FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Cash-Flow Underwriting: Adoption, Performance & Risk

17 min read · estimatedAI-generated analysis · Methodology
Historical version · 9 versions · Publication details

First published . This version published .

Version history

About this historical version

Added small-business cash-cycle analysis, a mortgage verification boundary and customer-process outcomes; retained the empirical research, provider comparisons, affordability examples and legal distinctions.

Compare with an earlier version →
Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
Transaction data can improve income verification and lending decisions, but value also depends on product design, customer effort and service reliability. Distinguish evidence of resources from prediction, legal eligibility and business profitability.
Why it matters
Cash-flow data can show when money arrives, where it goes and how much cushion remains between the two.Read in context
Who it affects
For a lender, that may improve a repayment assessment. For a product or operations team, it can also reveal why a payment date is inconvenient, why verification takes too long or why a customer needs an alternative way to supply evidence.Read in context
Evidence to watch
Evidence supporting expansion would include gains that persist in later , across connection sources and income patterns, after all applicant friction and costs are counted. Evidence against it would include disappearing gains outside the development sample, unstable income classification, disproportionate connection failures, unaffordable payment schedules, uncollectible expected revenue or an inability to reproduce reasons.Read in context
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

From observed transactions to a workable financial product

Cash-flow data can show when money arrives, where it goes and how much cushion remains between the two. For a lender, that may improve a repayment assessment. For a product or operations team, it can also reveal why a payment date is inconvenient, why verification takes too long or why a customer needs an alternative way to supply evidence. Better prediction is one possible benefit; a more usable financial process is another.

A household can finish a month with more cash than it started with and still be unable to make a payment during that month. That is the practical opportunity in : account activity can reveal the timing, composition and resilience of resources that a credit history alone does not describe. Turning those observations into an affordable credit offer requires several decisions beyond obtaining a score.

This article's analytical conclusion is that lenders should evaluate cash-flow underwriting against three separate outcomes: better estimates of repayment risk, payments that fit the borrower's resources, and a worthwhile return after data, operations and credit costs. An improvement in one does not establish the other two. A lender can rank applicants more accurately while setting an unaffordable payment, or reduce manual work without improving risk selection.

Primary sources were reviewed September 29, 2026. The dated launches and relationships below describe documented market development, rather than newly announced events. Vendor performance statements are attributed; worked examples and recommended controls are this article's analysis. The agencies' December 3, 2019 statement recognized potential benefits from alternative data, including bank-account cash flows, while emphasizing consumer-protection and compliance responsibilities. It did not approve every model or product. [1]

Separate income verification, risk prediction and affordability

These functions can use overlapping transactions but require different evidence. Income verification reconstructs the source and likely continuity of resources. A risk model estimates an outcome over a defined period. An affordability assessment compares resources, obligations, buffers and payment dates for the proposed product. Treating their outputs as interchangeable obscures what a lender has actually established.

An account-connection service, transaction classifier, consumer report, score and lending policy also perform different jobs. Identify who owns each transformation, which information is missing, and who can explain or correct a result. The lender still chooses the amount, price, term and decision threshold.

Scroll horizontally to see all columns.

DecisionUseful outputWhat it does not establish
Income verificationRecognized income sources, frequency, history and confidenceThat every incoming transfer is earnings or that historical income will continue
Credit-risk predictionCalibrated risk for a specified outcome, population and horizonThat a particular payment fits the applicant's budget
Affordability and product designResidual resources, minimum cash balance and stressed payment capacityThat all accounts, obligations or future shocks are visible
Operational efficiencyLess extraction work, faster decisions and fewer correctionsLower defaults or broader sustainable credit access

What the public empirical research supports

FinRegLab's July 2025 consumer study compared traditional and machine-learning models using credit-bureau and cash-flow information, separately and together. The combined approaches delivered the strongest overall results among the configurations tested. Its final modeling sample contained 424,546 observations for credit accounts opened from April 2018 through March 2019, with performance observed over twelve months. This is useful evidence that cash-flow information can add predictive value. [2, 3]

The study is an observational analysis and simulation, not a randomized lender rollout. Its sample skewed toward prime and higher-income borrowers, contained few people without conventional scores, and excluded consumers rejected on all applications. Its validation held out selected origination months within the study period rather than a separate later economic environment. Those limitations constrain claims about credit-invisible applicants, production approval gains and resilience in a different cycle. The publication discloses support from JPMorgan Chase and Capital One. [2, 3]

FinRegLab's June 2025 small-business study examined 38,021 seasoned loans from two anonymous U.S. online nonbank lenders, with included originations from February 2015 to January 2024. It found information in cash-flow measures beyond owners' personal credit scores. The lenders' eligibility rules and originated-loan sample limit generalization; this is not direct evidence of consumer-card outcomes or a causal estimate of access for all rejected businesses. [4]

The practical implication is to test incremental value in the lender's intended segment. Research evidence, a vendor backtest and a lender's seasoned production results answer different questions. None should be presented as a guarantee for another portfolio.

The provider market: compare the function before the score

The reviewed products occupy different layers. A familiar score scale does not make two models equivalent, and higher values do not always mean lower risk. A comparison needs the exact version, outcome definition, performance horizon, minimum data history and population on which the product was validated.

The table records provider descriptions, not an independent product ranking. FICO announced general availability of its next-generation UltraFICO on May 20, 2026; Plaid's reviewed documentation still labels LendScore beta. Those are distinct products even though both can involve Plaid Check. [5, 7]

Scroll horizontally to see all columns.

Provider / productDocumented functionImportant distinction
FICO / UltraFICOCombines a traditional FICO Score with permissioned cash-flow information; distributed through Plaid Check [5]A combined score; its availability does not establish lender-wide deployment
Experian / Cashflow ScoreCash-flow score using transaction data supplied by clients; 300–850 scale [6]The familiar range does not establish equivalence to another 300–850 score
Plaid Check / Consumer Report and LendScoreReports and attributes; beta LendScore ranges 1–99, higher indicating better repayment likelihood over twelve months [7]Data modules, scoring and servicing permissions have separate implementation requirements
Mastercard / Payment Risk InsightsPayment-risk score over the next 180 days; 0–100, higher indicating greater risk [8]Different direction and horizon from LendScore
Prism Data / CashScoreRisk scoring from deposit data obtained through different aggregators or client systems [9]An analytics layer does not itself solve data coverage or consent
Nova Credit / Cash AtlasCash-flow analytics used in announced underwriting relationships [10, 11, 12, 13]Keep cash-flow analytics distinct from Nova's international credit-data product
Ocrolus / statement analysisExtraction, categorization and fraud signals supporting underwriters [14]Workflow automation and risk-model performance require separate measurement

Adoption is visible; comparable performance remains harder to establish

Named relationships provide stronger adoption evidence than an unexplained customer-logo wall. Their wording still matters. An intention to implement, a selection and an account of actual workflow use are different stages. These primary announcements do not disclose comparable funded volumes, coverage rates, loss curves or independently verified causal improvements.

Ocrolus's undated TAB Bank customer story describes statement-analysis use in small-business underwriting. Its headline says a thirty-minute review became seconds, while its narrative also describes processing within minutes and continued underwriter review. Treat the story as attributed workflow evidence without converting it into a precise end-to-end productivity or loss-reduction estimate. [14]

Scroll horizontally to see all columns.

Organization and original dateWhat the source establishesBoundary of the evidence
SoFi — October 15, 2024Nova announced an expanded relationship and SoFi's intention to implement Cash Atlas in loan underwriting [10]No portfolio-wide rollout or measured credit result established by this announcement
Imprint — June 25, 2025Nova announced Cash Atlas integration through Alloy for card underwriting [11]Announcement language includes future implementation; deployment breadth is not quantified
Chase — September 3, 2025Nova announced selection of Cash Atlas and, separately, Credit Passport [12]International credit history and cash-flow analytics must not be combined into one adoption claim
PayPal — September 4, 2025Nova announced selection of Cash Atlas for U.S. consumer-credit underwriting, with BNPL discussed [13]No independently measured approval or loss improvement disclosed

Reconstruct resources before calculating ratios

Hypothetical example: an account receives $6,000 during a month—$3,600 net pay, $1,200 transferred from the applicant's savings, $800 of new borrowing and a $400 merchant refund. Calling all $6,000 recurring earnings overstates the identified pay by $2,400, or 66.7%. The savings may be a usable buffer, the borrowing creates an obligation, and the refund reverses earlier spending. Preserve each fact in its appropriate place instead of deleting useful context.

Build an auditable chain from source account and transaction through classification, derived attribute and decision. Reconcile opening and closing balances, remove duplicate pending/posted transactions and reversals, identify internal transfers without counting both sides, and distinguish gross business receipts from owner income after expenses and taxes. Record account ownership and how much history is actually available. A recently connected account does not necessarily represent the whole household.

Missing rent or debt payments may mean another account is used. A recurring deposit may be a transfer, earned wages, public assistance or support from another person. Investigate material ambiguity rather than forcing every transaction into a confident category. Test edited statements, circular transfers and temporary balances as fraud scenarios; a successful connection alone does not authenticate the economic substance of every deposit.

Protected income requires particular care. Regulation B §1002.6(b)(5) permits consideration of amount and probable continuance, but prohibits automatically discounting income on specified protected grounds or because it comes from part-time work or covered retirement sources. Its commentary requires individual assessment of protected income. A blanket rule that treats benefits or part-time earnings as unreliable is not a sound substitute for evaluating actual circumstances. [15]

Worked example: a positive monthly surplus can hide a payment shortfall

Assume a hypothetical applicant starts with $1,700, receives two $1,800 paychecks, and has $2,900 of existing monthly expenses and debt payments. A proposed $500 installment leaves a positive $200 monthly surplus. The payment is nevertheless scheduled before the first paycheck, creating a $300 cash shortfall. The table is a projected cash path, not an assumption that the bank will permit an overdraft; a negative figure indicates an unmet payment need.

Moving the proposed installment from day 3 to day 6 eliminates that shortfall under these exact assumptions, while leaving the same $1,900 month-end balance. If the first paycheck slips to day 10, the problem returns. The appropriate analysis therefore includes timing, a buffer and plausible delays. Rescheduling can address a mismatch; it cannot create income or cure a persistent deficit.

This simplified example excludes unexpected expenses, fees and payment-return effects. A production assessment needs the actual bill calendar, available funds and uncertainty around both amounts and dates. The useful output is the lowest projected available balance across the period, together with the assumptions driving it.

Scroll horizontally to see all columns.

Date / eventCash movementProjected balance
Start of monthOpening available cash$1,700
Day 1 — rent−$1,500$200
Day 3 — proposed installment−$500−$300 shortfall
Day 5 — net pay+$1,800$1,500
Day 15 — other essential expenses−$1,000$500
Day 20 — net pay+$1,800$2,300
Day 25 — existing debt payments−$400$1,900

Variable income changes the buffer and the product decision

A second hypothetical borrower earns alternating monthly amounts of $2,000 and $6,000. Average income is $4,000. With $2,500 of existing outflows and a $500 proposed payment, the average surplus is $1,000, but every low-income month consumes $1,000 of savings. Two consecutive low months require $2,000 just to cover the assumed deficits, before a safety margin. A verified $3,000 reserve and a $200 reserve support different conclusions even with the same average income.

Use history long enough to capture the applicant's actual seasonality when available, and identify whether recent strength is recurring or exceptional. A conservative percentile or stress scenario can be informative, but should not become an unexplained universal haircut. Short histories, changed employment and self-employment tax obligations need explicit treatment. Assess protected income according to the individual's circumstances. [15]

For credit cards, line size and future utilization matter. Regulation Z §1026.51 requires consideration of minimum-payment capacity based on income or assets and current obligations at opening and line increases. Its safe-harbor estimation method assumes full use of the proposed line from the first billing-cycle day; the broader rule permits a reasonable estimation method. A cash-flow score alone does not document this assessment. [17]

For a long installment loan, a low recent default forecast cannot establish affordability throughout a multi-year term. Examine payment size, income interruption, fixed versus variable pricing, emergency expenses and refinancing dependence. For short installments, the next pay cycle may be more informative, but overlapping obligations and failed-payment timing can dominate. These are product-specific analytical controls; the card rule should not be described as a universal legal test for every installment product.

