Back to All Resources

AI Governance Starts With Inventory

Fannie Mae’s AI governance requirements go live on August 6th. Freddie Mac’s have been in effect since March. If your institution doesn’t have a clear picture of where AI is already operating inside your organization, the next 30 days matter more than you might think.

That was the core message from our latest Compliance & Coffee session, where ActiveComply’s Melissa Grindel sat down with James Brody, partner and founder at Brody Gap LLP and co-author of the upcoming Mortgage Bankers AI Governance Guide. Brody has spent the last several years mapping AI use cases to the current statutory framework, and he’s blunt about where most lenders stand today: they don’t know what they don’t know.

AI governance starts with a question most institutions haven’t answered

“You can’t govern AI unless you know what AI you have,” Brody said. It sounds obvious, but it’s the piece most compliance programs skip. AI isn’t arriving through one front door. It’s showing up through vendor updates, loan officers experimenting with a $20 chatbot on a 1003, IT-approved tools, and plenty of tools nobody approved at all.

Brody calls this shadow AI, and it’s often hiding in plain sight. He recommends a few concrete starting points:

  • Have IT sweep internal systems for what’s actually running
  • Review reimbursement forms for AI subscriptions employees are expensing on their own
  • Pull every vendor contract and check whether it even mentions AI (if it was signed before this year, it probably doesn’t)
  • Send a formal letter to every single vendor asking directly what AI they use, how, and why

That last one is a project Brody’s firm is actively building: a form letter lenders can send across their entire vendor list. The goal isn’t just information gathering. It’s leverage. If enough lenders start asking the same questions, vendors get pushed toward more transparency and better safeguards, and lenders get a real opening to renegotiate contracts that were written before AI was ever part of the conversation.

Why this can’t be a once-a-year checklist

One of the sharper points from the conversation: AI governance isn’t a periodic review. It’s ongoing monitoring. New model versions and vendor products show up every few months, and the risk profile of a tool you approved in January may look completely different by summer.

Melissa pushed this further, suggesting lenders revisit their AI risk tiering on a quarterly basis just to keep pace. Brody agreed and made the case that someone at the institution needs explicit ownership of this process. Not a committee. A person. Because when Fannie comes asking for your evidentiary file, the expectation isn’t a 72-day turnaround. It’s 72 hours.

Tiering risk: it’s about inputs and outputs, not buzzwords

A useful reframe from the discussion: don’t let vendor answers like “generative AI” or “agentic AI” drive your risk rating on their own. Those labels don’t tell you much. What matters is:

  • What information is going in
  • What the output actually does
  • Whether the tool touches consumers directly or stays internal
  • Whether the system trains on your data and what that means for PII exposure

A consumer-facing underwriting tool and an internal drafting assistant carry very different risks, even if they’re built on the same underlying model. And risk isn’t fixed. Brody pointed out that a high-risk use case can move down the scale once the right controls are in place. Tiering is a sliding scale, not a permanent label.

Where the regulatory pressure is actually coming from

Federal guidance has been light on specifics so far, which has left states to fill the gap. Brody flagged Texas, Colorado, New York, and California as states setting the pace, and for lenders operating across multiple states, building to the most stringent standard is often the more efficient path than maintaining a patchwork of separate models.

He also called out a few areas getting less attention than they deserve:

  • Marketing AI and fair lending
  • TCPA overlays
  • Synthetic performers in marketing content
  • The SAFE Act and licensable activity

The next 90 days

Asked what lenders should prioritize before year-end, Brody didn’t hesitate: inventory, now, not eventually. Everything else- tiering, vendor renegotiation, policy development- depends on knowing what AI is actually in use across the organization. As he put it, this isn’t about deciding whether to adopt AI. You already have it. The only question is whether you’re managing it.


Compliance & Coffee runs monthly, bringing in guests across the compliance and mortgage industry to talk through the issues shaping the space. Want the full conversation? Watch on demand.