EU AI Act  /  Annex III · Point 5
Annex III · Credit, Insurance & Essential Services

Is your credit-scoring AI high-risk? Annex III point 5, decoded

Credit scoring, insurance pricing, benefits eligibility and emergency triage — access to essential services is the fifth of the Annex III high-risk areas, and the only one where private companies carry the fundamental rights impact assessment duty. Here is what is caught, what the fraud and prudential carve-outs actually exclude, and how it lines up with model risk management you may already run.

Short answer

If an AI system decides who gets credit, at what insurance price, or whether a benefit is granted, it is high-risk under Annex III point 5. Two things are carved out and often misread as broader than they are: fraud detection (named in the Annex text) and prudential capital-requirement calculation (recital 58). And one duty is unique to this area: deployers of credit-scoring and life/health-insurance systems must run a fundamental rights impact assessment under Article 27 — the only Annex III systems named individually there.

Recital 58 explains the logic: these are services “necessary for people to fully participate in society or to improve one’s standard of living”, and the people applying for them are “typically dependent” and “in a vulnerable position in relation to the responsible authorities”. Credit scoring joins the list because it determines “access to financial resources or essential services such as housing, electricity, and telecommunication services”.

What Annex III point 5 actually covers

Point 5 (“Access to and enjoyment of essential private services and essential public services and benefits”) has four sub-points. The first is public-sector:

The second is the one most companies are searching for:

Note what is not in that sentence: any threshold, any qualifier about automation level, any exemption for “decision support”. Evaluating the creditworthiness of a natural person is enough. Note also what is there: natural persons. Point 5(b) is not drafted around corporate exposure.

The third covers insurance — but only two lines of it:

Motor, property and liability pricing are not named. And the fourth sub-point sits in a different world altogether: AI that evaluates and classifies emergency calls, dispatches or prioritises emergency first response services, and emergency healthcare patient triage.

Use-case verdicts: financial and public-service AI

Verdicts follow the text of the Regulation (Annex III point 5, Article 6(3) with recital 53) and recital 58. Where the answer turns on how the model is wired into the decision, the row says borderline rather than forcing a bucket.

Use caseVerdictWhy
Consumer credit scoring / application scorecardsHigh-riskPoint 5(b) — evaluating creditworthiness or establishing a credit score of natural persons
Mortgage affordability and approval modelsHigh-riskPoint 5(b); recital 58 names housing among the essential services credit decisions gate
Buy-now-pay-later and instant-lending decisioningHigh-riskPoint 5(b) — the speed and channel change nothing; creditworthiness of a natural person is still being evaluated
Behavioural or alternative-data credit scoringHigh-riskPoint 5(b), and squarely the discrimination concern recital 58 raises. Also check Article 5(1)(c): general-purpose social scoring is prohibited outright, not merely high-risk
Life or health insurance risk assessment and pricingHigh-riskPoint 5(c) names both risk assessment and pricing for natural persons
Benefits eligibility, granting, reduction or reclaimHigh-riskPoint 5(a), including where a contractor runs it on behalf of a public authority
Emergency call triage and dispatch prioritisationHigh-riskPoint 5(d) — explicitly includes police, fire, medical aid and patient triage
Financial fraud detectionNot high-riskNamed exception in point 5(b) itself, reinforced by recital 58. Scope follows purpose — see the carve-out section below
Prudential capital-requirement models (credit institutions, insurers)Not high-riskRecital 58: models provided for by Union law for prudential purposes to calculate capital requirements are not high-risk under this Regulation. Their own supervisory regime still applies in full
Motor, property or liability insurance pricingNot point 5(c)Point 5(c) is limited to life and health insurance. Other lines are outside this point — which is a scope answer, not a clearance from the rest of the Act
Corporate / SME exposure assessmentBorderline — depends whose creditworthinessPoint 5(b) says natural persons. Sole traders, personal guarantees and small-business decisions resting on an individual’s credit profile evaluate a natural person and are caught
Document classification and data extraction in loan intakeBorderline — assess under Art 6(3)Structuring unstructured data is a recital 53 narrow procedural task — provided it does not materially influence the decision and does not profile; document under Art 6(4)
Collections prioritisation and arrears treatmentBorderlineNot creditworthiness evaluation on its face, but where the score feeds back into credit limits or refinancing terms, that use is point 5(b). Classify per use, not per model

