โ†
AI for Banking & Lending
Visionary ยท M9 ยท lesson 9 of 16 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Redesigning Lending and Risk Around AI
๐Ÿ“–
now learning

Redesigning Lending and Risk Around AI

15 min

The following scenario is a composite illustration. When a mid-sized community bank redesigned its mortgage underwriting process in 2025, the chief lending officer expected the biggest argument to be about the AI vendor's credit model. It was not. The fiercest debate was about the org chart. Two senior underwriters had spent two decades building credit expertise, evaluating complex files, navigating exception requests, and mentoring junior staff. The question was not whether they would keep their jobs. It was whether their jobs would still be interesting. The operating model redesign that gave AI the standard applications and gave the underwriters the complex credits, the exceptions, and the judgment calls did not reduce the headcount. It transformed the nature of the work, and in doing so revealed the fundamental design principle for an AI-enabled lending and risk organization: AI handles throughput; humans handle judgment.

This lesson is about how to execute that redesign in practice, across the full arc of lending and risk operations. The principle is simple. The execution requires rethinking every process from origination through portfolio management, identifying precisely where AI has a genuine advantage and where human judgment is legally required, legally superior, or both. It requires new decision boundaries, new oversight mechanisms, new escalation paths, and new accountability structures. And it requires a change management approach that brings the people who know the business along, because an operating model designed without their input will fail in the details that only practitioners understand.

OCC Bulletin 2026-13, the April 2026 interagency guidance issued jointly by the OCC, the Federal Reserve, and the FDIC that superseded OCC 2011-12 and pulled AI and GenAI under model-risk management (MRM), fair-lending, and board governance expectations, provides the governance frame. The bank that uses this redesign to create a faster, more consistent process, while also creating a more defensible adverse-action trail, a more rigorous disparate-impact testing program, and a stronger model-risk record, wins on both the business and the compliance axis simultaneously. That dual win is available only if the operating model is designed for it.

The Design Principle: AI on Throughput, Humans on Judgment

The design principle is not "AI replaces humans where it can." That framing leads to cost-reduction plans that gut the staff needed for oversight, exception handling, and relationship lending. The design principle is "AI handles the work that benefits from speed, consistency, and scale; humans handle the work that requires judgment, accountability, or legal authority."

In lending, the distinction between AI-appropriate work and judgment-required work follows a recognizable pattern. AI-appropriate work includes: extracting structured data from unstructured documents (income verification from tax returns and paystubs, asset verification from bank statements); applying pre-defined credit-policy rules to structured application data to produce a pre-score or a recommendation; flagging applications that require additional review based on criteria defined in the credit policy; generating drafts of credit memos, adverse-action notices, and borrower communications that follow defined templates and compliant language patterns; and monitoring a portfolio of existing loans for early warning indicators based on data that can be quantified and compared against thresholds.

Judgment-required work includes: any decision that requires weighing facts that do not fit neatly into the credit policy's categories, which includes most exceptions and most complex credits; any adverse-action decision, because the Equal Credit Opportunity Act (ECOA, the federal statute prohibiting discrimination in any aspect of a credit transaction) and Regulation B (Reg B, the CFPB's implementing regulation for ECOA at 12 CFR Part 1002 that governs adverse-action notice requirements) make the specific reasons for a denial the legal accountability of the signing institution, not an automated output; any borrower conversation that involves a dispute, a complaint, or a nuanced explanation of a credit decision; and any override of an AI recommendation, which by definition requires a human to exercise independent judgment that the AI signal is not dispositive in this specific file.

The operational consequence of this design principle is that the division of labor in the lending workflow changes structurally. AI handles the intake, the document extraction, the pre-scoring, and the initial drafting. Humans handle the decision, the verification of AI outputs before relying on them, the exception analysis, and the borrower relationship. The volume each human can handle increases substantially, because the AI has eliminated the routine work that used to occupy most of their time. The nature of the human work shifts toward judgment and relationship, which is where experienced lenders add the most value and where the legal accountability is concentrated.

AI handles throughput and consistency; humans handle judgment and accountability; designing the line between them is the core operating-model decision for every AI-enabled lending and risk function.

Redesigning Origination and Underwriting

Origination is where the volume pressure is highest and where AI has the most immediate efficiency impact. In a bank without AI-assisted origination, each new application requires a loan officer or processor to manually request documents, chase the applicant for missing items, extract income and asset figures from the documents, run the figures through the LOS (loan origination system), and produce an initial assessment. With AI-assisted origination, the document extraction, data structuring, and initial credit-policy screening can happen within minutes of application, leaving the human responsible for verification, relationship management, and judgment on non-routine cases.

