GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
How Banks Are Rethinking Credit Risk in an AI-Driven Economy - Banking news and analysis from Global Banking & Finance Review
Banking

How Banks Are Rethinking Credit Risk in an AI-Driven Economy

Published by Barnali Pal Sinha

Posted on August 21, 2026

13 min read
Add as preferred source on Google

AI is changing not only how banks assess borrowers, but also what counts as risk, which data matters and how quickly credit decisions must adapt to a changing economy.

Credit risk used to be built around a familiar set of questions: Can the borrower repay? How much collateral is available? What does the credit history show? How will the exposure behave in a downturn? Those questions remain fundamental. What is changing is the information available to answer them, the speed at which that information can be processed and the range of risks banks must now model.

Artificial intelligence is pushing credit risk beyond a static scorecard. Machine-learning models can combine conventional bureau data with transaction histories, cash-flow patterns, account behaviour, supply-chain information and other signals. They can monitor changes after a loan is originated rather than waiting for a periodic review. They can also identify patterns that traditional models may miss. But greater predictive power comes with new questions about explainability, data quality, bias, model drift, third-party dependencies and the danger that many lenders could begin responding to the same signals in the same way.

The result is not the end of credit judgement. It is a redesign of it. Banks are increasingly moving toward a model in which AI augments underwriting, portfolio monitoring and early-warning systems while governance, validation and human accountability become more important rather than less.

Credit risk is moving from periodic assessment to continuous sensing

Traditional underwriting is strongest when the relevant facts are stable and well documented. A mortgage applicant with a long credit history, regular income and a conventional employment profile can often be assessed with relatively structured information. The challenge grows when banks lend to small businesses, gig-economy workers, younger borrowers, fast-changing industries or companies whose cash flows can shift sharply between reporting periods.

AI expands the range of usable signals. A bank can analyse transaction-level cash flows, payment regularity, customer concentration, invoice behaviour or account volatility and update risk indicators more frequently than a conventional annual review. The World Bank has documented the increasing use of alternative data in credit-risk assessment, including transaction, mobile, digital-platform and other non-traditional information, particularly where conventional credit histories are thin. World Bank research on alternative data shows why this matters for financial inclusion as well as risk selection.

For banks, the strategic attraction is not simply a higher approval rate. Better data can improve segmentation: distinguishing a thin-file borrower who is genuinely risky from one who is financially sound but poorly represented by traditional bureau data. That can reduce unnecessary rejection without requiring the lender to weaken its risk appetite.

AI is becoming a second layer of underwriting, not a replacement for it

Evidence from the Bank for International Settlements suggests that technology and relationship lending can be complements rather than substitutes. A 2025 BIS working paper on Italian banks found that AI investments in credit scoring can work alongside relationship-based lending, helping banks process hard information while relationship managers contribute softer information that is difficult to encode. The study also found limits: during the Covid shock, AI use did not provide additional credit or interest-rate protection. The BIS study is a reminder that models trained on normal conditions do not automatically become superior judges of unusual conditions.

That limitation matters in 2026 because the economy itself is being reshaped by AI. Banks are not only using AI to assess credit; they are also lending to companies whose business models may be disrupted by it. Software firms, business-process providers, professional services companies and knowledge-intensive industries may face productivity gains on one side and margin compression or displacement on the other. Credit analysis therefore has to ask two different AI questions: how AI changes the lender’s model, and how AI changes the borrower’s future cash flows.

The borrower is changing faster than historical models can learn

Traditional credit models depend heavily on historical relationships. That is useful when the future resembles the past. It becomes less reliable when an industry is undergoing structural change. If AI reduces labour intensity, alters pricing, lowers barriers to entry or concentrates market power around a small number of platforms and infrastructure providers, yesterday’s financial ratios may be less informative about tomorrow’s resilience.

The Bank of England has highlighted this two-way risk. Its 2025 assessment of AI in the financial system noted that advanced AI could increasingly influence core financial decisions such as credit underwriting, while AI-driven disruption to economic sectors could itself change borrower creditworthiness. The Bank of England’s Financial Stability in Focus report also warned that greater use of similar AI systems could create correlated behaviour across firms.

For credit committees, this points toward more scenario-based analysis. A bank lending to a data-centre operator, software vendor or outsourced services company may need scenarios that capture AI-specific demand, investment and obsolescence risks. The same logic applies outside the technology sector. Retail, logistics, media, healthcare administration and professional services may all experience changes in cost structures and competitive intensity that are not fully visible in backward-looking default data.

