Summary: Lenders adopting AI in underwriting hear one question from auditors, LPs and examiners: how did this number get here? The answer is an audit trail with three layers: the values, the policy tests and the decision. This post sets out what each layer should contain, what the rules require, and how the April 2026 change in model risk guidance shifts the burden onto the lender’s own standards. The loan underwriting page has the buyer’s checklist.
Layer one: every value
For each extracted value, the trail should hold the source document, the page and position it came from, the confidence of the extraction, and any edit a person made afterward, with who and when.
The test is whether someone who was not in the room can follow it. An auditor should be able to start from a figure in the committee memo and click back to the borrower document it came from, without asking the analyst to rebuild the spreadsheet.
Amended submissions belong here too. When a borrower restates financials, the original and the restatement should both be kept, with the differences and their effect on the ratios shown.
Layer two: every policy test
For each rule the system applied: the rule as written, its version, the inputs it used and the result. When a lender changes its credit policy, every decision made before the change should still tie to the version that was in force.
The OCC’s July 2026 Lending and Loan Portfolio Risk Management booklet addresses automated retail decisions in exactly these terms: “Decision criteria for auto approvals and manual reviews should adhere to the bank’s written guidelines,” and “a clear audit trail should document the approval process.”
Layer three: the decision
Exceptions and their approvals, the approver, and timestamps throughout. If a person overrode a rule, the trail shows the override and the reason.
This layer is what Regulation B depends on. A creditor that takes adverse action owes the applicant “A statement of specific reasons for the action taken,” and must retain application records “For 25 months (12 months for business credit” with limited exceptions. A system that cannot say why it reached a result cannot meet the first requirement.
What changed in April 2026
For fifteen years the reference for documenting decision tools was the 2011 model risk guidance. In April 2026 the agencies replaced it. The OCC’s bulletin says “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” The new guidance also excludes “deterministic rule-based processes” from its definition of a model.
Two consequences follow. A lender cannot point to model risk guidance as its checklist for an AI underwriting tool. And a tool built on deterministic policy checks sits under the ordinary controls for policies, change management and records, which are older and better understood. Until regulators say more, lenders set their own bar. NIST’s AI Risk Management Framework offers a useful one: “Explainable systems can be debugged and monitored more easily, and they lend themselves to more thorough documentation, audit, and governance.”
What to ask a vendor
Six questions, all answerable on a demo with one of your own files:
- Click a number in the memo. Does it open the page it came from?
- Which values were low confidence, and who confirmed them?
- Show the credit policy as text a credit officer can read. Which version applied to this file?
- Replay the file from raw documents to memo, in order, with timestamps.
- The borrower restated. Where are both versions?
- Export the trail for an auditor.
On the MightyBot platform each of those is a feature of the record rather than a report someone assembles later. The full checklist and the comparison of approaches are on the loan underwriting page.