Exception and Complex-Credit Routing
Consider a composite scenario drawn from the type of routing failures that fair-lending enforcement actions have documented: a commercial real estate lender receives an application for a $3.8 million acquisition loan on a mixed-use property in a neighborhood undergoing rapid gentrification. The borrower is a minority-owned development company with seven years of operating history, a track record of three successfully completed mixed-use projects, and a debt service coverage ratio (DSCR, the ratio of the property's projected net operating income to its annual debt service, the core underwriting metric for income-producing real estate) of 1.18, just below the institution's standard minimum of 1.20. The institution's AI pre-scoring model flags the file as an exception: DSCR below threshold, mixed-use property classification requiring committee review, and construction-to-permanent loan structure outside the standard residential product set. The model routes the file to the exception queue and attaches the relevant exception flags. So far, the AI has done exactly what it was designed to do. What happens next is where the process fails. A junior underwriter, facing a large queue and unfamiliar with the exception-routing protocols for complex commercial credits, sees the exception flags, notes the DSCR shortfall and the committee-review requirement, and denies the application without sending it to the commercial credit committee. The adverse-action notice cites "insufficient debt service coverage." The file never reaches a human with the authority and experience to evaluate the borrower's track record, the quality of the project, or the compensating factors that might have supported an exception under the institution's commercial lending policy. A competing regional bank later approves a substantially similar loan to the same borrower on comparable terms. The fair-lending complaint that follows cites the denial of a minority-owned business on a file with a DSCR that was within exception range, by a human who lacked the authority to exercise exception judgment. The AI routing system was not the problem. The routing protocol was.
Why Routing Is a Governance Function, Not a Convenience Feature
The central insight of exception and complex-credit routing is that deciding which human reviews a file is as consequential as the review itself. An AI pre-scoring system that routes every exception to the nearest available underwriter, regardless of that underwriter's authority level or product expertise, is not a governance improvement over manual queue management. It is a fast way to route important files to the wrong people.
Routing is a governance function because authority is not uniform across an underwriting team. Most lending institutions have explicit lending authority limits: loan amounts, risk levels, and exception types that require specific officer-approval levels or committee review. A loan officer may have authority to approve clean residential mortgages up to $750,000. An exception on a commercial real estate loan above $2 million may require a senior vice president or a credit committee. A complex structure involving a development company with multiple project-level entities may require the chief credit officer. These authority limits are defined in the credit policy manual, and they exist because the institution has determined that decisions above a certain complexity or risk level require proportionally more experienced human judgment. An AI routing system that ignores authority limits does not improve governance; it removes it.
OCC Bulletin 2026-13, the April 2026 interagency model-risk guidance that superseded OCC 2011-12 and explicitly pulled AI and generative AI under model-risk, fair-lending, third-party, and board-governance expectations, addresses this directly. The bulletin's human oversight requirements extend to the design of the routing function: the institution must demonstrate that its AI workflow routes files to humans with the appropriate authority and expertise to make the decisions required. A workflow design that permits an AI to route a complex credit exception to a junior underwriter without the exception authority for that transaction type is a governance deficiency, not a minor procedural gap.
The ECOA (Equal Credit Opportunity Act, the federal statute prohibiting credit discrimination on the basis of race, color, religion, national origin, sex, marital status, age, or receipt of public assistance) and Regulation B (Reg B, 12 CFR Part 1002, the CFPB's implementing regulation for ECOA) implications are equally direct. A denial of a file that should have been reviewed by a higher authority but was declined by a lower one is a procedural deficiency that can become the basis for a fair-lending claim if the borrower is a member of a protected class and a similarly situated non-protected-class borrower would have received the higher-authority review. The institution cannot defend this denial by saying "the AI routed it." The routing protocol was the institution's design choice, and the denial was the institution's action.
Routing determines which human reviews a file; the governance design must ensure that the human receiving the file has the authority, expertise, and time to make the decision the file requires.
Building a Routing Taxonomy for Lending AI
A routing taxonomy is the structured framework that defines how files are sorted by complexity, risk, and decision authority, and maps each category to the appropriate human reviewer. Building a routing taxonomy is the design step that most institutions skip or execute partially, and the skip is usually visible in the examination findings that follow.
A well-designed routing taxonomy for a lending institution's AI-integrated origination workflow has four tiers.
Tier one: standard approvals. Files in which all policy thresholds are met, no exception triggers are present, no unusual income structures are involved, and the loan amount is within the loan officer's standard approval authority. These files go to the clean-queue protocol: a structured review by a loan officer or junior underwriter with clear verification steps and standard documentation. The human review is efficient because the file is genuinely straightforward.
Tier two: minor exceptions. Files in which one or two policy flags are present but within the exception authority of a senior loan officer or senior underwriter (not requiring committee review). The exception types that fall in this tier are defined explicitly in the credit policy: a credit score within 20 points of the guideline minimum with documented compensating factors, a DTI above the standard threshold but within the institution's exception ceiling, or a property type that is slightly outside standard guidelines but within the loan officer's exception authority. These files are routed to a senior underwriter or loan officer with the authority to act on the specific exception type, with the exception flag and the compensating-factor data pre-populated by the AI.
Tier three: complex exceptions requiring committee review. Files in which the exception is above the individual officer's authority level, the loan amount exceeds the committee-review threshold, the structure is complex (construction-to-permanent, multi-entity borrower, development company, cross-collateralized credit facilities), or the property type requires specialized analysis (hospitality, healthcare, mixed-use development, special-purpose property). These files require committee review: a credit committee, a senior credit officer, or a designated review panel with the authority and expertise to evaluate the specific exception type. The AI routing function must identify this tier explicitly and send the file to the appropriate committee queue, not to the general underwriting queue.
Tier four: files requiring specialist routing. Files with characteristics that place them outside the standard credit underwriting function entirely, or that require specialist review before the credit decision can proceed. This tier includes: BSA/AML (Bank Secrecy Act/Anti-Money Laundering, the regulatory regime requiring financial institutions to maintain programs to detect, report, and prevent money laundering and other financial crimes) screening flags that require the file to be reviewed by the compliance department before credit review continues; fair-lending flags from the AI's pattern-detection layer; environmental or legal issues with the collateral; or unusual borrower structures (estate borrowers, trust borrowers, foreign nationals, bankruptcy dischargees) that require legal review before underwriting. These files are not simply complex credits: they have dimension that requires specialist expertise the underwriting team does not provide.
The routing taxonomy must be encoded in the LOS workflow: not as a static document, but as the logic that drives the queue-routing function. When the AI pre-scores a file and assigns it to a tier, the LOS routes the file to the appropriate queue automatically. The routing decision is logged, including the specific flags that determined the tier assignment, so the audit trail records why the file went to the reviewer it did.
Complex Credit Characteristics That Require Human Routing
Beyond the tier taxonomy, certain specific credit characteristics reliably indicate that a file requires human routing to a specialist or a higher authority, regardless of whether the pre-scoring model captures the characteristic in its policy-flag logic. Understanding these characteristics is part of the institutional knowledge that a well-designed routing protocol must encode.
Self-employment and non-traditional income structures. A borrower whose income derives from a pass-through business entity, multiple part-year employment arrangements, variable compensation (commissions, bonuses), or non-traditional sources (gig economy, rental income, cryptocurrency conversion) requires income analysis that most pre-scoring models cannot perform reliably. The pre-scoring model may see an adjusted gross income figure from the tax return and calculate a DTI, but the income available for qualifying under the institution's guidelines may differ substantially from the AGI figure, depending on the applicable income calculation method. Files with complex income structures should be routed to an underwriter with documented training and experience in non-traditional income analysis, not to the general queue.
Multi-entity and cross-collateralized credits. Commercial borrowers with multiple business entities, interlocking ownership structures, or cross-collateralized guaranty arrangements present analysis challenges that exceed the capabilities of a standard pre-scoring model. The global cash flow calculation for a borrower with ownership interests in three business entities, each with its own debt service obligations, requires the underwriter to consolidate financial statements across entities, eliminate intercompany transactions, and calculate the combined borrower's ability to service the requested debt alongside all existing obligations. An AI tool that evaluates the requesting entity in isolation may generate a pre-score that does not reflect the consolidated credit picture. These files require routing to a commercial credit analyst with experience in multi-entity credit analysis.
