Binding law — in force AI-adjacent law
Give credit applicants the specific principal reasons for adverse action, drawn from the factors the model actually scored (Regulation B, 12 CFR 1002.9)
A creditor that takes adverse action on a credit application must notify the applicant in writing with a statement of the action and either a statement of specific reasons or a disclosure of the right to one (12 CFR 1002.9(a)(2)); the reasons must be specific and indicate the principal reasons, and saying the applicant failed the creditor's internal standards or did not reach a qualifying score on its credit scoring system is insufficient (1002.9(b)(2)). Under the Official Interpretations the reasons must describe the factors actually considered or scored, and for a credit scoring system relate only to factors actually scored, with no principal reason left out (Supp. I, comments 9(b)(2)-2 and -4). The rule never mentions AI; it is encoded as AI-adjacent (owner decision D-19, D-11 pattern 1) because model-driven credit decisions must still produce these reasons. Detect credit code where a model or LLM decision sets a declined status with no reason codes.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
- Lane
- Binding law — in force In force: applies since 30 Dec 2011
- Official source
- 12 CFR 1002.9(b)(2) · captured 4 Oct 2026 · anchor hash (SHA-256)
c3e5658bbb31…· 8 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Adverse action notices generated by a separate service
- Declines encoded as numeric codes or enums
- Reasons may be computed in a separate adverse-action notice service; confirm the declined status always produces them. Reasons an LLM writes freely are not enough: they must describe the factors the model actually score…
Who it applies to
- Duty falls on: organization
- Sectors: lending
- Creditors (12 CFR 1002.2(l)) that take adverse action (1002.2(c)) on an application for credit, consumer or business, where a credit scoring model, machine-learning model or LLM drives or contributes to the decision, for applicants in the United States. Part 1002 is in force from 2011-12-30; the reasons duty predates it (the Board's Regulation B).
- Not covered:
- Persons excluded from coverage of part 1002 by section 1029 of the Consumer Financial Protection Act of 2010 (certain motor vehicle dealers) (12 CFR 1002.1(a))
- Actions that are not 'adverse action' under 1002.2(c)(2): agreed changes to account terms, action on inactive, defaulted or delinquent accounts, most point-of-sale authorization refusals, refusals required by law, and refusals of credit the creditor does not offer
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Compute each applicant's principal reasons from the factors the model actually scored, and put them (or the right to obtain them) in every adverse action notice.
Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Reasons must be specific and relate only to factors the scoring system actually scored; 'insufficient score' or 'internal standards' is not a reason, and disclosing more than four reasons is not likely to help.
- An appeal route is not required by 1002.9; the notice must carry the specific reasons or the right to request them within 60 days.
Example (Python + OpenAI SDK + Pydantic), before:
resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
application.status = 'denied'
send_email(applicant.email, 'Your application was declined.')After:
a = Assessment.model_validate_json(resp.choices[0].message.content) # decision, reason_codes
if a.decision == 'deny':
decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
send_email(applicant.email, render('adverse_action_notice.txt',
reasons=a.reason_codes,
role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))Control: Adverse AI decision without explanation/appeal. The same guard addresses 13 items with binding law in 9 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Significant AI decisions should be documented and contestable with remedies (CoE Framework Convention) (CoE AI Framework Convention (CETS 225) · CoE Framework Convention on AI (CETS 225), Article 14(2))
- Financial institutions should disclose AI use and explain AI-driven decisions on request (MAS FEAT) (MAS FEAT Principles · MAS FEAT Principles — Transparency, Principles 12-14)
- Health AI/LMMs should be transparent and documented before deployment (WHO) (WHO AI-for-Health (LMM) Guidance · WHO guidance on large multi-modal models (2024), Executive summary (Figure 1), section 1.2 and Box 1: the six consensus principles of WHO's 2021 guidance)
Related incidents
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id us-cfpb-reg-b-adverse-action.specific-principal-reasons-for-adverse-action · review status: primary source derived