Skip to content
Sei
Compliance

How Long the Agent's Evidence Has to Live: Retention Clocks for AI Mortgage Records Under Reg B, Reg Z, and Reg C, and the Default That Deletes Your Proof

9 min read
Ramkumar Venkataraman
Share

The Record That Proves the Decision Is the One You Forget to Keep

An AI agent in a mortgage workflow produces two things. It produces the decision or the document, the priced rate, the cleared condition, the adverse-action reason, the disclosure, and it produces the record of how it got there, the inputs it read, the values it computed, the timestamp, the version of the logic that ran. The first thing is the product. The second thing is the proof, and the proof is the part that gets built casually and deleted early, because it looks like operational logging rather than like a regulatory record. It is a regulatory record. The rules that govern mortgage lending do not just require the lender to do the right thing; they require the lender to keep the evidence that it did, for a defined period, and to produce it on demand. An agent whose reasoning is gone by the time an examiner asks is an agent that leaves the lender unable to prove a decision that may have been entirely correct.

We build the agent that touches origination and servicing records on lender platforms, and the retention of what the agent produces is a design problem we got wrong early enough to take seriously. The failure is quiet, because retention defaults do not throw errors. A log store with a ninety-day time-to-live does its job perfectly and destroys your evidence on schedule, and you find out fourteen months later when the exam or the complaint arrives and the record is gone. What follows is the set of clocks that actually govern, why they have to be keyed to the loan rather than to the infrastructure, and the litigation overlay that suspends all of them.

The ECOA Twenty-Five-Month Clock

The first clock is the Equal Credit Opportunity Act's, and it runs off the application. Regulation B at 12 CFR 1002.12 requires a creditor to retain records relating to a credit application for 25 months after the date the creditor notifies the applicant of the action taken, for consumer credit, and it reaches the material the agent produces during intake and decisioning, the application data, the information used in evaluating the application, and the adverse-action notice and the reasons behind it. The clock does not start at closing and it does not start at the pull. For most applications it runs from the notification of action taken, and Regulation B measures the other outcomes from their own events, a withdrawn application from the withdrawal, an incomplete application from the notice of incompleteness where one is given, and an application for which no notification is required from the date the creditor receives it. So the retention obligation is keyed to whichever per-application event actually applies, which the agent has to identify and record precisely, because the clock is measured from that event rather than from a single fixed point on every loan.

The reason this matters for an AI system specifically is that the agent's evaluation of the application is exactly the record the 25-month rule wants preserved. When an agent computed a value, flagged a condition, or produced the reasons that fed an adverse-action notice, the record of that computation is the record of how the application was evaluated, and 1002.12 wants it kept for the full period so that a fair-lending review, or the applicant, or the examiner can reconstruct the basis of the action. An agent that logs its reasoning to a store with a shorter horizon than 25 months has produced compliant decisions whose compliance it cannot demonstrate for most of the window the rule cares about.

The TILA Clocks, Which Are Longer and Split

The second set of clocks comes from the Truth in Lending Act, and they are longer than the ECOA clock and they split by document type, which is the part that trips a flat retention policy. Regulation Z at 12 CFR 1026.25 sets a general two-year retention for evidence of compliance, and then, for closed-end mortgages, it lengthens the period for the TRID records specifically. Under 1026.25(c)(1), the creditor has to retain evidence of compliance with the Loan Estimate and Closing Disclosure requirements of 1026.19(e) and (f) for three years after consummation, and it has to retain the Closing Disclosure and documents related to it for five years after consummation. The loan originator compensation records under 1026.25(c)(2) carry their own three-year period.

So a single mortgage loan generates records on at least three different Reg Z horizons, and the horizons do not share an anchor. The two-year general period under 1026.25(a) runs from the date the disclosures were required to be made or the action was required to be taken. The three-year TRID-compliance period under 1026.25(c)(1)(i) runs from the latest of consummation, the date the disclosures were required to be made, or the date the action was required to be taken, so a post-consummation correction can push that anchor past consummation. Only the five-year Closing Disclosure period is a flat clock from consummation. Those anchors differ from one another and from the ECOA clock's action-notification date, which is the whole problem with a flat retention policy. An agent that produced the Loan Estimate data, that tracked the changed-circumstance redisclosures, or that assembled the Closing Disclosure has produced evidence of compliance with 1026.19(e) and (f), and that evidence lives on the three-year clock, while the Closing Disclosure record itself lives on the five-year clock. A retention policy that keeps everything for two years satisfies the general rule and destroys the TRID evidence a full year early and the Closing Disclosure evidence three years early, and it does so silently, because two years is a plausible-sounding default that happens to be wrong for the documents that matter most on a mortgage.

