AI & Business Series · Daily Briefing

How Indian Credit Committees Should Read a Vendor AI Score Without Outsourcing the Sanction

Dr. Debasis Pahi  |  Ph.D. (IIT Kharagpur)  |  DrDPKlass
09 October 2026  ·  drdpklass.com
Vendor AI scores · CreditIndia & Emerging EconomiesBanks · NBFCs · Committees

Indian credit committees are being shown a new number. A fintech vendor, a bureau add-on, or the bank’s own analytics partner arrives with an “AI score” between 300 and 900, a green band, and a slide that says the model beat the bureau on a hold-out sample. The sanction note then reads as if the committee decided. Often the committee only confirmed a colour. That is outsourcing of the credit decision with the paperwork of a meeting. This briefing is for credit committees, chief risk officers, NBFC credit heads and the faculty who teach them: how to read a vendor score so the sanction stays inside the institution.

The setting is Indian and emerging-economy practice. A public-sector bank branch still writes a proposal in a format designed for a cash-flow memo. A mid-size NBFC runs MSME working-capital files on GST pulls and bank-statement PDFs. A small finance bank prices micro-enterprise loans from a partner app. In each case the vendor score is attractive because the file is thin, the analyst is junior, and the turnaround target is hours, not weeks. Thin files are exactly where a score can help and exactly where a score can hide a bad decision. The committee’s job is to keep those two facts in the same minute.

Further reading on DrDPKlass: how CFOs should govern GenAI in finance operations, and how audit teams should test AI-assisted working papers. Today’s note is narrower. It is not about chatbots in the close. It is about a scored recommendation that can become a limit, a price, or a decline.

1. A vendor score is not a sanction

Start with a sentence the committee can repeat. The score is an input. The sanction is a decision of the institution, taken by a person or a body named in the credit policy, against a limit, a tenor, a security and a purpose. If the policy says “auto-sanction above 720,” the policy has made the vendor the sanctioning authority. That may be a deliberate product design for a small-ticket, fully standardised loan. It is not a committee decision, and it should not be described as one in the board pack.

Three documents usually get confused. The vendor’s model card describes how a number was produced. The credit policy says who may approve what. The sanction note records what was approved for this borrower. A clean process keeps them separate. A muddy process pastes the model card into the sanction note and treats the paste as judgment.

Working rule. If the committee cannot state, in one line, what it decided that the score did not decide, the meeting did not sanction. It ratified.

Indian digital-lending practice already pushes institutions to remain responsible for the loan they book, even when a partner originates or scores. Outsourcing directions and IT outsourcing rules point the same way: a service provider can process, it does not absorb the credit risk. Check the current Reserve Bank master directions before you cite a clause in a paper or a board note. The governance point does not depend on a clause number. The loss, if it comes, sits in your book.

Scholars coding “AI credit” should not treat the vendor score as the bank’s decision variable. The decision variable is the limit, the price, the decline, or the override. The score is a covariate, and often an endogenous one, because the institution chose the vendor and the cut-off. A paper that regresses default on the score and calls it model quality is a vendor brochure, not an identification.

2. Ask what the score is actually scoring

Committees are shown a brand name and a band. They are rarely shown the target. A score trained to rank 90-day delinquency on salaried bureau files will not mean the same thing on a Kirana GST pull. Ask four questions before the first live file.

  1. Outcome. What event was the model trained to rank — 30-day, 90-day, write-off, or “ever delinquent on this product”? A marketing model that predicts take-up is not a credit model.
  2. Population. Which borrowers, which years, which product, which geography? A model fit on metro salaried accounts is a different object from a model fit on eastern-India MSME cash-credit.
  3. Window. How far ahead does the label look, and was the window long enough to see a monsoon, a GST filing gap, or a festival-season drawdown?
  4. Cut-off owner. Who chose the green band — the vendor’s default, or your risk team on your loss data? A vendor default cut-off is a sales setting until you re-estimate it.

Refuse the phrase “the AI decided the borrower is good.” AI here is usually a gradient-boosted ranker or a neural net on tabular features, sometimes with a large language model reading bank-statement narration. The committee does not need the architecture. It needs the outcome, the population, and the error it is willing to buy. A model can be accurate in rank and still useless if the rank is on the wrong event.

Do not. Accept a single AUC on a vendor slide as evidence. AUC on the vendor’s sample does not tell you the approval rate, the bad rate in the band you will actually book, or the cost of a false decline on a priority-sector file you needed.

Ask for a confusion table at the cut-off you will use, not at the cut-off that maximises a textbook metric. For a working-capital product, false approvals and false declines have different rupee costs. A committee that cannot see both is choosing a sales target, not a risk appetite.

3. Separate the model from the data feed

Many “AI failures” in Indian credit are feed failures. The model is stable. The GST return did not pull. The bank-statement PDF was a scanned passbook. The bureau hit matched the proprietor to a dormant consumer card. The score still printed, because the vendor filled blanks with a neutral value and did not flag the fill.

FeedWhat a clean file showsWhat a hollow score hidesCommittee question
BureauHit type, vintage, inquiriesThin file scored as if it were thickWas this a hit, a no-hit, or a near-hit?
GSTMonths filed, turnover bridgeOne filed month copied across a yearHow many months were observed, not imputed?
Bank statementAccount vintage, bounce countNarration model on a photo of a passbookWas the source a statement or an image?
Alternate dataDevice, utility, platform salesA partner’s internal grade renamed as yoursDo we have a right to the raw feature?

Write a data-completeness flag next to the score on the sanction screen. Green score plus red feed is not a green file. Indian MSME files fail completeness more often than they fail mathematics. A proprietor with two GSTINs, a cash-heavy season, and a spouse’s account used for collections will look “unstable” to a model trained on salaried salary credits. The instability may be the business. The committee should see the flag before it sees the band.

Do. Require the vendor to return a reason-code list and a missingness list with every score. If the API returns only a number, you have bought a black box you cannot defend to a borrower, an auditor, or a supervisor.

Ownership of the feed matters for disputes. If the GST pull is wrong and the borrower corrects the filing, who rescores, in what time, and does the old score stay on the file? Put that path in the operating procedure. A score without a correction path becomes a permanent stain on a thin-file entrepreneur.

4. Build a challenge set the committee can see

Validation that lives only in the vendor’s notebook will not survive a credit-committee question. Build a small challenge set the institution owns. Thirty to fifty files are enough for a first committee pack if they are chosen to break the story, not to confirm it.

Known goods that look odd

Long-standing borrowers with seasonal cash, a GST filing lag, or a bureau inquiry spike from a genuine refinance. If the score declines them, the cut-off is fighting your own book.

Known bads that look clean

Accounts that slipped to SMA or NPA with tidy statements until the month before. If the score was green on the last three reviews, the early-warning claim is false.

Add three Indian-specific slices. First, a priority-sector or weaker-district file where a national model has little support. Second, a woman proprietor or a first-time borrower where bureau thickness is low and the cost of a false decline is a policy issue, not only a statistical one. Third, a related-party or circular-sales file a junior analyst might miss and a narration model might praise because credits look regular.

The committee should see a one-page table: file type, score band, what a human underwriter said, what happened twelve months later if the file is historical, and whether the institution would book it today. Do not anonymise so hard that the pattern disappears. Use Borrower A, sector, state, and ticket size. Names are unnecessary. Sector and state are not.

A challenge set the vendor chose is a demonstration. A challenge set credit chose from your arrears and your declines is a test.

Faculty teaching credit analysis can run the same exercise on a teaching case. Give students the score, withhold the feed flag, then reveal the missing GST months. The pedagogical point is identical to the committee point: a number without a feed is not evidence.

5. Minute an override, not a shrug

Overrides are how institutions stay in charge. They are also how institutions quietly disable a model. Both things can be true. The difference is the minute.

An acceptable override names the score, the recommended action, the action taken, the evidence that justified the gap, the person who signed, and the review date. “Committee comfortable” is not an override. It is a shrug with a signature.

Split overrides into two directions. Overriding a decline — booking a file the score rejected — needs a reason a supervisor can re-read: cash-flow evidence, security, a programme mandate, or a data error in the feed. Overriding an approval — declining or cutting a file the score liked — needs a reason too: concentration, related party, purpose not matching the product, or a site visit that contradicted the statement. Institutions that only track one direction are managing sales or managing risk, not both.

Minute line. “Score 688, vendor band Approve, committee cuts limit from ₹40 lakh to ₹25 lakh because GST months observed are four, not twelve, and the peak-month credit is a related-party transfer. Review at the next stock statement.”

