What changed in 2026, and why it is now an audit question

Until this year, a lender could describe its AI tooling in general terms and satisfy most reviewers. That is no longer the position. Freddie Mac amended its Single-Family Seller/Servicer Guide through Bulletin 2025-16, adding Section 1302.8 with governance, audit, and security requirements for AI and machine learning systems, effective March 3, 2026. Fannie Mae followed with Lender Letter LL-2026-04, issued April 8, 2026 and effective 120 days later, on August 6.

Read the Fannie Mae letter and the operational demand is specific. A seller/servicer using AI or machine learning in origination or servicing must hold policies and procedures covering how those systems are developed, implemented, used, and maintained, and how the associated risks are measured and managed. Those policies have to be communicated to the people whose jobs involve AI, reflect the applicable legal and regulatory requirements, be calibrated to the lender's own risk tolerance, and carry a named owner who reviews them at least annually. The letter also extends to vendors: the lender must govern subcontractor and vendor use of AI to a standard no less protective than its own. And on request, it must promptly disclose what AI it uses, for what purpose, and what safeguards are in place.

01

Vendor AI is your exposure

The Fannie Mae letter does not distinguish between tools you built and tools you bought. If a vendor's AI touches a loan you sell, its governance is part of your governance.

02

Disclosure is on demand, not on schedule

The obligation is to disclose promptly on request. That favors lenders who already hold a current inventory of AI in use and what each tool does, rather than assembling one under a deadline.

03

Annual review needs an owner

A named owner who reviews the policies at least annually is an explicit requirement, not an implied best practice. This is usually the gap in a first read of the letter.

04

Freddie Mac got there first

Section 1302.8 has been in force since March 2026. Commentators reading the two side by side describe Freddie as the more prescriptive of the pair, including on audit standards and indemnification.

The practical consequence for a technology decision is straightforward. The question is no longer whether a platform uses AI. It is whether the platform can hand you the evidence you will be asked for: what model version touched this file, what it produced, who reviewed it, what they changed, and why. That is the lens the rest of this guide applies.

The four layers of the mortgage QC and audit stack

Almost every product in this category will tell you it supports QC and audit. The claim is usually true and almost never comparable, because the products sit at different layers of the same file. Naming the layer first is what stops a lender from buying a document engine to solve a defect reporting problem.

LAYER 1

Document and data

Classification, extraction, income and asset calculation, cross-document consistency checks. Everything downstream inherits the quality and the traceability of this layer.

LAYER 2

Decision and conditions

Guideline evaluation, condition generation and clearing, exception handling. The layer where the reasoning behind an outcome has to remain reviewable rather than implicit.

LAYER 3

QC and audit

Sample selection, testing against agency and investor guidelines, defect capture and severity, rebuttals and cures, and the trend reporting the agencies expect to see.

LAYER 4

AI governance

Model and tool inventory, version control, monitoring, and the record of how AI touched each file. New as a purchasing consideration in 2026, and currently the least mature layer.

Two things follow from the layering. First, a lender with a defect reporting problem and a lender with an income calculation problem should not end up shortlisting the same products, even though both would describe their goal as better loan quality. Second, layer four is not yet a product category so much as a set of obligations distributed across the other three, which is why the vendor questions later in this guide matter more than any feature comparison.

The shortlist at a glance

OptionLayerBest suited to
ACES Quality Management3 - dedicated QC and auditLenders wanting a purpose-built, configurable QC platform across pre-funding and post-close
Indecomm (AuditGenius)3 - QC platform, or QC as a serviceLenders who want the technology, the audit staff, or a combination of both
LoanLogics1 and 3 - document data plus post-close QCLenders and investors wanting extraction and audit from one provider
Ocrolus1 - document and income AILenders whose constraint is document handling and income calculation, usually on Encompass
Infrrd (MortgageCheckAI)1 and 3 - IDP with pre-fund and post-close auditTeams wanting document AI applied directly to the audit itself
ICE Mortgage Technology2 - capability inside Encompass and MSPLenders standardized on ICE who want AI governed inside the system of record
Dark Matter Technologies2 - capability inside EmpowerEmpower clients wanting auditable AI agents inside the LOS
Uptiq1 and 2, commercial lending onlyInstitutions whose lending extends beyond residential into C&I, CRE, or equipment finance

Two notes on reading that table. The layer assignment describes what each product is built around rather than the limit of what it can do, and several of these vendors are actively expanding across layers. And the last row is the one to read most skeptically, which is the subject of its own section below.

Layer 3: dedicated QC and audit platforms

These are the products built specifically to run the QC function: select the sample, test the file, record the defect, manage the rebuttal, and report the trend. Described from public information as of September 2026.

ACES Quality Management

ACES is the most widely referenced dedicated QC platform in US mortgage, and it positions itself on configurability: its Flexible Audit Technology is described as letting lenders manage and customize the audit system without depending on IT or the vendor to make changes. The company states that its users include more than 70 percent of the top 20 independent mortgage lenders, along with state housing finance agencies, mortgage insurers, a GSE, and third-party QC providers, and its coverage spans pre-funding through post-close.

On the AI side, ACES launched ACES Intelligence in September 2025, which the company describes as the industry's first AI-powered features for quality control: writing exceptions, building loan selection queries in plain English, and generating audit and executive summaries. In January 2026 it acquired BaseCap Analytics, an enterprise data quality platform, to extend the product into rule-based data validation ahead of the audit itself. The company also publishes quarterly mortgage QC industry defect trend reporting, which is a useful external benchmark whether or not you buy the platform.

The natural fit is a lender that wants QC to be its own configurable system rather than a module, and that has the internal QC function to run it.

Indecomm

Indecomm is unusual in this list because it sells the technology and the audit labor, and will do either or both. AuditGenius is its QC platform, covering pre-funding, post-close, servicing, and secondary market review, with AI-driven defect detection that tracks root cause by individual, category, and trend, real-time dashboards, and a maintained audit trail. Alongside it, Indecomm's own auditors and underwriters deliver QC reviews on behalf of lenders, including post-close, early payment default, and denied or withdrawn loan audits, with random, discretionary, and targeted sampling.

The surrounding Genius suite is what makes the QC layer faster: IDXGenius for document classification and extraction, which the company states covers more than 1,200 mapped document types and is used across processing, underwriting, QC, HMDA review, MSR transfers, and due diligence, and DecisionGenius for risk-based underwriting with automatic audit trails.

The fit is a lender whose QC capacity is the binding constraint rather than its QC software, or one that wants to shift between in-house and outsourced review without changing platforms.

LoanLogics

LoanLogics covers both the document layer and post-close QC, which is a meaningful combination when the recurring problem is that audit findings trace back to bad data rather than bad underwriting. Its LoanHD platform handles loan quality and post-closing audit, and its IDEA document processing engine underpins classification, extraction, and income analysis. The company, backed by Sun Capital Partners, states that the engine has processed more than 26 billion data points across mortgage documents.

It is also, notably, one of the few vendors publicly engaging with the explainability problem the new agency requirements create. In March 2026 LoanLogics announced it was evaluating Quantum General Intelligence's deterministic AI platform, within its own AI governance framework, specifically to strengthen explainability and provable audit trails in regulated mortgage decisioning. Whether that evaluation converts into product is worth asking about directly; the framing of the problem is the right one.

The fit is a lender or investor that wants extraction and audit from a single provider, and that cares about the defensibility of the reasoning rather than only the finding.

Layer 1: document and data AI that feeds the audit

These vendors do not run your QC function. They determine how good and how traceable the data is that your QC function, and your auditors, are working from. On any file where the defect turns out to be an income calculation, this is the layer that produced it.

