Talk to us
BlogBankingWhat Is ExplainerYusight

What Does Examiner Review Require From an AI-Drafted Credit Memo?

Bank examiner questions on AI underwriting, answered: which rules apply, whether an AI memo tool is a model, and the audit trail to build. See the exam file.

YT

YuVerse Team

Published August 30, 2026 · Updated August 30, 2026 · 16 min read

What Does Examiner Review Require From an AI-Drafted Credit Memo?

Examiner review requires three things: every figure in the memo traceable to a source document and page, a named human who reviewed the draft and can show what they changed, and an institution that can produce the governing policy, the vendor due-diligence file and the version history on request. No US rule bans AI-drafted memos. The exam risk is undocumented reliance.


Key facts

  • YuSight cites 100% of figures with one-click source verification — each number resolves to its source document and page, the exact artifact an examiner wants when they say "show me where this DSCR came from."
  • AI is now a standard exam topic. The OCC and Federal Reserve have been reported to be asking about AI governance, vendor risk and kill switches in routine examinations (Quartz, 12 June 2026). Press reporting, not an agency issuance.
  • Adoption is past the pilot stage. Among 416 senior executives at banks and credit unions in the $250 million to $50 billion range, 49% of banks and 59% of credit unions had already deployed generative AI (Cornerstone Advisors, 20 February 2026).
  • The model risk rulebook changed in April 2026. SR 26-2 superseded SR 11-7 and SR 21-8 and states that generative and agentic AI "are not within the scope of this guidance" (SR 26-2). Out of scope for the model guidance is not out of scope for governance.
  • Regulation B retention runs in months: 25 for consumer credit, 12 for business credit, 60 days above $1 million in applicant revenue (12 CFR 1002.12). Credit file expectations run far longer and bind in practice.

Which US rules actually apply to an AI-drafted credit memo?

Four bodies of guidance get cited. Only one is about AI, and it is the newest.

Model risk — SR 26-2 (April 2026), which replaced SR 11-7 (2011). On 17 April 2026 the Federal Reserve, OCC and FDIC issued revised interagency model risk guidance superseding SR 11-7 and SR 21-8 — issued by the OCC as Bulletin 2026-13, which rescinded the Comptroller's Handbook "Model Risk Management" booklet and OCC Bulletins 1997-24, 2011-12 and 2021-19. Two changes matter. On scope, the guidance "is expected to be most relevant to banking organizations with over $30 billion in total assets," with institutions at or below that generally excluded, subject to a carve-back for significant model exposure. On AI, quoted in full because it gets paraphrased badly: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."

Read the second half again. The agencies took generative AI out of the model risk framework and handed it back to your general governance framework. A redirection, not an exemption.

Third-party risk — the Interagency Guidance on Third-Party Relationships (June 2023). Adopted by the OCC as Bulletin 2023-17, rescinding OCC Bulletins 2013-29 and 2020-10. It covers the third-party risk life cycle and is explicitly proportionate — "commensurate with the bank's risk profile and complexity." If you buy an AI drafting tool rather than build it, this is the guidance that bites, and it applies whether or not the tool is a model. The companion Guide for Community Banks (May 2024) is, in the OCC's words, voluntary, and adds no expectations.

Credit administration — the Comptroller's Handbook. The Rating Credit Risk booklet says what a memo is for: "The rating assigned to a credit should be well supported and documented in the credit file," and "There is no substitute for rigorous analysis of a borrower's financial statements." Note what it does not say — nothing about who or what types the narrative. The expectation is support in the file. Confirm the current version before quoting page numbers; it dates to April 2001 with later updates.

FFIEC IT examination materials. The FFIEC's Development, Acquisition, and Maintenance booklet (September 2024) replaced the 2004 "Development and Acquisition" booklet and covers project management, the system development life cycle and supply chain risk for acquired systems. That is where an IT examiner looks when your AI tool is bought software. No FFIEC booklet is specific to AI underwriting as at August 2026.

Credit unions: none of those SR letters or OCC bulletins bind you. The NCUA's AI resource page (updated 28 April 2026) states that "NCUA has not issued AI specific rules or regulation," that credit unions may use AI when done safely and soundly, and that vendor due diligence runs through Letters 07-CU-13 and 01-CU-20.

Is an AI credit memo tool a "model" under SR 11-7?

