Alternative Data in AI Credit Underwriting: Risks & US Regulations
- 10Pearls Editorial Team
- 16 min read
Summary
Alternative data can help lenders work with millions of underserved thin-file and credit-invisible individuals, especially when combined with AI underwriting. But the new opportunities come with new risks and regulatory exposure, which we discuss in this blog.
About 9.8% of the US adult population was credit “unscored” with insufficient or stale data and 2.7% were credit invisible (no credit record to generate a score from), as per the latest Consumer Financial Protection Bureau (CFPB) report. Lenders have started using alternative financial data to score and serve this massive market segment, often in conjunction with AI credit underwriting, because traditional lending models rely on conventional credit scores. While it’s a boon for millions of underserved US adults that might otherwise not get access to credible loan products, using alternative data in AI underwriting may introduce a new range of regulatory challenges. This includes new bias dimensions, privacy issues, and fair lending concerns.
This blog aims to offer a broad overview (not legal advice) of the regulatory risks and opportunities tied to the use of alternative data in AI loan underwriting.
9.8%
Of US adults are credit “unscored,” with insufficient or stale data to generate a score
2.7%
Of US adults are credit invisible, with no credit record at all
What "alternative data in AI credit underwriting" actually means
The conventional credit scoring framework naturally concentrates around credit history, habits, and mix. Alternative data uses an individual’s non-credit-related financial data and some non-financial data to evaluate their creditworthiness. The financial data spans across cash flow elements like transaction history, balances, overdrafts, rent, utilities, and telco, and bill payments. It may also cover alternative lending products like Buy Now Pay Later (BNPL). Non-financial data includes behavioral data, employment history, education level, etc.
AI credit underwriting is the use of AI to assess credit risk and inform or make lending decisions, drawing on both conventional credit reports and alternative data. AI’s ability to extract relevant data and simultaneously identify patterns and anomalies from both structured and unstructured data sources makes it a strong fit for automating and accelerating the credit underwriting process. Lenders leveraging AI loan underwriting can decide whether to stop the process at recommendation or automate lending decisions as well.
For example, a lender might assess a thin-file applicant using twelve months of bank-transaction history showing steady income and on-time rent.
The subtle risk
Using alternative data for credit scoring introduces new regulatory risks, especially with non-financial data, which may lead to biased decisions. This is true even with purely human-based decision-making because some variables may correlate with protected classes, leading to discriminatory decisions that may be statistically sound by the lender’s own rubric yet still produce discriminatory outcomes that carry fair-lending and legal exposure, not just ethical concerns.
This is further compounded by using alternative data in AI underwriting, because it may identify and reinforce patterns and trends that may converge in certain borrower subsets and, without adequate controls, may make financially sound but biased recommendations for credit decision-making.
The opportunity
AI credit underwriting carries risk, but it also offers significant opportunities, including:
Financial inclusion
If the CFPB’s latest percentages of credit invisible (2.7%) and unscored US adults (9.8%) hold for the current population, there are about 33 million adults in the US without a credit score. This prevents access to a wide range of conventional credit products – from personal loans to mortgages. Using alternative credit data, ideally along with AI credit scoring, can help these individuals access a broader range of credit products.
Better risk modeling
Speed & automation
Conventional underwriting often requires employees to collect documents, verify income, review statements, compare information across systems and enter the same data more than once.
AI-automated underwriting can reduce that work. A system can classify documents, extract income and cash-flow data, compare the information with the application and return a recommendation or decision within minutes.
Straightforward approvals and declines may be processed automatically. Underwriters can then spend more time on exceptions, ambiguous cases and applications requiring judgment.
Borrowers receive decisions sooner. Lenders can reduce processing costs and increase capacity without removing the controls that make underwriting dependable.
Speed, however, should be the result of a well-designed process. It should not come from skipping verification, explanation or review.
New segments
Traditional scoring struggles with anyone who lacks a long credit history in the US, even when they are creditworthy. Immigrants arrive in the US with a blank profile regardless of their credit history in their home country; roughly 1.3 million immigrants came to the US between July 2024 and June 2025, and millions of Americans turn 18 each year, also starting with a blank “credit” slate.
Self-employed and small business owners are underserved too, mostly because of income volatility, which restricts their access to credit. Alternative data reaches these borrowers by reading what conventional scores miss – cash flow, including rent, bill payments, and business revenue.
The data: What counts as alternative data
Alternative data is not only about how much lenders can access, on their own or through alternative credit data providers. Open banking has enriched these datasets enormously, but having the right data matters far more than having more of it, since volume alone can simply introduce noise. The right sources let lenders derive thousands of behavioral signals to assess a borrower’s risk profile and creditworthiness. The categories below differ sharply in what they reveal and where they come from, and they demonstrate that even the right data can carry regulatory and ethical risks that lenders and fintechs building custom fintech solutions need to understand.
| Data type | What it signals | Typical source or provider | Coverage & data quality | Risk flag |
|---|---|---|---|---|
| Cash-flow & bank-transaction | Income stability, spending patterns, the ability to repay | Open banking aggregators (Like Plaid) | Wide and improving via open banking; high quality | Low |
| Rent payments | Consistent large recurring obligation met on time | Rent-reporting services, property managers | Inconsistent; reporting is voluntary and incomplete | Low |
| Utility & telecom | Bill-payment reliability, financial routine | Utility and telco providers, specialist bureaus | Uneven; varies by provider and region | Low to moderate |
| Employment & income verification | Current income and job stability | Payroll and verification services | Good where employer data is accessible | Low |
| Public records | Property, liens, and other formal financial events | Government and public-record aggregators | Broad but shallow; limited predictive depth | Low |
| Behavioral device data | Correlated (not causal) signals of risk | Digital-footprint and device-analytics vendors | Abundant but opaque | High: proxy-discrimination and privacy exposure |
The risks
Alternative data widens the lender’s view of an applicant, but a wider view is not automatically more accurate or fair.
The information may be incomplete, collected without meaningful understanding, or correlated with characteristics that should not influence a credit decision. Those concerns become more significant when models process thousands of variables and produce decisions faster than people can review them.
A candid and pragmatic view of AI credit underwriting must balance the opportunity with these risks.
Bias and proxy discrimination
Alternative data can act as a proxy, a stand-in for several protected characteristics in credit decisions, even when those characteristics are never used. ZIP code, device type, spending patterns, and rental history can all correlate with race, age, or nationality, so a model can produce discriminatory outcomes without any protected variable being used directly. The harm can be significant, and the intent unfortunately is irrelevant, which is precisely what makes proxy discrimination hard to catch.
Explainability and the black-box problem
Many machine learning models are black boxes and their decision-making rationale cannot be tracked or explained. In lending, that is a compliance and trust problem, not just a technical limitation. If a lender cannot explain exactly why an applicant was declined, it cannot produce the specific, accurate reason codes the law requires, which leaves it unable to defend a challenged decision.
Data quality, coverage, and accuracy
Alternative data is inherently uneven. Some sources are thin, stale, or wrong, and these coverage gaps impact the most vulnerable borrowers, which the alternative data was actually meant to help. An error in a traditional credit file can be handled with established dispute mechanisms. But an error in a novel data source may not have such a recourse, and the impacted borrower may never learn about it.
Privacy, consent, and security
A lot of alternative data is intimate and is either directly drawn from bank transactions, phone records, and online behavior or inferred from data points and patterns. Its use raises real questions about whether borrowers meaningfully consented to it because even if they consent to share data points, they may not understand how much can be inferred from it. Concentrating this data also amplifies the breach risk, turning an underwriting advantage into a security liability.
Regulatory and fair-lending exposure
Each of these issues ultimately becomes a governance concern. Lenders remain responsible for avoiding unlawful discrimination, producing valid explanations, maintaining accurate information and controlling third parties. Those obligations do not disappear because a model is technically sophisticated or supplied by a specialist vendor. The legal routes through which a claim may be brought can change. The need to understand and defend the decision remains.
Vendor and third-party dependency
Much of the alternative data market depends on outside providers. A lender may inherit a vendor’s weaknesses in consent, collection, identity matching, data quality and coverage. Changes to a provider’s methodology or access to a source can alter model behavior without an obvious change to the lender’s own system. This makes vendor management part of model governance. A contractual relationship does not transfer accountability away from the institution making the credit decision.
Model drift and overfitting
A model tuned on past behavior degrades as conditions change. Overfitting makes it look accurate in testing and unreliable in production, and drift means a model that was fair and accurately predictive at launch can deviate in production, unless it's actively monitored and "course corrected."
Regulatory exposure: The 2026 US compliance map
The US rules governing AI credit underwriting shifted in 2026, and the shift is easy to misread. The federal fair-lending lane narrowed, but the obligations that matter most for alternative data are still in force.
ECOA and Regulation B
The Equal Credit Opportunity Act (ECOA) prohibits discrimination in any credit transaction, regardless of the technology used to make the decision. A machine producing the output changes nothing about that.
Adverse action notices
When a lender denies credit or takes another adverse action, it must provide specific and accurate reasons or explain how the applicant may obtain them. Complexity is not an exemption. The reasons provided must correspond to the factors actually considered or scored by the creditor. A broad label that does not reflect the real cause of the decision is insufficient.
The April 2026 change
Disparate impact is the idea that a policy can be discriminatory if it produces unequal outcomes across protected groups, even when there was no intent to discriminate, and no protected characteristic was used directly. On April 22, 2026, the CFPB published a final rule amending Regulation B that eliminates disparate impact, the "effects test," as a theory of liability under ECOA. The rule takes effect July 21, 2026, and refocuses federal ECOA enforcement on statutory text and evidence of intentional discrimination rather than effects-based analysis. This is a significant narrowing of one federal enforcement channel.
But disparate impact exposure has not disappeared. The rule changes federal ECOA enforcement only. It does not touch the Fair Housing Act, which independently recognizes disparate impact in mortgage lending, nor state anti-discrimination laws, several of which still recognize it. For example, New York Department of Financial Services reminded lenders, the day the rule was published, that decisions producing a disparate impact may still be unlawful. Fair-lending testing remains a live expectation.
FCRA
When a provider assembles alternative data for credit decisions, that activity can bring the data within the Fair Credit Reporting Act's definition of a consumer report. This triggers certain accuracy and dispute obligations. Regulators addressed alternative data in underwriting directly in a 2019 interagency statement
Privacy
The Gramm-Leach-Bliley Act (GLBA) governs the handling and protection of nonpublic personal information by covered financial institutions. State privacy laws add another layer, with varying requirements. The overall theme is that more data creates more data governance responsibility for lenders.
Model risk
In April 2026, the OCC, Federal Reserve, and FDIC issued revised guidance, OCC Bulletin 2026-13, superseding the long-standing SR 11-7 framework. It keeps the core expectations, independent validation, ongoing monitoring, documentation, board oversight, and signals AI-specific guidance is likely to follow.
State AI laws
A fast-moving layer sits on top of this. Several states are enacting broad AI regulations that may impact lending decisions and lenders' liability. The Colorado AI Act is a leading example. These laws are broad rather than credit-specific, but aspects of them may influence AI credit underwriting, and the landscape is changing quickly enough to warrant ongoing attention.
It’s important to keep in mind that this is an overview of the current regulatory environment affecting alternative data and AI credit underwriting, not legal advice.
Capturing the opportunity without the exposure
Use explainable models and real reason codes
Select models whose decisions can be traced and generate specific reason codes mapped to the actual factors behind each decision. If a model cannot produce an honest, factor-level explanation, it is not ready for a lending decision.
Test for fair lending continuously
Run disparate-impact testing as an ongoing practice and document a search for Less Discriminatory Alternatives (LDA). This is a pragmatic practice despite the federal pivot since it remains a live expectation under the Fair Housing Act for AI mortgage underwriting and under state law elsewhere.
Govern the data itself
Maintain an inventory of every alternative source, including its owner, purpose, provenance, consent basis, quality, coverage, retention period, and its permitted uses. Data that cannot be traced is difficult to validate. Data that cannot be justified is difficult to defend.
Map every output to adverse-action requirements
Before a model goes live, confirm that each possible decision can produce the specific, accurate notice that the law requires. Explainability is only useful if it corresponds to the relevant compliance elements.
Stand up model risk management
Apply independent validation, ongoing monitoring, and documentation in line with the 2026 interagency guidance in OCC Bulletin 2026-13. A model that isn’t revalidated is at risk of compliance complications.
Keep humans in the loop for consequential decisions
Automate the routine, high-confidence cases where the policy and evidence are clear. Divert any unusual, low-confidence, or high-impact decisions to human experts with the knowledge and expertise for a meaningful review.
Do real vendor due diligence
Examine the data and model providers you depend on, their sources, consent practices, and validation, because their weaknesses become yours. Responsible AI credit underwriting is ultimately a supply-chain problem as much as a modeling one.
