All posts by Synergy

Mortgage AI/ML Compliance Q&A: Governance, Fair Lending, and Exam Readiness

AI/ML compliance for mortgage lenders is no longer a future-state planning exercise. Fannie Mae’s LL-2026-04 took effect August 6, 2026. Freddie Mac’s Section 1302.8 took effect March 3, 2026. The Colorado AI Act took effect February 1, 2026. The California DFPI is actively examining AI/ML programs. State AGs are bringing actions under existing UDAP authority.

This Q&A focuses on the practical questions your compliance team will face as the AI/ML governance framework comes into operational reality in 2026 — what to build, what to document, what examiners are looking at, and how to keep the program running as models evolve and rules change.

Q1: We Just Discovered LL-2026-04. What Do We Do First?

The first step is the AI/ML use case inventory. You cannot scope a governance program without knowing which systems are in scope. The inventory should identify every AI/ML system used in the mortgage lifecycle, the business function each supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

A common mistake is to start with the governance policy. A policy written before the inventory is complete is a policy that does not match the actual system footprint. The inventory drives the policy, not the other way around.

Aim to have a complete inventory within 30 days. Most lenders underestimate how many AI/ML systems they actually run — the inventory typically surfaces 30-50% more systems than the compliance team expected.

Q2: How Do We Decide Which AI/ML Systems Are “High-Impact”?

The GSE frameworks and the Colorado AI Act both use a risk-tiering approach. The relevant question for a high-impact designation is whether the system can materially affect a borrower’s loan terms, access to credit, or experience in the loan process.

High-impact systems for mortgage lenders typically include:

  • Automated underwriting systems (AUS)
  • AI-driven appraisal valuation models (AVMs with machine learning components)
  • AI-driven fraud detection models that affect application decisions
  • Pricing optimization models that influence loan pricing
  • Lead scoring models that affect credit decisions
  • Income and asset verification tools that use AI
  • Customer service chatbots that handle credit-related inquiries

Lower-risk systems include internal marketing analytics, business intelligence dashboards, and back-office automation that does not affect borrower outcomes. Document the risk tiering methodology so examiners can review the logic.

Q3: What Counts as an “AI/ML System” for Compliance Purposes?

The LL-2026-04 definition tracks the broad industry usage. An AI/ML system is any system that uses statistical learning, neural networks, natural language processing, or other machine learning techniques to produce an output from training data. Generative AI (text or image generation), predictive models, classification models, and clustering models are all in scope.

Out of scope: rule-based decision engines that do not learn from data, simple threshold-based scoring (e.g., credit score lookups without model adjustment), and traditional statistical models without a learning component. The key question is whether the system’s parameters are learned from data rather than set by human designers.

When in doubt, include the system in the inventory and document the determination. The cost of including a borderline system is much lower than the cost of an examiner discovering a missed system.

Q4: How Do We Build a Fair Lending Testing Program for AI/ML?

A defensible fair lending testing program has four components.

1. Outcomes-based testing. Compare actual loan decisions, pricing, or other outcomes across demographic segments. The relevant segments under federal law are race, national origin, sex, religion, familial status, age, and disability. Under state law, additional protected categories may apply.

2. Input-based testing. Audit model features for proxy variables that correlate with protected classes even when the protected class is not a direct input. ZIP code is a classic proxy for race. Language preference can be a proxy for national origin. Proxies are not always a violation, but they require documentation of why the proxy is appropriate and how its use is monitored.

3. Segment-level performance review. Model accuracy, false positive rates, and false negative rates should be reviewed at the segment level. A model that performs well on average but has materially different error rates across protected segments is a model that needs remediation before deployment.

4. Counterfactual testing. For loan decisions, change the protected class of an applicant and observe whether the decision changes. If the decision changes when only the protected class changes, the model is using protected class or proxy information inappropriately.

The testing should be performed before deployment, after material model changes, and at a defined cadence — at least annually for high-impact systems.

Q5: What Documentation Do Examiners Look For First?

Examiners start with the inventory and the governance policy. From there, the document request typically expands to model documentation, validation reports, fair lending testing, vendor contracts, and the most recent attestation.

The most common finding in early AI/ML examinations is a gap between what the inventory claims and what the documentation actually supports. Lenders may claim to have a fair lending testing program but produce a single slide with results, not a documented testing protocol with methodology, results, and remediation actions.

The exam-ready binder for AI/ML governance should include:

  • AI/ML use case inventory with risk tiering
  • Governance policy approved at senior committee level
  • Model documentation for each high-impact system (data sources, training methodology, performance metrics, validation results)
  • Fair lending testing reports for each high-impact system
  • Vendor contracts with AI/ML-related terms
  • Annual attestation
  • Incident log (any model failures, complaints, regulatory inquiries)

Q6: How Do We Handle AI Tools That Loan Officers Use Independently?

If loan officers use AI tools (ChatGPT, Claude, specialized mortgage AI assistants, etc.) in connection with loan files, the tools are in scope under LL-2026-04 and Section 1302.8. The lender is the deployer and is accountable for the tool’s compliance.

The minimum controls: an approved list of AI tools that may be used in connection with loans, prohibition on uploading borrower non-public personal information to tools that have not been approved, a confidentiality review of the tool’s data handling practices, and a documented training program for loan officers on the approved-use policy.

The most common exam finding: lenders have no visibility into which AI tools loan officers are using. Shadow AI use is a significant risk, and lenders are expected to address it proactively.

Q7: How Should We Structure the AI Governance Committee?

The committee structure varies by institution size. For mid-size and large lenders, the typical structure is:

AI Governance Committee: senior leadership (CRO, CIO, General Counsel, Head of Compliance, Head of Model Risk) meets quarterly or more frequently. Approves the governance policy, reviews high-impact model changes, signs off on attestations.

Model Risk Management function: dedicated staff (or a vendor) that runs the inventory, conducts validation, performs fair lending testing, maintains documentation.

Model Owners: business line leaders responsible for individual AI/ML systems. Own the system lifecycle, escalate issues to the committee, ensure documentation is current.

For smaller lenders without dedicated model risk staff, the model risk function may be outsourced or combined with compliance. The committee structure remains the same; the execution is shared.

Q8: How Do We Balance AI Innovation with AI Compliance?

The right framing is not “innovation vs. compliance” — it is “innovation with governance.” A model that cannot be explained to an examiner is a model that creates regulatory risk. A model that produces disparate outcomes is a model that creates litigation risk. Governance is what makes innovation sustainable.

The practical implementation: the governance framework should be designed to support business velocity, not slow it down. Pre-deployment validation, fair lending testing, and documentation should be efficient and well-scoped. The model risk function should be a partner to the business, not a bottleneck.

A common failure mode: over-engineering the governance process to the point where business teams route around it. The result is shadow AI use — business teams adopt new tools without governance review, and the compliance program loses visibility into the actual system footprint.

Q9: What Is the Most Common AI/ML Compliance Failure You See?

The most common failure is treating the AI/ML governance program as a documentation exercise rather than an operational one. Lenders produce a policy and a checklist, but they do not actually run the inventory, conduct the validation, or perform the fair lending testing. When the examiner asks for the supporting documentation, the program collapses.

The second most common failure is treating vendor-provided validation as a substitute for lender validation. The lender is accountable for the model’s performance in its own use context. The vendor’s validation report is an input, not an output.

The third most common failure is fair lending testing that is too narrow — testing only adverse action outcomes and missing proxy variable analysis, or testing only protected classes under federal law and missing the additional state-level protected categories.

Q10: Where Should AI/ML Compliance Be on the Q3 2026 Priority List?

For lenders that have not yet built a program, AI/ML governance should be at the top of the Q3 2026 priority list. The LL-2026-04 effective date has passed, and the first attestation cycle is approaching. The work cannot wait for Q4.

The Q3 priorities, in order:

This month: Complete the AI/ML use case inventory. Identify model owners and risk tiering.

Next 30 days: Draft the governance policy. Get committee approval.

Next 60 days: Begin fair lending testing for the highest-impact systems. Document the testing methodology.

By year-end: Complete the first round of validation. Stand up the annual attestation process. Build the exam-ready binder.

For lenders with a program already in place, the Q3 priority is to harden the documentation for examiner review and to verify the program covers the new state-level rules — particularly the Colorado AI Act if you originate or service in Colorado.

Need support on AI/ML governance, fair lending testing, or state-level compliance overlay? Synergy works with mortgage lenders on AI/ML program design, validation, multi-state compliance overlays, and exam readiness. Book a 30-minute AI/ML review.

State AI/ML Enforcement for Mortgage Lenders: What You Need to Know in 2026

Federal AI/ML guidance for mortgage lending remains a patchwork. The CFPB has issued interpretive guidance, the GSEs have published AI governance frameworks, and Congress has considered — but not passed — federal AI legislation. In the absence of a unified federal standard, state regulators have moved ahead with their own rules.

For mortgage lenders operating in multiple states, the practical effect is a growing set of state-specific AI/ML obligations layered on top of federal and GSE requirements. This article walks through the state rules that affect mortgage lenders in 2026, how they interact with each other and with federal frameworks, and what a defensible multi-state AI compliance program looks like.

Why State AI/ML Regulation Matters for Mortgage Lenders

State AI/ML rules were not written with mortgage lending as the primary use case. Most originate in consumer protection, employment, or insurance contexts. But the definitions of “automated decision tool,” “high-risk AI system,” and “consumer” are broad enough to capture mortgage lending activity — and state regulators have signaled that they will apply their AI rules to financial services, not just to the originally-targeted industries.

The compliance exposure is not theoretical. State AGs have been active in 2025 and 2026, with several settlements against financial services firms involving AI/ML use. Mortgage lenders that treat state AI compliance as a low-priority “tech company” issue are misreading the landscape.

Colorado AI Act (SB 24-205)

The Colorado AI Act took effect on February 1, 2026. It is the most comprehensive state AI statute in the United States and the one most likely to set a template for other states.

Who It Applies To

The Act applies to “developers” and “deployers” of “high-risk AI systems” used in Colorado. A deployer is any entity that uses a high-risk AI system to make decisions that affect Colorado residents. Mortgage lenders that use AI/ML systems for Colorado residents — including in origination, servicing, marketing, or customer service — are deployers under the Act.

What Counts as a High-Risk AI System

The Act specifies categories of high-risk systems. The relevant categories for mortgage lenders include:

  • AI systems used to make decisions about access to financial services, including credit
  • AI systems used for employment decisions (relevant for HR, recruiting, and internal loan officer evaluation)
  • AI systems that materially affect access to housing

Automated underwriting systems, AI-driven pricing tools, lead scoring systems that influence credit decisions, and AI-driven appraisal valuation models are all high-risk under the Act.

What Deployers Must Do

Deployers must implement a risk management program and policy, complete an impact assessment for each high-risk system, provide notice to consumers that an AI system is being used, and allow consumers to request human review of an AI-driven decision. The impact assessment must be made available to the Colorado AG on request.

The Act also prohibits algorithmic discrimination — defined in ways that overlap significantly with federal fair lending law but include additional categories of protected activity.

California AI Rules

California does not yet have a comprehensive AI statute, but the state has a layered set of AI-related rules that affect mortgage lenders.

AB 2013 (Generative AI Training Data)

AB 2013 requires developers of generative AI systems to publish a summary of the training data used. The rule is targeted at generative AI providers, not at deployers. For mortgage lenders, the relevance is downstream: if you use a generative AI tool (e.g., for document drafting, customer service), the underlying provider’s compliance affects your vendor risk profile.

