AI GOVERNANCE IN LENDING · 100,000-APPLICATION SCENARIO ANALYSIS

When decisions scale, governance must scale with them.

Across 12 scenarios spanning model and configuration, data and access, decision authority, human override, explainability and fairness drift, this synthetic mass-retail lending simulation shows how embedded governance changes decision quality, facility value linked to faulty cases, human intervention, residual risk and evidence for management action.
Why the comparison matters: Governance OFF is the comparison baseline where relevant controls are absent, bypassed, ineffective or not embedded at the point of decision. Governance ON applies access and segregation of duties, approved models, human review, targeted kill switch and fallback, control assurance, ERM response and evidence. The difference shows what governance stopped and what still requires management action.
Quick meaning guide — recurring terms
STP
Straight-through processing: automatic finalisation without human referral.
HITL / HOTL
HITL pauses a case for accountable human review. HOTL supervises portfolio behaviour while automation runs.
Kill switch
Targeted suspension of an affected AI path/cohort; the whole loan process does not stop.
Affected / residual
Affected = touched by a failure scenario. Residual = still remaining after governance/control treatment.
ToD / ToE
Design capability versus actual operating performance of a control.
Risk response / control
Response = accept, mitigate, transfer/share or avoid. Control = preventive, detective, corrective, containment or recovery.
12-month occurrence probability
Scenario-configured probability that a risk event occurs within the stated horizon. It is separate from the percentage of transactions currently affected.
Residual-case treatment
Known faulty cases remaining after automated controls must still be held, reviewed, corrected, stopped, remediated or investigated before closure.
Applications100,000
Same loan-application population used in both OFF and ON paths.
Gross requested facility valueIDR 6.78 tn
Sum of requested principal; this is exposure size, not expected loss.
Faulty transactions passed through57,254
IDR 3.98 tn requested facility value linked to faulty cases
Faulty transactions remaining after controls1,055
Residual cases not fully intercepted/contained. IDR 75.38 bn requested facility value remains linked to them.
Governance effectiveness98.16%
Share of baseline fault-affected transactions removed from the residual population by governance controls.
Decision errors OFF → ON2,235 → 97
Final decisions that differ from the clean reference path.
Kill switchTRIGGERED
Triggered means AI auto-finalisation was suspended only for the affected cohort/path. Those applications continue through HITL or an approved fallback; the overall loan process is not stopped.
Governance evidence10/10 PASS
Operating evidence shows whether governance controls actually ran, not merely whether policies exist.

1) Governance OFF vs ON

Reading note: Some metrics are intentionally identical in OFF and ON because they describe the same baseline portfolio and the same injected-fault population. The rows that should improve are the outcome rows: faulty transactions reaching outcome stage, residual facility-value risk, and decision errors.

Governance OFF

57,254

Faulty transactions passed through

IDR 3.98 tn in requested facility value linked to faulty cases.
STP 71.60%
HITL 28,397
Decision errors 2,235

Governance ON

1,055

Faulty transactions remaining after controls

Residual facility-value risk reduced to IDR 75.38 bn, down IDR 3.90 tn from OFF.
What happens next: these cases are not auto-approved; they enter the residual-case treatment workflow below.
STP 52.98%
HITL 38,542
Errors prevented 2,138
Comparison metricOFFONGovernance effect
Same baseline by design
Applications processed
same portfolio
100,000100,000Same by design
Gross requested facility value
same synthetic portfolio value
IDR 6.78 tnIDR 6.78 tnSame by design
Fault-affected transaction population
same injected-fault transaction population
57,25457,254Same by design
Requested facility value linked to fault-affected population
same injected-fault facility-value population
IDR 3.98 tnIDR 3.98 tnSame by design
Outcome comparison
Straight-through decisions
lower can reflect intentional governance friction
71,60352,980Reduced by 18,623 (26.01%)
Straight-through rate
automation retained
71.60%52.98%-18.62 pp
Total HITL volume
human review volume
28,39738,542Increased by 10,145 (35.73%)
Faulty transactions reaching outcome stage
lower is better; governance should intercept, redirect or contain these cases before final outcome
57,2541,055Reduced by 56,199 (98.16%)
Residual facility-value risk after controls
gross requested facility value linked to the remaining faulty transaction population; not expected credit loss
IDR 3.98 tnIDR 75.38 bnReduced by IDR 3.90 tn (98.10%)
Final decisions changed vs clean reference
decision impact
2,23597Reduced by 2,138 (95.66%)
Facility value linked to changed decisions
OFF exact; ON estimated from remaining changed-decision proportion
IDR 161.71 bnIDR 7.02 bnReduced by IDR 154.69 bn (95.66%)
Control interventions
governance action
056,199Introduced 56,199
Blocked actions
least-privilege enforcement
05,000Introduced 5,000
Blocked AI decisions
decision control
015,000Introduced 15,000
Fallback to approved configuration
model/config containment
040,000Introduced 40,000
Held before booking
final-integrity control
010,145Introduced 10,145
Unauthorized actions executed
lower is better
5,0000Reduced by 5,000 (100.00%)
Adverse decisions without reason
explainability / conduct control
81224Reduced by 788 (97.04%)

1A) Mass-loan amount distribution, deciles and concentration

Portfolio calibration: default 100K / seed 20,260,828 produces IDR 6.78 tn requested facilities, average IDR 67.8 mn and median IDR 47.6 mn. The median is deliberately below the average, consistent with a right-skewed mass-loan portfolio.
Percentile / decile meaning: P10 means 10% of applications request this amount or less; P50 is the median; P90 means 90% are at or below that amount. D1–D10 divide the portfolio into ten equal-count amount groups from lowest to highest requested facility value.
P10IDR 15.9 mn
P50 / medianIDR 47.6 mn
P90IDR 141.7 mn
P95IDR 192.5 mn
P99IDR 341.8 mn
D9–D10 residual value share52.96%
Key principle: Frequency does not equal materiality: a small share of high-ticket cases can contribute a disproportionate share of residual facility value. D10 represents 32.85% of portfolio requested value and 33.28% of estimated residual facility value.

Facility value by amount decile

Blue = requested facility value in each decile. Dark red = estimated facility value still tied to residual cases after governance. The same full-scale denominator is used.
D1
avg IDR 11.3 mn
IDR 114.99 bn · residual IDR 1.12 bn
D2
avg IDR 19.7 mn
IDR 192.56 bn · residual IDR 1.86 bn
D3
avg IDR 26.8 mn
IDR 272.34 bn · residual IDR 2.70 bn
D4
avg IDR 34.3 mn
IDR 343.53 bn · residual IDR 3.43 bn
D5
avg IDR 42.8 mn
IDR 426.16 bn · residual IDR 4.16 bn
D6
avg IDR 53.1 mn
IDR 526.78 bn · residual IDR 5.58 bn
D7
avg IDR 66.3 mn
IDR 665.78 bn · residual IDR 7.30 bn
D8
avg IDR 84.7 mn
IDR 836.12 bn · residual IDR 9.30 bn
D9
avg IDR 116.4 mn
IDR 1.17 tn · residual IDR 14.83 bn
D10
avg IDR 221.8 mn
IDR 2.23 tn · residual IDR 25.09 bn
DecileLoansAverage facilityTotal facilityApprovalSTPAffected by faultsStill remainingShare of residual value
D1
LOW_TICKET
10,138IDR 11.3 mnIDR 114.99 bn80.23%75.08%5,275
IDR 59.50 bn
101
IDR 1.12 bn
1.48%
D2
LOW_TICKET
9,778IDR 19.7 mnIDR 192.56 bn80.32%74.96%4,952
IDR 97.83 bn
93
IDR 1.86 bn
2.47%
D3
LOW_TICKET
10,151IDR 26.8 mnIDR 272.34 bn80.21%74.02%5,839
IDR 157.18 bn
101
IDR 2.70 bn
3.58%
D4
CORE_MASS
10,013IDR 34.3 mnIDR 343.53 bn80.34%74.22%5,893
IDR 202.11 bn
100
IDR 3.43 bn
4.55%
D5
CORE_MASS
9,946IDR 42.8 mnIDR 426.16 bn79.80%73.03%5,763
IDR 246.82 bn
97
IDR 4.16 bn
5.52%
D6
CORE_MASS
9,924IDR 53.1 mnIDR 526.78 bn80.42%73.00%5,861
IDR 311.33 bn
105
IDR 5.58 bn
7.40%
D7
CORE_MASS
10,049IDR 66.3 mnIDR 665.78 bn79.10%71.99%5,951
IDR 394.79 bn
109
IDR 7.30 bn
9.68%
D8
UPPER_MASS
9,868IDR 84.7 mnIDR 836.12 bn78.95%70.97%5,798
IDR 490.56 bn
110
IDR 9.30 bn
12.34%
D9
UPPER_MASS
10,090IDR 116.4 mnIDR 1.17 tn79.10%67.80%5,979
IDR 696.10 bn
127
IDR 14.83 bn
19.68%
D10
HIGH_TICKET
10,043IDR 221.8 mnIDR 2.23 tn76.41%61.02%5,943
IDR 1.32 tn
112
IDR 25.09 bn
33.28%
Amount-segment roll-up
SegmentLoansAverage facilityTotal facilityAffected casesResidual casesResidual facility valueResidual value share
LOW_TICKET30,067IDR 19.3 mnIDR 579.88 bn16,066295IDR 5.68 bn7.54%
CORE_MASS39,932IDR 49.1 mnIDR 1.96 tn23,468411IDR 20.47 bn27.16%
UPPER_MASS19,958IDR 100.7 mnIDR 2.01 tn11,777237IDR 24.14 bn32.02%
HIGH_TICKET10,043IDR 221.8 mnIDR 2.23 tn5,943112IDR 25.09 bn33.28%
Still remaining does not mean unresolved forever: the decile/segment tables identify where residual cases and value are concentrated. Every remaining case is then assigned to a concrete treatment route in the next section.

1B) Residual-case treatment — what happens to the 1,055 remaining cases?

