By
August 25, 2026
10 min read
Why Loan Origination Software Breaks Down on Non-Standard Underwriting



What loan origination software actually automates, and where it stops
Loan origination software (LOS) automates the parts of the loan lifecycle that are the same every time: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing a file between underwriter, processor, and closer. Platforms like Encompass, nCino, Blend, and MeridianLink do this well for mortgage and vanilla consumer lending, where the underwriting logic is largely dictated by GSE guidelines or a handful of well-known rules. That's the whole category, and it's a real one: banks and credit unions have run on this model for a decade because most of their loan volume is standard enough for a rules engine to handle.
Where it stops is underwriting judgment. The moment a loan doesn't fit the platform's decision tree, cash-flow lending against alternative data, a specialty asset class the vendor never built a module for, a community bank loan participation split across three institutions, an embedded lending product underwritten inside someone else's checkout flow, the LOS turns into a workflow shell around a manual process. Underwriters end up pulling data out of the system, running the real analysis in a spreadsheet, and keying the answer back in. You're paying six figures a year for a filing cabinet with a nice UI.
The real buyer question: license an LOS, build a custom underwriting agent, or both
Most lenders frame this as "which vendor should we pick," and that's the wrong question. The right one is whether your underwriting logic is standard enough to live inside someone else's rules engine, or specific enough that you need to own the decisioning layer yourself. Those are different problems with different answers, and a lot of institutions buy an LOS to solve the second problem, then spend two years fighting the platform's assumptions.
The honest answer for most lenders is "both, at different layers." An LOS is genuinely good at intake, document management, and audit trails, the plumbing nobody wants to build from scratch. A custom underwriting agent earns its keep at the decisioning layer, where your credit policy, your data sources, and your risk appetite are actually differentiated. Treating this as a single vendor-selection exercise is how banks end up buying a platform that's 80% right and then quietly building shadow spreadsheets to cover the other 20%, which is worse than either option done deliberately.
Why off-the-shelf loan origination systems struggle with non-standard underwriting
Four patterns show up over and over in lending shops that outgrow their LOS.
Alternative data. If your underwriting pulls in bank transaction data, POS revenue, or utility payment history instead of (or alongside) a FICO score, most LOS rules engines can ingest the data but can't reason over it the way your credit team does. You end up exporting to a data science tool, scoring outside the platform, and re-importing a number the LOS treats as a black box input.
Specialty asset classes. Equipment finance, agricultural lending, franchise lending, and non-QM mortgage all have underwriting logic that doesn't match the templates baked into mainstream platforms. Vendors will sell you a "configurable" rules engine, but configuration usually means IT tickets and change requests, not something your credit team can adjust when policy shifts.
Community bank loan consortiums. Participation loans split across multiple institutions need shared visibility into a single credit file with different permission and reporting requirements per institution. Most LOS platforms assume one lender, one file, one decision, and bolting on multi-institution logic is a custom project regardless of which vendor you pick.
Embedded and vertical lending. If you're underwriting inside a partner's checkout or a vertical SaaS product, the LOS needs to plug into someone else's stack via API, in real time, with a decision returned in seconds. Most legacy LOS platforms were built for a human-paced workflow, not a sub-second embedded decision, and retrofitting that is closer to building new infrastructure than configuring existing infrastructure.
None of this means LOS vendors are bad at their job. It means their job is standard-flow origination, and a meaningful share of mid-market and specialty lenders don't have a standard flow.
Can AI legally make or influence a credit decision?
Yes, but only if you can explain the specific reasons behind every denial, and "the model said no" is not a specific reason. The Consumer Financial Protection Bureau made this explicit in Circular 2022-03: adverse-action notice requirements under the Equal Credit Opportunity Act apply in full to decisions made with AI or complex algorithmic models. There is no carve-out for complexity. The CFPB followed up with more direct guidance in 2023, stating flatly that lenders using AI models must still give applicants accurate, specific reasons for a denial, not generic or boilerplate explanations pulled from a template that doesn't reflect what the model actually weighed (CFPB, September 2023).
This is where a vendor's opaque scoring engine becomes a real liability, not a hypothetical one. If your LOS's proprietary risk score contributes to a denial and you can't articulate which factors drove that score for that applicant, you have an ECOA problem regardless of how accurate the model is. This is also where owning the decisioning layer stops being an engineering preference and becomes a compliance requirement. A system you built and can trace end to end gives your compliance team an actual answer when an examiner or an applicant asks why. A vendor's black-box score gives you a support ticket.
Is creditworthiness assessment "high-risk" under the EU AI Act?
Yes, explicitly. Under Annex III of the EU AI Act, AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are classified as high-risk, and Article 6 sets out the classification mechanism that puts them there. High-risk classification isn't a label, it's a set of obligations: documented risk management processes, technical documentation you can hand to a regulator, human oversight built into the workflow rather than bolted on after the fact, and accuracy and robustness testing you can show your work on.
Any lender taking applications from EU consumers, directly or through an embedded partner, needs to treat this as a live compliance requirement now, not a future item. If your underwriting decisioning runs inside a vendor's platform, you're dependent on that vendor's documentation and audit posture to meet these obligations, and most mainstream LOS vendors were not built with EU AI Act Annex III in mind. We've covered the broader timeline and requirements in more detail in what the EU AI Act's high-risk deadline means for US and Singapore companies, and the compliance logic here runs parallel to the AML monitoring space, where the same buy-vs-build tension shows up for a different regulatory reason (see how banks and fintechs should decide on AML transaction monitoring software).
What it actually costs and how long it takes: LOS licensing vs. a custom underwriting agent
An LOS license for a mid-market lender typically runs from the low six figures to well over a million dollars a year depending on volume, modules, and integrations, and that's before implementation, which commonly runs six to twelve months for anything beyond a plain-vanilla configuration. You're renting the platform for as long as you use it, and every custom rule or non-standard asset class you add usually means a change order and a queue.
A custom underwriting agent is a different cost shape. You pay for the build once, you own the code and the models afterward, and you're not paying a per-seat or per-loan licensing fee indefinitely. Genta's typical project timeline across lending-adjacent and financial operations work runs 2 to 24 weeks depending on scope, and the honest comparison isn't "LOS is cheap, custom is expensive." It's that LOS pricing scales with volume forever, while a custom build front-loads the cost and then the marginal cost per loan approaches zero. For a lender processing thousands of non-standard loans a year, that math flips in favor of ownership faster than most buyers expect.
The catch, and we say this to clients directly: a custom underwriting agent is only worth building if your underwriting logic is genuinely differentiated. If your credit policy is close to boilerplate, buy the LOS and stop there. The build-vs-buy decision should follow from what your credit team actually does, not from a general preference for owning software. This is the same diagnostic discipline that mattered in a very different lending context: when Genta rebuilt billing operations for C&G Energy Services, most of the fix was process automation and integration work, not AI, and the value came from diagnosing the actual bottleneck before writing code, not from defaulting to "build" (case study).
A practical decision framework: when to buy, when to build, when to do both
Run your lending operation through these questions before you sign an LOS contract or scope a custom build.
Is your underwriting logic documented in a policy manual, or does it live in your senior underwriters' heads? If it's the latter, no off-the-shelf rules engine will replicate it, and you need a build phase just to formalize the logic before you can automate it.
Can you name the specific factors behind every adverse-action notice you send today? If the honest answer is "not really," that's a compliance gap regardless of what you buy next, and it's worth fixing before adding any AI to the decision.
Do you originate to EU consumers or through EU-based partners? If yes, Annex III obligations apply now, and vendor documentation quality should be a contract term, not an afterthought.
What share of your loan volume is standard flow versus exception handling? If exceptions are under 10%, an LOS with a manual override process is probably fine. Past 20-30%, you're paying for a platform that handles a minority of your actual work.
Who owns the model logic if you switch vendors in three years? If the answer is "the vendor," you're renting your credit policy, and that's worth pricing in as a real cost, not just a licensing line item.
McKinsey's July 2025 research on gen AI in credit found that 52% of banks now treat generative AI as a strategic priority in their credit business, but most are still early in actual deployment (McKinsey). That gap between intent and execution is exactly where the build-vs-buy decision gets made badly, usually by picking the vendor with the best sales deck rather than the one that matches the actual underwriting problem. A separate McKinsey study on small-business lending found banks using AI specifically to flag loans likely to underperform, a targeted augmentation use case that sits well inside a hybrid approach: LOS for intake and workflow, custom model for the risk signal that actually moves the needle (McKinsey).
If you're working through this decision, this is exactly what our Discovery phase maps out before any code gets written, and we're happy to compare notes. For lenders exploring what a custom decisioning layer actually involves, our AI agent development work covers the same build discipline referenced throughout this piece, and the debt-collection side of the lifecycle has its own regulatory pressure worth understanding alongside this one (what Regulation F and the CFPB mean for AI debt collection software), as does the broader compliance picture across financial services agents (AI agents in financial services, what changes when compliance is non-negotiable).
Frequently asked questions
What is loan origination software and what does it actually automate?
Loan origination software automates the repeatable parts of the loan lifecycle: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing files between underwriters, processors, and closers. It's built for standard consumer and mortgage flows. Non-standard underwriting, alternative data, or specialty asset classes usually fall outside what the platform handles well.
Can a lender legally let AI make or influence a credit decision?
Yes, but ECOA and Regulation B adverse-action requirements apply in full. Per CFPB Circular 2022-03, lenders must give applicants specific, accurate reasons for denial, even when a complex algorithm contributed to the decision. "The model said no" doesn't satisfy that requirement, so explainability has to be built into the system, not added after a denial is issued.
Is credit scoring or creditworthiness assessment considered "high-risk" under the EU AI Act?
Yes. Annex III of the EU AI Act explicitly classifies AI systems that evaluate creditworthiness or credit scoring of natural persons as high-risk. That triggers obligations around documentation, human oversight, and risk management for any lender serving EU consumers, directly or through embedded partners.
What's the real difference between buying a loan origination system and building a custom underwriting agent?
An LOS gives you standardized workflow, intake, and compliance checks fast, but you're renting a rules engine built for average cases. A custom underwriting agent costs more upfront but you own the decisioning logic outright, which matters most when your credit policy, data sources, or asset classes don't fit a vendor's template.
How long does it take to implement an LOS versus build a custom AI underwriting workflow?
A standard LOS implementation typically takes six to twelve months once you include integrations and configuration. Custom underwriting builds vary more by scope, commonly 2 to 24 weeks for a defined decisioning workflow, because you're building exactly what your credit policy needs rather than configuring a general-purpose platform around it.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
August 25, 2026
10 min read
Why Loan Origination Software Breaks Down on Non-Standard Underwriting



What loan origination software actually automates, and where it stops
Loan origination software (LOS) automates the parts of the loan lifecycle that are the same every time: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing a file between underwriter, processor, and closer. Platforms like Encompass, nCino, Blend, and MeridianLink do this well for mortgage and vanilla consumer lending, where the underwriting logic is largely dictated by GSE guidelines or a handful of well-known rules. That's the whole category, and it's a real one: banks and credit unions have run on this model for a decade because most of their loan volume is standard enough for a rules engine to handle.
Where it stops is underwriting judgment. The moment a loan doesn't fit the platform's decision tree, cash-flow lending against alternative data, a specialty asset class the vendor never built a module for, a community bank loan participation split across three institutions, an embedded lending product underwritten inside someone else's checkout flow, the LOS turns into a workflow shell around a manual process. Underwriters end up pulling data out of the system, running the real analysis in a spreadsheet, and keying the answer back in. You're paying six figures a year for a filing cabinet with a nice UI.
The real buyer question: license an LOS, build a custom underwriting agent, or both
Most lenders frame this as "which vendor should we pick," and that's the wrong question. The right one is whether your underwriting logic is standard enough to live inside someone else's rules engine, or specific enough that you need to own the decisioning layer yourself. Those are different problems with different answers, and a lot of institutions buy an LOS to solve the second problem, then spend two years fighting the platform's assumptions.
