AI Governance Policy

This AI Governance Policy explains how CreditVantage AI governs the responsible use of artificial intelligence, data processing, human oversight, and institutional accountability within the AI Credit Analyst platform.

1. Purpose of this Policy

This AI Governance Policy explains how CreditVantage AI governs the responsible use of artificial intelligence, data processing, human oversight, security controls, audit records, retention settings, service-provider workflows, and generated reports within the AI Credit Analyst platform.

This Policy supports institutional confidence, transparency, responsible AI use, human oversight, and sound credit governance.

2. Platform role

AI Credit Analyst is an AI-assisted credit analysis platform. It helps Client Institutions organize submitted borrower information, analyze repayment capacity and credit risk, review uploaded credit bureau reports where applicable, identify risk signals, and generate decision-ready credit analysis reports.

AI Credit Analyst is not a credit bureau, lender, debt collector, financial regulator, or automated final decision-maker.

3. Data flow summary

(a) An Authorized User logs into the platform or submits information through an approved secure form.

(b) The Authorized User enters borrower/application information using defined data fields.

(c) Where applicable, the Authorized User uploads a permitted credit bureau report or other approved credit-relevant document for analysis.

(d) The submission is routed through approved workflow automation, database, storage, artificial intelligence processing, document-generation, email delivery, hosting, security, and support systems, depending on the applicable workflow configuration.

(e) Relevant data may be sent to artificial intelligence processing and report-generation service providers to produce a structured credit report or memo.

(f) The completed report may be delivered by email, portal download, or another approved delivery method.

(g) Workflow records, generated reports, logs, and storage records may be retained for the period specified in the Privacy Policy, applicable client agreement, and platform configuration.

4. Service providers and subprocessors

The platform may use third-party service providers and subprocessors for workflow automation, storage, AI processing, report generation, email delivery, hosting, security, monitoring, support, backups, and similar technical functions.

These providers are described by category in published policies and contracts. CreditVantage AI may disclose specific vendor names separately where appropriate.

These providers are used to operate, secure, support, maintain, and deliver the platform. They are not used to sell borrower information.

CreditVantage AI maintains appropriate contractual, security, confidentiality, retention, and data protection arrangements with material providers.

5. AI use

The AI component is used to assist analysis, summarize information, apply structured credit reasoning, identify risk indicators, generate narrative explanations, and produce report-ready content.

The AI is guided by platform instructions, credit assessment logic, data fields, report templates, and institutional use cases.

The AI may process information contained in form submissions and uploaded documents. The platform is designed to limit AI processing to what is reasonably necessary for credit analysis and report generation.

Where third-party artificial intelligence processing providers are used, CreditVantage AI seeks to use provider arrangements and service configurations under which Client Institution data, borrower/application information, uploaded credit bureau information, and generated report content are not used to train or improve public AI models, unless expressly agreed in writing with the Client Institution.

6. Human oversight and accountability

The platform is AI-assisted, not AI-decisioning. It supports credit officers and committees but does not replace them.

Final judgment, policy interpretation, exception approval, borrower communication, and lending decisions remain with the Client Institution.

Every generated report must be reviewed by an appropriate officer, supervisor, committee, or other authorized institutional decision-maker before use. The reviewing officer or committee is responsible for confirming that the submitted data is accurate, the report is reasonable, the recommendation aligns with institutional policy, and the final decision is properly documented.

7. No automated final decision-making

The platform does not automatically approve, decline, price, or otherwise make final credit decisions.

Any recommendation generated by the platform is a decision-support output and must be treated as subject to human review, institutional policy, and authorized approval by the Client Institution.

8. Personal information minimization

The platform is designed to avoid requesting unnecessary personal identifiers as required form fields where such identifiers are not needed for credit analysis or report generation.

Uploaded credit bureau reports may contain personal identifiers and sensitive credit information. The platform is designed to focus generated outputs on credit-relevant analysis and to avoid unnecessary exposure of personal information where reasonably possible.

9. Client Institution consent and lawful authority

The Client Institution must ensure that it has borrower consent, lawful authority, internal approval, and any required regulatory basis before submitting borrower/application information or uploading a credit bureau report.

CreditVantage AI does not independently verify borrower consent unless an applicable platform workflow expressly provides for that verification.

10. Security and access controls

CreditVantage AI maintains layered security measures appropriate to the sensitivity of borrower/application data processed through the platform.

Controls may include SSL/TLS, web application firewall protections, multi-factor authentication, strong passwords, role-based access, restricted account provisioning, audit logs, secure file storage, controlled email delivery, security monitoring, staff confidentiality obligations, and incident response procedures.

Access to the platform is limited to Authorized Users approved by the Client Institution. Access may be suspended, restored, restricted, or removed where an Authorized User changes role, leaves the Client Institution, no longer requires access, or presents a security, confidentiality, legal, or operational risk. Access controls are designed to prevent suspended or offboarded users from initiating further AI-assisted processing or accessing restricted platform functions.

11. Auditability, documentation, and explainability

The platform is designed to support audit-ready credit review by producing structured reports that identify key facts, calculations, risk indicators, credit reasoning, and recommendations.

Workflow logs and report records are designed to support internal review, supervisory review, credit committee review, and reasonable post-decision audit.

The platform is designed to avoid unsupported “black box” conclusions. Generated reports are intended to connect material observations, risk flags, affordability comments, and credit recommendations to submitted data, credit bureau information where applicable, financial ratios, repayment capacity indicators, payment history, collateral information, verification gaps, and other credit-relevant factors.

Access suspension, user removal, branch closure, or institutional offboarding should not compromise the historical attribution, traceability, or auditability of previously submitted applications, workflow events, generated reports, or AI-assisted outputs. Relevant identifiers and audit records may therefore be preserved in accordance with the applicable retention schedule.

12. Bias, fairness, and responsible use

The platform is designed to support fair, consistent, and explainable credit review.

The platform must not be used to make discriminatory decisions or to rely on irrelevant personal characteristics.

Client Institutions are responsible for reviewing outputs for consistency, fairness, policy alignment, and unintended bias before relying on them in any credit review, recommendation, or decision-making process.

13. Data retention and deletion governance

Retention periods are defined for uploaded reports, generated reports, form submissions, database records, email records, logs, backups, support records, and related workflow records.

Retention is limited to what is necessary for the identified purposes, contractual requirements, legal obligations, audit, security, dispute resolution, and legitimate platform administration.

The retention approach reflects the Data Protection Act principle that personal information should not be retained longer than is necessary for the purpose for which it is processed.

Client Institutions remain responsible for their own statutory, regulatory, AML/CFT, credit-file, audit, internal governance, and institutional record-retention obligations.

Platform retention settings are governed by the Privacy Policy, applicable client agreement, and platform configuration. Where applicable, retention arrangements may be aligned contractually with the Client Institution’s lawful recordkeeping requirements.

Suspension, removal, or termination of access does not necessarily result in immediate deletion of related records. Relevant information may remain subject to the retention, deletion, backup, audit, security, contractual, and legal arrangements described in the Privacy Policy and applicable client agreement.

14. Incident response and breach handling

CreditVantage AI maintains procedures for detecting, investigating, containing, and responding to security incidents involving platform data.

Client Institutions will be notified of material incidents affecting their data in accordance with contract terms, applicable law, and the nature of the incident.

Where a Client Institution reports a material error, logical inconsistency, system issue, or suspected AI-generated inaccuracy in a generated report, CreditVantage AI may review the matter, investigate the relevant workflow or report-generation issue, and take reasonable corrective action where appropriate.

15. Governance review and continuous improvement

CreditVantage AI periodically reviews the platform’s data flow, AI-assisted analysis workflow, service-provider arrangements, retention settings, access controls, report-generation process, security safeguards, and governance procedures to support responsible AI use, platform reliability, and institutional accountability.

This review may include assessment of workflow automation, database and storage systems, AI processing, report generation, email delivery, hosting, security, backup systems, user roles, access controls, account provisioning, offboarding, report review procedures, incident response procedures, and governance documentation.

This AI Governance Policy is maintained by CreditVantage AI and may be reviewed and updated periodically as the platform, service-provider arrangements, legal requirements, institutional client needs, and responsible AI practices evolve.

16. Trinidad and Tobago regulatory and institutional alignment

CreditVantage AI is a technology platform and is not a licensed financial institution, credit bureau, lender, debt collector, financial regulator, or final credit decision-maker.

The platform is designed to support Client Institutions in maintaining structured, reviewable, and auditable credit assessment workflows. This may assist Client Institutions with their own legal, regulatory, outsourcing-risk, confidentiality, AML/CFT, credit-file, audit, internal governance, and record-keeping obligations.

Client Institutions remain responsible for determining and satisfying the laws, regulations, regulatory guidance, internal policies, credit bureau terms, borrower consent requirements, and supervisory expectations that apply to their own use of the platform.

17. Relationship to Privacy Policy, Terms of Use, and Disclaimer

This AI Governance Policy is to be read together with the Privacy Policy, Terms of Use, Disclaimer, and any applicable subscription agreement, service agreement, order form, or other written agreement with the Client Institution.

The Privacy Policy explains how information is handled. The Terms of Use govern institutional access and user obligations. The Disclaimer explains important limitations on use of the platform and generated outputs.

This AI Governance Policy provides a plain-English governance overview of the platform workflow, data processing, AI-assisted credit analysis model, human oversight approach, and responsible AI principles.

Appendix A: Responsible AI Principles for this Platform

PRINCIPLEPLATFORM COMMITMENT
Human oversightAI supports officers and committees. Final decisions remain with the Client Institution.
Purpose limitationData is processed for credit analysis, report generation, support, security, audit, and related authorized institutional purposes.
Data minimizationThe platform is designed to avoid unnecessary personal identifiers and to suppress unnecessary exposure of personal information where reasonably possible.
TransparencyReports are designed to explain key facts, risk indicators, calculations, and reasoning in a reviewable format.
SecurityLayered technical and organizational controls are used to protect submitted data and generated outputs.
AccountabilityClient Institutions remain responsible for borrower consent, lawful use, data accuracy, report review, and final decisions.
FairnessOutputs must be reviewed for consistency, policy alignment, and avoidance of irrelevant or discriminatory factors.
AuditabilityWorkflows and reports are designed to support review by officers, supervisors, committees, and auditors.

Credit
Vantage AI

AI CREDIT ANALYST

AI-powered credit assessment support for consumer lending institutions.

GET IN TOUCH

Based in Trinidad & Tobago

© 2026 CreditVantage AI. All rights reserved.