Feature AI Risk
AI Credit Adverse Action After July 21: Current Regulation B Controls
Separate withdrawn CFPB AI guidance from current Regulation B duties, then test reason accuracy, timing, vendor evidence, and notice delivery.
Table of Contents
TL;DR
- Do not cite “CFPB Circular 2026-03.” The asserted May 5, 2026 AI circular is not a valid source.
- CFPB Circular 2023-03 discussed AI and adverse-action specificity, but the CFPB lists it as withdrawn on May 12, 2025. It is historical material, not active guidance.
- The withdrawal did not repeal ECOA or current 12 CFR 1002.9. The regulation still governs notification timing, content, and specific principal reasons.
- Regulation B does not say every notice must automatically list exactly four reasons. Separate ECOA notice duties from FCRA credit-score disclosures and other applicable requirements.
The clean way to govern an AI credit notice process in August 2026 is to separate three layers:
- Current binding authority: ECOA and Regulation B, including section 1002.9.
- Historical CFPB interpretation: Circulars 2022-03 and 2023-03, both withdrawn on May 12, 2025.
- Practitioner controls: model tracing, reason-code mapping, notice testing, and vendor evidence designed to show compliance with current authority.
Mixing those layers produces bad citations and brittle controls. A lender can preserve a useful testing method from an older document without calling the document active guidance.
Status correction: the AI circular is withdrawn
The CFPB’s Withdrawn Guidance page identifies Consumer Financial Protection Circular 2023-03: Adverse Action Notification Requirements and Proper Use of Sample Forms as withdrawn on May 12, 2025. It lists Circular 2022-03, the earlier complex-algorithm document, as withdrawn on the same date.
The archived Circular 2023-03 remains useful for understanding what the Bureau said in September 2023. It discussed reasons that reflect factors actually considered or scored, the limits of sample-form checklists, and complex models using nontraditional data. But an article, policy, or issue log dated 2026 must label that status accurately.
There is no support for replacing it with a supposed “Circular 2026-03” dated May 5, 2026. That citation should be removed, not repaired into a new regulatory event.
What current section 1002.9 says
The current regulation—not the withdrawn circular—is the control baseline.
Under 12 CFR 1002.9(a)(1), a creditor must provide specified notifications within different timeframes depending on the event. Examples include 30 days after receiving a completed application, 30 days after adverse action on an incomplete application unless the incomplete-application procedure is used, 30 days after adverse action on an existing account, and 90 days after an unaccepted counteroffer. Business credit has additional provisions in paragraph (a)(3).
When adverse action is taken, paragraph (a)(2) generally calls for a written notification containing required creditor, action, ECOA, and agency information, plus either:
- a statement of specific reasons; or
- a disclosure of the applicant’s right to a statement of specific reasons, with the rule’s request and contact details.
Paragraph (b)(2) says the reasons must be specific and indicate the principal reason or reasons for the adverse action. Statements that the applicant failed to satisfy internal standards or failed to achieve a qualifying score are insufficient.
That is broader and more precise than “an AI model must explain every denial in four reasons.” The rule covers defined adverse-action events, contains notice alternatives and business-credit rules, and does not impose a universal four-reason formula.
Do not import the FCRA four-factor concept
The withdrawn 2023 circular itself distinguished ECOA from the Fair Credit Reporting Act. Its footnote explained that FCRA credit-score disclosures generally identify up to four key factors, with an additional rule for inquiries. It also stated that disclosing those credit-score factors does not by itself satisfy ECOA’s requirement for specific reasons.
A notice workflow should therefore maintain an obligation matrix:
| Notice component | Governing trigger | Control question |
|---|---|---|
| ECOA/Reg B action notice | Application or account event covered by section 1002.9 | Was the event classified correctly and was notice timely? |
| ECOA specific reasons or right-to-request path | Creditor’s selected section 1002.9 process | Are principal reasons specific and supported by the actual decision? |
| FCRA adverse-action content | Use of a consumer report, where applicable | Is required bureau and consumer-report content present? |
| FCRA credit-score disclosure | Use of a credit score, where applicable | Are key factors produced under the FCRA logic rather than substituted for ECOA reasons? |
| Product, state, or program notice | Applicable law or contract | Is the additional notice separately sourced, owned, and tested? |
This is a RiskTemplates implementation aid, not a claim that the CFPB prescribed this table.
