On 18 May 2026, the European Data Protection Supervisor (EDPS) published a Checklist on Human Intervention in Automated Decision-Making as a self-assessment tool for EU institutions, bodies, offices, and agencies (EUI) that operate automated decision-making systems capable of producing decisions with a significant effect on individuals. The checklist is addressed to EUI data controllers and processors and does not bind private entities directly, but its criteria draw on Article 22 GDPR and Article 24 of Regulation (EU) 2018/1725, and the EDPS will use the checklist when assessing EUI ADM practices in supervisory inquiries and audits.
The checklist groups requirements into five domains. Governance and accountability: a documented mandate and a named responsible officer for each ADM system. Reviewer competence and training: reviewers must understand the system's purpose, inputs, known biases, and failure modes. Process design: reviewers must have sufficient time, access to all relevant input data used by the system, and the ability to query the system's reasoning before confirming or overriding its output. Appeal and escalation: a mechanism for individuals to challenge ADM outcomes and for reviewers to escalate uncertain cases to a senior decision-maker. Performance monitoring: the entity must track override rates, error-detection rates, and audit outcomes to assess whether human intervention is functioning in practice and not merely on paper.
Data protection authorities in EU member states routinely cite EDPS guidance when interpreting Article 22 GDPR obligations applicable to private entities. Credit institutions, insurance firms, consumer lenders, employers, and online platforms using automated scoring, risk assessment, eligibility determination, or credit decisioning systems should treat the checklist as the current EU supervisory benchmark for meaningful human review. AI Act deployers of high-risk systems in Annex III categories, including AI used in employment decisions, creditworthiness assessment, education, and law enforcement, have parallel human oversight obligations under Article 14 of the EU AI Act. The EDPS checklist provides implementation detail for those Article 14 requirements where national data protection authorities are likely to look for practical compliance evidence.
The EDPS issued a TechDispatch on human oversight of ADM in September 2025 and is expected to publish further guidance addressing the interaction between GDPR Article 22 and EU AI Act Article 14 as the AI Act's high-risk provisions begin applying from August 2026. Financial institutions subject to EBA Guidelines on Internal Governance and EBA model risk management guidelines should map EDPS checklist requirements against the model validation and human review controls already required under those guidelines to identify gaps specific to ADM-intensive AI systems.
Licentium advises financial entities and AI deployers on human oversight programme design for the EU AI Act, GDPR, and sector-specific obligations. Work we undertake includes AI Act Annex III high-risk system assessments, Article 22 GDPR compliance reviews, ADM governance documentation, fundamental rights impact assessments, and DORA-aligned ICT risk documentation for AI systems.