Two years ago, a medium-sized Latin American financial institution introduced an AI-assisted credit scoring system supplied by an international technology provider. The model entered the personal loan approval process without a documented comparison with the previous system. During the first six months, the institution depended on the provider to explain specific decisions and did not obtain enough detail to verify them independently. This analysis sets out what that anonymised case reveals about algorithmic governance in the financial sector, from the perspective of audit practice.
The operational context
The Latin American financial sector is incorporating artificial intelligence into critical decisions — credit, fraud, anti-money laundering, biometric identification, customer service — at a pace its governance frameworks cannot match. The asymmetry takes a familiar form. Large and medium-sized institutions adopt models at commercial speed; regulatory frameworks and institutional risk management systems advance at administrative speed.
The opening case is not a rarity. It is the form that this gap takes when auditors encounter it in the field, with increasing regularity · algorithmic models making decisions in critical operations without a governance framework scaled to the level of risk the institution itself has just assumed.
Five technical findings from the case
| Finding | Evidence in the case | Principle compromised |
|---|---|---|
| 01 · No parallel operation | The model directly replaced the previous statistical model; the pre-production methodology omitted this stage | Principle 01 · parallel operation |
| 02 · Insufficient explainability | Compliance requested explanations for six decisions from the first quarter; the provider responded four weeks later, without sufficient detail for independent verification | Principle 02 · the adopter's own explainability capability |
| 03 · Nominal human oversight | Review of a limited sample with neither statistical representativeness nor sampling criteria; decisions were executed directly based on the model's output | Principle 03 · effective oversight |
| 04 · No drift monitoring | No technical control for model drift in a population whose behaviour changes relative to the training population | Principle 04 · drift detection |
| 05 · Broken traceability | The annual external audit fulfilled its remit regarding documented procedures; the model's behaviour in operation remained outside its scope | All four at once. The system was confirmed without being examined |
The fifth finding deserves a separate line, because it concerns the profession. The annual external review formally fulfilled its remit and saw nothing · its scope excluded technical verification of the model in operation. The documented procedure was in order; actual operation was left without a witness. Criterion 10 establishes the doctrine with the precise category ·
Four operational principles
Considered alongside other cases from the field, this one reveals four principles that serious algorithmic governance cannot delegate.
The transition requires a controlled comparison
Where justified by the criticality and nature of the change, the new model must be compared with the previous one or an equivalent control before taking over the entire decision. Duration and sample size are defined by risk, volume and the ability to detect discrepancies; there is no universal timeframe. In this case, the methodology omitted that comparison.
The organisation retains responsibility for the explanation
An institution that adopts an algorithmic model must be able to explain and review the decisions it uses, even if it contracts external technical capability. The case shows the risk of depending entirely on the provider · Compliance requested explanations for six decisions and the response arrived four weeks later, without verifiable detail. The capability must be available under conditions, timeframes and evidence requirements governed by the institution.
Human oversight must be effective
Human oversight can take three forms — effective, nominal, absent — and only the first counts (Criterion 10). Effective oversight requires three things · documented sampling criteria, authority to block model decisions and a record of the most recent blocked decision, with a date. The review in this case covered a tiny fraction of the flow, with no sampling criteria and without ever having blocked a decision · nominal oversight. Criterion 15 names the underlying issue · every sample is a theory of risk put in writing. The human review sample in this case had no theory; it had convenience.
Drift requires a detection and response rule
Drift is a foreseeable risk when the population, data or operating context change relative to training. The control must define how to detect and assess it, and how to decide whether to retrain, recalibrate or withdraw the model. In this case, there was no documented mechanism for doing so.
The limitations of the case · what it allows us to generalise
Limitations are not legal disclaimers · they are part of the argument. A piece without stated limitations claims more than it can support. This case is anonymised and is a single case. It allows three things. The questions — the five findings serve as a checklist applicable to any entity operating models in critical decision-making —, the pattern — read alongside other field cases, it is representative of a recurring configuration, without quantifying it — and the principles — which have normative support independent of the case. What falls outside the scope is also stated · sector proportions, attribution to an identifiable entity and any conclusion about the statistical performance of the model itself.
The applicable international framework
ISO/IEC 42001:2023 provides the management system framework for governing AI risks, impacts, responsibilities and monitoring. It does not explicitly prescribe the four mechanisms in this case: controlled comparison, available explainability, effective oversight and drift detection are operational criteria whose form must be justified according to risk. The accreditation chain for certification to the standard has existed since 2024 (ANAB; UKAS). For the financial sector, various Latin American authorities also publish guidelines on the use of AI in credit decisions.
The gap between the speed of technological adoption and that of governance frameworks is the most urgent area of work for auditing practice in the sector over the next decade.
The exercise for next quarter
If your entity operates algorithmic models in critical decisions, conduct a diagnostic exercise in the next quarter. Inventory all models in production. Check four components for each · a documented period of parallel operation, internal technical explainability capabilities, effective human oversight — with sampling criteria, authority to block decisions and records — and continuous drift monitoring. Each missing component means that the model operates with a governance risk above the declared institutional profile. And that no one decided this · it simply happened.
Artificial intelligence reached the financial sector before the institutional culture capable of governing it. The gap does not close on its own. It closes through technical judgement.