AI Governance: From Best Practice to Baseline Expectation (sponsored by ACES)

Amanda Phillips is general counsel and executive vice president of compliance at ACES Quality Management. With more than two decades of legal and compliance experience in the mortgage industry, she advises lenders, servicers and ACES clients on regulatory, fair lending and AI governance issues.

Artificial intelligence (AI) is quickly embedding across mortgage origination, servicing and quality control from automated underwriting and automated valuation models to fraud detection, document classification and decision-support tools. The pace of adoption has been remarkable. The pace at which regulators, the GSEs and state authorities are now defining their expectations is just as remarkable and as consequential.

Amanda Phillips

At our recent ACES Regional Workshop Series in San Diego and Charlotte, we walked through how rapidly the AI compliance landscape is shifting and what mortgage lenders should be thinking about in response. Over the past 12 months, federal regulators and state authorities issued dozens of new statutes, supervisory guidance documents, judicial decisions and executive orders touching AI and its use in financial services. The signal is clear: AI governance is moving from “best practice” toward a more standard exam expectation, and lenders who build that muscle now will be in a fundamentally stronger position than those waiting for a final rule or a first exam finding.

A patchwork of new AI expectations

Three sources of regulatory pressure are converging on mortgage lenders at once. The first is GSE guidance. Fannie Mae’s Lender Letter 2026-04, expected to take effect in August 2026, and Freddie Mac’s updates to Guide §1302.8 and §1302.2 set out detailed governance, documentation and disclosure requirements for any AI or machine learning system used in origination or servicing. Both GSEs call for written policies, designated policy owners, ongoing monitoring, training and incident response, and both impose an obligation to disclose AI use to the GSE upon request. Both also extend the same expectations to vendor and third-party systems and make clear that the seller/servicer remains responsible for compliance regardless of whether the AI was built internally or procured.

The second is federal banking regulator guidance. In April 2026, the OCC, Federal Reserve and FDIC issued interagency Model Risk Management guidance that rescinded and replaced the long-standing SR 11-7 framework. The new guidance reinforces familiar principles, such as conceptual soundness, outcomes analysis, ongoing monitoring, model inventory and effective challenge, and explicitly applies them to vendor and third-party models. Validation is not optional simply because the underlying code or data is proprietary.

The third is state activity. As federal fair lending enforcement has become less predictable, state attorneys general and state financial regulators have stepped into the gap, with California, New York, Illinois and several other states actively scrutinizing AI-assisted underwriting, valuation and servicing. Several states have signaled that documented AI governance policies and model inventories will be standard asks in their examinations.

For lenders, the question is no longer whether AI governance matters. It is about building a program that holds up under multiple, sometimes overlapping, regulatory lenses.

A familiar framework, applied to a new problem

Most lenders already have the vocabulary they need. The interagency Model Risk Management guidance, the GSE AI requirements and existing fair lending obligations all point toward a similar framework: identify the model, understand its purpose and exposure, document how it was developed and tested, validate it before it goes into production, monitor it afterward and assign clear accountability throughout.

The work is putting that framework into practice specifically for AI. A few elements deserve close attention:

A written AI policy. Lenders should have policies approved at the appropriate executive level that address development, implementation, use and maintenance of AI; integrate trustworthy AI principles; reflect current legal and regulatory requirements; and are reviewed at least annually. The policy should describe the tools you actually deploy today, not an aspirational future state.

An inventory. Every AI tool utilized by the organization should be documented and risk-tiered, including third-party systems. A workable inventory captures, at minimum, the tool name, date implemented, how and where it is used, whether it is consumer-facing, who owns it, its risk rating, regulatory and GSE scope, monitoring frequency, related policy references and current compliance status.

Vendor management that includes AI Tools. Regulators have been clear that the “we relied on our vendor” defense will not hold. Contracts should require appropriate representations, audit rights, and data security and breach notification commitments. For AI vendors, pre-onboarding due diligence should be scoped appropriately and may include model documentation, explainability standards, and disparate impact testing results.

Disparate impact testing and adverse action notices. When AI contributes to a credit decision, lenders need to know and document that the model’s outputs hold up across protected classes, and that any resulting adverse action notice explains the actual reasons in terms the applicant can understand. Generic codes will not satisfy the standard.

Risk-tiering: where to spend some effort

Not every AI tool warrants the same depth of governance, and a program that treats them all the same will collapse under its own weight. A tiered approach helps.

Some potential criteria for establishing and defining tiers include:

  • Critical-risk tools may be defined as those that carry the highest fair lending and consumer impact, such as automated underwriting systems, automated valuation models and credit scoring models that drive binding consumer outcomes.  These deserve the deepest documentation, validation, and monitoring.
  • High-risk tools may be those that materially influence decisions but typically operate with heavy human oversight, such as income or asset evaluation.
  • Medium-risk tools, may be defined as those affecting the customer experience but only having moderate compliance risk.
  • Low-risk tools are largely operational and require only a baseline level of governance.

Tiering the inventory clarifies where validation, testing cadence, and board-level attention belong. It also gives examiners a clean answer to a predictable question: how did you decide which systems get the most scrutiny?

Practical steps lenders can take today

Several steps can be taken without large budgets or new headcount:

  • Confirm there is a named owner for the company’s AI policy, and that the policy has been reviewed in the last 12 months.
  • Build or refresh the AI/ML inventory, including vendor-provided systems.
  • Risk-tier the inventory and align monitoring to risk level.
  • Update vendor management to include AI-specific due diligence and re-assessment dates.
  • Establish disparate impact testing on a defined cadence for any model influencing a credit or servicing decision.

None of these requires a finished regulatory landscape. They simply require ownership, documentation and consistency, putting lenders in a position to respond credibly when regulators ask.

Governance as a continuing discipline

The conversation about AI in mortgage compliance is still evolving, and lenders should expect that to continue. New guidance, new state activity and new tools will continue to emerge. ACES Quality Management is engaged in that conversation alongside our clients through our free resources, including the quarterly QC Industry Trends Reports, QCNow web series and Compliance NewsHub, in addition to the ongoing work we do with mortgage compliance, risk and QC leaders across the country.

We view AI governance as a continuing discipline rather than a one-time project, and we are building our platform, our content and our partnerships to support clients accordingly. The lenders most likely to weather the next wave of scrutiny will be those running their AI governance programs today as if an examiner were already in the building: measured, documented and ready to show their work.


(Sponsored content includes material submitted independently of the Mortgage Bankers Association and MBA NewsLink and does not connote an MBA endorsement of a specific company, product or service. For more information about sponsored content opportunities, contact Bill Farmakis at bill@jlfarmakis.com or 203/834-8832.)