Where fraud risk actually stands after Q2 2026
Cotality's National Mortgage Application Fraud Risk Index reached 132 in the second quarter of 2026, up 11 points or 9.1% from 121 in Q1, which the firm equates to roughly one in every 119 applications showing indications of fraud risk. That reverses the Q1 reading, which had been the best quarter since 2023. Year over year the index is still down 4.6% from 138 in Q2 2025, so the direction of travel depends heavily on which comparison you choose.
The mechanism behind the jump is the loan mix rather than a surge in criminal ingenuity. Purchase loans made up 72% of volume in Q2, up from 59% in Q1, because the rate cuts much of the industry expected did not arrive and refinancing stayed subdued. Purchase transactions carry structurally higher fraud risk than refinances, so a purchase-heavy quarter raises the index even if behaviour is unchanged.
The concentration matters more than the headline. Investment and multifamily applications were 12% of volume but carried far higher risk: roughly one in 44 investment applications and one in 27 multifamily applications showed fraud indicators, against one in 119 overall. Cotality has noted these segments historically run at least three times the average. Undisclosed real estate debt remained the category with the largest year-over-year increase, and its alerts are about 2.5 times more likely to fire on an investment property than an owner-occupied one.
A falling category-level number is not an all-clear. Cotality's own framing on the Q2 release was that most categories showing year-over-year declines should not be read as permission to relax, because the fraud has not gone anywhere. The firm's annual Mortgage Fraud Report was scheduled for September 2026, so the fuller category picture may have moved by the time you read this.
The six fraud types, and what AI does about each
Detection has to be built around how mortgage fraud actually happens rather than a generic model borrowed from card or account-opening fraud. These are the recurring categories and the technique that bears on each.
| Fraud type | What it looks like | What detection relies on |
|---|---|---|
| Income and employment misrepresentation | Inflated income, fabricated employment, altered pay stubs and W-2s. Historically the most commonly confirmed type in the GSEs' own investigations | Cross-reference stated income and employer against bank statement activity, payroll verification sources, and tax documents, then verify at source where possible |
| Undisclosed real estate debt | An existing mortgage or lien left off the application, understating obligations. Largest year-over-year riser in Cotality's recent data | Cross-reference credit tradelines and public property records against the application, which is difficult to do by hand on every file |
| Occupancy fraud | A property presented as owner-occupied to obtain better pricing when it is an investment or second home | Check the subject address against the borrower's mortgage history, other properties tied to them, and address and utility records |
| Transaction fraud | Misrepresented down payments, inflated sale prices with cash back to the buyer, undisclosed non-arm's-length relationships | Portfolio-level pattern analysis: rapid resales, repeat buyer-seller pairs, pricing out of line with comparables |
| Property and appraisal value fraud | Inflated appraisals through collusion or manipulated comparable selection | Automated valuation models and appraisal review that flag outliers against broader market data for a second look |
| Identity and synthetic identity fraud | Stolen, fabricated, or blended identities, sometimes aged for a year or more to build a clean credit file before being used | Document forensics, cross-database identity verification, and behavioural signals rather than one static check |
The first two categories account for most of what a document-driven detection layer can realistically contribute. The last four increasingly depend on data outside the file: property records, portfolio history, valuation data, identity databases. A vendor claiming to address all six from the document package alone is describing something narrower than it sounds.
The 2026 problem: bundles that agree with themselves
The significant change this year is not the volume of fraud but its manufacture. Fraudulent document sets are now generated rather than doctored, and the generation is coherent across the whole package. This deserves attention from anyone whose detection strategy rests on cross-checking documents against each other.
The bundle is internally consistent by design
Current schemes produce pay stubs, bank statements, tax forms and employment records built to agree with one another both arithmetically and narratively. They are produced at scale, lightly customised per applicant, and optimised to look mundane rather than impressive, because the goal is to survive a review rather than to look impressive to one.
Consistency checking alone does not defeat it
This is the uncomfortable implication. Comparing income across four documents catches the borrower who altered one figure. It does not catch a package where every figure was generated together to reconcile. The check remains necessary and stops being sufficient, which is a distinction worth pressing any vendor on, including us.
Verification calls are no longer a reliable backstop
Voice cloning and video deepfakes have made phone-based employer and borrower verification weaker than it was, and a large majority of financial services organisations have been reconsidering voice verification as a result. Fraudsters can also respond to lender enquiries at machine speed across multiple touchpoints.
The scale is not hypothetical
Australian press reporting in 2026 described suspected mortgage fraud in the multiple billions of dollars involving AI-fabricated financial documents, with one major bank reported to be investigating a substantial book of potentially fraudulent loans. Industry bodies there have pushed for direct consent-based access to tax authority income data, which is a telling response: it bypasses the document layer rather than trying to inspect it harder.
The strategic conclusion is that document inspection is becoming a weaker form of evidence than it was, and source verification is becoming a stronger one. Where income can be confirmed against payroll or tax authority data, an asset balance against the institution holding it, or an employer against an authoritative registry, the fabricated document stops mattering. Where that is not available, detection falls back on forensic signals of generation and on patterns visible only across many files.
None of which makes cross-document checking obsolete. Most fraud is still opportunistic and imperfect, and consistency checks catch a great deal of it cheaply. The point is to be honest about the ceiling and to layer accordingly.
Every AI in the file is now governed, from three directions
The compliance position has moved twice this year. A lender selling to the GSEs and supervised as a bank is now looking at three overlapping sets of expectations for the AI it uses to detect fraud. What follows describes the landscape as of September 2026 and is not legal advice.
Freddie Mac Section 1302.8, in force since March 3, 2026
Freddie Mac amended its Single-Family Seller/Servicer Guide via Guide Bulletin 2025-16 to require documented AI and machine-learning governance. It applies to AI used in origination and servicing, built in-house or supplied by a vendor, and explicitly reaches fraud detection tools and document recognition software rather than only the credit decision.
Fannie Mae Lender Letter LL-2026-04, effective August 6, 2026
Published April 8, 2026 and effective in August, establishing a parallel framework. Seller/Servicers are expected to maintain documented policies, assign senior management accountability, manage AI risk against their own risk tolerance, hold vendors and subcontractors to the same standard, and disclose on request which AI tools they use, how, and with what safeguards.
The revised interagency model risk guidance, April 17, 2026
The Federal Reserve, OCC and FDIC replaced SR 11-7 with SR 26-2, the first revision in roughly fifteen years. It preserves validation, monitoring, governance and effective challenge on a more risk-based footing, and a footnote places generative and agentic AI outside its scope as novel and rapidly evolving, directing institutions to their own risk management practices instead. For a bank mortgage lender the two regimes point the same way from opposite directions: the GSEs say govern the AI in your loan files, and the banking agencies decline to specify how for the newest systems. The framework is yours to build. The wider view is in AI agents for financial services.
Explainability is now a compliance property, not a preference
A model that flags a file as suspicious without a documented, reviewable reason is a compliance liability as well as an operational one, because a fraud flag can delay or deny an application and the reason has to survive scrutiny. Every extracted value and every flag should trace to a source document and page.
Vendor AI is your AI
All three frameworks reach through to suppliers. What documentation you receive, whether the model version that processed a file is retrievable later, how changes are announced and tested, and whether your borrowers' documents train anyone's models are procurement questions now. The list in SOC 2 Type II for commercial lending AI covers what a security report leaves out.
What the detection layer should actually produce
Fraud detection does not decide anything. It routes files to people who do, and its output is judged by whether those people can act on it. A flag that an underwriter cannot evaluate is noise with a compliance record attached.
- A reason, not a score. Which document, which field, which comparison failed. A number between zero and one tells a reviewer nothing they can investigate or defend.
- Citations to source. Every extracted value linked to the document and page it came from, so review is verification rather than re-performance and the reason survives an audit.
- Overrides retained in full. Prior value, new value, reason, user, timestamp. When a reviewer clears a flag, that clearance is itself evidence and should be as durable as the flag.
- Calibrated volume. A detection layer that flags a quarter of the pipeline gets ignored within a month. Thresholds should be set against how many files the team can genuinely investigate.
- Honesty about coverage. Which fraud types the layer addresses and which it does not. Document-based detection contributes most on income, employment and undisclosed debt, and least on appraisal collusion and identity aging.
Where Uptiq fits
Uptiq's AI Mortgage Processing Agent works on the document layer of this problem. It classifies and extracts across income documents, bank statements, tax returns and the rest of the file, cross-checks every value against the other sources in the package, and surfaces inconsistencies for underwriter review rather than passing them downstream. Every extraction is traceable back to its source document and page, which is what makes a flag reviewable and a decision defensible under the governance frameworks now in force. Extraction accuracy is certified per document type by a Knowledge Team of former underwriters, bankers and analysts rather than benchmarked on a generic corpus, and the agent runs alongside the existing loan origination system through 100+ integrations. It is a verification and fraud control layer, not a fraud guarantee: as the section above sets out, a coherently generated document bundle needs source-level verification behind the document checks.
