Category Archives: Q&A

Mortgage AI/ML Compliance Q&A: Governance, Fair Lending, and Exam Readiness

AI/ML compliance for mortgage lenders is no longer a future-state planning exercise. Fannie Mae’s LL-2026-04 took effect August 6, 2026. Freddie Mac’s Section 1302.8 took effect March 3, 2026. The Colorado AI Act took effect February 1, 2026. The California DFPI is actively examining AI/ML programs. State AGs are bringing actions under existing UDAP authority.

This Q&A focuses on the practical questions your compliance team will face as the AI/ML governance framework comes into operational reality in 2026 — what to build, what to document, what examiners are looking at, and how to keep the program running as models evolve and rules change.

Q1: We Just Discovered LL-2026-04. What Do We Do First?

The first step is the AI/ML use case inventory. You cannot scope a governance program without knowing which systems are in scope. The inventory should identify every AI/ML system used in the mortgage lifecycle, the business function each supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

A common mistake is to start with the governance policy. A policy written before the inventory is complete is a policy that does not match the actual system footprint. The inventory drives the policy, not the other way around.

Aim to have a complete inventory within 30 days. Most lenders underestimate how many AI/ML systems they actually run — the inventory typically surfaces 30-50% more systems than the compliance team expected.

Q2: How Do We Decide Which AI/ML Systems Are “High-Impact”?

The GSE frameworks and the Colorado AI Act both use a risk-tiering approach. The relevant question for a high-impact designation is whether the system can materially affect a borrower’s loan terms, access to credit, or experience in the loan process.

High-impact systems for mortgage lenders typically include:

  • Automated underwriting systems (AUS)
  • AI-driven appraisal valuation models (AVMs with machine learning components)
  • AI-driven fraud detection models that affect application decisions
  • Pricing optimization models that influence loan pricing
  • Lead scoring models that affect credit decisions
  • Income and asset verification tools that use AI
  • Customer service chatbots that handle credit-related inquiries

Lower-risk systems include internal marketing analytics, business intelligence dashboards, and back-office automation that does not affect borrower outcomes. Document the risk tiering methodology so examiners can review the logic.

Q3: What Counts as an “AI/ML System” for Compliance Purposes?

The LL-2026-04 definition tracks the broad industry usage. An AI/ML system is any system that uses statistical learning, neural networks, natural language processing, or other machine learning techniques to produce an output from training data. Generative AI (text or image generation), predictive models, classification models, and clustering models are all in scope.

Out of scope: rule-based decision engines that do not learn from data, simple threshold-based scoring (e.g., credit score lookups without model adjustment), and traditional statistical models without a learning component. The key question is whether the system’s parameters are learned from data rather than set by human designers.

When in doubt, include the system in the inventory and document the determination. The cost of including a borderline system is much lower than the cost of an examiner discovering a missed system.

Q4: How Do We Build a Fair Lending Testing Program for AI/ML?

A defensible fair lending testing program has four components.

1. Outcomes-based testing. Compare actual loan decisions, pricing, or other outcomes across demographic segments. The relevant segments under federal law are race, national origin, sex, religion, familial status, age, and disability. Under state law, additional protected categories may apply.

2. Input-based testing. Audit model features for proxy variables that correlate with protected classes even when the protected class is not a direct input. ZIP code is a classic proxy for race. Language preference can be a proxy for national origin. Proxies are not always a violation, but they require documentation of why the proxy is appropriate and how its use is monitored.

3. Segment-level performance review. Model accuracy, false positive rates, and false negative rates should be reviewed at the segment level. A model that performs well on average but has materially different error rates across protected segments is a model that needs remediation before deployment.

4. Counterfactual testing. For loan decisions, change the protected class of an applicant and observe whether the decision changes. If the decision changes when only the protected class changes, the model is using protected class or proxy information inappropriately.

The testing should be performed before deployment, after material model changes, and at a defined cadence — at least annually for high-impact systems.

Q5: What Documentation Do Examiners Look For First?

Examiners start with the inventory and the governance policy. From there, the document request typically expands to model documentation, validation reports, fair lending testing, vendor contracts, and the most recent attestation.

The most common finding in early AI/ML examinations is a gap between what the inventory claims and what the documentation actually supports. Lenders may claim to have a fair lending testing program but produce a single slide with results, not a documented testing protocol with methodology, results, and remediation actions.

The exam-ready binder for AI/ML governance should include:

  • AI/ML use case inventory with risk tiering
  • Governance policy approved at senior committee level
  • Model documentation for each high-impact system (data sources, training methodology, performance metrics, validation results)
  • Fair lending testing reports for each high-impact system
  • Vendor contracts with AI/ML-related terms
  • Annual attestation
  • Incident log (any model failures, complaints, regulatory inquiries)

Q6: How Do We Handle AI Tools That Loan Officers Use Independently?

If loan officers use AI tools (ChatGPT, Claude, specialized mortgage AI assistants, etc.) in connection with loan files, the tools are in scope under LL-2026-04 and Section 1302.8. The lender is the deployer and is accountable for the tool’s compliance.

The minimum controls: an approved list of AI tools that may be used in connection with loans, prohibition on uploading borrower non-public personal information to tools that have not been approved, a confidentiality review of the tool’s data handling practices, and a documented training program for loan officers on the approved-use policy.

The most common exam finding: lenders have no visibility into which AI tools loan officers are using. Shadow AI use is a significant risk, and lenders are expected to address it proactively.

Q7: How Should We Structure the AI Governance Committee?

The committee structure varies by institution size. For mid-size and large lenders, the typical structure is:

AI Governance Committee: senior leadership (CRO, CIO, General Counsel, Head of Compliance, Head of Model Risk) meets quarterly or more frequently. Approves the governance policy, reviews high-impact model changes, signs off on attestations.

Model Risk Management function: dedicated staff (or a vendor) that runs the inventory, conducts validation, performs fair lending testing, maintains documentation.

Model Owners: business line leaders responsible for individual AI/ML systems. Own the system lifecycle, escalate issues to the committee, ensure documentation is current.

For smaller lenders without dedicated model risk staff, the model risk function may be outsourced or combined with compliance. The committee structure remains the same; the execution is shared.

Q8: How Do We Balance AI Innovation with AI Compliance?

The right framing is not “innovation vs. compliance” — it is “innovation with governance.” A model that cannot be explained to an examiner is a model that creates regulatory risk. A model that produces disparate outcomes is a model that creates litigation risk. Governance is what makes innovation sustainable.

The practical implementation: the governance framework should be designed to support business velocity, not slow it down. Pre-deployment validation, fair lending testing, and documentation should be efficient and well-scoped. The model risk function should be a partner to the business, not a bottleneck.

A common failure mode: over-engineering the governance process to the point where business teams route around it. The result is shadow AI use — business teams adopt new tools without governance review, and the compliance program loses visibility into the actual system footprint.

Q9: What Is the Most Common AI/ML Compliance Failure You See?

The most common failure is treating the AI/ML governance program as a documentation exercise rather than an operational one. Lenders produce a policy and a checklist, but they do not actually run the inventory, conduct the validation, or perform the fair lending testing. When the examiner asks for the supporting documentation, the program collapses.

The second most common failure is treating vendor-provided validation as a substitute for lender validation. The lender is accountable for the model’s performance in its own use context. The vendor’s validation report is an input, not an output.

The third most common failure is fair lending testing that is too narrow — testing only adverse action outcomes and missing proxy variable analysis, or testing only protected classes under federal law and missing the additional state-level protected categories.

Q10: Where Should AI/ML Compliance Be on the Q3 2026 Priority List?

For lenders that have not yet built a program, AI/ML governance should be at the top of the Q3 2026 priority list. The LL-2026-04 effective date has passed, and the first attestation cycle is approaching. The work cannot wait for Q4.

The Q3 priorities, in order:

This month: Complete the AI/ML use case inventory. Identify model owners and risk tiering.

Next 30 days: Draft the governance policy. Get committee approval.

Next 60 days: Begin fair lending testing for the highest-impact systems. Document the testing methodology.

By year-end: Complete the first round of validation. Stand up the annual attestation process. Build the exam-ready binder.

For lenders with a program already in place, the Q3 priority is to harden the documentation for examiner review and to verify the program covers the new state-level rules — particularly the Colorado AI Act if you originate or service in Colorado.

Need support on AI/ML governance, fair lending testing, or state-level compliance overlay? Synergy works with mortgage lenders on AI/ML program design, validation, multi-state compliance overlays, and exam readiness. Book a 30-minute AI/ML review.

Mortgage Call Report Q&A: Build a Defensible MCR Process

Q1: What Is the Long-Term Regulatory Risk of a Pattern of Inaccurate MCR Filings?

This is the question compliance officers don’t ask until they’ve already had the problem.

A single late or inaccurate MCR filing is a clerical issue. A pattern is a compliance management system failure — and that’s the framing that triggers elevated examination activity, enhanced oversight requirements, and in some states, mandatory remediation plans.

Regulators have access to longitudinal MCR data across your entire licensing history. When they see a company with:

  1. Four consecutive quarters of rounded loan count figures
  2. Consistent mismatches between RMLA origination volume and HMDA LAR submissions
  3. Servicing portfolio data that tracks below industry benchmarks for similar portfolio sizes

…that company gets placed on the active examination list. The cost of an examination — in staff time, legal fees, and regulatory relationship risk — far exceeds the cost of building a defensible filing process.

Q2: How Does Synergy’s Approach to MCR Compliance Differ From Generic Regulatory Software?

Most MCR compliance solutions treat the filing as a data entry problem. Synergy treats it as a data integrity problem — and there’s a meaningful difference.

Data entry solutions give you a form to fill out. Data integrity solutions audit your entire loan origination, servicing, and financial reporting ecosystem to ensure that the numbers flowing into the form are accurate before you ever open the submission window.

Our MCR compliance process includes:

  1. Quarterly pre-reconciliation — we identify and resolve data inconsistencies across your LOS, servicing platform, accounting system, and HMDA LAR before the NMLS window opens
  2. FV7 category mapping — we maintain current NMLS field definitions and state-specific requirements (including the Texas supplemental filing) and verify your internal taxonomy aligns before each submission
  3. Examiner-ready documentation — every filing is supported by source system reconciliation reports and internal review records
  4. Proactive regulatory monitoring — as state regulators update their MCR examination focus areas, we adjust your data collection and validation processes to stay ahead of where examiners are looking

Q3: Ready to Build a Defensible MCR Process?

If your current mortgage call reporting process lives in a spreadsheet, gets assembled in the last week of the filing window, and has never been cross-referenced against your HMDA data — that’s the process an examiner will find when they review your licensing history.

The good news: MCR compliance doesn’t require rebuilding your entire technology stack. It requires disciplined reconciliation, documented procedures, and a compliance partner who understands how regulators actually use the data.

Synergy works with lenders and servicers to build MCR processes that hold up under regulatory scrutiny — from data validation through submission and audit documentation.

Contact us to discuss your current MCR compliance posture or book a demo at simplifyqc.com.

Mortgage Call Report Q&A: Servicing Data and Expanded Filers

Q1: What Is the Actual Enforcement Pattern for MCR Non-Compliance Across Major States?

Enforcement varies significantly by state regulator — which is one of the most underappreciated aspects of MCR risk management for multi-state lenders.

The SAFE Act mandates MCR filing as a condition of license maintenance, but the enforcement mechanisms are state-designed:

California (DFPI): DFPI has been increasingly active in examining MCR data against branch license activity. We’ve seen examination findings issued where branch-level MCR submissions showed activity inconsistent with the company’s NMLS licensing map.

New York (DFS): DFS takes a hard line on late or missing filings, and has included MCR non-compliance as a factor in consent order negotiations with mortgage servicers — even when the underlying issue was unrelated to call reporting.

Texas (SML): The new Q1 2026 supplemental filing requirement has caught several mid-sized servicers off guard. SML has signaled through industry communications that they will be actively validating supplemental submissions against RMLA data.

Washington (DFI): Washington DFI has issued fines for incomplete MCR filings — not just late ones — where companies filed but left required fields blank or submitted obviously rounded figures that suggested incomplete data collection.

The pattern across all states: regulators are using MCR data as a primary source for examination planning. A clean MCR history doesn’t just avoid penalties — it shapes which companies get examined and how intensively.

Q2: How Should Servicers Handle Loss Mitigation and Workout Data in the Expanded MCR?

For Expanded MCR filers — those approved by Fannie Mae, Freddie Mac, or Ginnie Mae — the servicing data section is where most reconciliation errors occur. With FHA’s revised loss mitigation waterfall (effective October 2025 under ML 2025-06 and subsequent revisions) adding new workout options including Payment Supplements and modified COVID-era relief transitions, the MCR servicing categories are under pressure to reflect activity that previous form versions didn’t anticipate.

Specifically:

  1. Payment supplement activity needs to be properly categorized — this is a relatively new tool in the FHA servicing waterfall, and companies that haven’t updated their internal reporting taxonomies are classifying it inconsistently
  2. COVID-era loss mitigation transitions are winding down under the updated permanent waterfall, but the activity is still appearing in MCR data under legacy categories, creating inconsistencies
  3. Modifications vs. forbearance re-defaults — there is genuine ambiguity in how to report certain workout scenarios, and companies making conservative assumptions may be underreporting while aggressive classifications create regulatory exposure

The practical recommendation: before each quarterly filing, your servicing data team and your compliance team need to review the categorization decisions together — not hand off data in a one-way process.

Q3: How Does MCR Data Interact With HMDA LAR — and Where Do the Reconciliations Break Down?

The intersection of MCR and HMDA reporting is where experienced compliance teams still make errors — not because the concepts are difficult, but because the two datasets use different segmentation logic and deadlines that create plenty of room for inconsistency.

Key reconciliation challenge: loan count segmentation. HMDA requires reporting of originated loans, purchased loans, and in some cases applications that didn’t close. The MCR RMLA captures origination activity by product type and purpose. When a company is active in both HMDA-reportable and business-purpose lending, the segmentation of the MCR data must align with the same population that drives HMDA reporting.

The “no activity” problem. Companies that originate no HMDA-reportable loans in a quarter still have MCR filing obligations — but the RMLA data must reflect zero origination activity consistent with what HMDA would show. If the company had any activity at all and is claiming zero in both, regulators will cross-reference and find the discrepancy.

Annual LAR reconciliation. HMDA’s annual submission deadline (March 2 for 2025 data) creates a natural reconciliation point with the four quarterly MCR submissions. Companies that perform this reconciliation annually rather than quarterly frequently discover errors that have compounded across multiple quarters.

Q4: What Documentation Do You Need to Survive an MCR Examination?

State examiners don’t just ask for your NMLS submission. They ask for the supporting documentation — and if you can’t produce it, the filing itself becomes a compliance issue.

The audit trail for a defensible MCR filing should include:

  1. Source system reconciliation reports showing how origination, servicing, and accounting data fed into each MCR field
  2. Data classification logic — documented rationale for how you categorized each loan type, product, and activity line
  3. Internal review sign-off — a named compliance officer or CFO who reviewed and approved the filing before submission
  4. Correction log — if prior quarters were amended, the documentation of what changed and why
  5. State-specific supplemental data — stored separately from the NMLS submission with its own supporting documentation

For Expanded MCR filers, the documentation burden is higher. Servicing portfolio data should tie to investor statements; loss mitigation figures should tie to your loss mitigation workflow system; delinquency and default data should tie to your default management reporting.

Mortgage Call Report Q&A: What Examiners Want to See

The Mortgage Call Report is one of the most examined regulatory filings in mortgage lending — and most compliance teams are treating it like a simple data submission exercise. Regulators are treating it as a risk signal. Here’s what every Mortgage Call Report filer needs to understand about how examiners actually review your submission.

Q1: What Are Examiners Actually Looking for When They Review Our MCR?

Most compliance teams treat the MCR as a data submission exercise. Regulators treat it as a risk signal.

State financial examiners don’t just check whether you filed — they cross-reference your MCR data against your HMDA submissions, your BSA/AML filings, your licensed MLO count on NMLS, and your audited financial statements. When those numbers don’t reconcile, you get an examination finding — not a conversation, a finding.

Specifically, examiners are flagging:

  1. Servicing portfolio totals that don’t match investor reporting — the most common Expanded MCR trigger
  2. MLO headcount that diverges from state licensing records — particularly after a layoff round or MLO migration
  3. Denial rate spikes without accompanying explanation — regulators are acutely focused on adverse action patterns
  4. Origination volume that doesn’t correlate with your stated product mix — a lender claiming $200M in originations but only two loan products raises questions

The takeaway: your MCR shouldn’t be assembled in the filing window. It should be reconciled continuously against your other regulatory outputs throughout the quarter.

Q2: What Actually Changed With MCR Form Version 7 — and What Filers Are Getting Wrong?

Starting Q1 2026, MCR FV7 replaced FV6 as the mandatory submission format. The headline change was structural consolidation — FV6 eliminated the separate Standard and Expanded MCR forms in favor of a single filing with conditionally required fields based on company type and license profile. But the practical implications run deeper than the form redesign.

The most common FV7 filing errors we’re seeing:

Servicing portfolio segment misclassification. FV7 restructured how servicing activity is reported across investors. Companies that didn’t update their internal data mappings before the Q1 2026 window opened are reporting data under old categories — meaning the numbers don’t align with what state regulators are now expecting to see.

Ginnie MaeIssuer-specific data gaps. FV7 introduced new conditional fields for Ginnie Mae Issuers that weren’t present in FV6. If your compliance team built your FV7 filing template from FV6 documentation rather than the current NMLS field definitions and instructions, you’re almost certainly missing required fields.

State-specific supplemental attachments. Texas’s new supplemental filing requirement — effective Q1 2026 for companies engaged in third-party processing or underwriting — is a separate submission from the NMLS MCR. Several lenders treated it as part of the MCR filing and either missed it entirely or submitted incomplete data.

Q3: How Do You Handle MCR Reporting When You Have both State-Licensed and Federally Chartered Entities?

This is one of the most complex MCR scenarios in the industry, and it’s becoming more common as large bank mortgage subsidiaries and credit union service organizations navigate dual chartering structures.

When a company operates both state-licensed entities and federally chartered affiliates, the MCR reporting obligations do not consolidate at the parent level — they file separately through NMLS for each licensed entity. The data must reflect only that entity’s activity, not the consolidated group.

The practical compliance challenge is cost allocation and data allocation. State regulators have increasingly scrutinizing whether shared services (compliance technology, QC staff, accounting functions) are being allocated appropriately across entities — particularly when one entity appears unprofitable while the parent is profitable. examiners are beginning to ask for supporting documentation on cost allocation methodologies.

Additionally, if your state-licensed entity services loans for your federally chartered affiliate, you may have MCR servicing data that needs to be reconciled against a separate federally required reporting framework — and the numbers must match.

Web Statistics