Banking Law And Monetary Policy Implementation Mechanisms Kuwait .

Banking Law and Model Risk Governance for AI in Spain

1. Introduction

AI model risk governance in Spanish banking concerns the legal and organisational controls that banks must apply when artificial intelligence, machine-learning systems, statistical models, or other automated models influence banking decisions.

Typical applications include:

credit scoring and creditworthiness assessment;

loan approval and pricing;

fraud detection;

anti-money-laundering monitoring;

customer segmentation;

capital and liquidity modelling;

market and credit-risk measurement;

stress testing;

algorithmic customer-service systems; and

internal prudential models.

Spain does not have one statute called the “AI Model Risk Governance Act.” Instead, banks operate under overlapping Spanish and EU rules.

Most importantly, Spanish banking legislation already expressly recognises model risk. Article 52 of Royal Decree 84/2015 requires institutions to maintain policies and procedures for operational risk, including model risk where appropriate. It defines model risk as the potential loss resulting from decisions based principally on internal-model outputs because of errors in the design, implementation or use of those models.

AI therefore does not create model risk from nothing. It makes an existing banking-law risk more complicated.

 

2. Main Legal Framework

The principal framework includes:

Spanish banking law

Law 10/2014 on the organisation, supervision and solvency of credit institutions;

Royal Decree 84/2015;

prudential requirements applying to credit institutions.

EU financial regulation

Capital Requirements Regulation and associated prudential rules;

supervisory requirements applicable through the European banking framework.

AI regulation

Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act.

Data protection

General Data Protection Regulation (GDPR);

Spanish Organic Law 3/2018 on data protection and digital rights.

The result is a multi-layered governance system.

A bank cannot argue that an AI model complies with banking rules and therefore GDPR does not matter, or that GDPR compliance automatically establishes prudential compliance.

Each layer addresses different risks.

 

3. Model Risk Under Spanish Banking Law

Royal Decree 84/2015 provides an unusually direct starting point.

Article 52 requires banks to implement policies and procedures for assessing and managing operational-risk exposure, expressly including model risk where appropriate.

This definition captures three major sources of AI risk.

Design risk

The mathematical or technological design itself may be defective.

For example, a credit model might rely on inappropriate variables or assumptions.

Implementation risk

A technically valid model may be incorrectly incorporated into the bank's systems.

Use risk

A valid model can still cause problems when employees use its output for a purpose for which it was not designed.

Therefore, AI accuracy alone is not enough.

Governance must consider the complete model lifecycle.

 

4. Responsibility of the Board

AI governance cannot be transferred completely to the data-science department.

Article 37 of Law 10/2014 provides that the board of directors is responsible for the risks assumed by a credit institution. The board must receive effective information concerning risk-management policies and significant risks.

It must also participate actively in managing material risks and pay particular attention to matters including the use of internal models.

Article 29 additionally requires robust corporate-governance arrangements, including effective procedures for identifying, managing, controlling and reporting risks.

Consequently, deploying an important AI model should not be treated merely as purchasing new software.

It can become a board-level governance matter.

 

5. AI Model Governance Structure

A sound banking model-governance system normally separates several responsibilities.

Model development

The model is created or configured.

Model ownership

A business function becomes accountable for its intended use.

Independent validation

Another function tests whether the model actually performs as expected.

Risk management

The institution evaluates financial, operational, legal and other material risks.

Compliance and data protection

These functions examine regulatory and customer-rights implications.

Internal audit

Audit evaluates whether the governance framework itself operates effectively.

Board oversight

The board receives sufficient information concerning material models and their risks.

This separation reduces the danger that the people who built a model become the only people deciding whether it is reliable.

 

6. AI Act and Credit Scoring

The EU AI Act is especially important for consumer credit.

The Regulation treats AI systems used to evaluate the credit score or creditworthiness of natural persons as high-risk because these decisions can determine access to important financial resources and essential services.

This is highly relevant to Spanish banks using machine learning for retail lending.

However, the AI Act distinguishes certain other financial uses. In particular, AI used for fraud detection in financial services and AI used for prudential purposes to calculate capital requirements of credit institutions are not treated as high-risk under that particular Annex III creditworthiness category merely for those purposes.

That does not mean such models are unregulated.

Banking, GDPR, cybersecurity and other rules can still apply.

 

7. AI Risk-Management System

Article 9 of the AI Act requires a risk-management system for high-risk AI.

It must operate as a continuous and iterative process throughout the AI system's lifecycle, rather than as a one-time test before deployment.

Among other things, the institution must identify reasonably foreseeable risks, evaluate them and introduce appropriate risk-management measures.

For banking, this suggests a lifecycle such as:

Design → Development → Validation → Approval → Deployment → Monitoring → Revalidation → Modification → Retirement

Every material stage should leave adequate documentation.

 

8. Data Quality

An AI model can be mathematically sophisticated while producing unreliable decisions because its underlying data are poor.

Potential problems include:

inaccurate customer information;

outdated information;

missing data;

unrepresentative training populations;

inappropriate proxy variables;

historical biases;

data leakage;

incorrectly labelled outcomes.

For example, suppose a credit model was trained predominantly on borrowers with characteristics materially different from the customers to whom the model is subsequently applied.

Its predictive performance may deteriorate.

Data governance is therefore part of model governance.

 

9. Explainability

Complex AI creates another problem:

Why did the model reach this result?

This becomes especially important when the result affects an individual.

A bank should be able to understand important aspects of a material model sufficiently to:

validate it;

challenge it;

identify errors;

monitor performance;

explain relevant automated decisions where legally required.

The CJEU's recent automated-credit jurisprudence makes this increasingly important.

 

10. Human Oversight

A human being should not merely confirm whatever the model recommends.

Effective human oversight requires the reviewer to have:

sufficient information;

appropriate authority;

adequate competence;

ability to challenge the output; and

practical ability to change the outcome where appropriate.

Otherwise, nominal “human review” can become automation bias: the person assumes the computer must be correct.

This risk should itself form part of model governance.

 

11. Model Validation

Before a material AI model is used, a bank should determine whether it is fit for its intended purpose.

Validation may examine:

conceptual soundness;

assumptions;

input data;

performance;

limitations;

stability;

sensitivity;

potential bias;

implementation;

output accuracy.

Validation should continue after deployment.

A model that performed well in 2024 may perform poorly several years later because customer behaviour, markets or economic conditions have changed.

 

12. Model Drift

Model drift occurs when model performance changes over time.

Suppose a lending model was trained during a period of relatively stable employment and interest rates.

A major economic change could alter borrower behaviour.

The relationship between historical data and future defaults might therefore weaken.

Governance should establish thresholds indicating when:

investigation is required;

recalibration is needed;

revalidation must occur;

the model should be suspended.

 

13. Third-Party AI Models

Banks increasingly obtain AI systems from external vendors.

This creates vendor model risk.

A bank cannot assume:

“The supplier developed it, so the supplier carries all regulatory responsibility.”

The institution using the system must still understand enough about the system to satisfy its own regulatory duties.

Relevant governance questions include:

What data trained the system?

What are its limitations?

How is performance tested?

Can the bank obtain necessary documentation?

Can independent validation be performed?

What happens when the vendor changes the algorithm?

Can the bank exit the arrangement safely?

Vendor opacity can therefore become a governance risk.

 

Important Case Law

There is not yet a large body of Spanish Supreme Court judgments specifically labelled “AI model risk governance.” The strongest authorities therefore include CJEU judgments binding or directly relevant within Spain, together with Spanish-origin data-protection jurisprudence.

Case 1 – CJEU, C-634/21, SCHUFA Holding (Scoring), 7 December 2023

This is one of the most important European judgments for AI-driven banking.

SCHUFA generated probability scores estimating an individual's future ability to meet payment obligations.

The Court examined whether automated generation of such a score can itself constitute automated individual decision-making under Article 22 GDPR when a third party relies strongly on that score.

The judgment establishes that automated scoring cannot necessarily escape Article 22 merely because the final formal decision is made by another organisation.

Importance for Spanish banks

A Spanish bank using an external AI credit score must consider the real influence of the score on the decision, rather than only asking who formally clicks “approve” or “reject.”

