web analytics
Agency Enforcement

CFPB AI Enforcement

Consumer Finance and AI

The one-paragraph answer

CFPB AI enforcement applies existing consumer finance law to AI in lending, credit, and financial products. The Consumer Financial Protection Bureau uses the Fair Credit Reporting Act (FCRA), the Equal Credit Opportunity Act (ECOA), the Truth in Lending Act, and UDAAP authority. AI-driven adverse action decisions must produce specific, accurate reasons. AI-driven lending must not produce disparate impact on protected classes. Enforcement is active and settlements have been substantial.

The pain CFPB AI enforcement is causing our customers

Fintech lenders and traditional banks adopting AI underwriting learned that black-box models are a compliance problem. When a consumer is denied credit, ECOA requires specific reasons for the adverse action. "The algorithm scored you 62" is not a valid reason. Neither is "you did not meet our proprietary criteria." AI decisions must produce human-understandable, specific, accurate explanations. Systems that cannot do this expose the lender to CFPB enforcement, private litigation, and state attorney general action.

What the CFPB actually enforces

ECOA (Equal Credit Opportunity Act)

Prohibits credit discrimination based on protected characteristics. AI-driven lending must not produce disparate impact on race, sex, national origin, age, marital status, or receipt of public assistance income. Adverse action notices must state specific reasons the applicant was denied.

FCRA (Fair Credit Reporting Act)

Governs consumer reports. AI systems that assemble or produce consumer reports must comply with accuracy, dispute-handling, and adverse-action requirements. See FCRA and AI.

UDAAP (Unfair, Deceptive, or Abusive Acts or Practices)

The CFPB's UDAAP authority reaches AI-driven practices that are unfair or deceptive to consumers.

TILA (Truth in Lending Act)

AI-driven pricing and disclosure must comply with TILA transparency requirements.

What the CFPB looks for

Specific and accurate adverse action reasons for AI-driven denials. Disparate impact analysis of AI models before deployment and periodically after. Documentation of model development, validation, and monitoring. Compliance with fair lending redlining and steering rules. Model risk management aligned with SR 11-7 for banks and analogous practices for non-banks.

Why CFPB AI enforcement matters to you

Any company that touches consumer credit, lending, deposit accounts, prepaid cards, mortgage servicing, debt collection, or student loans faces CFPB authority. AI systems used in these contexts are subject to CFPB oversight. Enforcement settlements have been substantial, and the CFPB has been explicit that AI does not reduce compliance obligations under existing consumer finance law.

What the research says about CFPB AI enforcement

The academic literature on CFPB AI enforcement is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“modern machine learning techniques substantially outperform logistic regression, though at the cost of being substantially harder to explain”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“banks and other financial institutions could, potentially unwittingly, engage in illegal discrimination through the use of this technology”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about CFPB AI enforcement arrives from the board, the buyer, or the regulator.

How to get compliant with CFPB AI Enforcement: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under CFPB AI enforcement. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities CFPB AI enforcement reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation CFPB AI enforcement expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, CFPB AI enforcement becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about CFPB AI enforcement

Do we need to explain AI credit decisions to consumers?

Yes. ECOA requires specific reasons for adverse action, regardless of whether the decision was made by AI or by a human. AI systems must produce human-understandable, specific, accurate reasons.

Does the CFPB AI enforcement approach apply to fintechs?

Yes. The CFPB has enforcement authority over both banks and non-bank financial services providers.

How does CFPB AI enforcement interact with SR 11-7?

The federal banking model risk framework governs how banks manage model risk. Note that SR 11-7 was superseded in April 2026 by revised interagency guidance (Fed SR 26-2, OCC Bulletin 2026-13). The CFPB still uses banking model risk practice as a benchmark when evaluating whether a lender's AI governance is adequate, and non-banks are expected to follow analogous practices, but the specific document to cite has changed.

Where does CFPB AI enforcement fit in SRJ's work?

The lending dossier and adverse action documentation from Volume III of The Operating Discipline for AI Library™ are designed to satisfy CFPB expectations for AI-driven credit decisions.

Why explainability is the whole problem in CFPB AI enforcement

Regulation B does not ask whether the model was accurate. It asks what you told the consumer. When credit is denied, the applicant is entitled to the specific reasons, and those reasons have to reflect what actually drove the decision. A model that produces a score without producing reasons has not made a lending decision that can lawfully be communicated. That is the core of CFPB AI enforcement, and it is why sophisticated models create compliance problems that simple scorecards never did.

Post-hoc interpretation tools help, but they are not a complete answer. If SHAP values say the top contributing feature was a variable the applicant cannot understand or influence, the adverse action notice built from it is technically derived and practically useless. The requirement is a reason a person can act on.

Alternative data raises the stakes

Fintechs using cash-flow data, education history, device signals, or behavioural features face a compounding problem under CFPB AI enforcement. These variables can improve predictive accuracy while correlating with protected characteristics, producing disparate impact without any protected variable appearing in the model. The Bureau has been explicit that a model can be discriminatory without anyone intending it, and that predictive lift is not by itself a business necessity defence.

What to build before the exam

Documented fair lending testing before deployment and on a recurring cadence. A reason-code mapping that a compliance officer, not just a data scientist, can defend. A record of less-discriminatory alternatives considered and why they were rejected. Model governance that would satisfy SR 11-7 even if you are not a bank, because the Bureau uses it as the benchmark regardless.

Primary sources on CFPB AI enforcement

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning CFPB AI enforcement that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including CFPB AI Enforcement, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation