Credit Policy Design: Setting Cutoffs, Limits, and Pricing That Hold Up

Credit Policy Design: Setting Cutoffs, Limits, and Pricing That Hold Up | HL Hunt
Payments & AI

Credit Policy Design: Setting Cutoffs, Limits, and Pricing That Hold Up

Most discussion of credit decisioning focuses on models — the data, the algorithm, the predictive lift. But a model produces a probability, and a probability is not a decision. What converts one into the other is credit policy: the cutoff, the pricing tiers, the limit assignment, the exclusions, and the rules that override everything else. Policy determines who you serve, what you earn, and what you lose, and it's frequently set by inheritance, intuition, or fear rather than by arithmetic. This guide covers the arithmetic — why the cutoff is an economic decision rather than a risk one, how expected loss converts a score into a price, how to size limits on capacity, and how to change any of it without discovering the effect at full scale.

By the HL Hunt Research Desk · 15 min read · Updated July 2026

The cutoff is an economic decision

Ask most lenders why their cutoff sits where it does and you'll get an answer about acceptable risk. That framing is the source of a great deal of avoidable underperformance, because there is no such thing as an acceptable risk level in the abstract — only a price at which a given risk is or isn't worth taking.

The correct question is marginal: for the next applicant just below my current cutoff, does the expected revenue exceed the expected cost? Expected revenue is interest, fees, and any ancillary income across the expected life of the account. Expected cost is expected loss, funding cost, servicing cost, and acquisition cost. Where that difference turns negative, the cutoff belongs. Where it's still positive, every declined application is a decision to leave money on the table.

Two things fall out of this reframing immediately. First, the cutoff moves when the economics move — a change in funding costs, servicing efficiency, or pricing shifts the profitable frontier, which means a cutoff set three years ago and never revisited is almost certainly wrong now. Second, a higher-risk applicant is rarely unacceptable; they're unacceptable at the wrong price. Which turns the conversation from exclusion to pricing, within whatever legal and market constraints apply — the argument that underpins responsible expansion of the credit box rather than loosening of it.

The constraint that keeps this honest: the economics have to be calculated on realized performance, not projected. A cutoff justified by a model's expectation and never validated against actual vintage outcomes is a hypothesis, not a policy.

Expected loss, and how to use it

Expected loss is the bridge between a risk score and a dollar amount, and it has three components:

ComponentWhat it measures
Probability of defaultHow likely this account is to default over the relevant horizon — the model's output
Exposure at defaultHow much will be outstanding when it happens, which for revolving products is often higher than the average balance because distressed borrowers draw down available credit
Loss given defaultThe share not recovered after collection, settlement, or liquidation of collateral

Multiply them and you get an expected loss figure per account, per segment — which is the number that makes everything else possible. It sets the minimum revenue a segment must generate. It makes segments comparable, so you can see that a low-score segment priced appropriately may contribute more than a high-score segment priced competitively. And it converts loss from a surprise into a budgeted cost.

Two components deserve more attention than they usually get. Exposure at default is systematically underestimated for revolving credit, because borrowers approaching distress use available headroom — the dynamic our credit limit analysis examines from the consumer side. Modeling exposure as the current balance rather than as a draw-down-adjusted figure understates loss meaningfully. And loss given default depends on your collections capability, which means recovery performance is a credit policy input, not just an operational one — improving recovery lowers expected loss, which lowers the profitable cutoff, which expands who you can serve. The economics of that recovery function are in our write-off decision guide.

Price, not permission
A higher-risk applicant is rarely unacceptable in principle — they're unacceptable at a price that doesn't cover their expected loss. Which turns most cutoff debates into pricing questions, and most declines into missed segments.

Risk-based pricing and its limits

Risk-based pricing charges more where expected loss is higher, which is what allows a lender to serve applicants who would otherwise be declined outright. Done well it expands access; done carelessly it produces both commercial and legal problems.

The commercial constraints. Price elasticity is real — a rate high enough to cover risk may be high enough that the applicants who accept it are adversely selected, meaning the borrowers with better options leave and the ones remaining are worse than the model predicted. That's the classic failure mode of aggressively priced tiers: the pricing was right for the segment as modeled, but the segment that actually accepted was different. Monitoring take rates and performance by offered price, not just by risk band, is what catches it.

The legal constraints. State rate caps set hard ceilings that vary substantially, which means the same pricing tier may be lawful in one state and unlawful in another — the licensing and rate landscape our regulatory map covers. Beyond caps, pricing outcomes are subject to fair lending analysis: a pricing structure that produces disparities along protected lines creates exposure regardless of whether the inputs were neutral, which is why pricing belongs in the outcome testing described in our model governance report alongside approval decisions.

The design principle that avoids most trouble: keep pricing tiers few enough to explain and defend. A structure with a handful of bands, each with a documented rationale tied to expected loss, is both easier to test for disparity and easier to justify than a continuous pricing surface nobody can articulate.

What belongs in policy rather than in the model

Some decisions should never be learned from data, and separating them out is one of the most important structural choices in a lending stack.

Policy rules — explicit, deterministic, and under your direct control — should hold:

  • Legal and regulatory requirements: minimum age, state eligibility, product restrictions, and anything driven by licensing.
  • Hard exclusions: prohibited business types, sanctions screening outcomes, and situations where you simply won't lend regardless of what the model says.
  • Verification requirements: what must be confirmed before funding, and what documentation triggers.
  • Fraud outcomes: which should route to verification rather than to a credit decline, per our application fraud analysis.
  • Concentration limits: exposure caps by segment, geography, or product that protect the portfolio rather than assessing the applicant.
  • Capacity floors: minimum verified income or debt-service capacity independent of risk score.

The reasons to keep these outside the model are practical. They need to change instantly when law or appetite changes, without retraining anything. They must be explainable exactly. And a model that learns a legal constraint from historical data will apply it imperfectly and inconsistently — which is a compliance problem waiting to be discovered.

Limit assignment and capacity

Limit setting is where lenders most often conflate two separate questions. Risk asks whether this borrower repays. Capacity asks how much they can service. A borrower can be very low risk and have very limited capacity, and giving them a large limit because the risk model is comfortable is how a good customer becomes a bad one.

What informs a defensible limit:

  • Verified income and obligations, which is where cash flow data outperforms everything else — deposits, recurring outflows, and the buffer between them are direct evidence of capacity that no score contains, per our underwriting analysis.
  • Existing obligations across the file, so you're sizing to total capacity rather than to your share of it.
  • Product purpose. A limit meant to smooth cash flow is sized differently from one meant to fund a purchase.
  • Loss exposure. Since exposure at default rises with the limit, limit assignment is a direct loss control, not merely a customer experience decision.
  • Customer value. Limits that are too small produce disengagement and attrition; a customer who can't use the product doesn't stay. The optimal limit maximizes contribution, which is neither the largest nor the smallest defensible number.

The pattern that generally works: start conservative and grow on performance. A modest initial limit with a defined path to increases based on payment behavior and utilization caps early exposure while giving good customers a reason to stay engaged — and it generates the internal performance data that makes later increases well-founded rather than speculative.

Ongoing line management

Policy doesn't end at origination. Accounts are re-evaluated continuously, and the decisions made there — increases, decreases, and closures — have consequences the consumer side of our coverage documents in detail.

Increases reward performance, grow balances, and improve retention. The inputs are on-us payment history, refreshed bureau data, updated income where available, and utilization patterns. The discipline is to size increases to capacity rather than to score improvement alone.

Decreases reduce exposure on deteriorating accounts and are entirely rational from a portfolio perspective. They are also, from the customer's side, the mechanism our ceiling analysis shows to be severe — median decreases removing a large share of open credit, mechanically raising utilization and lowering scores, which can cascade across the customer's other accounts. Two implications for policy design: calibrate decreases to actual risk change rather than to blunt triggers, since an unnecessary cut damages a customer who was performing; and consider the cascade, because a decrease that pushes a marginal customer into distress can create the default it was meant to avoid.

Both directions require governance. Line management decisions are automated at scale, which makes them exactly the kind of activity that needs documentation, monitoring, and fair lending outcome testing — and it's the area lenders most often discover, mid-examination, was never formally governed at all.

Testing changes safely

The temptation with a policy change is to implement it and watch. The problem is that credit outcomes take months to mature, so "watching" means running the new policy across all volume for a year before knowing whether it worked.

Champion-challenger testing is the discipline that solves this: route a defined percentage of applications through the proposed policy while the majority continue under the existing one, then compare outcomes on populations that are otherwise matched. Done properly it requires random assignment, a slice large enough to produce meaningful results, and patience.

Because full outcomes lag, use early indicators to get directional signal sooner: first-payment default, delinquency in the first few billing cycles, utilization trajectory, and take rate. These correlate with eventual performance well enough to catch a badly wrong change quickly — while not being conclusive enough to justify declaring victory early, which is the more common error.

Three additional practices worth building in. Test one change at a time, or you won't know which one produced the result. Keep a holdout — a small population continuing under the old policy even after a change rolls out, which is the only way to distinguish a policy effect from an economic one. And test in both directions: lenders routinely test loosening and rarely test tightening, which means the cost of over-conservative policy stays invisible, exactly as the false decline problem in our fraud coverage describes.

Monitoring what matters

A credit policy is a live system, and the reporting that keeps it honest is more specific than a portfolio dashboard.

  • Vintage analysis. Performance by origination cohort, which is the only way to see whether recent policy is performing differently from older policy. Portfolio-level delinquency blends vintages and hides deterioration behind seasoned accounts.
  • Approval and take rates by segment, to catch adverse selection in pricing tiers.
  • Score distribution drift in the applicant population, since a stable cutoff applied to a shifting population is effectively a changing policy.
  • Model performance versus prediction, at the segment level — the drift monitoring our governance analysis treats as mandatory rather than optional.
  • Realized loss against expected loss, which validates or invalidates the entire economic basis of the cutoff.
  • Fair lending outcomes across approval, pricing, and limit assignment, tested continuously rather than at review time.
  • Override rates and outcomes. If manual overrides are frequent, either the policy is wrong or the overrides are — and the performance of overridden accounts answers which.

Documentation and compliance

Credit policy is examinable, and the standard applied is not merely whether the outcomes were reasonable but whether the decisions were documented and governed.

What a defensible file contains: the written policy itself, with cutoffs, pricing tiers, limit rules, and exclusions stated explicitly; the rationale for each, tied to the economic and risk analysis supporting it; change history, including who approved what and when, and the test results that justified it; monitoring reports demonstrating ongoing oversight rather than a one-time setup; fair lending testing covering approval, pricing, and limits, including the documented search for less discriminatory alternatives where disparities appear; and adverse action mapping, showing how each decline reason connects to the factors actually used — the requirement that makes explainability a design constraint rather than a reporting afterthought.

The practical standard worth internalizing: in an examination, an undocumented decision and an indefensible one are treated identically. A policy that performed well but was never written down, tested, or governed is a finding regardless of its results — and a policy that underperformed but was thoughtfully designed, documented, and monitored is a conversation rather than a violation.

Policy you control, decisions you can explain

HL Hunt AI Underwriting keeps the policy layer separate and under your control — cutoffs, exclusions, pricing bands, and limit rules configured explicitly — while the model scores the ambiguity, with explainable adverse action reasons, segment-level monitoring, and champion-challenger testing built in.

Explore HL Hunt AI Underwriting

Frequently asked questions

How do lenders decide where to set an approval cutoff?

By marginal economics: expected revenue against expected loss, funding, servicing, and acquisition cost for the next applicant below the line. Risk tolerance in the abstract isn't the question — price is.

What is expected loss and how is it used in pricing?

Probability of default times exposure at default times loss given default, producing a dollar figure per account. It sets the minimum revenue a segment must generate and makes segments comparable.

Should credit limits be based on risk or on income?

Both — risk decides whether and at what price, capacity decides how much. Cash flow evidence beats a score for capacity, and limits are also a direct loss control since exposure at default rises with the line.

How do you test a credit policy change safely?

Champion-challenger on a defined slice with random assignment, using early indicators like first-payment default for direction while waiting for vintages to season. Keep a holdout, and test tightening as well as loosening.

Key takeaways

  • The cutoff is an economic decision about the marginal account, not a statement about acceptable risk — and it should move when the economics do.
  • Expected loss converts a score into a price; exposure at default is systematically underestimated on revolving products.
  • Risk-based pricing expands access but invites adverse selection and fair lending exposure — monitor performance by offered price, not just by risk band.
  • Keep legal requirements, exclusions, and capacity floors in an explicit policy layer rather than learned inside a model.
  • Size limits on capacity, start conservative, and grow on performance — and calibrate decreases carefully, because cuts cascade.
  • Test with champion-challenger and a holdout, monitor by vintage, and document decisions — because undocumented and indefensible look the same in an examination.

Model the change before you make it

See how HL Hunt AI Underwriting scores your live applications alongside your current policy — so you can measure a cutoff, pricing, or limit change on real volume before it reaches your whole portfolio.

Get Started with HL Hunt AI Underwriting


This guide is educational and does not constitute legal or compliance advice. Rate caps, fair lending obligations, and model risk expectations vary by product and jurisdiction; consult qualified counsel regarding your specific program.