10 to the 23 AI logo

Domain Atlas / Lending & credit collections AI

Case fileUnited States (federal — CFPB no-action letter; fair-lending monitorship via private agreement with civil-rights organizations)large deployment

Automated underwriting with its fair-lending testing on the record

Explore this deployment in the PAN Lab ↗

A machine-learning underwriting and pricing platform using education and other alternative data operated for five years under a regulator's no-action letter with a reporting obligation, and the regulator published the access results: 27 percent more applicants approved than a traditional model at 16 percent lower average APRs, with near-prime applicants (FICO 620 to 660) approved at roughly twice the rate, and gains across the tested demographic segments. This is the lending family's only regulator-verified service term. Underwriting is fully automated with no per-application human review, so the organizational levers are all upstream — model choice, the testing regime, the search for alternatives, and the reporting channel to the regulator.[]

What happened

Upstart's machine-learning model underwrites and prices personal loans using education and other alternative data. Underwriting is fully automated: there is no per-application human review, so the model's decision is the decision, and every governable lever sits upstream of it — the choice of model, the fair-lending testing regime, the search for a less-discriminatory alternative, and the two reporting channels the deployment ran under. That structure is what makes the case legible, because when there is no human in the loop to catch a single error, governance is entirely a question of how the upstream levers are resourced.

The service regime here is the lending family's only regulator-verified term. The model operated for five years under a regulator's no-action letter that carried a reporting obligation, and the regulator published the access results directly: the model approved about 27 percent more applicants than a traditional model at about 16 percent lower average APRs, approved near-prime applicants (FICO credit score roughly 620 to 660) at about twice the rate, and showed access gains across the demographic segments tested. Those are not the deployer's dashboard; they are a regulator's published finding, which is why this deployment anchors the domain's service side rather than merely claiming it.

The governance side is on the record in equal detail, and it does not simply confirm the service story. Under a separate agreement with civil-rights organizations, an independent monitorship produced four public reports on the live model. Quantitatively they found no close protected-class proxies among the model's inputs — but they also identified approval disparities for Black applicants, flagged a likely-viable less-discriminatory alternative model that appeared to perform comparably, and ended in a documented methodological impasse: not over whether a disparity existed, but over how hard the law actually requires an organization to search for a less-discriminatory alternative before it may keep the model it has. That is the domain's hardest governance question, and the record shows it left unresolved rather than settled.

Running underneath both is a duty that is independent of the disparity question entirely. When the model declines an applicant, the organization must still give that applicant specific, accurate principal reasons for the denial — and a regulator has made explicit that a model's complexity is no excuse: if the system cannot produce an accurate reason, the organization may not use it. The explanation is therefore a separately-resourced, separately-failable surface. An organization can pass its bias testing and still fail here, by being unable to tell a declined applicant why. The honest reading is that this deployment's access gains are real and regulator-verified, its fair-lending testing is more transparent than almost any peer's and still ended at an impasse, and its duty to explain a denial is a third thing that neither of those discharges.

The sociotechnical reading

This case sits at the well-lit end of the lending domain: both regimes are on the public record, neither claimed-but-unaudited nor shielded behind privilege. A regulator published the access results, and an independent monitorship published four reports on the live model. That transparency is exactly what makes the case instructive, because it lets you see the limits that survive good governance rather than the ones good governance hides.

Three of those limits generalize. First, with fully automated underwriting there is no per-application human to catch an error, so the whole of governance is upstream — the model chosen, the testing done, the search for alternatives, the reporting channel maintained. "The model decided" is not the end of accountability; it relocates all of it to those upstream levers, and the governable question is whether they are resourced or merely declared. Second, a facially-neutral aggregate feature — a school's cohort default rate priced into an individual's terms — can carry protected-class impact even when no input is a close proxy, which is precisely why disparate-impact testing exists and why "no proxies found" is a finding about inputs, not a clearance of outcomes. Third, and hardest, the live question is not whether a disparity exists but how hard the law requires an organization to search for a less-discriminatory model that performs as well; this deployment's record shows that question reaching a documented impasse, which is the honest state of the art rather than a solved problem.

The explanation duty is the separable fourth surface, and it is the one most easily mistaken for the others. Passing a disparity test does not discharge the obligation to give a declined applicant specific, accurate reasons; a regulator has said complexity is no excuse. So an organization can be statistically clean and still fail its applicants at the moment of the denial notice — which is why the map treats explanation as its own failable duty rather than a byproduct of fairness testing.

The Lab network models only the deploying organization: its model, its compliance and testing functions, and its decision records. No credit outcome and no applicant is computed on any diagram. Applicants are boundary-only; approvals, declines, disparity findings, and the search-for-alternatives impasse are institutional signals that live in this case file, never on any network. The map's instruction is to read the regulator-verified access as real, the monitorship's transparency as real and still bounded by an unresolved legal question, and the duty to explain a denial as a third obligation that being accurate does not satisfy.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

consumerfinancialprotectionb2019GroundingGovernmentSave

Consumer Financial Protection Bureau — Ficklin, P.A., & Watkins, P. (2019). An update on credit access and the Bureau's first No-Action Letter. CFPB Blog. https://www.consumerfinance.gov/about-us/blog/update-credit-access-and-no-action-letter/

https://www.consumerfinance.gov/about-us/blog/update-credit-access-and-no-action-letter/

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM); model org: upstart_nal_underwriting

relmancolfaxpllc2021GroundingAdvocacySave

Relman Colfax PLLC (2021-2024). Fair Lending Monitorship of Upstart Network's Lending Model (Initial, Second, Third, and Final Reports). https://www.relmanlaw.com/cases-upstart-network-fair-lending-counseling

https://www.relmanlaw.com/cases-upstart-network-fair-lending-counseling

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM); model org: upstart_nal_underwriting

Topics: complexity-science

consumerfinancialprotectionb2022bGroundingRegulatorySave

Consumer Financial Protection Bureau (2022, 2023). Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms; and Circular 2023-03 on Regulation B sample forms. https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/

https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM)

Topics: complexity-science

boardofgovernorsofthefederal2011aGroundingRegulatorySave

Board of Governors of the Federal Reserve System & OCC (2011). SR Letter 11-7: Supervisory Guidance on Model Risk Management (superseded April 17, 2026 by SR 26-2). https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm

https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM)

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalA machine-learning underwriting and pricing platform using education and other alternative data operated for f…

A machine-learning underwriting and pricing platform using education and other alternative data operated for five years under a regulator's no-action letter with a reporting obligation, and the regulator published the access results: 27 percent more applicants approved than a traditional model at 16 percent lower average APRs, with near-prime applicants (FICO 620 to 660) approved at roughly twice the rate, and gains across the tested demographic segments. This is the lending family's only regulator-verified service term. Underwriting is fully automated with no per-application human review, so the organizational levers are all upstream — model choice, the testing regime, the search for alternatives, and the reporting channel to the regulator.

consumerfinancialprotectionb2019GroundingGovernmentSave

Consumer Financial Protection Bureau — Ficklin, P.A., & Watkins, P. (2019). An update on credit access and the Bureau's first No-Action Letter. CFPB Blog. https://www.consumerfinance.gov/about-us/blog/update-credit-access-and-no-action-letter/

https://www.consumerfinance.gov/about-us/blog/update-credit-access-and-no-action-letter/

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM); model org: upstart_nal_underwriting

EmpiricalThe same deployment carries the family's most detailed public fair-lending testing record: four reports from a…

The same deployment carries the family's most detailed public fair-lending testing record: four reports from an independent monitorship agreed with civil-rights organizations found no close protected-class proxies quantitatively, but identified approval disparities for Black applicants, flagged a likely viable less-discriminatory alternative model, and ended in a documented methodological impasse over how hard the law requires an organization to search for such an alternative. Independently of the disparity question, adverse-action notices must give specific, accurate principal reasons for a denial regardless of the model's complexity — a governed explanation duty a complex model does not discharge by being accurate.

relmancolfaxpllc2021GroundingAdvocacySave

Relman Colfax PLLC (2021-2024). Fair Lending Monitorship of Upstart Network's Lending Model (Initial, Second, Third, and Final Reports). https://www.relmanlaw.com/cases-upstart-network-fair-lending-counseling

https://www.relmanlaw.com/cases-upstart-network-fair-lending-counseling

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM); model org: upstart_nal_underwriting

Topics: complexity-science

consumerfinancialprotectionb2022bGroundingRegulatorySave

Consumer Financial Protection Bureau (2022, 2023). Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms; and Circular 2023-03 on Regulation B sample forms. https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/

https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/

Appears in: PAN framework development

Grounds: domain grounding: lending, credit and collections (underwriting, adverse action, MRM)

Topics: complexity-science