Alternative data improves coverage, but raises the stakes for data governance

The more signals a model consumes, the more important it becomes to understand their provenance and meaning. Transaction data may be highly predictive, but it can also be seasonal. Device or behavioural data may appear useful but could introduce privacy, fairness or proxy-discrimination concerns. Data obtained from external vendors may be incomplete, unstable or subject to contractual limitations. Even conventional data can become misleading if definitions change or if a bank merges sources that were not designed to be compared.

This makes data governance part of credit risk rather than a separate technology issue. Banks need to know which variables influence a decision, whether those variables are permitted and appropriate, how frequently data is refreshed and what happens when a source disappears. They also need clear fallbacks. A model that performs well when every data feed is available may behave very differently during an outage or after a vendor changes its methodology.

Explainability is becoming an operating requirement

Credit decisions affect customers directly, and that makes explainability more than a technical preference. A bank must be able to understand why a model recommends a decline, a lower limit, a higher price or a change in risk grade. The more complex the model, the harder it can be to translate statistical relationships into a reason that is meaningful to a customer, a credit officer, an internal validator or a supervisor.

This is one reason many institutions are unlikely to move straight from conventional scoring to fully autonomous generative or agentic underwriting. In the United States, the Federal Reserve, OCC and FDIC issued revised model-risk guidance on 17 April 2026. The guidance retains a risk-based framework for traditional statistical, quantitative and non-generative AI models, but explicitly states that generative and agentic AI are outside its scope because they are novel and rapidly evolving. The revised Federal Reserve guidance nevertheless says banks should apply appropriate governance and controls to tools not covered by the document.

That distinction is important. It does not mean generative AI is ungoverned. It means banks cannot assume that a familiar model-validation checklist is sufficient for technologies whose outputs may be more dynamic, context dependent or difficult to reproduce.

Regulation is moving toward risk-based AI governance

The regulatory direction is becoming clearer across jurisdictions. The Financial Stability Board published a consultation in June 2026 proposing 12 sound practices for responsible AI adoption by financial institutions. The practices cover organisation-wide governance, lifecycle risk management, cyber and technology risk, and third-party dependencies. The FSB consultation is not a binding international standard, but it reflects a broad supervisory expectation: boards and senior management should understand where AI is used, what risks it creates and who is accountable for them.

The consultation attracted responses from banks, industry bodies, technology companies and other stakeholders, published by the FSB on 6 August 2026. That breadth of participation shows that the debate is moving beyond whether financial institutions should use AI and toward how governance should work in practice. FSB consultation responses are likely to inform the final report expected later in 2026.

In the European Union, AI systems used to evaluate the creditworthiness of natural persons or establish a credit score are classified as high-risk under Annex III of the AI Act, subject to the Act’s exceptions. The European Commission’s AI Act Service Desk states that the Annex III high-risk rules are scheduled to apply from 2 December 2027, while certain transparency and enforcement provisions began applying from 2 August 2026. EU AI Act Service Desk This gives banks time to prepare, but it also raises the value of building governance now rather than retrofitting it later.

Third-party AI is becoming part of the credit-risk perimeter

Banks rarely build every AI component themselves. They may rely on cloud providers, external data suppliers, fraud models, document-intelligence tools, model platforms and specialist credit-decisioning software. This can accelerate deployment, but it also changes where operational and model risk sits.

The concentration issue is already visible. In the Bank of England and FCA’s 2024 survey of AI in UK financial services, one-third of reported AI use cases involved third-party implementations. The top three providers accounted for 73% of reported cloud providers, 44% of model providers and 33% of data providers. The joint Bank of England/FCA survey suggests that AI risk can become correlated through shared infrastructure even when individual banks appear well diversified at the borrower level.

For credit risk, vendor governance therefore needs to cover more than cybersecurity and uptime. Banks need sufficient understanding of third-party models to assess conceptual soundness, data dependencies, performance and changes over time. The 2026 U.S. model-risk guidance explicitly emphasises ongoing monitoring and outcome analysis for vendor models, including understanding design, development data and performance.

The risk of model drift is becoming a credit-cycle issue

AI models can degrade when the relationships they learned change. Inflation, interest rates, employment patterns, payment behaviour, fraud techniques or industry structures can all shift. A model may still run correctly from a technical perspective while its economic assumptions are becoming less useful.

That makes monitoring central to AI-enabled credit risk. Banks need to track not only accuracy but stability across borrower groups, geographies, products and economic conditions. Overrides should be analysed rather than treated as noise. A rising rate of human overrides may indicate that frontline staff are seeing something the model has not captured. Conversely, a sudden collapse in overrides can be a warning sign if staff have become overly deferential to automated recommendations.

Human judgement is likely to migrate toward exceptions and uncertainty

The strongest case for AI is in situations where the bank has large volumes of data and repeated decisions. The strongest case for human judgement is where information is sparse, context matters or the future is unusually uncertain. That suggests a redistribution of work rather than a simple substitution of people by models.

Relationship managers and credit officers may spend less time assembling routine data and more time interpreting exceptions, challenging model outputs and assessing strategic risks. In commercial banking, the value of a relationship manager may increasingly come from understanding the borrower’s business model, management quality, competitive position and transition risks - precisely the kinds of factors that are difficult to reduce to a single score.

Could AI make credit risk more procyclical?

There is also a system-level question. If many banks and fintechs train models on similar data and use similar model architectures or third-party providers, they may identify the same deterioration at roughly the same time. Individually, that can look prudent. Collectively, it could amplify a downturn if lenders simultaneously reduce limits, tighten pricing or withdraw credit from the same sectors.

The Bank of England has explicitly identified the possibility that AI-enabled decision-making could encourage correlated behaviour. This does not imply that AI necessarily increases systemic risk; more responsive models could also identify problems earlier and reduce losses. The policy challenge is that speed and similarity can change the transmission of a credit shock. Stress testing may therefore need to consider not only borrower defaults but also how automated decision systems react to the same stress signals.

What the leading credit-risk model is likely to look like

The likely destination is not a single all-powerful AI underwriting engine. It is a layered architecture. Conventional credit metrics will remain important because they are interpretable, stable and embedded in regulation and accounting. Machine-learning models will add predictive signals and pattern detection. Generative AI may help summarise documents, extract covenants, analyse borrower disclosures or prepare credit memoranda. Human decision-makers will remain responsible for material exceptions, complex cases and policy judgements.

Five implications for bank credit-risk leaders

Priority What changes
Data governance Treat data lineage, quality and availability as part of credit-risk management, not only IT governance.
Model governance Validate performance, monitor drift and define controls proportionate to the model’s role in the decision.
Human accountability Use AI to support decisions without obscuring who owns approvals, overrides and customer outcomes.
Scenario design Add AI-driven industry disruption, provider concentration and correlated model behaviour to stress assumptions.
Vendor oversight Extend third-party due diligence to model design, data dependencies, change management and exit plans.

The competitive advantage may be better judgement, not simply faster decisions

AI can make credit processes faster and more granular, but speed is not the same as risk intelligence. The real advantage will come from combining models with disciplined governance and a richer understanding of borrowers. Banks that merely automate existing scorecards may lower processing costs. Banks that redesign the entire credit process - data collection, early warning, portfolio monitoring, scenario analysis, human challenge and model oversight - have a better chance of improving risk-adjusted decision-making.

The transformation also has a boundary. Credit is ultimately a claim on future cash flow, and the future is never fully observable. Models can improve estimates, identify patterns and update signals rapidly, but they cannot remove uncertainty. The more powerful AI becomes, the more important it is for banks to know where prediction ends and judgement begins.

For banks, the central question is therefore no longer whether AI will enter credit risk. It already has. The more important question is whether institutions can make their credit processes more adaptive without making them less understandable, less accountable or more fragile.

References

1. Federal Reserve - SR 26-2: Revised Guidance on Model Risk Management (17 April 2026)

2. Federal Reserve - Supervisory Guidance on Model Risk Management

3. Financial Stability Board - Sound Practices for Responsible Adoption of AI: Consultation Report (10 June 2026)

4. Financial Stability Board - Public responses to AI consultation (6 August 2026)

5. European Commission AI Act Service Desk - When does enforcement start?

6. European Commission AI Act Service Desk - Annex III high-risk systems

7. Bank for International Settlements - Artificial intelligence and relationship lending (19 February 2025)

8. Bank of England - Financial Stability in Focus: Artificial intelligence in the financial system (9 April 2025)

9. Bank of England and FCA - Artificial intelligence in UK financial services - 2024

10. World Bank - The Use of Alternative Data in Credit Risk Assessment

11. Federal Reserve - Speech by Vice Chair for Supervision Michelle W. Bowman on AI in the financial system (1 May 2026)

Related Articles

More from Banking

Explore more articles in the Banking category