Key interpretation: 1,055 residual cases means automated governance did not fully resolve them. They must be held, reviewed, corrected, stopped before booking/disbursement, remediated after booking, or investigated. Residual does not mean allowed to proceed.
Treatment routeCasesFacility value linked to casesWhat happensOwnerWhen the case can close
Correct + reprocess
CORRECTIVE
260
24.64% of residual cases
IDR 18.49 bn
24.53% of residual facility value
Correct data, reason code, threshold or rule issue and re-run the affected application through the approved decision path.Credit Operations + AI GovernanceCorrected inputs/rules evidenced and reprocessed result passes applicable controls.
Hold + human review
CONTAINMENT + HUMAN REVIEW
579
54.88% of residual cases
IDR 40.83 bn
54.17% of residual facility value
Prevent automatic finalisation and assign the application to an accountable human reviewer.Credit Operations / UnderwritingHuman decision recorded with rationale; case either corrected/reprocessed or approved/declined under delegated authority.
Incident investigation
DETECTIVE + CORRECTIVE
46
4.36% of residual cases
IDR 3.55 bn
4.71% of residual facility value
Open an incident/root-cause investigation, preserve evidence, identify affected population and implement preventive actions.AI Governance + Credit Risk / Incident ManagementRoot cause confirmed, actions completed, affected population treated and retest/closure evidence approved.
Stop before booking / disbursement
PREVENTIVE + CONTAINMENT
130
12.32% of residual cases
IDR 9.68 bn
12.84% of residual facility value
Keep the case from booking or disbursement while the high-risk exception is investigated and resolved.Credit Risk + OperationsException cleared or application cancelled/declined; no uncontrolled disbursement occurs.
Post-booking remediation
CORRECTIVE + CUSTOMER REMEDIATION
40
3.79% of residual cases
IDR 2.83 bn
3.75% of residual facility value
For a case already booked, review the account, correct terms/data where required and apply customer/credit remediation and enhanced monitoring.Credit Operations + Conduct / Customer RemediationCustomer/account remediation completed, approvals evidenced and account monitoring updated.
Closure rule: A case is closed only after the required treatment is completed and evidence is recorded. Systemic issues also require control remediation/retest before unrestricted automated processing restarts.

2) Root-cause propagation, affected transactions and residual exposure

Terminology note: “Blast radius” is useful operational shorthand, but the formal dashboard uses propagation / affected transactions / residual exposure. IDR values are gross requested facility amounts touched by the scenario, not expected credit loss. Light red = transactions affected by the scenario. Dark red = the portion still remaining after controls. Both use the same denominator, so the remaining-risk bar can never appear larger than the initial affected population.
RC09 Segregation-of-duties self-approval
affected 20,000 (IDR 1.37 tn) · contained 20,000 · still remaining 0 (IDR 0)
RC01 Unauthorized model deployment
affected 20,000 (IDR 1.37 tn) · contained 20,000 · still remaining 0 (IDR 0)
RC02 Model calibration defect
affected 20,000 (IDR 1.37 tn) · contained 20,000 · still remaining 0 (IDR 0)
RC03 Unapproved proxy feature
affected 10,000 (IDR 681.36 bn) · contained 10,000 · still remaining 0 (IDR 0)
RC11 Silent material configuration drift
affected 5,000 (IDR 341.80 bn) · contained 5,000 · still remaining 0 (IDR 0)
RC12 Shadow AI / unapproved provider invocation
affected 5,000 (IDR 337.62 bn) · contained 5,000 · still remaining 0 (IDR 0)
RC08 Excessive user/agent privilege
affected 5,000 (IDR 338.29 bn) · contained 5,000 · still remaining 0 (IDR 0)
RC04 Low-uncertainty-confidence STP misrouting
affected 4,220 (IDR 296.27 bn) · contained 3,967 · still remaining 253 (IDR 17.78 bn)
RC10 Missing adverse-decision reason code
affected 812 (IDR 59.57 bn) · contained 788 · still remaining 24 (IDR 1.85 bn)
RC05 Automation authority misconfiguration
affected 5,390 (IDR 418.78 bn) · contained 5,390 · still remaining 0 (IDR 0)
RC06 Unsupported human override
affected 810 (IDR 64.44 bn) · contained 713 · still remaining 97 (IDR 7.65 bn)
RC07 Cohort calibration / fairness drift
affected 1,022 (IDR 72.12 bn) · contained 341 · still remaining 681 (IDR 48.10 bn)

2A) AI platform governance — controls that act before and around the loan process

PG01 · Agent inventory + permission lifecycle
No agent should operate anonymously or keep access merely because it had access before.

Protocol: Register agent + owner + purpose + environment + risk tier → Grant only required data/tools/actions → Time-bound elevated privilege → Periodic recertification → Detect permission creep / expiry → Revoke or re-approve with evidence

Control test: 8/8 agents registered; 17 grants reviewed; 2 excess/expired detected and revoked; 0 unresolved.

Why it matters: Least privilege is not a one-time access matrix. Permissions can creep or outlive their business need.

Owner: IAM / Security + AI Governance · Evidence: Agent registry + access recertification log + revocation event
PG02 · Test / production boundary
A development, evaluation or test identity must not silently become a production actor.

Protocol: Bind identity to environment → Separate test/prod credentials and network routes → Deny production API/data access from non-production identity → Log boundary violations → Escalate repeated attempts

Control test: 3/3 unauthorized boundary attempts blocked; zero production escape.

Why it matters: A test agent must not silently become a production actor simply because it has a reachable endpoint.

Owner: Platform Engineering + Security · Evidence: Environment identity policy + denied-access / boundary-test logs
PG03 · Shadow AI discovery + approval lifecycle
Unknown AI use must become visible before it becomes normal operating practice.

Protocol: Discover unregistered AI/provider invocation → Match against approved inventory → Assess data/system access + intended use → Assign risk tier → Approve / restrict / reject → Onboard approved tool to IAM + logging → Periodically reassess

Control test: 1/1 unregistered provider attempts blocked; linked RC12 scope 5,000 applications.

Why it matters: Discovery alone does not govern shadow AI; the organization needs a decision and onboarding/rejection lifecycle.

Owner: AI Governance + Security / Procurement · Evidence: Discovery event + risk review decision + provider registry record
PG04 · AI component / supply-chain integrity
Production promotion checks the whole AI component set, not model version alone.

Protocol: Approved source / registry → Pinned version → Artifact/model/feature hash check → Provider identity check → Dependency / release manifest review → Block mismatch → Fallback to last-known-good configuration → Record remediation evidence

Control test: 4 components checked; 1 mismatch blocked; last-known-good retained.

Why it matters: An approved model can still be paired with an unapproved dependency, provider or release artifact.

Owner: Model / Platform Engineering + Model Risk / Security · Evidence: Signed release manifest + version/hash/provider checks + fallback record
Added platform fault scenarios: PF01 Permission creep / expired privilege and PF02 Unapproved component reaches release candidate. RC12 is enriched rather than duplicated: Shadow AI now demonstrates discover → assess → approve/restrict/reject → monitor.

2B) Evidence of Governance — is the governance system itself operating?

Overall status: OPERATING — CONTROL TESTS PASSED
This section tests the governance layer itself. A policy document is not enough; inventory, permissions, boundaries, integrity controls, evidence and recovery must leave observable proof.
Why this matters: governance is only credible if a reviewer can trace registration, permission review, blocked boundary/provider/component events, kill-switch/fallback actions, residual-case assignments and controlled restart evidence.
Operating metricResultStatusWhat the evidence provesEvidence source
AI agent inventory completeness8/8PASSEvery simulated agent has an owner, purpose, environment and risk tier before it can operate.Agent registry snapshot
High-risk permission recertification17 grants reviewedPASSAccess is periodically re-justified; two expired/excess grants were detected and revoked.Access recertification + revocation log
Test / production boundary control test3/3 blockedPASSNon-production identities were prevented from becoming production actors.Boundary-test / denied-access log
Shadow AI / unregistered-provider containment1/1 blockedPASSThe unregistered provider attempt was discovered, assessed and blocked before escape; linked RC12 scope = 5,000 applications.Provider discovery + approval/rejection record
AI component integrity gate4 checked; 1 mismatch blockedPASSThe release candidate is checked beyond model version alone; a mismatch triggers block + known-good fallback.Release manifest + hash/provider attestation + fallback record
Governance controls with explicit evidence trace8/8PASSEach platform/system governance control records a trace statement showing what was checked and the result.Governance control trace
Evidence-ledger sample completeness25 sampled eventsPASSSampled decision/control events contain model, policy, AI output, governance output, oversight, intervention and evidence-hash fields.Evidence ledger
Kill-switch control testTRIGGERED + CONTROLLED FALLBACKPASSThe test proves targeted suspension of the affected AI auto-finalisation path while cases continue through HITL/fallback.Kill-switch event + routing/fallback log
Residual-case treatment assignment1055/1055 assignedPASSEvery known residual faulty case is assigned a treatment path instead of being allowed to proceed automatically or remain unmanaged.Residual-case treatment / case-management assignment log
Controlled restart protocolNORMAL_AFTER_CONTROLLED_REACTIVATIONPASSRestart is only allowed after incident analysis, corrective action, revalidation and independent approval.Restart approval / revalidation record
Evidence chain
Control objective → trigger/check → action → evidence record → accountable owner → exception/remediation → retest/closure. This is what makes governance auditable rather than aspirational.

