Alternative Data in AI Credit Underwriting: Risks & US Regulations

Summary

Alternative data can help lenders work with millions of underserved thin-file and credit-invisible individuals, especially when combined with AI underwriting. But the new opportunities come with new risks and regulatory exposure, which we discuss in this blog.

About 9.8% of the US adult population was credit “unscored” with insufficient or stale data and 2.7% were credit invisible (no credit record to generate a score from), as per the latest Consumer Financial Protection Bureau (CFPB) report. Lenders have started using alternative financial data to score and serve this massive market segment, often in conjunction with AI credit underwriting, because traditional lending models rely on conventional credit scores. While it’s a boon for millions of underserved US adults that might otherwise not get access to credible loan products, using alternative data in AI underwriting may introduce a new range of regulatory challenges. This includes new bias dimensions, privacy issues, and fair lending concerns.  

This blog aims to offer a broad overview (not legal advice) of the regulatory risks and opportunities tied to the use of alternative data in AI loan underwriting.

9.8%

Of US adults are credit “unscored,” with insufficient or stale data to generate a score

2.7%

Of US adults are credit invisible, with no credit record at all

What "alternative data in AI credit underwriting" actually means

The conventional credit scoring framework naturally concentrates around credit history, habits, and mix. Alternative data uses an individual’s non-credit-related financial data and some non-financial data to evaluate their creditworthiness. The financial data spans across cash flow elements like transaction history, balances, overdrafts, rent, utilities, and telco, and bill payments. It may also cover alternative lending products like Buy Now Pay Later (BNPL). Non-financial data includes behavioral data, employment history, education level, etc.

AI credit underwriting is the use of AI to assess credit risk and inform or make lending decisions, drawing on both conventional credit reports and alternative data. AI’s ability to extract relevant data and simultaneously identify patterns and anomalies from both structured and unstructured data sources makes it a strong fit for automating and accelerating the credit underwriting process. Lenders leveraging AI loan underwriting can decide whether to stop the process at recommendation or automate lending decisions as well.

For example, a lender might assess a thin-file applicant using twelve months of bank-transaction history showing steady income and on-time rent.

The subtle risk

Using alternative data for credit scoring introduces new regulatory risks, especially with non-financial data, which may lead to biased decisions. This is true even with purely human-based decision-making because some variables may correlate with protected classes, leading to discriminatory decisions that may be statistically sound by the lender’s own rubric yet still produce discriminatory outcomes that carry fair-lending and legal exposure, not just ethical concerns.

This is further compounded by using alternative data in AI underwriting, because it may identify and reinforce patterns and trends that may converge in certain borrower subsets and, without adequate controls, may make financially sound but biased recommendations for credit decision-making.

The opportunity

AI credit underwriting carries risk, but it also offers significant opportunities, including:

Financial inclusion

If the CFPB’s latest percentages of credit invisible (2.7%) and unscored US adults (9.8%) hold for the current population, there are about 33 million adults in the US without a credit score. This prevents access to a wide range of conventional credit products – from personal loans to mortgages. Using alternative credit data, ideally along with AI credit scoring, can help these individuals access a broader range of credit products.

Better risk modeling

Risk modeling is among the most mature AI and Machine Learning (ML) domains, with proven results across multiple lending categories. One example is Klarna, a BNPL giant that has leveraged ML to improve its credit underwriting model with 2x better default predictability compared to the VantageScore benchmark, a widely used US scoring model. AI credit decisioning can leverage alternative data points and identify cash flow and financial behavior patterns that classic credit data misses, enabling lenders to approve creditworthy borrowers that traditional scores overlook, while flagging high-scoring applicants who are likely to default.

Speed & automation

Conventional underwriting often requires employees to collect documents, verify income, review statements, compare information across systems and enter the same data more than once.

AI-automated underwriting can reduce that work. A system can classify documents, extract income and cash-flow data, compare the information with the application and return a recommendation or decision within minutes.

Straightforward approvals and declines may be processed automatically. Underwriters can then spend more time on exceptions, ambiguous cases and applications requiring judgment.

Borrowers receive decisions sooner. Lenders can reduce processing costs and increase capacity without removing the controls that make underwriting dependable.

Speed, however, should be the result of a well-designed process. It should not come from skipping verification, explanation or review.

New segments

Traditional scoring struggles with anyone who lacks a long credit history in the US, even when they are creditworthy. Immigrants arrive in the US with a blank profile regardless of their credit history in their home country; roughly 1.3 million immigrants came to the US between July 2024 and June 2025, and millions of Americans turn 18 each year, also starting with a blank “credit” slate.

