How Bank Examiners View AI Underwriting Tools
Published 2026-06-08. Updated 2026-09-30. A buyer-side guide from The LOS Directory.
Bank examiners do not treat AI underwriting as a separate regime with its own rulebook. They apply the frameworks already on the books: model risk management, third-party risk management, and the Equal Credit Opportunity Act and Regulation B. An AI tool that helps decide credit is a vendor relationship and a driver of adverse-action notices, and it may be a model under the agencies' model risk guidance, depending on how it is built and the size of the bank. The recurring theme across every one of them is that the bank, not the software vendor, owns the risk.
This guide is for credit officers, chief risk officers, compliance leaders, and the lending and technology buyers who have to defend a tool to an examiner. It walks through the guidance examiners actually reference, what they probe in an exam, and the concrete things to require from any AI underwriting vendor so the system stays examinable. It is buyer-side, not vendor marketing, and every regulatory reference is anchored to its primary source.
Model risk: what the 2026 guidance covers
The starting point is model risk management. The framework was set by SR 11-7, the "Supervisory Guidance on Model Risk Management" the Federal Reserve and OCC issued jointly in 2011. It defines a model broadly, as a quantitative method that turns input data into estimates, and it built the vocabulary examiners still use: independent validation, ongoing monitoring, governance, and the guiding principle of "effective challenge," meaning critical review by objective, informed parties who can find a model's limitations and force changes.
One currency point matters here. SR 11-7 predates modern machine learning and never uses the words "artificial intelligence," but because it is principles-based, supervisors applied it to AI and machine-learning models for years. On April 17, 2026 the Federal Reserve, OCC, and FDIC replaced SR 11-7 with revised interagency guidance, SR 26-2 and the parallel OCC Bulletin 2026-13, which sets out a risk-based approach tailored to each institution's model risk profile. The revision narrows the guidance in ways that matter for AI underwriting. It states that generative AI and agentic AI models are novel and rapidly evolving and are not within its scope. It is expected to be most relevant to banking organizations with more than $30 billion in total assets, though it may be relevant to smaller organizations with significant exposure to model risk. The OCC bulletin also states that the guidance does not set enforceable standards and that non-compliance "will not result in supervisory criticism against a banking organization." The OCC had already said in October 2025, in Bulletin 2025-26, that its model risk guidance does not require community banks to perform annual model validation. The agencies plan to issue a request for information on banks' use of AI, including generative and agentic AI.
For an AI underwriting tool, the coverage depends on the tool. A statistical or machine-learning credit-scoring model fits the guidance's definition of a model, and the guidance is expected to be most relevant when the bank is above $30 billion in assets. A generative AI tool that reads documents and drafts analysis is outside the guidance at a bank of any size, and the guidance is non-binding in every case. Examiners can still ask how the bank governs the tool under third-party risk management guidance, fair lending law, and general safety and soundness authority, and the model risk principles of documentation, independent validation, ongoing monitoring, and effective challenge remain a reasonable template for answering. A bank that can show documentation, testing, and a named internal owner for the tool is better placed than one that answers "the vendor handles that."
The vendor builds it; the bank owns it
Most community and regional banks will buy AI underwriting rather than build it, which pulls in the second framework: third-party risk. The agencies issued joint Interagency Guidance on Third-Party Relationships in June 2023, replacing the older OCC guidance from 2013. It sets expectations across the full life cycle of a vendor relationship: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination, with the depth of oversight scaled to how critical the activity is. On September 15, 2026 the OCC, Federal Reserve, FDIC, and NCUA published proposed third-party risk management guidance (91 FR 58536) that would replace the 2023 guidance once finalized. Comments are due November 16, 2026, and the 2023 guidance stays in effect in the meantime.
Credit underwriting is about as critical as a banking activity gets, so examiners expect serious diligence here. That means evaluating the vendor's model, its data practices, and its financial stability before signing, and monitoring performance after. It also means contract terms that preserve your ability to supervise: access to model documentation, the right to audit, defined performance expectations, and a clean exit. The guidance is explicit that outsourcing the activity does not outsource the responsibility. If a vendor cannot or will not give you what you need to validate and monitor its model, that is an examination problem waiting to happen, regardless of how good the demo looked.
Explainability is a fair-lending requirement
The third framework is the one that turns explainability from an engineering preference into a legal obligation. The Equal Credit Opportunity Act and Regulation B require a creditor to tell a declined applicant the specific principal reasons for the adverse action. Regulation B is explicit that a vague reason, such as a failure to reach a qualifying score, is not enough, and the notice generally has to go out within 30 days.
The CFPB applied this directly to AI in two circulars. Circular 2022-03 stated that the duty to give specific, accurate reasons holds even when a decision relies on complex algorithms. Circular 2023-03 addressed artificial intelligence by name and warned that creditors cannot pick the closest-sounding reason from the sample-form checklist if it does not reflect the real basis for the decision. The CFPB withdrew both circulars on May 12, 2025 (90 FR 20084), so they no longer state the Bureau's position. The requirement they interpreted remains in force. 12 CFR 1002.9(b)(2) requires that the statement of reasons be specific and indicate the principal reasons for the adverse action. The official commentary says the reasons disclosed must relate to and accurately describe the factors actually considered or scored, and Appendix C to Regulation B says a creditor does not satisfy the notice requirement by checking the closest identifiable factor on a sample form when that factor was not actually used. If your AI tool cannot produce the true, specific reason a borrower was declined, it cannot meet the adverse-action requirement, and an examiner will treat that as a finding. This is why source traceability and reason codes are not features to skip.
Fair lending: where it is solid, and where it is shifting
Fair lending is the area buyers ask about most, and it is also the area in flux, so it is worth being precise. Two things did not change. The prohibition on disparate treatment, declining or pricing a borrower differently because of a protected characteristic, is statutory and unchanged. And the adverse-action explainability duty above is unchanged. Those are durable ground to build controls on.
What changed is the disparate-impact, or "effects test," theory. The CFPB's final rule, published April 22, 2026 and effective July 21, 2026, provides that ECOA does not authorize disparate-impact liability and removed the effects test from Regulation B. A challenge to the rule, National Fair Housing Alliance v. CFPB, No. 1:26-cv-01820, is pending in the U.S. District Court for the District of Columbia (complaint). The rule is a meaningful shift from the prior posture, in which fair-lending reviews routinely tested models for disproportionate effects on protected classes. We track the moving regulatory dates on our regulatory calendar for LOS buyers. The buyer-side conclusion does not actually change much: you still want a tool whose decisions you can explain and test, because disparate-treatment exposure, reputational risk, and the practical need to defend a credit decision all remain. Build for explainability and documentation, and you are covered regardless of how the impact theory settles.
What examiners actually probe
There is no single AI rule to point to, which is exactly why examiners reach for the frameworks above. In practice, an exam touching an AI underwriting tool tends to ask the same set of questions:
- Model documentation. Is the model described well enough that an independent party could understand and challenge it?
- Validation and effective challenge. Has someone independent of the model's developers tested it, and is there a process to keep doing so?
- Explainability. Can the tool produce specific, accurate reasons for a decision, including a denial?
- Fair-lending controls. Are decisions documented and testable, and is disparate-treatment risk managed?
- Human oversight. Is a qualified underwriter making or confirming the credit decision, rather than the model auto-deciding unchecked?
- Vendor oversight. Did the bank perform due diligence, and can it monitor and audit the vendor's model?
- Audit trail and data lineage. Can every output be traced back to the inputs and source documents that produced it?
- Ongoing monitoring. Is performance tracked after deployment, with a trigger to revalidate when it drifts?
None of these are exotic. They are the standard model-risk and compliance questions, applied to a newer kind of model. For a generative AI tool, or at a bank under $30 billion in assets, they come from third-party risk management, fair lending, and safety and soundness reviews more than from the model risk guidance, which does not set enforceable standards. A tool that was built with them in mind is straightforward to defend. One that treats them as afterthoughts turns every exam into an argument.
What to require from an AI underwriting vendor
Translate the examiner's questions into procurement requirements, and the diligence gets concrete. Before you sign, require the following, and write the ones that belong in a contract into the contract:
- Model documentation you can hand to a validator. Enough detail on inputs, logic, and limitations for independent review.
- Specific, accurate adverse-action reasons. Proof the tool surfaces the true principal reason for a decline, not a generic label.
- A complete audit trail. Every figure, spread, and risk flag traceable to its source document and page, with overrides logged.
- Clarity on data. What data the model uses or was trained on, where it lives, and how it is secured.
- Fair-lending support. The ability to document and test decisions, and outputs that support your own monitoring.
- Human-in-the-loop by design. A workflow where an underwriter decides, and the system supports rather than replaces that judgment.
- Contractual access and audit rights. The right to documentation, validation support, performance reporting, and an exit, per third-party risk guidance.
This is also where AI-native tools that were designed around auditability have an advantage. Aloan, for instance, ties every number in a spread or credit memo back to the source document and page it came from and keeps an override history, which is the kind of traceable record an examiner is looking for, and it prepares analysis for a human underwriter rather than making the credit decision itself. That design is the bar to hold any vendor to, not a feature unique to one product. We compare the broader field on our best commercial loan underwriting software guide.
The bottom line for buyers
Examiners are not hostile to AI in underwriting, and there is no rule that forbids it. What they look for is a bank that governs an AI tool with the discipline it applies to anything that touches credit: documented, tested, explainable, monitored, overseen at the vendor level, and fully auditable. The 2026 model risk guidance does not require that of a generative AI tool, and third-party risk, fair lending, and safety and soundness reviews still reach it. The institutions that will have the easiest exams are the ones that made those requirements part of the buying decision instead of discovering them afterward. For the wider view of how AI is moving into the community-bank credit shop, see our 2026 community bank technology trends guide and our overview of LOS platforms for community banks.
Frequently asked questions
How do bank examiners view AI underwriting tools?
They apply existing frameworks: third-party risk management, the Equal Credit Opportunity Act and Regulation B, and model risk management where it applies. The revised interagency model risk guidance issued April 17, 2026 (SR 26-2 and OCC Bulletin 2026-13) places generative and agentic AI outside its scope and is expected to be most relevant to banking organizations with more than $30 billion in total assets, so it does not by its terms require validation of a generative AI underwriting tool at a community bank. Examiners can still ask how the bank governs the tool, how it oversees the vendor, how it manages fair-lending risk, and how it produces specific adverse-action reasons. An audit trail that traces every output to its inputs answers most of those questions. The bank remains responsible for the activity when a vendor builds the tool.
Is SR 11-7 still the model risk guidance for AI?
No. SR 11-7, from 2011, defined the model risk vocabulary examiners still use, including effective challenge and independent validation. On April 17, 2026 the Federal Reserve, OCC, and FDIC replaced it with revised interagency guidance, SR 26-2 and OCC Bulletin 2026-13, which sets out a risk-based approach tailored to each institution's model risk profile. The revised guidance states that generative AI and agentic AI are not within its scope, is expected to be most relevant to banking organizations with more than $30 billion in total assets, and does not set enforceable standards. The core concepts carry forward as principles, so cite the current guidance and check whether it covers the tool you are evaluating.
What does Regulation B require when underwriting uses AI?
It requires the creditor to give the specific principal reasons for an adverse action. Under 12 CFR 1002.9(b)(2) and Regulation B's official commentary, the reasons disclosed must relate to and accurately describe the factors actually considered or scored, and a creditor does not satisfy the requirement by checking the closest factor on a sample form if that factor was not actually used. The regulation makes no exception for decisions that rely on complex algorithms or artificial intelligence. The CFPB said so directly in Circulars 2022-03 and 2023-03, which it withdrew on May 12, 2025; the regulation and commentary they interpreted are unchanged. Explainability is a compliance requirement.
What should a bank require from an AI underwriting vendor?
Model documentation a validator can use, evidence supporting specific adverse-action reasons, a complete audit trail to source documents, clarity on the data, fair-lending testing support, a human-in-the-loop workflow, and contract terms granting access and audit rights. Under third-party risk guidance the bank stays responsible for the model even when a vendor builds it, so the system has to remain examinable.
Sources: Federal Reserve SR 11-7 (superseded) and SR 26-2 (Revised Guidance on Model Risk Management, April 17, 2026); OCC Bulletins 2026-13 and 2025-26; Interagency Guidance on Third-Party Relationships: Risk Management (June 2023); Proposed Third-Party Risk Management Guidance (91 FR 58536, September 15, 2026); 12 CFR 1002.9 (Regulation B) and its official commentary; CFPB Circulars 2022-03 and 2023-03 on adverse-action requirements and complex algorithms (withdrawn May 12, 2025, 90 FR 20084); CFPB final rule amending Regulation B (91 FR 21620, effective July 21, 2026); FFIEC. This guide is general information for buyers, not legal advice. The LOS Directory is a buyer-side research site and does not sell loan origination software.