OptimalAgents.aiOptimal Agents
OAassure — Credit File Assurance & Policy Effectiveness

Every lender enforces a credit policy. Almost none can tell you which parts of it are working.

OAassure reads every loan file you write, checks it against your own policy, and then does the thing no system does today: links each policy breach to what the loan actually went on to do. You find out which controls are protecting the book, and which are only adding days to your turnaround.

Start with 100 filesSee the two products
100% file coverageRuns in your own cloudNo LOS integration to startEvidence on every finding
Why this matters at board level

Three questions your credit function almost certainly cannot answer today

Not because the team is weak. Because the data to answer them has never been assembled — file-level policy compliance has never been joined to loan performance.

01

What share of the loans we wrote last year actually complied with our own credit policy?

Internal audit samples. Sampling gives you a range with wide error bars, not a number you would put in front of a board or a regulator. Most lenders quote a deviation rate drawn from under 5% of files.

02

Of the breaches we did find, which ones actually cost us money?

Exception registers count breaches. They do not weight them. An unsigned form and an undeclared debt obligation both land in the same report as one exception each — and only one of them precedes a write-off.

03

What is each control costing us in turnaround, for the risk it actually removes?

Every check is a document chased, a callback, a file parked. Some of that cost buys real loss protection. Some buys nothing. Without the loss link, there is no basis on which to relax a single control — so nobody ever does.

100%Of files reviewed, against 5–10% under manual audit
3.3×Default rate on the highest-ranked policy breach vs clean files
~30%Of checks typically show no measurable link to loss
6 weeksFrom first file to a board-ready diagnostic

Illustrative figures from modelled engagements, not results attributed to a named customer.

Two products, one policy rubric

One stops the bad file going out. One tells you what the bad files already cost.

Both run on the same engine and the same machine-readable version of your credit policy. You can buy either first. Most lenders start with the second, because it pays for the first.

OAassure Review

Product 1Before disbursal

An independent policy check on every file, before the money leaves. The AI reads the application and all supporting documents, recalculates the ratios from source rather than trusting what was typed into the form, and hands your credit team a short, evidenced list of what is wrong.

What goes wrong today
  • Policy is applied unevenly — the same file gets a different answer from a different reviewer
  • Ratios are checked against declared figures, not against the bank statement behind them
  • Deviations get verbal approval and a note, with no trace of who authorised what
  • Credit committee reviews summaries, not files, and cannot see what was waived
  • The maker–checker control only works if the checker has time to open the documents
What OAassure Review does
  • Runs every rule in your rubric against every file, in minutes
  • Recomputes debt-to-income and income from the source documents
  • Blocks disbursal on a critical breach until a named authority signs off
  • Routes each exception to the correct approver under your delegation matrix
  • Records the full trail: what fired, who saw it, who waived it, and why
Chief Risk OfficerPolicy enforcement stops depending on staffing levels. Coverage is total and consistent, and the exception register becomes complete rather than indicative.
Head of CreditReviewers stop spending their day verifying arithmetic and spend it on judgement calls. Throughput rises without adding headcount.
Chief Operating OfficerTurnaround improves because rework falls — files come back complete the first time instead of bouncing between sales and credit.
Internal AuditThe evidence trail is generated as a by-product of the process, rather than reconstructed months later during an inspection.
Document extraction file 2291 · 14 docs
Documents in
📄 Bank statement · 6 mo
📄 Payslips ×3
📄 Tax return
📄 ID document
📄 Application form
→
Data out
net_income4,820 /mo
declared_debt610 /mo
found_in_stmt1,155 /mo
dti_declared61%
dti_recomputed94%
income_sources1
Review output file 2291 · 68/100
CRITICALDebt-to-income above policy limitDTI-021File records 61% against a 55% cap and was passed. Recomputed with the payment found in the statement: 94%.
CRITICALExisting obligation missing from the fileDEBT-014545 debited on the 5th of each month for six months. Never declared, never questioned.
MAJORIncome confirmed from one source onlyINC-007Payslips on file. No corroborating salary credits attached.
MINORPhotograph not attested on the formDOC-033
PASSIdentity documents consistentID-003

OAassure Audit

Product 2After disbursal

Point the same rubric at the loans you have already written. You get complete, file-level compliance across the book — and, once repayment data is joined, the answer to the question that changes credit policy: which breaches were followed by bad loans, and how much did they cost.

What goes wrong today
  • A bad cohort is identified two years after the money went out, when nothing can be recovered
  • Portfolio reviews explain performance by product and vintage, never by control failure
  • Concentrations of weak files under one manager or one channel stay invisible
  • Inspection preparation becomes a manual scramble through physical and scanned files
  • Policy is tightened after a loss event, uniformly, because nobody knows which clause failed
What OAassure Audit does
  • Scores every disbursed file against the policy version in force at the time
  • Breaks compliance down by branch, product, sourcing channel and approver
  • Quantifies the exposure sitting behind critical findings
  • Ranks every rule by the additional default it predicts
  • Produces a board pack and a regulator-ready pack from the same run
Chief Risk OfficerPolicy moves from a document to an instrument with measured effect. Tightening decisions are supported by loss data instead of by the most recent incident.
Chief Financial OfficerA defensible estimate of credit loss attributable to control failure, separated from loss attributable to the market or the segment.
Chief Executive / BoardA concentration view that names where weak files are being written, rather than a single portfolio-level deviation rate that invites an argument about methodology.
Internal AuditAny past audit can be re-run exactly as it stood, on the rubric version that applied then — which is what an inspection actually asks for.
Compliance by branch 412 files · Q1
North94%
Central91%
Harbour88%
West61%
Southgate58%
West and Southgate report to one regional manager2.1M exposed

The concentration table is the conversation. A portfolio-wide deviation rate of 33% produces a debate about whether your rules are too strict. Two branches under one manager at 58% and 61% produces a management decision by the end of the meeting.

That distinction matters more than it sounds. The first number gets your methodology audited. The second gets someone's span of control reviewed.

The shared layer

Underneath both

Neither product is a checklist app. Both depend on two pieces of infrastructure that are the actual engineering work: turning a written credit policy into executable rules, and reading the documents well enough to test them.

Rubric builder

Your credit policy, product programmes and delegation matrix become numbered checks — each with a source clause, a threshold, a severity and a weight. Your compliance lead edits them in a browser; no developer is involved after setup.

  • Testable clauses become rules; judgement clauses route to manual review rather than being guessed
  • Separate rubrics by product, region, scheme or co-lending partner
  • Version-locked and dated, so historical audits stay reproducible
Document AI

Scans, photographs and digital files are read and reduced to the values the rules need. This is where most breaches are actually found — in the gap between what a document says and what someone entered into the system.

  • Handles mixed languages, layouts and scan quality
  • Detects recurring obligations the applicant never disclosed
  • Every extracted value keeps a link back to its source page
📥
01 Ingest

Files arrive

Application, statements, payslips, tax returns, ID, valuations. Scans included.

🔎
02 Extract

AI reads them

Numbers, names, dates and obligations pulled from the documents themselves.

🔗
03 Reconcile

Sources compared

What the documents say against what the file claims. Mismatches surface here.

📋
04 Test

Rubric applied

Every rule passes or fails, each with the page reference that proves it.

🚩
05 Route

Exceptions queued

Ranked by severity and sent to the right approver. Critical breaches can block.

🔄
06 Correct

Disputes fed back

A disputed finding is treated as a rule defect and used to fix the rubric.

Credit policy effectiveness analysis

The output that changes how a lender thinks about its own rulebook

We run your rubric across a thousand or more seasoned loans, join the results to repayment data, and compare files that breached each rule against files that did not. Every rule comes back with a measured effect on default.

