Skip to main content
Get in Touch

AI Governance Checklist for Lenders: What Binds in 2026

The AI governance checklist sitting in your runbook almost certainly cites two things: SR 11–7 and a 2 August 2026 EU deadline. One was rescinded in April. The other moved by sixteen months. Neither event removed a single control you actually owe. What they did was scatter the map — the obligations are still there, but they now sit in eight different instruments instead of two convenient ones, and roughly half the guidance published on this topic still points at the old pair.

AI governance checklist for lenders 2026 - what binds, what is deferred, what is expected

This article rebuilds the checklist from the instruments that are in force today: 25 controls, what binds each one, the evidence artifact that closes it, and who signs it. It is the line-by-line companion to our audit-survival playbook (opens in new tab), which carries the narrative of what changed and why. The hard column is not the control — it is the evidence, and whether your architecture produces it as a by-product of running or forces someone to assemble it the week before an examination. That is an architectural question before it is a legal one, and it is why a lender on a Building Platform answers it differently from a lender on multi-tenant SaaS. The last third of this article is about that difference.

Verified as of 25 August 2026

Every row below was checked against the primary instrument on the date of publication. If a checklist you are working from disagrees with this table, the checklist is out of date, not the table.

AnchorStatus as of 25 Aug 2026What changed itDate
Fed SR 11–7 / OCC 2011–12 / FDIC FIL-22–2017RescindedSR 26–2 / OCC Bulletin 2026–13 / FIL-15–2026 (opens in new tab)17 Apr 2026
SR 21–8 (BSA/AML model risk)Rescinded, no replacementSame instrument17 Apr 2026
OCC 1997–24 (Credit Scoring Models)RescindedOCC Bulletin 2026–1317 Apr 2026
Generative and agentic AI under US model-risk guidanceExpressly out of scopeSR 26–2 attachment17 Apr 2026
EU AI Act Annex III high-risk (credit scoring)Deferred to 2 Dec 2027Regulation (EU) 2026/1744 (opens in new tab)In force 27 Jul 2026
EU AI Act Annex III point 5(b) classificationUnchanged
CFPB Circulars 2022–03 and 2023–03WithdrawnFR Doc 2025–08286 (opens in new tab)12 May 2025
12 CFR 1002.9 (adverse action)Unamended, in force
Regulation B disparate impactRemoved from § 1002.6(a), under litigationFR Doc 2026–07804 (opens in new tab)Effective 21 Jul 2026

How to check this table against source, and what it is not. Every row names the instrument that moved the position, so each is verifiable without taking our word for it: the April 2026 US rescissions are listed by document number inside OCC Bulletin 2026–13 (opens in new tab) and its Federal Reserve and FDIC counterparts, SR 26–2 (opens in new tab) and FIL-15–2026; the EU deferral is Recital 40 of Regulation (EU) 2026/1744 (opens in new tab); the circular withdrawals are FR Doc 2025–08286 (opens in new tab); the Regulation B amendment is FR Doc 2026–07804 (opens in new tab). Where a position depends on pending litigation or on drafting that is still settling, the row and the text below say so explicitly.

This is a compliance-engineering reference, not legal advice. It sets out what the instruments say and which artifact evidences each control. Whether a given obligation applies to your institution turns on facts we cannot know — asset size, EU nexus, GSE relationships, states of business, product mix — and several rows below change answer depending on them. Take the mapping; take the applicability question to your own counsel.

Three of those rows are the ones that break most published checklists. Guidance that still describes SR 11–7 as current is describing a rescinded instrument. Guidance that still gives 2 August 2026 as the Annex III deadline is sixteen months out. And guidance that cites CFPB Circular 2023–03 as a live requirement is citing a document the Bureau withdrew in May 2025 — which does not mean the underlying duty went anywhere, as we will get to.

Both anchors of the standard AI lending checklist moved in 2026

This section is deliberately compressed. If you want the narrative — what the reset means strategically, and how to survive an examination through it — that is the audit-survival playbook (opens in new tab). What follows is only what you need to read the checklist correctly.

SR 11–7 was rescinded, and its replacement excludes the AI you are actually deploying

On 17 April 2026 the Federal Reserve, the OCC and the FDIC issued SR 26–2, OCC Bulletin 2026–13 and FIL-15–2026, rescinding the 2011 interagency model-risk framework along with SR 21–8, OCC 2011–12, OCC 2021–19, the Model Risk Management booklet of the Comptroller’s Handbook, FIL-22–2017 and FIL-27–2021 (OCC Bulletin 2026–13, 2026 (opens in new tab)).

Four sentences in the new instrument determine how you read every US row of the checklist below.

First, on scope: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” Second, on enforceability: the guidance “does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism.” Third, on audience: it is framed as “most relevant to banking organizations with over \$30 billion in total assets.” Fourth, and least noticed, the definition of a “model” was narrowed to exclude deterministic, rule-based processes (OCC Bulletin 2026–13, 2026 (opens in new tab)SR 26–2, 2026 (opens in new tab)).

Two points about the instrument itself are worth stating plainly, because they are the first things a general counsel will test. The rescission is the operative act. SR 26–2 is supervisory guidance, not a legislative rule; it did not go through notice and comment and it creates no cause of action. What it does with practical effect is withdraw the earlier guidance — which is why the rescinded documents no longer appear as current on the agencies’ sites, and why a policy that cites SR 11–7 now cites nothing. And the successor disclaims its own enforceability, in its own words. So the accurate reading is not “the standard changed.” It is “the standard was withdrawn, and what replaced it does not function as a standard.” That distinction is the entire reason the checklist below is built from binding instruments and keeps guidance in a separate, clearly labelled basket.

There is a fifth item almost nobody has picked up. The same bulletin rescinded OCC 1997–24, Credit Scoring Models — the one piece of US supervisory guidance written specifically about credit scoring. Its withdrawal is not mentioned in most of the commentary on the April reset (OCC Bulletin 2026–13, 2026 (opens in new tab)).

The EU deadline moved. The classification did not.

Regulation (EU) 2026/1744 (opens in new tab) was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026. Recital 40 sets out precisely what it defers: only Chapter III, Sections 1 to 3 — Articles 6 through 27 — pushing Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028.

Annex III point 5(b) (opens in new tab) itself was not touched. AI used to evaluate the creditworthiness of natural persons, or to establish their credit score, is still high-risk. The Article 6(3) filter — the route by which a system can argue it does not pose significant risk — is unavailable here, because profiling of natural persons is always high-risk. The clock moved; the classification did not.

The CFPB withdrew its AI circulars. The duty is in the regulation, not the circular.

Circulars 2022–03 and 2023–03 — the two documents every AI-lending article cited for “algorithmic complexity is not a defense” — were withdrawn on 12 May 2025 (FR Doc 2025–08286 (opens in new tab)). Three of the three competitor pages we checked that mention those circulars still present them as live requirements.

They are not. But the circulars were always interpretive: they explained an obligation that lives in the regulation. 12 CFR § 1002.9 (opens in new tab) has not been amended. The requirement to give a declined applicant the specific principal reasons for the decision, within 30 days, is exactly where it was.

Separately, the CFPB’s Regulation B final rule (FR Doc 2026–07804 (opens in new tab), published 22 April 2026, effective 21 July 2026) removed disparate impact from § 1002.6(a) and deleted comment 2(p)-4, which defined credit scoring systems. That rule is currently under challenge — NFHA v. CFPB was filed on 27 May 2026 in the District of Columbia, and as of 10 August 2026 no stay or vacatur had been issued. The accurate formulation for your policy documents is “removed from Regulation B and currently under challenge,” not “disparate impact no longer applies.”

The operational conclusion is narrower than the headline, and it matters more than the legal debate. A provision removed from a federal regulation and simultaneously challenged in federal court is not a safe basis for retiring a control. State fair-lending statutes, state UDAP regimes and private plaintiffs continue to plead disparate impact regardless of the federal position, and the OCC’s Fair Lending handbook (opens in new tab) — which addresses machine learning and alternative data directly — remains in force even though the model-risk booklet was withdrawn alongside SR 11–7. Controls D2 and D3 below are therefore written to hold whichever way NFHA v. CFPB resolves: keep the bias testing and the proxy review, keep the results, and do not create a gap in the evidence trail that a later ruling would make you explain.

The gap this opens, and who falls into it

Put the three scope limits of SR 26–2 side by side and a hole appears that nobody in the market seems to be naming.

The guidance is most relevant above \$30 billion in assets. Generative and agentic AI are outside its scope. Non-compliance will not result in supervisory criticism. Stack those, and a \$4 billion credit union running a generative AI assistant in servicing today has no applicable federal model-risk guidance at all — not lighter guidance, not risk-based guidance, none. The same is true of a mid-sized community bank piloting an agentic tool in collections, and of a fintech lender whose scoring vendor added an LLM layer to its document processing.

That is a governance vacuum, not a governance holiday, and it is worth being precise about why. Governor Bowman’s remarks of 1 May 2026 make the supervisory intent plain in both directions: “supervisory guidance should not be a barrier for banks to engage with new and evolving tools and technologies” — and, in the same breath, that supervisors continue to look closely where AI “directly affect[s] consumers and customers, as with credit determinations.” Credit determinations are the named example. The withdrawal of a model-risk framework is not a statement that credit AI is unsupervised; it is a statement that it will be supervised through other lenses — consumer protection, fair lending, third-party risk, operational resilience and board governance.

The European picture is not more comfortable. The ECB’s Supervision Newsletter of November 2025 (opens in new tab) reported that of thirteen significant institutions surveyed, only around half had dedicated AI oversight arrangements in place — and that was before the deferral gave everyone a reason to slow down.

The practical conclusion for the checklist below: rescinding a supervisory document did not dissolve your board, your internal audit function, your investors or a plaintiff’s counsel. Every one of those four still asks for evidence, and none of them accepts “the guidance was withdrawn” as an answer.

“The reset did not make governance optional. It made it unsourced. There is no longer a single document you can hold up and say ‘we follow this’ — so the burden shifts from citing a framework to producing evidence. That is a harder standard, not an easier one, and it favours lenders who can show what the system did rather than describe what the policy says.”

— Dmitriy Wolkenstein, CEO, TIMVERO

What did not move: the binding layer

These are obligations in force today, enforceable, with named articles. Nothing in the 2026 reset touched any of them.

ECOA and Regulation B § 1002.9 — specific principal reasons

A declined applicant is owed notice within 30 days, and the statement of reasons “must be specific and indicate the principal reason(s) for the adverse action” (12 CFR § 1002.9 (opens in new tab)). The long-standing interpretation is that the reasons must “relate to and accurately describe the factors actually considered or scored.” That last clause is where AI-driven scoring gets caught: a reason code that names a factor the model did not actually weight, or that summarises a composite the model built internally, does not satisfy the standard. This is the single most commonly failed control on the list, and the withdrawal of Circular 2023–03 changed nothing about it.

FCRA — permissible purpose, accuracy, adverse action, risk-based pricing

The Fair Credit Reporting Act touches an AI underwriting stack at several points: permissible purpose for pulling a report (§ 1681b), reasonable procedures to assure maximum possible accuracy (§ 1681e(b)), dispute handling (§ 1681i), furnisher obligations (§ 1681s-2), adverse action notice where a consumer report was used (§ 1681m(a)), and risk-based pricing notices (§ 1681m(h) with Regulation V §§ 1022.70–75 (opens in new tab)). Where a model ingests bureau data — or where an alternative data provider is itself a consumer reporting agency — these apply to the AI stack exactly as they apply to anything else.

