In brief
In financial services, AI touches decisions that get contested: credit access, fraud detection, pricing. The EU AI Act classifies credit access at the high-risk level. Three properties of the iDIA framework carry most of the weight: Reproducible, because a decision gets replayed; Accountable, because it gets attributed; Supervised, because human recourse is designed before the contest arrives.
Where is AI used in financial services?
Published · Last updated · Wissam Daibess
Four families of use dominate. Credit risk assessment and pricing. Fraud detection and transaction monitoring. Compliance, from regulatory screening to report production. And client service, from conversational agents to file summarization.
The first two families touch decisions that directly affect a person. The last two often process personal information without the decision being visible from outside.
Unlisted use poses a particular risk here: a team preparing an analysis in a consumer AI tool pours client data into it.
What risks does AI introduce in finance?
The first is reproducibility. A credit decision gets contested, sometimes months later. If the model, its parameters and the input data were not documented at the moment of the decision, the organization can neither replay the result nor explain a deviation.
The second is automated-decision transparency. When a decision is made without human intervention, the person concerned holds rights over the information owed to them and over the possibility of review.
The third is security. Financial data attracts attack. An AI system that reads untrusted content widens the injection surface, and every tool it can reach becomes a capability handed to whoever takes control.
What does regulation say about AI in finance?
The EU AI Act classifies credit access among high-risk uses, with the requirements that follow: risk management, data quality, human oversight, documentation, registration.
In Quebec, Law 25 governs the processing of personal information and transparency for decisions made without human intervention. The two regimes stack for an organization serving clients on both sides of the Atlantic.
identifiable certifies compliance in AI governance, with the NIST AI RMF and with Law 25, and aligns practices with the AI Act. Obligations specific to financial-sector supervisory frameworks remain with legal counsel and the relevant regulator.
How is AI evaluated in a financial institution?
The AI Index evaluates systems and agents one by one, across the six properties of the iDIA framework, scored on documented evidence.
In finance, three properties are read first. Reproducible: configuration documentation, and the ability to replay a past result while explaining a deviation. Accountable: the person named responsible for each system. Supervised: the human recourse point, calibrated to the risk of the decision.
The Responsible AI Practice designation is granted at the threshold, and only there. A Reproducible property below the floor is enough to refuse it, whatever the average.
Related reading
Hub
AI governance in Quebec
The four frameworks, and which ones actually oblige.
Sector
AI in healthcare
The most sensitive data, governed to its level.
Sector
AI in human resources
Recruitment and evaluation, at the high-risk level.
Risk
AI security and risk
The AI Risk SOLN framework, model to posture.
Frequently asked questions
Is credit access a high-risk use under the EU AI Act?
Yes. The EU AI Act places credit access among high-risk uses, with the accompanying requirements for risk management, data quality, human oversight and documentation.
Must an AI-assisted credit decision be explainable?
A decision that gets contested must be replayable. That requires having documented, at the moment of the decision, the system used, its version, its parameters and the input data.
Which iDIA properties weigh most in finance?
Reproducible, Accountable and Supervised. They answer the three questions a contested decision raises: can it be replayed, who answers for it, and where the human intervenes.
Does Law 25 govern automated decisions?
It sets transparency obligations where a decision is based exclusively on automated processing, along with rights for the person concerned. Detailed interpretation remains with legal counsel.