The author

Deborah Hiscott

Lead Consultant

View profile
News & Views / Credit risk modelling statistics 2026: What risk managers need to know
23 July 2026

Credit risk modelling statistics 2026: What risk managers need to know

For risk managers in 2026, there are plenty of challenges. With regulatory scrutiny rising and market signals lagging, your models need to be more precise than ever.

That’s why we have curated the most impactful statistics across the sector to help you identify hidden vulnerabilities in your books, validate your AI governance, and sharpen your stress-testing capabilities.

Here is what the data shows, and what it means for modelling decisions in 2026.

AI in credit modelling: Adoption is ahead of governance

This section is lighter on statistics than the others. That’s because quantitative data on AI model governance in UK credit risk is still sparse and most of what the PRA and FCA are finding sits in supervisory dialogue rather than published datasets.

What we do know is this. 75% of UK financial services firms are already using AI, per the Bank of England and FCA's third joint survey, with the median number of AI use cases per firm expected to rise from 9 to 21 over the next few years. The governance frameworks have not followed at the same pace.

Keen to learn more about AI adoption? We did our own internal research report. Read it here now.

Jaywing research report

In October 2025, the PRA convened two CRO roundtable sessions with 21 regulated firms against SS1/23. The findings were pointed. Boards were approving AI and ML models without quantitative model risk appetite statements, leaving no defensible basis for challenge when model behaviour drifted. As a result, explainability tools used to show which variables drove a credit decision were being deployed without validating whether those explanations remained stable as market conditions changed. This is a position that does not survive supervisory scrutiny.

Take this a step further, and the bias exposure is also quantifiable. A November 2025 academic review found that AI credit scoring models consistently produced scores six to eight points lower for female applicants than male applicants with comparable financial profiles, with effects persisting across multiple borrowing cycles. ML models absorb and amplify bias from training data. And for credit risk functions using models calibrated on historical lending decisions, the bias is already in the data.

Meanwhile, in February 2026 the BoE published its summary of AI roundtables with banks and insurers, flagging material concerns about whether SS1/23 validation approaches can scale for AI systems making autonomous credit decisions without human oversight at each stage. In other words, the human-in-the-loop assumption embedded in SS1/23 is already being tested.

So where does the regulatory response sit? The FCA launched the Mills Review in January 2026 — a long-term examination of how AI reshapes retail financial services, with recommendations to the FCA Board due this summer. The Treasury Committee has mandated comprehensive guidance on how consumer protection rules and SMCR accountability apply to AI-driven credit harm by end of 2026. That guidance does not yet exist.

As a result, three specific pressure points from the PRA's findings sit unresolved for many firms:

  • Model tiering: complexity needs to be justified by incremental performance, not treated as a default.
  • Validation methodology: standard model testing techniques assume the underlying data is stable over time — an assumption that does not hold in credit data under macro stress. Validation frameworks need to test explicitly for this.
  • Model risk appetite: where there is no quantitative tolerance statement attached to an AI credit model, it cannot be governed, challenged, or defended in a supervisory review.

The Mills Review recommendations land this summer. The regulatory framework for autonomous AI decision-making in credit is still being written. So, the firms deploying it now are ahead of the rules that will govern it.

➡️Further reading: Combined vs bespoke models in credit risk: Does segmentation still add value?

Jaywing Risk AI

Fraud: What the Cifas numbers mean for credit models

The latest Cifas Fraudscape 2026 report shows that:

When borrowers apply for credit with no intent to repay, those accounts pass affordability checks and enter performing portfolios. They only register as defaults when they fail — at which point they are recorded as credit losses rather than fraud. Meanwhile, PD models trained on historical default data are increasingly incorporating these accounts as though they represent genuine credit risk.

The borrower cohort the model was calibrated on does not match the book being scored. That miscalibration compounds with each refresh cycle that does not separate fraud-driven defaults from credit-driven ones.

➡️Further reading: Identifying hidden fraud networks: Why fraud detection needs a network-based approach

Jaywing Risk fraud

Corporate credit: Persistent stress beneath stable headline figures

2026 insolvency volumes are volatile month to month. The underlying trend is not.

