DNA Advisory · AI Governance Benchmark

Financial Services
AI Governance Readiness

Banking, insurance, and capital markets face the highest regulatory urgency for AI governance. This benchmark — measured against ISO 42001, the international standard for AI management systems — reveals where the industry stands and where the gaps are hiding.

Read the Analysis ↓
0
Industry Average
0%
Small (<200)
0%
Medium
0%
Large (1000+)
00 — URGENCY
The Clock Is Ticking
Four major regulatory deadlines are converging on financial services simultaneously — creating the most urgent AI governance compliance window the industry has ever faced. Every day without a structured governance framework increases exposure to penalties, lost deals, and reputational risk.
Days Until EU AI Act
High-risk obligations · Aug 2, 2026
LIVE
DORA
Fully applicable since Jan 2025
KSA PDPL
Full enforcement · Sep 2025
ACTIVE
ADGM / DIFC
AI governance guidance in effect
01 — EXECUTIVE SUMMARY
The Financial Services AI Governance Gap

AI governance has become a regulatory and competitive imperative for financial services. With the EU AI Act classifying credit scoring and insurance pricing as high-risk AI, and regulators across the GCC mandating governance frameworks, banks and insurers can no longer treat AI oversight as optional.

Yet most financial institutions lack a structured AI governance framework. When measured against ISO 42001 — the international standard for AI management systems and the most comprehensive certifiable framework available — the industry averages 46% readiness. That's the highest of any sector, reflecting decades of compliance culture, but still materially short of the 70–75% threshold required to pursue certification with confidence.

The gap isn't awareness — it's structure. Most institutions have AI policies, ethics committees, and model risk functions. What they lack is a unified management system that ties leadership accountability, risk planning, operational controls, and continuous improvement together in an auditable framework. That's precisely what ISO 42001 provides.

