Skip to main content
FromNine
Menu

Financial Services

AI and platforms built for supervisory review.

What we build for banks, insurers, asset managers and payment institutions: AI that can be explained to a supervisor, integration that respects the core, and operations designed around DORA from the first architecture decision.

For financial institutions operating under European supervision, from national authorities to the ECB, EBA, EIOPA, ESMA and AMLA.

Edges of stacked glass panels catching a line of light
  1. 17 January 2025

    DORA applies

    ICT risk management, third-party registers, incident reporting and resilience testing for financial entities.

    SourceRegulation (EU) 2022/2554 (opens external site)

  2. 10 July 2027

    EU AML Regulation applies

    One rulebook for customer due diligence across the EU, with the new authority AMLA.

    SourceRegulation (EU) 2024/1624 (opens external site)

  3. 2 December 2027

    AI Act high-risk duties for credit and insurance

    Creditworthiness assessment and life and health insurance pricing are listed high-risk uses; application date as amended in 2026.

    SourceRegulation (EU) 2024/1689 (opens external site)

What is changing in financial services

  1. Resilience is now a legal duty

    DORA turns operational resilience into specific obligations: ICT risk management, a register of every ICT third-party arrangement, classified incident reporting and regular testing. Cloud and AI suppliers are now part of the supervisory picture.

    SourceRegulation (EU) 2022/2554

  2. AI decisions need an audit trail

    Credit scoring and insurance pricing become high-risk uses under the AI Act. Model risk management has to cover machine-learning and generative models, with documentation, monitoring and human oversight proportionate to the impact.

    SourceRegulation (EU) 2024/1689

  3. Customers compare you with their best app

    Instant payments, verification of payee and open banking have raised expectations for speed and transparency. The next payment services rules will tighten fraud prevention and API quality further.

  4. Core systems hold decades of logic

    Mainframes and core platforms still run the books. Change has to happen around them, through APIs and events, without putting stability or regulatory reporting at risk.

Challenges and what we build

  1. The challenge

    Customer onboarding and periodic reviews depend on analysts reading documents by hand.

    Our response

    Document intelligence extracts and checks identity, ownership and source-of-funds evidence. Analysts review flagged cases, and every check is logged for audit and the coming AML rulebook.

  2. The challenge

    Advisers and service teams search five systems to answer one question.

    Our response

    A permission-aware assistant over products, policies and procedures that cites its sources and records what was shown, so advice records stay complete.

  3. The challenge

    Every change to the core is slow, expensive and risky.

    Our response

    We expose core capabilities through APIs and event streams, move functions out step by step and keep reconciliation running until the old path can be retired.

  4. The challenge

    The DORA register and incident workflow live in spreadsheets.

    Our response

    We build the register of information, incident classification and reporting workflows into your service management and cloud tooling, linked to the critical functions they support.

  5. The challenge

    Models that cannot be explained do not pass validation.

    Our response

    An evaluation framework agreed with risk and validation teams: test sets, explainability where the decision needs it, monitoring for drift and a documented human override.

  6. The challenge

    Regulatory reports are reconciled by hand every quarter.

    Our response

    Data pipelines with documented lineage and automated quality checks, following the BCBS 239 principles, so figures can be traced back to source.

A control-first reference landscape

Where AI sits between channels and core systems, with an approval gate on consequential steps and the DORA controls running alongside every layer.

Illustrative example
Customers, advisers and service teams: app, web, branch and contact centreOnboarding and KYCdocument intakeAnalyst approvalAdviser and serviceassistantIntegration layer: APIs and event streamsCore banking or policyadministrationCRM and serviceplatformData platform withlineageDORA CONTROLSICT risk managementRegister of ICTthird partiesIncidentclassification andreportingResilience testingEvery model is registered, validated and monitored under model risk management.
Reference landscape for AI in a regulated financial institution

AI services connect to core systems only through the integration layer. DORA controls apply to every component.

Read the diagram as text

Customers, advisers and service teams use the app, web, branch and contact centre channels.

Behind the channels sit three AI services: onboarding and KYC document intake, an adviser and service assistant, and an analyst approval step that every consequential decision passes through.

The AI services reach core systems only through an integration layer of APIs and event streams. The core systems are core banking or policy administration, the CRM and service platform, and a data platform with documented lineage.

Alongside all layers run the DORA controls: ICT risk management, the register of ICT third parties, incident classification and reporting, and resilience testing. Every model is registered, validated and monitored under model risk management.

  • Approval before consequence

    AI drafts, extracts and suggests. Decisions on credit, claims or account restrictions stay with a named person.

  • Explainable by design

    The level of explanation is decided per decision type during design, not bolted on before validation.

  • Exit and concentration risk

    Cloud and model providers are chosen with exit plans and substitution paths documented for the register.

  • Logs as evidence

    Inputs, outputs, model versions and approvals are retained so supervisors and auditors can reconstruct any case.

The regulatory timeline for financial institutions

Dates that change what a delivery partner must show. National supervisors and the European supervisory authorities add guidelines and technical standards on top.

  1. In application

    DORA: Digital operational resilience rules apply

    ICT risk, third-party register, incident reporting and testing.

  2. In application

    AI Act: Prohibited practices banned, AI literacy required

  3. In application

    AMLA: EU Anti-Money Laundering Authority starts operating

    Preparing the single rulebook and direct supervision of selected institutions.

  4. In application

    Instant Payments Regulation: Verification of payee required for euro transfers

    Payment service providers in the euro area check the payee name before a transfer is executed.

  5. In application

    AI Act: Transparency obligations apply

    Customers must be told when they are dealing with an AI system.

