AI Governance Review: Automated Loan Underwriting System

Role: AI Governance Lead · Frameworks: EU AI Act · NIST AI RMF · ISO/IEC 42001
Applied Training Case Study
← Back to all projects

Executive Summary

As AI Governance Lead, I ran a high-risk AI governance assessment of Meridian Financial Services' pilot for an automated small business loan underwriting system — scoping the risk classification, running the review against three major frameworks, and producing the evidence package a governance committee would need to make a production decision.

The system uses a third-party AI model, CrediSure Credit Decision Engine v2.3, to evaluate small business loan applications and produce one of three outcomes: auto-approve, auto-deny, or route to manual review.

Because approximately 94% of applications are processed automatically and the system affects access to credit, I classified this as a high-risk AI use case requiring governance review before production deployment.

Final recommendation: Proceed with conditions. Meridian should not approve unrestricted production deployment until fairness testing, proxy-bias review, reason code validation, human oversight triggers, appeal procedures, vendor evidence review, monitoring thresholds, and governance committee approval are completed.
EU AI Act FRIA summary
EU AI Act FRIA summary for the Meridian Automated Loan Underwriting System, including stakeholder consultation status, flagged rights, risk score, and conditional approval recommendation.

Skills Demonstrated

High-risk AI classification Risk register & scoring Fundamental Rights Impact Assessment Third-party vendor governance Human oversight design Governance decision memos

Frameworks Applied

EU AI ActNIST AI Risk Management FrameworkISO/IEC 42001
High-risk AI classificationGovernance roles and responsibilitiesAI management system scope
Fundamental Rights Impact AssessmentSystem context and intended useOrganizational roles and responsibilities
Human oversightRisk measurement and testing evidenceAI risk assessment
LoggingRisk prioritization and treatmentAI risk treatment
Explanation to affected personsHuman-AI oversightManagement review
Appeal and contestabilityAI system lifecycle management
Deployment conditionsThird-party AI risk management

Central Governance Question

Should Meridian Financial Services approve production deployment of a 94% automated AI loan underwriting system?

My answer: Not for unrestricted production deployment. The system may proceed only with conditions because the current governance evidence does not fully support safe, fair, explainable, accountable, and well-monitored deployment.

Portfolio Artifacts

Practical AI Governance Skill Proof

1. Use Case Registration

Use case registration in VerifyWise
Use case registration detail
The Meridian Automated Loan Underwriting System registered as a high-risk AI use case in VerifyWise, with applicable frameworks, approval workflow, and pre-production governance status.
Skill demonstrated: AI use case intake, risk classification, and governance workflow setup.

2. Model Inventory

Model inventory
Model inventory detail
The CrediSure Credit Decision Engine v2.3 documented in the model inventory.
Skill demonstrated: Model inventory documentation, model limitation tracking, and third-party AI model governance.

3. Dataset Record

Dataset record
Dataset record detail
Dataset record fields
The Small Business Loan Underwriting Dataset registered in VerifyWise, including data purpose, source, format, PII status, known bias concerns, mitigation approach, and connection to the CrediSure Credit Decision Engine and Meridian Automated Loan Underwriting System.
Skill demonstrated: Dataset governance, PII awareness, data source documentation, and bias mitigation planning.

4. AI Risk Register

AI risk register
The six required risks for the Meridian Automated Loan Underwriting System, including risks imported from IBM AI Risk Database, MIT AI Risk Repository, and manually created custom risks.
Skill demonstrated: AI risk identification, risk rating, mitigation planning, residual risk analysis, and approval workflow documentation.

Key Risks Identified

RiskWhy It Matters
Discriminatory lending outcomesThe system may unfairly approve or deny applicants based on biased data, proxy variables, or historical lending patterns.
Proxy bias through credit and business variablesVariables such as geography, business age, industry, credit history, thin credit files, or cash-flow volatility may create unfair outcomes.
Weak explainability and incomplete reason codesMeridian may be unable to explain automated denials, support appeals, or demonstrate compliance during review.
Accountability gaps in third-party AI deploymentMeridian remains responsible for deployment even if the vendor controls key model details.
Inaccurate automated denialsQualified applicants may be incorrectly denied credit due to model error, incomplete data, or overly strict thresholds.
Lack of meaningful human oversightRouting only 6% of applications to human review may be insufficient for a high-risk credit decision system.

5. Vendor Record

Vendor record
Vendor record detail
Vendor record fields
The CrediSure AI vendor record in VerifyWise, documenting the third-party provider responsible for the credit decisioning model used by the Meridian Automated Loan Underwriting System.
Skill demonstrated: Third-party AI vendor risk management and vendor governance documentation.

6. Framework Assessments

Framework assessment
Framework assessment detail
The three must-have ISO 42001 Annex controls completed for the Meridian Automated Loan Underwriting System: AI governance framework, AI system lifecycle management, and third-party AI risk management.
Skill demonstrated: Practical framework application and evidence-based AI governance assessment.

7. Fundamental Rights Impact Assessment (FRIA) Summary

FRIA summary
The EU AI Act FRIA summary for the Meridian Automated Loan Underwriting System, including stakeholder consultation status, flagged rights, risk score, and conditional approval recommendation.
Skill demonstrated: Fundamental rights risk assessment, high-risk AI review, human oversight analysis, and conditional deployment recommendation.

8. Final Report

Oyinadesola Edu_AI_Governance_Portfolio_Report.pdf

Final report
The final VerifyWise portfolio report generated for the Meridian Automated Loan Underwriting System.
Skill demonstrated: Governance evidence organization and final reporting.

Final Recommendation

Proceed with conditions.

Meridian should not approve unrestricted production deployment at this time. The system may move forward only if the following conditions are completed:

Portfolio Conclusion

This project demonstrates my ability to evaluate a high-risk AI system from an AI governance, risk, and compliance perspective. The Meridian Automated Loan Underwriting System offers business benefits, including faster decisions, improved consistency, and operational efficiency. However, because it affects access to credit and automates most decisions, it requires strong governance before deployment.

As AI Governance Lead, my assessment found that the system should not receive unrestricted production approval until Meridian completes required fairness, explainability, human oversight, vendor, monitoring, privacy, and governance controls.

About this case study: This is an applied training exercise completed as part of an AI GRC practitioner program, using a simulated organization and vendor to demonstrate a full high-risk AI governance review end to end. It does not constitute legal advice, regulatory certification, or an assessment of any real financial institution.

← Back to all projects