The honest answer for most lenders is "both, at different layers." An LOS is genuinely good at intake, document management, and audit trails, the plumbing nobody wants to build from scratch. A custom underwriting agent earns its keep at the decisioning layer, where your credit policy, your data sources, and your risk appetite are actually differentiated. Treating this as a single vendor-selection exercise is how banks end up buying a platform that's 80% right and then quietly building shadow spreadsheets to cover the other 20%, which is worse than either option done deliberately.
Why off-the-shelf loan origination systems struggle with non-standard underwriting
Four patterns show up over and over in lending shops that outgrow their LOS.
Alternative data. If your underwriting pulls in bank transaction data, POS revenue, or utility payment history instead of (or alongside) a FICO score, most LOS rules engines can ingest the data but can't reason over it the way your credit team does. You end up exporting to a data science tool, scoring outside the platform, and re-importing a number the LOS treats as a black box input.
Specialty asset classes. Equipment finance, agricultural lending, franchise lending, and non-QM mortgage all have underwriting logic that doesn't match the templates baked into mainstream platforms. Vendors will sell you a "configurable" rules engine, but configuration usually means IT tickets and change requests, not something your credit team can adjust when policy shifts.
Community bank loan consortiums. Participation loans split across multiple institutions need shared visibility into a single credit file with different permission and reporting requirements per institution. Most LOS platforms assume one lender, one file, one decision, and bolting on multi-institution logic is a custom project regardless of which vendor you pick.
Embedded and vertical lending. If you're underwriting inside a partner's checkout or a vertical SaaS product, the LOS needs to plug into someone else's stack via API, in real time, with a decision returned in seconds. Most legacy LOS platforms were built for a human-paced workflow, not a sub-second embedded decision, and retrofitting that is closer to building new infrastructure than configuring existing infrastructure.
None of this means LOS vendors are bad at their job. It means their job is standard-flow origination, and a meaningful share of mid-market and specialty lenders don't have a standard flow.
Can AI legally make or influence a credit decision?
Yes, but only if you can explain the specific reasons behind every denial, and "the model said no" is not a specific reason. The Consumer Financial Protection Bureau made this explicit in Circular 2022-03: adverse-action notice requirements under the Equal Credit Opportunity Act apply in full to decisions made with AI or complex algorithmic models. There is no carve-out for complexity. The CFPB followed up with more direct guidance in 2023, stating flatly that lenders using AI models must still give applicants accurate, specific reasons for a denial, not generic or boilerplate explanations pulled from a template that doesn't reflect what the model actually weighed (CFPB, September 2023).
This is where a vendor's opaque scoring engine becomes a real liability, not a hypothetical one. If your LOS's proprietary risk score contributes to a denial and you can't articulate which factors drove that score for that applicant, you have an ECOA problem regardless of how accurate the model is. This is also where owning the decisioning layer stops being an engineering preference and becomes a compliance requirement. A system you built and can trace end to end gives your compliance team an actual answer when an examiner or an applicant asks why. A vendor's black-box score gives you a support ticket.
Is creditworthiness assessment "high-risk" under the EU AI Act?
Yes, explicitly. Under Annex III of the EU AI Act, AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are classified as high-risk, and Article 6 sets out the classification mechanism that puts them there. High-risk classification isn't a label, it's a set of obligations: documented risk management processes, technical documentation you can hand to a regulator, human oversight built into the workflow rather than bolted on after the fact, and accuracy and robustness testing you can show your work on.
Any lender taking applications from EU consumers, directly or through an embedded partner, needs to treat this as a live compliance requirement now, not a future item. If your underwriting decisioning runs inside a vendor's platform, you're dependent on that vendor's documentation and audit posture to meet these obligations, and most mainstream LOS vendors were not built with EU AI Act Annex III in mind. We've covered the broader timeline and requirements in more detail in what the EU AI Act's high-risk deadline means for US and Singapore companies, and the compliance logic here runs parallel to the AML monitoring space, where the same buy-vs-build tension shows up for a different regulatory reason (see how banks and fintechs should decide on AML transaction monitoring software).
What it actually costs and how long it takes: LOS licensing vs. a custom underwriting agent
An LOS license for a mid-market lender typically runs from the low six figures to well over a million dollars a year depending on volume, modules, and integrations, and that's before implementation, which commonly runs six to twelve months for anything beyond a plain-vanilla configuration. You're renting the platform for as long as you use it, and every custom rule or non-standard asset class you add usually means a change order and a queue.
A custom underwriting agent is a different cost shape. You pay for the build once, you own the code and the models afterward, and you're not paying a per-seat or per-loan licensing fee indefinitely. Genta's typical project timeline across lending-adjacent and financial operations work runs 2 to 24 weeks depending on scope, and the honest comparison isn't "LOS is cheap, custom is expensive." It's that LOS pricing scales with volume forever, while a custom build front-loads the cost and then the marginal cost per loan approaches zero. For a lender processing thousands of non-standard loans a year, that math flips in favor of ownership faster than most buyers expect.
The catch, and we say this to clients directly: a custom underwriting agent is only worth building if your underwriting logic is genuinely differentiated. If your credit policy is close to boilerplate, buy the LOS and stop there. The build-vs-buy decision should follow from what your credit team actually does, not from a general preference for owning software. This is the same diagnostic discipline that mattered in a very different lending context: when Genta rebuilt billing operations for C&G Energy Services, most of the fix was process automation and integration work, not AI, and the value came from diagnosing the actual bottleneck before writing code, not from defaulting to "build" (case study).
A practical decision framework: when to buy, when to build, when to do both
Run your lending operation through these questions before you sign an LOS contract or scope a custom build.
Is your underwriting logic documented in a policy manual, or does it live in your senior underwriters' heads? If it's the latter, no off-the-shelf rules engine will replicate it, and you need a build phase just to formalize the logic before you can automate it.
Can you name the specific factors behind every adverse-action notice you send today? If the honest answer is "not really," that's a compliance gap regardless of what you buy next, and it's worth fixing before adding any AI to the decision.
Do you originate to EU consumers or through EU-based partners? If yes, Annex III obligations apply now, and vendor documentation quality should be a contract term, not an afterthought.
What share of your loan volume is standard flow versus exception handling? If exceptions are under 10%, an LOS with a manual override process is probably fine. Past 20-30%, you're paying for a platform that handles a minority of your actual work.
Who owns the model logic if you switch vendors in three years? If the answer is "the vendor," you're renting your credit policy, and that's worth pricing in as a real cost, not just a licensing line item.
McKinsey's July 2025 research on gen AI in credit found that 52% of banks now treat generative AI as a strategic priority in their credit business, but most are still early in actual deployment (McKinsey). That gap between intent and execution is exactly where the build-vs-buy decision gets made badly, usually by picking the vendor with the best sales deck rather than the one that matches the actual underwriting problem. A separate McKinsey study on small-business lending found banks using AI specifically to flag loans likely to underperform, a targeted augmentation use case that sits well inside a hybrid approach: LOS for intake and workflow, custom model for the risk signal that actually moves the needle (McKinsey).
If you're working through this decision, this is exactly what our Discovery phase maps out before any code gets written, and we're happy to compare notes. For lenders exploring what a custom decisioning layer actually involves, our AI agent development work covers the same build discipline referenced throughout this piece, and the debt-collection side of the lifecycle has its own regulatory pressure worth understanding alongside this one (what Regulation F and the CFPB mean for AI debt collection software), as does the broader compliance picture across financial services agents (AI agents in financial services, what changes when compliance is non-negotiable).
Frequently asked questions
What is loan origination software and what does it actually automate?
Loan origination software automates the repeatable parts of the loan lifecycle: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing files between underwriters, processors, and closers. It's built for standard consumer and mortgage flows. Non-standard underwriting, alternative data, or specialty asset classes usually fall outside what the platform handles well.
Can a lender legally let AI make or influence a credit decision?
Yes, but ECOA and Regulation B adverse-action requirements apply in full. Per CFPB Circular 2022-03, lenders must give applicants specific, accurate reasons for denial, even when a complex algorithm contributed to the decision. "The model said no" doesn't satisfy that requirement, so explainability has to be built into the system, not added after a denial is issued.
Is credit scoring or creditworthiness assessment considered "high-risk" under the EU AI Act?
Yes. Annex III of the EU AI Act explicitly classifies AI systems that evaluate creditworthiness or credit scoring of natural persons as high-risk. That triggers obligations around documentation, human oversight, and risk management for any lender serving EU consumers, directly or through embedded partners.
What's the real difference between buying a loan origination system and building a custom underwriting agent?
An LOS gives you standardized workflow, intake, and compliance checks fast, but you're renting a rules engine built for average cases. A custom underwriting agent costs more upfront but you own the decisioning logic outright, which matters most when your credit policy, data sources, or asset classes don't fit a vendor's template.
How long does it take to implement an LOS versus build a custom AI underwriting workflow?
A standard LOS implementation typically takes six to twelve months once you include integrations and configuration. Custom underwriting builds vary more by scope, commonly 2 to 24 weeks for a defined decisioning workflow, because you're building exactly what your credit policy needs rather than configuring a general-purpose platform around it.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
August 25, 2026
10 min read
Why Loan Origination Software Breaks Down on Non-Standard Underwriting



What loan origination software actually automates, and where it stops
Loan origination software (LOS) automates the parts of the loan lifecycle that are the same every time: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing a file between underwriter, processor, and closer. Platforms like Encompass, nCino, Blend, and MeridianLink do this well for mortgage and vanilla consumer lending, where the underwriting logic is largely dictated by GSE guidelines or a handful of well-known rules. That's the whole category, and it's a real one: banks and credit unions have run on this model for a decade because most of their loan volume is standard enough for a rules engine to handle.
Where it stops is underwriting judgment. The moment a loan doesn't fit the platform's decision tree, cash-flow lending against alternative data, a specialty asset class the vendor never built a module for, a community bank loan participation split across three institutions, an embedded lending product underwritten inside someone else's checkout flow, the LOS turns into a workflow shell around a manual process. Underwriters end up pulling data out of the system, running the real analysis in a spreadsheet, and keying the answer back in. You're paying six figures a year for a filing cabinet with a nice UI.
The real buyer question: license an LOS, build a custom underwriting agent, or both
Most lenders frame this as "which vendor should we pick," and that's the wrong question. The right one is whether your underwriting logic is standard enough to live inside someone else's rules engine, or specific enough that you need to own the decisioning layer yourself. Those are different problems with different answers, and a lot of institutions buy an LOS to solve the second problem, then spend two years fighting the platform's assumptions.
The honest answer for most lenders is "both, at different layers." An LOS is genuinely good at intake, document management, and audit trails, the plumbing nobody wants to build from scratch. A custom underwriting agent earns its keep at the decisioning layer, where your credit policy, your data sources, and your risk appetite are actually differentiated. Treating this as a single vendor-selection exercise is how banks end up buying a platform that's 80% right and then quietly building shadow spreadsheets to cover the other 20%, which is worse than either option done deliberately.
Why off-the-shelf loan origination systems struggle with non-standard underwriting
Four patterns show up over and over in lending shops that outgrow their LOS.
Alternative data. If your underwriting pulls in bank transaction data, POS revenue, or utility payment history instead of (or alongside) a FICO score, most LOS rules engines can ingest the data but can't reason over it the way your credit team does. You end up exporting to a data science tool, scoring outside the platform, and re-importing a number the LOS treats as a black box input.
Specialty asset classes. Equipment finance, agricultural lending, franchise lending, and non-QM mortgage all have underwriting logic that doesn't match the templates baked into mainstream platforms. Vendors will sell you a "configurable" rules engine, but configuration usually means IT tickets and change requests, not something your credit team can adjust when policy shifts.