Development and construction lending. Loans to developers, contractors, and real estate investors undertaking construction or substantial rehabilitation require analysis that a standard pre-scoring model is not designed to perform: project feasibility, cost-to-complete estimation, absorption analysis for speculative development, and the borrower's track record of project execution. The DSCR at stabilized occupancy is a projection, not a verified figure, and the underwriter's judgment about the reasonableness of the projection is a substantive credit call that requires construction lending expertise.
Borrowers with recent adverse credit events. A borrower who has emerged from bankruptcy, completed a loan modification, or had a prior foreclosure within the lookback period defined by the institution's credit policy is not automatically disqualified in all cases: many credit policies permit loans to such borrowers after a specified seasoning period, with documented compensating factors. But the analysis of these files is more fact-intensive than a standard credit review. The pre-score may flag the adverse event as an exception trigger, but the underwriter reviewing the file needs the experience and authority to evaluate the specific circumstances of the adverse event, the borrower's post-event credit behavior, and the compensating factors present in the file. This is not junior-underwriter work.
Geographic and community context flags. A file involving a property in a majority-minority census tract, a historically underserved community, or an area the institution has designated as a Community Reinvestment Act (CRA, the federal statute encouraging depository institutions to meet the credit needs of the communities they serve, including low- and moderate-income communities) target area may warrant specialist routing on fair-lending grounds. This is not because such files are more complex in a credit sense, but because the institution's governance framework should include a quality-control review of lending decisions in these areas to confirm that the AI pipeline's outcomes in these geographies are consistent with outcomes in comparable non-protected-class geographies. Routing a sample of such files through a fair-lending review checkpoint is a proactive governance control, not a compliance burden.
The Fair-Lending Dimension of Routing Decisions
Routing decisions have a fair-lending dimension that institutions often underweight when designing their AI origination workflows. The routing protocol does not just affect efficiency: it affects who gets the benefit of human judgment, exception analysis, and the institution's full range of credit options. If the routing protocol, intentionally or through design flaws, directs files from protected-class borrowers to lower-authority reviewers, shorter review protocols, or faster-to-decline queues, the protocol itself can produce disparate impact even if every individual reviewer is acting in good faith.
This is the structural fair-lending risk in AI-assisted routing that OCC Bulletin 2026-13 addresses under its model-risk and fair-lending testing requirements. The bulletin requires that institutions test the outputs of their AI models, including routing decisions, for disparate impact across protected classes. For a routing model, this means testing whether protected-class borrowers are routed to exception queues at higher rates than similarly situated non-protected-class borrowers, whether protected-class borrowers in exception queues receive lower exception-grant rates than comparable non-protected-class borrowers, and whether the throughput and outcomes in the institution's AI pipeline differ systematically by geography (as a proxy for race or national origin in redlining analysis).
The less-discriminatory alternative standard that applies to disparate-impact findings is relevant to routing as well as to pre-scoring. If the institution's routing protocol produces a disparity, the institution must demonstrate that it explored less-discriminatory alternatives: routing designs that produce equal or better credit quality outcomes with less disparity in access to exception review and higher-authority decision-making. The documentation of this exploration is part of the institution's fair-lending compliance record under OCC 2026-13.
The practical governance control for routing disparities is periodic population-level analysis: at least quarterly, the institution's fair-lending or model-risk team should analyze the routing outcomes in the AI pipeline by borrower demographics (to the extent available and permissible under HMDA, the Home Mortgage Disclosure Act, which requires data collection on mortgage applications and lending patterns) and by geography. The analysis should ask: are there systematic patterns in which borrower or application characteristics predict routing to lower-authority or faster-to-decline queues, and do those patterns correlate with protected class? If yes, the routing protocol needs re-examination.
