In application
DORA: Digital operational resilience rules apply
ICT risk, third-party register, incident reporting and testing.
Financial Services
What we build for banks, insurers, asset managers and payment institutions: AI that can be explained to a supervisor, integration that respects the core, and operations designed around DORA from the first architecture decision.
For financial institutions operating under European supervision, from national authorities to the ECB, EBA, EIOPA, ESMA and AMLA.

17 January 2025
DORA applies
ICT risk management, third-party registers, incident reporting and resilience testing for financial entities.
10 July 2027
EU AML Regulation applies
One rulebook for customer due diligence across the EU, with the new authority AMLA.
2 December 2027
AI Act high-risk duties for credit and insurance
Creditworthiness assessment and life and health insurance pricing are listed high-risk uses; application date as amended in 2026.
DORA turns operational resilience into specific obligations: ICT risk management, a register of every ICT third-party arrangement, classified incident reporting and regular testing. Cloud and AI suppliers are now part of the supervisory picture.
Credit scoring and insurance pricing become high-risk uses under the AI Act. Model risk management has to cover machine-learning and generative models, with documentation, monitoring and human oversight proportionate to the impact.
Instant payments, verification of payee and open banking have raised expectations for speed and transparency. The next payment services rules will tighten fraud prevention and API quality further.
Mainframes and core platforms still run the books. Change has to happen around them, through APIs and events, without putting stability or regulatory reporting at risk.
Customer onboarding and periodic reviews depend on analysts reading documents by hand.
Document intelligence extracts and checks identity, ownership and source-of-funds evidence. Analysts review flagged cases, and every check is logged for audit and the coming AML rulebook.
Advisers and service teams search five systems to answer one question.
A permission-aware assistant over products, policies and procedures that cites its sources and records what was shown, so advice records stay complete.
Every change to the core is slow, expensive and risky.
We expose core capabilities through APIs and event streams, move functions out step by step and keep reconciliation running until the old path can be retired.
The DORA register and incident workflow live in spreadsheets.
We build the register of information, incident classification and reporting workflows into your service management and cloud tooling, linked to the critical functions they support.
Models that cannot be explained do not pass validation.
An evaluation framework agreed with risk and validation teams: test sets, explainability where the decision needs it, monitoring for drift and a documented human override.
Regulatory reports are reconciled by hand every quarter.
Data pipelines with documented lineage and automated quality checks, following the BCBS 239 principles, so figures can be traced back to source.
Where AI sits between channels and core systems, with an approval gate on consequential steps and the DORA controls running alongside every layer.
AI services connect to core systems only through the integration layer. DORA controls apply to every component.
Customers, advisers and service teams use the app, web, branch and contact centre channels.
Behind the channels sit three AI services: onboarding and KYC document intake, an adviser and service assistant, and an analyst approval step that every consequential decision passes through.
The AI services reach core systems only through an integration layer of APIs and event streams. The core systems are core banking or policy administration, the CRM and service platform, and a data platform with documented lineage.
Alongside all layers run the DORA controls: ICT risk management, the register of ICT third parties, incident classification and reporting, and resilience testing. Every model is registered, validated and monitored under model risk management.
AI drafts, extracts and suggests. Decisions on credit, claims or account restrictions stay with a named person.
The level of explanation is decided per decision type during design, not bolted on before validation.
Cloud and model providers are chosen with exit plans and substitution paths documented for the register.
Inputs, outputs, model versions and approvals are retained so supervisors and auditors can reconstruct any case.
Dates that change what a delivery partner must show. National supervisors and the European supervisory authorities add guidelines and technical standards on top.
In application
ICT risk, third-party register, incident reporting and testing.
In application
In application
Preparing the single rulebook and direct supervision of selected institutions.
In application
Payment service providers in the euro area check the payee name before a transfer is executed.
In application
Customers must be told when they are dealing with an AI system.
Status as of 2 October 2026
Upcoming
Customer due diligence, beneficial ownership and record-keeping harmonised.
Upcoming
Including creditworthiness assessment and life and health insurance pricing, as amended in 2026.
Upcoming
The instruments that most often shape AI and platform work in financial institutions, and what each means for a delivery programme.
This overview supports planning conversations. It is not legal or regulatory advice. Dates reviewed on 2 October 2026.
The Digital Operational Resilience Act applies since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. It covers ICT risk management, incident reporting, resilience testing and the management of ICT third-party risk, including key contract clauses (Article 30).
As an ICT supplier we support your obligations: contract terms, incident notification, exit plans, participation in testing and the information your register needs.
SourceRegulation (EU) 2022/2554, EUR-Lex (opens external site)
AI used to assess the creditworthiness of individuals or to set risk-based prices for life and health insurance is high-risk. Providers and deployers need risk management, data governance, logging, human oversight and documentation. Under the Act as amended in 2026, these duties apply from 2 December 2027.
We classify each use case early, design human oversight into the process and produce documentation that fits your model risk framework.
SourceRegulation (EU) 2024/1689, EUR-Lex (opens external site)
The Anti-Money Laundering Regulation replaces national rules on customer due diligence with one EU rulebook from 10 July 2027. The new authority AMLA coordinates national supervisors and will directly supervise selected high-risk institutions.
Onboarding and review processes need consistent evidence handling and audit trails. We design document intake and case workflows for that standard.
SourceRegulation (EU) 2024/1624, EUR-Lex (opens external site)
Article 22 gives people the right not to be subject to decisions based solely on automated processing that significantly affect them, with exceptions that require safeguards such as human intervention and the right to contest.
We design processes where a person can review, explain and change an automated outcome, and record that they did.
SourceRegulation (EU) 2016/679, EUR-Lex (opens external site)
Investment and insurance distribution rules require suitability or demands-and-needs assessments and records of the advice given. AI that assists advisers becomes part of that record.
Assistants log what they showed and which sources they used, so the advice file stays complete and reviewable.
PSD2 governs payment services and open banking access today. Its successors, PSD3 and the Payment Services Regulation, were provisionally agreed in 2025 and will strengthen fraud prevention and API performance requirements after a transition period.
API platforms built now should anticipate stricter performance, monitoring and fraud-data sharing duties.
SourceDirective (EU) 2015/2366, EUR-Lex (opens external site)
Identity and ownership documents extracted and cross-checked; analysts decide on every flagged case.
Product, policy and procedure answers with sources, within the adviser's access rights.
Complaints classified by topic and urgency, routed with a draft summary, deadlines tracked for the complaint-handling rules.
Claim forms, invoices and reports read and matched to the policy; handlers approve payment.
Mainframe transactions exposed as documented APIs and events, so new channels stop depending on batch files.
Adviser workspaces, onboarding journeys and service operations, connected to core systems and document intake.
Finance and group reporting, with SAP data made available for risk and regulatory reporting with documented lineage.
Partner levels are those held by FromNine. Product names are trademarks of their respective owners.
International
Financial institutions in Europe answer to national supervisors and the European supervisory authorities, and from 2028 some will be supervised directly by AMLA. DORA, the AI Act and the AML package are EU-wide, but supervisory expectations, reporting formats and outsourcing practice still differ per country.
We design delivery so evidence is produced once and can be shown to any of them: architecture and model documentation, logs, test results and exit plans kept current as the system changes.
We agree the contract provisions DORA requires, notify incidents through the agreed channel, document exit plans, take part in resilience testing and supply the information your register of ICT third parties needs.
It can, as a high-risk use under the AI Act, with risk management, data governance, logging, human oversight and documentation. We design so that a person takes the decision and can explain it, and GDPR safeguards on automated decisions are respected.
In the environment your risk appetite allows: your own cloud tenancy, an EU region of a public cloud or on premises for sensitive workloads. Model and hosting choices are documented with exit options for your third-party register.
No. We integrate by default and modernise in steps: APIs and events around the core first, moving functions out only where it pays off, with reconciliation until the old path is retired.
With test sets and quality criteria agreed with your risk and validation teams before release, monitoring after release and review steps for uncertain output. The process assumes some output will be wrong and routes it to people.
Planning AI in onboarding, advice or claims, or preparing your estate for DORA testing? Talk to engineers who design for supervisors as well as users.