THE CHAIN A REVIEWER HAS TO WALK BACKWARDSFigure in the fileQualifying income$9,412 / moThe calculationMethod, inputs, and theguideline it was run underThe overridePrior value, new value,reason, user, timestampSourcepagePay stub, p.2BREAK ANY LINK AND THE REVIEWER RE-PERFORMS THE WORKWhich is the cost the software was bought to remove, and the reason a QC finding turns into a repurchase conversation.Under LL-2026-04 and Freddie Mac Guide Section 1302.8, the model version and the governance around it sit behind thischain as well: not just what the number was, but which tool produced it, under what policy, reviewed by whom.
Audit support is a chain, and it is only as strong as the weakest link in it.

Ocrolus

Ocrolus is the AI-native document and income layer most often found on top of Encompass. It classifies and indexes borrower packages at intake, automates income calculation across W2, 1099, gig, and self-employed borrowers, and identifies discrepancies between borrower documents and the 1003 data in the LOS. Two claims on its site are worth noting for a QC conversation specifically: income outputs eligible for Fannie Mae reps and warranties relief, and data capture accuracy insured by Lloyd's of London. Both are unusual and both are worth asking the company to define precisely in writing.

In March 2026 Ocrolus announced general availability of automated conditioning, which generates conditions aligned to selling guide requirements, matches them to the supporting documents, and syncs with Encompass. The company described the engine as deterministic by design rather than bolted onto a legacy workflow, and said it had signed close to 90 mortgage lender customers over the previous year.

The fit is a lender whose cycle time and defect rate both trace back to document handling and income calculation. It is a complement to a QC platform, not a replacement for one.

Infrrd

Infrrd applies its intelligent document processing platform directly to the audit, through MortgageCheckAI, which targets pre-fund and post-close QC. Its stated approach is to extract data from the loan documents, auto-verify consistency against the LOS and AUS through API integrations, match data across documents and sources, and flag mismatches, with audit trails accessible in the platform. The company was named a HousingWire 2026 Tech100 Mortgage winner.

The fit is a QC team whose review time is dominated by stare-and-compare across a large document package rather than by judgment on findings. As with any IDP-led approach, the question to test is what happens at the edges: handwritten notes, poor scans, and non-standard documents are where extraction accuracy and audit confidence diverge.

Inside the origination platform

The origination platforms have moved quickly, and for a lender already standardized on one of them the native capability is the lowest-friction option. Both of the major US platforms now frame their AI around governance rather than only speed, which is a direct response to the agency requirements.

ICE Mortgage Technology

ICE runs Encompass and MSP, two of the industry's systems of record, and has been layering AI across both. Its Mortgage Analyzers include an Audit Analyzer alongside the Income and Asset Analyzers, and its AI work is now described under ICE Aurora, which the company positions as embedding agentic AI directly into mortgage workflows rather than as standalone tools, with governance, auditability, and system-of-record integration as the stated rationale.

ICE Fraud Monitor, launched with Encompass integration, is a useful example of what audit support looks like when it is built in: configurable risk scoring drawing on property records, credit and employment validation, exclusionary lists and watchlists, with audit trails, automated recordkeeping, user permissions, time-stamped condition clearances, and compliance reporting. At ICE Experience 2026 the company also introduced AI voice and chat agents for servicing and made 16 exception-based servicing automation agents available.

The fit is an Encompass lender that wants AI inside the system that already holds the record. The thing to test is the depth of the audit and defect layer against a dedicated QC platform on a real post-close sample.

Dark Matter Technologies

Dark Matter brings point of sale, origination, servicing, and intelligence onto one platform around its Empower LOS. In March 2026 it introduced a compliant AI agent framework, letting lenders deploy auditable AI agents inside Empower while preserving identity controls, data permissions, and regulatory compliance. In April 2026 it launched Ask Aiva, a retrieval-augmented AI assistant embedded in Empower that lets users query their own origination data in plain language, with answers traceable back to the source.

That last detail is the one that matters for this topic. Traceability to source is the difference between an assistant that produces an answer and one that produces an answer a reviewer can stand behind. The fit is an Empower client; the evaluation question is the same as for ICE.

