Feature AI Risk
EU AI Act Compliance KRIs: 8 Metrics for the August 2, 2026 Deadline — Before Your Supervisor Asks
August 2, 2026 is the full enforcement date for EU AI Act high-risk system obligations. Banks, fintechs, and insurers using credit scoring, AML, or underwriting AI need more than a compliance checklist — they need KRIs that show whether the program is actually running. Here's the framework.
Table of Contents
TL;DR:
- August 2, 2026 is the full enforcement date for EU AI Act high-risk AI obligations. Banks and fintechs using credit scoring, AML, or insurance underwriting AI are in scope.
- The gap most compliance teams are discovering: they have checklists of what the Act requires, but no ongoing KRIs showing whether the compliance program is actually functioning.
- 8 KRIs — mapped to specific EU AI Act articles — cover inventory coverage, technical documentation, conformity assessment, human oversight, post-market monitoring, bias testing, and incident reporting.
- Provider and deployer obligations differ significantly; your KRI framework needs to reflect which role your institution occupies for each system.
Fifty-Seven Days Out and the Program Isn’t Running
As of today, August 2, 2026 — the date high-risk AI system obligations under the EU AI Act become fully enforceable — is 57 days away.
Most financial services AI teams know what the Act requires. They’ve read the Annex III list, they’ve classified their credit scoring models as high-risk, they understand the provider/deployer distinction. What they don’t have is a repeatable, measurable way to know whether the compliance program is actually functioning — whether technical documentation is being maintained, whether post-market monitoring plans are being followed, whether bias assessments have been completed and documented, whether incident reporting procedures have been tested.
That’s what EU AI Act compliance KRIs are for. Not a one-time audit checklist. Ongoing metrics that show whether the program is running and whether it would hold up when a national competent authority examiner asks to see evidence.
Penalties under Article 99 for high-risk system violations reach €15 million or 3% of global annual turnover, whichever is higher. The EBA’s November 2025 analysis of AI Act implications for the banking sector makes clear that EU supervisors expect banks to treat AI Act compliance with the same rigor applied to prudential requirements. KRIs are how you demonstrate that rigor.
Who Is In Scope: High-Risk AI in Financial Services
Annex III of the EU AI Act classifies three categories of AI systems as high-risk when used in financial services:
-
Creditworthiness assessment and credit scoring of natural persons. Retail lending models, mortgage origination systems, credit line decisioning. This covers any AI system that evaluates an individual’s creditworthiness or generates a credit score used in a lending decision. Financial fraud detection is explicitly excluded from this category.
-
Risk assessment and pricing in life and health insurance. AI underwriting models that affect whether a natural person can obtain insurance or what premium they pay.
-
AML and CFT transaction monitoring. The EBA’s November 2025 guidance confirmed that AML and CFT transaction monitoring systems operated by supervised institutions fall within the Annex III scope as systems used in law enforcement-adjacent contexts affecting individuals.
If your institution uses any of these systems for EU customers or in EU-regulated subsidiaries, you’re a provider, a deployer, or both — and August 2, 2026 is your compliance date.
The Provider vs. Deployer Split
Most financial institutions are deployers for vendor-supplied AI and providers for internally built models — and sometimes both for the same use case. Provider KRIs focus on technical documentation, conformity assessments, EU database registration, post-market monitoring plans, and incident reporting to national competent authorities. Deployer KRIs focus on human oversight protocols, staff training, and log maintenance. The KRIs below cover both. Identify which role applies to each system before assigning ownership.
8 EU AI Act Compliance KRIs
1. High-Risk AI System Inventory Coverage Rate
Definition: % of AI systems in use that have been assessed for Annex III high-risk classification (documented assessment, not just classification assumption)
Relevant Articles: Article 6 + Annex III
You can’t manage what you haven’t inventoried. Many institutions have a rough list of their AI systems but haven’t formally assessed each one against the Annex III criteria with documented rationale. A system assumed to be low-risk without a documented assessment is an undocumented gap.
| Threshold | Signal |
|---|---|
| 100% of known AI systems assessed | Green |
| 85–99% assessed | Amber — complete by month end |
| < 85% assessed | Red — material gap, remediate immediately |
2. Technical Documentation Completeness Rate
Definition: % of high-risk AI systems with technical documentation meeting Annex IV requirements (for providers)
Relevant Articles: Article 11 + Annex IV
Annex IV sets the content requirements for technical documentation: general description of the AI system, design specifications, data governance, accuracy and robustness testing results, and instructions for use. Incomplete documentation is one of the most common compliance gaps — often because teams treat it as a one-time project rather than a living document.
| Threshold | Signal |
|---|---|
| 100% with compliant Annex IV docs | Green |
| 80–99% | Amber |
| < 80% | Red — prioritize before August 2 |
Track separately: “documentation exists” vs. “documentation is current” (updated within 12 months or when the system is materially modified).
