Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
State-Federal Split on Fair Lending: Policy TemplateRegulatory Obligations Management
6 min readFor CISOs

State-Federal Split on Fair Lending: Policy Template

Illinois incorporated disparate impact into its state lending law the same month a New Jersey federal court blocked a bank's early exit from a redlining consent order. Meanwhile, the CFPB, HUD, and FTC moved to drop disparate impact enforcement at the federal level. If your team operates in multiple states, you're now managing two compliance regimes, not one.

Purpose of This Template

This policy template helps your institution maintain compliance with state-level disparate impact requirements and federal fair lending obligations when they diverge. Use it to document your approach to pricing models, credit scoring, automated underwriting, and fraud detection tools that could produce discriminatory effects in states like Illinois, California, New York, or New Jersey, even as federal agencies retreat from that enforcement theory.

The template covers:

  • Scope determination (which products, which states)
  • Impact assessment methodology
  • Documentation of business necessity
  • Alternative analysis requirements
  • Escalation triggers

Prerequisites

Before customizing this template, confirm:

  1. Your geographic footprint. Which states recognize disparate impact in lending? Illinois does as of January 1, 2027. California, New York, and New Jersey already do. You need a current list.

  2. Your product inventory. Which credit products operate in those states? Consumer loans, mortgages, credit cards, business lines of credit? List them all.

  3. Your decisioning stack. What tools make or influence credit decisions? Include third-party models, vendor scorecards, fraud detection systems, and any policy overlays your team applies manually.

  4. Your data access. Can you segment approval rates, pricing outcomes, and denial reasons by protected class within each state? If not, start building that capability now.

  5. Your legal resources. Disparate impact defenses hinge on business necessity and less discriminatory alternatives. You'll need access to counsel who can evaluate both.

The Policy Template

Fair Lending Compliance Policy: State Disparate Impact Requirements

1. Scope

This policy applies to all credit products offered to consumers or small businesses in [list states with disparate impact liability]. It covers pricing models, credit scoring systems, automated underwriting platforms, fraud detection tools, and any policy or practice that could produce differential outcomes by race, color, religion, sex, national origin, disability, or familial status.

2. Impact Assessment

The Compliance team will conduct a disparate impact analysis for each covered product annually and whenever a material change occurs to underwriting criteria, pricing logic, or decisioning tools.

The analysis must:

  • Segment approval rates, denial reasons, and pricing by protected class within each covered state
  • Compare outcomes to a baseline (either the general applicant population or a control group matched on credit characteristics)
  • Flag any statistically significant disparity of [X percentage points or more] for escalation

3. Business Necessity Documentation

For any flagged disparity, the product owner must document:

  • The specific business purpose the challenged practice serves (e.g., credit risk prediction, fraud prevention, operational efficiency)
  • Quantitative evidence that the practice achieves that purpose (validation studies, loss data, performance metrics)
  • Why the business purpose is legitimate and substantial, not merely convenient

This documentation must be contemporaneous. You can't retrofit a business justification after a disparity surfaces.

4. Less Discriminatory Alternative Analysis

Once business necessity is documented, the Compliance team will evaluate whether a less discriminatory alternative exists that serves the same purpose equally well.

The analysis must:

  • Identify at least three alternative approaches (different scoring thresholds, alternative data sources, manual review overlays, policy exceptions)
  • Model the impact of each alternative on both the disparity and the business outcome
  • Document why each alternative either fails to serve the business purpose or isn't feasible to implement

If a less discriminatory alternative exists and is feasible, the product owner must either adopt it or escalate to the Chief Risk Officer with a written justification for declining.

5. Escalation and Approval

Any practice that produces a statistically significant disparity and lacks either documented business necessity or a completed alternative analysis requires approval from:

  • Chief Risk Officer (for consumer products under $50 million annual origination volume)
  • Chief Risk Officer and General Counsel (for all other products)

Approval expires after 12 months and must be renewed with updated impact data.

6. Federal-State Divergence Management

Where federal agencies have removed disparate impact enforcement but state law retains it, this policy follows the stricter standard. The fact that a practice complies with federal fair lending rules doesn't exempt it from state-level impact assessment.

7. Training and Monitoring

All product managers, underwriters, and model developers must complete annual training on disparate impact liability in covered states. The Compliance team will monitor approval and pricing data quarterly and escalate emerging disparities within 30 days of detection.

How to Customize It

Adjust the statistical threshold. The template uses "statistically significant disparity" as a trigger. Define what that means for your institution: a specific percentage-point gap, a ratio (e.g., approval rates for one group at least 80% of another), or a statistical test like chi-square. Pick a standard and document it.

Tailor the product scope. If you don't offer small business credit, remove it. If you operate only in one or two states with disparate impact liability, list them explicitly rather than maintaining a dynamic list.

Set realistic escalation thresholds. The template uses $50 million in annual originations as the line between CRO-only and CRO-plus-counsel approval. Adjust that based on your institution's size and risk appetite.

Integrate with existing fair lending programs. You likely already have a fair lending policy covering ECOA and Regulation B. This template supplements it for states where disparate impact remains enforceable. Cross-reference both policies so your team knows which standard applies where.

Link to your vendor risk program. Third-party models and scorecards can create disparate impact liability even if you didn't build them. If you use vendor tools in covered states, add a contract provision requiring the vendor to provide impact data on request and to cooperate with your alternative analysis.

Validation Steps

Once you've customized the template, test it:

  1. Run a pilot analysis. Pick one product in one covered state. Pull 12 months of approval, denial, and pricing data. Segment by protected class. Can you complete the analysis with the data you have? If not, what's missing?

  2. Draft a business necessity memo. Choose a practice that's likely to show a disparity (e.g., a minimum credit score threshold). Write the business necessity justification as if you're defending it in litigation. Is the evidence persuasive? If you're not sure, your regulator won't be either.

  3. Model an alternative. For the same practice, identify one less discriminatory alternative and model its impact on both the disparity and your loss rate. Can you quantify the trade-off? If not, build that modeling capability before you need it under deadline.

  4. Test the escalation path. Walk through the approval workflow with your Chief Risk Officer and General Counsel. Do they understand what they're approving and what liability they're accepting? Clarify now, not during an exam.

  5. Train a cross-functional team. Fair lending compliance isn't just a Compliance function. Product managers need to understand impact assessment. Model developers need to document business necessity. Underwriters need to know when to escalate. Run a tabletop exercise where each group explains their role.

This policy won't eliminate your exposure in states that retain disparate impact liability, but it will demonstrate that you're managing it deliberately rather than hoping it doesn't come up. That distinction matters when a regulator or a plaintiff's attorney asks what you knew and when you knew it.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like