The guidance does not settle this for you. Take the argument seriously both ways.

The case that it is a model. SR 11-7 defined a model as "a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates," extending that to approaches "whose inputs are partially or wholly qualitative or based on expert judgment, provided that the output is quantitative in nature." A tool that reads a tax return and emits a DSCR is processing input data into a quantitative estimate. The extraction layer underneath is statistical machine learning with a measurable error rate. If the spread feeds a risk rating, the tool sits upstream of a number the examiner cares about.

The case that it is not. SR 26-2 narrowed the definition. A model is now "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," and the term "excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use." Cash flow divided by debt service is arithmetic. Generative AI is out of scope by name. And below $30 billion, the guidance is largely not addressed to you.

Where most institutions land. Record the tool in the model or technology inventory, classify it as a non-model tool with a written rationale, and apply proportionate controls anyway — accuracy testing against a manual benchmark, mandatory human review, an audit trail, periodic re-testing. We are not aware of published survey data on how institutions classify AI drafting tools; treat this as observed practice, not a measured distribution.

What an examiner tests is rarely the classification. It is whether a named committee made the decision, wrote down why, and can defend it. "We decided it is not a model, here is the memo, here is who approved it, here are the compensating controls" beats never having asked.

What documentation will an examiner actually ask to see?

Seven artifacts. Assemble them before the exam, not during it.

  1. Provenance for every figure — source document, page and extracted region behind each number.
  2. The human review record — who reviewed, when, and what they attested to.
  3. Version history — the AI draft as generated, the analyst's edits, and a diff.
  4. The vendor due-diligence file — the 2023 interagency assessment, including subcontractors and where data is processed.
  5. Validation or accuracy evidence — a measured extraction error rate against a manual benchmark, re-tested on a stated cadence.
  6. Override and exception logs — where the analyst disagreed with the tool, where policy was deviated from, and who approved each.
  7. The governing policy — the committee-approved statement of when AI output may be relied on and when independent verification is mandatory.

What questions will a bank examiner ask about AI underwriting?

Fifteen questions, six themes, phrased the way an examiner phrases them.

Model status

  1. "Is this tool in your model inventory? If it is not, show me the written rationale for excluding it and who approved that decision."
  2. "Who owns this tool, and does that owner sit in the first line or the second line?"
  3. "Tell me exactly which numbers this tool computes, and which of those feed a risk rating, a limit or a pricing decision."

Data provenance

  1. "Pick this loan. Show me where the DSCR in this memo came from."
  2. "How do you know the figures were pulled off the borrower's documents correctly? What is your measured error rate, and when did you last test it?"
  3. "What happens when the tool cannot read a document, or produces a figure the analyst thinks is wrong?"

Human oversight

  1. "Show me who reviewed this memo, what they changed from the machine draft, and when."
  2. "What does your policy say about when AI output can be relied on without independent verification?"
  3. "In the last twelve months, how many memos went to approval with no analyst edits at all?"

Third-party risk

  1. "Show me the due diligence file on this vendor — including their subcontractors and the models behind their extraction."
  2. "What does the contract say about access to records, audit rights, data ownership and exit?"
  3. "If this vendor stopped operating tomorrow, could you still produce three years of memos with their citations intact?"

Fair lending

  1. "Does this tool score, rate, rank or recommend approval or denial in any respect?"
  2. "Where do the specific reasons in your adverse action notices come from, and are they the actual reasons the credit was denied?"

Records retention

  1. "How long do you keep each version, and can you reproduce this memo exactly as it stood on the approval date, with the citations resolving as they did then?"

Which artifact answers which examiner concern?

Examiner concern

The question behind it

Artifact that answers it

Where it lives

Is this a model?

Governance classification

Written model-status determination plus committee minute

Model risk / technology inventory

Is the number right?

Data integrity

Figure-level citation to source document and page

The memo itself

Did a human actually look?

Reliance and accountability

Named reviewer, timestamp, attestation

Workflow audit trail

What did the machine get wrong?

Effective challenge

Diff between AI draft and approved memo

Version history

Do you understand your vendor?

Third-party risk

Due-diligence file, contract, subcontractor list

Vendor management file

Does it work?

Accuracy

Benchmark test results and re-test cadence

Validation / QA file

Is judgement being overridden?

Exception discipline

Override and deviation log with approvers

Credit administration

Is it fair?