Why the Article 6(3) derogation is closed to credit scoring. Elsewhere in Annex III, a listed system can argue its way out under Article 6(3) by showing it performs only a narrow procedural or preparatory task. That route is unavailable here. The final subparagraph of Article 6(3) states that an Annex III system “shall always be considered to be high-risk where the AI system performs profiling of natural persons” — and Article 3(52) defines profiling by reference to Article 4(4) GDPR: automated processing used to evaluate personal aspects, expressly including a person’s economic situation and reliability. Evaluating creditworthiness is that, by definition. The derogation can still apply to genuinely peripheral tooling around the decision — document intake, deduplication — but not to the scoring itself.

The fraud and prudential carve-outs

These two exclusions are real, and they are narrower than the relief people take from them. Recital 58 states both in one sentence:

Purpose, not plumbing. Annex III classifies by intended use. One gradient-boosted model can serve a fraud-screening purpose and a credit-decisioning purpose, and the carve-out follows only the first. If the fraud score also caps a limit, prices a product or drives a decline, that second use is a point 5(b) use and needs its own recorded verdict. The practical consequence for model inventories: the unit of registration is the use of a model, not the model artefact — and teams that inventory by artefact tend to discover this late.

The FRIA duty and the right to an explanation

Most Annex III areas leave private-sector deployers with the Article 26 duties and no fundamental rights impact assessment. Point 5 is the exception. Article 27(1) requires a FRIA from deployers that are bodies governed by public law, from private entities providing public services — and, naming them individually, from deployers of the AI systems referred to in points 5(b) and 5(c) of Annex III. A commercial bank scoring credit, and an insurer pricing life or health cover, carry the duty because of what the system does, not because of who they are.

The assessment has to describe the deployer’s processes in which the system will be used, the period and frequency of use, the categories of natural persons likely to be affected, the specific risks of harm to them, the human-oversight measures, and what happens if those risks materialise. It is a different exercise from a data protection impact assessment, and a different exercise again from model validation — the question is harm to people, not error rates.

The applicant’s right to an explanation

One duty in this area points outward, at the customer. Article 86 gives any affected person subject to a decision taken by the deployer on the basis of the output of an Annex III high-risk system — where that decision produces legal effects or similarly significantly affects them adversely — the right to obtain from the deployer “clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken”. A declined loan application is the textbook case.

Two qualifications worth knowing before this drives an explainability programme. Article 86 excludes Annex III point 2 systems, and it does not apply where an equivalent right already follows from other Union law — which for automated credit decisions often means GDPR Article 22 is already doing the work. The practical consequence is the same either way: the decision has to be explainable to the person it was taken about, and the explanation has to be reconstructable months later, which is a record-keeping problem as much as a modelling one.

If you already run model risk management

Banks and insurers reading this are rarely starting from zero. Supervisory model risk management — the US Federal Reserve and OCC framework long known as SR 11-7, replaced in April 2026 by SR 26-2, and its equivalents in EU supervision — already demands a model inventory, documented development and testing, independent validation, and ongoing performance monitoring. That maps closely onto the provider stack: Article 9 risk management, technical documentation, record-keeping, accuracy and robustness, and post-market monitoring.

Two gaps remain, and they are the ones that catch mature institutions out:

The practical route is to treat the existing model risk management estate as the foundation, extend the inventory to the wider AI population, and add the fundamental-rights layer on top — rather than standing up a parallel regime. We wrote about how those two worlds line up in from SR 11-7 to the EU AI Act.

Provider or deployer: what you must do

If you buy the scoring or pricing system, you are a deployer: use per instructions, assign human oversight to people with the necessary competence, training and authority, control input data quality where you control the inputs, monitor operation and report serious incidents, keep logs for at least six months (Article 26) — plus the FRIA above.

If you build it in-house, which most lenders and insurers do for their core scorecards, you are the provider and the deployer, and you carry both stacks: risk management system (Art 9), data governance, technical documentation, transparency to deployers (Art 13), human-oversight design (Art 14), accuracy and robustness, conformity assessment and registration. Putting your name on a bought system, or substantially modifying it, has the same effect (Article 25).

When this applies

The Regulation as enacted set 2 August 2026 for the Annex III obligations. The Digital Omnibus on AIRegulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — moved that date to 2 December 2027. The Article 5 prohibitions, including social scoring, have applied since February 2025 and did not move. Neither did the reality that a FRIA covering every affected customer segment is not a quarter’s work.

Recording the classification

The recurring failure mode in this area is inventorying models when the Act classifies uses. The same scorecard can be a fraud screen (out of scope) and a credit gate (in scope); the same customer model can price a life policy (point 5(c)) and a motor policy (outside point 5). What has to be recorded per use is the verdict, the sub-point relied on, whether an Article 6(3) condition was claimed and why, whether a FRIA is required, and who signed it off — with a history that survives the next model refresh.

Track this in your Jira

Give every model use its own classification record

Model Inventory for Jira turns each AI system into a work item in the Jira your team already uses, with a built-in EU AI Act category field and dynamic risk tiering. It comes from Model Governance Suite, the model risk platform we built for and run with a European banking group — so the data model reflects how regulated model inventories actually behave: per-use records, immutable change history, and evidence attached where an auditor will look for it.

See how it works

FAQ

Is credit scoring high-risk under the EU AI Act?

Yes. Point 5(b) covers evaluating the creditworthiness of natural persons or establishing their credit score, with no threshold and no decision-support exemption. The only exception written into the Annex is fraud detection.

Is fraud detection high-risk?

No — it is excluded by point 5(b) itself, and recital 58 also excludes prudential capital-requirement models. But the exclusion attaches to the purpose. A fraud model whose output also gates credit decisions is in scope for that second use.

Does point 5(b) cover corporate lending?

It is drafted around natural persons, so pure corporate exposure sits outside. Sole traders, personal guarantees and small-business decisions resting on an individual’s credit profile do evaluate a natural person — classify by whose creditworthiness is assessed, not by the lending product.

Do banks and insurers need a FRIA?

For point 5(b) and 5(c) systems, yes. Article 27 names them specifically, which makes credit scoring and life/health insurance the two places where a private company carries the FRIA duty purely because of the system’s function.

Does a rejected applicant have a right to an explanation?

Yes — Article 86 gives affected persons the right to clear and meaningful explanations of the role the AI system played and the main elements of the decision, where the decision produces legal effects or similarly significantly affects them adversely. It does not apply where an equivalent right already follows from other Union law, which for automated credit decisions often means GDPR Article 22 is already doing the work.

Can credit scoring use the Article 6(3) exception?

No. Article 6(3) closes the derogation for any Annex III system that performs profiling of natural persons, and Article 3(52) defines profiling via GDPR Article 4(4) — evaluating personal aspects including economic situation and reliability. That is what creditworthiness assessment does. Peripheral tooling around the decision may still qualify.

How does this map to SR 11-7 / SR 26-2?

Existing model risk management covers most of the provider stack — inventory, documentation, validation, monitoring. It does not cover the fundamental-rights framing the FRIA demands, and its inventory scope is usually narrower than the Act’s. Extend rather than duplicate.

When do these rules start to apply?

Annex III high-risk obligations: 2 December 2027, moved from 2 August 2026 by the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026). Prohibitions, including social scoring: since February 2025.

This page is a practical explanation, not legal advice. Always confirm classification against the official text of Regulation (EU) 2024/1689 and, where the stakes warrant it, qualified counsel.