Upstart
Upstart operates an artificial intelligence lending marketplace through which more than 100 banks and credit unions use its underwriting models and cloud applications to originate consumer credit. Its personal loan model weighs more than 3,000 variables and retrains against loan level repayment and delinquency data arriving daily across the whole partner base, covering personal loans, automotive retail and refinance lending, home equity lines and small dollar relief loans. Lending partners set their own credit policy, objectives and risk appetite and remain the lender of record.
The company publishes annual comparisons of its model against a traditional benchmark including outcomes broken out by borrower race and ethnicity, maintains hundreds of state licences, and has applied for a national bank charter to be held in a separately regulated sister company.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The removal test leaves a loan application form. The entire proposition is that a model weighing more than 3,000 variables approves more applicants at lower rates than a credit score driven rule set, and the company's stated comparisons are all against that traditional benchmark, so without the model there is no product and no reason for a lender to be there.
The model retrains continuously rather than periodically, optimising against loan level repayment and delinquency data from an average of more than 136,000 payments falling due each business day across the partner base, and more than 90 percent of loans complete with no human involvement from the company at all.
The highest stated automation rate in this index, with more than 90 percent of loans fully automated and no human intervention by the company, and the stated ambition is a world where the right borrower is approved at the right price instantly and effortlessly. Real control exists and is stated forcefully, with lending partners retaining complete authority over credit policy, business objectives and risk appetite, so the institution defines the box within which automation operates.
That is design time governance of a strong kind. What is not described is anything at decision time: no referral threshold, no manual review path for marginal or unusual applications, no confidence exposure to the partner, and no account of what happens to the applicant the model cannot assess confidently rather than simply declining.
Sixth A on this axis and the only one built on a permanent internal function rather than on output traceability. Dedicated model risk management and model governance teams are named as overseeing model production, changes and performance, which is the structure a supervised institution's own examiners expect to find and which almost no vendor here evidences.
Validation is continuous rather than periodic, since the model optimises against loan level repayment and delinquency outcomes arriving daily, so performance is measured against what actually happened to the loans rather than against a held out sample. Annual retrospective studies compare the model to a benchmark on around a million bureau records, and public company reporting obligations subject the surrounding claims to audit. The gap that remains is granular: no discrimination statistic, stability monitoring detail or model documentation package is published for external review.
Among the strongest evidence surfaces in this index, and it carries public company disclosure obligations behind it. More than 100 banks and credit unions use the platform, with individual institutions named including a large credit union, a listed bank holding company and two further credit unions, each quoted on why they selected it.
Volume, automation rate, cumulative originations and funding mix are all disclosed and periodically restated, including the split of funded loans across institutional investors, lending partners and the company's own balance sheet.
Outcome claims are benchmarked rather than absolute, with the model stated to approve 43 percent more applicants at 33 percent lower rates than a traditional score driven model on full year 2024 data, and a retrospective study analysing approximately one million credit reports from a named bureau supports the underlying method.
Cross partner pooling is not merely present here, it is the stated mechanism of the product. Models are described as optimising in response to daily loan level repayment and delinquency data across all lending partners, which means every institution's borrower outcomes train the model that prices credit for every other institution, including its direct competitors in the same markets. That is a coherent design for a marketplace and it is disclosed plainly rather than concealed.
What is absent is governance around it: no statement of whether a partner can decline to contribute performance data, no description of what is aggregated or at what threshold, and no account of how a departing partner's contribution is treated.
The company names the regimes it operates under rather than referring to compliance generally, stating that it works with lending partners to follow applicable regulations on data privacy, data security and fair credit reporting, and the last of those is the specific statute governing how consumer credit information may be collected, used, disputed and corrected. Naming it matters because it carries dispute and accuracy obligations that attach to the applicant.
Held at B because no retention schedule, subprocessor list or data processing terms were located, and the volume of consumer financial data flowing through a platform serving more than 100 institutions is substantial.
No attestation, certification, trust centre or enumerated framework was located, though data security is named as a regime the company follows alongside privacy and fair credit reporting. Listed company status brings audited internal controls over financial reporting, which is a genuine external examination of a different thing, and bank partners plainly conduct their own security diligence given the third party oversight process the company itself describes. None of that assurance is published, so a new partner starts from the beginning.
The most extensive regulatory position recorded in this index. The company maintains 248 separate state lending licences, publishes its nationwide mortgage licensing identifier and names the separate entity conducting mortgage lending, and has applied for a national bank charter to be held in a separately regulated sister company alongside the technology platform.
It engages the federal banking agencies by name, and its own submission to one of them, published in the Federal Register, sets out how bank partners should oversee the relationship, covering initial diligence, contractual allocation of obligations and ongoing monitoring, which is a vendor describing its customers' third party risk duties rather than only its own compliance. Fair credit reporting, data privacy and data security are each named. Eighth A on this axis and the only one resting on licences held rather than infrastructure connected.
The first A on this axis in the index, and it is earned by doing precisely what every other credit vendor here is marked down for omitting. The company evaluates its model annually against a constructed traditional benchmark built on criteria such as credit score and debt to income, and publishes the results broken out by borrower race and ethnicity rather than in aggregate, reporting that the model approves more applicants including Black and Hispanic applicants at lower rates, with specific figures for approval uplift and rate reduction by group.
The underlying method is tested on a large independent sample, roughly one million bureau credit reports, and the analysis has been submitted to a federal banking regulator on the public record rather than published only as marketing. Named model risk management and model governance functions oversee the models producing those outcomes.
The model was also examined under a Consumer Financial Protection Bureau no action letter issued in 2017, which tested whether it produced greater disparities than a traditional model by race, ethnicity, sex or age; the Bureau terminated that letter in 2022, and a fair lending monitorship conducted by the law firm Relman Colfax identified approval disparities in first quarter 2022 data while the letter was in force.
That finding is recorded here rather than treated as a mark against the grade, and the reason is a principle this index has to hold: submitting a model to independent testing and letting an unflattering result reach the public record is a stronger disclosure position than never being tested at all, and an index that grades publication cannot penalise a vendor for the content of what it published.
Three further honest qualifications belong on the record: the benchmark is of the company's own construction, approving more applicants at lower rates is a different question from equal error rates across groups, and disparate impact in a model weighing 3,000 variables cannot be fully characterised by approval and pricing comparisons alone. The access to credit figures the company cites were reported by the Bureau based on the company's own analysis rather than independently produced. Even so, this is disclosure of a different order from anything else in the category.
No vendor level guarantee or indemnity was located, and the applicant's position is materially better than elsewhere in this category because the surrounding legal structure is engaged rather than avoided. A partner bank or credit union is the lender of record and carries the adverse action and equal credit opportunity duties that attach to a decline, the company names fair credit reporting compliance which brings dispute and correction rights over the underlying data, and it holds hundreds of state lending licences making it a supervised entity in its own right rather than an unregulated supplier.
Its published account of how partners should monitor the relationship reinforces where accountability sits. What is still missing is anything specific to model failure: no correction or notification process is described for a decision traced to a model error rather than to bad data.
Models are built in house and the company's own governance functions own them, which shortens the chain at the decisive point and is stated clearly. On the data side a major credit bureau is named as the source underpinning its retrospective validation work, and lending partners are individually identified, so the institutional chain is visible.
What is not published is the input inventory: a model weighing more than 3,000 variables necessarily draws on sources beyond the bureau file, and none of the alternative or supplementary providers is named, which leaves a partner unable to assess coverage or bias in the inputs feeding decisions made under its own licence.
More than 100 institutions run the platform in production, which evidences that the integration works at scale across banks and credit unions with very different technology estates, and the company emphasises that a partner gets one implementation, one compliance relationship and one account team across several loan products rather than separate builds for each. Servicing can sit with either party.
What is not published is the technical surface: no core banking system, loan origination platform, servicing system or bureau connection is named, and no developer documentation was located, so a prospective partner cannot establish what integrating actually involves before entering a commercial conversation.
No hosting provider, region selection, residency commitment or private deployment option was located. The platform is described as cloud based and the business operates in a single country, so cross border transfer is unlikely to arise in practice, but a supervised institution outsourcing consumer credit decisioning will still be expected by its examiners to know where the processing occurs and under what arrangements. Nothing published addresses it.
No rate card is published and two things lift this above the floor. The company states that it seeks to set transparent pricing of services for its bank partners, which is a commitment about the commercial relationship rather than a general claim, and as a listed company its revenue composition, fee structure and the economics of the platform are set out in periodic filings any prospective partner can read.
Those filings also disclose uncomfortable facts, including that a single customer generated about a third of revenue in the most recent year, identified only as Customer A. Held at B because a partner still cannot see a price before negotiating.
More than 100 lending partners spanning banks and credit unions of varying size, plus a separate category of loan buyers including institutional credit funds, so institutions engage either as originators or as capital. Product coverage runs across unsecured personal lending, automotive retail and refinance, home equity lines and small dollar relief loans, which is a wider consumer set than any other credit vendor here offers, and partners can access several products through a single implementation and compliance relationship. Reach is nationwide, supported by 248 separate state licences, and partners configure the platform to their own credit box and net return targets rather than accepting a standard product.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Upstart
The closest documented capability profiles to Upstart in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Upstart
Stronger documented coverage on Core Systems and Integration Depth
Documents Autonomy and Oversight Model where Upstart does not
Documents Autonomy and Oversight Model where Upstart does not
Documents AI Safety and Data Stewardship and Autonomy and Oversight Model where Upstart does not
Documents AI Safety and Data Stewardship and Autonomy and Oversight Model where Upstart does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.