Turning AI Act obligations into everyday governance

Introduction

Our client is a Belgian bank and insurer serving millions of retail and business clients. As a systemically important financial institution, it operates under overlapping regulatory frameworks and the EU AI Act added a new layer of obligation that couldn't be absorbed through existing compliance routines.

Client

Belgian Bank

Client since

Technologies

No items found.
No items found.

The problem

Our client had AI systems in use across the business but no consistent framework to assess what those systems were, how risky they were, or what the EU AI Act required of them. The gap wasn't awareness. It was operationalisation: turning a 100-article regulation into repeatable decisions, concrete controls, and audit-ready documentation. Without that, every AI use case was a governance blind spot.

DTA walked into an environment where AI use cases were already in production and regulatory obligations were starting to crystallise. The challenge was building governance that could handle both: structured enough to satisfy regulators, practical enough for teams to actually use.

How we solved it

Map and classify the AI landscape

DTA developed a structured approach to identify AI use cases across the organisation, determine their regulatory classification under the EU AI Act, and assess the risks and obligations attached to each. This gave our client a clear picture of its exposure, use case by use case, for the first time.

Translate obligations into controls and documentation

DTA converted regulatory requirements into concrete controls and documentation standards covering the full AI lifecycle: data management, model validation, human oversight, risk management, and record keeping. Relevant stakeholders got clear, role-specific guidance on what was expected of them and why.

Build post-market monitoring into the governance model

DTA established an ongoing oversight framework for AI systems after deployment. The bank can now track performance, risks, and compliance continuously, not just at go-live. Governance doesn't stop when a system launches; it adapts as the system changes.

The results

Our client now has a working governance system, not a policy document, but a live process that handles AI use cases from first assessment through ongoing oversight.

A repeatable governance process across the full AI lifecycle

The bank can now assess and govern AI use cases from initial classification through ongoing oversight, with defined requirements at every stage. The process works for new use cases and retrospective reviews.

Consistent, defensible decision-making on AI classification

Teams across the organisation apply the same classification logic to every AI use case. Decisions are traceable, documented, and auditable, exactly what regulators will look for.

Clear documentation and evidence standards for all stakeholders

Each role in the AI lifecycle now has explicit expectations around documentation and controls. There's no ambiguity about what "compliant" looks like for a given system.

Key Learnings

Three things we'd carry into every AI governance engagement from here.

Classify first, govern second

Without a reliable classification of each system's risk profile, governance efforts scatter. A structured assessment framework is the foundation everything else builds on.

Policy Only Fails

Governance that lives only in policy documents fails. Effective AI governance requires clear ownership and active oversight, controls embedded in workflows, not left as standalone documentation obligations.

Post-deployment

Post-deployment is where most governance breaks down. Organisations focus compliance effort on pre-launch. The harder problem is maintaining oversight as AI systems drift, get retrained, or change scope. Building monitoring in from the start prevents the gap from opening.

Degroof Petercam

From fragmented controls to scalable regulatory data quality

Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.

Mega

Managing GDPR compliance across a complex stakeholder landscape

Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

LM Oost-Vlaanderen

From regulatory scrutiny to demonstrated compliance

LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.