Skip to content
RiskTemplates · The Daily Brief Friday, October 2, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Operational Risk

40 States Just Made Credit Acceptance Corporation Pay $700 Million for Loans It Knew Borrowers Couldn't Repay. Here's What Consumer Lenders Need to Lock In Now.

On September 17, 2026, a 40-state coalition secured a $700 million settlement against Credit Acceptance Corporation for predatory subprime auto loans—including $634M in debt relief for 55,000 consumers. The smoking gun was CAC's own internal predictive model showing expected defaults. Here's what every consumer lender needs to do before November.

Table of Contents

TL;DR

  • On September 17, 2026, NY Attorney General Letitia James and 39 other states secured a $700+ million settlement against Credit Acceptance Corporation (CAC) for predatory subprime auto lending
  • The smoking gun: CAC’s own predictive model showed many borrowers would default within 12–18 months — but the loans were originated anyway at average APRs above 38%, some over 100%
  • 55,000+ consumers will receive $634M in debt relief, $60M in cash restitution, and $15.5M in penalties
  • Settlement effective November 2, 2026, with injunctive requirements targeting ability-to-repay disclosure, add-on product controls, and securitization practices
  • The enforcement mechanism: 40 state AGs operating under state UDAP statutes, entirely independent of a federal CFPB action

A consumer lender’s biggest regulatory liability rarely comes from a surprise. It comes from internal data that its compliance and legal teams never fully reckoned with.

That’s the story inside the Credit Acceptance Corporation settlement. CAC didn’t just originate loans to borrowers who defaulted. According to the 40-state coalition’s complaint, CAC operated a predictive model that, down to the penny, projected how much it would extract from borrowers across the full loan lifecycle: payments, fees, repossession proceeds, auction recovery, debt collection, and wage garnishment. The model showed, for large segments of the portfolio, that borrowers were structurally unable to repay under any realistic income scenario.

The loans were originated anyway. More than 55,000 consumers. Average APRs above 38%. Some exceeding 100%.

On September 17, 2026, New York Attorney General Letitia James announced the resulting settlement: more than $700 million from CAC, the largest multistate consumer lending enforcement action in recent memory. The settlement becomes effective November 2, 2026.

What the Coalition Alleged

The 40-state complaint, joined by the District of Columbia, centered on four categories of conduct:

1. Lending Into Known Default

The core allegation is that CAC structured its business model around borrower default rather than repayment. The complaint describes a predictive model that CAC used to forecast a “collection forecast” — the total amount it expected to collect across all recovery channels when a loan was originated. This model accounted for the likelihood and timing of default as an expected outcome, not an anomaly to be avoided.

The coalition alleged that CAC knowingly placed borrowers into loans where the collection forecast included repossession and post-default collection as primary revenue sources, not edge cases. Originating loans you know — through your own analytics — a substantial portion of borrowers will be unable to repay is the core of a modern ability-to-repay claim under state UDAP statutes.

2. Add-On Product “Packing”

The complaint alleged that CAC structured dealer incentives to encourage the bundling of vehicle service contracts, guaranteed asset protection (GAP) insurance, and similar products into financing packages without adequate disclosure or consent. Consumers were enrolled without being told the cost, the nature of the product, or how it affected their loan terms.

This practice — sometimes called “packing” — is a well-established UDAP violation. The settlement permanently prohibits CAC from including add-on products in loan contracts without affirmative, informed consumer consent.

3. Securitization Misrepresentation

CAC securitized large volumes of the loans at issue. The coalition alleged that, when packaging these loans into asset-backed securities, CAC represented the underlying loan quality in ways inconsistent with what its own models projected. This layer of the claim extends the liability beyond consumer protection law into potential securities fraud territory.

4. Post-Default Collection Practices

For borrowers who defaulted, the complaint alleged a suite of aggressive collection practices: immediate repossession with little warning, high auction markups charged back to borrowers, sustained wage garnishment pursuit, and sale of deficiency balances to third-party debt collectors.

The Settlement Terms

The $710 million settlement (different sources cite $694M to $710M depending on which components are included) divides across three categories:

ComponentAmountStructure
Debt relief$634M+Waiver of outstanding balances for qualifying accounts
Cash restitution$60MDirect payments to consumers who lost vehicles to repossession
Civil penalties$15.5MPaid to the states

The injunctive requirements are the more operationally significant piece. Under the settlement, CAC must:

  • Disclose default risk in advance. For new loans in loan risk categories with historically high default rates, CAC must inform borrowers in writing before consummation.
  • Waive 95% of amounts owed on early defaults. If a borrower defaults within 12 months of origination (or, for certain loan types, 18 months), CAC must waive 95% of the outstanding balance and forego further collection activity.
  • Prohibit add-on product packing. Vehicle service contracts, GAP insurance, and similar products may not be included in loan contracts unless the consumer provides affirmative written consent after clear disclosure.
  • Reform dealer incentive structures. The settlement restricts dealer compensation structures that create incentives to enroll borrowers in add-on products they don’t request.

CAC filed an 8-K with the SEC on September 17, 2026 disclosing the settlement. The order’s effective date is November 2, 2026.

Why This Settlement Matters Beyond Auto Lending

The CAC case isn’t just about subprime auto loans. The legal theories it rests on travel across consumer lending categories. Any lender — fintech originator, bank, BNPL provider, personal loan company — should map its practices against four specific risk factors this settlement highlights.

The Internal Model Problem

CAC’s worst moment in the enforcement record is not what it did to borrowers. It’s what it wrote down internally about what it expected to happen to them.

Predictive models are valuable compliance tools when they’re used to set appropriate credit standards and product terms. They become liabilities when they document expected consumer harm that the institution then ignores.

This creates an uncomfortable question for consumer lenders with sophisticated analytics capabilities: what does your model say about expected default rates by segment, and what do your underwriting standards require you to do with that information? If you have internal data showing elevated default risk in a product segment, that data is discoverable in enforcement proceedings.

The answer is not to stop building predictive models. The answer is to have a written policy governing how default risk analytics feed into credit decisions, product terms, and forbearance design — and to follow it.

The State AG Enforcement Architecture

The CAC settlement was brought by 40 state AGs operating under state UDAP statutes, entirely independent of any CFPB action. As the blog has covered, the CFPB’s enforcement posture under the current administration has dramatically changed — but that pullback has not reduced consumer lending enforcement exposure. It has shifted the enforcement venue to the states.

State AG coordination is sophisticated. The current multistate enforcement infrastructure, developed over decades of tobacco, pharma, and financial services cases, allows state AGs to share investigative resources, coordinate discovery, and pool settlement negotiations. The result is enforcement pressure that can match or exceed any single federal agency.

The practical implication: compliance programs that were calibrated to CFPB risk need to be recalibrated for a multistate coalition risk model. CFPB enforcement requires the Bureau to initiate a case. A multistate action requires only one motivated state AG to begin an investigation, share it with the coalition, and trigger coordinated action.

The Add-On Product Controls Gap

The FTC’s enforcement posture on unauthorized fees and add-on products has been consistent for years: the question is not whether the product was technically disclosed, but whether the enrollment was affirmative and informed. A disclosure buried in a loan agreement paragraph, or a product included in the financing without a separate opt-in, doesn’t satisfy the UDAP standard.

Consumer lenders with add-on product programs — including warranty products, debt cancellation agreements, credit insurance, and payment protection plans — should audit three things:

  1. Enrollment trigger: Is add-on product enrollment triggered by affirmative consumer action, or is it a default that consumers must opt out of?
  2. Disclosure clarity: Does the pre-enrollment disclosure clearly state the product name, cost, benefit description, and how to decline?
  3. Dealer or agent incentive structure: Do incentive payments to dealers, brokers, or agents vary based on add-on product enrollment rates in ways that create pressure to enroll borrowers regardless of their interest?

The Securitization Disclosure Layer

Consumer lenders who securitize originated loans face a compound exposure: consumer protection liability from origination practices and securities disclosure liability if loan quality is misrepresented in securitization disclosures. The CAC complaint alleges both simultaneously.

For lenders operating ABS programs, the question is whether internal credit risk data — including model-projected default rates by loan cohort — is consistent with what is disclosed to ABS investors in offering documents and ongoing remittance reports. A UDAP violation at origination doesn’t disappear when the loan is sold into an ABS trust. It travels with the obligation.

The RCSA for Consumer Lending Programs

For compliance teams, the CAC settlement is a UDAP risk self-assessment prompt. The four violations at issue — ability-to-repay, add-on product enrollment, securitization disclosure, and post-default collection — each map to controls that should appear in a Risk and Control Self-Assessment (RCSA) for any consumer lending program.

An RCSA that doesn’t specifically evaluate whether loan origination models inform ability-to-repay decisions, whether add-on product enrollment requires affirmative consent, and whether securitization disclosures reflect actual credit quality is an RCSA with material gaps in the consumer lending risk domain.

So What?

The CAC settlement is not a cautionary tale about a predatory fringe operator. CAC is a publicly traded company with a compliance program, legal counsel, and investor disclosures. The settlement shows that sophistication doesn’t insulate a lender from UDAP liability — in this case, it made the liability worse, because CAC’s own analytics became evidence of intentional harm.

Three things consumer lenders should do before November 2, 2026 (when the CAC settlement takes effect, and when multistate AG enforcement of similar practices will intensify):

  1. Run an ability-to-repay audit against your highest-default-rate products. If your models show materially elevated default probabilities in a segment, what do your underwriting policies require in response? Document the answer.

  2. Audit your add-on product enrollment process. Default enrollment — even with a disclosed opt-out — is higher risk than affirmative opt-in. State AG investigations often start with enrollment rate anomalies.

  3. Check whether your securitization disclosures reflect your internal view of loan quality. If you have cohort-level default projections that are materially higher than what you’re representing to ABS investors, you have both a consumer protection issue and a potential securities disclosure issue.

The 40-state coalition doesn’t need CFPB authorization to open the next case. It needs the same kind of documentation CAC spent years generating.


Sources: NY AG Press Release (Sep 17, 2026) · Claims Journal Settlement Report · CAC 8-K SEC Filing · Hawaii News Now State Coverage

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did Credit Acceptance Corporation actually do wrong?
According to the 40-state coalition's complaint, CAC originated subprime auto loans with average APRs above 38%—some exceeding 100%—while its own internal predictive model showed that many borrowers were highly likely to default within 12 to 18 months. CAC also pushed consumers into unwanted add-on products (vehicle service contracts, guaranteed asset protection) through dealer incentives, and then securitized the loans while allegedly misrepresenting loan quality to investors.
What does the CAC settlement require in terms of compliance program changes?
The $710 million settlement (effective November 2, 2026) requires CAC to disclose to borrowers in advance when their loan carries a historically high risk of default, waive 95% of sums owed if those borrowers default within 12 or 18 months, refrain from suing to collect that debt, ban 'packing' of vehicle service contracts and GAP insurance without affirmative consumer consent, and implement business practice reforms verified through compliance monitoring.
Did the state AGs use federal law or state UDAP statutes?
Both. The coalition brought claims under individual state consumer protection laws (most state UDAP statutes closely parallel FTC Act Section 5) as well as relevant state lending laws. The multistate structure allows each state AG to enforce under its own statute, which is why a federal CFPB pullback doesn't eliminate exposure—the states operate independently.
What's the risk to lenders whose internal analytics show elevated default risk?
This is the core lesson from CAC: internal predictive models that forecast default probability are now potential evidence in enforcement actions. If your analytics team can quantify expected default rates by loan segment, and you originate those loans anyway without adequate ability-to-repay analysis, that internal data can be used to show you knew about the risk. It transforms what might otherwise look like a negligence case into an intentional one.
Does this settlement apply beyond auto lending?
The CAC case is specific to auto loans, but the legal theories—UDAP violations for originating loans without adequate ability-to-repay review, unfair practices in add-on product enrollment, and securitization misrepresentation—apply broadly across consumer lending. Mortgage servicers, personal loan providers, BNPL lenders, and any fintech originating consumer credit products face the same frameworks.
What is the practical difference between a UDAP claim and a federal CFPB unfair practice claim?
The substantive standards are virtually identical: both prohibit unfair, deceptive, or abusive acts or practices that cause substantial consumer harm. The practical difference is enforcement authority. CFPB enforcement under UDAAP requires the CFPB to initiate an action. State UDAP enforcement requires only the relevant state AG—and as the CAC coalition shows, states can coordinate to create settlement pressure that rivals any federal action. With the current CFPB enforcement posture, state UDAP is the operative risk.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.

◆ Keep reading

Related posts.

Operational Risk

The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.

The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.

Oct 1, 2026

Operational Risk

FTC Just Fined a Payment Processor $12 Million for Sham Merchants. Here's What 'Knowingly Facilitating Fraud' Actually Looks Like.

On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services for processing payments for 1,000+ sham merchant accounts running chargebacks at 10x card network thresholds. This is what payment processor liability looks like—and why it matters for every fintech that routes transactions.

Sep 28, 2026

Operational Risk

FTC Made Corpay's CEO Pay Personally. The $100 Million Unauthorized Fee Case Rewrites What 'Authorization' Means for Billing Controls.

On September 17, 2026, the FTC announced a $100 million settlement with Corpay (formerly FleetCor) and personally named CEO Ronald Clarke for charging unauthorized fees on commercial fuel cards. The injunction's 'clear and unavoidable' disclosure standard goes further than any prior FTC action. Here's what every compliance team with a recurring billing product needs to audit.

Sep 26, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.