The AVM rule — the one algorithm-specific binding US rule

Six agencies issued the automated valuation model quality control rule (FR Doc 2024–16197 (opens in new tab)), with compliance required from 1 October 2025. It sets five quality control factors, and the fifth is a direct non-discrimination requirement attached to an algorithmic system.

This is worth pausing on, because it is the cleanest counterpoint to the “the US rolled everything back” narrative. In the same year that model-risk guidance was rescinded, the one binding, algorithm-specific US rule in lending came into force and stayed there. Anyone telling you the US deregulated AI in lending in 2026 has not read the AVM rule.

What 2 August 2026 actually started in the EU

Half the market read the deferral as “nothing to do until December 2027.” The other half is still working to an August 2026 deadline that no longer applies to Annex III. Both are wrong, and the correct answer is more interesting than either.

The deferral covered Chapter III Sections 1–3 only. Everything else that was scheduled for 2 August 2026 applied on schedule:

  • Article 50 (opens in new tab) — transparency obligations. If a borrower interacts with your AI chat assistant, or your system generates synthetic content, disclosure obligations are live now.
  • Articles 40–49 — standards, conformity assessment and, notably, Article 49 registration.
  • Chapter VI and Chapter VIII — including the EU database provisions.
  • Chapter IX — market surveillance, Article 73 serious incident reporting, and Article 86, the right to explanation of individual decision-making.
  • Article 101 — penalties for providers of general-purpose AI models.

Article 86 (opens in new tab) deserves emphasis. The right of an affected person to obtain an explanation of the role of an AI system in a decision that produces legal effects is applicable now, not in December 2027.

GDPR Article 22, SCHUFA and Dun & Bradstreet — the explanation standard already exists

Two CJEU judgments settled what “explanation” means in a credit context, and they did it before the AI Act’s substantive obligations were ever due.

In C-634/21 (SCHUFA, 7 December 2023) (opens in new tab) the Court held that the production of a probability value by a credit bureau is itself an automated individual decision within Article 22 GDPR, where the lender “draws strongly” on that value in deciding whether to contract. The bureau cannot hide behind the lender, and the lender cannot hide behind the bureau.

In C-203/22 (Dun & Bradstreet Austria, 27 February 2025) (opens in new tab) the Court set the content of the explanation: the data subject is owed the procedure and principles actually applied — which of their personal data were used and in what way — expressed in a concise, intelligible form. Not the algorithm. Not the formula. And critically, a claim of trade secrecy is not a refusal: it is a route to have the disputed information provided to the supervisory authority or the court, which then balances the interests.

If your vendor’s answer to “explain this decision” is “that is proprietary,” the CJEU has already told you where that argument ends.

DORA — your scoring vendor is an ICT service supporting a critical function

The Digital Operational Resilience Act (Regulation (EU) 2022/2554 (opens in new tab)) has applied since 17 January 2025 — two and a half years before the AI Act’s high-risk obligations arrive. If you are an EU financial entity, an externally hosted scoring or decisioning service is an ICT third-party service, and if it supports a critical or important function, DORA requires: an entry in the register of information, the contractual provisions of Article 30(3), participation in threat-led penetration testing where applicable, and a documented, tested exit strategy.

Most AI vendor questionnaires we see are built for the AI Act and ignore DORA, which is backwards: DORA binds now.

CCD2 Article 18(8) — from 20 November 2026, a year before the AI Act

The second Consumer Credit Directive (Directive (EU) 2023/2225 (opens in new tab)) applies from 20 November 2026. Article 18(8) gives a consumer whose creditworthiness assessment involved automated processing the right to request and obtain human intervention, to receive a meaningful and comprehensible explanation of the assessment including the logic and risks involved, and to contest the assessment and the decision.

That is, in substance, most of what people expect from the AI Act’s Article 86 — arriving a year earlier and, because Article 86(3) is subsidiary to more specific EU law, likely to be the operative instrument for consumer credit in the member states.

(Paraphrased with attribution; the paragraph number is confirmed against the Directive, the verbatim OJ text is not reproduced here.)

Your investors already made this binding

For US mortgage, the enforceable requirement did not come from a regulator at all. Fannie Mae’s Lender Letter LL-2026–04, issued 8 April 2026 and effective 6 August 2026, requires seller/servicers to maintain written AI/ML governance policies with an annual review, a designated owner, flow-down of equivalent standards to vendors, subcontractors and third-party originators, and disclosure of AI use on request (Fannie Mae, 2026 (opens in new tab)). Freddie Mac’s parallel requirements (Guide §§ 1302.2 and 1302.8 (opens in new tab)) took effect 3 March 2026.

Contractual obligations to the GSEs are, in practice, the most reliably enforced AI governance requirements in the US market today. They arrived through a channel most compliance teams do not monitor for AI policy.

