Your underwriters spend most of their day assembling a file, not judging it. We automate that half — intake, verification, completeness, case assembly — and draw the regulatory boundary through the architecture, so the decision stays theirs and stays defensible.
Not a menu of capabilities. Three groups, split by what an error costs — because that is what decides the order of work, and almost nobody writes it down before the proposal.
Document intake and classification, field and table extraction from scans and forms, completeness checks, cross-document consistency, flagging of missing or contradictory evidence, identity verification and fraud screening.
An error here costs a correction. This is where the hours are, and it sits outside the high-risk perimeter. We take it first, in almost every engagement.
Ranking cases by likelihood of needing attention, exception routing, straight-through eligibility against written criteria, queue assignment, and the evidence chain that lets a specific case be reconstructed months later.
An error here costs a delay. Worth automating once the document layer is stable — and the evidence chain is much cheaper to build now than to retrofit.
Creditworthiness scoring, approve/decline, limit and pricing decisions, life and health insurance risk assessment.
An error here costs the loan, the customer, or a regulatory finding. This is the high-risk perimeter. We will build it, and we will first tell you why most teams should not — see below.
Typical stack:
We say no to underwriting automation more often than this market does, so it is worth being specific. If any of these describes you, the honest answer is that the project fails and we would rather say it now.
If the doubt is broader than this project — whether the company should be automating anything yet — that is a different question and it has its own answer: the free AI Readiness Score takes three minutes, and the AI Adoption Assessment gives a company-level verdict from $20,000, up to and including “not yet”.
Your compliance function will ask this in the first meeting. Here is the answer before they ask it. Under Annex III of the EU AI Act the classification attaches to the function, not to your licence — so being a fintech rather than a bank changes nothing.
| What the component decides | Status | Reference |
|---|---|---|
| Creditworthiness or credit score of a natural person | High-risk | Annex III, 5(b) |
| Risk assessment and pricing, life and health insurance | High-risk | Annex III, 5(c) |
| Fraud detection — and nothing else | Excluded | express exception in 5(b) |
| Fraud scoring and credit scoring in one inseparable model | High-risk | the exception does not survive the combination |
| Document intake, extraction, identity verification | Outside | provided it is genuinely separable from the decision |
| Creditworthiness of a legal entity | Outside | 5(b) covers natural persons |
The obligations bind on 2 December 2027 — Regulation (EU) 2026/1744 moved the date from August 2026. That is design headroom, not a reprieve: a system built as one inseparable pipeline pulls your whole document stack into the high-risk regime for the sake of one component, and separating it afterwards is a rewrite. Other rules apply today regardless — GDPR Article 22 has covered automated credit decisions since 2018.
The usual assumption inverts here. The Gulf and Asia did not arrive late to automated credit decisions — several regimes bind sooner than the EU’s, and they arrived through data protection law rather than a dedicated AI act.
| Where | Binding | Instrument, and what it asks |
|---|---|---|
| DIFC, Dubai | since Jan 2026 | Regulation 10 of the DIFC Data Protection Law — automated credit decisioning is a High Risk Processing Activity. Assess and document before processing; tell the applicant, and let them object. |
| Mainland China | since 2021 | PIPL Article 24 — right to an explanation and to refuse a decision made solely by automated means; credit status named explicitly. |
| Hong Kong | since Mar 2026 | HKMA guidance on alternative data in credit assessment, on top of the 2019 big-data-and-AI circular. |
| Singapore | supervisory | MAS FEAT plus the AI Risk Management guidelines — credit and insurance models explainable enough for meaningful challenge and customer recourse. |
| EU | 2 Dec 2027 | AI Act Annex III 5(b)/5(c) — the full high-risk regime. |
The labels differ; what they want converges on four things — the applicant can tell a machine was involved, a specific past decision can be explained, a human is reachable where the decision bites, and the evidence outlives the complaint window. Build to those once and you are not rebuilding per jurisdiction. We design to the strictest regime in your footprint by default.
