By
October 3, 2026
9 min read
Deciding Whether to Build, Buy, or Augment Your AI Underwriting Stack



What "AI underwriting" actually means (and what it isn't)
AI underwriting is software that makes or materially informs the risk decision itself: approve, decline, price, or flag for human review, based on a model's read of financial, behavioral, or claims data. It is not the same thing as a loan origination system or a policy administration system, and conflating the two is the first mistake we see buyers make. An LOS manages the application, the documents, the workflow stages, and the handoffs between departments. AI underwriting is the engine that sits inside or alongside that workflow and actually scores the risk.
That distinction matters because it changes who you're buying from and what you're buying. A vendor like Zest AI builds credit risk models for banks and credit unions. Sixfold builds risk-decisioning tools for P&C and life insurers. Underwrite.ai focuses on credit risk modeling. Ocrolus and Uptiq sit closer to document intelligence feeding into lending decisions. None of these replace your core LOS or PAS. They plug into it, or they're supposed to.
If you're evaluating the application-intake side of this problem separately, we've written a dedicated breakdown on loan origination software build-vs-buy decisions that's worth reading alongside this one. This post is about the decision engine, not the paperwork around it.
Why lenders and insurers are automating underwriting now
The speed gains are real and large enough to justify the attention. BizTech Magazine reports that AI has cut underwriting decision time from 3 to 5 days down to 12.4 minutes for standard policies, and for complex policies, AI reduced processing time by 31% while improving risk assessment accuracy by 43% (BizTech Magazine, March 2025). Sixfold, one of the vendors in this space, claims a 50% reduction in underwriter review time, though that's a vendor-attributed figure rather than independently verified, worth noting if you see it repeated in sales decks. Deloitte's take on generative AI underwriting is more measured, and it's the right instinct: the firm argues that innovation has to be balanced against risk management and compliance, and that human oversight remains essential for complex cases (Deloitte). That's the tension every mid-market lender and insurer is navigating right now: the speed is real, but so is the exposure if the model gets it wrong and nobody can explain why.
Search behavior backs up how new this buying decision is. Query volume for "ai underwriting software" was near zero for most of the past year and spiked sharply in late 2026, which tells you this is a decision a lot of operations and compliance leaders are making for the first time, without much of a playbook to follow. Most of what's published is either a vendor homepage or an abstract explainer. Almost none of it is written from the buyer's seat.
Should you build, buy, or augment? The three paths explained
Buy means licensing a platform like Zest AI, Sixfold, or Underwrite.ai and adapting your process to fit its model and its data requirements. Build means Genta AI Solutions (or any firm doing custom engineering) constructs a risk-decisioning model and workflow trained on your own underwriting policy, your own historical outcomes, and your own risk appetite. Augment means you keep your existing LOS or PAS and add an AI layer, document intelligence, a scoring assist, a human-in-the-loop review agent, without replacing the underlying system of record. Vendor content almost never presents augment as a real third option, because it doesn't sell platform seats. But for a lot of mid-market lenders, augmenting the system you already have, rather than ripping it out for a new underwriting platform, is the cheaper and lower-risk path. You keep your compliance documentation, your examiner relationships understand the system, and you add a narrow AI capability (say, automated reason-code generation, or a triage model that routes files to the right underwriter) without betting the whole decisioning process on a vendor's black box.
The honest framework looks like this: buy when your underwriting policy is close to industry-standard and your volume justifies a subscription. Build when your risk appetite is genuinely non-standard, your historical data is a real asset, or you can't accept not owning the model. Augment when your core system works fine and the gap is narrow, like explainability or a specific bottleneck, not the whole decisioning process.
Where off-the-shelf underwriting AI breaks down
Three failure modes show up repeatedly, and none of them are visible in a vendor demo. The first is policy mismatch. Vendor risk models are trained on aggregate data across many lenders or insurers. If your underwriting policy has genuinely non-standard risk tolerances, say you intentionally underwrite a book of business other lenders avoid, a vendor's model will score against the market average, not your appetite. You end up either overriding the model constantly (which defeats the point) or drifting your risk policy toward what the vendor's model can handle.
