← Blog
lendingunderwritingcompliancehow-to

What an Audit Trail for AI-Extracted Loan Data Should Contain

The three layers of an audit trail for AI in loan underwriting: value-level sources and confidence, policy tests with versions, and decisions with approvals. What Regulation B, the OCC and NIST expect, and what changed in April 2026.

MightyBot ·

Summary: Lenders adopting AI in underwriting hear one question from auditors, LPs and examiners: how did this number get here? The answer is an audit trail with three layers: the values, the policy tests and the decision. This post sets out what each layer should contain, what the rules require, and how the April 2026 change in model risk guidance shifts the burden onto the lender’s own standards. The loan underwriting page has the buyer’s checklist.

Layer one: every value

For each extracted value, the trail should hold the source document, the page and position it came from, the confidence of the extraction, and any edit a person made afterward, with who and when.

The test is whether someone who was not in the room can follow it. An auditor should be able to start from a figure in the committee memo and click back to the borrower document it came from, without asking the analyst to rebuild the spreadsheet.

Amended submissions belong here too. When a borrower restates financials, the original and the restatement should both be kept, with the differences and their effect on the ratios shown.

Layer two: every policy test

For each rule the system applied: the rule as written, its version, the inputs it used and the result. When a lender changes its credit policy, every decision made before the change should still tie to the version that was in force.

The OCC’s July 2026 Lending and Loan Portfolio Risk Management booklet addresses automated retail decisions in exactly these terms: “Decision criteria for auto approvals and manual reviews should adhere to the bank’s written guidelines,” and “a clear audit trail should document the approval process.”

Layer three: the decision

Exceptions and their approvals, the approver, and timestamps throughout. If a person overrode a rule, the trail shows the override and the reason.

This layer is what Regulation B depends on. A creditor that takes adverse action owes the applicant “A statement of specific reasons for the action taken,” and must retain application records “For 25 months (12 months for business credit” with limited exceptions. A system that cannot say why it reached a result cannot meet the first requirement.

What changed in April 2026

For fifteen years the reference for documenting decision tools was the 2011 model risk guidance. In April 2026 the agencies replaced it. The OCC’s bulletin says “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” The new guidance also excludes “deterministic rule-based processes” from its definition of a model.

Two consequences follow. A lender cannot point to model risk guidance as its checklist for an AI underwriting tool. And a tool built on deterministic policy checks sits under the ordinary controls for policies, change management and records, which are older and better understood. Until regulators say more, lenders set their own bar. NIST’s AI Risk Management Framework offers a useful one: “Explainable systems can be debugged and monitored more easily, and they lend themselves to more thorough documentation, audit, and governance.”

What to ask a vendor

Six questions, all answerable on a demo with one of your own files:

  1. Click a number in the memo. Does it open the page it came from?
  2. Which values were low confidence, and who confirmed them?
  3. Show the credit policy as text a credit officer can read. Which version applied to this file?
  4. Replay the file from raw documents to memo, in order, with timestamps.
  5. The borrower restated. Where are both versions?
  6. Export the trail for an auditor.

On the MightyBot platform each of those is a feature of the record rather than a report someone assembles later. The full checklist and the comparison of approaches are on the loan underwriting page.

FAQ

Frequently Asked Questions

What should an audit trail for AI-extracted loan data contain?

For every value: the source document, page and position, the extraction confidence, and any human edit. For every policy test: the rule, its version, the inputs and the result. For the decision: exceptions, approvals, the approver and timestamps.

Does model risk guidance cover AI underwriting tools?

The revised interagency guidance of April 2026 says generative and agentic AI are not within its scope, and its definition of a model excludes deterministic rule-based processes. Lenders set their own documentation bar for those tools until regulators say more.

How long must underwriting records be kept?

Regulation B requires application records to be retained for 25 months for consumer credit and 12 months for business credit, with limited exceptions. Other rules and investor requirements can extend that.

Can an auditor replay an AI-underwritten file?

They can if the system kept the trail in order: documents, extracted values with sources, policy results, exceptions, approvals and the memo, each with timestamps. Ask a vendor to demonstrate that replay on one file.