Lending & credit collections AI
Machine-learning underwriting, pricing, and credit decisioning — often fully automated, with no per-application human review, so the organizational levers all sit upstream: the choice of model, the fair-lending testing regime, the search for a less-discriminatory alternative, and the adverse-action notice that must explain a denial. Three facts shape the governance. A denial's explanation is a separately-resourced, separately-failable duty independent of statistical bias: a model can pass the disparity test and the organization can still fail by being unable to give an applicant specific, accurate reasons. Facially-neutral aggregate features — a school's default rate priced into an individual's terms — can carry protected-class impact, which is exactly what disparate-impact testing exists to catch. And the harder governance question is not whether a disparity exists but how hard the law requires an organization to search for a less-discriminatory model that performs as well — a question the record shows resolved by enforcement or left at an impasse, rather than settled. The Lab networks model only the deploying organization — its model, compliance and testing functions, and decision records; the applicants being decided sit outside the dynamics, and no credit outcome is computed on any diagram.
Use cases
What AI is doing here
ML underwriting & risk-based pricing
PredictiveMachine-learning models that approve, decline, and price credit — often fully automated with no per-application human review, so every governable lever is upstream: the model chosen, the fair-lending testing regime, and the search for a less-discriminatory alternative that performs as well.
Adverse-action reason generation
PredictiveThe system that must turn a model's denial into specific, accurate principal reasons for the applicant — a separately-resourced, separately-failable duty a complex model does not discharge by being statistically accurate, and one an organization can fail even when its bias testing passes.
Fair-lending & disparate-impact testing
PredictiveThe testing regime that checks a model for protected-class impact carried by facially-neutral aggregate features — and, past detection, the contested search for a less-discriminatory model, where the hard governance question is how hard the law requires an organization to look.
Case files
What has gone wrong and right
Documented deployments, presented as model organizations calibrated to the evidence, with full citations.
Automated underwriting with its fair-lending testing on the record
United States (federal — CFPB no-action letter; fair-lending monitorship via private agreement with civil-rights organizations)Upstart's machine-learning underwriting and pricing model, which uses education and other alternative data, ran for five years under a regulator's no-action letter with a reporting duty, and the regulator published the access results: 27% more applicants approved than a traditional model, at 16% lower average APRs, with near-prime applicants approved at roughly twice the rate. It is the lending family's only regulator-verified service term — and its most detailed public fair-lending record. Four monitorship reports found no close protected-class proxies, but identified approval disparities for Black applicants, flagged a likely-viable less-discriminatory alternative, and ended in a documented impasse over how hard the law requires an organization to search. Underwriting is fully automated, so every governable lever is upstream.
Explore this deployment in the PAN Lab →Cleared on the numbers but faulted on the explanation
United States (state financial-services supervisory investigation of a bank's card underwriting)A bank's automated credit-decisioning for a widely used consumer card drew viral allegations of gender bias in credit-line assignment. A state regulator analyzed roughly 400,000 in-state applicants and found no unlawful discrimination on a prohibited basis — the model was cleared on the numbers. The same investigation documented failures of explanation, customer service, and perceived transparency: applicants could not learn why they received the terms they did, front-line staff could not explain the decisions, and the opacity destroyed consumer trust even though the underwriting was found lawful. The cleared-but-faulted case: a statistically clean model paired with a failed duty to explain, which regulators treat as a separate obligation a black box does not discharge by being accurate.
Explore this deployment in the PAN Lab →The governance an enforcement action had to write
United States (state attorney general fair-lending enforcement; Assurance of Discontinuance)A state attorney general reached a $2.5 million settlement with the student-loan lender Earnest over its AI underwriting — the domain's cleanest failure-then-mandated-governance arc. The model used a cohort-default-rate feature (a school's aggregate default rate priced into an individual's terms) that disparately impacted Black and Hispanic applicants, and an immigration-status rule that automatically denied certain non-citizen applicants, while the organization ran no disparate-impact testing and gave inadequate adverse-action notices. The remedy did not fine-and-close: it mandated the missing program — model governance, disparate-impact testing, documentation, and reporting controls. The enforcement action wrote the governance the deployment had never built.
Explore this deployment in the PAN Lab →M-Shwari & Kenya's Digital Credit Market
Kenya — mobile-money-linked digital consumer credit, regulated by the Central Bank of Kenya; the anchor deployment is national, and the market layer spans hundreds of digital credit providersKenya's M-Shwari — launched 2012 by the Commercial Bank of Africa (now NCBA) with Safaricom over the M-PESA rails — scores people with no credit file from six months of their phone company's records: a hidden score set before anyone asks to borrow, whose only published test at the margin found a first-loan default difference of 0.007 against a control mean of 0.066, and whose 120-day arrears pipeline writes durable entries into a register the whole market reads. It took three regulators three instruments — a listing floor with a mass delisting, a licensing regime with prior approval over pricing, and data-collection guidance — to put a governed surface under a market defaulting at roughly twice the formal rate and blacklisted at roughly four times it.
Explore this deployment in the PAN Lab →Citi Retail Services Judgmental Review & the Armenian surname screen
United States — federal. Consumer Financial Protection Bureau administrative proceeding 2023-CFPB-0013, In the Matter of Citibank, N.A.; stipulation executed 3 November 2023, consent order issued 8 November 2023, without any admission or denial of the findings of fact or conclusions of law. The order reaches Citi's credit cards nationwide; the documented conduct is concentrated in California, in and around Glendale. The Bureau terminated the order on 16 October 2025 under 12 U.S.C. 5563(b)(3), roughly 23 months into a five-year term, expressly waiving any alleged noncompliance.A federal consent order found that for seven years employees manually underwriting Citi Retail Services credit-card applications used a last name ending in -ian or -yan, weighted by an address in or around Glendale, California, to mark applicants as fraud risks — and that the bank took corrective action against employees who failed to apply it, that supervisors and trainers instructed staff to keep the basis out of writing and off recorded phone lines, and that the reasons entered into the legally compelled denial notices were pretextual. There is no model anywhere in this record. The discriminating artifact was an authored rule carried in training, supervision, and performance management, which is why none of the usual model-governance instruments had anything to bite on and why the practice was found not by any internal control but by a regulator running regressions across seven years of outcomes. Citi neither admitted nor denied the findings. The order installed a five-year monitoring, statistical-testing, and root-cause-reporting regime around exactly that gap; the same agency terminated it about twenty-three months in, waiving any alleged noncompliance.
Explore this deployment in the PAN Lab →Credit Acceptance Corporation's net-collections score
United States — nationwide deployment; the operator, Credit Acceptance Corporation, is headquartered in Southfield, Michigan and listed on Nasdaq. The litigation of record is Consumer Financial Protection Bureau and the People of the State of New York v. Credit Acceptance Corporation, No. 1:23-cv-00038, in the United States District Court for the Southern District of New York, filed 4 January 2023 and pleading nationwide conduct under the federal Consumer Financial Protection Act alongside New York state claims. The Bureau was dropped as a plaintiff on its own consented motion on 29 April 2025, after which the action concerned New York consumers with the state attorney general as sole plaintiff. The fully briefed motion to dismiss was terminated unruled on 6 February 2026; the action was dismissed and discontinued without prejudice on 5 June 2026 on a settlement in principle, and on 23 July 2026 the parties reported agreement on all terms with a forty-five day extension of the reopen deadline. A parallel attorney-general investigation begun with Maryland subpoenas in 2016 and 2020 and expanded in August 2020 to 41 further states plus the District of Columbia remains separate; Kansas, Texas, and Iowa later withdrew. A separate and RESOLVED action on materially the same theories was settled with the Massachusetts Attorney General on 1 September 2021 for $27.2 million, without admission.A subprime vehicle lender's algorithm estimated, at origination, what share of everything owed it expected to collect — counting not only the scheduled payments but the auction proceeds after repossession, the post-default recoveries, the deficiency judgment, and the garnishment. Regulators alleged that on more than a third of loans nationwide that estimate fell below the amount financed, and that the number priced what the lender paid the dealership rather than what the borrower was charged. This is the atlas's case where the grievance is not that the model is wrong. There is no protected class, no false-positive rate, and no denied applicant: the Score decides no application and sets no interest rate, and the operator publishes quarterly how each year's loans are collecting against what it forecast for them. The dispute is over what the forecast was for, and over a borrower who was never shown it. Nothing here was ever adjudicated: the federal plaintiff was dropped on its own consented motion, the fully briefed motion to dismiss was terminated unruled, and the action was dismissed on a settlement in principle with no findings, no admissions, and no public terms.
Explore this deployment in the PAN Lab →Dave ExtraCash: an advertised ceiling, an automated amount, and a case that never asks how the amount is set
United States — federal. United States v. Dave, Inc. and Jason Wilk, No. 2:24-cv-09566-MRA-AGR (C.D. Cal.). Filed by the Federal Trade Commission on 5 November 2024 on a 4-1 Commission vote, and continued by the Department of Justice Consumer Protection Branch on referral from 30 December 2024, when the operative First Amended Complaint added the chief executive personally and a demand for civil penalties on a second 4-1 vote. Two counts under Section 5(a) of the FTC Act and three under Section 4 of the Restore Online Shoppers' Confidence Act. The motion to dismiss was DENIED IN FULL on 12 September 2025; the defendants answered on 10 October 2025 with seven affirmative defences; a Civil Trial Order of 14 November 2025 set a final pretrial conference for 9 November 2026; contested discovery ran from March through June 2026 and the last docket activity as of this file is 6 August 2026. There is no settlement, no consent order, and no adjudication on the merits. The CourtListener caption still reads 'Federal Trade Commission v. Dave, Inc.' from the original filing; that is a docket artifact, and the United States is the plaintiff and real party in interest. The product is nationwide.A consumer cash-advance app advertises up to $500 in five minutes. A fully automated cash-flow engine the operator calls CashAI reads the member's linked checking account and returns an eligibility verdict and a dollar amount; a partner bank originates the advance as a discretionary overdraft. The United States alleges that in the first fourteen months after the ceiling was advertised, the maximum was offered to a new user 0.002 per cent of the time, that the most common offer was $25, that more than three-quarters of the time no advance was offered at all, and that a monthly subscription was charged whether or not any offer ever came. Dave and its chief executive deny those paragraphs in their entirety, and the court that denied dismissal in full recorded in the same order that the parties dispute how the government computed the figures at all. The governance interest is what the record does NOT contain: nothing anywhere in the pleadings, the briefs, the answer, or the 34-page order mentions an algorithm, a model, or underwriting. The engine is known only from the operator's own investor filings, where it is named, versioned, and described as retrained on an eleven-day cycle. A five-count federal case counts this system's outputs without ever asking how they are produced, and no regulator, court, or auditor has examined it.
Explore this deployment in the PAN Lab →Enova International servicing defects & the debits nobody authorised
United States — federal. Consumer Financial Protection Bureau administrative adjudications 2019-BCFP-0003, In the Matter of Enova International, Inc. (issued 25 January 2019, $3,200,000 civil money penalty, four permanent conduct prohibitions, five-year term), and 2023-CFPB-0014 (issued 15 November 2023, $15,000,000 civil money penalty, a seven-year ban on Covered Loans, a ban on using or selling the associated consumer information, five behavioural prohibitions, a compliance plan and an executive-compensation provision, seven-year term). Both were entered without Enova admitting or denying the findings. The conduct spans consumer lending across US states, with harmed cohorts the orders identify state by state, including Idaho and Delaware, Ohio and Texas. NO FEDERAL ORDER IS IN FORCE: the 2019 order was superseded by the 2023 order, and the 2023 order was terminated by the Bureau on 2 September 2025 — Enova reports it as effective 29 August 2025 — with an express waiver of any alleged non-compliance.Two federal consent orders, four years apart, found that an online lender's own loan-servicing and payment-processing software took money out of consumers' bank accounts without permission — and both orders name executing code as the cause. The 2019 order applied the statutory unfairness test to a software defect and weighed the injury against the cost of debugging software. The 2023 order found the first order violated, set out eleven separately-described defect classes with their date ranges, consumer counts, and remediation figures, and attributed them to a coding error in the internal systems, flaws in the system logic, code that failed to register a consumer's change, and an automatic payment generation system firing on payments already made. One relapse happened because a new lead-routing project launched in 2020 and, in the Bureau's words, no one at Enova had checked whether it would reintroduce the prohibited defect. Enova neither admitted nor denied the findings and calls the matters unintended computer and system errors. Neither order contains a requirement about code review, change control, regression testing, or payment-integrity monitoring. On 2 September 2025 the Bureau terminated the second order about five years early and expressly waived any alleged non-compliance.
Explore this deployment in the PAN Lab →Equifax Online Model Server coding error (2022)
United States, nationwide. Two regulator instruments specific to this incident: Consumer Financial Protection Bureau consent order 2025-CFPB-0002, issued 17 January 2025 against Equifax Inc. and Equifax Information Services LLC; and New York Attorney General Assurance of Discontinuance No. 24-102, accepted 14 January 2025. Private consolidated class litigation in the United States District Court for the Northern District of Georgia (In re: Equifax Fair Credit Reporting Act Litigation, No. 1:22-cv-03072-LMM-CCB, Judge Leigh Martin May; lead case Jenkins v. Equifax, Inc., filed 3 August 2022). Congressional demand letters from Senators Elizabeth Warren and Mark Warner with Representative Raja Krishnamoorthi (4 August 2022) and from House Financial Services Chair Maxine Waters (9 August 2022). Fannie Mae, Freddie Mac, and the Federal Housing Finance Agency acted on the mortgage channel in June 2022.For twenty-two days in spring 2022 a credit bureau's legacy scoring platform computed date-relative credit attributes against a frozen calendar and sold the results to lenders. There was no defect in any scoring model, no change to any consumer's credit report, and no automated decision by the bureau at all — which is exactly why this is the atlas's clean counterexample to model-centric governance. Because the report was never wrong there was nothing to dispute, and a dispute channel handling roughly 765,000 contacts a month had no purchase on it. Nobody told the people whose numbers were wrong. Correction ran between companies instead: reissued scores to lenders, and a mandatory resubmission requirement from the two mortgage enterprises that reached loans rather than people. Two regulators closed in January 2025 with instruments aimed entirely at the change-control pipeline, and neither imposed a duty to notify anyone.
Explore this deployment in the PAN Lab →Hello Digit's automated-savings algorithm
United States, federal. Consumer Financial Protection Bureau administrative proceeding 2022-CFPB-0007, In the Matter of Hello Digit, LLC: stipulation dated 9 August 2022, consent order entered and docketed 10 August 2022, signed by Director Rohit Chopra. Hello Digit, Inc. launched the product in February 2015 from San Francisco, California and offered it nationwide; Oportun Financial Corporation acquired it on 22 December 2021 and merged it into Hello Digit, LLC, the respondent. The order runs for five years from its effective date, to 10 August 2027, and travels to any successor entity. The overdraft fees themselves were charged by each member's own bank, a party outside the deployment. The product's terms carry a binding arbitration provision with a class-action and jury waiver, and no class litigation over the autosave overdrafts was located.This is the lending roster's automation-with-a-warranty case, and the one where the algorithm decides nothing about a person: it reaches into their checking account and moves their own money, under an express undertaking that it would never transfer more than they could afford and would pay the fee if it overdrew them. In August 2022 the Consumer Financial Protection Bureau entered a consent order finding that the company had known since inception that the algorithm could not deliver that promise, that autosaves routinely caused overdrafts, and that of nearly 70,000 members who asked for the promised reimbursement, over 7,200 were refused under quotas the company had written for itself — two per lifetime, nothing if you disconnected the account that had just cost you the fee. All three counts are deception counts. The order requires no change to the algorithm, imposes a 2,700,000-dollar penalty against a redress floor of 68,145 dollars, and the operator's compliance move was to replace the undertaking with a disclaimer. The deployment then grew.