 

Case 2 – CJEU, C-203/22, Dun & Bradstreet Austria, 27 February 2025

This case significantly developed the law on explainability.

A customer was refused a contract following an automated creditworthiness assessment.

The Court held that the data subject is entitled to an explanation concerning how the automated decision was reached. The explanation must enable the individual to understand and challenge the decision.

Banking significance

An institution cannot necessarily satisfy transparency obligations by providing incomprehensible mathematical formulas.

For AI governance, the practical objective is meaningful explanation.

This makes explainability a legal governance issue rather than merely a technical preference.

 

Case 3 – CJEU, Joined Cases C-26/22 and C-64/22, SCHUFA Holding, 7 December 2023

These joined cases concerned the storage of information relating to discharge from remaining debts by a credit-information agency.

The Court addressed GDPR principles including lawfulness, legitimate interests, erasure and judicial protection. It also held that a supervisory authority's complaint decision must be capable of full judicial review.

Importance for AI models

A model cannot be governed properly by looking only at the algorithm.

The lawfulness and retention of input data are equally important.

An accurate model using unlawfully retained personal data can still create serious compliance problems.

 

Case 4 – CJEU, Google Spain, C-131/12, 13 May 2014

This landmark case originated from Spain's Audiencia Nacional and concerned Google Spain, Google Inc., the Spanish Data Protection Agency and Mario Costeja González.

The Court examined processing of personal information, responsibility of the controller and the individual's data-protection rights.

The case pre-dates today's generative AI systems and the GDPR, so it should not be described as an AI banking case.

Nevertheless, it established foundational European principles concerning accountability for algorithmically organised personal information and the protection afforded by Articles 7 and 8 of the EU Charter.

Banking significance

A bank cannot treat algorithmic processing as legally neutral simply because software rather than an employee performs the processing.

 

Case 5 – Spanish Supreme Court Google Spain Decisions, March 2016

Following the European Google Spain litigation, Spain's Supreme Court dealt with responsibility for data processing.

The administrative chamber's judgments of 11, 14 and 15 March 2016 concluded that Google Spain itself could not be treated as the controller for the relevant processing because, on that analysis, Google Inc. satisfied the controller conditions identified by the CJEU.

AI governance significance

These cases demonstrate the importance of correctly identifying the legally responsible entity.

For banking groups this can become important where:

one company develops an AI model;

another hosts it;

a vendor supplies data;

the regulated bank deploys it.

Model governance should clearly map legal responsibility across this chain.

 

Case 6 – Spanish Supreme Court, Civil Chamber, 5 April 2016 – Google Spain

The Spanish Supreme Court's Civil Chamber reached a different conclusion concerning responsibility and treated Google Spain as jointly responsible alongside Google Inc. in the litigation described by the CJEU's case-law review.

Although this was not banking litigation, the disagreement demonstrates why identifying the controller and allocating responsibility within complex technological corporate structures can be legally difficult.

Banking significance

Banks should not leave responsibility for AI models ambiguous between:

bank → technology subsidiary → cloud provider → model vendor → data provider.

Governance documentation should identify who controls each relevant activity and what obligations each participant carries.

 

Case 7 – SCHUFA Jurisprudence on Automated Credit Decisions

The broader SCHUFA jurisprudence deserves separate emphasis because it directly concerns credit-information ecosystems.

C-634/21 concerned automated scoring, while C-26/22 and C-64/22 dealt with the underlying credit-information environment and data retention.

Together they demonstrate an important principle:

model governance and data governance cannot be separated.

A credit algorithm may be technically sound, but its legal reliability also depends on the legitimacy, quality and retention of its inputs.

 

14. Automated Credit Decisions and GDPR Article 22

For banks, one of the most important questions is whether an AI system is merely assisting an employee or effectively determining the customer's outcome.

Article 22 GDPR provides important protections regarding decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals.

SCHUFA shows that courts may look at substance rather than formal structure.

A bank therefore cannot necessarily avoid automated-decision requirements by placing a nominal employee between the algorithm and the customer.

Human intervention must be meaningful where the law requires it.