In the 12 months to May 2026, according to the Insolvency Service and R3, the UK's insolvency and restructuring trade body:

The rise in compulsory liquidations relative to creditors' voluntary liquidations (CVLs) is the more important signal. Distressed firms are staying in operation longer before failure, which means PD signals based on voluntary behaviour are lagging actual credit deterioration. Bureau flags and late-stage delinquency triggers are working with stale information in this part of the market.

Meanwhile, most credit models in use today were trained predominantly on data from before 2022 — meaning they were trained on a period of low rates, low defaults, and low leverage stress. The post-2022 environment, where debt structure rather than market sentiment or asset volatility is driving default risk, sits largely outside their training window. That recalibration is overdue for most corporate credit books.

Mortgage risk: falling arrears, rising cohort risk

Arrears are falling. But 1.8 million fixed-rate deals expire this year.

According to UK Finance and the FCA's Q1 2026 data:

There is a caveat to the positive arrears trajectory. Geopolitical developments since March 2026 have put upward pressure on energy prices and inflation, with industry commentary explicitly flagging the Iran conflict as a risk to the forward rate path. In other words, the 1.8 million borrowers repricing in 2026 are doing so into a rate outlook that has become materially less certain since the start of the year.

Meanwhile, the cohort data warrants attention. Borrowers aged 21 to 40 saw arrears rise from a lower base in Q4 2025 — smaller deposits, larger relative loan balances, household cost pressure compounding the rate shock. Possessions in Q1 2026 increased 3% quarter-on-quarter, with more than two-thirds of cases relating to mortgages arranged at least a decade ago.

It is worth noting that court processing times are a significant factor here. Ministry of Justice data shows the median time from possession claim to repossession reached 46 weeks in Q3 2025, meaning older cases are working through a system that was already heavily backlogged before the abolition of Section 21 in May 2026 added further pressure.

Aggregate arrears are a lagging indicator. Origination vintage, LTV at current valuation, borrower age cohort, and rate sensitivity on the repricing book are the leading signals. Models not disaggregating on these dimensions will see the deterioration late, particularly as 1.8 million deals, per UK Finance's 2026 Mortgage Market Forecast, reprice through 2026 and into 2027 against an increasingly uncertain rate path.

➡️Further reading: Geopolitical shocks and credit risk: Are your models ready?

Jaywing Risk

Stress testing: What passing the 2025 test actually tells you

All seven banks passed. The more useful signal came after the results were published.

But digging into the post-test commentary is where it gets interesting. Deloitte's analysis noted an explicit regulatory move away from the concurrent stress test as the primary supervisory tool, with the PRA's focus turning toward internal stress testing capabilities across AI financing risks, geopolitical shocks, climate, and private market exposures.

And the PRA's 2026 supervisory priorities letter confirmed credit risk model frameworks and the robustness of internal ratings as active supervisory scrutiny areas for 2026.

Meanwhile, the second System-Wide Exploratory Scenario, launching in 2026, focuses specifically on private markets and their interactions with banks — a risk category the annual concurrent test does not reach.

The PRA expects internal models capable of scenario-planning credibly across non-cyclical tail risks, at pace, and outside the annual cycle. Credit risk functions that have treated the concurrent exercise as the ceiling of their stress testing obligation have work to do before Basel 3.1 lands in January 2027.

Jaywing Risk

What the data adds up to

To sum up, we've got three key takeaways from the data above:

  1. Aggregate figures conceal segment-level deterioration. Falling arrears, stress test passes, and stable headline insolvency rates are all real. None of them tells you what is happening to smaller leveraged corporates, or 21-to-40-year-old mortgage borrowers rolling off cheap fixed rates. Models calibrated at the aggregate level are not seeing the deterioration that is already visible at the cohort level.
  2. Most credit models in use today were trained predominantly on data from before 2022. The drivers of corporate default risk and the arrears trajectory for residential mortgages have all moved materially since then. Refresh cycles that do not reflect this carry unquantified basis risk.
  3. The PRA has been explicit on AI governance. Firms that have deployed machine learning in credit decisioning without quantitative risk appetite statements, stress-tested validation approaches, and defensible explainability frameworks will face supervisory scrutiny that their current documentation will not withstand.

Jaywing's credit risk and modelling teams work with firms across all three of these areas, from model recalibration and validation through to AI governance frameworks built to withstand PRA scrutiny. Get in touch to find out more.