Credolab on Taking Behavioural Credit Scoring into FICO Platform

Credolab, a behavioural data and alternative credit scoring company founded in Singapore in 2016, joined the FICO Marketplace on 19 August, listed under the Data and Intelligence and Fraud and Threat Intelligence categories. The listing puts its score in front of lenders already running on FICO Platform, which FICO says is used by businesses in more than 80 countries. In the US alone, Credolab cites roughly 7 million adults who are credit invisible and a further 25 million with files too thin for conventional models to score.

Michele Tucci, chief strategy officer and co-founder of Credolab

Michele Tucci, chief strategy officer and co-founder of Credolab, answered written questions from The Fintech Times on what the integration involves for a lender, what the score does and does not collect, how the evidence is produced and how the company answers the proxy question regulators are asking of every alternative model.

Behavioural scoring, as Tucci describes it, assesses credit risk from how people interact with their devices rather than from their financial history. Any bank or lender on FICO Platform can now add Credolab’s behavioural signal to an existing credit model without rebuilding its decisioning stack. A lender finds CredoScore in the Marketplace catalogue inside the environment it already works in, can make test calls against it within hours, and consumes the score as one more attribute in a strategy it has already built.

“The only work required on their side is genuinely small: they embed our SDK in the mobile app they already have, or a JavaScript on the web journey, and it captures metadata during the application itself.” The existing API call returns the score and its features, the score becomes a new attribute in the strategy tree and the risk team decides what to do with it. “Most implementations run in one sprint, not months.”

Behavioural and device data has largely sat at the edges of underwriting, used for thin-file or emerging-market cases. Tucci does not claim the FICO listing changes the substance of how Credolab is bought. “What the FICO partnership changes is discovery and endorsement.” A risk team that has never heard of the company now finds it in a catalogue curated by a supplier it has trusted for decades, but Credolab still signs a contract with each client and still goes through full diligence on information security and data governance. “The endorsement lowers the barrier to being found and being taken seriously. It does not, and should not, lower the bar for scrutiny.”

What he does challenge is the assumption that behavioural data is a patch for thin files, useful only where the bureau cannot see. Credolab’s own data, he said, shows the signal is strongest precisely where the lender already has the most conventional data, which makes it a complementary layer rather than a stopgap. The reason is what is being measured. “Bureau data tells you whether someone has paid before. Open finance tells you whether they can afford to. Neither tells you whether they mean to.”

The population Credolab says it surfaces most sharply is one it calls non-starters and never-repayers: applicants with valid identity documents, normal devices and clean records who take the money with no intention of repaying it. Lenders usually treat them as fraud, but they pass every identity check they face. “That population is invisible to both the bureau and the fraud stack, and it is expensive.”

What is collected, and what is not

Asked to be specific about what the score draws on, Tucci said this is the question that decides whether a data protection officer keeps reading. Credolab collects metadata: facts about how a device is configured and how a person behaved while completing an application. That includes typing cadence and correction behaviour, time spent on a terms screen, scroll velocity, whether a form was completed in one sitting, copy and paste behaviour, and aggregate device signals such as storage and memory use, battery patterns, and counts of calendar entries, photos, media files and installed applications by category.

It does not collect names, phone numbers, email addresses, contacts, message content, photographs, calendar entry content, browsing history, GPS coordinates, bank credentials or account data. “We count photos. We never see a photo. We count calendar entries. We never see what the meeting is. Nothing we hold identifies a person.”

Two points, he said, matter more than the list. Everything is user-permissioned at runtime: the SDK mirrors the permissions the host application already has and nothing more, on both Android and iOS. “There is no back door and no workaround, because the operating system is the enforcement mechanism, not our policy.” The score is still produced when the so-called dangerous permissions are denied, because the approach does not depend on any single permission being granted. Second, Credolab is always the processor and never the controller: the bank, buy now pay later provider or card issuer owns the customer relationship and collects the opt-in inside its own journey. The company signs a data processing agreement with every client, holds ISO 27001 certification and stores metadata in-country where a regulator requires data residency.

He also drew a line between this and behavioural biometrics. “We are not authenticating a person against a stored template of how they type. We infer statistically meaningful traits from a single session, and we do not care who the person is.”

The evidence from a neobank portfolio

On where behavioural data makes the clearest difference, Tucci pointed to a recent evaluation run with a credit bureau on a regional neobank’s unsecured loan portfolio: roughly 20,000 applications over a six-month window, measured out of sample. He would not name either party. The bureau score alone produced a Gini coefficient of 0.26, Credolab’s score alone 0.37, and the two combined 0.44. Segmented by file depth, the result runs against the usual expectation: on thick files the combined model rose from 0.36 to 0.44, a gain of eight points, while on thin files and new-to-credit applicants it rose from 0.35 to 0.39, a gain of four.

“So the honest answer to where it makes the clearest difference is: everywhere, but most of all where the industry least expects it.” On thick files the lender already knows what the applicant has done and is missing intent, which is orthogonal information. On thin and credit-invisible files the Gini gain is smaller but, in his words, larger in human terms, because the alternative for those applicants is no score, a manual review, a punitive price or a decline.

He was equally direct about the limits. “Credolab tells you nothing about affordability. It is not a substitute for income verification or a debt-to-income calculation, and a lender who uses it that way will get hurt.” It does nothing for originations that are not digital, so branch, paper and call-centre channels sit outside it. It does not compensate for a mispriced product or a weak collections operation, and in secured lending, where collateral and loan-to-value dominate, the incremental contribution is much smaller. “It is a layer. It was never meant to be the whole stack.”

Lenders, he said, test everything, and will backtest a bureau score as rigorously as Credolab’s. The difference is mechanical. To backtest a bureau score a bank ships personal data to a third party so historical records can be matched. Credolab cannot do that because it holds no personal data to match against, so its validation runs forward rather than backward. The SDK goes live in shadow mode for up to three months, scoring real applications in real time and being used for nothing, and the lender joins the scores to outcomes as they mature. That means the score is validated against the conditions it will face in production rather than a year-old population, and when validation is complete the score is already live. “Going into production is a switch, not a project.”

Every client receives a full scorecard report: the target definition agreed up front, the train, test and out-of-time holdout split, and performance on each sample separately, with AUC, Gini, KS and F1 against a no-skill baseline, score density curves, bad rate by decile, gains, a calibration plot and a cut-off explorer with the confusion matrix at every threshold. It then goes down to feature level, with information value, weight of evidence by bin, VIF for multicollinearity, stability across five time slices and a retraining trigger stated in advance. “That is not a marketing deck. It is the document a model validation team needs to do their job, and it is the same document for every client.”

Explainability and the proxy question

Regulators are looking harder at explainability and fairness in credit models. “Our explainability is rooted in statistics. It is not a set of narrative labels attached to an output after the fact.” The score estimates the probability that an applicant will behave like the population of borrowers the client itself has identified as bad, with the target, from first payment default through to 90 days past due at nine months on book, agreed with each client before anything is built. From there it is explained the way any credit model should be: by its demonstrated ability to separate a population by probability of default, with every feature’s direction and magnitude of risk visible per bin, monotonic ordering enforced across time slices, and performance reported separately on data the model never saw.

On whether the score could act as a proxy for a protected characteristic, his answer is structural. Credolab has never held race, gender, ethnicity, address, postcode or any other personally identifiable attribute. “You cannot proxy for a variable through a pipeline that has no access to it and no mechanism to reconstruct it, and there is no point at which such an attribute could enter our model, because it does not exist anywhere in our environment.” The statistical evidence, he added, is correlation: Credolab’s score typically correlates at under five per cent with every other data source a lender uses, including bureau, cashflow, transactional and socio-demographic data, which he offers as proof the signal is orthogonal rather than a re-encoding of what those sources already contain.

Credolab says its platform draws on nearly 80,000 behavioural data points across Android, iOS and web and serves nearly 200 clients across the United States, Latin America, Southeast Asia and EMEA, from offices in Singapore and Miami. FICO Marketplace is accessible directly within FICO Platform, and FICO says clients can move from discovery to test calls with a third-party data service within hours.

The post Credolab on Taking Behavioural Credit Scoring into FICO Platform appeared first on The Fintech Times.

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *