Domain Atlas / Lending & credit collections AI
Equifax Online Model Server coding error (2022)
Explore this deployment in the PAN Lab ↗
In the PAN Lab, the readouts of this case's model organization carry a shaded evidence band whose width follows the least-established class among the modeling inputs the readings rest on.
The least-established input behind this case's model organization's readings is an assumption, not a measurement. Evidence base: 1 assumed · 8 published baseline.
Equifax's Online Model Server is the legacy on-premise platform that takes a consumer credit file, derives credit attributes from it, executes third-party scoring models over those attributes, and returns a score — and under some contracts the attributes themselves — to the requesting lender or credit reseller. Many of the attributes are date-relative: whether a consumer has ever been sixty days late on a credit card, the age of the oldest tradeline, the number of inquiries within one month. On 17 March 2022 a code change entered that production environment. The Consumer Financial Protection Bureau found, in consent order 2025-CFPB-0002, that Equifax introduced test code in a production environment in a scoring model server, and that certain scoring models thereafter computed date-based attributes against a fixed reference date rather than the then-current date. Every model downstream then produced arithmetically correct outputs over silently wrong inputs. There was no defect in the scoring models themselves: FICO stated publicly that the problem was an Equifax issue and not a FICO issue. This is therefore not an artificial-intelligence failure, not a discriminatory-design failure, and not an automated decision by Equifax at all — the scoring algorithms behaved correctly and the input pipeline feeding them did not, which is why no model-level audit, fairness test or explainability review would have caught it. The scale is the operator's own, cited to its published material: credit scores maintained on more than 200 million United States consumers, and more than 2.8 billion consumer credit files delivered to United States lenders in 2021.[4]
What happened
A lender pulls a credit score on an applicant. Behind that request sits Equifax's Online Model Server, the legacy on-premise platform that takes the consumer's credit file, derives credit attributes from it, executes third-party scoring models over those attributes, and returns a score — and under some contracts the attributes themselves — to the requesting lender or credit reseller. Many of those attributes are arithmetic on a date. Whether the consumer has ever been sixty days late on a credit card. The age of the oldest tradeline. The number of inquiries within one month.
On 17 March 2022 a code change entered that production environment. The Consumer Financial Protection Bureau's finding, in a consent order Equifax signed, is that the company introduced test code in a production environment in a scoring model server, and that certain scoring models thereafter computed date-based attributes against a fixed reference date rather than the then-current date. Everything downstream of that then worked exactly as designed. Third-party scoring algorithms, FICO's among them, ran over the attributes they were handed and returned arithmetically correct numbers. FICO said publicly that the problem was an Equifax issue and not a FICO issue. Equifax said, correctly, that the information in consumer credit reports had not been changed. Both statements are true, and together they describe a failure that no model audit, no fairness test and no explainability review would have found, because there was nothing wrong with the model and nothing wrong with the record. What was wrong was a calendar.
The window ran twenty-two days, and its end date is genuinely disputed in the record. Equifax opened an internal investigation into the issue on 22 March 2022, five days after the code change; no source located says what triggered it, so nothing here asserts that anyone outside the company found it first. The New York Attorney General's Assurance records the issue partially resolved on 6 April and fully resolved on 8 April. The Bureau's order says the error persisted until 8 April. The settlement class period runs to 8 April. Equifax's own public statements say 17 March to 6 April, and that the fix was put in place on 6 April. This file uses the outer window and notes that the operator's date is the narrower one.
The magnitude comes in two framings and they are not the same size. Equifax told mortgage clients that approximately 12 percent of scores calculated from its data during the window may have been impacted, a representation independently confirmed as Equifax's own by Freddie Mac's notice of 2 June 2022. Its public statement of 2 August 2022 said there was no shift in the majority of scores, that fewer than 300,000 consumers experienced a score shift of 25 points or more, and that a score shift does not necessarily mean a consumer's credit decision was negatively impacted; its consumer-facing statement two days later added that only a small number may have received a different credit decision. The Bureau, reciting Equifax's own score-shift analysis, counts more than 600,000 consumers underscored by 10 or more points and 139,000 with a score decrease of 25 points or more. Those figures reconcile — the Bureau counts only decreases — and the operator's public number is still the one that reads smaller. Chief executive Mark Begor was quoted at a June 2022 investor conference saying the impact was going to be quite small and not something meaningful to Equifax; the company later said the remark was about materiality to its financial profile and had been quoted out of context, and Representative Maxine Waters quoted it back to him with the observation that she was less interested in how the inaccuracies would affect Equifax.
