An adverse action notice under Regulation B states the specific principal reasons for the credit decision. The official interpretations tie those reasons to the factors actually considered or scored — including the relevant component or components where a creditor used a combined scoring and judgmental process. A generic statement that an application did not score enough points does not satisfy this.

No particular method of selecting reasons is mandated. What is required is that the reasons correspond to the decision.

Check the authority before citing it

Two CFPB circulars are cited in most internal materials on this subject: 2022-03 on complex algorithms and 2023-03. Both were withdrawn effective 12 May 2025, and the withdrawal notice and the withdrawn-guidance index both list them.

The pages continue to resolve. A link returning content is an availability check, not an authority check, and a transfer binder describing Circular 2022-03 as an active AI regulation is describing a document that was withdrawn.

Withdrawal of the circulars does not repeal the notification requirements. Those sit in §1002.9 and were inspected separately. So the correction is a citation migration rather than a change of obligation: mark the circulars withdrawn, keep their historical wording as history, and support present-day propositions from the current regulation.

Timing and route

Section 1002.9(a) specifies when notification must occur and permits two routes: stating the reasons, or disclosing the applicant’s right to request them under the prescribed procedure.

Qualifications apply for business credit, incomplete applications, creditors below specified volumes, and notices given through third parties. A blanket internal rule requiring immediate written reasons in every case overstates the text, and building a system around that overstatement produces obligations the regulation does not impose while obscuring the ones it does.

The failure this creates for language models

The architectural consequence arrives before any model is chosen. The notice must reflect the reasons the decision actually used, so the system needs a recoverable record linking the application, the decision stage that produced the outcome, the factors and policy or model version in force, any override, and the notice that was delivered.

Consider a pipeline where an applicant passes automated scoring and a human underwriter then declines after reviewing an unresolved income discrepancy. A language model asked to draft the notice produces a fluent reason about payment history. The text is plausible, well-formed, and describes a decision nobody made.

Nothing about the model prevents this, because the model was never given the thing the notice has to reflect. The check that catches it compares proposed reasons against the preserved decision evidence and routes mismatches for correction. A fluent answer with no recoverable decision trail fails that check by construction.

Explanation is not audit trail

These are separate objects and the distinction is what makes the check possible.

The four principles set out in NISTIR 8312 separate explanation, meaningfulness, explanation accuracy, and knowledge limits. Explanation accuracy concerns fidelity to the system’s actual process, and is distinct from whether the decision itself was correct. An intelligible explanation establishes neither of those things.

An audit trail records events and responsibility. The provenance vocabulary standardised by W3C describes this as entities, activities, derivations, and responsible agents — inputs, retrieved source versions, model and configuration identifiers, tool activity, outputs, and human intervention, with unavailable evidence and replay limits recorded rather than omitted.

Treat every generated explanation as a claim, and the trail as the thing that tests it.

The rule

What stays fixed is that the notice reflects the decision, not the system. What changes is which stage produced the outcome — automated, human, or a combination — and the record has to identify that stage for each application, because the required reasons come from whichever one actually decided.

Where this fails

Score factors are substituted for decision reasons. The factors that most influenced a credit score and the principal reasons for the creditor’s action are different things and coincide only sometimes. Where a human overrode the score, the score’s factors describe a path not taken.

Post-hoc explanation is treated as the process. A method that approximates a model’s behaviour after the fact produces an account of the model, not a record of the decision. It is useful for understanding the system and it is not the evidence the notice requires.

Not to be confused with

A ban on complex models. Nothing here prohibits them. The requirement is that the reasons be recoverable, which is a constraint on the surrounding architecture rather than on the model class.

Complete compliance. ECOA, FCRA, and state law impose their own duties, and which activity constitutes an application or an adverse action is itself a determination about the specific product and workflow.