See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Financial Services Compliance

    Reg B Notice Requirements for AI-Driven Loan Decisions

    Regulation B does not establish a 100-day notice period. Creditors must notify applicants within 30 days of a completed application, and adverse action notices must state specific, accurate reasons, even when AI models drive the decision.

    Regulation B does not establish a 100-day notice period. Under 12 CFR §1002.9(a)(1), creditors must notify applicants of the action taken within 30 days of receiving a completed application, and adverse action notices must include specific, accurate reasons for denial or notice of the applicant's right to request them. When AI or machine learning models contribute to the decision, CFPB Circular 2022-03 confirms creditors must still produce reasons reflecting the model's actual determinative factors, regardless of model complexity or interpretability.

    Reg B's Actual Notice Timing and Content Requirements

    Under 12 CFR §1002.9(a)(1), the clock for notice runs from receipt of a completed application. Within 30 days, the creditor must tell the applicant of the action taken. For adverse action, that notice must either state the principal reasons for the action or tell the applicant how to request those reasons. No 100-day adverse action notice period appears in the regulation or in its incomplete-application provisions.

    Specificity matters as much as timing. Generic checklist language does not satisfy Regulation B if it does not match the factors that actually drove the decision. When an AI or machine learning model contributes to underwriting, CFPB Circular 2022-03 confirms there is no exception based on model complexity or limited interpretability. The institution still must produce reasons that reflect the model's real determinative factors.

    Compliance Checkpoints for AI Credit Decisions

    • 30-day notice deadline Applies to completed applications under §1002.9(a)(1), not 100 days.
    • Specific reasons required Notices must state actual determinative factors, not generic checklist reasons.
    • No black-box exception CFPB Circular 2022-03 applies specificity requirements regardless of model complexity.
    • Reconstructable decision logic Audit trails must tie model version, inputs, and outputs to each decision.

    How AI and Machine Learning Models Change the Compliance Calculus

    Traditional scorecards often map cleanly to a short list of reason codes. Many modern models do not. Feature interactions, non-linear scoring, frequent retraining, and vendor-hosted pipelines can obscure which inputs moved a particular decision. That opacity does not relax Reg B. It raises the bar for documentation, reason-code design, and the ability to reconstruct what the model did at decision time.

    Institutions remain responsible for notice accuracy whether the model is built in-house or supplied by a third-party vendor. Contracts and operating models need to ensure enough transparency and audit data exist to support both consumer notices and examiner review.

    Technical Barriers to Specific and Accurate Reasons

    Three technical gaps commonly undermine compliant notices. First, reason codes may be generated from a static checklist that is never validated against live model behavior. Second, model updates can change feature importance without a matching update to the reason-code mapping. Third, logs may retain only an approve/deny outcome, not the model version, input values, and score that produced it.

    Without decision-level capture and a documented methodology for translating feature contributions into notice language, teams cannot reliably show that stated reasons match the factors that determined the outcome.

    Audit Trail and Traceability Requirements for AI Credit Decisions

    Examiners and internal compliance teams need more than a final decision status. They need a path from a specific application to the model state and inputs that produced the outcome, and from those inputs to the language on the adverse action notice.

    1. Decision-level capture

      Retain the specific model version, inputs, and output score tied to each individual credit decision at the time it was made.

    2. Model state reconstruction

      Maintain the ability to snapshot model version, parameters, and feature set independent of subsequent retraining.

    3. Documented reason-code methodology

      Establish an auditable process for translating model feature contributions into the specific reason-code language required in notices.

    4. Retention of records

      Retain decision logs, input feature values, and generated notices for applicable regulatory retention periods.

    5. Evidentiary integrity

      Apply access controls and immutability protections to decision and audit logs to preserve their integrity for examinations.

    Implementation Considerations for Compliance and Technical Teams

    • Validate reason-code generation methodology against actual model behavior prior to deployment, rather than defaulting to generic checklist reasons.
    • Establish a review process to update reason-code mappings whenever the underlying model, features, or scoring logic change.
    • Coordinate compliance and technical teams to confirm generated reasons meet Reg B's specificity and accuracy standard before notices are issued.
    • Contractually require third-party AI underwriting vendors to provide sufficient transparency and audit data to support notice generation and examiner requests.
    • Test end-to-end notice generation timing across the full decisioning pipeline to confirm compliance with Reg B's 30-day notice period.

    Governance Accountability and Runtime Oversight

    Governance is not complete at model approval. Runtime controls need to keep decision records complete, reason codes aligned with current model behavior, and notice generation inside the 30-day window. When models retrain or vendors ship updates, accountability stays with the deploying institution: it must still reconstruct the decision logic that applied at the time of the action and produce accurate consumer-facing reasons.

    Access controls, immutability protections, and clear ownership between risk, compliance, and technology teams turn audit logs into usable evidence rather than incomplete operational residue.

    Frequently Asked Questions

    Is there a 100-day adverse action notice requirement under Regulation B?

    No. Regulation B requires notice of the action taken within 30 days of receiving a completed application, per 12 CFR §1002.9(a)(1). No 100-day period appears in the regulation or its incomplete-application provisions.

    Can a generic checklist reason satisfy Reg B for an AI-driven denial?

    Not if the checklist reason does not reflect the model's actual determinative factors. CFPB Circular 2022-03 confirms there is no exception to the specificity requirement based on model complexity.

    How should institutions handle audit requests for retrained or updated AI models?

    Institutions need the ability to reconstruct the specific model version, parameters, and feature set active at the time of the original decision, independent of later retraining or updates.

    What obligations apply when a third-party vendor supplies the AI underwriting model?

    The deploying institution remains responsible for notice accuracy. Vendor contracts should require sufficient transparency and audit data to support reason-code generation and examiner review.

    Strengthen Governance Over AI-Driven Credit Decisions

    Reg B's specificity and timing requirements do not change because a model is complex. Runtime governance and audit logging can help institutions maintain the decision-level traceability that examiners and compliance teams require.

    Request a Demo