Then comes the part that makes this case unusual, and it follows directly from the fact that the report was never wrong. There was nothing to dispute. Equifax processes approximately 765,000 disputes a month, an enormous standing correction capacity, and against a score computed wrong at delivery and correctly thereafter that capacity returned nothing, because what it reads was right the whole time. Equifax never notified affected consumers. Its consumer-facing statement told anyone who attempted to obtain credit in the window and thought their decision may have been impacted to reach out to the lender for more information — which places discovery on the applicant, who had no way to learn that the number behind a denial had been wrong.
So correction ran between companies. Equifax reissued corrected scores and data to lenders from May 2022 and gave lenders updated data for their own custom scores. The incident reached the public through that same channel rather than through Equifax: National Mortgage Professional published the first press account on 27 May 2022, and the Wall Street Journal published on 2 August, the day Equifax issued its first public statement. On 2 June 2022 Freddie Mac and Fannie Mae notified their sellers and required affected loans in process to be resubmitted through Loan Product Advisor or Desktop Underwriter with corrected credit data, or manually underwritten, with already-sold loans corrected post-purchase under the life-of-loan representation and warranty for data inaccuracies. The Federal Housing Finance Agency worked with both enterprises to determine impacts. That is the only mandatory correction anywhere in this record, and its reach is a loan file rather than a person.
Two congressional letters in August 2022 asked the questions that would settle the rest. How was the error detected. How long did Equifax know before it alerted lenders. Were particular classes of borrowers disproportionately affected. Have the affected consumers been identified, notified, and made whole. No public response by Equifax to either letter was located, and no answer to the disparate-impact question exists in the record in either direction.
There was a second coding error the same month, and it is carried here because the pair is the point. It duplicated disputed collection tradelines in 46,400 consumer files. The code was remediated on 12 April 2022; the duplicates it had already written were not fully removed until at least November 2022; and the cleanup surfaced roughly 10,000 further system-generated duplicates dating to at least 1 January 2020, which no standing check had found. That defect wrote durable rows into consumer files. A duplicated row is a wrong entry, so the dispute machinery and the ordinary integrity checks had something to bite on — and it still took seven months to clear.
The regulatory phase closed in January 2025. On the 14th the New York Attorney General accepted Assurance of Discontinuance No. 24-102: $725,000 in restitution and penalties, no admission of any negligence, wrongdoing or violation of law, and prospective relief comprising Change Advisory Board review of system changes, pre-deployment code review consistent with industry standards, a Fair Credit Reporting Act module in developer training, and at least weekly monitoring of incident reports filed by Equifax's own customers. On the 17th the Bureau issued consent order 2025-CFPB-0002. The Online Model Server coding error is one of five findings in it; it is held to violate Fair Credit Reporting Act section 607(b) and to be an unfair act or practice under the Consumer Financial Protection Act; and the $15,000,000 civil money penalty covers the whole order rather than this defect alone and carries no consumer redress specific to it. The order requires policies addressing potential consumer impact in the development, testing and implementation of system changes, Change Advisory Board review of any change reasonably anticipated to materially impact consumer files or reports once in production, systems to monitor the results of such changes, a senior-executive committee including the Chief Compliance Officer meeting at least quarterly and reporting to the Board, and developer training on accuracy obligations. Read that list twice. Every item on it acts on the pipeline that ships code. Not one acts on a delivered number, on the record it landed in, or on the person it described, and neither instrument imposes a duty to notify anyone.
The civil phase is not final. Roughly nine suits filed in August and September 2022 were consolidated before Judge Leigh Martin May in the Northern District of Georgia. On 11 September 2023 the court largely denied the motion to dismiss: the willful section 1681e(b) claim and the class allegations proceeded, the Georgia negligence claim and the demand for injunctive relief were dismissed, and the court rejected the argument that section 1681e(b) does not reach credit scores — a pleading-stage ruling on the sufficiency of allegations, not a finding that anyone acted willfully. Equifax agreed in principle in June 2026 to settle nationwide and class-wide, and its own Form 10-Q for the quarter ended 30 June 2026 accrues $100.0 million against a $60.0 million insurance receivable for a $40.0 million net charge, which is what ties that figure to this matter and no other. Preliminary approval was granted on 17 August 2026 for a class of approximately four million United States residents whose affected scores or attributes were reported to a third party in the window, with a final fairness hearing set for 22 January 2027. Nothing has been paid. Equifax denies liability. No court has adjudicated the merits.
