MARKETS, CREDIT & POLICYAbout & methodology
c.The Credit CurrentDAILY INTELLIGENCEWhat matters in Credit
Deep-dive library
Supervisory Cases

Bank of America’s HMDA case: when missing data conceal a broken process

The terminated 2023 CFPB order shows why a valid data code can still describe an event that never happened, and how source-level controls differ from file validation.

5 min read · estimatedAI-generated analysis · Methodology
Current version · 1 version · Publication details

Initial full research article; sources and status reviewed September 27, 2026.

My private notes

Only in this browser; never published or sent to the site. This note belongs to the selected research version. Use Backup & restore on the Saved tab to transfer notes. Anyone using this browser profile can read them.

0 / 10,000 characters

No note saved yet.

Key takeaways

From this version
Main finding
The terminated 2023 CFPB order shows why a valid data code can still describe an event that never happened, and how source-level controls differ from file validation.
Practical implication
Reviewers should distinguish observed information, self-reported information and required coding conventions according to the applicable instructions.
Key limitation
That cost is justified where a field’s truth depends on a human interaction the database cannot reconstruct.
0% through article

Tap a dotted-underlined term for a definition. Use Aa in the navigation for reading preferences.

In this article

Status: terminated order, continuing data lesson

On November 28, 2023, the CFPB issued a consent order against Bank of America, N.A. concerning mortgage demographic information reported under the Home Mortgage Disclosure Act. It imposed a $12 million penalty. The CFPB’s public case page reports that the order was terminated on June 5, 2025 after the bank fulfilled the order’s obligations. [1]

The termination document identifies the penalty, compliance plan, annual report and improvements to HMDA management. [2] This article treats the matter as a historical, terminated supervisory case. It does not describe the bank as presently subject to that order or infer a confidential supervisory rating from either the original action or its termination.

A syntactically valid answer can be false

The order describes loan officers recording that applicants did not wish to provide demographic information when the required inquiry had not been properly made. It also describes the discontinuation of monitoring and later discovery of highly unusual information-not-provided patterns. The bank consented without admitting or denying the findings except as stated for jurisdiction. [3]

The analytical distinction is between an allowed code and a truthful representation of the event. A file can pass format edits while recording an applicant refusal that never occurred. Downstream software cannot reliably recover that distinction from the code alone. The strongest control must therefore sit near the original interaction and preserve evidence of what was asked and answered.

Regulation C’s Appendix B gives instructions for collecting ethnicity, race and sex information, including differences across application methods and treatment when applicants decline to provide it. [4] The consumer’s ability to decline is not permission for staff to skip the inquiry. Nor should staff pressure a consumer to answer simply to improve a missing-data metric.

The unit of monitoring changes what becomes visible

An overall missing-information percentage averages across channels, offices, loan officers and application types. A small problematic group can disappear inside an acceptable enterprise average. Conversely, a legitimate channel difference can look suspicious if compared against an inappropriate benchmark. Monitoring should therefore compare relevant peers and examine changes over time before drawing conclusions.

The historical order gives concrete examples of concentrated information-not-provided patterns and the consequences of discontinuing a monitoring report. [3] The broader lesson is not that one fixed percentage proves misconduct. It is that unusual distributions can identify where to test the actual process. Statistical outliers are investigative leads; recordings, forms and system histories provide the more direct evidence.

Recommended segmentation includes application channel, employee tenure, product, office and the method by which information entered the system. Automated feeds should be separated from manually entered records. A sudden improvement in completion may reflect a new process, inappropriate default values or pressure on staff; each possibility requires different follow-up.

A hypothetical quality-control exercise

Assume two teams each process 1,000 applications. Team A records information-not-provided for 5%; Team B records it for 45%. This difference alone does not establish a violation. First compare application methods and applicant choices, then draw a risk-based sample of source interactions and a random sample from both teams.

Suppose source review shows that some Team B staff never asked the demographic questions while selecting the refusal code. The remediation should address scripts, training, user-interface defaults, supervision and affected records. Simply requiring Team B to reduce its percentage can create a new incentive to fabricate answers. Quality is truthful collection and reporting, not maximum completion at any cost.

A useful control also samples apparently complete records. Otherwise, monitoring rewards false precision: fabricated demographic entries can look better than honestly recorded refusals. Reviewers should distinguish observed information, self-reported information and required coding conventions according to the applicable instructions. Preserve the original record and authorized corrections rather than erasing the audit trail.

Why this matters beyond HMDA

Mortgage demographic data support public transparency and analysis of lending patterns. [1][4] If missingness is related to employee behavior or channel selection, comparisons can be distorted. A model trained on such data may learn artifacts of collection rather than meaningful borrower or market differences.

Analysis: the same control problem appears in adverse-action reasons, complaint dispositions and fraud labels. A permitted reason code is only useful if it accurately reflects the decision. Before automating analysis, establish how the label was generated, who could override it and what incentives affected entry. An AI classifier that predicts unreliable labels with high accuracy can institutionalize the original weakness.

Remediation should prove persistence

A recommended review follows data from the interaction to the loan-origination system, intermediate transformations and final regulatory submission. Reconcile counts and field changes at each stage. Test that corrections propagate through all relevant reporting processes and that a valid local change does not get overwritten by a later batch feed.

Management reporting should include sampled error rates, unresolved exceptions, repeat findings and the outcomes of corrective training. Distinguish a completed training course from observed behavioral change. Independent review should revisit the same process after the immediate remediation period, when heightened attention may have faded.

Costs and evidence that would change the view

Source-level sampling is more expensive than running automated file edits. It can require secure access to recordings, specialist reviewers and careful handling of sensitive information. That cost is justified where a field’s truth depends on a human interaction the database cannot reconstruct. Automation remains valuable for population screening and reconciliation, provided it is not mistaken for proof of truth.

New authoritative findings could change the bank-specific assessment. For process quality, sustained source-to-report accuracy would be stronger evidence than a favorable aggregate missing-data percentage. The verified legal status remains termination of the 2023 order; the practical lesson is to validate the event behind the data, not just the data’s format.

Sources

  1. CFPB, Bank of America HMDA action, November 28, 2023; termination status June 5, 2025Official sourceBack to text: ↑1↑2
  2. CFPB, order terminating Bank of America consent order, filed June 5, 2025Official source · PDFBack to text: ↑
  3. CFPB, Bank of America consent order 2023-CFPB-0016, November 28, 2023Official source · PDFBack to text: ↑1↑2
  4. CFPB, Regulation C Appendix B, demographic collection instructions; reviewed September 27, 2026Official textBack to text: ↑1↑2

Flag an error or suggest a correction →Public corrections log →