What should an audit trail for AI-extracted loan data contain?
Three layers. For every extracted value: the source document, the page and position, the confidence of the extraction, and any edit a person made afterward. For every policy test: the rule as written, its version, the inputs it used and the result. For the decision: exceptions and their approvals, the approver, and timestamps throughout.
The test of a good trail is whether someone who was not in the room can follow it. An auditor, an LP or an examiner should be able to start at a number in the committee memo and click back to the borrower document it came from, without asking the analyst to rebuild the work.
Amended submissions belong in the trail too. When a borrower restates financials, the original and the restatement should both be kept, with the differences and their effect on the ratios shown.
How do AI agents take a loan from raw documents to committee memo?
On MightyBot, agents classify the package first: financial statements, tax returns, bank statements, rent rolls, appraisals, entity documents. They extract the fields your credit policy needs and normalize them to one schema. Each value carries a pointer to its page and a confidence score, and low-confidence values route to a person.
Your credit policy is written in plain English and compiled into an execution plan. The agent spreads the financials, computes the ratios, tests each policy rule, and lists exceptions with the evidence attached. It then drafts the credit memo from those results, so every figure in the memo traces to a test and every test traces to a document.
Underwriters and approvers stay in charge of the decision. Teams usually begin with agents preparing the file for an underwriter to review, then widen what runs straight through for clean, low-risk requests as results hold up.
What do regulators say about automated underwriting and its records?
The OCC's July 2026 Lending and Loan Portfolio Risk Management booklet addresses automated retail decisions directly: "Decision criteria for auto approvals and manual reviews should adhere to the bank's written guidelines," and "a clear audit trail should document the approval process."
Regulation B applies whatever technology makes the decision. A creditor that takes adverse action owes the applicant "A statement of specific reasons for the action taken," and must retain application records "For 25 months (12 months for business credit" with limited exceptions. A system that cannot say why it reached a result cannot meet the first requirement.
Model risk guidance changed in April 2026, when the agencies replaced their 2011 guidance. The OCC's bulletin says "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." Until regulators say more, lenders set their own bar. NIST's AI Risk Management Framework gives a useful one: "Explainable systems can be debugged and monitored more easily, and they lend themselves to more thorough documentation, audit, and governance."
What to look for in AI loan underwriting software
Use these questions when you compare underwriting automation, whether you are a bank, a credit union or a direct lender.
- Does every value cite its source?Each extracted number should link to the page and position it came from, so reviewers can check it without redoing the work.
- Are extractions confidence scored?Low-confidence values should route to a person, and the record should show who confirmed or corrected them.
- Can you read the credit policy it applies?Rules should be written in language your credit officers can review, versioned, and tested against past files before they go live.
- Can an auditor step through a file?Look for a replay from raw documents to extracted data, policy results, exceptions, approvals and the memo, in order, with timestamps.
- How does it handle restated or amended submissions?Both versions should be retained, with the differences and their effect on ratios shown.
- Can you export and retain the record?The trail should export for examiners, external auditors and LPs, and be kept for at least the retention periods your regulators require.