web analytics
Sector Rules

FCRA and AI

Fair Credit Reporting and AI

The one-paragraph answer

FCRA AI compliance applies when AI systems produce or use consumer reports. The Fair Credit Reporting Act governs consumer reporting agencies (CRAs), users of consumer reports, and furnishers of information to CRAs. AI that assembles data about consumers to be used for credit, employment, insurance, or other permissible purposes may qualify as a consumer report, and the operator may qualify as a CRA. FCRA requires accuracy, dispute-handling, and adverse-action procedures. FTC and CFPB both enforce FCRA against AI.

The pain FCRA AI compliance is causing our customers

Companies building AI to score, rank, or evaluate consumers often do not realize they may be operating as consumer reporting agencies. FCRA has a broad definition of "consumer report" that reaches any communication of information about a consumer's creditworthiness, character, or personal characteristics used or expected to be used for eligibility decisions. AI-powered background checks, tenant screening, employment screening, and credit assessment all fit inside FCRA. Operating as a CRA without knowing it is one of the most common FCRA violations, and it produces significant enforcement exposure.

What FCRA AI compliance requires

Accuracy

CRAs must follow reasonable procedures to assure maximum possible accuracy of the information reported. AI-produced consumer reports must be tested for accuracy, and processes must exist to identify and correct errors.

Adverse action notices

Users of consumer reports must provide adverse action notices when a report contributes to an adverse decision (credit denial, higher pricing, employment denial). The notice must identify the CRA and inform the consumer of their rights.

Dispute handling

CRAs must accept and investigate consumer disputes about accuracy. AI-produced reports must have dispute channels and remediation processes.

Permissible purpose

Consumer reports can only be furnished for permissible purposes (credit, employment, insurance, licensing, and a few others). AI systems must verify permissible purpose before delivering reports.

Why FCRA AI compliance matters to you

FCRA has a private right of action with statutory damages of $100 to $1,000 per willful violation, plus actual damages and attorneys' fees. Class actions are common. FTC and CFPB pursue FCRA cases, and state attorneys general have concurrent authority. AI companies that thought they were building "insights" or "analytics" but actually built consumer reports face substantial exposure.

What the research says about FCRA AI

The academic literature on FCRA AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“modern machine learning techniques substantially outperform logistic regression, though at the cost of being substantially harder to explain”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“regulators demand these models to be transparent and auditable”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about FCRA AI arrives from the board, the buyer, or the regulator.

How to get compliant with FCRA and AI: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under FCRA AI. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities FCRA AI reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation FCRA AI expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, FCRA AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about FCRA AI compliance

Are we a consumer reporting agency?

If you regularly assemble consumer information for use in eligibility decisions, likely yes. Get FCRA counsel to review.

Does FCRA apply to LLM-generated summaries about people?

If the summary is used for eligibility decisions, likely yes. AI does not exempt a report from FCRA.

Where does FCRA AI compliance fit in SRJ's work?

The lending and employment dossiers in Volume III of The Operating Discipline for AI Library™ address FCRA-specific AI compliance.

How companies become a consumer reporting agency by accident

The definition is broader than almost anyone building an AI product expects. If you regularly assemble or evaluate information about consumers, and that output is used or expected to be used to decide eligibility for credit, employment, insurance, housing, or a similar benefit, you are producing a consumer report and you are probably a CRA. Nothing about calling it "insights", "risk scoring", or "candidate analytics" changes the analysis. FCRA AI exposure attaches to function, not to labels.

Why the private right of action is the real risk

Regulators are not the main threat here. FCRA carries a private right of action with statutory damages, and the plaintiffs' bar knows the statute intimately. A willful violation supports statutory damages per consumer plus attorneys' fees, which makes class treatment economically attractive against a product used at scale. An AI screening tool used across ten thousand applicants is ten thousand potential claims.

What compliance requires if you are in scope

Reasonable procedures to assure maximum possible accuracy, which for an AI system means documented testing, not a claim. A dispute process a consumer can actually use, with investigation and correction. Permissible purpose verification before you furnish a report. Adverse action notices identifying you as the source. And a decision, made deliberately, about whether you want to be a CRA at all, because the alternative is redesigning the product so that it is not one.

Primary sources on FCRA AI

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning FCRA AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including FCRA and AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation