EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · CREDIT SCORING · LENDING · HIGH-RISK AI

WHEN AI SHAPES ACCESS TO CREDIT,
THE DECISION RECORD HAS TO SURVIVE THE SCORE.

Creditworthiness and credit-scoring AI can directly affect access to lending, mortgages and other essential private services. Annex III treats these uses as high-risk, while expressly separating fraud-detection systems from this specific category. The governance challenge is proving the classification, the evidence behind the decision, the human role, and the basis for continued reliance after change.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 6 and Annex III, Point 5(b)

Annex III classifies AI used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, while excluding systems used for financial-fraud detection from that specific category. Article 6(3) provides a limited derogation, but profiling remains high-risk and the provider must document any reliance on the derogation.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE SYSTEM EVALUATING CREDITWORTHINESS OR ESTABLISHING A CREDIT SCORE?

Annex III classifies AI intended to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, including consumer lending and mortgage use cases.

02

IS THE SYSTEM USED ONLY FOR FINANCIAL-FRAUD DETECTION?

Annex III expressly excludes AI systems used for the purpose of detecting financial fraud from this specific creditworthiness high-risk category. The exact intended purpose still matters, and other AI Act or sector rules may apply.

03

DOES ARTICLE 6(3) CHANGE THE CLASSIFICATION?

An Annex III system may avoid high-risk status only in limited circumstances where it does not pose a significant risk or materially influence the decision. Profiling of natural persons remains high-risk, and any exclusion analysis must be documented.

04

CAN YOU PROVE WHY CREDIT WAS OFFERED, PRICED, LIMITED OR DENIED?

Preserve the system and model version, credit-use case, input data, score or recommendation, human review, overrides, notices, adverse-outcome reasoning, logs, complaints, policy changes, and the evidence supporting continued reliance.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Define the exact lending function

Separate affordability assessment, creditworthiness evaluation, credit scoring, pricing support, fraud detection, collections, marketing and purely administrative processing. These functions do not all sit on the same AI Act route.

02

Classify the system and document the basis

Test Annex III point 5(b), Article 6(3), profiling, operator roles, and any other applicable product or sector obligations. Preserve the classification analysis before deployment or market placement.

03

Bind human review and evidence to the credit decision

Connect data inputs, model output, decision rules, human reviewer, override, explanations or notices, logs, performance and bias evidence, complaint or challenge pathways, and the resulting lending outcome.

04

Revalidate after model, policy, data or product changes

A new scorecard, changed lending policy, new data source, model update, broader product scope, removed human checkpoint or changed intended purpose can make the prior classification and evidence stale.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Is AI credit scoring high-risk under the EU AI Act?

Yes, when the system is intended to evaluate the creditworthiness of natural persons or establish their credit score, subject to the Regulation’s classification rules and limited Article 6(3) derogation.

Is AI fraud detection also high-risk under the same credit-scoring category?

No. Annex III expressly excludes AI systems used for the purpose of detecting financial fraud from point 5(b). That does not mean every fraud-detection system is unregulated; it means this specific creditworthiness category does not apply on that basis alone.

Can a credit-scoring system avoid high-risk classification under Article 6(3)?

Potentially, but only if it does not pose a significant risk or materially influence the outcome and fits one of the listed conditions. Systems that perform profiling of natural persons remain high-risk, and providers relying on the derogation must document their assessment.

When do these high-risk credit-scoring rules apply?

Current European Commission guidance states that high-risk rules for Annex III systems apply from 2 December 2027.

What evidence should be preserved for lending AI?

Preserve system identity and version, intended purpose, provider and deployer roles, classification basis, data provenance, score or recommendation, human review, overrides, notices, logs, performance and bias evidence, complaints, material changes and revalidation history.

Does TA-14 certify a lending or credit-scoring AI system as compliant?

No. TA-14 can preserve the classification basis, evidence, human-oversight state, gaps, decision history and revalidation record. It does not provide legal advice, certification, conformity assessment or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views