Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

Fannie Mae LL-2026-04: What Mortgage Sellers and Servicers Must Build Before August 6 — and Why Freddie Mac's March 3 Deadline Already Exposed Gaps

Fannie Mae's AI/ML governance framework (LL-2026-04) takes effect August 6, 2026. Freddie Mac's equivalent hit March 3. Both cover all AI in origination and servicing, including vendor tools. Here's what a compliant program actually looks like.

By Rebecca Leung · July 14, 2026 ·
Table of Contents

Freddie Mac’s AI governance requirement took effect March 3. Most mortgage lenders either barely noticed or treated it as a vendor pass-through. That logic doesn’t survive Fannie Mae’s August 6 deadline — and it didn’t survive Freddie Mac’s March 3 deadline either.

TL;DR

  • Freddie Mac’s AI/ML governance requirements (Guide Section 1302.8) went live March 3, 2026, requiring documented programs, NIST 800-53 and ISO 27001 alignment, senior management approval, and active monitoring for drift and bias
  • Fannie Mae’s LL-2026-04 takes effect August 6, 2026, requiring documented governance programs for any seller or servicer using AI in origination or servicing
  • Both requirements extend to vendor and subcontractor AI under a “no less protective” standard — third-party documentation gaps are your compliance gaps
  • Neither framework is limited to credit decisioning: fraud detection, document intelligence, chatbots, income tools, and borrower communications are all in scope
  • Most lenders are running a materially incomplete program right now, even if they think they aren’t

Why the GSEs Got Here

Fannie Mae and Freddie Mac don’t supervise banks. They govern the terms under which sellers deliver loans and servicers manage them. That distinction matters for how you think about this requirement: it isn’t a prudential regulatory mandate from the OCC or FDIC. It’s a contract requirement embedded in your seller/servicer agreement. Violations don’t result in an MRA or consent order. They result in repurchase demands, indemnification claims, and in the worst case, termination of seller/servicer approval.

The practical pressure driving this is the explosive growth of AI in the mortgage process. Lenders are using automated document review, AI-assisted income verification, fraud detection models, and natural language tools for borrower communications — sometimes without compliance teams knowing the full inventory. The GSEs carry credit risk on a significant portion of the loans these tools are used to originate and service. They have direct financial exposure to AI model failures that produce inaccurate income calculations, miss fraud signals, or generate biased outputs that produce discriminatory lending patterns.

This isn’t a theoretical governance concern. It’s a counterparty risk problem — and the GSEs are now managing it through seller/servicer obligations.

What Freddie Mac Required (Already in Effect Since March 3, 2026)

Freddie Mac updated its Seller/Servicer Guide in December 2025 with Guide Section 1302.8, effective March 3, 2026. The framework is built around three core principles: transparency (know where you’re using AI), accountability (assign clear ownership of each system’s risk), and ethical stewardship (operate controls and monitoring in practice, not just on paper).

The specific requirements are more detailed than most enterprise AI policies:

AI inventory across the full loan lifecycle. Every place where AI or ML touches loan origination or servicing must be identified — not just the underwriting engine. This includes vendors embedded in document processing, fraud detection, quality control, customer communications, and payment processing. If a tool used anywhere in your mortgage workflow has AI functionality, it belongs in the inventory.

Audits mapped to named standards. Regular internal and external audits are required. Critically, Freddie Mac specifically named NIST 800-53 and ISO 27001 as the baseline audit standards. This is meaningfully more specific than frameworks that reference “industry standards” without naming them — and it means lenders using AI governance programs built to generic checklists may not satisfy the requirement.

Ongoing performance and bias monitoring. Sellers and servicers must monitor AI/ML systems for performance degradation and bias on a continuous basis, not just at initial deployment.

Segregation of duties. Documented accountability structures must separate those who develop or configure AI systems from those who approve and monitor them.

Senior management approval. AI/ML policies must be approved by at minimum the chief information officer, chief technology officer, chief information security officer, or chief risk officer.

If your existing AI governance program doesn’t meet these criteria — documented, audited against named standards, actively monitored, officer-approved, with vendor scope — Freddie Mac’s March 3 deadline has already passed you.

What Fannie Mae LL-2026-04 Requires (Effective August 6, 2026)

Fannie Mae’s LL-2026-04 takes a principles-based approach rather than prescribing specific control standards. The core requirement: any seller or servicer that uses AI or ML in origination or servicing must operate under a documented, actively maintained governance program.

The specific program elements:

Written policies and procedures covering the development, implementation, use, and maintenance of any AI/ML system. Policies must be reviewed and updated at least annually, communicated to relevant staff, grounded in applicable legal and regulatory requirements, calibrated to the institution’s own risk tolerance, and assigned to a designated owner.

Full lifecycle coverage. The policies must address the entire AI lifecycle from design and training data governance through deployment, monitoring, and retirement. This isn’t a deployment checklist — it has to cover every stage.

Vendor and subcontractor governance at the same standard as internal tools. LL-2026-04 explicitly requires sellers and servicers to govern the AI use of vendors, subcontractors, and third-party originators to “no less protective” standards than they apply to their own systems.

Disclosure upon request. On request by Fannie Mae, a seller or servicer must promptly disclose: the types of AI/ML used, the purpose and manner of use, the safeguards implemented to manage AI/ML risk, and any other information Fannie Mae may require. “Promptly” is undefined but the practical implication is clear — the documentation must exist now, not be assembled in response to a request.

Comparison: What Each GSE Requires

RequirementFreddie Mac (effective March 3, 2026)Fannie Mae LL-2026-04 (effective August 6, 2026)
AI/ML inventoryRequired — full loan lifecycleImplied by governance program scope
Written policiesRequiredRequired
Annual policy reviewImpliedExplicitly required
Vendor governanceExplicit”No less protective” standard
Audit standardsNIST 800-53, ISO 27001 namedPrinciples-based (no specific standard named)
Bias monitoringOngoing monitoring requiredRisk-calibrated program implied
Senior approvalCIO, CTO, CISO, or CRODesignated owner required
Disclosure obligationFreddie Mac inspection rightsPrompt disclosure upon request

Neither framework is limited to credit decisioning or underwriting. Both cover the entire origination and servicing technology stack wherever AI or ML is present.

The Part Most Lenders Are Missing: Vendor Scope

Both frameworks apply to vendor AI. Not just in-house models. Every AI or ML tool embedded in the loan lifecycle from any source.

Consider a typical lender’s technology stack: a point-of-sale platform with AI document extraction, a third-party income verification service using ML models, a fraud detection vendor, a servicing platform with AI-assisted payment processing, an outbound communications tool using generative AI for borrower messages, a quality control platform with automated review flags. Each of these vendors is using AI. Each is in scope under both GSE frameworks.

Most lenders’ current AI governance programs — to the extent they exist — cover the underwriting model and perhaps proprietary internal tools. They don’t govern vendor AI with meaningful rigor. When Fannie Mae requests disclosure of the AI tools in use across origination and servicing, a lender without a vendor AI inventory cannot answer the question accurately.

This is the structural gap: lenders don’t know their full AI footprint, so they can’t document governance over what they haven’t inventoried. The first step is not writing a policy. It’s conducting the inventory.

For the vendor governance piece specifically, the questions to ask vendors mirror standard TPRM due diligence: What AI/ML tools do you use in connection with our mortgage business? What is your model governance policy? How do you test for and monitor bias? What audit rights do you provide? What are your incident notification procedures for AI failures? The third-party AI vendor due diligence framework covers the specific questions and documentation to request.

Building a Compliant Program: A 22-Day Playbook

With 22 days to August 6, a lender starting today has enough time to close material gaps if there is a framework to populate — not enough to build one from scratch. The following sequence gets you to a defensible minimum:

Week 1: Run the AI/ML inventory. Survey product, technology, and operations leads across origination and servicing. Document every AI tool in use, including vendor-provided tools. The survey should capture: what the tool does, who owns it, what data it processes, whether it touches consumer-facing outputs, and whether the vendor has its own AI governance program. This is the foundational step — everything else depends on knowing what’s in your stack.

Week 1-2: Assess vendor documentation. For each vendor AI tool identified: confirm you have the vendor’s AI governance policies, any relevant audit attestations (SOC 2 reports, penetration test results), and contractual provisions covering AI-specific obligations — bias testing, incident notification, model governance. Send a request to any vendor where documentation is missing. Document what you’ve requested and when.

Week 2: Write or update the AI governance policy. The policy must cover development, implementation, use, and maintenance of AI/ML — including vendor tools. Assign a designated owner. Build in annual review. The policy doesn’t have to be long but must be documented, accurate, and reflective of your actual AI inventory.

Week 2-3: Establish monitoring cadences. Freddie Mac requires ongoing monitoring for performance degradation and bias. Fannie Mae requires programs calibrated to risk tolerance. Build a monitoring schedule: what gets monitored, at what frequency, who reviews, and what triggers remediation or escalation.

Week 3: Get officer-level sign-off. Freddie Mac explicitly requires CIO, CTO, CISO, or CRO approval of AI/ML policies. Fannie Mae requires designation of a program owner. Convene the appropriate executives, walk through the inventory and program scope, and document the approval.

For lenders who want a structured framework to populate rather than building from scratch, the NIST AI RMF MEASURE function provides the evaluation and testing methodology that maps closely to what Freddie Mac’s bias monitoring and performance monitoring requirements require in practice.

What Happens If You’re Not Ready by August 6

Fannie Mae has not announced a specific enforcement timeline tied to the August 6 effective date. But the disclosure right embedded in LL-2026-04 gives Fannie Mae ongoing authority to request your documentation at any time. More immediately, your certifications under the seller/servicer agreement — which require compliance with the guide — become legally questionable if you knowingly use AI tools without the governance the letter requires.

The more practical risk is downstream: when the first repurchase demand or indemnification claim is tied to an AI-related error — an income calculation the model got wrong, a fraud detection tool that missed something material, a borrower communication that was generated by AI and was inaccurate — the question will be what your AI governance program looked like at the time of the error. “We hadn’t built one yet” is not a defensible answer once the August 6 effective date has passed.

The GSE frameworks also set the floor for what regulators, state AGs, and class action plaintiffs will expect to see when AI failures produce consumer harm in mortgage transactions. The EU AI Act high-risk AI framework documents what “high-risk” AI governance documentation requirements look like at the international standard — worth reviewing for firms with any EU operations alongside the GSE-specific requirements.

So What?

If Freddie Mac’s March 3 deadline passed without a formal AI governance program, August 6 is the remediation window.

Three things to do this week:

  1. Run the AI/ML inventory. You cannot govern what you cannot see. Build the full list before you write the policy.
  2. Identify vendor documentation gaps. For each vendor AI tool, confirm you have their governance documentation or request it now. Missing documentation is a gap under both GSE frameworks.
  3. Assign an owner. Both frameworks require a designated program owner. If no one is accountable for AI governance, that’s the first structural fix.

The window between now and August 6 is tight but workable. The window between August 6 and Fannie Mae’s first documentation request is unknown — which is why the work needs to happen now, not after the deadline.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is Fannie Mae LL-2026-04?
Lender Letter LL-2026-04 is Fannie Mae's AI and machine learning governance framework for single-family sellers and servicers. It requires any Fannie Mae-approved seller or servicer using AI or ML in origination or servicing to operate under a documented, actively maintained governance program. The requirements are effective August 6, 2026.
When did Freddie Mac's AI governance requirement take effect?
Freddie Mac's requirement (Guide Section 1302.8, announced in Bulletins 2025-16 and 2025-17 in December 2025) took effect March 3, 2026. Sellers and servicers were required to implement an auditable AI governance program covering inventory, risk assessment, regular audits aligned to NIST 800-53 and ISO 27001, ongoing monitoring, segregation of duties, and senior management sign-off from the CIO, CTO, CISO, or CRO.
Does the AI governance requirement only apply to credit decisioning models?
No. Both LL-2026-04 and Freddie Mac Section 1302.8 cover any AI or ML used anywhere in origination or servicing — underwriting automation, document processing, fraud detection, income calculation, chatbots, quality control, borrower communications, payment processing. The scope is the full loan lifecycle.
What does Fannie Mae mean by 'no less protective' for vendor governance?
LL-2026-04 requires sellers and servicers to apply the same AI governance standards to vendors, subcontractors, and third-party originators that they apply internally. If your document processing vendor or income verification tool uses AI and you have no documented governance over it, that's your compliance gap — not the vendor's.
What information must a lender produce to Fannie Mae 'upon request'?
Upon request, sellers and servicers must promptly disclose: the types of AI/ML used, the purpose and manner of use, the safeguards implemented to manage AI/ML risk, and any other information Fannie Mae may require. The practical implication is that this documentation must exist before Fannie Mae asks — not be assembled in response to the request.
What's the minimum a lender needs in place by August 6?
At minimum: an inventory of all AI/ML in origination and servicing (including vendor tools), written policies covering the AI lifecycle (development, implementation, use, maintenance), a designated program owner, annual review, and documented governance over vendor AI at the same standard as internal tools. Freddie Mac's framework adds NIST 800-53 and ISO 27001 alignment, segregation of duties, and active monitoring for model drift and bias.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.