Credit Risk & Lending

AI in Credit Risk Management: Actions for lenders after the Mills Review

By Harry Charalambous, Principal Consultant at Broadstone

This article reflects Broadstone’s views on developments in AI and credit risk management and is provided for information purposes only.

The Mills Review, published by the FCA in July, sets out how AI could reshape retail financial services by 2030. For lenders, it highlights a practical opportunity: using AI and machine learning to improve risk assessment, make processes more efficient, and drive better customer experiences.

That opportunity is already visible in credit modelling. In my experience, well-developed machine learning models may outperform some traditional approaches in certain lending environments, depending on data quality, model design and governance, identifying patterns and relationships that conventional models may miss to give lenders a more granular view of risk.

Better performance, however, brings greater demands around control. The more sophisticated the model, the more important strong data, robust validation, effective monitoring and clear accountability become. 

In this article, I’ll look at three actions lenders should take to use AI effectively, in line with the Mills Review’s findings.

Key takeaways

  • The Mills Review raises the bar for AI governance: It highlights both the opportunities AI could create for lenders and the need for stronger oversight as models become more capable and autonomous.
  • Strengthen model governance: Move beyond one-off approval to continuous monitoring, clear human oversight and robust controls around third-party models and data.
  • Prepare for wider changes across the credit lifecycle: Consider how AI could reshape fraud risk, pricing and customer acquisition, not just credit decisioning.
  • Fix data and infrastructure before scaling AI: Make sure your data, decisioning platforms and monitoring systems are strong enough to support more sophisticated models in production.

Learn more about our Banking & Credit Advisory services

Strengthen governance as credit models become more sophisticated

Credit risk modelling has changed significantly over the past 20 years, but the fundamentals of good model risk management haven’t – even as AI transforms credit risk management.  

Whether you’re using a traditional scorecard or a machine learning model, you still need good-quality data, independent validation, effective monitoring and clear accountability.

More sophisticated models make those requirements harder to deliver. Lenders need to be able to demonstrate:

  • Whether model performance remains stable over time.
  • Whether changes in customer behaviour are causing model drift.
  • Whether outputs can be explained clearly enough to support governance and customer outcomes.
  • Whether third-party models, data or infrastructure introduce risks that are properly understood and controlled.

The Mills Review is explicit that more capable models still require “controls for reliability, consistency, explainability and accountability”, alongside human oversight as more activity is delegated to AI.

That human oversight can’t just mean keeping someone notionally in the loop. Firms need to be clear about what people are expected to do, what information they receive, when they can intervene, how challenge is recorded and how escalation works.

For lenders, that means moving from one-off model approval to continuous oversight: monitoring performance and drift, defining where human challenge or approval is required, recording how decisions are reached, and making sure third-party models and data remain within the same governance framework.

Read more: Unlocking AI’s Potential in Consumer Lending: Why Model Monitoring is Essential

Prepare for AI to change fraud, pricing and customer acquisition

Strong model governance is only part of the picture. Lenders also need to consider how AI could affect the wider credit lifecycle.

Take fraud, for example. The Mills Review highlights deepfakes, synthetic identities and personalised social engineering as threats that could make fraud “faster, cheaper, more scalable and more persuasive”.

At the same time, AI can also strengthen lenders’ defences. Behavioural analytics, anomaly detection and machine learning can help identify emerging fraud patterns faster than fixed rules alone.

Other changes are likely to affect how lenders compete across:

  • Customer acquisition: The Review expects consumers to increasingly use AI agents to compare products and potentially act on their behalf. Lenders may need to think differently about how their products are found, assessed and compared in AI-led journeys.
  • Pricing: More sophisticated analytics could allow lenders to price risk more precisely, but firms will still need to distinguish legitimate risk-based pricing from unfair or discriminatory outcomes.
  • Fraud controls: As fraud techniques become more sophisticated, lenders will need to evolve detection and verification alongside their credit decisioning models.

For lenders, the practical response is to widen AI governance beyond model development. 

Credit, fraud, pricing, distribution and customer outcome teams should be working from a shared framework that sets clear ownership, defines where human review is required, and uses common monitoring to identify unintended effects across the customer journey. 

That way, firms can capture the benefits of AI without allowing risks to emerge in one part of the credit lifecycle simply because responsibility sits somewhere else.

Fix data and decisioning infrastructure before scaling AI

For many lenders, the biggest obstacle to AI adoption won’t be choosing a more sophisticated modelling technique. It will be whether the organisation has the data and systems needed to deploy, monitor and govern that model effectively.

Before scaling AI, credit risk teams should assess whether they have:

  • Sufficiently complete and reliable customer, account and performance data.
  • Decisioning platforms capable of deploying modern machine learning models.
  • Monitoring systems that can identify deterioration in model performance.
  • Clear governance over model changes, third-party providers and data use.
  • Resilient infrastructure capable of supporting models in live decisioning.

A model that performs better in development delivers little value if the lender can’t deploy it reliably or monitor it effectively in production.

For lenders, data and infrastructure readiness should come before wider AI rollout. That means identifying gaps in historical and live data, testing whether decisioning platforms can deploy and monitor more complex models, and addressing weaknesses in governance and resilience early.

Firms that do this will be better placed to move successful models into production without creating avoidable operational or regulatory risk.

Ultimately, that’s the Mills Review’s central lesson for lenders. AI will create the most value where better modelling is matched by the governance, data and infrastructure needed to use it well.

Talk to our team

Are you considering how AI and machine learning could strengthen your credit risk strategy? 

Talk to Broadstone’s Banking & Credit Advisory team.

Need more help? Contact us today.