Archives

Mortgage AI/ML Compliance Q&A: Governance, Fair Lending, and Exam Readiness

AI/ML compliance for mortgage lenders is no longer a future-state planning exercise. Fannie Mae’s LL-2026-04 took effect August 6, 2026. Freddie Mac’s Section 1302.8 took effect March 3, 2026. The Colorado AI Act took effect February 1, 2026. The California DFPI is actively examining AI/ML programs. State AGs are bringing actions under existing UDAP authority.

This Q&A focuses on the practical questions your compliance team will face as the AI/ML governance framework comes into operational reality in 2026 — what to build, what to document, what examiners are looking at, and how to keep the program running as models evolve and rules change.

Q1: We Just Discovered LL-2026-04. What Do We Do First?

The first step is the AI/ML use case inventory. You cannot scope a governance program without knowing which systems are in scope. The inventory should identify every AI/ML system used in the mortgage lifecycle, the business function each supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

A common mistake is to start with the governance policy. A policy written before the inventory is complete is a policy that does not match the actual system footprint. The inventory drives the policy, not the other way around.

Aim to have a complete inventory within 30 days. Most lenders underestimate how many AI/ML systems they actually run — the inventory typically surfaces 30-50% more systems than the compliance team expected.

Q2: How Do We Decide Which AI/ML Systems Are “High-Impact”?

The GSE frameworks and the Colorado AI Act both use a risk-tiering approach. The relevant question for a high-impact designation is whether the system can materially affect a borrower’s loan terms, access to credit, or experience in the loan process.

High-impact systems for mortgage lenders typically include:

  • Automated underwriting systems (AUS)
  • AI-driven appraisal valuation models (AVMs with machine learning components)
  • AI-driven fraud detection models that affect application decisions
  • Pricing optimization models that influence loan pricing
  • Lead scoring models that affect credit decisions
  • Income and asset verification tools that use AI
  • Customer service chatbots that handle credit-related inquiries

Lower-risk systems include internal marketing analytics, business intelligence dashboards, and back-office automation that does not affect borrower outcomes. Document the risk tiering methodology so examiners can review the logic.

Q3: What Counts as an “AI/ML System” for Compliance Purposes?

The LL-2026-04 definition tracks the broad industry usage. An AI/ML system is any system that uses statistical learning, neural networks, natural language processing, or other machine learning techniques to produce an output from training data. Generative AI (text or image generation), predictive models, classification models, and clustering models are all in scope.

Out of scope: rule-based decision engines that do not learn from data, simple threshold-based scoring (e.g., credit score lookups without model adjustment), and traditional statistical models without a learning component. The key question is whether the system’s parameters are learned from data rather than set by human designers.

When in doubt, include the system in the inventory and document the determination. The cost of including a borderline system is much lower than the cost of an examiner discovering a missed system.

Q4: How Do We Build a Fair Lending Testing Program for AI/ML?

A defensible fair lending testing program has four components.

1. Outcomes-based testing. Compare actual loan decisions, pricing, or other outcomes across demographic segments. The relevant segments under federal law are race, national origin, sex, religion, familial status, age, and disability. Under state law, additional protected categories may apply.

2. Input-based testing. Audit model features for proxy variables that correlate with protected classes even when the protected class is not a direct input. ZIP code is a classic proxy for race. Language preference can be a proxy for national origin. Proxies are not always a violation, but they require documentation of why the proxy is appropriate and how its use is monitored.

3. Segment-level performance review. Model accuracy, false positive rates, and false negative rates should be reviewed at the segment level. A model that performs well on average but has materially different error rates across protected segments is a model that needs remediation before deployment.

4. Counterfactual testing. For loan decisions, change the protected class of an applicant and observe whether the decision changes. If the decision changes when only the protected class changes, the model is using protected class or proxy information inappropriately.

The testing should be performed before deployment, after material model changes, and at a defined cadence — at least annually for high-impact systems.

Q5: What Documentation Do Examiners Look For First?

Examiners start with the inventory and the governance policy. From there, the document request typically expands to model documentation, validation reports, fair lending testing, vendor contracts, and the most recent attestation.

The most common finding in early AI/ML examinations is a gap between what the inventory claims and what the documentation actually supports. Lenders may claim to have a fair lending testing program but produce a single slide with results, not a documented testing protocol with methodology, results, and remediation actions.

The exam-ready binder for AI/ML governance should include:

  • AI/ML use case inventory with risk tiering
  • Governance policy approved at senior committee level
  • Model documentation for each high-impact system (data sources, training methodology, performance metrics, validation results)
  • Fair lending testing reports for each high-impact system
  • Vendor contracts with AI/ML-related terms
  • Annual attestation
  • Incident log (any model failures, complaints, regulatory inquiries)

Q6: How Do We Handle AI Tools That Loan Officers Use Independently?

If loan officers use AI tools (ChatGPT, Claude, specialized mortgage AI assistants, etc.) in connection with loan files, the tools are in scope under LL-2026-04 and Section 1302.8. The lender is the deployer and is accountable for the tool’s compliance.

The minimum controls: an approved list of AI tools that may be used in connection with loans, prohibition on uploading borrower non-public personal information to tools that have not been approved, a confidentiality review of the tool’s data handling practices, and a documented training program for loan officers on the approved-use policy.

The most common exam finding: lenders have no visibility into which AI tools loan officers are using. Shadow AI use is a significant risk, and lenders are expected to address it proactively.

Q7: How Should We Structure the AI Governance Committee?

The committee structure varies by institution size. For mid-size and large lenders, the typical structure is:

AI Governance Committee: senior leadership (CRO, CIO, General Counsel, Head of Compliance, Head of Model Risk) meets quarterly or more frequently. Approves the governance policy, reviews high-impact model changes, signs off on attestations.

Model Risk Management function: dedicated staff (or a vendor) that runs the inventory, conducts validation, performs fair lending testing, maintains documentation.

Model Owners: business line leaders responsible for individual AI/ML systems. Own the system lifecycle, escalate issues to the committee, ensure documentation is current.

For smaller lenders without dedicated model risk staff, the model risk function may be outsourced or combined with compliance. The committee structure remains the same; the execution is shared.

Q8: How Do We Balance AI Innovation with AI Compliance?

The right framing is not “innovation vs. compliance” — it is “innovation with governance.” A model that cannot be explained to an examiner is a model that creates regulatory risk. A model that produces disparate outcomes is a model that creates litigation risk. Governance is what makes innovation sustainable.

The practical implementation: the governance framework should be designed to support business velocity, not slow it down. Pre-deployment validation, fair lending testing, and documentation should be efficient and well-scoped. The model risk function should be a partner to the business, not a bottleneck.

A common failure mode: over-engineering the governance process to the point where business teams route around it. The result is shadow AI use — business teams adopt new tools without governance review, and the compliance program loses visibility into the actual system footprint.

Q9: What Is the Most Common AI/ML Compliance Failure You See?

The most common failure is treating the AI/ML governance program as a documentation exercise rather than an operational one. Lenders produce a policy and a checklist, but they do not actually run the inventory, conduct the validation, or perform the fair lending testing. When the examiner asks for the supporting documentation, the program collapses.

The second most common failure is treating vendor-provided validation as a substitute for lender validation. The lender is accountable for the model’s performance in its own use context. The vendor’s validation report is an input, not an output.

The third most common failure is fair lending testing that is too narrow — testing only adverse action outcomes and missing proxy variable analysis, or testing only protected classes under federal law and missing the additional state-level protected categories.

Q10: Where Should AI/ML Compliance Be on the Q3 2026 Priority List?

For lenders that have not yet built a program, AI/ML governance should be at the top of the Q3 2026 priority list. The LL-2026-04 effective date has passed, and the first attestation cycle is approaching. The work cannot wait for Q4.

The Q3 priorities, in order:

This month: Complete the AI/ML use case inventory. Identify model owners and risk tiering.

Next 30 days: Draft the governance policy. Get committee approval.

Next 60 days: Begin fair lending testing for the highest-impact systems. Document the testing methodology.

By year-end: Complete the first round of validation. Stand up the annual attestation process. Build the exam-ready binder.

For lenders with a program already in place, the Q3 priority is to harden the documentation for examiner review and to verify the program covers the new state-level rules — particularly the Colorado AI Act if you originate or service in Colorado.

Need support on AI/ML governance, fair lending testing, or state-level compliance overlay? Synergy works with mortgage lenders on AI/ML program design, validation, multi-state compliance overlays, and exam readiness. Book a 30-minute AI/ML review.

Fannie Mae AI/ML Governance: What Lenders Must Do by August 6

Fannie Mae’s AI/ML governance framework — Lender Letter LL-2026-04 — took effect on August 6, 2026. For any single-family seller or servicer using artificial intelligence or machine learning in connection with mortgages sold to Fannie Mae, the framework is now in force. The compliance bar is no longer aspirational; it is operational.

LL-2026-04 is the companion to Freddie Mac’s Seller/Servicer Guide Section 1302.8, which took effect March 3, 2026. Together, the two frameworks establish the GSE position on AI/ML governance: lenders are accountable for the design, performance, and outcomes of any AI/ML system used in the mortgage lifecycle, regardless of whether the system is built in-house, provided by a third-party vendor, or accessed through a marketplace platform.

This guide walks through what LL-2026-04 requires, how it interacts with Freddie Mac Section 1302.8 and state-level AI rules, and what a defensible AI/ML governance program looks like for a mortgage lender as of August 2026.

What LL-2026-04 Actually Requires

LL-2026-04 is structured around six governance obligations. Each is a stand-alone compliance topic and each requires documentary evidence.

1. AI/ML Use Case Inventory

Lenders must maintain a complete inventory of every AI/ML system used in the mortgage lifecycle. The inventory should identify the system, the business function it supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

In scope: automated underwriting, appraisal valuation models, fraud detection, lead scoring, marketing optimization, customer service chatbots, document classification, income and asset verification, and any pricing or margin optimization tool that uses statistical learning.

Out of scope: rule-based decision engines that do not learn from data, simple statistical scoring (e.g., credit score lookups without model adjustment), and standard business intelligence dashboards.

2. Model Risk Management Framework

Each inventoried AI/ML system must be classified by risk tier based on its impact on loan decisions, borrower outcomes, and regulatory exposure. High-impact systems (underwriting, pricing, fraud, valuations) require the most rigorous controls.

The framework should document validation activities (pre-deployment testing, ongoing monitoring, periodic revalidation), performance thresholds, change management procedures, and override mechanisms for human review.

3. Fair Lending Testing

Each AI/ML system that affects loan decisions, pricing, or adverse action notices must be tested for fair lending impact. Testing should include disparate impact analysis across prohibited basis categories (race, national origin, sex, religion, familial status, age, disability), proxy variable analysis (identifying features that correlate with protected classes even when the protected class is not a direct input), and segment-level performance review.

The testing should occur before deployment, after material model changes, and at a defined cadence (typically annually for high-impact systems).

4. Governance Documentation

LL-2026-04 requires a written AI/ML governance policy that is approved at the board or senior committee level. The policy should cover roles and responsibilities, model lifecycle controls, escalation paths, exception handling, and incident response.

Documentation must be maintained for the life of each model plus a defined retention period. The retention floor is generally three years post-decommissioning, consistent with other mortgage compliance records.

5. Third-Party Vendor Oversight

Lenders remain accountable for AI/ML systems provided by third parties. The oversight program should include vendor due diligence (model documentation review, validation access, audit rights), ongoing monitoring (performance reports, incident notification, regulatory change tracking), and contractual protections (indemnification, data security, model decommissioning rights).

A common gap: lenders that treat vendor systems as “off the shelf” and skip validation. LL-2026-04 treats this as a compliance failure. The lender is responsible for validating the model in the context of its own use, even if the vendor provides the validation methodology.

6. Annual Attestation

Lenders must attest annually to Fannie Mae that they have an AI/ML governance program in place that meets LL-2026-04 requirements. The attestation is a senior officer certification, not a procedural check-the-box. Officers signing the attestation should expect to defend the substance of the program if challenged.

How LL-2026-04 Interacts with Freddie Mac Section 1302.8

If your institution sells to both GSEs, you do not need to maintain two separate AI/ML governance programs. A unified program that satisfies both frameworks is acceptable, and Fannie Mae and Freddie Mac have signaled that they will accept each other’s attestations in most cases.

The two frameworks differ in three operational details:

  • Effective dates: Freddie Mac Section 1302.8 took effect March 3, 2026. Fannie Mae LL-2026-04 took effect August 6, 2026. If you implemented a Section 1302.8 program in the spring, you should be in good shape on the substance of LL-2026-04. The remaining work is typically attestation timing and documentation reconciliation.
  • Attestation cadence: Freddie Mac requires annual attestation. Fannie Mae requires annual attestation. The two attestations can be filed separately even if the underlying program is the same.
  • High-impact system definition: The two frameworks use slightly different definitions of “high-impact.” Where they differ, the more conservative definition should govern.

If your institution sells to only one of the two GSEs, you only need to meet that GSE’s framework. But state-level AI rules may still apply regardless of GSE relationship — see the August 2026 article on state AI/ML enforcement.

What “In Connection With Mortgages Sold to Fannie Mae” Means

LL-2026-04 applies to AI/ML systems used in connection with mortgages sold to Fannie Mae. The phrase is interpreted broadly. If a system touches a loan that may eventually be sold to Fannie Mae, the governance obligations apply.

In practice, this covers:

  • Systems used at the point of application (lead scoring, prequalification)
  • Systems used during origination (automated underwriting, fraud detection, document processing)
  • Systems used post-closing (servicing decisioning, loss mitigation, default management)
  • Marketing and customer service systems if they influence the loan pipeline that includes Fannie Mae-sold loans

A practical approach: inventory every AI/ML system in your mortgage technology stack. If any of them touch a loan that may be sold to Fannie Mae, the system is in scope.

The Fair Lending Layer

The fair lending testing requirement under LL-2026-04 is the area where most lenders are least prepared. Standard model risk management covers performance, drift, and stability. Fair lending testing is a separate discipline with its own methodology, its own tooling, and its own documentation requirements.

If your institution has not yet built a fair lending testing program for AI/ML, the August 6 effective date is the trigger to either build it or engage external support. The testing cadence is at least annual for high-impact systems, and the documentation must be available for Fannie Mae review on request.

Two common testing approaches:

  • Outcomes-based testing: Compare actual loan decisions, pricing, or other outcomes across demographic segments. Identifies disparate impact at the output level.
  • Input-based testing: Audit model features for proxies that correlate with protected classes. Identifies structural risk before the model produces an outcome.

The most defensible approach is both. Outcomes-based testing identifies what the model is doing. Input-based testing identifies how the model could produce a problematic outcome before it happens.

Action Steps for August 2026

If your institution has not yet built a LL-2026-04 program, the immediate priorities are:

This month: Inventory every AI/ML system in the mortgage technology stack. Identify model owners, deployment dates, and vendors. This is the foundation for everything else.

This quarter: Classify each system by risk tier. Document the validation activities already performed. Identify gaps relative to LL-2026-04 requirements.

By year-end: Complete the governance policy. Establish fair lending testing for high-impact systems. Build the vendor oversight program. Stand up the annual attestation process.

By Q1 2027: Complete the first attestation cycle. Document the validation work performed. Build the exam-ready binder.

Frequently Asked Questions

We Don’t Use AI/ML Anywhere. Does LL-2026-04 Still Apply?

If you genuinely use no AI/ML systems in connection with mortgages sold to Fannie Mae, the framework does not impose substantive obligations. The annual attestation, however, is still required — you attest that you have no in-scope systems. Document the basis for that conclusion (the inventory and the analysis) so the attestation is defensible.

What About AI Tools Used by Individual Loan Officers?

If a loan officer uses a third-party AI tool (e.g., a ChatGPT-style assistant) in connection with a loan, the tool is in scope. The lender’s vendor oversight program must cover the tool, including the data security and confidentiality controls.

How Does LL-2026-04 Interact With State AI Laws?

LL-2026-04 is a GSE framework. State AI laws are separate obligations. In most cases, the state law is additive — you must satisfy both. See the August 2026 article on state AI/ML enforcement for the specific state rules that apply to mortgage lenders.

What Records Must We Retain?

Three years post-decommissioning for each model, consistent with other mortgage compliance records. The retention applies to model documentation, validation results, fair lending testing, governance decisions, vendor contracts, and attestation records.

Ready to build or audit your AI/ML governance program? Synergy supports mortgage lenders with model inventory design, governance policy drafting, fair lending testing frameworks, and AI/ML exam-readiness reviews. Book a 30-minute governance review.

Web Statistics