Community bank loan consortiums. Participation loans split across multiple institutions need shared visibility into a single credit file with different permission and reporting requirements per institution. Most LOS platforms assume one lender, one file, one decision, and bolting on multi-institution logic is a custom project regardless of which vendor you pick.
Embedded and vertical lending. If you're underwriting inside a partner's checkout or a vertical SaaS product, the LOS needs to plug into someone else's stack via API, in real time, with a decision returned in seconds. Most legacy LOS platforms were built for a human-paced workflow, not a sub-second embedded decision, and retrofitting that is closer to building new infrastructure than configuring existing infrastructure.
None of this means LOS vendors are bad at their job. It means their job is standard-flow origination, and a meaningful share of mid-market and specialty lenders don't have a standard flow.
Can AI legally make or influence a credit decision?
Yes, but only if you can explain the specific reasons behind every denial, and "the model said no" is not a specific reason. The Consumer Financial Protection Bureau made this explicit in Circular 2022-03: adverse-action notice requirements under the Equal Credit Opportunity Act apply in full to decisions made with AI or complex algorithmic models. There is no carve-out for complexity. The CFPB followed up with more direct guidance in 2023, stating flatly that lenders using AI models must still give applicants accurate, specific reasons for a denial, not generic or boilerplate explanations pulled from a template that doesn't reflect what the model actually weighed (CFPB, September 2023).
This is where a vendor's opaque scoring engine becomes a real liability, not a hypothetical one. If your LOS's proprietary risk score contributes to a denial and you can't articulate which factors drove that score for that applicant, you have an ECOA problem regardless of how accurate the model is. This is also where owning the decisioning layer stops being an engineering preference and becomes a compliance requirement. A system you built and can trace end to end gives your compliance team an actual answer when an examiner or an applicant asks why. A vendor's black-box score gives you a support ticket.
Is creditworthiness assessment "high-risk" under the EU AI Act?
Yes, explicitly. Under Annex III of the EU AI Act, AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are classified as high-risk, and Article 6 sets out the classification mechanism that puts them there. High-risk classification isn't a label, it's a set of obligations: documented risk management processes, technical documentation you can hand to a regulator, human oversight built into the workflow rather than bolted on after the fact, and accuracy and robustness testing you can show your work on.
Any lender taking applications from EU consumers, directly or through an embedded partner, needs to treat this as a live compliance requirement now, not a future item. If your underwriting decisioning runs inside a vendor's platform, you're dependent on that vendor's documentation and audit posture to meet these obligations, and most mainstream LOS vendors were not built with EU AI Act Annex III in mind. We've covered the broader timeline and requirements in more detail in what the EU AI Act's high-risk deadline means for US and Singapore companies, and the compliance logic here runs parallel to the AML monitoring space, where the same buy-vs-build tension shows up for a different regulatory reason (see how banks and fintechs should decide on AML transaction monitoring software).
What it actually costs and how long it takes: LOS licensing vs. a custom underwriting agent
An LOS license for a mid-market lender typically runs from the low six figures to well over a million dollars a year depending on volume, modules, and integrations, and that's before implementation, which commonly runs six to twelve months for anything beyond a plain-vanilla configuration. You're renting the platform for as long as you use it, and every custom rule or non-standard asset class you add usually means a change order and a queue.
A custom underwriting agent is a different cost shape. You pay for the build once, you own the code and the models afterward, and you're not paying a per-seat or per-loan licensing fee indefinitely. Genta's typical project timeline across lending-adjacent and financial operations work runs 2 to 24 weeks depending on scope, and the honest comparison isn't "LOS is cheap, custom is expensive." It's that LOS pricing scales with volume forever, while a custom build front-loads the cost and then the marginal cost per loan approaches zero. For a lender processing thousands of non-standard loans a year, that math flips in favor of ownership faster than most buyers expect.
The catch, and we say this to clients directly: a custom underwriting agent is only worth building if your underwriting logic is genuinely differentiated. If your credit policy is close to boilerplate, buy the LOS and stop there. The build-vs-buy decision should follow from what your credit team actually does, not from a general preference for owning software. This is the same diagnostic discipline that mattered in a very different lending context: when Genta rebuilt billing operations for C&G Energy Services, most of the fix was process automation and integration work, not AI, and the value came from diagnosing the actual bottleneck before writing code, not from defaulting to "build" (case study).
