Fannie Mae’s AI Governance Requirements Are Now in Effect: What Lenders Should Expect from Their Third Party Vendors

August 12, 2026
Fannie Mae’s new artificial intelligence (AI) and machine learning (ML) governance framework went into effect for Seller/Servicers on August 6, 2026 (Lender Letter LL-2026-04). While the guidance directly targets industry participants selling to or servicing for Fannie Mae, its operational reach extends heavily into the third-party vendor ecosystem. As lenders implement required risk management policies, […]

Fannie Mae’s new artificial intelligence (AI) and machine learning (ML) governance framework went into effect for Seller/Servicers on August 6, 2026 (Lender Letter LL-2026-04). While the guidance directly targets industry participants selling to or servicing for Fannie Mae, its operational reach extends heavily into the third-party vendor ecosystem. As lenders implement required risk management policies, evaluating how AI is deployed across their third-party vendor ecosystem is critical.

Fannie Mae’s framework underscores that Seller/Servicers remain fully accountable for the quality, safety, and compliance of AI/ML tools used in origination and servicing. Consequently, vendor due diligence must evaluate how third-party AI/ML systems operate, how risks are mitigated, and how generated outputs are verified.

Core Requirements Under Lender Letter LL-2026-04

Fannie Mae’s framework reinforces that Seller/Servicers remain fully accountable for the quality, safety, and compliance of AI/ML tools used throughout the origination and servicing lifecycle. Under the directive, organizations utilizing AI/ML tools must satisfy three primary pillars:

  1. Governance Policies: Maintain written, actively managed policies covering the full life cycle of AI/ML systems—reviewed at least annually—that incorporate ethical standards, regulatory requirements, and clear ownership.
  2. Information Security & Resiliency Standards: Comply with all data security, incident management, and business resiliency requirements set forth in the Fannie Mae Information Security and Business Resiliency Supplement (published September 2, 2025).
  3. Vendor & Subcontractor Oversight: Manage third-party vendor and subcontractor AI/ML risks under standards no less protective than those applied to internal systems.

Because Fannie Mae explicitly connects AI governance to its Information Security and Business Resiliency Supplement, vendor risk evaluations must address not only model accuracy and bias, but also data security, system resilience, and incident response capability.

Key Questions Organizations Should Ask Third Party Vendors

As lenders and servicers conduct vendor risk assessments under Fannie Mae's framework, key questions to ask when evaluating tech providers include:

  • Scope & Function: How is AI incorporated into the product or service? Is it restricted to administrative or operational tasks or does it drive decision-making, eligibility determinations, or document creation?
  • Governance Frameworks: What formal governance policies, change-management protocols, and oversight govern the development, deployment, and ongoing monitoring of the use of AI/ML?
  • Information Security & Resiliency: Does the vendor align with Fannie Mae’s Information Security and Business Resiliency Supplement standards, including data encryption, access controls, and business continuity protocols?
  • Data Privacy & Security: Is non-public personal information (NPI) or borrower data shared with third-party AI platforms? What safeguards prevent borrower data from being used to train external models?
  • Disclosure & Regulatory Audit Support: Is the vendor prepared to supply the necessary documentation and transparency to support disclosure obligations to Fannie Mae and/or regulators?

Categorizing Risk Across the Vendor Ecosystem

Not all AI applications present the same level of risk. Administrative functions such as document classification, data extraction, or workflow automation generally present different governance considerations than AI/ML tools used to calculate borrower income, evaluate collateral, draft legal provisions, or automate credit decisions. Understanding where each vendor sits on this spectrum is essential for determining vendor risk.

We’re Here to Help

At Asurity, we recognize that our clients require innovative technology backed by robust governance, legal oversight, and enterprise compliance controls and remain committed to responsible AI/ML deployment.

If you have questions about Asurity’s use of AI/ML or need documentation regarding Asurity’s security and compliance framework to support your third-party risk assessments, please contact your Asurity representative or email support@asurity.com.

Sign up for news + updates

Expert insights and regulatory updates on RegTech, compliance management, and fair lending.

Recommended Resources

What Sets RegCheck Apart

Discover how RegCheck® delivers smarter mortgage compliance reviews through loan-specific testing, configurable compliance logic, built-in expertise, and support for evolving industry standards.

Propel Smarter DSCR Lending — Built for Investor Success

Discover how Propel™ streamlines DSCR loan production. Generate compliant DSCR documentation nationwide, close faster, and scale investor lending with seamless integration and compliance-first automation.

Propel™ by Asurity - Case Study: Proprietary LOS Integration

Find out why a top-ten mortgage lender with a proprietary loan origination system (LOS) needed to convert from a legacy document platform.

chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram