exact.works
HomeTrust CenterFinancial Services
Trust Center/Financial Services
SCHEDULE F ACTIVE

Financial Services Compliance

How SAISA Schedule F writes DORA, MiFID II and EU AI Act requirements into the agreement between the two parties — as obligations they owe each other, performed and evidenced on their side, not ours.

Schedule F: Financial Services Supplement

When an engagement is in finance, insurance, banking or fintech, Schedule F attaches to the agreement. It adds 26 sections of regulatory terms covering DORA, MiFID II and EU AI Act Annex III. It is drafting: it says who must do what, and what each side must be able to produce. exact.works performs none of it and holds none of the resulting evidence.

26
Sections
v1.1.0
Version
3
New Regulations
Apr 2026
Effective Date

DORA Compliance

Digital Operational Resilience Act — Regulation (EU) 2022/2554

DORA

Articles 11, 28, 29

ICT third-party risk management requirements for EU financial entities using AI agents for critical or important functions.

Requirements
  • -ICT risk assessment of third-party providers
  • -Subcontractor chain disclosure
  • -Exit strategy and transition provisions
  • -Audit and inspection rights
  • -ICT-related incident reporting
  • -Data location and processing disclosure
How the agreement addresses it
ICT Risk Assessment (Art.11)
The AI Provider must deliver ICT risk assessment documentation to the Buyer before the engagement starts, and both parties keep it. It is held by the financial entity that has to produce it, not by us.
Subcontractor Disclosure (Art.29)
The AI Provider must disclose its subcontracting chain to the Buyer and keep the disclosure current, including agents engaged under delegated authority. The disclosure runs between the parties.
Exit Strategy (Art.28(8))
The termination provisions require an orderly exit, with the AI Provider supporting data portability so the Buyer can transition without depending on either the provider or us.
Audit Rights (Art.28(3)(a))
The Buyer and its competent authorities retain audit and inspection rights against the AI Provider directly, over records the AI Provider is required to keep to the standard the agreement names.
Incident Reporting (Art.19)
The AI Provider must notify the Buyer of ICT-related incidents within the window the schedule sets, with enough detail for the Buyer to meet its own reporting deadline. The reporting duty to the regulator is the financial entity’s, and it is not delegable to a drafting tool.

MiFID II Algorithmic Trading

Directive 2014/65/EU Article 17 + RTS 6

MiFID II

Article 17(1), RTS 6

Algorithmic trading requirements for AI agents that execute trades or generate trading signals without human intervention for each trade decision.

Requirements
  • -Kill switch to halt trading immediately
  • -Pre-trade and post-trade risk controls
  • -Annual validation and stress testing
  • -Real-time monitoring
  • -Regulatory reporting capability
How the agreement addresses it
Kill Switch (Art.17(1))
The AI Provider must give the Buyer a disablement control that halts the agent immediately, operated by the Buyer on its own systems. exact.works does not hold, host or trigger it — a kill switch that runs through a third party is not a kill switch.
Risk Controls (RTS 6 Art.5)
AI Provider must implement pre-trade risk controls (price collars, position limits), post-trade monitoring, and circuit breakers. Documentation is captured in the Execution Manifest.
Real-Time Monitoring (RTS 6 Art.12)
The schedule requires real-time monitoring by the investment firm and records of trade decisions and executions to the standard it names, kept in the firm’s own systems. We specify the record standard; we never receive a record.
Harm Classification Override
Answering yes to algorithmic trading during drafting attaches the schedule’s heightened terms — tighter approval points, stricter records, and mandatory human oversight — to the agreement itself.
Algorithmic Trading Detection

The drafting flow asks whether the agent executes trades without a human decision on each one. When the answer is yes, the schedule's MiFID II terms attach and the heightened obligations apply, regardless of other factors.

EU AI Act Annex III

Regulation (EU) 2024/1689 — High-Risk Financial AI

EU AI Act Annex III paragraph 5 classifies the following financial AI applications as high-risk. When the drafting flow records one of them, the schedule's extended terms attach to the agreement. The obligations they create run between the two parties.

HIGH-RISKAnnex III 5(a)

Creditworthiness Assessment

AI systems used to evaluate creditworthiness of natural persons.

Implications
  • Extended record retention (365 days minimum)
  • Heightened approval and oversight terms
  • Mandatory human oversight capability
  • Technical documentation requirements
HIGH-RISKAnnex III 5(b)

Credit Scoring

AI systems used for credit scoring of natural persons.

Implications
  • Financial exclusion risk assessment
  • Explainability requirements
  • Human review accessibility
  • Non-discrimination monitoring
HIGH-RISKAnnex III 5(c)

Insurance Risk Assessment

AI systems for risk assessment and pricing in life and health insurance.

Implications
  • Protected characteristic monitoring
  • Actuarial justification requirements
  • Consumer disclosure obligations
  • Appeals process documentation
HIGH-RISKAnnex III 5(d)

Robo-Advisory Services

AI systems providing investment advice to natural persons.

Implications
  • Suitability assessment requirements
  • Risk disclosure obligations
  • Human advisor escalation path
  • Portfolio monitoring requirements

What a high-risk answer changes in the document

When the drafting flow records an Annex III 5 use, the following terms attach:

isHighRiskAISystem = true
Triggers extended compliance workflow
365-day record retention
A term the parties owe each other, per EU AI Act Article 26(6)
Heightened terms attach
Stricter approval points and records
Human oversight required
Per EU AI Act Article 14

Additional Financial Services Warranties

When Schedule F applies, the following warranties are automatically incorporated into the SAISA:

1.AI Provider warrants agent does not execute unauthorized financial transactions.
2.AI Provider warrants all financial outputs include appropriate risk disclosures.
3.AI Provider warrants compliance with applicable AML/KYC requirements.
4.AI Provider warrants human oversight capability per EU AI Act Art.14.
5.AI Provider warrants technical documentation per EU AI Act Art.11.
6.AI Provider warrants conformity assessment completed per EU AI Act Art.43.

What each side must be able to produce

Schedule F states what the parties must document and keep. These are their records, in their own systems — exact.works does not collect, hold or export any of them, and cannot produce them for a regulator on anyone's behalf.

DORA Evidence
  • - ICT risk assessment status
  • - Subcontractor chain disclosure
  • - Exit strategy provisions
  • - Incident reporting history
MiFID II Evidence
  • - Kill switch capability verification
  • - Risk controls documentation
  • - Annual review status
  • - Monitoring configuration
EU AI Act Evidence
  • - High-risk classification flags
  • - Human oversight capability
  • - Technical documentation
  • - Conformity assessment status
Records
  • - Retention period (365 days)
  • - Incident classifications
  • - Hash-chained, gap-detectable integrity
  • - Held by the party that made them
Schedule F v1.1.0 — Effective April 9, 2026
Sanctions ComplianceThe standard form