Self-employed and small business owners are underserved too, mostly because of income volatility, which restricts their access to credit. Alternative data reaches these borrowers by reading what conventional scores miss – cash flow, including rent, bill payments, and business revenue. 

The data: What counts as alternative data

Alternative data is not only about how much lenders can access, on their own or through alternative credit data providers. Open banking has enriched these datasets enormously, but having the right data matters far more than having more of it, since volume alone can simply introduce noise. The right sources let lenders derive thousands of behavioral signals to assess a borrower’s risk profile and creditworthiness. The categories below differ sharply in what they reveal and where they come from, and they demonstrate that even the right data can carry regulatory and ethical risks that lenders and fintechs building custom fintech solutions need to understand. 

Data type What it signals Typical source or provider Coverage & data quality Risk flag
Cash-flow & bank-transaction Income stability, spending patterns, the ability to repay Open banking aggregators (Like Plaid) Wide and improving via open banking; high quality Low
Rent payments Consistent large recurring obligation met on time Rent-reporting services, property managers Inconsistent; reporting is voluntary and incomplete Low
Utility & telecom Bill-payment reliability, financial routine Utility and telco providers, specialist bureaus Uneven; varies by provider and region Low to moderate
Employment & income verification Current income and job stability Payroll and verification services Good where employer data is accessible Low
Public records Property, liens, and other formal financial events Government and public-record aggregators Broad but shallow; limited predictive depth Low
Behavioral device data Correlated (not causal) signals of risk Digital-footprint and device-analytics vendors Abundant but opaque High: proxy-discrimination and privacy exposure

The risks

Alternative data widens the lender’s view of an applicant, but a wider view is not automatically more accurate or fair.

The information may be incomplete, collected without meaningful understanding, or correlated with characteristics that should not influence a credit decision. Those concerns become more significant when models process thousands of variables and produce decisions faster than people can review them.

A candid and pragmatic view of AI credit underwriting must balance the opportunity with these risks.

Bias and proxy discrimination

Alternative data can act as a proxy, a stand-in for several protected characteristics in credit decisions, even when those characteristics are never used. ZIP code, device type, spending patterns, and rental history can all correlate with race, age, or nationality, so a model can produce discriminatory outcomes without any protected variable being used directly. The harm can be significant, and the intent unfortunately is irrelevant, which is precisely what makes proxy discrimination hard to catch.

Explainability and the black-box problem

Many machine learning models are black boxes and their decision-making rationale cannot be tracked or explained. In lending, that is a compliance and trust problem, not just a technical limitation. If a lender cannot explain exactly why an applicant was declined, it cannot produce the specific, accurate reason codes the law requires, which leaves it unable to defend a challenged decision.

Data quality, coverage, and accuracy

Alternative data is inherently uneven. Some sources are thin, stale, or wrong, and these coverage gaps impact the most vulnerable borrowers, which the alternative data was actually meant to help. An error in a traditional credit file can be handled with established dispute mechanisms. But an error in a novel data source may not have such a recourse, and the impacted borrower may never learn about it.

Privacy, consent, and security

A lot of alternative data is intimate and is either directly drawn from bank transactions, phone records, and online behavior or inferred from data points and patterns. Its use raises real questions about whether borrowers meaningfully consented to it because even if they consent to share data points, they may not understand how much can be inferred from it. Concentrating this data also amplifies the breach risk, turning an underwriting advantage into a security liability.

Regulatory and fair-lending exposure

Each of these issues ultimately becomes a governance concern. Lenders remain responsible for avoiding unlawful discrimination, producing valid explanations, maintaining accurate information and controlling third parties. Those obligations do not disappear because a model is technically sophisticated or supplied by a specialist vendor. The legal routes through which a claim may be brought can change. The need to understand and defend the decision remains.

Vendor and third-party dependency

Much of the alternative data market depends on outside providers. A lender may inherit a vendor’s weaknesses in consent, collection, identity matching, data quality and coverage. Changes to a provider’s methodology or access to a source can alter model behavior without an obvious change to the lender’s own system. This makes vendor management part of model governance. A contractual relationship does not transfer accountability away from the institution making the credit decision.

Model drift and overfitting

A model tuned on past behavior degrades as conditions change. Overfitting makes it look accurate in testing and unreliable in production, and drift means a model that was fair and accurately predictive at launch can deviate in production, unless it's actively monitored and "course corrected."

Regulatory exposure: The 2026 US compliance map

The US rules governing AI credit underwriting shifted in 2026, and the shift is easy to misread. The federal fair-lending lane narrowed, but the obligations that matter most for alternative data are still in force.