ECOA / Reg B

Scope statement that the tool does not score; adverse action reason mapping

Compliance file

Can you reproduce it?

Records

Immutable version snapshots, life-of-loan

Records retention

Does using AI to draft credit memos create fair lending risk?

Regulation B covers business credit, not just consumer credit — the Interagency Fair Lending Examination Procedures state that ECOA "applies to any extension of credit, including extensions of credit to small businesses, corporations, partnerships, and trusts." The question is real for commercial lenders, not only the consumer side.

Here is the distinction most vendors blur, and the one an examiner will press on:

 

A tool that drafts and spreads

A tool that scores or decisions

What it produces

Standardised financials, ratios, narrative

An approve/decline, score, rating or price

Where the decision sits

Analyst and credit committee

Partly inside the tool

Disparate treatment exposure

Indirect — what it surfaces, how it phrases

Direct — the output is the decision

Disparate impact exposure

Low unless variable selection is skewed

Central; requires testing

Adverse action reasons

Must be checked before reuse

Must derive from actual model reasons

Examiner posture

Documentation and consistency review

Statistical analysis, less-discriminatory-alternative testing

YuSight drafts and spreads. It does not score, rate or decision. That is the left column, and the left column is a genuinely different risk posture — but not a zero one. Three residual exposures:

  • Reason-code leakage. If the memo's AI-drafted risk factors become the drafting source for adverse action reasons, Regulation B's accuracy standard attaches. Section 1002.9(b)(2) treats statements that the action was based on the creditor's internal standards or policies as insufficient. The reasons must be the actual reasons.
  • Prohibited-basis information in the file. Tax returns and bank statements carry marital status, names, addresses and sometimes age. A narrative generator that surfaces information the underwriter did not need creates a record a fair lending examiner will read.
  • Inconsistent documentation quality. The Interagency Fair Lending Examination Procedures list inadequate file documentation, vague underwriting standards and unclear guidance on exceptions and overrides as underwriting risk factors. A tool that produces thorough files for some segments and thin ones for others has created a disparity pattern in the evidence, whatever the decisions were.

What does an audit trail look like for one number?

This is the walkthrough an examiner actually runs. Illustrative figures — constructed to show the mechanics, not drawn from a real account.

👤
Borrower: Meridian Fabrication LLC, an S-corporation metal fabricator in Ohio. Request: $2,400,000 equipment term loan, 84 months, 7.25% fixed. Covenant: minimum global DSCR 1.25x.

The examiner points at one sentence: "FY2025 global DSCR of 1.38x."

Step 1 — the memo figure. Click 1.38x. The citation opens the DSCR panel in the spread, not a footnote. The arithmetic, line by line:

Line

Amount

Source

Ordinary business income

$412,000

Form 1120-S, page 1

Add: depreciation

$268,000

Form 1120-S, page 1

Add: amortization

$15,000

Schedule K-1 footnote

Add: interest expense

$96,000

Form 1120-S, page 1

Less: gain on asset sale (non-recurring)

($40,000)

Form 4797

Cash flow available for debt service

$751,000

 

Existing term debt P&I

$106,000

Bank amortization schedules

Proposed loan annual P&I

$438,000

$2,400,000 / 84 months / 7.25%

Total debt service

$544,000

 

$751,000 ÷ $544,000 = 1.3805 → 1.38x, against a 1.25x covenant.

Form 1120-S line numbers move between tax years. Cite the line number for the specific return year in the file, not a generic one.

Step 2 — back to the page. Click the $268,000 depreciation line. It opens Meridian's 2025 Form 1120-S at the page where depreciation is reported, extracted region highlighted, with the Form 4562 tie-out alongside. The examiner is now looking at the taxpayer's own document, two clicks from the memo sentence.

Step 3 — who touched it. Figures extracted 3 March, 09:14 ET. Analyst J. Ruiz edited amortization from $0 to $15,000 at 10:41 with the note "amortization of loan costs picked up from the Schedule K-1 footnote; not captured on the face of the return." Credit officer M. Alvarez approved at 11:02.

Step 4 — what changed. Version history shows memo v2 carried a DSCR of 1.35x ($736,000 ÷ $544,000) and v3 carried 1.38x after that $15,000 correction flowed through. That diff is the most valuable artifact in the file — documentary proof of effective challenge. A human found something the machine missed, wrote down why, and the number moved.

That answers question 4 on the examiner's list, and it takes about ninety seconds.

Frequently asked questions

Is an AI credit memo tool a model under SR 11-7?

SR 11-7 was superseded in April 2026 by SR 26-2, which narrowed the definition of a model and put generative AI expressly outside its scope. Most institutions still inventory the tool, classify it as a non-model with a written rationale, and apply proportionate controls anyway — the classification matters less to an examiner than the documented reasoning behind it.

What documentation do examiners want for AI-assisted underwriting?

Provenance for every figure, the human review record, version history showing what the analyst changed, the vendor due-diligence file, accuracy or validation evidence, override and exception logs, and the policy governing when AI output may be relied on.

Does using AI to draft credit memos create fair lending risk?

Drafting and spreading carries meaningfully less ECOA exposure than scoring or decisioning, because the decision stays with the analyst and the committee. The residual risks are reason-code accuracy, prohibited-basis information surfacing in the narrative, and documentation quality that varies systematically across borrower segments.

How long must we retain AI-drafted memo versions?

Regulation B sets 25 months for consumer credit, 12 months for business credit, and 60 days for business applicants with revenues above $1 million or for trade credit — extended to 12 months on a written request (12 CFR 1002.12). Credit file expectations run far longer, typically life-of-loan plus your retention schedule, and that is what governs in practice.

Is the AI draft itself a record we have to keep?

If the draft was used in evaluating the application, the conservative reading of 12 CFR 1002.12(b)(1) is yes. Practice varies and we are not aware of an agency issuance on AI drafts specifically — confirm with your own counsel, not with a vendor.

Who is accountable for an error in an AI-drafted memo?

The bank, and specifically the people who signed it. No US guidance transfers accountability to a vendor, and the Comptroller's Handbook puts responsibility for the credit risk rating system with the board and those it designates. The audit trail shows a named person exercised judgement; it does not shift the blame.

Do we need to disclose AI use to our regulator?

There is no general affirmative disclosure requirement we are aware of. Expect it to surface anyway — through pre-examination questionnaires, vendor lists and IT examination scoping. Better to raise it yourself with a governance file behind you.

How do we keep an auditable trail when AI drafts our credit memos?

Require that every figure carries a citation to a source document and page, that every version is snapshotted immutably, and that approval cannot happen without a named reviewer and timestamp. If any one of those is optional in your workflow, the trail has a hole in it.

Does the $30 billion threshold in SR 26-2 mean community banks can ignore model risk?

No. It means the interagency guidance is generally not addressed to you and your own practices, sized to your risk profile, are what govern. SR 26-2 says exactly that about tools outside its scope.

Our vendor says their tool is "examiner-ready." What should we ask them?

Ask for the measured extraction accuracy and the benchmark behind it, whether every figure carries a citation, whether version history is immutable, and what happens to your memos and citations if you terminate the contract.

Key takeaways

  • No US regulation prohibits AI-drafted credit memos. The exam finding risk sits in undocumented reliance, not in the drafting.
  • SR 26-2 replaced SR 11-7 in April 2026 and put generative AI outside the model risk framework — redirecting the governance question to you, not removing it.
  • The 2023 Interagency Third-Party Guidance applies to a purchased AI tool whether or not it is a model.
  • Drafts versus scores is the most consequential distinction in the fair lending conversation. Get your vendor's answer in writing.
  • Build the seven artifacts before the exam: provenance, review record, version history, due-diligence file, validation evidence, override log, policy.
  • The best answer to "show me where this number came from" is two clicks, not two days.

YuSight generates a Credit Assessment Memo with 100% of figures cited and one-click source verification, complete version history and a single-platform workflow audit trail — the file an examiner asks for, assembled as the memo is written rather than reconstructed afterwards.

See the audit trail an examiner would see — book a live demo.


This article is general information for credit and risk professionals, not legal or regulatory advice. Guidance changes; verify every citation against the issuing agency before relying on it.

Stay Updated

Get the latest AI insights delivered to your inbox.

Product Brochure

A complete overview of YuVerse products, use cases, and capabilities.

Topics

bank examiner questions on AI underwritingcredit memo audit trail examinerexaminer readiness AIFFIEC AI underwritingSR 11-7 AI credit memoAI underwriting documentation