Consumer credit and fair lending,explained
Consumer credit compliance is the set of rules governing how you advertise, underwrite, price, service and collect consumer loans, and fair lending is the part that forbids discrimination in any of it. In the US the core is ECOA, TILA, FCRA, HMDA, the prohibition on unfair, deceptive or abusive acts, and the debt-collection rules.
Fair lending: ECOA and Regulation B
The Equal Credit Opportunity Act prohibits discrimination against an applicant on prohibited bases including race, colour, religion, national origin, sex, marital status, age, and because income comes from public assistance. Regulation B puts the operational detail around it, most visibly the requirement to give an applicant notice of adverse action with the specific principal reasons for the decision.
Regulators look at two theories. Disparate treatment is treating a protected applicant differently. Disparate impact is a neutral policy that falls harder on a protected group without a sufficient business justification. The second is the one that catches firms by surprise, because nobody wrote a discriminatory rule; the outcome data simply came out skewed.
Disclosure: TILA and Regulation Z
The Truth in Lending Act exists so a borrower can compare the cost of credit. Regulation Z prescribes what has to be disclosed and how, including the annual percentage rate, the finance charge, the amount financed, and the payment schedule, along with rules on advertising, billing errors, and the right to rescind in certain secured transactions.
The recurring failure mode is not the initial disclosure, it is drift: a pricing or product change ships, and the disclosure logic and the marketing copy are updated on a different schedule from the code that calculates the number.
Data: FCRA and HMDA
- FCRA governs consumer reports: pull them only for a permissible purpose, give the required notice when you take adverse action based on one, and investigate disputes within the statutory window.
- If you furnish data to the bureaus, you carry accuracy and dispute-handling obligations of your own, which are examined.
- HMDA requires covered mortgage lenders to collect and report loan-level data, which regulators and the public then use to look for lending disparities.
Conduct: UDAAP and collections
Beyond the specific statutes sits a general prohibition on unfair or deceptive acts or practices, extended in the consumer-finance context to abusive practices as well. It is deliberately broad, and it is the hook used when a practice is harmful but no line-item rule squarely forbids it. On the back end, the debt-collection rules constrain how, when and how often you may contact a consumer, and what you must tell them.
Automated and AI underwriting
Model-driven credit decisions do not get a lighter touch. Regulators have been explicit that using a complex or machine-learned model is not an excuse for a vague adverse action notice: if you cannot explain the specific principal reasons a particular applicant was declined, you cannot use the model for that decision. Expect to evidence model documentation, the variables used and rejected, proxy analysis for prohibited bases, ongoing outcome testing, and human review of overrides.
The UK picture
The UK route is different in shape but similar in intent. Consumer credit firms are authorised by the FCA and follow the CONC sourcebook, with creditworthiness and affordability assessments at the centre, and the Consumer Duty layered on top requiring firms to deliver good outcomes across products, price and value, understanding, and support. Equality law rather than ECOA carries the anti-discrimination weight.
How it relates to security frameworks
ISO 27001 and SOC 2 carry a real slice of this: records retention, access control over applicant data, change management over the systems that price and decide, vendor oversight, logging, and an independent assurance habit. What they do not carry is the substance, meaning the disclosure content, the fairness testing, and the notice obligations. Treat the security programme as the foundation and the credit rules as a distinct control layer that reuses the same evidence where it genuinely applies.
Frequently asked questions
What is the difference between disparate treatment and disparate impact?
Disparate treatment is treating an applicant differently because of a prohibited basis, whether openly or through a proxy. Disparate impact is a facially neutral policy that produces a significantly worse outcome for a protected group without a sufficient business justification, and it can be a violation even with no intent to discriminate.
Do I have to explain a declined application if an AI model made the decision?
Yes. The adverse action notice must state the specific principal reasons for the decision, and regulators have said plainly that model complexity is not a defence. In practice that means you need explainability good enough to name real reasons for a specific applicant, not a generic list.
Does consumer credit compliance overlap ISO 27001 or SOC 2?
Partly. Access control over applicant data, retention, change management over decisioning systems, vendor oversight and independent assurance all map across, so the evidence can be reused. Disclosure accuracy, fair lending testing and the notice obligations are specific to the credit rules and need their own controls.
Do this in a fraction of the time
Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.
Related guides
What is a DDQ (due-diligence questionnaire)?
Due diligenceDDQ vs RFP: what is the difference?
RFPsRFP vs RFI vs RFQ: what is the difference?
RFPsThe RFP response process: a step-by-step guide
RFPsHow to build an RFP content library
RFPsThe bid/no-bid decision: when to respond to an RFP
Security questionnairesHow to respond to security questionnaires faster
Security questionnairesSIG vs CAIQ vs VSAQ: the security questionnaires explained
Security questionnairesVendor security assessment checklist
ComplianceSOC 2 vs ISO 27001: what is the difference?
ComplianceISO 27001 readiness checklist: how to prepare for certification
ComplianceSOC 2 for startups: a practical guide
ComplianceGDPR compliance for SaaS: a practical guide
ComplianceHIPAA compliance for software vendors
CompliancePCI DSS compliance, explained
ComplianceThe NIST Cybersecurity Framework, explained
ComplianceISO 42001, the AI management standard, explained
ComplianceISO 27017 and ISO 27018: cloud security and privacy, explained
ComplianceISO 22301 and business continuity, explained
ComplianceDORA, explained
ComplianceCyber Essentials, explained
ComplianceThe CCPA and CPRA, explained
ComplianceNIST 800-53, explained
ComplianceNIST 800-171 and CMMC, explained
ComplianceFedRAMP, explained
ComplianceHITRUST CSF, explained
Financial regulationBSA/AML, explained
Financial regulationThe FATF 40 Recommendations, explained
Financial regulationMiFID II and MAR, explained
Due diligenceThird-party risk management (TPRM): a practical guide
Putting Consumer Credit and Fair Lending into practice? See Diligio Compliance for Consumer Credit and Fair Lending.