Case Study: AI Governance Framework for a Mid-Market Fintech Lender
Client: A 340-employee consumer lending platform operating in the US and EU, using automated credit-scoring models to process loan applications. (Real version: name them if permitted, or use an accurate-but-anonymized descriptor like this if not — never a vague label like “a company.”)
The trigger: The client’s largest EU banking partner required proof of AI Act compliance ahead of the August 2026 high-risk system deadline before renewing their contract. They had no formal AI inventory and no documented human-oversight process for their credit model.
The challenge:
- 14 AI-driven tools in active use across underwriting, fraud detection, and customer support chat — only 4 were known to their compliance team before the engagement started.
- Their credit-scoring model qualified as “high-risk” under the EU AI Act, requiring documented human oversight, which didn’t exist in writing.
- No incident-response process if the model produced a disputed or biased outcome.
What we did (4-week engagement):
- Week 1: Full AI system inventory across underwriting, fraud, and support — surfaced 10 previously undocumented tools, including two vendor-embedded scoring add-ons the compliance team wasn’t aware of.
- Week 2: Risk classification against EU AI Act tiers; identified the core credit model and one fraud-detection tool as high-risk, requiring full documentation.
- Weeks 3–4: Built the governance policy — human oversight procedure for loan denials, incident-response protocol for disputed decisions, and a documentation standard for any future AI tool adoption.
Deliverables:
- Complete AI system inventory (14 systems, risk-classified)
- Governance policy document (oversight procedures, incident response, documentation standards)
- A working session training their compliance team to apply the framework going forward
Outcome:
- Client passed their EU banking partner’s compliance review and retained the contract.
- Reduced undocumented “shadow AI” tools from 10 to 0.
- Established a documented human-review step for all denied loan applications above a risk threshold — closing their single biggest audit exposure.
Timeline: Delivered in 5 weeks (1 week over the original 4-week estimate, due to the size of the shadow-AI discovery in week 1).