Cap the override rate by product. A product that overrides 40 percent of scores does not have a model. It has a suggestion box. A product that overrides 0 percent has either a perfect model or a committee that has stopped reading. Neither is likely. Report the rate to the risk committee quarterly, with three examples, not a dashboard alone.

Auto-decisioning, where it exists, should sit below the committee threshold and inside a product policy the board has seen. Above that threshold, a human name goes on the sanction. Emerging-economy NBFCs sometimes let a partner app auto-book into the institution’s book and call the daily MIS a committee. If the committee meets after the loan is disbursed, it is an audit, not a sanction. Say so in the policy.

6. Contract, reason codes and adverse action

The vendor contract is part of credit governance. Four clauses decide whether the committee can do its job six months later.

Adverse action needs a human sentence. If a borrower is declined or priced up because of the score, someone at the institution must be able to say which reason codes fired and what the borrower could correct. Pointing at the vendor is not an explanation. Indian grievance practice, the digital-lending expectation that the regulated entity owns the customer interface, and ordinary fairness all point the same way. You booked the decision. You explain it.

Do not. Let the partner app send the decline text if you have not approved the text. A chatbot apology that invents a reason is worse than a short honest sentence. Hallucinated reasons are a conduct problem, not a wording problem.

Price the model-risk review in the contract. A score used for sanction is not a free pilot. Ask who inside your institution signs model acceptance — risk, not only vendor management — and what evidence they saw. If acceptance is an email from a relationship manager, you do not have acceptance.

7. Watch drift after go-live

Models drift when the book drifts. Indian portfolios drift for ordinary reasons: a new district, a push on unsecured MSME, a festival campaign, a change in GST filing behaviour, a bureau inquiry surge when every lender shops the same file. The score can stay “accurate” on old data and fail on the book you are booking now.

A quarterly pack the credit committee can actually read has five lines. Approval rate by band. Early delinquency by band, lagged so the label is real. Override rate, both directions. Share of files with a red feed flag. A short note on any vendor change since the last quarter. If early delinquency is flat across bands, the score is not ranking this book. If the green band is widening because the campaign changed, the cut-off is being gamed by volume.

Do not wait for a full-year loss given default to notice a problem. On short-tenor products, 30-day and 60-day outcomes are the committee’s early signal. On cash-credit, stock-statement delays and SMA migration are the signal. Match the monitor to the product. A single institution-wide AUC is a slide, not a control.

When drift appears, the response is a cut-off review or a pause, not a quieter dashboard. Name the person who can pause auto-decisioning. If that person is the vendor’s customer-success manager, the pause does not exist. Emerging-economy groups with several NBFCs under one brand should not assume a model accepted in one entity is accepted in another. Different books, different feeds, different committees.

Scholars and internal auditors can use the same five lines. An audit of an AI credit tool that only inspects the policy PDF will miss the live band. An audit that samples sanction notes for the minute line in section 5 will see whether the committee is still deciding.

8. Field checklist and closing brief

Use this list before the next committee that is shown a vendor score. It is short enough to sit on the agenda cover.

  1. State the outcome the score ranks, the population it was fit on, and who owns the cut-off.
  2. Put a feed-completeness flag beside the score. Green score plus red feed is not a green file.
  3. Table a challenge set you chose: known goods that look odd, known bads that looked clean, one thin-file slice.
  4. Write the sanction as a decision the score did not make: limit, tenor, price, decline, or conditions.
  5. Minute overrides in both directions, with evidence and a review date. Cap the rate.
  6. Confirm reason codes, change notice, and exit explainability in the contract.
  7. Own the borrower-facing sentence. Do not let an unapproved partner text invent a reason.
  8. Report five quarterly lines: approval by band, early delinquency by band, overrides, red-feed share, vendor changes.
  9. Name the person who can pause the score. If you cannot name them, you cannot govern it.
  10. Teach the distinction. In a classroom or a branch huddle, a score is an input. A sanction is a name.

The commercial pressure will not fade. Vendors will keep arriving with a better rank on last year’s sample, and turnaround targets will keep shrinking. Committees that treat the score as a colleague — useful, fallible, not in charge — will keep the book. Committees that treat the score as a verdict will discover, in the arrears pack, that they outsourced the only decision the institution is paid to make.

Dr. Debasis Pahi
Ph.D. (IIT Kharagpur) · DrDPKlass · drdpklass.com
AI & Business Series · 09 October 2026