3) Control effectiveness — ToD + ToE + improvement action

RiskControlFramework mappingToD + rationaleToE + rationaleOverallResidualHow to improve
RC09SoD Gate + Independent Model ApprovalBAI06 Managed IT Changes; MEA02 Managed System of Internal Control; MEA04 Managed Assurance
COSO: Control Environment, Control Activities, Monitoring Activities
ADEQUATE (100.00%)
Four-eyes segregation prevents the model developer from approving the same change; independent approval is required before release. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Maintain independent approval and periodically recertify SoD; make self-approval technically impossible rather than policy-only.
RC01SoD + GATE 3 Model RegistryBAI06 Managed IT Changes; BAI10 Managed Configuration; MEA02 Managed System of Internal Control; MEA04 Managed Assurance
COSO: Risk Assessment, Control Activities, Monitoring Activities
ADEQUATE (100.00%)
The active model/version/hash is checked against the approved registry before automated decisioning, with a fallback to the last approved model. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Add signed artifact/hash verification at deployment and automated rollback to last approved version.
RC02GATE 3 + HOTL MonitorAPO12 Managed Risk; BAI06 Managed IT Changes; MEA01 Managed Performance and Conformance Monitoring; MEA04 Managed Assurance
COSO: Risk Assessment, Control Activities, Monitoring Activities
ADEQUATE (100.00%)
Pre-deployment validation plus post-deployment performance monitoring jointly address calibration defects before and after release. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 20,000 intercepted / 20,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Add monthly calibration-by-cohort monitoring, outcome backtesting and independent validation after material change.
RC03GATE 2 + GATE 3APO13 Managed Security; APO14 Managed Data; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control
COSO: Control Environment, Control Activities, Information & Communication
ADEQUATE (100.00%)
Data-purpose and feature allow-list gates prevent unapproved proxy features from entering the approved scoring feature set. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 10,000 intercepted / 10,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Automate feature-store allow-list checks and data-purpose attestations at every model release.
RC11GATE 3 Lineage / Hash ControlBAI06 Managed IT Changes; BAI10 Managed Configuration; MEA01 Managed Performance and Conformance Monitoring
COSO: Control Activities, Monitoring Activities
ADEQUATE (100.00%)
Hash and lineage checks detect material configuration changes even when the displayed version label is unchanged. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Cryptographically sign model/config artifacts; alert on threshold/config changes even when version label is unchanged.
RC12IAM + GATE 3 Provider RegistryAPO10 Managed Vendors; APO12 Managed Risk; APO13 Managed Security; MEA03 Managed Compliance with External Requirements
COSO: Risk Assessment, Control Activities, Information & Communication
ADEQUATE (100.00%)
Provider registry and access controls prevent an unregistered external model/provider from being invoked by the Decision Agent. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Add egress allow-list, provider attestation and shadow-AI discovery/alerting.
RC08Dual IAM Permission GatesAPO13 Managed Security; DSS05 Managed Security Services; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control
COSO: Control Environment, Control Activities
ADEQUATE (100.00%)
Dual permission gates constrain both human→agent invocation and agent→data/tool/action permissions under least privilege. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 5,000 intercepted / 5,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Move to JIT/JEA permissions, short-lived scoped tokens and periodic user/agent access recertification.
RC04GATE 4 + HITLAPO12 Managed Risk; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control
COSO: Risk Assessment, Control Activities
ADEQUATE (100.00%)
Decision uncertainty thresholds route near-threshold or low-confidence cases to HITL instead of allowing unsupported STP. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
PARTIALLY EFFECTIVE (94.00%)
Simulation evidence: 3,967 intercepted / 4,220 tested; 253 exceptions. Pass rate 94.00% is below Effective 98% but meets Partially Effective ≥ 90%.
PARTIALLY EFFECTIVE253Tune uncertainty/OOD referral thresholds and review false-approval/false-decline trade-offs using backtesting.
RC10GATE 4 ExplainabilityDSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control; MEA03 Managed Compliance with External Requirements
COSO: Control Activities, Information & Communication
ADEQUATE (100.00%)
The adverse-decision gate requires a valid reason code before finalisation, making explainability an executable control. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
PARTIALLY EFFECTIVE (97.04%)
Simulation evidence: 788 intercepted / 812 tested; 24 exceptions. Pass rate 97.04% is below Effective 98% but meets Partially Effective ≥ 90%.
PARTIALLY EFFECTIVE24Make reason-code completeness a hard pre-finalisation condition and sample adverse decisions for quality, not only presence.
RC05GATE 6 AuthorityEDM03 Ensured Risk Optimization; APO12 Managed Risk; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control
COSO: Control Environment, Control Activities
ADEQUATE (100.00%)
Delegated-authority service hard-stops automated decisions above the approved automation limit and routes them to human authority. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
EFFECTIVE (100.00%)
Simulation evidence: 5,390 intercepted / 5,390 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%.
EFFECTIVE0Bind every automated decision to a central authority service with hard fail-closed behavior and immutable authority evidence.
RC06GATE 5 HITL OverrideDSS06 Managed Business Process Controls; MEA01 Managed Performance and Conformance Monitoring; MEA02 Managed System of Internal Control
COSO: Control Environment, Control Activities, Monitoring Activities
ADEQUATE (100.00%)
Override governance requires rationale, evidence and authority before a human reversal can become final. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
INEFFECTIVE (88.02%)
Simulation evidence: 713 intercepted / 810 tested; 97 exceptions. Pass rate 88.02% is below the Partially Effective threshold 90%.
INEFFECTIVE97Require structured override rationale/evidence, peer-rate anomaly monitoring and temporary restriction for repeat outliers.
RC07HOTL Monitor + Kill SwitchEDM03 Ensured Risk Optimization; APO12 Managed Risk; MEA01 Managed Performance and Conformance Monitoring; MEA02 Managed System of Internal Control
COSO: Risk Assessment, Monitoring Activities
ADEQUATE (100.00%)
Portfolio HOTL monitoring plus kill-switch authority is designed to detect systemic cohort drift and contain its portfolio-level magnitude. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification.
INEFFECTIVE (33.37%)
Simulation evidence: 341 intercepted / 1,022 tested; 681 exceptions. Pass rate 33.37% is below the Partially Effective threshold 90%.
INEFFECTIVE681Shorten monitoring latency, add cohort calibration/fairness triggers and pre-agreed kill-switch/restart criteria.

4) Credit model outcomes analysis / backtesting

Important: Synthetic realized-default ground truth is generated from an independent RNG and a latent true-PD function. In real lending, declined applicants do not produce observed repayment outcomes without reject-inference or external performance data.
Model metricApproved/referenceObserved/faulted pathPreferred
AUC
How well the score ranks borrowers who default versus those who do not; 0.5 is random ranking and higher is better.
0.61060.603higher
Gini
A discrimination measure derived from AUC; higher means stronger rank ordering.
0.22120.2061higher
KS
Maximum separation between cumulative good and bad borrower distributions; higher means stronger discrimination.
0.16060.1494higher
Average PD
Average predicted probability of default across the portfolio.
25.50825.182context
Observed default rate
Synthetic realised default rate used as the common outcome set for backtesting.
26.54926.549same outcomes
Calibration gap (pp)
Difference between average predicted PD and realised default rate; closer to zero means better calibration.
-1.041-1.367closer to 0
ECE (%)
Expected calibration error across probability buckets; lower means predicted probabilities align better with outcomes.
1.1021.466lower
Brier score
Mean squared error of probability forecasts; lower means better probabilistic accuracy.
0.188550.18966lower
Approved model assessment
WITHIN LIMITS
Whether the approved/reference model meets the configured validation limits.
Observed path assessment
REVIEW / REMEDIATE
Whether the observed/faulted scoring path remains acceptable against the same validation limits.
Brier deterioration
0.59% · WITHIN LIMIT
Relative worsening in probability forecast error; lower deterioration is better.

