# Massachusetts AG Earnest Operations settlement (July 2025): Assurance of Discontinuance: In the matter of Earnest Operations LLC (Massachusetts Attorney General, announced July 10, 2025)

Source: https://www.bankingnewsai.com/ai-regulation/documents/ma-ag-earnest-settlement-2025
Last updated: Oct 5, 2026

On July 10, 2025 Massachusetts Attorney General Andrea Joy Campbell announced a $2.5 million settlement with Earnest Operations LLC, a Delaware-based student-loan lender, over its AI-driven underwriting. The settlement is an assurance of discontinuance under G.L. c. 93A, §§2 and 5, filed in Suffolk County Superior Court; the office alleged that Earnest failed to test its models for disparate impact, used a Cohort Default Rate variable that penalized Black and Hispanic applicants, automatically denied applicants without a green card, and sent inaccurate adverse-action notices in violation of ECOA and Regulation B. Earnest denies the allegations and admitted nothing. Beyond the payment, it must run a written AI governance program with an algorithmic oversight team, annual fair-lending testing of underwriting models and knockout rules, annual model inventories, four-year decision records, interpretable models with validated decline reasons, and report compliance to the Attorney General.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) |
| Type | Enforcement |
| Status | In force |
| Published | Jul 10, 2025 |
| Applies to | Binds only Earnest Operations LLC, a Delaware-based private student-loan lender, and its successors and controlled businesses; the release does not bind other private or governmental parties. Its terms are the clearest published statement of what the Massachusetts Attorney General expects of any lender, bank or fintech using AI models in underwriting |
| Official text | https://www.mass.gov/news/ag-campbell-announces-25-million-settlement-with-student-loan-lender-for-unlawful-practices-through-ai-use-other-consumer-protection-violations |

## Key points

- Payment (¶64): Earnest pays $2,500,000 to the Commonwealth within 30 days of the Effective Date, defined (¶9) as the date the AOD is filed in a Massachusetts court; the Attorney General may use the funds for consumers, the General Fund, the Local Consumer Aid Fund or consumer-protection programs (¶65).
- Allegations (¶5, ¶¶23–63): failing to guard against disparate outcomes in algorithmic and judgmental underwriting; using the Cohort Default Rate (CDR) variable, which the AOD says was a weighted input in the student loan refinance model until September 13, 2017 and produced disparate impact for Black and Hispanic applicants; an immigration-status knockout rule in use until June 30, 2023; and inaccurate adverse-action notices under ECOA and Regulation B.
- Governance (¶¶67–72): a written corporate governance system of fair lending testing, internal controls and risk assessments for AI models, reviewed at least annually; an internal algorithmic oversight team with a named chairperson; and a way for anyone at Earnest to report algorithmic-bias concerns without repercussions.
- Policies (¶¶73–75): written policies for responsible design, development and deployment of AI models, including a Model Risk Management policy with specific provisions for compliance with Regulation B; annual fair lending testing of algorithmic underwriting models with defined trigger events; an annual inventory of models covering training algorithms, training and test data, parameters, dates in use and test results; and four-year retention of decision documentation.
- Knockout rules and judgmental underwriting (¶¶76–77): annual fair lending testing, inventory and a designated steward for knockout rules; training, annual assessment and override controls for human underwriters, with four-year records.
- Adverse action (¶78): policies to ensure adverse-action models comply with 15 U.S.C. §1691(d), including methods to use interpretable models for credit underwriting, to validate the accuracy of every decline reason, and to ensure notices state the principal reasons specifically and accurately.
- Prohibitions (¶¶79–82): no AI model or process may use the school rank or Cohort Default Rate variables as inputs; the immigration-status knockout must stay discontinued and not be replicated by any model; Earnest may not ask consumers for access to a social-media account as a step in applying for a loan.
- Oversight (¶¶83–89): self-review of ECOA, Regulation B and AOD compliance within 180 days of the Effective Date (an independent third party may assist), corrective action within 90 days, a written report to the Attorney General within 60 days, then annual reports for three years, plus raw data on request; the Attorney General must give 10 days' notice and meet and confer before seeking judicial intervention (¶89).

## What changed for banks

The settlement turned the Attorney General's April 2024 AI advisory into a concrete expectation for lenders: fair-lending testing of models and of the human judgment layered on top of them, a model inventory, a named oversight function, and decline reasons that can be traced to the model's real drivers. It also shows the office is willing to treat a lender's failure to test for disparate impact, and training a model on arbitrary human selections, as an unfair or deceptive practice under c. 93A. It does not create new law and the allegations are unproven, but its governance terms are a ready-made checklist for any bank's model risk and fair-lending teams.

## Use cases it governs

- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [Fair lending & discrimination](https://www.bankingnewsai.com/ai-regulation/by-use-case#fair-lending)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)

## What does the Massachusetts AG's Earnest settlement require of an AI lender?

The Earnest Operations LLC assurance of discontinuance, announced July 10, 2025, requires a $2.5 million payment and a fair-lending-centred AI governance program. Earnest must maintain a written governance system with an internal algorithmic oversight team, run annual fair-lending tests of its algorithmic underwriting models, knockout rules and judgmental underwriting, keep an annual inventory of every underwriting model and rule, retain four years of decision documentation, use interpretable models with validated adverse-action reasons, and stop using the Cohort Default Rate and school rank variables and the immigration-status knockout. It must review its own compliance within 180 days of the effective date, fix gaps, and report to the Attorney General annually for three years. The AOD binds only Earnest and Earnest denies the allegations, but it is the most detailed public template of what the office expects from a lender using AI.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| ¶64 — Monetary payment | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Pay $2,500,000 to the Commonwealth within 30 days of the Effective Date (the date the AOD is filed in court). | Announced July 10, 2025 | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶¶67–72 — Corporate governance | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Maintain a written governance system of fair lending testing, internal controls and risk assessments for AI models, with an algorithmic oversight team and chairperson, annual review, and a no-retaliation channel for bias concerns. | From the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶¶73–74 — Written policies and model risk management | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Adopt written policies for the design, development and deployment of AI models, including a Model Risk Management policy with Regulation B compliance provisions and accountability for documenting model-development decisions. | From the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶75 — Underwriting models | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Test and retrain models for fair lending law compliance, run annual fair lending testing with trigger events, inventory models annually (algorithms, data, parameters, dates, test results), retain decision documentation four years and keep account-level data. | Annual; from the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶76 — Knockout rules | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Assess and monitor every knockout rule, test annually, inventory features, thresholds and time in use, and designate a steward responsible for testing, documentation and data. | Annual; from the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶77 — Judgmental underwriting | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Train human underwriters on fair lending law, assess decisions annually, control overrides and adjustments to scores or prices, and retain documentation for at least four years. | Annual; from the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶78 — Adverse action notices | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Use interpretable models for credit underwriting, validate the accuracy of each decline reason on every notice, and state the principal reasons specifically and accurately under 15 U.S.C. §1691(d). | From the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶¶79–82 — Discontinued variables and practices | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Do not use the school rank or Cohort Default Rate variables as inputs, keep the immigration-status knockout rule discontinued and un-replicated, and do not require access to social-media accounts to apply for a loan. | From the Effective Date | [official text](https://www.mass.gov/doc/earnest-aod/download) |
| ¶¶83–88 — Compliance review and reporting | [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | Review ECOA, Regulation B and AOD compliance within 180 days, implement corrective action within 90 days, report within 60 days, then file annual reports for three years and provide data on request. | 180-day review from the Effective Date; annual reports for three years | [official text](https://www.mass.gov/doc/earnest-aod/download) |

The AOD's allegations explain its remedies. The office alleged that Earnest trained a scorecard model on human-selected variables and weights without firm procedures for deciding whether they predicted default, that the Cohort Default Rate subscore penalized Black and Hispanic applicants more than White applicants, that a later model was designed in part to replicate those earlier decisions, and that nobody tested the models or the human underwriting layer for disparate impact. It also alleged that the compliance officer never received the written certification Earnest's own policy required before a new underwriting criterion went live. Each undertaking in Part IV answers one of those findings.

The adverse-action terms are the most transferable. The AOD alleges that Earnest's staff picked decline reasons from a drop-down menu that omitted variables the models actually used, such as Cohort Default Rate, school rank and degree type, and chose an available reason instead, and that an auto-generated reasons model sometimes produced nothing specific. The remedy is a requirement to use interpretable models, to validate each reason on every notice, and to state the principal reasons accurately, which is a direct application of ECOA and Regulation B to AI.

The AOD is not a rule and binds only Earnest, which denies the allegations. Its release does not bind other private or governmental entities. For banks it is evidence of the Attorney General's enforcement theory under c. 93A, and a benchmark for how a regulator might measure a lender's AI governance. Federally chartered institutions answer first to their federal regulators and the AOD does not address preemption.

### What this means in practice

- Map every credit model and knockout rule into a single inventory with training data, parameters, dates in use and latest fair lending test results, refreshed at least annually and after trigger events.
- Run annual disparate-impact testing on models, on their individual weighted inputs and on human overrides, and keep the reports, documentation and analyses as examinable records.
- Reconcile the reason codes in adverse-action systems against the variables the models actually use, and test that a model-generated decline always yields a specific, accurate reason.
- Review any variable that proxies for school, geography or immigration status, and any rule that denies applicants before creditworthiness is assessed, for national-origin and race risk.
- Name an accountable oversight function (a chair or committee) with a protected route for staff to raise algorithmic-bias concerns, and make sure compliance sign-off on new underwriting criteria really happens and is recorded.

## FAQ

### What did the Massachusetts AG's Earnest settlement require?

Earnest Operations LLC agreed to pay $2.5 million, build a written AI governance program with an algorithmic oversight team, test its underwriting models and knockout rules for fair lending every year, inventory its models, keep four years of decision records, use interpretable models with validated adverse-action reasons, stop using the Cohort Default Rate and school rank variables, and report to the Attorney General. It denies the allegations.

### Did Earnest admit wrongdoing in the Massachusetts settlement?

No. The assurance of discontinuance states that Earnest denies the allegations and any violation of Massachusetts or federal law, and that agreeing to the AOD is not an admission. The allegations are the Attorney General's, and the AOD says it does not approve Earnest's practices.

### Does the Earnest settlement apply to banks?

It binds only Earnest, and the Attorney General's release does not bind any other party. Banks are not parties, but its governance, testing and adverse-action terms show what the office expects of lenders using AI, and a bank's exposure under c. 93A and ECOA depends on its charter and facts.

### How does the Earnest settlement compare with SR 11-7 model risk management?

Its model inventory, independent oversight, validation of outputs and ongoing monitoring resemble familiar model risk practice, but the AOD is built around fair lending: annual disparate-impact testing of models, knockout rules and human overrides, and validation that each adverse-action reason is accurate. It is a state enforcement outcome, not supervisory guidance.

## Related documents

- [Massachusetts AG AI Advisory (April 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ma-ag-ai-advisory-2024) — Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Civil Rights, and Data Privacy Laws to Artificial Intelligence (Apr 16, 2024)
- [Colorado AG proposed ADMT rules](https://www.bankingnewsai.com/ai-regulation/documents/co-ag-admt-proposed-rules-2026) — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) (Aug 11, 2026)
- [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Jul 24, 2026)
- [RBI draft Guidance on Regulatory Principles for Model Risk Management](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risk-management-guidance-2026) — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) (Jun 24, 2026)
- [Draft Commission guidelines on high-risk classification](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-draft-guidelines-high-risk-classification-2026) — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act (May 19, 2026)
- [SB 26-189](https://www.bankingnewsai.com/ai-regulation/documents/co-sb26-189) — Automated Decision-Making Technology Act (repeal and reenactment of the Colorado AI Act) (May 14, 2026)
- [Regulation B final rule on disparate impact (April 2026)](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-regulation-b-final-rule-2026) — Equal Credit Opportunity Act (Regulation B) — final rule amending disparate impact, discouragement and special purpose credit program provisions (Apr 22, 2026)
- [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) — Revised Guidance on Model Risk Management (Apr 17, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.mass.gov/news/ag-campbell-announces-25-million-settlement-with-student-loan-lender-for-unlawful-practices-through-ai-use-other-consumer-protection-violations) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/ma-ag-earnest-settlement-2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
