Regulatory brief · ECOA / FCRA / TILA

The statutes that did not move.

SR 26-2 removed generative and agentic AI from model-risk guidance in April 2026. It did not touch a single statute. ECOA, FCRA and TILA apply to an agentic credit decision exactly as they apply to a human one, and the CFPB has already said in terms that not understanding your own model is not a defence.

The sentence that decides most AI lending arguments

“A creditor’s lack of understanding of its own methods is not a cognizable defense against liability.”

CFPB Circular 2022-03, Adverse Action Notification Requirements and Complex Algorithms (May 2022)

The circular holds that ECOA and Regulation B adverse-action requirements apply equally to all credit decisions regardless of the technology used. A model that cannot produce specific, accurate adverse-action reasons violates ECOA. Not “is risky” — violates.

  • Reasons must relate to and accurately describe the factors actually considered or scored — not the closest item on a sample form.
  • Internal standards or policies are not a substitute for specific reasons.
  • Up to four principal reasons are disclosed per adverse action.
  • Post-hoc explanation methods such as SHAP or LIME must be validated for accuracy, not just produced.
  • Circular 2023-03 extended this: if a model uses non-traditional data such as rent or utility payments, the reasons must reference those actual factors.

It applies to denials, credit line decreases, unfavourable term changes, and refusals to increase a limit — not only to declines.

What each statute demands of an automated decision

StatuteObligation that reaches an AI decision
ECOA / Reg BNo discrimination on protected characteristics; specific adverse-action reasons; notice within the required period
FCRAPermissible purpose for credit report use; adverse-action notices citing specific reasons; dispute rights
TILA / QMDisclosure of APR, finance charges and total cost; ability-to-repay; the 43% DTI limit for Qualified Mortgages

What Sentinel does about it

  • Prohibited factors are detected before the action executes, not found in a quarterly review.
  • Disparate impact is monitored against the four-fifths rule, computed as arithmetic over group counts.
  • Reason codes are generated from the rules that actually fired — the explainability module reports the decision path, so the stated reason and the operative factor are the same object rather than two artefacts you hope agree.
  • Every decision is chained and exportable as an evidence bundle a third party can verify.

What this does not do

Sentinel enforces the policy you configure. It does not certify that your policy is lawful, it does not write your adverse-action notices, and a verdict is not a regulatory determination. If your rules encode a proxy for a protected characteristic, Sentinel will enforce that faithfully. The disparate-impact monitor is designed to surface exactly that case, but the obligation remains yours.

Sources

Check every claim above. We would rather you did.

If we have characterised any of this incorrectly, tell us and we will correct the page.

Design partners

Bring your adverse-action process.

The fastest way to see whether this helps you is a shadow run against real declines, comparing the reasons your agent gives with the factors that actually drove the decision.