You can make a defensible lending decision today and still have a problem eight months from now: can you reconstruct exactly why you made it?
Your model may have changed. Your credit policy may have changed. Thresholds may have been retuned. New data may have arrived. The system running today may be materially better than the one that made the original assessment.
None of that matters to the borrower asking about one decision, made on one day, using one set of information. They are not asking how your system works now. They are asking why it made that decision then.
That distinction is becoming an operational requirement.
The obligations are arriving on different clocks
Some of this already exists under GDPR for decisions based solely on automated processing that produce legal or similarly significant effects.
The revised Consumer Credit Directive makes the lending context explicit. From 20 November 2026, where a creditworthiness assessment involves automated processing, consumers have the right to human intervention and to a clear and comprehensible explanation of the assessment. The directive is specific about what that explanation must cover: the logic and risks involved in the automated processing, and its significance and effects on the decision. Consumers can also express their point of view and request a review.
That is not a description of a model. It is an account of one assessment.
The EU AI Act goes further on the systems themselves. AI systems used to evaluate the creditworthiness of natural persons are classified as high-risk, subject to the fraud-detection exception. Those obligations were due to apply from August 2026. The Digital Omnibus on AI, in force since July 2026, moved standalone Annex III systems to 2 December 2027.
The deadline moved. The engineering problem did not.
The record has to outlive the system
A credit policy is rarely static. By the time somebody asks about an assessment you made eight months ago, the rules running in production may no longer be the rules that applied at the time.
Reconstructing that decision from today's system is not reconstructing it. It is producing a new answer to an old question.
The Court of Justice addressed the underlying distinction in CK v Dun & Bradstreet Austria. A meaningful explanation is not satisfied by handing someone an algorithm or walking them through every processing step. The person has to understand what happened well enough to challenge it.
Take a declined application. A generic explanation says the application did not meet our credit criteria. That describes the outcome without explaining it. Your applicant does not know what mattered, whether the information was correct, or what would have needed to be different.
A decision-level explanation says that recurring obligations were too high relative to observed income for the amount requested.
Now there is something to inspect. Was the income measured correctly? Were those obligations actually recurring? Would a lower requested amount have changed the assessment?
That does not require exposing every parameter inside your model. It requires preserving what actually drove this particular assessment: the data available, the signals derived from it, how certain those signals were, which policy version applied, which thresholds were evaluated, and what that combination produced.
Your record has to hold the values actually used, not pointers to whatever those values would be if calculated today. That distinction sounds technical. It is what makes an explanation defensible months or years later.
What this changed on our side
Lend is Neumetria's layer for lenders. It takes the behavioral state we interpret from financial activity and makes it usable inside your credit process.
We separate two things that often get blurred: our reading of financial state, and your decision policy. You author the policy. Neumetria does not set what constitutes an approval, a limit, or a price. Our job is to make the information underneath your policy usable and reconstructable.
That starts with versioning. Once you publish a policy version, it is preserved rather than silently overwritten by the next one, so a historical assessment stays tied to the rules that actually applied when it ran. Before a new policy reaches live applicants, you can evaluate it against historical assessments to see how those rules would have behaved.
The same principle applies to explanation and review. The evidence needed to understand an assessment belongs in the decision record itself, not assembled after somebody contests the result. Which is also why model documentation cannot be a file written once and left in a folder. The system changes, so the documentation has to stay connected to it.
What we have not finished
Some of that work is complete. Some is not.
Systematic discrimination testing and our full model-validation framework are still being completed. We would rather state that boundary explicitly than imply that documentation alone resolves model risk.
Transaction data makes this particularly important. Spending patterns can act as proxies for characteristics you are not permitted to use, even when you never collect them.
Explainability does not solve that. Neither does auditability. They let you find, test and challenge what your system is doing. Fairness still has to be demonstrated separately.
Build the record before somebody asks for it
The temptation is to treat this as documentation work to finish when the regulation bites. The December 2027 deferral makes that temptation stronger.
It gets the sequence backwards. You cannot reconstruct a decision retrospectively if you did not preserve what happened when you made it. Data lineage, policy version, model state, confidence and outcome have to be in the record from day one. By the time a borrower, a model risk team, an auditor or a regulator asks why, the answer either already exists or it does not.
Getting the assessment right was always the job. What has changed is that being right is no longer enough on its own.
You also have to stand behind the decision months later, in front of someone entitled to ask why. That changes what your lending infrastructure has to preserve: not only the answer, but the evidence, policy and reasoning that produced it.
See how Lend makes a lending assessment reconstructable
This article is provided for general informational purposes and does not constitute legal, compliance or credit advice.
by Amr Mohamed