ECOA and Regulation B

The Equal Credit Opportunity Act (ECOA) prohibits discrimination in any credit transaction, regardless of the technology used to make the decision. A machine producing the output changes nothing about that. 

Adverse action notices

When a lender denies credit or takes another adverse action, it must provide specific and accurate reasons or explain how the applicant may obtain them. Complexity is not an exemption. The reasons provided must correspond to the factors actually considered or scored by the creditor. A broad label that does not reflect the real cause of the decision is insufficient.

The April 2026 change

Disparate impact is the idea that a policy can be discriminatory if it produces unequal outcomes across protected groups, even when there was no intent to discriminate, and no protected characteristic was used directly. On April 22, 2026, the CFPB published a final rule amending Regulation B that eliminates disparate impact, the "effects test," as a theory of liability under ECOA. The rule takes effect July 21, 2026, and refocuses federal ECOA enforcement on statutory text and evidence of intentional discrimination rather than effects-based analysis. This is a significant narrowing of one federal enforcement channel. 



But disparate impact exposure has not disappeared. The rule changes federal ECOA enforcement only. It does not touch the Fair Housing Act, which independently recognizes disparate impact in mortgage lending, nor state anti-discrimination laws, several of which still recognize it. For example, New York Department of Financial Services reminded lenders, the day the rule was published, that decisions producing a disparate impact may still be unlawful. Fair-lending testing remains a live expectation.

FCRA

When a provider assembles alternative data for credit decisions, that activity can bring the data within the Fair Credit Reporting Act's definition of a consumer report. This triggers certain accuracy and dispute obligations. Regulators addressed alternative data in underwriting directly in a 2019 interagency statement

Privacy

The Gramm-Leach-Bliley Act (GLBA) governs the handling and protection of nonpublic personal information by covered financial institutions. State privacy laws add another layer, with varying requirements. The overall theme is that more data creates more data governance responsibility for lenders.

Model risk

In April 2026, the OCC, Federal Reserve, and FDIC issued revised guidance, OCC Bulletin 2026-13, superseding the long-standing SR 11-7 framework. It keeps the core expectations, independent validation, ongoing monitoring, documentation, board oversight, and signals AI-specific guidance is likely to follow.

State AI laws

A fast-moving layer sits on top of this. Several states are enacting broad AI regulations that may impact lending decisions and lenders' liability. The Colorado AI Act is a leading example. These laws are broad rather than credit-specific, but aspects of them may influence AI credit underwriting, and the landscape is changing quickly enough to warrant ongoing attention.

It’s important to keep in mind that this is an overview of the current regulatory environment affecting alternative data and AI credit underwriting, not legal advice.

Capturing the opportunity without the exposure

The risks are real, but they are manageable. Each one requires a specific responsible AI approach, and ai governance consulting services are how lenders turn alternative data from a liability into an advantage.

Use explainable models and real reason codes

Select models whose decisions can be traced and generate specific reason codes mapped to the actual factors behind each decision. If a model cannot produce an honest, factor-level explanation, it is not ready for a lending decision.

Test for fair lending continuously

Run disparate-impact testing as an ongoing practice and document a search for Less Discriminatory Alternatives (LDA). This is a pragmatic practice despite the federal pivot since it remains a live expectation under the Fair Housing Act for AI mortgage underwriting and under state law elsewhere.

Govern the data itself

Maintain an inventory of every alternative source, including its owner, purpose, provenance, consent basis, quality, coverage, retention period, and its permitted uses. Data that cannot be traced is difficult to validate. Data that cannot be justified is difficult to defend.

Map every output to adverse-action requirements

Before a model goes live, confirm that each possible decision can produce the specific, accurate notice that the law requires. Explainability is only useful if it corresponds to the relevant compliance elements.

Stand up model risk management

Apply independent validation, ongoing monitoring, and documentation in line with the 2026 interagency guidance in OCC Bulletin 2026-13. A model that isn’t revalidated is at risk of compliance complications.

Keep humans in the loop for consequential decisions

Automate the routine, high-confidence cases where the policy and evidence are clear. Divert any unusual, low-confidence, or high-impact decisions to human experts with the knowledge and expertise for a meaningful review.

Do real vendor due diligence

Examine the data and model providers you depend on, their sources, consent practices, and validation, because their weaknesses become yours. Responsible AI credit underwriting is ultimately a supply-chain problem as much as a modeling one.

What this means for lenders now

Alternative data and AI credit underwriting will continue to grow because the commercial and inclusion opportunity is too significant to ignore.

Thin-file borrowers, immigrants, young adults, self-employed workers and small-business owners represent large populations whose risk cannot always be understood through conventional scores alone. Better data and better modeling can help lenders serve them
more confidently.

The 2026 regulatory changes do not remove the need for governance. They simply redistribute the exposure across ECOA intent-based claims, adverse-action requirements, the Fair Housing Act, FCRA, privacy rules, state laws, and internal model controls.

The lenders have two different paths in front of them. The ones who treat governance as an afterthought will keep meeting the same bias, explainability, and compliance problems downstream, where they are most expensive to fix. The ones who build explainability, fair-lending testing, and data governance into the AI credit systems from day one will be the ones who can actually scale AI lending and AI credit decisioning and are able to defend it.

Conclusion

Alternative data and AI credit underwriting can widen access to credit while improving lenders’ understanding of risk.

Neither outcome is automatic.

The value depends on disciplined data selection, explainable decisions, fair-lending testing and governance that reflects the changing US regulatory environment. The objective should not be to collect the most information or deploy the most complex model. It should be to make a more informed credit decision that the institution can support, explain and monitor.

At 10Pearls, our fintech software development services teams help financial institutions put that discipline into practice. Our work spans data engineering, AI and machine learning, model governance, and ai integration services for explainable decision systems designed for regulated environments. 

For lenders evaluating where alternative data belongs in their underwriting process, the
right starting point is not the model alone. It is the operating, data and governance foundation around it.

FAQs

What is alternative data in AI credit underwriting?

It is the use of AI models to assess credit risk using both traditional credit data and alternative data, information beyond the credit bureau file, such as cash flow, rent, utility, and telecom payments.

Yes, but its use is regulated. Lenders must comply with ECOA, the FCRA, and other fair-lending requirements. Decisions must be non-discriminatory, supported by reliable data and accompanied by specific, accurate reasons when adverse action is taken.

The main risks include bias and proxy discrimination, limited explainability, poor or incomplete data, privacy and consent concerns, model drift, third-party dependency, and the broader fair-lending exposure created by these issues.

It can do either. Well-governed, it can widen fair access; poorly governed, alternative data can encode proxies for protected characteristics and amplify bias. Governance, not the data alone, decides which.

ECOA and Regulation B, the FCRA, the Fair Housing Act for mortgages, model-risk guidance (OCC Bulletin 2026-13), privacy laws like GLBA, and a growing layer of state AI laws.

The federal ECOA enforcement was readjusted in April 2026 to drop disparate-impact liability via a new rule. But the Fair Housing Act and state laws still recognize it, so fair-lending obligations are still very much alive.

People with no credit record at all. As per the CFPB, about 2.7% of US adults are credit invisible, with a further 9.8% unscorable, together roughly 33 million people.  

Related blogs

AI in Banking Use Cases: What Works and What Stalls

Fintech

AI in Banking Use Cases: What Works and What Stalls

A guide to AI in banking use cases, from fraud detection to document processing, the risks that stall them, and...

What is Alternative Data in AI Credit Underwriting

Fintech

What is Alternative Data in AI Credit Underwriting

The CFPB dropped disparate impact from ECOA in April 2026. Here is what that changed for AI credit underwriting, and...

Banking as a Service (BaaS): How It Works

Fintech

Banking as a Service (BaaS): How It Works

Learn what Banking as a Service (BaaS) is, how it powers embedded finance, and how non-banks integrate accounts, cards, payments,...

Synthetic Identity Fraud Detection and Prevention

Fintech

Synthetic Identity Fraud Detection and Prevention

Synthetic identity fraud is the fastest growing financial crime in the US. Understanding why that is and what its life...

How AI creates value with open banking data

Fintech

How AI creates value with open banking data

Every fintech company with an open banking license in Saudi Arabia must build the basic infrastructure to receive open banking...

Key strategies for navigating 1033 compliance in finance

Fintech

Key strategies for navigating 1033 compliance in finance

In its final rule, implementing section 1033 of the Dodd-Frank Act, the Consumer Financial Protection Bureau (CFPB) defined requirements that...

Explore common misconceptions of agile fatigue

Fintech

Explore common misconceptions of agile fatigue

Within the past few years, there has been relative fatigue in many organizations in adopting and implementing Agile practices, processes,...

Comparing the top 8 fintech app development companies to help you access transformative digital products faster and more cost-effectively

Fintech

Comparing the top 8 fintech app development companies to help you access transformative digital products faster and more cost-effectively

Fintech, or Financial Technology, is transforming financial services. The fintech industry has seen explosive growth over the past decade, and...

Privacy Overview
10Pearls Logo

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly necessary cookies

Strictly necessary cookies should be enabled at all times so that we can save your preferences for cookie settings.

Third-party cookies

This website uses third party tools such as Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.