3. Conformity Assessment Completion Rate
Definition: % of high-risk AI systems with completed conformity assessments (for providers)
Relevant Articles: Article 43
Most financial services AI systems under Annex III don’t require third-party notified body assessment — providers can conduct internal conformity assessments. But “internal” doesn’t mean undocumented. The assessment must demonstrate compliance with Chapter III, Section 2 requirements and be documented in the technical file.
| Threshold | Signal |
|---|---|
| 100% completed | Green |
| 75–99% | Amber — complete gap analysis |
| < 75% | Red — enforcement risk |
4. EU AI Database Registration Rate
Definition: % of applicable high-risk AI systems registered in the EU AI database (for providers of Annex III systems)
Relevant Articles: Article 49
Providers of Annex III high-risk AI systems must register in the EU database before placing the system on the market or putting it into service. The registration creates a public record of system type, intended purpose, and conformity status. This is verifiable by supervisors and the public — making it a straightforward compliance test.
| Threshold | Signal |
|---|---|
| 100% of required systems registered | Green |
| Any required system unregistered | Red |
5. Human Oversight Protocol Coverage and Testing Rate
Definition: % of high-risk AI systems with documented, tested human oversight procedures in place (for deployers)
Relevant Articles: Article 14
Article 14 requires that high-risk AI systems be designed so that humans can effectively oversee them — understanding the system’s capabilities and limitations, monitoring for anomalies, and being able to intervene or override. For deployers, this means maintaining documented oversight procedures and demonstrating that the humans responsible for oversight have been trained and tested.
| Threshold | Signal |
|---|---|
| 100% with documented + tested protocols | Green |
| 80–99% documented; testing incomplete | Amber |
| < 80% documented | Red |
Track training completion separately: the oversight procedure exists vs. the responsible staff member has completed training on it.
6. Post-Market Monitoring Cadence Adherence
Definition: % of high-risk AI systems where the post-market monitoring plan’s review schedule is being followed (for providers)
Relevant Articles: Article 72
Article 72 requires providers to actively and systematically collect and analyze performance data throughout the system’s lifetime. The monitoring plan must define what data is collected, how often it’s reviewed, and what triggers corrective action. This KRI measures whether you’re actually running the plan, not just whether you wrote one.
| Threshold | Signal |
|---|---|
| 100% of systems on monitoring schedule | Green |
| Any system with overdue monitoring review | Amber |
| Multiple systems with overdue reviews or no plan | Red |
For consumer-facing credit scoring systems, most monitoring plans call for at least quarterly performance reviews. For AML systems, the frequency should reflect transaction volume and the pace of money laundering tactic evolution.
7. Bias and Accuracy Testing Completion Rate
Definition: % of high-risk AI systems with a current bias and accuracy assessment completed per the monitoring plan (for providers and deployers)
Relevant Articles: Article 10 (data governance), Article 9 (risk management)
Article 10 requires training, validation, and testing data to be sufficiently representative and free from errors. In practice, this means ongoing testing for protected characteristic proxies, demographic performance disparities, and accuracy degradation. For credit scoring models in scope of fair lending regulation, this obligation overlaps with existing ECOA/CCPA requirements in the US context — but the EU AI Act standard applies independently.
| Threshold | Signal |
|---|---|
| 100% with current assessment (per plan cadence) | Green |
| Last assessment > 12 months ago | Amber |
| No bias assessment documented | Red |
Coordinate with your existing fair lending monitoring program. Duplication of effort is avoidable; the documentation can satisfy both EU AI Act Article 10 and domestic fair lending requirements if structured correctly.
8. Serious Incident Reporting Timeliness
Definition: % of serious incidents reported to the relevant national competent authority within the required timeframe (for providers)
Relevant Articles: Article 73
Article 73 requires providers to report serious incidents — AI system malfunctions or failures that result in death, serious harm, or significant disruption to critical infrastructure — to the market surveillance authority without undue delay. In practice, this means having an incident classification process that distinguishes “serious incident” from general model performance issues and a notification workflow that’s been documented and tested before an incident occurs.
| Threshold | Signal |
|---|---|
| 100% of incidents reported on time | Green |
| Any incident reported late | Amber — investigate and document |
| No incident reporting procedure in place | Red |
Track whether an incident reporting procedure exists, whether it’s been tested (tabletop or drill), and whether any actual incidents have occurred and been reported.
So What? August 2 Is a Line, Not a Finish
The August 2, 2026 enforcement date is not a compliance checkbox — it’s the start of ongoing regulatory scrutiny. EU national competent authorities and financial supervisors (including the EBA in its coordinating role) will be looking for evidence that institutions with high-risk AI in production have functioning compliance programs, not just audit reports saying they achieved compliance as of a specific date.
The KRIs above give you that evidence. Each one produces a data point that, reviewed monthly or quarterly, shows whether the program is running and where it’s degrading. When a supervisor asks “show me your post-market monitoring cadence for your credit scoring model” or “have all staff responsible for human oversight completed training,” the answer should come from your KRI dashboard — not from a rushed document pull.
For a comprehensive AI risk assessment framework that maps EU AI Act Article requirements to compliance documentation, bias testing templates, and model risk governance workflows, the AI Risk Assessment Template & Guide is built for financial services teams navigating both EU Act obligations and domestic model risk requirements simultaneously.
For EU AI Act background: EU AI Act High-Risk AI in Financial Services covers the full Annex III obligations and documentation requirements. AI Governance Dashboard: What KRIs Belong in Committee Reporting covers how to structure AI risk reporting at the committee and board level. For the NIST AI RMF measurement framework that maps closely to EU Act monitoring requirements, see NIST AI RMF MEASURE Function: TEVV, Bias Testing, and Metrics That Actually Matter.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Which AI systems in financial services qualify as high-risk under the EU AI Act?
What's the difference between provider and deployer obligations under the EU AI Act?
What are the penalties for EU AI Act non-compliance?
What is post-market monitoring under Article 72 and what does it require?
Do US financial institutions need to comply with the EU AI Act?
What should financial institutions do if they miss the August 2 deadline?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026