Verified Digital Agents → Samples → Agent risk assessment
Agent Risk Assessment
Sample artefact — synthetic data (Northwind Bank)
Produced by C2MD assess_agent_risk from a plain-language description of the
agent. How this skill works →
DOCUMENT STATUS — DEMO DATA · NOT FOR REGULATORY RELIANCE.
Northwind Bank is a synthetic organisation. This output illustrates the shape of an
assessment; it is not advice about any real system.
Subject
| Agent | Northwind Credit Decision Assistant |
|---|---|
| Described as | "Evaluates consumer loan applications and returns an approve / decline / refer recommendation with a reason code, using applicant-supplied financial data and internal repayment history." |
| Assessed against | Regulation (EU) 2024/1689 (AI Act) · Regulation (EU) 2016/679 (GDPR) |
1 — Risk category
| Determination | HIGH RISK |
|---|---|
| Basis | Annex III §5(b) — AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. |
| Consequence | Articles 9–15 apply as mandatory obligations, not voluntary good practice. Article 49 registration is likely engaged; confirm against your role determination below. |
The exclusion for systems used to detect financial fraud does not apply here: the described purpose is creditworthiness evaluation, not fraud detection.
2 — Provider vs deployer
| Determination | PROVIDER (with deployer obligations also engaged) |
|---|---|
| Why | The system is placed on the market and put into service under Northwind's own name, and Northwind determines its intended purpose. Building on a third-party foundation model does not move this to deployer. |
| Watch | This is the most commonly mis-set field. Organisations assume "deployer" because they did not train a model — but branding a system, or substantially modifying one, makes you a provider with the fuller Article 16 duty set. |
3 — Lawful basis (GDPR Art. 6)
| Proposed basis | Art. 6(1)(b) — necessary for performance of a contract, or steps prior to entering one. |
|---|---|
| Also engaged | Art. 22 — automated individual decision-making producing legal or similarly significant effects. A credit decline is squarely within scope. |
| Customer action | Art. 22(3) requires meaningful human intervention, the right to express a point of view, and the right to contest. The "refer" path partially addresses this — but only if referral reaches a human with authority to overturn, not one who rubber-stamps. |
4 — Special-category data (GDPR Art. 9)
| Directly processed | None declared. |
|---|---|
| Inference risk | FLAGGED — repayment history combined with transaction-derived features can act as a proxy for health (medical expenditure) or trade-union membership (subscription patterns). |
| Customer action | Article 9 is reached by inference as well as by field. Evidence a feature review that shows which inputs could proxy for a special category, and what was done about it. |
5 — Assessment triggers
| DPIA — GDPR Art. 35 | REQUIRED — systematic and extensive automated evaluation with legal or similarly significant effect. |
|---|---|
| FRIA — EU AI Act Art. 27 | REQUIRED if deployed by a body governed by public law or a private entity providing public services; otherwise assess against your deployer profile. |
Generate the DPIA / FRIA scaffold →
Indeterminate items
The Article 27 FRIA trigger above is indeterminate without the deployer
profile. It is reported as indeterminate rather than resolved — a classification this
assessment cannot settle must not be relied upon until a Compliance Officer and legal
determination resolve it.
Next steps in the cycle
- Generate the governance bundle — the rules this agent will follow.
- Scaffold the DPIA triggered above.
- Hand the bundle to ACP to version, test, ratify and sign.
- Evidence & Readiness Report once the agent is producing a sealed trail.