What Does Examiner Review Require From an AI-Drafted Credit Memo?
Examiner review requires three things: every figure in the memo traceable to a source document and page, a named human who reviewed the draft and can show what they changed, and an institution that can produce the governing policy, the vendor due-diligence file and the version history on request. No US rule bans AI-drafted memos. The exam risk is undocumented reliance.
Key facts
- YuSight cites 100% of figures with one-click source verification — each number resolves to its source document and page, the exact artifact an examiner wants when they say "show me where this DSCR came from."
- AI is now a standard exam topic. The OCC and Federal Reserve have been reported to be asking about AI governance, vendor risk and kill switches in routine examinations (Quartz, 12 June 2026). Press reporting, not an agency issuance.
- Adoption is past the pilot stage. Among 416 senior executives at banks and credit unions in the $250 million to $50 billion range, 49% of banks and 59% of credit unions had already deployed generative AI (Cornerstone Advisors, 20 February 2026).
- The model risk rulebook changed in April 2026. SR 26-2 superseded SR 11-7 and SR 21-8 and states that generative and agentic AI "are not within the scope of this guidance" (SR 26-2). Out of scope for the model guidance is not out of scope for governance.
- Regulation B retention runs in months: 25 for consumer credit, 12 for business credit, 60 days above $1 million in applicant revenue (12 CFR 1002.12). Credit file expectations run far longer and bind in practice.
Which US rules actually apply to an AI-drafted credit memo?
Four bodies of guidance get cited. Only one is about AI, and it is the newest.
Model risk — SR 26-2 (April 2026), which replaced SR 11-7 (2011). On 17 April 2026 the Federal Reserve, OCC and FDIC issued revised interagency model risk guidance superseding SR 11-7 and SR 21-8 — issued by the OCC as Bulletin 2026-13, which rescinded the Comptroller's Handbook "Model Risk Management" booklet and OCC Bulletins 1997-24, 2011-12 and 2021-19. Two changes matter. On scope, the guidance "is expected to be most relevant to banking organizations with over $30 billion in total assets," with institutions at or below that generally excluded, subject to a carve-back for significant model exposure. On AI, quoted in full because it gets paraphrased badly: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."
Read the second half again. The agencies took generative AI out of the model risk framework and handed it back to your general governance framework. A redirection, not an exemption.
Third-party risk — the Interagency Guidance on Third-Party Relationships (June 2023). Adopted by the OCC as Bulletin 2023-17, rescinding OCC Bulletins 2013-29 and 2020-10. It covers the third-party risk life cycle and is explicitly proportionate — "commensurate with the bank's risk profile and complexity." If you buy an AI drafting tool rather than build it, this is the guidance that bites, and it applies whether or not the tool is a model. The companion Guide for Community Banks (May 2024) is, in the OCC's words, voluntary, and adds no expectations.
Credit administration — the Comptroller's Handbook. The Rating Credit Risk booklet says what a memo is for: "The rating assigned to a credit should be well supported and documented in the credit file," and "There is no substitute for rigorous analysis of a borrower's financial statements." Note what it does not say — nothing about who or what types the narrative. The expectation is support in the file. Confirm the current version before quoting page numbers; it dates to April 2001 with later updates.
FFIEC IT examination materials. The FFIEC's Development, Acquisition, and Maintenance booklet (September 2024) replaced the 2004 "Development and Acquisition" booklet and covers project management, the system development life cycle and supply chain risk for acquired systems. That is where an IT examiner looks when your AI tool is bought software. No FFIEC booklet is specific to AI underwriting as at August 2026.
Credit unions: none of those SR letters or OCC bulletins bind you. The NCUA's AI resource page (updated 28 April 2026) states that "NCUA has not issued AI specific rules or regulation," that credit unions may use AI when done safely and soundly, and that vendor due diligence runs through Letters 07-CU-13 and 01-CU-20.
Is an AI credit memo tool a "model" under SR 11-7?
The guidance does not settle this for you. Take the argument seriously both ways.
The case that it is a model. SR 11-7 defined a model as "a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates," extending that to approaches "whose inputs are partially or wholly qualitative or based on expert judgment, provided that the output is quantitative in nature." A tool that reads a tax return and emits a DSCR is processing input data into a quantitative estimate. The extraction layer underneath is statistical machine learning with a measurable error rate. If the spread feeds a risk rating, the tool sits upstream of a number the examiner cares about.
The case that it is not. SR 26-2 narrowed the definition. A model is now "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," and the term "excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use." Cash flow divided by debt service is arithmetic. Generative AI is out of scope by name. And below $30 billion, the guidance is largely not addressed to you.
Where most institutions land. Record the tool in the model or technology inventory, classify it as a non-model tool with a written rationale, and apply proportionate controls anyway — accuracy testing against a manual benchmark, mandatory human review, an audit trail, periodic re-testing. We are not aware of published survey data on how institutions classify AI drafting tools; treat this as observed practice, not a measured distribution.
What an examiner tests is rarely the classification. It is whether a named committee made the decision, wrote down why, and can defend it. "We decided it is not a model, here is the memo, here is who approved it, here are the compensating controls" beats never having asked.
What documentation will an examiner actually ask to see?
Seven artifacts. Assemble them before the exam, not during it.
- Provenance for every figure — source document, page and extracted region behind each number.
- The human review record — who reviewed, when, and what they attested to.
- Version history — the AI draft as generated, the analyst's edits, and a diff.
- The vendor due-diligence file — the 2023 interagency assessment, including subcontractors and where data is processed.
- Validation or accuracy evidence — a measured extraction error rate against a manual benchmark, re-tested on a stated cadence.
- Override and exception logs — where the analyst disagreed with the tool, where policy was deviated from, and who approved each.
- The governing policy — the committee-approved statement of when AI output may be relied on and when independent verification is mandatory.
What questions will a bank examiner ask about AI underwriting?
Fifteen questions, six themes, phrased the way an examiner phrases them.
Model status
- "Is this tool in your model inventory? If it is not, show me the written rationale for excluding it and who approved that decision."
- "Who owns this tool, and does that owner sit in the first line or the second line?"
- "Tell me exactly which numbers this tool computes, and which of those feed a risk rating, a limit or a pricing decision."
Data provenance
- "Pick this loan. Show me where the DSCR in this memo came from."
- "How do you know the figures were pulled off the borrower's documents correctly? What is your measured error rate, and when did you last test it?"
- "What happens when the tool cannot read a document, or produces a figure the analyst thinks is wrong?"
Human oversight
- "Show me who reviewed this memo, what they changed from the machine draft, and when."
- "What does your policy say about when AI output can be relied on without independent verification?"
- "In the last twelve months, how many memos went to approval with no analyst edits at all?"
Third-party risk
- "Show me the due diligence file on this vendor — including their subcontractors and the models behind their extraction."
- "What does the contract say about access to records, audit rights, data ownership and exit?"
- "If this vendor stopped operating tomorrow, could you still produce three years of memos with their citations intact?"
Fair lending
- "Does this tool score, rate, rank or recommend approval or denial in any respect?"
- "Where do the specific reasons in your adverse action notices come from, and are they the actual reasons the credit was denied?"
Records retention
- "How long do you keep each version, and can you reproduce this memo exactly as it stood on the approval date, with the citations resolving as they did then?"
Which artifact answers which examiner concern?
Examiner concern | The question behind it | Artifact that answers it | Where it lives |
|---|---|---|---|
Is this a model? | Governance classification | Written model-status determination plus committee minute | Model risk / technology inventory |
Is the number right? | Data integrity | Figure-level citation to source document and page | The memo itself |
Did a human actually look? | Reliance and accountability | Named reviewer, timestamp, attestation | Workflow audit trail |
What did the machine get wrong? | Effective challenge | Diff between AI draft and approved memo | Version history |
Do you understand your vendor? | Third-party risk | Due-diligence file, contract, subcontractor list | Vendor management file |
Does it work? | Accuracy | Benchmark test results and re-test cadence | Validation / QA file |
Is judgement being overridden? | Exception discipline | Override and deviation log with approvers | Credit administration |
Is it fair? | ECOA / Reg B | Scope statement that the tool does not score; adverse action reason mapping | Compliance file |
Can you reproduce it? | Records | Immutable version snapshots, life-of-loan | Records retention |
Does using AI to draft credit memos create fair lending risk?
Regulation B covers business credit, not just consumer credit — the Interagency Fair Lending Examination Procedures state that ECOA "applies to any extension of credit, including extensions of credit to small businesses, corporations, partnerships, and trusts." The question is real for commercial lenders, not only the consumer side.
Here is the distinction most vendors blur, and the one an examiner will press on:
| A tool that drafts and spreads | A tool that scores or decisions |
|---|---|---|
What it produces | Standardised financials, ratios, narrative | An approve/decline, score, rating or price |
Where the decision sits | Analyst and credit committee | Partly inside the tool |
Disparate treatment exposure | Indirect — what it surfaces, how it phrases | Direct — the output is the decision |
Disparate impact exposure | Low unless variable selection is skewed | Central; requires testing |
Adverse action reasons | Must be checked before reuse | Must derive from actual model reasons |
Examiner posture | Documentation and consistency review | Statistical analysis, less-discriminatory-alternative testing |
YuSight drafts and spreads. It does not score, rate or decision. That is the left column, and the left column is a genuinely different risk posture — but not a zero one. Three residual exposures:
- Reason-code leakage. If the memo's AI-drafted risk factors become the drafting source for adverse action reasons, Regulation B's accuracy standard attaches. Section 1002.9(b)(2) treats statements that the action was based on the creditor's internal standards or policies as insufficient. The reasons must be the actual reasons.
- Prohibited-basis information in the file. Tax returns and bank statements carry marital status, names, addresses and sometimes age. A narrative generator that surfaces information the underwriter did not need creates a record a fair lending examiner will read.
- Inconsistent documentation quality. The Interagency Fair Lending Examination Procedures list inadequate file documentation, vague underwriting standards and unclear guidance on exceptions and overrides as underwriting risk factors. A tool that produces thorough files for some segments and thin ones for others has created a disparity pattern in the evidence, whatever the decisions were.
What does an audit trail look like for one number?
This is the walkthrough an examiner actually runs. Illustrative figures — constructed to show the mechanics, not drawn from a real account.
The examiner points at one sentence: "FY2025 global DSCR of 1.38x."
Step 1 — the memo figure. Click 1.38x. The citation opens the DSCR panel in the spread, not a footnote. The arithmetic, line by line:
Line | Amount | Source |
|---|---|---|
Ordinary business income | $412,000 | Form 1120-S, page 1 |
Add: depreciation | $268,000 | Form 1120-S, page 1 |
Add: amortization | $15,000 | Schedule K-1 footnote |
Add: interest expense | $96,000 | Form 1120-S, page 1 |
Less: gain on asset sale (non-recurring) | ($40,000) | Form 4797 |
Cash flow available for debt service | $751,000 |
|
Existing term debt P&I | $106,000 | Bank amortization schedules |
Proposed loan annual P&I | $438,000 | $2,400,000 / 84 months / 7.25% |
Total debt service | $544,000 |
|
$751,000 ÷ $544,000 = 1.3805 → 1.38x, against a 1.25x covenant.
Form 1120-S line numbers move between tax years. Cite the line number for the specific return year in the file, not a generic one.
Step 2 — back to the page. Click the $268,000 depreciation line. It opens Meridian's 2025 Form 1120-S at the page where depreciation is reported, extracted region highlighted, with the Form 4562 tie-out alongside. The examiner is now looking at the taxpayer's own document, two clicks from the memo sentence.
Step 3 — who touched it. Figures extracted 3 March, 09:14 ET. Analyst J. Ruiz edited amortization from $0 to $15,000 at 10:41 with the note "amortization of loan costs picked up from the Schedule K-1 footnote; not captured on the face of the return." Credit officer M. Alvarez approved at 11:02.
Step 4 — what changed. Version history shows memo v2 carried a DSCR of 1.35x ($736,000 ÷ $544,000) and v3 carried 1.38x after that $15,000 correction flowed through. That diff is the most valuable artifact in the file — documentary proof of effective challenge. A human found something the machine missed, wrote down why, and the number moved.
That answers question 4 on the examiner's list, and it takes about ninety seconds.
Related reading
Frequently asked questions
Is an AI credit memo tool a model under SR 11-7?
SR 11-7 was superseded in April 2026 by SR 26-2, which narrowed the definition of a model and put generative AI expressly outside its scope. Most institutions still inventory the tool, classify it as a non-model with a written rationale, and apply proportionate controls anyway — the classification matters less to an examiner than the documented reasoning behind it.
What documentation do examiners want for AI-assisted underwriting?
Provenance for every figure, the human review record, version history showing what the analyst changed, the vendor due-diligence file, accuracy or validation evidence, override and exception logs, and the policy governing when AI output may be relied on.
Does using AI to draft credit memos create fair lending risk?
Drafting and spreading carries meaningfully less ECOA exposure than scoring or decisioning, because the decision stays with the analyst and the committee. The residual risks are reason-code accuracy, prohibited-basis information surfacing in the narrative, and documentation quality that varies systematically across borrower segments.
How long must we retain AI-drafted memo versions?
Regulation B sets 25 months for consumer credit, 12 months for business credit, and 60 days for business applicants with revenues above $1 million or for trade credit — extended to 12 months on a written request (12 CFR 1002.12). Credit file expectations run far longer, typically life-of-loan plus your retention schedule, and that is what governs in practice.
Is the AI draft itself a record we have to keep?
If the draft was used in evaluating the application, the conservative reading of 12 CFR 1002.12(b)(1) is yes. Practice varies and we are not aware of an agency issuance on AI drafts specifically — confirm with your own counsel, not with a vendor.
Who is accountable for an error in an AI-drafted memo?
The bank, and specifically the people who signed it. No US guidance transfers accountability to a vendor, and the Comptroller's Handbook puts responsibility for the credit risk rating system with the board and those it designates. The audit trail shows a named person exercised judgement; it does not shift the blame.
Do we need to disclose AI use to our regulator?
There is no general affirmative disclosure requirement we are aware of. Expect it to surface anyway — through pre-examination questionnaires, vendor lists and IT examination scoping. Better to raise it yourself with a governance file behind you.
How do we keep an auditable trail when AI drafts our credit memos?
Require that every figure carries a citation to a source document and page, that every version is snapshotted immutably, and that approval cannot happen without a named reviewer and timestamp. If any one of those is optional in your workflow, the trail has a hole in it.
Does the $30 billion threshold in SR 26-2 mean community banks can ignore model risk?
No. It means the interagency guidance is generally not addressed to you and your own practices, sized to your risk profile, are what govern. SR 26-2 says exactly that about tools outside its scope.
Our vendor says their tool is "examiner-ready." What should we ask them?
Ask for the measured extraction accuracy and the benchmark behind it, whether every figure carries a citation, whether version history is immutable, and what happens to your memos and citations if you terminate the contract.
Key takeaways
- No US regulation prohibits AI-drafted credit memos. The exam finding risk sits in undocumented reliance, not in the drafting.
- SR 26-2 replaced SR 11-7 in April 2026 and put generative AI outside the model risk framework — redirecting the governance question to you, not removing it.
- The 2023 Interagency Third-Party Guidance applies to a purchased AI tool whether or not it is a model.
- Drafts versus scores is the most consequential distinction in the fair lending conversation. Get your vendor's answer in writing.
- Build the seven artifacts before the exam: provenance, review record, version history, due-diligence file, validation evidence, override log, policy.
- The best answer to "show me where this number came from" is two clicks, not two days.
YuSight generates a Credit Assessment Memo with 100% of figures cited and one-click source verification, complete version history and a single-platform workflow audit trail — the file an examiner asks for, assembled as the memo is written rather than reconstructed afterwards.
See the audit trail an examiner would see — book a live demo.
This article is general information for credit and risk professionals, not legal or regulatory advice. Guidance changes; verify every citation against the issuing agency before relying on it.