RecommendationHigh riskComparison recommended

AI Decision Audit for Regulatory Inquiry Playbook

A bank's AI-powered fraud detection system flagged and froze 840 customer accounts in a 48-hour period. Customers are complaining and the OCC has requested a full audit trail of every account freeze decision, including which model made the determination, what factors drove the score, and what human review occurred.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A bank's AI-powered fraud detection system flagged and froze 840 customer accounts in a 48-hour period.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Decision Audit for Regulatory Inquiry".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • AI fraud detection system logs (840 freeze events: model scores, features, decision timestamps)
  • Human review records for freeze decisions
  • Customer complaint log
  • OCC guidance on AI model governance and audit trails
  • Bank's fraud operations procedures manual

Attachments: Documents (Documents)

The Prompt

You are an AI governance specialist preparing a regulatory audit response for an OCC inquiry into AI-driven account freezes. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Reconstruct the decision trail for each of the 840 freeze events: what model score triggered the freeze, what features drove the score, and what human review occurred?
2. Identify the false positive rate: how many of the 840 freezes were reversed after customer contact, and what feature patterns drove the false positives?
3. Assess the human-in-the-loop compliance: did the bank's procedures require human review before freezing, and was it followed?
4. Prepare the OCC response: organize the audit trail in the format that demonstrates model governance compliance.
5. Tell me what process changes are needed to prevent a repeat and how to frame the corrective action plan for the OCC.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Per-event decision trail reconstruction
  • False positive analysis with feature patterns
  • Human-in-the-loop compliance assessment
  • OCC response organization
  • Corrective action plan and process change recommendations

Review before you act

  • Validate this output against source files before relying on it: Reconstruct the decision trail for each of the 840 freeze events: what model score triggered the freeze, what features drove the score, and what human review occurred?.
  • Validate this output against source files before relying on it: Identify the false positive rate: how many of the 840 freezes were reversed after customer contact, and what feature patterns drove the false positives?.
  • Validate this output against source files before relying on it: Assess the human-in-the-loop compliance: did the bank's procedures require human review before freezing, and was it followed?.
  • Validate this output against source files before relying on it: Prepare the OCC response: organize the audit trail in the format that demonstrates model governance compliance.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Decision Audit for Regulatory Inquiry, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface per-event decision trail reconstruction; false positive analysis with feature patterns; human-in-the-loop compliance assessment; occ response organization. Those are comparison artifacts — they only exist if more than one model runs. Reconciliation protocols exist because models disagree. The playbook's job is to make disagreement inspectable, not to hide it behind a single blended answer.

AI Governance LayerAudit and Vendor TermsRecommendationHighDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.