Discover how RegCheck® delivers smarter mortgage compliance reviews through loan-specific testing, configurable compliance logic, built-in expertise, and support for evolving industry standards.

Fannie Mae’s new artificial intelligence (AI) and machine learning (ML) governance framework went into effect for Seller/Servicers on August 6, 2026 (Lender Letter LL-2026-04). While the guidance directly targets industry participants selling to or servicing for Fannie Mae, its operational reach extends heavily into the third-party vendor ecosystem. As lenders implement required risk management policies, evaluating how AI is deployed across their third-party vendor ecosystem is critical.
Fannie Mae’s framework underscores that Seller/Servicers remain fully accountable for the quality, safety, and compliance of AI/ML tools used in origination and servicing. Consequently, vendor due diligence must evaluate how third-party AI/ML systems operate, how risks are mitigated, and how generated outputs are verified.
Fannie Mae’s framework reinforces that Seller/Servicers remain fully accountable for the quality, safety, and compliance of AI/ML tools used throughout the origination and servicing lifecycle. Under the directive, organizations utilizing AI/ML tools must satisfy three primary pillars:
Because Fannie Mae explicitly connects AI governance to its Information Security and Business Resiliency Supplement, vendor risk evaluations must address not only model accuracy and bias, but also data security, system resilience, and incident response capability.
As lenders and servicers conduct vendor risk assessments under Fannie Mae's framework, key questions to ask when evaluating tech providers include:
Not all AI applications present the same level of risk. Administrative functions such as document classification, data extraction, or workflow automation generally present different governance considerations than AI/ML tools used to calculate borrower income, evaluate collateral, draft legal provisions, or automate credit decisions. Understanding where each vendor sits on this spectrum is essential for determining vendor risk.
At Asurity, we recognize that our clients require innovative technology backed by robust governance, legal oversight, and enterprise compliance controls and remain committed to responsible AI/ML deployment.
If you have questions about Asurity’s use of AI/ML or need documentation regarding Asurity’s security and compliance framework to support your third-party risk assessments, please contact your Asurity representative or email support@asurity.com.
Discover how RegCheck® delivers smarter mortgage compliance reviews through loan-specific testing, configurable compliance logic, built-in expertise, and support for evolving industry standards.
Discover how Propel™ streamlines DSCR loan production. Generate compliant DSCR documentation nationwide, close faster, and scale investor lending with seamless integration and compliance-first automation.
Find out why a top-ten mortgage lender with a proprietary loan origination system (LOS) needed to convert from a legacy document platform.