Skip to main content

Smart automation adoption for credit unions 

Read about two credit unions that have modernized their lending operations with Abrigo and what a similar journey could look like for other credit unions.

Credit unions are known for reliable and responsive service, supporting local businesses, and caring for the financial well-being of their communities. But upholding these values while sustaining growth becomes much more difficult when staff spend their days chasing documents, updating spreadsheets, emailing status updates, and trying to determine where a loan sits in the approval process.

Expanding a credit union’s reach in its community requires more than adding more lending opportunities. To sustain growth, credit unions also need practical workflows and portfolio visibility to help staff manage increasing loan volume efficiently. Technology that eliminates repetitive administrative work allows lenders to spend more time getting to know members and their needs and making sound lending decisions.

Here's how two credit unions have modernized their lending operations with Abrigo.

Grow understanding and build buy-in with this webinar, "AI governance for credit unions."

Watch webinar

Accessible, organized commercial lending workflows

Like many credit unions, 3Rivers Federal Credit Union found that commercial lending had become increasingly difficult to manage through manual processes as the department grew. Disconnected systems made tracking loans time-consuming, while missing documentation, unclear ownership, and inconsistent reporting often slowed approvals and created unnecessary administrative work. Team members needed a better way to see where loans stood, communicate with one another, and avoid repetitive tasks.

3Rivers Federal Credit Union expanded its use of Abrigo Commercial Lending to consolidate its commercial lending activities into a single centralized workflow. By standardizing documentation, communication, reporting, and task management, the credit union gained greater visibility into every stage of the lending process.

Kristin Smith, AVP of Commercial Lending, explained, "We log on and know exactly where a loan is at, whose hands it is in, and what the team is waiting on. Our time is spent on what matters and not just typing out the same email 15 times to 15 different members asking for a tax return."

Instead of searching across emails or spreadsheets, lending teams can quickly identify:

  • Which loans are in process
  • Who owns the next step
  • What documentation is still outstanding
  • Where potential bottlenecks exist

Automation reduced the time employees spent on repetitive administrative work, but the payoff wasn't only internal. Faster workflows translated into a better member experience. "It's faster, it's more efficient," Smith said. "That's what you want when you're working with a member."

For credit unions pursuing lending automation, centralized workflows provide a strong operational foundation before additional automation is introduced. It also helps managers allocate resources and responsibilities more evenly across lending teams.

Faster small business lending decisions

Tennessee Valley Federal Credit Union (TVCU) faced a different challenge. The credit union was managing small business and commercial lending through two separate systems with limited automation, creating extra manual work and slower turnaround times.

After implementing Abrigo Small Business Lending, TVFCU combined its lending processes into a single platform and introduced automation through decision models and workflow automation. Rather than replacing lenders' judgment, the technology handled routine decisions so staff could focus on more complex loans and member relationships.

TVFCU moved from zero automated decisions before implementation to an 11% auto-decision rate in the first month, then 35% after additional refinements, and ultimately reached a 48% auto-decision rate. The team also estimates it increased loan volume by approximately 25%.

"Auto-decisioning changed the game,” said Marah Wood, Business Loan Servicing Lead. “The decision model being able to look at the parameters that you set and make a decision for you before you even have to look at it is extremely valuable."

Leveraging automation technology to handle routine decisions allows experienced lenders to focus on more complex loans and member relationships, improving turnaround times while maintaining consistency across the lending process.

"In the industries we're in, the turn time really can't be more than two days,” said Wood, “or you're just not going to get the deal."

What implementation could look like for your credit union

While the examples above come from larger credit unions, the operational challenges are familiar to institutions of every size. Many credit unions operate with lean lending teams where employees wear multiple hats. In those environments, reducing manual work, improving visibility, and eliminating repetitive tasks can have an even greater impact.

One misconception about modernizing lending is that every process must change at once. In reality, many credit unions begin by improving one area that creates the greatest operational friction.

That could include:

  • Improving commercial lending workflow visibility
  • Accelerating small business lending decisions
  • Reducing manual document collection
  • Standardizing approval paths
  • Improving reporting around loan status and workflow bottlenecks

Implementation typically begins with information the credit union already has, including:

  • Current lending workflows
  • Approval paths
  • Lending policies
  • Member and borrower information
  • Loan data
  • Documentation requirements
  • Operational goals for improving efficiency

From there, technology can be configured to align with the institution's existing processes while identifying opportunities to eliminate unnecessary manual steps. Because every credit union has unique priorities, lending automation can be introduced incrementally rather than through a large-scale operational overhaul.

Growth without piling more work on the team

Growing a loan portfolio doesn't have to mean growing administrative work at the same pace. Credit unions face increasing competition while working to preserve relationship banking, and technology can help staff focus on the work that matters most: responsive customer service, meaningful community outreach, and making timely lending decisions. Rather than spending valuable time on repetitive manual tasks, lenders can devote more attention to developing new opportunities and supporting their communities.

With better workflows, improved visibility, and lending automation, credit unions can manage higher loan volumes more efficiently, improve the experience for members, and continue expanding small business lending without placing additional strain on their teams. Incremental improvements can free employees to spend more time where they create the greatest value—with members.

Ramping up member business lending at your credit union? Do this, not that.

Download the guide

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

The credit mistakes we keep making

Commercial lenders have access to more information than ever before, yet problem loans still happen. The following are four common credit analysis mistakes that lenders can avoid by asking better questions and identifying risk before it becomes obvious.

1Trusting the numbers too much

Financial statements remain the foundation of commercial credit analysis, but reported earnings, strong leverage ratios, or favorable debt service coverage can create confidence that isn't always warranted.

Profitability does not necessarily translate into cash generation, and borrowers with healthy-looking financial statements may still experience significant liquidity pressure. Working capital trends, changes in receivables, inventory turnover, or payment behavior often reveal developing stress well before earnings begin to decline.

Likewise, management adjustments, normalization assumptions, and optimistic projections deserve thoughtful scrutiny rather than automatic acceptance.

You might also like this webinar, "Borrower assessment mistakes: Looking beyond the financial statements"

Watch the webinar

In a recent Abrigo webinar, Senior Consultant Kent Kirby warned lenders not to confuse accounting performance with repayment capacity. Strong credit judgment requires understanding how cash actually moves through the business and whether the borrower can continue generating enough cash to meet future obligations.

Kirby recalled an example from his own career: a rundown neighborhood strip center that seemed to be failing. Occupancy dropped from roughly 80% to about 50%, tenants moved out, and the financial statements during the renovation would almost certainly have shown deteriorating debt service coverage.

But what looked like deterioration was actually a carefully planned repositioning. The owner intentionally emptied the property, renovated it completely, upgraded the tenants, and accepted two years of weaker financial performance to create a much stronger property afterward.

2Failing to understand the business

Hand in hand with not relying solely on numbers is a second mistake: failing to understand the nature of a borrower's business. During the webinar, Kirby encouraged lenders to replace technical interrogation with genuine curiosity.

Rather than asking a borrower to explain maintenance capital expenditures, ask, "What did you have to replace last year?" Instead of questioning a growth projection, ask, "What are you planning to do to grow the business?" Those conversations often reveal risks or strengths that financial statements alone cannot. As Kirby noted, most business owners enjoy talking about their businesses. If they don't, that itself may be a warning sign.

A working capital line, an equipment loan, and a growth investment each carry different risks and require different analytical approaches. Looking at every loan through the same financial lens can cause lenders to focus on the wrong issues and miss what really drives repayment.

To sum up these first two common errors: "Don't mistake precision for understanding the business," Kirby said. “A lender focused only on declining ratios might downgrade the loan unnecessarily. A lender who understands the borrower's plan sees temporary weakness as part of a long-term strategy.”

3Missing early signs of deterioration

Problem loans rarely become problems overnight. Most begin with relatively small warning signs that are easy to explain away: slowing receivable collections, inventory growth, repeated covenant exceptions, declining margins, or subtle shifts in management behavior.

One common challenge is delayed risk recognition. Over time, covenant exceptions may become routine, annual reviews can turn into documentation exercises, and lenders may become accustomed to explaining away incremental deterioration rather than investigating its cause.

Strong portfolio monitoring means revisiting the original underwriting assumptions throughout the life of the loan. Are the conditions that supported the original approval still valid? Has the borrower's business changed? Have industry conditions shifted? Are management's original projections still realistic?

Kirby emphasized that rapid growth can consume cash just as quickly as declining performance. Lenders should investigate why cash is disappearing before assuming deterioration.

Every review should ask whether the borrower's story has changed and whether previously identified risks are evolving. Recognizing early warning signs allows financial institutions to engage borrowers sooner, explore potential solutions, and reduce the likelihood that manageable issues become significant credit problems.

4Letting bias shape credit decisions

Even experienced lenders are susceptible to biases that influence judgment. Confirmation bias encourages analysts to seek information that supports their existing conclusions while overlooking contradictory evidence. Strong customer relationships may create pressure to maintain favorable opinions despite emerging concerns. Groupthink can discourage individuals from asking difficult questions during committee discussions, while overconfidence may lead experienced lenders to underestimate evolving risks.

These influences often feel reasonable in the moment because they reinforce existing beliefs. Unfortunately, assumption-driven decisions can quickly unravel when business conditions change.

Healthy credit cultures recognize that thoughtful disagreement strengthens decision-making. Institutions that encourage independent thinking, constructive debate, and objective review are often better positioned to identify mistakes in credit analysis before they affect portfolio performance.

Kirby admitted that early in his career, he had a tendency to pay less attention to guarantors and care mostly about cash flow. Later, he realized that guarantors can either strengthen or weaken a deal depending on their own financial position. His lesson: Every experienced lender develops biases. Good credit culture requires recognizing those biases before they shape lending decisions.

Better credit judgment is a discipline

Lending will always involve uncertainty and risk. The objective is to improve the quality of decisions by strengthening how risks are identified, questioned, monitored, and discussed.

Disciplined lenders consistently ask:

  • What could go wrong?
  • Which conclusions are supported by facts versus assumptions?
  • Have the original underwriting risks changed?
  • Do policy exceptions indicate something more significant?
  • Are independent perspectives being encouraged throughout the credit process?

As discussed in Abrigo's webinar series, better lending decisions depend on preserving sound judgment, even as institutions continue to improve efficiency through automation. Technological advances create tremendous value, but they cannot replace nuanced credit analysis. The strongest analysts remain curious, challenge assumptions, and focus on understanding the story behind the numbers rather than simply processing them.

Build stronger credit judgment today with this three-part webinar series.

View the series

FAQs

What are the most common credit analysis mistakes?

Some of the most common credit analysis mistakes include relying too heavily on financial ratios, confusing earnings with cash flow, failing to understand how a borrower generates cash, overlooking early warning signs of deterioration, and allowing assumptions or biases to influence lending decisions. Strong credit analysis combines quantitative data with sound judgment and ongoing borrower monitoring

Why isn't a strong financial statement enough to support a lending decision?

Financial statements provide an important snapshot of a borrower's performance, but they don't always explain the underlying business. A profitable company may still experience liquidity challenges, while temporary declines in financial performance may reflect a strategic investment rather than deteriorating credit quality. Understanding the story behind the numbers is essential to making informed credit decisions.

How can lenders identify credit risk earlier?

Early risk identification begins with active portfolio monitoring. Reviewing covenant compliance, changes in cash flow, working capital trends, borrower performance, and the assumptions made during underwriting can help lenders recognize developing issues before they become significant credit problems.

Why are borrower conversations important during credit analysis?

Conversations with borrowers provide context that financial statements alone cannot. Asking practical questions about operations, growth plans, capital investments, and business challenges helps lenders better understand how the company generates cash and how management is responding to changing conditions. Those insights often strengthen both underwriting and ongoing risk assessment.

How can financial institutions improve credit judgment?

Improving credit judgment requires consistent habits rather than simply adding more data or technology. Encouraging independent thinking, challenging assumptions, revisiting risks throughout the life of the loan, and maintaining disciplined credit discussions all help lenders make more informed decisions while supporting a strong credit culture.

Independent credit risk review benefits extend to private credit funds 

Independent loan review for private credit funds can provide advantages such as objective risk validation and enhanced valuation credibility.

Credit risk review’s value beyond regulated banks

Modern loan review—an independent process that evaluates the adequacy of an institution’s ability to monitor and manage portfolio credit risk—has been a staple of commercial banking for decades. Private credit funds, by contrast, rose to prominence following the regulatory constraints imposed after the 2008–09 financial crisis, which limited banks' and credit unions' ability to meet certain borrower needs.

A defining feature of private credit, beyond a higher risk appetite, has been the relative absence of regulatory oversight. That freedom is now showing signs of strain. Recent developments point to weaknesses in credit monitoring and a rise in problem loans, according to reports like this. These developments have gotten me thinking: While loan review is most common in regulated financial institutions, its value extends to any environment where disciplined credit risk management is essential.

Spot hidden risks, challenge assumptions, and strengthen credit judgment. Learn how in this webinar series..

Access webinars

7 Ways loan review benefits private credit funds

This raises a straightforward question: should private credit funds adopt an independent loan review function as part of their fiduciary responsibility to investors?

The answer is yes, for several reasons:

  1. Independent risk validation
    Deal teams are incentivized to deploy capital and generate yield. An independent loan review function brings an objective perspective by challenging key assumptions, for example, around cash flow durability, covenant compliance, and ongoing loan portfolio monitoring. This helps counter confirmation bias and deal momentum.
  2. Portfolio-level risk intelligence
    Effective loan review assesses portfolio risk from the ground up, not just at the deal level. It identifies trends, concentrations, and emerging risks that may not be visible in isolation, answering a critical question: what risks are accumulating across the portfolio?
  3. Valuation discipline and mark credibility
    Private credit relies on internal marks rather than market pricing, which can lead to abrupt and credibility-damaging adjustments. A robust loan review process reinforces consistency in risk ratings, challenges overly optimistic valuations, and scrutinizes underlying methodologies. Done well, it helps reduce the likelihood of sudden “mark shocks” and supports investor confidence.
  4. Downturn preparedness
    Weak credits often remain hidden in benign environments. Loan review stress-tests downside scenarios and recovery assumptions to ensure portfolios are not positioned solely for favorable conditions.
  5. Feedback loop to improve origination
    Loan review is not an inquisition. Its purpose is not to identify “gotcha” moments, but to surface weaknesses in underwriting—whether in adjustments, projections, or valuation approaches—and strengthen the process over time. The objective is not adherence to process for its own sake, but confidence in its adequacy.
  6. Governance and fiduciary responsibility
    Banks operate with a fiduciary duty to depositors, who benefit from insurance protections. Private credit investors have no such backstop. That makes robust, independent risk oversight even more critical, particularly as funds grow in size and complexity.
  7. Reputation and fundraising advantage
    Recent headlines suggest investors are increasingly willing to exit—or attempt to exit—these funds. While still modest in scale, these actions are growing and highly visible. Managing both investor concerns and complex portfolios is distracting and inefficient. A credible, independent loan review function strengthens governance and provides reassurance where it matters most: investors want yield, but they also want their capital returned.

Structural differences will influence loan review implementation

The devil, of course, is in the details. While lending fundamentals are similar, structural differences between private credit and regulated institutions will influence how loan review should be implemented. What is clear, however, is that inaction is not a viable option.

Commercial banks have significant exposure to private credit funds, making this a shared concern. Private credit funds can benefit from conversations with their commercial banking brethren to develop a best practices approach to implementing an effective loan review program geared to their needs. 

As “sophisticated” investors grow more cautious—and as public policy trends toward broader retail access to private credit, including through vehicles like 401(k)s—the need for credible portfolio credit risk management becomes more urgent.  It is time to address it.

Ensure portfolio credit quality aligns with risk appetite and expectations. See how Abrigo's software and AI assistant can help.

Loan review software

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

FAQs

Why should private credit funds consider independent loan review?

Independent loan review can help private credit funds strengthen credible portfolio credit risk management. As sophisticated investors become more cautious and public policy trends toward broader retail access, the need for effective credit risk oversight is becoming more urgent.

What can private credit funds learn from commercial banks about loan review?

Private credit funds can benefit from conversations with commercial banks about loan review best practices. These discussions can help funds develop an effective loan review approach that is geared to their specific structures and needs.

How should loan review be implemented for private credit funds?

Loan review should be implemented in a way that reflects the structural differences between private credit funds and regulated financial institutions. Although lending fundamentals are similar, those structural differences will influence how an effective loan review program should be designed.

Why is portfolio credit risk management becoming more urgent for private credit funds?

Portfolio credit risk management is becoming more urgent as sophisticated investors grow more cautious and policymakers consider broader retail access to private credit. Potential access through vehicles such as 401(k) plans increases the importance of credible credit risk management.

Survey reveals opportunities for credit unions to strengthen fraud programs

While credit unions have long benefited from strong member relationships and high levels of trust, the findings from Abrigo’s 2026 State of Fraud Survey suggest that trust alone may not be enough to address growing concerns about fraud, artificial intelligence, and financial security.

The survey, which included responses from 248 credit union members across the United States, found that members generally feel safe with their credit unions and appreciate the fraud prevention efforts already in place. However, the results also reveal opportunities for credit unions to strengthen communication, improve member education, and build greater confidence in their fraud detection programs.

 

Fraud remains a personal concern

Fraud is not a distant threat for many credit union members. Nearly 40% of respondents reported being victims of financial fraud at some point. Additionally, 21% experienced fraudulent activity involving their account during the previous 12 months, while 17% experienced fraudulent activity involving a credit card.

When fraud occurs, the impact extends beyond financial loss. Among credit union members who experienced fraud:

  • 59% spent significant time resolving the issue
  • 56% experienced stress or anxiety
  • 44% experienced financial loss
  • 35% reported a loss of trust in their financial institution

Staying on top of fraud is a full-time job. Let our Advisory Services team help when you need it.

Connect with an expert

Members trust their credit unions, but confidence has room to grow

One of the most encouraging findings in the survey is that credit union members generally feel safe with their institutions. More than 85% reported feeling either very safe or somewhat safe with their credit union. Nearly half, 45%, said they feel very safe.

Interestingly, confidence in fraud protection does not fully match those safety perceptions. Only 41% reported being very or extremely confident that their credit union is protecting them from fraud. More than half described themselves as only somewhat confident.

This distinction matters. Members clearly trust their credit unions, but many are uncertain about the specific tools, technologies, and processes being used to protect their accounts. This creates an opportunity for credit unions to strengthen member confidence through education and transparency.

Credit union members are concerned about AI-enabled fraud

Artificial intelligence is becoming a larger part of the fraud conversation. Nearly two-thirds of credit union members, 66%, reported being very or extremely concerned about AI-powered fraud techniques such as deepfake videos, synthetic voices, and AI-generated phishing emails. Another 26% reported being moderately concerned.

Data breaches and hacking remain the greatest concern among digital fraud threats, selected by 59% of respondents. Smart fake emails, deepfake scams, and peer-to-peer payment fraud also ranked among the most concerning fraud tactics.

At the same time, members recognize that AI can also play a role in fighting fraud. Nearly one-third said they would feel more confident in their credit union’s fraud detection capabilities if AI-powered fraud detection tools were being used. However, more than half of respondents said they do not know whether their credit union currently uses AI-powered fraud detection technology.

This finding highlights a common challenge facing many financial institutions. Technology investments alone may not increase confidence if members do not understand how those tools help protect them.

Members want faster alerts and stronger authentication

Credit union members were clear about the types of fraud prevention tools they value most. When asked what would make them feel more secure, respondents most frequently selected:

  • Faster fraud alerts and automatic transaction blocking (59%)
  • Stronger authentication methods such as biometrics and multi-factor authentication (46%)
  • Personalized fraud prevention tips from their credit union (29%)
  • AI-driven fraud detection that learns from spending habits (24%)

Education remains a powerful fraud prevention tool

Many credit union members already take an active role in protecting themselves. Nearly half reported educating themselves about emerging threats, while 44% use transaction notifications and 42% use multi-factor authentication on financial accounts.

Despite these efforts, many members still feel they need additional information. When asked about AI’s role in fraud detection, 44% selected “neutral” because they need to learn more. Only 16% viewed AI as highly effective in fraud detection. For credit unions, this presents an opportunity to strengthen member relationships through education.

Providing practical information about emerging scams, fraud prevention technologies, account security practices, and artificial intelligence can help members make informed decisions while increasing confidence in the institution’s fraud prevention efforts.

Fraud prevention is becoming a member experience issue

Perhaps the most important finding for credit unions involves the potential impact of fraud on member relationships. Nearly 60% of respondents said they would be more likely to reduce their banking relationship if they became victims of fraud.

This means fraud prevention is no longer solely a risk management issue. It is also a member experience issue. Credit unions have long differentiated themselves through service, trust, and community relationships. Those strengths can become even more valuable as fraud threats continue to evolve.

Members want to know that their credit union is actively protecting them. They want timely alerts, effective fraud controls, and clear communication. Most importantly, they want confidence that their institution is prepared to respond when fraud occurs.

The bottom line

The 2026 survey findings show that credit union members continue to trust their institutions, but they also expect more from them.

Members are concerned about fraud. They are increasingly aware of AI-enabled threats. They want stronger fraud prevention tools, faster alerts, and greater transparency about how their credit union is protecting them.

Credit unions are uniquely positioned to meet these expectations. By combining strong member relationships with effective fraud prevention programs, ongoing education, and clear communication, credit unions can continue to build trust while helping members navigate an increasingly complex fraud environment. The credit unions that invest in both fraud prevention and member confidence today will be better positioned to strengthen relationships, reduce losses, and serve their communities in the years ahead.

See how Taunton Federal Credit Union streamlined and strengthened fraud detection with Abrigo.

Read the case study Learn more

What is an AML/CFT risk assessment?  

An AML/CFT risk assessment is the foundation of a financial institution's anti-money laundering and countering the financing of terrorism compliance program. It is the process of identifying, evaluating, and understanding the money laundering, terrorist financing, fraud, sanctions, and other illicit financial activity risks associated with an institution's customers, products, services, delivery channels, and geographic footprint. More importantly, the risk assessment provides the framework for designing controls, allocating compliance resources, and ensuring the institution's AML/CFT program remains aligned with its unique risk profile. 

Rethinking the AML/CFT Risk Assessment 

For many financial institutions, the AML/CFT risk assessment has traditionally been viewed as an annual milestone. Data is gathered, risk ratings are updated, a report is presented to senior management and the board, and then the document sits largely untouched until the next review cycle. 

That approach no longer reflects today’s financial crime landscape. Criminals continuously adapt their methods. New payment channels are emerging, digital banking is expanding customer access, and artificial intelligence (AI) is changing both how financial institutions detect suspicious activity and how criminals carry out fraud schemes. At the same time, regulatory expectations continue to evolve, emphasizing that institutions should understand how their unique risk profile changes over time rather than relying on a static assessment. 

The AML/CFT risk assessment has become the foundation of an effective financial crime program. Institutions that treat it as a living process rather than an annual exercise are better positioned to identify emerging risks, allocate resources strategically, and strengthen the overall effectiveness of their compliance programs. 

Staying on top of fraud is a full-time job. Let our Advisory Services team help when you need it.

Connect with an expert

How are regulatory expectations for risk assessments changing? 

This shift also aligns with regulatory expectations. The FFIEC BSA/AML Examination Manual emphasizes that an institution's risk assessment should identify and evaluate the specific risks it faces from money laundering, terrorist financing, and other illicit financial activities and serve as the foundation for a risk-focused compliance program.  

Every financial institution has a unique risk profile shaped by its customers, products, services, delivery channels, and geographic footprint. In the past, many of those risk factors evolved gradually. Today, meaningful changes can occur almost overnight. 

A community bank may introduce digital account opening. A credit union may expand its faster payment capabilities. Even relatively small business decisions can significantly change an institution’s exposure to money laundering, terrorist financing, fraud, and sanctions risks. 

External events reshape risk just as quickly. Criminal organizations rapidly adopt new technologies. AI is being used to create increasingly convincing phishing campaigns, synthetic identities, and social engineering attacks. Geopolitical conflicts create new sanctions requirements. Human trafficking networks adjust their methods, and fraud schemes that were uncommon just a year ago quickly become widespread. Financial institutions cannot afford to wait until the next annual review to evaluate these changes. 

If an institution’s understanding of risk remains unchanged while financial crime continues to evolve, gaps inevitably develop between actual exposure and the controls designed to manage that risk. 

Connected financial crime 

Another important shift is the growing recognition that fraud and AML/CFT risks are closely connected. Identity theft, account takeover, business email compromise, elder financial exploitation, and authorized fraud often represent the beginning of a much larger financial crime event. Once criminals obtain funds through fraud, they must move, conceal, or integrate those proceeds into the financial system.  

When fraud and AML/CFT teams operate independently, institutions often see only part of the story. Information uncovered during a fraud investigation may significantly influence customer risk ratings, transaction monitoring, or investigations into suspicious activity. Likewise, AML/CFT investigations frequently identify behavioral patterns that strengthen fraud detection efforts. 

Institutions should evaluate not only individual risks but also how those risks intersect across the organization. A more connected view of financial crime supports stronger investigations, better resource allocation, and a more complete understanding of emerging threats. 

 

How do risk assessments affect business decisions at an FI? 

The purpose of a risk assessment extends far beyond assigning risk ratings. An effective AML/CFT risk assessment provides the context for many of the most important decisions a financial institution makes. It influences staffing priorities, customer due diligencetransaction monitoring strategies, independent testing, employee training, and technology investments. More importantly, it helps leadership determine whether the institution’s current risk exposure remains consistent with its established risk appetite. 

As an institution’s risk profile changes, leadership should regularly evaluate whether existing controls remain appropriate for the level of risk the organization has chosen to accept. If new risks exceed that tolerance, leadership can strengthen controls, dedicate additional resources, or reconsider strategic initiatives before vulnerabilities become larger problems. 

When risk assessments actively support business planning, compliance becomes an enabler of responsible growth rather than simply a regulatory obligation. A risk assessment that actively shapes decision-making is not only more valuable to the institution but also more consistent with the direction regulators continue to encourage. 

What are the regulatory expectations for risk assessments? 

While regulations do not prescribe how often an AML/CFT risk assessment must be updated, institutions are expected to reassess risk whenever meaningful changes occur. The FFIEC examination procedures make clear that risk assessments should reflect the institution's current products, services, customers, geographic footprint, and delivery channels. As those elements change, institutions should evaluate whether their assessments and corresponding controls continue to reflect their risk profiles accurately. 

Regulators continue to emphasize effectiveness over documentation alone. Institutions are increasingly expected to demonstrate that their risk assessment informs the design of their controls, resource allocation, and monitoring activities rather than existing as a standalone compliance document. 

Examiners also expect compliance teams to have a seat at the table before strategic decisions are finalized. Bringing compliance into discussions early allows institutions to identify potential risks before they become operational challenges. It also helps ensure that new initiatives are designed with appropriate controls from the outset rather than requiring costly adjustments later. 

This collaborative approach positions compliance as a strategic business partner while demonstrating that risk management is fully integrated into organizational decision-making. 

 

How have technology and AI affected risk assessments? 

Maintaining a current understanding of institutional risk would be difficult using manual processes alone. Modern AML/CFT platforms enable continuous analysis of customer onboarding, transaction monitoring, fraud detection, sanctions screening, cybersecurity, and case management. However, technology is only as effective as the quality of the data supporting it. Institutions should regularly evaluate whether the information used throughout the risk assessment process is complete, accurate, and relevant. Collecting more data does not automatically produce better insights. The objective is to identify the information that truly reflects changing risk and to use it consistently to support sound decision-making. 

AI is also becoming an increasingly valuable component of risk assessment. As institutions adopt AI-driven tools, they should also ensure those models are appropriately governed, validated, and monitored over time. Effective governance builds confidence that AI produces reliable, explainable results while meeting regulatory expectations. 

Rather than relying exclusively on predefined rules, AI can identify subtle behavioral changes, emerging transaction patterns, and complex relationships that may otherwise go unnoticed. These capabilities help compliance teams recognize meaningful shifts in risk earlier and respond more effectively. 

Automation further strengthens the process by reducing the manual effort traditionally associated with risk assessments. Instead of spending valuable time gathering information from multiple systems, compliance professionals can focus on evaluating emerging risks, validating findings, and recommending actions that strengthen the institution’s overall control environment. 

The goal is not simply to process more information. It is to transform information into timely intelligence that supports better decisions. 

 

A Stronger AML/CFT Program 

The strongest AML/CFT programs are no longer centered on an annual risk assessment. They are built on continuous risk awareness. When institutions use the assessment to shape strategy, strengthen controls, and guide resource allocation, they can respond more effectively to emerging threats while supporting safe, sustainable growth. 

In an increasingly complex financial crime environment, a dynamic risk assessment is more than a regulatory expectation; it is a competitive advantage. Institutions that adopt this mindset are better positioned to protect customers, demonstrate a truly risk-focused compliance program, and adapt confidently to future challenges. 

Find out how to automate sanctions screening to reduce false positives.

Abrigo Intelligent Scan

FAQs

What does an AML/CFT risk assessment evaluate?

An AML/CFT risk assessment evaluates a financial institution’s exposure to money laundering, terrorist financing, fraud, sanctions, and other illicit financial activity. It considers customers, products, services, delivery channels, and geographic markets so the institution can design proportionate controls, allocate compliance resources, and keep its financial crime program aligned with its actual risk profile.

Why should an AML/CFT risk assessment be treated as a living process?

An AML/CFT risk assessment should be treated as a living process because customer behavior, payment channels, criminal methods, sanctions exposure, and digital threats can change faster than an annual review cycle. Ongoing risk awareness helps institutions identify gaps between current exposure and existing controls early enough to adjust monitoring, staffing, training, or strategy.

What events should trigger an AML/CFT risk assessment update?

Meaningful changes to an institution’s risk profile should trigger a full or partial AML/CFT risk assessment update. Common triggers include launching new products, entering new markets, adding customer types, expanding digital account opening or faster payments, completing a merger, or encountering significant changes in criminal activity, technology, or sanctions requirements.

Why should fraud and AML/CFT teams share risk information?

Fraud and AML/CFT teams should share information because fraud proceeds often must be moved, concealed, or integrated through the financial system. Connecting insights from identity theft, account takeover, business email compromise, elder exploitation, and similar investigations can improve customer risk ratings, transaction monitoring, suspicious activity investigations, and the identification of broader financial crime patterns.

How can AML/CFT risk assessments support strategic business decisions?

AML/CFT risk assessments support strategic decisions by informing staffing, customer due diligence, transaction monitoring, independent testing, training, technology investments, and control design. They also help leadership compare current exposure with the institution’s risk appetite and determine whether to strengthen controls, allocate additional resources, or reconsider an initiative before risk exceeds acceptable levels.

Making the case for using AI at banks and credit unions 

Build buy-in by defining the business problem first, tailoring messages to each stakeholder group, emphasizing human oversight, and documenting governance, controls, and success metrics.

Tips for getting internal AI  support

Inside financial institutions and other organizations, a major obstacle to innovation is often getting people with different responsibilities, incentives, and concerns to agree that the change is worth making.

Apple faced an alignment challenge while developing the first iPhone. Many inside and outside Apple questioned whether people would ever accept typing on a sheet of glass instead of a smartphone keyboard. Steve Jobs argued that a software keyboard could adapt to the user, whereas physical keys permanently constrained what the device could become. But turning that vision into a successful product required buy-in from engineers, carrier partners, software developers, and consumers. As a result, the touchscreen became the foundation for an entirely new generation of mobile computing.

Related webinar, “Defensible AI in financial services: Operationalize AI safely and effectively.”

Watch webinar

Artificial intelligence (AI) presents a similar leadership challenge for financial institutions. Success tapping into the technology’s potential depends on earning buy-in from people who evaluate it through very different lenses. Executives want a business case. Compliance leaders want governance. IT wants security and integration. End users want confidence that AI will help them do their jobs rather than replace them.
Here’s how financial institution leaders can build AI support among stakeholders so your bank or credit union can survive and thrive in a rapidly changing industry.

Buy-in starts with the problem, not the technology

Abrigo Chief Technology and Product Officer Ravi Nemalikanti says that for banks and credit unions, preparing institutions and their people to build trust and use AI wisely has become a major focus.

Nemalikanti

“This conversation about AI has truly shifted from if we are going to use the technology to how well we are going to use the technology and how well we are going to adopt AI into our day-to-day workforce,” he said during a recent webinar on AI. “It’s ‘How do we create leverage and get that adoption to really get going?’ and ‘How do we build that trust and get our organizations to be ready to consume AI and AI capabilities?’”

He and other Abrigo experts say leaders looking to develop buy-in for AI should begin by clearly defining the business problem before advocating for AI. Rather than positioning AI as a broad transformation, begin by tying AI strategy to specific problems it might help solve.

“Try to think of one friction point in your day-to-day—one workflow, one bottleneck—and see how AI might be able to… make it a little bit smoother,” Nemalikanti said.

Look for places where employees spend time on repeatable work that can be described, controlled, and reviewed. Examples Abrigo product teams have heard from institutions include:

  • Staff spend too much time creating or updating documentation manually
  • Policies, procedures, or customer information are hard to find quickly
  • Similar work is handled differently across teams or branches
  • Analysts perform repetitive reviews that limit time for higher-value judgment-based tasks
  • Teams must manage growing workloads without adding staff

AI buy-in is easier when stakeholders can see a low-risk, measurable first AI use case and the data and controls that will be applied.

How should you tailor the message to each stakeholder group?

Because AI can be adopted and scaled across the bank or credit union, leaders looking to encourage stakeholders to embrace a different way of solving business problems must frame their communications for each group. Each audience may have a different motivation and see different risks, so messaging should speak to their specific interests and questions.

Senior leadership: How does AI support business priorities?

Executives need to understand how AI supports the institution’s broader goals. Frame the discussion around practical outcomes such as improving efficiency, increasing consistency, and making better use of employee time.

Boards: How will we oversee and defend AI use?

Board members do not need a technical deep dive, but they do need confidence that AI use cases can be explained, monitored, and governed. Focus the conversation on transparency, accountability, human review, and how the institution will document and defend its approach.

Compliance and audit teams: How will we meet regulatory and internal controls?

Compliance and audit teams need to review AI plans early in the process—before decisions are made. These teams can help clarify expectations for documentation, data use, review processes, testing, and ongoing monitoring.

IT teams: What are the privacy and security implications?

Addressing AI-related information security and privacy concerns is foundational to creating buy-in for AI, just as it is when launching any new technology. Infosec teams need information about the model and the data that will be provided to it so that they can focus on security and data privacy protocols.

Department leaders/peers: How will this help my team now?

Department leaders can more easily support AI when they see how it can help their teams solve real problems. Ask where teams are losing time, duplicating effort, or struggling to keep up with volume. When possible, provide examples of other financial institutions’ experience using AI to make the opportunity more concrete.

Frontline employees: Will this replace my job?

Be clear that AI is meant to reduce repetitive work, not replace the judgment, relationships, and accountability employees bring to their roles. Provide examples of how this might work in practice.

Emphasize human oversight

Bailey Barretto, Consultant and Change Manger with Abrigo Advisory

Barretto

AI is a support tool, not a substitute for institutional judgment. Strong internal advocacy should make clear where people remain in the process, whether it’s reviewing outputs, making decisions, or owning outcomes.

“AI is not about replacing human judgment; it’s augmenting it,” said Bailey Barretto, Abrigo’s Director of Advisory Services. The goal is to give decision makers intelligent tools that will give them better information and visibility, and more time for their judgment-based work.

An example of how that works in real-life financial services is Old National Bank’s use of Abrigo’s AI-powered Loan Review Assistant to scale its commercial loan review capacity. Read the Loan Review Assistant case study.

The assistant analyzes credit memoranda, annual reviews, financial statements, collateral documentation, guarantor information, and supporting credit files and drafts review narratives and workpapers. But reviewers validate the AI-generated content, and analysts remain responsible for conclusions and documentation. Even with the time required for a staff member to stay in the evaluation loop, reviewers report average efficiency improvements of 20% to 40%. The increased level of document analysis possible translates into nearly two full work weeks of analyst capacity each month, leaving reviewers more time to evaluate risk, support conclusions, and apply professional judgment.

Defensibility is the bridge from AI interest to action

Stakeholders who see AI’s value will next ask whether the institution can implement it responsibly. Build trust and secure support from various people and teams by addressing AI explainability, control, documentation, and governance.

Leaders need to help stakeholders trust the guardrails around AI so they feel confident using it. Internal buy-in grows when those involved or affected by the technology understand both what AI can do and how the institution will oversee and defend its use.

Corporate governance should align AI use with the institution’s strategic goals and regulatory expectations. Support AI efforts with documentation, board-level oversight, and training. Learn key questions for AI governance at credit unions. 

A quick checklist before proposing an AI use case

To build internal buy-in, be ready to answer:
  • What specific problem are we solving?
  • Who benefits from the improvement and how will it be measured?
  • What data is involved?
  • Where and how will human review occur?
  • How will outputs be explained and documented?
  • Who owns ongoing oversight and monitoring?
  • How will success be measured and who reports on it?

Buy-in requires clarity

Successful AI adoption takes more than one person championing the technology. It gains traction when stakeholders understand what the bank or credit union is trying to accomplish, how they will control AI, and why the effort is worth supporting. Start with one workflow. Document governance and controls, and report results against agreed success metrics. For practical guidance and templates, see Abrigo’s additional resources on AI.
This blog was written with the assistance of ChatGPT, a large language model. It was reviewed by Abrigo subject matter experts.

Download this brief guide to learn more: "10 Moves that strengthen AI oversight & compliance"

Download now

FAQs

How do banks and credit unions build buy-in for AI?

Banks and credit unions build buy-in for AI by connecting each initiative to a clearly defined business problem, such as reducing manual work, improving service, or strengthening risk monitoring. Early involvement from leadership, compliance, IT, operations, and frontline employees helps create shared ownership and address concerns before implementation.

Which stakeholders should be involved to build support for AI?

AI initiatives should involve executive leadership, IT, operations, compliance, risk, legal, data teams, and employees who will use or be affected by the technology. Early cross-functional participation helps identify concerns, clarify responsibilities, and prevent AI from being treated as a technology-only initiative.

How should banks and credit unions address employee questions about AI?

Banks and credit unions should explain how AI will change specific tasks, where human judgment remains necessary, and what training employees will receive. Involving employees in testing and workflow design can reduce uncertainty, surface operational risks, and create greater trust in the adoption process.

The information, content and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

What AI explainability means and why it matters in financial services 

As financial regulators focus on AI governance, explainable AI is quickly becoming a regulatory expectation. Learn explainability techniques and what banks and credit unions should ask AI vendors.

How does explainable AI in banking compare to black-box AI? 

Explainable AI (XAI) is any artificial intelligence system that shows why it generated a certain output, including what influenced it, how, and how much. Black-box AI produces outputs without enough transparency to understand the model’s approach, limitations, reliability, or the factors driving a specific decision.

For banking compliance officers and other technology decision makers, AI explainability is tied to regulatory and examination expectations, so it is a business necessity rather than merely a technical consideration. An opaque AI model can make it harder for financial institutions to validate, document, and defend AI-driven decisions, whether they are in credit underwriting, financial crime investigations, customer service, or other areas. Financial institutions must know how the AI works and how to know if it’s working right.

Here’s what examiners expect, how XAI works in practice, what questions every bank or credit union should ask an AI vendor, and how Abrigo delivers explainable AI solutions.

Related webinar: "Defensible AI in financial services: How to operationalize AI safely and effectively"

Watch the webinar

Explainability is becoming a compliance requirement

As financial regulators increase their focus on AI governance, explainable AI is quickly becoming a regulatory expectation. Across the banking industry, regulators have sent the same message: if AI influences an important business decision, the institution must be able to explain how the technology reached its conclusion. Saying a model is a "black box" is insufficient.

SR 26-2 and model risk management

The expectation starts with model risk management. Earlier this year, the Federal Reserve, FDIC, and OCC issued SR 26-2, which replaces SR 11-7 and SR 21-8. At its core, the guidance says institutions need to understand and manage their models well enough to manage the risks of their use. That includes model design, assumptions, data, methods, limitations, performance, and monitoring. The principles apply to AI and machine learning models used in banking as well as traditional statistical and quantitative models. Credit unions should view these expectations through their own supervisory framework, including NCUA’s risk-management focus for AI use.

FFIEC IT Examination Handbook

But explainability extends well beyond model risk. The FFIEC IT Examination Handbook warns that AI lacking transparency or explainability can be “unclear how inputs are translated into outputs,” increasing compliance and operational risk.

Reg B

Regulation B requires creditors to provide specific reasons for adverse credit actions, including when AI is involved. Saying the technology was too complex or opaque to understand doesn’t void the obligation. Fair lending reviews also depend on understanding why models produce the outcomes they do related to credit access, pricing, and underwriting. AI explainability is essential for identifying and managing potential bias.

Other organizations

Other leading organizations reinforce an emphasis on explainability. The Financial Action Task Force (FATF) has highlighted explainability and transparency as key considerations for AI used in AML and financial crime solutions. The GAO defines explainability as the ability to understand how and why an AI system produces its decisions, predictions, or recommendations. The National Institute of Standards and Technology (NIST) builds on that definition with four principles: explanations should be supported, meaningful to the intended audience, faithful to the model's actual behavior, and transparent about the model's knowledge limits.

These principles align closely with what banking supervisors increasingly expect. Whether the issue is model risk management, fair lending, or AML, the question is ultimately the same: Can the institution explain how its AI reached a decision and when that decision should not be trusted? That's the difference between explainable AI and a black-box model. It is also the difference between AI that can withstand regulatory scrutiny and AI that cannot.

How explainable AI works in practice

AI explainability isn't one-size-fits-all. The degree and output should fit the use case and depend on the type of AI and the decision being made. For predictive AI, explainability focuses on why a model made a prediction or score. For generative AI, it's about understanding how a response was produced, including the prompts, retrieved information, and supporting evidence. For agentic AI, explainability extends a step further, capturing why the AI chose a particular course of action and the sequence of decisions it took to complete a task.

Regardless of the technology, the goal is the same: make AI decisions understandable, traceable, and defensible. In practice, XAI can utilize many techniques. These include feature attribution, reason codes, confidence scores, prompt and response traceability, supporting evidence, action logs, or other artifacts that help analysts, validators, auditors, and examiners understand how an AI system reached its conclusion.

Two explainability techniques common in banking AI

For predictive AI models, the two explainability techniques financial institutions are most likely to encounter are SHapley Additive exPlanations (SHAP) and Local Interpretable Model-Agnostic Explanations (LIME). They are not regulatory requirements, but they have become widely used methods for opening the black box.

SHAP

SHAP explains why a model reached a specific score or decision by showing how much each input contributed to the outcome. For example, in banking, it can identify whether cash flow, debt levels, or transaction behavior had the greatest influence on a credit decision, fraud score, or AML alert. Being able to attribute specific influencing features can be useful for supporting internal review, model validation, and adverse action analysis.

LIME

LIME takes a different approach. Rather than assigning contribution values to each feature, it builds a simpler approximation of the model around a single prediction. The surrogate model helps analysts and validators better understand the model's behavior for that specific decision.
The important point isn't whether an AI solution uses SHAP, LIME, or another explainability technique. It's whether the system can produce clear, defensible explanations and the evidence to support them that stand up to model validation, audits, and regulatory examinations.

Graphic showing AI explainability techniques

Banks and credit unions evaluating AI vendors should ask whether the system provides SHAP, LIME, reason codes, or an equivalent method for explaining individual outputs. The answer should include how explanations are generated, whether they can be exported, who can access them, and how they are documented for validation, audit, and examination.

Examples of problems with black-box AI

Black-box AI creates practical problems because banking decisions must be explainable to several audiences: customers, compliance staff, validators, auditors, management, boards, and examiners. Predictive performance alone does not answer the institution’s governance questions. Examples of how black-box AI can be problematic include:

  1. Loan denial with no usable reason code. A credit model recommends denial, but the institution cannot identify the principal factors that drove the decision. That creates adverse action risk under Regulation B and CFPB guidance.
  2. Fraud alert with no explainable trigger. If an analyst cannot determine which activity caused a fraud detection system to flag an account or transaction, the review may take longer. Documentation may be weaker, and confidence in the alerting process may decline, as the FFIEC Handbook warns.
  3. Model drift goes undetected. A model may perform differently over time as borrower behavior, market conditions, products, or data quality changes. SR 26-2 describes ongoing monitoring, including whether a model continues to perform as expected, as part of model risk management. An institution that cannot understand what is changing in the model’s behavior may have difficulty identifying problems or deciding when remediation is needed.
  4. Fair lending review cannot identify outcome drivers. An examiner, auditor, or compliance officer asks which variables influenced different outcomes across applicants or markets. If the institution cannot evaluate the drivers of model outcomes, it may struggle to assess fair lending risk, test for unintended bias, or explain how the model is being controlled.

An explainability checklist for AI vendors

Vendor due diligence should include whether the financial institution can oversee, validate, monitor, and document the AI system throughout its lifecycle.

Ask vendors these XAI questions:

  • What is the model’s intended use, and what uses are out of scope?
  • What data is used to train, test, and operate the model?
  • What validation documentation is available, including assumptions, limitations, methodology, and performance?
  • Can the system explain individual decisions, recommendations, alerts, or scores?
  • Does the system provide SHAP, LIME, reason codes, feature attribution, or an equivalent explanation method?
  • Can explanations be exported for audit, validation, or examiner review?
  • Does the system support accurate adverse action reasons when used in credit decisions?
  • How are performance, drift, data quality, retraining, and version updates monitored and documented?
  • What audit trail is maintained, including inputs, outputs, timestamps, users, overrides, and final decisions?
  • How does the vendor support independent validation, examiner review, and alignment with FFIEC, consumer compliance, and internal governance expectations?
  • What controls prevent unauthorized changes or inappropriate use?
  • For community financial institutions, the goal is practical exam defensibility. The institution should be able to show what the AI system does, how it is controlled, how performance is monitored, how exceptions are handled, and how decisions or recommendations can be explained.

How Abrigo delivers explainable AI

Explainability isn't something Abrigo adds after an AI model is built; it's designed into the entire AI lifecycle. Whether AI is making a prediction, generating a recommendation, or executing an agentic workflow, every outcome should be understandable, auditable, and aligned with the institution's governance requirements.

Strong model governance

Abrigo starts with strong model governance. AI models undergo independent third-party validation before deployment and are supported by comprehensive documentation describing their intended use, development methodology, assumptions, limitations, performance, governance, and monitoring. This gives financial institutions the information they need to incorporate Abrigo's AI into their own model risk management programs.

Decision-level explainability

For AI-driven predictions, Abrigo provides decision-level explainability using SHAP-based feature attribution. Rather than presenting only a score, the platform identifies the factors that most influenced the outcome and translates them into intuitive, human-readable explanations. Analysts can understand what drove a credit decision, fraud score, or AML alert, making decisions easier to review, document, and defend.

Graphic showing Abrigo Fraud Detection's transparency dashboard

Traceability

For AI-generated recommendations and agentic workflows, explainability comes through traceability. Abrigo records user prompts, AI responses, supporting citations, timestamps, user identity, interaction history, and administrative actions, creating a comprehensive audit trail that can be exported for governance, audit, and examiner review. As AI agents perform increasingly sophisticated tasks, Abrigo also emphasizes policy alignment, human oversight for higher-risk situations, and continuous quality controls so institutions retain control over AI-assisted actions.

Model monitoring

Explainability also extends beyond individual decisions. Abrigo continuously monitors its consortium-trained AI models for performance, feature stability, data drift, and prediction quality. When meaningful changes are detected, models are reviewed and refreshed as appropriate to help ensure they continue to perform as intended.

Ultimately, AI explainability is about trust. Analysts need to understand what drove a recommendation. Validators need evidence that models behave as expected. Auditors need a complete record of AI activity. And examiners need confidence that AI-assisted decisions can be understood, challenged, and defended.

That's the philosophy behind Abrigo's AI platform. Abrigo’s AI is built not only to be intelligent but also explainable, auditable, and governed from end to end.

Explainability from the start for AI governance

In a regulated environment, an AI system’s value depends on whether the institution can use it responsibly, control it effectively, and explain it when asked. Explainability should be part of AI governance from the start. Financial institutions evaluating AI should require clear documentation, individual-level explanations where needed, audit trails, performance monitoring, and vendor support for validation and examiner review.

Find out more about Abrigo's comprehensive portfolio of AI-powered solutions.

AI-powered products

FAQs

What is explainable AI?

Explainable AI is AI that allows an organization to understand how the system produces outputs, what inputs influenced a decision or recommendation, and how the model should be validated, monitored, documented, and controlled. For financial institutions,  the level of explanation needed depends on the use case, model complexity, customer impact, and risk to the institution.

What is the difference between explainable AI and black-box AI?

Explainable AI gives the organization enough visibility to understand the model’s inputs, outputs, assumptions, limitations, and decision drivers. Black-box AI produces outputs without enough transparency to understand how the result was generated. In banking, that difference affects validation, monitoring, adverse action support, fair lending review, vendor oversight, and examination readiness.

Why do banking regulators care about explainable AI?

Banking and financial services regulators care because financial institutions are expected to manage the risks of the models and technology systems they use. Explainability supports documentation, validation, effective challenge, monitoring, auditability, consumer compliance, and fair lending review. The FFIEC IT Examination Handbook specifically identifies lack of AI transparency or explainability as a risk.

What is SR 26-2, and how does it relate to AI explainability?

SR 26-2 is the 2026 interagency model risk management guidance that supersedes SR 11-7. It does not impose a universal explainability rule for AI, but it emphasizes risk-based model governance, validation, monitoring, documentation, limitations, assumptions, and effective challenge. Those expectations are difficult to support when a material AI model cannot be meaningfully understood or reviewed.

What are SHAP and LIME, and do community financial institutions need to know about them?

SHAP and LIME are techniques used to explain model outputs. SHAP shows how individual inputs contributed to a prediction. LIME creates a simpler local explanation for a specific output. Community banks and credit unions do not need to use those exact methods in every case, but they should understand whether a vendor provides individual-level explanations that support validation, audit, compliance, and examination needs.

What should a community financial institution ask an AI vendor about explainability?

A community bank or credit union should ask whether the vendor can explain individual model outputs, provide validation documentation, support adverse action reasons where relevant, export explanation artifacts, document model changes, monitor drift, and maintain audit trails. The institution should also ask how the vendor supports independent validation, examiner review, and ongoing performance monitoring.

The information, content, and materials provided through this website are for informational purposes only and are not intended to constitute legal advice. Customers should consult with their legal counsel regarding the application of laws and regulations to their specific circumstances.

Not all developers of banking AI technology are the same 

Regulated financial institutions require AI technology designed for data protection, auditability, and human involvement.  Here’s Abrigo’s AI development approach.

"Nothing can be a black box."

Financial institutions cannot afford mystery in their technology. They need tools that protect data, support auditability, and help teams understand how outputs are produced. As artificial intelligence becomes part of more banking workflows, those expectations should guide how AI is developed, deployed, and reviewed.

I recently spoke with Danny Piangerelli, Abrigo’s Senior Vice President of Technology, on Abrigo’s “Ahead of the curve” podcast for bankers, and we discussed responsible AI in banking and what it takes to build AI tools for regulated institutions.

Piangerelli leads data and AI platform engineering at Abrigo, and his approach starts with the environment in which banks and credit unions operate. Financial institutions are regulated and audited. Their vendors have to account for those realities from the beginning.

Visit Abrigo's AI Hub for resources, product info, and an AI glossary

Visit the AI Hub

As Piangerelli put it, “Nothing can be a black box.”

This idea is central to how Abrigo develops responsible AI in a regulated environment. AI can help users find information faster, generate drafts, review patterns, and interact with complex data in more natural ways. For those tools to be useful in banking, they also need to be secure, explainable, and transparent.

Responsible AI starts with the realities of banking

AI can feel new, but Abrigo’s approach to new technology is grounded in long-standing company principles: protect customer data, protect access to that data, and give users visibility into how systems work.

During our discussion, Piangerelli described Abrigo’s starting point as consistent with other technology decisions the company has made over the past 20 years. Each unique financial institution must be in the driver’s seat and able to defend its software to auditors and examiners.

For AI development, the practical test is straightforward, with focus areas like.

  • Can the data be protected?
  • Can users explain what the system is doing?
  • Can the user review the output?
  • Can the institution understand how the tool fits into its workflow and risk framework?

Responsible AI in banking must address those questions before a tool can be trusted for real work inside a financial institution.

Secure AI depends on data protection and controlled access

One of the clearest risks with AI in financial services is data exposure. Banks and credit unions often want to use AI to search policies, summarize documents, answer questions, or support staff. They also have sensitive data that cannot be treated casually.

Abrigo heard this directly from customers, Piangerelli said. Financial institutions wanted the usefulness of a ChatGPT-like experience, but they could not upload private documentation into public tools.

Abrigo’s response with AskAbrigo, our AI-powered banking agent, was to provide a place where customers could upload and interact with their own documentation. The goal was to give users access to AI-powered knowledge assistance while keeping their information within a controlled environment.

He described it as giving customers “a place within the defined and secure Abrigo-hosted environment, where all their other applications and data have been hosted, to upload safely and to be able to interact with those documents safely through this knowledge agent.”

Secure AI for financial institutions also requires boundaries between private data and public research. Customers may want internet-enabled capabilities for public information, while their internal documents and customer data remain protected.

“[Financial institutions’] data is still kept private, and it's not sent out to the internet in any of these searches,” Piangerelli said. He added that Abrigo prevents the agent from accessing internally uploaded data when the user is interacting with the internet.

For banks and credit unions, those controls make AI more usable. Teams get flexibility without sending sensitive information outside the appropriate environment.

Explainable AI gives users visibility into outputs

Responsible AI in banking also requires explainable AI. Financial institutions need to know where answers, alerts, summaries, and narratives come from. Piangerelli says Abrigo tools are built with “the ability for the systems to be able to explain and audit what they're doing and decisions they're making.”

The form of explainability depends on the use case.

For Abrigo’s anti-fraud models in Abrigo Fraud Detection, the models are designed to produce an explanation of how they arrive at an answer, including which values were weighted more heavily. In AI-generated narratives or assistant-style tools, explainability may come through documentation and source visibility. When AskAbrigo answers questions using documentation or data, Abrigo provides references that show where the answer came from. Visibility into model behavior helps users understand why a model is surfacing a result. It also supports stronger review, escalation, and documentation.

Anyone who has used AI tools for research or drafting knows how useful source visibility can be. A polished answer can still be wrong, incomplete, or unsupported. In banking, users need a way to verify the answer and decide whether it is usable.

Transparent AI keeps users in the workflow

Transparency also means making clear what role the AI plays. Abrigo’s approach keeps people involved in review and decision-making. Piangerelli described the narrative use case, which Abrigo incorporates as a draft-and-edit workflow in solutions for financial-crime fighting, credit-memo generation, loan review, and allowance for credit losses reporting. The AI can generate text. The user, he said, “can agree or disagree or edit it or delete it or do whatever they want.”

Human review is essential for regulated workflows. AI can help users move faster, but the user still brings judgment, institutional knowledge, borrower context, and accountability.

I thought about this in the context of my own work with transcripts. I may use AI to help summarize a long discussion or draft content from a webinar, but I still need to review the result closely. I need to know where the content came from, whether the quotes are exact, and whether the draft reflects the speaker’s meaning.

The same principle applies inside banking workflows. A model or assistant may surface information, create a first draft, or help a user explore data. The person using the tool still needs confidence in the source and control over the final output.

Transparent AI helps create confidence by showing the user what the system used, how the output was created, and where human review belongs.

Abrigo’s AI development approach focuses on empowerment

One of the parts of our conversation on Abrigo’s approach that stood out was Piangerelli’s explanation of how Abrigo thinks about AI and team development. He described Abrigo’s approach as the “Iron Man approach.”

“Instead of building a robot that goes and does your job, what if we built an Iron Man suit?” he said. “You're still in control, but now you are empowered to do some big-time stuff that you couldn't do in the past.”

That is a useful way to think about responsible AI in banking. The strongest applications of AI help skilled people at banks and credit unions do more with the knowledge, judgment, and experience they already have.

For developers, AI may help generate tests, review code, create documentation, or support product workflows. For product managers, it may help create prototypes or documentation that communicate an idea earlier in the process. For bankers, it may help users find information faster, draft narratives, review data, or reduce repetitive work that slows down customer-facing activity.

The common thread is control. The user remains responsible for reviewing the work and deciding how to apply it.

Responsible AI should build on a trusted foundation

We also discussed an important point about pace. AI is developing quickly, and the pressure to react can be intense. Abrigo’s approach for its financial institution customers is to build from a strong foundation and keep customer trust at the center of the work.

“We've built a business on top of a really secure, very resilient underlying data system, structure that passes all of the regulations, passes all of the audits,” Piangerelli said. “On top of that, we've built software that our customers are pleased with. It is growing, it is getting better, it's getting stronger.”

Abrigo uses that foundation to evaluate AI opportunities. The goal is to bring useful AI into financial institution workflows at a pace customers can depend on, allowing banks and credit unions to adopt AI as they’re comfortable doing so.

In other words, Abrigo is focusing on “the latest and greatest” while incorporating it “at a pace that our customers can really depend on, and trust, and still be out in front,” he said.

Responsible AI in banking requires innovation and continuity. Financial institutions need tools that help them adapt, along with confidence that the systems supporting their work remain secure, explainable, and auditable. The track record Abrigo already has of doing each of these with some 2,400 financial institutions should support confidence in the vendor partnership as banks and credit unions move more into using AI.

What responsible AI looks like at Abrigo

For Abrigo, responsible AI in a regulated environment comes down to several practical commitments. It means:

  • Building AI inside secure environments designed for banks and credit unions.
  • Protecting institutional and customer data.
  • Creating clear boundaries between private documentation and public research.
  • Giving users source references and explanations.
  • Keeping people in control of review, edits, and final decisions.
  • Designing tools that help teams work faster without hiding how outputs are created.

Those principles are critical as AI becomes more embedded in banking workflows. The technology will keep changing, so financial institutions using AI successfully will need systems they can trust, vendors that understand regulation, and tools that support human judgment.

Responsible AI in banking requires discipline. At Abrigo, it also starts with a simple expectation: no black boxes allowed.

Need help adopting AI with confidence and control? Our advisors can help with policy development and governance structure.

Abrigo Advisory Services

Is your financial institution ready to deter AI-enabled elder fraud?

For years, financial institutions have worked to protect older adults from elder financial abuse ranging from government impersonation schemes to romance fraud and fraudulent investment opportunities. While these scams are not new, the tools criminals use today are dramatically different.

Artificial intelligence (AI) has transformed the fraud landscape, enabling bad actors to create convincing voices, realistic videos, sophisticated messages, and entirely fabricated identities at a scale we have never seen before. For financial institutions, this means traditional fraud indicators are becoming harder to spot, and the consequences for customers can be devastating.

The question is no longer whether AI will impact fraud. The question is whether financial institutions are prepared for the new generation of AI-enabled scams.

Learn how Abrigo Fraud Detection prevents elder fraud

Connect with an expert

 

How AI is affecting elder fraud

Older adults remain one of the most targeted populations for fraud. According to the FBI, adults over 60 lost more than $7.7 billion in 2025, up 59% from the previous year. Seniors often have significant accumulated assets, may live alone, and frequently place trust in authority figures and personal relationships. According to industry estimates, only a fraction of elder financial abuse incidents are ever reported due to a variety of reasons, such as shame, embarrassment, and sometimes the victim's diminished mental capacity.

Artificial intelligence has amplified the effectiveness of these scams in several ways:

  • Personalized fraud campaigns can be created almost instantly
  • Scam communications contain fewer grammatical mistakes and obvious warning signs
  • Criminals can rapidly adapt their tactics based on victim responses
  • Emotional manipulation becomes more convincing and more scalable

In other words, AI allows fraudsters to automate trust-building.

 

Leveraging AI voice technology for fraud

One of the most concerning developments is voice cloning technology. With only a few seconds of audio obtained from social media videos, voicemail recordings, or other public sources, criminals can create convincing replicas of a person’s voice. A grandparent may receive a frantic call that appears to come from a grandchild claiming to be in trouble. The voice sounds authentic. The story sounds urgent. The request for money feels legitimate.

The victim often acts before verifying the situation. For front-line bank staff, this creates a challenge. Customers may arrive convinced they are helping a loved one or responding to an emergency. What appears to be an ordinary wire transfer may actually be the result of sophisticated AI-enabled social engineering.

 

Deepfakes create new risks

AI-generated images and videos are also creating significant challenges for financial institutions. Fraudsters increasingly combine stolen personally identifiable information with AI-generated images to create synthetic identities. These identities can be used to facilitate:

  • Fraudulent account openings
  • Check fraud
  • Credit card fraud
  • Loan fraud
  • Employment fraud
  • Online scams

The challenge is that many traditional identity verification processes were not designed to detect AI-generated personas.

Financial institutions should be aware of warning signs such as inconsistent identity documents, suspicious technical issues during remote verification sessions, refusal to complete multifactor authentication, and photos that appear altered or inconsistent with other identifying information.

The emergence of deepfake technology has become such a concern that FinCEN issued an alert highlighting its use in financial crimes and encouraging institutions to identify and report related activity appropriately.

 

How is AI being used in Romance scams?

Perhaps nowhere is AI’s impact more evident than in romance and investment scams. Historically, fraud investigators could often identify fraudulent profiles through poorly written messages, inconsistent stories, or obvious fake photographs. AI has changed that equation.

Today’s criminals can generate realistic photos, create believable online personas, and maintain sophisticated conversations over extended periods. These tools allow fraudsters to build trust faster and with greater credibility.

Pig butchering” schemes, a type of sophisticated investment fraud, have become one of the fastest-growing fraud threats affecting older adults. This troubling analogy refers to a manipulation technique that exploits a victim's vulnerabilities through frequent interactions, text messaging, and social engineering. Today, these usually involve investment schemes and cryptocurrency fraud.

Victims may spend months communicating with someone they believe is a romantic partner or a trusted friend before the conversation shifts toward an investment opportunity. The fraudster then introduces cryptocurrency investments, exclusive trading platforms, or supposedly guaranteed returns. Fake account dashboards display fabricated profits, reinforcing the victim’s confidence.

By the time fraud is discovered, retirement accounts may have been liquidated, and life savings lost. Many seniors have outlived their earning capacity and are no longer able to make up a significant financial loss, which often leads to depression and even premature death.

The human element remains the strongest defense

Despite increasingly sophisticated technology, AI-enabled fraud still relies on human emotions.

Fear. Trust. Loneliness. Urgency.

Financial institutions remain uniquely positioned to identify these situations before losses occur because they can observe both transactional activity and customer behavior.

Some common warning signs include:

  • Sudden large wire transfers to unfamiliar recipients
  • New cryptocurrency activity that is inconsistent with the customer's history
  • Liquidation of retirement assets for unexplained investments
  • Customers who appear coached, fearful, or unusually secretive
  • Requests that follow urgent phone, video, or online communications

In many cases, the transaction itself is only part of the story. The customer’s behavior often provides the strongest indication that fraud may be occurring.

 

Why early intervention matters

One of the most difficult realities of elder fraud is that victims often believe they are making informed decisions. The customer who is sending funds to a fraudulent investment platform may be convinced they are building wealth. The customer responding to a cloned voice emergency may be certain they are helping a family member. That is why early intervention is critical.

A delayed transaction, additional questioning, or escalation to a fraud specialist can prevent life-altering losses. Financial institutions should empower front-line employees to slow down suspicious transactions, document behavioral observations, and escalate concerns, even when the customer appears confident. Training, collaboration between fraud and AML teams, and strong internal procedures remain essential components of an effective response strategy.

Detection technology must evolve just as quickly as fraud. Criminals are using AI to make scams more believable and harder to detect, so financial institutions should use AI to strengthen their defenses as well. AI-powered fraud monitoring can identify unusual transaction patterns, behavioral changes, and emerging fraud trends that may not be recognized through traditional rules alone.

Combined with experienced investigators and well-trained frontline employees, these solutions help institutions focus on the highest risk activity, intervene sooner, and protect customers before a suspicious transaction becomes a devastating loss. AI is not replacing human judgment. It is giving financial institutions another tool to stay one step ahead of increasingly sophisticated fraudsters.

The future of fraud is AI-enabled

Artificial intelligence is not creating entirely new fraud schemes. Instead, it is making existing elder financial abuse scams more believable, scalable, and harder to detect.

For financial institutions, success will depend on recognizing that fraud prevention is no longer solely about monitoring transactions. It also requires understanding customer behavior, identifying emerging AI-driven tactics, and intervening before a transaction becomes a loss.

As fraudsters continue to adopt new technologies, financial institutions must evolve just as quickly. When AI is used to manufacture trust, vigilance becomes more important than ever.

 

Learn more about current fraud trends with our 2026 Abrigo Fraud Survey results.

Read now

FAQs

What is elder fraud?

Elder fraud is an act targeting older adults that attempts to deceive with promises of goods, services, or financial benefits that do not exist, were never intended to be provided, or were misrepresented. 

How is AI affecting elder fraud?

Artificial intelligence has amplified the effectiveness of these scams in several ways:

  • Personalized fraud campaigns can be created almost instantly
  • Scam communications contain fewer grammatical mistakes and obvious warning signs
  • Criminals can rapidly adapt their tactics based on victim responses
  • Emotional manipulation becomes more convincing and more scalable
How is AI being used in Romance scams?

Today’s criminals can generate realistic photos, create believable online personas, and maintain sophisticated conversations over extended periods. These tools allow fraudsters to build trust faster and with greater credibility.

Why does early intervention matter?

The customer who is sending funds to a fraudulent investment platform may be convinced they are building wealth. The customer responding to a cloned voice emergency may be certain they are helping a family member. That is why early intervention is critical.