Feature AI Risk
Fannie Mae LL-2026-04: What Mortgage Sellers and Servicers Must Build Before August 6 — and Why Freddie Mac's March 3 Deadline Already Exposed Gaps
Fannie Mae's AI/ML governance framework (LL-2026-04) takes effect August 6, 2026. Freddie Mac's equivalent hit March 3. Both cover all AI in origination and servicing, including vendor tools. Here's what a compliant program actually looks like.
Table of Contents
Freddie Mac’s AI governance requirement took effect March 3. Most mortgage lenders either barely noticed or treated it as a vendor pass-through. That logic doesn’t survive Fannie Mae’s August 6 deadline — and it didn’t survive Freddie Mac’s March 3 deadline either.
TL;DR
- Freddie Mac’s AI/ML governance requirements (Guide Section 1302.8) went live March 3, 2026, requiring documented programs, NIST 800-53 and ISO 27001 alignment, senior management approval, and active monitoring for drift and bias
- Fannie Mae’s LL-2026-04 takes effect August 6, 2026, requiring documented governance programs for any seller or servicer using AI in origination or servicing
- Both requirements extend to vendor and subcontractor AI under a “no less protective” standard — third-party documentation gaps are your compliance gaps
- Neither framework is limited to credit decisioning: fraud detection, document intelligence, chatbots, income tools, and borrower communications are all in scope
- Most lenders are running a materially incomplete program right now, even if they think they aren’t
Why the GSEs Got Here
Fannie Mae and Freddie Mac don’t supervise banks. They govern the terms under which sellers deliver loans and servicers manage them. That distinction matters for how you think about this requirement: it isn’t a prudential regulatory mandate from the OCC or FDIC. It’s a contract requirement embedded in your seller/servicer agreement. Violations don’t result in an MRA or consent order. They result in repurchase demands, indemnification claims, and in the worst case, termination of seller/servicer approval.
The practical pressure driving this is the explosive growth of AI in the mortgage process. Lenders are using automated document review, AI-assisted income verification, fraud detection models, and natural language tools for borrower communications — sometimes without compliance teams knowing the full inventory. The GSEs carry credit risk on a significant portion of the loans these tools are used to originate and service. They have direct financial exposure to AI model failures that produce inaccurate income calculations, miss fraud signals, or generate biased outputs that produce discriminatory lending patterns.
This isn’t a theoretical governance concern. It’s a counterparty risk problem — and the GSEs are now managing it through seller/servicer obligations.
What Freddie Mac Required (Already in Effect Since March 3, 2026)
Freddie Mac updated its Seller/Servicer Guide in December 2025 with Guide Section 1302.8, effective March 3, 2026. The framework is built around three core principles: transparency (know where you’re using AI), accountability (assign clear ownership of each system’s risk), and ethical stewardship (operate controls and monitoring in practice, not just on paper).
The specific requirements are more detailed than most enterprise AI policies:
AI inventory across the full loan lifecycle. Every place where AI or ML touches loan origination or servicing must be identified — not just the underwriting engine. This includes vendors embedded in document processing, fraud detection, quality control, customer communications, and payment processing. If a tool used anywhere in your mortgage workflow has AI functionality, it belongs in the inventory.
Audits mapped to named standards. Regular internal and external audits are required. Critically, Freddie Mac specifically named NIST 800-53 and ISO 27001 as the baseline audit standards. This is meaningfully more specific than frameworks that reference “industry standards” without naming them — and it means lenders using AI governance programs built to generic checklists may not satisfy the requirement.
Ongoing performance and bias monitoring. Sellers and servicers must monitor AI/ML systems for performance degradation and bias on a continuous basis, not just at initial deployment.
Segregation of duties. Documented accountability structures must separate those who develop or configure AI systems from those who approve and monitor them.
Senior management approval. AI/ML policies must be approved by at minimum the chief information officer, chief technology officer, chief information security officer, or chief risk officer.
If your existing AI governance program doesn’t meet these criteria — documented, audited against named standards, actively monitored, officer-approved, with vendor scope — Freddie Mac’s March 3 deadline has already passed you.
What Fannie Mae LL-2026-04 Requires (Effective August 6, 2026)
Fannie Mae’s LL-2026-04 takes a principles-based approach rather than prescribing specific control standards. The core requirement: any seller or servicer that uses AI or ML in origination or servicing must operate under a documented, actively maintained governance program.
The specific program elements:
Written policies and procedures covering the development, implementation, use, and maintenance of any AI/ML system. Policies must be reviewed and updated at least annually, communicated to relevant staff, grounded in applicable legal and regulatory requirements, calibrated to the institution’s own risk tolerance, and assigned to a designated owner.
Full lifecycle coverage. The policies must address the entire AI lifecycle from design and training data governance through deployment, monitoring, and retirement. This isn’t a deployment checklist — it has to cover every stage.
Vendor and subcontractor governance at the same standard as internal tools. LL-2026-04 explicitly requires sellers and servicers to govern the AI use of vendors, subcontractors, and third-party originators to “no less protective” standards than they apply to their own systems.
Disclosure upon request. On request by Fannie Mae, a seller or servicer must promptly disclose: the types of AI/ML used, the purpose and manner of use, the safeguards implemented to manage AI/ML risk, and any other information Fannie Mae may require. “Promptly” is undefined but the practical implication is clear — the documentation must exist now, not be assembled in response to a request.
Comparison: What Each GSE Requires
| Requirement | Freddie Mac (effective March 3, 2026) | Fannie Mae LL-2026-04 (effective August 6, 2026) |
|---|---|---|
| AI/ML inventory | Required — full loan lifecycle | Implied by governance program scope |
| Written policies | Required | Required |
| Annual policy review | Implied | Explicitly required |
| Vendor governance | Explicit | ”No less protective” standard |
| Audit standards | NIST 800-53, ISO 27001 named | Principles-based (no specific standard named) |
| Bias monitoring | Ongoing monitoring required | Risk-calibrated program implied |
| Senior approval | CIO, CTO, CISO, or CRO | Designated owner required |
| Disclosure obligation | Freddie Mac inspection rights | Prompt disclosure upon request |
Neither framework is limited to credit decisioning or underwriting. Both cover the entire origination and servicing technology stack wherever AI or ML is present.
The Part Most Lenders Are Missing: Vendor Scope
Both frameworks apply to vendor AI. Not just in-house models. Every AI or ML tool embedded in the loan lifecycle from any source.
Consider a typical lender’s technology stack: a point-of-sale platform with AI document extraction, a third-party income verification service using ML models, a fraud detection vendor, a servicing platform with AI-assisted payment processing, an outbound communications tool using generative AI for borrower messages, a quality control platform with automated review flags. Each of these vendors is using AI. Each is in scope under both GSE frameworks.
Most lenders’ current AI governance programs — to the extent they exist — cover the underwriting model and perhaps proprietary internal tools. They don’t govern vendor AI with meaningful rigor. When Fannie Mae requests disclosure of the AI tools in use across origination and servicing, a lender without a vendor AI inventory cannot answer the question accurately.
This is the structural gap: lenders don’t know their full AI footprint, so they can’t document governance over what they haven’t inventoried. The first step is not writing a policy. It’s conducting the inventory.
For the vendor governance piece specifically, the questions to ask vendors mirror standard TPRM due diligence: What AI/ML tools do you use in connection with our mortgage business? What is your model governance policy? How do you test for and monitor bias? What audit rights do you provide? What are your incident notification procedures for AI failures? The third-party AI vendor due diligence framework covers the specific questions and documentation to request.
Building a Compliant Program: A 22-Day Playbook
With 22 days to August 6, a lender starting today has enough time to close material gaps if there is a framework to populate — not enough to build one from scratch. The following sequence gets you to a defensible minimum:
Week 1: Run the AI/ML inventory. Survey product, technology, and operations leads across origination and servicing. Document every AI tool in use, including vendor-provided tools. The survey should capture: what the tool does, who owns it, what data it processes, whether it touches consumer-facing outputs, and whether the vendor has its own AI governance program. This is the foundational step — everything else depends on knowing what’s in your stack.
Week 1-2: Assess vendor documentation. For each vendor AI tool identified: confirm you have the vendor’s AI governance policies, any relevant audit attestations (SOC 2 reports, penetration test results), and contractual provisions covering AI-specific obligations — bias testing, incident notification, model governance. Send a request to any vendor where documentation is missing. Document what you’ve requested and when.
Week 2: Write or update the AI governance policy. The policy must cover development, implementation, use, and maintenance of AI/ML — including vendor tools. Assign a designated owner. Build in annual review. The policy doesn’t have to be long but must be documented, accurate, and reflective of your actual AI inventory.
Week 2-3: Establish monitoring cadences. Freddie Mac requires ongoing monitoring for performance degradation and bias. Fannie Mae requires programs calibrated to risk tolerance. Build a monitoring schedule: what gets monitored, at what frequency, who reviews, and what triggers remediation or escalation.
Week 3: Get officer-level sign-off. Freddie Mac explicitly requires CIO, CTO, CISO, or CRO approval of AI/ML policies. Fannie Mae requires designation of a program owner. Convene the appropriate executives, walk through the inventory and program scope, and document the approval.
For lenders who want a structured framework to populate rather than building from scratch, the NIST AI RMF MEASURE function provides the evaluation and testing methodology that maps closely to what Freddie Mac’s bias monitoring and performance monitoring requirements require in practice.
What Happens If You’re Not Ready by August 6
Fannie Mae has not announced a specific enforcement timeline tied to the August 6 effective date. But the disclosure right embedded in LL-2026-04 gives Fannie Mae ongoing authority to request your documentation at any time. More immediately, your certifications under the seller/servicer agreement — which require compliance with the guide — become legally questionable if you knowingly use AI tools without the governance the letter requires.
The more practical risk is downstream: when the first repurchase demand or indemnification claim is tied to an AI-related error — an income calculation the model got wrong, a fraud detection tool that missed something material, a borrower communication that was generated by AI and was inaccurate — the question will be what your AI governance program looked like at the time of the error. “We hadn’t built one yet” is not a defensible answer once the August 6 effective date has passed.
The GSE frameworks also set the floor for what regulators, state AGs, and class action plaintiffs will expect to see when AI failures produce consumer harm in mortgage transactions. The EU AI Act high-risk AI framework documents what “high-risk” AI governance documentation requirements look like at the international standard — worth reviewing for firms with any EU operations alongside the GSE-specific requirements.
So What?
If Freddie Mac’s March 3 deadline passed without a formal AI governance program, August 6 is the remediation window.
Three things to do this week:
- Run the AI/ML inventory. You cannot govern what you cannot see. Build the full list before you write the policy.
- Identify vendor documentation gaps. For each vendor AI tool, confirm you have their governance documentation or request it now. Missing documentation is a gap under both GSE frameworks.
- Assign an owner. Both frameworks require a designated program owner. If no one is accountable for AI governance, that’s the first structural fix.
The window between now and August 6 is tight but workable. The window between August 6 and Fannie Mae’s first documentation request is unknown — which is why the work needs to happen now, not after the deadline.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is Fannie Mae LL-2026-04?
When did Freddie Mac's AI governance requirement take effect?
Does the AI governance requirement only apply to credit decisioning models?
What does Fannie Mae mean by 'no less protective' for vendor governance?
What information must a lender produce to Fannie Mae 'upon request'?
What's the minimum a lender needs in place by August 6?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026