Lending & credit collections AI
Machine-learning underwriting, pricing, and credit decisioning — often fully automated, with no per-application human review, so the organizational levers all sit upstream: the choice of model, the fair-lending testing regime, the search for a less-discriminatory alternative, and the adverse-action notice that must explain a denial. Three facts shape the governance. A denial's explanation is a separately-resourced, separately-failable duty independent of statistical bias: a model can pass the disparity test and the organization can still fail by being unable to give an applicant specific, accurate reasons. Facially-neutral aggregate features — a school's default rate priced into an individual's terms — can carry protected-class impact, which is exactly what disparate-impact testing exists to catch. And the harder governance question is not whether a disparity exists but how hard the law requires an organization to search for a less-discriminatory model that performs as well — a question the record shows resolved by enforcement or left at an impasse, rather than settled. The Lab networks model only the deploying organization — its model, compliance and testing functions, and decision records; the applicants being decided sit outside the dynamics, and no credit outcome is computed on any diagram.
Use cases
What AI is doing here
ML underwriting & risk-based pricing
PredictiveMachine-learning models that approve, decline, and price credit — often fully automated with no per-application human review, so every governable lever is upstream: the model chosen, the fair-lending testing regime, and the search for a less-discriminatory alternative that performs as well.
Adverse-action reason generation
PredictiveThe system that must turn a model's denial into specific, accurate principal reasons for the applicant — a separately-resourced, separately-failable duty a complex model does not discharge by being statistically accurate, and one an organization can fail even when its bias testing passes.
Fair-lending & disparate-impact testing
PredictiveThe testing regime that checks a model for protected-class impact carried by facially-neutral aggregate features — and, past detection, the contested search for a less-discriminatory model, where the hard governance question is how hard the law requires an organization to look.
Case files
What has gone wrong and right
Documented deployments, presented as model organizations calibrated to the evidence, with full citations.
Automated underwriting with its fair-lending testing on the record
United States (federal — CFPB no-action letter; fair-lending monitorship via private agreement with civil-rights organizations)Upstart's machine-learning underwriting and pricing model, which uses education and other alternative data, ran for five years under a regulator's no-action letter with a reporting duty, and the regulator published the access results: 27% more applicants approved than a traditional model, at 16% lower average APRs, with near-prime applicants approved at roughly twice the rate. It is the lending family's only regulator-published service term — and its most detailed public fair-lending record. Four monitorship reports found no close protected-class proxies, but identified approval disparities for Black applicants, flagged a likely-viable less-discriminatory alternative, and ended in a documented impasse over the legally required way to judge whether such an alternative performs comparably. Underwriting is fully automated, so every governable lever is upstream.
Explore this deployment in the PAN Lab →Cleared on the numbers but faulted on the explanation
United States (state financial-services supervisory investigation of a bank's card underwriting)A bank's automated credit-decisioning for a widely used consumer card drew viral allegations of gender bias in credit-line assignment. A state regulator analyzed roughly 400,000 in-state applicants and found no unlawful discrimination on a prohibited basis — the model was cleared on the numbers. The same investigation documented failures of explanation, customer service, and perceived transparency: applicants had little insight into why they received the terms they did, a complainant said customer service could not explain the decisions, and the opacity undermined consumer trust even though the underwriting was found lawful. The cleared-but-faulted case: a statistically clean model paired with a failure of transparency, which regulators treat as a separate obligation a black box does not discharge by being accurate.
Explore this deployment in the PAN Lab →The governance an enforcement action had to write
United States (state attorney general fair-lending enforcement; Assurance of Discontinuance)A state attorney general reached a $2.5 million settlement with the student-loan lender Earnest over its AI underwriting — the domain's cleanest failure-then-mandated-governance arc. The attorney general alleged that the model used a cohort-default-rate feature (a school's aggregate default rate priced into an individual's terms) that disparately impacted Black and Hispanic applicants, and an immigration-status rule that automatically denied certain non-citizen applicants, while the organization ran no disparate-impact testing and gave inadequate adverse-action notices. Earnest denied the allegations and admitted nothing. The remedy did not fine-and-close: it barred both features and mandated the missing program — model governance, disparate-impact testing, documentation, and reporting controls. The enforcement action wrote the governance the deployment had never built.
Explore this deployment in the PAN Lab →TransUnion's OFAC Name Screen & the people who could not sue
United States — federal. Principal action: Ramirez v. Trans Union, LLC, No. 3:12-cv-00632-JSC (N.D. Cal.), class of 8,185 certified July 2014, jury verdict 21 June 2017, affirmed in part with punitive damages reduced by the Ninth Circuit on 27 February 2020 (No. 17-17244), and reversed and remanded by the Supreme Court on 25 June 2021 in TransUnion LLC v. Ramirez, 594 U.S. 413 (No. 20-297). Predecessor action: Cortez v. Trans Union, LLC, 617 F.3d 688 (3d Cir. 2010) (Nos. 08-2465 & 08-2466), out of the Eastern District of Pennsylvania — the one final appellate liability holding against this practice, and what put the operator on notice. Sequel action: Ramirez Arrizon v. TransUnion, LLC, 2025 IL App (1st) 231911, in the Circuit Court of Cook County, Illinois and the Illinois Appellate Court, First District, where a class member held to lack federal standing refiled in a forum with no concreteness requirement and the dismissal as time-barred was affirmed on 31 March 2025.TransUnion sold an add-on that compared a consumer's first and last name against the U.S. Treasury's terrorist and narcotics sanctions list and nothing else — no date of birth, no middle initial, no Social Security number — then wrote a potential-match alert on the front page of the credit report and, from 2002, redacted it from the copy it sent the consumer. Across more than a decade the courts recorded thousands of false positives and not a single confirmed true match; in one seven-month window in 2011 the product labelled 8,185 people. In TransUnion LLC v. Ramirez the Supreme Court held that only the 1,853 whose reports a business happened to pull inside that window had suffered a concrete harm and could sue, and expressly took no position on whether the product was accurate or whether the statute had been violated as to the other 6,332. Two thousand people were eventually paid; when one of the excluded 6,332 refiled in a state court without a concreteness requirement, the claim was held time-barred.
Explore this deployment in the PAN Lab →System map
Who is in the system and what pushes on it
Who is in the system
- Agency leadership. Owns procurement, policy, and the authority map; answers for the system publicly.
- Served people & families. Those the decisions land on. Deliberately outside the PAN dynamics — their outcomes are measured, never simulated.
- Vendors. Build and update the systems; hold the information asymmetry procurement must govern.
- Regulators & oversight bodies. Boards, auditors, data-protection officers, inspectorates — external correction capacity.
- Courts & commissions. The heaviest, slowest actors — who end most of the failures documented in this Atlas.
- Advocates & community organizations. Surface harms institutions do not see; historically the earliest accurate signal.
Dominant pressures
- Reviewer bottleneck. One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Austerity & recovery incentives. Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity. The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift. The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance. Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
Governance
Questions leaders should be asking
- 1. Underwriting here is fully automated, so there is no per-application human to catch an error — which means every governable lever is upstream (model choice, testing, the search for alternatives); are those levers actually resourced, or is 'the model decides' treated as the end of the accountability?
- 2. A denial has to be explained with specific, accurate reasons regardless of how complex the model is — so can the organization and its front line actually tell an applicant why, or has passing the disparity test been mistaken for discharging the separate duty to explain?
- 3. A facially-neutral aggregate feature — a school's default rate, a ZIP code — can price a group's history into an individual's terms; so is anyone testing the features for protected-class impact, and would a disparity be caught by design or only by a regulator?
- 4. The hard question is not only whether a disparity exists but how hard the law requires searching for a less-discriminatory model that performs as well — so is that search being done and documented, or is it left to an impasse or an enforcement order to force it?
For the actions behind these questions, see the Practice Library.
Seeing your organization in this domain? Mapping its actual pathways, pressures, and correction capacity is engagement work.
Work With Paramerge