SB 942 (AI Transparency)

SB 942 requires AI providers to offer a free AI detection tool to users. The rule is targeted at AI providers, not at deployers. The relevance is the same as AB 2013 — vendor due diligence.

California Department of Financial Protection and Innovation (DFPI)

The California DFPI has been the most active state financial regulator on AI/ML. The DFPI has issued multiple guidance documents on AI use in lending, conducted examinations focused on AI/ML systems, and entered into consent orders with lenders involving AI/ML model risk management and fair lending testing.

The DFPI’s approach is consistent with the federal and GSE frameworks, but it includes California-specific requirements on consumer notification, model documentation, and the right to human review. For lenders operating in California, DFPI expectations are effectively a fourth layer of AI/ML governance on top of CFPB, GSE, and other state rules.

New York State and City

New York has not passed a comprehensive state AI statute, but the New York Department of Financial Services (DFS) has issued guidance on AI/ML use by regulated financial institutions. The DFS guidance is supervisory in nature — not a binding regulation — but it sets the expectation for AI/ML governance programs for insurers and banks under DFS jurisdiction.

For mortgage lenders operating in New York, the DFS guidance effectively requires an AI/ML governance program consistent with the GSE frameworks. Examiners will look for documentation of model risk management, fair lending testing, and consumer protection controls.

New York City Local Law 144 (automated employment decision tools) affects mortgage lenders that use AI in hiring — for loan officer recruiting, underwriting staff screening, or any other employment decision. The law requires an annual bias audit and public posting of the audit results.

Texas: UDAP Authority

Texas has not passed a state AI statute, but the Texas Attorney General and state financial regulators have used existing Unfair, Deceptive, or Abusive Acts or Practices (UDAP) authority to bring AI/ML-related actions. The state has been particularly active on AI-driven decisions that result in disparate impact on protected classes — using UDAP rather than a separate AI statute.

For Texas-licensed mortgage lenders, the practical implication is that AI/ML use is regulated — even without a specific AI statute. The compliance program that satisfies the Texas SML for the SSSF, the GSE AI/ML frameworks, and the federal fair lending rules is the foundation for UDAP defensibility.

Other State Activity

State AI/ML activity is moving fast. The states that have either passed AI rules or have active rulemaking in 2026 include Illinois, New Jersey, Virginia, Washington, and Oregon. The rules vary in scope and approach, but the direction is consistent: more state regulation, with mortgage lending in scope.

A practical approach for mortgage lenders operating nationally: design the AI/ML governance program to the strictest applicable state requirement, and apply it uniformly. The marginal cost of running a single, conservative program is much lower than the cost of running multiple state-specific programs.

How State AI Rules Interact with Federal and GSE Frameworks

A consolidated view of the AI/ML compliance landscape for mortgage lenders in 2026:

  • CFPB: interpretive guidance, focus on adverse action notices, fair lending, and accuracy of AI-driven decisions. Exam focus in 2026.
  • Fannie Mae LL-2026-04: AI/ML governance framework, effective August 6, 2026. Six governance obligations, annual attestation.
  • Freddie Mac Section 1302.8: companion AI/ML governance framework, effective March 3, 2026. Substantively similar to LL-2026-04.
  • Colorado AI Act: high-risk AI system requirements, impact assessments, consumer notice, right to human review. Effective February 1, 2026.
  • California DFPI: AI/ML supervisory guidance, focused on documentation, fair lending testing, and consumer protection.
  • New York DFS: supervisory guidance, treated as effective standard for New York-licensed institutions.
  • State AGs: UDAP authority, used to bring AI/ML-related actions in states without specific AI statutes.

These frameworks are additive. A lender that satisfies Fannie Mae LL-2026-04 still has separate Colorado, California, and New York obligations. The Colorado impact assessment is not a substitute for the LL-2026-04 attestation.

Building a Multi-State AI/ML Compliance Program

A defensible program has five components.

1. Unified AI/ML Use Case Inventory

Maintain a single inventory that flags which systems are in scope under which state rules. The inventory is the foundation — without it, you cannot determine your compliance obligations.

2. State-Overlay Documentation

For each state with AI/ML rules, maintain an overlay document that maps the state requirements to your existing governance program. The overlay identifies the gaps and the remediation work.

3. Consumer Notice and Human Review Workflows

Colorado and other state rules require consumer notice of AI use and a right to human review. The workflows should be designed to comply with the strictest applicable state requirement.

4. Impact Assessment Library

Maintain an impact assessment for each high-risk AI system, updated annually or after material model changes. The assessment is a state regulatory document, not a federal one — different states may require different formats.

5. Multi-State Vendor Oversight

Your vendor oversight program must cover state-specific requirements. A vendor providing AI/ML services in Colorado has different disclosure obligations than a vendor providing the same services in Texas.

Frequently Asked Questions

Does the Colorado AI Act Apply If We Don’t Have a Physical Office in Colorado?

Yes. The Act applies to any deployer that uses a high-risk AI system to make decisions affecting Colorado residents. If you originate or service a mortgage for a Colorado resident and use an AI/ML system in connection with that loan, the Act applies.

How Do State AI Rules Interact with Fair Lending Law?

State AI rules typically add anti-discrimination requirements that overlap with federal fair lending law but are not identical. A fair lending test that satisfies the CFPB may not satisfy the Colorado AI Act. The conservative approach is to test to the strictest applicable standard.

What If a Vendor Provides Our AI/ML System? Are We Still Liable?

Yes. Under the Colorado AI Act, the GSE frameworks, and most state-level approaches, the lender is the deployer and remains accountable for the system’s compliance. Vendor contracts can shift some financial risk, but not regulatory risk.

