Banking AI Security Audit

Banks use AI to grant credit, flag fraud and serve customers. Adversaries probe all three: applicants game scoring models, fraudsters adapt to detectors, chatbots face injection. An audit tests each under attack.

See the workflow →

Four Areas to Test

A sector audit covers each of these areas.

  • Scoring & credit
  • Fraud & AML
  • Customer assistants
  • Third parties & resilience

Core Concepts

The foundations of this sector's AI risk.

Why banking is different

Attackers are motivated by money and can iterate cheaply on live systems. Decisions are also regulated: they must be explainable and contestable.

  • Fraud models are attacked through evasion and fast-adapting patterns
  • Scoring models can be gamed, or extracted through repeated queries
  • Customer chatbots can be manipulated into disclosing data or taking actions

Regulatory frame

Banking AI falls under AI law, digital resilience and model risk management at once.

  • EU AI Act: creditworthiness assessment is high-risk (fraud detection is carved out)
  • DORA: ICT risk management and threat-led penetration testing for significant entities
  • GDPR Art. 22 on automated decisions; for model risk, guidance such as SR 11-7 in the US

The Audit Workflow

Each phase is methodical and repeatable.

Inventory models and vendors

List credit, fraud, AML and chatbot models, their data and every third-party provider.

Test decision models

Probe scoring and fraud models with adversarial and synthetic cases; test extraction by repeated queries; check bias and stability.

Red team customer-facing AI

Test chatbots and agents for prompt injection, data disclosure and unauthorized actions.

Report to risk and compliance

Feed results into model risk management, DORA testing programmes and AI Act documentation.

Related Pages

Deep dives into complementary topics.

AI Governance & EU AI Act

Obligations, controls, audit evidence.

Model Extraction & Privacy Attacks

Model theft, membership inference.

Prompt Injection Attacks

Direct, indirect and RAG injection.

AI Audit & Security Framework

Scope, method, evidence, report.