Compliance requirements for the financial sector and fintech.
Sector Profile
Attribute
Value
AI Act impact
CRITICAL (High-Risk)
NIS2 category
Essential (Annex I — Banking)
GDPR impact
HIGH
Other regulations
PSD2, DORA, AML, MiFID II
AI Act for Finance
High-Risk AI Systems (Annex III)
System
Classification
Obligations
Credit scoring
HIGH-RISK
Full obligations
Fraud detection
HIGH-RISK
DPIA, explainability
AML screening
HIGH-RISK
Human oversight
Algorithmic trading
MEDIUM
Monitoring, testing
Customer service chatbot
MEDIUM
Transparency
Risk assessment
HIGH-RISK
Documentation
Credit Scoring Specifics
NIS2 + DORA for Finance
DORA = Lex Specialis
The financial sector is subject to DORA (Digital Operational Resilience Act), which is lex specialis and supersedes NIS2 for ICT risk management in the financial sector.
Requirement
NIS2
DORA
ICT Risk Management
Yes
Yes (more detailed)
Incident Reporting
24-72h
4h initial, 72h full
Testing
Penetration testing
TLPT (Threat-Led)
Third-party risk
Vendor audit
ICT concentration risk
Resilience
Business continuity
Operational resilience
DORA Timeline
17 January 2025: DORA fully applicable (NOW!)
30 April 2025: ICT third-party registers submitted to ESAs
Ongoing: Supervision by national competent authorities