Answer first
Start with labels, not a real applicant or credit file.
A safe first use is a local packet containing only fictional or organization-approved, minimum-necessary labels: source, owner, time/version, stated purpose, type, and an honest status of supplied, unknown, or conflicting. AI can format those labels and draft neutral questions. Authorized people retain every data, analysis, model, eligibility, pricing, notice, and communication decision.
Mission outcome
What you make in one focused session.
Source register
Supplied policy, model, source, and workflow-reference labels tied to an owner and time/version.
Unknown log
Gaps and conflicts that remain visible instead of becoming invented credit analysis.
Review handoff
Neutral questions and an authority map ending only at needs_review.
Field map
Six bounded steps
Choose a fictional or approved label-only scope.
Name the purpose and accountable owner. Exclude consumer reports, applications, financial statements, scores, bank records, loan data, collateral, and all other private information.
Register supplied labels without treating them as facts.
Capture only the source label, owner, time/version, purpose, type, and status. Do not ask AI to infer income, repayment, value, risk, or missing values.
Use AI as an organizer, not an analyst or decision engine.
AI may format fields, surface duplicates, and group blanks. It must not retrieve data, score risk, rank an applicant, recommend terms, or create a credit determination.
Turn gaps into neutral reviewer questions.
Keep missing authority, freshness, privacy basis, model governance, policy, or legal context as
unknown. Ask the authorized owner which process governs the gap; do not fill it from model inference.Route decisions to the owner who has them.
Credit and underwriting owners control analysis and decisions; model-risk and compliance owners control model/process governance; privacy and records owners control data; qualified legal/regulatory reviewers control applicable obligations; authorized humans control communications.
Stop at the review handoff.
Create a local
needs_reviewreceipt only. Do not analyze a file, create a score/rating, determine eligibility or terms, draft an adverse-action reason, update a record, send, or publish.
Bounded agent roles
Three clerks. No credit decision-maker.
O*NET says credit analysts work with credit data and financial statements in a lending-risk context.1 That occupational context makes this manual more conservative, not less: this packet is neither a credit analysis nor a decision.
Safe versus approval-required
AI prepares labels. Authorized people decide and act.
| AI may prepare | Named human approval is required |
|---|---|
| Format fictional or organization-approved, minimum-necessary source and process labels. | Access, retrieve, upload, query, analyze, share, retain, or disclose applicant, borrower, guarantor, consumer-report, credit, financial, account, collateral, loan, or payment data. |
| Preserve supplied source, owner, time/version, purpose, type, and unknown/conflict status. | Assess creditworthiness; score/rank risk; determine eligibility, approval/denial, amount, limit, rate, fee, term, collateral, pricing, or a recommendation. |
| Draft neutral questions about authority, freshness, policy, privacy, records, model governance, or legal/process review. | Use, validate, monitor, override, or approve a model; create a notice or reason; decide compliance; or make an exception. |
| Produce a local review-only receipt. | Write a system record, communicate with an applicant/customer/third party, publish, procure, or take any external action. |
Failure modes
Five shortcuts that quietly become decisions.
| Mistake | Why it fails | Repair |
|---|---|---|
| “Is this borrower safe?” | It asks the model to assess a real credit outcome. | Do not enter the file. Keep only approved labels and route analysis to authorized credit personnel. |
| “Give this application a risk grade.” | It becomes a score or credit determination. | Preserve only source/process labels; route the methodology and judgment to the approved process. |
| “What interest rate should we offer?” | Price and terms can create a financial commitment and may be regulated. | Mark pricing authority unknown and route it through the current approved policy and owners. |
| “Write the reason for denial.” | It asks for a decision-adjacent notice; CFPB’s current Appendix C page says reasons must reflect actual factors used.5 | Do not generate a reason or notice. Route to authorized qualified reviewers and approved procedures. |
| “Update the system and email the applicant.” | That is a data write and communication, not preparation. | Stop at the local receipt. An authorized human decides any system or communication action. |
Runnable local artifact
Credit Evidence & Review Desk
Enter only fictional or organization-approved, minimum-necessary labels. This form stays in the browser and produces a review-only receipt. It does not send, save, retrieve, query, score, decide, or connect to anything.
Primary sources
What this manual is built on.
- O*NET OnLine: Credit AnalystsOccupation context; profile marked Updated 2026. [1]
- Federal Reserve SR 26-2: Revised Guidance on Model Risk ManagementCurrent model-risk guidance context; issued April 2026 with scope limits. [2]
- NIST AI 600-1: Generative AI ProfileVoluntary cross-sector generative-AI risk-management context; page updated April 2026. [3]
- CFPB: Providing Equal Credit Opportunities (ECOA)Current CFPB ECOA and Regulation B resource hub; not individualized legal advice. [4]
- CFPB: Appendix C to Regulation BCurrent sample-notification-form context; not a notice-generation instruction. [5]
Sources provide context, not permission to use private data, make a credit determination, or take external action. Recheck current sources, organization policy, qualified reviewers, and applicable jurisdiction before non-fictional use.
Related guides
Where this guide fits.
Proposed links: the Occupation AI Workflow Guide Directory for the broader shelf; the Financial Quantitative Analyst Evidence Desk for a research/model-review boundary; the Loan Interviewer & Clerk Review Desk for intake boundaries; the Insurance Underwriter Evidence Desk for a regulated pre-decision comparison; and the Accountant & Auditor Guide for financial-record review boundaries. Use these related guides to keep each workflow's authority boundary clear.