  6. Status as of 2 October 2026

  7. Upcoming

    AML Regulation: Single EU rulebook applies

    Customer due diligence, beneficial ownership and record-keeping harmonised.

  8. Upcoming

    AI Act: High-risk obligations apply

    Including creditworthiness assessment and life and health insurance pricing, as amended in 2026.

  9. Upcoming

    AMLA: Direct supervision of selected institutions begins

Regulation and standards reference

The instruments that most often shape AI and platform work in financial institutions, and what each means for a delivery programme.

This overview supports planning conversations. It is not legal or regulatory advice. Dates reviewed on 2 October 2026.

DORAScopeEU-wide

The Digital Operational Resilience Act applies since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. It covers ICT risk management, incident reporting, resilience testing and the management of ICT third-party risk, including key contract clauses (Article 30).

What it means for your programme

As an ICT supplier we support your obligations: contract terms, incident notification, exit plans, participation in testing and the information your register needs.

SourceRegulation (EU) 2022/2554, EUR-Lex (opens external site)

EU AI ActScopeEU-wide

AI used to assess the creditworthiness of individuals or to set risk-based prices for life and health insurance is high-risk. Providers and deployers need risk management, data governance, logging, human oversight and documentation. Under the Act as amended in 2026, these duties apply from 2 December 2027.

What it means for your programme

We classify each use case early, design human oversight into the process and produce documentation that fits your model risk framework.

SourceRegulation (EU) 2024/1689, EUR-Lex (opens external site)

EU AML package (AMLR and AMLA)ScopeEU-wide

The Anti-Money Laundering Regulation replaces national rules on customer due diligence with one EU rulebook from 10 July 2027. The new authority AMLA coordinates national supervisors and will directly supervise selected high-risk institutions.

What it means for your programme

Onboarding and review processes need consistent evidence handling and audit trails. We design document intake and case workflows for that standard.

SourceRegulation (EU) 2024/1624, EUR-Lex (opens external site)

GDPR and automated decisionsScopeEU-wide

Article 22 gives people the right not to be subject to decisions based solely on automated processing that significantly affect them, with exceptions that require safeguards such as human intervention and the right to contest.

What it means for your programme

We design processes where a person can review, explain and change an automated outcome, and record that they did.

SourceRegulation (EU) 2016/679, EUR-Lex (opens external site)

MiFID II and IDD advice recordsScopeEU-wide

Investment and insurance distribution rules require suitability or demands-and-needs assessments and records of the advice given. AI that assists advisers becomes part of that record.

What it means for your programme

Assistants log what they showed and which sources they used, so the advice file stays complete and reviewable.

SourceDirective 2014/65/EU, EUR-Lex (opens external site)

PSD2 and the next payment services rulesScopeEU-wide

PSD2 governs payment services and open banking access today. Its successors, PSD3 and the Payment Services Regulation, were provisionally agreed in 2025 and will strengthen fraud prevention and API performance requirements after a transition period.

What it means for your programme

API platforms built now should anticipate stricter performance, monitoring and fraud-data sharing duties.

SourceDirective (EU) 2015/2366, EUR-Lex (opens external site)

Illustrative use cases

Illustrative example
  1. Onboarding document checks

    Identity and ownership documents extracted and cross-checked; analysts decide on every flagged case.

  2. Adviser knowledge assistant

    Product, policy and procedure answers with sources, within the adviser's access rights.

  3. Complaint intake and routing

    Complaints classified by topic and urgency, routed with a draft summary, deadlines tracked for the complaint-handling rules.

  4. Insurance claims intake

    Claim forms, invoices and reports read and matched to the policy; handlers approve payment.

  5. Core functions behind APIs

    Mainframe transactions exposed as documented APIs and events, so new channels stop depending on batch files.

Platforms in financial services

  • Salesforce

    Summit Partner

    Adviser workspaces, onboarding journeys and service operations, connected to core systems and document intake.

  • SAP

    Gold Partner

    Finance and group reporting, with SAP data made available for risk and regulatory reporting with documented lineage.

Partner levels are those held by FromNine. Product names are trademarks of their respective owners.

International

Built for European supervision

Financial institutions in Europe answer to national supervisors and the European supervisory authorities, and from 2028 some will be supervised directly by AMLA. DORA, the AI Act and the AML package are EU-wide, but supervisory expectations, reporting formats and outsourcing practice still differ per country.

We design delivery so evidence is produced once and can be shown to any of them: architecture and model documentation, logs, test results and exit plans kept current as the system changes.

Frequently asked questions

How do you support our DORA obligations as a supplier?

We agree the contract provisions DORA requires, notify incidents through the agreed channel, document exit plans, take part in resilience testing and supply the information your register of ICT third parties needs.

Can AI be used in credit or underwriting decisions?

It can, as a high-risk use under the AI Act, with risk management, data governance, logging, human oversight and documentation. We design so that a person takes the decision and can explain it, and GDPR safeguards on automated decisions are respected.

Where do models and data run?

In the environment your risk appetite allows: your own cloud tenancy, an EU region of a public cloud or on premises for sensitive workloads. Model and hosting choices are documented with exit options for your third-party register.

Do we have to replace our core platform?

No. We integrate by default and modernise in steps: APIs and events around the core first, moving functions out only where it pays off, with reconciliation until the old path is retired.

How do you evaluate generative AI in regulated processes?

With test sets and quality criteria agreed with your risk and validation teams before release, monitoring after release and review steps for uncertain output. The process assumes some output will be wrong and routes it to people.

Discuss your financial-services programme

Planning AI in onboarding, advice or claims, or preparing your estate for DORA testing? Talk to engineers who design for supervisors as well as users.