Explore this deployment in the PAN Lab →Navy Federal mortgage underwriting & three readings of one gap
United States — federal. Navy Federal Credit Union is a federal credit union chartered and supervised by the National Credit Union Administration, with consumer-compliance supervision shared with the Consumer Financial Protection Bureau because its assets exceed $10 billion. The private litigation is Oliver v. Navy Federal Credit Union, No. 1:23-cv-01731-LMB-WEF (E.D. Va., filed 17 December 2023, Judge Leonie Brinkema), on appeal as No. 24-1656 (4th Cir.). On 30 May 2024 the district court dismissed the disparate-treatment theory, preserved the disparate-impact theory, and struck all class allegations before any discovery. On 9 February 2026 the Fourth Circuit, in a published two-to-one opinion, affirmed the denial of a damages class and vacated the denial of an injunctive class, holding only that a pre-discovery strike was premature and expressly reserving the merits. On 25 August 2026 all nine named plaintiffs filed a notice of dismissal with prejudice, which the court so-ordered the same day. The docket states no reason and discloses no settlement. No court and no regulator has ever found that this institution discriminated in mortgage underwriting.In December 2023 a news organisation ran the public mortgage-disclosure data and reported that Navy Federal Credit Union, the largest credit union in the United States, had approved 77 per cent of white applicants and 48 per cent of Black applicants for 2022 conventional home purchase mortgages — the widest spread among the fifty biggest lenders — and that the gap survived holding more than a dozen variables constant. What followed is a governance loop that ran all the way to the end without answering the question that started it. Three parties examined the lending and each held a different slice of the data: journalists, working from a public file with the applicant credit score removed by rule; the credit union's own commissioned reviewer, a partner at the firm defending it in the resulting class action, who had the complete file and published a single sentence saying the gap falls below one per cent; and the regulator's economists, who had the complete file and the strongest model and published an industry average naming no institution. Congress wrote four times and can compel nothing. A court reopened discovery into the algorithm in February 2026 and the plaintiffs dismissed with prejudice six months later. No court and no regulator has ever found that this credit union discriminated. The gap is still in the 2025 filing.
Explore this deployment in the PAN Lab →Oportun's legal-collections filing pipeline
United States — the documented conduct is in TEXAS and CALIFORNIA and must be scoped to both. In Texas: justice of the peace courts in nine of the state's ten largest counties, which cap claims at $10,000, charge about $50 to file, and permit non-attorney filing. In California: small-claims courts statewide, which cap a high-volume filer at $2,500, provide no guaranteed interpreter, and bar legal counsel on both sides. The operator, Oportun Financial Corporation (Nasdaq: OPRT), is headquartered in San Carlos, California and was lending in twelve states at the time. THERE IS NO ADVERSE FINDING IN THIS RECORD. The Consumer Financial Protection Bureau served a civil investigative demand on 3 March 2021, narrowed it to legal collection practices from 2019 to 2021 and to pandemic hardship treatments, sent a Notice and Opportunity to Respond and Advise letter on 15 September 2022, received the company's written rebuttal on 14 October 2022, and on 28 March 2023 concluded the investigation with its enforcement staff declining to recommend an enforcement action: no finding, no consent order, no penalty, no admission. A national bank charter application filed with the Office of the Comptroller of the Currency on 23 November 2020 was voluntarily withdrawn on 8 October 2021 before any decision. Treasury's CDFI Fund certified the operator in 2009, was asked by advocacy groups in December 2020 to revoke that certification, and did not: Oportun, Inc. appears on the list of currently certified CDFIs dated 14 August 2026 under CDFI number 131CE011959. A NAME COLLISION HAZARD is recorded here rather than left to the reader: this operator is NOT Opportunity Financial (OppFi) of Chicago, which litigated a separate true-lender case against a California regulator; multiple secondary sources conflate them, and no California enforcement action against this operator over collections exists in this record.Oportun Financial Corporation, a Treasury-certified community lender founded to give Latino borrowers with no credit history a first loan, filed more than 47,000 collection suits against borrowers who fell behind in nine Texas counties over four years — on a two-newsroom analysis of 1.45 million court records whose authors call the figure an undercount — and filed tens of thousands more in California, where it accounted for at least 15 per cent of all small-claims filings across one twelve-month window. This is the atlas's case where the governed thing sits DOWNSTREAM of the model. The scoring system is not accused of anything: there is no protected class, no denied applicant, and no adverse-action notice, and the pipeline that produced the volume is documented as a threshold on a delinquency counter and a staffed filing desk rather than as an algorithm choosing defendants. What the record shows is an inclusion premise expanding the approved population, a default-handling apparatus sized by that expansion, and no channel carrying what happened in court back to the model that approved the borrowers. It is also the domain's only case where the effective lever was measurement by somebody with no authority at all. There is no order, no penalty, and no finding: the federal investigation closed with enforcement staff declining to recommend an action, the bank charter application was withdrawn before any decision, and the mission certification was never revoked. What stopped the practice was a reporter running the same public court query the company could have run on itself at any time, and putting the answer to it. The company announced four days later, before either investigation published.