Four phases, each with what we need from you. Vague phase names are how a proposal avoids committing to anything — so these are specific to underwriting, and so is the list of what stalls each one.
Both from our own deliveries, both in the same shape as an underwriting stack. Client names withheld under NDA. See full case studies →
Document checks, face match and liveness for a lending marketplace. It verifies the applicant and hands them to the process that decides — it never evaluates creditworthiness. That separation was an engineering choice about latency and ownership before it was a regulatory one. Read the case →
A computer-vision service that classifies each page of a maintenance package, detects missing signatures and stamps, finds unfilled checklist cells and produces an annotated report — before a specialist signs off. The mechanics of case-completeness checking, in a setting where a missed field holds up the package. Read the case →
The whole pipeline can run on-premises or air-gapped, with no applicant document leaving your network. GPU hardware is quoted in the same contract, so residency is a deployment choice rather than a vendor negotiation. Details in security and compliance and private AI infrastructure.
Version-pinned models and prompts, self-hosted open weights where reproducibility matters, deterministic rules wherever the criterion is written in a policy rather than learned from data. The same case, months later, can be reconstructed with the inputs, versions and evidence that produced it.
Fixed price against a one-page scope agreed before the build starts. No time and materials, no discovery that bills indefinitely, no scope that grows between the proposal and the invoice. We do not quote a range before that scope exists — a number produced before anyone has counted your document types or read your underwriting policy is a guess, and guesses get repriced in month three.
Scope first, price second, and both numbers are published. The specification is a product: the AI Solution Blueprint, one system, 5–6 weeks, from $30,000, credited in full against the build if implementation starts within 90 days. It maps the boundary on your actual flow and ends with a build-ready spec, a fixed price and a timeline. Builds of this kind typically start around $150,000 over 4–6 months for a document layer covering one line of business. The exact figure comes out of the Blueprint rather than before it, because a number produced before anyone has counted your document types or read your underwriting policy is a guess, and guesses get repriced in month three.
Most engagements reach first working results in 2–4 weeks after a discovery and data-audit phase, then iterate to production. For underwriting that first result is usually the document layer running on real historical files, not a demo on clean samples.
If your system evaluates the creditworthiness of natural persons or prices life and health insurance risk, yes — that is when the Annex III high-risk obligations bind, after Regulation (EU) 2026/1744 moved the date from August 2026. Other rules apply now regardless: GDPR Article 22 has covered automated credit decisions since 2018. The full breakdown is here.
More than most people assume, and often sooner. DIFC Regulation 10 has been in full enforcement since January 2026 and treats automated credit decisioning as a High Risk Processing Activity. China's PIPL Article 24 has given a right to refuse a decision made solely by automated means since 2021. The HKMA issued guidance in March 2026 on alternative data in credit assessment, and MAS expects credit models to be explainable enough for meaningful challenge. The EU is the late one here, not the early one. We design to the strictest regime in your footprint rather than to each in turn.
Yes. The full stack can run on-premises or air-gapped, with no applicant document leaving your network, and we can quote the GPU hardware in the same contract. For regulated lenders with data-residency constraints this is usually the only configuration that clears legal review.
Usually we advise against it, and we say so before the proposal. Automating everything up to the decision captures most of the speed at a fraction of the risk. If you do want the decision layer automated, that is the high-risk path under Annex III 5(b) or 5(c) and we will scope it as such rather than quietly build it into a document project.
Then start there and do not touch the decision. It is cheaper, the errors are correctable, the regulatory exposure is lower, and it produces the labelled data any future decision layer would need. This is the most common recommendation we give in this sector.
The layer underneath: a capture method chosen per document type, not one method for the whole estate.
Explore →The same separation problem downstream of the policy — assembly and routing, isolated from the settlement decision.
Explore →The wider IDP practice: extraction, classification and drafting across any document-heavy process.
Explore →How the exempt half of an underwriting pipeline actually works.
Read →An engineer replies, not an account manager. You get back a one-page scope and a fixed price.
Want the spec first? AI Solution Blueprint — from $30,000, credited against the build.