The redesigned origination workflow has five stages, each with a defined division of responsibility. First, AI-assisted intake and document extraction: the applicant submits the application and documents. AI extracts the structured data fields (income, assets, liabilities, employment history) and populates the LOS. The human's role at this stage is verification, not extraction: confirming that the AI-extracted figures match the source documents, flagging discrepancies for investigation, and confirming that the document set is complete. The verification step is not optional. It is the governance control that prevents an AI extraction error from propagating into the credit decision.

Second, AI pre-scoring: the LOS runs the AI pre-score against the verified data. The pre-score produces a signal (proceed to standard underwriting, proceed with conditions, refer to senior underwriting, decline) and, if the signal is decline or refer, a list of the factors that drove the signal. The human does not treat the pre-score as a decision. The human treats it as a structured input to their independent analysis. When the pre-score says decline, the underwriter's job is to verify that the factors cited are accurate, assess whether there are compensating factors the model did not capture, and make their own credit judgment, which may or may not align with the pre-score.

Third, human underwriting decision: the underwriter makes the credit decision, using the AI pre-score and the verified document data as inputs, alongside their own judgment about factors the model does not capture. The credit decision and the documentation of the reasoning behind it belong to the underwriter. If the decision is a denial, the adverse-action reason codes are the underwriter's responsibility: they must be specific, accurate, grounded in the actual file data, and reviewed against the AI-suggested reasons to confirm alignment before the notice is issued. The underwriter may use AI to draft the adverse-action notice, but the verification of each reason code is a human accountability that cannot be delegated to the AI output.

Fourth, exception handling: files that do not fit the standard credit policy are referred to senior underwriting, where the most experienced underwriters handle the cases that require genuine judgment. This is where the redesigned operating model concentrates experienced human talent. Standard files, which in most consumer mortgage shops represent 60 to 80 percent of volume, run through AI-assisted stages one through three with relatively limited senior human involvement. Complex files, exceptions, and unusual circumstances require senior judgment, and the redesigned workflow ensures that senior underwriters spend their time on those files rather than on standard application processing that AI handles more consistently.

Fifth, quality and oversight: the Model-Risk-AI Lead's team and the Fair-Lending-AI Lead's team conduct regular sample reviews of AI-assisted origination decisions, checking that the verification step was performed, that the adverse-action reasons are accurate, and that there are no patterns in the AI-assisted decisions that suggest a fair-lending problem. These reviews are governance controls, not quality-control audits in the traditional sense. They are the institutional mechanism for confirming that the operating model is producing the defensible, explainable outcomes that OCC Bulletin 2026-13 requires.

The staffing model for AI-assisted origination typically involves a reduction in the number of processors (whose primary function was document extraction and data entry, work the AI now handles) and a concentration of experienced underwriter talent in the exception and complex-credit functions. Loan officer roles are generally retained or expanded, because AI-assisted origination increases the volume each loan officer can manage without reducing the relationship and judgment work that loan officers perform. Early deployments of AI-assisted origination in 2024 and 2025 suggested that total mortgage volume per loan officer could increase substantially while loan officer headcount remained approximately flat; illustrative productivity gains of 30 to 60 percent have been cited in industry case studies, which is consistent with the broader finding that 38 percent of mortgage lenders used AI and ML in 2024 without significantly reducing their front-line workforce.

Redesigning Risk Management and Model Governance

The risk management function has a dual challenge in the AI-enabled bank. It needs to operate AI-assisted risk monitoring tools (portfolio monitoring, stress testing, concentration analysis) while simultaneously governing the AI models used across the institution. These two functions can conflict: the same risk team that benefits from AI's portfolio-monitoring capabilities must also provide independent oversight of the AI models that produce those benefits. The redesigned risk function addresses this conflict by separating the risk operations function, which uses AI tools in its daily work, from the model-risk governance function, which provides independent oversight of those same tools.

In the risk operations function, AI handles the throughput work: scanning the portfolio for early warning signals, aggregating data from the LOS and the core system for concentration and exposure analysis, generating the standard risk reports that the risk committee and the board receive on a regular cadence, and monitoring covenant compliance and collateral values for commercial credits. Human risk managers spend their time on the judgment work: interpreting the AI's portfolio signals in the context of market conditions and relationship knowledge, deciding which signals warrant an active management response, presenting the risk committee with a synthesized view that reflects both the AI's quantitative findings and the human judgment that puts those findings in business context, and managing the exceptions and workouts that require negotiation and relationship management.