What this means for lenders now
Alternative data and AI credit underwriting will continue to grow because the commercial and inclusion opportunity is too significant to ignore.
Thin-file borrowers, immigrants, young adults, self-employed workers and small-business owners represent large populations whose risk cannot always be understood through conventional scores alone. Better data and better modeling can help lenders serve them
more confidently.
The 2026 regulatory changes do not remove the need for governance. They simply redistribute the exposure across ECOA intent-based claims, adverse-action requirements, the Fair Housing Act, FCRA, privacy rules, state laws, and internal model controls.
The lenders have two different paths in front of them. The ones who treat governance as an afterthought will keep meeting the same bias, explainability, and compliance problems downstream, where they are most expensive to fix. The ones who build explainability, fair-lending testing, and data governance into the AI credit systems from day one will be the ones who can actually scale AI lending and AI credit decisioning and are able to defend it.
Conclusion
Alternative data and AI credit underwriting can widen access to credit while improving lenders’ understanding of risk.
Neither outcome is automatic.
The value depends on disciplined data selection, explainable decisions, fair-lending testing and governance that reflects the changing US regulatory environment. The objective should not be to collect the most information or deploy the most complex model. It should be to make a more informed credit decision that the institution can support, explain and monitor.
At 10Pearls, our fintech software development services teams help financial institutions put that discipline into practice. Our work spans data engineering, AI and machine learning, model governance, and ai integration services for explainable decision systems designed for regulated environments.
For lenders evaluating where alternative data belongs in their underwriting process, the
right starting point is not the model alone. It is the operating, data and governance foundation around it.
FAQs
What is alternative data in AI credit underwriting?
It is the use of AI models to assess credit risk using both traditional credit data and alternative data, information beyond the credit bureau file, such as cash flow, rent, utility, and telecom payments.
Is using alternative data for credit decisions legal in the US?
Yes, but its use is regulated. Lenders must comply with ECOA, the FCRA, and other fair-lending requirements. Decisions must be non-discriminatory, supported by reliable data and accompanied by specific, accurate reasons when adverse action is taken.
What are the main risks of AI credit underwriting?
The main risks include bias and proxy discrimination, limited explainability, poor or incomplete data, privacy and consent concerns, model drift, third-party dependency, and the broader fair-lending exposure created by these issues.
Does alternative data reduce or increase bias in lending?
It can do either. Well-governed, it can widen fair access; poorly governed, alternative data can encode proxies for protected characteristics and amplify bias. Governance, not the data alone, decides which.
What regulations apply to AI credit underwriting in 2026?
ECOA and Regulation B, the FCRA, the Fair Housing Act for mortgages, model-risk guidance (OCC Bulletin 2026-13), privacy laws like GLBA, and a growing layer of state AI laws.
Did the CFPB weaken fair-lending rules for AI underwriting in 2026?
The federal ECOA enforcement was readjusted in April 2026 to drop disparate-impact liability via a new rule. But the Fair Housing Act and state laws still recognize it, so fair-lending obligations are still very much alive.
What is the credit-invisible population?
People with no credit record at all. As per the CFPB, about 2.7% of US adults are credit invisible, with a further 9.8% unscorable, together roughly 33 million people.
Related blogs
Fintech
AI in Banking Use Cases: What Works and What Stalls
A guide to AI in banking use cases, from fraud detection to document processing, the risks that stall them, and...
Fintech
What is Alternative Data in AI Credit Underwriting
The CFPB dropped disparate impact from ECOA in April 2026. Here is what that changed for AI credit underwriting, and...
Fintech
Banking as a Service (BaaS): How It Works
Learn what Banking as a Service (BaaS) is, how it powers embedded finance, and how non-banks integrate accounts, cards, payments,...

Fintech
Synthetic Identity Fraud Detection and Prevention
Synthetic identity fraud is the fastest growing financial crime in the US. Understanding why that is and what its life...

Fintech
How AI creates value with open banking data
Every fintech company with an open banking license in Saudi Arabia must build the basic infrastructure to receive open banking...
Fintech
Key strategies for navigating 1033 compliance in finance
In its final rule, implementing section 1033 of the Dodd-Frank Act, the Consumer Financial Protection Bureau (CFPB) defined requirements that...
Fintech
Explore common misconceptions of agile fatigue
Within the past few years, there has been relative fatigue in many organizations in adopting and implementing Agile practices, processes,...
