AI in Underwriting and Credit Decisioning
When a regional bank in the Midwest replaced its manual consumer-loan underwriting process with an AI pre-scoring system in 2024, the head of retail lending celebrated the efficiency numbers: average file-decision time dropped from four days to under six hours, and volume per underwriter increased by roughly 60 percent. The celebration ended eight months later when a fair-lending exam found that denial rates for Hispanic applicants were 22 percentage points higher than for statistically comparable non-Hispanic applicants, and the bank could not produce a coherent explanation of why, because the pre-scoring model it purchased from its technology vendor did not come with an explainability report, a disparate-impact test, or a validation record. The resulting supervisory agreement required two years of enhanced monitoring, a $4.2 million community benefit commitment, and remediation payments to identified affected applicants. That story, with details changed to protect institutional identity, captures the exact collision that defines AI in underwriting in 2026: the speed is real, the efficiency gain is real, and the compliance liability from an unexplainable model is equally real.
What Underwriting Is, and Why It Is Different from Origination
Underwriting is the phase of lending where a qualified human professional evaluates a complete loan file and makes a credit decision: approve, deny, or counter-offer. It is the phase where the legal obligations of the Equal Credit Opportunity Act (ECOA) and its implementing Regulation B attach most concretely to the institution's conduct. ECOA is the federal statute that prohibits discrimination in credit transactions. Regulation B is the implementing regulation that specifies, among other things, that an adverse action must be accompanied by a notice stating the specific reasons for the denial within 30 days of application completion.
The difference between origination and underwriting is significant for AI deployment. In origination, AI assists with file preparation; the regulatory consequences of an error are manageable and correctable. In underwriting, AI influences or informs the credit decision itself; the regulatory consequences of a systematic error are category-different. A disparate-impact pattern in underwriting outcomes is not a software bug; it is a fair-lending violation that carries civil money penalties, consent order exposure, and potential referral to the Department of Justice.
This is why the phrase "AI in underwriting" requires immediate precision about what role AI is actually playing. There are at least four distinct roles AI can play, and they carry dramatically different compliance implications.
Four Roles AI Plays in Underwriting, Ranked by Risk
Role 1: File preparation and summary. The AI produces a file summary, a pre-computed debt-to-income ratio, an extracted income and asset schedule, and a preliminary exception checklist for the underwriter to review. The underwriter still reads the file, exercises judgment, and makes the decision. This is the lowest-risk AI deployment; it accelerates the underwriter without displacing the decision. Risk level: manageable with standard verification discipline.
Role 2: Pre-scoring with a human decision boundary. The AI produces a pre-score or risk tier for each file, which the underwriter uses as one input among several. Pre-scores at the clearly-approve end of the spectrum might allow underwriters to clear files faster; pre-scores at the clearly-decline end flag files for closer scrutiny. The underwriter's decision is still documented independently of the score, and the score is one input rather than a decision gate. Risk level: moderate; requires disparate-impact testing of pre-score distributions and documentation that the human decision is independent.
Role 3: Automated underwriting with human review for exceptions. The AI makes the primary credit determination, and humans review files that the AI flags as exceptions or edge cases. This is the architecture used by Fannie Mae's Desktop Underwriter (DU) and Freddie Mac's Loan Product Advisor (LPA) for conforming mortgage, and it is being extended to non-agency and portfolio lending by fintech and larger institutions. Risk level: high; requires robust model validation, disparate-impact testing, explainability infrastructure, and a governance trail under OCC Bulletin 2026-13.
Role 4: Fully automated credit decisions. AI makes the decision with no human review on the majority of files. This is the fintech-approval-in-minutes model. Risk level: very high for a regulated depository institution in 2026; the adverse-action explainability requirement and disparate-impact obligation do not relax in automated systems, and OCC Bulletin 2026-13 makes the board and senior management accountable for the model-risk program that governs them.
Most community banks and regional banks in 2026 are operating at Role 1 or Role 2. Larger banks and fintech lenders are at Role 3. Fully automated Role 4 decisioning in regulated consumer lending remains limited outside of very low-balance products with narrow credit parameters. Understanding which role your institution's AI is playing is the starting point for understanding what governance obligations apply.
What a Score Is and What a Decision Is, and Why the Difference Matters
One of the most important conceptual distinctions in AI underwriting is the difference between a score and a decision. This distinction is legally significant, operationally significant, and commonly blurred.
A score is a numerical output of a statistical or machine-learning model that represents the model's assessment of some characteristic of the borrower or the loan. A credit score like a FICO score represents the model's assessment of the probability of default over a defined horizon. A pre-score in an AI underwriting system might represent the model's assessment of whether the loan meets the institution's credit guidelines. Scores are model outputs; they are the product of a mathematical process applied to input data.
A decision is a human judgment, made by a licensed and accountable professional, that a specific loan application should be approved, denied, or counter-offered. The decision uses scores as inputs. The decision incorporates information, context, and policy judgment that the score does not capture. The decision is what the institution is legally accountable for, and the decision is what the adverse-action notice documents.
The confusion between scores and decisions creates a specific legal problem. An underwriter who says "the model gave this file a 47, which is below our 50 cutoff, so we denied it" has not made a decision; they have deferred to a score. The denial notice that follows from that process will say something like "model score" or "credit score below minimum" as the reason, which does not satisfy Regulation B's requirement for specific, accurate reasons unless the score is a recognized credit score with all required disclosures. The borrower has a right to know not just that their score was low, but what specific factors drove the score and therefore what specific aspects of their financial profile were the basis for the denial. "The model said no" is not that.
A credit score is an input to a decision. The decision belongs to the underwriter. The adverse-action reason belongs to the underwriter. The model cannot own any of these things in a regulated institution.
Pre-Scoring with a Defensible Human Decision Boundary
The pre-scoring model, used as Role 2 above, is the AI deployment that creates the most daily operational value for underwriting teams at community and regional banks in 2026, because it is the model that genuinely accelerates throughput without displacing human judgment. Understanding how to use it defensibly is a practical skill, not just a compliance aspiration.
A well-designed pre-scoring workflow has four components: the score itself, the score explanation, the human decision record, and the final adverse-action reason.
The score itself is the numerical output of the AI model. It should be recorded in the LOS file along with the model version, the date of scoring, and the input data that generated it. If the model uses alternate data or any non-standard variables, those should be documented.
The score explanation is the set of factors the model identifies as driving the score, in order of significance. This is where explainability infrastructure matters practically. A pre-scoring model that produces a score but no explanation of the factors driving that score is not usable for adverse-action purposes in most lending contexts, because the underwriter cannot translate the model's output into a specific, accurate adverse-action reason without knowing what the model was looking at. Many AI underwriting vendors provide what they call SHAP (SHapley Additive exPlanations) values or feature importance rankings alongside scores; these are the starting point for reason code generation. But they require a trained human to translate into the specific language required by Regulation B.
The human decision record is the underwriter's documented judgment on the file, which includes their review of the score, their review of the score explanation, their independent assessment of the file, and their final recommendation. The record must show that the underwriter actually reviewed the file and exercised judgment, not merely transmitted a model output. In practice, this means the underwriter's notes in the LOS must contain substantive content beyond "pre-score: 47, below guideline minimum." They should contain the underwriter's assessment of the key factors in the file, the specific policy or guideline provisions that apply, and the specific reasons for their recommendation.
The final adverse-action reason is the set of specific reasons, grounded in the actual file and the actual credit guidelines, that will appear in the borrower's adverse-action notice. It derives from the underwriter's decision record, not directly from the AI output. The AI output can inform and accelerate the reason-generation process, but the underwriter owns the reasons and must be able to confirm they are accurate and that they represent the actual reasons for the denial.
What the Approved End Looks Like at the Human Boundary
Pre-scoring is often discussed primarily in terms of how AI helps identify denials, but the human decision boundary is equally important on the approval side, for a different reason. When an AI pre-score indicates a file is clearly within guidelines, there is a natural tendency for underwriters to review it less carefully. This creates two problems.
First, the pre-score can be wrong. An extraction error in the income calculation, a credit report with an unresolved dispute, or a recently changed employment status that post-dates the extracted data can all produce a pre-score that says "approve" on a file that should require more scrutiny. An underwriter who gives that file a light review because the score is green may miss the error.
Second, approving a file based primarily on an AI score without independent review creates a governance gap. If the AI score is later found to have produced disparate impact (a pattern of more favorable scores for one demographic group versus another with comparable credit characteristics), the institution needs to be able to demonstrate that the human underwriter independently evaluated the file. If the file record shows nothing more than "AI score: 78, approved," that is not a demonstration of independent review; it is a demonstration of AI score reliance.
Disparate Impact in Underwriting AI: The Legal and Operational Reality
Disparate impact under fair-lending law is the concept that a facially neutral lending practice or policy produces statistically significantly worse outcomes for a protected class of applicants, even when no discriminatory intent is present. The legal framework derives from ECOA and from case law; it was extended to AI underwriting in interpretive guidance from the Consumer Financial Protection Bureau (CFPB) and in OCC Bulletin 2026-13. Disparate impact in underwriting is not a theoretical concern; it has been the basis of enforcement actions and consent orders against institutions using automated underwriting systems.
The mechanism by which a facially neutral AI model produces disparate impact is through proxy variables: input variables that are correlated with protected class characteristics, even though those characteristics are not explicit inputs. ZIP code is the canonical example: geographic data that appears neutral but correlates strongly with race and national origin because of residential segregation patterns. Employer name, in some models, correlates with national origin. Shopping behavior data correlates with religious practice. The model does not "know" it is using these proxies; it is finding statistical patterns that happen to be racially or ethnically distributed. The outcome is discriminatory regardless of intent.
The legal standard in fair-lending enforcement is that if an institution is shown to use a practice that produces disparate impact on a protected class, the burden shifts to the institution to demonstrate that the practice is a business necessity and that no less discriminatory alternative exists. The "less discriminatory alternative" requirement is operationally demanding: it requires the institution to have actually searched for and tested alternative model specifications that would produce equivalent predictive performance with less disparate impact, and to have documented that search. An institution that deployed an AI underwriting model without performing this analysis is not in a defensible position if a fair-lending examination finds disparate impact.
For banks using vendor-provided AI underwriting models, this creates a procurement challenge. The vendor's model documentation may not include a disparate-impact analysis. The vendor may not be willing to share the model's feature importances or training data composition. OCC Bulletin 2026-13 and the interagency model-risk framework are explicit that these limitations do not relieve the institution of its fair-lending obligations. If the vendor cannot provide the information needed to perform a disparate-impact analysis, that is a vendor-selection disqualifier, not a documentation waiver.
The Less Discriminatory Alternative Search in Practice
For institutions that have discovered or suspect disparate impact in their AI underwriting model, the less discriminatory alternative (LDA) search is the documented process that can transform a finding from an enforcement action into a manageable examination finding. The LDA search involves testing alternative model specifications or configurations to determine whether they can achieve comparable predictive performance with less disparate impact on protected classes. A documented LDA search that shows the institution actively sought a fairer model and selected the least discriminatory option is a meaningful mitigation, even when the selected model still produces some disparity.
Institutions that have never done an LDA search, do not know what one is, and have not required vendors to provide one are in the weakest possible position when a disparate-impact finding emerges. The cost of building this capability into the vendor due diligence and model-risk management process is minor compared to the cost of a consent order. This is the core practical lesson of OCC Bulletin 2026-13 for underwriting AI.
Automated Underwriting Systems in Mortgage: The GSE Baseline
Mortgage lending has the longest history of automated underwriting of any retail credit product, through the government-sponsored enterprise (GSE) systems. Fannie Mae's Desktop Underwriter and Freddie Mac's Loan Product Advisor are the two dominant automated underwriting systems (AUS) for conforming mortgage; nearly every conforming mortgage application is run through one or both before being sold to a GSE. These systems are score-and-recommend engines: they produce an "Approve/Eligible," "Refer," or "Refer with Caution" recommendation, which lenders use to structure their underwriting workflow.
The key compliance discipline in GSE AUS usage is the same as in any AI-assisted underwriting: the AUS recommendation is an input to the underwriter's decision, not the decision itself. A loan officer who presents a denial to a borrower solely on the basis of a "Refer with Caution" from DU, without an underwriter reviewing the file and articulating specific adverse-action reasons grounded in the file, has not completed the required adverse-action process under Regulation B. The GSE systems produce "key factors" that drove the recommendation, which are the starting point for reason code development, but they require human translation and verification before they become a Regulation B-compliant adverse-action notice.
