EU AI Act Guide

AI Credit Scoring Under the EU AI Act: High-Risk, With One Exception

Last updated: 2026-07-09

AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are explicitly listed in Annex III 5(b) of the EU AI Act. That makes them high-risk by default - the full obligation stack, with current Commission implementation material pointing to 2 December 2027 for Annex III systems.

There is one notable carve-out (fraud detection) and one nuance that matters for fintech SaaS: both the vendor building the scoring engine and the lender deploying it carry obligations. Here is the breakdown.

Not sure which tier applies to you? Check your system in 2 minutes — free and rule-based.

Quick shortcut

Already know you need documents? Skip straight to the Doc Pack — your classification is done for you.

Get Doc Pack ($229$499)

Why credit scoring is named explicitly

Annex III 5(b) covers AI systems “intended to be used to evaluate the creditworthiness of natural persons or establish their credit score”. The reasoning is access to essential services: a score decides whether someone gets a mortgage, a loan or a phone contract, and errors or bias scale across entire populations.

The classification does not depend on model sophistication. A gradient-boosted scorecard, an LLM-assisted underwriting assistant and a deep-learning affordability model all land in the same tier if they score natural persons. Scoring businesses (B2B credit) is outside this entry — it targets natural persons.

The fraud-detection exception

The same Annex III entry excludes AI systems used for the purpose of detecting financial fraud. A model that flags anomalous transactions or fake identities is not high-risk under 5(b) — even though it operates in finance and affects customers.

The boundary is purpose: a system that blocks a fraudulent application is fraud detection; a system that estimates the probability of repayment is creditworthiness assessment. If one model does both, assume the high-risk regime applies and document the fraud-only components separately.

Provider obligations — the fintech vendor

If you build and sell the scoring system, you are the provider and carry the core stack before the Annex III application date currently indicated as 2 December 2027: risk management system (Art. 9), data governance covering training data representativeness and bias examination (Art. 10), technical documentation per Annex IV (Art. 11), automatic logging (Art. 12), instructions for use enabling deployer oversight (Art. 13), human oversight design (Art. 14), accuracy and robustness testing (Art. 15), conformity assessment and CE marking (Art. 43, 47–49), and registration in the EU database (Art. 49).

Data governance is where credit models feel the most heat: Article 10 demands examination for possible biases and appropriate mitigation. Expect to evidence performance across demographic groups — a single Gini coefficient will not satisfy an auditor.

Deployer obligations — the bank or lender

Lenders using a third-party scoring system are deployers: they must use the system per instructions, assign competent human oversight, ensure input data relevance, monitor operation, keep logs (Art. 26), and — because credit decisions affect individuals — inform affected persons that they are subject to a high-risk AI system and, on request, explain the decision’s role (Art. 26(11), Art. 86).

Banks and insurers also connect to sectoral law: the Act aligns some governance duties with existing financial-services requirements to avoid duplication, but it does not waive them. If you sell scoring software to EU lenders, expect their procurement to pass these duties through to you contractually.

What to do now, in order

First, write the risk classification memo — confirm which of your systems fall under 5(b) and which sit in the fraud carve-out. Second, start Annex IV technical documentation; data provenance and bias-testing sections take the longest for credit models. Third, formalise human oversight: who can override a score, and how is that logged? Fourth, plan conformity assessment — Annex III point 5 systems generally follow internal control under Annex VI, without notified-body involvement under Article 43(2).

You now know what's required. Rather not write it from scratch?

The AI Act Documentation Pack delivers your risk classification memo, Annex IV technical documentation, model card, AI usage policy and compliance roadmap — generated from a 15-minute questionnaire after checkout confirmation, from $229. 14-day refund if the delivered pack materially differs from the contents described at purchase. Not legal advice.

See the Doc Pack →

Frequently asked questions

We score thin-file customers with alternative data. Does that change anything?

The tier is the same, but Article 10 scrutiny is higher: alternative data (device signals, behavioural data) raises representativeness and bias questions an auditor will probe. Document why each feature class is relevant and how you tested for proxy discrimination.

Is buy-now-pay-later affordability checking in scope?

Assessing a natural person’s ability to repay is creditworthiness assessment — the ticket size and the label on the product do not matter. BNPL affordability models should be treated as Annex III 5(b) systems.

Does GDPR Article 22 already cover this?

GDPR governs the lawfulness of automated decisions about individuals; the AI Act governs the system itself — its documentation, testing, oversight and market access. You need both: GDPR compliance does not produce Annex IV documentation, and AI Act compliance does not create a legal basis for processing.

About these guides

Written by the TrustPacket team. We track Regulation (EU) 2024/1689, Commission guidance, and enforcement developments to keep these guides current. Not legal advice — when in doubt, consult qualified counsel.

Last updated: 2026-07-09 · Content review: 11 July 2026 · Questions? Email us

This is informational editorial content based on Regulation (EU) 2024/1689 and cited official implementation material. It is not legal advice, not a conformity assessment, and does not create a lawyer-client relationship. Application depends on facts this guide cannot verify. Consult qualified counsel for a binding assessment.