Your 90-Day On-Ramp
Ninety days is the right unit of time for this transition. It is long enough to build a real workflow and run it through enough production files to know whether it holds up. It is short enough to maintain momentum against the competing demands of an actual job. And it maps to the internal performance and review cycles at most banks, which matters because the credential you are building is meant to be visible inside your institution, not just on a resume. By day ninety, you are not finished with AI. You have shipped one verified, defensible AI-assisted workflow, and you can explain it to a compliance examiner. That is the on-ramp. What comes next is L2, and the path from there to L5 is documented in this program. But day one matters. This lesson is about getting to day one, and then day ninety, without the false starts that trip up most bankers who attempt this transition on their own.
The biggest risk in a 90-day plan is not lack of motivation. It is loss of focus. Banking professionals who try to "learn AI" broadly, without a specific workflow target, tend to accumulate knowledge without building competency. They take general AI courses that do not mention the Equal Credit Opportunity Act (ECOA) or Regulation B (Reg B). They experiment with consumer AI tools that are not connected to their actual LOS. They read vendor whitepapers and conference summaries that describe capabilities without teaching operational practice. After ninety days, they have opinions about AI but no workflow to show for it, and the opportunity to demonstrate institutional value has not materialized. This plan is designed to avoid that outcome.
What You Are Building, and Why It Matters
The output of this 90-day plan is a single documented, verified AI-assisted workflow that you can describe in three sentences: what AI does in the workflow, what the human verification step is, and what the compliance output looks like. You are not building a technology project. You are not becoming a data scientist. You are becoming a banking professional who runs one specific AI-assisted task in a way that is faster than the manual alternative, produces defensible output, and can survive a regulatory examination.
The reason this specific output matters is that it is auditable. An auditable workflow is the institutional currency of AI competency in a regulated environment. Your employer, your examiner, and eventually your next employer can look at it and evaluate it. A general AI literacy certificate cannot be evaluated this way. A workflow can.
The three-sentence description does real work. It forces you to know what the AI is actually doing (not just "it helps me," which is not a description), what your verification step is (not just "I review it," which is not a procedure), and what the compliance output looks like (not just "the file," which does not specify what makes the output defensible). If you cannot write those three sentences by day ninety, the workflow is not finished yet.
Choosing the right workflow to build is the most important decision in this plan. The criteria are:
- It is in your current job, not a hypothetical future role.
- It involves a task you do frequently enough to build real proficiency in ninety days (at least a dozen times, preferably more).
- It has a clear verification step where your domain expertise adds value.
- It produces output that has a compliance dimension (adverse-action documentation, income extraction that feeds an underwriting decision, BSA/AML alert triage, borrower communication) so that the regulatory knowledge you are building is directly relevant.
If you are a loan officer, the most accessible target is AI-assisted income verification and pre-populated LOS entry: using AI to extract income from a pay stub or tax return, verifying the extraction against the source document, and entering the verified figures into the LOS. If you are an underwriter, the most accessible target is AI-assisted adverse-action reason drafting: using AI to produce a first draft of the specific Reg B reasons for a denial, then verifying each reason against the file before the notice goes out. If you are a BSA analyst, the most accessible target is AI-assisted alert summary and triage: using AI to summarize the transaction context for a flagged alert, then verifying the summary against the actual transaction record before making the disposition decision.
Days 1 to 30: Vocabulary and Observation
The first thirty days are not about doing. They are about seeing. The goal of this phase is to develop the vocabulary and observational framework that makes the operational practice in the next phase effective.
Week one and two: the regulatory foundation
Start with the regulation, not the technology. This may feel counterintuitive. You came here because you want to learn AI. But in banking, the regulation defines what "good" looks like for AI-assisted output. If you do not know what a Reg B-compliant adverse-action notice requires, you cannot evaluate whether an AI-drafted notice is good. If you do not know what disparate impact means under ECOA and fair-lending law, you cannot evaluate whether an AI pre-scoring model is creating regulatory exposure. The regulatory foundation is not a detour; it is the framework that makes the technology practice meaningful.
In the first two weeks, focus on three regulatory concepts: adverse action under ECOA and Reg B, disparate impact under ECOA and the Fair Housing Act (FHA), and model risk under OCC Bulletin 2026-13. For adverse action, the key question is: what must a denial notice contain, and what does "specific reasons" mean in practice? For disparate impact, the key question is: why do outcomes matter even when protected-class characteristics are not inputs, and what is a proxy variable? For OCC Bulletin 2026-13, the key question is: what does the bulletin require an institution to document about an AI tool used in credit decisions, and why does it supersede OCC 2011-12?
The lessons immediately preceding this one in the program cover ECOA, Reg B, and OCC Bulletin 2026-13 in detail. This 90-day plan assumes you have read them. If you have not, start there before starting this plan.
Week three and four: the AI tool in your institution
In the second two weeks, identify the AI tools that are currently operating in your institution's lending workflow. The sources for this information are: the LOS vendor's documentation, the technology team, the operations lead, or the model-risk officer if your institution has one. The questions to ask are: what does the tool do (document extraction, pre-scoring, communication drafting, alert triage), what model or vendor underlies it, and what documentation exists about how it was validated and tested for fair-lending outcomes?
If your institution does not yet have AI tools in the lending workflow, this phase is about identifying the tools that are most commonly deployed in your role type. This is entirely feasible without institutional access: the LOS vendors (the major platforms in mortgage origination all have AI-assisted features now), the BSA/AML platform vendors, and the credit-scoring platform vendors all publish documentation about their AI tools. Review two or three vendor technology overviews with the regulatory questions from weeks one and two in mind: what does this tool do, what would the adverse-action documentation look like in a workflow that uses it, and what would a fair-lending examiner want to know about it?
The observation skill you are building in this phase is the ability to see an AI tool's role in a workflow clearly, without the marketing framing the vendor applies and without the skepticism that comes from unfamiliarity. You are training yourself to describe the tool the same way a model-risk examiner would: what it does, what it produces, what the limitations are, and what human oversight is required.
The one-page observation log
At the end of this first thirty days, write one page. Not a formal document. One page with three sections: what the AI tool in your target workflow does, what the human verification step is (or should be, if it is not currently explicit), and what the compliance output requirement is for your chosen workflow target. This is the first draft of the three-sentence description you will refine over the next sixty days. It does not need to be perfect. It needs to exist, because the act of writing it identifies the gaps in your understanding that the next phase will close.
Days 31 to 60: Building the Workflow
The second thirty days are about building. By the end of this phase, you have a draft workflow that you have run through at least five real files and that you can describe to a colleague in plain language.
Week five and six: the first run
Start with the simplest possible version of your target workflow. If your target is AI-assisted income extraction, start with a single straightforward file: a salaried borrower with a simple W-2 and two recent pay stubs. Run the AI extraction, then verify every figure the AI extracted against the source document. Not "spot-check." Every figure. At this stage, you are not trying to be efficient. You are trying to understand where the AI makes errors, what kinds of errors it makes, and how your domain expertise catches them.
The error patterns matter. AI document-extraction tools make specific kinds of errors: they sometimes misread a figure when the document is a poor-quality scan, they sometimes extract the gross figure when the relevant figure is the net, they sometimes miss a relevant income type because the document format is unusual. Understanding these patterns in the specific tool you are using is what makes your verification step reliable rather than perfunctory. A perfunctory verification step does not protect you; it gives you false confidence.
Document what you find. A simple log: the file identifier (anonymized as needed for privacy), the AI-extracted figures, the source-document figures, the discrepancy if any, and your disposition (accepted the extraction, corrected to source, flagged for review). This log is the raw material for the verification procedure you will formalize in weeks seven and eight. It is also early evidence for the workflow documentation you will complete by day ninety.
Week seven and eight: formalizing the verification step
After five to ten files, you have enough data to formalize the verification step. The verification procedure should be specific: which figures get verified against which source documents, in what order, with what check (arithmetic recalculation, visual comparison, LOS field cross-reference). The procedure should also include the disposition logic: if the AI extraction and the source document agree, proceed; if they differ, use the source document and log the discrepancy; if the source document is ambiguous or missing, flag for underwriter review.
The formalized verification step is what converts an informal practice into a defensible procedure. An informal practice says: "I checked the numbers." A defensible procedure says: "I verified gross W-2 income against box 1 of the W-2 form, verified YTD gross from the pay stub against the most recent pay stub in the file, and recalculated the monthly income figure using the applicable annualization method for the income type." The latter is what a compliance examiner can evaluate. The former is not.
In this phase, also start building your knowledge of the adverse-action documentation step for your chosen workflow. If your workflow is income extraction feeding an underwriting decision, the adverse-action step is downstream: when the underwriting decision is a denial, the reasons must be specific, accurate, and grounded in the file facts that the AI-assisted extraction produced. If the extraction was wrong and was not caught, the adverse-action reason may be wrong too, which is a compliance failure. Understanding this downstream consequence is what makes the verification step feel genuinely important rather than procedurally required.
The check-in conversation
At the end of day sixty, have one conversation about the workflow with someone whose judgment you trust: a peer underwriter, a compliance officer, your manager, or a mentor in another institution. The goal of the conversation is not validation. It is to identify the gap in your understanding that you cannot see because you are too close to the work. Ask specifically: "Is there a fair-lending or adverse-action dimension to this workflow that I have not accounted for?" That question tends to surface the most valuable feedback at this stage because fair-lending exposure in AI-assisted workflows is easy to miss if you are focused on the operational mechanics.
Days 61 to 90: Verifying, Shipping, and Documenting
The third thirty days are about reaching production quality: the workflow is running on real files, the verification procedure is documented, and you can describe the whole thing in the three sentences that matter.
Week nine and ten: the compliance layer
Return to the regulatory foundation from weeks one and two with your specific workflow in mind. For your target workflow, answer these questions in writing: where does ECOA's adverse-action requirement touch this workflow? Where does disparate impact risk exist in this workflow, and what is the mitigation? What does OCC Bulletin 2026-13 require the institution to document about the AI tool in this workflow? What is the institution's current documentation status on those requirements?
These questions may require conversations with your compliance team. That is intentional. The conversations position you as someone who is proactively managing the compliance dimension of the AI tool, not just using it. They also give you access to any existing model-risk documentation the institution has for the tool, which may be more complete than you expect or may reveal documentation gaps that represent an opportunity to contribute.
If your institution uses a third-party AI vendor (as most do for LOS-integrated AI features), this is also the moment to review the vendor's documentation from a third-party risk perspective. OCC Bulletin 2026-13 makes clear that the institution cannot transfer its compliance obligations to a vendor: if the vendor's AI tool produces a disparate-impact outcome or generates an inaccurate adverse-action reason, the institution owns that outcome, not the vendor. Knowing what the vendor has documented about the tool's validation and fair-lending testing tells you how much institutional supplementation is needed.
Week eleven and twelve: the documentation sprint
In the final two weeks, produce the workflow documentation. The document has four sections.
Section one: workflow description. What AI does in the workflow, step by step, with the specific tool identified. What data or documents feed the AI. What the AI produces. What happens with that output.
Section two: verification procedure. Every verification check, specified by field, source document, and check method. The disposition logic for each possible verification outcome. The logging requirement for discrepancies.
Section three: compliance documentation. How ECOA's adverse-action requirement is satisfied in this workflow. Where the disparate-impact risk is and how the workflow addresses it. What the institution's model-risk documentation covers for this tool and what is outstanding.
Section four: the three-sentence summary. What AI does in this workflow. What the human verification step is. What the compliance output looks like. Three sentences. If you cannot write them in three sentences, the workflow is not documented clearly enough yet.
The documentation does not need to be a formal compliance memo. It needs to be specific enough that someone who did not build the workflow can read it and understand exactly what happens at each step. That clarity is what makes it a governance artifact rather than a personal note.
The day-ninety milestone
By day ninety, the milestone is: the workflow is running on production files, the verification procedure is documented and is being followed consistently, and you have the three-sentence description ready. If you can also say that you have had one conversation with your compliance team about the AI tool's model-risk documentation status, you have done all four things this plan is designed to produce: operational practice, verification discipline, regulatory integration, and governance contribution.
That combination is the L1 credential. It is the foundation for L2, where you will build more sophisticated AI-assisted workflows in credit memo drafting, adverse-action drafting, and BSA/AML triage. And it is the foundation for the titles described in the previous lesson, because the titles require demonstrated competency, and demonstrated competency requires a workflow you can point to.
What Can Go Wrong, and How to Stay on Track
Most bankers who attempt this transition encounter one or more of the following obstacles. Knowing them in advance reduces the time lost to them.
The perfect-tool problem
Some bankers stall in the first phase because the AI tool in their institution is not the one they wanted to use, or the institution has not yet deployed an AI tool in the specific workflow they have in mind. This is a real constraint, but it is not a blocker. The verification habit, the regulatory knowledge, and the documentation practice are all buildable with whatever tool is available, even if it is a simple AI drafting assistant rather than a purpose-built LOS AI feature. A workflow built around manually using an AI drafting tool to produce a first draft of an adverse-action notice, with a documented verification step and a compliance output, is a real workflow. It demonstrates the same competency as a workflow built around a sophisticated LOS integration.
The knowledge-not-practice trap
The most common obstacle is accumulating knowledge without building practice. You have read the ECOA overview, the Reg B adverse-action requirements, the OCC Bulletin 2026-13 summary, and two vendor whitepapers. You know what disparate impact means. You understand the proxy-variable concept. But you have not run a file through a workflow, and you have not written a verification procedure. This trap is seductive because reading feels like progress. The plan's structure pushes back by making the operational work (the first run, the verification log, the documentation sprint) the deliverable at each phase checkpoint. If you are in day forty and you have not run a file through a workflow yet, you are in the knowledge trap. Stop reading and run a file.
The compliance team distance problem
In some institutions, the compliance team and the origination team operate in silos that do not communicate well on technology questions. A loan officer who tries to have the week-nine compliance conversation about the AI tool's model-risk documentation may be told "that is a technology question" or "that is the model-risk team's responsibility." These are real organizational dynamics, and working around them requires either a different conversation partner or a different framing. The framing that tends to work best is: "I am building a documented AI-assisted workflow for the files I originate, and I want to make sure the adverse-action documentation step aligns with what the compliance team expects to see in a regulatory examination." That framing puts the question in terms the compliance team owns and is motivated to answer correctly.
The scale problem
Some bankers, after completing the 90-day plan, find that the workflow works well but their institution is not ready to deploy it at scale. The model-risk documentation is incomplete. The fair-lending testing has not been done. The third-party risk assessment for the vendor is outstanding. These gaps are real, and they represent governance work the institution needs to do before the AI tool can be used with full confidence in a regulatory examination. The 90-day plan is not a substitute for that institutional governance work. What it gives you is the specific knowledge to identify the gaps, articulate them to the compliance and risk teams, and contribute to closing them. That contribution is part of the governance layer that positions you for the advanced titles.
The Path from Day Ninety to the L2 Credential
This plan ends at the L1 milestone, but L1 is only the awareness and vocabulary level. The career arc described in the previous two lessons in this chapter runs through L2, L3, L4, and L5. This section sketches what the path from day ninety forward looks like, so the 90-day plan fits into a larger progression rather than standing alone.
L2 (AI-Assisted Lender/Analyst) builds the hands-on workflow skills that L1 introduced. The L2 curriculum covers AI-assisted credit memo drafting, AI-assisted adverse-action reason drafting (the goldmine workflow in the middle of the program), AI-assisted document processing, and AI-assisted BSA/AML triage. Each lesson includes a hands-on workflow with a specific verification procedure and compliance output. The L2 capstone is a verified AI-assisted deliverable: a credit memo, an adverse-action package, or a SAR narrative, with the source-verification log and compliance check attached. By the end of L2, you have built several documented workflows and have deep practice with the verification habit.
L3 (AI-Integrated Practitioner) moves from individual workflows to end-to-end systems: AI-assisted origination from application to decision, fair-lending testing workflows, and BSA/AML workflows from alert to SAR. L3 introduces grounded retrieval (using AI that is connected to your actual credit-policy documents and loan files rather than the open web), which is the technical architecture that makes AI-assisted credit work defensible at scale. The L3 capstone is a deployed or pilot workflow with grounded retrieval, human sign-off, a bias test, and a model-risk audit trail.
L4 (AI Lending Strategist) shifts from practice to governance: building the institution's AI roadmap, evaluating AI vendors under OCC Bulletin 2026-13's third-party risk requirements, standing up a fair-lending AI testing program, and leading the change management required to get an origination team to adopt a new AI-assisted workflow. This is the level where the titles described in the previous lesson (fair-lending analyst with AI scope, model-risk officer for lending, AI governance coordinator) have their full context.
L5 (AI Banking Transformer) is the enterprise level: building the institution's end-to-end AI governance program, managing board-level reporting on AI risk, and designing the organizational structure for an AI-native lending operation. This is where the CLO or CCO with AI scope titles live.
The 90-day plan is the entrance ramp to this progression. Every concept this plan introduces (the verification habit, the regulatory framework, the workflow documentation practice, the governance contribution mindset) is a foundation that the subsequent levels build on. Completing the 90-day plan well, meaning with a real workflow and real documentation, not just a read-through of the concepts, is the prerequisite for L2 working as it is designed to work.
A Note on the Community and the Credential
This program is built for the banking professional who is doing this work while doing their actual job. The 90-day plan is designed with that constraint in mind: thirty minutes a day, three to four days a week, plus the time to run files through the workflow. That is realistic inside the workload of an active loan officer, underwriter, or BSA analyst, provided the plan is treated as a professional development priority rather than an optional extra.
The certification at the end of L1 (the exam that this lesson's practice and certification questions are part of preparing you for) tests the vocabulary and regulatory knowledge from the entire L1 curriculum, including the three chapters that precede this one. The passing score is 80 percent, which reflects a genuine standard: the knowledge tested is the knowledge you need to operate AI tools in a lending environment without creating the compliance and regulatory exposures that this program is designed to help you avoid.
Passing the L1 certification is a credential you can put in your professional profile, reference in a performance review, and use as the foundation for the L2 curriculum. It is also a signal to your institution that you have built the regulatory and AI literacy foundation required for the more advanced roles described in the previous lesson. The institutions that are most actively hiring for those roles are the ones most motivated to recognize and act on that signal.
The program also runs cohort-based sessions and a practitioner community where banking professionals working through the curriculum can share workflow documents, ask questions about specific regulatory scenarios, and give and receive feedback on the verification procedures they are building. That community is a resource throughout the 90-day plan and beyond; the specific regulatory and compliance questions that arise when you build a real workflow in a real institution are the questions that the community is best positioned to answer.
Key Takeaways
- The goal of the 90-day on-ramp is one documented, verified AI-assisted workflow with a three-sentence description: what AI does, what the human verification step is, and what the compliance output looks like. That specific output is auditable and positions you for the advanced titles.
- The first thirty days are about regulatory foundation and observation: understanding ECOA, Reg B adverse-action requirements, and OCC Bulletin 2026-13 before touching the AI tool, and observing the AI tool in your current workflow without the marketing framing.
- The second thirty days are about building: running the first files through the workflow, building the error log, formalizing the verification procedure into something specific enough to be evaluated by a compliance examiner.
- The third thirty days are about compliance integration and documentation: connecting the workflow to the adverse-action requirement, assessing the model-risk documentation for the AI tool, and completing the four-section workflow document.
- The most common obstacles are the perfect-tool problem (waiting for a better AI tool instead of building with what exists), the knowledge-not-practice trap (accumulating reading without running files), and the compliance team distance problem (not connecting the technical work to the regulatory framework).
- The verification habit is the non-negotiable: every extracted figure checked against the source document, every adverse-action reason confirmed against the actual decision logic, every AI-drafted communication reviewed before it goes out. Building this habit in the first thirty days makes the subsequent workflow development reliable rather than approximate.
- The 90-day plan is the entrance to a five-level curriculum that moves from L1 awareness through L2 hands-on workflow practice, L3 end-to-end system integration, L4 governance strategy, and L5 enterprise transformation. The plan's outputs are explicitly designed as the prerequisites for L2 to work as designed.
- Completing the L1 certification (80 percent passing score) is the milestone that closes the 90-day plan and opens the path to the advanced roles and compensation described in the previous two lessons in this chapter.
Skill.re