The second is vendor lock-in. Once your underwriting decisions and your historical outcome data live inside a third-party platform, switching costs compound fast. You don't just lose a subscription, you lose the model's learned behavior on your book, and rebuilding that history with a new vendor can take a year or more.
The third, and the one that actually creates legal exposure, is explainability failure. Under the Consumer Financial Protection Bureau's Circular 2023-03, creditors using AI or complex algorithms still have to give specific, accurate reasons for adverse credit actions under ECOA and Regulation B. The CFPB is explicit that "the model is too complex to explain" is not a valid defense (CFPB Circular 2023-03). If your vendor's model can't generate specific, auditable reason codes tied to the actual variables that drove a decision, you have a compliance problem the vendor contract probably doesn't fix for you.
What building custom underwriting AI actually requires
The parts a vendor demo never shows you are the parts that take the most time. A real build starts with data pipelines out of your core system, your LOS, your claims system, or your policy admin platform, and those integrations are usually messier than anyone estimates up front. Legacy cores weren't built with API-first access in mind, and a meaningful chunk of a build timeline goes into getting clean, structured data flowing before a model ever gets trained. Model risk governance is the second piece, and it's not optional if you're a US bank or credit union. Federal Reserve SR 11-7, issued in 2011, remains the baseline supervisory guidance examiners apply to AI and machine learning underwriting models, covering model validation, ongoing monitoring, and documented limitations (Federal Reserve SR 11-7). A custom model needs a validation plan and a challenger model process built in from day one, not bolted on after an exam finding. Human-in-the-loop design is the third piece, and it's where most first attempts underperform. The question isn't whether to keep a human in the loop, it's which decisions route to a human and on what confidence threshold. We've built this pattern for clients outside underwriting too: at Preferred Med Network, document intake and case assignment run on autopilot and only raise exceptions when confidence is low or data is missing (case study). That same shape, autonomous on the clear cases, human review on the ambiguous ones, is exactly what a defensible underwriting agent needs, and it's the piece a vendor's generic confidence score usually can't tune to your specific risk tolerance.
Can you even buy this? The regulatory floor you can't negotiate around
You can buy underwriting AI and still comply, but only if you ask the vendor questions most buyers skip. For US lenders, two frameworks apply regardless of who built the model: ECOA and Regulation B require specific adverse-action reasons, and SR 11-7 requires documented model validation and ongoing monitoring, whether the model is yours or licensed. A vendor contract that doesn't give you the artifacts to satisfy both (reason-code logic, validation documentation, performance monitoring data) leaves the compliance burden on you with none of the tools to meet it. For insurers, the NAIC Model Bulletin on the Use of Artificial Intelligence Systems (Model #692, adopted in 2023) requires carriers to govern and audit third-party AI tools used in underwriting and claims, not just deploy them. We've written a full breakdown of what that bulletin actually requires in our NAIC AI Model Bulletin guide, which is worth reading in full if you're an MGA or carrier evaluating vendors right now. EU-based lenders and insurers face a sharper line. The EU AI Act classifies systems used to evaluate creditworthiness or establish credit scores of natural persons as high-risk under Annex III, which triggers obligations around risk management, data governance, logging, and human oversight, with phased compliance deadlines running through 2026 and 2027. If you're vetting a vendor and they can't tell you how their system satisfies Annex III documentation requirements, that's a disqualifying answer, not a minor gap. For the broader compliance picture around AI vendor contracts in financial services, our piece on what actually changes when compliance is non-negotiable goes deeper on contract terms worth insisting on.
A practical decision checklist
Before you pick a path, answer these honestly, in writing, with your compliance owner in the room:
What's your underwriting volume? Under a few thousand decisions a year, the economics rarely justify a custom build; buy or augment instead.
