By Lynn Woosley, CRCM
(Originally published in ABA Risk and Compliance, July/August 2026)
As banks focus on increasing efficiency, some are turning to models to increase the efficacy of their compliance monitoring and testing functions. Properly implemented, algorithmic testing can provide both broader coverage and faster detection of risks. When accompanied by targeted testing and human oversight, financial institutions (FIs) may become better at early detection and prevention of customer harm.
FIs may find compliance algorithms and automation beneficial in technical compliance testing, complaints analysis, and detection of fair lending or fair servicing risks. Some of the tools Fis use include robotic process automation (RPA), large language models (LLMs), and more traditional statistical inference models, such as regressions, to detect compliance risks.
Over the past several years, banking practices have evolved in ways that make traditional sampling approaches increasingly difficult to defend as adequate controls. As transaction volumes grow and product structures become more complex, compliance management systems need to adapt. This is particularly true in areas such as fair lending, UDAAP, and complaints management. FIs are under pressure to demonstrate not only that controls exist, but that they operate consistently across the full population of activity.
This overview will focus on compliance modeling and analytic approaches for monitoring both technical compliance and substantive fairness, exclusive of financial crimes models and proxy models.[i]
The shift from sampling to full-population testing
At the same time, advances in data availability and processing capacity have made broader testing more feasible. Where FIs once relied on limited samples to identify potential issues, many now have the ability to evaluate entire portfolios on a recurring basis. This shift is not purely technological; it reflects a broader change in expectations. Examiners and auditors are increasingly focused on whether FIs can identify patterns, explain outcomes, and produce defensible, repeatable results. In that environment, automation and modeling are becoming less of an enhancement and more of an operational necessity.
Technical compliance testing
Automation is reshaping technical compliance testing. Robotic process automation (RPA) and large language models (LLMs) are two emerging tools for loan-level testing, deposit operations, and marketing oversight.
RPA is particularly effective where compliance requirements have hard and fast rules. In loan-level testing, RPA routines can complete required tasks such as validation of disclosure timing and application of fee tolerance thresholds under TRID, recalculation of APRs, and reconciling HMDA fields against source documentation. Some RPAs also have the ability to test state-specific loan and disclosure requirements. RPA may also identify changes needed to bring the loan into compliance before closing documents are issued, thereby empowering lenders to avoid costly post-closing remediations.
In deposit testing, RPA can confirm account-opening disclosure delivery, recalculate APYs under Regulation DD, validate Regulation E dispute timelines, and test Regulation CC hold logic. Potential errors are flagged for human review. In marketing oversight, RPA can detect trigger terms, verify required disclosures, and confirm APR/APY accuracy.
These rule-based activities expand compliance testing from sampling to population-level monitoring. Because RPA executes codified logic consistently, it strengthens audit trails and enhances defensibility during examinations. However, its effectiveness depends on accurate regulatory interpretation and disciplined change management when thresholds or guidance evolve.
Where the risk arises from interpretation rather than deterministic rules, LLMs can complement RPAs for ongoing monitoring and testing. FIs may use LLMs to assist in reviewing marketing language for misleading language or tone. LLMs can help verify adverse action reasons, screen loan and deposit account disclosures, or summarize operational exceptions.
Fair lending and fair servicing modeling
Compliance professionals also use statistical inference testing, including regression models, in managing compliance risks. This is especially common in fair lending testing, where statistical inference testing may be used to assess differences in a variety of applicant outcomes, such as underwriting, pricing, receipt of exceptions or fee waivers, and servicing decisions. The purpose of fair lending models is to estimate fair lending risks inherent in an FI’s underwriting and pricing practices, so that the bank can appropriately manage its risks in a fashion consistent with regulatory expectations and to ensure the bank is treating customers and consumers in a fair and equitable manner.
Where sufficient data exists, regression is the preferred statistical inference method for fair lending testing. Regression models permit consideration of legitimate, nondiscriminatory risk factors when comparing differences in outcomes. This is particularly beneficial when determining whether applicants with differences in outcomes are truly similarly situated. Additionally, conformity with regulatory practice drives choice of modeling approach.
Unlike other forms of statistical inference modeling used in risk management, where developers try to maximize predictive or classification power based on available data, data selection in fair lending and fair servicing models is constrained. The goal of these models is to mimic the documented credit decision processes with an overlay for membership in a prohibited basis group. This means that modelers derive explanatory variables from the lender’s underwriting and pricing policies and procedures, product guidelines, rate sheets, and loan-level pricing adjustments (LLPAs).
Explanatory variables may be further limited by electronic data availability, sparsity, and exclusion of leaky variables, which would embed information in the model that was not available at the time of decision. For example, if pricing is not finalized on declined applications, the note rate or APR would be leaky variables in a fair lending decisioning model. Similarly, variables that might mask discrimination, such as receipt of an exception, should be used with caution. If exception volume is adequate, lenders should consider testing the distribution of exceptions.
When testing binary outcomes, such as loan application approval or denial, logistic regressions are commonly used. Logistic regression can also be used to assess binary differences in other outcomes, such as whether a borrower received a loan modification or an exception. By adding an indicator variable signifying membership in a prohibited basis group, modelers can determine whether outcomes appear to vary on a prohibited basis after controlling for legitimate, nondiscriminatory decision factors. Additionally, classification into probable outcomes permits lenders to identify outliers, which are applications that received unexpected outcomes, for further investigation.
For continuous outcomes, such as APR, interest rate, or fees, ordinary least squares regression (OLS) is the most common approach. As with decisioning regressions, adding an indicator variable signifying membership in a prohibited basis group permits determining whether pricing appears to vary on a prohibited basis after controlling for the interest rate environment, product differences, and the lender’s loan-level pricing adjustments for legitimate, nondiscriminatory risk factors. By using the error bands generated by the regression, compliance teams also may identify loans receiving unusually high or low pricing.
Risk management and governance
While automation and modeling can expand coverage and improve consistency, they also introduce new forms of risk that must be actively managed. In some cases, these risks arise not from the tools themselves, but from how they are implemented and governed. As with other models and tools, compliance automation need robust governance and validation routines. The governance implications differ materially by the type of model used and the data sources. The recent revision to Supervisory Guidance on Model Risk Management (SGMRM) increases the focus of data lineage, accuracy, and appropriateness, as well as vendor risk.[ii]
Perhaps the simplest type of compliance automation to manage is RPA. RPA is transparent and rule-driven; its primary risk is miscoding. However, “simple” and “transparent” do not necessarily translate into “easy.” In any automated testing, banks must take care to ensure RPA rule engines are accurate, current, and complete. In periods of rapid regulatory change, maintaining RPA rules engines may require extensive effort.
For rule-based systems such as RPA, scale is a key risk. An incorrectly interpreted regulatory requirement or a miscoded rule can result in systematic errors applied across an entire population of transactions. Unlike manual processes, where errors may be isolated, automated systems can propagate issues quickly and consistently, increasing the potential for customer impact and remediation exposure.
For LLMs and other AI-assisted tools, the risk profile is different. LLMs generate probabilistic outputs influenced by prompts and training data, requiring validation, performance monitoring, and human oversight. These models may produce outputs that are directionally useful but not consistently reproducible or fully explainable. If used without appropriate controls, this can create challenges in demonstrating how conclusions were reached — particularly in areas such as adverse action reasoning, complaints analysis, or marketing review, where defensibility is critical. Despite their exclusion from the latest version of the SGMRM, LLMs require oversight that is appropriate to their usage. Any LLM components or overlays should operate under human oversight. As with other types of AI, “human in the loop” definitely applies.
Statistical models introduce their own considerations. Regression models, whether logistic or OLS, are more consistent with traditional model validation requirements. In fair lending and servicing contexts, model specification, variable selection, and data limitations can materially influence results. Fair lending or servicing algorithms should be sound, with explanatory variables traceable to written policies, procedures, rate sheets, and similar sources.
Many institutions subject compliance regression models to the same validation and performance monitoring requirements as other regression models. Misinterpretation of model outputs — such as treating indicators as conclusions rather than signals — can lead to either overcorrection or missed risk. Additionally, gaps in data lineage or documentation may make it difficult to support findings during examinations. Appropriate documentation of modeling and data choices and the resulting risks memorializes these decisions.
Additionally, most FIs want to measure their performance in a manner that is consistent with regulatory approaches. This may mean using logistic or least square regression in cases where all statistical assumptions are not met or where an alternate approach might improve model fit.
