Kaaj raises $3.8M in seed funding to power the future of small business lending πŸŽ‰Read more
← Resources

Security and compliance guide

AI underwriting vendor due diligence: security, model risk, and examiner questions

Last updated Β· Kaaj editorial team

Before sending borrower documents to an AI underwriting vendor, review five areas: security (a current SOC 2 Type II report, penetration testing, encryption, access control, and subprocessors), data use (retention, deletion, location, and whether your data trains models, written into the contract), model risk (how outputs are validated and monitored on your own files), decision governance (who decides, how overrides are recorded, and whether every number traces to its source document), and compliance (specific adverse action reasons, fair lending consistency, and permissible purpose for credit pulls). Kaaj is SOC 2 Type II compliant, publishes architecture, subprocessor, and penetration-test documentation in its trust center, links every finding to its source, and leaves credit decisions with your underwriters.

The AI underwriting vendor due diligence checklist

Scale the depth of review to the vendor's role: a tool that drafts analysis for human review carries different risk from one that auto-decides.

  1. Get the SOC 2 Type II report

    Ask for the full report, not a badge, plus any bridge letter covering the gap since the audit period ended. Read the exceptions and the complementary user-entity controls you are expected to run.

  2. Map the data flow

    Document which borrower data the vendor receives, where it is processed and stored, which subprocessors touch it, and how it returns to your systems.

  3. Put data use in the contract

    Retention periods, deletion on request and at termination, data location, and whether your data is used to train or improve models should be contractual terms, not sales answers.

  4. Check access and identity controls

    Confirm SSO, role-based access, MFA, and audit logs of who viewed or changed what.

  5. Test on your own files

    Run a pilot on recent deals, including messy and known-bad files, and compare the vendor's output with your analysts' work before relying on it.

  6. Document model risk proportionately

    Record what the tool does, how its outputs were validated, how errors are caught, and how performance is monitored after go-live. Depth should match the decision's impact.

  7. Confirm human authority and the audit trail

    Define which decisions people make, how overrides and exceptions are recorded, and whether every number in the credit file links to the page it came from.

  8. Plan adverse action and fair lending

    Make sure decline reasons are specific and traceable, rules are applied consistently across applicants, and credit pulls run only with authorization and a permissible purpose.

Security questions to ask an AI underwriting vendor

Ask for evidence, not yes or no answers.

QuestionWhy it mattersEvidence to request
Do you have a current SOC 2 Type II report?Type II tests controls over a period, not just their design.Full report, bridge letter, and remediation of any exceptions
Which subprocessors handle our data?Your data's exposure includes every downstream provider, including AI model providers.Subprocessor list with locations and purposes
Is our data used to train or improve models?Borrower data used in training can persist beyond your relationship.Contract clause and data processing terms
How long do you keep our data, and how is it deleted?Retention drives breach exposure and record-keeping obligations.Retention schedule and deletion certificate process
How is data encrypted in transit and at rest?Baseline control for financial data.Architecture overview and key management description
When was your last penetration test?Shows whether controls hold against real attacks.Penetration test summary and remediation status
How do you control and log access?You need to know who saw borrower data.SSO and role documentation, sample audit log
What happens if you go down?Underwriting cannot stop if the vendor does.Uptime history, incident process, and a manual fallback

How to explain AI-assisted credit decisions to examiners

What examiners and auditors askWhat to be able to show
Who made the decision?The underwriter or approver of record, with the AI output as an input, not the decision
Where did this number come from?A link from each figure to the page and line of the source document
Why was this applicant declined?Specific, principal reasons tied to policy rules and evidence
Is the policy applied consistently?The same rules for every applicant, with exceptions and overrides logged and reviewed
How do you know the tool works?Pilot results on your own files, ongoing accuracy checks, and how errors are caught
How did you manage the vendor?Due diligence records, the contract, and ongoing monitoring under your third-party risk program

Frequently asked questions

Which AI underwriting platforms are SOC 2 Type II certified?

Kaaj is SOC 2 Type II compliant and publishes its security documentation at its trust center. For any vendor, ask for the full SOC 2 Type II report and bridge letter rather than relying on a badge or website claim.

What security questions should a lender ask an AI underwriting vendor?

Ask for the SOC 2 Type II report, the subprocessor list, data retention and deletion terms, whether your data trains models, encryption and access controls, the latest penetration test, and the outage plan. Get data-use answers into the contract.

What should a model risk or vendor risk review cover for AI underwriting?

What the tool does and where its outputs feed decisions, how it was validated on your own data, how errors are caught, how performance is monitored, and who is accountable. Banks also manage the vendor under interagency third-party risk guidance. Scale the review to the decision's impact.

Does SR 11-7 still apply to AI underwriting tools?

SR 11-7 was replaced in April 2026 by SR 26-2, the Federal Reserve's revised, risk-based model risk management guidance for banking organizations over $30 billion in assets. Smaller lenders often apply similar principles proportionately. Confirm expectations with your regulator; this is not legal advice.

How do lenders explain AI-assisted credit decisions to bank examiners?

Show that a person made the decision, that each number traces to a source document, that decline reasons are specific and tied to policy, and that rules are applied consistently with exceptions logged.

How do lenders keep fair lending compliance when using AI in small business underwriting?

Apply the same documented rules to every applicant, avoid inputs that act as proxies for protected characteristics, log and review exceptions and overrides, give specific adverse action reasons, and monitor outcomes over time.

Which AI underwriting tools keep a source-linked audit trail?

Kaaj links every finding and spread number to the page and line of the source document, and underwriters edit and decide. Ask any vendor to trace five numbers in a sample file back to the source during the demo.