How close is your risk policy to industry standard? If a vendor's training data looks like your book, buying gets you most of the value for a fraction of the cost.
Can you get specific, auditable reason codes out of a vendor's model today, in writing, tied to your jurisdiction's adverse-action requirements?
Does your core LOS or PAS expose a real API, or will "integration" mean screen-scraping and brittle middleware?
Who owns model validation and monitoring once it's live, you or the vendor, and does that match who your examiner will actually hold accountable?
If the vendor shuts down or doubles pricing in three years, what happens to your historical model performance data?
If more than two of these point toward "we don't know" or "the vendor won't say," that's usually a signal to augment rather than buy outright, or to scope a custom build before committing to a multi-year platform contract.
If you're working through this decision, this is exactly what Genta AI Solutions' Discovery phase maps out before any model gets built, and we're happy to compare notes.
Frequently asked questions
What is AI underwriting, and how is it different from a decisioning engine or loan origination system?
AI underwriting is the model and logic that scores risk and recommends or makes an approve/decline/price decision. A loan origination system manages the application workflow around that decision: document collection, stage tracking, disclosures. They're often sold together but they solve different problems, and a lender can automate one without touching the other.
Is AI actually taking over underwriting, or just assisting human underwriters?
Mostly assisting, not replacing. Deloitte's research on generative AI in underwriting is explicit that human oversight remains essential for complex cases, and the fastest wins (standard policies, routine credit files) are where AI handles volume so underwriters focus on the judgment calls machines handle poorly.
Are banks and credit unions actually using AI for underwriting today?
Yes, though adoption is uneven. Vendors like Zest AI serve banks and credit unions directly, and most mid-market lenders are piloting some form of AI-assisted scoring or document review. Few are fully AI-native end to end; most run AI as an assist layer inside an existing decisioning process, which is a reasonable starting point.
Can a lender use AI underwriting and still comply with ECOA adverse-action notice requirements?
Yes, but it requires deliberate design. CFPB Circular 2023-03 makes clear that creditors must give specific, accurate reasons for adverse actions even when using complex algorithms, and "too complex to explain" isn't an acceptable answer. Any AI underwriting system, bought or built, needs a reason-code mechanism tied to the actual variables driving each decision.
Should a mid-market lender or insurer build custom underwriting AI or buy a platform like Zest AI or Sixfold?
Buy if your risk policy tracks industry norms and your volume supports a subscription. Build if your risk appetite is genuinely non-standard, your historical data is a real differentiator, or you need to own the model outright for governance reasons. Augment your existing system when the gap is narrow, like explainability or triage, not the whole decisioning process.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
October 3, 2026
9 min read
Deciding Whether to Build, Buy, or Augment Your AI Underwriting Stack



What "AI underwriting" actually means (and what it isn't)
AI underwriting is software that makes or materially informs the risk decision itself: approve, decline, price, or flag for human review, based on a model's read of financial, behavioral, or claims data. It is not the same thing as a loan origination system or a policy administration system, and conflating the two is the first mistake we see buyers make. An LOS manages the application, the documents, the workflow stages, and the handoffs between departments. AI underwriting is the engine that sits inside or alongside that workflow and actually scores the risk.
That distinction matters because it changes who you're buying from and what you're buying. A vendor like Zest AI builds credit risk models for banks and credit unions. Sixfold builds risk-decisioning tools for P&C and life insurers. Underwrite.ai focuses on credit risk modeling. Ocrolus and Uptiq sit closer to document intelligence feeding into lending decisions. None of these replace your core LOS or PAS. They plug into it, or they're supposed to.
If you're evaluating the application-intake side of this problem separately, we've written a dedicated breakdown on loan origination software build-vs-buy decisions that's worth reading alongside this one. This post is about the decision engine, not the paperwork around it.
