AI at banks and insurers: what the regulators expect
Supervised institutions may deploy AI – but under control. In Germany the framework is set by MaRisk and the EBA guidelines on outsourcing, in Austria by the FMA on the same European basis; on top of that, DORA has applied across the EU since January 2025 with requirements for managing ICT third-party risk. In Switzerland, FINMA set out its expectations for governance and risk management in AI deployment in a 2024 supervisory notice, supplemented by the outsourcing requirements of circular 2018/3.
For banks, insurers and wealth managers this means: deploying AI is a question of organisation – inventory, responsibilities, traceability and clean contracts with service providers.
What the regulators expect
Across regulators, four expectations sit at the centre: clear governance with defined responsibilities for AI deployment; an inventory of the AI applications in use, with risk classification; robust controls across the lifecycle – from data quality through to monitoring in operation; and traceability: institutions must be able to explain where AI is used and how results come about.
AI tools as outsourcing
Where an institution uses an external AI platform, this regularly constitutes outsourcing as soon as material functions are affected – under MaRisk and the EBA guidelines in the EU, under FINMA circular 2018/3 in Switzerland. The familiar requirements then apply: careful selection and instruction of the service provider, contractual assurance of rights to issue instructions, control and audit, provisions on data security and confidentiality, and the ability to bring the service back in an orderly way.
The data location plays a practical role here: processing in the EU or Switzerland makes assessing banking secrecy and data protection considerably simpler.
Typical AI use cases in institutions
Proven entry points are where AI assists rather than decides:
- Summarising research, studies and internal analyses
- Drafts for client communication and reports – multilingual
- Internal knowledge search across directives and regulations
- Structuring minutes and file notes
- Preparing documentation packages during onboarding
Implementation: start in a controlled way
The pragmatic route starts with a clearly delimited pilot: one team, defined use cases, a platform with roles, SSO and audit logs, a DPA and the compliance review before the start. The pilot produces the evidence – inventory entry, risk assessment, controls – that carries the broader rollout. That turns a supervisory expectation into a structured adoption plan.
Frequently asked questions
May banks use ChatGPT?
There is no blanket prohibition – but consumer tools without a contract, controls and an audit trail are hard to reconcile with supervisory expectations. Institutions need an enterprise solution that is properly set up as an outsourcing arrangement.
Is every use of AI an outsourcing that requires approval?
No. What is decisive is whether a material function is being outsourced. The institution makes that classification within its outsourcing governance – in the EU additionally documented in the register of information under DORA. AI applications belong in the inventory for that purpose.
What belongs in an AI inventory?
At minimum: the application and its purpose, the models and service providers used, the categories of data processed, the risk classification, responsibilities and existing controls. The inventory is the basis for audits and for the dialogue with the regulator.
Related reading
Bring AI into your company securely.
Try Vidimas with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
