AI-powered risk analysis makes it possible to estimate more accurately the likelihood that an applicant will repay a loan. But estimating risk is not the same as making a decision. Credit underwriting is the stage that turns that estimate into a concrete decision: approve, reject, or escalate an application, under what conditions, and with what controls. And that is precisely where artificial intelligence faces its biggest challenge.
A 2026 Experian study surveyed more than 200 decision-makers at financial institutions. 84% consider AI a critical or high priority for the next two years. However, 73% expressed concern about the regulatory environment for AI. In addition, 65% ranked AI-ready data among their biggest challenges. In other words, the obstacle to AI underwriting isn't the technology, but how the decision is controlled.
In this Crombie article, you'll see how scoring, risk analysis, and AI underwriting differ. You'll also learn which parts of the process can be automated and which are better escalated. Finally, you'll see how to measure whether the system truly works.
What's the Difference Between Risk Analysis, Credit Scoring, and Underwriting?
Credit scoring assigns a risk level to each applicant. Credit risk analysis, on the other hand, explains which factors affect their ability to repay. Underwriting decides what to do with that information: approve, reject, or escalate. Finally, credit decisioning executes that decision through rules, models, and workflows.
Concept | Question it answers | Role in the process |
Concept | Question it answers | Role in the process |
Credit scoring | What level of risk does this applicant present? | Assigns a score |
Credit risk analysis | What factors affect their ability and likelihood to repay? | Explains the risk |
Credit underwriting | Should this application be approved, under what conditions, and with what controls? | Makes the decision |
Credit decisioning | How is that decision executed consistently? | Operationalizes the decision |
Confusing these four concepts leads to a common mistake. Many institutions assume that a better model, by itself, produces better decisions. However, AI-powered risk analysis improves the estimate, not the decision. The decision also depends on the institution's credit policies and risk appetite. It also depends on how cases that don't fit any rule are handled. If you want to dive deeper into how these factors are evaluated, we recommend our article on credit risk analysis.
What Changes with AI Underwriting in Lending?
When risk analysis is powered by AI, the institution gains speed and consistency in evaluating applications. However, the most important change is a different one. The decision no longer depends solely on manual review and becomes a combined system. This system integrates models, rules, and human intervention, with a level of autonomy that varies by decision.
The priority for AI-powered risk analysis is clear, but implementation is moving more slowly. In a 2025 study by McKinsey and IACPM, 52% of institutions prioritized generative AI. However, only 12% of the North American institutions surveyed had deployed any use case.
At the same time, pressure to decide quickly is also growing on the customer side. In the United States, the Federal Reserve's 2025 Small Business Credit Survey showed a clear shift. The share of small businesses that applied for credit from online lenders went from 17% to 29% in five years.
The path to AI-powered risk analysis typically follows four stages:
- Manual underwriting: An analyst reviews each application and decides based on their judgment and the current policy.
- Rules-based underwriting: Policies are translated into rules that filter or approve standard applications.
- AI-assisted underwriting: Models estimate risk and recommend a decision. A person then validates it in defined cases.
- Automated decisioning: The system decides on its own only in high-confidence cases. The rest, in turn, are escalated.
Automated decisioning doesn't mean everything is resolved without people. It means the institution defines in advance which decisions the system can make on its own. That upfront design is what separates reliable automation from automation that, sooner or later, has to be dismantled.

Which Stages of Credit Underwriting Can Be Automated?
Almost every stage of credit underwriting allows for some degree of automation. For example: data validation, policy application, risk assessment, application prioritization, decision recommendation, and exception detection. What changes from one stage to another is how much autonomy it makes sense to give the system.
Credit decisioning is also one of the areas where the most experimentation is happening. According to McKinsey, most institutions are testing generative AI in early warning alerts and credit decisions. Even so, none of the banks surveyed had fully deployed information synthesis for credit decisions. By contrast, 27% were in the pilot stage.
Data Validation and Enrichment
The system verifies that the application is complete and validates the applicant's identity. It also queries external sources, such as credit bureaus. Automating this stage reduces rework for the team. That way, analysts spend their time evaluating data, not completing it.
