For credit unions and member-owned institutions
Fair lending exposure is the largest legal risk a small institution carries, and an automated hand anywhere near a credit decision is how it materialises. Those stay with your lenders and your compliance officer. What can be carried is member service, document completeness, and the examination preparation that takes your staff out of the business for weeks.
Members are owners, which changes the arithmetic of every decision. A fee that a bank treats as revenue is, here, a charge levied by an institution on the people who own it — and the board hears about it from people they see at the grocery store.
The regulatory burden does not scale down. Examination expectations, lending regulations, reporting obligations and consumer protection rules apply broadly regardless of size, so a small institution carries close to a large one’s compliance surface on a fraction of the staff.
Field of membership bounds who can be served, which means growth is structurally constrained in a way competitors are not, and every expansion is an application rather than a decision.
Technology is bought rather than built, from a core provider whose roadmap is not yours, with integration priced per interface and a contract that renews in multi-year blocks. The gap against a large institution’s digital experience widens every year and cannot be closed by effort.
And examination is a period rather than an event. Preparation consumes weeks, the examination consumes weeks, and the response consumes more — done by the same people who run the operation, with the findings landing on a chief executive who has three direct reports.
A loan file cannot be decided until it is complete, and completing it is a chase across a member, an employer, an insurer and a title company — so a lender’s day is documentation rather than judgement, and the member waits.
That is the same shape the public benefits page describes, in a different institution, and it has the same resolution: separate the completeness band from the decision band, and move only the first.
Completeness here means checking a file against the credit union’s own written requirement list, naming every missing item at once, confirming a received document is legible and is the item requested, and reminding before a rate lock or a commitment expires. It does not mean assessing what a document shows, which is underwriting.
The second band is examination preparation: assembling the file an examiner asks for, identifying where two of your own records disagree before an examiner does, and tracking the response items from a prior examination until your compliance officer closes them.
The third is member service: the balance question, the status question, the "did my payment post" question — the band that consumes a small branch and requires no judgement.
What never moves: any credit decision, any pricing or rate decision, any adverse action or the reasons given for one, any collections decision, any suspicious activity determination or report, and any scoring, ranking or prioritisation of members. Fair lending and consumer protection exposure is the largest legal risk here and none of it is an efficiency opportunity.
Days from application to a complete file — measured by elapsed days to completeness, separated from days to decision, against your own baseline.
Document requests issued one at a time — measured by count of separate requests per application, before and after.
Commitments and rate locks lapsing — measured by count expiring before a decision, and whether a reminder preceded each.
Lender hours on documentation rather than lending — measured by time-on-task sampling across both bands, taken the same way before and after.
Records that disagree, found before an examiner finds them — measured by count of internal disagreements surfaced, against findings raised at examination.
Time to assemble an examination file — measured by elapsed hours from an examiner request to a complete file, timed on a real request.
Prior examination response items still open — measured by count and age of open items, tracked rather than remembered.
any credit decision, underwriting judgement, pricing or rate decision, adverse action or its stated reasons, collections decision, suspicious activity determination or report, or scoring, ranking or prioritisation of any member. Nothing here reads a member file to form a view about a member. Fair lending and consumer protection exposure is the largest legal risk a small institution carries and none of it is delegated.
It reads and writes through whatever interfaces your core and loan origination systems expose, and the honest position is that this is frequently the binding constraint rather than anything technical — a core provider charging per interface can make a small improvement uneconomic, and that should be established before scoping rather than discovered during it.
Where an interface does not exist or cannot be afforded, that is a limitation and the step stays manual. Screen automation against a core banking system is refused, for the same reason it is refused against an eligibility system: a fragile process operating on the institution’s system of record.
Nothing creates a second record of a member or an account. In an examined institution a second record is a finding.
And member-facing surfaces have to work for the whole membership, which for most credit unions spans a very wide range of age and technology comfort.
The exclusion is not just "no credit decision". It is no influence on one — no scoring, no ordering, no prioritisation, no flag, and no reading of a member file to form a view. A system that ordered a queue of applications would be affecting outcomes without appearing to decide anything, and that is exactly the shape a fair lending examination is designed to find.
Suspicious activity is excluded on the same principle and for a second reason: a report is a confidential filing whose existence cannot be disclosed, and a vendor system in that path creates a disclosure surface that should not exist.
Member financial data stays inside your tenancy, on your retention schedule, exportable by you, and is not used to train anything serving another organisation. Member data is never training material at any tier.
And on assurance: an independent SOC 2 Type II attestation is in progress and no report exists yet, and no certification is claimed under any framework.
The compliance officer’s question is fair lending, and the answer they should test is the influence exclusion rather than the decision exclusion — ask specifically whether anything orders, flags or prioritises, because that is the version that survives an examination question.
The supervisory committee should see the record format, since it is the internal audit function in most credit unions and the record is what it would rely on.
The board is elected by members and will ask what members will think. The sentence worth having is one a member would find unobjectionable at an annual meeting.
And the examiner will ask what a third party does and what access it has. That answer belongs in your vendor management file in writing before the examination rather than assembled during it.
One loan product’s applications over a defined period, measured retrospectively for days to completeness and reasons for incompleteness, with no access to underwriting content and no live file affected.
Retrospective and completeness-only: no credit content is needed, no member is affected, and the interface cost is minimal because it reads status rather than driving anything.
The output separates two numbers most institutions report as one — days to complete and days to decide — and produces the specific list of items that most often go missing. Several credit unions have improved a cycle time by rewriting their own requirement list off that finding, with no vendor at all.
If it continues, the first grant covers completeness checking for one product, with the influence exclusion written into the scope document and reviewed by your compliance officer.
Correct instinct, and the exclusion here is drawn at influence rather than at decision for exactly that reason — nothing scores, orders, flags or prioritises, and nothing reads a member file to form a view. A system that merely ordered a queue would affect outcomes without appearing to decide anything, which is the shape an examination is built to find. Ask for the influence exclusion in writing rather than the decision exclusion; the second one is easy to say and the first one is the one that matters.
It does, and it should be established before scoping rather than discovered during it. The retrospective measurement is deliberately shaped to need very little — status and timestamps rather than content — because that is what a small institution can actually afford. If your core’s pricing makes even that uneconomic, the honest conclusion is that this is not available to you at a sensible price, and we would rather say so than design around a cost you will carry.
They will, and the answer belongs in your vendor management file in writing before the examination rather than assembled during it: what it does, what it cannot do, what it can reach, and where the records live. The exclusion list is written as refusals precisely so it reads clearly in that file. If your compliance officer cannot imagine that conversation going well, that is a reason to stop.
Which is why the first phase is retrospective, needs minimal interface, affects no live file and delegates nothing. The output is a measurement you keep. If your institution is one where the honest answer is that no external arrangement is worth the operational risk, that is a legitimate position for a small examined institution and we would rather you held it than tested it.