AI Without the Chaos: What Responsible AI Actually Looks Like for Lenders
By: Bob Jennings, Chief Executive Officer
October 9, 2026
Lenders are being sold AI from every direction. Most don’t have the infrastructure or governance to evaluate it, let alone deploy it responsibly.
That’s not a knock on lenders. It’s the market reality right now. And the stakes are real: secondary market eligibility, CFPB exposure, fair lending risk.
In the latest episode of TrustEngine’s Intelligence Briefing series, I sat down with two industry executives who live in this world daily: Melissa Grindel, Head of Compliance and Industry Strategy at ActiveComply, and Brian Vieaux, President of MISMO. The goal was simple. Skip the theory. Get specific about what responsible AI looks like inside a real mortgage operation.
Here’s what we learned.
The exposure gap is a communication gap
Ask a mortgage compliance team how exposed they are to AI and you’ll hear “very.” They don’t know what they don’t know. They may project confidence to a regulator, but internally, as Melissa put it, “a few ulcers are forming”.
Ask production staff and you’ll get the opposite answer. They see AI baked into Zoom, Canva, LinkedIn and other tools they use every day. It feels routine. Low risk. Just another feature.
Both sides sit at opposite ends of the spectrum, and they rarely meet in the middle. That disconnect is the real exposure. Closing it starts with getting compliance, production and leadership looking at the same picture.
FRAME is the foundation, not the finish line
About a year ago, the MBA’s Residential Board of Governors made responsible AI guardrails a priority for 2026. MISMO already had the infrastructure to act on it: an AI community of practice with 100+ members across the industry. In under six months, they published FRAME, the Framework for Responsible AI in Mortgage Ecosystems.
Brian was clear about what FRAME is and isn’t. It’s not a magic wand that makes you compliant. It’s the foundation to build your own AI guidance and governance. Your risk appetite determines how you leverage FRAME to get there.
At minimum, FRAME gives lenders two things:
- A policy and procedures template. If you don’t have written AI policies yet, start here. Then actually implement them.
- A use-case inventory tool. Brian called this the most important piece. One vendor can carry three or four distinct AI use cases, and each gets its own line item and its own owner.
Why does the inventory matter so much? Because when Fannie, Freddie or your state regulator knocks, producing it on the spot changes the entire tone of the exam. “Give me 30 days” is not where you want to be. And in 2026, there’s no excuse to have this foundational element.
FRAME also does the heavy lifting on scope. It pulls in the key components of NIST, current GSE seller/servicer requirements and early state legislation. A smaller institution could struggle to comply with NIST directly. FRAME makes it workable. As Melissa noted, without an industry standard to point to, compliance teams tend to over-rotate and build programs the business can’t actually run.
Copilot, not decision maker
The industry has relied on automated decisioning for years. DU and LPA have been helping lenders decide on loans long before anyone said “AI.” What’s new is how much faster and deeper AI now reaches into loan manufacturing.
And that changes the risk math. It’s no longer just regulatory. It’s contractual.
With Fannie’s guidelines on AI in loan manufacturing effective August 6, here’s the reality Brian laid out:
- It’s now harder to find a loan without AI in its manufacturing process than one with it.
- Any loan that defaults gets QC’d by the agencies. Aggregators do the same.
- If they can tie that default to a defect caused or amplified by AI, you’re looking at an indemnification or a repurchase.
- Reps and warrants roll downhill. They stop at the originator.
The irony? Investors are now using AI to find the AI-driven defects that justify a putback. Melissa’s counter: lenders can use AI to check their own work first and break that loop.
Brian’s bottom line was simple. Let AI be the accelerator. Keep a human in the loop. Underwriters still sign off. If he were running a lender today, “human in the loop” would be the sign over the door.
Don’t ban your LOs’ AI tools. Inventory them.
Governance conversations tend to center on technology and policy. The loan officer often gets left out. That’s a problem, because LOs are already using AI, often tools the company never approved.
Melissa flagged what can go wrong when an LO puts an unvetted chatbot in front of a borrower:
- Stale data. What is the model referencing when it quotes today’s rates? Can you follow through on what it says?
- Fair lending. Does the response change if a borrower mentions she’s a single woman, or that part of her income is federal assistance?
- UDAP. General-purpose tools weren’t built for mortgage. “We can absolutely get you the lowest rate” is low-hanging fruit for any examiner.
She also made a point that goes beyond compliance. The LO relationship is the product. Trading that for a little efficiency is a bad deal.
Within our own product, MortgageCoach, our borrower-facing AI chat is designed to route the borrower back to their LO. For most borrowers, this is the largest financial transaction of their lives. We believe that taking the human professional out of it isn’t responsible.
