Lenders and servicers vetting an AI vendor for compliance work should check for three things: independent certification of how the AI is governed, not a self-reported compliance statement; a documented method for measuring AI accuracy and triggering human review; and a track record of adapting to real regulatory changes on a real deadline. Those three checks separate a vendor with governed, defensible AI from one running an unproven model behind a compliance disclaimer.
Every vendor in mortgage technology now claims to “do AI.” For a lender or servicer trying to vet those claims, the harder question is how to tell which vendors have actually built AI that a regulator will accept. Outamation, a Dallas, Texas-based mortgage technology company, became the first U.S. mortgage technology company to achieve ISO/IEC 42001 certification, the international standard for AI management systems, and its leadership has a clear answer for what an ISO 42001 AI certification for mortgage lenders is meant to prove.
“It’s an independent, rigorous verification that we hold ourselves accountable for how our AI makes decisions, that it’s transparent, fair, and controlled,” said Outamation CEO Sapan Bafna. For a lender being examined by a regulator, that distinction is not academic. Being unable to explain how a vendor’s AI reaches a decision is a real liability during an exam, and Bafna said the certification exists specifically to remove that gap.
Why AI governance certifications answer a different question than data security certifications
Outamation holds three separate certifications: SOC 2 Type II, ISO 27001, and ISO 42001. Bafna explained that each one answers a different question a serious buyer will ask. SOC 2 and ISO 27001 address data security and handling. ISO 42001 addresses something newer and harder for a lender to verify on its own: whether the AI itself is being governed responsibly. Together, he said, the three certifications close the loop across data security, data handling, and AI governance under one roof.
That distinction matters for procurement and compliance teams specifically. Instead of taking a vendor’s word for it, they get documentation that has already been independently verified, which shortens due diligence and simplifies AI risk questionnaires that are becoming standard in vendor reviews for mortgage lenders.
Certification is not a substitute for evaluating a specific product against a specific workflow, though. ISO 42001 verifies how a vendor’s AI is governed across the organization; it does not certify the accuracy of any single model or use case, and a lender should still ask a certified vendor for use-case-level performance data rather than treating the certification itself as proof of fitness for a particular task.
How AI vendor compliance work should handle accuracy and human review
A common assumption is that a vendor moving fast on AI adoption is cutting corners somewhere. Outamation’s leadership pushed back on that framing directly. Every AI-driven extraction or decision includes a measured probability of accuracy, and clients can set their own thresholds for when a human needs to review the result before it goes out. Lisa Guadagno, VP of Global Strategic Initiatives and a board member at Outamation, who works closely with clients on implementation, described this as a deliberate design choice rather than a blanket safeguard. “We have a methodology where we say here are some things where it makes sense for us to insert a human into the process,” she said. It is not human review for its own sake. It is targeted at the specific cases where confidence is lower.
Bafna added that Outamation does not claim its AI performs at 100 percent accuracy on any use case, because internally the team does not believe that claim and treats accuracy as something to keep improving. Errors get tracked, fed back into the system, and used to improve future results.
Domain experience is what turns AI governance into fast regulatory response
Certifications only mean something if the underlying team understands the workflows they are automating. Bafna pointed to this as the real differentiator between Outamation and a generic robotic process automation or AI vendor entering the mortgage space. A generalist vendor can build a capable model, but it does not know the investor guidelines, the compliance requirements, or how a loan modification actually has to move through a servicer’s process.
That gap showed up concretely when FHA issued Mortgagee Letter 2025-14 on June 3, 2025. The letter superseded ML 2024-24 and made technical corrections to two earlier letters, ML 2025-06 and ML 2025-12, while the first tranche of its provisions became mandatory just four weeks later, on July 1, 2025. An Outamation client became the first servicer to launch FHA Partial Claim under FHA’s new loss mitigation framework, something Bafna attributed directly to the team’s depth in mortgage servicing rather than general AI capability. FHA has since updated the guidance again with ML 2025-21, issued in the fall of 2025, a reminder that vendors working in this space need to track compliance on a rolling basis rather than treat any single mortgagee letter as a fixed target.
The same pattern is now unfolding with the VA. On June 1, 2026, the VA published the final version of its updated Servicer Handbook, M26-4, adding a new Loss Mitigation Waterfall and a VA Partial Claim program. The program went live on June 15, 2026, and servicers must be fully compliant by November 28, 2026, 180 days after the handbook’s effective date. Because the VA Partial Claim can only be offered when a borrower is routed to it through the waterfall, and the guidance requires the two to be implemented together, a servicer cannot comply by automating one piece in isolation. It has to automate the decisioning that moves a delinquent loan through the waterfall to the right option. In August 2026, Outamation announced that its OutamateMods platform was the first to bring VA Partial Claim waterfall decisioning into client user acceptance testing, with a top 10 servicer already testing a finished solution well ahead of the deadline.
What lenders should ask an AI vendor before signing
For a lender or servicer evaluating AI vendors on compliance work, the practical questions are straightforward. Ask for independent certification, not a self-reported compliance statement. Ask how the vendor measures AI accuracy and where human review kicks in. Ask how quickly the vendor has adapted to recent regulatory changes, since that track record says more than a product roadmap. And ask what the certification does not cover, since a vendor willing to draw that line clearly is usually the one being straight about the rest of it too.
About Outamation: Outamation is a mortgage technology company based in Dallas, Texas, providing AI-driven automation for loan modifications, document processing, and quality management across the mortgage servicing lifecycle. Outamation is the first mortgage technology company in the United States to achieve ISO/IEC 42001 certification for AI governance, in addition to ISO 27001 and SOC 2 Type II.
Disclaimer: This article is based on information provided by the expert source cited above. It is intended for general informational purposes only and does not constitute legal, financial, or real estate advice. Readers should conduct their own research and consult qualified professionals before making any real estate or financial decisions.