What to do about it this quarter
Most of the useful moves here are cheap and do not require a procurement cycle.
Inventory the AI already in your loan files
Both GSE frameworks expect you to know what you are running, including capabilities switched on inside software you already licensed. This is usually a short exercise with a surprising answer, and it is the first thing an examiner or a GSE request will ask for.
Push verification toward the source where you can
Payroll and tax data verified at source, asset balances confirmed with the holding institution, employers checked against an authoritative registry. Each substitution removes a document from the set a fraudster can fabricate, which is a structurally stronger position than inspecting that document more carefully.
Re-test your detection against generated documents, not altered ones
If your evaluation set is made of files where somebody changed a number, it is testing last year's threat. Build a set that includes coherent packages, and ask any vendor what signal they use when nothing in the file disagrees with anything else.
Weight review toward the concentrated segments
Investment and multifamily applications carry several times the average fraud risk. Allocating scarce review capacity by segment risk rather than evenly across the pipeline is one of the few changes that costs nothing.
Write down the governance you already practise
Much of what the GSE frameworks ask for exists informally at most lenders. Documented policies, a named accountable executive, vendor standards, and a disclosure-ready inventory are mostly a writing exercise, and they are what gets asked for on short notice.
Related reading: AI mortgage lending platforms with strong QC and audit support covers the quality control side of the same file, and best AI for business document analysis covers the underlying document category.
Frequently asked questions
What is AI mortgage underwriting fraud detection?
The use of machine learning and document AI to identify indications of fraud in a mortgage application automatically: signs of document manipulation, inconsistencies between documents, and application patterns that do not fit expectations across a portfolio. It routes suspect files to a human underwriter with a reason attached, rather than deciding anything itself.
How much mortgage fraud risk is there in 2026?
Cotality's National Mortgage Application Fraud Risk Index reached 132 in Q2 2026, about one in 119 applications, up 9.1% from Q1 but still 4.6% below Q2 2025. Risk is heavily concentrated by segment: roughly one in 44 investment applications and one in 27 multifamily applications carried indicators, against one in 119 overall. The quarterly rise tracked purchase lending reaching 72% of volume as refinancing stayed subdued.
Can AI detect AI-generated fraudulent documents?
Partly, and less reliably than it detects altered ones. Generated document sets are now built to be internally consistent, so cross-document comparison, which catches a borrower who changed one figure, does not by itself catch a package generated to reconcile. Detection in that case depends on forensic signals of generation, patterns visible across many applications, and above all on verifying income, assets and employment against their source rather than against the document. Treat any claim to fully solve this from document inspection alone with scepticism.
What are the most common types of mortgage fraud?
Income and employment misrepresentation has historically been the most commonly confirmed type in the GSEs' own investigations. Undisclosed real estate debt has been the fastest-growing category in Cotality's recent reports. Occupancy fraud, transaction fraud, appraisal value fraud, and identity or synthetic identity fraud make up the rest, with synthetic identity schemes sometimes aged for a year or more before being used.
Do Fannie Mae and Freddie Mac require lenders to have AI governance policies?
Yes. Freddie Mac's Section 1302.8, introduced via Guide Bulletin 2025-16, has required documented AI and machine-learning governance since March 3, 2026, and Fannie Mae's Lender Letter LL-2026-04 established a parallel framework effective August 6, 2026. Both reach any AI used in origination or servicing, including fraud detection tools and vendor-supplied systems. Separately, the Federal Reserve, OCC and FDIC replaced SR 11-7 with SR 26-2 in April 2026, which puts generative and agentic AI outside its scope and leaves those controls to the institution's own framework. Confirm how each applies to you with your compliance function.
Can AI replace manual fraud review in mortgage underwriting?
No, and current guidance assumes it will not. Automation surfaces files worth a closer look and finds patterns across a pipeline that no individual reviewer could see, but the determination stays with a person, and the GSE frameworks expect human accountability to remain in the chain. The realistic gain is that reviewers spend their time investigating rather than cross-checking.
Fraud risk figures are from Cotality's National Mortgage Application Fraud Risk Index for Q2 2026 and related reporting, and are subject to revision; Cotality's annual fraud report was due in September 2026. Reporting on overseas fraud losses reflects press accounts rather than confirmed findings. Regulatory descriptions reflect publicly available sources as of September 2026 and may change. Nothing here is legal, compliance, or supervisory advice; how the GSE frameworks and the revised interagency model risk guidance apply to your institution should be confirmed with your own legal, compliance, and model risk functions.
Send us a file you know was fraudulent
One that got through, or one you caught late. We will show you what the document layer flags, what it does not, and where every figure came from.
