FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Cash-Flow Underwriting: Adoption, Performance & Risk

16 min read · estimatedAI-generated analysis · Methodology
Historical version · 9 versions · Publication details

First published . This version published .

Version history

About this historical version

Expanded the September 29 review with provider roles, dated adoption evidence, small-business research, score comparability and the current data-rights timetable. Retained the earlier worked examples and validation framework.

Compare with an earlier version →
Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
A market map of cash-flow data, scores and analytics; documented lender adoption; and practical tests of affordability, evidence quality and implementation cost.
Controls, consent and operational costs
must connect the actual decision to understandable reasons. A vague reference to cash-flow risk does not by itself explain whether the issue was insufficient income, volatile inflows, existing obligations or missing information. Model feature importance can inform analysis, but operational notices need legal review for the applicable product and decision.Read in context
Who is adopting: separate selection, intent and implementation
Original announcement dates are retained. These are company releases with named customer participation or a vendor/customer case study, not independent audits of portfolio outcomes. The evidence supports the stated relationship; it does not support a universal rollout, a measured adoption rate or equivalent credit results across these lenders.Read in context
Limits of the evidence

The study excludes applicants rejected on every application during the sampled period, so it cannot observe how all rejected applicants would have performed. The report also discusses sample and generalizability limits. Its appendix compares logistic regression and XGBoost across different information sets, providing a useful way to separate the contribution of data from that of model architecture. Neither method makes an affordability determination automatic. [2][3]Read in context

0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

A bank statement can answer several different questions

uses transaction and balance information to assess repayment capacity or risk. It can reveal recurring income, essential expenses, volatility and buffers that a traditional credit file does not fully capture. But observed inflows are not automatically income, and successful collection is not the same thing as affordable repayment. Those distinctions are especially important for gig workers, seasonal earners and households moving money among several accounts.

Federal banking agencies and the CFPB acknowledged potential benefits and compliance considerations in their December 2019 alternative-data statement. [1] FinRegLab's July 2025 empirical research examines machine learning and cash-flow information in consumer underwriting. [2][3] These sources support evaluating the approach; they do not establish that every vendor model, product or borrower segment will experience the same improvement. This article makes no universal approval-lift or loss-reduction claim.

Market status: available products, uneven adoption

As of September 29, 2026, has commercially available scores, transaction analytics and document-analysis products, alongside named lender partnerships. FICO announced general availability of its next-generation UltraFICO on May 20, 2026; Experian launched Cashflow Score in March 2025. Those are product milestones, not measures of industry penetration. Plaid’s separate LendScore remains labeled beta in the documentation reviewed for this article. [7][8][9]

Our assessment is that the market has moved beyond a single experimental technique into several distinct buying decisions: obtain permissioned data, classify it, estimate repayment risk, test affordability and integrate the result into policy. The strongest public adoption evidence below identifies specific relationships and their announced scope. It does not establish what share of applications uses cash-flow analysis, how much lending is incremental, or whether every announced integration has reached full production.

The immediate opportunity is often a defined second-look population, an income-verification bottleneck or a small-business statement-review workflow. A whole-book replacement of existing underwriting requires a much stronger portfolio-specific case. A useful launch can improve processing without changing the approval model; a better risk rank can still leave an applicant unable to afford the proposed payment.

Who is in the market—and what each layer does

These are illustrative providers with inspected product descriptions, not a market-share ranking or an exhaustive directory. Products sold by the same company can have different data rights, score definitions and deployment maturity.

Scroll horizontally to see all columns.

Provider / productRole and verified scopeImportant boundary
FICO + Plaid / UltraFICOCombines traditional FICO information with permissioned cash flow; distributed through Plaid Check. General availability announced May 20, 2026. [7]Distinct from Plaid LendScore. Broad use of traditional FICO scores does not establish adoption of this product.
Experian / Cashflow ScoreTransaction-based score on a 300–850 scale, launched March 25, 2025; clients supply transaction information for processing. [8]A product launch and vendor validation are not proof of realized loss improvement at a named lender.
Plaid Check / LendScore and report modulesLendScore beta: 1–99, higher is better, with a 12-month default horizon; report modules provide cash-flow and other attributes. [9]Confirm beta access and change controls. Raw observations, income attributes and predicted default are different outputs.
Mastercard / Payment Risk InsightsPayment-risk score described on April 7, 2026: 0–100, higher is riskier, with a 180-day horizon. [10]Opposite score direction and a different horizon from LendScore; thresholds are not interchangeable.
Prism Data / CashScoreDeposit-account-data risk scoring; its current description supports data from aggregators or directly from the client. [11]Assess the exact score version, training population and lender-specific performance; no market-share inference.
Nova Credit / Cash AtlasCash-flow analytics and underwriting integration with named selections discussed below. [12][13][14][15]Do not count customers of income-verification or cross-border credit products as Cash Atlas adopters.
Ocrolus / statement analyticsDocument extraction, transaction analysis and fraud-review support; TAB Bank is a named implementation example. [16]Reduced document handling does not by itself establish more accurate credit decisions.

Who is adopting: separate selection, intent and implementation

Original announcement dates are retained. These are company releases with named customer participation or a vendor/customer case study, not independent audits of portfolio outcomes. The evidence supports the stated relationship; it does not support a universal rollout, a measured adoption rate or equivalent credit results across these lenders.

Scroll horizontally to see all columns.

Lender / customerDated evidenceWhat it establishes—and leaves open
SoFiOctober 15, 2024: expanded Nova Credit relationship. [12]Stated intent to implement Cash Atlas for loan underwriting. The announcement alone does not establish the later production share.
ImprintJune 25, 2025: Cash Atlas integration announcement. [13]Planned use in co-branded-card underwriting through Alloy’s workflow. No realized approval or loss outcome supplied here.
Chase, JPMorgan Chase’s consumer businessSeptember 3, 2025: selected Nova Credit solutions. [14]Cash Atlas was selected alongside the separate Credit Passport product. Selection does not mean every Chase card application uses cash-flow scoring.
PayPalSeptember 4, 2025: Cash Atlas selection. [15]Announced U.S. consumer-credit use, including buy now, pay later. No verified portfolio-wide utilization or comparable loss series.
TAB BankUndated Ocrolus case study, reviewed September 29, 2026. [16]Describes implemented statement analysis and less manual review, with a named bank executive. The page’s speed claims vary between its headline and narrative; this article does not treat them as an independently measured service-level guarantee.

Small-business evidence broadens the case, with limits

FinRegLab’s June 2025 study examined 38,021 loans from two anonymous U.S. online nonbank lenders, covering originations between February 2015 and January 2024. The analysis found incremental predictive information in bank-statement cash-flow data beyond owners’ personal credit scores, with particular relevance to lower-score borrowers and younger firms. Its nonperformance outcome includes more than , and loans without sufficiently resolved outcomes were excluded. [17]

This supports testing a specific information advantage; it is not a randomized estimate of how many additional businesses will receive sustainable credit. A lender still needs to handle seasonality, owner transfers, payroll taxes, merchant-processor deductions and other debts before converting gross receipts into available debt service. Validate consumer and business products separately: the unit of analysis, obligation structure and outcome definition differ.

Why headline performance claims cannot be put on one leaderboard

FICO reports relative approval and predictive-performance findings for UltraFICO; Experian’s Cashflow Score release describes predictive lift using a ranking statistic; Mastercard describes an analysis involving an unnamed regional card issuer. These are vendor-reported results with different populations, metrics and comparison points. They cannot be combined into a single percentage improvement or treated as independently observed lender outcomes. [7][8][10]

Require a comparison sheet that fixes the eligible population, observation window, performance horizon, or loss definition, approval rate, pricing and connection completion. Then ask whether the result holds out of time, after costs, and across relevant groups. A higher separation statistic may help ranking while adding little value at the lender’s actual approval cutoff. Faster statement review may have value even without a credit-loss benefit.

The main adoption barriers now

Data completeness is a business constraint. Applicants may keep income and spending in different accounts, decline permission, fail to connect or supply too little history. A model evaluated only on successful connections can overstate the benefit to the full applicant population. Transfers, refunds, loan proceeds and business-owner movements need consistent treatment; otherwise the system can mistake borrowed or recycled cash for recurring capacity.

Governance includes explainable decisions, suitable reasons, fair-lending testing and the responsibilities attached to a chosen consumer-reporting arrangement. Buying a report does not resolve the lender’s own policy obligations. The current Regulation B notification requirements and the institution’s applicable model-risk framework remain relevant; product-specific legal analysis may be needed. [5][6]

Data access remains an unsettled implementation variable. The CFPB’s current compliance page states that a court stayed the Personal Financial Data Rights rule’s compliance dates on October 29, 2025, and identifies an August 2025 reconsideration process. That is a stay of the compliance timetable, not a conclusion that voluntary permissioned sharing is prohibited or that a replacement rule has been finalized. Contracts, permission scope, retention and access economics still need attention. [18]

Commercial adoption also depends on who pays for retrieval, reconnection, exception review and ongoing monitoring; whether a purchaser or funding partner accepts the resulting loans; and whether the application experience loses otherwise good borrowers. Public product pages generally do not supply a normalized all-in price. Compare cost per completed decision and incremental performing loan, not just the cheapest advertised data call.

What the empirical evidence establishes—and what it does not

FinRegLab’s July 1, 2025 study used anonymized bureau and aggregator records linked to new credit accounts opened in 2018–2019. Its hybrid machine-learning model was the strongest overall predictor among the tested alternatives and produced comparatively favorable simulated access results at many risk thresholds. These are historical modeling results, not a live randomized rollout or evidence that today’s particular vendor will reproduce them. The project page identifies support from JPMorgan Chase and Capital One. That funding context belongs alongside the results. [2][4]

The study excludes applicants rejected on every application during the sampled period, so it cannot observe how all rejected applicants would have performed. The report also discusses sample and generalizability limits. Its appendix compares logistic regression and XGBoost across different information sets, providing a useful way to separate the contribution of data from that of model architecture. Neither method makes an affordability determination automatic. [2][3]

For a prospective deployment, define the outcome before examining performance. A score predicting serious answers a different question from a budget test asking whether repayment leaves enough money for essential expenses. Also track hardship, repeated overdrafts, payment reversals and complaints where lawfully available. A low default rate achieved by collecting ahead of rent is not, by itself, evidence of a better consumer outcome.

Reconstruct income before estimating capacity

A useful pipeline identifies the account owner, observation period, missing intervals and transaction source. It then distinguishes wages and benefits from transfers, loan proceeds, refunds and reimbursements. Counting an advance as recurring earnings can create a feedback loop in which borrowing appears to improve affordability. Counting a transfer twice can produce a similar error across linked accounts.

Classification uncertainty should remain visible. A payment platform deposit may combine sales, reimbursements and transfers. A business owner's gross receipts may precede substantial operating expenses and taxes. A lender should not silently treat every ambiguous credit as disposable household income. Conservative treatment, documentation requests or a transparent manual review can be preferable to false precision, depending on the product and stakes.

Observation coverage also affects interpretation. A single account may capture payroll but omit rent paid elsewhere, or show spending while income arrives in another account. A new account's short history can make a stable household appear volatile. Conversely, a long history can hide a recent job loss if the model gives too much weight to older months. Coverage and recency belong in both the decision and its explanation.

Build features that preserve the meaning of money

Illustrative monthly statement: $6,000 of credits consists of $3,600 net payroll, $1,200 transferred from the applicant’s own savings, $800 of new borrowing and a $400 merchant refund. Treating all credits as income overstates recurring earnings by $2,400, or two-thirds of the payroll figure. The transfer may support a buffer, but it should not simultaneously increase recurring income and available assets without reconciling both accounts.

Likewise, avoid counting a card payment and the purchases it repays as two separate consumption expenses when both the card and deposit data are linked. Debt-service cash needs still matter; the feature definition must state whether it measures consumption, contractual payments or actual cash outflow. Reversals, reimbursements and disputed transactions need explicit treatment. Store confidence flags alongside classifications so uncertain data can lead to a different process rather than a fabricated exact answer.

Scroll horizontally to see all columns.

FeatureUseful calculationTest before use
Recurring net incomeIdentified earnings after reversals, separated from transfers and financingManually reconcile a representative labeled sample
Income variabilityDispersion and low-income periods over a stated observation windowTest seasonal patterns and short histories separately
Liquidity bufferAvailable balances after known near-term obligationsCheck linked-account duplication, restricted funds and pending debits
Payment capacityCash available on relevant due dates under a stated stressDistinguish new payment from obligations already counted
Data completenessAccounts, days and fields actually observedKeep unavailable data separate from a measured zero

Worked example: average income conceals timing risk

Consider a hypothetical applicant with six monthly net-income observations of $2,000, $6,000, $2,000, $6,000, $2,000 and $6,000. The mean is $4,000. Assume essential monthly expenses of $2,500 and a proposed payment of $500. An average-based calculation shows a $1,000 monthly surplus. Yet every low-income month has a $1,000 deficit before any unexpected expense.

With a reliable $3,000 starting cash buffer and income arriving on schedule, the household may bridge those troughs. With only $200 available or delayed customer payments, the same average income can produce missed obligations. Neither assumption should be invented from the average. The analysis needs observed balances, payment timing, existing debt and the borrower's ability to access the buffer.

