When your AI vendor gets it wrong, you’re still responsible
Mortgage servicers are misreading the current moment. Enforcement looks quiet, but accountability has never been broader. The Consumer Financial Protection Bureau (CFPB) has issued zero consent orders against servicers in 2026. Enforcement staffing is being cut by 80%, and the Office of the Comptroller of the Currency’s (OCC) most significant mortgage action this year touches VA origination, not servicing. Some servicers may read the lack of enforcement as a reprieve. The enforcement gap is real, but the compliance burden is not shrinking. What happened is a fracture. Three non-overlapping AI governance regimes are now in effect, and they don’t form a unified standard. They do, however, create a maze that every servicer will need to navigate without a map, with the same accountability question: When AI models make bad calls on account decisions, who owns the outcomes? The answer, under every framework in effect today, is the servicer, not their AI vendor. The first regime is traditional model risk governance under OCC Bulletin 2026-13 and SR 26-2, issued April 17, 2026. The most meaningful change here is vendor parity. Third-party models now carry the same validation, monitoring and outcomes-analysis requirements as internal models. If a vendor’s scoring tool influences an account-level decision, your model risk management (MRM) program owns that tool and must be able to explain it. And sorry, SOC 2 reports don’t satisfy a model validation question. They never did. At the same time, OCC 2026-13 explicitly excludes generative and agentic AI, calling them ‘novel and rapidly evolving.’ But those are exactly the tools servicers are deploying today, and they sit outside the guidance. The second regime is the GSE contractual mandates, with Freddie Mac Bulletin 2025-16 as the anchor. It has been in force since March 3, 2026, and requires documented AI governance with CIO, CTO, CISO or CRO sign-off, audits mapped to NIST 800-53 and ISO 27001, continuous bias monitoring and explicit safeguards against prompt injection, data poisoning and model inversion. Compared to the agencies, Freddie is much more prescriptive. The mandate also carries a broad indemnification clause, making non-compliance a direct contractual liability sitting inside your seller/servicer agreements today. Fannie Mae Lender Letter LL-2026-04, effective August 6, 2026, is softer but lands in a similar place. It requires that your vendor’s AI governance meet a standard no less protective than your own. Fannie also reserves the right to demand, without notice, a full inventory of every AI system you operate, including purpose, data classes and safeguards for each system. Could your organization produce that today? Most can’t. The third regime is the Treasury Financial Services AI Risk Management Framework, released February 19, 2026. It’s technically voluntary. But in practice, this is the de facto reference for examiners and internal audit, since no binding federal standard exists for generative tools yet. Its 230 control objectives cover AI governance, data integrity and bias monitoring, model lifecycle management, third-party AI risk and operational resilience. Third-party AI risk is where most servicers fall short today, and that gap almost always lives in the vendor contract. Every servicer wants the benefits vendors promise, but few have built a real risk model to understand the impacts and support them. That urgency gap will be visible the first time an examiner or auditor asks for the inventory. The regulatory guidance playbook vendors operate from is familiar. SOC 2 shows up quickly, compliance gets treated as a feature instead of a shared liability and contracts routinely omit the provisions that actually matter: These aren’t aggressive asks. They’re derived directly from OCC 2026-13 vendor parity expectations, OCC Bulletin 2023-17 third-party risk management and the Fannie and Freddie AI disclosure requirements. The regulatory groundwork already exists. Most sourcing departments just haven’t updated their contract standards to reflect it. They should, regardless of the resistance vendors are likely to raise. Has yours kept up? Adverse action processes are another gap. CFPB Circular 2023-03 remains in force and requires specific, principal-reason explanations tied to the borrower’s actual data and the model’s decision logic.