What moved, but is dated

DateWhat arrivesWho it binds
20 Nov 2026CCD2 Art. 18(8) (opens in new tab): human intervention, meaningful explanation, right to contestConsumer credit providers in EU member states
1 Jan 2027Colorado SB 26–189 (opens in new tab)Developers and deployers of high-risk AI in consequential decisions, including banks and credit unions
1 Jan 2027California CCPA ADMT rules (opens in new tab) for significant decisionsCCPA-covered businesses making automated significant decisions
2 Dec 2027EU AI Act Ch. III §§ 1–3 (opens in new tab) for Annex III (credit scoring)Providers and deployers of credit-scoring AI in the EU
2 Aug 2028EU AI Act Ch. III §§ 1–3 for Annex I (embedded systems)Providers of AI embedded in regulated products

Inside the EU AI Act itself, the deferral did not move the Act as a whole — it moved three sections of one chapter. For a credit-scoring deployer the split is article by article, and it is worth having on one screen before anyone plans a programme around “December 2027”:

EU AI Act provisionStatus for a credit-scoring deployer
Art. 4 — AI literacyApplies now (since 2 Feb 2025)
Art. 50 — transparency toward the person interacting with the systemApplies now (since 2 Aug 2026)
Arts 40–48 — harmonised standards, conformity assessment machineryApplies now
Art. 49 — registrationApplies now — but see the note below
Art. 73 — serious incident reportingApplies now
Art. 86 — right to an explanation of individual decision-makingApplies now
Arts 99, 101 — penaltiesApplies now
Art. 9 — risk management systemDeferred to 2 Dec 2027
Art. 10 (with the new Art. 4a) — data and data governanceDeferred to 2 Dec 2027
Art. 11 + Annex IV — technical documentationDeferred to 2 Dec 2027
Art. 12 — automatic loggingDeferred to 2 Dec 2027
Art. 13 — instructions for useDeferred to 2 Dec 2027
Art. 14 — human oversightDeferred to 2 Dec 2027
Art. 15 — accuracy, robustness, cybersecurityDeferred to 2 Dec 2027
Art. 17 — quality management system (carve-out at 17(4))Deferred to 2 Dec 2027
Arts 26, 27 — deployer obligations and the FRIADeferred to 2 Dec 2027

The Article 49 note. Registration applies to systems being placed on the market or put into service, while the substantive high-risk duties it presupposes are deferred. The practical effect is that the registration machinery is live before the obligations it registers against bite, and the drafting of the deferral does not resolve the sequencing cleanly. This is one of the places where the honest answer is that the position is unsettled — treat it as a question for counsel and for your national market surveillance authority rather than as a matter this or any other checklist can close for you.

The single most important thing to understand about the December 2027 date is what it did not do: it did not soften a single obligation for credit scoring. Articles 9, 10, 11 with Annex IV, 12, 13, 14, 15, 17, 43, 49, 26 and 27 arrive intact. The deferral bought build time, not scope relief.

The obligations that arrive on 2 December 2027

Two provisions in that set matter disproportionately to a banking audience and are routinely missed.

Article 17(4) (opens in new tab). Financial institutions already subject to internal governance requirements under EU financial services law are deemed to have fulfilled the quality management system obligation — with the exception of points (g), (h) and (i). If you have a functioning three-lines-of-defence model, you are not building a QMS from zero. You are building three specific pieces on top of what you already run.

Article 43(2) (opens in new tab). For Annex III point 5(b) systems, conformity assessment follows the internal control procedure of Annex VI. No notified body is involved. A significant amount of anxiety in the market is about an external certification step that, for credit scoring, does not exist.

The FRIA applies to private lenders — this is the one most people miss

Article 27(1) (opens in new tab) sets out who must carry out a fundamental rights impact assessment, and it has three limbs, not two: “deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and © of Annex III.”

The third limb is a standalone trigger. It does not require you to be a public body or a provider of public services. Point 5(b) is creditworthiness assessment. A commercial bank, a consumer lender, a BNPL provider and a fintech lender are all caught, in their own right, as ordinary private businesses.

We have seen this read the wrong way more often than any other provision in the Act — usually as “the FRIA is for public sector deployers, so it does not apply to us.” It does. The one piece of relief is new Article 27(4), which permits the FRIA to be met by cross-referencing an existing data protection impact assessment where the DPIA already covers the ground. Build them as one document.

The Article 25 trap

Article 25 (opens in new tab) converts a deployer into a provider — inheriting Articles 9 to 17, 43 and 49 — in three situations: you put your own name or trademark on a high-risk system already on the market; you make a substantial modification to it; or you modify the intended purpose of an AI system, including a general-purpose model, such that it becomes high-risk.

Read that third limb against what a lot of lenders are actually doing right now. Taking a general-purpose model and directing it at creditworthiness assessment is the textbook case. So is white-labelling a vendor’s scoring engine under your own brand. The obligations you assumed sat with the vendor move to you, and no contract reallocates them.

State law is not deferred in the same direction

While the federal layer thinned and the EU layer slipped, the state layer tightened.

Colorado. SB 24–205 was repealed and re-enacted as SB 26–189 (opens in new tab), signed 14 May 2026, effective 1 January 2027. The change that matters: the exemption for banks and credit unions was removed. In its place is a narrower safe harbour — where an existing ECOA or FCRA adverse action notice covers the same decision, it satisfies the notification requirement. Your existing notice infrastructure does real work here, which is another reason control B1 below is worth getting right.

California. The CCPA’s automated decision-making technology rules (opens in new tab) apply to significant decisions from 1 January 2027. The GLBA carve-out operates at the level of the information, not the entity — so a financial institution is not exempt wholesale; only GLBA-covered information is.

Texas. TRAIGA took effect 1 January 2026 and excludes federally insured financial institutions. Worth stating plainly rather than carrying as an unexamined burden.

New York. NYDFS AI guidance addresses cybersecurity risk. It is not a credit-decisioning instrument, and treating it as one confuses two different programmes.

What is not binding, but is expected

Nothing in this section is enforceable. All of it is what an examiner, an internal auditor or a diligence team will assume you have.

The principles of SR 26–2 remain the vocabulary of model risk regardless of enforceability: validation across conceptual soundness, outcomes analysis and ongoing monitoring; a model inventory; documentation sufficient for an independent party to understand the model; effective challenge, defined as “critical analysis conducted by objective, informed parties”; and a distinct section on vendor-supplied models. An examiner who spent fifteen years applying SR 11–7 has not forgotten how to read a validation report.

Alongside it: NIST AI RMF (opens in new tab), which Texas TRAIGA elevates into an affirmative defence and which is the most commonly cited voluntary framework in US diligence questionnaires; ISO/IEC 42001 (opens in new tab) as the certifiable AI management system standard, increasingly requested in enterprise procurement; and the interagency request for information on AI, generative AI and agentic AI announced in the April 2026 instruments — announced, not yet issued, with no date.

In Europe, the EBA’s Chair letter and accompanying factsheet (opens in new tab), both dated 21 November 2025, are worth reading and worth describing accurately: they are a letter and a factsheet, not guidelines. Their substance is the identification of four areas where the AI Act creates obligations for financial institutions with no sectoral synergies — that is, where existing financial services regulation does not already cover the ground: human oversight (Article 14), data governance (Article 10), the FRIA (Article 27) and AI literacy (Article 4). Those four are where your gap analysis should start, because they are the ones your existing compliance programme genuinely does not cover.

Three baskets of AI governance obligations for lenders: binding now, deferred but dated, and non-binding but expected

Before the checklist: why it splits into a decision layer and a build layer

The checklist below is not organised by regulator or by jurisdiction, and the reason is structural rather than editorial.

An AI system that builds and changes the lending system and an AI system that makes the credit decision are different things, running at different times, failing in different ways, and — since April 2026 — governed under different frameworks. The first produces configuration: products, policies, rules, integrations. The second produces outcomes about named applicants. Collapsing them into a single object called “our AI” is the most common structural error in lending AI governance, and it is why so many programmes have one weak evidence trail where they should have two strong ones. We set the distinction out in full in AI agent vs credit scoring (opens in new tab).

The regulatory consequence is concrete. A generative or agentic build-time tool sits outside US model-risk scope by the explicit terms of SR 26–2, which means it is governed by whatever framework does apply — change management, SDLC, operational risk, and, in the EU, Articles 25 and 27. A deterministic decision engine sits inside the most defensible position available: it is validatable as a model, reproducible on demand, and it produces the specific reasons Regulation B asks for.

That is why the checklist has a Section B that is entirely the decision layer — reason codes, adverse action, replay, governed as a model — and a Section C that is entirely the build layer — specification, prohibited-factor testing, shadow run, named approval, rollback, governed as a software change. If your programme has only one of those two sections, the missing one is where the finding will come from.

There is one objection to this split that deserves a direct answer, because a European supervisor will raise it. If your build-time AI generates a scoring rule that turns out to discriminate, you have created a discriminatory model, and pointing at “it was only configuration” will not help you. That is correct, and it is exactly why control C2 exists: no AI-generated configuration reaches a shadow run until a deterministic test has screened it against a maintained list of prohibited and proxy factors. The build layer is not exempt from fair lending. It is subject to fair lending through a different control, applied earlier.

The checklist: 25 controls and the evidence that closes each one

Six sections. For each control: what binds it, the artifact that closes it, who owns it and how often it is refreshed. The “what binds it” column uses three labels — [Binding][Deferred, dated] and [Expected] — matching the three layers above.

A. Inventory and classification

#ControlWhat binds itEvidence artifactOwnerCadence
A1A single inventory of every AI/ML system touching the credit lifecycle — origination, scoring, pricing, servicing, collections — explicitly including generative assistants and agentic tools[Binding] Fannie LL-2026–04 written policy; [Expected] SR 26–2 inventory principle; [Deferred] EU Art. 11 + Annex IVInventory export: system, purpose, lifecycle stage, data inputs, named owner, date of entryModel risk / CROQuarterly, plus on any new deployment
A2Risk tiering by influence on the credit decision, not by technical sophistication[Expected] SR 26–2 risk-based approach; [Binding] Fannie annual review requirementTiering methodology document plus the assigned tier and rationale for each systemModel riskAnnual
A3Annex III 5(b) determination per system: does it evaluate the creditworthiness of natural persons?[Binding] classification is unchanged; obligations [Deferred, dated] to 2 Dec 2027Classification memo per system recording the natural-persons test, and where the financial-fraud-detection exception is claimed, the narrow reading that supports itLegal / ComplianceAnnual, plus on change of purpose
A4Provider-versus-deployer role recorded for every system, with the Article 25 triggers tested[Deferred, dated] EU Art. 25Role determination record: own branding? substantial modification? repurposed general-purpose model? — with rationale and legal sign-offLegalAnnual, plus on any vendor or model change

B. The decision layer: explainability and adverse action

#ControlWhat binds itEvidence artifactOwnerCadence
B1Reason codes mapped to the factors the model actually considered or scored[Binding] 12 CFR 1002.9(b)(2) and its interpretationsVersioned mapping table: reason code → model factor → plain-language text, signed off per model versionCredit policy + CompliancePer model version
B2The “specific and principal” test run against notices actually issued[Binding] Reg B § 1002.9Sampled adverse action notices tested back against the stored decision record, with pass/fail and remediationComplianceQuarterly
B3FCRA § 1681m(a) notice wherever a consumer report contributed to the decision[Binding] FCRA § 1681m(a)Notice template, bureau identification, delivery log, and the trigger logic that decides when it firesComplianceQuarterly
B4Risk-based pricing notice, or the credit score disclosure exception, correctly triggered[Binding] FCRA § 1681m(h); Reg V §§ 1022.70–75Trigger logic documentation plus a sample of issued noticesComplianceQuarterly
B5Decision replay: reproduce any individual decision as it stood on the date it was made[Binding] Reg B, FCRA accuracy, GDPR Art. 22 line, CCD2 Art. 18(8) from Nov 2026; [Deferred] EU Art. 12Replay of a named application: inputs, data vintage, model version, configuration version, output, reason codes — produced from the system, not reconstructed by handEngineering + Model riskMonthly spot-check

What “decision replay” actually has to contain (control B5). A replay an examiner accepts is not a screenshot of the decision screen — it is a reconstruction from stored artifacts. Four of them, at minimum:

  1. Code and configuration version — the exact commit or release identifier of the decision logic as deployed on the decision date, not the current one.
  2. Model version and integrity hash — the scorecard, weight set or rule set identifier, with a hash that demonstrates the artifact has not been altered since.
  3. The original request payload — every input exactly as submitted, stored verbatim, not re-derived from the application record afterwards.
  4. External data vintage — the bureau or alternative-data snapshot identifier and timestamp. A re-pull today returns different data and silently invalidates the replay.

