Criterica Group — The institutional data science platform for regulated outcomes. A Splitifi company.
Governance

The Two Audit Trails: Predict and Underwrite

A prediction record and an underwriting record answer different questions and have to exist as separate, timestamped artifacts, or no one can tell a bad model from a bad price after the fact.

September 2026

Every position an institution deploys capital against leaves behind two records that describe two different decisions, and in most legal-asset finance operations those two records are compressed into a single memo written after the fact, when someone needs to explain what happened. The compression is where accountability disappears, because a single memo can always be written to make the outcome look like the inevitable consequence of the facts, whether or not that is true. The discipline this market actually requires is keeping the two records separate from the moment each one is created, not reconciling them into a tidy narrative once a result is already known.

The first record is the prediction. It states, for a matter with a defined set of characteristics, a probability distribution over resolution classes and a distribution over time to resolution, produced by a model with a specific version identifier, run against a specific set of inputs, at a specific timestamp. Captured correctly, this record exists before anyone on the capital side has seen the number, and it does not change after that point regardless of what the capital side later wants it to say. A prediction record that can be regenerated with different assumptions after the desk expresses a preference is not a prediction record; it is a negotiating position wearing a model's output format.

The second record is the underwriting decision. It states the price, the structure, the capital committed, the cost of that capital, and the portfolio context the position was evaluated against, all captured at the moment capital was actually committed. This record should reference the specific prediction record it relied on, by version and timestamp, so that a reviewer can later confirm exactly which distribution the desk was pricing against, rather than reconstructing it from memory or from a document written well after the fact to justify a result that had already occurred.

Keeping these as two artifacts rather than one matters because a single merged document allows the sequence of events to be rewritten quietly. A memo drafted after a difficult resolution can present the underwriting price as a direct, obvious consequence of the prediction, when the actual sequence involved a desk that requested adjustments, received a revised number, and priced against the revision without documenting that a revision occurred at all. Two separate, timestamped artifacts make that sequence checkable. A single narrative document makes it whatever the author needs it to be.

A genuine governance review does not read the narrative memo. It pulls the two artifacts independently, for a sample of positions chosen without the reviewed desk's input, and checks three things: whether the prediction record predates the underwriting record, whether the underwriting record's stated price and structure are consistent with the distribution the prediction record actually reported, and whether any gap between the two was disclosed at the time rather than explained after the fact. A review that cannot perform this check because one of the two records does not exist in an independently verifiable form has found its first finding before it has looked at a single outcome.

Without this separation, an institution loses the ability to distinguish two very different kinds of failure after a loss. A position can lose money because the prediction was wrong, the model's distribution genuinely did not describe what this matter would do. Or it can lose money because the prediction was right and the desk priced it badly anyway, ignoring the tail the distribution disclosed or committing capital at a structure the distribution never supported. These are different problems requiring different fixes, one a modeling fix, one a discipline fix, and an institution that cannot tell them apart will keep applying the wrong one.

Checkable, in practice, means the prediction record is written to an append-only or version-controlled store before the underwriting function accesses it, that the model version and input set are captured alongside the output rather than reconstructed later, and that the underwriting record references the specific prediction it relied on rather than a general description of what the model 'said.' None of this requires exotic infrastructure. It requires treating the prediction as a data product with its own lifecycle, not as a conversational input the underwriting team is free to paraphrase.

The separation also protects the modeling function from a pressure it should never have to absorb: being blamed for a pricing decision it did not make. When the two trails are merged, a desk that priced a position aggressively against a distribution it fully understood can, after a loss, attribute the result to the model rather than to its own pricing choice, and there is no independent record to contradict that attribution once the two decisions have been folded into one narrative. Separate, timestamped trails remove this ambiguity in both directions. They protect the modeling function from being blamed for a pricing failure and protect the underwriting function from being blamed for a genuine model error, which is exactly the accountability structure a governance process is supposed to produce.

This same two-trail discipline should extend to monitoring events that occur after underwriting but before resolution, because a re-scoring triggered by a procedural development is itself a new prediction record, and the underwriting function's response to that updated prediction, hold, adjust reserves, seek additional structure, deserves its own timestamped record for the same reason the original decision does. A position with a rich audit trail at origination and none afterward has only solved half of the governance problem this discipline is meant to address.

An institutional buyer evaluating a counterparty's governance should ask to see both trails for a specific, named position, not a description of the process that generates them. A counterparty that can produce a timestamped prediction and a separately timestamped underwriting decision, each referencing the other, has a governance structure that survives scrutiny. A counterparty that can only produce a single retrospective memo has a story, and a story is exactly what a review after a loss cannot afford to rely on.

← All InsightsRequest Access →