EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Credit Scoring and Lending AI: High-Risk Requirements

AI used to evaluate creditworthiness or establish a credit score is high-risk under Annex III(5)(b) of the EU AI Act. Obligations for lenders, fintechs and BNPL providers.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

High-risk

High-risk (Annex III, point 5(b))

When it applies

High-risk obligations apply from 2 December 2027.

Regulation (EU) 2024/1689, Annex III(5)(b); Art. 27 fundamental rights impact assessment; Consumer Credit Directive (EU) 2023/2225 Art. 18

AI that decides whether a person gets a loan, a credit card, a buy-now-pay-later limit or a mortgage is high-risk under the EU AI Act. The reasoning is simple: access to credit determines access to housing, education and essential services, so errors and bias have serious consequences for fundamental rights.

This applies to banks, consumer-credit providers, BNPL and fintech lenders, credit bureaus that compute scores, and to vendors that sell scoring models to them. It also applies to models that only pre-screen applications or set limits, not just final approvals.

Classification

Why this classification applies

Annex III, point 5(b) lists “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud”. The fraud exception is important and is covered on the fraud-detection page: it removes fraud models from the list, but not the scoring model itself.

Since credit scoring is profiling of natural persons, the Article 6(3) exception cannot be used to argue the system is not high-risk. Business-to-business credit assessment of companies is outside this point because it concerns legal persons, although the data of sole traders can bring it back in.

Banks and financial institutions also face sectoral overlap: the Consumer Credit Directive requires that creditworthiness assessments involving automated processing give the consumer a right to human intervention and a meaningful explanation, and the AI Act lets financial institutions integrate several AI Act duties into their existing internal governance under sectoral law.

Obligations

What you have to do

  • Risk management with explicit assessment of discrimination risk on protected characteristics and proxies such as postcode or device type (Art. 9).
  • Data governance: provenance and representativeness of training data, examination for bias, and safeguards where special categories of data are used to detect bias (Art. 10).
  • Technical documentation, automatic logging and record-keeping; financial institutions may keep logs as part of the documentation under EU financial services law (Arts. 11, 12, 18).
  • Human oversight: credit officers must be able to understand the drivers of a score, override it, and stop the system (Art. 14).
  • Accuracy and robustness monitoring, including drift on new customer populations (Art. 15).
  • Conformity assessment, EU declaration of conformity, CE marking, EU database registration (Arts. 43, 47, 48, 49).
  • Deployers that are financial institutions must perform a fundamental rights impact assessment before first use (Art. 27), which can be combined with the GDPR DPIA.
  • Right to explanation of individual decisions for applicants (Art. 86), alongside the Consumer Credit Directive right to human intervention.

Paperwork

Documents to have on file

Annex IV technical documentation
Risk management file
Data governance records with bias examination
Model validation and monitoring reports (accuracy, robustness, drift)
Human oversight procedure
Fundamental rights impact assessment (deployers, Art. 27)
EU declaration of conformity and EU database registration
Customer-facing explanation template for adverse decisions

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Using alternative data (app usage, social signals, shopping behaviour) without a documented bias examination. Proxies for protected characteristics are the main enforcement risk.
  • Treating the model as “decision support” to avoid GDPR Art. 22 and assuming that also avoids the AI Act. It does not: the Annex III entry is about intended use, not the degree of automation.
  • Vendors selling scoring models as “software components” without technical documentation. The provider of the model is the provider under the AI Act even if the lender integrates it.
  • Missing the Art. 27 fundamental rights impact assessment because it is often confused with the DPIA.

FAQ

Frequently asked questions

Does this cover B2B lending or invoice financing?

Annex III(5)(b) refers to natural persons. Scoring companies is outside it, but scoring sole traders or using directors’ personal data as inputs can bring a system back in scope. Document the analysis.

Is a rules-based scorecard an “AI system”?

An AI system under Art. 3(1) is a machine-based system that infers from input how to generate outputs, with some autonomy. A static expert-defined scorecard applied by hand is generally not; a logistic regression or gradient-boosted model trained on data generally is. The European Commission’s guidelines on the definition confirm that classic statistical learning is covered.

What are the fines for non-compliance?

Breaching high-risk obligations can be fined up to €15M or 3% of global annual turnover, whichever is higher (for SMEs, whichever is lower). National financial supervisors act as market surveillance authorities for credit institutions.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.

Related use cases

Depends on use

Insurance risk assessment & pricing

Read →

Depends on use

Fraud detection & AML

Read →

High-risk

Recruitment & CV screening

Read →

Guide

EU AI Act compliance guide

Read →