AI-BaFin-Oorientation
Help
-eCChecklists

Checklists for Internal Audit on ICT Risks when using AI in Financial Institutions

What are the testing requirements under DORA for financial institutions when using AI?

The BaFin has published its guidance on ICT risks when using AI in financial institutions, its first framework to support financial institutions in implementing regulatory requirements in the context of AI. This was also to be expected, as the BaFin is also taking over further supervisory tasks in monitoring the implementation of the AI Regulation from the supreme supervisory authority for the EU AI Regulation, the Federal Network Agency. Emphasis is placed on the fundamental requirement to significantly increase AI training competencies within institutions.

The focus of the guidance is specifically on ICT risk management and ICT third-party risk management, including the Delegated Regulation on ICT risk management (RTS RMF) as well as the Delegated Regulation on the outsourcing of ICT services supporting critical or important functions (RTS outsourcing/chain outsourcing).

The guidance is therefore aimed in particular at those companies supervised by BaFin that have to comply with ICT risk management requirements pursuant to Articles 5 to 15 of DORA.

The implementation and operation of AI systems can carry significant risks, particularly concerning ICT risks from an regulatory perspective. AI systems are assessed analogously to general ICT systems with regard to their risk profile, complexity, and the functions they support, such as processing sensitive data or supporting critical or important functions.

Based on the AI orientation guide, we have developed a checklist for examination use which can be provided as an e-checklist.

With our practical checklist, you will receive:

Clearly structured AI requirements from the BaFin orientation guide

Simple self-assessment of your current status quo

Identification of deficiencies and need for action – basis for the annual financial statement auditor

Internal Audit Examination Checklist

Ideal for IT, AI Compliance, Audit and Management

Who is the e-checklist suitable for?

Internal Audit in Companies Using Diverse AI Applications (Cross-Industry)

Critically-aligned organisations

IT and AI Compliance officers & CISOs

Management boards with AI compliance responsibility

Your benefits at a glance:

Internal Audit receives first audit manual

Saving time on analysis

Identify Targeted Action Needs

Avoid fines help

Simplify audit preparation

Convinced? Then simply order directly via our order button or download our Order form down.

Our cooperation partners

Regulartech-IT-Audit-Consult GmbH is a consulting firm specialising in IT regulation, banking supervisory law, IT audit, and compliance for financial institutions.