What Records Must We Retain?

Three years for most state requirements, but some state rules require longer retention for impact assessments. Document the retention requirement for each state in scope and apply the longest applicable period uniformly.

Need help designing or auditing your multi-state AI/ML compliance program? Synergy supports mortgage lenders with state overlay documentation, impact assessment design, and multi-state governance program reviews. Book a 30-minute program review.

Q2 2026 MCR Filing Cycle: What Went Right, What Went Wrong

The Q2 2026 NMLS Mortgage Call Report cycle closed on August 14, 2026. It was the second cycle under MCR Form Version 7 and the first full quarter where the Texas SML applied normal — not transitional — enforcement to the new State-Specific Supplemental Form. With the cycle now in the books, the data is clear about what worked, what didn’t, and where the gaps are heading into Q3.

This is a practitioner’s post-mortem. It walks through the most common filing issues observed in the Q2 cycle, the structural improvements that worked, and the priorities for the Q3 2026 filing window (deadline November 14).

What Went Right

The headline: most filers made the August 14 deadline with accurate data. The Q2 2026 cycle did not produce the wave of placeholder filings some state regulators had feared. Three factors drove the improvement.

FV7 Field Mappings Stabilized

The Q1 2026 cycle was the debut of FV7. Lenders that built their filing templates from FV6 documentation — or that did not have time to fully reconcile the new field structure before the May 15 deadline — produced filings with systematic field-mapping errors. The Q2 cycle showed a measurable improvement: most lenders had updated their internal mappings, retrained their teams, and validated against the current NMLS field definitions before the August 14 window opened.

Texas SSSF Transition Period Closed Cleanly

The Texas SML signaled in March 2026 that it would not actively pursue enforcement for Q1 2026 SSSF late filings absent other compliance concerns. The SML’s calibrated posture gave Texas-licensed lenders room to bring their SF600/SF610 data quality up to standard without the immediate risk of a violation.

By Q2 2026, normal enforcement was in effect. Filers had a clear deadline, a clear signal that the transition was over, and a quarter of operational experience. The result: clean SSSF submissions for most filers, with the SML reporting no widespread data quality issues at the cycle close.

Reconciliation Discipline Took Hold

Lenders that built HMDA-MCR reconciliation into their monthly close process — rather than scrambling at filing time — produced filings with materially fewer reconciliation gaps. The structural investment paid off.

What Went Wrong

Three categories of issues showed up repeatedly in the Q2 cycle.

1. Ginnie Mae Issuer Field Gaps

FV7 introduced new conditional fields for Ginnie Mae Issuers that did not exist in FV6. In Q1, the issue was that lenders were unaware of the fields. In Q2, the issue is that lenders are aware but have not fully populated them — particularly the fields that depend on data from upstream systems (e.g., pool composition, issuer monthly volume).

The fix is data lineage: trace each Ginnie Mae field back to its source system, validate the data, and document the lineage for examiner review.

2. Servicing Portfolio Segment Misclassification

FV7 restructured how servicing activity is reported across investors. The misclassification pattern in Q2 is the same as Q1: companies using FV6 mappings for FV7 data.

If your Q1 MCR was filed under FV6 mappings, the Q2 filing should have been the cycle to correct the issue. If it was not, the misclassification will be flagged in your next examination — and the longer it persists, the more filing periods you have to amend.

3. Origination Count Drift vs. HMDA LAR

Q2 origination counts in the MCR are being compared by examiners to Q2 origination counts in HMDA LAR. The most common drift comes from brokered-out loans (MCR typically excludes, HMDA may include) and from loans in process at quarter-end (MCR uses settlement date, HMDA uses application date).

The fix is documented scope rules plus a quarterly reconciliation. If the delta persists, the answer is not “we’re right” — it is “here is the documented scope difference and here is the supporting reconciliation.”

The Texas SSSF Normal-Enforcement Reality

Q2 2026 was the first SSSF cycle under normal enforcement. Three observations from the cycle.

SF600 and SF610 accuracy was the focus. The SML reviewed SSSF submissions for consistency with the NMLS MCR and with internal origination data. Filers with material variance received follow-up requests from the SML within a week of submission. Most variance was attributable to either scope-rule ambiguity (own-account vs. third-party processing) or timing (settled-file vs. application-based volume).

SF630 and SF660 stayed empty. The reserved fields remained reserved. Filers that entered data in SF630 or SF660 (a few did, by mistake) received validation errors. No enforcement action was taken in Q2 for SF630/SF660 errors, but the SML is treating these as validations to flag, not as substantive violations — yet.

Amended filings are working as designed. Several filers filed amended SSSFs after discovering post-filing errors. The SML accepted the amendments without enforcement action. The amendment process is functioning as a self-correction mechanism, which is the right outcome — but it requires filers to actually run post-filing QC, which not all do.

Three Things to Fix Before Q3 2026

The Q3 2026 MCR cycle closes on November 14. The window between mid-August and mid-November is the right time to address the most common Q2 issues.

1. Build or Refresh the FV7 Field Map

Pull the current NMLS MCR field definitions and instructions. Compare them against your internal mapping. Document the differences. Update your filing template.

The current field definitions are the only authoritative source. Documentation from FV6, third-party vendor field lists, and templates from prior cycles are not sufficient — they will replicate errors rather than fix them.

2. Run HMDA-MCR Reconciliation Monthly

Quarterly reconciliation is not enough. Monthly reconciliation catches drift early, when it is easy to remediate, rather than at filing time, when the remediation is an amendment.

Set a reconciliation tolerance (0.5% at the aggregate level is a reasonable starting point) and document any exceptions. The documentation is what examiners will ask for.

