Home
Public Policy · Last reviewed August 2026

AI Governance Policy

Mortgage Workflow Partners' (MWP) framework for the responsible, transparent, and accountable use of artificial intelligence and machine learning across the loan lifecycle — aligned to the published requirements of Fannie Mae, Freddie Mac, and MISMO.

In effect

March 3, 2026

Freddie Mac — Guide Section 1302.8 (Bulletin 2025-16)

In effect

August 6, 2026

Fannie Mae — Lender Letter LL-2026-04

Published

June 11, 2026

MISMO FRAME (Framework for Responsible AI in Mortgage Ecosystems)

Purpose & Scope

Why this policy exists

Artificial intelligence and machine learning are now embedded across the mortgage lifecycle — from intake and document processing to underwriting, pricing, fraud detection, quality control, and servicing. Fannie Mae and Freddie Mac have translated long-standing fair lending and consumer protection expectations into concrete governance requirements that directly condition a lender's ability to sell loans into the secondary market. MISMO's FRAME provides the industry's common toolkit for operationalizing those expectations.

This policy establishes how MWP governs the AI/ML systems we operate and the AI capabilities embedded in the tools we integrate on our clients' behalf. It applies broadly — internally developed and vendor-provided systems alike, and across every AI touchpoint in origination and servicing, not only underwriting.

This policy covers:

  • WorkflowCoach™ workflow documentation, governance, and analytics features that incorporate AI assistance.
  • AI-assisted workflow extraction, transcription, summarization, and future-state design tooling.
  • Any vendor-embedded AI capabilities in tools we integrate with on behalf of clients (document classification, income/asset verification, fraud detection, pricing, and similar).
  • Internal productivity AI used by MWP staff in connection with origination or servicing support activities.

WorkflowCoach™ does not ingest, process, or access borrower data

WorkflowCoach™ is a workflow documentation, governance, and analytics platform. It is exclusively focused on workflow and technical configuration data — process steps, system settings, and operational metadata. It never ingests, stores, or has access to any borrower, loan applicant, or consumer personally identifiable information (PII), loan file data, credit data, or underwriting decision data. Any AI/ML features embedded in WorkflowCoach™ operate solely on the workflow and technical data described above.

Governance Principles

The six principles we hold every AI system to

Transparency

We maintain a current inventory of every AI/ML system we use, its purpose, the data it touches, and the decisions it informs. We can disclose, upon request, the types of AI systems in use and the safeguards that mitigate associated risk.

Accountability

AI governance is owned by designated leadership and embedded in enterprise risk management. The CEO — who at MWP performs the CIO, CTO, CISO, and Chief Risk Officer roles — approves this policy and reviews it at least annually.

Ethical & Trustworthy AI

We commit to fair, responsible, non-discriminatory use of AI. Models are assessed for bias, adverse-action explainability is preserved, and human judgment remains in the loop for consumer-impacting decisions.

Security & Integrity

We assess and mitigate AI-specific threats — including data poisoning, adversarial inputs, and prompt injection — as part of our information security program, distinct from traditional software controls.

Ongoing Monitoring

We monitor for model drift, performance degradation, and emerging risk across the full lifecycle — development, deployment, use, maintenance, and retirement — and reassess when systems, data, or vendors change.

Vendor Stewardship

Third-party and subcontractor AI use is governed no less protectively than our own. Responsibility for AI outcomes does not transfer to vendors; we retain oversight of every AI touchpoint in the loan lifecycle.

Operational Framework

The AI system lifecycle we follow

Every AI/ML system we use passes through six governed phases. This operationalizes the inventory-assess-monitor-govern approach recommended by MISMO FRAME and required by the GSEs.

1

Identify & Inventory

Maintain a centralized AI System Inventory of all internally developed and vendor-provided AI/ML used in origination or servicing, including the function it performs and the data it processes.

2

Assess & Classify

Perform an AI System Risk Assessment for each system, tiering by materiality, borrower impact, and decisioning influence. High-risk systems receive enhanced oversight and review cadence.

3

Approve & Deploy

Deployment requires documented approval by the system owner and, for high-risk systems, sign-off from senior management. Legal, compliance, risk, and security review is completed before go-live.

4

Monitor & Maintain

Ongoing monitoring for model drift, bias, performance, and security threats. Vendor changes, model updates, and new capabilities trigger documented reassessment.

5

Disclose & Document

Upon request, we disclose the types of AI systems used, their purposes, and the safeguards in place. Decision traceability and audit-ready evidence are retained for the life of the program.

6

Retire & Remediate

Retirement of an AI system follows a controlled decommission process. Issues identified through monitoring or audit are remediated through documented corrective action with owner accountability.

Compliance Mapping

How this policy maps to each published framework

The table below maps the published AI governance requirements of Fannie Mae, Freddie Mac, and MISMO to the specific controls MWP maintains under this policy.

Fannie Mae — Lender Letter LL-2026-04

Documented, actively maintained AI/ML governance program

This policy, owned and reviewed at least annually by designated leadership.

Written policies covering the full AI/ML lifecycle

Lifecycle framework below — identify, assess, approve, monitor, disclose, retire.

Reflect applicable legal & regulatory requirements

Aligned to ECOA/Reg B, Fair Housing Act, GLBA, state fair lending, and FHFA guidance.

Incorporate trustworthy & ethical AI principles

Six governance principles above — transparency, accountability, fairness, security, monitoring, vendor stewardship.

Aligned to risk tolerance; communicated to personnel

Risk-tiered oversight; policy distributed to all relevant staff with acknowledgment.

Transparency & disclosure upon request

AI System Inventory and disclosure capability maintained for seller/servicer and counterparty requests.

Vendor/subcontractor AI risk no less protective than internal

Vendor AI governance standard applied uniformly; responsibility retained, not transferred.

Senior leadership oversight embedded in ERM

CEO serves as CIO/CTO/CISO/CRO; policy approved and annually reviewed; integrated into enterprise risk management.

Freddie Mac — Seller/Servicer Guide Section 1302.8

Legal/regulatory requirements understood, managed, documented

Regulatory change management tracks AI requirements through impact analysis and documented implementation.

Risk management — identify, measure, manage (ongoing program)

AI System Risk Assessment per system; ongoing monitoring — not a one-time assessment.

Transparency — no black boxes

Documented purpose, data lineage, and decisioning influence for every system in inventory.

Accountability — oversight, escalation, where the buck stops

Named system owners, defined escalation paths, documented risk-acceptance decisions.

Ethical standards — fair, responsible, compliant

Bias assessment, adverse-action explainability review, human-in-the-loop for consumer decisions.

Audit trail — prove all of the above

Audit-ready evidence retained: approvals, exceptions, monitoring results, vendor assessments.

Senior management approval (CIO/CTO/CISO/CRO)

Policy approved and annually re-approved by the CEO, who performs these roles at MWP.

Security & integrity (data poisoning, adversarial inputs)

AI-specific threat assessment within the information security program.

Vendor AI governance — responsibility retained

Standardized vendor oversight questions, certifications, and change-triggered reassessment.

Model drift monitoring (FHFA AB 2022-02)

Ongoing performance and bias monitoring; reassessment on material change.

MISMO FRAME

Governance Policy template adoption

This policy serves as MWP's adopted AI Governance Policy, structured to FRAME conventions.

AI System Inventory

Centralized inventory of all AI-enabled systems used across the business, maintained and reviewed.

AI System Risk Assessment

Per-system risk assessment aligned to FRAME methodology, tiered by materiality and borrower impact.

Implementation guidance & Getting Started Guide alignment

Lifecycle framework operationalizes FRAME's inventory, assess, monitor, govern approach.

Alignment with broader AI governance standards

Cross-referenced to NIST AI RMF and FHFA Advisory Bulletin 2022-02 principles.

Risk Management

How we identify, measure, and manage AI risk

Every AI system in our inventory is assessed for materiality, borrower impact, decisioning influence, data sensitivity, and security exposure. Systems are tiered, and high-risk systems receive enhanced oversight, more frequent re-assessment, and senior-management sign-off before deployment. This is an ongoing program, not a one-time assessment.

Governance & Accountability

Who owns this policy

Policy owner: The Chief Executive Officer, who at MWP performs the roles of Chief Risk Officer, Chief Information Officer, Chief Technology Officer, and Chief Information Security Officer. This policy is approved by the CEO and reviewed and updated at least annually, or sooner upon material regulatory or operational change.

Roles: Legal, compliance, risk management, information security, and senior leadership each hold defined roles in AI governance. AI governance is not delegated solely to technology teams.

Audit readiness: Documentation — approvals, exceptions, monitoring results, vendor assessments, and risk-acceptance decisions — is retained and can be produced on request.

Authoritative Sources

Published frameworks this policy aligns to

Questions & Disclosure

How to reach us

Upon request, MWP will disclose the types of AI systems used, their purposes, and the safeguards in place to mitigate risk, consistent with Fannie Mae's transparency requirements. For AI governance inquiries, disclosure requests, or vendor oversight coordination:

AI Governance Team

support@mwpinc.com

Mortgage Workflow Partners, Inc. · Encompass® and WorkflowCoach™

© 2026 Mortgage Workflow Partners, Inc. This AI Governance Policy is published for public review and may be updated to reflect evolving regulatory requirements.Contact us

Encompass® is a registered trademark of ICE Mortgage Technology. WorkflowCoach™ is a trademark of Mortgage Workflow Partners, Inc. Fannie Mae, Freddie Mac, and MISMO are referenced solely to identify the published frameworks this policy aligns to.