Regulation — banking-specific

CFPB UDAAP — Dodd-Frank Section 1031 applied to AI decisions

The unfair / deceptive / abusive acts + practices authority is where a silent AI credit-underwriting failure stops being a model-risk story and becomes a consumer-protection matter. CFPB's supervisory reach on AI is grounded in this section — and the civil-money-penalty schedule has real teeth.

What the statute actually says

"The Bureau may take any action authorized under part E to prevent a covered person or service provider from committing or engaging in an unfair, deceptive, or abusive act or practice under Federal law in connection with any transaction with a consumer for a consumer financial product or service, or the offering of a consumer financial product or service." 12 USC §5531(a) — Dodd-Frank Section 1031
"The Bureau shall have no authority under this section to declare an act or practice in connection with a transaction with a consumer for a consumer financial product or service, or the offering of a consumer financial product or service, to be unlawful on the grounds that such act or practice is unfair, unless the Bureau has a reasonable basis to conclude that — (A) the act or practice causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers; and (B) such substantial injury is not outweighed by countervailing benefits to consumers or to competition." 12 USC §5531(c) — unfairness standard

What this means in plain English

For an AI credit-underwriting engine, three UDAAP tests run in parallel:

  1. Unfair. Substantial consumer injury (wrongful decline / higher-priced offer) not reasonably avoidable by the consumer, not outweighed by legitimate benefit.
  2. Deceptive. A representation about the product (rate, approval odds, treatment of the application) that misled the consumer in a way that mattered.
  3. Abusive. Takes unreasonable advantage of the consumer's lack of understanding of the product's risks or terms — an AI blackbox output can meet this test.

The 2024 adjusted civil-money-penalty schedule is $6,813 to $1,362,567 per day per violation — the range moves with the tier of violation and knowledge.

What triggers the exposure in the sample

Silent 45+ day drift + ~810 potentially-misrouted B3 applications. The unfairness test bites here: the injury was substantial (declined credit / higher-priced offer), not reasonably avoidable by the applicant, and no countervailing benefit runs to the consumer. Once CFPB opens a supervisory file, the daily civil-money-penalty clock is a real budget line.

What the $499 Snapshot shows against this rule

Read the full scenario walkthrough →

How does this help me?

The civil-money-penalty range is only part of the exposure. CFPB consent orders bundle restitution + ongoing monitor + reputational cost. The dollar frame is real.

Read: CFPB UDAAP -- what a consent order actually costs →

$499 Snapshot. 3 business days.

The dated good-faith diligence record you want on file BEFORE CFPB supervisory examination lands.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.