Credit Policy and Rule Application
The institution's minimum requirements are translated into explicit rules. For example, amounts, terms, eligible profiles, or debt limits. The system applies those rules the same way every time. As a result, two identical applications receive the same treatment.
Risk Model Evaluation
Risk models estimate the likelihood of repayment based on the available data. This stage is the one most associated with AI-powered risk analysis. However, it is only one part of the underwriting process. To see how these models are applied, you can read our article on machine learning in finance.
Application Classification and Prioritization
The system ranks applications by risk, amount, or urgency. This determines which ones are resolved first and which require more attention. As a result, the credit team focuses its time where it adds the most value.
Decision Recommendation or Execution
In the simplest cases, the system executes the decision directly. In all others, it recommends the decision and leaves the final say to an analyst.

Exception Detection
The system identifies applications that don't fit any rule. It also flags contradictory data or cases in zones of uncertainty. Catching these exceptions early prevents automated decisions on cases that need human judgment.
What to Automate and What to Escalate: Autonomy Levels in Credit Decisions
Automated credit decisions work best when they are organized by autonomy levels. High-confidence, low-risk applications are resolved automatically. Those with intermediate confidence, in turn, receive an assisted decision. Finally, exceptions and high-risk cases are escalated to human review. With AI-powered risk analysis, the key is to define those levels before automating.
A practical way to structure this definition is the credit autonomy matrix. It is a map that crosses the system's confidence with the risk of the decision. Based on that intersection, the matrix defines who decides in each case.
Level | Criteria | Who decides |
Level | Criteria | Who decides |
Automatic decision | High confidence and low risk | The system, within defined rules and thresholds |
Assisted decision | Intermediate confidence | An analyst, with the system's recommendation |
Human review | Exception, uncertainty, or high risk | An analyst or a committee, with all information on record |
The credit autonomy matrix also helps clarify what human in the loop means. It doesn't mean a person reviews every application. In fact, that would defeat the benefit of automating. Rather, it means defining the points where human intervention adds the most value. It also means making sure the analyst has the context needed to decide well.
Do you know what level of autonomy your credit process is at today?
An assessment of your decision flow shows which applications could already be resolved with AI-powered risk analysis.
How to Design a Credit Decision Engine That Keeps You in Control
A credit decision engine stays in control when it separates three elements. On one hand, what the model estimates. On the other, what the rules establish and what business policy defines. To that separation, add explicit thresholds, exception routes, and controlled overrides.
Separate Risk Models, Rules, and Business Policies
The risk model estimates, but it doesn't decide. Business policy determines what to do with that estimate. For example, what score warrants approval, under what conditions, or when to escalate. This separation allows you to adjust policy without retraining the model. Likewise, it allows you to review the model without altering business rules.
Define Decision Thresholds
Thresholds determine when an application moves from one autonomy level to another. That's why they need to be explicit and documented. It's also a good idea to review them periodically using real performance data.
Design Exception Routes
Each type of exception needs a defined path. That is, who it gets routed to, with what information, and within what timeframe. An exception without a route ends up being resolved informally. And that is exactly what automation was meant to avoid.
Allow Controlled Overrides
An analyst must be able to correct a system decision. However, they must always record the reason for the change. Overrides aren't a system failure. On the contrary, they are a source of learning for adjusting rules, thresholds, or models.
Bringing AI-powered risk analysis into a decision engine requires combining models, rules, integrations, and governance. That is the approach behind custom AI solutions focused on automated evaluation.
How Do You Explain and Audit an Automated Credit Decision Made with AI?
To explain a credit decision made with AI-powered risk analysis, the institution must be able to reconstruct it. That is, it must know why an application ended up approved, rejected, or escalated. To do that, it must preserve every step of the journey, from the input data to human intervention.
Trust in results is another barrier to scaling. According to McKinsey, more than two in five institutions slowed down projects because of disappointing results. In addition, 41% cited model validation issues as an obstacle.

Record Every Decision
Every decision, whether automated or manual, must be recorded with the same structure. Without that record, explainability depends on people's memory. Or, at best, on partial reconstructions.
What to Keep to Reconstruct a Decision
Full traceability of a credit decision includes:
- the input data and the sources consulted;
- the model's score or estimate, with its version;
- the rules and policies that were applied;
- the resulting decision and its autonomy level;
- the exception detected, if any;
- the human intervention and its justification;
- the subsequent outcome of the loan.
The credit decision log serves two purposes. On one hand, it makes it possible to respond to internal audits or regulatory requirements. On the other, it enables continuous improvement of the system. It shows where rules fail and where overrides are concentrated. It also reveals which automated decisions led to poor subsequent outcomes.
Do You Have to Replace the Core to Automate Underwriting?
Not necessarily. Automating underwriting doesn't require replacing the lending core or existing systems. In many cases, the most efficient approach is to add a decisioning layer on top of the current infrastructure.
A decisioning layer can coordinate what the institution already has:
- the lending core;
- rules engines;
- credit bureaus;
- KYC/AML validations;
- legacy systems;
- machine learning models.
Replacing the entire stack usually means long, costly projects with high operational risk. By contrast, a modular, API-based architecture makes it possible to modernize the decision process without touching what works. In 2024, McKinsey analyzed institutions that combined modular architecture with reuse of existing components. Those institutions reported generative AI deployments that were 30% to 50% faster. Its 2025 study, moreover, once again recommends modular architecture as a key step for scaling.
Companies specializing in fintech software, like Crombie, typically implement AI-powered risk analysis with this approach. For example, in digital lending projects, they integrate the decision engine with the client's infrastructure. They also automate progressively, rather than proposing a complete replacement.
What Metrics Show Whether Automated Underwriting Is Working?
Automated underwriting works when it improves the decision process, not just the model's accuracy. That's why the most useful metrics measure how many applications are resolved without intervention. They also measure how long each decision takes and how many are escalated or corrected. Finally, they evaluate how automatically approved loans perform afterward.
Metric | What it indicates | Warning sign |
Metric | What it indicates | Warning sign |
Straight-through processing (STP) rate | Percentage of applications resolved without human intervention | A very high value with poor subsequent performance |
Time to decision | End-to-end process speed | Delays concentrated in certain stages |
Escalation rate | Percentage of applications referred to review | Sustained growth with no changes in the portfolio |
Exception rate | Frequency of cases that don't fit the rules | Repeated exceptions of the same type |
Override rate | How often analysts correct the system | High overrides at a single autonomy level |
Decision consistency | Whether similar cases receive the same decision | Different outcomes for equivalent profiles |
Subsequent performance | Repayment behavior of approved loans | Deterioration in automatically approved loans |
Automated underwriting metrics should be read together, never in isolation. For example, a high override rate may indicate poorly calibrated thresholds. Likewise, repeated exceptions of the same type usually signal that a rule is missing.
Step by Step: How to Automate Credit Underwriting
Moving to AI-powered risk analysis doesn't start with choosing a model. It starts, instead, with understanding how the institution decides today. The path goes from mapping current decisions to automating them progressively.
Moving gradually is, in fact, the most popular strategy. According to McKinsey, 36% of institutions are betting on incremental adoption of generative AI. In addition, the most advanced ones start with the lowest-risk use cases.
- Map current decisions: Identify which decisions are made, who makes them, and with what information.
- Make rules and policies explicit: Document the criteria analysts apply, including those that aren't written down.
- Connect data and models: Integrate internal and external sources with the available risk models.
- Define autonomy levels: Build the credit autonomy matrix for each type of application.
- Design exception routes: Establish who each case is routed to and with what information.
- Implement traceability: Record every decision with the same structure from day one.
- Automate progressively: Start with the lowest-risk cases. Then, expand autonomy when the metrics justify it.
The fundamental difference is one of approach. It's not about implementing AI, but about designing a decision system. In that system, AI plays a defined role.
Why Can't the Most Advanced Credit Underwriting Be Fully Automated?
More automation doesn't always mean better decisions. The institutions with the best results aren't necessarily the ones that eliminate all human intervention. Rather, they're the ones that define precisely when the system can decide on its own. And also when an analyst's judgment still makes the difference.
AI-powered risk analysis is a key piece of that system. However, it isn't enough on its own. What sustains the result is the design of the decision. That is: clear rules, explicit thresholds, exceptions with an owner, and recorded decisions. In a context of accelerating financial innovation, that is the difference between automating and automating with control.
The most advanced underwriting won't be the one that eliminates the most human intervention. It will be the one that knows exactly when it doesn't need it.
Do you know which decisions in your credit process could be automated today?
Schedule an assessment with the Crombie team and discover how to move your institution to AI-powered risk analysis.
Frequently Asked Questions About Underwriting and AI-Powered Risk Analysis
Underwriting and AI-Powered Risk Analysis Basics
Credit underwriting is the process that decides whether a credit application is approved, rejected, or escalated. It also defines the conditions under which credit is granted. At a fintech, it turns risk assessment into fast, consistent decisions. That's why, when properly automated, it allows you to grow in volume without losing control over the portfolio.
Credit risk analysis estimates how likely it is that an applicant will repay. Underwriting, on the other hand, uses that estimate to decide: approve, reject, or escalate. That's why good risk analysis is necessary, but not sufficient. The quality of the decision also depends on policies, thresholds, and exception management.
Credit scoring assigns a score that summarizes an applicant's risk level. Credit decisioning, on the other hand, combines that score with business rules and policies. It then executes a concrete decision. In other words, scoring informs, and decisioning decides.
No. AI-powered risk analysis automates high-confidence, low-risk decisions. However, analysts remain key in exceptions and high-risk cases. What changes is their role: they spend more time on the cases where their judgment adds value.
Human in the loop means the decision system includes defined points of human intervention. It doesn't mean a person reviews every application. Rather, it's designed in advance for when the system decides and when an analyst does. This combines the speed of automation with the judgment of the credit team.
Traceability is the ability to reconstruct how a credit decision was reached. It includes the input data, the model's output, the rules applied, and human intervention. Without traceability, an automated decision can't be explained or audited. In addition, the system can't learn from its own mistakes.
How to Decide What to Automate in Credit Underwriting
High-confidence, low-risk applications should be automated. On the other hand, exceptions and cases of uncertainty should be escalated to human review. However, the cutoff point isn't universal. It depends on your credit policies, your risk appetite, and the quality of your data. That's why, before automating, it's worth mapping how your team decides today.
Thresholds are defined based on credit policies and risk appetite. They are then validated with real performance data and reviewed periodically. Calibrating them well requires knowing your portfolio and your current decision flow. That's why it's best to analyze them case by case before setting them.
In general, it's best to start with the stages that have the heaviest manual workload and the lowest risk. For example, data validation or rule application on standard applications. With an API-based integration, those stages can be automated without modifying the core. Which stage to prioritize depends on where the delays in your process are concentrated today.
Exceptions are handled with defined routes for each type of case. Each route establishes a recipient, the required information, and a resolution timeframe. In addition, every resolved exception provides data to adjust rules or thresholds. The design of those routes depends on your credit team and your portfolio.
It is audited by reconstructing its full journey. That is, the input data, the model's output, the rules applied, and the decision. Also, the human intervention, if there was any. To do that, the system must record every decision with the same structure from the start.
The most useful metrics measure the decision process, not just the model. For example, the straight-through processing rate, time to decision, and escalation rate. Also the override rate and the subsequent performance of approved loans. No single metric is enough on its own; that's why they should be read together.
Implementing a Credit Decision Engine
You need explicit credit policies, integrated data, and risk models. You also need defined autonomy levels, exception routes, and a decision log. The scope depends on your systems, the quality of your data, and your application volume. To size it for your case, you can schedule a meeting with the Crombie team.
It's worth asking how they integrate the decision engine with your existing systems. Also, how they handle traceability and how they design rules and exceptions, in addition to models. Companies specializing in fintech software, like Crombie, typically work on top of the client's infrastructure rather than replacing it. If you want to evaluate your case, you can schedule a conversation with their team of experts.
Scope is estimated based on three variables. First, how many types of decisions will be automated. Second, which systems need to be integrated. Third, what state the data is in.
The safest way to move to AI-powered risk analysis is to automate progressively. First, the lowest-risk cases are automated, and the results are validated. Then, autonomy is expanded when the metrics justify it. In addition, a common practice is to run the engine in parallel before enabling it to make decisions.
0 comments
·
18 min Read