GDPR and NIS2 documentation for your fintech clients
Fintech clients: GDPR, NIS2 scope and credit-scoring AI
Payments, lending and financial software bring more than GDPR: whether NIS2 reaches the client, and whether a scoring model is high risk under the AI Act. Each is suggested with the reason, and you decide.
Is NIS2 in play?
Banking and financial market infrastructure are Annex I sectors. Where DORA applies to a financial entity, it takes precedence over NIS2's security and reporting rules (NIS2, Article 4), so the scope check is where this starts.
Credit scoring under the AI Act
Creditworthiness assessment and credit scoring of individuals are listed as high risk in Annex III. The AI inventory records each system and suggests its category for you to confirm.
Vendors that handle the money
Payment and banking providers come from the registry with their legal entities and DPA links, and the subprocessor list follows the client's actual vendors.
The pack for a client like this
With GDPR, NIS2, EU AI Act enabled. NIS2 and the AI Act are add-on modules, enabled per client once you confirm they apply.
- Privacy policy
- Cookie policy
- Data processing agreement
- Subprocessor list
- Records of processing activities
- Retention schedule
- Data subject request procedure
- Access control policy
- Incident response policy
- Business continuity and disaster recovery policy
- Secure development policy
- Vendor management policy
- Acceptable use policy
- Security overview
- AI system inventory
- AI technical documentation
- AI risk assessment
- Fundamental rights impact assessment
- AI human oversight procedure
- AI literacy policy
- AI contract clauses
- AI logging policy
- NIS2 cybersecurity risk-management policy
- NIS2 incident reporting procedure
- NIS2 supply chain security policy
- NIS2 business continuity and crisis management plan
- NIS2 management accountability record
- NIS2 asset and supplier register
Not covered
Said here rather than found out later.
- DORA itself: its ICT risk framework, register of information and incident reporting
- PCI DSS
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.