AI-BaFin-Oorientation
Help-eCChecklists
Checklists for Internal Audit on ICT Risks when using AI in Financial Institutions
What are the testing requirements under DORA for financial institutions when using AI?
The BaFin has published its guidance on ICT risks when using AI in financial institutions, its first framework to support financial institutions in implementing regulatory requirements in the context of AI. This was also to be expected, as the BaFin is also taking over further supervisory tasks in monitoring the implementation of the AI Regulation from the supreme supervisory authority for the EU AI Regulation, the Federal Network Agency. Emphasis is placed on the fundamental requirement to significantly increase AI training competencies within institutions.
The focus of the guidance is specifically on ICT risk management and ICT third-party risk management, including the Delegated Regulation on ICT risk management (RTS RMF) as well as the Delegated Regulation on the outsourcing of ICT services supporting critical or important functions (RTS outsourcing/chain outsourcing).
The guidance is therefore aimed in particular at those companies supervised by BaFin that have to comply with ICT risk management requirements pursuant to Articles 5 to 15 of DORA.
The implementation and operation of AI systems can carry significant risks, particularly concerning ICT risks from an regulatory perspective. AI systems are assessed analogously to general ICT systems with regard to their risk profile, complexity, and the functions they support, such as processing sensitive data or supporting critical or important functions.
Based on the AI orientation guide, we have developed a checklist for examination use which can be provided as an e-checklist.
With our practical checklist, you will receive:
Clearly structured AI requirements from the BaFin orientation guide
Simple self-assessment of your current status quo
Identification of deficiencies and need for action – basis for the annual financial statement auditor
Internal Audit Examination Checklist
Ideal for IT, AI Compliance, Audit and Management
Who is the e-checklist suitable for?
Internal Audit in Companies Using Diverse AI Applications (Cross-Industry)
Critically-aligned organisations
IT and AI Compliance officers & CISOs
Management boards with AI compliance responsibility
Your benefits at a glance:
Internal Audit receives first audit manual
Saving time on analysis
Identify Targeted Action Needs
Avoid fines help
Simplify audit preparation
Our cooperation partners
Regulartech-IT-Audit-Consult GmbH is a consulting firm specialising in IT regulation, banking supervisory law, IT audit, and compliance for financial institutions.