Underwriting files that arrive complete and verified

Your underwriters spend most of their day assembling a file, not judging it. We automate that half — intake, verification, completeness, case assembly — and draw the regulatory boundary through the architecture, so the decision stays theirs and stays defensible.

from $30,000Solution Blueprint: build-ready spec in 5–6 weeks, credited against the build
from $150,000typical build — document layer, one line of business, 3–5 case types, 4–6 months
Fixed pricequoted against the Blueprint scope — no time and materials
On-prem or cloudfull pipeline can run inside your perimeter, GPUs in the same contract

What we automate first — and why

Not a menu of capabilities. Three groups, split by what an error costs — because that is what decides the order of work, and almost nobody writes it down before the proposal.

01

Cheap, high-volume, correctable

Document intake and classification, field and table extraction from scans and forms, completeness checks, cross-document consistency, flagging of missing or contradictory evidence, identity verification and fraud screening.

An error here costs a correction. This is where the hours are, and it sits outside the high-risk perimeter. We take it first, in almost every engagement.

02

Prioritisation and routing

Ranking cases by likelihood of needing attention, exception routing, straight-through eligibility against written criteria, queue assignment, and the evidence chain that lets a specific case be reconstructed months later.

An error here costs a delay. Worth automating once the document layer is stable — and the evidence chain is much cheaper to build now than to retrofit.

03

The decision itself

Creditworthiness scoring, approve/decline, limit and pricing decisions, life and health insurance risk assessment.

An error here costs the loan, the customer, or a regulatory finding. This is the high-risk perimeter. We will build it, and we will first tell you why most teams should not — see below.

Typical stack:

OCR + layout modelsLayoutLM / DonutLLM extractionJSON schema validationface match & livenessdeterministic rule enginepgvectorPythonvLLM (self-hosted)

When we tell you not to do this

We say no to underwriting automation more often than this market does, so it is worth being specific. If any of these describes you, the honest answer is that the project fails and we would rather say it now.

Fragmented intakeApplications arrive across email, portals and paper and nobody owns the data. The pilot will work on the clean subset and die in production — the ordinary way these projects fail. Fix ownership first.
Policy, not throughputIf the real constraint is that the underwriting policy is contested, automation just produces disagreeable decisions faster. Settle the policy; the software is the easy part.
Document layer untouchedIf nothing upstream of the decision is automated yet, start there and leave the decision alone. Cheaper, lower exposure, and it produces the labelled data a decision layer would later need.
Too small to be worth itBelow a few thousand cases a year the arithmetic rarely closes — volume times hours saved has to beat build plus run plus the cost of being wrong. We will do that calculation with you before quoting.

If the doubt is broader than this project — whether the company should be automating anything yet — that is a different question and it has its own answer: the free AI Readiness Score takes three minutes, and the AI Adoption Assessment gives a company-level verdict from $20,000, up to and including “not yet”.

Where the high-risk line falls

Your compliance function will ask this in the first meeting. Here is the answer before they ask it. Under Annex III of the EU AI Act the classification attaches to the function, not to your licence — so being a fintech rather than a bank changes nothing.

What the component decidesStatusReference
Creditworthiness or credit score of a natural personHigh-riskAnnex III, 5(b)
Risk assessment and pricing, life and health insuranceHigh-riskAnnex III, 5(c)
Fraud detection — and nothing elseExcludedexpress exception in 5(b)
Fraud scoring and credit scoring in one inseparable modelHigh-riskthe exception does not survive the combination
Document intake, extraction, identity verificationOutsideprovided it is genuinely separable from the decision
Creditworthiness of a legal entityOutside5(b) covers natural persons

The obligations bind on 2 December 2027 — Regulation (EU) 2026/1744 moved the date from August 2026. That is design headroom, not a reprieve: a system built as one inseparable pipeline pulls your whole document stack into the high-risk regime for the sake of one component, and separating it afterwards is a rewrite. Other rules apply today regardless — GDPR Article 22 has covered automated credit decisions since 2018.

If you do not lend in the EU

The usual assumption inverts here. The Gulf and Asia did not arrive late to automated credit decisions — several regimes bind sooner than the EU’s, and they arrived through data protection law rather than a dedicated AI act.

WhereBindingInstrument, and what it asks
DIFC, Dubaisince Jan 2026Regulation 10 of the DIFC Data Protection Law — automated credit decisioning is a High Risk Processing Activity. Assess and document before processing; tell the applicant, and let them object.
Mainland Chinasince 2021PIPL Article 24 — right to an explanation and to refuse a decision made solely by automated means; credit status named explicitly.
Hong Kongsince Mar 2026HKMA guidance on alternative data in credit assessment, on top of the 2019 big-data-and-AI circular.
SingaporesupervisoryMAS FEAT plus the AI Risk Management guidelines — credit and insurance models explainable enough for meaningful challenge and customer recourse.
EU2 Dec 2027AI Act Annex III 5(b)/5(c) — the full high-risk regime.

The labels differ; what they want converges on four things — the applicant can tell a machine was involved, a specific past decision can be explained, a human is reachable where the decision bites, and the evidence outlives the complaint window. Build to those once and you are not rebuilding per jurisdiction. We design to the strictest regime in your footprint by default.

Full breakdown of all six regimes, with sources →

How the work runs

Four phases, each with what we need from you. Vague phase names are how a proposal avoids committing to anything — so these are specific to underwriting, and so is the list of what stalls each one.

PHASE 01
Boundary and scopeWe map your current flow onto the table above and mark, component by component, what prepares a decision and what makes one. Output is a build-ready specification, a fixed price and a timeline. This phase is a product you buy on its own — the AI Solution Blueprint, from $30,000, credited against the build. The spec is yours; you can implement it with us, in-house or elsewhere.You provide
  • Current architecture diagram, however rough
  • 50–100 real application packages
  • The written underwriting policy, if one exists
PHASE 02
Document layerIntake, classification, extraction, completeness and consistency checks running on real historical files — not clean samples. First working results in 2–4 weeks.You provide
  • 200–500 labelled documents per type
  • One named owner for the data
  • Target schema, or an hour to define it with us
PHASE 03
Routing and evidence chainException routing against criteria written down in advance, plus per-case logging of inputs, versions, evidence and the human review step, so any decision can be reconstructed later.You provide
  • Straight-through criteria in writing, before we build
  • A named reviewer for the exception queue
  • Retention and residency requirements
PHASE 04
Integration and handoverWiring into your core system, DMS or CRM with reprocessing and monitoring; deployment into your environment; acceptance against the criteria set in phase 01.You provide
  • Integration contacts and a test environment
  • An acceptance owner who can sign
  • A decision on where it runs — your cloud or on-prem

Systems we have already shipped

Both from our own deliveries, both in the same shape as an underwriting stack. Client names withheld under NDA. See full case studies →

Lending marketplace · identity

Identity and fraud screening, outside the decision perimeter

Document checks, face match and liveness for a lending marketplace. It verifies the applicant and hands them to the process that decides — it never evaluates creditworthiness. That separation was an engineering choice about latency and ownership before it was a regulatory one. Read the case →

−75% fraudulent applications+35% conversion0 credit decisions made by the system
Aviation · MRO

Checking a document against a regulation, automatically

A computer-vision service that classifies each page of a maintenance package, detects missing signatures and stamps, finds unfilled checklist cells and produces an annotated report — before a specialist signs off. The mechanics of case-completeness checking, in a setting where a missed field holds up the package. Read the case →

6 document types classifiedCV signature & stamp detectionCLI + API delivery

No surprises

Your data

The whole pipeline can run on-premises or air-gapped, with no applicant document leaving your network. GPU hardware is quoted in the same contract, so residency is a deployment choice rather than a vendor negotiation. Details in security and compliance and private AI infrastructure.

Your models

Version-pinned models and prompts, self-hosted open weights where reproducibility matters, deterministic rules wherever the criterion is written in a policy rather than learned from data. The same case, months later, can be reconstructed with the inputs, versions and evidence that produced it.

Your budget

Fixed price against a one-page scope agreed before the build starts. No time and materials, no discovery that bills indefinitely, no scope that grows between the proposal and the invoice. We do not quote a range before that scope exists — a number produced before anyone has counted your document types or read your underwriting policy is a guess, and guesses get repriced in month three.

Frequently asked questions

How is an underwriting project scoped and priced?

Scope first, price second, and both numbers are published. The specification is a product: the AI Solution Blueprint, one system, 5–6 weeks, from $30,000, credited in full against the build if implementation starts within 90 days. It maps the boundary on your actual flow and ends with a build-ready spec, a fixed price and a timeline. Builds of this kind typically start around $150,000 over 4–6 months for a document layer covering one line of business. The exact figure comes out of the Blueprint rather than before it, because a number produced before anyone has counted your document types or read your underwriting policy is a guess, and guesses get repriced in month three.

How long before we see something working?

Most engagements reach first working results in 2–4 weeks after a discovery and data-audit phase, then iterate to production. For underwriting that first result is usually the document layer running on real historical files, not a demo on clean samples.

Do we have to be compliant by 2 December 2027?

If your system evaluates the creditworthiness of natural persons or prices life and health insurance risk, yes — that is when the Annex III high-risk obligations bind, after Regulation (EU) 2026/1744 moved the date from August 2026. Other rules apply now regardless: GDPR Article 22 has covered automated credit decisions since 2018. The full breakdown is here.

We lend in the Gulf and Asia, not the EU. Does this matter to us?

More than most people assume, and often sooner. DIFC Regulation 10 has been in full enforcement since January 2026 and treats automated credit decisioning as a High Risk Processing Activity. China's PIPL Article 24 has given a right to refuse a decision made solely by automated means since 2021. The HKMA issued guidance in March 2026 on alternative data in credit assessment, and MAS expects credit models to be explainable enough for meaningful challenge. The EU is the late one here, not the early one. We design to the strictest regime in your footprint rather than to each in turn.

Can the whole pipeline run on our own infrastructure?

Yes. The full stack can run on-premises or air-gapped, with no applicant document leaving your network, and we can quote the GPU hardware in the same contract. For regulated lenders with data-residency constraints this is usually the only configuration that clears legal review.

Will you automate the credit decision itself?

Usually we advise against it, and we say so before the proposal. Automating everything up to the decision captures most of the speed at a fraction of the risk. If you do want the decision layer automated, that is the high-risk path under Annex III 5(b) or 5(c) and we will scope it as such rather than quietly build it into a document project.

What if we only need the document layer?

Then start there and do not touch the decision. It is cheaper, the errors are correctable, the regulatory exposure is lower, and it produces the labelled data any future decision layer would need. This is the most common recommendation we give in this sector.

Related practices

Tell us what your underwriting flow looks like

An engineer replies, not an account manager. You get back a one-page scope and a fixed price.

Want the spec first? AI Solution Blueprint — from $30,000, credited against the build.

We reply within one business day. Prefer email? sales@haink.org