Case Study 2 — When the Decision Is a Model: Algorithmic Underwriting and Fair Lending
A complementary angle: what automation moved, what it did not, and what the law requires anyway
Why this case study exists
Case Study 1 ended on a genuine achievement: automated underwriting approves borrowers a two-number benchmark would decline, and that expansion of access is real and visible in every findings report you will pull. The Harlow Street file is a house that a 31/43 benchmark does not buy.
This case study is about the other half of the sentence, and it needs to be read carefully, because the subject attracts both complacency and hysteria and neither is useful at a loan officer's desk.
The claim made for automation in the 1990s was partly a fair-lending claim: a model applies the same rules to every applicant, so replacing an underwriter's discretion with a model removes a channel through which bias can operate. That claim is true as far as it goes, and it does not go as far as people wanted it to.
Chapter 25 covers fair lending as a body of law and a professional obligation. Chapter 36 covers the technology stack. This case study sits between them and asks one narrow question: what does it mean that the thing evaluating your borrower is a model whose internals nobody outside the agency can inspect?
Background: what the law actually requires
Three legal facts, all of them settled, all of them Tier 1.
The Equal Credit Opportunity Act and Regulation B prohibit discrimination in any aspect of a credit transaction on the basis of race, color, religion, national origin, sex, marital status, age, receipt of public assistance income, or the good-faith exercise of rights under the Consumer Credit Protection Act. The Fair Housing Act separately prohibits discrimination in residential real-estate-related transactions, including on the basis of familial status and disability.
ECOA requires an adverse action notice that states the specific principal reasons for the action, or discloses the applicant's right to obtain them. Not a general reason. Not "credit scoring." The specific principal reasons.
Disparate impact is a recognized theory of liability. A facially neutral policy or practice that produces a disproportionate adverse effect on a protected class can violate fair-lending law even absent any intent to discriminate, subject to the legal framework for business justification and less discriminatory alternatives. The doctrine's precise contours have been litigated and its implementing regulations have been amended more than once; the concept itself is long-established.
Now put those next to a proprietary risk model, and the tension is obvious.
The issue, in four parts
1. The demographic firewall — real, and narrower than it sounds
Applications collect demographic information — ethnicity, race, sex — under the Home Mortgage Disclosure Act and Regulation C, for government monitoring. The agencies state that this information is not an input to the automated risk assessment. It appears on the Uniform Residential Loan Application in its own section, marked for government monitoring purposes, and Chapter 9 covers how you collect it and what you may and may not do with it.
That firewall is real and it matters. It also does not settle the question, for a reason that is well understood in every field that uses statistical models: removing a variable from a model does not remove its effects if other variables carry the same information. Credit history, credit score, the type and stability of income, the size of the down payment, and the presence or absence of a traditional credit file are all facially neutral and all distributed unevenly across a population whose wealth and credit access were shaped by a documented history of discrimination in American housing finance.
An underwriting model built on historical loan performance learns from the loans that were actually made. Which populations got loans, on what terms, in which neighborhoods, is not a neutral historical record.
2. The thin-file problem, and what has been done about it
The clearest concrete example is credit history itself.
A borrower who has never carried traditional credit — who pays rent, utilities, and insurance on time and in cash or by transfer, and who has no card, no auto loan, and no student debt — is not a risky borrower. They are an invisible one. Conventional scoring models need tradelines; a thin file produces either no score or a poor one, and the AUS reads what the credit report gives it.
Both enterprises have moved on this in ways a loan officer should know about because they change files:
- Fannie Mae announced in 2021 that Desktop Underwriter would consider positive rental payment history identified from asset data for eligible first-time homebuyers.
- Freddie Mac subsequently announced that Loan Product Advisor would consider on-time rent payments in its assessment.
- Both enterprises' guides provide for nontraditional credit documentation paths for borrowers without usable traditional credit, generally requiring a set of alternative payment references.
Verify the current scope, eligibility conditions, and mechanics of every one of these before you rely on them — they have all been revised since announcement and they will be again. The structural point stands regardless: the model's blind spots are addressed by feeding it better data, not by arguing with the recommendation. Which is, once again, the loan officer's job.
3. The measurement fight
In August 2021, the newsroom The Markup published an investigation — The Secret Bias Hidden in Mortgage-Approval Algorithms, by Emmanuel Martinez and Lauren Kirchner, distributed with the Associated Press — analyzing national HMDA data and reporting that applicants of color were substantially more likely than similarly-situated white applicants to be denied conventional mortgages. Go read the original rather than a summary of it, including its published methodology.
The industry response raised a genuine methodological limitation, and it is one every mortgage professional should understand: the public HMDA data does not contain credit score. It contains a great deal — income, loan amount, debt-to-income and combined loan-to-value ranges, property characteristics, denial reasons — but not the single variable that most drives an underwriting outcome. Analyses built on it therefore cannot fully control for creditworthiness, and reasonable researchers disagree about how much of an observed disparity that explains.
That is a real limitation and it is not a dismissal. Both things are true: the public data cannot settle the question, and "the data cannot settle it" is not evidence that the answer is zero. A professional holds both.
4. The black-box problem, and what the regulator has said about it
Here is where the law is unambiguous and recent.
The Consumer Financial Protection Bureau issued Circular 2022-03 in May 2022, addressing adverse action notification requirements in connection with credit decisions based on complex algorithms. Its position: ECOA and Regulation B require creditors to provide accurate and specific statements of the principal reasons for adverse action, and the complexity or opacity of the model used does not excuse that obligation. There is no black-box exception. A creditor that cannot explain why it declined an applicant has a problem with its model, not a defense.
The Bureau has since issued further guidance in the same vein regarding the use of sample reason-code checklists — reinforcing that a creditor must give the actual, specific reasons, whether or not a convenient sample reason exists. Verify the current guidance; this area is active.
Separately, prudential regulators have long-standing supervisory expectations for model risk management at supervised institutions — governance, validation, documentation, and ongoing monitoring of models used in decisions. Lenders subject to that supervision do not get to treat a vendor model as a black box either.
Put together: the law's answer to "the model decided" is that no it did not — the creditor decided, and the creditor owes the applicant specific reasons. Which is exactly §15.10's point, arriving from the legal side.
What it shows: the loan officer's actual exposure
Nothing above is abstract at a desk. Here is where it lands, in the two places it lands.
It lands in what you say
A composite, drawn from documented industry patterns rather than any single case. Labeled as a composite; no real borrower, lender, or enforcement action is described.
A borrower with a thin credit file, steady income from two part-time jobs, and thirty-six months of documented on-time rent asks about buying. A loan officer, glancing at the score, says: "With your credit you're probably not going to qualify — you should work on that for a year and call me back."
No application was taken. No credit was pulled with permission. No AUS was run. No adverse action notice was generated, because there was no application to act adversely on.
That conversation is where fair-lending exposure actually lives for a loan officer. The pre-application discouragement of a prospective applicant on a prohibited basis is itself unlawful under Regulation B, and it does not require anyone to intend anything. It requires only a habit of predicting outcomes instead of producing them — and the borrower above may well have received an Approve, on a program built for exactly their profile, with rent payment history considered.
The professional response is the opposite of a prediction: take the application, run the system, read the findings, and tell the borrower what the file actually says. That is not merely the compliant answer. It is also the accurate one, because the loan officer in that story did not know what the AUS would return and neither do you.
It lands in what you do with a Refer
The second exposure is subtler and more common: giving up.
A Refer routes a file to manual underwriting, restructuring, the other agency's system, or a different program. Every one of those paths closes loans. A loan officer who treats a Refer as a decline, systematically, is applying a filter of their own on top of the model's — and if that loan officer's caseload is not evenly distributed across their market, neither is the effect of their filter.
Nobody audits your persistence. That is exactly why it is worth thinking about.
The contested part: appraisal, valuation, and automating it away
One more thread, because it connects directly to §15.7 and it is genuinely unresolved.