A business cash cycle and a mortgage file need different interpretation

Hypothetical small-business example: a merchant receives $60,000 in monthly deposits, but $10,000 is a transfer from another owned account and $5,000 is a new loan. Operating receipts are therefore $45,000 before assessing expenses. With $35,000 of operating outflows, the apparent operating cash surplus is $10,000, not $25,000. Taxes, owner withdrawals, capital expenditure, seasonality and existing debt payments may further change the resources available. This is a classification example, not a business valuation or a lending limit.

Analysis: receipt timing also matters. A business that buys inventory before collecting sales can have healthy annual margins and still need working capital. A schedule aligned with its cash cycle may be more useful than a larger limit with inflexible payment dates. Testing such a design requires observing costs and customer outcomes; transaction history alone does not establish that the proposed terms are suitable.

Mortgage use has a separate boundary. For covered transactions, Regulation Z § 1026.43 includes repayment-ability and verification requirements, including reasonably reliable third-party records for income or assets relied upon. An account-data feed can contribute evidence; a cash-flow score does not by itself establish satisfaction of those requirements or an investor’s purchase criteria. Match the evidence to the applicable mortgage standard and the facts of the file. [20]

Evaluate vendor lift with a matched comparison

FICO's May 2026 release reports a 7% relative approval increase without incremental risk in its analysis. Experian's March 2025 release claims up to 25% predictive lift using the KS statistic in targeted risk tiers. Prism's reviewed page reports an average 30% KS-based predictive lift when adding CashScore across client portfolios. These are provider claims about different comparisons. They cannot be ranked as if they measured the same economic outcome. [5, 6, 9]

A hypothetical 7% relative improvement on a 40% approval rate produces 42.8% approval—a 2.8 percentage-point increase. It does not produce 47%. A predictive metric such as KS or area under the curve measures discrimination; it does not directly state approvals, dollar loss, borrower welfare or profit. Require definitions, denominators, confidence intervals and threshold choices before translating a claim into a business case.

Separate the contribution of new data from the contribution of a new model. Hold the target, eligible population and evaluation window consistent. Preserve historical application-time data, including the classifier and model versions, so later information cannot leak into a backtest. Evaluate calibration, losses by amount, fraud, returns, fairness and performance across income patterns, connection sources and channels.

Scroll horizontally to see all columns.

ComparisonQuestion answered
Existing model and existing dataWhat is the actual baseline policy's performance?
Comparable model with added cash-flow dataHow much incremental value comes from the data?
New model using existing dataHow much comes from the modeling change?
New model with added cash-flow dataDoes the combined gain justify the added cost and control burden?

Measure everyone offered the process, including failed connections

Track eligible applicants, those invited, consent, connection success, usable history, approval, funding and seasoned performance. Suppose, hypothetically, 70% consent, 80% of those connect and 90% of connections meet data standards. Only 50.4% of invited applicants reach usable data. An excellent result in that subset leaves the other 49.6% unresolved.

Selection can distort results: people willing and able to link accounts may differ from those who decline or fail. Report results for all invited applicants and for the usable-data subset. Where appropriate and approved within the lender's controls, randomizing the offer of an optional second look can help assess the overall process. It does not remove the need to study funding selection, missing outcomes and fair-lending effects.

Separate refusal, unsupported institutions, outages, stale permissions and genuinely insufficient history. Provide an appropriate alternative verification path and record its completion and outcomes. Treating every connection failure as financial weakness embeds technical coverage into the credit decision.

Seasoned outcomes are essential. Ten adverse outcomes among 500 loans equal 2%, but the approximate 95% Wilson interval is 1.1%–3.6%, assuming independent binary observations with complete comparable follow-up. That interval does not capture correlated shocks, selection bias, unseasoned loans or dollar severity. A promising small pilot warrants continued observation before broad rollout.

A pilot must clear an economic test after friction and loss

Hypothetical economics: 10,000 evaluation attempts at an assumed $2 data cost each cost $20,000. Another 1,000 manual reviews at $8 add $8,000. If the process produces 400 genuinely incremental funded loans with $100 expected contribution each after funding, servicing and expected credit losses, gross incremental contribution is $40,000 and the remainder is $12,000 before fixed implementation and governance costs. None of these assumptions is a vendor price quote.

The variable-cost break-even is 280 incremental loans at that $100 contribution. If only 250 are incremental, the pilot loses $3,000 before fixed costs. Count approved borrowers who would have funded through the baseline correctly; moving them between channels is not incremental growth. Recalculate contribution when lower pricing, larger balances or a different risk mix changes revenue and loss expectations.

Include failed attempts, re-pulls, minimum contractual commitments, document fallback, disputes, validation, monitoring and vendor replacement. Credit performance has a lag; reconcile forecast contribution to actual as losses emerge. Operational time saved should count only when work is truly removed or productively redeployed.

Explanations and corrections must survive the production workflow

Regulation B §1002.9 requires specific principal reasons for when reasons are provided, and rejects explanations that merely say an applicant failed internal standards or a qualifying score. Trace the actual decision through eligibility rules, fraud checks, score thresholds and affordability overlays. A vendor's reasons why its score was not higher are inputs to this process; they are not automatically the reasons for the lender's final action. [16]

A useful control is to replay sampled decisions from retained application-time records, reproduce the result, and confirm that the notice identifies what actually drove it. If payroll was mislabeled as a transfer, staff need a correction and reconsideration path. If the decision turned on missing information, do not describe the problem as low income. Apply the regulation's distinctions between incompleteness and a credit denial supported by information already available. [16]

Limit unnecessary sensitive transaction detail and govern access, retention and reuse. Identify the consumer-reporting and service-provider roles in the actual arrangement; a vendor's compliance label cannot establish the lender's compliance. Test complaints and corrections alongside model performance. A more predictive process that applicants cannot understand or correct can create material operational and customer costs.

Current governance: model risk and data access are separate questions

The Federal Reserve's April 17, 2026 SR 26-2 states that revised interagency model-risk guidance supersedes and replaces SR 11-7 and SR 21-8. It emphasizes risk-based practices tailored to the institution's model-risk profile, size and complexity; the letter says it is expected to be most relevant to Federal Reserve-regulated organizations above $30 billion in assets. Do not cite SR 11-7 as the current standalone guidance or portray as a new statutory underwriting rule. [18]

For this use case, maintain responsibility for data transformations, score versions, validation, monitoring, overrides and retirement. The depth should reflect the model's actual use and consequences. A purchased score and an internal affordability overlay can interact even if each appears reasonable in isolation. Set controls for vendor changes and degraded data before changing a decision threshold.

Data-access policy has a distinct status. The CFPB compliance page reviewed September 29, 2026 states that a court stayed the Section 1033 rule's compliance dates on October 29, 2025, and identifies the August 22, 2025 reconsideration notice. That is a stay of compliance dates, not a statement that every data-rights obligation or existing contract disappeared. Do not promise universal access based on the original timetable. [19]

Maintain a documented basis for access, clear permissions and a workable fallback if connections or contractual terms change. Origination access should not be assumed to authorize indefinite servicing surveillance. Repeated access, retention and later uses require their own review.

What would justify expansion—and what would change the conclusion?

Start with a defined decision: for example, an optional second look for a specified applicant group or a better-supported line assignment. Establish baseline outcomes, data-quality tolerances, expected economics, reasons and correction procedures before funding. Set expansion gates using mature performance, stable calibration, acceptable outcomes across relevant groups, functioning fallback and demonstrated ability to explain decisions.