AI underwriting tools marketed to lenders in 2026 often position themselves as extensions or replacements of GSE AUS systems for non-conforming and portfolio lending. The same disciplines apply, without the benefit of the regulatory scrutiny and public validation record that the Fannie Mae and Freddie Mac systems have accumulated. A new AI underwriting tool for a community bank's portfolio product is an untested model in a high-stakes regulatory environment, which is precisely the scenario OCC Bulletin 2026-13 was written to address.
The Accountability Chain: Who Owns What in an AI-Assisted Decision
In a fully manual underwriting process, the accountability chain is simple: the underwriter reviews the file, makes a recommendation, the credit committee or loan committee approves it, and the institution records the decision and provides the required notice. Every step in that chain has a named human accountable for it.
AI-assisted underwriting creates potential gaps in that chain if the workflow is not designed carefully. Here is where accountability sits in a well-designed AI-assisted underwriting process, and what happens when it slips.
The model vendor is accountable for delivering a model that performs as documented and for providing the institution with the information needed to govern the model under OCC Bulletin 2026-13. The vendor is not accountable for the institution's credit decisions or the institution's compliance with ECOA. The vendor contract should specify what model documentation, validation reports, and disparate-impact testing data the vendor will provide and on what schedule.
The model-risk management function at the institution is accountable for the institution's validation of the model (or its review of vendor-provided validation), for ongoing performance monitoring, for disparate-impact testing, and for escalating findings to senior management and the board as required by OCC Bulletin 2026-13. In smaller institutions that lack a dedicated model-risk team, this function may sit with the chief credit officer, the chief risk officer, or a compliance function, but it must sit somewhere and the accountability must be named.
The underwriter is accountable for the credit decision on each individual file. This accountability cannot be delegated to the model. The underwriter must be able to articulate why they approved or denied the application in terms of specific credit factors, and those reasons must be consistent with the institution's credit policy. An underwriter who cannot explain a decision in their own words, as distinct from restating a model output, has not performed underwriting; they have performed model transmission.
The senior credit officer or loan committee is accountable for the institution's overall credit policy, including the decision to use AI in underwriting and the approval of the governance framework under which AI operates. In the supervisory agreement scenario described at the opening of this lesson, the accountability went up to the senior credit officer and the board, because the institution-level decision to use an ungoverned AI underwriting tool was a governance failure, not just an underwriter error.
Key Takeaways
- AI in underwriting operates in four distinct roles, ranging from file preparation and summary (lower risk) to fully automated credit decisions (highest risk). Most community and regional banks operate at Role 1 or Role 2 in 2026; understanding which role your institution uses determines what governance obligations apply.
- A score is a model output; a decision is a human judgment. Adverse-action notices must be based on the human decision and must contain specific, accurate reasons grounded in the actual file, never "the model said no" and never a reason the data does not support.
- The legal asymmetry between approvals and denials is absolute in underwriting: every adverse action requires a specific, timely, accurate notice to the applicant, and the reasons must represent the actual reasons the underwriter applied to the specific file.
- Disparate impact in underwriting AI can occur through proxy variables, even when no protected characteristic is an explicit model input. ZIP code, employer name, and other facially neutral variables can correlate with race, ethnicity, or national origin and produce discriminatory outcomes.
- The less discriminatory alternative search is both a legal requirement and a practical mitigation: institutions that have documented their search for a fairer model before deployment are in a meaningfully better position when a fair-lending examination finds disparity.
- OCC Bulletin 2026-13 requires that vendor-provided AI underwriting models be subject to the same model-risk management governance as internally developed models. A vendor's inability to provide a disparate-impact analysis or model documentation is a procurement disqualifier, not a waiver.
- The human accountability chain in AI-assisted underwriting must be explicit and documented: the model vendor provides the tool, the model-risk function validates it, the underwriter owns the credit decision, and senior credit leadership owns the governance framework.
- Pre-scoring systems that accelerate high-volume consumer lending require disparate-impact testing of both denial rates and approval terms across protected classes, because AI-influenced outcomes in consumer credit are subject to the same fair-lending standards as mortgage.
Skill.re