Saidot Library
Product
Insights
EU AI Act
PricingAbout
Log in
Get started
ProductInsightsEU AI ActAboutPricingLog in
Saidot Library

What the European Central Bank expects from your AI governance from inventory to audit readiness

The European Central Bank (ECB) has been watching how banks use AI for years. In 2025, it started also collecting data.

In November 2025, the European Central Bank’s (ECB) Banking Supervision elevated AI-related strategies, governance, and risk management from Priority 3 in its 2025–2027 supervisory cycle to Priority 2 in its 2026–2028 cycle, placing them alongside operational resilience as core supervisory focuses.  

In 2025, the ECB also intensified its monitoring by beginning to collect data directly from supervised banks on their use of AI and generative AI.

By reading this article, you will learn:

  1. Why the ECB escalated AI governance and what triggered it
  2. What supervisors look for in AI system inventories
  3. What on-site inspections assess
  4. How the Three Lines Model applies to AI governance
  5. What audit-ready AI governance looks like in practice

1. The ECB escalation: from background topic to supervisory priority

In December 2024, the ECB published its SSM Supervisory Priorities for 2025–2027. AI and emerging technology risks sat under Priority 3: a relevant concern, but behind macro-financial resilience and remediation of persistent material shortcomings.

A year later, the SSM Supervisory Priorities for 2026–2028 moved AI governance to Priority 2, under operational resilience and ICT capabilities. The ECB stated it will "step up its effort to engage with banks on how they use new technologies, and in particular AI, to exploit the potential gains while also being aware of the associated risks."

What triggered this escalation? ECB supervisory data from 2024–2025 revealed a sharp increase in AI adoption across supervised banks. The ECB's SSM Newsletter from November 2025 reported that AI use cases, particularly in credit scoring and fraud detection, grew significantly between 2023 and 2024.

The adoption outpaced governance readiness. While about half of banks in the ECB's sample have introduced dedicated AI governance policies or committees, the other half have not. And policies alone do not equal operational governance: the ECB is looking for something more structured.

2. What is the ECB looking for in AI system inventories?

You cannot govern AI use cases that you don't know exist — that’s the ECB's starting point.

AI system inventories have been a recurring theme in ECB supervisory reviews, targeted inspections, and on-site examinations since 2024. The ECB expects banks to maintain a complete, living register of all AI systems in use across the organisation, including third-party AI embedded in vendor products.

Banks often maintain inventories of statistical models used in credit risk or market risk, but that’s not enough. These registers do not capture the full picture. Many AI systems involve multiple models, datasets, third-party products, and integrations.  

A customer chatbot built on Azure OpenAI, for example, inherits risks from the underlying AI model, the cloud platform, the data it accesses, and the prompts it uses. A model register captures just one layer: AI governance requires visibility across all of them.

Based on the ECB's supervisory findings and established AI governance best practices, we at Saidot believe a strong AI inventory should cover four dimensions:

  • Completeness. All AI systems documented, including generative AI tools and AI embedded in third-party software.
  • Risk classification. Each system assessed against the EU AI Act risk categories (prohibited, high, limited, minimal) and the bank's own business impact criteria. Classification must be consistent across teams and systems.
  • Clear ownership. Every AI system has a named accountable owner. Ownership is documented and visible to second and third-line functions.
  • Lifecycle tracking. Systems move through stages from initiation through design and development, verification and validation, deployment, operation and monitoring, re-evaluation, and eventual retirement. The inventory should track each AI system’s lifecycle, with governance activities mapped to each stage.

The ECB's November 2025 newsletter noted that some banks are already conducting self-assessments to identify high-risk AI use cases and mapping AI models across their organisations.

3. What do supervisors assess in on-site inspections?

ECB on-site inspections of AI governance have been running since 2022, with a fourth consecutive year of targeted digital transformation reviews in 2025.

The on-site inspections to assess risks, internal controls, business models, and governance at supervised banks. These inspections are carried out by the ECB and national supervisory authorities within a predefined scope and timeframe, at the bank's premises. They are risk-based, proportionate, and forward-looking, designed to produce concrete findings and follow-up actions, not general observations.

Based on ECB SSM Newsletter (November 2025) findings from on-site inspections and targeted reviews, supplemented by established best practices and legal requirements, here’s what you should also have ready for inspections:

Explainability tools. Banks using AI for credit scoring or fraud detection must be able to explain model outputs to management. The ECB has observed that most banks in its sample use explainability tools to monitor model performance. Black-box AI models that cannot be explained to senior management are a supervisory red flag.

Governance policies and structures. Supervisors check whether the bank has a formal AI governance policy, a dedicated AI governance committee or function, and documented processes for registering, classifying, and reviewing AI systems. About half of ECB-supervised banks now have these in place. The other half face increasingly pointed supervisory questions.

Risk management integration. AI governance cannot operate as a standalone function. It should be integrated into the bank's broader enterprise risk management framework. Risk and compliance functions need to be able to evaluate, oversee, and audit AI use. So, governance cannot be left to the first line of defence (development and AI teams) alone.

Second and third-line capability. Can your risk function challenge AI model decisions? Can your internal audit function conduct an independent assessment of AI governance? The skills gap in second and third-line functions remains one of the most persistent weaknesses organisations encounter.

4. How to apply the Three Lines Model to AI governance?

The Institute of Internal Auditors’ (IIA) Three Lines Model is the standard governance structure in European banking. Applying it to AI requires adapting each line's responsibilities to the specific characteristics of AI systems.

First line: management (business and AI teams). This includes people who build, provide, and operate AI systems. They are responsible for the design and operation of processes, system-level governance, registering systems in the inventory, risk management, documenting intended use, selecting risk treatment strategies and controls, and ensuring human oversight is in place. The first line ownership is where governance starts.

Second line: risk, compliance, and legal. The people who establish policies and practices, provide specialised expertise, support, monitoring, and challenge the first line to enhance risk management, compliance, and control practices. For AI governance, this means defining risk appetite for AI use cases, establishing risk classification criteria, reviewing first-line risk assessments, monitoring compliance with internal policies and external regulations (e.g. EU AI Act, DORA, GDPR), and escalating issues to the governing body. The second line needs enough AI/ML literacy to challenge model design decisions and risk assessments meaningfully.

Third line: internal audit. The internal auditors deliver independent and objective assurance. They evaluate whether the AI governance framework works as intended and assess inventory completeness, risk classification consistency, documentation quality, control status, and review histories. The third line reports directly to the governing body. For AI governance, the challenge is that most internal audit functions lack the technical expertise to audit AI/ML systems.

Governing body: board and executive leadership. They are accountable for the AI governance framework and the lines, ensuring adequate resources are allocated, oversight structures are functioning, and AI risk exposure is understood at the executive level. McKinsey's State of AI report (March 2025) found that CEO-level oversight of AI governance is one element most correlated with higher bottom-line impact from generative AI.

Sources: AI Governance Handbook by Saidot, Version 1.2 (March 2026); Statement of Position: The Three Lines Model by The Institute of Internal Auditors.

5. How to make your AI governance ready for audit

Audit readiness means an internal auditor or ECB inspector can trace a clear governance trail from any AI system back through its risk assessment, controls, and sign-offs without relying on the system owner to narrate the story.

The governance trail follows a documented sequence:

System registration. The AI system is registered in a centralised inventory with its intended purpose, lifecycle stage, system type, risk classification, and accountable owner. Components (models, datasets, third-party products) are linked to the system record.

Risk assessment. Risks are identified from multiple sources: curated risk libraries, risks inherited from linked third-party models and products, and custom risks identified by the system owner. Each risk is evaluated for inherent severity and assigned a treatment strategy: accept, treat, or avoid.

Control assignment. For risks being treated, specific controls are assigned with documented ownership and evidence of status. Controls can come from your organisation's control catalogue or from curated best-practice libraries.

Review and sign-off. Formal reviews are conducted at key lifecycle transitions, before deployment, at scheduled re-evaluation points, and when significant changes occur. Reviews are scoped, assigned to designated reviewers (including second and third-line stakeholders), and marked as complete with documented outcomes.

Continuous monitoring. Governance does not end at deployment. Risk profiles change as models are updated, vendor terms shift, or new regulatory guidance emerges. Audit-ready governance means the system record stays current, reflecting the system as it operates today, not as it was documented months ago.

This process works when it’s embedded in a platform that connects all the pieces. When risk assessments, controls, reviews, and evidence is stored in disconnected spreadsheets and documents, the governance trail fragments, auditors find inconsistencies, sign-offs go missing, and documentation lags behind reality.

How Saidot helps you get audit-ready

Saidot Governance provides a centralised AI inventory where every system is documented with its components, lifecycle stage, risk classification, and ownership, matching exactly what the ECB expects to see.

Saidot Graph connects each system to its underlying models, agents, datasets, and third-party products. When you link a system to a model in Azure OpenAI or Amazon Bedrock, for example, risks identified in Saidot Library are inherited automatically — and you don’t need to do any manual research or information re-entry to any other platform. Saidot Library contains 260+ AI-related risks and 620+ controls, curated by governance and AI safety experts.

Risk classification can be set manually or inherited automatically from the system's components, so the highest-risk component determines the system's overall risk level. This matches the EU AI Act's risk-based approach and ensures consistent classification across your organisation.

Saidot's Review feature lets you plan, assign, and complete formal governance reviews with scoped assessment criteria, designated reviewers, and documented outcomes, creating the audit trail that internal auditors and ECB inspectors can follow.

The Control Catalogue connects controls to the risks they address and the policies they enforce, with coverage metrics that show you exactly where gaps remain.

You don't want another tool where we re-enter information that exists on other platforms. Saidot integrates with Azure AI Foundry and Amazon Bedrock to sync deployed systems and models directly into your governance inventory. No manual entry. No stale documentation.

Sign up for an on-demand demo to see the platform in action →

Frequently asked questions

Is the ECB examining AI governance at banks? Yes. The ECB elevated AI governance to Priority 2 in its 2026–2028 supervisory cycle (published November 2025) and has intensified data collection on AI and generative AI use at supervised banks. On-site inspections of banks' digital transformation strategies, including AI governance, have run since 2022.

What does the ECB expect from an AI system inventory? The ECB expects a complete, living register of all AI systems, including third-party AI, generative AI tools, and AI embedded in vendor products. Each system should have a risk classification, a named owner, lifecycle tracking, and linked components (models, datasets, products). A model register alone does not meet the expectation.

How does the IIA’s Three Lines Model apply to AI? The first line (AI and business teams) owns system-level governance. The second line (risk, compliance, legal) sets policies and challenges the first line. The third line (internal audit) provides independent assurance. The ECB has emphasised that governance cannot be left to the first line alone: second and third-line capability is a supervisory expectation.

What does audit-ready AI governance look like? An internal auditor or supervisor can trace a clear trail from any AI system through its risk assessment, control assignment, and review sign-off without relying on the system owner to explain it. This requires centralised documentation, consistent risk classification, assigned controls with evidence, and formal review records.

When do banks need to comply with the EU AI Act's high-risk obligations? The EU AI Act classifies credit scoring and insurance pricing AI as high-risk under Annex III. Full obligations for high-risk AI systems apply from Dec 2, 2027. DORA's ICT risk management requirements, which cover AI systems, have been fully applicable since January 2025.


Sources:

  • ECB (December 2024). "SSM Supervisory Priorities 2025–2027." https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202412~6f69ad032f.en.html
  • ECB (November 2025). "SSM Supervisory Priorities 2026–2028." https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html
  • ECB (November 2025). "AI's impact on banking: credit scoring and fraud detection" (SSM Newsletter). https://www.bankingsupervision.europa.eu/press/supervisory-newsletters/newsletter/2025/html/ssm.nl251120_1.en.html
  • ECB (October 2025). Speech: "Artificial intelligence and supervision: innovation with caution." https://www.bankingsupervision.europa.eu/press/speeches/date/2025/html/ssm.sp251014~5bc6e60334.en.html
  • McKinsey (March 2025). "The State of AI." https://www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/the%20state%20of%20ai/2025/the-state-of-ai-how-organizations-are-rewiring-to-capture-value_final.pdf
  • The Institute of Internal Affairs (2026): “Statement of Position: Three Lines Model — Assurance and Advice in Support of Effective Governance.”  
    https://www.theiia.org/globalassets/site/resources/statements-of-position/tlm_assurance_advice_support_effective_gov_en.pdf

‍

This blog was generated by AI, but proofpread, fact-checked and edited by experts.

More Insights

What is agent-first AI governance, and why is it a must in 2026?

The 14 most common AI agent risks — and controls to mitigate them

Vivicta and Saidot join forces to address AI governance and accelerate responsible AI adoption

Get started with responsible AI governance.

Book intro
Saidot Library
hello@saidot.ai
sales@saidot.ai
+358 407725010
Saidot Ltd.
Lapinlahdenkatu 16
00180 Helsinki, Finland
Terms of ServicePrivacy PolicyCookie PolicyAI Policy

Product

Insights

EU AI Act

On-demand demo

About us

Get started

Book intro

EU AI Act Classifier

AI Governance Maturity Calculator

Help

Log in

Get Saidot on Microsoft Azure Marketplace

Saidot's Information Security Management System (ISMS) is ISO/IEC 27001:2022 certified. Certification body: Prescient Security.
© 2026 Saidot Ltd. All rights reserved