As AI becomes part of the financial system’s “plumbing”, the question is no longer if we need AI governance – but whether our existing supervisory architecture is fit for purpose. And Germany’s Federal Office for Information Security (BSI) has taken an important step with its finalised Test Criteria Catalogue for AI Systems in Finance, developed as part of its AICRIV-Finanz project.
From generic AI frameworks to sector-specific controls
Over the last few years, a growing body of AI governance standards and legislation has emerged:
- AI-related ISO standards (from the ISO/IEC 42000 series to ISO/IEC 22989, 23894, 23053),
- the EU AI Act,
- the NIST AI Risk Management Framework,
- and several other, largely horizontal, initiatives.
The BSI has now changed the conversation – not by launching yet another framework, but by providing a test criteria catalogue specific to the financial sector that is mapped to key provisions of the EU AI Act and DORA.
In other words: instead of adding another layer of governance, the BSI offers a concrete way to operationalise existing regulation for financial institutions, with a focus on how AI systems are tested, validated, and evidenced.
Why financial institutions need dedicated AI governance
Financial institutions are already tightly regulated, reflecting their role in economic stability. What is new is that AI now permeates established workflows and decisions, increasingly entering risk management itself. Thereby, AI finds itself at the intersection of two regulatory logics: the EU AI Act is primarily designed to protect natural persons – their fundamental rights, health and safety – while sectoral financial regulation in banking, insurance and capital markets is designed to preserve financial stability. These objectives overlap, but they are not identical. Annex III of the EU AI Act, for example, designates use cases such as “creditworthiness assessment of natural persons” and “risk assessment and pricing in life and health insurance” as high risk, while not mentioning other core financial applications, including fraud detection and capital calculation.
Against this backdrop, the conclusion is straightforward: generic AI governance principles are necessary, but sector-specific AI controls are indispensable.
An augmentation, not “just another framework”
The AICRIV-Finanz criteria catalogue is best understood as an augmentation to what already exists: it supports implementation of regulatory requirements, but does not by itself prove full legal compliance.
It adds value in three ways:
- Concrete test criteria and methods
It provides examples of how controls can be tested and verified in practice, including a scenario-specific tool catalogue – moving from abstract expectations to tangible evidence. - Explicit mapping to DORA and the EU AI Act
It enables an integrated approach across regulations by making overlaps and connections between requirements transparent. Financial institutions can therefore position AI governance within their existing regulatory architecture, rather than building a parallel universe for AI. - Support for internal control adaptation
By mapping the BSI catalogue to internal controls, organisations can identify gaps and overlaps, adapt existing controls, rather than start from scratch, and build a coherent control environment across IT, risk and business lines.
For banks, capital markets, asset management, and insurers, the AICRIV-Finanz catalogue offers a pragmatic and adjustable route from high-level principles to auditable practice. It strengthens both organisational resilience and regulatory readiness, while reflecting the direction of regulatory expectations: towards robust and reliable measures for AI resilience and the operationalisation of integrated security.