Credit scoring is one of the most consequential applications of AI in financial services — and one of the most directly regulated under the EU AI Act. AI systems used to evaluate creditworthiness are explicitly listed as high-risk in Annex III of the Act, meaning they carry the full weight of the regulation's technical and governance requirements.
Why Credit Scoring Is Classified High-Risk
The classification reflects the nature of the impact. Credit decisions determine whether individuals can access mortgages, business loans, consumer credit, and insurance. An AI system that systematically underestimates or overestimates creditworthiness for specific demographic groups — even in statistically subtle ways — can deny economic access at scale. The EU AI Act's Annex III classification ensures that the same rigour applied to AI in critical infrastructure is applied to AI that affects individual financial lives.
Technical Requirements for Credit AI Systems
Under the EU AI Act, high-risk AI systems in credit scoring must satisfy five categories of technical requirement before deployment in the EU market.
Risk management system (Article 9): A continuous, iterative risk management process covering identification of risks throughout the AI system's lifecycle, risk estimation and evaluation, implementation of risk management measures, and residual risk assessment. For credit AI, risk management must specifically address demographic bias in credit outcomes, performance variance across customer segments, and the potential for feedback loops where past credit decisions affect future model training data.
Data governance (Article 10): Training, validation, and testing data must be subject to data governance practices that ensure relevance, representativeness, freedom from errors, and compliance with data protection law. For credit scoring, this means demonstrating that training data does not encode historical discrimination patterns, that validation data covers all relevant demographic segments, and that protected characteristics are handled in accordance with both the AI Act and applicable anti-discrimination law.
Technical documentation (Article 11): Comprehensive documentation of the system design, development process, training data governance, performance testing, and risk management measures. This documentation must be maintained for 10 years and be available to regulators on request.
Automatic logging (Article 12): The credit AI system must automatically generate logs enabling post-hoc monitoring. At minimum, logs must capture the input data used for each credit decision, the model output and confidence level, the timestamp and model version, and any human review or override applied to the AI recommendation. These logs must be retained for periods consistent with the Act's requirements — typically 7 years for credit decisions — and must be tamper-evident.
Human oversight (Article 14): Human overseer roles must be defined, with individuals who understand the system's capabilities and limitations, who can identify and address bias or performance issues, and who have genuine override authority over AI credit decisions when required.
GDPR and the Right to Explanation
The EU AI Act sits alongside GDPR in the regulatory landscape for credit AI. GDPR Article 22 gives data subjects the right not to be subject to solely automated decisions that significantly affect them — unless specific conditions are met. Where credit decisions are made using automated AI systems without human review, GDPR requires that the individual be informed, have the right to obtain human intervention, and be able to contest the decision.
The AI Act's explainability provisions reinforce GDPR: high-risk AI systems must be designed so that their outputs can be interpreted and, where required, explained to affected individuals. For credit AI, this means the audit trail must capture not just what decision was made, but the factors that drove it — enabling the institution to provide a meaningful explanation to a declined applicant.
Alignment with SR 11-7 Model Risk Management
For US-domiciled banks and bank holding companies, SR 11-7 model risk management guidance from the Federal Reserve has long imposed rigorous validation, governance, and documentation requirements on credit models. Institutions that have strong SR 11-7 programmes are well-positioned for EU AI Act compliance — but the Acts are not identical. EU AI Act requirements for human oversight, automatic logging, and audit trail tamper-evidence go beyond typical SR 11-7 implementations and will require incremental investment for most institutions.
Building Compliant Credit AI Infrastructure
The most common gap we see in credit AI compliance is in the audit trail. Institutions often have robust model validation and documentation practices but have not implemented the automatic, tamper-evident decision logging that Article 12 requires. The business case for investment is clear: the cost of building compliant logging infrastructure is a fraction of the penalty exposure from operating non-compliant credit AI at scale. And the operational benefits — the ability to investigate credit decision anomalies, demonstrate fair lending compliance, and respond to regulatory examinations with complete evidence — accrue regardless of the regulatory mandate.