Decision-direction diagnostic

For credit decisions, the dashboard uses false approval / false decline rather than relying on Type I / Type II labels because Type-I/II conventions depend on which class is defined as the positive/error event.
Error directionOFFON
False approval vs clean reference
Observed path APPROVES a case the clean reference would DECLINE — credit-loss / adverse-selection direction.
1,16420
False decline vs clean reference
Observed path DECLINES a case the clean reference would APPROVE — missed-good-business direction.
1,07177

Governance OFF vs ON is a controlled governance-state experiment, not a substitute for a model champion/challenger test.

5) ERM — 5×5 heatmap, appetite, movement and concrete response

Impact anchor: Very Low < IDR 25bn · Low IDR 25–100bn · Moderate IDR 100–250bn · High IDR 250–500bn · Very High > IDR 500bn. Important: financial value is only one impact dimension. Customer, conduct, legal, regulatory and reputational severity can move a risk to a higher impact category even when the monetary value is lower.
Probability methodology: Scenario-configured event occurrence probabilities make the ordinal likelihood scale visible. They are not a historical probability density function; production calibration should use observed event/exposure data and approved expert or statistical estimation. The dashboard therefore reports a point estimate and range for the probability that each risk event occurs within a 12-month horizon. This is different from the current residual-transaction rate.
Improbable (1)Very Low (1)Remote (2)Low (2)Occasional (3)Moderate (3)Probable (4)High (4)Frequent (5)Very High (5)LIKELIHOOD →IMPACT →IRM&CIRD&AIRD&CIRA&HIRF&P
I = inherent risk before controls; R = residual risk after controls. Arrows show movement. Risk positions are scenario-configured settings and are independent from the raw residual-transaction rate.
Risk event/themeInherent occurrence probabilityResidual occurrence probabilityLikelihood improvementTime horizonFinancial impact anchorManagement insight
MODEL_AND_CHANGE40.00%
band 30–50%
3.00%
band 0–5%
92.50%
37.0 percentage-point reduction
12 monthsIDR 56.80 bn
Direct financial anchor; not expected loss.
Controls reduce the configured 12-month occurrence likelihood from 40.0% to 3.0% (92.5% relative reduction). A residual 3.0% probability remains that a material model or configuration change event could occur within the next 12 months. The direct financial anchor is IDR 56.80 bn and the final impact category is 4 (High impact); non-financial consequences may increase severity.
DATA_AND_ACCESS40.00%
band 30–50%
3.00%
band 0–5%
92.50%
37.0 percentage-point reduction
12 monthsIDR 25.27 bn
Direct financial anchor; not expected loss.
Controls reduce the configured 12-month occurrence likelihood from 40.0% to 3.0% (92.5% relative reduction). A residual 3.0% probability remains that an unauthorized data, privileged-access or unapproved-provider event could occur within the next 12 months. The direct financial anchor is IDR 25.27 bn and the final impact category is 5 (Very High impact); non-financial consequences may increase severity.
DECISION_AND_CONDUCT40.00%
band 30–50%
10.00%
band 5–15%
75.00%
30.0 percentage-point reduction
12 monthsIDR 0
Direct financial anchor; not expected loss.
Controls reduce the configured 12-month occurrence likelihood from 40.0% to 10.0% (75.0% relative reduction). A residual 10.0% probability remains that an unresolved decision-quality or conduct event could occur within the next 12 months. The direct financial anchor is IDR 19.63 bn and the final impact category is 3 (Moderate impact); non-financial consequences may increase severity.
AUTHORITY_AND_HUMAN22.00%
band 15–30%
10.00%
band 5–15%
54.50%
12.0 percentage-point reduction
12 monthsIDR 64.44 bn
Direct financial anchor; not expected loss.
Controls reduce the configured 12-month occurrence likelihood from 22.0% to 10.0% (54.5% relative reduction). A residual 10.0% probability remains that an authority-bypass or unsupported-human-override event could occur within the next 12 months. The direct financial anchor is IDR 64.44 bn and the final impact category is 4 (High impact); non-financial consequences may increase severity.
FAIRNESS_AND_PORTFOLIO40.00%
band 30–50%
22.00%
band 15–30%
45.00%
18.0 percentage-point reduction
12 monthsIDR 15.21 bn
Direct financial anchor; not expected loss.
Controls reduce the configured 12-month occurrence likelihood from 40.0% to 22.0% (45.0% relative reduction). A residual 22.0% probability remains that a cohort calibration or fairness-drift event could occur within the next 12 months. The direct financial anchor is IDR 15.21 bn and the final impact category is 3 (Moderate impact); non-financial consequences may increase severity.
Risks that matter
  • DECISION_AND_CONDUCT — MANAGEMENT ATTENTION. Current 0.277 % applications versus appetite 0.1; response: MITIGATE.
  • AUTHORITY_AND_HUMAN — WATCHLIST. Current 0.097 % applications versus appetite 0.05; response: MITIGATE.
  • FAIRNESS_AND_PORTFOLIO — EXECUTIVE / BOARD ATTENTION. Current 17.02 percentage points versus appetite 3; response: MITIGATE.
Response versus control: Risk response is the management strategy (accept, mitigate, transfer or avoid). Control posture describes how controls act (preventive, detective, corrective, containment or recovery). Accept does not mean removing controls; it means the current residual risk is within appetite and existing controls/monitoring are maintained.
Risk themeInherentResidual + movementFacility value footprintAppetite metricAppetiteWarningBreachCurrentStatusRisk responseControl posture + immediate actionEscalation
MODEL_AND_CHANGEHigh impact × Probable likelihood
Risk position before the simulated governance/control treatment.
High impact × Improbable likelihood
Likelihood ↓ through pre-deployment prevention and fallback Residual = risk remaining after controls.
IDR 1.71 tn linked to affected cases
Direct decision-value anchor: IDR 56.80 bn → Low financial anchor. IDR 0 facility value remains linked to residual cases. Systemic model/change failure can affect portfolio integrity beyond direct decision-value impact.
Unauthorized material model/configuration change reaching production
Metric used by management to judge whether this risk is tolerable.
0 events
Target maximum residual level accepted in normal operation.
0 events
Early-warning level that requires management attention before breach.
1 events
Threshold requiring formal response/restriction/escalation.
0 events
Observed value from this simulation run.
WITHIN APPETITEACCEPT
Accept residual risk within appetite. Monitoring is maintained as an oversight/control activity, not treated as a separate risk-response category.
PREVENTIVE + RECOVERY
Maintain release approval, approved model registry, independent validation and fallback readiness. If an unapproved change is detected, block the release and fall back to the last approved configuration.
Model Risk / AI Governance; Risk Committee if a confirmed escape occurs.
DATA_AND_ACCESSVery High impact × Probable likelihood
Risk position before the simulated governance/control treatment.
Very High impact × Improbable likelihood
Likelihood ↓ through least privilege, allow-lists and provider registry Residual = risk remaining after controls.
IDR 1.36 tn linked to affected cases
Direct decision-value anchor: IDR 25.27 bn → Low financial anchor. IDR 0 facility value remains linked to residual cases. Privacy, security, data-purpose and regulatory consequences can be severe even where direct credit decision value is limited.
Unauthorized privileged action, prohibited feature or unapproved provider escaping controls
Metric used by management to judge whether this risk is tolerable.
0 events
Target maximum residual level accepted in normal operation.
0 events
Early-warning level that requires management attention before breach.
1 events
Threshold requiring formal response/restriction/escalation.
0 events
Observed value from this simulation run.
WITHIN APPETITEACCEPT
Accept residual risk within appetite. Monitoring is maintained as an oversight/control activity, not treated as a separate risk-response category.
PREVENTIVE + DETECTIVE
Maintain least-privilege access, feature/provider allow-lists and periodic access recertification. If an exception is detected, deny the action/provider, revoke excess privilege and isolate the affected path.
Security + Data Governance + AI Governance; executive notification for confirmed data exposure.
DECISION_AND_CONDUCTModerate impact × Probable likelihood
Risk position before the simulated governance/control treatment.
Moderate impact × Remote likelihood
Likelihood ↓ through uncertainty referral and adverse-reason gate Residual = risk remaining after controls.
IDR 355.83 bn linked to affected cases
Direct decision-value anchor: IDR 0 → Very Low financial anchor. IDR 19.63 bn facility value remains linked to residual cases. Customer treatment, explainability and conduct consequences can raise impact above direct financial value.
Unresolved decision / conduct exceptions as % of applications
Metric used by management to judge whether this risk is tolerable.
0.1 % applications
Target maximum residual level accepted in normal operation.
0.2 % applications
Early-warning level that requires management attention before breach.
0.25 % applications
Threshold requiring formal response/restriction/escalation.
0.277 % applications
Observed value from this simulation run.
BREACHMITIGATE
Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories.
DETECTIVE + CORRECTIVE
Route uncertain cases to HITL and hold adverse decisions lacking a valid reason code.
Credit Risk / Conduct / AI Governance until residual rate returns within appetite.
AUTHORITY_AND_HUMANHigh impact × Occasional likelihood
Risk position before the simulated governance/control treatment.
High impact × Remote likelihood
Likelihood ↓ through hard authority service and override evidence Residual = risk remaining after controls.
IDR 483.22 bn linked to affected cases
Direct decision-value anchor: IDR 64.44 bn → Low financial anchor. IDR 7.65 bn facility value remains linked to residual cases. Authority bypass and unsupported override create governance/accountability consequences beyond direct facility value.
Residual authority / unsupported override exceptions as % of applications
Metric used by management to judge whether this risk is tolerable.
0.05 % applications
Target maximum residual level accepted in normal operation.
0.1 % applications
Early-warning level that requires management attention before breach.
0.2 % applications
Threshold requiring formal response/restriction/escalation.
0.097 % applications
Observed value from this simulation run.
ABOVE APPETITEMITIGATE
Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories.
PREVENTIVE + DETECTIVE
Remove automated authority outside limits; challenge unsupported overrides and route to senior authority.
Credit Risk management; Risk Committee if breach threshold is exceeded.
FAIRNESS_AND_PORTFOLIOHigh impact × Probable likelihood
Risk position before the simulated governance/control treatment.
Moderate impact × Occasional likelihood
Likelihood ↓ and impact ↓ through HOTL detection, kill switch and affected-cohort containment Residual = risk remaining after controls.
IDR 72.12 bn linked to affected cases
Direct decision-value anchor: IDR 15.21 bn → Very Low financial anchor. IDR 48.10 bn facility value remains linked to residual cases. Systemic cohort fairness and regulatory/customer harm can raise impact above direct facility-value impact.
Absolute cohort approval-rate drift versus reference
Metric used by management to judge whether this risk is tolerable.
3 percentage points
Target maximum residual level accepted in normal operation.
5 percentage points
Early-warning level that requires management attention before breach.
8 percentage points
Threshold requiring formal response/restriction/escalation.
17.02 percentage points
Observed value from this simulation run.
BREACHMITIGATE
Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories.
DETECTIVE + CONTAINMENT + CORRECTIVE
Temporarily suspend AI auto-finalisation for the affected cohort/path, route those cases to HITL or approved fallback, and investigate drift/fairness drivers.
Risk Committee / senior management while outside appetite.