3. Tie MLO Headcount to NMLS Records

MLO headcount in the MCR should reconcile to NMLS licensing records for the reporting period. The Q2 cycle saw headcount drift in institutions that have had MLO turnover — particularly layoffs, acquisitions, or MLO migration to a different sponsor.

A monthly tie between HR data and NMLS licensing records catches the drift before it shows up in the MCR. The fix is process, not a one-time clean-up.

The Q3 Calendar

For the Q3 2026 MCR cycle, the key dates are:

  • October 1, 2026 — Q3 reporting period begins (the September 30 cutoff is the data boundary)
  • October 31, 2026 — internal books should be closed (recommended 14 days before the deadline)
  • November 7, 2026 — internal QC and pre-submission reconciliation (recommended hard stop)
  • November 14, 2026 — NMLS filing deadline

A common Q3 challenge: the November 14 deadline is three weeks after the federal election. Election years tend to compress close calendars at the back end of Q3 and Q4 — the Q3 close gets squeezed by election prep, holiday coverage planning, and year-end activity stacking up. Build the Q3 close calendar now to avoid the squeeze.

Frequently Asked Questions

Will the SML Provide Q2 2026 SSSF Feedback to All Filers?

The SML has signaled that it will provide substantive feedback on the first full normal-enforcement cycle. Filers should expect to receive follow-up requests if there are scope-rule ambiguities, data quality issues, or reconciliation gaps with the NMLS MCR. The window for resolving the feedback is typically 30 days.

What Happens If We Discover an MCR Error After the August 14 Filing?

File an amended MCR. The NMLS amendment process is the same as the original filing process. Self-discovered and promptly amended errors are treated more favorably by examiners than errors discovered during an examination. Maintain an internal amendment log so you can answer examiner questions about specific filings quickly.

How Should We Handle the FV6 Mappings in the Q3 Cycle?

If you are still using any FV6 mappings for FV7 data, the Q3 cycle is the right time to fix them. The longer the legacy mappings persist, the more filing periods you have to amend retrospectively. Build the corrected mapping now, validate it against the current NMLS field definitions, and document the change.

What Is the Examiner Focus for Q3 2026?

Based on Q1 and Q2 examination findings, the focus areas are FV7 field mapping (Ginnie Mae Issuer fields, servicing portfolio segments), HMDA-MCR reconciliation gaps, MLO headcount reconciliation, and Texas SSSF data quality. Q3 will likely see a continuation of these focus areas with a particular emphasis on the Q1-to-Q2-to-Q3 trend — examiners will be looking for whether issues are being remediated or persisting across cycles.

Need help hardening your Q3 2026 MCR process? Synergy supports mortgage lenders with FV7 field mapping reviews, monthly reconciliation design, and exam-readiness assessments. Book a 30-minute Q3 review.

Fannie Mae AI/ML Governance: What Lenders Must Do by August 6

Fannie Mae’s AI/ML governance framework — Lender Letter LL-2026-04 — took effect on August 6, 2026. For any single-family seller or servicer using artificial intelligence or machine learning in connection with mortgages sold to Fannie Mae, the framework is now in force. The compliance bar is no longer aspirational; it is operational.

LL-2026-04 is the companion to Freddie Mac’s Seller/Servicer Guide Section 1302.8, which took effect March 3, 2026. Together, the two frameworks establish the GSE position on AI/ML governance: lenders are accountable for the design, performance, and outcomes of any AI/ML system used in the mortgage lifecycle, regardless of whether the system is built in-house, provided by a third-party vendor, or accessed through a marketplace platform.

This guide walks through what LL-2026-04 requires, how it interacts with Freddie Mac Section 1302.8 and state-level AI rules, and what a defensible AI/ML governance program looks like for a mortgage lender as of August 2026.

What LL-2026-04 Actually Requires

LL-2026-04 is structured around six governance obligations. Each is a stand-alone compliance topic and each requires documentary evidence.

1. AI/ML Use Case Inventory

Lenders must maintain a complete inventory of every AI/ML system used in the mortgage lifecycle. The inventory should identify the system, the business function it supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

In scope: automated underwriting, appraisal valuation models, fraud detection, lead scoring, marketing optimization, customer service chatbots, document classification, income and asset verification, and any pricing or margin optimization tool that uses statistical learning.

Out of scope: rule-based decision engines that do not learn from data, simple statistical scoring (e.g., credit score lookups without model adjustment), and standard business intelligence dashboards.

2. Model Risk Management Framework

Each inventoried AI/ML system must be classified by risk tier based on its impact on loan decisions, borrower outcomes, and regulatory exposure. High-impact systems (underwriting, pricing, fraud, valuations) require the most rigorous controls.

The framework should document validation activities (pre-deployment testing, ongoing monitoring, periodic revalidation), performance thresholds, change management procedures, and override mechanisms for human review.

3. Fair Lending Testing

Each AI/ML system that affects loan decisions, pricing, or adverse action notices must be tested for fair lending impact. Testing should include disparate impact analysis across prohibited basis categories (race, national origin, sex, religion, familial status, age, disability), proxy variable analysis (identifying features that correlate with protected classes even when the protected class is not a direct input), and segment-level performance review.

The testing should occur before deployment, after material model changes, and at a defined cadence (typically annually for high-impact systems).

4. Governance Documentation

LL-2026-04 requires a written AI/ML governance policy that is approved at the board or senior committee level. The policy should cover roles and responsibilities, model lifecycle controls, escalation paths, exception handling, and incident response.

Documentation must be maintained for the life of each model plus a defined retention period. The retention floor is generally three years post-decommissioning, consistent with other mortgage compliance records.

5. Third-Party Vendor Oversight

Lenders remain accountable for AI/ML systems provided by third parties. The oversight program should include vendor due diligence (model documentation review, validation access, audit rights), ongoing monitoring (performance reports, incident notification, regulatory change tracking), and contractual protections (indemnification, data security, model decommissioning rights).

