Cadence
Audit

Annex III 5(b) makes this system high risk

Control tests CO2, CO3 and CO4 failed for one reason between them: the questions had been thought about and never written down. These are the answers, each with the reasoning that produced it, an owner, a date, and the change that would make it wrong.

A self-assessment of a prototype running on synthetic data. It carries no legal advice and asserts nothing about any institution. The tests that read it are at control tests.

AI Act Articles 6 and 49, Annex III point 5(b)

Risk classification of the lending system

Conclusion

High risk. Annex III point 5(b), with no derogation available.

  1. 1

    The purpose is the one Annex III names

    The system evaluates the creditworthiness of a natural person applying for a consumer loan. Annex III point 5(b) names that use case, and it is the only banking use case the Annex names. The same point carves out systems used to detect financial fraud, and that carve-out does not reach this system.

  2. 2

    A model on the inputs is still a component of the assessment

    The credit decision is deterministic code. The models label statement lines, draft the explanation and score that explanation. A label that feeds the Haushaltsrechnung is a component of the creditworthiness assessment, and classification follows the purpose a component serves rather than the technique it uses. Building the decision out of rules narrows what can go wrong, and it does not take the system out of Annex III.

  3. 3

    The Article 6(3) derogation looked available

    Article 6(3) releases an Annex III system from the high-risk category when it poses no significant risk of harm and does one of 4 things: a narrow procedural task, an improvement to a completed human activity, detection of decision patterns without replacing human assessment, or a preparatory task. Read alone, the categoriser is a preparatory task to the affordability calculation.

  4. 4

    The profiling sentence closes it

    The final subparagraph of Article 6(3) holds that an Annex III system performing profiling of natural persons is always high risk. Deriving income, recurring commitments and credit obligations from a person's own transactions is an evaluation of their economic situation, which is profiling on the GDPR Article 4(4) definition the AI Act adopts. The derogation is therefore unavailable, and the Article 6(4) documentation and registration route that follows a derogation does not arise.

What follows from it
  • Deployer duties under Article 26 attach and cannot be contracted away to a model provider.
  • A fundamental rights impact assessment is required under Article 27 before use. It is the third assessment on this page.
  • An affected applicant holds the Article 86 right to an explanation of the decision.
  • Annex III obligations apply from 2 December 2027 after the deferral by Regulation (EU) 2026/1744. Article 50 transparency was not deferred and applies from 2 August 2026.
What would make it wrong

Re-assess if the decision stops being deterministic, if a model output reaches the outcome with no deterministic step between, or if the product is offered to anyone other than a consumer borrower.

Assessed 2026-09-05 · Product owner, lending decisioning

AI Act Article 25

Provider or deployer, and which one applies to what

Conclusion

Provider of the Cadence lending system. Deployer of the 2 third-party models it calls.

  1. 1

    2 roles run at once and they attach to different things

    Groq and Google are the providers of the general-purpose models. Cadence takes those models, builds a high-risk system around them and puts its own name on the result, which makes Cadence the provider of that system while remaining the deployer of the models inside it.

  2. 2

    The modifications actually made

    A system prompt and 6 few-shot exemplars are layered over both models for categorisation, and a second prompt drafts the rationale. No fine-tuning has been performed. No retrieval augmentation over customer data is present. Every modification is prompt-level and is versioned, so a label can be tied to the prompt that produced it.

  3. 3

    Prompt layering is not what decides the role here

    Layering a prompt over a third-party model is too slight to transfer that model provider's obligations. Article 25(1)(c) is what applies: modifying the intended purpose of a general-purpose system already on the market so that it becomes high risk under Article 6 makes the modifier the provider. Assembling these models into a creditworthiness system is that modification, and the name on the system is Cadence's own.

  4. 4

    What the 2 roles oblige

    Provider obligations attach to the Cadence system. Deployer obligations under Article 26 attach to the use of the models and cannot be contracted back to Groq or Google, so a conformity statement from either provider discharges nothing.

What follows from it
  • Provider obligations for a high-risk system attach to Cadence, including the quality management, logging and post-market monitoring duties.
  • A conformity claim obtained from a model provider is evidence about their model and not about this system.
  • Adding a third model provider does not divide the role. It adds one more model under the same system.
What would make it wrong

Re-assess on any fine-tuning, on adding retrieval augmentation over customer data, on a change to the stated purpose of the system, and on adding a model provider.