Documenting Routing Decisions in the LOS
A routing decision that is not documented is a routing decision that cannot be defended. The audit trail for the routing function must capture, for every file, the specific flags that triggered the tier assignment, the queue the file was routed to, the reviewer assigned, and the time between routing and review. This record is the foundation of the institution's ability to demonstrate, in an examination, that complex credits received appropriate human review and that the routing protocol was applied consistently.
The routing log in the LOS serves several governance functions. First, it enables the institution to confirm that all files were reviewed: no file should leave the pipeline without a routing record that shows it was assigned to a human reviewer and that the reviewer acted on it. A file that sits in a queue unreviewed is not a governance success, regardless of how well the AI classified it. Second, it enables the institution to monitor queue aging: if exception-queue files are waiting more than 48 hours for review, the institution may have a capacity problem in the exception-review function, which could be systematically affecting certain borrower or loan types. Third, it enables the population-level routing analysis described above: the routing log provides the data for the fair-lending testing of routing outcomes.
For each file in the exception queue, the routing documentation should include: the pre-score flags with their specific values (DSCR of 1.18, below the 1.20 standard threshold; credit score of 648, below the 660 guideline minimum; etc.); the tier assignment and the criteria that drove it; the reviewer assigned and their authority level for the applicable exception type; the exception analysis completed by the reviewer (compensating factors considered, exception authority cited, decision rationale); and the final decision with its documented reasons. This documentation is not just the audit trail for the individual file: it is the institutional record of how exception authority is exercised, which is a key input to the fair-lending analysis of whether exception-grant rates are consistent across borrower demographics.
The human reviewer who acts on an exception file owns the documentation. The AI's routing flags are inputs to the reviewer's analysis, not a substitute for it. When the exception is granted, the reviewer documents why the compensating factors support the exception under the credit policy. When the exception is denied, the reviewer documents the specific, accurate, ECOA-compliant adverse-action reasons, grounded in the file, that explain the denial. The pre-score's flags may inform those reasons, but the reasons belong to the human reviewer's analysis of the file.
Key Takeaways
- Routing is a governance function, not a convenience feature: the decision about which human reviews a file is as consequential as the review itself, because authority is not uniform across an underwriting team. An AI routing system that ignores lending authority limits does not improve governance; it removes it.
- A routing taxonomy with four tiers (standard approvals, minor exceptions, complex exceptions requiring committee review, and files requiring specialist routing) provides the structural framework for consistent, authority-appropriate routing. The taxonomy must be encoded in the LOS workflow, not just described in a policy document.
- Complex credit characteristics that reliably indicate human specialist routing include: self-employment and non-traditional income structures, multi-entity and cross-collateralized credits, development and construction lending, borrowers with recent adverse credit events, and geographic or community context flags relevant to fair-lending review.
- The fair-lending dimension of routing decisions is load-bearing: if the routing protocol directs protected-class borrowers to lower-authority reviewers, shorter review protocols, or faster-to-decline queues, the protocol itself can produce disparate impact even if every individual reviewer acts in good faith. OCC Bulletin 2026-13 requires that routing outcomes be tested for disparate impact as part of the model-risk testing framework.
- Periodic population-level routing analysis, at minimum quarterly, should assess whether routing outcomes differ systematically by borrower demographic or geography. The analysis should include exception routing rates, exception-grant rates by protected class, and throughput timing by loan type and geography. Disparities require documented investigation and a search for less-discriminatory alternatives.
- Routing documentation in the LOS must capture the specific flags that drove the tier assignment, the reviewer assigned, the exception analysis completed, and the final decision with reasons. This record enables the population-level fair-lending analysis and provides the audit trail for individual file challenges.
- The composite scenario that opens this lesson illustrates the specific failure mode: the AI routed correctly, but the routing protocol did not enforce the authority requirement for a complex commercial exception. The result was a denial by an underwriter without exception authority on a file a committee might have approved. Fair-lending exposure was created not by the AI, but by the gap between the routing design and the governance requirement it was supposed to enforce.
- Human judgment adds the most value in the exception and complex-credit review function, not in the clean-queue review function. The governance design should concentrate experienced underwriter capacity in the exception queue, where the combination of AI-surfaced signals and experienced human judgment produces the best outcomes for both credit quality and fair-lending compliance.
Skill.re