Regulation (EU) 2026/1744 (the Digital Omnibus on AI) entered into force on 27 July 2026 and moved the Annex III high-risk compliance date from 2 August 2026 to 2 December 2027. The classification of credit scoring as high-risk was not changed.
Our approach builds on established model validation practices, extending them to provide:
- Robust and well-performing models
- Stability over time and across portfolio changes
- Transparent and explainable model drivers
- Consistent model behaviour across customer segments
- Clear identification and assessment of differences in model outcomes
Regulatory Context
Why credit scoring models are in scope
The EU AI Act classifies credit scoring systems under Annex III as high-risk AI systems — based on their purpose, not the underlying technology.
This means institutions must demonstrate that models are:
- Appropriately governed throughout their lifecycle
- Based on sound and representative data
- Validated, monitored, and documented
- Transparent and explainable in their decisioning
StatDec's framework addresses key requirements from:
- EU AI Act (high-risk AI systems)
- EBA GL/2020/06 (model risk management)
- GDPR Article 22 (automated decisioning & transparency)
Supporting a consistent and efficient approach to model validation and governance.
Obligations
Key AI Act requirements for credit scoring models
Risk management across the model lifecycle
Data governance and representativeness
Technical documentation (Annex IV)
Transparency and logging
Human oversight mechanisms
Accuracy, robustness, and performance monitoring
Require careful assessment of variables and model design to avoid unintended reconstruction of protected characteristics.
Our Framework
A structured validation framework across the model lifecycle
StatDec's framework extends traditional model validation to assess how models behave in practice — across data, features, outputs, and decision outcomes. It applies equally to models StatDec has built and to scorecards developed elsewhere.
Data Assessment
Evaluate training and validation datasets for representativeness, completeness, and potential sources of bias.
Feature Analysis
Review model inputs to ensure appropriate use, clear justification, and assessment of potential proxy effects.
Model Performance
Assess discriminatory power, calibration, and overall model performance.
Consistency Across Segments
Evaluate whether model performance and risk estimation are consistent across customer segments.
Outcome & Error Analysis
Analyse differences in approval rates, default rates, and error patterns across populations.
Monitoring & Stability
Design monitoring approaches covering performance, stability, and behaviour over time.
Documentation & Governance
Produce structured documentation supporting transparency, audit readiness, and regulatory review.
What You Receive
Deliverables
Structured outputs designed for validation, governance, and regulatory review:
AI Act Readiness Assessment
Gap analysis of your model inventory against Annex III obligations — scope, gaps, and priority actions.
Model Behaviour & Consistency Analysis
Full validation across the seven dimensions with documented metrics, findings, and recommendations per model.
Technical Documentation (Annex IV)
Structured documentation aligned with Annex IV expectations, suitable for regulatory review.
Feature Review & Proxy Risk Assessment
Systematic review of model inputs for appropriateness, justification, and potential proxy effects.
Human Oversight Framework Design
Design of oversight mechanisms aligned with Art. 14 requirements and operational workflows.
Monitoring & Validation Framework
Ongoing monitoring plan covering performance, stability, and outcome review over time.
Key Dates
Compliance Timeline
AI Act — Regulation (EU) 2024/1689 — entered into force on 1 August 2024.
Prohibited practices (Art. 5) and the AI literacy duty (Art. 4) applicable from 2 February 2025 — including restrictions relevant to proxy variable use. Already enforceable.
Regulation (EU) 2026/1744 (Digital Omnibus on AI) published in the Official Journal on 24 July 2026, in force 27 July 2026. It amended Art. 113 to defer the Annex III high-risk obligations, and amended Art. 111(2) accordingly. Annex III itself was not amended: credit scoring remains high-risk.
From 2 August 2026 the AI Office and national market surveillance authorities exercise their supervisory and penalty powers, and the Art. 50 transparency obligations apply. The high-risk obligations in Chapter III were not triggered on this date for Annex III systems.
From 2 December 2026 the prohibitions added by the Omnibus (Art. 5(1)(ba) and (bb), non-consensual intimate imagery and CSAM) apply, and generative systems already on the market must meet the Art. 50(2) marking duty under the new Art. 111(4).
By 2 August 2027, general-purpose AI models placed on the market before 2 August 2025 must be brought into compliance (Art. 111(3), unchanged by the Omnibus). Relevant where LLMs or foundation models are used in any part of the credit decisioning process.
Chapter III obligations apply to Annex III high-risk systems. Credit scoring models must be compliant — Annex IV documentation, risk management, data governance, logging, human oversight, conformity assessment, registration and post-market monitoring.
From 2 August 2028 the same obligations apply to AI that is a safety component of a product covered by the Annex I harmonisation legislation. Not normally relevant to credit scoring.
