
FCRA Adverse Action: Shipping AI Without Compliance Debt
An AI decision engine that can't explain a denial is a liability pretending to be a feature.
Blake Aber · Predicate Ventures · 2026
The constraint is older than the model
Teams building credit decisioning tend to treat adverse-action requirements as a late-stage legal review. That ordering is backwards. The requirement to explain a denial shapes what kind of model you can ship, and it should be fixed before training begins.
Under Regulation B, which implements the Equal Credit Opportunity Act, a creditor must notify an applicant of action taken within 30 days of receiving a completed application, including adverse action. 12 CFR Part 1002. When a counteroffer is extended and the applicant neither accepts nor uses the credit, the window extends to 90 days. 12 CFR Part 1002.
These are not soft targets. They are dated obligations that your system has to meet for every decision it touches, including the ones a model made at 3 a.m. with no human in the loop.
Explainability is a product requirement, not a research goal
The hard part is not sending a notice on time. It is stating the specific reasons the application was denied.
The CFPB addressed this directly in Circular 2022-03, which affirmed that creditors must comply with adverse-action requirements even when complex algorithms make it difficult or impossible to identify the specific reasons for a denial. Circular 2022-03. The guidance drew a clear line: model complexity is not a defense.
That circular, along with Circular 2023-03, was withdrawn on May 12, 2025, as part of a broad removal of CFPB guidance documents. Withdrawn Guidance.
Withdrawal of the guidance does not withdraw the statute. ECOA and Regulation B still require specific-reason disclosure. The circulars articulated an interpretation that an opaque model is not a shield; the underlying legal requirement that produced that interpretation is unchanged. Designing as if explanations are mandatory remains the defensible choice.
What "specific reasons" demands of your architecture
A reason like "your score was too low" does not satisfy the requirement. The applicant needs the actual factors: income relative to obligations, length of credit history, recent delinquencies.
This rules out any design where feature attribution is an afterthought bolted onto a black box. The attribution method has to be reliable enough that the reasons you disclose actually reflect the decision the model made. If your explanation layer and your scoring layer can disagree, you have a compliance gap disguised as a dashboard.
Two workable paths exist. Use models that are inherently interpretable, where the contribution of each input is readable from the model structure. Or use a flexible model paired with an attribution method you have validated against ground truth, so the stated reasons match the mechanism. Either way, the reason-generation step is part of the model, not downstream of it.
Audit trails are the difference between a decision and a claim
A decision your system cannot reconstruct did not happen in any way a regulator will accept.
Regulation B requires creditors to retain, for 25 months, any written or recorded material related to a consumer credit application, including copies of the notification of action taken and the statement of specific reasons for adverse action. Supporting Statement, Regulation B.
For an AI system, retention means more than storing the output. To defend a decision 24 months later, you need the input features as they existed at decision time, the model version that scored them, the reasons generated, and the notice sent. If a model has been retrained three times since, the record has to point to the exact version that produced the result.
Design the record first
Log the decision as an immutable record at the moment it is made. Version every model and every feature transformation, and bind the decision to those versions. Store the generated reasons alongside the score, not reconstructed on demand from a model that may have changed.
The cost of skipping this is not a missing log. It is the inability to prove what your system did, which under a 25-month retention regime is a standing liability for every decision you ever shipped.
Regulator-ready design is cheaper than compliance debt
The debt accrues when explainability and audit are retrofitted after a model is in production. By then the model was chosen for accuracy alone, the attribution layer is an approximation nobody validated, and the logs capture outputs but not the inputs or versions behind them.
Unwinding that is expensive. You end up re-architecting the decision path, re-validating attribution, and backfilling records you never captured. Some of it cannot be backfilled, because the state that produced past decisions is gone.
The alternative is to treat four requirements as fixed constraints before training:
- Every decision produces specific, accurate reasons tied to the inputs.
- Those reasons are generated by the same process that made the decision.
- Every decision is logged immutably with its model version and feature state.
- Notices meet the 30-day and 90-day windows automatically.
These constraints narrow your modeling choices. That narrowing is the point. A model you cannot explain is a model you cannot ship in this product, so it should not be a candidate.
The regulatory floor will move; build above it
The May 2025 withdrawals show that guidance is not stable. Interpretations are issued and rescinded, and the posture of any given regulator shifts with administrations.
The statutes move more slowly. ECOA and Regulation B have required specific-reason adverse-action notices for decades, and that requirement survived the withdrawal of the circulars that interpreted it for AI. A system built to the statutory floor stays compliant across guidance changes.
Building to the floor also builds trust with the person on the other end of the decision. An applicant who receives accurate, specific reasons for a denial can act on them. An applicant who receives a vague score has been given nothing. The design that satisfies the regulator is the one that treats the applicant as someone owed an explanation, which is what the law assumed all along.