Regulation & Compliance6 min readFree to read

Brussels puts finance functions inside the high-risk perimeter

New implementing guidance drags internal forecasting and credit models into scope. The compliance clock is shorter than most finance teams assume.

Illustrated avatar of Iris Vane

Iris VaneAI Analyst

Regulation & Compliance

Narrated by Iris Vane

Narration pending — audio is being generated

The European Commission has published implementing guidance clarifying which enterprise AI systems fall inside the high-risk classification, and the reading for finance functions is less comfortable than the initial summaries suggested. Systems that materially inform decisions about access to credit, insurance pricing, or the assessment of an individual's economic position are squarely captured. Crucially, the guidance treats internally built models the same as procured ones. There is no exemption for a spreadsheet-plus-model arrangement stitched together by an FP&A team.

What matters practically is the documentation burden rather than any prohibition. Organisations operating in-scope systems must maintain technical documentation, keep logs, run a risk management process across the lifecycle, and be able to describe the data governance behind training and validation sets. In supervisory terms this is closer to model risk management as banks already know it than to anything in the software procurement playbook. Finance functions outside regulated financial services have generally never done this work.

The second-order effect is on vendors. Providers of general-purpose models pass certain obligations downstream through contractual terms, and deployers inherit responsibilities they may not have priced. Most enterprise agreements signed in the last eighteen months predate the guidance and contain transparency clauses that will not survive contact with a supervisor asking for training data provenance. Renewal season is the leverage point; mid-term renegotiation rarely is.

There is a temptation to wait for national competent authorities to publish their own interpretations before committing resource. That instinct is understandable and, on this occasion, wrong. The deliverable a regulator will ask for is evidence that governance existed at the time decisions were made. Evidence cannot be produced retrospectively. A model inventory, an owner per model, and a dated review cycle are cheap now and expensive later.

For the CFO the question is not whether the organisation is compliant today. It is whether, asked next quarter, anyone could produce a defensible list of every model influencing a number that reaches the board. In most finance functions we speak to, that list does not exist in one place.

Sources

Researched and written by an AI analyst and reviewed for accuracy before publication. Original analysis and paraphrase only.

Share this briefing

Know a finance leader who should read this?