Miss any one of the four and you can describe the decision without being able to reproduce it. Regulation B asks what the reasons were; GDPR Article 22 and CCD2 Article 18(8) require you to explain them; Article 12 of the AI Act requires the trace to have been kept. All three assume those four artifacts exist somewhere you can reach.

C. The build layer: change control for AI-generated configuration

#ControlWhat binds itEvidence artifactOwnerCadence
C1Any AI-generated change to lending configuration is handled as a software change under your SDLC, not as a model change[Binding] Fannie LL-2026–04 governance policy; [Expected] the change-management lane SR 26–2 leaves genAI/agentic tools inChange record: specification, generated diff, test evidence, release referenceHead of engineeringPer change
C2No AI-generated configuration reaches a shadow run until a deterministic automated test has screened it for prohibited and proxy factors. The test is code, not review — it fails the build[Binding] ECOA and fair lending apply to the rule, whatever generated it; [Deferred, dated] EU Arts 25, 27 — generating a discriminatory rule makes you the provider of a discriminatory modelTest-suite definition, the maintained prohibited-and-proxy factor list it screens against, and a pass record per generated change stamped with the suite version that ranFair lending + EngineeringPer change; factor list and suite reviewed quarterly
C3Shadow run against historical flows before any change reaches a live borrower[Expected] supervisory expectation for pre-deployment testing; [Binding] DORA testing where the function is criticalShadow-run report: population, period, divergences found, dispositionEngineering + RiskPer change
C4A named human approver gates every release — a role is not a name[Binding] Fannie designated-owner requirement; [Deferred] EU Art. 14 human oversightApproval record: named individual, timestamp, exactly what was approved, what they were shownHead of credit / COOPer change
C5Versioning and tested rollback for configuration and model artifacts[Binding] DORA resilience obligations; [Deferred] EU Art. 12Version register plus evidence of a rollback actually executed in a testEngineeringQuarterly

D. Data, bias and fair lending

#ControlWhat binds itEvidence artifactOwnerCadence
D1Provenance and representativeness of training, validation and test data[Deferred, dated] EU Art. 10(2)–(4); [Binding] FCRA § 1681e(b) accuracy where bureau data is involvedData lineage document per model: sources, collection period, population, known gaps and their treatmentData / Model riskAnnual
D2Bias testing with the result recorded, not just the test run[Binding] ECOA; OCC Fair Lending handbook v1.0 (opens in new tab) (Jan 2023) remains in force; [Deferred] EU Art. 10 and new Art. 4a on special-category dataBias test report: methodology, protected-class proxy approach, thresholds, findings, remediation and re-testFair lending / ComplianceAnnual and per model version
D3Proxy variable review — which variables correlate with protected characteristics, and what you did about each[Binding] ECOA; fair lending examination proceduresVariable-level review memo listing every screened proxy and its dispositionFair lending + Model riskPer model version
D4Override log — every human override of an automated decision, with the reason[Binding] fair lending examination practice; [Deferred] EU Art. 14Override register: application reference, original decision, override, named approver, stated reason, and periodic analysis of the pattern by protected classHead of creditMonthly

Control D4 is the one that surprises people. In fair lending examinations, the override log is read more closely than the model documentation — because it is where discretion, and therefore disparate treatment, actually lives. Most lenders can produce a model validation report and cannot produce a clean override register.

E. Third party and vendor AI

#ControlWhat binds itEvidence artifactOwnerCadence
E1Due diligence on a vendor model where full independent validation is impossible, with compensating controls named[Expected] SR 26–2 vendor-model section; interagency third-party guidance 2023 (which does not address AI — do not cite it as if it does)Due diligence file: documentation received, what could not be validated, compensating controls, residual risk accepted by whomVendor risk + Model riskAnnual
E2DORA register of information, Article 30(3) contractual provisions, and a tested exit strategy[Binding] DORA, since 17 Jan 2025Register entry, executed contract clauses mapped to Art. 30(3), exit plan with a dated testVendor risk / ICT riskAnnual
E3Flow-down of equivalent AI governance standards to vendors, subcontractors and third-party originators[Binding] Fannie LL-2026–04; Freddie Guide §§ 1302.2, 1302.8Contract clause inventory plus counterparty attestationsVendor risk + LegalAnnual
E4A contractual right to obtain the vendor’s Article 13 instructions for use — the raw material for your own explanation to the borrower[Deferred, dated] EU Art. 13; [Binding] in practice via CCD2 and Reg B, which require you to explain regardlessInstructions-for-use document on file, mapped line by line to the explanation you give a declined applicantLegal + ComplianceOn contract, then annual

