Direct answer
An AI credit-decision review should answer five questions: What decision was made? Which population and comparison groups were evaluated? Where did outcomes diverge? What data and candidate reasons help explain the finding? What evidence and human action were recorded afterward?
What should be measured?
Start with the actual decision outcome, not a generic model score. Depending on the workflow, useful measures can include favorable-outcome rates, adverse impact ratio, statistical parity difference, pricing or term differences, exception patterns, and the stability of results across time windows. Every measure should retain its population definition, comparison group, denominator, exclusions, configuration, and interpretation limits.
A threshold crossing is a screening signal. It does not identify cause or establish a legal conclusion by itself. Sample size, missing or inferred demographic attributes, reference-group selection, policy context, and statistical uncertainty can materially change the interpretation.
What belongs in a reviewable evidence packet?
- The evaluation question, workflow, outcome, population, comparison group, and time window.
- The data fields used, excluded, derived, missing, or inferred.
- The metric definitions, thresholds, configuration, software version, and calculation output.
- Material findings with supporting records and alternative explanations to investigate.
- Candidate adverse-action reasons and the fields supporting or contradicting them.
- Reviewer identity, review date, disposition, next action, and unresolved limitations.
- An export manifest that lets another reviewer locate and reproduce the artifacts.
A practical review sequence
- 01
Define one decision question
Name the workflow, outcome, population, comparison, time window, and decision the review must support.
- 02
Reproduce a baseline
Confirm that the supplied inputs and agreed method reproduce a known measure within an accepted tolerance.
- 03
Investigate material findings
Review population design, sample size, inputs, policy context, reason codes, and plausible alternative explanations.
- 04
Record the human decision
Document what was concluded, what remains uncertain, who owns the next action, and when the finding will be revisited.
Who should participate?
Primary sources
This guide is an operational framework, not legal advice. Review the underlying requirements and guidance directly:
Primary regulation, including notification requirements under § 1002.9.
↗Supervisory Guidance on Model Risk Management (SR 11-7)Federal Reserve and OCCModel development, validation, governance, policies, and controls.
↗Interagency Guidance on Third-Party RelationshipsFederal Reserve, FDIC, and OCCPlanning, due diligence, contracting, monitoring, and termination considerations.
↗AI Risk Management Framework 1.0NISTVoluntary framework organized around govern, map, measure, and manage.
↗