Back to research
AI Tools

AI Underwriting: Where Faster Credit Decisions Are Credible

A practical evidence framework for faster credit decisions, alternative data, adverse-action explanations and model risk.

Updated 8 min read
In this research

Machine learning can shorten parts of a credit decision when identity, income and account data arrive in structured form. It does not guarantee an instant approval, a lower default rate or a fairer outcome. Those results depend on the product, applicant mix, model, operating controls and the evidence collected after deployment.

The useful question is therefore not whether "AI underwriting" is faster in the abstract. It is which steps can be automated safely, which applications should be referred to a person, and whether the lender can reproduce and explain every outcome. This article sets out that decision framework without treating vendor case studies as universal evidence.

The data advantage

Cash-flow data can add signals that a bureau file does not contain: income regularity, recurring commitments, returned payments and overdraft use. A simple illustration is two applicants with the same monthly income but different buffers after essential spending. That difference may be relevant, but only if the feature is lawful, stable, accurately categorised and demonstrably predictive for the lender's population.

Open-banking APIs can supply permissioned transaction histories. In the UK, the number of consumers and small businesses regularly using open banking passed ten million in 2024[1]. That adoption statistic shows that the data rail exists; it does not show that any particular underwriting model is accurate. Lenders still need a lawful basis, clear consent or other applicable permissions, reliable transaction categorisation and a fallback for applicants who cannot or do not use the rail.

How the models actually work

There is no single model family that dominates every lender and product. The Bank of England and FCA survey of machine learning in UK financial services[2] found ML used both to support lending decisions and as an input to automated retail underwriting. A lender might use a scorecard, gradient-boosted trees or another model, but the choice must be justified against predictive performance, stability, fairness, operational complexity and the ability to give accurate reasons.

In the United States, Regulation B requires specific principal reasons for adverse action[3]. The requirement applies to the creditor's decision process, not to a particular model type: a generic score or post-hoc attribution chart is not enough if it does not accurately describe factors the creditor actually considered or scored.

The second unglamorous truth is that the algorithm is rarely the differentiator. Feature engineering, turning raw bank transactions into signals like days-in-overdraft per quarter, gambling-spend ratio, or income-source concentration, is where the proprietary value sits. Two lenders running the same algorithm over differently engineered features will write materially different loan books.

What the evidence shows so far

Vendor studies may report more approvals, lower pricing or faster decisions, but those are first-party results for a particular model and comparison set. They should be treated as hypotheses for a lender's own controlled test, not evidence that alternative data expands access for every group. A credible evaluation reports approval rate, loss and arrears outcomes, pricing, overrides and error rates by relevant customer segment over a stated period.

Models can also degrade when applicant behaviour or economic conditions move away from their training data. Monitoring should therefore cover input drift, calibration, approval and decline distributions, overrides, arrears, losses and customer outcomes. A challenger model can be useful, but it does not replace limits, human escalation and a tested rollback route.

Traditional credit scorecards compared with AI cash-flow underwriting, across five decision dimensions.
Dimension Traditional scorecard AI cash-flow underwriting
Primary data Bureau score, declared income Bureau data plus open-banking transaction history
Decision time Can include document collection and manual review Potentially faster for complete, low-complexity cases
Thin-file applicants May have limited bureau evidence May add permissioned cash-flow evidence
Model type Fixed rules / logistic scorecards Use-case-dependent ML with validated explanations
Main failure mode Limited or stale features Drift, proxy bias and unreliable explanations

The regulatory squeeze

The EU AI Act[4] lists certain systems used to evaluate a natural person's creditworthiness or establish a credit score as high-risk, subject to the regulation's scope, qualifications and exceptions. Following the 2026 AI Omnibus, the core Annex III high-risk requirements apply from 2 December 2027; affected firms are preparing now rather than treating those duties as already operative. In the US, equal-credit and fair-lending obligations apply regardless of the technology. In the UK, the FCA's Consumer Duty[5] focuses firms on customer outcomes. Product-specific legal advice is still required; "AI" is not a separate permission or exemption.

Where it spreads next

SME credit is a plausible use case because permissioned bank and accounting data can reduce document handling and support cash-flow analysis. Whether a facility is economic to automate depends on acquisition cost, expected loss, fraud, servicing cost, funding and margin; no universal loan-size threshold makes the model profitable.

Mortgages and other complex products add property, affordability, documentation and legal steps that a fast model score cannot remove. An "instant" agreement in principle should not be confused with completion of the full underwrite. The automation boundary should be defined per product and customer risk, not as an industry-wide destination.

What this means for incumbents

A bank can build, buy or combine components. A defensible rollout begins in shadow mode, freezes the comparison policy, records disagreements and overrides, and moves only bounded cohorts after pre-agreed outcome checks. Procurement must also cover data rights, model changes, incident handling, audit access and an exit path; outsourcing a score does not outsource accountability.

Where AI is landing across fraud, servicing and compliance is mapped in our evidence-led guide to AI in financial services in 2026. For underwriting, speed is a useful operating metric only after accuracy, fairness, explainability and customer outcomes are shown to hold.

Evidence standard. Industry-use claims were checked against the Bank of England/FCA survey; US adverse-action requirements against current Regulation B; EU classification and timing against the official AI Act and 2026 amending regulation; and UK outcomes expectations against the FCA. Vendor performance claims are intentionally not used as market-wide benchmarks.

Sources

Numbered references are anchored to the specific claims they support. Primary documents are preferred wherever available.

  1. regularly using open banking passed ten million in 2024 openbanking.org.uk
  2. Bank of England and FCA survey of machine learning in UK financial services bankofengland.co.uk
  3. Regulation B requires specific principal reasons for adverse action consumerfinance.gov
  4. EU AI Act eur-lex.europa.eu
  5. Consumer Duty fca.org.uk

Frequently asked questions

Which credit applications are suitable for faster automated decisions?

Complete, lower-complexity applications with verified data and a model validated for that product and population are the clearest candidates. Policies should route missing, conflicting, vulnerable-customer or out-of-distribution cases to an appropriate human review rather than forcing every application through one automated path.

Can open-banking data replace a credit-bureau file?

Not as a universal rule. Permissioned transaction data can add current cash-flow evidence, but coverage, categorisation and history vary. A lender should test the incremental value for its own applicants and provide a fair route for people who cannot or choose not to share an account feed.

What evidence should a lender require before rollout?

At minimum: a frozen comparison policy, held-out and prospective performance, calibration, approval and loss outcomes, subgroup testing, explanation accuracy, override analysis, drift limits and a rollback plan. Vendor-reported approval or default improvements are not a substitute for that lender-specific evidence.

How should an AI-supported credit denial be explained?

The explanation should state the accurate principal factors that actually drove the decision in language the applicant can understand. In the United States, the CFPB says a complex or opaque algorithm does not remove this obligation; a generic score or the closest item on a template may be insufficient.

AIlendingcredit scoring

The CloudFintech Briefing

Independent fintech analysis — AI in banking, payments, crypto, and regulation. No spam, unsubscribe any time.

By subscribing you agree to our Privacy Policy.