When your AI vendor gets it wrong, you’re still responsible 

by Frank Barilone Jr.

Mortgage servicers are misreading the current moment. Enforcement looks quiet, but accountability has never been broader. The Consumer Financial Protection Bureau (CFPB) has issued zero consent orders against servicers in 2026. Enforcement staffing is being cut by 80%, and the Office of the Comptroller of the Currency’s (OCC) most significant mortgage action this year touches VA origination, not servicing. Some servicers may read the lack of enforcement as a reprieve. The enforcement gap is real, but the compliance burden is not shrinking. 

What happened is a fracture. Three non-overlapping AI governance regimes are now in effect, and they don’t form a unified standard. They do, however, create a maze that every servicer will need to navigate without a map, with the same accountability question: When AI models make bad calls on account decisions, who owns the outcomes? The answer, under every framework in effect today, is the servicer, not their AI vendor. 

The regimes 

The first regime is traditional model risk governance under OCC Bulletin 2026-13 and SR 26-2,  issued April 17, 2026. The most meaningful change here is vendor parity. Third-party models now carry the same validation, monitoring and outcomes-analysis requirements as internal models. If a vendor’s scoring tool influences an account-level decision, your model risk management (MRM) program owns that tool and must be able to explain it. And sorry, SOC 2 reports don’t satisfy a model validation question. They never did. 

At the same time, OCC 2026-13 explicitly excludes generative and agentic AI, calling them  ‘novel and rapidly evolving.’ But those are exactly the tools servicers are deploying today, and they sit outside the guidance. 

The second regime is the GSE contractual mandates, with Freddie Mac Bulletin 2025-16 as the anchor. It has been in force since March 3, 2026, and requires documented AI governance with  CIO, CTO, CISO or CRO sign-off, audits mapped to NIST 800-53 and ISO 27001, continuous bias monitoring and explicit safeguards against prompt injection, data poisoning and model inversion. Compared to the agencies, Freddie is much more prescriptive. The mandate also  carries a broad indemnification clause, making non-compliance a direct contractual liability sitting inside your seller/servicer agreements today.  

Fannie Mae Lender Letter LL-2026-04, effective August 6, 2026, is softer but lands in a similar place. It requires that your vendor’s AI governance meet a standard no less protective than your own. Fannie also reserves the right to demand, without notice, a full inventory of every AI 

system you operate, including purpose, data classes and safeguards for each system. Could your organization produce that today? Most can’t. 

The third regime is the Treasury Financial Services AI Risk Management Framework, released  February 19, 2026. It’s technically voluntary. But in practice, this is the de facto reference for examiners and internal audit, since no binding federal standard exists for generative tools yet.  Its 230 control objectives cover AI governance, data integrity and bias monitoring, model lifecycle management, third-party AI risk and operational resilience.  

Third-party AI risk is where most servicers fall short today, and that gap almost always lives in the vendor contract. Every servicer wants the benefits vendors promise, but few have built a real risk model to understand the impacts and support them. That urgency gap will be visible the first time an examiner or auditor asks for the inventory.  

The outlook 

The regulatory guidance playbook vendors operate from is familiar. SOC 2 shows up quickly, compliance gets treated as a feature instead of a shared liability and contracts routinely omit  the provisions that actually matter: 

  • Zero-training data-use prohibitions that cover sub-processors, blocking borrower data from being used to train or improve their foundation models. 
  • Model-change notification clauses requiring advance notice before changes that affect model outputs. 
  • Audit and inspection rights that empower the servicer to examine model behavior and validation documentation. 
  • Termination data retrieval provisions that guarantee that audit logs, override history and source-document mappings are returned to the servicer when the contract ends. 

These aren’t aggressive asks. They’re derived directly from OCC 2026-13 vendor parity expectations, OCC Bulletin 2023-17 third-party risk management and the Fannie and Freddie AI  disclosure requirements. The regulatory groundwork already exists. Most sourcing departments just haven’t updated their contract standards to reflect it. They should, regardless of the resistance vendors are likely to raise. Has yours kept up?  

Adverse action processes are another gap. CFPB Circular 2023-03 remains in force and requires specific, principal-reason explanations tied to the borrower’s actual data and the model’s decision logic. Generic checklist reasons most servicers use today will struggle to satisfy the standard for any servicer that uses AI for loss-mitigation triage, workout eligibility or default communication routing. Interpretability is not a product feature; it’s a compliance requirement.  If you can’t get model-behavior documentation from your vendor sufficient to produce a borrower-specific explanation, you have a Circular 2023-03 problem.

State attorneys general in New York, Massachusetts and California are expanding enforcement activity to fill the federal gap, operating under state Unfair or Deceptive Acts or Practices (UDAP) statutes and the new NY FAIR  Business Practices Act. The Fair Housing Act’s disparate impact standard survived the April 2026 rollback of the Equal Credit Opportunity Act (ECOA). 

Servicers that dismantled or scaled back disparate impact testing in response to the Reg B final rule created FHA exposure and GSE compliance gaps in the same move. The CFPB’s posture may shift with the political winds, but the underlying statutes do not. 

The accountability structure is not ambiguous. When an AI system makes a call, right or wrong,  on loss mitigation decisions, the servicer answers for it under model risk guidance, GSE  contracts, adverse action notice requirements and Fair Housing Act exposure, all at the same time. No vendor compliance slide changes that structure. Don’t be dazzled by cost-savings projections into thinking otherwise. 

Closing the gap is operational. You need: 

  • A current AI use-case inventory covering every servicing tool and every vendor embedded capability 
  • Vendor contracts with the four provisions above 
  • Model validation records that treat third-party tools on par with internal models 
  • Adverse action processes that can produce model-specific reasoning for each denial 

August 6 is the near-term forcing function as Fannie’s Lender Letter goes into effect and closes the GSE loop. But the accountability gap has been a miss in vendor contracts for years.  

AI didn’t change who is responsible. It made that responsibility harder to ignore, and the regulatory environment has run out of patience.

Frank Barilone Jr., MBA, is a product management leader with over 20 years of experience in mortgage servicing and consumer lending, with a focus on vendor governance and AI adoption in regulated financial services. 

This column does not necessarily reflect the opinion of HousingWire’s editorial department and its owners. To contact the editor responsible for this piece: zeb@hwmedia.com. 

REFERENCES 

CFPB Enforcement Collapse / Staffing Cuts Covers claims: (1) zero CFPB consent orders  against mortgage servicers in 2026 to date; (2) enforcement staffing cut 80 percent (254  to 50 staff); (3) overall headcount reduction from 1,723 to 556. Source: CFPB Workforce  Reduction Plan filed March 31, 2026 in NTEU v. Vought, U.S. District Court for D.C.  Reported by American Banker (April 1, 2026) and Consumer Finance Monitor (April 8,  2026). Consent order absence confirmed via CFPB public enforcement actions database. 

OCC’s Most Significant 2026 Mortgage Action Touches Origination, Not Servicing Source: OCC Enforcement Actions for April 2026. Consent Order against The Federal  Savings Bank, Chicago, Docket AA-ENF-2025-63, for FTC Act Section 5 violations on VA  cash-out refinances.

OCC Bulletin 2026-13 / Federal Reserve SR 26-2 / FDIC FIL-15-2026 (April 17, 2026) Covers four claims: (1) vendor/third-party models now carry the same MRM  expectations as internal models; (2) generative and agentic AI explicitly excluded,  described as “novel and rapidly evolving”; (3) the agencies announced a forthcoming RFI  on generative and agentic AI with no published timetable as of June 8, 2026; (4) those  excluded tools are exactly what servicers are currently deploying. 

Freddie Mac Bulletin 2025-16 (December 3, 2025; effective March 3, 2026) Covers five  claims: (1) already in force as of publication date; (2) requires CIO/CTO/CISO/CRO sign off; (3) requires audits mapped to NIST 800-53 and ISO 27001; (4) requires safeguards  against prompt injection, data poisoning, and model inversion; (5) carries a broad  indemnification clause making non-compliance a direct contractual liability. The  characterization of Freddie as “much more prescriptive” than the agencies is supported  by Cooley Finsights analysis cited in the underlying research. Link: Guide Bulletin 2025- 16. Sections 1302.2 and 1302.8 of the guide specifically identify the claims. 

Fannie Mae Lender Letter LL-2026-04 (April 8, 2026; effective August 6, 2026) Covers  three claims: (1) effective August 6, 2026; (2) vendor AI governance must meet a  standard “no less protective” than the servicer’s own; (3) Fannie reserves the right to  demand, without notice, a full inventory of every AI system including purpose, data  classes, and safeguards. 

Treasury Financial Services AI Risk Management Framework (February 19, 2026) Covers three claims: (1) released February 19, 2026 in partnership with the Cyber Risk  Institute, FSSCC, and AIEOG, with input from 100+ financial institutions; (2) 230 control  objectives across five domains including third-party AI risk; (3) technically voluntary but  the de facto examiner and internal audit reference given the absence of binding federal  standards for generative tools. The “de facto reference” characterization is supported by  ZwillGen’s analysis, which noted these resources “are likely to become an important  reference in examinations, internal audit expectations, third-party oversight, and  contract negotiations.” 

OCC Bulletin 2023-17 (June 2023) – Third-Party Risk Management Covers the claim that  the four vendor contract provisions (zero-training data use, model-change notification,  audit/inspection rights, termination data egress) flow directly from existing TPRM  expectations. OCC 2023-17 remains the operative federal framework with no narrowing  updates specific to AI vendors issued in 2025 or 2026 as of report date. 

CFPB Circular 2023-03 (September 2023; still in force) Covers two claims: (1) requires  adverse action notices for AI-assisted decisions to provide specific, principal-reason  explanations tied to the borrower’s actual data and the model’s decision logic; (2) has  not been withdrawn under the current administration. 

CFPB Regulation B Final Rule / Fair Housing Act Disparate Impact Covers two claims: (1)  Reg B final rule effective July 21, 2026 eliminates ECOA disparate impact liability,  meaning servicers who dismantled testing in response created a gap; (2) the Fair  Housing Act’s disparate impact standard is unaffected, grounded in Texas Dept. of  Housing & Community Affairs v. Inclusive Communities Project, 576 U.S. 519 (2015), a  Supreme Court holding not subject to agency rollback. 

State AG Enforcement Expansion Covers the claim that New York, Massachusetts, and  California are expanding enforcement activity under state UDAP statutes and the NY 

FAIR Business Practices Act (December 2025), which expanded General Business Law  Section 349 to cover “unfair” acts. Links:  1, 2, 3, 4

GET MORE INFORMATION

Robert Kazazian

Robert Kazazian

Agent | License ID: 3314089

+1(386) 320-6124

Name
Phone*
Message