In the model-risk governance function, the key redesign is the expansion of model oversight responsibility to cover AI models with the same rigor previously applied to statistical scoring models. The model inventory must include every AI tool used in lending and risk operations, with documentation of inputs, outputs, validation status, and risk tier. The validation program must include the explainability testing, stability testing, and fair-lending testing that AI models require in addition to the predictive-performance testing that traditional model validation covered. The vendor oversight function must include the technical due diligence and contract review that the Model-Risk-AI Lead performs before any third-party AI model is allowed into production.

The critical governance rule for both functions is that the AI's outputs are inputs to human decisions, not substitutes for them. A portfolio monitoring AI that flags a commercial credit for deteriorating cash flow metrics has performed its function correctly when it surfaces the flag; the credit officer who reviews that flag, talks to the borrower, assesses whether the metrics reflect a temporary disruption or a structural deterioration, and recommends a management response is performing a judgment function that the AI cannot perform and should not attempt. The redesigned workflow makes this division explicit, documented, and reviewable: the AI flag is logged, the human review is logged, the human decision is logged, and the model-risk program monitors whether the human review is actually happening or whether staff have begun treating AI flags as self-executing decisions.

Redesigning Fair-Lending and Compliance Operations

Fair-lending and compliance operations face the most complex redesign challenge, because AI changes both the nature of the compliance risk and the tools available for managing it. The compliance function that responds to AI by treating it as a risk to be minimized from a distance will be outpaced by the examiner who understands AI better than the institution's compliance team does. The compliance function that learns to use AI as a tool for compliance operations, while governing it rigorously, positions the institution for a stronger regulatory posture than the pre-AI bank ever achieved.

On the risk side, AI-assisted lending creates two categories of new fair-lending risk that the compliance operating model must address. The first is proxy variable risk: AI models can produce disparate impact on protected classes through features that are correlated with protected characteristics rather than directly incorporating them. Geographic features, purchasing pattern features, and behavioral features that correlate with race, national origin, or sex can produce disparate outcomes even when the model designer intended no discrimination. The Fair-Lending-AI Lead's disparate-impact testing program is the detection mechanism for this risk, but the compliance operating model must also ensure that loan officers, underwriters, and risk managers can recognize and escalate potential proxy variable patterns at the file level, before systematic monitoring would catch them.

The second category is adverse-action quality risk: when AI contributes to a denial, the adverse-action notice must cite specific, accurate reasons that reflect the actual basis for the decision. A reason code that reflects the AI model's output rather than the specific file-level facts is a Regulation B deficiency. The compliance operating model must include a regular adverse-action quality review that samples AI-assisted denial files and confirms that the reason codes are accurate, specific, and grounded in the applicant's actual data. When the quality review identifies a pattern of deficient reason codes, the remediation path runs through the training program (if the problem is that underwriters are not verifying AI-suggested reasons) or through the model governance program (if the problem is that the AI is generating reasons that are systematically inaccurate).

On the opportunity side, AI-assisted compliance operations can give the compliance function capabilities it never had in the pre-AI bank. Fair-lending testing that previously required a dedicated analyst several weeks of statistical work can now be performed on a quarterly basis with much less analyst time. Adverse-action quality reviews that previously required manual file pulls and hand scoring can now use AI to perform an initial review that flags potential quality problems for analyst attention. Compliance staff can use AI to track regulatory guidance changes, draft comment letters, and monitor for patterns in examination findings across the industry, so the bank's compliance posture is informed by the full landscape of regulatory expectations rather than just the findings in its own examination history.

The compliance operating model redesign must address one structural tension: compliance staff who use AI tools in their own work have an inherent interest in validating those tools as adequate. The independence principle that makes model-risk governance effective (the validators who assess model quality are independent from the business lines that use the models) applies to compliance tools as well. The compliance team that relies on AI to perform adverse-action quality reviews should not be the same team that validates the AI's review methodology. The Model-Risk-AI Lead's validation authority should extend to AI tools used in compliance operations, with the same rigor applied to AI underwriting models.

The Change Management Challenge

No operating model redesign survives first contact with the organization if the people who need to execute it were not part of designing it. The underwriters who have built careers on manual credit analysis, the compliance officers who have built expertise in review methodologies developed over decades, and the risk managers who have built knowledge of the portfolio through years of relationship management all have legitimate concerns about a redesign that changes the nature of their work. Those concerns are worth taking seriously, not because change should be deferred, but because the practitioners who raise them often identify design flaws that would have undermined the redesign if left unaddressed.

The change management approach for an AI operating model redesign has three components. The first is early and genuine involvement of front-line practitioners in the design process. The underwriters who will execute the new workflow should be on the design team, not as consultants who are asked to validate a completed design, but as designers who define the verification checkpoints, the escalation criteria, and the exception handling process based on their knowledge of what actually goes wrong in complex files. The designs that practitioners build tend to be more robust than the designs built by project managers or consultants who have not underwritten a mortgage or reviewed a fair-lending file.

