Kaaj raises $3.8M in seed funding to power the future of small business lending 🎉Read more
← Resources

Credit policy guide

Automated credit decisioning with humans in the loop: rules, waterfalls, and when to auto-decide

Last updated · Kaaj editorial team

To automate credit decisions without losing control, write your policy as two layers: hard-stop knockouts (restricted industry, entity status, time in business, fraud flags) and scored factors (credit, cash flow, DSCR, collateral). Run the cheapest checks first so obvious declines never pay for a full credit pull or bank-statement analysis. Auto-decide only inside a clearly defined box, usually small tickets where every rule passes, and route everything else, including new businesses and exceptions, to an underwriter with the reasons attached. Backtest rule changes on past applications, keep the rules in your team's hands, and log every decision. Kaaj applies lender-defined rules as pass or fail checks with reasons, runs inexpensive checks first, and can feed its results to the decision engine you already use.

How to set up automated decisioning in 10 steps

Start conservative: automate declines and data gathering before you automate approvals.

  1. Write the policy down as rules

    Turn each guideline into a testable rule with a threshold and a source, for example minimum time in business from the state record, not from the application.

  2. Separate knockouts from scored factors

    Knockouts decline or route a file on their own. Scored factors combine into a scorecard or weighted matrix for everything that survives.

  3. Order checks by cost

    Run instant checks (industry, entity status, fraud) first, then a soft credit pull, then bank-statement and financial analysis. Obvious declines should never reach the expensive steps.

  4. Set hard-stop declines carefully

    Common hard stops include restricted industries, inactive entities, confirmed document tampering, and extreme NSF counts or negative days. Keep the list short and review it often.

  5. Define the auto-decision box

    Limit automatic approvals to a narrow set, such as small tickets from established businesses where every rule passes. Everything else goes to a person.

  6. Route exceptions with reasons

    New businesses, deals using personal financials, and borderline scores should reach an underwriter with the rule results and evidence attached.

  7. Decide what the output is

    Approve and decline, or also a risk tier that drives pricing and structure. Keep humans responsible for exceptions either way.

  8. Backtest before you switch on

    Run a new or changed rule on past applications and compare with what actually happened before it touches live deals.

  9. Keep the rules in your hands

    Your credit team should be able to see and change thresholds quickly after a market shock, with every change dated and logged.

  10. Get compliance sign-off and log everything

    Have compliance review automated decisions before launch, and keep a record of every rule result, decision, and override for audit and adverse-action notices.

A credit-first waterfall

Each stage costs more than the last, so each one only runs on files that survive the previous stage.

Credit-first waterfall · cheapest checks first

1 · KnockoutsSeconds
Restricted industry, entity status, time in business, document fraudObvious declines stop here
2 · Credit pullOne soft pull
Owner score and tradelines against policy minimumsWeak credit stops before statements are analyzed
3 · Cash flowMinutes
True revenue, NSF count, negative days, MCA positions, DSCRSurviving files get full analysis
4 · Route—
Inside the small-ticket box and every rule passed?Eligible for auto-decision; everything else goes to an underwriter

Every stop and route should show its reason, so an underwriter can review or override it.

Illustrative waterfall. Stages and thresholds are examples, not a recommended credit policy.

Knockouts vs. scorecards

Pass/fail knockoutsWeighted scorecard or matrix
What it doesDeclines or routes a file on one ruleCombines many factors into a score or tier
Best forNon-negotiables: restricted industries, fraud, inactive entitiesCredit, cash flow, DSCR, collateral, and time in business together
RiskToo many knockouts decline good dealsOpaque if weights are not documented
Explaining decisionsEasy: the rule that failedNeeds the top contributing factors

What to automate and what to keep with underwriters

DecisionAutomate?
Declines on hard-stop rulesYes, with the reason logged
Data gathering, verification, and analysisYes
Approvals inside a narrow small-ticket boxYes, after backtesting and compliance review
New businesses and startupsRoute to an underwriter
Deals using personal financials or guarantor strengthRoute to an underwriter
Large tickets and committee dealsUnderwriter and committee decide
Exceptions and overridesUnderwriter decides and documents

Frequently asked questions

How do you encode a credit policy into a rules engine?

Write each guideline as a rule with a data source and threshold, split non-negotiable knockouts from scored factors, and test the rules on past applications before using them live.

Can small-ticket equipment deals be auto-decided while humans handle larger ones?

Yes. Many lenders auto-decide a narrow small-ticket box where every rule passes and send everything else, including larger deals and exceptions, to underwriters and committee.

What is a credit-first waterfall?

An order of checks from cheapest to most expensive, so obvious declines are caught by instant checks or a soft pull before anyone pays for full bank-statement or financial analysis.

Who should maintain the rules, the lender or the vendor?

The lender should own the rules and be able to change thresholds quickly, with every change logged. In Kaaj, rules are configured to your policy and your team decides when they change.

Can AI underwriting feed an existing decision engine?

Yes. Verified KYB, bank-statement, and fraud results can be sent by API or webhook, or written to Salesforce, so an existing scorecard or decision engine makes the call.

Do we need compliance approval before turning on auto-decisioning?

You should have compliance review it first, including how decisions are explained and how adverse-action notices are produced. Automated declines still need clear, specific reasons.

How should we test a new knockout rule?

Backtest it on historical applications and compare its decisions with actual outcomes before it touches live deals, rather than learning from a live split.

Apply your policy the same way on every file

Kaaj runs your rules as pass or fail checks with reasons, runs inexpensive checks first, and sends results to your CRM, LOS, or decision engine.

Book a demoSee the Kaaj platform
How to automate an underwriting workflow →Credit pulls in automated underwriting →Best automated underwriting software for small business loans →How to calculate DSCR →