Credit scoring is the one AI use case that appears on every regulatory list at once: Annex III high-risk under the AI Act, FRIA-triggering under Article 27, automated-decision territory under KVKK Article 11, and squarely inside BDDK’s and the CMB’s supervisory instincts at home. If your fintech scores, prices or pre-approves with models, your compliance stack has four floors, and most companies have furnished only one.
Floor 1. KVKK, in force now
A declined applicant has the Article 11 right to object to an exclusively automated adverse result. Your loan funnel needs: a human-review path with real authority to overturn; aydınlatma that names scoring and profiling; lawful-basis discipline for every data source feeding the model (KKB data, telecom signals, device data, open-banking flows have different legal characters); and retention limits for declined files. Alternative-data enthusiasm is where fintechs most often step outside their lawful basis.
Floor 2. Turkish financial regulation
Model-driven lending lives inside existing prudential expectations: internal-model governance, validation independent of the developers, audit trails for decisions, and outsourcing rules when the model or data is a vendor’s. BDDK’s outsourcing and information-systems frameworks apply to your scoring vendor stack today; no AI-specific law needed. For lending-adjacent products (BNPL and its perimeter questions, see our BNPL analysis), the model often is the licensable activity’s core.
Floor 3. AI Act, for EU-facing lending
Creditworthiness assessment of natural persons is Annex III high-risk: from 2 December 2027, the full regime applies; risk management, data governance and bias controls, technical documentation, logging, human oversight, accuracy monitoring. And because credit scoring is one of Article 27’s named triggers, deployers face a FRIA obligation (our walkthrough). The Article 50 transparency layer arrives earlier, on 2 August 2026.
Floor 4; discrimination and explainability
Equal-treatment law does not wait for the AI Act: a model that proxies gender through shopping categories or ethnicity through postcode produces documented, discoverable disparate impact. The defensible position combines bias testing on Turkish-market data, feature governance (a written list of prohibited and proxy-suspicious features), and an explainability layer able to produce a human-readable principal-reasons statement for every adverse decision, which conveniently is also what good customer service wants.
The build order we recommend
- Article 11 human-review path + aydınlatma refresh (weeks, not months).
- Feature governance and bias-test baseline; log everything the model sees and decides.
- Vendor stack review against BDDK outsourcing rules and the six AI-contract clauses from our GPAI piece.
- Map the December 2027 Annex III gap (risk management system, technical file, FRIA template) and put it on the roadmap now; conformity is a product feature with a lead time.
We advise scoring fintechs across this stack at the intersection of AI & Algorithm Law and financial regulation.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
When the Model Causes Harm: AI Incident Response Across the AI Act, KVKK and the New Product Liability Rules
July 28, 2026The Classification Memo: How to Map Your Product to the AI Act in One Afternoon
July 30, 2026You Didn’t Train the Model, but You Still Have AI Act Obligations: GPAI Rules for Companies Building on GPT, Claude and Llama
July 14, 2026FRIA Without the Fog: Who Really Needs a Fundamental Rights Impact Assessment, and How to Run One on Top of Your KVKK DPIA
July 13, 2026Türkiye's Draft AI Law (2/2234): What It Takes from the EU AI Act: and What It Leaves Out
July 7, 2026The EU AI Act Was Postponed: Except the Part That Hits on 2 August
July 6, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →