
ECOA Adverse Action Notice: Shipping AI Safely
An AI credit model is only shippable if it can name the specific reason it said no.
Blake Aber · Predicate Ventures · 2026
The hard part of putting a model behind a lending decision is not accuracy. It is the letter you have to send when the answer is no.
The Equal Credit Opportunity Act and Regulation B require creditors to give applicants a written statement of specific reasons when they take adverse action. Those requirements apply to every credit decision, regardless of the technology that produced it. A model does not get a compliance discount for being complicated.
What the notice actually requires
Regulation B is precise about what counts. The statement of reasons must be specific and indicate the principal reason or reasons for the decision. Saying the action was based on internal standards, general policies, or a failure to reach a qualifying credit score does not satisfy the rule.
The timing is fixed too. A notice of adverse action must generally be given within 30 days after a completed application. A creditor making a counteroffer has 90 days to send the notice if the applicant declines it. Regulation B sets both windows.
There is a narrower path for large business applicants. For business credit applicants with gross revenues over $1 million, the creditor may give notice orally or in writing within a reasonable time, and must provide a written statement of reasons only if the applicant requests it within 60 days. That exception is defined in Part 1002. It does not extend to consumer lending.
The black-box problem is a design constraint
The CFPB has been direct. ECOA and Regulation B do not permit creditors to use complex algorithms when doing so means they cannot state specific and accurate reasons for an adverse action.
Read that as an engineering requirement, not a legal footnote. If your model cannot produce a faithful, decision-level explanation, you cannot legally deploy it for credit. Explainability moves from a nice-to-have into a gate that a model must clear before it reaches production.
The follow-up guidance closed a common shortcut. In Circular 2023-03, issued September 19, 2023, the CFPB said creditors using AI or complex credit models may not rely on the checklist of sample reasons in the Regulation B sample forms if those reasons do not specifically and accurately identify the actual reasons for the decision.
So the sample forms are a starting vocabulary, not a safe harbor. A team that maps every denial to "insufficient credit history" because it is on the list, when the model actually keyed on something else, has produced an inaccurate notice.
One more trap. Disclosing the key factors that adversely affected a consumer's credit score does not by itself satisfy the ECOA requirement to disclose specific reasons for adverse action. Credit-score reason codes and adverse-action reasons are different obligations. Shipping the former and calling it done leaves a gap.
What non-compliance costs
The exposure is concrete. ECOA provides for punitive damages of up to $10,000 in individual lawsuits, and up to the lesser of $500,000 or 1 percent of the creditor's net worth in class actions, on top of actual damages.
A class action is the shape that matters for a model. A single denial letter with a wrong reason is a defect. The same defect across a population of applicants, produced by the same model, is a class. Systematic errors scale the same way the system does.
Designing for the notice from day one
The cheapest time to build adverse-action reasoning is before the model ships. Retrofitting explanations onto a system that was optimized only for accuracy is where compliance debt accumulates.
Make explanations part of the prediction
Every scored decision should emit the score and the reasons together, in the same call. The reasons should be derived from the features the model actually used, weighted by their contribution to that specific decision. If your explanation method cannot answer "why this applicant, not the average one," it is not producing an adverse-action reason.
Favor model architectures and attribution methods whose outputs you can defend to an examiner. A per-decision explanation you cannot reproduce or reason about is worse than a simpler model you can.
Map reasons to language that is specific and true
The reason a model produces internally is a feature and a direction. The reason on the letter is a sentence a person reads. The mapping between them is a controlled artifact.
Build that mapping so each phrase is accurate for the decision it describes, and version it. When the model changes, the reason mapping is part of what gets re-reviewed. Do not let the letter drift from the model.
Keep an audit trail that reconstructs the decision
For any past decision, you should be able to recover the model version, the input features, the score, the reasons emitted, and the notice sent. That record is what turns a regulator inquiry from a fire drill into a query.
Store inputs and outputs together, immutably, keyed to the applicant and the decision. The 30-day notice window and the 60-day business-request window both assume you can find the decision later. An audit trail that cannot reconstruct a specific case is not an audit trail.
Treat the model registry as a compliance record
Every deployed model version should carry its evaluation, its reason mapping, its approval, and the dates it was live. When a class-action question arrives about decisions from a given quarter, you want to name the exact model that made them and produce its documentation without archaeology.
The shippable posture
A credit AI system is regulator-ready when three things are true at once. It produces a specific, accurate reason for every adverse action. It records enough to reconstruct any past decision. And its explanation, reason mapping, and model version move together through review.
None of this is a tax on the model. It is the difference between a system you can defend and a class action waiting to be filed. Build the notice into the architecture, and the letter takes care of itself.