Financial regulation

Consumer credit and fair lending,explained

8 min read · Updated July 2026

Consumer credit compliance is the set of rules governing how you advertise, underwrite, price, service and collect consumer loans, and fair lending is the part that forbids discrimination in any of it. In the US the core is ECOA, TILA, FCRA, HMDA, the prohibition on unfair, deceptive or abusive acts, and the debt-collection rules.

Fair lending: ECOA and Regulation B

The Equal Credit Opportunity Act prohibits discrimination against an applicant on prohibited bases including race, colour, religion, national origin, sex, marital status, age, and because income comes from public assistance. Regulation B puts the operational detail around it, most visibly the requirement to give an applicant notice of adverse action with the specific principal reasons for the decision.

Regulators look at two theories. Disparate treatment is treating a protected applicant differently. Disparate impact is a neutral policy that falls harder on a protected group without a sufficient business justification. The second is the one that catches firms by surprise, because nobody wrote a discriminatory rule; the outcome data simply came out skewed.

Disclosure: TILA and Regulation Z

The Truth in Lending Act exists so a borrower can compare the cost of credit. Regulation Z prescribes what has to be disclosed and how, including the annual percentage rate, the finance charge, the amount financed, and the payment schedule, along with rules on advertising, billing errors, and the right to rescind in certain secured transactions.

The recurring failure mode is not the initial disclosure, it is drift: a pricing or product change ships, and the disclosure logic and the marketing copy are updated on a different schedule from the code that calculates the number.

Data: FCRA and HMDA

  • FCRA governs consumer reports: pull them only for a permissible purpose, give the required notice when you take adverse action based on one, and investigate disputes within the statutory window.
  • If you furnish data to the bureaus, you carry accuracy and dispute-handling obligations of your own, which are examined.
  • HMDA requires covered mortgage lenders to collect and report loan-level data, which regulators and the public then use to look for lending disparities.

Conduct: UDAAP and collections

Beyond the specific statutes sits a general prohibition on unfair or deceptive acts or practices, extended in the consumer-finance context to abusive practices as well. It is deliberately broad, and it is the hook used when a practice is harmful but no line-item rule squarely forbids it. On the back end, the debt-collection rules constrain how, when and how often you may contact a consumer, and what you must tell them.

Automated and AI underwriting

Model-driven credit decisions do not get a lighter touch. Regulators have been explicit that using a complex or machine-learned model is not an excuse for a vague adverse action notice: if you cannot explain the specific principal reasons a particular applicant was declined, you cannot use the model for that decision. Expect to evidence model documentation, the variables used and rejected, proxy analysis for prohibited bases, ongoing outcome testing, and human review of overrides.

The UK picture

The UK route is different in shape but similar in intent. Consumer credit firms are authorised by the FCA and follow the CONC sourcebook, with creditworthiness and affordability assessments at the centre, and the Consumer Duty layered on top requiring firms to deliver good outcomes across products, price and value, understanding, and support. Equality law rather than ECOA carries the anti-discrimination weight.

How it relates to security frameworks

ISO 27001 and SOC 2 carry a real slice of this: records retention, access control over applicant data, change management over the systems that price and decide, vendor oversight, logging, and an independent assurance habit. What they do not carry is the substance, meaning the disclosure content, the fairness testing, and the notice obligations. Treat the security programme as the foundation and the credit rules as a distinct control layer that reuses the same evidence where it genuinely applies.

Frequently asked questions

What is the difference between disparate treatment and disparate impact?

Disparate treatment is treating an applicant differently because of a prohibited basis, whether openly or through a proxy. Disparate impact is a facially neutral policy that produces a significantly worse outcome for a protected group without a sufficient business justification, and it can be a violation even with no intent to discriminate.

Do I have to explain a declined application if an AI model made the decision?

Yes. The adverse action notice must state the specific principal reasons for the decision, and regulators have said plainly that model complexity is not a defence. In practice that means you need explainability good enough to name real reasons for a specific applicant, not a generic list.

Does consumer credit compliance overlap ISO 27001 or SOC 2?

Partly. Access control over applicant data, retention, change management over decisioning systems, vendor oversight and independent assurance all map across, so the evidence can be reused. Disclosure accuracy, fair lending testing and the notice obligations are specific to the credit rules and need their own controls.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides

Putting Consumer Credit and Fair Lending into practice? See Diligio Compliance for Consumer Credit and Fair Lending.