Scope - What This Guide Covers
This guide focuses on the EU AI Act's postponed high-risk system reporting requirements for financial institutions. It's designed for your team to classify AI systems, prepare Technical Documentation (Annex IV), and establish conformity assessment processes before the new deadline.
You'll find requirement breakdowns, classification decision trees, and implementation steps you can start this quarter. This guide is not about the EU AI Act's broader provisions like prohibited practices or transparency obligations. It focuses specifically on high-risk system preparation.
Key Concepts and Definitions
High-Risk AI System: Under the EU AI Act, systems used in credit scoring, creditworthiness assessment, and certain financial service risk evaluations fall into Annex III's high-risk categories. These require conformity assessment, Technical Documentation (Annex IV), and Post-Market Monitoring.
Conformity Assessment: This is the process you'll use to demonstrate compliance before deployment. For most financial AI systems, this means internal validation plus Vendor Due Diligence if you're using a novel architecture or can't demonstrate adequate internal controls.
Technical Documentation (Annex IV): This is your system's compliance dossier. It includes design specifications, training data characteristics, validation evidence, risk management documentation, and human oversight protocols. Think of it as SR 11-7 model documentation extended to cover fundamental rights impact and transparency requirements.
Post-Market Monitoring: This involves ongoing surveillance after deployment. You're required to track performance drift, collect incident reports, and maintain logs that demonstrate continued compliance with your approved use case.
Requirements Breakdown
Classification Triggers
Your AI system qualifies as high-risk if it:
- Falls under Annex III, Section 5(b): creditworthiness assessment or credit scoring that determines access to financial services.
- Evaluates insurance pricing, claims, or policy terms (Annex III, Section 5(a)).
- Performs risk assessment or pricing for financial services where the output materially affects customer access or terms.
Decision Point: If your model informs but doesn't determine the decision (a human reviews every output and can override without justification), you may argue it's not high-risk. Document this control rigorously, as supervisors will challenge weak human-in-the-loop claims.
Documentation Requirements (Annex IV)
You must maintain:
- General description: Intended purpose, deployment context, version control.
- Design specifications: Architecture, algorithms, training approach, data requirements.
- Development process: How you selected training data, addressed bias mitigation, validated performance.
- Validation Evidence: Test results, performance metrics across demographic subgroups, Adversarial Simulation outcomes.
- Risk management: Your AI System Impact Assessment, Contextual Risk Factors analysis, mitigation controls.
- Human oversight measures: Who can intervene, under what circumstances, with what authority.
- Accuracy, robustness, cybersecurity: Reproducibility protocols, model recalibration procedures, rate limiting, access controls.
Conformity Assessment Process
Before deployment, you'll need:
- Internal validation (your existing model risk framework likely covers 60-70% of this).
- Quality management system documentation (ISO/IEC 42001 certification helps but isn't required).
- For certain systems: third-party conformity assessment by a notified body.
Timeline: Conformity assessment for a complex credit model typically takes 8-12 weeks if your documentation is ready. Add another 4-6 weeks if you need external review.
Implementation Guidance
Month 1: Inventory and Gap Analysis
Week 1-2: Build your high-risk system inventory.
- List all AI systems in credit decisioning, pricing, and risk assessment.
- For each system, document: business purpose, decision authority (automated vs. human-reviewed), customer impact, current validation status.
- Flag systems where you lack Technical Documentation (Annex IV) components.
Week 3-4: Run gap analysis against Annex IV.
- Compare your SR 11-7 model documentation to Annex IV requirements.
- Identify missing elements (common gaps: fundamental rights impact analysis, demographic performance breakdowns, human oversight protocols).
- Estimate documentation effort per system.
Month 2: Prioritize and Document
Prioritization criteria:
- Systems making fully automated decisions (highest regulatory risk).
- Systems affecting large customer populations.
- Systems with known performance disparities across subgroups.
- Systems you plan to modify or expand in the next 12 months.
Documentation sprint:
- Assign Technical Documentation (Annex IV) ownership (model owner + compliance + legal).
- Run AI System Impact Assessment for each high-risk system.
- Document Model Limitations and Use Restrictions explicitly.
- Establish Post-Market Monitoring metrics and thresholds.
Month 3: Establish Ongoing Processes
Set up:
- Post-Market Monitoring dashboards (performance by demographic segment, drift detection, incident logging).
- Human oversight protocols (escalation paths, override authority, decision review sampling).
- Change management process (when does a model update require new conformity assessment?).
- Vendor Due Diligence templates for Outsourced Models.
Test your process: Run a mock conformity assessment on one system. Time each step. Identify documentation bottlenecks.
Common Pitfalls
Pitfall 1: Treating this as a documentation exercise
Your Technical Documentation (Annex IV) must reflect actual controls, not aspirational ones. If you document quarterly model recalibration but only revalidate annually, you're creating audit risk.
Pitfall 2: Weak human oversight claims
"A human reviews the output" doesn't satisfy human oversight requirements if that human lacks authority to override, doesn't understand the model's logic, or faces productivity pressure to approve quickly. Document decision authority, training, and override rates.
Pitfall 3: Ignoring demographic performance breakdowns
You need validation evidence across relevant subgroups. If your credit model performs differently for different demographics and you haven't documented this with mitigation controls, you're not ready for conformity assessment.
Pitfall 4: Assuming SR 11-7 compliance equals EU AI Act compliance
SR 11-7 gets you 60-70% there, but you still need: fundamental rights impact analysis, transparency measures (Instructions for Use, Disclosure of AI Interaction for customer-facing systems), and explicit demographic fairness validation.
Pitfall 5: No Post-Market Monitoring plan
Conformity assessment approves your system as designed and validated. Post-Market Monitoring proves it performs as approved in production. Without continuous monitoring, you can't demonstrate ongoing compliance.
Quick Reference Table
| Requirement | What You Need | Where It Lives | Update Frequency |
|---|---|---|---|
| System classification | High-risk determination, use case documentation | Model inventory, risk tier assignments | At deployment, when use case changes |
| Technical Documentation (Annex IV) | Complete system dossier per Annex IV checklist | Model documentation repository | At major version changes |
| Validation Evidence | Performance metrics, demographic breakdowns, Adversarial Simulation results | Validation reports, test logs | Before deployment, at recalibration |
| AI System Impact Assessment | Fundamental rights analysis, Contextual Risk Factors, mitigation controls | Risk assessment documentation | Annually, when system scope changes |
| Human oversight protocols | Decision authority matrix, override procedures, training records | Operations manual, audit logs | Annually, review override rates quarterly |
| Post-Market Monitoring | Performance dashboards, incident logs, drift detection | Monitoring platform, incident management system | Real-time monitoring, formal review quarterly |
| Instructions for Use | Deployment context, Model Limitations and Use Restrictions, intended users | User documentation, training materials | At deployment, when limitations change |
| Conformity assessment | Internal validation + Vendor Due Diligence (if required) | Compliance records, certification documentation | Before initial deployment, after substantial modifications |
Next step: Block four hours this week to build your high-risk system inventory. You can't plan documentation sprints until you know what you're documenting. Start with systems making automated credit decisions, as those are your highest-priority conformity assessment candidates.