The sociotechnical reading
Most cases in this atlas are about a model that was wrong about people. This one is about a model that was right about the wrong thing, and it is worth reading precisely because every instinct trained on the others misfires here.
Start with what was and was not broken. The scoring algorithms were sound and their supplier said so. The consumer credit reports were accurate and both the company and its regulator say so. The defect sat in the layer between them: a deterministic pipeline that turns a file into attributes and hands the attributes to a model. That layer is not usually anybody's idea of a governance surface. It has no training data, no feature importances, no protected classes and no explanations to audit. It is plumbing. And for twenty-two days it produced internally consistent, correctly formatted, arithmetically flawless numbers computed from a date that had stopped moving, and sold them to people making decisions about strangers.
The second thing to notice is what the cleanliness of the record cost. It is natural to read "consumer credit reports were not changed" as reassurance, and the company presented it that way. Structurally it is the opposite. The Fair Credit Reporting Act's entire correction machinery is built around a wrong entry: you read your report, you find the error, you dispute it, the bureau reinvestigates. Roughly 765,000 people a month use that machinery. Against this defect all of it was inert, because there was no entry. The value that hurt somebody existed for the duration of one delivery, inside a computation, and was then correctly recomputed. The person on the other end of it had nothing to look at, nothing to point to, and no way to know a number had ever been wrong. The Bureau's unfairness finding says this in its own register: consumers could not avoid the errors or the method and speed with which the company responded to them.
The third thing is where correction actually landed, because the ranking is instructive. The company's own dispute channel reached nothing. Consumer notification did not happen, and no instrument in the record requires it. What did produce compelled action was a purchaser: on 2 June 2022 the two mortgage enterprises told their sellers to resubmit affected loans through the automated underwriting engines with corrected credit data, or to underwrite them manually, and to correct already-sold loans post-purchase under the life-of-loan data-accuracy warranty. That is the only mandatory correction anywhere in this file, and it came from the leverage of somebody who buys loans rather than from the statute written to protect the people the loans are about. Its reach is exactly what its source implies: it fixes loan files inside that channel, and it does not tell a single applicant anything.
The fourth thing is the remedy, and this is the finding to take away. Both regulators looked at this and both aimed at the same place: the change-control pipeline. Advisory-board review of changes that could materially affect consumer files. Pre-deployment code review. Monitoring of the results of system changes. Weekly intake of customer incident reports. A quarterly senior-executive committee. Developer training on accuracy obligations. Every one of those is a real control and every one of them is aimed upstream of the moment the damage occurred. That is a coherent theory of the case — this was a release failure, so govern releases — and it leaves an entire half of the problem untouched. Nothing in either instrument attaches to the delivered number: no requirement that a score travel with a marker saying which pipeline version and which reference date produced it, no reconciliation of a delivered value against a recomputation, and above all no duty to tell the person the number was about. Two regulators, five ordered controls between them, and the applicant is not in any of them.
The fifth thing is the pair of defects, which is why both are on the board. In the same month the same company shipped a second coding error that duplicated disputed collection tradelines in 46,400 files. That one wrote durable rows into the record, so the ordinary machinery could reach it: a duplicated tradeline is a wrong entry, a consumer can see it, a dispute can bite on it. And it still took from April to at least November to clear the rows the code had already written, turning up roughly 10,000 older duplicates from 2020 that nothing had been looking for. Set the two side by side and you get the whole shape of the deployment. The defect that contaminated a store was slow to fix and had a remedy. The defect that contaminated nothing was fast to fix and had none.
Two boundaries hold and they are not decoration. This is not an artificial-intelligence case: there was no learned model at fault, no discriminatory design, and no automated decision by the modelled operator. Describing it as one would import a whole apparatus of governance — bias audits, explainability, model cards — that would have caught precisely nothing here, which is the reason the case is in the atlas. And served people are not modelled: no applicant, denial, rate or household outcome is computed from anything on this board. The score-shift counts, the point bands and the settlement class size are recorded external observations, and they are floors rather than totals, because the record notes that consumers whose soft inquiries were affected were excluded from the company's own count entirely.
What remains is a question the record does not answer and can still be asked plainly. More than 600,000 people were scored at least ten points below their true score by the company's own reconstruction. That reconstruction exists; it is where the regulators' figures come from and it is what defined who is in the class. The company could therefore have told any one of those people, at any point after April 2022, that the number behind their application had been wrong. Nobody required it to, and it did not.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.