Short answer. A bank operationalizes the EU AI Act for credit scoring by treating the model as a high-risk system under Annex III point 5(b) and mapping the 7 core obligations in Articles 9 to 15 onto controls it already runs: model risk management, data governance, four-eyes override, and back-testing. The hard deadline is 2 August 2026, with a one-year grace period to 2 August 2027 for models already in production. Non-compliance carries fines up to EUR 35 million or 7% of global annual turnover.
Credit scoring is one of the clearest high-risk cases in the Act. Any AI system that evaluates the creditworthiness of a natural person or produces a credit score falls under Annex III, point 5(b). That single classification triggers a fixed set of obligations, and it applies whether the bank built the model or bought it from a vendor.
In practice the work splits by role. If the bank trains and deploys its own scorecard, it is both provider and deployer and carries the full weight of Articles 9 to 15 plus registration in the EU database under Article 49. If the bank buys a scoring engine, it is a deployer under Article 26 and still owns human oversight, post-market monitoring, and a Fundamental Rights Impact Assessment.
The EU AI Office confirmed in March 2026 that these obligations reach existing production models, not only new builds. A scorecard that has run for years is in scope.
For a bank the deadline is concrete. High-risk obligations for credit scoring apply from 2 August 2026. Systems placed on the market before that date have until 2 August 2027, so a bank running a legacy scorecard has a defined runway, not an exemption. Miss it and the exposure reaches EUR 35 million or 7% of worldwide annual turnover, the top penalty band in the Act.
The Act does not replace the rules a bank already lives under. It stacks on top of GDPR, DORA, and the EBA guidelines on loan origination and internal governance. A credit institution has to satisfy all of them at once, which is why the operating question is integration, not a separate AI compliance project running beside everything else.
Credit scoring is high-risk under Annex III point 5(b); obligations apply from 2 August 2026, with a grace period to 2 August 2027 for models already in production.
The fastest path anchors each obligation in a framework the bank already operates. Article 9 risk management maps to the existing model risk management framework. Article 10 data governance maps to data quality and representativeness controls. Article 14 human oversight maps to override and four-eyes governance. Article 15 accuracy and robustness maps to model validation and back-testing. The EBA has signalled the same approach: expand existing model governance, credit risk processes, and DORA ICT frameworks, and anchor the AI requirements inside them rather than build a parallel structure.
This mapping is where most of the effort goes. A gap analysis against the EBA mapping shows which controls already produce the evidence a regulator will ask for and which ones need extending. The output is one control library that serves several regulations, not four disconnected checklists.
Article 14 treats human oversight as a design requirement, not a policy statement. A named reviewer has to understand the score, question it, and override it before it moves downstream. A system that produces a generic score rationale can satisfy a documentation checkbox and still fail Article 14 if no qualified person can intervene in time.
This is where the Act meets Article 86, which gives a customer the right to a clear explanation of the AI system’s role in a credit decision. Banks operationalize it with adverse action reason codes, local explanation methods such as SHAP, and monotonicity constraints that keep the model’s logic reviewable. Oversight and explainability sit inside the scoring workflow, not bolted on after a complaint arrives.
They stack, and meeting one does not satisfy the others. GDPR Article 22 governs the individual’s right not to be subject to a solely automated decision. The Court of Justice ruled in the SCHUFA case (C-634/21) that producing a credit score is itself an automated decision when the score plays a determining role in the lending outcome. That pulls the GDPR rights to human review, explanation, and contestation forward to the scoring stage, not just the final lending decision.
DORA adds operational resilience obligations for the ICT systems that run the model, and NIS2 adds security duties. A workable operating model uses one shared rulebook across the AI Act, GDPR, DORA, and the bank’s own model governance, so a single piece of evidence answers several regulators. Running four separate programs repeats the same work and opens gaps at the seams.
Start with an inventory. Identify every AI or statistical system that touches a creditworthiness decision, including vendor engines and models embedded in a loan origination platform. Classify each against Annex III, then run a gap analysis using the EBA mapping. Complete the Fundamental Rights Impact Assessment, which is automatic for a banking deployer once the Annex III obligations bind. Assign named accountability for oversight and monitoring, and register provider systems in the EU database. Banks that treat this as a governance program with an owner, rather than a documentation exercise, reach the deadline with a system a regulator can audit.
Ableneo works inside this regulated-production problem. Across a 2025 portfolio of 34 production AI projects, roughly 4 of 5 reached production, and the financial services work with banks and insurers in Central Europe is where governance, legacy core systems, and audit evidence meet. The pattern from that track record is consistent: AI Act readiness for credit scoring is won by wiring oversight and logging into the model’s operating workflow, not by writing a policy after the model ships. Ableneo’s AI transformation practice treats the regulation as an operating design input from the first sprint.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.