framed and verified case by case
Alignment with the FINMA expectations on governance, robustness, transparency and data quality
Per-model gap analysis with a board-ready report and a prioritised roadmap
Inventory and classifications set up in the Priverion Platform, ready to continue
The ongoing operation: someone who runs AI governance, classifies new use cases, maintains the model documentation and is your point of contact towards the supervisor.
External AI Officer who runs AI governance as a mandate and anchors it in operations
Ongoing classification of new use cases under the EU AI Act and FINMA expectations
Maintenance of the AI inventory, model documentation and measures in the Priverion Platform
Concept and support for human oversight and ongoing model monitoring
Point of contact for AI questions towards FINMA, internal audit and management, in DE, FR or EN
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your AI governance in the financial sector, concretely: LexCommand backs every risk classification of your financial AI use cases with the exact provision in the EU AI Act and FINMA supervisory practice, and maps overlapping duties across the AI Act, ISO/IEC 42001 and the FADP/GDPR, so your roadmap rests on retrievable sources rather than judgement calls.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Does the EU AI Act even apply to our Swiss institution?
Not automatically. For Swiss institutions the EU AI Act usually bites indirectly, for instance when you operate through EU branches or subsidiaries or when the outputs of your AI systems are used in the EU. Whether directly or indirectly, we check this per institution and per use case. Regardless, the FINMA expectations and the nFADP remain decisive in Switzerland. The EU AI Act also applies in phases and is under revision (Digital Omnibus), so we frame the classification cautiously.
Is our credit scoring automatically a high-risk system?
Creditworthiness assessment and credit scoring of natural persons are designated as high-risk in the EU AI Act, which triggers duties on risk management, data governance, documentation and human oversight. Whether your specific system falls under it, and in which form, depends on the use and is assessed case by case. We classify per use case and derive the applicable duties, instead of assuming the strictest regime across the board.
Does FINMA issue an AI certification?
No. FINMA does not issue its own AI certification. It does expect a supervised institution to master AI on a risk basis, that is to be able to demonstrate governance, accountability, robustness, transparency and data quality. We build exactly this evidence and keep it so it withstands a supervisory request. We advise and prepare, we do not issue certificates.
What does human oversight mean in practice?
Human oversight means that a responsible person can understand, question and, if necessary, override a model's outputs for decisions that affect clients. In practice we define who reviews which decisions, when a manual sign-off is required and how anomalous or poorly explainable outputs are escalated. We anchor this in the governance framework and the model documentation.
We use third-party generative AI tools, do we have to capture those too?
Yes. Generative tools and AI features in third-party systems in particular often enter operations unnoticed and belong in the AI inventory. We capture them with purpose, data flow and provider, clarify transparency and confidentiality questions and review the provider side as part of your third-party risk management. So bought-in AI also stays attributable and governable.
Do you work in French and English?
Yes. We advise throughout in German, French and English and keep the inventory, classification and model documentation in your institution's language, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and with EU exposure.
Matching next steps
Your AI governance builds on our dedicated AI services:
We build your AI inventory, classify per use case under the EU AI Act, set up a FINMA-aligned governance framework and keep model documentation and oversight audit-ready.