PAN Lab example
Apple Card underwriting
Cleared on the numbers but unable to say why
An automated model underwrites a widely used consumer card. Modeled on a deployment a regulator investigated after a viral bias allegation: it analyzed about 400,000 applicants and cleared the model - no unlawful discrimination - then faulted the deployment anyway. Applicants could not learn why they got the terms they did, and the front line could not explain the decisions. The model was fair and the organization still could not say why it decided as it did. Those are two surfaces, and only the first one passed.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Cleared-underwriting-class with the explanation channel unbuilt network: 6 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
The principal-reasons notice is modeled as a component, because in this deployment it is the artifact the whole case turns on. The supervisory finding pairs a model cleared on the numbers with documented failures of explanation, so the notice is where the deployment failed while the model held - and a surface that fails on its own is a component, not a clause inside a pathway's copy. It sits between the model's output and the person decided on, carrying no flow of its own: what a notice does is state reasons, and whether those reasons are specific and accurate is a separately resourced question from whether the model is fair. A heavy workload against limited capacity for a mass-market consumer card whose inquiry volume is what the investigation examined.
- baseline
This models the cleared-but-faulted pattern documented in the case file - not a reconstruction of the actual model. The regulator analyzed roughly 400,000 in-state applicants and found no unlawful discrimination on a prohibited basis: the model was cleared on the numbers. That finding is drawn as the present fair-lending check, at a low level, the deployment's genuine strength on the public record.
- baseline
The failure is the separate explanation / customer-service channel, drawn as the latent oversight check, empty at baseline: the same investigation documented that applicants could not learn why they received the terms they did and that the front line could not explain the model's decisions, and the resulting opacity destroyed consumer trust even though the underwriting was lawful. The two surfaces fail independently - passing the fair-lending test did not build the explanation channel.
- assumed
The explanation duty is not discharged by model accuracy: adverse-action rules require specific, accurate principal reasons for a decision regardless of model complexity, and supervisors have said a black box is no defense and that checking the nearest sample-form box does not comply. The gap is drawn on the operator-to-operator edge between the customer-facing function and the model-holding function - each holds part of an explanation the other would have to complete.
- assumed
No credit outcome and no applicant is modeled here. This Lab reads institutional propagation only, and applicants are boundary-only. The cleared finding, the documented explanation failures, and the trust collapse live in the case file, and are never computed from anything in this diagram. The viral allegation that prompted the investigation is recorded as the trigger for a supervised finding, never as a verdict the diagram adjudicates.
What this example does not show
- No credit outcome and no applicant is modeled. The Lab reads institutional propagation only; applicants are boundary-only, and the cleared fair-lending finding, the documented explanation failures, and the trust collapse live in the case file, never computed on this diagram.
- The regulator's finding was that the underwriting was lawful and the deployment's explanation, customer-service, and transparency failed; the diagram draws those as two independent surfaces (a present fair-lending check, a latent explanation channel), not a computed harm, and the viral allegation that prompted the investigation is recorded as the trigger for a supervised finding, never as a verdict.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
A bank's automated credit-decisioning for a widely used consumer card was investigated by a state regulator after viral allegations of gender bias in credit-line assignment. The regulator analyzed roughly 400,000 in-state applicants and found no unlawful discrimination on a prohibited basis — the model was cleared on the numbers. But the same investigation documented failures of explanation, customer service, and perceived transparency: applicants could not learn why they received the terms they did, front-line staff could not explain the decisions, and the resulting opacity destroyed consumer trust even though the underwriting itself was found lawful. This is the domain's cleared-but-faulted case: a statistically clean model paired with a failed duty to explain.
empirical- Government evaluation New York State Department of Financial Services (2021, March 23). Report on Apple Card Investigation. https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202103231
The lesson the cleared-but-faulted outcome carries is that a lawful, statistically clean model does not discharge the separate duty to explain a decision. Regulators have made explicit that adverse-action notices must give specific, accurate principal reasons regardless of how complex the model is, and that a model being a black box is not a defense — checking the nearest sample-form box does not comply. The explanation and customer-service channel is therefore a distinct, separately-resourced surface that can fail on its own: an organization can pass its fair-lending testing and still fail the people it decides on by being unable to tell them why.
empirical- Regulatory Consumer Financial Protection Bureau (2022, 2023). Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms; and Circular 2023-03 on Regulation B sample forms. https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/
Where this connects
Institutional pressures in this domain
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Lending & credit collections AI domain page.
Levers available here and the patterns behind them
- Mark AI-written records — Provenance labeling
- Gate record entries — Human-in-the-loop write gating
- Peer sharing rules — Peer-edge governance
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model
Documented case histories
- Cleared on the numbers but faulted on the explanation
- Automated underwriting with its fair-lending testing on the record
- The governance an enforcement action had to write
- M-Shwari & Kenya's Digital Credit Market
- Citi Retail Services Judgmental Review & the Armenian surname screen
- Santander Consumer USA subprime vehicle loan scoring
- Credit Acceptance Corporation's net-collections score
- Wells Fargo refinance underwriting & the bridge nobody could build
- Navy Federal mortgage underwriting & three readings of one gap
- Enova International servicing defects & the debits nobody authorised
- Equifax Online Model Server coding error (2022)
- TransUnion's OFAC Name Screen & the people who could not sue
- Dave ExtraCash: an advertised ceiling, an automated amount, and a case that never asks how the amount is set
- Hello Digit's automated-savings algorithm
- Oportun's legal-collections filing pipeline