Finally, the limits of data availability and sound modeling practices may make it impossible to include all key underwriting or pricing inputs. As a result, compliance regression model results should be treated as risk indicators, rather than determinations of discrimination. This means model findings should be confirmed by additional testing, such as comparative or outlier file reviews, and supported by policy and procedures reviews.
These risks underscore the need for governance frameworks that extend beyond traditional model validation to include clear accountability, documentation standards, and ongoing performance monitoring. Automation can strengthen control environments, but only when it is implemented with the same rigor applied to other core compliance processes.
When automation materially informs compliance conclusions or reporting, FIs typically align governance with model risk management expectations consistent with the SGMRM. Certain AI use cases, including LLMs and agentic AI, were explicitly excluded from the SGMRM. [iii] However, this does not mean that FIs should not have appropriate controls over the use of such algorithms, including policies governing acceptable use, or fail to monitor LLM and agentic AI results. At least one state requires FIs to maintain an acceptable use policy even if the FI is not using AI at all.[iv]
What does this look like inside a bank?
In practice, many FIs are adopting a layered approach to implementation that aligns automation with existing control frameworks. Rule-based automation is often deployed first in areas where requirements are clear and testable — such as disclosure timing, fee tolerances, or transaction processing rules — allowing FIs to move from sample-based reviews to testing across entire populations. Exceptions identified through these processes are then routed for review, creating a more consistent and auditable workflow that evidences a robust control.
Statistical models are commonly applied as a second layer, particularly in fair lending and servicing contexts. FIs may use regression analysis to identify disparities in underwriting, pricing, or exception activity, with model outputs used to prioritize targeted file reviews. In this way, models function as a screening mechanism, helping compliance teams focus attention where risk is most likely to exist rather than attempting to review large volumes of files without direction.
Some FIs are also incorporating LLMs in a more limited, assistive capacity. For example, LLMs may be used to support the review of marketing materials for potentially misleading language, summarize complaint narratives, or identify themes in large datasets. In these use cases, outputs are typically subject to human validation and are not relied upon as standalone compliance determinations.
Across these implementations, a common pattern emerges: automation expands coverage and surfaces potential issues, while human review provides confirmation, context, and final judgment. FIs that are most effective in this space tend to design workflows that explicitly connect these layers, ensuring that automated outputs are traceable, reviewable, and integrated into existing compliance processes.
As with other compliance testing, controls and recordkeeping are required. A mature compliance architecture integrates these tools in a layered structure: deterministic rule engines at the base, semantic screening and regression modeling in the middle, and expert human judgment at the top. Properly implemented, this integrated framework enhances coverage, accelerates review cycles, and strengthens control environments across lending, deposit, and marketing domains. Improperly governed, however, automation can introduce new forms of model and compliance risk. The strategic challenge is therefore not whether to automate, but how to do so in a manner that preserves regulatory integrity and fits the institution’s needs.
ABOUT THE AUTHOR
Lynn Woosley, CRCM, is a Managing Director with Asurity Advisors and a member of the Editorial Advisory Board for ABA Risk and Compliance magazine. Lynn has over 30 years of experience in risk management, spanning both financial services and regulatory environments. She is an expert in consumer protection, including fair lending, fair servicing, community reinvestment, and UDAAP. Before joining Asurity Advisors, Lynn led the fair banking practice for an advisory firm. She has also held multiple leadership positions, including Senior Vice President and Fair and Responsible Banking Officer, within the Enterprise Risk Management division of a top 10 bank. Prior to joining the private sector, Lynn served as Senior Examiner and Fair Lending Advisory Economist at the Federal Reserve Bank of Atlanta. Reach her at lwoosley@asurity.com.
References
[i] For a discussion of proxy models, see Agarwal, Anurag, and Lynn Woosley, “Demographics without Disclosure: Proxy methods for fair lending analytics,” ABA Risk and Compliance, March/April 2026.
[ii] See Federal Reserve SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026.
[iii] See Federal Reserve SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026 at footnote 3.
[iv] https://www.michigan.gov/difs/-/media/Project/Websites/difs/Bulletins/2026/Bulletin_2026-03-BT-CF-CU.pdf