The complete regulatory compliance guide for LLMs in banking and fintech — DORA operational resilience requirements, MiFID II explainability obligations, FCA AI principles, SEC disclosure rules, and the exact AIZA-HexTyx controls that satisfy each.
Every major financial regulator — the ECB, FCA, SEC, OCC, and the EU collectively through DORA — issued substantive AI guidance between 2023 and 2025. Financial institutions deploying AI are not waiting for regulation to catch up; the regulation is already here, and enforcement is beginning. The specific challenge for AI teams in financial services is that the regulatory obligations are layered: a UK bank deploying an AI copilot with customer interaction capability must simultaneously satisfy FCA PS24/5 principles, MiFID II explainability requirements if the system influences investment decisions, DORA ICT risk management obligations, and GDPR Article 22 automated decision-making restrictions. These frameworks do not map neatly onto each other, and none of them was written with LLMs in mind.
This guide maps each framework to the specific AIZA-HexTyx controls that satisfy it, with the exact audit evidence artefacts auditors will request. The existing financial services AI security guide for deployment fundamentals: AI Security for Financial Services: LLM Compliance Guide →
DORA applies to virtually all financial entities operating in the EU — banks, investment firms, insurance companies, payment institutions, crypto-asset service providers — and creates binding requirements for ICT risk management, incident reporting, resilience testing, and third-party risk. LLM systems are ICT systems under DORA, and autonomous AI agents with operational authority are among the highest-risk ICT assets under the regulation.
Article 6 — ICT Risk Management Framework: Requires a comprehensive ICT risk management framework identifying, classifying, and documenting all ICT risks. For AI systems, this means: every LLM endpoint registered in the AI System Inventory with its risk tier (1-4 from the AIZA-HexTyx classification framework), its most recent HexTyx risk score, and the date of the last adversarial resilience test. DORA explicitly requires this framework to cover "risks arising from the use of artificial intelligence."
Article 10 — Detection: Requires "anomaly detection mechanisms" and "anomalous activity alert mechanisms." Aegis CP1-CP5 satisfies this directly: injection pattern detection, behavioral anomaly scoring via MultiTurnTracker, and SIEM webhook alerting for confirmed_leak and canary_exfiltration events. The audit evidence: GET /gateway/audit/stats showing anomaly detection is operational, plus SIEM webhook configuration documentation.
Article 11 — Response and Recovery: Requires documented incident response procedures for ICT-related incidents. The AI Incident Response Procedure (see SOC2 guide) maps directly here: confirmed_leak → immediate escalation, Dead Man's Switch → automated containment, calibration loop → post-incident detection update.
Article 25 — Advanced Testing (TLPT): Financial entities above specified thresholds must conduct threat-led penetration testing. For AI systems, TLPT increasingly includes adversarial AI testing. HexTyx's full 21-category scan with MITRE ATT&CK Navigator layer output is the documentation artefact for AI-specific TLPT coverage. POST /reports/generate with "formats": ["pdf", "mitre", "sarif"] produces the required evidence package.
Article 28-30 — Third-Party Risk: The Anthropic API used for AXIOM, the LLM evaluator, and the Playground proxy is an ICT third-party service provider under DORA. The Anthropic DPA and no-training attestation must be documented. DORA requires contractual guarantees from ICT third-party providers; verify these are current in your Anthropic agreement.
DORA's most important AI-specific implication: "operational resilience" now explicitly includes AI system resilience. A financial institution that cannot demonstrate that its AI systems have been adversarially tested, are actively monitored at runtime, and have documented incident response procedures for AI-specific failures is not DORA compliant — regardless of how strong its traditional ICT controls are.
MiFID II Article 17 requires investment firms using algorithmic trading to have systems and risk controls "appropriate to the business it operates." ESMA guidance issued in 2024 specifically addressed AI-driven investment decision support, requiring that AI recommendations to clients be explainable in terms a retail client can understand. This creates a direct obligation for any LLM used in investment advisory or order execution context.
Explainability obligation: AXIOM's reasoning traces in the AIZA-HexTyx assistant provide audit-trail explainability for AI-assisted decisions. Every conversation is logged in the immutable JSONL audit record with SHA-256 integrity hashing. For investment advisory AI, these records satisfy MiFID II's requirement that firms maintain records of all orders and decisions sufficient to enable regulatory reconstruction.
Algorithm governance: Any AI system that can influence order generation must be pre-approved, stress-tested, and subject to kill-switch controls. The HexTyx pre-deployment audit gate (fail-on-risk 70, fail-on-bypass 50%) is the stress-testing documentation. Aegis's Dead Man's Switch is the kill-switch mechanism. Both require documentation for MiFID II Article 17 purposes.
The FCA's 2024 AI principles (DP5/22 and subsequent PS24/5 guidance) established five high-level principles for AI in financial services: safety and security, accountability and governance, transparency and explainability, fairness, and market integrity. These are principles-based, not prescriptive — but the FCA has been explicit that it expects firms to demonstrate adherence through evidence, not assertions.
Safety and security principle: The FCA expects firms to demonstrate that AI systems are protected against adversarial attacks and that runtime monitoring is in place. HexTyx scan output (with bypass rates below 15% per strategy) and Aegis audit log showing continuous monitoring are the evidence artefacts. The FCA has specifically referenced prompt injection as a safety concern in supervisory communications.
Accountability and governance principle: Named accountability for AI systems at senior management level. The AI Governance Policy with named CISO ownership and documented board reporting cadence satisfies this. FCA expects this to map to SM&CR (Senior Managers and Certification Regime) accountability for firms in scope.
Transparency principle: Customer-facing AI must be identifiable as AI, and the basis for AI decisions must be explainable. Aegis audit logs + AXIOM reasoning traces provide the technical audit trail. Customer disclosure requirements must be addressed in product terms separately.
The SEC's 2024 guidance on AI use by registered investment advisers (under the Investment Advisers Act) and broker-dealers requires: disclosure to clients when AI materially influences investment decisions, documentation of AI systems in Form ADV, and prohibition of "AI washing" — misrepresenting the role or capabilities of AI in the firm's services.
Material AI influence disclosure: Any LLM system that influences portfolio construction, trade recommendations, or client communications in a material way must be disclosed. The AI System Inventory (required for SOC2 and DORA) serves as the underlying documentation for SEC disclosure purposes — it identifies which AI systems are in scope for material influence classification.
Books and records: SEC Rule 17a-4 requires electronic records to be retained in a non-rewriteable, non-erasable format. The Aegis audit log's tamper-evident SHA-256 per-record integrity hashing supports this requirement. Zero-retention mode configuration and retention policy documentation (GET /gateway/audit/config) provide the evidence.
The agentic runtime governance controls that operate across all four regulatory frameworks at runtime: AI Autonomous Agentic Runtime Governance: Complete Enterprise Control Guide →
The AI audit readiness framework that underpins DORA Art. 25 TLPT and FCA safety evidence: AI Audit: Is Your LLM System Ready? Complete 2026 Enterprise Guide →
All four frameworks require overlapping evidence. Generate once, satisfy all four:
GET /gateway/audit/export?format=csv) (DORA Art. 10, MiFID II records, FCA safety, SEC 17a-4)POST /reports/generate) (DORA Art. 25 TLPT, FCA safety, SEC documentation)GET /gateway/calibration/history) (DORA Art. 11, FCA safety, NCA governance)The EU AI Act compliance guide that covers obligations beyond financial services regulation: EU AI Act Requirements & Checklist: Complete Enterprise Compliance Guide →
The NIST AI RMF implementation that provides the US governance framework complement: NIST AI RMF Implementation: Complete Enterprise Checklist →
Run a HexTyx scan and generate the complete evidence package — MITRE layer, SARIF, audit log export, and compliance gap analysis mapped to DORA, MiFID II, FCA, and SEC requirements.
Generate Financial Compliance Evidence →