All Insights

    AI Governance

    Credit Decisioning AI Is a Governance Problem, Not a Technology One

    The first in a four-part series on responsible AI in lending: why trust in credit decisioning is built in layers — policy, data, then the model — and rarely in the order institutions attempt it.

    Prashant BhardwajJune 20267 min read
    Share

    Artificial intelligence is transforming how financial institutions assess credit risk. Work that once required hours of manual analysis — pulling a bureau report, reconciling income documents, weighing repayment history against exposure limits — can now be completed in seconds. For lenders, that speed is genuinely valuable: more applications served, lower cost per decision, faster turnaround for the customer waiting on an answer. But faster decisions do not remove responsibility from the process. They concentrate it.

    Credit decisioning is not like most other enterprise AI use cases. An AI system that misjudges a restaurant recommendation disappoints someone for an evening. A meeting summary that drops a sentence costs a few minutes of correction. A system that recommends against a ₹25 lakh business loan can determine whether an entrepreneur gets funded, whether a family buys its first home, whether a small business can hire the people it needs. Lending decisions have always been held to a higher standard than most business processes, and AI does not get an exemption from that standard because it is faster than the process it replaced.

    For Indian financial institutions specifically, that standard sits at the intersection of several obligations at once. Lending has to align with the fair-practice expectations regulators apply to credit decisioning generally. It has to respect the Digital Personal Data Protection Act's requirements for lawful, purpose-limited processing of the personal data a credit decision runs on. And increasingly, institutions are drawing on global model-risk frameworks — SR 11-7, the NIST AI Risk Management Framework, ISO/IEC 42001 — not because a regulator demands it directly, but because those frameworks are the most mature articulation available of what disciplined model governance actually looks like.

    The realization worth sitting with is this: successful AI adoption in lending is no longer primarily a technology initiative. It is a governance initiative that happens to be delivered through technology. Organizations rarely fail at this because their models are too simple. They fail because, when asked how an important decision was made, which data influenced it, and who remains accountable for it, they cannot produce a straight answer.

    Consider what that failure looks like in practice. A customer opens a banking app and applies for a personal loan. Within eighteen seconds, a model evaluates thousands of data points and recommends rejection. The customer gets a polite notification and, naturally, asks why. The relationship manager opens a dashboard and sees a risk score, nothing more. The data science team explains that the recommendation came from a model trained on historical lending data. Compliance wants to know whether the customer's information was processed only for the purposes they consented to. Risk wants evidence that the recommendation matches internal credit policy. Internal audit wants logs showing exactly which model version produced the decision. Senior management wants assurance that similar applicants are being treated consistently. Everyone in that chain has part of the answer. Nobody has the whole of it.

    That looks like an AI problem. It is not. The model generated a recommendation. Business policy determines whether that recommendation deserves to be trusted. Governance determines whether the institution can defend the decision — to the customer, to a regulator, to an auditor, and to its own leadership — after the fact. As AI moves from experimentation into core banking operations, that last capability is the one institutions are least prepared for.

    One of the most common misconceptions in enterprise AI is that introducing it replaces existing business processes. In lending, it does the opposite: it extends them, and it only works if the underlying process was sound to begin with. Think about how an experienced credit analyst is actually onboarded. On day one, they are not handed approval authority. They first learn the lending policy, the regulatory expectations, the internal workflows, the acceptable risk limits, the documentation standards, the customer privacy obligations that govern the data in front of them. Only once they demonstrate they understand those constraints are they trusted to make recommendations independently. An AI system deserves exactly the same onboarding discipline. It is a participant in the lending process. It is not the owner of it. The lending policy remains the source of truth; the model's job is to execute it faster, not to redefine it.

    A useful way to stress-test any AI deployment plan is to imagine hiring the fastest credit analyst your institution has ever seen — someone who can review 100,000 applications an hour, never gets tired, and instantly recognizes patterns across millions of historical records. Would you let that analyst approve loans without supervision on day one? Almost no institution would say yes. You would still expect them to follow lending policy, justify material recommendations, work only with data they are authorized to see, escalate unusual cases, and remain accountable to a manager who reviews their performance. None of those expectations disappear because the analyst happens to be a model instead of a person. The technology changed. The governance obligations did not.

    AI does not replace credit policy — it operationalizes it. And the quality of an AI-assisted credit decision depends far less on how sophisticated the underlying model is than on how disciplined the governance around it is. This is the single most common thing institutions get backwards.

    When institutions start building AI-assisted credit decisioning, most instinctively begin with model selection: which foundation model, which vendor, which fine-tuning approach. That instinct is understandable and it is also where trust actually gets built last, not first. Trust in an enterprise credit decisioning system is layered, in the same way a building depends on what is beneath the part you can see.

    The first layer, and the one that has to exist before any model touches a live application, is business policy. Before AI evaluates anything, the institution needs unambiguous answers to a short list of questions: who qualifies for credit under current policy, which lending rules are non-negotiable, which risks the institution is willing to accept, at what point a case must go to a human reviewer regardless of what the model recommends, and who is accountable for the final decision when it is challenged. If those answers are vague, no amount of model quality will compensate, because the model has nothing solid to operationalize.

    The second layer is data governance, and it is where even well-intentioned programmes quietly fail. A sophisticated model cannot compensate for data that is incomplete, stale, or improperly governed. Institutions need to know, for every dataset feeding a decision: where the data originated, whether valid consent exists for this specific use, how data quality is maintained over time, who has access to it, and how it is protected across its lifecycle — not just at the point of collection. This is where DPDP's purpose-limitation requirement stops being an abstract compliance clause and becomes an operational constraint the data pipeline has to enforce.

    Only once those two foundations are solid does the third layer — the AI decision model itself — deliver value an institution can actually rely on. Institutions that build in the reverse order, starting with the model and treating policy and data governance as things to retrofit once the pilot looks promising, consistently end up with systems that are technically impressive in a demo and operationally fragile the first time a regulator, an auditor, or an unhappy customer asks a hard question.

    None of this is solved by writing a better policy document and filing it away. Policy has to translate into specific, checkable principles that a technology team can actually build against — the kind of principles a model card can be scored on, an auditor can verify, and a risk committee can approve without a six-week back-and-forth. That translation is where most institutions get stuck, and it is the subject of the next piece in this series: The TRUST Framework for Responsible Credit Decisioning AI.

    Filed under

    GovernanceBFSICompliance

    Continue reading

    More on AI Governance