Assessed 2026-09-05 · Product owner, lending decisioning

AI Act Article 27

Fundamental rights impact assessment

Conclusion

Required and performed. Article 27(1) names deployers of Annex III point 5(b), which is the classification reached above.

Article 27(1) lists 6 matters the assessment must cover. Each is answered below under its own letter, and the control test reconciles the sections against the letters rather than checking that a document exists.

27(1)(a)

The processes the system is used in

Consumer loan origination, end to end. Account data is retrieved under a PSD2 account information consent, every statement line is categorised, a Haushaltsrechnung derives disposable income against a living-cost allowance, and a deterministic rules engine returns approve, refer or decline.

A loan officer reads the assessment in the console and confirms or overrides it before anything reaches the applicant.

27(1)(b)

Period and frequency of use

Continuous through the origination window, once per application, with a further run each time an officer recategorises a line and the decision is recomputed.

The account information consent expires after 180 days, which bounds how long retrieved data stays usable without a fresh consent.

27(1)(c)

Categories of natural persons affected

Consumer loan applicants in Germany, and any person named on a joint account whose transactions appear in a retrieved statement without being the applicant.

Three groups inside that population carry more exposure than the rest: applicants whose income arrives irregularly, applicants whose salary or benefit line reads in unusual vocabulary, and applicants with a short account history.

27(1)(d)

Specific risks of harm to those groups

A miscategorised inflow understates income and declines an applicant who could afford the loan. The categoriser scores 96.1% overall against the 1,067-case evaluation set, so a wrong label is an expected event rather than an exceptional one.

Categorisation quality is not uniform across applicants and the size of that is now measured. Against 97.1% for everyone else, applicants with irregular income and a short history score 84.4% and statements in unusual vocabulary score 64.3%. The error falls on the applicants least able to absorb it, and the pattern is legible: project fees arriving as transfers are labelled recurring income or other rather than salary, so income the affordability calculation should count is miscounted or dropped. The 95.0% gate is set on an overall figure of 96.3% and reacts to none of it.

The isObligation and gambling flags carry moral weight beyond their arithmetic effect. A wrong gambling flag on a declined application is a harm to reputation as well as to access.

The drafted rationale can read as more certain than the evidence under it, which risks an officer confirming a decision the figures do not support.

27(1)(e)

Human oversight measures

The officer sees every transaction, its category, the confidence attached to it and the source line it came from, and can recategorise any line, which recomputes the decision rather than annotating it.

The applicant is told on the decision screen that the assessment was produced automatically and that a language model categorised the transactions and drafted the reasoning, and can request human review under GDPR Article 22(3) from that screen.

Oversight is capable of changing the outcome and is not yet evidenced by a recorded override rate, which is why CO6 stands at partial rather than pass.

27(1)(f)

Measures if a risk materialises

A categoriser accuracy below 95.0% on the evaluation set holds the deploy and hands the traffic to the deterministic rules categoriser, which needs no model and no API key. That check is manual today: the owner of the threshold runs the evaluation from the product, reads the result and decides whether the deploy goes ahead.

Every override, every recategorisation and every silent substitution between model providers is written to an append-only audit trail that the officer console reads back.

Complaints route to the named owner of the attachment, who holds the breach action for that model use.

What this assessment cannot yet state
  • Accuracy by applicant group has now been scored and the risk under (d) is confirmed rather than reasoned: 84.4% for applicants with irregular income and 64.3% for unusual statement vocabulary, against 97.1% for everyone else. What remains open is a threshold that can react to it, because the categoriser is not reproducible enough to gate on a per-group figure yet. Recorded as F8.
  • No override rate exists, because no population of decisions has been recorded.
  • The rationale has never been validated against human judgement, so its quality is asserted by deterministic checks rather than by agreement with a person.

An assessment that declares its own gaps is more use than one that reads as complete. Each gap here has a route to closing it, and none of them is closed.

What would make it wrong

Re-run this assessment on any change to the affordability thresholds, on any change to the categories the model may assign, and on the first recorded population of decisions large enough to compute an override rate.

Assessed 2026-09-05 · Product owner, lending decisioning