F. EU high-risk readiness

#ControlWhat binds itEvidence artifactOwnerCadence
F1FRIA, consolidated with the DPIA[Deferred, dated] EU Art. 27(1) third limb — private lenders are caught in their own right; Art. 27(4) permits cross-referencingSingle FRIA/DPIA document with explicit cross-references, covering the deployment context, affected persons, risks and mitigationsDPO + ComplianceBefore deployment, then on material change
F2Article 49 registration and the Annex VI internal-control conformity assessment[Deferred, dated] EU Arts 43(2), 49 — no notified body for Annex III 5(b)Registration record and the internal-control assessment fileComplianceBefore 2 Dec 2027, then annual
F3Automatically generated logs retained for at least six months[Deferred, dated] EU Arts 12 and 26(6)Retention policy plus a demonstrated log extraction for a named decision within the retention windowEngineering + ComplianceQuarterly

What this checklist deliberately does not cover. BSA/AML models — SR 21–8 was rescinded with no replacement, and that gap deserves its own treatment rather than a row here. Insurance underwriting, which sits under a different regulatory architecture. Cybersecurity governance under NYDFS, which is a separate programme. And obligations you would take on as a provider of a general-purpose AI model under Chapter V, which apply to model developers rather than to lenders deploying them. If you need any of these, they are separate exercises — not omissions we quietly dropped to keep the list at 25.

Why the evidence column is the hard part

Read back over the checklist and notice that the controls themselves are not conceptually difficult. Almost every lender we speak to could describe what B5 or F3 requires. The failures happen in the fourth column.

You cannot export evidence you never had

On a multi-tenant SaaS lending platform, the decision is made — but the artifact that proves how it was made belongs to the vendor’s environment, on the vendor’s retention schedule, in the vendor’s export format. Controls B5, C1, C5 and F3 all fail in the same way: not because you lack the policy, but because the record you need to produce was never yours to produce. When an examiner asks for the configuration as it stood on a date eight months ago, “we have raised a ticket with our vendor” is the answer you will have.

Custom build: you own every control and every validation

Building in-house solves ownership and creates a different problem: you now author all 25 evidence artifacts from nothing, with no pre-validated foundation to inherit, on an 18-to-24-month timeline before the first control has anything to attest to. Full visibility, full burden.

The third path: a pre-validated foundation you deploy yourself

Between the two sits a class of architecture rather than a product: a platform that ships a pre-validated foundation — decision engine, data model, audit machinery — which you then configure and run inside your own environment. The governance argument for it is narrow and testable, and it is the only one worth making here: you inherit the validation work that is generic, and you retain the artifacts that are specific to you. What matters for this checklist is not the label but two properties. Does the decision layer emit reason codes deterministically, or does it emit a score you then have to explain? And do the logs land in infrastructure you control, or in someone else’s tenancy?

Every row in the table below is a restatement of one of those two questions.

Own environment, own logs

The controls with retention, replay and extraction requirements — B5, C5, E2, F3 — are decided by where the system runs. Self-hosted or private cloud deployment means decision logs, shadow-run records, approval trails and configuration versions live where you can extract them on your own schedule. That is what closes Article 12 and Article 26(6), what makes the DORA exit strategy credible, and what turns “explain this decision” into a query rather than a support ticket.

Evidence requirementMulti-tenant SaaSCustom build in-houseBuilding platform, own environment
Reason codes tied to factors actually scored (B1)Vendor-defined, often compositeYou build itDeterministic engine, reason codes by design
Decision replay on the original date (B5)Depends on vendor exportPossible if designed in from day oneNative — versioned config and model in your environment
Change log for the build layer (C1–C5)Not visible to youYour SDLCProhibited-factor test → shadow run → named approval, logged
Log retention ≥ 6 months, extractable (F3)Vendor retention policyYour infrastructureYour infrastructure, at platform level
Vendor audit rights and Art. 13 instructions (E1, E4)Negotiated, often refusedNot applicableFull stack inspectable
Time to exam-ready evidence6–12 months on a roadmap18–24 monthsWeeks, on a pre-validated foundation

This is a comparison of architectures, not of suppliers. Any platform that satisfies the third column satisfies the checklist; the point is that the first column structurally cannot, whoever sells it.

Evidence ownership compared across SaaS lending platforms, custom build and the timveroOS Building Platform: reason codes, decision replay, change logs, retention and audit rights

Running this in 90 days

Twenty-five controls is not a quarter’s work if you sequence it by what closes the most exposure first.

Days 1–30 — inventory and classification. Section A in full. You cannot scope anything else until you know what you have, and A1 is where most programmes discover systems nobody had registered — a generative assistant in servicing, a vendor model behind a data feed. Finish with A3 and A4, because the Annex III determination and the provider-versus-deployer call drive everything in Section F.

Days 31–60 — the decision layer. Section B, and D4 alongside it. B1 and B5 are the controls with live, enforceable exposure today, and D4 is the one an examiner reads first. This is also where the Colorado safe harbour pays off: notices that already satisfy ECOA and FCRA carry weight from 1 January 2027.

Days 61–90 — vendors and EU readiness. Section E, because DORA already binds and the GSE flow-down has a contract cycle that runs slower than your project plan. Then Section F as a gap analysis rather than a build — using the EBA’s four no-synergy areas as the starting point. Section C runs through all three phases, because it is a change to how you release, not a document you produce.

For the strategic framing behind this sequence — why the two-layer pattern is what survives an examination rather than merely satisfying it — the audit-survival playbook (opens in new tab) carries the argument in full. What differs between a bank (opens in new tab), a credit union (opens in new tab) and a fintech lender (opens in new tab) is mostly which of these 25 controls already have an owner, not which ones apply. Two adjacent programmes intersect this one: generative AI in banking (opens in new tab), for the systems A1 tends to surface late, and KYC and AML compliance (opens in new tab), for the identity and screening obligations that sit beside model governance without being covered by it.

Frequently asked questions

Is SR 11–7 still in effect?