Why lenders and insurers are automating underwriting now
The speed gains are real and large enough to justify the attention. BizTech Magazine reports that AI has cut underwriting decision time from 3 to 5 days down to 12.4 minutes for standard policies, and for complex policies, AI reduced processing time by 31% while improving risk assessment accuracy by 43% (BizTech Magazine, March 2025). Sixfold, one of the vendors in this space, claims a 50% reduction in underwriter review time, though that's a vendor-attributed figure rather than independently verified, worth noting if you see it repeated in sales decks. Deloitte's take on generative AI underwriting is more measured, and it's the right instinct: the firm argues that innovation has to be balanced against risk management and compliance, and that human oversight remains essential for complex cases (Deloitte). That's the tension every mid-market lender and insurer is navigating right now: the speed is real, but so is the exposure if the model gets it wrong and nobody can explain why.
Search behavior backs up how new this buying decision is. Query volume for "ai underwriting software" was near zero for most of the past year and spiked sharply in late 2026, which tells you this is a decision a lot of operations and compliance leaders are making for the first time, without much of a playbook to follow. Most of what's published is either a vendor homepage or an abstract explainer. Almost none of it is written from the buyer's seat.
Should you build, buy, or augment? The three paths explained
Buy means licensing a platform like Zest AI, Sixfold, or Underwrite.ai and adapting your process to fit its model and its data requirements. Build means Genta AI Solutions (or any firm doing custom engineering) constructs a risk-decisioning model and workflow trained on your own underwriting policy, your own historical outcomes, and your own risk appetite. Augment means you keep your existing LOS or PAS and add an AI layer, document intelligence, a scoring assist, a human-in-the-loop review agent, without replacing the underlying system of record. Vendor content almost never presents augment as a real third option, because it doesn't sell platform seats. But for a lot of mid-market lenders, augmenting the system you already have, rather than ripping it out for a new underwriting platform, is the cheaper and lower-risk path. You keep your compliance documentation, your examiner relationships understand the system, and you add a narrow AI capability (say, automated reason-code generation, or a triage model that routes files to the right underwriter) without betting the whole decisioning process on a vendor's black box.
The honest framework looks like this: buy when your underwriting policy is close to industry-standard and your volume justifies a subscription. Build when your risk appetite is genuinely non-standard, your historical data is a real asset, or you can't accept not owning the model. Augment when your core system works fine and the gap is narrow, like explainability or a specific bottleneck, not the whole decisioning process.
Where off-the-shelf underwriting AI breaks down
Three failure modes show up repeatedly, and none of them are visible in a vendor demo. The first is policy mismatch. Vendor risk models are trained on aggregate data across many lenders or insurers. If your underwriting policy has genuinely non-standard risk tolerances, say you intentionally underwrite a book of business other lenders avoid, a vendor's model will score against the market average, not your appetite. You end up either overriding the model constantly (which defeats the point) or drifting your risk policy toward what the vendor's model can handle.
The second is vendor lock-in. Once your underwriting decisions and your historical outcome data live inside a third-party platform, switching costs compound fast. You don't just lose a subscription, you lose the model's learned behavior on your book, and rebuilding that history with a new vendor can take a year or more.
The third, and the one that actually creates legal exposure, is explainability failure. Under the Consumer Financial Protection Bureau's Circular 2023-03, creditors using AI or complex algorithms still have to give specific, accurate reasons for adverse credit actions under ECOA and Regulation B. The CFPB is explicit that "the model is too complex to explain" is not a valid defense (CFPB Circular 2023-03). If your vendor's model can't generate specific, auditable reason codes tied to the actual variables that drove a decision, you have a compliance problem the vendor contract probably doesn't fix for you.