 

15. AI Credit Scoring Under the AI Act

There is significant overlap between GDPR and the AI Act.

For an AI creditworthiness model:

GDPR asks questions such as:

Is personal-data processing lawful?

Is automated decision-making permitted?

What information must be provided?

Can the individual challenge the outcome?

AI Act asks questions such as:

Is the system high-risk?

Is there an adequate risk-management system?

Is the data appropriately governed?

Is appropriate documentation maintained?

Is human oversight effective?

Banking regulation asks:

Is the model prudentially sound?

Does the bank understand its limitations?

Is model risk properly controlled?

Does the board receive appropriate risk information?

The same AI system may therefore be subject to all three layers.

 

16. Bias and Discrimination Risk

AI lending systems may unintentionally disadvantage groups of customers.

The AI Act itself recognises that credit-scoring AI can potentially produce discrimination or perpetuate historical patterns. That is one reason creditworthiness AI involving natural persons is classified as high-risk.

Banks should therefore test whether:

training data contain historical distortions;

apparently neutral variables operate as problematic proxies;

error rates differ materially across relevant populations;

model updates create unexpected effects.

This does not mean that every statistical difference automatically proves unlawful discrimination.

It means the institution needs an effective framework for identifying and investigating such outcomes.

 

17. Generative AI in Banking

Generative AI introduces additional model risks.

A conventional credit model might generate a probability such as:

Probability of default = 3.2%.

A generative model can instead produce free-form text.

This introduces risks such as:

fabricated information;

inconsistent answers;

prompt sensitivity;

confidential-data leakage;

unreliable explanations;

inappropriate customer advice.

Consequently, generative AI should not automatically be governed exactly like a conventional statistical model.

Its particular limitations must be considered.

 

18. Model Inventory

A bank cannot govern models that it does not know exist.

A comprehensive inventory should therefore identify material models and record matters such as:

Model name

Owner

Purpose

Risk classification

Data sources

AI/ML technique

Validation status

Last validation date

Known limitations

Dependencies

Third-party involvement

Monitoring indicators

Approval status

High-impact models should receive greater scrutiny than minor analytical tools.

 

19. Three Lines of Defence

AI model-risk governance can fit into the traditional banking three-lines structure.

First line – Business and model owners

Develop, operate and monitor models.

Second line – Independent risk and compliance functions

Challenge assumptions, validate risk controls and monitor regulatory compliance.

Third line – Internal audit

Independently assesses whether the entire governance framework is functioning.

The precise organisational arrangement can vary, but independence and effective challenge are crucial.

 

20. Model Changes

AI models can change more frequently than traditional banking models.

Changes can arise through:

retraining;

new datasets;

new variables;

parameter adjustments;

vendor updates;

changed prompts;

new model versions.

Governance therefore needs a clear distinction between minor changes and material model changes.

Material changes should trigger appropriate testing, documentation and approval before production use.

 

21. Documentation

Documentation is essential because regulators, auditors and courts may need to reconstruct what happened.

For an important AI model, documentation should allow the institution to establish:

why the model was created;

what data were used;

what assumptions were adopted;

who approved it;

how it was validated;

what limitations were identified;

how performance was monitored;

when changes occurred;

who was responsible for those changes.

This becomes particularly valuable when a customer challenges an automated credit decision.

Dun & Bradstreet confirms the growing importance of providing explanations capable of enabling affected individuals to understand and contest automated outcomes.

 

22. Relationship Between Accuracy and Legality

A fundamental distinction should be maintained:

A highly accurate model can still be unlawful.

For example, it might process data without an adequate legal basis.

Conversely:

A legally permissible model can still be prudentially unreliable.

For example, the processing may satisfy data-protection requirements while the model badly predicts defaults.

Consequently, model approval should not rely on one test alone.

A Spanish bank needs to consider:

accuracy + stability + prudential soundness + data protection + AI regulation + governance + customer rights.

 

23. Board-Level AI Governance

Law 10/2014 places significant responsibility for risk management on the board and expressly refers to its involvement concerning internal models.

