According to HousingWire, mortgage servicers need to wake up to a reality that might seem counterintuitive right now. Yes, enforcement looks quiet on the surface—the CFPB has issued zero consent orders against servicers so far this year, and enforcement staffing has been drastically cut. But that doesn't mean compliance requirements have gone away. In fact, the accountability for how you use AI in servicing decisions has never been broader or more complicated.
Here's what's happening. Three separate regulatory regimes for AI governance are now in effect simultaneously, and they don't align with each other. The OCC issued new guidance on model risk management that treats third-party AI tools exactly the same as internal models, meaning if a vendor's tool influences a decision about a borrower's account, you own that tool and need to explain it. At the same time, the OCC explicitly carved out generative AI from this guidance because it's still evolving, but that's exactly what servicers are using today. So you're in a gap.
Then you've got the GSEs layering in their own AI requirements. Freddie Mac's bulletin, in effect since March, requires documented AI governance with executive sign-offs, specific audits and continuous bias monitoring. Fannie Mae's letter, effective in August, is slightly less prescriptive but reserves the right to demand a complete inventory of every AI system your company uses without warning. Most servicers can't produce that today, and that's a problem because both GSEs can hold you liable for non-compliance in your seller-servicer agreements.
On top of all that sits the Treasury's AI Risk Management Framework, which is technically voluntary but functions as the de facto standard examiners and auditors actually use since there's no binding federal standard for generative AI yet. Where most servicers are falling short is managing third-party AI risk—understanding what your vendors' tools can actually do to borrowers and making sure your contracts protect you. The gap typically lives in vendor agreements that vendors want to keep loose and servicers haven't updated.
The bottom line according to the article is that accountability sits with you, the servicer, not your vendor. When an AI system makes a decision on loss mitigation, workouts, or who gets contacted about default, you answer for it under model risk rules, GSE contracts, adverse action notice requirements, and Fair Housing Act standards all at the same time. Generic explanations won't cut it anymore under current CFPB circular requirements—you need to trace specific borrower decisions back to what the AI actually did.
What I am seeing locally here in the Bay Area is that servicers handling mortgage portfolios across the East Bay and beyond need to get serious about this right now, not later. The August deadline when Fannie's requirements kick in is a forcing function, but the real issue is that your vendor contracts probably haven't kept up with any of this. If you're using AI for any account decisions and you can't explain to an examiner or auditor exactly what that system is doing and why, you're exposed. The quiet enforcement environment doesn't change that exposure—it just means you need to fix it on your own schedule rather than waiting for someone to force your hand.