A decision-to-notice evidence chain for AI models
The technology-neutral requirement is operationally harder when a decision combines a model score, policy rules, eligibility screens, fraud controls, manual judgment, and a vendor service. A feature-importance output alone may not identify the principal reason for the final action.
Build an evidence chain with six links:
1. Event classification
Record whether the event was a completed application decision, incomplete application, counteroffer, adverse action on an existing account, withdrawal, or business-credit action. That classification determines the applicable paragraph and clock.
2. Decision reconstruction
Retain the input snapshot, data lineage, model version, policy and threshold version, rule hits, score, overrides, and final decision. The evidence must reproduce what happened at the time—not what the current model would decide after a later update.
3. Principal-reason selection
Define how the system chooses the principal causes of the final action. Distinguish:
- a model feature that influenced a score;
- a policy rule that independently caused the action;
- a fraud or eligibility screen;
- a manual decision; and
- a post-model threshold or affordability test.
SHAP, LIME, feature attribution, or a vendor ranking may be useful technical evidence, but no particular explainability technique appears in section 1002.9. Validate that the method identifies the principal reason for the action, not merely the largest mathematical contributor to an intermediate score.
4. Reason-language mapping
Map approved reason language to the controlled decision fact. Avoid “internal policy,” “failed score,” or a nearby sample phrase that did not drive the outcome. The language should remain specific without exposing security logic, protected information, or prohibited SAR information.
5. Notice assembly and delivery
Test required creditor and agency fields, ECOA text, applicant and transaction data, channel, accessibility, language handling, delivery timestamp, return handling, and the right-to-request process where used. A correct reason generated after the deadline is still an operational failure.
6. Post-delivery evidence
Preserve the exact notice rendered to the applicant, not only a template or database code. Link complaints, disputes, requests for reasons, returned mail, corrected notices, and remediation to the original decision.
Vendor models: contract for evidence, not a preferred tool
Current section 1002.9 does not prescribe SHAP values, a separate explainability layer, or an interpretable model. Those can be design choices; they are not direct quotations from the rule.
For a vendor-supplied model, contract and operating procedures should support the creditor’s actual process. Depending on architecture, evidence may include:
- decision-level inputs and outputs;
- model, policy, and reason-mapping versions;
- documented treatment of missing and transformed data;
- reason-generation logic and tie handling;
- change notice and regression-test support;
- audit access and retention;
- incident and correction duties; and
- exit support that preserves historical decisions and notices.
A contractual promise that a model is “explainable” does not prove that a sampled applicant received a specific, supportable, timely notice.
Focused validation scenarios
Use a controlled sample that includes more than straightforward denials:
- completed applications with different principal reasons;
- decisions where a policy rule overrides a favorable model score;
- multiple factors near the reason-selection boundary;
- missing or corrected input data;
- manual overrides and exceptions;
- adverse action on an existing account;
- counteroffers not accepted;
- incomplete applications;
- business-credit applicants under each applicable process;
- third-party application channels and creditor-specific notices;
- right-to-request reason delivery; and
- model or mapping changes across effective dates.
For each case, reconcile source data → model/rules → final action → principal reason selection → rendered notice → delivery evidence. Record defects separately for inaccurate reasons, insufficient specificity, wrong event classification, missing content, or timing.
What the 2026 Regulation B rule changed—and did not change
The 2026 Regulation B final rule, effective July 21, 2026, states that ECOA does not authorize disparate-impact liability and revises the Bureau’s treatment of discouragement and special-purpose credit programs. It does not repeal section 1002.9’s notification and specific-reason provisions.
That does not mean all other AI credit risk disappeared. ECOA’s intentional-discrimination prohibition remains, the notice itself can reveal inconsistent or prohibited decision logic, and FCRA, fair-housing, privacy, state, and product-specific law may independently apply. Map those authorities to the lender and product rather than making a blanket claim about every state or model.
The defensible 2026 position is simple: retire the false circular citation, label Circular 2023-03 as withdrawn, and anchor the control in current law. Then make the model evidence strong enough to reconstruct each action and support the notice process the creditor actually chose under section 1002.9.
Related reading: CFPB Reg B disparate-impact change · AI model risk assessment
Authoritative sources
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Is CFPB Circular 2023-03 current guidance?
Did CFPB issue Circular 2026-03 on AI adverse action notices?
Does current Regulation B still require specific reasons for adverse action?
Does Regulation B require exactly four adverse action reasons?
What should an AI model evidence file prove?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026
AI Risk
The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.
The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.
Sep 5, 2026