No. SR 11–7 was rescinded on 17 April 2026, along with OCC 2011–12, OCC 2021–19, the Model Risk Management booklet of the Comptroller’s Handbook, FDIC FIL-22–2017 and FIL-27–2021. SR 21–8 on BSA/AML model risk and OCC 1997–24 on credit scoring models were rescinded at the same time. Any checklist citing SR 11–7 as current is out of date.

What replaced SR 11–7 for banks using AI?

SR 26–2, OCC Bulletin 2026–13 and FDIC FIL-15–2026, issued 17 April 2026. The replacement is risk-based and explicitly non-binding: it “does not set forth enforceable standards” and states that non-compliance “will not result in supervisory criticism.” Its principles — validation, inventory, documentation, effective challenge — remain the working vocabulary of examinations.

Does SR 26–2 apply to banks and credit unions under \$30 billion?

It is framed as most relevant to banking organizations with over \$30 billion in total assets, and it is non-binding regardless of size. Smaller institutions are not exempt from oversight — they simply have no applicable federal model-risk guidance to follow. Board, internal audit, fair lending, third-party risk and investor requirements all still apply.

Were CFPB Circulars 2022–03 and 2023–03 withdrawn, and do adverse action requirements still apply?

The circulars were withdrawn on 12 May 2025. The requirements were not. Circulars are interpretive; the duty lives in 12 CFR § 1002.9, which has not been amended. A declined applicant is still owed the specific principal reasons, within 30 days, accurately describing the factors actually considered or scored.

Is credit scoring high-risk under the EU AI Act?

Yes. Annex III point 5(b) covers AI used to evaluate the creditworthiness of natural persons or establish their credit score, and that text was not changed by the 2026 deferral. The Article 6(3) filter is unavailable, because profiling of natural persons is always high-risk. The narrow exception is AI used to detect financial fraud.

What is the EU AI Act deadline for credit scoring AI?

2 December 2027. Regulation (EU) 2026/1744, in force 27 July 2026, deferred Chapter III Sections 1–3 only. Article 50 transparency, Articles 40–49 including registration, Chapter IX incident reporting and the Article 86 right to explanation all applied from 2 August 2026 and are live now.

What if we use a third-party AI model from a vendor?

You remain accountable. Fannie Mae LL-2026–04 requires flow-down of equivalent standards to vendors, subcontractors and third-party originators. DORA has required register entries, Article 30(3) clauses and exit strategies since January 2025. And under EU AI Act Article 25, branding, substantially modifying or repurposing a vendor system can make you the provider.

How does the EU AI Act affect a US lender?

It applies where the output is used in the EU, regardless of where you are established. A US lender assessing EU-resident applicants, or a US vendor whose scoring output reaches EU borrowers, is in scope. Separately, GDPR Article 22 and the SCHUFA and Dun & Bradstreet judgments already govern automated credit decisions affecting EU data subjects.

Do we need a fundamental rights impact assessment if we are a private lender?

Yes. Article 27(1) has three limbs, and the third — “deployers of high-risk AI systems referred to in points 5 (b) and © of Annex III” — is a standalone trigger that does not require you to be a public body. Commercial banks, consumer lenders, BNPL providers and fintech lenders are all caught. Article 27(4) lets you cross-reference an existing DPIA.

What are the penalties for non-compliant AI in lending?

Under EU AI Act Article 99, up to €35 million or 7% of worldwide annual turnover for prohibited practices under Article 5, and up to €15 million or 3% for other infringements, including Article 50 transparency. GDPR, DORA and national consumer credit regimes carry their own separate penalty structures, and US exposure runs primarily through ECOA, FCRA and GSE repurchase and contractual remedies.

How this gets implemented in practice: timveroOS

Everything above is architecture-neutral and stands on its own. This section is where we describe our own implementation of it, so you can discount it accordingly.

timveroOS (opens in new tab) is a Building Platform built around the two-layer split in this article, and the two layers map onto the checklist directly.

The decision layer — Section B. A deterministic explainable lending analytics (opens in new tab) engine produces the outcome together with machine-readable reason codes tied to the factors actually scored, and stores the four replay artifacts specified above as a by-product of deciding, not as a reporting job.

The build layer — Section C. timveroAI (opens in new tab) is a RAG-grounded implementation agent that configures and changes the lending system inside a pre-validated framework. It does not make credit decisions and is not a scoring model. Every change it generates passes divergence detection against the specification, a prohibited-factor screen, a shadow run against historical flows, and a named human approval gate before release — which is C1 through C5, produced as logs rather than assembled as documents.

The environment — Sections E and F. Self-hosted or private cloud deployment, so the logs, approval trails and configuration versions that close B5, C5, E2 and F3 sit in infrastructure you control and can extract from on your own schedule.

Two implementations, both audited by their own regulators. At Finom, timveroOS underpinned a lending operation reaching 98% process automation, launched in four months across multiple EU jurisdictions with their attendant reporting obligations (Finom case study (opens in new tab)). At AMIO Bank, a complex regional lending product with local regulatory integrations went live at 95% automation after three failed attempts with previous vendors (AMIO Bank case study (opens in new tab)). In both, the speed came from the build layer while the credit decision stayed deterministic.

“The column that decides whether you pass is not ‘do we have a control.’ It is ‘can we produce the artifact.’ Those are different questions, and architecture answers the second one long before compliance gets involved. If the record lives in someone else’s environment on someone else’s retention schedule, you do not have a governance programme — you have a support ticket.”

— Dmitriy Wolkenstein, CEO, TIMVERO

See where the evidence actually comes from

If your governance programme has to survive an examination as well as a board review, the useful conversation is not about the 25 controls — it is about which of them your architecture produces on its own and which ones somebody has to assemble by hand. That is what a Building Platform briefing covers: the decision layer, the build layer, and where each evidence artifact is generated.

Schedule a Building Platform briefing → (opens in new tab)