Where Uptiq fits, and where it does not

Uptiq is not a residential mortgage QC platform, and if that is what you are shopping for, buy one of the products above. We do not run agency-guideline post-close QC sampling, we do not maintain a TRID or HMDA compliance rules library, and we do not produce agency defect taxonomy reporting. Saying otherwise on a page that ranks vendors would be the exact behavior this guide is warning about.

Where Uptiq is relevant to this search is narrower and worth stating plainly. Qore is a commercial lending AI platform used by banks, credit unions, non-bank lenders, and equipment finance companies for document AI, financial spreading, credit memo drafting, covenant monitoring, and intake. Two things make it worth a conversation for an institution that arrived here from a mortgage search.

If your lending is broader than residential

Depository institutions rarely have only a mortgage book. If the same credit and QC function also carries C&I, commercial real estate, or equipment finance, the mortgage QC platform does not reach that work, and it is usually being handled in spreadsheets. That is the gap Uptiq is built for, and it sits alongside the mortgage stack rather than competing with it.

The evidence architecture is the same problem

The requirement that every generated figure be defensible is not specific to mortgage. Every figure Uptiq extracts carries a citation back to the page of the source document. Any figure or classification can be overridden by an analyst, with the prior value, the new value, the reason, and the user retained. Discretionary adjustments are surfaced for a decision rather than applied silently. The platform runs alongside the existing core and origination systems rather than replacing them, with 100+ integrations, and a single agent is typically live in about five business days.

95%+ extraction accuracy, 36% less time in financial spreading, and 41% faster underwriting, in production at 150+ financial institutions.Uptiq platform benchmark

If you are evaluating any AI vendor against the new agency requirements, the vendor diligence questions in SOC 2 Type II for lending AI cover the half that a security report does not answer, and how to review AI-generated financial spreads covers the review discipline that has to sit on top of any vendor's controls.

Seven questions that separate real audit support from a log file

Most demos in this category look alike, and every vendor will say yes to "do you support audit." These seven questions surface the difference in a single working session, and they apply at every layer.

1. Can you show me the evidence chain on one real file?

Pick a figure in the output and ask the vendor to walk it back to the page of the borrower document it came from, in the product, not in a slide. Everything else on this list is downstream of the answer.

2. What exactly is recorded when a human overrides the AI?

Prior value, new value, reason, user, and timestamp, or some subset. A system that silently accepts the correction has destroyed the evidence that a review happened.

3. Which model version processed this file, and can you tell me later?

LL-2026-04 assumes you can describe what AI was used and how. If the vendor cannot tell you which version ran on a file from four months ago, you cannot either.

4. How are model changes governed and communicated?

Are versions pinned, are changes announced before they reach production, and can you test first? Silent model updates are a model risk problem regardless of how good the update is.

5. How would either of us know accuracy had degraded?

Ask for the monitoring, the cadence, and what gets reported to you. The agency requirements assume ongoing monitoring rather than a one-time implementation check.

6. What will you provide to our model risk function and during an examination?

Documentation, not assurances. Vendors comfortable with regulated buyers have this assembled already; the ones who do not will offer to build it for you.

7. Is our borrower data used to train your models?

By default, and can it be contractually excluded? This is a question your counsel will ask eventually, and it is cheaper to ask it before the contract.

Two of those, questions three and six, are new to most evaluation scripts. They are the ones that have changed this year, and they are where vendors currently differ most.

How to run the evaluation

Test on a file that already caused you a problem

Give every vendor the same package, and choose a bad one: a self-employed borrower with two years of returns and a K-1, a scanned bank statement, a document that contradicts the 1003, and a defect your own QC team found after the fact. Ask each vendor to produce their output and then to evidence it. The exercise resolves the layer question in under an hour, which no feature matrix will.

Then confirm the operational fit

  • How does the sample get selected, and can the methodology be configured to your QC plan rather than the vendor's default?
  • What does the rebuttal and cure workflow look like, including who approves and how the resolution is recorded?
  • What trend reporting exists at portfolio level: defect rate by category, by channel, by branch, by originator, over time?
  • How does it read from and write to your LOS, your document repository, and your servicing system?
  • What is genuinely live in 30 days, what does that require from your team, and what is on a roadmap?
  • What does the vendor provide when your investor, your regulator, or a GSE asks how AI was used on a sampled file?

