CASE FILE #47

An algorithm decides on a loan. The law requires more than the words “internal scoring”

Credit scoring can be fast and statistically accurate, yet it must remain reviewable. What the GDPR, the SCHUFA judgment and the European AI Act actually require.

An algorithm decides on a loan. The law requires more than the words “internal scoring”
Editorial illustration created with AI assistance.Credit scoring can be fast and statistically accurate, yet it must remain reviewable. What the GDPR, the SCHUFA judgment and the European AI Act actually require.
Listen
00:00/00:00
1.00 ×
Ready
Article contents
  1. 1. What can be substantiated
  2. 2. How to interpret the claims in context
  3. 3. Five questions to ask
  4. 4. Conclusion

Technology, finance & law

A rejected credit application is not proof of discrimination. But nor is it enough to claim that a model is a trade secret and therefore cannot be explained. What matters is the role the automated output actually played, the data that were used and whether a person can obtain a meaningful review.

1. What can be substantiated

Article 22 of the GDPR governs decisions based solely on automated processing that produce legal or similarly significant effects. Where an applicable exception is used, it also establishes safeguards, including the right to obtain human intervention and to contest the decision.[1]

In the SCHUFA case, the Court of Justice of the European Union ruled that creating a probability score may itself constitute automated decision-making if a third party attributes a determining role to it when entering into or performing a contract.[2]

The Artificial Intelligence Act classifies certain systems used to assess the creditworthiness of natural persons as high-risk. This entails obligations concerning risk management, data, documentation, logs, information and human oversight; it does not, however, ban all scoring.[3]

2. How to interpret the claims in context

Discrimination can arise even without using a protected characteristic if another variable acts as its proxy. This is a known risk mechanism, not proof that it occurred in a particular model. Establishing that requires an audit of the data, error rates and impacts on different groups.

A meaningful explanation need not disclose source code or the entire model. It must, however, enable a person to understand the main logic and decisive circumstances well enough to correct inaccurate data or contest the outcome.

Formal human approval does not automatically amount to genuine oversight. If the employee lacks the information, time or authority to change the verdict, it may be no more than a rubber stamp on the automated output.

What we know
  • European law does not leave automated lending processes unregulated.
  • What matters is the score's actual influence, not merely the name of an internal process.
  • High-risk classification entails obligations, not automatic illegality.
What we do not yet know
  • The variables and training data used by a particular bank's model.
  • Differences in error rates between groups in the absence of audit findings.
  • Whether human review at a particular institution can actually change a decision.

3. Five questions to ask

  1. Was the decision determined solely or effectively by the score?
  2. Which data can the applicant review and correct?
  3. What does human review involve, and who has the authority to change the verdict?
  4. How does the institution test for disparate impacts on different groups?
  5. Is the explanation sufficient to contest the decision effectively?

4. Conclusion

Algorithmic scoring is neither automatically fair nor automatically prohibited. It becomes trustworthy only through reviewable data, genuine human intervention and the opportunity to correct an error that denied someone access to credit.

— Jiný Kontext
Sources and literature

Sources and further reading 3 sources

  1. Other sourceGeneral Data Protection Regulation (GDPR) — Article 22 and the related rights to information. Source checked: August 31, 2026.
    General Data Protection Regulation (GDPR) — Article 22 and the related rights to information. Source checked: August 31 · 2026
  2. Other sourceCourt of Justice of the European Union: judgment in Case C-634/21, SCHUFA — the determining role of a probability score. Source checked: August 31, 2026.
    Court of Justice of the European Union: judgment in Case C-634/21, SCHUFA — the determining role of a probability score. Source checked: August 31 · 2026
  3. Other source/1689 — Artificial Intelligence Act — classification and obligations of high-risk systems. Source checked: August 31, 2026.
    Regulation (EU) · 2024