How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment
    Implementation Guide

    How to Write an AI Fair Lending Monitoring Plan

    A practical structure for governance roles, testing methods, escalation paths, and audit trails that connect AI and ML credit model behavior to ECOA and Regulation B obligations.

    An AI fair lending monitoring plan is a documented set of governance roles, testing methods, escalation paths, and audit trails that ties AI/ML credit model behavior to ECOA and Regulation B obligations, giving compliance and model risk teams a defensible way to detect, document, and remediate discriminatory outcomes on an ongoing basis.

    Core Elements of an AI Fair Lending Monitoring Plan

    These four elements form the operational backbone of a defensible monitoring plan. Together they support continuous oversight as models are deployed, retrained, and updated.

    Governance and Independent Review

    Defined roles across compliance, model risk, and legal, separate from model development.

    Testing Methodology

    Disparate impact analysis and proxy variable detection with a documented statistical approach.

    Documentation and Audit Trail

    Recorded testing inputs, results, and remediation decisions for examination readiness.

    Escalation and Remediation

    Defined paths for reviewing findings and deciding on model adjustment, retraining, or discontinuation.

    Core Components a Monitoring Plan Should Document

    • Governance roles for testing, review, and sign-off, with validation kept independent of model development functions
    • A documented testing methodology covering disparate impact analysis and proxy variable detection
    • An adverse action notice process capable of generating specific, accurate reasons for AI/ML-driven decisions
    • Audit trail requirements capturing data inputs, testing methodology, results, and remediation decisions
    • Escalation criteria defining who reviews findings and what remediation options are available
    • Monitoring cadence tied to deployment, retraining, and material data or feature changes

    What the Monitoring Plan Needs to Accomplish

    A fair lending monitoring plan for AI-driven credit decisioning is not a one-time validation exercise. It is a standing operational process that connects model testing to compliance obligations under ECOA and Regulation B, and it needs to function continuously as models are deployed, retrained, and updated. The plan should make it possible for compliance leaders to answer three questions at any point in time: what testing has been performed, what the results show, and who reviewed and acted on those results.

    Institutions that treat fair lending monitoring as a periodic report rather than a documented control tend to struggle during examinations because they cannot reconstruct the decision trail behind a model change or a testing result. The plan itself is the artifact that closes that gap.

    Examination readiness: At any point, compliance should be able to show what was tested, what the results were, and who reviewed and acted on those results.

    Regulatory Basis for Monitoring AI Credit Models

    ECOA, at 15 U.S.C. § 1691, prohibits creditors from discriminating against applicants on a prohibited basis in any aspect of a credit transaction. Regulation B, at 12 CFR Part 1002, implements ECOA and requires creditors to provide specific and accurate reasons for adverse action taken on a credit application.

    CFPB Circular 2022-03 directly addresses AI/ML models by stating that the use of complex algorithms does not exempt creditors from adverse action notice requirements, and that a model's black-box nature is not a valid defense for failing to provide specific and accurate denial reasons.

    Separately, the interagency Supervisory Guidance on Model Risk Management, SR 11-7, establishes expectations for model development, validation, and ongoing monitoring that supervisory agencies commonly apply to credit models regardless of whether they are AI/ML based. None of these sources specify a fixed numeric threshold for disparate impact. Institutions are expected to build and document a defensible testing methodology rather than rely on a single codified standard.

    Testing Methodology: Disparate Impact and Proxy Variables

    Disparate impact analysis compares approval, pricing, or decisioning outcomes between a control group and a group defined by a prohibited basis characteristic, using statistical significance testing. Proxy variable analysis examines whether model inputs or derived features correlate with protected class characteristics even when those characteristics are not directly used as model inputs.

    Both forms of testing need to be documented in enough detail that an examiner or independent reviewer can reproduce the analysis:

    • The population tested
    • The variables examined
    • The statistical method applied
    • The threshold used to flag a result for further review

    Because no regulation specifies a fixed disparity ratio that automatically constitutes unlawful discrimination, the plan should state the institution's chosen methodology and the rationale for it, rather than assume a single external benchmark will satisfy examiners.

    Monitoring Cadence and Retraining Triggers

    Monitoring cadence should be tied to points of material change in the model lifecycle, not only to a fixed calendar schedule. At minimum, the plan should define when testing runs in connection with initial deployment, model retraining, and material data or feature changes, so that fair lending review stays aligned with how the model actually evolves in production.

    Governance Roles and Escalation

    SR 11-7 supports assigning independent validation responsibilities separate from the functions that build and deploy the model. In practice, this means fair lending monitoring plans should name specific roles across compliance, model risk management, and legal functions, and should specify who has authority to review disparate impact and proxy detection findings.

    The escalation path needs to state what happens when a test flags a result: who evaluates it, what remediation options are considered (model adjustment, retraining, or discontinuation), and how the decision is documented. Recordkeeping should align with Regulation B obligations and general examination expectations, meaning the plan should specify how long testing records, governance decisions, and remediation actions are retained.

    Bring Structure to AI Model Oversight

    A documented monitoring plan is only as effective as the controls that enforce it. Trussed AI provides runtime governance, monitoring, and audit logging capabilities that support ongoing oversight of AI systems in regulated environments.

    Request a Demo