Policy breaches, matched to loan performanceIllustrative output · 1,180 files · 24 months on book
RuleControlFiles breachingDefault if breachedDefault if cleanAdjusted liftRecommendation
DTI-021Debt-to-income above sanctioned cap9.1%10.6%3.2%3.3×Hard block
DEBT-014Obligation in statement absent from file12.4%9.8%3.1%3.2×Hard block
APPR-002Approved below delegated authority4.8%11.2%3.5%3.2×Hard block
ID-003Address mismatch across ID and statement6.2%8.9%3.4%2.6×Escalate
INC-007Income verified from a single source18.9%7.4%3.3%2.2×Escalate
BUR-011Bureau report older than 30 days at sanction22.1%4.1%3.6%1.1×Relax — no signal
DOC-033Photograph not attested on the form31.5%3.8%3.7%1.0×Relax — no signal

Lift is adjusted for product, ticket band and bureau score, because weak applicants tend to breach several controls at once. Unadjusted single-rule comparisons systematically overstate effect. Confidence intervals are reported beside every figure in the delivered analysis.

The controls worth defending

Typically six to ten rules where a breach is followed by materially worse repayment. These become hard blocks, escalate up the authority matrix, and get monitored by branch and channel. This is where credit losses are being originated, and it is a short enough list to actually enforce.

We price every breach of these rules across your last year of lending, so the cost of the control gap is a number rather than an argument.

The controls that only cost turnaround

Checks that fail on a fifth or a third of files while default barely moves. Each is a document chased, a customer called back, a file parked for a day — buying no measurable loss protection. Relaxing them is free throughput.

This half is what makes the analysis commercially interesting rather than merely a compliance finding. Tightening policy is a cost. Tightening and loosening it in the same exercise is a margin conversation.

Why the sample has to be large, and why we say so up front

At a four percent default rate, a hundred files contains roughly four bad loans. Distributed across seven rules, that is one or two cases per rule. Any competent risk function will take that apart in the first meeting — and should.

A thousand seasoned files gives each control enough events behind it to carry weight. Files disbursed in the last year are excluded regardless of volume, because they have not yet had the opportunity to go bad. We would rather scope the engagement honestly than defend a number that cannot survive scrutiny.

What the diagnostic requires
  • 1,000+ files with at least 12 months on book
  • Repayment data — delinquency buckets, write-offs, restructures
  • Credit policy, product programmes and delegation matrix
  • Six weeks end to end
  • Deliverables — ranked control effectiveness, exposure quantification, concentration analysis, and a written policy recommendation
  • Packs — one for the board, one for inspection
How to start

Begin with 100 files. Two weeks, no charge, no integration.

The first step deliberately does not attempt the loss analysis. It answers a narrower and more important question first: does this read your files correctly?

📨
Week 1 · Day 1

You send

100 closed files from one product, plus your credit policy and delegation matrix. A document folder and a spreadsheet export — no system access required.

🛠️
Week 1

We map the policy

Your policy becomes 40–60 testable checks, confirmed with your credit lead in a single working session. Ambiguous clauses are marked for manual review rather than approximated.

⚙️
Week 2

We run and self-check

All 100 files go through the engine. We read every finding ourselves and correct any misfiring rule before anything reaches you.

📊
Week 2 · End

You verify

Breach rate, rule-by-rule distribution, and every finding with its source page — so your team can audit our output file by file.

What you learn

Whether the extraction is accurate on your document set. What proportion of your own files breach your own policy. Which controls fail most often. And our false-positive rate, which we report before you ask for it.

If it doesn't convince you

You walk away and keep the machine-readable rubric built from your policy. It is yours, and it has standalone value. No fee, no commitment, no data retained. Two weeks is a cheaper way to find out than six months.

If it does

The natural next step is the 1,000-file effectiveness diagnostic, which is where the commercial case sits. Deployment of OAassure Review into live underwriting usually follows the first diagnostic, not the pilot.

Where OAassure fits

Credit file audit, policy compliance and loss attribution

AI loan file audit software

Automated loan file audit replaces sample-based credit file review with complete coverage. Every application, supporting document and approval record is tested against a machine-readable version of the lender's credit policy, producing a file-level compliance score with the evidence attached to each finding.

Credit policy compliance automation

Policy clauses, product programmes and delegation matrices are converted into executable checks with thresholds, severities and weights. Compliance monitoring becomes continuous rather than periodic, and enforcement no longer depends on which reviewer opened the file.

Post-disbursement loan audit and portfolio review

Disbursed loan files are re-audited against the policy version in force at sanction, producing compliance rates by branch, product, sourcing channel and approving authority — together with the exposure sitting behind each critical finding.

Loan document data extraction

Document AI reads bank statements, payslips, tax returns, identity documents and valuation reports across languages, layouts and scan quality, then recomputes income, obligations and debt-to-income from the source rather than from declared fields.

Deviation and exception management

Exceptions are ranked by severity and routed to the correct approving authority, with a complete record of what fired, who reviewed it, who waived it and on what basis — the evidence trail an inspection asks for and that most lenders reconstruct after the fact.

Credit loss attribution and NPA root-cause analysis

Rule-level default lift analysis links each policy breach to subsequent loan performance, separating credit loss attributable to control failure from loss attributable to segment or market, and identifying which controls can be relaxed without adding risk.

Built for banks, non-bank lenders, NBFCs, housing finance companies, microfinance institutions, digital lenders and co-lending partners across secured and unsecured products.

Common questions

What risk and credit teams ask first

How is this different from our loan origination system?

An LOS records that a decision was made and stores the fields someone entered. OAassure independently tests whether that decision followed your policy, by reading the underlying documents rather than trusting the data entry. It sits beside your LOS and changes nothing in your workflow until you decide a rule should block a disbursal.

Isn't this what our internal audit team already does?

Your audit team does it on a sample, after the fact, and cannot weight one finding against another. OAassure gives them full coverage and a loss-ranked view of which findings matter. In practice it makes internal audit more influential, not redundant — the constraint on that function has always been reading capacity.

What if our credit policy isn't well documented?

That is the normal starting point, and the mapping work is part of the engagement. We convert what exists into 40–60 testable checks and confirm them with your credit lead. Clauses that genuinely require human judgement are routed to manual review rather than approximated into a rule.

How many files do you need to link breaches to defaults?

At least 1,000 with twelve or more months on book. At a four percent default rate, 100 files holds about four bad loans, which cannot support rule-level conclusions. The 100-file step proves the engine reads your files; the 1,000-file diagnostic proves what the breaches cost.

Where does our borrower data go?

OAassure can be deployed inside your own cloud account or on your own infrastructure, so customer data never leaves your environment. Data residency and retention remain your decisions, and most of a vendor security review reduces to a licence agreement.

What happens when the AI is wrong?

Any reviewer can dispute any finding in one click. Disputes are treated as rule defects rather than user error and are used to correct the rubric. We calibrate before delivery and report our own false-positive rate unprompted.

How long before we see anything useful?

Two weeks to verified findings on 100 files. Six weeks to a board-ready effectiveness diagnostic. Live deployment into underwriting typically follows the diagnostic rather than preceding it, because the diagnostic is what determines which rules should block.

Available for demo

OAassure

The assurance layer between your credit policy and your loan book

Tell us how loan files are reviewed today and roughly how many you write a month. We will tell you whether a diagnostic is worth running on your book — including if the answer is that your volume is too small to produce a reliable result.

  • We say up front what we cannot check
  • We report our own error rate before you ask
  • Deploys inside your own cloud if required
  • No integration needed to begin

Contact us

A short conversation with someone who has scoped these engagements — not a sales qualification call.

No spam. Your info is shared only with the OptimalAgents team.

← Back to OptimalAgents.ai