TwinEthos homeAPI access

Law

CFPB Regulation B (12 CFR part 1002), 1002.9 adverse action notifications

Consumer Financial Protection Bureau · United States (federal) (US) · 1 provision encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.ecfr.gov, www.federalregister.gov.

Trust and provenance 5 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 1 provision added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Give credit applicants the specific principal reasons for adverse action, drawn from the factors the model actually scored (Regulation B, 12 CFR 1002.9)

12 CFR 1002.9(b)(2) · official text · In force: applies since 30 Dec 2011 · United States (federal) (US)

A creditor that takes adverse action on a credit application must notify the applicant in writing with a statement of the action and either a statement of specific reasons or a disclosure of the right to one (12 CFR 1002.9(a)(2)); the reasons must be specific and indicate the principal reasons, and saying the applicant failed the creditor's internal standards or did not reach a qualifying score on its credit scoring system is insufficient (1002.9(b)(2)). Under the Official Interpretations the reasons must describe the factors actually considered or scored, and for a credit scoring system relate only to factors actually scored, with no principal reason left out (Supp. I, comments 9(b)(2)-2 and -4). The rule never mentions AI; it is encoded as AI-adjacent (owner decision D-19, D-11 pattern 1) because model-driven credit decisions must still produce these reasons. Detect credit code where a model or LLM decision sets a declined status with no reason codes.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 30 Dec 2011
Official source
12 CFR 1002.9(b)(2) · captured 4 Oct 2026 · anchor hash (SHA-256) c3e5658bbb31… · 8 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Adverse action notices generated by a separate service
  • Declines encoded as numeric codes or enums
  • Reasons may be computed in a separate adverse-action notice service; confirm the declined status always produces them. Reasons an LLM writes freely are not enough: they must describe the factors the model actually score…

Who it applies to

  • Duty falls on: organization
  • Sectors: lending
  • Creditors (12 CFR 1002.2(l)) that take adverse action (1002.2(c)) on an application for credit, consumer or business, where a credit scoring model, machine-learning model or LLM drives or contributes to the decision, for applicants in the United States. Part 1002 is in force from 2011-12-30; the reasons duty predates it (the Board's Regulation B).
  • Not covered:
    • Persons excluded from coverage of part 1002 by section 1029 of the Consumer Financial Protection Act of 2010 (certain motor vehicle dealers) (12 CFR 1002.1(a))
    • Actions that are not 'adverse action' under 1002.2(c)(2): agreed changes to account terms, action on inactive, defaulted or delinquent accounts, most point-of-sale authorization refusals, refusals required by law, and refusals of credit the creditor does not offer
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Compute each applicant's principal reasons from the factors the model actually scored, and put them (or the right to obtain them) in every adverse action notice.

Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Reasons must be specific and relate only to factors the scoring system actually scored; 'insufficient score' or 'internal standards' is not a reason, and disclosing more than four reasons is not likely to help.
  • An appeal route is not required by 1002.9; the notice must carry the specific reasons or the right to request them within 60 days.

Example (Python + OpenAI SDK + Pydantic), before:

resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
    application.status = 'denied'
    send_email(applicant.email, 'Your application was declined.')

After:

a = Assessment.model_validate_json(resp.choices[0].message.content)   # decision, reason_codes
if a.decision == 'deny':
    decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
                     model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
    send_email(applicant.email, render('adverse_action_notice.txt',
        reasons=a.reason_codes,
        role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
        correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))

Control: Adverse AI decision without explanation/appeal. The same guard addresses 13 items with binding law in 9 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id us-cfpb-reg-b-adverse-action.specific-principal-reasons-for-adverse-action · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.