LENDING & CREDIT AI · INDEPENDENT AUDIT · PER RELEASE

Your AI makes credit decisions. Can you defend them?

Regulation B follows the credit decision, not the code - disparity testing, proxy analysis, and reason codes that match the model as it ran.


A reviewer with blonde hair tied back, in a charcoal blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Independent means no stake in the answer
ECOA / Reg B Adverse action Disparate impact Proxy analysis Model risk

Our promise

“The numbers are not negotiable. That is what you are buying.”

Every finding is written against the obligation it answers — defensible line by line, to anyone who asks. The fee starts at $5,000, and nothing is charged until you approve it.

Request this lending AI audit
The case file

Lending AI, in three chapters

The Rules

Nobody is waiting for an AI statute to look at a credit model. The Equal Credit Opportunity Act, Regulation B and the Fair Credit Reporting Act already reach it, exactly as they reach a human underwriter: by asking what the decision rested on and precisely what the applicant was told.

The Gap

Most lenders assume their vendor’s fairness testing covers them. It rarely does: it describes the vendor’s population, not your book, your cut-offs or your overrides. Add reason codes generated from a simplified stand-in for the live model, and quiet exposure is the default outcome.

The Office

We are the independent reviewer your risk committee, partner bank and examiner mean when they ask who checked it. iDharma tests your decisions - disparity by protected class, alternative data for proxy effect, and each reason code against the live model that produced it, not a stand-in.

What counts as lending AI?

A model that decides before you do.

Anything that scores or ranks an applicant and shapes the credit decision.

What we look at № 01
  • Scorecards and machine-learning underwriting models
  • Pricing, line-assignment and limit-increase engines
  • Fraud and identity screens that can suppress an application
  • Vendor scores and third-party APIs you call at decision time
Lending AI · iDharma · Presented for assay
When the duty bites № 02
  • The output changes an approval, a price or a limit
  • On every decline - the notice carries the real reasons
  • Whenever the model is retrained, recalibrated or re-cut
  • When a partner bank or an examiner asks what you tested
Lending AI · iDharma · Presented for assay
Whose duty is it

The duty is yours. The model is theirs.

You

The creditor

ECOA and Regulation B follow the credit decision. Whoever decides to extend, price or decline the credit owes the applicant a notice with the specific principal reasons, and owes the regulator an explanation of how the decision was reached. Neither duty can be handed to somebody else.

Your vendor

The people who built the model

Carries no adverse-action duty to your applicant. Many vendors do genuinely careful fairness work and publish it, and a good model card is worth having. The difficulty is not its quality - it is whose applicants it was measured on, and those were never the people you declined.

The catch

When their testing helps you

A vendor's testing tells you about the vendor's population. Your own book has its own geography, its own marketing, its own cut-offs and its own overrides - and disparity is produced by all four of them. If the numbers were never run on your decisions, they say nothing about your decisions.

What most teams assume

“Our vendor tested the model, so we’re covered.”

What the rule says

The duty follows the decision, not the code.

It is the most common finding we write up.

  • Who it is for
  • Banks & credit unions
  • Fintech lenders
  • Mortgage originators
  • Risk & compliance
  • Model risk management
Why this matters now

Enforcement is already live

A black archive binder closed on a dark desk under a low lamp, a blank brass label plate screwed to its spine and a wax seal holding the page block shut, with a clipped sheaf of papers, reading glasses and a fountain pen laid out beside it: the model record, sealed and unopened until somebody asks for it.
01 Nobody is waiting for an AI statute. The rules that already govern a credit decision reach the model that made it, and they were written to be applied after the fact.
02

Model complexity is not a defence to Regulation B. A notice still owes the applicant the specific principal reasons the credit was denied.

03

Exposure runs on decisions, not on findings. It is every applicant affected, for as long as the model ran - which is arithmetic, not a fine.

04

Your partner bank asks before any regulator does. Diligence now opens with what you tested, on whose data, and who signed it.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

A model shapes the decision -

Routing counts. A score that sends an application to a different queue, a different cut-off or a different price is shaping the decision, even where a person signs it off at the end.

Tested on your own book -

Vendor testing rarely transfers. It describes the vendor’s population. Your geography, marketing, cut-offs and overrides all move outcomes, and none of them were in it.

Reasons from the live model -

Regulation B wants the real ones. The specific principal reasons this applicant was declined, from the model that declined them - not from a simpler model standing in for it.

The calendar

Four moments, and only one is a deadline.

Only the second is fixed by a rule. The other three are the moments somebody asks — and the only variable you control is whether the work was already done.

  1. Test

    Before launch

    Disparity and proxy testing before the model decides anything - after launch it is a remediation, not a design choice.

  2. Notify

    Within 30 days

    Regulation B's clock on a completed application, and the only hard deadline here. The reasons must be the real ones.

  3. Revalidate

    On every change

    A retrain is a new model. New weights, new cut-offs and new data all move outcomes across groups - so they move the answer.

  4. Review

    Annually

    Drift is silent and cumulative. The population changes underneath a model that has not been touched, and so do its outcomes.

The trap

Teams schedule the fairness testing for after launch, and forget that the notice duty starts on the first decline. If the model goes live on the 1st, the reason codes had to be right on the 1st - and the testing that tells you whether they are had to be finished before that.

Requirement & coverage

What the rules ask, what we ship

12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

Whose obligation it is The creditor, never the model vendor
A written determination of who owes the duty for each decision, so a vendor's testing is never mistaken for yours.
Reliance on vendor testing Their population is not your book
An assessment of what your vendor's testing does and does not cover for you - and exactly what must be re-run on your own decisions.
Specific principal reasons ECOA / Regulation B - no model-complexity exemption
Every reason code traced back to the model as it actually ran, so the notice says what the decision was really made on.
Adverse-action timing Within 30 days of a completed application
A walk of the notice path end to end, including the declines your queue routes around, with the gaps named.
Disparate impact A neutral rule can still produce a disparity
Outcome rates and disparity ratios by protected class, for approval, pricing, line assignment and override.
Intersectional outcomes Disparities hide on a single axis
The full intersected grid, not one variable at a time - which is where the findings usually are.
Proxy analysis Alternative data standing in for a protected class
Each alternative-data feature tested for how much of a protected characteristic it carries, ranked by contribution.
Less discriminatory alternative Whether a fairer model performs comparably
A documented search for alternatives at comparable performance, and the record of what was tried and rejected.
Data provenance FCRA permissible purpose, and the right to use it
Where each input came from, on what basis you hold it, and what bias it brings in with it.
Model documentation SR 11-7 practice for supervised institutions
An inventory entry per model: owner, purpose, limitations, change history, and who signed each change off.
Independent validation Effective challenge from outside the build team
A validation by people with no role in building, selling or operating the model - and no fee tied to the finding.
Ongoing monitoring Drift, overrides and the population underneath
The monitoring you have, the monitoring you need, and the thresholds that should trigger a human looking at it.
The engagement

Lending AI, independently audited

From a scorecard to a vendor API.

  1. Request and scope

    Which models, which decisions, which book. Priced and approved before anything is charged.

  2. Test

    Disparity across protected classes, proxy analysis, reason codes, documentation. One to four weeks.

  3. Sign off and report

    You see the draft first. Then the report, the tables and the shortlist - dated and signed.

Request a lending AI audit
An auditor in a charcoal suit and white shirt, with grey hair, standing against a warm pale wall and pointing into the open space alongside.
The numbers are not negotiable - that is what you are buying.
Struck in your favour

Why lenders choose iDharma to review their models

Genuinely independent

We build, resell and score no credit models, and we take no fee tied to what the audit finds.

Written to the obligation

Every finding maps to the rule it answers, so your counsel checks it against the rule itself.

One engagement, end to end

Fairness, reasons, data and governance in one scope, so nothing falls between two reviewers.

Proxy analysis by default

Alternative data is tested for proxy effect in the base scope, not sold on - it is where findings are.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Fair-lending audit report

The full review: method, data sources, every disparity figure, and the findings written in language your risk committee can act on - approval, pricing, line-assignment and override outcomes by protected class and by the classes intersected, each alternative-data feature scored for proxy effect, and every reason code traced to the model that produced it.

Signed by a named independent reviewer with no role in building, selling or operating the model, and no fee tied to the finding. Written so a partner bank, an examiner or your own board can read it without a translator.

Workbook

Disparity tables

The underlying rates and ratios in a workbook, so your own analysts can reproduce every figure in the report, cell by cell, without asking us.

Memo

Adverse-action review

Each reason code checked against what the model actually weighed for that decision, with the codes that cannot be substantiated named individually.

Analysis

Proxy analysis

Every alternative-data feature ranked by how much of a protected characteristic it carries, with the ones worth removing or replacing called out.

Memo

Model documentation review

What your inventory records against what the model does, with the gaps a validator or an examiner would open the conversation with, listed.

Ranked

Remediation shortlist

Where the numbers point to a problem, what to look at first, and why. Ranked by consequence to borrowers, not by which fix is easiest to ship.

Memo

Vendor-model assessment

What your vendor's testing covers for your book and what it does not - and exactly which figures have to be re-run on your own decisions.

Format & fee

Real numbers, upfront.

Scope
Agreed with you, then fixed
Data
Your own decision records
Re-review
On every material retrain - $3,000 against your known baseline

Nothing fixes the scope but the models you run, so the fee is quoted rather than listed - and nothing is charged until you have approved it.

Request a lending AI audit
Lending AI · Scoped engagement $5,000 from
  • Independent fair-lending review
  • Disparity by protected class, intersected
  • Proxy analysis on alternative data
  • Adverse-action reason substantiation
Show your hand

Four things you have to be able to produce

Fair lending is not graded on intent. Each of these is either in your hand on the day somebody asks, or it is not.

The reasons,
specific

The principal reasons this applicant was declined, reproducible from the model that declined them. A checklist reason is the one an examiner reads as an admission.

The testing,
dated

Fair-lending testing on your own decisions, carrying the date it was run and the version of the model it was run against. Testing without a version is testing of nothing.

The record,
complete

What the model is for, what it may not be used for, what changed, when, and who approved it. The change nobody wrote down is the one the question will be about.

The numbers,
by group

Approval, pricing and override outcomes by protected class and by the classes intersected. The table is the evidence; a fairness score is not the same thing.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Scope, testing, the engagement, exposure. Answered straight.

Request this audit
Our vendor scores the applications. Are we still on the hook?

Yes. ECOA and Regulation B follow the credit decision, not the code. Their testing describes their population; your approvals, your pricing and your overrides are what a regulator will ask about.

What counts as a lending AI model here?

Anything that scores, ranks or classifies an applicant and shapes the credit decision - a scorecard, an ML underwriting model, a pricing engine, a fraud screen or a vendor API. The test is what the output does to the decision.

What exactly do you test?

Outcome disparity by protected class and by classes intersected, alternative data for proxy effect, whether reason codes match the model as it ran, data provenance, and the documentation and monitoring behind it.

How long does it take, and what does it cost?

One to four weeks for most engagements. The scope and the price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.

What happens if we get this wrong?

Fair-lending exposure is not a fixed fine. It runs on the decisions - every applicant affected, for as long as the model ran - and reaches restitution, model changes under supervision, and the referral that follows.

Get started

Operating AI in lending, credit or underwriting?

Tell us what decides, and we come back with a scope and a price within one business day.

What we need from you

Nothing you do not already have. Most of this is an extract of your decision records and a folder your model owner assembles in an afternoon, named in writing first.

  1. Which models decide, and at which stage
  2. Whether they are built in-house, bought, or both
  3. Decision records for the period, with outcomes
  4. Any fairness testing already done, and by whom
  5. Your target date for a read, if you have one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a lending AI audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • ECOA & Regulation B, 12 CFR 1002
  • FCRA; Fair Housing Act; SR 11-7
Applies to
Credit decisions today
Last read
9 September 2026

What it means

  • General information about what these rules require — not legal advice, and no professional relationship arises from reading it. It determines nothing about your own models.
  • Where a fair-lending question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • Use it as a starting point for a scoping conversation, not as your final word.
  • Whether a disparity is a legal problem turns on your product, your market and what a comparably performing alternative would have done — none of which a web page can see.

Something on this page out of date?

Tell us