Where the AI Act Goes Beyond Your Existing Model Risk Management

A cross-border reading for risk control and validation functions at banks and insurers across the EU. What prudential validation already covers — and what the AI Act adds, wherever in the Union you sit.

“We have functioning model risk management. What we don’t have is a clear picture of where the AI Act goes further, and where it simply duplicates what we already do.”

We hear a version of this in nearly every first conversation with a risk control or validation function, regardless of which EU capital they’re based in. It’s a fair question, and it has a precise answer — more precise than most AI Act overview articles manage, since they tend to lump model risk and algorithmic fairness into the same basket.

Your validation is not the problem

Start where misunderstandings usually begin: your existing model validation is not called into question by the AI Act. Measured against what it was built for, it’s rigorous and mature — and largely the same rigor, wherever you’re regulated.

Article 185 CRR requires validation of internal estimates using established quantitative standards — discriminatory power (typically via AUC/Gini) and calibration, meaning the fit between estimated and actually observed default probability. For insurers, Articles 121 (statistical quality standards), 122 (calibration standards), and 124 (validation standards) of Solvency II prescribe a recurring validation cycle: backtesting against actual experience, stability analysis, sensitivity testing of key assumptions, and data quality and completeness assessments. None of this is Germany-specific — it’s the same CRR and Solvency II text in Paris, Amsterdam, and Rome as in Frankfurt.

What does vary is the layer of national supervisory expectation sitting on top of it, and for banks classified as significant under the Single Supervisory Mechanism, there’s a genuinely unifying document worth knowing about: the ECB Guide to Internal Models, in force since 2019 and updated with a dedicated section on machine learning and explainability. If your institution is directly supervised by the ECB, this Guide — not your national circular — is very likely your operative validation standard, and it applies identically whether you’re headquartered in Frankfurt, Paris, Amsterdam, or Milan.

Below SSM-significance, the national layer differs more than the EU layer suggests:

France — the ACPR has no single MaRisk-style circular, but achieves comparable rigour through targeted instruments: five Solvency II notices published in December 2023 (covering ORSA, data quality, and model validation specifically, with explicit requirements for AMSB approval of validation policy and independence of the validation function), plus a 16-criteria reference framework used during internal-model pre-candidacy review.

Netherlands — DNB has no generic model-risk circular at all. Instead, DNB and the AFM jointly published AI-specific principles as early as 2019 (the “SAFEST” framework: soundness, accountability, fairness, ethics, skills, transparency), years ahead of the AI Act, followed by a 2022 AI good-practices review and a 2025/2026 sector survey of insurers’ AI governance. If your validation documentation currently has nothing to say about fairness or ethics, Dutch supervisory expectations may already be ahead of what CRR/Solvency II validation alone requires.

Italy — Banca d’Italia’s Circolare n. 285/2013, continuously updated (most recently in 2025), is the closest single-document equivalent to MaRisk, covering internal models and governance for banks directly.

None of this changes your obligations under Art. 10, Art. 9(2)(a), Art. 27, or Art. 86 AI Act — those are explored below, and they’re identical regardless of country. What changes is which document you’d point to if a supervisor asked “how does this connect to what you already do.”

The actual gap: three questions prudential validation was never built to answer

Prudential validation answers one question at its core: is the model statistically reliable, and are the resulting capital requirements adequate? For high-risk AI systems, the AI Act asks three further questions that are not equivalent to that first one — mathematically or legally — and this part of the argument is genuinely EU-wide, with no national variation.

First: algorithmic fairness toward protected groups. A model can show excellent discriminatory power and clean calibration — both measured in aggregate across the portfolio — and still produce systematically different outcomes for protected groups without any underlying difference in actual risk. This isn’t a hypothetical tension: once base rates differ between groups, statistical discriminatory power and group fairness are not simultaneously satisfiable under most common definitions of fairness. Article 10 AI Act requires an explicit examination of training data for bias that could adversely affect protected characteristics. Your IRB or Solvency II validation doesn’t test for this — it was never designed to.

Second: transparency toward the person affected — not toward the supervisor. Your validation documentation is written for risk control, the board, and the supervisor. Article 86 AI Act addresses a different party entirely: any individual subject to a decision with significant effect based on a high-risk AI system has the right to a clear, meaningful explanation of the system’s role and the main elements of the decision. For creditworthiness assessment and life/health insurance risk assessment and pricing — both explicitly listed in Annex III, points 5(b) and 5(c) — this means the customer whose loan application or insurance premium was shaped by the model has an individual, personal claim. No existing validation artefact covers this, because none was written to.

Third: fundamental rights as a distinct risk register. Article 9(2)(a) AI Act requires identification of risks to “health, safety, or fundamental rights” for high-risk systems — a categorically different risk class from credit, market, or actuarial risk. And this becomes concrete for exactly your systems: Article 27 AI Act obliges deployers of high-risk systems under Annex III 5(b) (creditworthiness assessment) and 5(c) (risk assessment/pricing for life and health insurance) to conduct a Fundamental Rights Impact Assessment before first use — regardless of whether you’re a public or private institution. Affected population groups, specific harm risks, human oversight measures, and complaint mechanisms all need documenting. There’s no prudential-validation equivalent this can be derived from.

