Skip to content

PAN Lab example

Upstart lending model

Regulator-verified access — and a search left at an impasse

A machine-learning model approves, declines, and prices credit with no per-application human review. Modeled on a deployment with both regimes on the record: a regulator published its access gains - about 27% more approvals at about 16% lower APRs - and a monitorship published four reports on the live model. The testing found no close proxies, yet flagged approval disparities and a likely-viable less-discriminatory alternative. Then it reached an impasse over how hard the law requires you to search. Every governable lever here is upstream of a model that decides on its own.

Stylized model of a documented deploymentLending & credit collections AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Automated-underwriting-class with its fair-lending testing on the record network: 5 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    The two external actors are drawn separately because the record documents two, with different authority and different provenance. The monitorship was seated by private agreement with civil-rights and borrower-advocacy organizations and got access to the live model, publishing four reports on its testing; the reporting channel existed because a federal regulator issued a no-action letter, ran for about five years, and produced the access figures the regulator published under its own name. Blending them into one node loses the fact that made this deployment legible: a supervisory channel and an adversarially-seated one, watching the same model and reaching different places. The reporting channel is drawn faint because it demonstrably ran; the monitorship's own hardest finding stays empty because the record leaves it at an impasse. A heavy workload against limited capacity for a national lending platform whose human function tests in aggregate and never sees an application.

  • baseline

    This models the well-lit lending pattern documented in the case file - not a reconstruction of the actual model. The service regime is the family's only regulator-verified term: the model ran for five years under a regulator's no-action letter with a reporting duty, and the regulator published the access results directly - about 27% more applicants approved than a traditional model at about 16% lower average APRs, near-prime applicants approved at roughly twice the rate, gains across the demographic segments tested. Drawn as a regulator's published finding, not a deployer dashboard.

  • assumed

    Underwriting is fully automated - there is no per-application human review - so every governable lever is upstream and the operator here is the fair-lending / model-risk compliance function testing the model in aggregate, never a per-decision reviewer. 'The model decided' does not end accountability; it relocates all of it to the upstream levers (model choice, testing, the search for alternatives, the reporting channel), and the governable question is whether those are resourced or merely declared.

  • baseline

    The fair-lending testing regime is drawn present, at a low level on the model check, because it is externally documented in four public monitorship reports on the live model. Quantitatively the monitorship found no close protected-class proxies among the inputs - but it also identified approval disparities for Black applicants, so a 'no proxies' finding is about inputs, not a clearance of outcomes. A facially-neutral aggregate feature (a school's cohort default rate priced into an individual's terms) can carry protected-class impact even when no input is a close proxy, which is exactly what disparate-impact testing exists to catch.

  • assumed

    The domain's deepest question is drawn as the latent oversight check, empty at baseline: the monitorship flagged a likely-viable less-discriminatory alternative that appeared to perform comparably, then reached a documented methodological impasse over how hard the law requires an organization to search for such an alternative before keeping the model it has. The live question is not whether a disparity exists but how hard you must look, and the record shows it left open rather than settled - the honest state of the art, not a solved problem.

  • baseline

    The adverse-action explanation duty is a separately-resourced, separately-failable surface, drawn on the decisions-logged edge: when the model declines an applicant, the organization must still give specific, accurate principal reasons, and a regulator has made explicit that a model's complexity is no excuse. An organization can pass its bias testing and still fail here, by being unable to tell a declined applicant why - which is why explanation is its own duty, not a byproduct of fairness testing.

  • assumed

    No credit outcome and no applicant is modeled here. This Lab reads institutional propagation only, and applicants are boundary-only. Approvals, declines, disparity findings, the search-for-alternatives impasse, and the reasons on any denial notice live in the case file, and are never computed from anything in this diagram.

What this example does not show

  • No credit outcome is modeled. The Lab reads institutional propagation only; applicants are boundary-only, and the regulator-verified access figures, the monitorship findings, the search-for-alternatives impasse, and the reasons on any denial notice live in the case file, never computed on this diagram.
  • The ~27%/~16% access figures are a regulator's published no-action-letter results entered as such; the 'no close proxies' finding, the identified approval disparities, and the less-discriminatory-alternative impasse are the monitorship's public record, and the adverse-action explanation duty is drawn as a surface on the decisions-logged edge, not a computed harm.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • A machine-learning underwriting and pricing platform using education and other alternative data operated for five years under a regulator's no-action letter with a reporting obligation, and the regulator published the access results: 27 percent more applicants approved than a traditional model at 16 percent lower average APRs, with near-prime applicants (FICO 620 to 660) approved at roughly twice the rate, and gains across the tested demographic segments. This is the lending family's only regulator-verified service term. Underwriting is fully automated with no per-application human review, so the organizational levers are all upstream — model choice, the testing regime, the search for alternatives, and the reporting channel to the regulator.

    empirical
    • Government Consumer Financial Protection Bureau — Ficklin, P.A., & Watkins, P. (2019). An update on credit access and the Bureau's first No-Action Letter. CFPB Blog. https://www.consumerfinance.gov/about-us/blog/update-credit-access-and-no-action-letter/
  • The same deployment carries the family's most detailed public fair-lending testing record: four reports from an independent monitorship agreed with civil-rights organizations found no close protected-class proxies quantitatively, but identified approval disparities for Black applicants, flagged a likely viable less-discriminatory alternative model, and ended in a documented methodological impasse over how hard the law requires an organization to search for such an alternative. Independently of the disparity question, adverse-action notices must give specific, accurate principal reasons for a denial regardless of the model's complexity — a governed explanation duty a complex model does not discharge by being accurate.

    empirical
    • Advocacy Relman Colfax PLLC (2021-2024). Fair Lending Monitorship of Upstart Network's Lending Model (Initial, Second, Third, and Final Reports). https://www.relmanlaw.com/cases-upstart-network-fair-lending-counseling
    • Regulatory Consumer Financial Protection Bureau (2022, 2023). Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms; and Circular 2023-03 on Regulation B sample forms. https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/

Where this connects

Institutional pressures in this domain

  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Lending & credit collections AI domain page.

Levers available here and the patterns behind them

Documented case histories