How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment

    Implementation Guide

    How to Run an AI Fair Lending Tabletop Exercise for Lenders

    A structured, cross-functional simulation that tests whether a lender’s governance, model risk management, and compliance functions can detect, escalate, and remediate disparate impact or discriminatory outcomes from an AI-driven credit decisioning model.

    An AI fair lending tabletop exercise is built around defined scenarios, pre-assigned participant roles, and governance artifacts such as validation reports and monitoring logs. It concludes with tracked remediation actions mapped to control owners.

    Why AI credit models require a purpose-built tabletop

    Most lenders already run fair lending tabletop exercises tied to traditional underwriting processes. AI-driven credit decisioning introduces risks that a generic exercise will not surface. Machine learning models can incorporate proxy variables correlated with prohibited bases even when protected characteristics are excluded from model inputs. Model behavior can also drift over time, changing a model’s disparate impact profile without any code change, which means a one-time validation is not sufficient.

    A tabletop exercise scoped specifically to AI decisioning tests whether the institution’s governance structure can detect these AI-native failure modes, not just traditional underwriting errors.

    Exercise phases at a glance

    1. Scenario design

      Build scenarios around model lifecycle stages and known AI-native risks such as proxy variables and drift.

    2. Role assignment

      Pre-assign model risk, compliance, legal, data science, and business owners to reflect real accountability.

    3. Detection and escalation

      Test whether monitoring alerts trigger the correct compliance and legal escalation path.

    4. Remediation tracking

      Convert findings into owned, dated corrective actions and verification steps.

    Regulatory foundations that should shape scenario design

    ECOA prohibits discrimination against applicants on prohibited bases in any aspect of a credit transaction, and fair lending analysis under ECOA and Regulation B recognizes both disparate treatment and disparate impact theories. Regulation B implements ECOA and requires creditors to provide specific reasons when adverse action is taken, and to retain application records and related documentation for a defined retention period.

    The CFPB has stated that use of complex or black-box credit models does not exempt creditors from these adverse action explanation requirements. Interagency model risk management guidance separately establishes expectations for model validation, ongoing monitoring, and governance of decisioning models, and identifies model risk as arising from both fundamental model errors and incorrect use of model outputs. Tabletop scenarios should be built to test compliance against each of these expectations directly, rather than in the abstract.

    Participant roles that should be pre-assigned

    Roles should mirror real accountability so the exercise surfaces ownership gaps rather than inventing temporary ones.

    • Model risk management: owns validation documentation and lifecycle sign-off
    • Compliance: owns fair lending analysis and adverse action review
    • Legal: owns escalation decisions and regulatory exposure assessment
    • Data science: owns model behavior explanation and technical remediation options
    • Business line owner: owns operational use of the model and monitoring follow-through
    • Exercise facilitator: owns scenario pacing and documentation of gaps identified

    Structuring the exercise around the model lifecycle

    Scenarios should follow the path a credit model actually takes through the institution: development and validation, production deployment, ongoing monitoring, escalation when alerts fire, and remediation when controls fail. Framing the exercise this way keeps discussion tied to concrete handoffs, artifacts, and decision rights rather than abstract policy statements.

    Governance artifacts to build into the exercise

    Use operational materials participants would touch in a real event. Summaries hide friction that only appears under time pressure.

    • Use real or realistic model development and validation documentation as exercise exhibits rather than summaries
    • Include actual monitoring alert formats so participants practice with the tools they will use in a real event
    • Require participants to locate audit trail entries under time pressure to test whether decision reconstruction is actually feasible
    • Test record retention practices against Regulation B requirements by asking participants to retrieve a specific application file
    • Evaluate whether explainability outputs used for adverse action statements are interpretable by non-technical compliance staff

    Facilitator note

    If participants cannot produce an adverse action reason, locate a monitoring log entry, or identify the control owner within the exercise window, treat that as a finding. Do not resolve the gap in the room and move on.

    Turning findings into remediation

    A tabletop exercise has limited value if findings are not converted into tracked action. Each identified gap, whether it is a missing escalation trigger, an incomplete validation test, or an adverse action statement that could not be produced within a reasonable timeframe, should be mapped to a specific control owner with a documented remediation deadline.

    Follow-up verification should confirm the gap was closed, not just that a plan was written. Institutions that run this exercise on a recurring basis, rather than as a one-time event, are better positioned to account for model drift and evolving regulatory expectations over time. Runtime monitoring and audit logging infrastructure that captures model decisions and escalation events as they occur can support this recurring testing by giving exercise facilitators real artifacts to work from, rather than reconstructed summaries.

    Strengthen the governance layer behind your tabletop exercises

    A tabletop exercise is only as effective as the monitoring and audit infrastructure it tests. Trussed AI provides runtime governance and audit logging for AI systems, giving compliance and model risk teams real artifacts to exercise against.

    Explore Runtime Governance