A practical decision framework: when to buy, when to build, when to do both
Run your lending operation through these questions before you sign an LOS contract or scope a custom build.
Is your underwriting logic documented in a policy manual, or does it live in your senior underwriters' heads? If it's the latter, no off-the-shelf rules engine will replicate it, and you need a build phase just to formalize the logic before you can automate it.
Can you name the specific factors behind every adverse-action notice you send today? If the honest answer is "not really," that's a compliance gap regardless of what you buy next, and it's worth fixing before adding any AI to the decision.
Do you originate to EU consumers or through EU-based partners? If yes, Annex III obligations apply now, and vendor documentation quality should be a contract term, not an afterthought.
What share of your loan volume is standard flow versus exception handling? If exceptions are under 10%, an LOS with a manual override process is probably fine. Past 20-30%, you're paying for a platform that handles a minority of your actual work.
Who owns the model logic if you switch vendors in three years? If the answer is "the vendor," you're renting your credit policy, and that's worth pricing in as a real cost, not just a licensing line item.
McKinsey's July 2025 research on gen AI in credit found that 52% of banks now treat generative AI as a strategic priority in their credit business, but most are still early in actual deployment (McKinsey). That gap between intent and execution is exactly where the build-vs-buy decision gets made badly, usually by picking the vendor with the best sales deck rather than the one that matches the actual underwriting problem. A separate McKinsey study on small-business lending found banks using AI specifically to flag loans likely to underperform, a targeted augmentation use case that sits well inside a hybrid approach: LOS for intake and workflow, custom model for the risk signal that actually moves the needle (McKinsey).
If you're working through this decision, this is exactly what our Discovery phase maps out before any code gets written, and we're happy to compare notes. For lenders exploring what a custom decisioning layer actually involves, our AI agent development work covers the same build discipline referenced throughout this piece, and the debt-collection side of the lifecycle has its own regulatory pressure worth understanding alongside this one (what Regulation F and the CFPB mean for AI debt collection software), as does the broader compliance picture across financial services agents (AI agents in financial services, what changes when compliance is non-negotiable).
Frequently asked questions
What is loan origination software and what does it actually automate?
Loan origination software automates the repeatable parts of the loan lifecycle: application intake, document collection, credit pulls, standard decisioning rules, compliance checks, and routing files between underwriters, processors, and closers. It's built for standard consumer and mortgage flows. Non-standard underwriting, alternative data, or specialty asset classes usually fall outside what the platform handles well.
Can a lender legally let AI make or influence a credit decision?
Yes, but ECOA and Regulation B adverse-action requirements apply in full. Per CFPB Circular 2022-03, lenders must give applicants specific, accurate reasons for denial, even when a complex algorithm contributed to the decision. "The model said no" doesn't satisfy that requirement, so explainability has to be built into the system, not added after a denial is issued.
Is credit scoring or creditworthiness assessment considered "high-risk" under the EU AI Act?
Yes. Annex III of the EU AI Act explicitly classifies AI systems that evaluate creditworthiness or credit scoring of natural persons as high-risk. That triggers obligations around documentation, human oversight, and risk management for any lender serving EU consumers, directly or through embedded partners.
What's the real difference between buying a loan origination system and building a custom underwriting agent?
An LOS gives you standardized workflow, intake, and compliance checks fast, but you're renting a rules engine built for average cases. A custom underwriting agent costs more upfront but you own the decisioning logic outright, which matters most when your credit policy, data sources, or asset classes don't fit a vendor's template.
How long does it take to implement an LOS versus build a custom AI underwriting workflow?
A standard LOS implementation typically takes six to twelve months once you include integrations and configuration. Custom underwriting builds vary more by scope, commonly 2 to 24 weeks for a defined decisioning workflow, because you're building exactly what your credit policy needs rather than configuring a general-purpose platform around it.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.