One sequencing note. If you are replacing the document layer and the QC layer at the same time, stagger them. When defect rates move after a dual rollout, nobody can say which change caused it, and that ambiguity tends to outlast both projects.

For the adjacent decisions, the companion guides are AI mortgage underwriting fraud detection and best AI for business document analysis.

Frequently asked questions

What is the best AI mortgage lending platform with strong QC and audit support in 2026?

There is no single best platform, because QC and audit support is delivered at three different layers and most lenders end up buying at two of them. For agency-aligned pre-funding and post-close QC with defect taxonomies, sampling, and trend reporting, the dedicated platforms are ACES Quality Management, Indecomm's AuditGenius, and LoanLogics. For the document and income data those audits run on, Ocrolus and Infrrd are the AI-native options. For audit capability inside the origination system itself, ICE Mortgage Technology and Dark Matter Technologies both now ship governed AI inside Encompass and Empower respectively. Start by naming which layer your gap is in.

What does Fannie Mae Lender Letter LL-2026-04 require?

It requires seller/servicers using AI or machine learning in origination or servicing to have policies and procedures covering how those systems are developed, implemented, used, and maintained, and how AI risk is measured and managed. Those policies must be communicated to the staff who use AI, reflect the applicable legal and regulatory requirements, be based on the lender's own risk tolerance, and have a named owner who reviews them at least annually. The letter also requires compliance with the Fannie Mae Information Security and Business Resiliency Supplement, and governance of subcontractor and vendor use of AI that is no less protective. On request, the lender must promptly disclose what AI is used, for what purpose, and what safeguards are in place. It was issued April 8, 2026 and took effect 120 days later.

Does a document AI vendor replace a QC platform?

No, and treating them as interchangeable is the most common purchasing error in this category. Document AI classifies, extracts, and validates the data in the loan file. A QC platform selects the sample, runs the file against agency and investor guidelines, records the defect and its severity, manages rebuttals and cures, and produces the trend reporting the agencies expect. They compose well and they are not substitutes; a strong document layer makes QC faster and better evidenced, but it does not perform the audit.

Should QC and audit come from our LOS vendor?

It is the convenient answer and sometimes the right one, particularly if you are standardized on the platform and your QC need is largely workflow and recordkeeping. The thing to test specifically is the audit and defect layer on a real file, because QC capability inside an origination system is generally built as one feature of a platform designed for something else. Many lenders run a dedicated QC platform alongside the LOS for exactly this reason.

What audit evidence should an AI mortgage tool be able to produce?

At minimum: which model or tool version processed the file and when, what it produced, the source document and page behind every extracted figure, who reviewed the output, and every override with the prior value, the new value, the reason, and the user. If a reviewer cannot reconstruct how a number reached the file, the file has an assertion in it rather than a tested result, and reconstructing it later costs as much as doing the work by hand.

Is this an independent ranking?

No. Uptiq publishes this page and sells lending AI, though not residential mortgage QC software, so read it as a vendor's guide rather than analyst research. The layer framework and the evaluation questions are written to stay useful to a reader who picks a product we did not list, and the vendor descriptions are drawn from public sources rather than from our own competitive positioning.

Vendor information is compiled from publicly available sources as of September 2026 and may be out of date. Product names, ownership, and capabilities change, and capability varies by configuration. Nothing here is an endorsement of, or a statement about the current capabilities of, any third-party product; verify directly with each vendor. Agency, investor, and examination requirements are set by Fannie Mae, Freddie Mac, HUD, your investors, and your regulators, and the summaries here are not a substitute for the source documents or for advice from your own compliance, model risk, and legal teams.

Different book, same evidence problem

If your credit team also carries commercial, CRE, or equipment finance, send us one real file. We will spread it, cite every figure to the page it came from, and show you what the override record looks like.