Service
Decisioning and override review
Automated scores and policy rules only matter if the origination application keeps a usable trail when a person changes the outcome. This review samples approved, declined, and referred files, then tests whether overrides were authorised, reasoned, and visible to the next reviewer.
Sample design
We draw from a period you nominate — often the last two quarter-ends — and overweight files with manual grade changes, policy exceptions, and second-level approvals. Declined files are included. A book that only samples approvals will miss the same control twice.
Evidence we expect to see
The name of the override, the rule that was broken or stretched, the reason recorded at the time, the authoriser, and whether the application locked further edits. Where reasons are free-text only, we still read them; vague phrases such as “exception approved” are reported as a finding, not accepted as a control.
Use of the report
Credit risk and internal audit typically use the workbook to reset override matrices and training. We do not re-underwrite the customer. We test whether the origination application forced the bank to leave a financial-control record of the decision it actually took.