Regulation

SR 11-7 model risk management and AI use cases

US supervisory guidance on model risk management, applied by banks to AI and machine learning models.

Read the source text (Federal Reserve and OCC)

High risk under the EU AI Act

Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.

  • AI credit scoring with alternative data for thin file applicants

    Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).

Depends on design under the EU AI Act

The tier depends on how the system is used, for example whether it decides on access to an essential service.

  • AI assistant for investment suitability assessment and reports

    Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.

  • AI cash flow underwriting for small business loans

    Annex III point 5(b) makes AI systems that evaluate the creditworthiness of natural persons or establish their credit score high risk. Scoring a company is outside that point, but a sole trader is a natural person, and a model that also assesses the personal credit of owners, partners or guarantors evaluates natural persons. The tier therefore depends on who the borrower is and whose creditworthiness the model assesses.

  • AI early warning and covenant monitoring for loan portfolios

    Monitoring the credit of companies is not listed in Annex III. Where the same system evaluates the creditworthiness of natural persons, such as sole traders or personal guarantors, it falls under Annex III point 5(b) and is high risk; because that evaluation profiles natural persons, the Article 6(3) exemption does not apply.

  • AI for application and identity fraud detection

    Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.

  • AI for market abuse surveillance alert triage

    Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).

  • AI for settlement fail prediction and post trade exception management

    Predicting settlement fails and handling post trade exceptions between professional market participants is not a use listed in Annex III and is not a prohibited practice under Article 5, so the tier depends on how the agent communicates. While an operator reviews and sends every message, the system is minimal risk: the messages are the firm's own correspondence and the firm as deployer owes AI literacy for staff (Article 4). Once the agent sends queries or chasers to counterparty or custodian staff itself, as the playbook recommends for routine information requests, it interacts directly with natural persons and Article 50(1) requires telling the recipients they are dealing with an AI system. In both designs the provider of the text generating system must mark its output as AI generated in a machine readable format under Article 50(2). Model risk and operational resilience controls apply on top.

  • AI next best action prompts for wealth advisors

    Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.

  • AI recommendations for loan restructuring and hardship arrangements

    Recommending restructuring terms for individuals involves assessing their ability to pay, which can amount to evaluating the creditworthiness of natural persons under Annex III point 5(b). Human approval alone does not remove that: the Article 6(3) exception covers only systems that do not materially influence the decision, such as a narrow procedural or preparatory task, and never applies when the system profiles natural persons. A tool that only assembles the case file can fall under the exception; restructuring for companies is outside point 5(b).

  • AI system and model inventory with shadow AI discovery

    Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.

  • Dynamic AML customer risk rating with machine learning

    An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.

Limited risk (transparency) under the EU AI Act

People must be told they are dealing with AI, and generated content must be identifiable (Article 50).

  • AI cash flow forecasting for corporate treasury

    Forecasting a company's cash flows is not listed in Annex III and makes no decision about a natural person, so the forecasting model itself carries no obligations beyond AI literacy (Article 4). The conversational layer interacts directly with treasury staff, so under Article 50(1) they must be informed that they are dealing with an AI system unless that is obvious from the context. Without a conversational layer the use case is minimal risk.

  • AI for regulatory report assembly

    Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.

Minimal risk under the EU AI Act

No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.

  • AI agent for fraud alert triage

    Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.

  • AI for AML transaction monitoring alert triage

    AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.

  • AI for fee and interest leakage detection

    Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.

  • AI for money mule account and network detection

    Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.

  • AI for sanctions screening alert adjudication

    Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.

  • AI screening of trade finance transactions for trade based money laundering

    Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.

  • Real time fraud scoring for card and instant payments

    Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.