€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
15–50
AI Models in Production
Typical mid-size bank
3–6
Months to Cert-Ready
With DNA advisory & platform
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations. Understanding the full landscape is essential before choosing a path, and helps explain why ISO 42001 has emerged as the leading certifiable option for organizations serious about structured AI governance.
ApproachWhat It IsStrengthsLimitations
Internal AI Policies Self-defined governance frameworks developed in-house Flexible, quick to implement, tailored to organization No external validation, inconsistent across teams, not recognized by regulators or clients as proof of governance
EU AI Act Compliance Meeting requirements of Regulation 2024/1689 Mandatory in EU, clear penalties create urgency, detailed requirements for high-risk AI Jurisdiction-specific, not certifiable, reactive (compliance ≠ governance), doesn't cover full management lifecycle
NIST AI RMF 1.0 Voluntary US framework: GOVERN, MAP, MEASURE, MANAGE functions
Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001 concepts Voluntary only — no certification, no audit mechanism, US-centric, no enforcement
IEEE Ethically Aligned Design Ethics-focused standards for autonomous systems
Source: IEEE P7000 series
Strong on fairness, transparency, and human rights Narrow scope (ethics, not full governance), not widely adopted, not a management system
Industry-Specific Frameworks Basel Committee (banking), FDA (medical AI), EBA Guidelines (EU banking)
Source: BCBS d/575 (May 2024), EBA GL on ML for IRB
Deep domain expertise, regulatory weight in specific sectors Siloed — doesn't transfer across industries, can't certify against them, doesn't cover full AI governance
ISO/IEC 42001:2023 International standard for AI Management Systems (AIMS)
Source: ISO/IEC 42001:2023, published December 2023
Certifiable by accredited bodies worldwide. Covers full lifecycle (Clauses 4–10 + 39 Annex A controls). Compatible with ISO 27001/9001. Satisfies multiple regulations simultaneously. Continuous improvement built in. Relatively new (27 months old). Certification body capacity still scaling. Requires genuine organizational commitment.
03 — WHY ISO 42001
The Case for ISO 42001
ISO 42001 is not the only approach to AI governance — but for organizations seeking a structured, certifiable, and internationally recognized framework that covers the full AI lifecycle from leadership accountability through operational controls to continuous improvement, it is the strongest available option. Here's why it stands apart from other approaches.
The Only Certifiable AI Framework
You cannot get a certificate for NIST AI RMF compliance. You cannot certify against the EU AI Act. ISO 42001 is the only AI governance framework where an accredited third-party auditor can verify your implementation and issue an internationally recognized certificate. Certificates are proof — and proof is what regulators, clients, and boards demand.
Source: ISO/IEC 42001:2023, Clause 1 — Scope. Certification per ISO/IEC 17021-1.
A Management System, Not a Checklist
ISO 42001 follows the Annex SL management system structure used by ISO 27001, ISO 9001, and ISO 14001. It covers leadership commitment (Cl.5), risk planning (Cl.6), operational controls (Cl.8), performance measurement (Cl.9), and continuous improvement (Cl.10). It doesn't say "do these 10 things" — it says "build a system that governs AI across your entire organization."
Source: ISO/IEC 42001:2023 follows the ISO Harmonized Structure (Annex SL) for management system standards.
The Regulatory Multiplier
A single ISO 42001 implementation addresses requirements across the EU AI Act (risk management, transparency, human oversight), DORA (ICT risk for AI), Basel supervisory expectations, ADGM Responsible AI Guidance, and SAMA AI Guidelines. Instead of five separate compliance projects, organizations can build one governance system that satisfies the majority of overlapping requirements.
Source: EU AI Act Recital 40 references harmonized standards; ISO 42001 submitted for harmonization under the EU AI Act framework.
Compatible with Existing ISO Systems
Organizations already certified to ISO 27001 (information security) or ISO 9001 (quality) can integrate ISO 42001 into their existing management system. The shared Annex SL structure means common elements — context analysis, leadership, risk management, internal audit, management review — need only be extended, not rebuilt. ISO estimates that organizations with existing ISO certifications can reduce implementation effort by 30–40%.
Source: ISO Annex SL harmonized structure; ISO/IEC 42001:2023 Annex D (informative) on relationship to other standards.
39 Controls Across the Full AI Lifecycle
Annex A provides 39 specific controls covering data governance (A.4), transparency (A.5), accountability (A.6), bias and fairness (A.7), reliability (A.8), security (A.9), privacy (A.10), human oversight (A.11), documentation (A.12), and third-party AI management (A.13). No other framework provides this breadth of AI-specific controls in a single, auditable structure.
Source: ISO/IEC 42001:2023, Annex A — Reference control objectives and controls.
What ISO 42001 Does Not Cover
Jurisdiction-specific compliance. ISO 42001 is a governance framework, not a legal compliance tool. Organizations must still address EU AI Act conformity assessments, GDPR DPIAs, and local regulatory filings separately — though ISO 42001 provides the foundation.
Technical AI safety. The standard covers governance and management of AI risks, but does not prescribe specific technical solutions for model testing, adversarial robustness, or algorithmic fairness. Organizations must select appropriate technical approaches within the governance framework.
Our position: ISO 42001 is not a silver bullet — no single framework can solve AI governance in isolation. But for organizations seeking a structured, certifiable, internationally recognized starting point that addresses the majority of converging regulatory requirements, it is the strongest option available today. The benchmarks in this report measure readiness against this standard specifically.
The Benchmark
The industry averages 46% readiness.
