DSI 001Decision Standards Institute
DSI 001 · Worked example

FinCo Credit Engine

An illustrative, end-to-end read of an autonomous credit system under DSI 001. It shows how the standard produces a single governance result, and how that one result answers the different question a board, an underwriter and an investor each ask.

This is a constructed example

FinCo is not a real organisation and this is not a real assessment. It is deliberately built as a system that does not pass, because a standard that only illustrates passing systems demonstrates nothing. A DSI 001 result can be issued only by an assessor authorised by Decision Standards Institute under the DSI 001 scheme, against the methodology.

Download this worked example (PDF)

The system

A machine-learning credit decisioning system, deployed 22 months ago, that commits the organisation's capital at machine volume.

The Credit Engine assesses creditworthiness, issues approve and decline decisions, sets loan terms within a parameter range, and commits capital for approved applications. It runs at Level 3 operational autonomy: it executes consequential decisions within defined parameters without per-decision human authorisation. Human review exists only as an exception path. In practice two analysts review roughly 300 applications a week against more than 5,000 automated decisions in the same period, so oversight is supervisory, not authorial, for about 95 per cent of the credit decisions made.

~94%
Decided autonomously
of retail loan applications, with no per-decision human sign-off.
AUD 250k
Committed per decision
the capital the engine can commit without human authorisation.
22 months
Since last reassessment
run against no defined governance framework in that time.

Where governance exists, and where it does not

Before scoring, DSI 001 maps the decision supply chain: the path a decision travels from data to capital commitment, and the governance layer that should exist at each stage. FinCo's governance operates at the policy and reporting layers. It is absent at the three stages where the engine's autonomous authority is greatest.

StageFinCo implementationGovernance present?
Data inputsApplication data plus historical repayment data used for fine-tuningPartial. Provenance incomplete for fine-tuning data.
Model processingFoundation model fine-tuned over 14 months; quarterly retrainingAbsent. Retraining is not treated as a governance trigger.
Decision formationAutonomous approve or decline, with loan terms set in rangeAbsent. AE3 not recognised; no scope-boundary documentation.
ExecutionCapital commitment up to AUD 250,000 without sign-offAbsent. No audit trail adequate for governance purposes.
Institutional exposureBalance-sheet exposure across roughly 5,000 decisions a weekAbsent. Liability architecture does not address AE3 at this volume.

The dimensional profile

DSI 001 reads the system across six dimensions. The profile concentrates risk in contract infrastructure and liability architecture, the two stages where the engine acts with the least governance.

DimensionWhat the assessment foundExposure
D1 AutonomyLevel 3 execution; oversight supervisory for about 95 per cent of decisions; commitment authority to AUD 250k with no per-decision sign-off.Elevated
D2 DataFinancial and identity data in production; training-data provenance partly documented; consent basis for historical repayment data not fully evidenced.Moderate
D3 ContractNo AI-specific provisions in any material agreement; no audit rights over the model provider; customer documentation does not represent how decisions are made.Elevated
D4 LiabilityAE3 not recognised; a recourse process that implies a human review which does not occur at volume; insurance that excludes the actual exposure.Highest in the assessment
D5 LeverageThe lending line depends on the engine running across roughly 5,000 decisions a week; scope-restriction protocols are not defined.Moderate
D6 StabilityQuarterly retraining is not treated as a governance event; reassessment triggers are undefined; no reassessment in 22 months.Elevated
Result
GBI 3.42
Not Compliant

On the 1.0 to 5.0 scale, where lower is stronger, the composite sits above the 2.50 threshold for Compliant. At this governance posture, a board or reliance party would have a clear basis to withhold scale expansion pending remediation.

Why the weaknesses compound

The result is not the average of the six dimensions. Some governance weaknesses amplify others, and where they combine the standard treats the exposure as systemic rather than additive. Two compounding conditions are active in this profile.

Systemic Escalation

High-volume autonomous commitment combined with an unrecognised and uninsured liability category. The system makes consequential decisions at machine volume while the liability governance needed to manage their consequences does not exist.

