Three instruments reach the same model. The EU AI Act classifies systems that judge people as high-risk, MiFID II demands an algorithmic decision be reconstructable, and SR 11-7 expects a model challenged by somebody who did not build it. None exempts complexity at all.
AI used in banking, lending and investment. Audited once.
The EU AI Act does not replace MiFID II or SR 11-7; it sits on top - and all three ask for the same evidence differently.
Our promise
“Three regimes. One examination. One gap register.”
Every finding is tagged with the instrument it answers — defensible line by line, to whichever of the three is asking. The fee starts at $5,000, and nothing is charged until you approve it.
Request this finance AI auditFinancial AI, in three chapters
Most institutions answer them separately: a validation workstream, a conformity project, a trading-controls review. Three teams examine one model, write three documents that overlap by two thirds, and nobody holds the list of what is actually still open across all three of them.
We are the independent reviewer all three regimes have in mind. iDharma examines the model once - design, data, oversight, reconstruction and monitoring - and reports it against each instrument in turn, so what you receive is one technical file and one ranked gap register, not three.
AI systems in scope for finance
Every system that decides, prices or advises - whoever built it.
- Credit-scoring and lending models
- AI-assisted investment advice and robo-advisory
- Algorithmic trading systems
- Retail and commercial banking AI
- Before deployment - the assessment precedes the decision
- On every algorithmic decision, which must reconstruct
- Whenever the model is retrained, recalibrated or re-cut
- From 2 December 2027 for the Annex III high-risk limb
Three regimes. One evidence base.
The regulated firm
Every one of the three attaches to the institution taking the decision. The EU AI Act binds you as the provider or the deployer, MiFID II binds the investment firm, and SR 11-7 binds the supervised bank. Not one of the three has any route at all by which the obligation moves to somebody else instead.
The people who built the model
Carries duties of its own under the EU AI Act where it is the provider, and none at all under MiFID II or SR 11-7. A vendor conformity file is worth having, and it is a different document from your own technical file - it describes their system, not your deployment of it. Ask them for it, then write your own.
Three regimes, one evidence base
The duties do not merge, but the evidence does. Conceptual soundness, independent validation, decision reconstruction and ongoing monitoring are asked for by all three in different words - so a firm that runs three separate reviews ends up paying three times over to examine one single model.
“Three regimes, so three separate reviews.”
One model. The same evidence, three times over.
It is the most expensive assumption on this page.
- Who it is for
- Retail & commercial banks
- Lenders & credit
- Wealth & investment
- Trading desks
- Model risk & compliance
Finance at a glance
MiFID II requires an algorithmic decision to be reconstructable. No complexity exemption exists, and none has ever been read into it.
Annex III high-risk obligations apply from 2 December 2027. A technical file behind them is a year of work, not a quarter.
US regulators have confirmed SR 11-7 reaches machine-learning models. Independent validation is the baseline, not the ceiling.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four moments, and only one is a date.
Only the third is fixed by an instrument. The other three are the moments somebody asks — and none of the four can be added to another.
-
Assess
Before deploymentConformity assessment and conceptual-soundness review come before the model decides, not after it has a track record.
-
Reconstruct
Every decisionMiFID II Article 17 wants an algorithmic decision reconstructable. That is a design property, not a report you write later.
-
Comply
2 December 2027Annex III high-risk obligations apply from that date. The technical file behind them is a year of work, not a quarter.
-
Revalidate
AnnuallySR 11-7 expects ongoing monitoring and periodic validation. A model nobody has revalidated is a model nobody can defend.
Teams read 2 December 2027 as the start date and plan backwards from it. The conformity assessment sits in front of deployment, and the technical file behind it is assembled from evidence that has to have been collected while the model was being built - not reconstructed from memory in the quarter before the deadline.
What the three ask, what we ship
12 obligations across three instruments, and the artefact that discharges each one. Each row names which regime is speaking, so a claim on this page can be checked against the requirement beside it.
- Which regimes reach you Entity, activity and market, not sector label
- A written determination of which of the three bind which system, so nothing is audited twice and nothing is missed.
- Provider or deployer EU AI Act - the roles carry different duties
- Your role recorded per system, with the vendor obligations separated from yours in writing.
- High-risk classification EU AI Act Annex III
- Each system classified against Annex III with the reasoning stated, including the ones we conclude are out.
- Conformity assessment EU AI Act - before the system is placed in service
- The assessment run and evidenced, with the gaps that would stop it named before you are committed to a date.
- Technical documentation EU AI Act Annex IV; SR 11-7 documentation
- One package built to satisfy both, rather than a technical file and a validation report saying the same thing twice.
- Human oversight EU AI Act - effective, not nominal
- Override paths tested as they actually run, with the rate at which a human changes the outcome measured.
- Decision reconstruction MiFID II Article 17
- A sample of live decisions reconstructed end to end from your own records - the test that either passes or does not.
- Systems and risk controls MiFID II - kill switches, limits, testing
- Controls walked against the algorithm as deployed, including what happens when it is switched off mid-session.
- Conceptual soundness SR 11-7 - is the model right for the use
- The design, the assumptions and the data reviewed against the decision the model is actually being used to make.
- Independent validation SR 11-7; effective challenge from outside
- A validation by people with no role in building, selling or operating the model - and no fee tied to the finding.
- Ongoing monitoring SR 11-7; EU AI Act post-market monitoring
- The monitoring you have, the monitoring each regime expects, and the thresholds that should trigger a human looking.
