How Bank Examiners View AI Underwriting Tools
Published 2026-06-08. A buyer-side guide from The LOS Directory.
Bank examiners do not treat AI underwriting as a separate regime with its own rulebook. They apply the frameworks already on the books: model risk management, third-party risk management, and the Equal Credit Opportunity Act and Regulation B. An AI tool that helps decide credit is a model, a vendor relationship, and a driver of adverse-action notices all at once, so it inherits all three sets of expectations. The recurring theme across every one of them is that the bank, not the software vendor, owns the risk.
This guide is for credit officers, chief risk officers, compliance leaders, and the lending and technology buyers who have to defend a tool to an examiner. It walks through the guidance examiners actually reference, what they probe in an exam, and the concrete things to require from any AI underwriting vendor so the system stays examinable. It is buyer-side, not vendor marketing, and every regulatory reference is anchored to its primary source.
An AI tool is a model: start with model risk
The foundational lens is model risk management. The framework was set by SR 11-7, the "Supervisory Guidance on Model Risk Management" the Federal Reserve and OCC issued jointly in 2011. It defines a model broadly, as a quantitative method that turns input data into estimates, and it built the vocabulary examiners still use: independent validation, ongoing monitoring, governance, and the guiding principle of "effective challenge," meaning critical review by objective, informed parties who can find a model's limitations and force changes.
One currency point matters here. SR 11-7 predates modern machine learning and never uses the words "artificial intelligence," but because it is principles-based, supervisors have applied it to AI and machine-learning models for years. In April 2026 the agencies replaced SR 11-7 with revised interagency guidance, SR 26-2 and the parallel OCC Bulletin 2026-13, which emphasizes a risk-based approach tailored to each institution's model risk profile. The core concepts carry straight through, and the OCC had already signaled, in an October 2025 bulletin, that model risk management for community banks should be scaled to their risk profile rather than applied as a one-size template. The practical takeaway: a bank that built its program on SR 11-7 principles is on solid ground, but it should cite the current guidance and confirm its framework reflects the 2026 revision.
For an AI underwriting tool, this means an examiner expects to see the model documented, independently validated, and monitored over time, with someone inside the bank competent to challenge it. "The vendor handles that" is not an answer the framework accepts.
The vendor builds it; the bank owns it
Most community and regional banks will buy AI underwriting rather than build it, which pulls in the second framework: third-party risk. The agencies issued joint Interagency Guidance on Third-Party Relationships in June 2023, replacing the older OCC guidance from 2013. It sets expectations across the full life cycle of a vendor relationship: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination, with the depth of oversight scaled to how critical the activity is.
Credit underwriting is about as critical as a banking activity gets, so examiners expect serious diligence here. That means evaluating the vendor's model, its data practices, and its financial stability before signing, and monitoring performance after. It also means contract terms that preserve your ability to supervise: access to model documentation, the right to audit, defined performance expectations, and a clean exit. The guidance is explicit that outsourcing the activity does not outsource the responsibility. If a vendor cannot or will not give you what you need to validate and monitor its model, that is an examination problem waiting to happen, regardless of how good the demo looked.
Explainability is a fair-lending requirement
The third framework is the one that turns explainability from an engineering preference into a legal obligation. The Equal Credit Opportunity Act and Regulation B require a creditor to tell a declined applicant the specific principal reasons for the adverse action. Regulation B is explicit that a vague reason, such as a failure to reach a qualifying score, is not enough, and the notice generally has to go out within 30 days.
The CFPB has applied this directly to AI. In a 2022 circular, it stated that the duty to give specific, accurate reasons holds even when a decision relies on complex algorithms, and that creditors may not use models so opaque they cannot identify the actual reasons for a denial. A 2023 circular went further, addressing artificial intelligence by name and warning that creditors cannot simply pick the closest-sounding reason from the sample-form checklist if it does not reflect the real basis for the decision. Read together, these mean a "black box" is not a defense. If your AI tool cannot produce the true, specific reason a borrower was declined, it cannot meet the adverse-action requirement, and an examiner will treat that as a finding. This is why source traceability and reason codes are not features to skip.
Fair lending: where it is solid, and where it is shifting
Fair lending is the area buyers ask about most, and it is also the area in flux, so it is worth being precise. Two things are not changing. The prohibition on disparate treatment, declining or pricing a borrower differently because of a protected characteristic, is statutory and unchanged. And the adverse-action explainability duty above is unchanged. Those are durable ground to build controls on.
What is changing is the disparate-impact, or "effects test," theory. The CFPB finalized a rule in April 2026, effective July 21, 2026, that removes the disparate-impact effects test from Regulation B. That is a meaningful shift from the prior posture, in which fair-lending reviews routinely tested models for disproportionate effects on protected classes. We track the moving regulatory dates on our regulatory calendar for LOS buyers. The buyer-side conclusion does not actually change much: you still want a tool whose decisions you can explain and test, because disparate-treatment exposure, reputational risk, and the practical need to defend a credit decision all remain. Build for explainability and documentation, and you are covered regardless of how the impact theory settles.
What examiners actually probe
There is no single AI rule to point to, which is exactly why examiners reach for the frameworks above. In practice, an exam touching an AI underwriting tool tends to ask the same set of questions:
- Model documentation. Is the model described well enough that an independent party could understand and challenge it?
- Validation and effective challenge. Has someone independent of the model's developers tested it, and is there a process to keep doing so?
- Explainability. Can the tool produce specific, accurate reasons for a decision, including a denial?
- Fair-lending controls. Are decisions documented and testable, and is disparate-treatment risk managed?
- Human oversight. Is a qualified underwriter making or confirming the credit decision, rather than the model auto-deciding unchecked?
- Vendor oversight. Did the bank perform due diligence, and can it monitor and audit the vendor's model?
- Audit trail and data lineage. Can every output be traced back to the inputs and source documents that produced it?
- Ongoing monitoring. Is performance tracked after deployment, with a trigger to revalidate when it drifts?
None of these are exotic. They are the standard model-risk and compliance questions, applied to a newer kind of model. A tool that was built with them in mind is straightforward to defend. One that treats them as afterthoughts turns every exam into an argument.
What to require from an AI underwriting vendor
Translate the examiner's questions into procurement requirements, and the diligence gets concrete. Before you sign, require the following, and write the ones that belong in a contract into the contract:
- Model documentation you can hand to a validator. Enough detail on inputs, logic, and limitations for independent review.
- Specific, accurate adverse-action reasons. Proof the tool surfaces the true principal reason for a decline, not a generic label.
- A complete audit trail. Every figure, spread, and risk flag traceable to its source document and page, with overrides logged.
- Clarity on data. What data the model uses or was trained on, where it lives, and how it is secured.
- Fair-lending support. The ability to document and test decisions, and outputs that support your own monitoring.
- Human-in-the-loop by design. A workflow where an underwriter decides, and the system supports rather than replaces that judgment.
- Contractual access and audit rights. The right to documentation, validation support, performance reporting, and an exit, per third-party risk guidance.
This is also where AI-native tools that were designed around auditability have an advantage. Aloan, for instance, ties every number in a spread or credit memo back to the source document and page it came from and keeps an override history, which is the kind of traceable record an examiner is looking for, and it prepares analysis for a human underwriter rather than making the credit decision itself. That design is the bar to hold any vendor to, not a feature unique to one product. We compare the broader field on our best commercial loan underwriting software guide.
The bottom line for buyers
Examiners are not hostile to AI in underwriting, and there is no rule that forbids it. What they expect is that a bank can govern an AI model the same way it governs any model that touches credit: documented, validated, explainable, monitored, overseen at the vendor level, and fully auditable. The institutions that will have the easiest exams are the ones that made those requirements part of the buying decision instead of discovering them afterward. For the wider view of how AI is moving into the community-bank credit shop, see our 2026 community bank technology trends guide and our overview of LOS platforms for community banks.
Frequently asked questions
How do bank examiners view AI underwriting tools?
They apply the existing frameworks rather than a new one: model risk management, third-party risk management, and the Equal Credit Opportunity Act and Regulation B. An AI underwriting tool is a model, so examiners expect documentation, independent validation, ongoing monitoring, and effective challenge. Because it drives credit decisions, they also expect specific adverse-action reasons, fair-lending controls, human oversight, vendor due diligence, and an audit trail. The bank, not the vendor, owns the model risk.
Is SR 11-7 still the model risk guidance for AI?
SR 11-7, from 2011, defined the model risk vocabulary examiners still use, including effective challenge and independent validation. In April 2026 the agencies replaced it with revised interagency guidance, SR 26-2 and OCC Bulletin 2026-13, emphasizing a risk-based approach tailored to each institution's model risk profile. The core concepts carry forward, so cite the current guidance and confirm your framework reflects the 2026 revision.
What does Regulation B require when underwriting uses AI?
It requires the creditor to give the specific principal reasons for an adverse action. The CFPB has stated in two circulars that this applies fully when decisions rely on complex algorithms or artificial intelligence. A creditor may not use a model so opaque it cannot produce specific, accurate reasons, and may not fall back on vague checklist reasons. Explainability is a compliance requirement, not optional.
What should a bank require from an AI underwriting vendor?
Model documentation a validator can use, evidence supporting specific adverse-action reasons, a complete audit trail to source documents, clarity on the data, fair-lending testing support, a human-in-the-loop workflow, and contract terms granting access and audit rights. Under third-party risk guidance the bank stays responsible for the model even when a vendor builds it, so the system has to remain examinable.
Sources: Federal Reserve SR 11-7 and SR 26-2 (Revised Guidance on Model Risk Management, April 2026); OCC Bulletins 2026-13 and 2025-26; Interagency Guidance on Third-Party Relationships: Risk Management (June 2023); 12 CFR 1002.9 (Regulation B); CFPB Circulars 2022-03 and 2023-03 on adverse-action requirements and complex algorithms; CFPB final rule amending Regulation B (effective July 21, 2026); FFIEC. This guide is general information for buyers, not legal advice. The LOS Directory is a buyer-side research site and does not sell loan origination software.