Artificial Intelligence Policy
Last updated: August 18, 2026 · Preliminary version
1. Where we use AI
Cauce applies AI models at four points of the credit conveyor:
- Extraction — normalising Open Banking and alternative-source data obtained with the applicant's consent.
- Profiling — hybrid scoring (traditional + alternative) with feature attribution.
- Compliance (CASE) — verifying KYC/due diligence, sanctions and PEP lists, consent, limits and internal policy through an LLM-as-a-judge design.
- Routing — matching and ranking offers compatible with each institution's rules.
2. What Cauce's AI does not do
- It does not make the credit decision. It delivers verifications and evidence; the decision — and its justification to the applicant — belongs to the lender.
- It does not replace the bureau or issue an official score with regulatory effect.
- It does not operate unsupervised: no change reaches production without prior validation.
- It does not use applicant data for purposes outside the service contracted by the lender.
3. Explainability and auditable trail
Every verification produces a human-readable explanation traceable back to source data, together with a trace identifier tied to the transaction. The trail records what was checked, with which data, under which model and rule versions, and with what result, so that internal governance and the supervisor can reconstruct the decision. No black boxes.
4. Human oversight and governance
Verifications are reviewable by people: the lender can inspect, challenge and override any result before deciding. We maintain environment separation, version control over models and rules, and change logging. Applicants retain the right to request human review of a decision with significant effects from the responsible institution.
5. Self-evolution under control
The system follows a run → evaluate → modify → verify → retain cycle. Every modification is generated and tested in a sandbox, must pass CASE validation before reaching production, and remains subject to rollback and human oversight. The system never changes itself live or without a record.
6. Open measurement: CACE-Bench
AI quality is measured with CACE-Bench, an open, reproducible benchmark over synthetic cases, with a byte-identical reference run and declared version and seed, published with a DOI (10.5281/zenodo.21394049). Anyone can reproduce the figures. We do not publish quality metrics that cannot be verified this way.
Benchmark results are obtained on synthetic data and do not guarantee identical production performance, which depends on each institution's data and configuration.
7. Data, bias and fairness
We work with data minimisation and evaluate model behaviour by segment and jurisdiction to detect unjustified disparities. Alternative data is used to widen credit access for those the bureau cannot see, not to narrow it. Where a material bias is found, we document the incident, the correction applied and its verification.
8. Known limits
Language models can produce errors and hallucinations. That is why we explicitly measure the hallucination rate, compliance false positives and the share of decisions taken without sufficient data, and publish how these evolve. A Cauce output is a verification with evidence, not an infallible certification.
9. Regulatory framework
The compliance engine is designed to map its metrics to regional frameworks and to explainability (XAI) and data-protection requirements: Bacen (Brazil), CNBV (Mexico), SFC (Colombia) and Ecuador's Superintendency of Banks, alongside available AI regulatory sandboxes. This document does not replace the obligations of each supervised institution.
10. Incidents and contact
If you find an incorrect result, unexpected model behaviour or possible bias, write to [email protected] quoting the trace identifier. We investigate, document and communicate the fix to affected institutions.
[email protected]