Guide for lenders

An AI governance framework lenders can actually run.

Most organizations have more AI than they realize. Far fewer can say how it got there, what problem it solves, what it changed, or who owns it. This guide is the framework I build with banks, credit unions, and independent mortgage banks: how to inventory what you have, tier it by risk, write policy people will follow, oversee your vendors, and report to the board in a way that stands up to examiners.

Suha Beidas Zehl leading an AI readiness workshop for mortgage lending executives

Why Lenders Need AI Governance Now

AI is already inside your organization, whether or not anyone approved it. It is in your LOS, your CRM, your servicing platform, and in the browser tabs your team opened on their own. Examiners, investors, and boards are all asking the same question: do you know what your AI is doing?

A governance framework is not a brake on innovation. It is what lets you say yes faster, because the rules of the road are written down. The lenders moving quickest right now are the ones who can approve a use case in days because the approval path, risk tiers, and review standards already exist.

The framework

Six Pillars of a Working Framework.

Inventory and Ownership

You cannot govern what you have not counted. Start with a register of every place AI or automated decisioning touches the business, including the AI hiding inside vendor tools you already own, and give each one a named human owner.

Use-Case Risk Tiering

Not every use case carries the same risk. Tier them: low-risk internal productivity tools, customer-facing assistance, and anything that touches credit, pricing, or borrower treatment. Each tier gets its own approval path and review cadence.

Policy and Standards

A short, readable policy that states what is allowed, what needs approval, what is prohibited, and who decides. Add standards for data use, human review thresholds, documentation, and disclosure. If staff cannot read it in ten minutes, they will not follow it.

Vendor Oversight

Your vendors' AI is your AI in the eyes of an examiner. Extend third-party risk management to cover model updates, data use, fair lending testing, decision records, and the right to audit. Ask the hard questions before signature, not after go-live.

Board and Executive Reporting

Boards do not need model math. They need a one-page view: what AI is in use, what changed this quarter, what incidents occurred, what is coming, and where the open risks sit. A standing agenda item, not an annual surprise.

Monitoring and Evidence

Governance is a loop, not a binder. Track accuracy drift, exception volumes, overrides, and complaints. Keep decision logs, version history, and review records so you can answer an examiner with evidence instead of memory.

Risk tiering

Tier the Risk Before You Write the Rules.

Tier 1 · Low Risk

Internal drafting, summarization, meeting notes, knowledge search

Approved tool list and a simple acceptable-use policy. Annual review.

Tier 2 · Moderate Risk

Customer-facing chat, marketing content, borrower communications, process automation

Use-case approval, disclosure review, human review path, quarterly monitoring.

Tier 3 · High Risk

Credit, pricing, underwriting support, quality control, anything touching borrower treatment

Executive sign-off, fair lending review, documented validation, continuous monitoring, and a rollback plan.

Board reporting

What the Board Actually Needs to See.

A standing AI agenda item, one page, every quarter. These six elements give the board real oversight without burying them in technical detail.

  • AI inventory: what is in use, by whom, and what changed this quarter
  • Risk posture: tier counts, open issues, and anything past its review date
  • Incidents: errors, complaints, overrides, and how each was resolved
  • Vendor movement: model updates, new features enabled, contract changes
  • Pipeline: proposed use cases awaiting approval, with expected benefit
  • Actions taken: policies updated, training delivered, reviews completed

Order of operations

How to Put It in Place.

  1. 01

    Take the Inventory

    List every AI and automated tool in use, including the AI features your LOS, CRM, and servicing vendors switched on without asking. Most organizations find two to three times more than they expected.

  2. 02

    Assign Owners

    Every use case gets a business owner who can answer for it: what it does, what data it touches, and who reviews its output. No owner means no deployment.

  3. 03

    Tier the Risk

    Sort the inventory into the three tiers. This is where governance gets practical: low-risk tools move fast, high-risk tools get the scrutiny regulators expect.

  4. 04

    Write the Policy People Will Read

    One to two pages: what is allowed, what needs approval, what is off-limits, and who decides. Attach the standards and procedures as living documents.

  5. 05

    Stand Up the Approval Path

    A short intake form, a cross-functional review for Tier 2 and 3, and a documented decision. Fast enough that people use it instead of routing around it.

  6. 06

    Report, Review, Repeat

    Put AI on the board agenda, review the inventory quarterly, and re-tier as tools and regulations change. Governance that does not update itself becomes shelfware.

Next step

Want Help Standing This Up?

I help lenders build this framework as a focused governance engagement: inventory, risk tiers, policy, vendor oversight, and board reporting, sized to your organization and your exam calendar. Bring your current state to a discovery call, or read how the consulting engagements are structured.