Verifying Customer-Facing Output
At a mid-sized bank in the spring of 2026, a compliance officer named Sandra Chen was reviewing a batch of AI-generated adverse action notices before a routine pre-examination self-assessment. The notices had been produced by the bank's AI drafting tool and reviewed, in theory, by loan officers before going out. What Sandra found in the sample disturbed her: 14 of the 40 notices she reviewed contained at least one factual inaccuracy, ranging from wrong income figures to misidentified reason codes to one notice that cited a property appraisal value that appeared nowhere in the file. All 14 had been reviewed by a loan officer. All 14 had been released. The failure was not in the AI tool, which was performing as designed. The failure was in the verification step, which had been reduced, under production pressure, from a structured comparison of each claim to the file, to a quick read for tone and length. Sandra's finding had a name: a compliance gap waiting to become a CFPB action. The cheap step that could have prevented each error took under ten minutes per notice. The remediation that followed consumed three months and touched every adverse action notice the bank had sent in the prior six months. The compliance pass before send is not optional, and this lesson is the map for doing it right.
What the Compliance Pass Before Send Actually Is
The phrase "compliance pass before send" describes a structured human review of AI-generated or AI-assisted customer-facing output that occurs before the output reaches a consumer. It is not a quality check in the generic sense of reviewing for professionalism, grammar, or tone. It is a specific, methodical verification process that confirms four things about every customer-facing communication: the facts are accurate, the regulatory requirements are satisfied, the language does not create UDAAP or other legal risk, and the human reviewer has taken documented accountability for the output.
The compliance pass is the operational realization of the principle that accountability for AI-generated output stays with the human. Under the Equal Credit Opportunity Act (ECOA, 15 U.S.C. 1691) and its implementing regulation, Regulation B (Reg B, 12 CFR Part 1002), the institution that produces an adverse action notice owns every statement in it. Under the Real Estate Settlement Procedures Act (RESPA, 12 U.S.C. 2601), the servicer that sends a QWR response owns its accuracy and completeness. Under UDAAP (Unfair, Deceptive, or Abusive Acts or Practices, the consumer protection standard under the Dodd-Frank Act enforced by the Consumer Financial Protection Bureau (CFPB)), any customer-facing communication that creates consumer harm because of inaccuracy or misleading content is a potential violation regardless of whether a human or an AI produced the draft. The compliance pass is how the human takes ownership of AI output before the institution's legal exposure attaches.
OCC Bulletin 2026-13, the April 2026 interagency model-risk guidance that superseded OCC Bulletin 2011-12 and pulled AI and generative AI under model-risk, fair-lending, third-party, and board governance expectations, is explicit that human oversight of AI-generated consumer communications is a model governance requirement, not an optional enhancement. A bank that deploys AI drafting tools for customer communications without a documented, structured verification process is operating without the governance controls the 2026 guidance requires for any AI tool that influences consumer interactions.
The Four Dimensions of the Compliance Pass
A complete compliance pass evaluates AI-generated customer-facing output on four distinct dimensions. Each dimension addresses a different category of risk, and all four must be checked for any regulated communication. Checking only one or two of these dimensions, which is the failure mode that led to Sandra Chen's finding in the opening story, provides the appearance of verification without the substance.
Dimension One: Factual Accuracy
Factual accuracy is the most foundational dimension of the compliance pass, and it is the dimension most directly compromised by the pressure to review quickly. AI drafting tools generate confident, fluent prose that reads as though it is accurate. Loan officers and servicing analysts who review AI output quickly tend to read for plausibility rather than accuracy, which means they catch obvious errors (wrong borrower name, entirely wrong loan product) but miss nuanced errors (income figure from the wrong tax year, reason code that references debt-to-income when the actual reason was collateral value).
Factual accuracy verification requires tracing every specific claim in the AI-generated output back to a source document. For a credit-related communication, this means checking each figure against the loan file: the income amount in the AI draft against the tax returns or paystubs, the property value against the appraisal, the reason codes against the underwriting decision memo or credit policy exception. For a servicing communication, this means checking each account-specific claim against the servicing system data: the escrow amount against the escrow analysis, the insurance premium against the insurance payment record, the delinquency status against the payment history.
This verification is not a reading task. It is a comparison task. The reviewer needs the AI draft and the source file open simultaneously, moving through the draft claim by claim and confirming each claim against the corresponding source. A reviewer who reads the draft, thinks "that sounds about right," and moves on has not performed factual accuracy verification. That is the failure mode that produced 14 inaccurate notices in Sandra Chen's sample.
The specific items to verify in factual accuracy for common communication types are as follows. For adverse action notices: each reason code and the file data that supports it, any income or asset figures cited, any property value or appraisal figures cited, the application date and the action date, and any statements about the basis for the action. For QWR responses: each account fact cited (payment amounts, disbursement dates, fee amounts, escrow figures), any regulatory timeline claims (RESPA response period, escrow analysis timing), and the specific answer to the borrower's question. For loss mitigation notices: the specific option offered or declined, the basis for the determination, any income or asset figures cited in the evaluation, and the timeline for any required response by the borrower.
Dimension Two: Regulatory Completeness
Regulatory completeness verification confirms that the AI-generated output contains all elements required by the applicable regulation. This dimension is distinct from factual accuracy: a communication can be factually accurate in every claim but still be noncompliant if it is missing a required disclosure, a required contact reference, or a required statement of consumer rights.
AI drafting tools miss required regulatory elements for a predictable reason: the elements are required by regulation but are not always naturally present in training data examples of the communication type. A model trained on examples of adverse action notices written by loan officers who did not consistently include the CFPB contact information will learn to write adverse action notices that do not include the CFPB contact information. A model trained on QWR responses that variably included or excluded the RESPA right-to-dispute-further language will produce responses that sometimes include it and sometimes do not. Regulatory completeness verification uses a checklist of required elements, not the reviewer's memory of what belongs in the communication.
The required elements checklists for common communication types are as follows.
For adverse action notices under Reg B: a statement of the action taken, the name and address of the creditor, a statement of the applicant's rights under ECOA, the name or contact information of the federal agency that administers compliance, and a statement of specific reasons or a disclosure of the right to request specific reasons within 60 days. If specific reasons are given, they must be at least four (or the actual number of factors that contributed, if fewer than four were material) and they must be accurate. If the decision was based on information from a consumer reporting agency, the adverse action notice must include the consumer reporting agency's name and contact information and a statement of the applicant's right to obtain a free copy of the report within 60 days. This is an FCRA (Fair Credit Reporting Act, 15 U.S.C. 1681) requirement that applies independently of Reg B and that AI tools frequently omit if not specifically prompted.
For RESPA QWR responses under Regulation X: the servicer must acknowledge receipt within five business days, investigate within 30 business days (extendable to 45 business days with notice to the borrower), and provide a written response that either (a) acknowledges the error and states the action taken, (b) provides the information requested and states the reason it cannot be corrected if correction is not possible, or (c) explains why the servicer believes the account is correct and provides information about the complaint process. The written response must include the servicer's name and contact information and a statement explaining how the borrower can contact the servicer's designated error resolution department.
For CFPB loss mitigation decision notices under Regulation X: if the servicer approves the borrower for a loss mitigation option, the notice must identify the specific option offered and the deadline for the borrower to accept. If the servicer denies the borrower for all loss mitigation options, the notice must state the reason for denial for each option, and if the reason for denial is an investor restriction, the notice must identify the applicable investor restriction. The denial notice must also include a statement of the borrower's right to appeal the denial within 14 days; this appeal right applies when the servicer received a complete loss mitigation application 90 or more days before a scheduled foreclosure sale (12 CFR 1024.41(h)).
Dimension Three: UDAAP and Legal Risk in the Language
Even when an AI-generated communication is factually accurate and contains all required regulatory elements, it can still create UDAAP or other legal risk through the specific language choices it makes. This is the subtlest and most judgment-dependent dimension of the compliance pass, and it is the one that requires the most experienced reviewer.
UDAAP language risk takes several forms in AI-generated banking communications. The first form is misleading framing: language that is technically accurate but creates a false impression. An adverse action notice that says "your application has been placed on hold for additional review" when the action is a denial creates a false impression that the decision is provisional, which may mislead the borrower about their legal rights and the timeline for any reconsideration. The communication is not factually false, but it is deceptive under the UDAAP standard because a reasonable consumer would understand it to mean something other than what the bank has actually done.
