March 3, 2026
Freddie Mac — Guide Section 1302.8 (Bulletin 2025-16)
August 6, 2026
Fannie Mae — Lender Letter LL-2026-04
June 11, 2026
MISMO FRAME (Framework for Responsible AI in Mortgage Ecosystems)
Purpose & Scope
Why this policy exists
Artificial intelligence and machine learning are now embedded across the mortgage lifecycle — from intake and document processing to underwriting, pricing, fraud detection, quality control, and servicing. Fannie Mae and Freddie Mac have translated long-standing fair lending and consumer protection expectations into concrete governance requirements that directly condition a lender's ability to sell loans into the secondary market. MISMO's FRAME provides the industry's common toolkit for operationalizing those expectations.
This policy establishes how MWP governs the AI/ML systems we operate and the AI capabilities embedded in the tools we integrate on our clients' behalf. It applies broadly — internally developed and vendor-provided systems alike, and across every AI touchpoint in origination and servicing, not only underwriting.
This policy covers:
- WorkflowCoach™ workflow documentation, governance, and analytics features that incorporate AI assistance.
- AI-assisted workflow extraction, transcription, summarization, and future-state design tooling.
- Any vendor-embedded AI capabilities in tools we integrate with on behalf of clients (document classification, income/asset verification, fraud detection, pricing, and similar).
- Internal productivity AI used by MWP staff in connection with origination or servicing support activities.
WorkflowCoach™ does not ingest, process, or access borrower data
WorkflowCoach™ is a workflow documentation, governance, and analytics platform. It is exclusively focused on workflow and technical configuration data — process steps, system settings, and operational metadata. It never ingests, stores, or has access to any borrower, loan applicant, or consumer personally identifiable information (PII), loan file data, credit data, or underwriting decision data. Any AI/ML features embedded in WorkflowCoach™ operate solely on the workflow and technical data described above.
Governance Principles
The six principles we hold every AI system to
Transparency
We maintain a current inventory of every AI/ML system we use, its purpose, the data it touches, and the decisions it informs. We can disclose, upon request, the types of AI systems in use and the safeguards that mitigate associated risk.
Accountability
AI governance is owned by designated leadership and embedded in enterprise risk management. The CEO — who at MWP performs the CIO, CTO, CISO, and Chief Risk Officer roles — approves this policy and reviews it at least annually.
Ethical & Trustworthy AI
We commit to fair, responsible, non-discriminatory use of AI. Models are assessed for bias, adverse-action explainability is preserved, and human judgment remains in the loop for consumer-impacting decisions.
Security & Integrity
We assess and mitigate AI-specific threats — including data poisoning, adversarial inputs, and prompt injection — as part of our information security program, distinct from traditional software controls.
Ongoing Monitoring
We monitor for model drift, performance degradation, and emerging risk across the full lifecycle — development, deployment, use, maintenance, and retirement — and reassess when systems, data, or vendors change.
Vendor Stewardship
Third-party and subcontractor AI use is governed no less protectively than our own. Responsibility for AI outcomes does not transfer to vendors; we retain oversight of every AI touchpoint in the loan lifecycle.
Operational Framework
The AI system lifecycle we follow
Every AI/ML system we use passes through six governed phases. This operationalizes the inventory-assess-monitor-govern approach recommended by MISMO FRAME and required by the GSEs.
Identify & Inventory
Maintain a centralized AI System Inventory of all internally developed and vendor-provided AI/ML used in origination or servicing, including the function it performs and the data it processes.
Assess & Classify
Perform an AI System Risk Assessment for each system, tiering by materiality, borrower impact, and decisioning influence. High-risk systems receive enhanced oversight and review cadence.
Approve & Deploy
Deployment requires documented approval by the system owner and, for high-risk systems, sign-off from senior management. Legal, compliance, risk, and security review is completed before go-live.
Monitor & Maintain
Ongoing monitoring for model drift, bias, performance, and security threats. Vendor changes, model updates, and new capabilities trigger documented reassessment.
Disclose & Document
Upon request, we disclose the types of AI systems used, their purposes, and the safeguards in place. Decision traceability and audit-ready evidence are retained for the life of the program.
Retire & Remediate
Retirement of an AI system follows a controlled decommission process. Issues identified through monitoring or audit are remediated through documented corrective action with owner accountability.
Compliance Mapping
How this policy maps to each published framework
The table below maps the published AI governance requirements of Fannie Mae, Freddie Mac, and MISMO to the specific controls MWP maintains under this policy.