The example does not prescribe a regulatory affordability formula. Requirements differ across products, and a mortgage analysis has specific rules. It demonstrates an analytical distinction between a probability-of-default prediction and a budget stress. A model can rank repayment risk well while failing to show how a household manages the worst weeks of its cash cycle.

Design a test that separates data value from model value

To evaluate performance, compare a baseline using established information with a model adding cash-flow features, keeping the outcome window and population comparable. Separately test whether changing the modeling method improves results. Otherwise a reported benefit may conflate richer data with more flexible algorithms. FinRegLab's main report and technical appendix are useful methodological references, not a substitute for validation on the lender's own intended use. [2][3]

Out-of-time testing matters because income patterns, fraud behavior and economic conditions change. Evaluate thin-file applicants, irregular earners and incomplete-data cases separately where sample sizes permit. Prevent leakage from transactions recorded after the decision or from outcomes that would not have been known at origination. Document exclusions so the reported result is not driven by quietly removing difficult cases.

Selection bias is another limit. Applicants willing and able to connect an account may differ from those who cannot or decline. Outcomes observed only among approved borrowers do not automatically reveal performance for rejected applicants. An evaluation should explain these boundaries rather than translating a strong retrospective score into a claim of proven broad access gains.

Controls, consent and operational costs

Recommended controls include permission tracking, data minimization, retention limits and a fallback for connection failures. Validate account ownership and monitor changes in aggregator coverage. Retain the data and feature versions necessary to reconstruct a decision without collecting unrelated information indefinitely. A correction process should address misclassified income or missing accounts as well as conventional credit-report disputes where applicable.

must connect the actual decision to understandable reasons. A vague reference to cash-flow risk does not by itself explain whether the issue was insufficient income, volatile inflows, existing obligations or missing information. Model feature importance can inform analysis, but operational notices need legal review for the applicable product and decision.

Costs include data access, connection support, classification review, validation and handling applicants with incomplete coverage. More data can improve decisions while increasing privacy exposure and technical dependencies. A lender should evaluate net economics after those costs and after any additional manual reviews, not solely an offline discrimination statistic.

Choose the product and prove the net benefit

An installment decision commits the borrower to a fixed schedule, often beyond the available transaction history. Stress both the low-income month and the persistence of a reduced income level. Revolving credit adds uncertainty about future utilization, rates and minimum-payment rules. A low current balance does not establish that a large line is affordable if the borrower draws it after an income shock. Initial line setting and later line management therefore need different tests.

Hypothetical pilot economics: assume 10,000 applicants incur $2 each in data costs and 1,000 require an additional $8 manual review. Variable cost is $28,000. If the pilot produces 400 additional funded loans with an assumed $100 contribution per loan after expected credit loss, funding and servicing, the incremental contribution is $40,000 and the remaining benefit is $12,000 before fixed integration and validation expense. Break-even requires 280 such loans. Lower take-up or worse incremental losses can erase the benefit even if model discrimination improves.

For model governance, the current Federal Reserve reference is SR 26-2, issued April 17, 2026, which supersedes SR 11-7 and SR 21-8. Its applicability statement says the guidance is expected to be most relevant to Fed-regulated organizations above $30 billion in assets and emphasizes tailoring. Do not present a historical SR 11-7 checklist as the unchanged current standard. [5] Proportionate controls still include independent challenge, decision reconstruction, feature-version control and monitoring tied to the actual use.

Regulation B requires specific reasons for under its notification framework; saying that an applicant failed an internal standard is insufficient. [6] As an implementation test, trace a sample of notices back to the features that actually determined the outcome. Check that a missing bank connection has not been mislabeled insufficient income, and that manual overrides and alternative evidence are governed consistently. A model explanation is useful only when it faithfully describes the decision being communicated.

Evidence that would change the conclusion

Consistent out-of-time improvement, stable classifications, explainable decisions and measured outcomes across relevant applicant groups would support deployment. Fragile performance under missing data, unexplained disparities, frequent income misclassification or customer harm despite low defaults would weaken the case. The strongest conclusion is conditional: cash-flow data can add useful evidence, provided the lender demonstrates which question it answers and where the evidence stops.

Evaluate the whole applicant funnel

Recommended pilot reporting begins before account connection. Track eligible applicants, invitations, consent, successful connections, usable histories, decisions, take-up and observed outcomes. A benefit measured only among clean connected records cannot be assumed for everyone who applied.

When feasible and lawful, randomize an invitation or phased rollout among otherwise eligible applicants, retaining a safe established decision process. Analyze results according to the assigned group as well as actual usage, and explain noncompliance and missing outcomes. This is a proposed evaluation design, not evidence that a lender has run such a trial. Do not randomize away required protections or infer rejected applicants’ loan performance from nonexistent loans.

Scroll horizontally to see all columns.

StageMeasureInterpretation limit
Invitation and consentShare offered and share consentingWillingness to connect may be selective
ConnectionSuccessful and failed connectionsTechnical coverage is not financial capacity
DecisionApproval and terms by assigned groupDifferent populations can confound comparisons
Take-upFunded loans among offersApproval lift is not funded access
PerformanceMature comparable outcomesShort observation misses later losses
Customer experienceComplaints, hardship and correctionLow default alone does not prove affordability

Report uncertainty around the pilot result

Hypothetical: 10 of 500 funded loans reach a defined adverse outcome, an observed rate of 2%. A Wilson 95% interval is approximately 1.1% to 3.6%. That interval illustrates sampling uncertainty under a simple binomial model; it does not capture selection bias, correlated shocks, censoring or mismeasured outcomes.

If the expected advantage over the baseline is small, 500 loans may not distinguish improvement from noise. Set the comparison, observation window and minimum detectable effect before reading results. Do not repeatedly inspect outcomes and stop at the first favorable result without an appropriate statistical design. Report both statistical uncertainty and economically meaningful loss differences.

Missing data needs an operationally fair fallback

Recommended controls separate a declined consent request, a provider outage, an unsupported institution and a genuinely short account history. None automatically means zero income. Record the reason and offer appropriate alternative evidence under the product’s policy and applicable law.

Compare processing time, approval rates, terms and complaints for connected and fallback paths, acknowledging selection limits. Audit whether staff classify the same missing-data condition consistently. A technically stronger model can still deliver a worse product if difficult-to-connect applicants face unexplained delays or inaccurate reasons. Evaluate these frictions alongside credit performance and the earlier break-even economics.

Sources

  1. Federal Reserve and other agencies, joint alternative-data statement; December 3, 2019Official releaseBack to text: ↑
  2. FinRegLab, Advancing the Credit Ecosystem: Machine Learning & Cash Flow Data in Consumer Underwriting; July 1, 2025Source · PDFBack to text: ↑1↑2↑3↑4↑5
  3. FinRegLab, accompanying technical appendix; July 2025Source · PDFBack to text: ↑1↑2↑3↑4
  4. FinRegLab, research project and publication record; July 1, 2025SourceBack to text: ↑
  5. Federal Reserve SR 26-2, Revised Guidance on Model Risk Management; April 17, 2026; supersedes SR 11-7 and SR 21-8Official sourceBack to text: ↑1↑2
  6. CFPB, Regulation B §1002.9, notifications and specific adverse-action reasons; current text checked September 27, 2026Official textBack to text: ↑1↑2
  7. FICO: next-generation UltraFICO general availability; May 20, 2026; company announcementSourceBack to text: ↑1↑2↑3
  8. Experian: Cashflow Score launch; March 25, 2025; company announcementSourceBack to text: ↑1↑2↑3
  9. Plaid Check documentation; undated current product status reviewed September 29, 2026SourceBack to text: ↑1↑2
  10. Mastercard: Payment Risk Insights and cash-flow analytics; April 7, 2026; vendor analysisSourceBack to text: ↑1↑2
  11. Prism Data: CashScore product description; undated, reviewed September 29, 2026SourceBack to text: ↑
  12. Nova Credit and SoFi: expanded relationship; October 15, 2024SourceBack to text: ↑1↑2
  13. Nova Credit and Imprint: Cash Atlas integration announcement; June 25, 2025SourceBack to text: ↑1↑2
  14. Nova Credit: Chase selection; September 3, 2025SourceBack to text: ↑1↑2
  15. Nova Credit: PayPal selection; September 4, 2025SourceBack to text: ↑1↑2
  16. Ocrolus: TAB Bank implementation case study; undated, reviewed September 29, 2026; vendor/customer accountSourceBack to text: ↑1↑2
  17. FinRegLab: Sharpening the Focus, small-business cash-flow underwriting study; June 2025Source · PDFBack to text: ↑
  18. CFPB: Personal Financial Data Rights compliance resources; current court-stay notice checked September 29, 2026Official sourceBack to text: ↑

Flag an error or suggest a correction →Public corrections log →