The second form is unsupported implication. AI tools trained on financial communication data will generate contextually plausible language that implies things about the borrower's situation that the file does not support. Language like "we encourage you to work on your credit profile before reapplying" in a denial notice implies that the basis for the denial was a credit profile issue, even if the actual basis was a debt-to-income issue, a property issue, or a policy exception. That implication is a Reg B inaccuracy and a UDAAP concern simultaneously.
The third form is inappropriate urgency or minimization. An AI tool that produces a loss mitigation outreach letter that characterizes an impending foreclosure referral as a "next step in our standard servicing process" has minimized a consequential action in a way that is likely to mislead the borrower about the seriousness of their situation and the importance of responding. Conversely, a collections communication that implies foreclosure is imminent when regulatory timelines have not run is creating false urgency that constitutes a UDAAP concern and may implicate the Fair Debt Collection Practices Act.
The fourth form is inaccessible language that constitutes abusive practice. Under the UDAAP standard, a communication that materially interferes with a consumer's ability to understand their rights or the terms of their financial product can be abusive even if every statement in it is accurate. AI drafting tools can produce technically accurate but functionally incomprehensible communications by stringing together regulatory citations, defined terms, and passive-voice constructions in ways that satisfy the letter of the disclosure requirement without its spirit. The plain-language check in this dimension asks: would a person without legal training, reading this communication for the first time, understand what the bank has done, why, and what the consumer's options are?
Dimension Four: Documentation of Human Accountability
The fourth dimension of the compliance pass is not about the communication itself; it is about the institutional record that the communication was reviewed. Documentation of human accountability is the mechanism that allows the bank to demonstrate, in any subsequent regulatory examination or litigation, that the AI-generated output was reviewed by a named human, on a specific date, against a specific checklist, before it was sent.
This documentation requirement is not bureaucratic excess. It is the factual foundation of the bank's defense if a communication is later found to contain an error. A bank that can show that its AI-assisted adverse action notice was reviewed by a loan officer on a specific date using a documented checklist, and that the officer confirmed each reason code against the file, is in a fundamentally different position than a bank that can show only that the notice was generated by an AI tool and released. The former has a documented human control; the latter has an uncontrolled AI output.
The documentation must capture: the name of the reviewer, the date and time of the review, the communication type and the borrower account to which it relates, a confirmation that the factual accuracy, regulatory completeness, and UDAAP language dimensions were checked, and any modifications made to the AI draft during the review process. For most communication types, this can be accomplished through an annotation in the loan origination system (LOS, the software platform managing the origination workflow) or servicing system, without requiring a separate documentation artifact. The key is that the record is tied to the specific communication and the specific file, so that it can be retrieved if needed.
Building the Verification Checklist: A Practical Tool
The verification checklist is the practical implementation of the four-dimension compliance pass. A checklist converts the abstract requirement to verify AI output into a concrete, executable series of steps that a loan officer, servicing analyst, or compliance reviewer can complete in a consistent, documented way. The checklist is the difference between verification that happens reliably and verification that is ad hoc, inconsistent, and likely to be skipped under volume pressure.
An effective verification checklist for a specific communication type has the following structure.
Header: Communication type and applicable regulation. The checklist begins by identifying the communication type (adverse action notice, incomplete application notice, QWR response, loss mitigation denial, early intervention letter) and the primary regulation that governs it. This identification step ensures that the reviewer is using the correct checklist for the communication being reviewed and is applying the right regulatory standard.
Section 1: Factual accuracy items. A list of specific factual claims to verify, organized by data source. For an adverse action notice: the reason codes and the file element supporting each (debt-to-income ratio: verify against underwriting worksheet), the income figure (verify against tax returns page X), the property value (verify against appraisal page Y), the application date (verify against LOS intake record). For a QWR response: the escrow amount (verify against escrow analysis statement), the insurance premium (verify against insurance disbursement record), the tax amount (verify against tax payment record). The factual accuracy section should be specific enough that a reviewer cannot check it without actually comparing the draft to the file.
Section 2: Required regulatory elements. A list of all elements required by the applicable regulation for this communication type, with a yes/no check for each. For an adverse action notice: reason codes present (yes/no), ECOA rights statement present (yes/no), federal agency contact present (yes/no), consumer reporting agency notification if applicable (yes/no). For a QWR response: direct answer to borrower's question present (yes/no), servicer contact information present (yes/no), statement of further dispute rights present (yes/no). The regulatory elements section should be maintained by the compliance team and updated when regulations change.
