ArticleAI in banking

AI in credit underwriting: faster memos, wider data, and explanations that still have to hold up

Generative AI is shortening credit memos and cash-flow data is widening who can be scored. The rules on explaining and testing those decisions are shifting on both sides of the Atlantic, but the obligations have not gone away.

8 min read By · Article
20–60%
credit analyst productivity gain reported in a bank case study of generative-AI credit memo drafting1

Key takeaways

  • Generative AI in credit is real but slower than promised: in late 2023, 80% of North American credit risk chiefs expected a live use case within a year; about 30% of North American respondents had reached deployment by the end of 20241.
  • The clearest wins are in memo drafting and synthesis, with one bank case reporting 20–60% analyst productivity gains and roughly 30% faster decisions1.
  • Cash-flow data and machine learning each improved predictiveness and approvals in independent testing, and worked best together3.
  • US guidance has been withdrawn and Regulation B rewritten, and the EU has deferred high-risk AI obligations for credit scoring to 2 December 2027. The duty to explain a decline, and to evidence fair and robust models, remains5678.

Credit is where AI promises the most and where the rules bite hardest. A lending decision is consequential for the applicant, regulated for the lender and, unlike a marketing model, must be explained to the person on the receiving end. That is why credit has been a slower, more careful adopter of generative AI than contact centres or software engineering, and why the gap between pilot and production is wider here than almost anywhere else in the bank.

Two things are now changing at once. The work of underwriting is being reshaped by generative AI, which drafts, summarises and checks. And the data behind the decision is widening, as bank-account cash-flow data moves from fintech niche into mainstream models. Both raise the same question: can the lender still explain, test and defend the decision?

Where generative AI is landing in credit

Joint research by the IACPM and McKinsey, covering 44 institutions across North America, Europe, Asia and Africa, found that every participant was testing at least one generative AI use case in credit. The most common were synthesising information for credit decisions, drafting credit memos, assessing data quality and early-warning monitoring1. Several large banks were piloting agents that extract information from structured and unstructured documents to produce a first-draft credit memo1.

The value case is concrete. In one bank's automated credit memo drafting, the researchers reported a 20–60% productivity gain for credit analysts and around 30% faster decisioning1. That matches what we see in practice. The analyst's time goes on assembling financials, covenants, industry context and account history, and that is exactly the work a well-grounded model does well.

Progress has still been slower than expected. At an October 2023 roundtable with chief risk officers of 24 North American institutions, 20% already had a generative AI use case in credit risk and 80% expected to have one within a year12. By the December 2024 survey, only about 30% of North American respondents had reached deployment1. The obstacles were familiar: 75% of the 2023 group cited risk and governance, and 67% a shortage of internal capability2. Where use cases were abandoned, the top reasons were insufficient performance and an inability to articulate the benefit, each cited by 41%1.

Exhibit 1

Expectations ran well ahead of deployment

Generative AI in credit risk, North American institutions, % of respondents (%)

Note: October 2023 figures from a roundtable of chief risk officers at 24 North American institutions; December 2024 figure is approximate (about 30%) and from a different, broader respondent group.

Source: IACPM and McKinsey & Company, “Emerging Generative AI Use Cases in Credit: Research results (IACPM–McKinsey webinar)” (2025)

Cash-flow data widens the aperture

The second shift is in the inputs. FinRegLab's 2025 comparative study built models on anonymised credit bureau and bank-account data. Machine learning improved predictive accuracy by up to 2% over logistic regression on the same data, which raised approval rates by as much as 4% at thresholds mainstream lenders might use. The authors estimate that, at 2023 origination volumes, this would mean roughly two million more credit card accounts and 152,000 more mortgages3. Adding cash-flow data also helped, though by less, and the model combining bureau and cash-flow data under machine learning was the most predictive and generally approved the most applicants3.

The size of the thin-file problem has also been restated. In June 2025 the CFPB corrected its widely cited estimate of US ‘credit invisibles’. The 2010 figure fell from 11.0% of adults to 5.8%, while the share with an unscored credit record rose from 7.4% to 12.7%. By 2020, 2.7% of adults were credit invisible4. For most thin-file applicants, the problem is a record too sparse to score rather than no record at all, and that is where cash-flow data adds most.

