Illustrative mapping for compliance and onboarding teams — not legal advice.
Social scoring for client reliability or AML risk
Unacceptable riskScoring based on general behaviour, political views, or lifestyle rather than strictly financial or AML-relevant data.
Art. 5(1)(c) prohibits social scoring that leads to unjustified or disproportionate treatment. A financial-reliability score built on non-financial behaviour falls in this category.
Creditworthiness and insurance pricing AI
High riskModels that evaluate creditworthiness or price life and health insurance.
Annex III §5(b)(c) explicitly lists credit scoring and insurance pricing as high-risk — conformity assessment, documentation, and oversight apply from the Annex III application date.
Fraud detection (distinct from credit scoring)
Minimal riskTransaction or application fraud detection that does not determine creditworthiness or insurance terms.
Annex III §5 carves out fraud detection from the credit-scoring high-risk category. Other law (AML, consumer credit, GDPR) may still apply, but not this Annex III bucket.
Formal document completeness checks
Minimal riskVerifying required fields are present and documents meet format rules — without assessing content or making risk decisions.
Rule-based or AI-assisted formal validation that does not materially influence access to essential services is typically minimal risk. Risk rises once the system scores or decides eligibility.
Transaction monitoring and anomaly detection
Minimal riskML models that flag unusual patterns, reduce false positives, or prioritise alerts for AML analysts.
AML transaction monitoring is not listed in Annex III. Deployers still need vendor due diligence, GDPR/DPIA where personal data is processed, and AML governance — but not automatic high-risk AI Act conformity for the monitoring layer itself.
Remote biometric identity verification (KYC onboarding)
High riskFacial matching or liveness checks to verify identity during remote customer onboarding.
Remote biometric identification and categorisation are high-risk under Annex III §1 (subject to strict conditions). Real-time identification in public spaces is separately restricted under Art. 5.
OCR / NLP for KYC document extraction
Minimal riskExtracting and structuring data from identity documents or corporate filings.
Data extraction without automated eligibility or risk decisions is usually minimal risk. If outputs feed high-risk scoring or biometric matching, classify the downstream system instead.
Client-facing AML or support chatbots
Limited riskAI that interacts with customers without making high-risk eligibility decisions.
Art. 50 requires users to know they are interacting with AI. Limited-risk transparency duties apply even when the underlying AML process is not Annex III high-risk.