Annex III point 5(b): creditworthiness and credit scoring
Annex III point 5(b) makes high-risk any AI system intended to evaluate the creditworthiness of natural persons or to establish their credit score. It is one of the shortest entries on the high-risk list and one of the widest in effect, because it does not describe a niche technology. It describes what a consumer lending stack already does: score an applicant, estimate a probability of default, rate affordability, and return an accept, decline or refer. From 2 December 2027 the full Chapter III obligation stack attaches to those systems.
The classification follows the function, not the product name or the model architecture. A bespoke scorecard, a gradient-boosted default model and a general-purpose model prompted to assess an application are the same thing for this purpose: each evaluates the creditworthiness of a natural person. That is why buying rather than building changes nothing, and why a system marketed as decision support rather than decision making is still caught if the score is what the lender acts on. The only words in 5(b) that carve anything out are the fraud-detection exception, and they carve out much less than firms assume.
The fraud-detection carve-out, and why it is misread
Point 5(b) high-risks creditworthiness AI with the exception of AI systems used for the purpose of detecting financial fraud. That clause is the single most over-claimed line in the whole of Annex III point 5. The argument runs: our model looks at risk, fraud is a kind of risk, therefore the exception applies. It does not. The exception turns on purpose. It removes systems whose job is to detect fraudulent applications or transactions, not systems that decide whether a genuine applicant is creditworthy.
The distinction is not academic, because the two functions answer different questions. A fraud-detection system asks whether this application is what it claims to be. A creditworthiness system asks whether this real person can afford and is likely to repay the credit. The first can be excluded; the second cannot. Bundling them in one model does not launder the lending decision through the fraud carve-out, and running a genuine fraud engine alongside a scorecard does not pull the scorecard out with it.
| System | Annex III point | High-risk? | Why |
|---|---|---|---|
| Consumer credit score or probability-of-default model | 5(b) | Yes | It evaluates the creditworthiness of a natural person. The named use, with no exception available to it. |
| Affordability or income-verification model feeding a lending decision | 5(b) | Yes | It assesses whether a real applicant can repay. That is creditworthiness, not fraud, whatever the internal team calls it. |
| Transaction-fraud or application-fraud detection engine | 5(b) exception | No | Its purpose is detecting fraud, so the express carve-out reaches it, provided that is genuinely all it does. |
| One model that both scores creditworthiness and flags fraud | 5(b) | Yes, for the scoring function | The carve-out is read by purpose, function by function. The creditworthiness function stays high-risk; the fraud function does not rescue it. |
| Life or health insurance underwriting and pricing model | 5(c) | Yes | Risk assessment and pricing for life and health insurance in relation to natural persons is separately named. |
| Commercial lending decision about an incorporated company | none | No | 5(b) is limited to natural persons. A decision about a legal person is outside it, unless it scores an individual guarantor. |
Read the carve-out by purpose, one function at a time.The exception in 5(b) is for systems used for the purpose of detecting financial fraud. It is not a general risk exemption, and it does not travel from a fraud module to a scoring module just because they share a codebase. Write down which model does which job, and treat any function that answers “should we lend to this real person” as high-risk.
Point 5(c): risk assessment and pricing for life and health insurance
Sitting next to credit in the same Annex III entry is point 5(c): AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Underwriting models, risk-rating engines and premium-setting tools for those two lines are high-risk on the same 2 December 2027 timeline. The reasoning is the same as for credit: these systems decide an individual's access to, and the cost of, a service that materially affects their life.
Two limits are written into the point and worth holding onto. It reaches life and health insurance only, so motor, home, travel and commercial lines are not caught by 5(c). And it reaches risk assessment and pricing in relation to natural persons, so a model pricing a group scheme at the level of an employer, rather than rating the individuals within it, is a different analysis. Do not stretch 5(c) to every insurance model, and do not assume a health or life product escapes it because the pricing is dressed up as portfolio analytics.
Natural persons, not companies, and where SME lending sits
Both 5(b) and 5(c) are tied to natural persons, and that word does real work. A lending or insurance decision about a company as a legal person is outside these points. The place it bites is small-business and sole-trader credit, where the borrower often is an individual. A facility to an incorporated company is generally outside 5(b); credit assessed against a sole trader, a partner, or a named personal guarantor is inside it, because the model is evaluating the creditworthiness of a natural person.
The practical error is to wave SME lending through as commercial and therefore exempt. It is not categorical. Where the decision blends a company and an individual, the function that scores the natural person is the high-risk one, and it has to be documented and classified as such even if the headline product is business lending.
Where the Article 6(3) derogation gets over-claimed
Credit and insurance are, after hiring, the second place the Article 6(3) derogation is most often stretched past what it can bear. The pitch is familiar: the model only produces a score, a human makes the decision, so it merely performs a preparatory task or improves a human activity and lifts out of the high-risk regime. The text does not support it, for two independent reasons.
First, Article 6(3) ends with an override: a system that performs profiling of natural persons is alwayshigh-risk, with no balancing and no human-in-the-loop cure. A credit score evaluates a person's economic situation and behaviour to predict their likelihood of repayment. That is profiling, and it forecloses the derogation before the four conditions are reached. Second, even without the profiling override, the derogation's first limb asks whether the system poses a significant risk by materially influencing the outcome. A score a lender acts on materially influences whether a person gets credit, so the significant-risk gate closes. Art 6(3)
A human signature at the end does not rescue it. Human review of a ranked or scored list does not undo profiling, and a reviewer who sees the score but not the applicants the model already filtered out is not exercising the oversight the derogation imagines. Claiming 6(3) also does not make paperwork disappear: under Article 6(4) the provider must document the assessment before placing the system on the market, and a system self-assessed as non-high-risk must still be registered in the EU database. The realistic comparison is the full Chapter III high-risk stack against a documented, registered, defensible assessment you have to stand behind.
The overlap with existing financial services supervision
Lenders and insurers do not meet the AI Act on a blank sheet. They are already supervised, already run risk-management and governance frameworks, and already document models. The Act is built to coordinate with that rather than duplicate it, and getting the interaction right saves genuine work.
- Supervision runs through the financial authority. For high-risk AI systems placed on the market or used by regulated financial institutions, the market surveillance authority is the body already responsible for supervising that institution under Union financial services law, not a separate AI regulator. Art 74
- Existing governance can carry the equivalent duties. The Act is designed so that internal governance you already run under prudential rules can be used to meet the corresponding Article 9 risk-management and Article 17 quality-management obligations, rather than building a parallel system that says the same thing twice. Art 9, Art 17
- The AI-specific duties still stand. Coordination is not exemption. Data governance, logging, transparency to deployers, human oversight, accuracy and robustness and the conformity and registration steps apply on top of your prudential obligations.
One boundary is worth stating plainly, because clients ask: a lawful credit score is not the prohibited practice of social scoring. Article 5(1)(c) bans social scoring that leads to disproportionate or detrimental treatment across unrelated contexts, which is a different thing from assessing creditworthiness for a credit decision. A creditworthiness model is high-risk and permitted with obligations; it only strays toward the prohibition if it is turned into a general-purpose reputation score used to disadvantage people in contexts unrelated to the data. Keep the two apart in your documentation.
What to fix before 2 December 2027
Standalone Annex III obligations apply from 2 December 2027, a seventeen-month extension from the original 2 August 2026 date. For a lending or underwriting book that is not comfortable headroom: models live in production for years, and conformity assessment is not a sprint.
Five things that belong in the model inventory and the vendor questionnaire now:
- A function-level map of every model. For each model, record whether it evaluates creditworthiness (5(b)), prices life or health insurance (5(c)), detects fraud (the carve-out), or does something outside Annex III, and treat any system that mixes these as several functions rather than one.
- A written purpose for every fraud claim. If you rely on the 5(b) exception, the documented purpose has to be fraud detection, and the model must not be the one deciding creditworthiness. A claim that cannot survive that reading is not a claim.
- A natural-person test on the lending book. Flag where SME and sole-trader decisions score an individual or a guarantor, and classify those functions as high-risk rather than assuming commercial lending is exempt.
- A conformity and registration commitment. A dated plan to complete the assessment, issue the EU declaration of conformity and register ahead of 2 December 2027, with the Annex IV technical documentation maintained and available.
- Clarity on who is the provider. A bought scorecard used as supplied puts the vendor in the provider seat and you in the deployer seat, but retraining it on your own book or repurposing a general model to score applicants can flip you into the provider role. Settle that before it is settled for you in an inspection. Provider and deployer roles sets out the flip.
If you want the per-system answer rather than a general one, run each model through the free seven-stage triage classifier, which walks scope, prohibitions, Annex III, the derogation and your role in order and keeps the dated output as the start of your record. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.