The second component is clear communication about what the redesign means for roles and careers. The framing that resonates with experienced lenders is not "AI is making your job simpler." That framing implies deskilling and is often received as condescension. The framing that resonates is "AI is taking the routine extraction and screening work off your desk so you can spend your time on the files that actually need your expertise." This framing is accurate: in an AI-assisted origination model, the experienced underwriter's time is almost entirely occupied by complex credits, exceptions, and relationship management, which are the parts of the job that require and reward genuine expertise. Making this concrete, by showing practitioners the specific queue of files they would no longer need to touch and the specific queue of exceptions they would now handle more thoroughly, is more convincing than any abstract promise about job security.

The third component is a training and capability-building program that runs concurrently with the operating model redesign. Practitioners who feel equipped to work effectively with AI tools are far more likely to become genuine adopters than practitioners who feel that AI has been imposed on them without adequate preparation. The certification program described in the broader level-five curriculum provides the governance framework; the training program for the specific AI tools in use at the institution provides the workflow-level competency. Both are necessary, and both need to be in place before the new operating model goes live, not rolled out afterward as a remediation for adoption problems that were predictable from the start.

Measuring Whether the Redesign Is Working

An operating model redesign produces measurable outcomes. Measuring the right outcomes confirms that the redesign is achieving its goals and creates the evidence base for board reporting, examiner inquiries, and internal continuous improvement. The wrong outcomes, or the right outcomes measured incorrectly, can mask problems that will surface in an examination or a fair-lending audit.

On the business side, the metrics that indicate the redesign is working include: origination volume per loan officer (should increase as AI handles document extraction and initial screening); cycle time from application to decision (should decrease as AI accelerates the pre-screening and documentation stages); exception rate (should stabilize or decrease as AI-assisted pre-screening flags non-standard files earlier, allowing earlier human engagement); and customer satisfaction with the application process (should improve as faster decisions and cleaner communications reduce friction).

On the compliance side, the metrics that indicate the redesign is working include: adverse-action quality score from the monthly sample review (should improve as underwriters develop consistent verification habits and the AI-suggested reason codes align more reliably with file-level facts); disparate-impact testing results by demographic group (should remain within acceptable thresholds, with documented LDA searches when disparities are identified); override rate and pattern (should reflect genuine independent underwriter judgment, neither zero (which suggests underwriters are rubber-stamping AI signals) nor anomalously high (which may suggest the model is unreliable or underwriters were not trained to interpret it)); and escalation utilization and quality (should reflect a functioning escalation path where staff escalate identifiable concerns with specific documentation).

On the governance side, the metrics that confirm the redesign is sustainable include: model inventory currency (all AI models in production have current validation records); validation backlog (the queue of models awaiting validation does not exceed the team's capacity to clear it within a defined timeframe); vendor contract compliance (all vendor contracts include the audit rights and model-information access that OCC Bulletin 2026-13 governance requires); and board reporting quality (the AI governance report presented to the risk committee is substantive enough to support genuine board oversight, not just a summary that confirms nothing went wrong).

Key Takeaways

  • The fundamental operating-model design principle for AI-enabled lending and risk is that AI handles throughput and consistency while humans handle judgment and legal accountability, and the division of responsibility at each stage of every workflow must be explicit, documented, and monitored.
  • Redesigned origination has five stages: AI-assisted intake and extraction, AI pre-scoring, human underwriting decision, exception handling by senior underwriters, and quality and oversight reviews; the verification step at each AI-assisted stage is a governance control, not a quality check.
  • Adverse-action accountability under ECOA and Reg B stays with the signing human at every stage of the redesigned workflow; the AI may suggest reason codes but the underwriter must verify each code against the actual file data before the notice is issued.
  • Risk management redesign separates AI-assisted risk operations (portfolio monitoring, standard reporting) from model-risk governance (independent validation oversight), maintaining the independence principle that makes governance credible to regulators.
  • Fair-lending and compliance redesign addresses both new AI-created risks (proxy variable disparate impact, adverse-action quality degradation) and new AI-enabled compliance capabilities (automated testing, pattern detection, regulatory tracking), with validation independence maintained across compliance tools as well as business tools.
  • Change management requires early and genuine involvement of front-line practitioners in the operating model design, clear communication that frames AI as concentrating human expertise on high-judgment work rather than replacing expertise, and training that runs concurrently with the redesign rather than being remediated afterward.
  • The redesign produces measurable outcomes across three dimensions: business (volume per officer, cycle time, exception rate), compliance (adverse-action quality, disparate-impact testing results, override rate pattern), and governance (model inventory currency, validation backlog, board reporting quality).