Financial Services
AI agent governance for financial services.
Bakara helps banks, fintechs, insurers, and payment companies govern AI agents connected to ICT systems, vendors, and operations — and produce the evidence. Built around DORA, NIS2, and NYDFS expectations.
The challenge
AI agents now touch ICT systems and third parties.
Financial firms are connecting AI agents to core systems, vendor APIs, developer tools, and customer operations. Regulators expect ICT risk management, third-party oversight, incident handling, and management accountability.
Bakara helps financial security and GRC teams govern AI-agent capabilities — and show the evidence when supervisors, customers, or auditors ask.
Frameworks
One control plane, several expectations.
DORA
Applies from 17 January 2025. Requires ICT risk management, incident handling, testing, and third-party risk management for financial firms.
NIS2
Requires cybersecurity risk-management measures and incident notification across more sectors, with management accountability.
NYDFS Part 500
A cybersecurity regulation for covered New York financial entities. The risk assessment is the foundation of the program.
SEC cyber disclosure
Public companies must disclose material cyber incidents and describe their cybersecurity risk management, strategy, and governance.
Evidence mapping
Map AI agent governance to financial expectations.
Obligations depend on your firm, sector, and supervisor. Bakara does not certify, verify, or guarantee compliance with DORA, NIS2, NYDFS, SEC rules, or any other regulation. It helps produce evidence for AI agent governance.
Regulatory expectation
ICT and AI-agent dependency mapping
What Bakara helps show
An inventory of AI agents and the systems, tools, and connectors they depend on.
Regulatory expectation
Third-party AI risk
What Bakara helps show
A register of third-party AI models, MCP servers, and APIs that agents can call.
Regulatory expectation
Access control and least privilege
What Bakara helps show
Which roles and agents can use each AI capability, and which are restricted or blocked.
Regulatory expectation
Incident handling
What Bakara helps show
Investigation records for risky AI behavior, policy violations, and exceptions.
Regulatory expectation
Critical workflow restrictions
What Bakara helps show
Capabilities blocked or gated on critical financial and operational workflows.
Regulatory expectation
Management reporting
What Bakara helps show
Board- and CISO-ready views of AI capability risk, approvals, and review status.
Evidence pack
Export the AI governance evidence supervisors and customers ask for.
FAQ
Frequently asked questions
Does Bakara make my firm DORA or NIS2 compliant?
No. Bakara does not certify, verify, or guarantee compliance with DORA, NIS2, NYDFS Part 500, SEC rules, or any other regulation. It helps you govern AI agents and produce evidence that supports your own compliance work.
How does this handle third-party AI risk?
Bakara keeps a register of the third-party AI models, MCP servers, and APIs that agents can call, and lets you restrict or block capabilities that reach external services.
Can it produce board- and supervisor-ready reporting?
Yes. Bakara provides management views of AI capability risk, approvals, exceptions, and review status that support board reporting and supervisory conversations.
Does this replace our ICT risk or incident processes?
No. Bakara extends your existing access control, monitoring, and incident processes to AI agents — it is an evidence and control layer, not a replacement for your risk program.
Govern AI agents across your financial operations.
Show which AI capabilities are approved, restricted, monitored, and reviewed — with evidence ready for supervisors and customers.
Related resource: DORA/NIS2 AI skills evidence pack
Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.