What building custom underwriting AI actually requires
The parts a vendor demo never shows you are the parts that take the most time. A real build starts with data pipelines out of your core system, your LOS, your claims system, or your policy admin platform, and those integrations are usually messier than anyone estimates up front. Legacy cores weren't built with API-first access in mind, and a meaningful chunk of a build timeline goes into getting clean, structured data flowing before a model ever gets trained. Model risk governance is the second piece, and it's not optional if you're a US bank or credit union. Federal Reserve SR 11-7, issued in 2011, remains the baseline supervisory guidance examiners apply to AI and machine learning underwriting models, covering model validation, ongoing monitoring, and documented limitations (Federal Reserve SR 11-7). A custom model needs a validation plan and a challenger model process built in from day one, not bolted on after an exam finding. Human-in-the-loop design is the third piece, and it's where most first attempts underperform. The question isn't whether to keep a human in the loop, it's which decisions route to a human and on what confidence threshold. We've built this pattern for clients outside underwriting too: at Preferred Med Network, document intake and case assignment run on autopilot and only raise exceptions when confidence is low or data is missing (case study). That same shape, autonomous on the clear cases, human review on the ambiguous ones, is exactly what a defensible underwriting agent needs, and it's the piece a vendor's generic confidence score usually can't tune to your specific risk tolerance.
Can you even buy this? The regulatory floor you can't negotiate around
You can buy underwriting AI and still comply, but only if you ask the vendor questions most buyers skip. For US lenders, two frameworks apply regardless of who built the model: ECOA and Regulation B require specific adverse-action reasons, and SR 11-7 requires documented model validation and ongoing monitoring, whether the model is yours or licensed. A vendor contract that doesn't give you the artifacts to satisfy both (reason-code logic, validation documentation, performance monitoring data) leaves the compliance burden on you with none of the tools to meet it. For insurers, the NAIC Model Bulletin on the Use of Artificial Intelligence Systems (Model #692, adopted in 2023) requires carriers to govern and audit third-party AI tools used in underwriting and claims, not just deploy them. We've written a full breakdown of what that bulletin actually requires in our NAIC AI Model Bulletin guide, which is worth reading in full if you're an MGA or carrier evaluating vendors right now. EU-based lenders and insurers face a sharper line. The EU AI Act classifies systems used to evaluate creditworthiness or establish credit scores of natural persons as high-risk under Annex III, which triggers obligations around risk management, data governance, logging, and human oversight, with phased compliance deadlines running through 2026 and 2027. If you're vetting a vendor and they can't tell you how their system satisfies Annex III documentation requirements, that's a disqualifying answer, not a minor gap. For the broader compliance picture around AI vendor contracts in financial services, our piece on what actually changes when compliance is non-negotiable goes deeper on contract terms worth insisting on.
A practical decision checklist
Before you pick a path, answer these honestly, in writing, with your compliance owner in the room:
What's your underwriting volume? Under a few thousand decisions a year, the economics rarely justify a custom build; buy or augment instead.
How close is your risk policy to industry standard? If a vendor's training data looks like your book, buying gets you most of the value for a fraction of the cost.
Can you get specific, auditable reason codes out of a vendor's model today, in writing, tied to your jurisdiction's adverse-action requirements?
Does your core LOS or PAS expose a real API, or will "integration" mean screen-scraping and brittle middleware?
Who owns model validation and monitoring once it's live, you or the vendor, and does that match who your examiner will actually hold accountable?
If the vendor shuts down or doubles pricing in three years, what happens to your historical model performance data?
If more than two of these point toward "we don't know" or "the vendor won't say," that's usually a signal to augment rather than buy outright, or to scope a custom build before committing to a multi-year platform contract.
If you're working through this decision, this is exactly what Genta AI Solutions' Discovery phase maps out before any model gets built, and we're happy to compare notes.
Frequently asked questions
What is AI underwriting, and how is it different from a decisioning engine or loan origination system?
AI underwriting is the model and logic that scores risk and recommends or makes an approve/decline/price decision. A loan origination system manages the application workflow around that decision: document collection, stage tracking, disclosures. They're often sold together but they solve different problems, and a lender can automate one without touching the other.
Is AI actually taking over underwriting, or just assisting human underwriters?
Mostly assisting, not replacing. Deloitte's research on generative AI in underwriting is explicit that human oversight remains essential for complex cases, and the fastest wins (standard policies, routine credit files) are where AI handles volume so underwriters focus on the judgment calls machines handle poorly.
Are banks and credit unions actually using AI for underwriting today?
Yes, though adoption is uneven. Vendors like Zest AI serve banks and credit unions directly, and most mid-market lenders are piloting some form of AI-assisted scoring or document review. Few are fully AI-native end to end; most run AI as an assist layer inside an existing decisioning process, which is a reasonable starting point.
Can a lender use AI underwriting and still comply with ECOA adverse-action notice requirements?
Yes, but it requires deliberate design. CFPB Circular 2023-03 makes clear that creditors must give specific, accurate reasons for adverse actions even when using complex algorithms, and "too complex to explain" isn't an acceptable answer. Any AI underwriting system, bought or built, needs a reason-code mechanism tied to the actual variables driving each decision.
Should a mid-market lender or insurer build custom underwriting AI or buy a platform like Zest AI or Sixfold?
Buy if your risk policy tracks industry norms and your volume supports a subscription. Build if your risk appetite is genuinely non-standard, your historical data is a real differentiator, or you need to own the model outright for governance reasons. Augment your existing system when the gap is narrow, like explainability or triage, not the whole decisioning process.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
October 3, 2026
9 min read
Deciding Whether to Build, Buy, or Augment Your AI Underwriting Stack



What "AI underwriting" actually means (and what it isn't)
AI underwriting is software that makes or materially informs the risk decision itself: approve, decline, price, or flag for human review, based on a model's read of financial, behavioral, or claims data. It is not the same thing as a loan origination system or a policy administration system, and conflating the two is the first mistake we see buyers make. An LOS manages the application, the documents, the workflow stages, and the handoffs between departments. AI underwriting is the engine that sits inside or alongside that workflow and actually scores the risk.
That distinction matters because it changes who you're buying from and what you're buying. A vendor like Zest AI builds credit risk models for banks and credit unions. Sixfold builds risk-decisioning tools for P&C and life insurers. Underwrite.ai focuses on credit risk modeling. Ocrolus and Uptiq sit closer to document intelligence feeding into lending decisions. None of these replace your core LOS or PAS. They plug into it, or they're supposed to.
If you're evaluating the application-intake side of this problem separately, we've written a dedicated breakdown on loan origination software build-vs-buy decisions that's worth reading alongside this one. This post is about the decision engine, not the paperwork around it.
Why lenders and insurers are automating underwriting now
The speed gains are real and large enough to justify the attention. BizTech Magazine reports that AI has cut underwriting decision time from 3 to 5 days down to 12.4 minutes for standard policies, and for complex policies, AI reduced processing time by 31% while improving risk assessment accuracy by 43% (BizTech Magazine, March 2025). Sixfold, one of the vendors in this space, claims a 50% reduction in underwriter review time, though that's a vendor-attributed figure rather than independently verified, worth noting if you see it repeated in sales decks. Deloitte's take on generative AI underwriting is more measured, and it's the right instinct: the firm argues that innovation has to be balanced against risk management and compliance, and that human oversight remains essential for complex cases (Deloitte). That's the tension every mid-market lender and insurer is navigating right now: the speed is real, but so is the exposure if the model gets it wrong and nobody can explain why.
Search behavior backs up how new this buying decision is. Query volume for "ai underwriting software" was near zero for most of the past year and spiked sharply in late 2026, which tells you this is a decision a lot of operations and compliance leaders are making for the first time, without much of a playbook to follow. Most of what's published is either a vendor homepage or an abstract explainer. Almost none of it is written from the buyer's seat.
Should you build, buy, or augment? The three paths explained
Buy means licensing a platform like Zest AI, Sixfold, or Underwrite.ai and adapting your process to fit its model and its data requirements. Build means Genta AI Solutions (or any firm doing custom engineering) constructs a risk-decisioning model and workflow trained on your own underwriting policy, your own historical outcomes, and your own risk appetite. Augment means you keep your existing LOS or PAS and add an AI layer, document intelligence, a scoring assist, a human-in-the-loop review agent, without replacing the underlying system of record. Vendor content almost never presents augment as a real third option, because it doesn't sell platform seats. But for a lot of mid-market lenders, augmenting the system you already have, rather than ripping it out for a new underwriting platform, is the cheaper and lower-risk path. You keep your compliance documentation, your examiner relationships understand the system, and you add a narrow AI capability (say, automated reason-code generation, or a triage model that routes files to the right underwriter) without betting the whole decisioning process on a vendor's black box.
The honest framework looks like this: buy when your underwriting policy is close to industry-standard and your volume justifies a subscription. Build when your risk appetite is genuinely non-standard, your historical data is a real asset, or you can't accept not owning the model. Augment when your core system works fine and the gap is narrow, like explainability or a specific bottleneck, not the whole decisioning process.
Where off-the-shelf underwriting AI breaks down
Three failure modes show up repeatedly, and none of them are visible in a vendor demo. The first is policy mismatch. Vendor risk models are trained on aggregate data across many lenders or insurers. If your underwriting policy has genuinely non-standard risk tolerances, say you intentionally underwrite a book of business other lenders avoid, a vendor's model will score against the market average, not your appetite. You end up either overriding the model constantly (which defeats the point) or drifting your risk policy toward what the vendor's model can handle.
The second is vendor lock-in. Once your underwriting decisions and your historical outcome data live inside a third-party platform, switching costs compound fast. You don't just lose a subscription, you lose the model's learned behavior on your book, and rebuilding that history with a new vendor can take a year or more.
The third, and the one that actually creates legal exposure, is explainability failure. Under the Consumer Financial Protection Bureau's Circular 2023-03, creditors using AI or complex algorithms still have to give specific, accurate reasons for adverse credit actions under ECOA and Regulation B. The CFPB is explicit that "the model is too complex to explain" is not a valid defense (CFPB Circular 2023-03). If your vendor's model can't generate specific, auditable reason codes tied to the actual variables that drove a decision, you have a compliance problem the vendor contract probably doesn't fix for you.
What building custom underwriting AI actually requires
The parts a vendor demo never shows you are the parts that take the most time. A real build starts with data pipelines out of your core system, your LOS, your claims system, or your policy admin platform, and those integrations are usually messier than anyone estimates up front. Legacy cores weren't built with API-first access in mind, and a meaningful chunk of a build timeline goes into getting clean, structured data flowing before a model ever gets trained. Model risk governance is the second piece, and it's not optional if you're a US bank or credit union. Federal Reserve SR 11-7, issued in 2011, remains the baseline supervisory guidance examiners apply to AI and machine learning underwriting models, covering model validation, ongoing monitoring, and documented limitations (Federal Reserve SR 11-7). A custom model needs a validation plan and a challenger model process built in from day one, not bolted on after an exam finding. Human-in-the-loop design is the third piece, and it's where most first attempts underperform. The question isn't whether to keep a human in the loop, it's which decisions route to a human and on what confidence threshold. We've built this pattern for clients outside underwriting too: at Preferred Med Network, document intake and case assignment run on autopilot and only raise exceptions when confidence is low or data is missing (case study). That same shape, autonomous on the clear cases, human review on the ambiguous ones, is exactly what a defensible underwriting agent needs, and it's the piece a vendor's generic confidence score usually can't tune to your specific risk tolerance.
Can you even buy this? The regulatory floor you can't negotiate around
You can buy underwriting AI and still comply, but only if you ask the vendor questions most buyers skip. For US lenders, two frameworks apply regardless of who built the model: ECOA and Regulation B require specific adverse-action reasons, and SR 11-7 requires documented model validation and ongoing monitoring, whether the model is yours or licensed. A vendor contract that doesn't give you the artifacts to satisfy both (reason-code logic, validation documentation, performance monitoring data) leaves the compliance burden on you with none of the tools to meet it. For insurers, the NAIC Model Bulletin on the Use of Artificial Intelligence Systems (Model #692, adopted in 2023) requires carriers to govern and audit third-party AI tools used in underwriting and claims, not just deploy them. We've written a full breakdown of what that bulletin actually requires in our NAIC AI Model Bulletin guide, which is worth reading in full if you're an MGA or carrier evaluating vendors right now. EU-based lenders and insurers face a sharper line. The EU AI Act classifies systems used to evaluate creditworthiness or establish credit scores of natural persons as high-risk under Annex III, which triggers obligations around risk management, data governance, logging, and human oversight, with phased compliance deadlines running through 2026 and 2027. If you're vetting a vendor and they can't tell you how their system satisfies Annex III documentation requirements, that's a disqualifying answer, not a minor gap. For the broader compliance picture around AI vendor contracts in financial services, our piece on what actually changes when compliance is non-negotiable goes deeper on contract terms worth insisting on.
A practical decision checklist
Before you pick a path, answer these honestly, in writing, with your compliance owner in the room:
What's your underwriting volume? Under a few thousand decisions a year, the economics rarely justify a custom build; buy or augment instead.
How close is your risk policy to industry standard? If a vendor's training data looks like your book, buying gets you most of the value for a fraction of the cost.
Can you get specific, auditable reason codes out of a vendor's model today, in writing, tied to your jurisdiction's adverse-action requirements?
Does your core LOS or PAS expose a real API, or will "integration" mean screen-scraping and brittle middleware?
Who owns model validation and monitoring once it's live, you or the vendor, and does that match who your examiner will actually hold accountable?
If the vendor shuts down or doubles pricing in three years, what happens to your historical model performance data?
If more than two of these point toward "we don't know" or "the vendor won't say," that's usually a signal to augment rather than buy outright, or to scope a custom build before committing to a multi-year platform contract.
If you're working through this decision, this is exactly what Genta AI Solutions' Discovery phase maps out before any model gets built, and we're happy to compare notes.
Frequently asked questions
What is AI underwriting, and how is it different from a decisioning engine or loan origination system?
AI underwriting is the model and logic that scores risk and recommends or makes an approve/decline/price decision. A loan origination system manages the application workflow around that decision: document collection, stage tracking, disclosures. They're often sold together but they solve different problems, and a lender can automate one without touching the other.
Is AI actually taking over underwriting, or just assisting human underwriters?
Mostly assisting, not replacing. Deloitte's research on generative AI in underwriting is explicit that human oversight remains essential for complex cases, and the fastest wins (standard policies, routine credit files) are where AI handles volume so underwriters focus on the judgment calls machines handle poorly.
Are banks and credit unions actually using AI for underwriting today?
Yes, though adoption is uneven. Vendors like Zest AI serve banks and credit unions directly, and most mid-market lenders are piloting some form of AI-assisted scoring or document review. Few are fully AI-native end to end; most run AI as an assist layer inside an existing decisioning process, which is a reasonable starting point.
Can a lender use AI underwriting and still comply with ECOA adverse-action notice requirements?
Yes, but it requires deliberate design. CFPB Circular 2023-03 makes clear that creditors must give specific, accurate reasons for adverse actions even when using complex algorithms, and "too complex to explain" isn't an acceptable answer. Any AI underwriting system, bought or built, needs a reason-code mechanism tied to the actual variables driving each decision.
Should a mid-market lender or insurer build custom underwriting AI or buy a platform like Zest AI or Sixfold?
Buy if your risk policy tracks industry norms and your volume supports a subscription. Build if your risk appetite is genuinely non-standard, your historical data is a real differentiator, or you need to own the model outright for governance reasons. Augment your existing system when the gap is narrow, like explainability or triage, not the whole decisioning process.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.