Loan officer and small business owner reviewing cash flow data

Why Cash-Flow Data Beats Credit Scores for CDFI Lenders

I spend a lot of time in rooms with COOs and Heads of Lending at CDFIs and community lenders, and for the last few years one conversation keeps repeating itself. Someone brings up cash-flow underwriting, someone else nods and says it sounds promising, and then the conversation quietly moves on because nobody feels like they have enough evidence to make the case to their board or their funders. That excuse just got a lot harder to use.

FinRegLab, a nonprofit research organization, recently published a study analyzing more than 38,000 small business loans originated by fintech lenders between 2015 and 2024. The research was conducted with faculty from the NYU Stern School of Business, and the findings are about as definitive as empirical lending research gets. Cash-flow variables derived from electronic bank account data are a stronger and more accurate predictor of loan performance than personal credit scores alone. Not marginally stronger. Meaningfully stronger, and especially so for the exact borrower population that CDFIs and community lenders were created to serve.

The Borrowers Traditional Credit Scoring Was Never Built For

Early-stage businesses. Businesses owned by people with limited credit histories. Financially constrained entrepreneurs. These are the categories the study highlights, and if you work in community lending you already know these borrowers well. They are not high-risk. They are underserved by a scoring system that was never designed to evaluate them fairly in the first place.

A low credit score does not mean a business is a bad bet. It might mean the owner is young and has not had time to build a long credit history. It might mean the owner is an immigrant who arrived in this country without an existing credit file. It might mean there was a difficult stretch four or five years ago, medical debt, a divorce, a failed first venture, that has since fully resolved and no longer reflects the person running the business today. Personal credit scores are backward looking by design. They are a historical proxy, and for a huge share of the borrowers community lenders exist to serve, that proxy is simply wrong.

Cash-flow underwriting evaluates something different. It looks at deposits, expenses, revenue patterns, and payment behavior as they exist right now, inside the business, based on actual bank account activity. It answers the question a lender actually needs answered, which is whether this business can service debt today, not whether the owner had good or bad credit years ago. That is not a philosophical argument anymore. It is what the data shows across 38,000 loans and nearly a decade of originations.

This Is No Longer a Theoretical Debate

What makes this study different from the cash-flow underwriting conversations the industry has been having for years is that it is not theoretical. FinRegLab documented real-world implementation pilots at operating lending institutions, including Allies for Community Business, Ascendus, LiftFund, Ponce Bank, and Texas National Bank. These are CDFIs and minority depository institutions that have already put cash-flow underwriting into production and are using it right now to approve borrowers they could not previously serve under a credit-score-first model.

That distinction matters. It is one thing for a research paper to conclude that a methodology is theoretically sound. It is another thing entirely when five different lending organizations, with real portfolios and real regulatory obligations, have implemented it and can point to outcomes. The debate over whether cash-flow underwriting works has effectively closed. The research settled it, and the pilots proved it operationally.

So if the evidence is this strong, and the pilots are already running, the obvious question is why cash-flow underwriting still is not standard practice across the CDFI sector. The FinRegLab report is honest about this, and the answer has nothing to do with skepticism about the methodology. It has to do with infrastructure.

The Real Barrier Is Not Belief. It Is Plumbing.

To underwrite on cash flow, a CDFI needs to securely access bank transaction data through third-party aggregators, bring that data into the underwriting workflow in a usable form, train staff to interpret it consistently across every application, and do all of this while protecting borrower privacy and meeting the compliance obligations that come with handling sensitive financial data. None of that happens by wishing it into existence. It requires a technology platform that can actually support it, and a meaningful number of CDFIs are still running loan origination on a patchwork of spreadsheets, PDFs, email threads, and a core system that was never built to ingest a live bank data feed.

I have sat with underwriting teams who believe completely in cash-flow analysis, who have read the research, who want to move on it, and who are stuck because their current system has no way to pull transaction data into the file where the credit decision actually gets made. So what happens instead is someone downloads a PDF bank statement, someone else manually reviews it line by line, and the process that was supposed to expand access to underserved borrowers ends up being slower and more labor-intensive than traditional underwriting, not faster. The intent is right. The infrastructure is not there to support it, so the benefit never reaches the borrower.

This is the part of the FinRegLab report that deserves the most attention from lending leadership teams, because it is the most actionable. The report specifically points to lending platforms as the mechanism that makes cash-flow underwriting operational rather than aspirational. The CDFIs that have successfully reduced paperwork burdens and cut processing times from months down to weeks are not the ones with the most conviction about cash-flow data. They are the ones that integrated bank data feeds directly into their loan origination and underwriting systems, so the information flows automatically into the workflow instead of being manually assembled by an analyst every single time.

What Automated Data Flow Actually Changes

It is worth being specific about what changes when bank data flows directly into an origination system instead of arriving as a static export. First, consistency improves. When every underwriter is looking at the same structured categorization of deposits, expenses, and revenue trends, you get a repeatable credit decision framework instead of individual analysts each interpreting a bank statement their own way. Second, speed improves, not because anyone is cutting corners, but because the manual transcription and reconciliation step disappears entirely. Third, and this is the one boards and funders care about most, documentation improves. Every cash-flow variable that fed into the decision is captured in the system of record, which matters enormously when a CDFI has to justify its underwriting methodology to a funder, an examiner, or its own risk committee.

None of this requires exotic technology. It requires a loan origination and servicing platform that was built with the flexibility to connect to third-party data sources and route that data into the underwriting workflow where decisions get made and documented, rather than a system that was built purely around static application forms and manual document uploads. This is precisely the operational gap that separates CDFIs that are scaling cash-flow underwriting from CDFIs that are still talking about it in strategy meetings.

What This Means for CDFI and Community Lending Leadership Right Now

If you lead lending operations at a CDFI or a community lender, the research has effectively done its job. You no longer need to build an internal case for why cash-flow underwriting deserves serious consideration. FinRegLab and NYU Stern have built that case for you, with 38,000 loans of evidence and five operating institutions as proof points. The question in front of your leadership team is no longer whether cash-flow underwriting works. It is whether your current technology platform can support it.

That is an honest question worth asking plainly, without defensiveness. Can your system securely connect to a bank data aggregator. Can it bring transaction-level data into the file an underwriter is reviewing, rather than requiring someone to open a separate tool and manually cross-reference it. Can it document which cash-flow variables informed a given credit decision, in a form that would satisfy a funder or an examiner asking how that decision was made. If the honest answer is no, that gap is not a reason to keep cash-flow underwriting on the someday list. It is simply the next problem to solve, and it is a solvable one.

I would also push back gently on a version of this conversation I hear often, which is treating the technology gap as a reason to wait for a better moment. There is no better moment coming. The evidence is published. The pilots are running. Competing lenders in your market, including fintech lenders with far less mission alignment to underserved borrowers than a CDFI has, are already using cash-flow data to approve loans your traditional underwriting process would decline. Every quarter a CDFI spends without the infrastructure to act on this research is a quarter where bankable, viable, financially healthy small businesses are being turned away not because they are risky, but because the system evaluating them cannot see what is actually happening in their bank account.

The mission case for cash-flow underwriting was never really in question for most CDFI leaders. What this study removes is the last credible reason to treat it as unproven. What remains is an implementation question, and implementation questions get solved with the right platform, the right data integrations, and a workflow that puts cash-flow data in front of underwriters at the moment they need it, not after the fact. That is a much better problem to have than the one most of the sector has been stuck on, which is whether the methodology itself can be trusted. It can. Now it is a matter of building the operational capability to use it.