What we are watching in this sector, and the research that touches it. This is the research view; the services view is on the industry page.
Whether a specific adverse decision can be explained to a specific customer, months later.
Whether the AI inventory was built to answer a cybersecurity control set as well as an AI framework.
Whether the model was tested on your own population or on somebody else’s benchmark.
Every obligation below is dated, named and externally imposed. Read them against what your organisation could evidence this week rather than against what it intends to build.
Migration off OTP; 24/7/365 fraud monitoring with device, location and behaviour analysis.
Formally approved post-quantum transition plans; automated cryptographic inventory; crypto-agility.
A migration plan resting on an inventory you can defend.
Documented pre-processing risk assessments, transparency notices, human-oversight design, and either certification or a named Autonomous Systems Officer.
Board and senior-management accountability for every AI system deployed; human oversight of high-impact decisions.
Statutory fraud-prevention capability, prompt breach reporting; criminal liability attaches to management negligence.
Private right of action including for distress; processors carry direct liability.
Governance, audit, third-party and cloud-provider controls.
Biometric identity proofing for licensed digital banks and payment service providers.
Participant migration inside a 15-month window.
Migration executed on critical systems.
Reproduced from the Orvix Financial services industry page. Last reviewed 26 August 2026.
The obligation that applies here, and the artefacts most firms in this sector do not hold.
Where organisations in this sector typically sit, and the one artefact that moves them up.
Ten statements. Three minutes. Nothing submitted.
The industry page sets out what we actually do in this sector and who delivers it.