Start Free Trial
Home/Regulations/HMDA — Home Mortgage Disclosure Act — Regulatory Reference
Regulatory Reference
Real Estate Federal (US) high

HMDA — Home Mortgage Disclosure Act — Regulatory Reference

Loan-level data on AI underwriting decisions — lineage tracking and access logging support fair lending audit requirements.

Key Provisions
  • Regulation C (12 CFR Part 1003) implements HMDA
  • Loan Application Register (LAR) — detailed loan-level data
  • Application processing time, denial reasons, applicant demographics
  • Used by regulators for fair lending exams
How AutoPIL Enforces It
  • Source registry documents authoritative loan and applicant data
  • Audit chain provides lineage for AI-derived underwriting decisions reported in the LAR
  • Agent registry documents AI agents whose outputs influence LAR-reportable decisions
Audit LogPolicy EngineSensitivity LabelsLineage
AutoPIL Policy IDs
RE-HMDA-LAR-001LAR Reporting Lineage Audit
RE-HMDA-FL-001Fair Lending Audit Support
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does HMDA require for AI agents used in mortgage underwriting?
HMDA (implemented by Regulation C, 12 CFR Part 1003) requires lenders to collect and report loan-level data in the Loan Application Register (LAR), including application outcomes, denial reasons, and applicant demographics. When AI agents influence underwriting decisions — credit scoring, risk assessment, document review — those AI-derived outputs become inputs to LAR-reportable decisions. Lenders must be able to trace which data the AI agent accessed, which model version made the recommendation, and what policy governed that access. Without data lineage from the moment of retrieval through the reported outcome, regulators cannot assess whether the AI introduced fair lending violations. HMDA compliance for AI requires access logging and decision lineage, not just final LAR data.
When does HMDA apply to mortgage lenders using automated decision systems?
HMDA applies to any financial institution — bank, credit union, mortgage company, or savings association — that meets Regulation C's volume and asset thresholds and originates or purchases covered mortgage loans. When that institution uses an AI agent to assist with underwriting, pricing, or application processing, HMDA's audit requirements extend to the data and logic those agents touch. The CFPB's fair lending supervisory program uses HMDA data as a screening tool to identify disparate impact. If an AI system produces outcomes that show demographic disparity, examiners will request documentation of what data fed the model. Institutions that cannot produce that documentation face elevated scrutiny and potential referral to the DOJ.
What are the fair lending audit risks under HMDA for AI-assisted underwriting?
HMDA data is the primary screening tool CFPB and federal bank regulators use to identify fair lending violations — disparate treatment and disparate impact. For AI-assisted underwriting, the audit risk is two-sided. First, if the AI accessed biased or incomplete training data, the model's outputs may reflect that bias in loan approvals and pricing — visible in LAR statistics. Second, if the lender cannot produce documentation of what data the AI accessed for a specific application and why an outcome occurred, examiners cannot isolate whether a violation stems from the model, the data, or human override. Penalties include civil money penalties, required remediation programs, and DOJ referral for pattern-or-practice violations. Unexplained AI decision chains are a growing examiner focus.
How does AutoPIL support HMDA compliance for AI agents in mortgage lending?
AutoPIL enforces access policy before sensitive loan and applicant data enters the AI agent's context window and writes a tamper-evident audit record of every decision. For HMDA, this creates the data lineage trail examiners require: which AI agent accessed which loan file, which source data was retrieved, and what policy governed that retrieval — tied to the exact LAR-reportable decision. AutoPIL's source registry documents authoritative loan and applicant data assets. The agent registry records which AI models and agents influenced underwriting. Policy IDs RE-HMDA-LAR-001 and RE-HMDA-FL-001 map directly to LAR reporting lineage and fair lending audit workflows. The cryptographic audit chain ensures the record cannot be altered after the fact, satisfying examiner requests for complete and reliable decision documentation.
What is the Loan Application Register (LAR) and why does it matter for AI governance?
The Loan Application Register is the loan-level dataset every HMDA-covered institution must compile and submit annually to the CFPB. It captures application date, loan type, property location, applicant demographics, action taken, denial reasons, and pricing data for each covered transaction. Regulators use the LAR to run statistical analyses that flag potential fair lending violations. When AI agents assist with underwriting, their outputs feed directly into LAR-reportable outcomes — approval, denial, pricing. If an AI recommendation cannot be linked to documented data inputs and access controls, the institution cannot explain disparities found in its LAR. AI governance programs that treat the LAR as just a reporting exercise — rather than the audit anchor it is — leave examiners without the lineage trail needed to clear fair lending findings.
Covered Industries

HMDA applies to banks, credit unions, mortgage companies, and savings associations that meet Regulation C's coverage thresholds. For any of these institutions deploying AI agents in mortgage origination or underwriting, HMDA's fair lending audit requirements create a direct obligation to document and retain data lineage for every AI-influenced decision reported in the Loan Application Register.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries