Human approval before customer or regulatory impact

Human approval before customer or regulatory impact. A practical lesson in the complete pipeline for banking and payments practitioners.

Plain language meaning

Human approval before customer or regulatory impact is the accountability checkpoint where Malla Bank confirms that AI-supported recommendations are reviewed by authorised staff before denial, limit change, pricing action, regulatory report, suspicious activity disposition or other material outcome takes effect.

This topic is about banking authority, accountability and control before material impact. It is not about adding a cosmetic approval button after the system has already made the real decision.

In a real bank, this is not a loose technology idea. It is a controlled operating step where customer facts, banking policy, model behaviour, human authority, legal obligations and retained evidence must line up. AI and ML can improve speed, consistency and detection quality, but the bank must still prove why the process was fair, explainable, secure, monitored and fit for purpose.

Where it sits in the banking AI journey

This card belongs to The Complete Pipeline. The working flow is AI recommendation, Policy and impact check, Authorised human review, Approval or override, and Evidence retained.

Read the flow as a banking control journey. Each stage needs a source system, a decision purpose, a failure mode, a control owner, a fallback path, a customer-impact view and retained evidence. Without those elements, the bank may have automation, but it does not yet have a bank-grade AI process.

Banking data and evidence

The important data points are recommendation score, decision reason, customer impact type, regulatory impact type, approval authority, override reason, review timestamp, and final outcome. These items matter because they influence lending eligibility, affordability, fraud risk, compliance treatment, operational queueing, regulatory reporting, customer explanation and audit traceability.

The evidence pack should include approval record, review note, reason-code evidence, override approval, policy checklist, customer communication record, and regulatory filing support. A strong bank can replay the case from source data to feature values, model output, control result, human review, final outcome and monitoring result. A weak bank only knows that a system produced an answer.

Controls that make AI adoption safe

The core controls are approval matrix, segregation of duties, four-eyes review, reason-code check, override limits, regulatory escalation, and retained approval evidence. These controls make the topic bank-grade because they tie technical output to approved policy, legal obligations, model governance, operational resilience and management accountability.

AI can help compare records, detect anomalies, retrieve policy, summarise case evidence, prioritise work, highlight weak signals and improve investigator consistency. It should not invent missing facts, ignore failed checks, bypass authority, hide uncertainty, decide material customer outcomes without approval or create explanations that cannot be tied back to approved sources.

Regulatory and governance lens

For banking use cases, model risk, fair lending, adverse-action explanation, credit-risk governance, data lineage, operational resilience, AML/CFT risk-based controls, sanctions compliance, fraud information sharing and auditability can meet in the same workflow. The practical design must therefore be narrower and more disciplined than a generic AI design.

The practical test is simple: if a reviewer asks why the bank used the data, why the model output was trusted, why the customer received that action, why an alert was cleared, why an exception was approved, or why a regulatory record was prepared, the evidence must already exist.

Diagram walkthrough

Read the diagram from left to right as AI recommendation, Policy and impact check, Authorised human review, Approval or override, and Evidence retained. The diagram is a control map, not decoration. It shows the minimum route by which data, AI or ML output, human action and audit evidence should connect.

Use it as a 30-minute study method. For each box, ask what system produces the data, what can go wrong, what control detects the weakness, who reviews the case, what customer or regulatory impact could arise and what record proves closure.

Most important mistake to avoid

The common failure is confusing human presence with human accountability. A reviewer who cannot see the evidence, change the outcome, escalate concerns or record reasons is not a meaningful control.

The correction is to slow down the thinking, not necessarily the process. A well-designed banking AI process can be fast, but every fast step must still leave behind source lineage, control evidence, decision reason, human accountability, monitoring data and issue ownership.

Source anchors for accurate study

Federal Reserve SR 26-2, dated 17 April 2026, supersedes SR 11-7 and SR 21-8 for traditional model risk management and clarifies that generative and agentic AI need governance through broader risk-management controls.

NIST AI RMF 1.0 uses Govern, Map, Measure and Manage functions for AI risk management, and NIST AI 600-1 adds generative-AI risk actions for content provenance, hallucination, data protection, cybersecurity and human oversight.

U.S. Regulation B, 12 CFR 1002.9, requires specific principal reasons for adverse action in covered credit decisions, including when a creditor uses an AI model. CFPB Circular 2022-03 was withdrawn on 12 May 2025; do not cite it as current guidance. Primary sources: https://www.consumerfinance.gov/rules-policy/regulations/1002/9 and https://www.consumerfinance.gov/compliance/guidance/withdrawn-guidance/.

The EU AI Act treats AI systems used to evaluate creditworthiness or establish credit scores for natural persons as high-risk, except certain fraud detection and prudential capital contexts.

The Basel Framework IRB standards require banks to estimate and validate PD, LGD and EAD using relevant data, meaningful risk differentiation and ongoing governance.

FFIEC BSA/AML examination guidance expects suspicious activity monitoring systems to be risk-based, explainable by management, periodically reviewed and independently validated where appropriate.

Federal Reserve SR 26-3 and FinCEN's 12 June 2026 Section 314(b) materials clarify fraud-related information sharing under the USA PATRIOT Act safe-harbor framework for participating financial institutions.

OFAC's Framework for Compliance Commitments describes sanctions compliance programme components including management commitment, risk assessment, internal controls, testing and auditing, and training.

Make the approval boundary visible

An AI recommendation may summarize policy, flag an affordability concern or rank an exception. The authorized decision maker must see the underlying evidence, model limitations and applicable rule before approving an action that affects a customer. A human click is not meaningful oversight if the interface hides the source data or makes disagreement impractical. The approval record should identify the person, authority, evidence version, model output, reason, time and final action. It should distinguish an approval of a model suggestion from a decision made on independent evidence.

