AI Rating in banking: which gate blocks the class, and why
The four dimensions read through a banking lens, the typical profile with Risk below threshold, the two gates that close most often, and what each class means in terms of decisions.
In short. In banking, AI Rating measures the same four dimensions as anywhere else, Readiness, Delivery, Risk and Confidence, and weighs them differently. Where elsewhere a weakness on Risk is an area to improve, here it is a gate that blocks: an organisation with Annex III systems and no inventory cannot rise above class C, however advanced it is on everything else. The useful output isn't the score, it's knowing which gate is closed and why.
Banks come to AI maturity measurement with one advantage and one disadvantage. The advantage is familiarity with rating systems: nobody needs an explanation of what a class or a non-compensable gate is. The disadvantage is the temptation to read the result as a grade, when it exists to decide where to intervene.
The four dimensions through a banking lens
Readiness measures preparation: strategy, data, skills, infrastructure. In banks it tends to be the highest dimension, because the data governance framework already exists for prudential reasons. The recurring weak point is the distance between data quality in risk systems and data quality in commercial processes, where many of the proposed use cases originate.
Delivery measures the ability to reach production and maintain: release processes, monitoring, integration. Banks divide sharply here. Those with a structured model lifecycle for credit risk start ahead; those who experimented with generative AI outside that perimeter find the pilot has none of the controls needed to go live.
Risk measures governance, compliance and ethics. It is the dimension that determines the class in banking more than any other, because Annex III systems raise the bar and because supervisory authorities are already present.
Confidence measures board commitment, user trust and perceived robustness. It is often high in statements and low in behaviour, and the gap shows when you ask who signed the last adoption decision and on what basis.
The gate that stops nearly everyone
In our assessments the typical banking profile is one: good Readiness and Confidence, acceptable Delivery, Risk below threshold. And since the gates are non-compensable, the final class falls to the level of the constraint rather than the average.
The gate that closes most often is the system inventory. Not for lack of will, but because in a bank AI systems arrived through three separate routes, none of which passes through a single point: models developed internally within risk functions, AI features switched on inside software already purchased, and tools adopted by individual departments.
The second gate concerns the role assumed. Almost every bank declares itself a deployer, and some no longer are: fine-tuning on proprietary data or changing a decision threshold can trigger Article 25 of the AI Act, with the obligations in Article 16. Until that field is verified system by system, the Risk dimension stays exposed.
What a class means in practice
| Class | Typical situation in a bank | What's reasonable to do |
|---|---|---|
| D | Systems in use unmapped, no formal controls | Pause new adoptions and build the inventory |
| C | Partial inventory, governance stated but not implemented | Close the gates before scaling onto core processes |
| B | Working framework, evidence in place, some areas exposed | Extend to high-risk processes and prepare for audit |
| A | Mature system verified across all dimensions | Reserved for verified assessments, not self-assessments |
On that last row it's worth being explicit: a self-assessment does not produce a class A, because that class presupposes a structured verification with checked evidence. A tool returning A on its own would devalue everyone else's result.
Which framework does your company actually need?
AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.
Start your AI RatingWhy measure before setting the budget
The link between rating and budget is direct. A bank in class C allocating budget to scale AI onto credit is paying twice: once for the project that won't clear the controls, and again to redo it once the gates are closed.
The same money, spent first on closing the gates, produces an organisation able to absorb subsequent projects without redoing them. This is why rating belongs at the start of the planning cycle rather than at the end, as a check on decisions already made.
What it takes to do properly
A useful assessment requires material that almost always exists in a bank, scattered across different functions: the list of AI systems in use or under evaluation, the model validation procedures already running in risk functions, training evidence linked to roles, contracts with model suppliers, and minutes of adoption decisions.
Gathering that material is half the work already, and on its own produces the picture many banks have never had in one place.
Where to start
The prerequisite is the AI system inventory, because without it the rating measures perceptions. From there you move to verifying the role for each system and to risk assessment.
The full model, with the four dimensions and the gate logic, is described on the AI Rating page. The sector's regulatory context, with the rules overlapping the AI Act, is on the AI governance for banks and financial services page.
For an assessment of your bank's position you can book a meeting or start the self-assessment.