---
title: "Credit risk review"
summary: "Lock a dated loan universe, sample it into a credit review, keep each reviewer independent of the credit, and track review exceptions."
updated: "2026-10-07"
section: "Programs"
url: "https://zovos.ai/docs-credit-risk-review.html"
---

# Credit risk review

Credit risk review, often called loan review, is the independent check that a community bank or credit union rates its loans honestly and catches problem credits early. In Zovos it is the **Credit risk review** group of the sidebar, which holds three screens: **Loan universe**, **Credit reviews** and **Review exceptions**. The loan review officer and the credit risk review staff work here, an approver who holds risk sign-off authority signs each review off, and senior management and the board read the exceptions that stay open.

## The loan universe

A review samples from a **loan universe**, which is the loan population as of one date. Choose **New universe**, record the as-of date and the source, such as the commercial portfolio from your core trial balance export, and the universe opens as a draft.

You fill a draft two ways. **Import a loan listing** takes a CSV or an Excel workbook exported from your core or loan system, reading the first worksheet with a header row. Headings ignore case and spacing, and common core export names such as Loan Number, Risk Rating, Loan Officer and Approved By are recognized. Rows with a problem, and loan numbers already in the universe, are listed and skipped while the other rows import. Tick the preview option to validate a file without saving any of it. You can also enter loans one by one.

Each loan carries its loan number, a description, a segment, the product, the commitment and outstanding balance, the origination, last renewal and maturity dates, the officer's risk rating and regulatory classification, and its flags. The flags are watch list, policy exception, insider, nonaccrual, restructured and days past due. Each loan also records who originated it and who approved it, which is what the independence check below reads. The segments are commercial real estate, commercial and industrial, construction and land, agricultural, residential mortgage, home equity, consumer, member business, and other.

A credit is its loan number and a description. Every loan entry screen asks you not to enter borrower names or other nonpublic personal information, and Zovos does not connect to your core.

When the population is complete, **Lock universe** records the loan count, the total commitment, a SHA-256 content digest, your name and the time. A locked universe can never change. No loan can be added, edited or removed, and the universe cannot be deleted. Samples are drawn only from a locked universe, so the population a review rests on is the population you locked. A draft that is no longer needed can be deleted, and the deletion stays in the audit trail.

## Scoping and sampling a review

**New review** on the Credit reviews screen starts a review against one locked universe. You record a title, an optional scope narrative, the segments in scope and a lead reviewer from your team roster. The scope is risk-based. You can require every loan with a commitment at or over a threshold, and every loan that carries a chosen flag, including adversely classified credits. Required loans are always reviewed, and the rest of the in-scope population is sampled.

The sample method is random, statistical, judgmental or full population. A random or statistical sample is drawn from a recorded seed, which you can supply or let Zovos generate. The population is ordered by loan number before the draw, so re-performing the same selection produces the same credits regardless of the order of the original file. A statistical sample records its confidence level and its tolerable and expected rates, and a sample smaller than that basis supports is refused rather than accepted. A judgmental sample names its loan numbers.

**Select sample** takes the required loans plus the sample, seals the selection with a digest and moves the review from planning to fieldwork. The scope and the method cannot change after that. The **Credit reviews** list shows each review's universe as-of date, lead reviewer, status, credits completed of the total, coverage and creation date. The review header shows how many credits are complete and what share of the in-scope commitment the sampled credits cover. The review opens on four tabs: **Scope & selection**, **Credits**, **Independence** and **Exceptions**.

## The independence rule

Each sampled credit is assigned to a reviewer. Zovos checks the reviewer, by team member record, against the originator and every approver the locked universe records for that credit. A reviewer who originated or approved a credit cannot be assigned to it or record its result, and there is no override. The same records decide who cannot sign the review off, which is the reviewers and everyone who originated or approved a sampled credit.

Some things Zovos cannot know, and the Independence tab says so. A name on a loan that matches no single team member leaves the credit **Unverified**, and the assigned reviewer then attests to having no involvement in it. Whether reviewers report to the lending function, or are paid in a way the assigned ratings could influence, is attested by the lead reviewer. The tab opens with **Cannot sign off this review**, which lists each person who cannot sign the review off and why, before anyone tries. A name that matches no single team member is marked as such. Below that, the tab counts the credits that are clear, unverified and attested, unverified and still needing attestation, and not yet assigned.

## Reviewing a credit

For each sampled credit the reviewer records whether it was reviewed. A credit that was not reviewed needs the reason. A reviewed credit needs the reviewer's answer to one question, which is whether they agree with the officer's rating, and a written conclusion. A disagreement also records the reviewer's own rating, an optional regulatory classification of pass, special mention, substandard, doubtful or loss, and a target date for correction. Recording a disagreement also opens a risk-rating exception for that credit, at most one per credit, so a rating dispute cannot be noted and then forgotten.

**Submit for sign-off** lists everything that still blocks submission at once. A review cannot be submitted with no sampled credits, with a credit still pending, with an unverified credit whose reviewer has not attested, or before the lead reviewer has attested. Submitting sends the review through the shared approvals queue to an approver holding risk sign-off authority, and fieldwork stops unless the approver returns it. Sign-off records the approver, the rationale and a manifest digest, seals the event in the proof ledger, and from then on the review and its credits cannot be changed.

## The review report

A signed-off review offers **Report**, which generates the credit risk review report in one of two editions, as a PDF or a Word (DOCX) file. The **Internal report** covers every credit and reviewer. It holds the scope and as-of date of the universe, coverage, each credit reviewed with its reviewer and review date, the officer's rating against the reviewer's with the downgrades, the exceptions by status with their corrective action, person responsible and target date, the overdue exceptions called out, and the independence attestations. The **Board edition** holds aggregates only, with no loan numbers and no names. Zovos stores the file and seals it on the proof ledger.

The board pack carries a **Credit risk review** section in aggregate. It covers the reviews signed off in the twelve months to the pack date, with credits and commitment reviewed against the scope, the ratings the reviewer disagreed with, downgrades and upgrades, exceptions by status, and the independence attestation. It also counts the open exceptions past their target date on any signed-off review, whatever the review's age, and how many days past target the oldest one is. An overdue exception therefore stays in front of the board after its review leaves the twelve-month window. Each figure is a sealed claim that resolves back to its records. See [Board & governance](docs-board-governance.html).

## Review exceptions

A review exception is a deficiency found in fieldwork. You log it on the review's Exceptions tab, against a sampled credit or the review as a whole. Each one records its type, its severity of high, medium or low, a description, the corrective action, the person responsible and a target date. The types are risk rating, documentation, underwriting, approval, covenant, collateral, policy and other.

The **Review exceptions** screen lists exceptions across every review and filters them by open, overdue, resolved and promoted, by type and by review. An open exception past its target date reads overdue, so it can be reported to senior management and the board.

Resolving an exception records how the follow-up was verified, and it must be done by someone independent of the credit. That person cannot be the one responsible for the corrective action, or an originator or approver of the loan, and there is no override. A risk-rating exception also records which rating stands, either that the lower rating prevails or that the reviewer concurred with the officer. An exception can instead be promoted into the findings register as a self-identified finding linked back to it, after which it follows that finding rather than being resolved here. See [Findings & remediation](docs-findings.html).

## Notes and limits

Examiner sessions never see the Credit risk review group. Zovos does not rate loans, pull data from your core, or decide a classification. It records the population you locked, the sample drawn from it, each reviewer's conclusion, and the follow-up on what they found. The group is part of the credit risk review job family, which arranges the sidebar for loan review staff. See [Roles & permissions](docs-roles-permissions.html) and, for the buyer-facing summary, [credit risk review](role-loan-review.html).