Evidence supporting expansion would include gains that persist in later , across connection sources and income patterns, after all applicant friction and costs are counted. Evidence against it would include disappearing gains outside the development sample, unstable income classification, disproportionate connection failures, unaffordable payment schedules, uncollectible expected revenue or an inability to reproduce reasons.

Pause or narrow a use when those failures are material; retraining a model does not by itself repair a broken data pipeline or payment schedule. The strongest implementation makes a specific credit decision better for a defined population and can demonstrate why. The amount of data collected is a poor substitute for that evidence.

A broader success test also measures customer effort: repeated document requests, elapsed time, correction rates, completion among applicants who cannot connect an account, and whether payment schedules match observed cash timing. Faster verification is valuable when it reduces work for both the customer and the institution without weakening the evidence. If model lift is small but the process becomes meaningfully cheaper and easier, that can support a limited use; if a stronger score produces more failed applications and unresolved errors, prediction alone is an incomplete business case.

Sources

  1. Federal financial regulators — joint alternative-data statement, December 3, 2019; reviewed September 29, 2026Official releaseBack to text: ↑
  2. FinRegLab — Advancing the Credit Ecosystem, July 2025 main empirical paper; reviewed September 29, 2026Source · PDFBack to text: ↑1↑2
  3. FinRegLab — July 2025 technical appendix and sample limitations; reviewed September 29, 2026Source · PDFBack to text: ↑1↑2
  4. FinRegLab — Sharpening the Focus: Using Cash-Flow Data to Underwrite Financially Constrained Businesses, June 2025; reviewed September 29, 2026Source · PDFBack to text: ↑
  5. FICO — next-generation UltraFICO general availability and attributed performance claims, May 20, 2026SourceBack to text: ↑1↑2↑3
  6. Experian — Cashflow Score launch, scale and KS-based claim, March 25, 2025SourceBack to text: ↑1↑2
  7. Plaid — current Consumer Report / Plaid Check documentation and LendScore beta specification; undated, accessed September 29, 2026SourceBack to text: ↑1↑2
  8. Mastercard — Payment Risk Insights score and 180-day horizon, April 7, 2026SourceBack to text: ↑
  9. Prism Data — CashScore product description and attributed lift claim; undated, accessed September 29, 2026SourceBack to text: ↑1↑2
  10. Nova Credit — SoFi relationship expansion and implementation intention, October 15, 2024SourceBack to text: ↑1↑2
  11. Nova Credit — Imprint / Alloy integration announcement, June 25, 2025SourceBack to text: ↑1↑2
  12. Nova Credit — Chase selection of Cash Atlas and Credit Passport, September 3, 2025SourceBack to text: ↑1↑2
  13. Nova Credit — PayPal U.S. cash-flow underwriting selection, September 4, 2025SourceBack to text: ↑1↑2
  14. Ocrolus — attributed TAB Bank statement-analysis customer story; undated, accessed September 29, 2026SourceBack to text: ↑1↑2
  15. CFPB — current Regulation B §1002.6(b)(5) and commentary on income evaluation; accessed September 29, 2026Official textBack to text: ↑1↑2
  16. CFPB — current Regulation B §1002.9 and commentary on specific reasons and incompleteness; accessed September 29, 2026Official textBack to text: ↑1↑2
  17. CFPB — current Regulation Z §1026.51, card ability to pay and payment-estimation safe harbor; accessed September 29, 2026Official textBack to text: ↑
  18. Federal Reserve — SR 26-2 revised model-risk guidance, April 17, 2026; supersedes SR 11-7 and SR 21-8Official sourceBack to text: ↑
  19. CFPB — Personal Financial Data Rights compliance page, modified January 6, 2026; reports October 29, 2025 court stay of compliance dates; accessed September 29, 2026Official sourceBack to text: ↑
  20. CFPB, Regulation Z § 1026.43, repayment-ability and verification provisionsOfficial textBack to text: ↑

Flag an error or suggest a correction →Public corrections log →