Credit-scoring & lending models
Underwriting, credit-risk (PD/LGD), and adverse-action decisions — proxy-discrimination testing, explanation quality, and ECOA/FCRA compliance.
Financial Services AI Compliance
Everything financial beyond payments — retail and commercial banking, credit and lending, wealth management, and algorithmic trading — faces a layered compliance stack. The EU AI Act does not replace MiFID II or SR 11-7; it sits on top of them. None offers a model-complexity exemption.
What we audit
Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.
Underwriting, credit-risk (PD/LGD), and adverse-action decisions — proxy-discrimination testing, explanation quality, and ECOA/FCRA compliance.
Suitability algorithms and robo-advisory models — MiFID II conduct requirements, client explanation rights, and EU AI Act conformity.
Audit-trail completeness, decision reconstruction, circuit-breaker documentation, and MiFID II Article 17 compliance.
Segmentation, churn, early-warning, and product-recommendation models — fair treatment, data governance, and transparency obligations.
Regulatory frameworks
Every iDharma Finance engagement maps simultaneously against the frameworks below — producing one gap register, not three separate reports.
Financial-services AI making or influencing creditworthiness, insurance, and investment-suitability decisions is classified high-risk. Conformity assessment required before deployment.
Algorithmic trading firms must have effective systems and risk controls. Every algorithmic decision must be fully auditable and reconstructable.
US bank regulators confirm this guidance applies to machine-learning models. Independent validation, conceptual-soundness review, and performance monitoring are baseline expectations.
Our methodology
We do not accept vendor documentation as evidence, and we do not produce checkbox compliance reports. Every audit gives you a named auditor, a cited methodology, and a straight answer on where your AI stands.
We run a single unified audit against SR 11-7, EU AI Act Annex III, and MiFID II — not three separate workstreams.
We produce one technical documentation package that satisfies both SR 11-7 validation requirements and EU AI Act technical-file requirements.
We independently verify accuracy claims by requesting test data, evaluation methodology, and ground-truth construction — not just accepting vendor reports.
Our gap register is ordered by legal priority across all three frameworks simultaneously, so your remediation effort addresses the highest-exposure items first.
More sectors
Get started
The free Risk Snapshot identifies which obligations apply to your specific deployment and where your highest-priority gaps are.
“AI is already making finance decisions — with no independent proof it holds up.”
One prioritised gap register mapped to the frameworks you answer to — signed by a named auditor.
Scoped before you pay — nothing is charged until you approve what the engagement covers.