Infrastructure Collapse

Significant autonomy combined with the absence of AI-specific provisions in any material agreement. There is no contractual infrastructure through which liability for autonomous decisions can be allocated, and no audit rights over the model provider on which the system depends.

Individual governance weaknesses are manageable. Compound weaknesses are systemic.

The evidence behind the claims

DSI 001 reads not only the risk posture but whether the governance could be demonstrated rather than asserted. Under EIS-01 the evidence is graded across the system lifecycle: design, deployment, operation and outcome.

Design
Partial
Architecture and pre-deployment testing exist; no prior classification record.
Deployment
Absent
No record that governance was assessed before go-live.
Operational
Inadequate
Engineering telemetry exists; governance telemetry does not.
Outcome
Absent
No contemporaneous record of decisions reviewed against governance.
Reconstruction risk is high

Where the only available source for a control is a management representation made after the fact, DSI 001 records the control as not evidenced. A governance claim that cannot be demonstrated from contemporaneous records is not a governance claim the standard can credit.

One result, four audiences

The same finding answers the different question each institution asks. This is not four assessments. It is one assessment, applied to four governance questions.

AudienceWhat the one result tells them
BoardNot Compliant. At this governance posture a board would have a clear basis to withhold scale expansion pending remediation, to establish an oversight committee (AIOC), and to report the GBI to the board each quarter until Compliant. The result also forms part of the record a director would point to on the question of what was known and what was done.
InsurerLevel 3 autonomy with three live coverage gaps: a professional-indemnity AI carve-out, a technology errors-and-omissions limitation on autonomous decisions, and no treatment of AE3 at all. This may support a move from conditional review during remediation toward standard review once a Compliant result is issued, subject to the insurer’s own underwriting process. It does not determine cover, terms or price.
InvestorA governance deficit relevant to valuation and to deal terms, with a remediation timeline and milestones that can be written into the agreement as conditions and monitored to exit.
ProcurementA system-level classification that the vendor is not yet suitable for a regulated buyer's reliance process without remediation, with a defined path to adequacy rather than a pass or fail on the vendor's name.

The remediation pathway

The same assessment sequences the work. The profile points to contract and liability first, because that is where the compounding exposure sits.

WindowWorkDimensionsMilestone
Months 1 to 2Contract renegotiation: AI-specific provisions, audit rights, AE3 liability allocationD3, D4Agreements updated; AE3 recognised; provider AI-liability exclusion addressed
Months 2 to 4Oversight committee established; accountability documented; operational evidence programme begunD1, D6Decision log active; anomaly escalation operational; reassessment triggers defined
Months 3 to 5Training-data provenance documented; consent basis evidencedD2Provenance held; legal basis recorded for each data category
Months 5 to 7Commercial-leverage review; scope-restriction protocols; board reporting cadenceD5Board receives periodic GBI; escalation defined
Months 6 to 9Formal reassessment by the assessorAll sixTarget: GBI at or below 2.50 (Compliant)

In the worked example, deployment authorisation is withheld pending remediation, and the target is Compliant within 12 months of the first assessment.

The point

This is what DSI 001 produces: one defensible, portable result that a board can act on, an underwriter can evaluate, and an investor can condition a deal on, with a sequenced path to a stronger position. A framework that only illustrates passing systems is marketing. A standard has to be able to read the systems that do not pass, and show the remediation sequence required to move toward a stronger classification.

Status and limits. This is an illustrative worked example, not a real assessment, and not legal, insurance or financial advice. FinCo is constructed. A GBI result is authentic only when issued by an assessor authorised by Decision Standards Institute under the DSI 001 scheme, against the methodology; self-scored or indicative figures are not DSI 001 results. DSI 001 does not determine legal compliance, regulatory approval, insurability, creditworthiness, or the discharge of fiduciary duties. It provides a scoped governance classification and evidence record that may be relevant to those analyses.