AI and automation for brokers
Mortgage broker AI governance policy: what to include
A practical policy framework for data handling, human review, client transparency, permissions and audit trails when using AI.
An AI policy for a mortgage firm should be short enough that the team reads it and specific enough that it settles arguments. A long document that nobody opens gives you no protection; three pages that people can actually apply will change behaviour.
What follows is a structure for that document, section by section, with the questions each section has to answer.
Scope and approved tools
Name the tools that are approved and say what each may be used for. A list is better than a principle here, because staff need to know whether the thing on their phone is allowed.
State plainly that any tool not on the list is not approved for client information, and give people a route to ask for something to be added. A policy with no path to approval produces exactly the unrecorded usage it was written to prevent.
Say what AI is not used for. The clearest wording covers regulated advice, suitability assessment, affordability judgement, lender selection and any client-facing communication that has not been reviewed by a named person.
Data and confidentiality
Define what client information may be processed and by which tool. Cover recordings and transcripts, bank statements and payslips, identity documents, and anything concerning a client's health or personal circumstances.
Set the rules for retention, deletion, access and supplier review, and state where processing takes place. Include the sentence that does the most work: client information is never pasted into an unapproved tool, however convenient it would be.
Explain how to report a suspected data incident, to whom, and how quickly. Make the reporting route a name, not a department.
Human review and accountability
For each approved use, say who reviews the output and what they check. Name the roles rather than leaving it to whoever is nearest.
State the principle explicitly: a member of the firm remains accountable for the record and the client outcome even where a system produced the first draft. Say where the approved version is stored and how it is distinguished from a draft, so that a file review months later can tell the difference.
Client transparency and consent
Explain when the firm records or transcribes a conversation, what the client is told, when they are told it, and what alternative is offered if they would rather not.
Set the rule for what may be said about your use of AI in marketing. Claims that a tool is accurate, impartial, secure or approved by anybody need to be true and evidenced. This is a financial promotion question as much as a technology one.
Roles and change control
Say who may approve a new tool or a new use of an existing one, and what they must consider before saying yes: purpose, data involved, review step, owner, and how it would be switched off.
Every workflow gets a named owner, training notes and a sign-off date. Nothing goes live because someone was experimenting and it seemed to work.
Monitoring, incidents and stopping
Describe what is monitored: correction rates, rejected outputs, complaints, missed tasks, anything sent in error. Say how often it is reviewed and by whom.
Give someone the explicit authority to pause a workflow immediately if it produces unsafe or misleading output, without needing permission first. Record incidents, what was done and what changed as a result. An incident log that shows problems being caught and fixed is evidence that the controls are real.
Training and competence
State that staff are trained before using an approved tool, and that the training covers how it fails as well as how it works. Keep a record of who has been trained on what.
Include a line about not losing the underlying skill. If a task is only ever done by a system, the firm loses its ability to judge whether the output is right, which is the thing the policy depends on.
Where the policy sits in the firm's wider arrangements
An AI policy is not a free-standing document. It should point at the arrangements you already have rather than duplicating them, and it should be consistent with them.
Cross-reference your data protection policy, your record-keeping and retention schedule, your financial promotions approval process, your complaints handling and your training and competence scheme. If any of those say something different from the AI policy, one of them is wrong and you should fix it now rather than during a review.
Say who signed the policy off and at what level of the firm. For a small business that is the principal; for a larger one it belongs with whoever holds responsibility for systems and controls. If you are an appointed representative, share it with your network and ask whether they have their own requirements, because they may, and finding out afterwards is worse.
Review
Put a review date on the document and keep it. The tools change, suppliers change their terms, and regulatory expectations develop. A policy dated two years ago tells a reviewer more about your governance than its contents do.
How to keep it usable
Write it in the same voice you use with clients. Avoid defining terms nobody uses. Keep the register of tools separate from the policy so the policy does not need rewriting every time you add one.
The purpose is not to prove the firm has a document. It is to let advisers use these tools confidently and consistently, and to stop anyone assuming an output is correct because it happens to read well.
Want to improve your broker workflow?
Speak to MortgageMatch about broker visibility, enquiry handling and practical ways to reduce admin without losing the human advice clients expect.
Contact MortgageMatch about this guide