Property valuation has its own documented equity problem. Freddie Mac published research in 2021 on racial and ethnic gaps in home purchase appraisal outcomes; the Federal Housing Finance Agency has published its own analyses of appraisal data; and in 2022 the interagency PAVE Task Force (Property Appraisal and Valuation Equity) issued an action plan addressing appraisal bias. Chapter 18 covers all of this properly, including reconsideration of value.
Now hold that next to value acceptance. If the appraisal is a documented site of bias, does replacing it with an automated valuation help or hurt?
Both answers are defensible and neither is proven. Removing an individual appraiser's discretion removes one channel for bias — the same argument made for automated underwriting in the 1990s, with the same limits. But an automated valuation trained on historical sales and prior appraisals inherits whatever is in that record, and a borrower who receives a value acceptance has no independent opinion of value in their file at all, which is also the loss of a check.
You do not have to resolve that to originate loans. You do have to know it is unresolved, and not repeat either side's talking point as though it were settled.
Outcome
There is no tidy ending here, and a textbook that manufactured one would be lying.
What can be said with confidence:
- Automated underwriting removed a real channel of discretionary bias from the first-pass decision, and that was a genuine improvement.
- It did not and could not remove disparities that live in the inputs, and the enterprises have spent the last several years adding data — rental history, cash-flow, nontraditional credit — that is aimed squarely at that problem.
- The law does not accept "the model decided" as an answer. Creditors owe applicants specific principal reasons for adverse action, model complexity notwithstanding, and the CFPB has said so directly.
- The individual loan officer's fair-lending exposure is overwhelmingly in pre-application conduct and in what they do with a hard file — not in the model.
The lesson
The model is not where your fair-lending obligation lives, and pointing at it is not a defense — for your employer or for you.
The findings report is a tool. It is a good tool. It does not have a duty to your borrower and it cannot discharge yours. Your duty is discharged in four specific acts, all of which happen before and after the machine: take the application, enter accurate data, read what comes back, and work the file that comes back hard.
And the one sentence to carry out of this case study, because it is both the ethical answer and the commercially correct one: do not predict outcomes you have the tools to produce.
Discussion questions
-
The demographic firewall is real: HMDA demographic data is not an input to the risk assessment. Explain, to someone with no statistics background, why that does not by itself guarantee that outcomes are unaffected by race.
-
The Markup's analysis could not control for credit score because public HMDA data does not contain it. A colleague concludes: "So the study is worthless." Evaluate that conclusion. What can an analysis without credit score establish, and what can it not?
-
CFPB Circular 2022-03 says there is no black-box exception to ECOA's adverse action requirements. What does that imply about a lender that adopts a model it cannot explain? What does it imply about a loan officer's ability to answer "why was I declined?"
-
The composite in this case study involves a conversation in which no application was taken. Why is that scenario more dangerous, from a fair-lending standpoint, than a declined application would be? What does Regulation B say about discouragement?
-
Argue both sides of the appraisal-waiver equity question honestly, in one paragraph each. Then state what additional evidence would move you.
-
Section 15.10 says the AUS does not decide and the lender does. This case study arrives at the same conclusion from the legal side. Write the single sentence you would use to explain that point to a real estate agent who just said "the computer turned them down."
-
Suppose your branch's Refer files close at a materially lower rate than a colleague's, and you both work the same market. What would you want to know, and what would you do about it? (Note that this is a question about your own practice, not about anyone's protected characteristics.)
Sources: the Equal Credit Opportunity Act and Regulation B; the Fair Housing Act; the Home Mortgage Disclosure Act and Regulation C; CFPB Circular 2022-03 and subsequent Bureau guidance on adverse action and complex models; supervisory guidance on model risk management; Freddie Mac's 2021 research note on appraisal valuation gaps; FHFA published appraisal analyses; the 2022 PAVE Task Force action plan; The Markup's 2021 mortgage-algorithm investigation and the published responses to it; Fannie Mae's and Freddie Mac's announcements regarding rental payment history in DU and LPA. Specific figures, penalty amounts, and study coefficients are deliberately not asserted; consult the primary sources. The illustrative conversation is a labeled composite and describes no real person, lender, or enforcement action. Requirements change and state law varies — verify current rules with your compliance department and your regulator.