Archives

Fannie Mae AI/ML Governance: What Lenders Must Do by August 6

Fannie Mae’s AI/ML governance framework — Lender Letter LL-2026-04 — took effect on August 6, 2026. For any single-family seller or servicer using artificial intelligence or machine learning in connection with mortgages sold to Fannie Mae, the framework is now in force. The compliance bar is no longer aspirational; it is operational.

LL-2026-04 is the companion to Freddie Mac’s Seller/Servicer Guide Section 1302.8, which took effect March 3, 2026. Together, the two frameworks establish the GSE position on AI/ML governance: lenders are accountable for the design, performance, and outcomes of any AI/ML system used in the mortgage lifecycle, regardless of whether the system is built in-house, provided by a third-party vendor, or accessed through a marketplace platform.

This guide walks through what LL-2026-04 requires, how it interacts with Freddie Mac Section 1302.8 and state-level AI rules, and what a defensible AI/ML governance program looks like for a mortgage lender as of August 2026.

What LL-2026-04 Actually Requires

LL-2026-04 is structured around six governance obligations. Each is a stand-alone compliance topic and each requires documentary evidence.

1. AI/ML Use Case Inventory

Lenders must maintain a complete inventory of every AI/ML system used in the mortgage lifecycle. The inventory should identify the system, the business function it supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

In scope: automated underwriting, appraisal valuation models, fraud detection, lead scoring, marketing optimization, customer service chatbots, document classification, income and asset verification, and any pricing or margin optimization tool that uses statistical learning.

Out of scope: rule-based decision engines that do not learn from data, simple statistical scoring (e.g., credit score lookups without model adjustment), and standard business intelligence dashboards.

2. Model Risk Management Framework

Each inventoried AI/ML system must be classified by risk tier based on its impact on loan decisions, borrower outcomes, and regulatory exposure. High-impact systems (underwriting, pricing, fraud, valuations) require the most rigorous controls.

The framework should document validation activities (pre-deployment testing, ongoing monitoring, periodic revalidation), performance thresholds, change management procedures, and override mechanisms for human review.

3. Fair Lending Testing

Each AI/ML system that affects loan decisions, pricing, or adverse action notices must be tested for fair lending impact. Testing should include disparate impact analysis across prohibited basis categories (race, national origin, sex, religion, familial status, age, disability), proxy variable analysis (identifying features that correlate with protected classes even when the protected class is not a direct input), and segment-level performance review.

The testing should occur before deployment, after material model changes, and at a defined cadence (typically annually for high-impact systems).

4. Governance Documentation

LL-2026-04 requires a written AI/ML governance policy that is approved at the board or senior committee level. The policy should cover roles and responsibilities, model lifecycle controls, escalation paths, exception handling, and incident response.

Documentation must be maintained for the life of each model plus a defined retention period. The retention floor is generally three years post-decommissioning, consistent with other mortgage compliance records.

5. Third-Party Vendor Oversight

Lenders remain accountable for AI/ML systems provided by third parties. The oversight program should include vendor due diligence (model documentation review, validation access, audit rights), ongoing monitoring (performance reports, incident notification, regulatory change tracking), and contractual protections (indemnification, data security, model decommissioning rights).

A common gap: lenders that treat vendor systems as “off the shelf” and skip validation. LL-2026-04 treats this as a compliance failure. The lender is responsible for validating the model in the context of its own use, even if the vendor provides the validation methodology.

6. Annual Attestation

Lenders must attest annually to Fannie Mae that they have an AI/ML governance program in place that meets LL-2026-04 requirements. The attestation is a senior officer certification, not a procedural check-the-box. Officers signing the attestation should expect to defend the substance of the program if challenged.

How LL-2026-04 Interacts with Freddie Mac Section 1302.8

If your institution sells to both GSEs, you do not need to maintain two separate AI/ML governance programs. A unified program that satisfies both frameworks is acceptable, and Fannie Mae and Freddie Mac have signaled that they will accept each other’s attestations in most cases.

The two frameworks differ in three operational details:

  • Effective dates: Freddie Mac Section 1302.8 took effect March 3, 2026. Fannie Mae LL-2026-04 took effect August 6, 2026. If you implemented a Section 1302.8 program in the spring, you should be in good shape on the substance of LL-2026-04. The remaining work is typically attestation timing and documentation reconciliation.
  • Attestation cadence: Freddie Mac requires annual attestation. Fannie Mae requires annual attestation. The two attestations can be filed separately even if the underlying program is the same.
  • High-impact system definition: The two frameworks use slightly different definitions of “high-impact.” Where they differ, the more conservative definition should govern.

If your institution sells to only one of the two GSEs, you only need to meet that GSE’s framework. But state-level AI rules may still apply regardless of GSE relationship — see the August 2026 article on state AI/ML enforcement.

What “In Connection With Mortgages Sold to Fannie Mae” Means

LL-2026-04 applies to AI/ML systems used in connection with mortgages sold to Fannie Mae. The phrase is interpreted broadly. If a system touches a loan that may eventually be sold to Fannie Mae, the governance obligations apply.

In practice, this covers:

  • Systems used at the point of application (lead scoring, prequalification)
  • Systems used during origination (automated underwriting, fraud detection, document processing)
  • Systems used post-closing (servicing decisioning, loss mitigation, default management)
  • Marketing and customer service systems if they influence the loan pipeline that includes Fannie Mae-sold loans

A practical approach: inventory every AI/ML system in your mortgage technology stack. If any of them touch a loan that may be sold to Fannie Mae, the system is in scope.

The Fair Lending Layer

The fair lending testing requirement under LL-2026-04 is the area where most lenders are least prepared. Standard model risk management covers performance, drift, and stability. Fair lending testing is a separate discipline with its own methodology, its own tooling, and its own documentation requirements.

If your institution has not yet built a fair lending testing program for AI/ML, the August 6 effective date is the trigger to either build it or engage external support. The testing cadence is at least annual for high-impact systems, and the documentation must be available for Fannie Mae review on request.

Two common testing approaches:

  • Outcomes-based testing: Compare actual loan decisions, pricing, or other outcomes across demographic segments. Identifies disparate impact at the output level.
  • Input-based testing: Audit model features for proxies that correlate with protected classes. Identifies structural risk before the model produces an outcome.

The most defensible approach is both. Outcomes-based testing identifies what the model is doing. Input-based testing identifies how the model could produce a problematic outcome before it happens.

Action Steps for August 2026

If your institution has not yet built a LL-2026-04 program, the immediate priorities are:

This month: Inventory every AI/ML system in the mortgage technology stack. Identify model owners, deployment dates, and vendors. This is the foundation for everything else.

This quarter: Classify each system by risk tier. Document the validation activities already performed. Identify gaps relative to LL-2026-04 requirements.

By year-end: Complete the governance policy. Establish fair lending testing for high-impact systems. Build the vendor oversight program. Stand up the annual attestation process.

By Q1 2027: Complete the first attestation cycle. Document the validation work performed. Build the exam-ready binder.

Frequently Asked Questions

We Don’t Use AI/ML Anywhere. Does LL-2026-04 Still Apply?

If you genuinely use no AI/ML systems in connection with mortgages sold to Fannie Mae, the framework does not impose substantive obligations. The annual attestation, however, is still required — you attest that you have no in-scope systems. Document the basis for that conclusion (the inventory and the analysis) so the attestation is defensible.

What About AI Tools Used by Individual Loan Officers?

If a loan officer uses a third-party AI tool (e.g., a ChatGPT-style assistant) in connection with a loan, the tool is in scope. The lender’s vendor oversight program must cover the tool, including the data security and confidentiality controls.

How Does LL-2026-04 Interact With State AI Laws?

LL-2026-04 is a GSE framework. State AI laws are separate obligations. In most cases, the state law is additive — you must satisfy both. See the August 2026 article on state AI/ML enforcement for the specific state rules that apply to mortgage lenders.

What Records Must We Retain?

Three years post-decommissioning for each model, consistent with other mortgage compliance records. The retention applies to model documentation, validation results, fair lending testing, governance decisions, vendor contracts, and attestation records.

Ready to build or audit your AI/ML governance program? Synergy supports mortgage lenders with model inventory design, governance policy drafting, fair lending testing frameworks, and AI/ML exam-readiness reviews. Book a 30-minute governance review.

Web Statistics