Domain Atlas / Lending & credit collections AI
The governance an enforcement action had to write
Explore this deployment in the PAN Lab ↗
A state attorney general reached a $2.5 million settlement with a student-loan lender over its AI underwriting. The documented conduct is the domain's cleanest failure-then-mandated-governance arc: the model used a cohort-default-rate feature — a school's aggregate default rate priced into an individual applicant's terms — that disparately impacted Black and Hispanic applicants, and an immigration-status rule that automatically denied certain non-citizen applicants, while the organization ran no disparate-impact testing and gave inadequate adverse-action notices. The remedy did not fine-and-close: it mandated the missing program — model governance, disparate-impact testing, documentation, and reporting controls — so the enforcement action wrote the governance the deployment had never built.[†]
What happened
Earnest, a student-loan lender, underwrote eligibility, terms, and pricing with algorithmic models. A state attorney general investigated and reached a $2.5 million settlement, and the documented conduct makes this the lending domain's cleanest failure-then-mandated-governance arc — not because the model was uniquely bad, but because the governance around it was uniquely absent, and the remedy is what installed it.
Two model features carried the documented impact. The first is a cohort-default-rate feature: the model priced a school's aggregate default rate into an individual applicant's terms. A cohort default rate is a property of an institution, not of the person applying, and it names no protected class — yet pricing a group's aggregate history into an individual's offer disparately impacted Black and Hispanic applicants. This is the domain's aggregate-feature mechanism in its sharpest form: a facially-neutral input, neutral line by line, producing a disparity visible only in outcomes. The second is an immigration-status rule that automatically denied certain non-citizen applicants — a categorical exclusion built into the decision.
What made these features a governance failure rather than a modeling choice is what was not there. The organization ran no disparate-impact testing, so the impact of the cohort-default-rate feature went unmeasured until an outside enforcement action found it. And its adverse-action notices were inadequate: applicants denied by the model were not given the specific, accurate reasons the law requires. The failure, in other words, was not only two features; it was the absence of the testing that would have caught the first and the explanation channel that would have told applicants about the second.
The remedy is the instructive part. The settlement did not simply penalize and close the matter; it mandated the program the deployment had never built — model governance, disparate-impact testing, documentation, and reporting controls. The enforcement action wrote the governance retroactively, which is the honest shape of this case: the levers that would have prevented the harm are exactly the levers the order installed, and they are ordinary, nameable governance functions that the organization could have run from the start. Nothing here required a more accurate model; it required the testing, the documentation, and the explanation the deployment skipped.
The sociotechnical reading
This case is the domain's demonstration that the failure of an AI underwriter can be, precisely, the absence of governance — and that the remedy is to install the governance, not to change the model. The two documented features (a cohort-default-rate input, an immigration-status auto-denial) are the visible harm, but the governable finding is what was missing around them: no disparate-impact testing to catch the aggregate feature's outcome disparity, and no adequate adverse-action explanation for the people the model denied. The enforcement action then mandated exactly those missing functions, which is why this case reads as a blueprint of the levers rather than a story about a bad model.
The aggregate-feature mechanism is the transferable lesson. A cohort default rate is neutral input-by-input — it is about a school, and it names no protected class — and it can still carry protected-class impact when it prices a group's aggregate history into an individual's terms. That is the exact gap disparate-impact testing exists to close: input-level neutrality is not outcome-level fairness, and only outcome testing can tell the difference. When that testing is absent, the disparity is not detected internally; it is detected by whoever looks from outside, which here was a regulator. The map's instruction is that an aggregate feature is a testing obligation, not a modeling convenience.
The remedy carries the second lesson: the governance an enforcement action mandates is ordinary governance. Model governance, testing, documentation, reporting, and an adequate explanation channel are nameable functions any deploying organization can run before an order compels them. The honest reading is that the settlement did not invent new controls; it installed the standard ones the deployment had skipped — so the case is less a story of unavoidable harm than of a resourcing choice made too late, with the levers drawn latent here precisely because they are the ones the order turned on.
The Lab network models only the deploying organization: its model, its compliance function, and its decision records. No credit outcome and no applicant is computed on any diagram. Applicants are boundary-only; the documented features, the absent testing, the inadequate notices, and the mandated remedy are institutional signals that live in this case file, never on any network. The map's instruction is to read the absence of testing and explanation as the failure itself, and the mandated program as the set of ordinary levers that were available the whole time.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.