← All posts

Industry Verticals

237 posts on industry verticals.

Fannie Mae LL-2026-04: What the Lender AI Governance Mandate Requires from Mortgage Originators

On April 8, 2026, Fannie Mae issued Lender Letter LL-2026-04, a governance framework for AI and ML in mortgage origination and servicing. It takes effect August 6, 2026, 120 days after publication. Freddie Mac Section 1302.8 has been enforced since March 3, 2026. The combined GSE regime requires inventory, governance, audit trails, and disclosure on demand for AI used in any step of the loan lifecycle, including vendor AI tools the lender does not control. This piece walks through what the mandate requires, where lender deployments are exposed, and the inspection architecture that satisfies the disclosure obligation.

fannie-maemortgageai-governanceai-complianceauditlender-letter
Read post →

EU AI Act for Fintech: How Credit Scoring and Fraud Detection Become High-Risk in August 2026

On August 2, 2026 the EU AI Act high-risk system requirements begin to apply to fintech credit scoring, creditworthiness assessment, and several adjacent financial decisions. The classification falls under Annex III point 5(b). Deployers inherit Article 26 obligations including per-decision logging, human oversight, instructions for use, and incident notification. The provisions overlap with DORA on third-party risk and incident reporting. This piece walks through which fintech AI use cases become high-risk, what the deployer obligation actually requires, and where most lender deployments are exposed.

eu-ai-actfintechcredit-scoringai-compliancefinancial-servicesaudit
Read post →

AI Gateway for Banks: The Inspection Layer for Regulated AI Traffic Under OCC, FFIEC, and the EU AI Act

Banks handle AI traffic that touches credit decisions, fraud screening, customer service transcripts, internal research copilots, and increasingly model-assisted regulatory reporting. Each route carries a different supervisory expectation. This piece walks through the regulatory regimes a US or EU bank operates under, the inspection target the gateway covers per route, the audit record format that satisfies OCC SR 11-7, FFIEC AIO guidance, EU AI Act Article 12, and the deployment topology that fits a bank-grade environment.

bankingfinanceoccffieceu-ai-actmodel-risk-management
Read post →

COPPA AI compliance checklist with owners, evidence, and pass conditions

This COPPA AI compliance checklist turns the current Rule into gradable work. Each item names an action and accountable owner, with an evidence artifact and pass condition. It covers scope and notice, consent and parental rights, minimization and security, vendors and retention, plus routed LLM traffic.

ai-complianceregulationcomplianceai-governancepolicy-enforcement
Read post →

EBA ICT Guidelines AI Controls Mapping After DORA

This EBA ICT Guidelines AI controls mapping uses the amended, post-DORA text rather than the original 2019 control set. It maps the remaining payment service user relationship requirements to objectives, owners, AI implementation points, tests, evidence, and coverage limits. The result keeps customer communications and LLM traffic distinct from payment execution and notification controls.

ai-governanceai-compliancecomplianceregulationdorapolicy-enforcementaudit
Read post →

EBA ICT Guidelines AI Compliance Checklist After DORA

This EBA ICT Guidelines AI compliance checklist begins with the post-DORA applicability fork. The amended Guidelines now focus on payment service user relationship management, while DORA governs the broader ICT risk framework. Use the checks to grade AI security guidance, customer controls, alerts, support, evidence integrity, and the boundary between LLM traffic and payment systems.

ai-governanceai-compliancecomplianceregulationdorapolicy-enforcement
Read post →

EBA ICT Guidelines AI Audit Evidence After the DORA Scope Change

The EBA narrowed its ICT and security risk management Guidelines after DORA began to apply. For AI used in payment-service customer interactions, the remaining evidence question concerns security guidance, customer choices, alerts, updates, and support. This guide builds an audit package around that current scope while separating runtime AI records from adjacent payment controls.

ai-governanceai-compliancecomplianceregulationdoraaudit
Read post →

COPPA AI audit evidence for sampling, retrieval, and integrity

COPPA AI audit evidence should let an assessor reconstruct which child-facing data flows existed, how consent and parental requests were handled, and which safeguards operated. This guide separates population sampling, record retrieval, integrity checks, and the bounded evidence available at a routed LLM request.

ai-complianceregulationauditforensic-auditpolicy-enforcement
Read post →

CJIS AI Controls Mapping: Requirements at the Authenticated LLM Boundary

This CJIS AI controls mapping connects selected access, information-flow, identity, and audit requirements to an implementation point, owner, test, evidence artifact, and explicit boundary. It shows where an HTTP AI gateway contributes direct or partial coverage and where IAM, records, operations, endpoints, and incident teams remain responsible.

ai-complianceai-governancearchitecturecjispolicy-enforcementpublic-sector
Read post →

CJIS AI Compliance Checklist: Owners, Evidence, and Pass Conditions

This CJIS AI compliance checklist converts policy requirements into actions with named owners, evidence artifacts, and pass conditions. It covers scope, authentication, information flow, event content, review, reporting, integrity, search, retention, and boundary ownership for AI requests that may handle criminal justice information.

ai-complianceai-governancechecklistcjispublic-sectorzero-trust
Read post →

CJIS AI Audit Evidence: Build a Review Package Investigators Can Replay

CJIS AI audit evidence should let a reviewer reproduce the population, sample selection, request decision, protected record, and retrieval result. This guide turns CJIS audit requirements into an evidence package for authenticated HTTP AI traffic while keeping IAM, endpoint, records, and incident duties with their proper owners.

ai-complianceai-governanceauditcjispublic-sectorzero-trust
Read post →

AI Governance for Real Estate Starts With the Property Decision

AI governance for real estate should separate tenant screening, leasing communications, brokerage work, property operations, valuation, and lending. Each use needs an owner, permitted data, exact model route, review requirement, and evidence tied to the property or applicant record. Request-layer controls can govern authenticated HTTP model traffic while housing decisions, consumer-report duties, fair-housing review, and vendor-managed AI remain with their assigned owners.

ai-governanceai-compliancepolicy-enforcementidentity-and-authorizationaudit
Read post →