Credit scoring is the one AI use case that appears on every regulatory list at once: Annex III high-risk under the AI Act, FRIA-triggering under Article 27, automated-decision territory under KVKK Article 11, and squarely inside BDDK’s and the CMB’s supervisory instincts at home. If your fintech scores, prices or pre-approves with models, your compliance stack has four floors, and most companies have furnished only one.
Floor 1. KVKK, in force now
A declined applicant has the Article 11 right to object to an exclusively automated adverse result. Your loan funnel needs: a human-review path with real authority to overturn; aydınlatma that names scoring and profiling; lawful-basis discipline for every data source feeding the model (KKB data, telecom signals, device data, open-banking flows have different legal characters); and retention limits for declined files. Alternative-data enthusiasm is where fintechs most often step outside their lawful basis.
Floor 2. Turkish financial regulation
Model-driven lending lives inside existing prudential expectations: internal-model governance, validation independent of the developers, audit trails for decisions, and outsourcing rules when the model or data is a vendor’s. BDDK’s outsourcing and information-systems frameworks apply to your scoring vendor stack today; no AI-specific law needed. For lending-adjacent products (BNPL and its perimeter questions, see our BNPL analysis), the model often is the licensable activity’s core.
Floor 3. AI Act, for EU-facing lending
Creditworthiness assessment of natural persons is Annex III high-risk: from 2 December 2027, the full regime applies; risk management, data governance and bias controls, technical documentation, logging, human oversight, accuracy monitoring. And because credit scoring is one of Article 27’s named triggers, deployers face a FRIA obligation (our walkthrough). The Article 50 transparency layer arrives earlier, on 2 August 2026.
Floor 4; discrimination and explainability
Equal-treatment law does not wait for the AI Act: a model that proxies gender through shopping categories or ethnicity through postcode produces documented, discoverable disparate impact. The defensible position combines bias testing on Turkish-market data, feature governance (a written list of prohibited and proxy-suspicious features), and an explainability layer able to produce a human-readable principal-reasons statement for every adverse decision, which conveniently is also what good customer service wants.
The build order we recommend
- Article 11 human-review path + aydınlatma refresh (weeks, not months).
- Feature governance and bias-test baseline; log everything the model sees and decides.
- Vendor stack review against BDDK outsourcing rules and the six AI-contract clauses from our GPAI piece.
- Map the December 2027 Annex III gap (risk management system, technical file, FRIA template) and put it on the roadmap now; conformity is a product feature with a lead time.
We advise scoring fintechs across this stack at the intersection of AI & Algorithm Law and financial regulation.
Sources. Regulation (EU) 2024/1689 (AI Act) and Law No. 6698 on the Protection of Personal Data (KVKK). Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
Whose Voice Is It Anyway? Voice Cloning Under Turkish Personality Rights, KVKK Biometrics and FSEK
August 26, 2026The Regulator Will See You Now: How Startups Get Into the AI Act Sandboxes (Deadline Moved to August 2027)
August 25, 2026"It’s Open Source" Is Not a Compliance Strategy: What the AI Act’s Open-Source Exemption Actually Covers
August 24, 2026A 12-Month Cap on Off-Exchange Share Sales: Rebuilding the Post-IPO Exit Plan
September 1, 2026Three Ways to Move Up the IPO Queue: Türkiye's New Priority Criteria
September 1, 2026English Is No Longer the Exception on KAP: The Process to Build Before 1 October 2026
August 31, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →