Financial services
DORA, supervisory scrutiny and the protection of client data.
Context
Banks, insurers and asset managers operate under the strictest ICT-risk regime in Europe. Supervisors now expect a credible answer to where AI runs, who can access client data and how the institution would exit a provider.
Key regulation
| Framework | Relevance |
|---|---|
| DORA | ICT third-party risk management, contract requirements and exit strategies, applicable since 17 January 2025. |
| EU AI Act | Creditworthiness assessment and life and health insurance pricing are high-risk uses, with obligations from 2 December 2027. |
| GDPR | Client data processed by AI systems remains subject to full data protection obligations. |
Challenges and opportunities
Challenges
- Provider concentration AWS, Google Cloud and Microsoft are among the 19 providers designated as critical to the EU financial sector.
- Exit planning Every material AI dependency requires a tested exit strategy.
- Model risk AI models fall under existing model risk management and validation expectations.
Opportunities
- Client due diligence Document review and case preparation on confidential client files, inside the institution.
- Knowledge assistants Internal search across policies, procedures and regulatory correspondence.
- Supervisory reporting Faster preparation of reporting and audit evidence, with full traceability.
How Lindstead helps
- AI strategy Define which workloads require in-house deployment and which remain suited to external APIs, with a clear board recommendation.
- Regulation and risk Map data flows, access rights and the resulting obligations under the AI Act, GDPR, DORA and NIS2 across the organisation.
- Deployment Deliver a production-grade first use case on your own infrastructure, with the security and quality controls auditors expect.
Discuss the priorities in financial services.
Schedule an introductory meeting with our team.