Audit as a Query, Told From the Risk Team's Side
Prakash Rengarajan
20 Jul, 2026
4 min read
How long does it take your team to answer one regulator question about one loan? For most lenders the honest answer is measured in days.
Consider what actually happens when the request lands. The regulator, or the internal auditor rehearsing for one, asks something concrete: who approved the deviation on this file, what information was in front of them, and did anything change afterward. Simple question, one loan.
The risk team opens the LOS, which records the outcome and a timestamp. The reasoning is elsewhere. Part of it sits in an email thread between the credit manager and the approver. Part sits in a spreadsheet on someone's drive, where the financial analysis was actually done. Part happened on a phone call. Reconstructing one decision means interviewing systems and people, and the people who can do the reconstructing are the same senior officers whose time the institution can least spare. Multiply by a full audit cycle and the cost shows up as weeks of diverted capacity, every year.
The Questions Just Got Harder
That was the situation before AI entered the workflow. Now the questions an auditor must ask have expanded, and the old record-keeping was never designed for them.
Who took this action, a human or an agent? If an AI produced a recommendation, what exactly did it recommend? Did the human accept it, adjust it, or override it entirely? Was the final output consistent with what a reviewing peer, human or AI, concluded? These questions require comparing what was suggested with what was done, a work diff, and a log line saying "status updated" carries none of that.
An institution that adopts AI in credit operations without upgrading its evidence model is setting up its future self for an unanswerable audit.
When the Record Is the Work
The Lending Labs platform approaches this from the other end. Rather than logging around the work, the platform makes the record and the work the same event.
Every action on every file, taken by any actor, dispatches a structured event at the moment it occurs. The event carries who acted and in what role, whether the actor was a person or an AI agent, which task and which application, precisely what data changed, and, where an AI recommendation was involved, what was recommended alongside what was actually done. Human and AI actions flow through one event stream with identical structure, so there is no separate AI log to correlate after the fact.
For the risk team, the practical consequence is that evidence stops being assembled and starts being retrieved.
One loan's complete history, every action, every actor, every change: one query. All deviation approvals in the quarter, grouped by approver: a query. Every file where a human overrode the AI recommendation, with both values side by side: a query. Turnaround time between any two stages, across the whole book: a query over timestamps that already exist.
What Changes for the Audit Cycle
The fire drill disappears first. Preparing for a regulatory review stops consuming senior credit capacity, because there is nothing to reconstruct; the record was complete the day the work happened.
Then the sampling changes. Traditional audits sample files because full review is impossibly expensive. When the full book is queryable, the risk team can screen the entire portfolio for the patterns that matter, deviations, overrides, unusual approval chains, and spend human attention only where the queries point.
The regulator's question deserves an answer in minutes. The institutions that can give one will find audits become smaller events, and the ones that cannot will keep paying for archaeology.
Get started
Want to learn more about what we are building?
We'd love to show you how Lending Labs can fit your institution.
