To run a fair lending regression analysis, you build a statistical model that predicts a loan outcome (approval, denial, interest rate, or fees) from the legitimate credit factors a lender actually uses, add a variable representing the borrower’s protected-class status, and check whether that protected-class variable still predicts a worse outcome once everything else has been held equal. If it does, and the effect is large enough to be statistically significant, you have a measurable disparity that the lender’s stated underwriting cannot explain. That gap is the starting point for a fair lending investigation, not the conclusion of one.
The technique is used by the Consumer Financial Protection Bureau, the Department of Justice, and prudential regulators including the FDIC, Federal Reserve, and Office of the Comptroller of the Currency to build enforcement cases under the Equal Credit Opportunity Act (15 U.S.C. § 1691) and the Fair Housing Act (42 U.S.C. § 3601 et seq.).1Office of the Law Revision Counsel. 15 USC 1691 – Scope of Prohibition2Office of the Law Revision Counsel. 42 USC Ch. 45 – Fair Housing Institutions with strong compliance programs run the same regressions on themselves before an examiner does.
What the Regression Is Trying to Prove
Before you write a single line of code, be clear on which legal theory the model is meant to support. That decision shapes the variables you include and how you interpret the results.
Disparate treatment means a lender intentionally applied different standards to a protected group. A regression showing that Black applicants with identical credit profiles received higher interest rates than white applicants points toward this theory. Disparate impact is subtler: a facially neutral policy, applied to everyone the same way, that disproportionately harms a protected class without a legitimate business justification.
Disparate impact claims follow a three-step burden-shifting framework. The agency first shows that a practice produces a statistically significant negative effect on a protected class. The lender then gets a chance to show the practice serves a legitimate business necessity. If the lender clears that step, the agency can still prevail by identifying a less discriminatory alternative that meets the same business objective. Regression feeds step one directly, and it can inform steps two and three when the model reveals alternative underwriting criteria that predict default risk just as well without producing the disparity.
Step 1: Pick the Outcome You’re Testing
The dependent variable is the lending outcome under investigation, and its type dictates the rest of the model.
For underwriting studies, the outcome is usually binary: approved or denied. For pricing studies, the outcome is continuous, such as the interest rate charged, the total origination charges, or the rate spread above the average prime offer rate. These call for different statistical techniques, so pick before you build.
You can also run separate regressions for different stages of the credit lifecycle: application-to-approval, approval-to-origination (which catches fall-out patterns), and pricing among originated loans. Each answers a distinct question about where in the process any disparity actually appears.
Step 2: Assemble and Clean the Data
Regression is only as good as the data behind it. For mortgages, the primary data source is the Loan Application Register that lenders compile under the Home Mortgage Disclosure Act, implemented through Regulation C at 12 CFR Part 1003.3Consumer Financial Protection Bureau. 12 CFR Part 1003 – Home Mortgage Disclosure (Regulation C)
Under 12 CFR 1003.4, a full HMDA reporter records dozens of fields for every covered transaction, including:
- Borrower financials: gross annual income relied on in the credit decision, debt-to-income ratio, credit score and scoring model used
- Loan characteristics: loan amount, interest rate, term, type, purpose (purchase, refinance, cash-out refinance, or home improvement), and lien status
- Property details: property value, construction method, occupancy type, census tract, and unit count
- Pricing data: rate spread over the average prime offer rate, total origination charges, discount points, lender credits, and total points and fees
- Demographics: ethnicity, race, sex, and age of applicant and co-applicant
- Outcome: action taken (originated, approved but not accepted, denied, withdrawn, or incomplete) and the principal reasons for denial
4eCFR. 12 CFR 1003.4 – Information To Be Collected Before modeling, scrub the LAR for duplicate entries, formatting errors, and demographic codes that don’t match standardized federal categories. Sloppy data preparation is one of the most common reasons regression results get challenged during an exam.
When You Don’t Have Race Data: BISG Proxies
HMDA gives you self-reported race and ethnicity, but auto lenders, credit card issuers, and most non-mortgage creditors are generally prohibited from collecting demographic information. Without it, you can’t run the regression. The CFPB’s answer is Bayesian Improved Surname Geocoding, or BISG.5Consumer Financial Protection Bureau. Using Publicly Available Information To Proxy for Unidentified Race and Ethnicity
BISG combines two pieces of public Census data: the demographic distribution associated with a borrower’s surname and the demographic composition of their residential census tract. Bayesian probability merges the two signals to assign each borrower a probability (0 to 100 percent) of belonging to each racial or ethnic category. The CFPB has found the proxies correlate highly with self-reported race and outperform surname-only or geography-only methods.6Consumer Financial Protection Bureau. Using Publicly Available Information To Proxy for Unidentified Race and Ethnicity
Proxies are not perfect. Because BISG produces an estimate rather than a known value, it introduces measurement error into the regression. The practical consequence: if discrimination exists, a proxy-based model will typically understate its size. The less accurate the proxy, the more the results tilt toward missing real disparities. Keep that asymmetry in mind when you read output from a non-mortgage portfolio.
Step 3: Classify Your Independent Variables
Every non-outcome data point in the model plays one of three roles. Getting these roles wrong is one of the fastest ways to produce results no one can rely on.
Control Variables (Legitimate Credit Factors)
These are the financial factors a lender actually uses to assess risk. The usual suspects are credit score, debt-to-income ratio, loan-to-value ratio, loan amount, and property type. Occupancy matters too, because default risk changes depending on whether the property is a primary residence or an investment. Control variables let the model account for genuine differences in borrower risk so that anything left over can be evaluated on its own terms.
Choosing the right controls is more judgment than formula. Include too few and you invite omitted variable bias, where a missing risk factor inflates the apparent effect of protected-class status. Include too many highly correlated variables (credit score and delinquency history, for example) and you introduce multicollinearity. That doesn’t bias the coefficients, but it inflates their standard errors and can hide real disparities by making individual coefficients look statistically insignificant even when the overall model is strong.
One rule specific to fair lending: a variable the lender doesn’t actually use in underwriting, but that correlates with both race and lending outcomes, generally should not go in. Adding it can mask real discrimination. The point of the model is to test the lender’s actual decision-making process, not to explain the disparity away.
Protected-Class Variables
These are the variables of central interest: race, ethnicity, sex, age, or another protected characteristic. They sit in the model alongside the financial controls. A well-specified model should show a protected-class variable with no statistically significant effect if the lender is treating everyone equally.
Discretionary Pricing Adjustments
One of the most common sources of fair lending risk is loan officer pricing discretion: any judgmental deviation from the standard rate sheet or pricing engine output. A loan officer might lower a rate to match a competitor or raise it because a file required extra work. The OCC has specifically flagged broad pricing discretion and loan officer compensation tied to higher rates as key risk factors for discriminatory pricing.7Office of the Comptroller of the Currency. Comptrollers Handbook – Fair Lending
In a pricing regression, discretionary adjustments are dangerous because they inject subjective judgment into what is otherwise an automated process. If your institution allows overrides, document the amount, the reason, and who approved it for every exception. Without that documentation, the regression has no way to distinguish legitimate business reasons from discriminatory ones, and the disparity gets attributed to the protected-class variable by default.
Step 4: Choose the Model Form
Statistical software does the arithmetic; you choose the form. For binary outcomes like approval or denial, the standard is logistic regression (logit), which estimates the probability that an applicant falls into one outcome category versus the other. For continuous outcomes like interest rate or total fees, ordinary least squares (linear) regression is the typical choice.
The model then compares a target group (say, Black or Hispanic applicants) against a control group (typically white or male applicants, depending on the protected characteristic under review). The software holds every legitimate financial factor constant, creating in effect a comparison between hypothetical applicants who differ only in their protected-class status. If a statistically significant gap remains after that equalization, the disparity demands explanation.
Consider running parallel models. One might focus on the whole portfolio; others might isolate specific products, loan officers, branches, or geographic areas where risk patterns concentrate. The same underlying framework produces different insights at different levels.
Step 5: Read the Output
Two numbers from the regression output do most of the work.
The p-value measures the probability that the observed disparity could have occurred by random chance alone. A p-value of 0.05 or lower is the conventional threshold for statistical significance, meaning there is at most a five percent probability the result is a fluke.8United States House Committee on Financial Services. Statistical Fair Lending Analyses Regulators often look for p-values well below 0.05 before building an enforcement case.
The coefficient tells you the size and direction of the disparity. In a logistic model of denials, a positive coefficient on the race variable means the target group faces higher odds of denial after controlling for financial factors. Convert the coefficient into an odds ratio for easier interpretation: an odds ratio of 1.5 means the target group is roughly 50 percent more likely to be denied after equalizing everything else. In a linear model of pricing, the coefficient is the dollar or basis-point difference in what the target group pays on average.
A statistically significant coefficient is not proof of intentional discrimination. It is proof of a measurable, non-random gap that the lender’s stated underwriting cannot explain. That gap is where the investigation begins.
Step 6: Validate Statistical Findings With File Review
Regression finds patterns across thousands of loans, but patterns alone do not close an investigation. The standard follow-up is a comparative file review, sometimes called matched-pair analysis. You pull actual loan files from the target group (usually denied applicants or those charged more) and compare them side by side against similarly situated applicants from the control group who got better outcomes.
File-level review answers questions the regression cannot. Did the denied applicant have compensating factors the model missed? Did the loan officer document a legitimate reason for a pricing deviation? Were stated policies actually followed? A regression can show that Hispanic applicants were denied at higher rates; only the file review reveals whether the fifth-highest-risk Hispanic applicant was treated the same as the fifth-highest-risk white applicant with a comparable profile. Broad statistical evidence combined with granular file analysis is what gives fair lending examinations their credibility, and it is the approach laid out in the Interagency Fair Lending Examination Procedures.9Federal Financial Institutions Examination Council. Interagency Fair Lending Examination Procedures
Testing AI and Algorithmic Underwriting Models
Machine learning models increasingly replace traditional scorecards, and they create particular problems for fair lending analysis. A neural network or gradient-boosted model might consider hundreds of variables and complex interactions no human can audit by reading the code. The legal obligations do not change. ECOA and the Fair Housing Act apply regardless of technology.
The CFPB has made clear that lenders cannot hide behind algorithmic complexity. Creditors using AI or other opaque models must still provide specific and accurate reasons when denying an applicant. CFPB Circular 2023-03 states that adverse action notice requirements apply equally to every credit decision, whether the technology is a simple scorecard or a black-box algorithm the creditor itself may not fully understand.10Consumer Financial Protection Bureau. CFPB Circular 2023-03 – Adverse Action Notification Requirements and the Proper Use of the CFPB Sample Forms A lender cannot use the boilerplate reasons on a standard denial-notice checklist if those reasons don’t accurately reflect what the model actually weighed.
For the regression analyst, the framework is the same. You run the same style of regression on the AI model’s outputs, checking whether protected-class status predicts worse outcomes after controlling for legitimate factors. The catch is that the underlying model is harder to interrogate. Variables like ZIP code, education level, or spending behavior can serve as proxies for race even when race itself is nowhere in the inputs. Institutions bear full responsibility for the outcomes their models produce, including models licensed from third-party vendors, and regulators expect them to pressure-test for discriminatory effects before deployment.
Geographic Testing: Redlining Doesn’t Show Up in Underwriting Data
Not all fair lending risk is visible in application-level regressions. Redlining, the practice of avoiding lending in minority neighborhoods, requires a different analytical lens. Regulators evaluate redlining by defining a Reasonably Expected Market Area, or REMA: the geographic footprint where the institution actually markets and originates loans, or reasonably could be expected to.
The REMA is built from branch and ATM locations, marketing reach, the geographic distribution of applications and originations, and natural barriers like rivers or highways. Once it is set, you map the institution’s lending activity against it. Gaps in lending, particularly in majority-minority census tracts sitting within the REMA, raise flags. Examiners look for patterns sometimes called geographic donut holes, where lending surrounds but avoids specific neighborhoods.
Spatial analysis complements traditional regression. A lender can pass every underwriting and pricing regression cleanly and still have a redlining problem if it systematically avoids marketing in or accepting applications from communities of color.
What to Do When the Regression Finds a Disparity
Detection is only useful if it leads to correction. Two tools sit at the front of the response.
Fix the Adverse Action Notices First
Under Regulation B, when a creditor takes adverse action on a credit application, it must provide either a statement of the specific reasons for denial or a notice of the applicant’s right to request those reasons within 60 days.11Consumer Financial Protection Bureau. 12 CFR 1002.9 – Notifications The reasons must accurately reflect what the lender actually considered. If your regression shows that the drivers of denial in practice don’t match the reasons your notices cite, that mismatch is itself potential evidence of discrimination. Align the notices with the model’s findings, and if AI is involved, translate its factors into specific, accurate reasons the applicant can understand.10Consumer Financial Protection Bureau. CFPB Circular 2023-03 – Adverse Action Notification Requirements and the Proper Use of the CFPB Sample Forms
Consider a Special Purpose Credit Program
Regulation B at 12 CFR 1002.8 explicitly permits for-profit lenders to create programs targeting classes of borrowers who would not otherwise qualify for credit, or would receive it on less favorable terms, under the institution’s standard underwriting.12eCFR. 12 CFR 1002.8 – Special Purpose Credit Programs
A for-profit lender running an SPCP must adopt a written plan identifying the class of people served, the specific credit standards and procedures, and either a duration or a reevaluation date. The program can modify existing underwriting standards, introduce a new product, adjust pricing, or change eligibility. Participants may be required to share a common characteristic such as race or national origin, and the lender may collect and consider that information for eligibility, which ECOA otherwise prohibits. The exception exists because the program expands access rather than restricts it.
SPCPs are not just an enforcement remedy. Institutions increasingly use them proactively after their own regression analyses show gaps. A lender that finds higher denial rates for Black applicants in specific census tracts can design an SPCP to close that gap without waiting for a regulator to raise the issue.