AI at banks and insurers: what the regulators expect
There is no dedicated AI supervisory regime for banks, wealth managers and insurers in the DACH region. The existing frameworks govern instead: outsourcing law, the requirements on operational risk and the governance duties – plus customer confidentiality and, where there is an EU nexus, the EU AI Act.
In supervisory terms, using an external AI service is as a rule an outsourcing. The familiar duties follow: materiality assessment, due diligence, contractual requirements, ongoing monitoring, an exit strategy and audit rights.
This article sorts the requirements of BaFin, the FMA and FINMA, places the role of DORA since January 2025 and describes what an institution should have on file.
The three regulators compared
The structure is similar, the legal sources differ – as does the way customer confidentiality is anchored.
| Germany | Austria | Switzerland | |
|---|---|---|---|
| Regulator | BaFin | FMA | FINMA |
| Outsourcing requirements | MaRisk, EBA guidelines on outsourcing, DORA | BWG, EBA guidelines on outsourcing, DORA | FINMA circulars on outsourcing and on operational risks and resilience |
| Customer confidentiality | Contractual ancillary duty, no dedicated criminal offence | Section 38 BWG, laid down by statute | Art. 47 Banking Act, criminally sanctioned |
| EU AI Act | Applicable | Applicable | Not directly; bites through EU clients and group policies |
In supervisory terms, AI is usually an outsourcing
As soon as an institution has a function it would otherwise perform itself provided on an ongoing basis by a service provider, that is an outsourcing. An externally operated AI service regularly meets that test – whether it is obtained as a platform, an API or an embedded feature.
The familiar set of duties follows: a documented assessment of whether the outsourcing is material, due diligence on the provider, contractual requirements including audit and instruction rights, ongoing monitoring, an outsourcing register and a workable exit strategy.
The exit strategy is the item most often missing for AI services. It requires an answer to how the institution continues operating if the provider fails or the contract ends – considerably harder to answer when tied to a single model provider than with a platform offering several models.
DORA: what has applied since January 2025
Regulation (EU) 2022/2554 on digital operational resilience in the financial sector has applied since 17 January 2025. It harmonises the requirements on ICT risk management and on ICT third-party providers – and it captures AI services as ICT services.
In concrete terms DORA requires, among other things, a register of information covering all contractual arrangements with ICT third-party providers, defined contractual content, a reporting regime for major ICT incidents, and testing of digital operational resilience.
DORA does not apply directly to Swiss institutions. It becomes relevant through EU subsidiaries, EU clients and group policies – in practice often enough that the requirements get implemented anyway.
Customer confidentiality: the DACH-specific point
Banking confidentiality is anchored to differing degrees across the three countries. In Switzerland it is criminally sanctioned under Art. 47 of the Banking Act, in Austria laid down by statute in Section 38 BWG, and in Germany constructed as a contractual ancillary duty with no dedicated criminal offence.
For provider assessment this means data protection permissibility and supervisory permissibility are two separate assessments, and in Switzerland customer confidentiality adds a third. A data processing agreement fully answers none of them.
What matters most in practice is which individuals at the provider can access data in the clear and whether every access is logged. That is the information asked for in a supervisory conversation – not an assurance that data is "secure".
Where the EU AI Act comes in
The EU AI Act classifies the assessment of the creditworthiness of natural persons as a high-risk application; the same applies to risk assessment and pricing in life and health insurance. Heightened requirements on data quality, documentation, human oversight and logging then apply.
Common office applications are not affected: drafting, summarising, research, answering internal questions. They typically fall under minimal risk – with one exception that already applies: the AI literacy obligation in Art. 4 has bound deployers since 2 February 2025, regardless of risk class.
The AI Act does not apply directly to Swiss institutions. It bites through EU subsidiaries, clients in the EU and tenders in which the requirements are passed down.
What an institution should have on file
The following records are what gets asked for in an audit. Together they cover outsourcing law, DORA and data protection.
- An inventory of all AI applications with purpose, data types, user group and the responsible function.
- The assessment of whether the outsourcing is material, with reasoning – and the entry in the outsourcing or information register.
- Due diligence on the provider: processing location, applicable law, sub-processors, ability to access data in the clear, logging.
- The contract with audit and instruction rights, notification duties for changes of sub-processors, and defined consequences on termination.
- A workable exit strategy answering how operations continue without this provider.
- The governance: named owners, an internal policy, documented training and a procedure for approving new use cases.
- The classification under the EU AI Act where it applies, with reasoning per use case.
Frequently asked questions
Is using an AI service an outsourcing?
As a rule yes, as soon as a function the institution would otherwise perform itself is obtained from an external provider on an ongoing basis. Materiality assessment, due diligence, contractual requirements, a register entry, ongoing monitoring and an exit strategy follow from that.
Does DORA apply to Swiss institutions?
Not directly. The regulation becomes relevant through EU subsidiaries, clients in the EU and group policies. Many institutions implement the requirements anyway, because otherwise they would have to run two standards in parallel.
May client data be entered into an AI system?
That turns on three separate assessments: data protection, supervisory law and customer confidentiality. In Switzerland the latter is criminally sanctioned under Art. 47 of the Banking Act, in Austria laid down in Section 38 BWG. A data processing agreement alone fully answers none of the three.
Is an AI chat for staff a high-risk application?
Usually not. Drafting, summarising and research typically fall under minimal risk. It becomes high risk where the AI Act says so – for instance assessing the creditworthiness of natural persons, or risk assessment and pricing in life and health insurance.
What traceability do regulators actually expect?
It must be evidenceable who used which application when, with which types of data, and who approved that use. Without centrally managed access and logging that cannot be shown – which is the practical reason private accounts do not hold up in supervisory terms.
Is a provider hosting in the EU or Switzerland enough?
The location is a necessary but not sufficient piece of information. Also to be clarified are the law applicable to the operator, the sub-processors, the ability to access data in the clear and the institution's audit rights. Only these together carry the supervisory assessment.
Sources
- Federal Financial Supervisory Authority · BaFin (Germany)
- Austrian Financial Market Authority · FMA (Austria)
- Swiss Financial Market Supervisory Authority · FINMA (Switzerland)
- Regulation (EU) 2022/2554 (DORA) · EUR-Lex
Related reading
Bring AI into your company securely.
Try Custodos with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
