REFERENCE · BANKING
Credit scoring: the classification rule and the deployer obligations
What the regulation provides for this sector. To read once the survey is done, not before.
Classification
When AI scoring puts you in Annex III §5(b)
Annex III §5(b) covers AI systems intended to evaluate creditworthiness or establish credit scores of natural persons. The text provides one narrow exception: fraud detection, and only where fraud detection is the main intended use of the AI system, preceding all other purposes (Draft Commission Guidelines on Article 6, §307, 19 May 2026). A second structural carve-out closes a common escape route: a system that performs profiling within the meaning of GDPR Article 4(4) is always high-risk under Annex III, regardless of the four filter conditions of Article 6(3) (Draft Guidelines §89). Most retail credit scoring meets the GDPR profiling definition by design. If the deployer is a credit institution under Regulation (EU) 575/2013 and uses third-party AI scoring (or fine-tunes a vendor model on internal data), the deployer cascade activates: Article 26 §1–§12 + Article 27 FRIA automatic + Article 25(1)(b) reverse-bascule check.
Test: do you make or substantially influence a credit decision using AI? If yes: Annex III §5(b) applies, Article 27 FRIA is automatic, and Article 26 deployer obligations cascade.
| Activity | Annex III §5 | Article 27 FRIA |
|---|---|---|
| Consumer credit scoring (third-party AI) | Yes · §5(b) | Yes · automatic by activity |
| Insurance pricing using AI | Yes · §5(c) | Yes · automatic by activity |
| Anti-fraud detection (narrow scope) | No · §5(b) exception | No (provider scope) |
| Internal credit risk modelling (no individual decision) | Case-by-case Art. 6(3) | Conditional |
Source: Reg. 2024/1689 Annex III §5 · Reg. (EU) 575/2013 (CRR) · CJEU SCHUFA C-634/21 precedent on automated credit decisions.
Four deltas
Four obligations specific to banking deployers
DORA, GDPR Art. 22, EBA guidelines, and CRR provide a strong foundation for credit-decision compliance. But none of them produces an AI Act paragraph map. These deltas need to be added to the existing risk framework.
Delta 1 · Article 27 FRIA automatic by activity
Unlike HRTech (where FRIA is conditional on works-council activation) or healthcare (where FRIA does not apply at all), Annex III §5 banking deployers face automatic FRIA the moment Annex III obligations bind. The fundamental rights impact assessment is not optional.
Delta 2 · DORA Article 28 × Article 26 (third-party ICT)
Your GPAI provider is a critical ICT third-party under DORA. Whether they have signed the EU GPAI Code of Practice, and whether they participate in coalitions like Project Glasswing, is now a deployer due-diligence question, not a vendor procurement question.
Delta 3 · Article 25(1)(b) reverse-bascule
Banks that fine-tune a vendor scoring model on their own historical data may be reclassified as providers under Article 25(1)(b), inheriting the heavier Articles 16–22 regime. The boundary check is contractual, not technical: performed at the moment a fine-tuning option is contractually accepted.
Delta 4 · SCHUFA precedent integration
CJEU SCHUFA (C-634/21) ruled that credit scoring constitutes automated decision-making under GDPR Article 22 even when a human formally signs off. Article 26 §11 post-decision information now interlocks with GDPR Article 22 explanation rights. Failure to integrate creates dual-regime exposure.
Sources: Reg. 2024/1689 Articles 25–27 · Reg. (EU) 2022/2554 DORA · Reg. (EU) 2016/679 GDPR Art. 22 · CJEU C-634/21 SCHUFA · EBA guidelines on internal governance.
Integration
How this fits with DORA, GDPR Article 22, and EBA guidelines
DORA covers ICT operational resilience, including third-party providers. The AI Act covers the AI-specific obligations layered on top: paragraph subset mapping, FRIA, reverse-bascule, and the GPAI provider due-diligence question that DORA frames but doesn't answer. GDPR Article 22 covers automated decision-making rights; AI Act Article 26 §11 specifies the post-decision information obligation. EBA guidelines on internal governance frame the broader risk function. Our report sits at the intersection, article-mapped, not regime-substitutive.
Concretely: the banking deployer ends up with four documents (DORA ICT risk register, GDPR Art. 22 record, AI Act Article 26 paragraph map, EBA governance trail). The Sprinkling Act report produces the third document. The other three are produced by your existing risk framework.
One specific interplay deserves attention. The Draft Commission Guidelines (§§322–328, 19 May 2026) clarify that an AI system used both for credit scoring of natural persons and for prudential purposes under Article 144 CRR (internal ratings-based approach) or Article 120 Solvency II remains high-risk under Annex III §5(b), regardless of the fact that the same system is also used for internal ratings or own funds calculation (§324, verbatim). The only narrow path out is architectural: if a bank uses two separate AI systems (one for credit scoring as IRB input, one for IRB itself derived from the first), the IRB system inherits the credit-scoring output but is not classified as high-risk under §5(b). For most existing IRB infrastructures that integrate scoring and rating in a single model, the high-risk classification applies. Grandfathering under Article 111(2) protects models placed on the market before the binding date, but only until the first ‘significant change in design’ (§328). The definition of significant change is set by the prudential legislation itself.
Sources: DORA Reg. (EU) 2022/2554 · GDPR Reg. (EU) 2016/679 · EBA Guidelines EBA/GL/2021/05 (internal governance) · AI Act Reg. 2024/1689 Articles 25–27 · Reg. (EU) 575/2013 (CRR) Art. 144 · Directive 2009/138/EC (Solvency II) Art. 120 · Draft Commission Guidelines on Article 6 (§§322–328, 19 May 2026).
From the regulation to your own workflows
This page describes what the regulation expects. It does not say where your own workflows stand. Six questions, two minutes, no account: they sort what you know about your AI uses, returned as a text you can take away. Nothing is sent, nothing is stored, and it concludes nothing about you.
This page is informational. It does not constitute legal advice, regulatory determination, or a conformity assessment under Article 43 AIA. Specific classifications for any specific banking deployer require a tailored screening. Credit institutions recognising themselves in the Annex III §5 description should consult qualified legal counsel and, where applicable, the relevant supervisor (ECB, EBA, ACPR, BaFin, etc.) before making compliance decisions.
SEE ALSO