Section 3: UDAAP language flags. A set of questions that the reviewer answers about the language of the communication: Is the action clearly and accurately described, not minimized or mischaracterized? Does the communication imply things about the borrower's situation that the file does not support? Is the urgency of the communication appropriate to the actual situation? Would a consumer without legal training understand what this communication means and what they need to do? The UDAAP section is the most judgment-dependent section and may benefit from examples of problematic language to watch for, drawn from past error tracking or examination findings.
Section 4: Sign-off. The reviewer's name, the date, and a confirmation that all three preceding sections were completed. This is the documentation of human accountability described in Dimension Four above.
An example of a complete adverse action notice verification checklist entry:
Reason Code 1: Excessive obligations in relation to income. Verify: debt-to-income ratio in draft matches the calculated ratio on the underwriting worksheet (file section: [underwriting analysis, tab DTI]). Draft states [X]%; file shows [Y]%. Match: yes/no. If no: correct the draft before sending.
Reason Code 2: Insufficient collateral value. Verify: property value cited in draft matches the appraisal conclusion (file section: [appraisal report, summary page]). Draft states [$X]; file shows [$Y]. Match: yes/no. If no: correct the draft before sending.
This level of specificity prevents the failure mode of reading for plausibility rather than comparing for accuracy. When the checklist says "draft states [X]%; file shows [Y]%," the reviewer must fill in those two values. That requires actually looking at the AI draft and the file, side by side, rather than reading the draft and assuming it is correct.
The Pre-Examination Self-Assessment for AI-Assisted Communication
A bank using AI-assisted customer communication should conduct periodic self-assessments of its verification workflow before examiners arrive. The self-assessment is the institutional analog to the individual compliance pass: a systematic review that identifies weaknesses in the workflow before they become examination findings.
The self-assessment has four components, drawn from the structure that Sandra Chen's compliance review in the opening story should have been conducting systematically rather than discovering reactively.
Sample review of outgoing communications. A random sample of AI-assisted communications sent in the prior period is reviewed by a compliance officer or quality assurance analyst against the full four-dimension checklist. The sample should cover all communication types and all staff members who use the AI drafting tool. The review identifies the error rate and error types: which dimension (factual accuracy, regulatory completeness, UDAAP language, documentation) is failing most frequently, and which communication types produce the highest error rate.
Complaint review with communication linkage. Consumer complaints from the prior period are reviewed for any indication that a complaint was triggered by or related to a customer-facing communication. Complaints that mention specific inaccuracies in a notice, specific misunderstandings created by a communication, or specific missing information that should have been in a notice are coded as potential AI-assisted communication errors and reviewed against the files to determine whether the communication was AI-assisted and whether the error was detectable through the standard verification workflow.
Staff verification workflow assessment. A review of the LOS and servicing system records for AI-assisted communications identifies whether the documentation of human review is present, complete, and dated. If the documentation is missing for a significant proportion of communications, the staff verification workflow is not being executed consistently, and the bank has an AI output going to consumers without the documented human accountability that OCC Bulletin 2026-13 requires.
Checklist currency review. The verification checklists for each communication type are reviewed against current regulatory requirements to confirm that the required elements sections are accurate and up to date. Regulations change; the CFPB has updated its mortgage servicing rules several times since 2015, and state-level borrower protection requirements have evolved alongside federal rules. A checklist that was current in 2024 may be missing elements required in 2026. The compliance team is responsible for maintaining checklist currency, and the self-assessment confirms that maintenance has occurred.
Scaling the Compliance Pass Without Losing the AI Benefit
The compliance pass takes time. A four-dimension verification of a complex adverse action notice, done correctly, takes 15 to 20 minutes. For an institution processing hundreds of adverse action notices per month, that is a significant staff time commitment. The legitimate question is whether the compliance pass erases the time saving that AI drafting provides, and if it does, whether the institution should use AI drafting at all.
