← Back to all projects
Executive Summary
As AI Governance Lead, I ran a high-risk AI governance assessment of Meridian
Financial Services' pilot for an automated small business loan underwriting system —
scoping the risk classification, running the review against three major frameworks, and
producing the evidence package a governance committee would need to make a production
decision.
The system uses a third-party AI model, CrediSure Credit Decision Engine v2.3,
to evaluate small business loan applications and produce one of three outcomes: auto-approve,
auto-deny, or route to manual review.
Because approximately 94% of applications are processed automatically and the
system affects access to credit, I classified this as a high-risk AI use case
requiring governance review before production deployment.
Final recommendation: Proceed with conditions. Meridian should not approve
unrestricted production deployment until fairness testing, proxy-bias review, reason code
validation, human oversight triggers, appeal procedures, vendor evidence review, monitoring
thresholds, and governance committee approval are completed.
EU AI Act FRIA summary for the Meridian Automated Loan Underwriting System, including stakeholder consultation status, flagged rights, risk score, and conditional approval recommendation.
Skills Demonstrated
High-risk AI classification
Risk register & scoring
Fundamental Rights Impact Assessment
Third-party vendor governance
Human oversight design
Governance decision memos
Frameworks Applied
| EU AI Act | NIST AI Risk Management Framework | ISO/IEC 42001 |
| High-risk AI classification | Governance roles and responsibilities | AI management system scope |
| Fundamental Rights Impact Assessment | System context and intended use | Organizational roles and responsibilities |
| Human oversight | Risk measurement and testing evidence | AI risk assessment |
| Logging | Risk prioritization and treatment | AI risk treatment |
| Explanation to affected persons | Human-AI oversight | Management review |
| Appeal and contestability | | AI system lifecycle management |
| Deployment conditions | | Third-party AI risk management |
Central Governance Question
Should Meridian Financial Services approve production deployment of a 94% automated AI
loan underwriting system?
My answer: Not for unrestricted production deployment. The system may
proceed only with conditions because the current governance evidence does not fully
support safe, fair, explainable, accountable, and well-monitored deployment.
Portfolio Artifacts
-
AI System Profile and Intake Record
Documents system purpose, users, affected groups, data, vendor, and risk classification.
-
AI Risk Register and Mitigation Summary
Documents key AI risks, severity, controls, residual risk, and recommendations.
-
Human Oversight and Appeal Procedure
Defines human review triggers, override authority, escalation, and applicant appeal process.
-
Third-Party Vendor and Model Review
Evaluates CrediSure AI vendor risk, model limitations, and required evidence.
-
Production Readiness Decision Memo
Provides final executive recommendation.
-
Final VerifyWise Portfolio Report
Consolidated portfolio report generated from VerifyWise.
Practical AI Governance Skill Proof
1. Use Case Registration
The Meridian Automated Loan Underwriting System registered as a high-risk AI use case in VerifyWise, with applicable frameworks, approval workflow, and pre-production governance status.
Skill demonstrated: AI use case intake, risk classification, and governance workflow setup.
2. Model Inventory
The CrediSure Credit Decision Engine v2.3 documented in the model inventory.
Skill demonstrated: Model inventory documentation, model limitation tracking, and third-party AI model governance.
3. Dataset Record
The Small Business Loan Underwriting Dataset registered in VerifyWise, including data purpose, source, format, PII status, known bias concerns, mitigation approach, and connection to the CrediSure Credit Decision Engine and Meridian Automated Loan Underwriting System.
Skill demonstrated: Dataset governance, PII awareness, data source documentation, and bias mitigation planning.
4. AI Risk Register
The six required risks for the Meridian Automated Loan Underwriting System, including risks imported from IBM AI Risk Database, MIT AI Risk Repository, and manually created custom risks.
Skill demonstrated: AI risk identification, risk rating, mitigation planning, residual risk analysis, and approval workflow documentation.
Key Risks Identified
| Risk | Why It Matters |
| Discriminatory lending outcomes | The system may unfairly approve or deny applicants based on biased data, proxy variables, or historical lending patterns. |
| Proxy bias through credit and business variables | Variables such as geography, business age, industry, credit history, thin credit files, or cash-flow volatility may create unfair outcomes. |
| Weak explainability and incomplete reason codes | Meridian may be unable to explain automated denials, support appeals, or demonstrate compliance during review. |
| Accountability gaps in third-party AI deployment | Meridian remains responsible for deployment even if the vendor controls key model details. |
| Inaccurate automated denials | Qualified applicants may be incorrectly denied credit due to model error, incomplete data, or overly strict thresholds. |
| Lack of meaningful human oversight | Routing only 6% of applications to human review may be insufficient for a high-risk credit decision system. |
5. Vendor Record
The CrediSure AI vendor record in VerifyWise, documenting the third-party provider responsible for the credit decisioning model used by the Meridian Automated Loan Underwriting System.
Skill demonstrated: Third-party AI vendor risk management and vendor governance documentation.
6. Framework Assessments
The three must-have ISO 42001 Annex controls completed for the Meridian Automated Loan Underwriting System: AI governance framework, AI system lifecycle management, and third-party AI risk management.
Skill demonstrated: Practical framework application and evidence-based AI governance assessment.
7. Fundamental Rights Impact Assessment (FRIA) Summary
The EU AI Act FRIA summary for the Meridian Automated Loan Underwriting System, including stakeholder consultation status, flagged rights, risk score, and conditional approval recommendation.
Skill demonstrated: Fundamental rights risk assessment, high-risk AI review, human oversight analysis, and conditional deployment recommendation.
8. Final Report
Oyinadesola Edu_AI_Governance_Portfolio_Report.pdf
The final VerifyWise portfolio report generated for the Meridian Automated Loan Underwriting System.
Skill demonstrated: Governance evidence organization and final reporting.
Final Recommendation
Proceed with conditions.
Meridian should not approve unrestricted production deployment at this time. The system may move forward only if the following conditions are completed:
- Complete fairness testing and disparate impact analysis
- Complete proxy-bias review
- Validate denial reason codes
- Define mandatory human review triggers
- Establish appeal and reconsideration procedures
- Complete vendor documentation review
- Complete security and privacy review
- Define model and outcome monitoring thresholds
- Implement decision-level audit logging
- Establish incident escalation procedures
- Obtain governance committee approval
Portfolio Conclusion
This project demonstrates my ability to evaluate a high-risk AI system from an AI
governance, risk, and compliance perspective. The Meridian Automated Loan Underwriting
System offers business benefits, including faster decisions, improved consistency, and
operational efficiency. However, because it affects access to credit and automates most
decisions, it requires strong governance before deployment.
As AI Governance Lead, my assessment found that the system should not receive unrestricted
production approval until Meridian completes required fairness, explainability, human
oversight, vendor, monitoring, privacy, and governance controls.
About this case study: This is an applied training exercise completed as
part of an AI GRC practitioner program, using a simulated organization and vendor to
demonstrate a full high-risk AI governance review end to end. It does not constitute legal
advice, regulatory certification, or an assessment of any real financial institution.
← Back to all projects