The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How financial services organizations score across each of the 7 mandatory ISO 42001 management system clauses — from context and leadership through planning, support, and operations to performance evaluation and improvement. Scores reflect the degree to which current industry practices align with each clause's specific requirements. Click any clause to see the detailed analysis, key gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and industry-specific compliance infrastructure patterns across banking, insurance, and capital markets.
05 — ANNEX A CONTROLS
Control Maturity by Domain
ISO 42001 Annex A defines 39 controls across 12 groups, which we organize into 5 operational domains for clarity. Each domain is scored on a 1–5 maturity scale based on typical implementation patterns observed across banking, insurance, and capital markets organizations. The industry's deepest vulnerability — third-party AI governance at just 1.5/5.0 maturity — stands out immediately and represents the most urgent area for remediation in any financial services AI governance programme.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and industry-specific control implementation analysis across banking, insurance, and capital markets.
06 — CRITICAL GAPS
Top 5 Gaps in Financial Services
The most significant AI governance gaps we consistently identify across banking, insurance, and capital markets organizations — ranked by severity, with ISO 42001 clause references and estimated remediation timelines for each.
07 — REGULATORY LANDSCAPE
Financial Services AI Regulations
A comprehensive reference of every regulation affecting AI governance in financial services — current status, enforcement dates, penalty structures, and the specific impact on banking, insurance, and capital markets operations. Use this as a quick reference when assessing your organization's regulatory exposure.
RegulationJurisdictionStatusPenaltiesImpact on BanksISO 42001 Alignment
EU AI ActEU/EEAHigh-risk: Aug 2026€35M / 7%Credit scoring & insurance = high-risk. Mandatory conformity assessment.Cl.6 · Cl.8 · A.5 · A.7 · A.11
DORAEU/EEALive since Jan 2025€10M / 5%ICT risk including AI. Third-party AI provider oversight.Cl.8 · A.8 · A.9 · A.13
GDPREU/EEAIn force€20M / 4%Art. 22: Automated decision-making rights. DPIAs for AI.A.4 · A.10 · A.12
Basel CommitteeGlobalGuidance (2024)Supervisory measuresAI/ML model risk as supervisory priority.Cl.6 · Cl.9 · A.3 · A.8
ADGM AI GuidanceAbu DhabiActiveFSRA actionTransparency, fairness, accountability for ADGM firms.A.5 · A.6 · A.7
DIFC DPLDubaiIn force$100K/violationGDPR-aligned. Automated decision-making provisions.A.4 · A.10
SAMA GuidelinesSaudi ArabiaPublishedRegulatory sanctionsAI governance for SAMA-supervised entities.Cl.5 · Cl.6 · A.11
KSA PDPLSaudi ArabiaFull: Sep 2025SAR 5MData protection + AI processing requirements.A.4 · A.9 · A.10
The regulatory multiplier: Every regulation in the table above maps to specific ISO 42001 clauses and controls. This is what makes ISO 42001 a regulatory multiplier — a single governance framework that addresses the overlapping requirements of multiple regulatory regimes simultaneously. Organizations that certify to ISO 42001 build the evidence base, documentation, and operational controls that satisfy the core governance expectations across all applicable jurisdictions.
08 — METHODOLOGY
How This Benchmark Was Built
Scores were derived by mapping each ISO 42001 clause requirement against known industry practices, regulatory compliance maturity data from ISO Survey certifications, and published AI governance maturity research. Each clause score reflects the estimated degree to which organizations of that size typically demonstrate alignment with the clause's specific requirements, adjusted for industry-specific factors such as regulatory pressure, existing compliance infrastructure, and AI deployment maturity.
Data Sources
  • ISO Survey of Management System Certifications (2019–2024)
  • EU AI Act (Regulation 2024/1689) — Articles 6–72, Annex III
  • Basel Committee BCBS d/575 (May 2024)
  • DORA (Regulation 2022/2554)
  • Regional frameworks: ADGM, DIFC, SAMA, SDAIA
  • NIST AI RMF 1.0 (January 2023)
Important Caveats
  • ISO 42001 published December 2023 — all industries are in early adoption
  • Scores are directional — 45% ≠ "45% of requirements met"
  • Organization size is a proxy, not deterministic
  • Financial services leads other industries due to compliance culture
  • Certification typically requires 70–75% readiness to engage and 80–85% to certify
  • These benchmarks will be updated as the market matures
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates

Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.

He is a transformation leader specializing in governance, large-scale change, and AI-driven operating models, with over 20 years of experience across North America, Europe, and the GCC. He has led complex transformation and M&A initiatives across banking, supply chain, retail, and the public sector — working both as a strategic advisor and as an internal transformation leader.

He has advised members of parliament from more than 20 Commonwealth countries on technology and governance strategy, and teaches emerging technologies at leading international universities. He holds an AI Strategy and Leadership certification from MIT and is currently pursuing Applied Agentic AI for Organizational Transformation (MIT, expected May 2026).

He is the founder of Digital North Associates, an AI governance and transformation firm focused on enabling organizations to operate at machine speed while maintaining control through policy-driven governance. The firm transitioned to an AI-first model in March 2026, with a clear principle: keep humans at the core, using AI to amplify expertise rather than replace it.

Under his leadership, DNA is on track to become a fully AI-augmented organization by May 2026, with intelligent systems embedded across sales, marketing, advisory, operations, delivery, and finance.

Mike Merdinian
Managing Partner · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology
© 2026 Digital North Associates. All rights reserved. Distribution requires written permission.
Where does your organization stand? Take the free ISO 42001 assessment — 15 minutes, no commitment.
Take Free Assessment