So what do you do about the tools LOs are already using? Brian’s answer: make it safe to disclose. Ask LOs to list every AI use case they rely on, from up-funnel marketing through post-close. Then use what you learn.
- Where LOs reveal a real need, solve it at the enterprise level.
- Where they’re using a one-off tool, point them to the approved one that does the job better, at a better seat cost.
- Add those use cases to your inventory so you can disclose them properly.
As Melissa put it, the goal is visibility, not punishment. And Brian expects liability to eventually reach the individual license holder. Whatever an LO gains from a homegrown tool isn’t worth putting their license on the line.
It’s no surprise that we all agreed on one rule: anything borrower-facing should be enterprise only. It’s been vetted, it’s under contract, and the lender is on the hook either way.
Governance that runs, not governance in a drawer
I posed a concrete scenario to Melissa and Brian for comment: a mid-sized IMB, 200 LOs, one compliance officer starting tomorrow. What are the first moves?
- Start with FRAME. Not because MISMO says so, but because adoption is a team sport. The more lenders build on the same foundation, the faster GSEs and state regulators recognize it in audits and get comfortable with how the industry operates.
- Run your existing vendor risk program through an AI lens. You already have third-party risk management. Add AI governance as a layer, not an automatic escalator. AI is in almost every vendor you use. Its presence alone doesn’t make a tool high risk. The questions that matter: Is it consumer-facing? Does it touch consumer data, credit decisions, the loan file, or sensitive internal systems like payroll?
- Tier the risk and publish SLAs. Low-risk use cases get a clear, expedited approval window. High-risk ones get a consistent testing program, sampling 5% or 10% of chatbot conversations or email outreach the way QC already samples loans. Consistent tests mean consistent SLAs.
That last step is how compliance earns production’s trust. When LOs know they’ll get a fair review on a predictable timeline, they stop going around the process. As Melissa put it, the answer isn’t no. It’s yes, with guardrails.
Where regulators are looking
There’s no single examiner. CFPB, FHFA, the GSEs and every state bring their own flavor. Melissa, fresh from a conference full of state regulators, heard answers ranging from “still evaluating” to “we’ve hired third-party auditors.” Here’s where attention is concentrating:
- Credit decisioning. How AI interacts with consumer data and renders credit decisions is top of mind, especially with the GSEs.
- Chatbots. Colorado has gone furthest, issuing guidance this year on the specific risks of interacting with consumers through chatbots.
- AI in advertising. New York now requires disclosures when ads feature a “synthetic performer,” a person who looks human but isn’t. That applies to any LO creating content who is licensed in or located in New York.
- Private lawsuits. Regulators aren’t the only risk. A current TCPA class action over AI cold calls is really a do-not-call case, but AI grabbed the headline and amplified it.
Brian added one warning: shadow tools used outside the enterprise are the fast path to massive TCPA liability.
Three questions to ask every AI vendor
Most lenders are buying AI faster than their due diligence can keep up. Beyond the standard risk-tier questions, Melissa’s three non-negotiables:
- Who do you serve? What share of your customers are in financial services, and specifically mortgage? Vendors who understand the industry are usually proud to share that number.
- What can I see? As an admin, how do I review inputs and outputs across all my users? Where can I put in hard stops?
- Who can I talk to? Give me a lender reference. Hearing it from a peer beats hearing it from a sales deck.
The red flag: hesitation. If a vendor hides behind “secret sauce” when you ask how its AI works, walk. Proprietary is fine. But you need to explain the tool clearly to your regulator. A good partner cares about your regulatory obligations as much as you do.
What about vendors claiming FRAME alignment? Brian previewed MISMO’s answer on the webinar: an AI governance certification for vendors, unveiled at the MISMO Fall Summit. Version one consolidates the core governance checks lenders would otherwise run on their own into a single, annual certification. MISMO is careful to note it doesn’t yet carry GSE or regulator approval. The long-term goal is for examiners to recognize it, so a certified vendor in a lender’s stack signals a known baseline.
FRAME’s policy template and inventory tool also include vendor-specific questions lenders can put to use today.
What’s the single non-negotiable thing to consider before your next AI deployment?
Brian: Build your inventory. Today, before close of business, list five AI use cases in a spreadsheet. Need a head start? Download the FRAME toolkit at mismo.org.
Melissa: Invest in training. Not a 20-minute video on double speed but rather real, ongoing training on how to use AI well and how to manage its risk. You can’t govern a technology you don’t understand.
Neither of them is anti-AI. That was the point. Responsible AI isn’t about slowing the industry down. It’s about building the infrastructure so you don’t blow up your secondary market relationships or end up in an enforcement action.
FRAME is the starting point. Training is the floor. Vendor diligence is the filter. Get those right and you get AI without the chaos.
Because the mission hasn’t changed. Put more people in homes.