Exhibit 2

The thin-file problem is mostly 'unscored', not 'invisible'

US adults with limited credit histories, CFPB estimates

Measure2015 estimate (Dec 2010)Corrected (Dec 2010)Latest (Dec 2020)
Credit invisible (no record)11.0% (25.9m)5.8% (13.5m)2.7% (7.0m)
Unscored credit record7.4% (17.2m)12.7% (29.7m)n/a
Scored credit recordn/a81.6% (191.3m)87.5% (225.3m)

Note: Technical correction published June 2025; n/a where the CFPB did not report a comparable figure.

Source: Consumer Financial Protection Bureau, “Technical correction and update to the CFPB's credit invisibles estimate” (2025)

Explaining the decision: the rules move, the duty stays

In the US, the guidance has moved a long way in 18 months. On 12 May 2025 the CFPB withdrew its 2022 and 2023 circulars on adverse action notices for decisions made with complex algorithms5. Those circulars had stressed that there is ‘no special exemption for artificial intelligence’ and that creditors must give accurate and specific reasons rather than rely on a generic checklist8. In April 2026 the Bureau went further, finalising a Regulation B rule, effective 21 July 2026, stating that ECOA does not authorise disparate-impact liability6.

It would be a mistake to read this as permission to stop explaining. The circulars interpreted a requirement that sits in ECOA and Regulation B themselves: an applicant who is declined must be told the principal reasons8. Withdrawing the guidance did not repeal that obligation. Intentional discrimination and proxy discrimination remain prohibited6. And a model a lender cannot explain is also one it cannot validate, monitor or defend to its own board.

In the EU, AI systems used to assess the creditworthiness of natural persons are high-risk under Annex III of the AI Act7. The Digital Omnibus on AI, approved by the European Parliament in June 2026 and adopted by the Council on 29 June 2026, moved the Annex III obligations from 2 August 2026 to 2 December 20277. The delay reflects unfinished standards, not a change of direction. The transparency obligations for systems that interact with people, such as a lending chatbot, still applied from 2 August 20267.

Fairness testing as a production discipline

With rules diverging across jurisdictions, the practical answer is to build one testing discipline strong enough for the strictest regime the bank operates in:

  • Reason codes by design. Choose model architectures and attribution methods that produce stable, specific principal reasons, and test that they are right, not just that they exist.
  • Segment performance testing. Measure accuracy, approval rates and false declines across customer segments before launch and continuously after it. FinRegLab found the gains from new techniques varied by credit history and income3.
  • Grounded generation. Every figure in an AI-drafted memo should trace to a source document or system of record, and the analyst should see the citation.
  • Human accountability. The credit officer signs the decision. The model drafts, flags and checks.

Deferral buys time, but not much. December 2027 is roughly one model development cycle away. Lenders that use the next 12 months to put evidence, testing and oversight into their credit workflows will be able to scale generative AI and alternative data. Those that wait will be retrofitting controls onto models already in production.

For executives

What this means for your bank

  1. Prioritise credit memo drafting and document synthesis as first production use cases, with every generated figure linked to its source.
  2. Stand up a single fairness and performance testing standard that meets the strictest jurisdiction you lend in, rather than per-market variants.
  3. Pilot cash-flow data for thin-file and unscored segments, and measure approval and loss outcomes by segment, not only in aggregate.
  4. Map every credit model and AI system against the EU AI Act Annex III requirements now, working back from 2 December 2027.
  5. Keep adverse-action reason generation under model risk management, with periodic checks that stated reasons match model drivers.
Put it to work

How DaasLabs can help

Assess credit data, model governance and AI readiness with our maturity diagnostic.

Take the maturity assessment

Put autonomy levels, human sign-off and audit trails around credit agents.

See governance & controls

Build governed data lineage from source systems to model features and memo figures.

Explore the accelerator

Watch an agent assemble a case file and hand it to a human for decision.

Watch an agent run

Sources

  1. 1
  2. 2
    Is a gen AI revolution coming to credit risk management? (opens in a new tab) ProSight Financial Association (summarising McKinsey research), 8 July 2024
  3. 3
  4. 4
  5. 5
    Withdrawn guidance (opens in a new tab) Consumer Financial Protection Bureau, 12 May 2025
  6. 6
  7. 7
  8. 8

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Stay informed

Get new banking insights in your inbox

New perspectives on AI, data and transformation in banking — a few times a month. Browse all insights.

AI
AI Analystagentic

I'm the DaasLabs AI Analyst, working with tools rather than from memory. I can:

  • Query the live platform APIs (disputes, fraud, AML, recon, revenue…)
  • Report what the digital workforce is doing: runs, approvals, overrides
  • Start an agent run on a real case and hand you the link to watch it

Every answer shows the tools it used.