For material AI systems, appropriate board information could therefore include:

major AI exposures;

model failures;

validation findings;

material bias concerns;

regulatory breaches;

significant model changes;

concentration in third-party AI providers;

customer complaints;

incidents affecting important AI systems.

The board does not need to write machine-learning code.

It does need sufficient information and expertise to govern the risks appropriately.

 

24. Practical Governance Framework

A practical Spanish banking framework can therefore be represented as:

AI Use Case Identification

↓

Risk Classification

↓

Legal and Data Assessment

↓

Model Development

↓

Independent Validation

↓

Approval

↓

Controlled Deployment

↓

Performance and Bias Monitoring

↓

Human Oversight

↓

Periodic Revalidation

↓

Incident and Change Management

↓

Retirement

This should operate as a continuous lifecycle rather than a one-time compliance exercise.

 

25. Supervisory Importance

Spanish banking law already places risk governance at the centre of institutional responsibility.

Law 10/2014 requires clear organisational structures, defined responsibility, effective risk identification and control, adequate internal controls and board oversight.

Royal Decree 84/2015 then expressly brings model risk into the operational-risk framework.

AI therefore fits naturally into existing prudential supervision even before considering the additional AI Act requirements.

 

26. Main Legal Risks for Spanish Banks

The principal AI model risks can be grouped into:

Model risk – incorrect design or implementation.

Data risk – inaccurate, inappropriate or unlawfully processed data.

Bias risk – unjustified differences in outcomes.

Explainability risk – inability to explain significant automated decisions.

Automation risk – excessive dependence on model output.

Validation risk – insufficient independent testing.

Drift risk – deterioration after deployment.

Third-party risk – dependence on external AI vendors.

Privacy risk – unlawful personal-data processing.

Governance risk – unclear accountability.

Operational risk – failures affecting banking operations.

Regulatory risk – failure to satisfy AI, banking or data-protection requirements.

These risks frequently overlap.

 

27. Lessons From the Case Law

At least six important authorities provide useful principles for Spanish AI banking governance:

1. C-634/21, SCHUFA Holding (Scoring) – automated credit scoring can fall within Article 22 where the score plays a determining role in a third party's decision.

2. C-203/22, Dun & Bradstreet Austria – individuals affected by automated credit assessment are entitled to meaningful information enabling them to understand and challenge the decision.

3. Joined Cases C-26/22 and C-64/22, SCHUFA Holding – lawful data retention and effective judicial protection matter in credit-information systems.

4. C-131/12, Google Spain – algorithmic processing of personal information remains subject to data-protection rights and controller responsibility.

5. Spanish Supreme Court judgments of 11, 14 and 15 March 2016 – identifying the legally responsible data controller can depend on the actual corporate and processing structure.

6. Spanish Supreme Court, Civil Chamber, 5 April 2016 – the related Google Spain litigation further illustrates the complexity of allocating responsibility within technology-driven processing structures.

These cases do not all concern banking AI directly. Their importance lies in the principles they establish concerning automated credit scoring, data governance, explainability, accountability and responsibility for algorithmic processing.

 

Conclusion

AI model risk governance in Spanish banking is the combination of traditional model-risk management with modern AI and data-protection regulation.

Spain already has an explicit legal concept of model risk. Article 52 of Royal Decree 84/2015 defines it around potential losses caused by decisions principally based on internal models where errors exist in their design, implementation or use.

Law 10/2014 places ultimate responsibility for banking risks on the institution's governance structure and requires the board to participate in the management of material risks, including matters involving internal models.

The EU AI Act adds another layer. In particular, AI used to assess the creditworthiness or credit score of natural persons is generally treated as a high-risk use case, subject to extensive governance safeguards.

Finally, SCHUFA and Dun & Bradstreet demonstrate that automated financial decisions cannot operate as unexplained black boxes when EU data-protection law gives affected individuals rights to understand or challenge those decisions.

The central principle for Spain is therefore:

AI may assist or automate banking decisions, but it does not automate away the bank's legal responsibility.

A compliant Spanish bank needs governance throughout the entire AI lifecycle—data, development, validation, approval, human oversight, explainability, monitoring, revalidation, change control and eventual retirement of the model.

LEAVE A COMMENT