2 December 2027 is roughly fifteen months away. A typical validation cycle runs 3–6 months, and a bank with several scorecards will run them in sequence rather than in parallel; conformity assessment, registration and Annex IV documentation sit after that work, not alongside it. Institutions that have not yet scoped their model inventory should do so in the 2026/27 planning round, so that remediation lands in the first half of 2027 and leaves the second half for documentation and sign-off. The models to look at first are those whose next redevelopment or recalibration falls after December 2027: under Art. 111(2) a significant change in design made from that date onwards pulls an otherwise grandfathered model into full scope.
FAQ
Frequently asked questions
Yes. The EU AI Act classifies credit scoring systems under Annex III as high-risk AI systems, on the basis of their purpose rather than the underlying technology. Institutions must demonstrate that models are appropriately governed throughout their lifecycle, based on sound and representative data, validated, monitored and documented, and transparent and explainable in their decisioning.
2 December 2027. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — amended Article 113 of the AI Act so that the Chapter III high-risk obligations apply from 2 December 2027 for Annex III systems including credit scoring, and from 2 August 2028 for AI embedded in Annex I regulated products. The original date of 2 August 2026 no longer applies to Annex III systems. This is settled law, not a proposal.
Not permanently. Article 111(2), as amended by Regulation (EU) 2026/1744, now ties the cut-off to the date of application of Chapter III — for credit scoring, 2 December 2027. Systems placed on the market before that date sit outside the obligations only until they are subject to significant changes in their design. For scorecards that includes redevelopment, retraining on new data, new input variables, expansion to a new population and characteristic realignment.
The requirements bearing directly on a scorecard are Article 9 on risk management across the model lifecycle, Article 10 on data governance and representativeness, Article 11 with Annex IV on technical documentation, Article 12 on transparency and logging, Article 14 on human oversight and Article 15 on accuracy, robustness and performance monitoring.
It is a gap analysis of your model inventory against the Annex III obligations, setting out which models are in scope, where the gaps are and which actions take priority. It is the usual starting point before the fuller work across data, features, performance, segment consistency, outcomes, monitoring and documentation.
Not on its own. StatDec's framework builds on established model validation practice and extends it to assess how models behave in practice, adding feature review and proxy risk assessment, consistency of performance across customer segments, outcome and error analysis, human oversight design under Article 14, and Annex IV technical documentation.
Discuss your model validation requirements
Talk to StatDec about your credit model inventory. We can help assess scope, identify gaps, and design an appropriate validation and governance approach.
Get in touchCompliance date settled: 2 December 2027
The legislative process is complete. Regulation (EU) 2026/1744 (the Digital Omnibus on AI) was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It replaced point (c) of the third paragraph of Article 113, so the Chapter III high-risk obligations now apply from 2 December 2027 to systems classified as high-risk under Article 6(2) and Annex III — which includes creditworthiness assessment and credit scoring — and from 2 August 2028 to systems classified under Article 6(1) and Annex I. The 2 August 2026 date is superseded for these systems.
The deferral is of timing, not of substance. Annex III was not amended and credit scoring remains high-risk; the Article 6(3) derogation for narrow procedural or preparatory tasks is unchanged; the Article 11 and Annex IV technical documentation requirement stands, with the simplified Commission form available only to SMEs and small mid-caps; and the Article 49 registration duty remains. Separately, the Omnibus moved the legal basis for processing special categories of personal data for bias detection and correction out of Article 10(5) into a new standalone Article 4a, which is not part of the deferred Chapter III obligations.
What is still unresolved
Three things that bear on how the obligations will be met in practice were still outstanding as at September 2026, and we have not assumed an outcome for any of them. First, no CEN-CENELEC harmonised standard under mandate M/613 had yet been cited in the Official Journal, so no presumption of conformity is available and conformity assessment must be argued on first principles. Second, the Commission's guidelines on the classification of high-risk AI systems under Article 6(5) were published in draft on 19 May 2026 and consulted on over the summer; the final text had not been adopted. Third, the Commission's guidelines under Article 96(1)(e) on the interplay between the AI Act and EU financial services law — the subject of the EBA's mapping letter to the Commission of November 2025, which set out how CRR, CRD and DORA already cover parts of the AI Act's requirements for creditworthiness and credit scoring — had not been issued. Until they are, the extent to which existing prudential model governance can be relied on to discharge AI Act obligations is a matter of judgement rather than settled guidance.
Models already live are not automatically exempt
Under Article 111(2), as amended by Regulation (EU) 2026/1744, high-risk AI systems placed on the market before the date of application of Chapter III — 2 December 2027 for Annex III systems — are not immediately subject to the Act's obligations, unless and until they are subject to significant changes in their designs from that date. For credit scoring models, this includes redevelopment, retraining on new data, addition of new input variables, expansion to a new portfolio or population, and characteristic realignment. Any such change triggers full compliance obligations from that point.
In practice, credit scoring models are routinely modified as part of normal lifecycle management. Institutions should not assume that a model currently in production will remain outside the Act's scope indefinitely. Early preparation reduces the risk of a compliance gap arising at the point of the next model change.