The FNMA AI Lender Letter playbook, run in your AI window

Fannie Mae’s Lender Letter LL-2026-04 took effect August 6, 2026. It requires every seller/servicer to govern its use of AI and ML, name an owner, and be ready to show its work. This playbook produces the AI System Inventory, the AI System Risk Assessment, and the AI Governance Policy, then updates the P&Ps the AI touches. Run it in your AI window.

What the FNMA AI Lender Letter (LL-2026-04) requires

Fannie Mae Lender Letter LL-2026-04 requires every seller/servicer to put a governance framework around its use of artificial intelligence and machine learning. In plain terms, you have to document where AI is used, the risk in each use, and how that risk is managed, and be ready to show Fannie Mae your work. It took effect August 6, 2026.

Specifically, a seller/servicer must:

Operationally, that comes down to three artifacts an examiner expects: an AI system inventory, an AI risk assessment, and an AI governance policy with a named owner, plus updates to every policy and procedure the AI touches. The playbook below builds all three, grounded in the verbatim rule and cited section by section.

How it runs

AI touches most of a lender’s P&Ps, so this playbook runs across a Project: one chat per batch of P&Ps, then a few chats that pull the batches together. Connect the MCP server first (below); the playbook works from the verbatim LL-2026-04 text it returns.

  1. 1 Start a new Project

    Name it FNMA AI Lender Letter. Open a new chat in the Project and upload roughly 75 pages of policies and procedures (100-page limit per chat). Repeat until all your P&Ps are uploaded to chats in the Project.

  2. 2 Create your AI System Inventory

    In every chat you uploaded P&Ps into, paste:

    Run the FNMA AI Lender Letter playbook: inventory this batch.
  3. 3 Reconcile: fill the gaps

    Step 2 pulls out the AI-relevant software, processes and workflow your P&Ps mention. Open a new chat and upload any documents, contracts or vendor lists you know are relevant. Then paste:

    Consolidate the findings from all my inventoried batches into one working list. Then show me the gaps, including the AI the P&Ps can't show (embedded vendor AI, shadow/employee AI, tools added since the P&Ps were written). I'm giving you our vendor inventory, contracts, and app list in the project: cross-reference them, surface any system no P&P showed, and validate the owners. Work through the high-risk gaps with me, then save a reconciled working-inventory.md to the project folder.
  4. 4 Draft your AI Governance Policy

    Open a new chat in the Project, then paste:

    Build the master AI System Inventory, Risk Assessment, and AI Governance Policy from working-inventory.md in the project folder. List every open CONFIRM grouped by who I need to ask and what to ask. Save the master policy as a file in the project folder.
  5. 5 Push the policy to your P&Ps

    Back in each chat that contains P&Ps, paste:

    Update these P&Ps to match the master AI policy in the project folder.
  6. 6 Change log (Appendix A)

    New chat, then paste:

    Make the Appendix-A change log for the master AI policy and every P&P we changed.

That’s the whole run: inventory each batch, reconcile (where your vendor list, contracts and app list go in, and the undocumented AI gets caught), one synthesis chat, realign each batch, change log. Every output is a working draft for your review, not legal advice.

No connector? The verbatim rule set this playbook uses is published free as one file: LL-2026-04 update kit (.csv). Attach it to each prompt in an ordinary chat.

Setting up the Project: a few rules that make it work

This structure is good general practice for keeping P&Ps current, and it’s especially strong on a job as broad as the FNMA AI letter. A handful of habits keep it clean:

  1. If you can, one P&P (or themed batch) per chat. Keep each chat focused so it does a thorough job and emits a clean FINDINGS block. If a single P&P runs over ~100 pages, split it across multiple chats rather than starving the context.
  2. Inventory first, in its own chats. Then a separate gap-analysis chat. Finish scanning all batches before you reconcile: the gap analysis needs the whole picture to tell you which systems no policy documented.

Run it in your AI window

  1. 1
    Connect the Claude for Compliance MCP server to Claude or ChatGPT. One time, about a minute, no account with us. Install steps →
  2. 2
    Open a new chat, attach your policies and procedures, plus any vendor list or contracts you have, and say:
    Run the FNMA AI Lender Letter playbook on my P&Ps.

    Start it in each batch chat. The prompts above continue the run.

  3. 3
    Review what comes back. The playbook works from the verbatim regulator text the server returns and cites each section with its effective date, so every finding can be checked.

Claude works on any plan (the free plan allows one custom connector); ChatGPT needs Plus, Pro, Business, Enterprise or Edu. The server has no upload: your documents stay in your own AI session.

Follow the rules this playbook uses

One email when the Fannie Mae rules behind the FNMA AI Lender Letter playbook change: what changed, the new verbatim text, and the effective date.

Double opt-in: we send a confirmation link first. Privacy.

The playbook produces working drafts for compliance and attorney review, not legal advice. All playbooks.