Verified Digital Agents → Samples → Agent risk assessment

Agent Risk Assessment

Sample artefact — synthetic data (Northwind Bank)

Produced by C2MD assess_agent_risk from a plain-language description of the agent. How this skill works →

DOCUMENT STATUS — DEMO DATA · NOT FOR REGULATORY RELIANCE. Northwind Bank is a synthetic organisation. This output illustrates the shape of an assessment; it is not advice about any real system.

Subject

AgentNorthwind Credit Decision Assistant
Described as"Evaluates consumer loan applications and returns an approve / decline / refer recommendation with a reason code, using applicant-supplied financial data and internal repayment history."
Assessed againstRegulation (EU) 2024/1689 (AI Act) · Regulation (EU) 2016/679 (GDPR)

1 — Risk category

DeterminationHIGH RISK
BasisAnnex III §5(b) — AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score.
ConsequenceArticles 9–15 apply as mandatory obligations, not voluntary good practice. Article 49 registration is likely engaged; confirm against your role determination below.

The exclusion for systems used to detect financial fraud does not apply here: the described purpose is creditworthiness evaluation, not fraud detection.

2 — Provider vs deployer

DeterminationPROVIDER (with deployer obligations also engaged)
WhyThe system is placed on the market and put into service under Northwind's own name, and Northwind determines its intended purpose. Building on a third-party foundation model does not move this to deployer.
WatchThis is the most commonly mis-set field. Organisations assume "deployer" because they did not train a model — but branding a system, or substantially modifying one, makes you a provider with the fuller Article 16 duty set.

3 — Lawful basis (GDPR Art. 6)

Proposed basisArt. 6(1)(b) — necessary for performance of a contract, or steps prior to entering one.
Also engagedArt. 22 — automated individual decision-making producing legal or similarly significant effects. A credit decline is squarely within scope.
Customer actionArt. 22(3) requires meaningful human intervention, the right to express a point of view, and the right to contest. The "refer" path partially addresses this — but only if referral reaches a human with authority to overturn, not one who rubber-stamps.

4 — Special-category data (GDPR Art. 9)

Directly processedNone declared.
Inference riskFLAGGED — repayment history combined with transaction-derived features can act as a proxy for health (medical expenditure) or trade-union membership (subscription patterns).
Customer actionArticle 9 is reached by inference as well as by field. Evidence a feature review that shows which inputs could proxy for a special category, and what was done about it.

5 — Assessment triggers

DPIA — GDPR Art. 35REQUIRED — systematic and extensive automated evaluation with legal or similarly significant effect.
FRIA — EU AI Act Art. 27REQUIRED if deployed by a body governed by public law or a private entity providing public services; otherwise assess against your deployer profile.

Generate the DPIA / FRIA scaffold →

Indeterminate items

The Article 27 FRIA trigger above is indeterminate without the deployer profile. It is reported as indeterminate rather than resolved — a classification this assessment cannot settle must not be relied upon until a Compliance Officer and legal determination resolve it.

Next steps in the cycle

  1. Generate the governance bundle — the rules this agent will follow.
  2. Scaffold the DPIA triggered above.
  3. Hand the bundle to ACP to version, test, ratify and sign.
  4. Evidence & Readiness Report once the agent is producing a sealed trail.