For a fictional referred loan, present the score and principal contributing factors alongside affordability findings and missing documents. The reviewer might request evidence, decline under policy, or override within defined authority. Each path needs a specific reason and customer communication. For covered U.S. credit decisions, adverse-action reasons must meet Regulation B, 12 CFR 1002.9; other jurisdictions require their own legal assessment. Test a second approval where required, an expired authority, an unavailable model service and a later appeal. The bank should be able to replay what the reviewer saw at the moment of action, not a revised dashboard assembled afterwards.

Banking practice note: customer purpose

For human approval before customer or regulatory impact, customer purpose is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from recommendation score to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

AI can assist by comparing records, detecting unusual patterns, retrieving approved policy, summarising weak evidence, prioritising exceptions and preparing review notes. The bank should not allow a generated explanation, a confident score or a convenient dashboard to replace validation, consent, human judgement, customer communication, regulatory judgment or issue closure.

A strong implementation records the source event, data timestamp, consent or lawful basis, model or prompt version, feature values, score or generated output, threshold, reason code, user action, exception status, monitoring result, owner review and final outcome. That record lets risk, compliance, audit, technology and operations speak from the same facts.

Banking practice note: consent and lawful use

For human approval before customer or regulatory impact, consent and lawful use is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from decision reason to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: source lineage

For human approval before customer or regulatory impact, source lineage is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from customer impact type to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: KYC and identity

For human approval before customer or regulatory impact, KYC and identity is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from regulatory impact type to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: account behaviour

For human approval before customer or regulatory impact, account behaviour is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from approval authority to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: feature freshness

For human approval before customer or regulatory impact, feature freshness is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from override reason to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: point-in-time correctness

For human approval before customer or regulatory impact, point-in-time correctness is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from review timestamp to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model version

For human approval before customer or regulatory impact, model version is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from final outcome to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: decision threshold

For human approval before customer or regulatory impact, decision threshold is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from recommendation score to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reason code

For human approval before customer or regulatory impact, reason code is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from decision reason to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: human review

For human approval before customer or regulatory impact, human review is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from customer impact type to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fraud control

For human approval before customer or regulatory impact, fraud control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from regulatory impact type to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: sanctions control

For human approval before customer or regulatory impact, sanctions control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from approval authority to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: AML control

For human approval before customer or regulatory impact, AML control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from override reason to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fair lending

For human approval before customer or regulatory impact, fair lending is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from review timestamp to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: regulatory reporting

For human approval before customer or regulatory impact, regulatory reporting is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from final outcome to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: operational exception

For human approval before customer or regulatory impact, operational exception is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from recommendation score to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: customer harm

For human approval before customer or regulatory impact, customer harm is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from decision reason to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: audit trail

For human approval before customer or regulatory impact, audit trail is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from customer impact type to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: data quality

For human approval before customer or regulatory impact, data quality is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from regulatory impact type to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: privacy minimisation

For human approval before customer or regulatory impact, privacy minimisation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from approval authority to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: committee reporting

For human approval before customer or regulatory impact, committee reporting is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from override reason to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reconciliation

For human approval before customer or regulatory impact, reconciliation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from review timestamp to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: exception ownership

For human approval before customer or regulatory impact, exception ownership is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from final outcome to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: monitoring cadence

For human approval before customer or regulatory impact, monitoring cadence is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from recommendation score to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: closure evidence

For human approval before customer or regulatory impact, closure evidence is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from decision reason to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: policy retrieval

For human approval before customer or regulatory impact, policy retrieval is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from customer impact type to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: investigator feedback

For human approval before customer or regulatory impact, investigator feedback is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from regulatory impact type to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model drift

For human approval before customer or regulatory impact, model drift is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from approval authority to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: control attestation

For human approval before customer or regulatory impact, control attestation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from override reason to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: customer purpose

Trace one item from review timestamp to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: consent and lawful use

Trace one item from final outcome to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: source lineage

Trace one item from recommendation score to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: KYC and identity

Trace one item from decision reason to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: account behaviour

Trace one item from customer impact type to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: feature freshness

Trace one item from regulatory impact type to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: point-in-time correctness

Trace one item from approval authority to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model version

Trace one item from override reason to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: decision threshold

Trace one item from review timestamp to override approval. Then ask which control from reason-code check proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reason code

Trace one item from final outcome to policy checklist. Then ask which control from override limits proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: human review

Trace one item from recommendation score to customer communication record. Then ask which control from regulatory escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fraud control

Trace one item from decision reason to regulatory filing support. Then ask which control from retained approval evidence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: sanctions control

Trace one item from customer impact type to approval record. Then ask which control from approval matrix proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: AML control

Trace one item from regulatory impact type to review note. Then ask which control from segregation of duties proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fair lending

Trace one item from approval authority to reason-code evidence. Then ask which control from four-eyes review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Make review possible

Before an AI-supported credit decline or material compliance response, the authorized reviewer needs the source evidence, model output, policy requirements, uncertainty and available choices. A generic approval button without time or evidence does not supply meaningful oversight. Record reviewer ID, decision time, reason, override and final customer or reporting action. Separate the model's suggestion from the institution's decision.

Test a score produced with missing income evidence and an assistant draft containing an unsupported regulatory assertion. The credit case should refer for verification; the draft should be rejected or corrected against approved sources. Monitor override quality and review capacity, not just the percentage clicked through. If the service is unavailable, established approval and deadline processes continue.

Related learning paths

This application uses JavaScript for the full interactive experience. This text summary is served for accessibility and search indexing.

Human approval before customer or regulatory impact · Malla Banking Academy