6) Control environment improvement — ex-post root cause, corrective action and retest

Internal-control meaning: a control weakness should feed back into control design and operating practice. Preventive controls stop an event before it happens; detective controls identify it; corrective/containment/recovery controls limit impact and restore a controlled state.
What retest means
Repeat the same failure scenario after remediation.
How to test
Same seed/comparable population → same root cause → rerun ToE/model outcomes → compare exceptions and appetite.
Closure
Action completed + retest passes + residual risk within appetite + required independent/challenge sign-off.
RCRoot causeRisk responseControl typeImmediate actionControl changeRestrictionOwnerRetest methodExpected resultClosure criteria
RC04Low-uncertainty-confidence STP misroutingMITIGATE
ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories.
DETECTIVE + CORRECTIVE
How the control acts: preventive, detective, corrective, containment or recovery.
Route near-threshold/uncertain cases to HITL.Tune uncertainty/OOD referral threshold using false-approval/false-decline trade-off.Mandatory HITL while residual exception rate is above appetite.AI Governance / Credit RiskSame seed/comparable population → reinject low-confidence misrouting → rerun ToE; target ≥98% pass and residual rate within appetite.ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite.Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required
RC10Missing adverse-decision reason codeMITIGATE
ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories.
PREVENTIVE + DETECTIVE
How the control acts: preventive, detective, corrective, containment or recovery.
Hold adverse decisions missing a valid reason code.Hard pre-finalisation reason-code completeness and quality checks.No adverse decision finalisation without usable explanation.AI Governance / Credit RiskInject missing/invalid reason codes; target ≥98% interception and residual rate within appetite.ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite.Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required
RC06Unsupported human overrideMITIGATE
ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories.
DETECTIVE + CORRECTIVE
How the control acts: preventive, detective, corrective, containment or recovery.
Challenge unsupported overrides and require evidence before finalisation.Structured rationale/evidence plus peer-rate anomaly monitoring.Restrict repeat outlier reviewers pending investigation.AI Governance / Credit RiskReplay override anomalies; target ≥98% effective interception and residual exception rate ≤ theme appetite.ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite.Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required
RC07Cohort calibration / fairness driftMITIGATE
ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories.
DETECTIVE + CONTAINMENT + CORRECTIVE
How the control acts: preventive, detective, corrective, containment or recovery.
Suspend affected auto-decision path and make HITL mandatory for the cohort.Tighter cohort drift/fairness monitoring, recalibration and kill-switch criteria.No controlled restart until independent validation and appetite re-entry.AI Governance / Credit RiskReinject cohort drift with same monitoring checkpoint; verify trigger latency, containment, fairness drift ≤3pp and ToE ≥98% before restart.ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite.Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required

7) Meaning of recurring dashboard terms

STP
Straight-through processing: applications finalized without human review. Higher is faster, but not automatically better if control risk rises.
HITL
Human in the loop: a specific application is paused for accountable human review before finalisation.
HOTL
Human on the loop: portfolio-level supervision while automation runs, with authority to intervene when thresholds are breached.
Kill switch
Targeted suspension/deactivation of the affected AI automated path or component. In this simulation the loan process continues through HITL or approved fallback.
Residual risk
Risk remaining after governance and controls have acted; it is compared with risk appetite to decide whether further treatment is required.
Governance effectiveness
Percentage reduction from baseline fault-affected transactions to the residual population after controls.
ToD / ToE
Test of Design asks whether the control is capable by design. Test of Operating Effectiveness asks whether it actually worked over the tested population.
Risk appetite / warning / breach
Appetite = accepted residual level; warning = early management trigger; breach = formal response/escalation threshold.
Inherent / residual
Inherent = risk before the specified controls. Residual = risk after those controls and treatments.
Risk response
Management strategy for the risk: accept, mitigate, transfer/share or avoid. It is different from the type of control used.
Control type
Preventive stops an event; detective identifies it; corrective fixes causes; containment limits spread/impact; recovery restores a controlled operating state.
Facility value
Gross requested principal linked to the cases being discussed. It is not expected loss, impairment, capital impact or realised loss.
Occurrence probability
Probability that a defined risk event occurs within the stated time horizon. It is not the same as the percentage of applications currently affected and is not presented as a historical probability-density function.
Residual-case treatment
Disposition applied to known faulty cases after automated controls: hold/review, correct/reprocess, stop, post-booking remediation or incident investigation.
Synthetic educational demonstration. Quantitative appetite levels, heatmap positions and 12-month event probabilities are scenario-configured assumptions, not universal regulatory thresholds or empirically fitted probability distributions. Model-validation metrics use synthetic realised outcomes. In production, thresholds must be approved by the institution and calibrated to portfolio materiality, legal obligations and risk appetite.