The HMDA Clock and the Data Underneath It

The third clock is the Home Mortgage Disclosure Act's. Regulation C at 12 CFR 1003.5(d) requires a covered institution to retain its loan/application register for three years, and the field-provenance record that supports the LAR belongs to the same retention posture, because a LAR the institution cannot reconstruct from its underlying records is a LAR the institution cannot defend on examination. The HMDA clock runs on the reporting cycle rather than on the individual loan's consummation, which is yet another anchor, and an institution that stores its LAR support on the loan's servicing-transfer schedule can lose the support before the three-year HMDA window closes if the loan leaves the platform.

The pattern across these three regulations is the point. ECOA runs 25 months from the action event that applies to the application. Reg Z runs two, three, and five years depending on the document, from anchors that are not all consummation. Reg C runs three years on the reporting cycle. There is no single number that satisfies all of them, and the longest applicable clock on a given loan depends on which records the agent produced for it. A retention design that picks one number for everything is guaranteed to be too short for some records and pointlessly long for others, and the too-short direction is the one that costs the lender the ability to prove compliance.

Why Retention Has to Be Keyed to the Loan, Not the Storage

The design conclusion is that retention is a property of the record and the loan event, not a property of the storage tier. Each record the agent produces gets a retention class that names the governing rule and the anchoring event, the ECOA record keyed to the application's applicable action event with a 25-month horizon, the TRID-compliance record keyed to the latest of consummation and the required disclosure or action date with a three-year horizon, the Closing Disclosure record keyed to consummation with a five-year horizon, the LAR-support record keyed to the reporting cycle with a three-year horizon. The record carries its own clock, and the deletion logic reads the clock on the record rather than applying a blanket time-to-live to the store.

This is the same discipline the field-provenance file follows on the HMDA pipeline and that the audit trail follows at the LOS system-of-record boundary, and it has one more requirement the loan lifecycle forces, which is that the record has to survive the loan moving. A mortgage does not stay in one system. It moves from origination to servicing, it may transfer servicers, and the origination-era records the ECOA and TRID clocks want kept are still on their clocks after the loan has left the platform that created them. So the agent's records are retained against the loan's identity and their own retention class, in storage that outlives the loan's tenancy in any one system, rather than in the operational store of the platform that happened to produce them, because a record deleted when the loan transferred is a record deleted before its clock ran out.

The Litigation Hold That Overrides Every Clock

Every retention clock above describes the minimum period to keep a record, and every one of them is overridden upward by a litigation hold or a preservation obligation. When a loan becomes the subject of a complaint, a dispute, a regulatory inquiry, or litigation, the ordinary retention schedule stops applying to that loan's records and they have to be preserved until the matter resolves, regardless of whether the regulatory clock would otherwise have expired. Destroying records under a routine retention policy after a preservation duty has attached is spoliation, and it is a worse problem than the underlying matter, because it converts a defensible decision into an adverse inference about what the destroyed records would have shown.

The mechanism for this in an automated system is a hold flag that suspends deletion, applied at the loan level and evaluated by the deletion logic before any record is destroyed. The deletion logic never deletes a record whose loan carries an active hold, even when the record's own retention clock has expired, and it resumes ordinary retention only when the hold is released. The reason this has to be built rather than handled procedurally is that automated deletion runs on schedule and does not pause to ask whether a loan is in litigation, so the pause has to be a value the deletion logic checks, not a person the logic assumes will intervene. An agent that deletes on its retention clock without checking a hold flag will, eventually, destroy the records of exactly the loan someone is suing over, because that is the loan whose records the clock and the plaintiff both had reason to reach at the same time.

The Failure Mode We Engineered Against

The failure that produced this whole design was mundane and total. On an early build the agent's decision logs, the record of what it read and computed and why, lived in the platform's operational logging store, which carried an infrastructure retention default measured in months because it was sized for debugging and observability rather than for regulatory recordkeeping. The decisions the agent made were sound and the documents it produced were correct. The evidence of how it made them aged out on the infrastructure clock, and when we went to reconstruct a decision from a loan that was well within its ECOA and TRID windows, the operational reasoning behind the agent's output was gone, because the store it lived in had done exactly what it was configured to do.

Nothing broke, which is what made it dangerous. There was no error, no alert, no failed job. The evidence was simply not there when it was needed, and the gap was invisible until the moment it was expensive. The decision from that was to separate the agent's regulatory records from its operational logs entirely, to give each regulatory record a retention class keyed to its governing rule and loan event, to store those records against the loan's identity in a tier that outlives the operational platform, and to gate all deletion behind the litigation-hold flag. Observability logs still expire on the short infrastructure clock, because that is what they are for. The records that prove a decision was compliant live on the clock the regulation sets, and they do not share a deletion policy with the debug logs ever again.

Retention Is Part of the Control, Not Cleanup After It

The instinct is to treat recordkeeping as housekeeping that happens after the real compliance work is done, and that instinct is what deletes the proof. The record of how the agent reached a compliant decision is not separate from the compliance; it is the demonstrable part of it, and a decision whose basis cannot be produced for the period the rule requires is, for practical purposes, a decision the lender cannot defend. The clocks are specific and they do not agree with each other, 25 months from notification under Reg B, three and five years from consummation under Reg Z, three years on the cycle under Reg C, and no single storage default satisfies them. We build the agent to attach a retention class to every record it produces, to key each clock to the loan event the rule measures from, to keep the record alive after the loan leaves the platform, and to stop every deletion at a litigation hold. The evidence outlives the loan's tenancy in any one system because the obligation to produce it does, and building retention as a property of the record is the only version of this that stays correct while loans move and clocks run underneath it.

Ramkumar Venkataraman

Ramkumar Venkataraman

CTO & Co-Founder

Related Articles

Compliance

When the Model Writes the Ad: Mortgage Marketing Copy Under the MAP Rule and Reg Z 1026.24, and the Review Gate Before a Generated Line Ships

Generative AI now drafts mortgage emails, landing pages, and social copy at a scale no compliance team has reviewed a piece at a time. The moment a model writes a sentence about a rate or a payment, two regimes bite: Reg Z 1026.24 triggering terms and the MAP Rule, Regulation N at 12 CFR 1014, which bars material misrepresentation about a mortgage credit product and makes you keep every materially different version for 24 months. Here is the gate we put between the model and the send, the 'no closing costs' line it caught, and why AI turns the recordkeeping rule from a burden into a byproduct.

Sep 24, 20265 min read
Read more
Compliance

Serving the Borrower Who Applied in Spanish: Limited-English-Proficiency Mortgage Origination With AI, the CFPB Line, and Where a Translated Disclosure Becomes a Liability

AI voice and chat agents make it cheap to talk to a borrower in their language, which is exactly why the risk moves from access to accuracy. Where ECOA and the UDAAP standard still draw the line after the CFPB pulled back its 2021 guidance, why we run the conversation in the borrower's language but keep the operative disclosures in English, and the translation-QA control that stops a servicing term from drifting in the second language.

Sep 16, 20268 min read
Read more
Compliance

Trigger Leads After the Homebuyers Privacy Protection Act: What an AI Outreach Agent Can Buy, Call, and Text in 2026

The Homebuyers Privacy Protection Act amended FCRA 604(c) and took effect March 5, 2026. Here is the eligibility gate an AI outreach agent has to run before it dials a prescreened mortgage lead, the exceptions that still let you contact your own borrowers, and the audit file that proves the lead was legal.

Sep 1, 20267 min read
Read more

You Ain't Seen Nothin' Yet

Book a Demo
Pack up some of your complex historical files — any loan type, any investor. We run them through intake, income and condition clearing, and in 30 minutes you see every condition we created and cleared efficiently for your own team, and why.
  • Any loan type, any agency guideline or custom investor overlays.
  • Every finding cited to the guideline or document it came from

Please provide your full name so we know how to address you.

Tell us which company you represent so we can personalise our response.

Use your work email so we can connect you with the right specialist.

Which desks would you like to discuss?*

Choose the desks you’d like us to cover. Pick “Not sure yet” if you’d rather we worked it out on the call.

Roughly, so we bring the right person to the call.

Complete the verification to submit the form.