The answer is that a well-designed compliance pass captures most of the AI time saving while providing the verification required for safe deployment. Without AI, drafting a complete adverse action notice from scratch, including looking up the regulatory requirements, assembling the applicable reasons from the file, and writing the required disclosures, takes approximately 30 to 45 minutes for a loan officer who performs this task regularly. With AI drafting and a structured compliance pass, the combined time is approximately 15 to 25 minutes: the AI produces the draft in under two minutes, and the compliance pass takes 13 to 23 minutes depending on complexity. The time saving relative to full manual drafting is roughly 50 to 60 percent. That saving compounds across hundreds of communications per month and translates to real capacity freed for higher-value underwriting and relationship work.
The compliance pass can also be scaled more efficiently as the workflow matures, through several design choices that reduce verification time without reducing verification quality.
Risk-tiered review intensity. Not every communication carries equal regulatory risk. A general account status update carries lower risk than a loss mitigation denial or an adverse action notice for a mortgage application. The institution can implement risk-tiered review intensity: a comprehensive four-dimension check for high-risk communication types, a streamlined two-dimension check (factual accuracy and regulatory completeness) for lower-risk types, and a spot-check sampling approach for the lowest-risk categories. The tiering must be documented and approved by compliance; it cannot be left to individual reviewer discretion.
Pre-verified prompt templates. When an approved prompt template is used, the AI output is more predictable and the systematic errors are more narrowly defined. A reviewer using an approved template can focus the verification on the variable elements (the file-specific facts the prompt provided) rather than re-checking the regulatory elements that the template was designed to include. This does not eliminate the regulatory completeness check, which must confirm the template is still current, but it reduces the time required for that dimension.
Second-tier sampling for chronic error patterns. If the self-assessment identifies a specific staff member, communication type, or AI tool behavior that is producing recurring errors, a second-tier review requirement (two-person verification for communications from that staff member or of that type) can be implemented as a targeted control while the root cause is addressed. This concentrates additional verification time where the risk is highest rather than applying uniform additional burden across all communications.
Key Takeaways
- The compliance pass before send is a four-dimension structured review: factual accuracy (every claim traced to a source document), regulatory completeness (all required elements present per applicable law), UDAAP and legal language risk (no misleading framing, unsupported implication, inappropriate urgency, or inaccessible language), and documentation of human accountability (named reviewer, date, checklist completion). All four dimensions must be checked for every regulated communication.
- Factual accuracy verification is a comparison task, not a reading task. The reviewer must compare each specific claim in the AI draft against the corresponding file source with both open simultaneously. Reading the draft and confirming it "looks right" is the failure mode that produced 14 inaccurate notices in the opening story's compliance review sample.
- Regulatory completeness verification uses a checklist, not memory. AI drafting tools miss required regulatory elements because their training data does not consistently model complete compliance. A required elements checklist maintained by the compliance team and updated when regulations change is the mechanism that prevents regulatory incompleteness from becoming an examination finding.
- UDAAP language risk survives factual accuracy and regulatory completeness. A communication can be factually correct and contain all required elements while still being misleading in its framing, implying unsupported characterizations of the borrower's situation, or using language inaccessible to a reasonable consumer. The UDAAP dimension of the compliance pass requires experienced judgment, not just mechanical comparison.
- Documentation of human accountability is not bureaucratic overhead; it is the institutional evidence that AI output was controlled before it reached consumers. OCC Bulletin 2026-13 requires documented governance controls on AI in consumer-facing applications, and the compliance pass documentation is the specific artifact that satisfies that requirement for customer communication AI.
- AI drafting with a structured compliance pass delivers approximately 50 to 60 percent time savings relative to full manual drafting, capturing most of the productivity benefit while maintaining the human oversight that ECOA, RESPA, UDAAP, and OCC Bulletin 2026-13 require. The time saved by AI drafting more than justifies the 15 to 25 minutes required for a complete verification pass.
- The periodic pre-examination self-assessment, covering sample communication review, complaint linkage, staff workflow documentation review, and checklist currency review, is the institutional mechanism for identifying weaknesses in the compliance pass before they become examination findings. A bank that runs this self-assessment consistently is building the exam-ready documentation posture that OCC Bulletin 2026-13's governance expectations require.
- Accountability for AI-generated customer-facing output stays with the human who reviewed and approved it. The compliance pass is not a formality; it is the moment when the institution's legal exposure attaches to a named individual's judgment and documented review. That accountability is both the compliance requirement and the professional standard for responsible AI use in banking.
Skill.re