Algorithmic credit scoring
🤖 AI rejected your loan. Can the bank explain why? Τhis is no longer a technical question – it is a legal one. The new rule of the game is simple: No explanation = legal risk. 🕶️
Banks are increasingly using AI and machine learning models to assess consumer creditworthiness. These models can process traditional credit history, income, debt burden, transactional behaviour, alternative data, digital patterns and indirect risk indicators. From a business perspective, the logic is clear: faster decisions, greater scalability and potentially more accurate default prediction. But the legal problem appears at the moment of refusal:
Can the bank explain why the algorithm rejected the customer?
The answer “the system decided so” is no longer sufficient. In the EU regulatory environment, algorithmic credit scoring is moving from a purely risk-management tool to a regulated decision-making process that must be explainable, documented and subject to human oversight.
1. Credit scoring as a high-risk AI use case under the EU AI Act
The EU AI Act directly captures AI-based credit scoring within the high-risk category. Under Article 6 of Regulation (EU) 2024/1689, AI systems referred to in Annex III are classified as:
high-risk, subject to the conditions of the Regulation. Annex III, point 5(b) specifically covers AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with an exception for systems used to detect financial fraud.
This classification matters because high-risk AI systems are not simply “advanced analytics”. They trigger compliance obligations around risk management, data governance, technical documentation, record-keeping, transparency, accuracy, robustness, cybersecurity and human oversight. For banks, this means that AI credit scoring models must be designed not only to predict risk, but also to withstand regulatory scrutiny.
2. The right to explanation: Article 86 EU AI Act
A particularly important provision is Article 86 EU AI Act, which introduces a right to explanation of individual decision-making in certain cases involving high-risk AI systems. Where a person is affected by a decision taken by a deployer on the basis of the output of a high-risk AI system listed in Annex III, and that decision produces legal effects or similarly significantly affects that person, the person has the right to obtain clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision.
In the context of consumer lending, a credit refusal is exactly the kind of decision that can materially affect a person’s access to financial services. This does not necessarily mean that banks must disclose the full source code, model weights or proprietary architecture. But they must be able to explain, in a legally meaningful way, how the AI system influenced the outcome and what the main factors behind the decision were.
3. GDPR: automated decision-making and profiling
The AI Act does not operate in isolation. It sits alongside the GDPR, which has already been relevant to automated credit decisions for years.
Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning them or similarly significantly affects them. A refusal of consumer credit may fall within this logic, especially where the decision is made without meaningful human involvement.
In addition, Articles 13(2)(f), 14(2)(g) and 15(1)(h) GDPR require controllers to provide meaningful information about the logic involved in automated decision-making, as well as the significance and envisaged consequences of such processing for the data subject.
The practical message is simple: automation does not remove accountability. If personal data is used to make or materially support a credit decision, the customer must not be left facing an unexplained black box.
4. Case law: CJEU’s warning on credit scores
The Court of Justice of the European Union strengthened this approach in SCHUFA Holding, Case C-634/21. The Court held that the automated establishment of a probability value concerning a person’s ability to meet future payment obligations may constitute automated individual decision-making under Article 22 GDPR, where a third party, such as a bank, draws strongly on that score when deciding whether to grant credit.
This is highly relevant for banks and credit reference agencies. A score is not always “just an input”. If it effectively determines the outcome, it may become part of a legally significant automated decision-making process. For AI-based credit scoring, the SCHUFA judgment confirms that regulatory analysis should focus not only on the formal decision-maker, but also on the real influence of the score on the final decision.
5. Enforcement risk: explainability as compliance
The sanction risk under the EU AI Act is also significant.
Under the penalty regime of the AI Act, certain infringements may lead to administrative fines of up to €15 million or 3% of total worldwide annual turnover, while infringements related to prohibited AI practices may reach up to €35 million or 7% of worldwide annual turnover, depending on the nature of the violation.
This changes the risk profile of AI credit scoring. If a bank uses AI to reject a loan application but cannot explain the logic of the decision, the key factors, the model governance and the human oversight mechanism, this is no longer merely a technical limitation of a complex model.
Conclusion
The direction of travel is clear: the EU is moving from black-box AI to accountable AI in financial services.
For banks, this means that AI credit scoring should be built around three core requirements:
- Explainability – the bank must be able to identify and communicate the main reasons for the decision.
- Auditability – there must be a traceable record of the data, model, factors, outputs, controls and decision process.
- Human oversight – there must be a meaningful possibility of human review, intervention and contestation where required.
FInally, banks can use AI to support credit decisions. But they must be able to prove that the decision was fair, explainable, documented and subject to appropriate human control.
Build Your Legacy With Confidence
We are here to understand your goals and create solutions tailored to your future.
Get in touch