Explore this deployment in the PAN Lab →Santander Consumer USA subprime vehicle loan scoring
United States — nationwide deployment. Santander Consumer USA Inc. was headquartered in Dallas, Texas and incorporated in Illinois; its then-parent Santander Consumer USA Holdings Inc. was a Delaware corporation, majority-owned and, from 31 January 2022, wholly owned by Santander Holdings USA, Inc., a subsidiary of Banco Santander, S.A. Resolved by parallel consent judgments entered in 34 jurisdictions — 33 states plus the District of Columbia — on 19 May 2020, effective 1 May 2020, the reference instance being People of the State of Illinois v. Santander Consumer USA Inc. in the Circuit Court of Cook County, Chancery Division, with the companion pleading People of the State of California v. Santander Consumer USA Inc., No. 20-CIV-02157 (Superior Court of California, County of San Mateo). Separate resolved actions in Massachusetts (November 2015, March 2017, February 2022), Delaware (March 2017) and Mississippi (Hinds County Chancery, filed January 2017, settled July 2021), and before the Consumer Financial Protection Bureau (December 2020), the Securities and Exchange Commission (December 2018), the Federal Reserve Bank of Boston (March 2017 written agreement, closed February 2021), the Department of Justice (February 2015 and October 2021 servicemember consent orders) and the New York State Department of Financial Services (June 2026).Santander Consumer USA's own models forecast, before the loan was written, that its weakest borrowers would fail at a high rate — and the forecast set the price rather than the answer. This is the atlas's case where the levers are documented and binding: when thirty-four attorneys general settled in May 2020 they did not ask for a better model. They froze the one it had, banded the entire remedy on that frozen score, added an affordability gate the model does not compute, ordered a second model built whose only job is to score confidence in the first one's inputs, took away the discretion to waive dealer documentation, and made every future default re-checked against the gate an automatic debt forgiveness and a request to delete the credit-bureau tradeline. Everything alleged about the operator's knowledge or intent is allegation entered by consent without proof, without adjudication, and without admission. The remedy is a court order and is live.
Explore this deployment in the PAN Lab →TransUnion's OFAC Name Screen & the people who could not sue
United States — federal. Principal action: Ramirez v. Trans Union, LLC, No. 3:12-cv-00632-JSC (N.D. Cal.), class of 8,185 certified July 2014, jury verdict 21 June 2017, affirmed in part with punitive damages reduced by the Ninth Circuit on 27 February 2020 (No. 17-17244), and reversed and remanded by the Supreme Court on 25 June 2021 in TransUnion LLC v. Ramirez, 594 U.S. 413 (No. 20-297). Predecessor action: Cortez v. Trans Union, LLC, 617 F.3d 688 (3d Cir. 2010) (Nos. 08-2465 & 08-2466), out of the Eastern District of Pennsylvania — the one final appellate liability holding against this practice, and what put the operator on notice. Sequel action: Ramirez Arrizon v. TransUnion, LLC, 2025 IL App (1st) 231911, in the Circuit Court of Cook County, Illinois and the Illinois Appellate Court, First District, where a class member held to lack federal standing refiled in a forum with no concreteness requirement and the dismissal as time-barred was affirmed on 31 March 2025.TransUnion sold an add-on that compared a consumer's first and last name against the U.S. Treasury's terrorist and narcotics sanctions list and nothing else — no date of birth, no middle initial, no Social Security number — then wrote a potential-match alert on the front page of the credit report and, from 2002, redacted it from the copy it sent the consumer. Across more than a decade the courts recorded thousands of false positives and not a single confirmed true match; in one seven-month window in 2011 the product labelled 8,185 people. In TransUnion LLC v. Ramirez the Supreme Court held that only the 1,853 whose reports a business happened to pull inside that window had suffered a concrete harm and could sue, and expressly took no position on whether the product was accurate or whether the statute had been violated as to the other 6,332. Two thousand people were eventually paid; when one of the excluded 6,332 refiled in a state court without a concreteness requirement, the claim was held time-barred.
