YuVerse at Global Fintech Fest 2026View event
Talk to us
BlogBankingUse Case ListicleYusight

What Questions Do Bank Examiners Ask About AI Underwriting?

The 41 questions bank examiners ask about AI underwriting, grouped by examiner role, with the weak answer, the strong answer and the evidence each one needs.

YT

YuVerse Team

Published September 2, 2026 · Updated September 2, 2026 · 14 min read

What Questions Do Bank Examiners Ask About AI Underwriting?

Examiners ask four kinds of question: what the tool does, where its numbers came from, who checked them, and what happens when it is wrong. They arrive from four different desks — credit, IT, compliance and model risk — and each asks a different subset. The list below is 41 questions, with the answer that fails and the answer that holds.


Key facts

  • YuSight cites 100% of figures with one-click source verification. When an examiner says "show me where this DSCR came from," the answer is a click, not a two-day file reconstruction.
  • The model rulebook changed on 17 April 2026. SR 26-2 superseded SR 11-7 and SR 21-8, is "expected to be most relevant to banking organizations with over $30 billion in total assets," and states that "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance" (SR 26-2; OCC Bulletin 2026-13).
  • Adoption is mainstream, so the questions are routine. Across 416 senior executives at banks and credit unions, 49% of banks and 59% of credit unions had already deployed generative AI (Cornerstone Advisors, *What's Going On in Banking 2026*, 29 January 2026).
  • Automated *decisioning* is still rare in small business credit. "One in ten banks have a credit-scoring system that can partially or fully automate the underwriting of some non-credit-card lending," and "less than one in thirty banks use a credit-scoring system to auto-approve loans" (FDIC, *2024 Small Business Lending Survey*). Most AI in commercial credit drafts and spreads. Say so plainly, because it changes the examiner's whole line of questioning.
  • Credit unions are governed differently. The NCUA states "NCUA has not issued AI specific rules or regulation," and routes vendor diligence through Letters 07-CU-13 and 01-CU-20 (NCUA AI resources, updated 28 April 2026).

This page is the question list. The governance framework behind the answers — which rules bind you, what artifacts to build, how the fair lending analysis runs — is set out in what examiner review requires from an AI-drafted credit memo. Read that one to build the file. Read this one to rehearse the interview.

Who actually asks the questions?

Not one person. An exam team splits the work, and the same tool gets interrogated from four angles that do not talk to each other in the room. Answers that contradict across desks are what create findings.

Examiner

What they are testing

Their opening question

Where a bank usually fails

Credit / safety-and-soundness examiner

Whether the credit file supports the rating

"Pull this loan. Walk me through this number."

Cannot reproduce a figure without opening five documents

IT examiner

Whether the acquired system is governed

"Show me the vendor file and the SOC 2."

Diligence file predates the AI feature being used

Compliance examiner

ECOA, Reg B, adverse action, UDAP

"Does this tool score, rate or recommend?"

Nobody has written down what the tool does not do

Model risk specialist

Inventory, classification, validation

"Is this in your model inventory? If not, why not?"

No written determination, no approver

Three practical consequences. First, one designated owner should answer for the tool across all four desks. Second, the written scope statement — what the tool computes, what it never touches — is the single document all four ask for in different words. Third, the credit examiner's question is the hardest, because it is answered at the level of one number in one file, not at the level of policy.

What do they ask in the entry meeting?

Five questions, asked before anyone opens a loan file.

  1. "List every AI or machine-learning tool touching the credit process, and who owns each."
  2. "Which of them are in the model inventory, and which are not, and who decided?"
  3. "What has changed since the last exam — new tools, new features, new vendors, new versions?"
  4. "Is any of this making, scoring or recommending a credit decision?"
  5. "Show me the board or committee minute where AI use in credit was approved."

Question 3 is the one that catches people. A vendor pushing a generative drafting feature into a spreading product you bought three years ago is a change in the tool's risk profile, whether or not you were told. Version notes belong in the vendor file.

What does the credit examiner ask when they pull a file?

Nine questions, and they all reduce to provenance.

  1. "Where did this DSCR come from? Show me every input."
  2. "Which document and which page is that depreciation add-back on?"
  3. "Who spread these statements, the tool or a person?"
  4. "What did the analyst change from the machine draft?"
  5. "Show me the same borrower's prior-year spread. Were the adjustments made consistently?"
  6. "This memo says the borrower's largest customer is 34% of revenue. Where is that from?"
  7. "What did the tool flag as low-confidence, and what happened to those fields?"
  8. "How does the risk rating input trace back to the spread?"
  9. "Reproduce this memo as it stood on the approval date."

A worked answer to question 6

Kestrel Fabrication LLC, FY2025 audited statements plus the federal return. The memo says DSCR 1.33x. The examiner wants the arithmetic and the source of each line.

Line

Amount (USD)

Source

Net income

412,000

Form 1120, page 1

+ Depreciation

268,000

Form 4562, and audited cash flow statement

+ Amortisation

31,000

Audited cash flow statement

+ Interest expense

194,000

Audited income statement; agrees to Form 1120

= EBITDA

905,000

Computed

+ Non-recurring legal settlement

46,000

Audit footnote 14, analyst-accepted add-back

= Adjusted EBITDA

951,000

Computed

− Cash taxes paid

118,000

Audited cash flow statement

− Unfinanced capex

140,000

Audited cash flow statement, net of new equipment note

= Cash available for debt service

693,000

Computed

Interest

194,000

Audited income statement

+ Current maturities of long-term debt

268,000

Balance sheet, current liabilities

+ Capital lease payments

61,000

Lease footnote 9

= Total debt service

523,000

Computed

DSCR = 693,000 ÷ 523,000 = 1.325, presented as 1.33x.

Three things make that answer survivable. The add-back at 46,000 has a named analyst who accepted it and a footnote reference, so it is a judgement with an owner rather than a machine artifact. Capex is deducted, so the number is not an EBITDA-only coverage figure dressed up as cash flow — the variant question that causes most covenant arguments is covered in DSCR formula: every variant lenders use. And every input resolves to a document and page without anyone re-opening the file cabinet.

If your platform cannot do that in the room, the examiner's next request is a sample, and a sample is how a single unsupported number becomes a documentation finding across a portfolio.

What does the IT and third-party examiner ask?

Eight questions, driven by the Interagency Guidance on Third-Party Relationships (OCC Bulletin 2023-17, 6 June 2023), which expects practices "commensurate with the bank's risk profile and complexity as well as the criticality of the activity supported by the third party."

  1. "Show me the due diligence you performed before this tool touched a live file."
  2. "Which subcontractors and which foundation models sit behind the vendor's product?"
  3. "Where is borrower data processed and stored, and does any of it train a shared model?"
  4. "What are your contractual audit rights, and have you exercised them?"
  5. "What is the current SOC 2 Type II, and did you read the exceptions?"
  6. "What is your exit plan, and can you retain the memos and citations if the vendor fails?"
  7. "How are new model versions released to you, and do you test before they go live?"
  8. "Who at the bank is accountable for this relationship, by name and title?"

Question 17 is the one vendors answer badly. Get it in writing, and get it re-confirmed at renewal.

What does the compliance examiner ask?

Seven questions. Note that Regulation B reaches business credit, so this is not a consumer-only conversation.

  1. "Does this tool score, rate, rank, price or recommend approval or denial, in any respect?"
  2. "Show me the written scope statement, and who signed it."
  3. "Where do the specific reasons in your adverse action notices come from?"
  4. "Are those the actual reasons the credit was denied?"
  5. "Does the tool surface any prohibited-basis information the underwriter did not need?"
  6. "Are declines documented as consistently as approvals?"
  7. "If a borrower asked why they were declined, could you answer without referring to the tool?"

Questions 25 and 26 are a pair, and they are the trap. Regulation B requires the statement of specific reasons to be the actual principal reasons. A risk narrative drafted by a language model and then copied into a notice is a compliance exposure created by convenience, not by AI.

What does the model risk specialist ask after SR 26-2?

Six questions, and the ground has moved under all of them. SR 26-2 defines a model as "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," and excludes "simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes."

  1. "Is this tool in the model inventory? If not, show me the written rationale and the approver."
  2. "Does the tool apply a statistical, economic or financial theory, or does it do arithmetic on extracted values?"
  3. "You are below $30 billion. Have you nonetheless assessed whether you have significant model exposure here?"
  4. "Generative AI is out of scope for the model guidance. What governance did you apply instead?"
  5. "What is your measured extraction accuracy, against what benchmark, tested when?"
  6. "Who performs effective challenge on this tool, and are they independent of the credit line?"

Question 33 is the whole point of the 2026 revision, and it is routinely misread. The guidance continues: "Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document." Out of scope for model risk means governed elsewhere, not ungoverned. An institution that says "generative AI is exempt now" has answered the question wrong in one sentence.

Which answers fail, and what to say instead?

Question

The answer that fails

The answer that holds

Evidence to hand over

Where did this number come from?

"The system calculated it."

"Adjusted EBITDA 951,000 over debt service 523,000; here is each input at its source page."

Figure-level citations

Is it a model?

"It's just AI, so it's out of scope."

"Classified as a non-model tool on 12 May 2026 by the model risk committee; here is the rationale and the compensating controls."

Written determination plus minute

Did a human review it?

"Analysts review everything."

"Named reviewer, timestamped, with a diff showing four changed figures."

Version history

How accurate is it?

The vendor's marketing number.

"94.6% field-level accuracy on our own 200-file benchmark, re-tested quarterly, last run 4 August 2026."

Benchmark results

Does it decide?

"It helps us decide."

"It extracts, computes and drafts. It does not score, rate or recommend. Scope statement approved 3 March 2026."

Scope statement

What if the vendor disappears?

"We'd deal with it."

"Memos and citations are exported monthly to our own archive; last restore test 20 June 2026."

Exit plan and test log

The pattern is not sophistication. It is that every strong answer contains a date, a name and a document.

The last six questions, and how to rehearse

  1. "How many memos in the last twelve months went to approval with no analyst edits?"
  2. "Show me an override log entry where the analyst disagreed with the tool."
  3. "What happens when the tool cannot read a document?"
  4. "How long do you retain each version of a memo?"
  5. "Has internal audit looked at this?"
  6. "What would you change if we asked you to stop using it tomorrow?"

Rehearse by running your own mini-exam. Pick five approved loans at random. Have someone outside credit ask questions 6 to 14 with a stopwatch. Anything that takes more than two minutes to evidence is a finding waiting to be written. Then repeat it on a file from eighteen months ago, because reproducing a current memo is easy and reproducing an old one is the actual test. The vendor-side version of this drill is in what to ask a credit memo automation vendor, and the underlying process these questions probe is mapped in commercial loan underwriting in US banks.

Frequently asked questions

What will an examiner ask about an AI-drafted credit memo?

Mostly one question, phrased forty different ways: show me where this number came from and who checked it. Everything else — inventory status, vendor diligence, fair lending scope — is the framework that makes that answer credible.

Does AI underwriting need model validation?

It depends on classification, and after SR 26-2 that is genuinely arguable. Arithmetic on extracted values is excluded from the model definition, and generative AI is out of scope entirely, but you still need a written determination, an approver and proportionate controls such as accuracy testing.

How do you evidence human judgement in an AI-assisted decision?

With a diff. Show the machine draft, show the approved memo, and show what the named analyst changed and when. A review checkbox proves nothing; a change record proves someone actually read it.

Does the $30 billion threshold mean smaller banks can ignore all this?

No. It means the model risk guidance is largely not addressed to you. Third-party risk, credit administration, records retention and Regulation B do not have an asset threshold, and neither does an examiner's expectation that the file supports the rating.

Do we have to tell our examiner we are using AI?

There is no general AI notification rule, but concealment is a worse position than disclosure. Raise it in the entry meeting with a one-page scope statement and the tool will be examined as a governed process rather than discovered as a surprise.

What if the AI got a number wrong and the loan was approved?

Then you have an error, an override log gap and a control question — in that order. Examiners are far more interested in whether the process would have caught it than in the single wrong figure. Design for detection, not perfection, and see how to stop an AI credit memo tool from hallucinating numbers.

How many of these questions should we prepare answers for?

All of them, but only six matter under time pressure: what does it do, what does it not do, where did this number come from, who reviewed it, how accurate is it, and who owns the vendor. If those six have crisp answers with dates and names, the rest follow.

Who should answer examiner questions about the tool — credit or technology?

One named owner, briefed on all four desks' angles, with credit, IT and compliance available for detail. Four people giving four slightly different descriptions of the same tool is how a documentation finding starts.

Will examiners accept a vendor's accuracy claim?

Not as your evidence. Vendor numbers come from vendor test sets. Run a benchmark on your own files, record the field-level result, state the re-test cadence, and cite that. The comparison logic behind those claims is unpacked in Ocrolus vs Docsumo vs YuSight.

Key takeaways

  • Four desks, four angles. Credit wants provenance, IT wants the vendor file, compliance wants the scope statement, model risk wants the classification. One owner, one consistent story.
  • The credit examiner's question is the hard one because it is answered at the level of one figure in one file. 693,000 over 523,000 equals 1.33x, and every input has a page.
  • SR 26-2 narrowed the model definition and put generative AI out of scope, then handed those tools back to general governance. "It's exempt" is the wrong answer to question 33.
  • Every strong answer has a date, a name and a document. Every weak one is a description of intent.
  • Rehearse on an eighteen-month-old file. Reproducing today's memo proves nothing.

See the audit trail an examiner would see — pick one of your own approved files, and watch every figure in the memo resolve to its source document and page in one click. Book a live demo.

Stay Updated

Get the latest AI insights delivered to your inbox.

Product Brochure

A complete overview of YuVerse products, use cases, and capabilities.

Topics

bank examiner questions on AI underwritingAI underwriting examiner reviewmodel documentationcredit memo audit trail examinerSR 26-2 AI underwritingAI exam preparation bank