TwinEthosRequest access

Control

Significant-decision ADMT without consumer access explanation

Consumers must be able to obtain a plain-language explanation of the purpose, logic, and outcome of significant-decision automated decisionmaking technology used about them.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People cannot obtain an explanation of an AI-assisted decision about them · control id cond.admt-no-access-explanation

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in California (US-CA); next date 2027-01-01.

The guard to add

Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.

At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What reviewers look for: decision rows carrying purpose, key factors, output, how it was used, and human role for every significant decision; an access-request handler or export job that reads those rows and returns a plain-language explanation plus rights information to the verified consumer.

Example (Python + scikit-learn), before:

score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')

After:

score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
                     'key_factors': reason_codes(features), 'model_output': score,
                     'how_used': 'scores of 0.6 or more approve; lower scores deny',
                     'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Upcoming dates

Every rule this guard addresses

Binding law — not yet in force or stayed (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere