How to evaluate AI vendors for a regulated private bank
Two regulations govern this decision, and they're not the same thing. DORA has applied since January 17, 2025. It doesn't regulate AI directly, it governs ICT risk, and any AI vendor counts as an ICT third party. The EU AI Act is AI-specific. Its highest-stakes obligations for banks, covering credit-scoring and creditworthiness systems, were due August 2, 2026. They've since been pushed to December 2, 2027 under a Digital Omnibus agreement reached in May 2026.
That delay doesn't mean wait. It means the vendors worth shortlisting are the ones already building to the standard, not the ones relieved they have more runway.
This isn't another argument for why AI governance stalls at the architecture, what 120+ bank deployments reveal about AI governance failure and what 120+ bank deployments reveal about agentic AI compliance already make that case well. This is the specific DORA and EU AI Act checklist to run before a private bank signs an AI vendor contract, including the one regulatory delay that just changed what's urgent and what isn't.
What DORA already requires from any AI vendor, no delay attached
DORA has been live for over 18 months. If an AI system touches a critical or important function, the vendor providing it is an ICT third party under Chapter V, and your bank has to be able to show:
Ask any AI vendor for their Register of Information inputs before the contract, not after.
What the EU AI Act requires, and what changed in 2026
If a system evaluates creditworthiness or credit scoring, Annex III classifies it high-risk by default. The substantive obligations that follow from that classification, laid out in sequence across Articles 9 through 15, cover:
What changed: the deadline for these Annex III obligations moved from August 2, 2026 to December 2, 2027. What didn't change: the AI Office and Member State authorities began enforcement on August 2, 2026, and general transparency obligations for deployers are already live. A vendor who treats the 16-month extension as a reason to slow down is telling you something about how they'll treat the next deadline too.
The evaluation checklist
Before signing, ask for:
- Technical documentation mapped to Article 11, not a sales deck, an actual document a regulator could review
- A working audit trail, not a screenshot, an exportable record showing why a recommendation surfaced and what data fed it
- Enforced human oversight, meaning the system technically prevents an un-reviewed action from executing, not a procedural approval step someone can click through
- Their DORA third-party risk posture, including whether they'd be classified as supporting a critical or important function for your bank specifically
- Where the classification burden sits. If you fine-tune or substantially modify a vendor's model, you can assume the provider's compliance obligations yourself, that's worth knowing before deployment, not after
Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, citing unclear business value and inadequate risk controls as leading causes. A vendor that can't answer the five questions above is a candidate for that statistic, not an exception to it.
Why this matters more in private banking specifically
Private banking concentrates exactly the use cases Annex III flags: creditworthiness assessment for lending, and increasingly, AI-assisted advisory decisions that touch a client's financial position. The same governance gap shows up across wealth management generally: most vendors answer "what does this require" with clean data and a pilot, not with who decides what an AI system is allowed to surface before it reaches a relationship manager's screen. That's the DORA and AI Act question too, just asked earlier in the sales cycle instead of during an examination.
Frequently asked questions
How do regulators expect banks to audit and explain AI agent decisions?
Through an enforced record, not a retrospective explanation. Article 12 requires automatic logging throughout a high-risk system's lifecycle, and Article 14 requires human oversight built into the workflow, not added after a decision ships. Regulators expect to see why an action was authorized, not just that it happened.
What new security risks does agentic AI introduce, and how do you control them?
An agent that plans and executes multi-step work expands the attack surface beyond a single model output: prompt injection, unauthorized action chains, and excessive permissions all become live risks once a system can act, not just answer. Controlling for it means an authority layer that checks identity, policy, and evidence before every consequential action, not after.
Is Backbase DORA or EU AI Act compliant?
Backbase holds SOC 2 Type I certification scoped to the Banking OS's Connectivity layer, and SOC 2 Type II for Managed Hosting. Broader claims of DORA or EU AI Act compliance aren't something any vendor can honestly make on a client's behalf, compliance under both regimes is the deploying bank's obligation, informed by the evidence its vendors provide.
Further reading: What 120+ bank deployments reveal about AI governance failure Β· What 120+ bank deployments reveal about agentic AI compliance Β· AI in wealth management needs an authority layer, not a data checklist Β· Backbase Banking OS
