Before using AI in small-business lending, a credit union should divide the workflow into specific tasks and decide which ones may recommend, which may automate and which must remain with qualified lending staff. The go-live decision should then depend on evidence for each task: data provenance, reason accuracy, fair-lending tests, exception handling, vendor change controls and measured portfolio outcomes.
This is not simply a smaller version of consumer underwriting. A business file can combine entity records, owner or guarantor information, tax returns, financial statements, bank transactions, projections and collateral evidence. Missing periods, seasonal cash flow and inconsistent document formats are normal operating conditions. An AI tool that performs well on clean files can still create rework or obscure risk on the files that need the most judgment.
The current NCUA commercial-lending rule requires covered federally insured credit unions to maintain board-approved policy, qualified personnel, underwriting standards and risk-management processes appropriate to their programs. When a third party supplies qualified lending expertise, the rule says the actual decision to grant a loan must remain with the credit union and its staff must provide ongoing oversight. Some smaller credit unions meeting the rule’s stated thresholds are exempt from portions of Part 723, but an exemption is not a substitute for defining who owns an AI-assisted decision.
1. Draw the decision boundary
List every AI-enabled task: classifying documents, extracting fields, normalizing cash flow, detecting anomalies, recommending a risk grade, drafting conditions or producing a denial reason. For each task, record whether the output is informational, a recommendation or a binding action. Name the person or committee with authority to accept, override or stop it.
Pass evidence: a workflow map shows the input, output, decision owner, downstream use and prohibited use for every AI component. “The platform underwrites the loan” is not a sufficient boundary.
2. Keep an evidence trail from source to decision
For every material field, retain its source document, relevant date, extraction result, transformation and any employee correction. Test whether the system confuses a deposit with revenue, treats a transfer as operating cash flow, combines entities or misses a page. Part 723 calls for financial analysis and verification sufficient to support an accurate risk assessment; automation should make that evidence easier to reproduce, not harder.
Pass evidence: a reviewer can trace each material input in the credit memo or score back to the original file and see every automated and human change.
3. Test reasons before testing speed
Regulation B covers business credit as well as consumer credit. The CFPB has also said in its complex-algorithm adverse-action circular that creditors must provide specific principal reasons and cannot rely on opacity as a defense. Build reason testing into model acceptance: for a sample of adverse decisions, confirm that the disclosed reasons reflect the factors actually used—not the nearest item on a generic checklist.
Pass evidence: compliance and lending staff can reproduce the principal reasons from the decision record, resolve conflicts between model output and notice language and block a model version that cannot support accurate reasons.
4. Test outcomes across the business portfolio
Compare approval, pricing, conditions, review time and overrides across relevant applicant and loan segments. Include new and established businesses, industries, geographies, loan sizes, entity types and thin-file applications. Compliance counsel should define the fair-lending testing approach and protected-class analysis appropriate to the program; operations should also look for process disparities, such as one group being asked repeatedly for documents or routed more often to manual review.
Pass evidence: the credit union has documented thresholds, investigated material differences and assigned an owner and deadline for remediation before scaling.
5. Make exceptions a designed route
Create explicit routes for missing statements, seasonal businesses, recent ownership changes, suspected fraud, inconsistent owner and entity data, unusual collateral and projections that do not reconcile. Staff should be able to pause automation, request evidence, record an override and escalate without rebuilding the file. Part 723 requires a process to identify, report and monitor policy exceptions; AI exceptions belong in that same control environment.
Pass evidence: exception categories, approval authority, required documentation and management reporting are configured and tested with deliberately difficult files.
6. Contract for evidence and change control
The NCUA’s active third-party relationship guidance calls for risk assessment, due diligence, monitoring and controls. For an AI lending vendor, the contract should add model and rule version notices, data-use limits, subcontractor visibility, audit evidence, reason-code support, incident notification, performance reporting, record access and a tested exit path.
Pass evidence: no material model, prompt, data-source or decision-rule change can reach production without notice, regression testing, named approval and rollback capability.
7. Pilot against operating and credit outcomes
Start with a bounded product, volume and authority level. Compare the pilot with a credible baseline on cycle time, staff rework, document errors, withdrawals, approvals, overrides, corrected reasons, fraud referrals and early credit performance. Do not treat faster processing as a benefit if employees spend the saved time repairing files or explaining decisions.
The voluntary NIST AI Risk Management Framework organizes AI risk work around governing, mapping, measuring and managing. Use that structure for the pilot file: intended use and limits, tests and thresholds, monitoring owners, incident triggers, change decisions and retirement criteria.
The go-live file leaders should require
- the task and decision-authority map;
- the source-to-decision data trail;
- reason-code and fair-lending test results;
- exception categories, overrides and escalation evidence;
- vendor obligations, version controls and rollback test;
- pilot results against the agreed baseline; and
- the named owner, approval date, conditions and stop triggers.
This checklist complements CreditUnionAI News’ mortgage AI go-live tests, but it focuses on the mixed entity, owner, cash-flow and document evidence unique to business files. Use the AI vendor due-diligence checklist before selection and the AI business-case framework to decide whether verified benefits justify further investment.
Approve the control file before expanding the lending volume. Subscribe to the CreditUnionAI Weekly Briefing for practical AI governance and implementation coverage.
Get the Weekly Briefing