The good news: the legislator anticipated the duplication

This isn’t a courtesy argument on our part — it’s in the text. Recital 158 AI Act explicitly states that it’s appropriate for credit institutions under Directive 2013/36/EU (CRD) and insurance/reinsurance undertakings under Solvency II to integrate the AI Act’s procedural obligations on risk management, post-market monitoring, and documentation into their existing processes — with the express aim of avoiding duplicate work. In practice: the AI Act’s Article 9 risk management system should be anchored inside your existing risk-control governance, not built as a parallel structure beside it. This applies identically wherever in the EU you operate.

Supervisory continuity — where it holds, and where it doesn’t

Article 74(6) AI Act doesn’t create a new supervisory authority. It assigns AI Act market surveillance for high-risk systems used by regulated financial entities to whichever authority already supervises those entities under existing EU financial-services law. What that produces in practice depends entirely on how your country’s existing supervisory architecture is shaped — and this is where the picture stops being uniform.

  • Germany: BaFin already covers both banking and insurance prudential supervision, so it remains the single point of contact for AI Act purposes too.
  • France: for credit-scoring and insurance-pricing systems specifically, the picture mirrors Germany’s simplicity. The ACPR already covers both banking and insurance prudential and a substantial share of conduct supervision, and has been running internal preparatory sessions since at least September 2025 to map its probable AI Act role — including fairness-evaluation questions closely resembling the Article 10 discussion above.
  • Netherlands: no such simplicity. Dutch financial supervision already splits between DNB (prudential) and the AFM (conduct), and this split carries directly into AI Act supervision. As of a formal AFM consultation response in June 2026, the exact division of AI Act tasks between the two authorities was still flagged as needing clearer delineation before the implementing law passes parliament.
  • Italy: a three-way split. A preliminary decree approved by the Council of Ministers on 10 June 2026 assigns AI Act high-risk supervision in finance to Banca d’Italia (banking), CONSOB (investment services), and IVASS (insurance) separately, each within its existing remit, with ACN acting as central market-surveillance coordinator and AgID as the conformity-assessment-body authority.

Worth flagging plainly: as of this writing, none of these three national frameworks is finally adopted — France’s is internal preparatory work rather than statute, the Dutch implementing law is still working through parliament, and the Italian decree had only preliminary Council approval as of June 2026. If you’re building your governance narrative around “who will ask us about this,” it’s worth checking where each process stands before you finalise anything.

What actually has to be built from scratch

Three artefacts can’t be derived from existing validation documentation — this part, again, is identical across all four countries:

→ A recurring, documented fairness test across protected groups — group fairness and individual fairness, with trade-off decisions explicitly documented, run as a permanent part of the validation cycle rather than a one-off check.

→ An operational process for individual explanations under Article 86 — organisationally distinct from technical documentation written for a supervisor, because it has to respond to individual requests on demand, not to an annual review.

→ The Fundamental Rights Impact Assessment under Article 27 itself, for credit-scoring and life/health insurance pricing systems, as a standalone document produced before first use.

A note on vendor questions

One point that comes up before the substantive discussion in nearly every first conversation, regardless of country: bias and fairness testing typically means giving an external provider access to sensitive portfolio data — which triggers your own outsourcing-risk assessment and a DORA ICT third-party risk evaluation before any testing has even happened. DORA (Regulation (EU) 2022/2554) applies directly and uniformly across the EU without national transposition, which makes it a cleaner anchor for this argument than any national outsourcing circular. We built waveTest so the calculation runs client-side, in a Docker container inside your own infrastructure — only test results and reporting leave the building. Technically: your portfolio data never leaves your systems. From a governance standpoint: a materially lighter outsourcing assessment, because no third party gains access to the underlying data.

A closing thought

The question CROs and validation functions are actually wrestling with is rarely “do we have to do this” — it’s “where exactly does our existing framework stop, and where do we genuinely start from zero.” Draw that line precisely, and the incremental effort tends to be smaller than feared — provided you don’t accidentally duplicate what already works well.

Where does your Fundamental Rights Impact Assessment under Article 27 currently sit — with risk control, with compliance, or nowhere yet? And do you already know which of your national authorities will be the one asking?

Disclaimer

This article is provided for general informational purposes only and does not constitute legal, tax, or financial advice for any individual situation. Its contents reflect our understanding as of the publication date; regulatory frameworks in particular — including the EU AI Act and its national implementation — may have changed since. We make no warranty as to completeness, currency, or accuracy. Reading this article does not create an advisory or client relationship with waveImpact GmbH. For guidance tailored to your specific circumstances, please consult a suitably qualified professional.

Sources

Similar Posts