Explore this deployment in the PAN Lab →Wells Fargo refinance underwriting & the bridge nobody could build
United States — federal. In re Wells Fargo Mortgage Discrimination Litigation, No. 3:22-cv-00990-JD (N.D. Cal., Judge James Donato), consolidating six private actions on 18 January 2023 into a nationwide putative class pleaded under the Equal Credit Opportunity Act, the Fair Housing Act, 42 U.S.C. section 1981, California's Unruh Civil Rights Act, and the California Unfair Competition Law. Wells Fargo & Company and Wells Fargo Home Mortgage were dismissed without prejudice in May 2023, leaving Wells Fargo Bank, N.A. as the only defendant. There was never a motion to dismiss: the bank answered on 17 May 2023 and the case proceeded straight to discovery, expert work, and Rule 23 briefing. On 5 August 2025 class certification was DENIED for failure of Rule 23(a)(2) commonality; both Rule 23(f) petitions were denied by the Ninth Circuit on 8 January 2026; seven of the eight named plaintiffs settled confidentially and were dismissed WITH PREJUDICE between 7 May and 1 June 2026, with interim lead counsel relieved; and the last remaining individual claim was stayed on 28 July 2026 through 25 September 2026, the court noting that further requests to continue the stay are not likely to be granted. The pending summary-judgment motion was never decided. No court and no regulator has ever found that this bank discriminated in refinance underwriting, and no publicly announced federal investigation, enforcement action, or finding on that subject has been located.In March 2022 a news analysis of federal mortgage-disclosure data reported that Wells Fargo had approved 47 per cent of Black homeowners' completed 2020 refinance applications against 72 per cent of white homeowners' — the largest racial gap among major lenders. Four years of litigation followed and ended without anyone deciding whether the underwriting stack had anything to do with it. Both sides' statisticians agreed a disparity exists in the counts and disagreed only about what caused it. The evidence that could have settled that question was split in two: the loan-level record published by rule leaves the applicant credit score out, by rule, so no public analysis can control for the variable the bank says explains the gap; and the 14,000-rule engine and two scorecards behind the decision reached a court file only under a protective order, in a proceeding that stopped at Rule 23 without reaching the merits. Class certification was denied for want of class-wide evidence of robust causality, with the court observing that 1,300-plus data attributes under 14,000 rules made commonality 'not at all obvious'. Seven of eight named plaintiffs settled confidentially and were dismissed with prejudice. No court and no regulator has ever found that this bank discriminated in refinance underwriting, and nothing in the public record changed about how the engine decides.
Explore this deployment in the PAN Lab →System map
Who is in the system and what pushes on it
Who is in the system
- Agency leadership. Owns procurement, policy, and the authority map; answers for the system publicly.
- Served people & families. Those the decisions land on. Deliberately outside the PAN dynamics — their outcomes are measured, never simulated.
- Vendors. Build and update the systems; hold the information asymmetry procurement must govern.
- Regulators & oversight bodies. Boards, auditors, data-protection officers, inspectorates — external correction capacity.
- Courts & commissions. The heaviest, slowest actors — who end most of the failures documented in this Atlas.
- Advocates & community organizations. Surface harms institutions do not see; historically the earliest accurate signal.
Dominant pressures
- Reviewer bottleneck. One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Austerity & recovery incentives. Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity. The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift. The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance. Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
Governance
Questions leaders should be asking
- 1. Underwriting here is fully automated, so there is no per-application human to catch an error — which means every governable lever is upstream (model choice, testing, the search for alternatives); are those levers actually resourced, or is 'the model decides' treated as the end of the accountability?
- 2. A denial has to be explained with specific, accurate reasons regardless of how complex the model is — so can the organization and its front line actually tell an applicant why, or has passing the disparity test been mistaken for discharging the separate duty to explain?
- 3. A facially-neutral aggregate feature — a school's default rate, a ZIP code — can price a group's history into an individual's terms; so is anyone testing the features for protected-class impact, and would a disparity be caught by design or only by a regulator?
- 4. The hard question is not only whether a disparity exists but how hard the law requires searching for a less-discriminatory model that performs as well — so is that search being done and documented, or is it left to an impasse or an enforcement order to force it?
For the actions behind these questions, see the Practice Library.
Seeing your organization in this domain? Mapping its actual pathways, pressures, and correction capacity is engagement work.
Work With Paramerge