Credit scoring, insurance pricing, benefits eligibility and emergency triage — access to essential services is the fifth of the Annex III high-risk areas, and the only one where private companies carry the fundamental rights impact assessment duty. Here is what is caught, what the fraud and prudential carve-outs actually exclude, and how it lines up with model risk management you may already run.
If an AI system decides who gets credit, at what insurance price, or whether a benefit is granted, it is high-risk under Annex III point 5. Two things are carved out and often misread as broader than they are: fraud detection (named in the Annex text) and prudential capital-requirement calculation (recital 58). And one duty is unique to this area: deployers of credit-scoring and life/health-insurance systems must run a fundamental rights impact assessment under Article 27 — the only Annex III systems named individually there.
Recital 58 explains the logic: these are services “necessary for people to fully participate in society or to improve one’s standard of living”, and the people applying for them are “typically dependent” and “in a vulnerable position in relation to the responsible authorities”. Credit scoring joins the list because it determines “access to financial resources or essential services such as housing, electricity, and telecommunication services”.
Point 5 (“Access to and enjoyment of essential private services and essential public services and benefits”) has four sub-points. The first is public-sector:
“AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services”
Regulation (EU) 2024/1689, Annex III, point 5(a)The second is the one most companies are searching for:
“AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud”
Regulation (EU) 2024/1689, Annex III, point 5(b)Note what is not in that sentence: any threshold, any qualifier about automation level, any exemption for “decision support”. Evaluating the creditworthiness of a natural person is enough. Note also what is there: natural persons. Point 5(b) is not drafted around corporate exposure.
The third covers insurance — but only two lines of it:
“AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance”
Regulation (EU) 2024/1689, Annex III, point 5(c)Motor, property and liability pricing are not named. And the fourth sub-point sits in a different world altogether: AI that evaluates and classifies emergency calls, dispatches or prioritises emergency first response services, and emergency healthcare patient triage.
Verdicts follow the text of the Regulation (Annex III point 5, Article 6(3) with recital 53) and recital 58. Where the answer turns on how the model is wired into the decision, the row says borderline rather than forcing a bucket.
| Use case | Verdict | Why |
|---|---|---|
| Consumer credit scoring / application scorecards | High-risk | Point 5(b) — evaluating creditworthiness or establishing a credit score of natural persons |
| Mortgage affordability and approval models | High-risk | Point 5(b); recital 58 names housing among the essential services credit decisions gate |
| Buy-now-pay-later and instant-lending decisioning | High-risk | Point 5(b) — the speed and channel change nothing; creditworthiness of a natural person is still being evaluated |
| Behavioural or alternative-data credit scoring | High-risk | Point 5(b), and squarely the discrimination concern recital 58 raises. Also check Article 5(1)(c): general-purpose social scoring is prohibited outright, not merely high-risk |
| Life or health insurance risk assessment and pricing | High-risk | Point 5(c) names both risk assessment and pricing for natural persons |
| Benefits eligibility, granting, reduction or reclaim | High-risk | Point 5(a), including where a contractor runs it on behalf of a public authority |
| Emergency call triage and dispatch prioritisation | High-risk | Point 5(d) — explicitly includes police, fire, medical aid and patient triage |
| Financial fraud detection | Not high-risk | Named exception in point 5(b) itself, reinforced by recital 58. Scope follows purpose — see the carve-out section below |
| Prudential capital-requirement models (credit institutions, insurers) | Not high-risk | Recital 58: models provided for by Union law for prudential purposes to calculate capital requirements are not high-risk under this Regulation. Their own supervisory regime still applies in full |
| Motor, property or liability insurance pricing | Not point 5(c) | Point 5(c) is limited to life and health insurance. Other lines are outside this point — which is a scope answer, not a clearance from the rest of the Act |
| Corporate / SME exposure assessment | Borderline — depends whose creditworthiness | Point 5(b) says natural persons. Sole traders, personal guarantees and small-business decisions resting on an individual’s credit profile evaluate a natural person and are caught |
| Document classification and data extraction in loan intake | Borderline — assess under Art 6(3) | Structuring unstructured data is a recital 53 narrow procedural task — provided it does not materially influence the decision and does not profile; document under Art 6(4) |
| Collections prioritisation and arrears treatment | Borderline | Not creditworthiness evaluation on its face, but where the score feeds back into credit limits or refinancing terms, that use is point 5(b). Classify per use, not per model |
Why the Article 6(3) derogation is closed to credit scoring. Elsewhere in Annex III, a listed system can argue its way out under Article 6(3) by showing it performs only a narrow procedural or preparatory task. That route is unavailable here. The final subparagraph of Article 6(3) states that an Annex III system “shall always be considered to be high-risk where the AI system performs profiling of natural persons” — and Article 3(52) defines profiling by reference to Article 4(4) GDPR: automated processing used to evaluate personal aspects, expressly including a person’s economic situation and reliability. Evaluating creditworthiness is that, by definition. The derogation can still apply to genuinely peripheral tooling around the decision — document intake, deduplication — but not to the scoring itself.
These two exclusions are real, and they are narrower than the relief people take from them. Recital 58 states both in one sentence:
“However, AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions’ and insurance undertakings’ capital requirements should not be considered to be high-risk under this Regulation.”
Regulation (EU) 2024/1689, recital 58Purpose, not plumbing. Annex III classifies by intended use. One gradient-boosted model can serve a fraud-screening purpose and a credit-decisioning purpose, and the carve-out follows only the first. If the fraud score also caps a limit, prices a product or drives a decline, that second use is a point 5(b) use and needs its own recorded verdict. The practical consequence for model inventories: the unit of registration is the use of a model, not the model artefact — and teams that inventory by artefact tend to discover this late.
Most Annex III areas leave private-sector deployers with the Article 26 duties and no fundamental rights impact assessment. Point 5 is the exception. Article 27(1) requires a FRIA from deployers that are bodies governed by public law, from private entities providing public services — and, naming them individually, from deployers of the AI systems referred to in points 5(b) and 5(c) of Annex III. A commercial bank scoring credit, and an insurer pricing life or health cover, carry the duty because of what the system does, not because of who they are.
The assessment has to describe the deployer’s processes in which the system will be used, the period and frequency of use, the categories of natural persons likely to be affected, the specific risks of harm to them, the human-oversight measures, and what happens if those risks materialise. It is a different exercise from a data protection impact assessment, and a different exercise again from model validation — the question is harm to people, not error rates.
One duty in this area points outward, at the customer. Article 86 gives any affected person subject to a decision taken by the deployer on the basis of the output of an Annex III high-risk system — where that decision produces legal effects or similarly significantly affects them adversely — the right to obtain from the deployer “clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken”. A declined loan application is the textbook case.
Two qualifications worth knowing before this drives an explainability programme. Article 86 excludes Annex III point 2 systems, and it does not apply where an equivalent right already follows from other Union law — which for automated credit decisions often means GDPR Article 22 is already doing the work. The practical consequence is the same either way: the decision has to be explainable to the person it was taken about, and the explanation has to be reconstructable months later, which is a record-keeping problem as much as a modelling one.
Banks and insurers reading this are rarely starting from zero. Supervisory model risk management — the US Federal Reserve and OCC framework long known as SR 11-7, replaced in April 2026 by SR 26-2, and its equivalents in EU supervision — already demands a model inventory, documented development and testing, independent validation, and ongoing performance monitoring. That maps closely onto the provider stack: Article 9 risk management, technical documentation, record-keeping, accuracy and robustness, and post-market monitoring.
Two gaps remain, and they are the ones that catch mature institutions out:
The practical route is to treat the existing model risk management estate as the foundation, extend the inventory to the wider AI population, and add the fundamental-rights layer on top — rather than standing up a parallel regime. We wrote about how those two worlds line up in from SR 11-7 to the EU AI Act.
If you buy the scoring or pricing system, you are a deployer: use per instructions, assign human oversight to people with the necessary competence, training and authority, control input data quality where you control the inputs, monitor operation and report serious incidents, keep logs for at least six months (Article 26) — plus the FRIA above.
If you build it in-house, which most lenders and insurers do for their core scorecards, you are the provider and the deployer, and you carry both stacks: risk management system (Art 9), data governance, technical documentation, transparency to deployers (Art 13), human-oversight design (Art 14), accuracy and robustness, conformity assessment and registration. Putting your name on a bought system, or substantially modifying it, has the same effect (Article 25).
The Regulation as enacted set 2 August 2026 for the Annex III obligations. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — moved that date to 2 December 2027. The Article 5 prohibitions, including social scoring, have applied since February 2025 and did not move. Neither did the reality that a FRIA covering every affected customer segment is not a quarter’s work.
The recurring failure mode in this area is inventorying models when the Act classifies uses. The same scorecard can be a fraud screen (out of scope) and a credit gate (in scope); the same customer model can price a life policy (point 5(c)) and a motor policy (outside point 5). What has to be recorded per use is the verdict, the sub-point relied on, whether an Article 6(3) condition was claimed and why, whether a FRIA is required, and who signed it off — with a history that survives the next model refresh.
Model Inventory for Jira turns each AI system into a work item in the Jira your team already uses, with a built-in EU AI Act category field and dynamic risk tiering. It comes from Model Governance Suite, the model risk platform we built for and run with a European banking group — so the data model reflects how regulated model inventories actually behave: per-use records, immutable change history, and evidence attached where an auditor will look for it.
See how it worksYes. Point 5(b) covers evaluating the creditworthiness of natural persons or establishing their credit score, with no threshold and no decision-support exemption. The only exception written into the Annex is fraud detection.
No — it is excluded by point 5(b) itself, and recital 58 also excludes prudential capital-requirement models. But the exclusion attaches to the purpose. A fraud model whose output also gates credit decisions is in scope for that second use.
It is drafted around natural persons, so pure corporate exposure sits outside. Sole traders, personal guarantees and small-business decisions resting on an individual’s credit profile do evaluate a natural person — classify by whose creditworthiness is assessed, not by the lending product.
For point 5(b) and 5(c) systems, yes. Article 27 names them specifically, which makes credit scoring and life/health insurance the two places where a private company carries the FRIA duty purely because of the system’s function.
Yes — Article 86 gives affected persons the right to clear and meaningful explanations of the role the AI system played and the main elements of the decision, where the decision produces legal effects or similarly significantly affects them adversely. It does not apply where an equivalent right already follows from other Union law, which for automated credit decisions often means GDPR Article 22 is already doing the work.
No. Article 6(3) closes the derogation for any Annex III system that performs profiling of natural persons, and Article 3(52) defines profiling via GDPR Article 4(4) — evaluating personal aspects including economic situation and reliability. That is what creditworthiness assessment does. Peripheral tooling around the decision may still qualify.
Existing model risk management covers most of the provider stack — inventory, documentation, validation, monitoring. It does not cover the fundamental-rights framing the FRIA demands, and its inventory scope is usually narrower than the Act’s. Extend rather than duplicate.
Annex III high-risk obligations: 2 December 2027, moved from 2 August 2026 by the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026). Prohibitions, including social scoring: since February 2025.
This page is a practical explanation, not legal advice. Always confirm classification against the official text of Regulation (EU) 2024/1689 and, where the stakes warrant it, qualified counsel.