- Vendor accuracy claims Nobody accepts a supplier report as evidence
- Test data, evaluation method and ground-truth construction requested and checked, rather than a benchmark quoted back.
How an iDharma audit works
One pass over the model. Three regimes answered.
-
Request and scope
Which systems, which decisions, which entity. Priced and approved before anything is charged.
-
Test once, map three ways
One pass over the models, scored against the EU AI Act, MiFID II and SR 11-7 together. One to four weeks.
-
Sign off and report
You see the draft first. Then the technical file and one gap register - ranked, dated and signed.
Why financial firms choose iDharma to review their models
Genuinely independent
We build, resell and operate no financial models, and we take no fee tied to what the audit finds.
Three regimes, one pass
One examination of the model, scored against all three - not three workstreams meeting at the end.
One documentation package
A technical file that answers Annex IV and SR 11-7 together, rather than two documents restating one.
Ranked by legal priority
The gap register is ordered by exposure across all three at once, so the first fix is the costliest gap.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Unified audit report
The full review: scope, method, every system examined, and the findings written so a validator, a supervisor and your board can each read the part they need - each finding tagged with the instrument it answers, so nothing in it is a claim about compliance in general.
Signed by a named independent reviewer with no role in building, selling or operating the models, and no fee tied to the finding. One pass over the estate, scored against all three regimes rather than three times over.
Gap register
Every gap in one list, ordered by exposure across all three regimes at once - so the first thing you fix is the costliest thing, not the easiest.
Technical documentation
One file built to answer EU AI Act Annex IV and SR 11-7 documentation together, rather than two documents restating each other in different words.
System classification
Each system placed against Annex III with the reasoning stated, including the ones we conclude are out of scope and exactly why they are.
Decision reconstruction
A sample of live decisions rebuilt from your own records, cell by cell, so your team can repeat the exercise on any trade or application.
Validation report
Conceptual soundness, outcomes analysis and ongoing monitoring reviewed as SR 11-7 asks, by people with no role in building the model.
Vendor-file assessment
What your vendor's conformity file and accuracy claims cover for your deployment, what they do not, and what must be evidenced on your side.
Real numbers, upfront.
- Scope
- Agreed with you, then fixed
- Data
- Your own decision and trade records
- Re-review
- On every material retrain - $3,000 against your known baseline
Three regimes over an estate only you can size, so the fee is quoted rather than listed - and nothing is charged until you have approved it.
Request a finance AI audit- EU AI Act, MiFID II and SR 11-7 in one pass
- Annex IV technical documentation package
- Live decision reconstruction, sampled
- One gap register, ranked by exposure
Four things you have to be able to produce
None of the three is graded on intent. Each of these is either in your hand on the day somebody asks, or it is not.
The classification,
reasoned
Which of your systems are high-risk under Annex III and which are not, with the reasoning written down. An unclassified estate is the finding before any model finding.
The file,
complete
One technical documentation package answering Annex IV and SR 11-7 together: purpose, design, data, limitations, change history and who approved each change.
The decision,
reconstructed
A trade or a credit decision rebuilt from your own records, showing what the algorithm saw and what it did. Article 17 is not satisfied by a description of the system.
The validation,
independent
Effective challenge from outside the build team, dated against the model version in production. Validation by the people who built it is documentation, not validation.
Four cards, and the version on each one is part of the card.
Do we really need to satisfy all three?
The duties do not merge - but the evidence does. Conceptual soundness, validation, reconstruction and monitoring are asked for by all three in different words, so it is one examination reported three ways.
Does the EU AI Act replace MiFID II or SR 11-7?
No. It sits on top of them. A firm already validating models under SR 11-7 has a head start on the technical file and no exemption from it, and MiFID II's trading obligations are untouched.
Which of our systems are actually high-risk?
Annex III reaches creditworthiness evaluation and credit scoring, with a carve-out for financial-fraud detection. Trading, pricing and servicing models are judged on what the output does to the decision.
How long does it take, and what does it cost?
One to four weeks for most engagements. Scope and price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.
What happens if we are late?
EU AI Act penalties reach EUR 35 million or 7% of global annual turnover, whichever is higher, for the most serious breaches. MiFID II and supervisory consequences run separately and arrive sooner.
Operating AI in banking, lending or investment?
Tell us what decides, and we come back with a scope and a price within one business day.
What we need from you
Nothing you do not already have. Mostly your model inventory and one extract of decision records, and we name every document we need in writing first.
- Which systems decide, and at which stage
- Whether they are built in-house, bought, or both
- Decision or trade records for the period
- Any validation already done, and by whom
- Your target date for a read, if you have one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Regulation (EU) 2024/1689 - the AI Act
- MiFID II Art. 17; SR 11-7 / OCC 2011-12
- Annex III from
- 2 December 2027
- Last read
- 9 September 2026
What it means
- General information about what these three instruments require — not legal advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
- Where the three genuinely conflict, or a classification is arguable, our reports say so rather than pick the convenient reading.
Scope & limitation
- Do not rest a binding decision on it; engage qualified counsel.
- Use it as a starting point for a scoping conversation, not as your final word.
- The dates and ceilings here are stated once on our EU AI Act page and followed from there — check that page before relying on either.
Something on this page out of date?
Tell usFrom Insights
Related reading
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Your AI Vendor Is Now ICT You Depend On: What DORA Changed
DORA is not an AI regulation. It is an operational resilience regulation — and a model in a financial process is ICT you depend on. That is a different sentence than most firms signed.