Fannie Mae — Lender Letter LL-2026-04
Documented, actively maintained AI/ML governance program
This policy, owned and reviewed at least annually by designated leadership.
Written policies covering the full AI/ML lifecycle
Lifecycle framework below — identify, assess, approve, monitor, disclose, retire.
Reflect applicable legal & regulatory requirements
Aligned to ECOA/Reg B, Fair Housing Act, GLBA, state fair lending, and FHFA guidance.
Incorporate trustworthy & ethical AI principles
Six governance principles above — transparency, accountability, fairness, security, monitoring, vendor stewardship.
Aligned to risk tolerance; communicated to personnel
Risk-tiered oversight; policy distributed to all relevant staff with acknowledgment.
Transparency & disclosure upon request
AI System Inventory and disclosure capability maintained for seller/servicer and counterparty requests.
Vendor/subcontractor AI risk no less protective than internal
Vendor AI governance standard applied uniformly; responsibility retained, not transferred.
Senior leadership oversight embedded in ERM
CEO serves as CIO/CTO/CISO/CRO; policy approved and annually reviewed; integrated into enterprise risk management.
Freddie Mac — Seller/Servicer Guide Section 1302.8
Legal/regulatory requirements understood, managed, documented
Regulatory change management tracks AI requirements through impact analysis and documented implementation.
Risk management — identify, measure, manage (ongoing program)
AI System Risk Assessment per system; ongoing monitoring — not a one-time assessment.
Transparency — no black boxes
Documented purpose, data lineage, and decisioning influence for every system in inventory.
Accountability — oversight, escalation, where the buck stops
Named system owners, defined escalation paths, documented risk-acceptance decisions.
Ethical standards — fair, responsible, compliant
Bias assessment, adverse-action explainability review, human-in-the-loop for consumer decisions.
Audit trail — prove all of the above
Audit-ready evidence retained: approvals, exceptions, monitoring results, vendor assessments.
Senior management approval (CIO/CTO/CISO/CRO)
Policy approved and annually re-approved by the CEO, who performs these roles at MWP.
Security & integrity (data poisoning, adversarial inputs)
AI-specific threat assessment within the information security program.
Vendor AI governance — responsibility retained
Standardized vendor oversight questions, certifications, and change-triggered reassessment.
Model drift monitoring (FHFA AB 2022-02)
Ongoing performance and bias monitoring; reassessment on material change.
MISMO FRAME
Governance Policy template adoption
This policy serves as MWP's adopted AI Governance Policy, structured to FRAME conventions.
AI System Inventory
Centralized inventory of all AI-enabled systems used across the business, maintained and reviewed.
AI System Risk Assessment
Per-system risk assessment aligned to FRAME methodology, tiered by materiality and borrower impact.
Implementation guidance & Getting Started Guide alignment
Lifecycle framework operationalizes FRAME's inventory, assess, monitor, govern approach.
Alignment with broader AI governance standards
Cross-referenced to NIST AI RMF and FHFA Advisory Bulletin 2022-02 principles.
Risk Management
How we identify, measure, and manage AI risk
Governance & Accountability
Who owns this policy
Policy owner: The Chief Executive Officer, who at MWP performs the roles of Chief Risk Officer, Chief Information Officer, Chief Technology Officer, and Chief Information Security Officer. This policy is approved by the CEO and reviewed and updated at least annually, or sooner upon material regulatory or operational change.
Roles: Legal, compliance, risk management, information security, and senior leadership each hold defined roles in AI governance. AI governance is not delegated solely to technology teams.
Audit readiness: Documentation — approvals, exceptions, monitoring results, vendor assessments, and risk-acceptance decisions — is retained and can be produced on request.
Authoritative Sources
Published frameworks this policy aligns to
- Fannie Mae — Lender Letter LL-2026-04 (Governance framework for AI/ML)
- Freddie Mac — Seller/Servicer Guide Section 1302.8 (Use of AI and ML)
- Freddie Mac — Guide Bulletin 2025-16
- FHFA — Advisory Bulletin AB 2022-02 (AI and ML Risk Management)
- MISMO — FRAME: Framework for Responsible AI in Mortgage Ecosystems
Questions & Disclosure
How to reach us
Upon request, MWP will disclose the types of AI systems used, their purposes, and the safeguards in place to mitigate risk, consistent with Fannie Mae's transparency requirements. For AI governance inquiries, disclosure requests, or vendor oversight coordination:
AI Governance Team
support@mwpinc.comMortgage Workflow Partners, Inc. · Encompass® and WorkflowCoach™