A common gap: lenders that treat vendor systems as “off the shelf” and skip validation. LL-2026-04 treats this as a compliance failure. The lender is responsible for validating the model in the context of its own use, even if the vendor provides the validation methodology.

6. Annual Attestation

Lenders must attest annually to Fannie Mae that they have an AI/ML governance program in place that meets LL-2026-04 requirements. The attestation is a senior officer certification, not a procedural check-the-box. Officers signing the attestation should expect to defend the substance of the program if challenged.

How LL-2026-04 Interacts with Freddie Mac Section 1302.8

If your institution sells to both GSEs, you do not need to maintain two separate AI/ML governance programs. A unified program that satisfies both frameworks is acceptable, and Fannie Mae and Freddie Mac have signaled that they will accept each other’s attestations in most cases.

The two frameworks differ in three operational details:

  • Effective dates: Freddie Mac Section 1302.8 took effect March 3, 2026. Fannie Mae LL-2026-04 took effect August 6, 2026. If you implemented a Section 1302.8 program in the spring, you should be in good shape on the substance of LL-2026-04. The remaining work is typically attestation timing and documentation reconciliation.
  • Attestation cadence: Freddie Mac requires annual attestation. Fannie Mae requires annual attestation. The two attestations can be filed separately even if the underlying program is the same.
  • High-impact system definition: The two frameworks use slightly different definitions of “high-impact.” Where they differ, the more conservative definition should govern.

If your institution sells to only one of the two GSEs, you only need to meet that GSE’s framework. But state-level AI rules may still apply regardless of GSE relationship — see the August 2026 article on state AI/ML enforcement.

What “In Connection With Mortgages Sold to Fannie Mae” Means

LL-2026-04 applies to AI/ML systems used in connection with mortgages sold to Fannie Mae. The phrase is interpreted broadly. If a system touches a loan that may eventually be sold to Fannie Mae, the governance obligations apply.

In practice, this covers:

  • Systems used at the point of application (lead scoring, prequalification)
  • Systems used during origination (automated underwriting, fraud detection, document processing)
  • Systems used post-closing (servicing decisioning, loss mitigation, default management)
  • Marketing and customer service systems if they influence the loan pipeline that includes Fannie Mae-sold loans

A practical approach: inventory every AI/ML system in your mortgage technology stack. If any of them touch a loan that may be sold to Fannie Mae, the system is in scope.

The Fair Lending Layer

The fair lending testing requirement under LL-2026-04 is the area where most lenders are least prepared. Standard model risk management covers performance, drift, and stability. Fair lending testing is a separate discipline with its own methodology, its own tooling, and its own documentation requirements.

If your institution has not yet built a fair lending testing program for AI/ML, the August 6 effective date is the trigger to either build it or engage external support. The testing cadence is at least annual for high-impact systems, and the documentation must be available for Fannie Mae review on request.

Two common testing approaches:

  • Outcomes-based testing: Compare actual loan decisions, pricing, or other outcomes across demographic segments. Identifies disparate impact at the output level.
  • Input-based testing: Audit model features for proxies that correlate with protected classes. Identifies structural risk before the model produces an outcome.

The most defensible approach is both. Outcomes-based testing identifies what the model is doing. Input-based testing identifies how the model could produce a problematic outcome before it happens.

Action Steps for August 2026

If your institution has not yet built a LL-2026-04 program, the immediate priorities are:

This month: Inventory every AI/ML system in the mortgage technology stack. Identify model owners, deployment dates, and vendors. This is the foundation for everything else.

This quarter: Classify each system by risk tier. Document the validation activities already performed. Identify gaps relative to LL-2026-04 requirements.

By year-end: Complete the governance policy. Establish fair lending testing for high-impact systems. Build the vendor oversight program. Stand up the annual attestation process.

By Q1 2027: Complete the first attestation cycle. Document the validation work performed. Build the exam-ready binder.

Frequently Asked Questions

We Don’t Use AI/ML Anywhere. Does LL-2026-04 Still Apply?

If you genuinely use no AI/ML systems in connection with mortgages sold to Fannie Mae, the framework does not impose substantive obligations. The annual attestation, however, is still required — you attest that you have no in-scope systems. Document the basis for that conclusion (the inventory and the analysis) so the attestation is defensible.

What About AI Tools Used by Individual Loan Officers?

If a loan officer uses a third-party AI tool (e.g., a ChatGPT-style assistant) in connection with a loan, the tool is in scope. The lender’s vendor oversight program must cover the tool, including the data security and confidentiality controls.

How Does LL-2026-04 Interact With State AI Laws?

LL-2026-04 is a GSE framework. State AI laws are separate obligations. In most cases, the state law is additive — you must satisfy both. See the August 2026 article on state AI/ML enforcement for the specific state rules that apply to mortgage lenders.

What Records Must We Retain?

Three years post-decommissioning for each model, consistent with other mortgage compliance records. The retention applies to model documentation, validation results, fair lending testing, governance decisions, vendor contracts, and attestation records.

Ready to build or audit your AI/ML governance program? Synergy supports mortgage lenders with model inventory design, governance policy drafting, fair lending testing frameworks, and AI/ML exam-readiness reviews. Book a 30-minute governance review.

Q&A — Mortgage Call Report Q&A: NMLS MCR Compliance, FV7 Transition, and Timely Delivery

The Mortgage Call Report remains the most examined regulatory filing in mortgage lending. With the FV7 transition in Q1 2026, the Texas SML’s explicit “placeholder filings not acceptable” guidance, and a sharper supervisory focus on timely delivery, the stakes for getting your MCR right — and getting it in on time — have never been higher.

This Q&A focuses specifically on NMLS MCR compliance: the FV7 transition, what “timely delivery” means in 2026, how the Texas SML is approaching enforcement, and how to handle amended filings. For the broader examination-readiness conversation, see our related articles on HMDA–MCR reconciliation and Texas SSSF filings.

Q1: What Actually Changed With MCR Form Version 7, and What Filers Are Getting Wrong?

Starting Q1 2026, MCR FV7 replaced FV6 as the mandatory submission format. The headline change was structural consolidation: FV6 eliminated the separate Standard and Expanded MCR forms in favor of a single filing with conditionally required fields based on company type and license profile. But the practical implications run deeper than the form redesign.

The most common FV7 filing errors we are seeing:

Servicing portfolio segment misclassification. FV7 restructured how servicing activity is reported across investors. Companies that did not update their internal data mappings before the Q1 2026 window opened are reporting data under old categories, meaning the numbers do not align with what state regulators are now expecting to see.

Ginnie Mae Issuer-specific data gaps. FV7 introduced new conditional fields for Ginnie Mae Issuers that were not present in FV6. If your compliance team built your FV7 filing template from FV6 documentation rather than the current NMLS field definitions and instructions, you are almost certainly missing required fields.

State-specific supplemental attachments treated as part of the MCR. Texas’s new supplemental filing requirement (SSSF) is a separate submission from the NMLS MCR. Several lenders treated it as part of the MCR filing and either missed it entirely or submitted incomplete data.

Q2: What Does “Timely Delivery” Mean for the MCR in 2026?

Timely delivery has three components, and examiners are looking at all three.

Filed by the deadline. The NMLS MCR is due 45 days after quarter-end: May 15, August 14, November 14, and February 14 (with calendar adjustments for weekends and holidays). A filing that arrives after the deadline is a late filing, period. There is no extension request mechanism for routine quarterly filings.

Filed with accurate, finalized data. This is where the Texas SML’s “placeholder filings not acceptable” guidance has clarified the standard across all state regulators. The MCR is not a placeholder document — it is a regulatory filing that should reflect closed books. Filing on time with placeholder or estimated data is itself a violation.

Amended when errors are discovered. Timely delivery also means filing amendments when post-filing errors are discovered. Examiners treat undisclosed errors more harshly than disclosed and amended errors.

The practical standard: your books should be closable in time to produce a finalized filing within the 45-day window. If they aren’t, the issue is internal — your close process needs to be tightened, not your filing deadline relaxed.

Q3: The Texas SML Said “Placeholder Filings Not Acceptable” — What Does That Mean in Practice?

In its March 2026 industry advisory, the Texas Department of Savings and Mortgage Lending made an explicit statement that placeholder filings — submissions containing inaccurate, estimated, or placeholder data intended to meet the deadline — are not acceptable. The advisory applies to both the NMLS MCR and the new SSSF.

In practice, this means three things.

First, filing on time with estimated data is a violation. If you cannot finalize your data by the deadline, the right move is to file late with a written explanation, not to file on time with bad numbers.

Second, the SML has indicated it will not actively pursue enforcement for late Q1 2026 MCR and SSSF filings unless paired with other compliance concerns. That is a calibrated transition posture, not a free pass. Expect normal enforcement starting Q2 2026.

Third, if you file on time with bad data and try to amend it later, the original filing still counts as a placeholder filing. The amendment process does not retroactively cure the original violation. The right move is to file late, then amend if needed.

Q4: What Are the Most Common Examination Findings on MCR Compliance?

In our work with lenders preparing for MCR examinations, the recurring findings fall into six categories.

Late filings. The most straightforward finding. The cure is process: a documented close calendar with explicit milestones tied to the filing deadline.

Placeholder or estimated data. Increasingly common in the post-FV7 transition. The cure is a tightened close process and a documented escalation path when books are not ready by the filing deadline.

FV7 field-mapping errors. Filers using FV6 mappings for FV7 data. The cure is a current field map reviewed annually against the latest NMLS instructions.

HMDA–MCR reconciliation gaps. Origination counts and dollar volumes that don’t tie between HMDA LAR and the MCR. The cure is a documented reconciliation process with continuous (not just filing-window) execution.

MLO headcount that doesn’t match state licensing records. Particularly after a layoff round or MLO migration. The cure is a reconciliation between NMLS licensing records and HR data monthly.

Missing supplemental filings. Texas SSSF, state-specific addenda. The cure is a master filing calendar that includes all required supplemental submissions.

Q5: How Should We Handle Amended MCR Filings?

The amendment process for the NMLS MCR is the same as the original filing process: submit a corrected MCR through the NMLS portal, with a brief written explanation of the change.

The best practice is to maintain an internal log of all amendments: the original filing date, the amendment date, the fields changed, the reason for the change, the dollar or unit impact of the change, and the person responsible. This log is itself an exam-readiness document — when an examiner asks about a specific filing, the log provides an immediate, defensible answer.

For the Texas SSSF, the same amendment process applies through the SML portal, with the same documentation standard.

What examiners want to see is not that you never amend — they expect amendments, particularly in the first few FV7 cycles. They want to see that you have a process for identifying, documenting, and filing amendments on a timely basis.

Q6: How Are State Regulators Coordinating on MCR Enforcement in 2026?

State regulators coordinate through the NMLS Mortgage Call Report Working Group, which meets quarterly and includes representatives from state mortgage banking regulators, state banking departments, and the CSBS. The working group has increased its focus on cross-state consistency in 2026, particularly around FV7 transition issues and Texas SML guidance.

What this means in practice is that the Texas SML’s “placeholder filings not acceptable” guidance is being adopted by other state regulators, even where they have not issued their own public advisory. If you operate in multiple states, expect consistent enforcement posture across states on this issue.

It also means that a finding in one state can become a data point in another state’s exam of your affiliate. Examiners talk to each other, and the NMLS system makes it easy for them to share observations across licensed entities.

Q7: What Are Examiners Looking for When They Review Our MCR?

State financial examiners do not just check whether you filed — they cross-reference your MCR data against your HMDA submissions, your BSA/AML filings, your licensed MLO count on NMLS, and your audited financial statements. When those numbers do not reconcile, you get an examination finding.

Specifically, examiners are flagging:

  1. Servicing portfolio totals that do not match investor reporting — the most common Expanded MCR trigger
  2. MLO headcount that diverges from state licensing records — particularly after a layoff round or MLO migration
  3. Denial rate spikes without accompanying explanation — regulators are acutely focused on adverse action patterns
  4. Origination volume that does not correlate with your stated product mix — a lender claiming $200M in originations but only two loan products raises questions

The takeaway: your MCR should not be assembled in the filing window. It should be reconciled continuously against your other regulatory outputs throughout the quarter.

Q8: How Do You Handle MCR Reporting When You Have Both State-Licensed and Federally Chartered Entities?

When a company operates both state-licensed entities and federally chartered affiliates, the MCR reporting obligations do not consolidate at the parent level — they file separately through NMLS for each licensed entity. The data must reflect only that entity’s activity, not the consolidated group.

The practical compliance challenge is cost allocation and data allocation. State regulators are increasingly scrutinizing whether shared services (compliance technology, QC staff, accounting functions) are being allocated appropriately across entities — particularly when one entity appears unprofitable while the parent is profitable. Examiners are beginning to ask for supporting documentation on cost allocation methodologies.

Additionally, if your state-licensed entity services loans for your federally chartered affiliate, you may have MCR servicing data that needs to be reconciled against a separate federally required reporting framework — and the numbers must match.

Q9: What Is the Practical Impact of the FV7 Transition on Examination Timing?

The FV7 transition has shifted examination timing in two important ways.

First, examiners are providing a wider latitude for Q1 2026 filings — the first FV7 cycle. Most state regulators have stated they will not pursue enforcement for transition-period errors unless paired with other concerns. This window closes at the end of Q2 2026.

Second, examinations are running longer than in prior years. Examiners are spending more time on the MCR review because the new field structure requires them to verify mappings against current NMLS documentation. Expect a 30–45 day examination to extend to 60–75 days during 2026 as examiners work through the transition.

The practical implication for lenders: if you have a scheduled examination in 2026, plan for a longer timeline and have your reconciliation documentation ready earlier than you would have in 2025.

Q10: What Should We Be Doing Right Now to Get Our MCR Program in Shape?

For lenders still working through the FV7 transition, the priorities are:

Update your field map. Pull the current NMLS MCR field definitions and instructions. Compare them against your internal mapping. Document the differences and update your filing template.

Tighten your close calendar. Build a close calendar with milestones tied to the filing deadline. Include a hard stop at day 35 (10 days before deadline) for any data quality issues — if data is not finalized by day 35, file late with a written explanation.

Build reconciliation into the close. Run HMDA–MCR reconciliation at month-end, not just at filing. Document the reconciliation. Set a tight tolerance (0.5% or less).

Reconcile MLO headcount monthly. Tie your HR system to your NMLS licensing records. Identify and resolve discrepancies before they show up in the MCR.

Maintain an amendment log. When errors are discovered post-filing, document and amend. The log is your defense if an examiner later asks why a particular figure changed.

Stand up your exam binder. Compile the current period MCR, the corresponding HMDA LAR, reconciliation worksheets, scope rules, and amendment log. Make it producible within an hour of an examiner request.

Need support on your MCR compliance program? Synergy works with mortgage lenders on FV7 transition, reconciliation design, amendment procedures, and exam readiness. Book a 30-minute MCR review.

HMDA and Mortgage Call Report Cross-Referencing

Examiners are no longer treating the HMDA LAR and the NMLS Mortgage Call Report as independent filings. State financial regulators, the CFPB, and the prudential regulators now run cross-regime reconciliation as a standard exam procedure — and the findings they generate are some of the most common compliance deficiencies in mortgage lending today.

When your HMDA data and your MCR data tell different stories about the same loan portfolio, examiners treat the discrepancy as a risk signal. The conversation becomes about why your data is inconsistent, not whether you have a process at all.

This guide walks through the seven most common HMDA–MCR mismatches we see in mortgage compliance examinations, why each one happens, and how to build a reconciliation process that catches the issue before the examiner does.

Why Cross-Referencing Has Become a Supervisory Priority

Three forces have converged to make HMDA–MCR reconciliation an exam focus.

First, the data quality of HMDA filings has improved substantially since 2018, when the Bureau clarified its position that HMDA data is used for enforcement purposes. Examiners now trust HMDA as a reliable baseline.

Second, the MCR Form Version 7 (FV7) transition effective Q1 2026 has changed how origination and servicing data is structured, which creates natural reconciliation friction with HMDA fields that have not changed.

Third, the CFPB’s 2025–2026 supervisory priorities explicitly call out cross-regime data consistency as a focus area. Examiners have been directed to test HMDA–MCR reconciliation as a matter of routine.

The Seven Most Common Mismatches

1. Origination Count Differences

The single most common mismatch. Your HMDA LAR reports X originations; your MCR reports Y. The delta can be small (a handful of loans) or large (hundreds).

The root causes are usually scope differences: which legal entity is reporting (HMDA is at the institutional level, MCR is at the licensed-entity level); whether purchased loans are included (HMDA includes purchased loans, MCR typically does not); whether brokered-out loans are included (HMDA may include, MCR typically excludes); and how prequalifications are handled.

How to fix it: Document the scope rules for each filing. Build a reconciliation that adjusts each total to a common basis before comparison. If the adjusted totals still don’t tie, the difference is a data integrity issue.

2. Dollar Volume Mismatches

Origination dollar volume differs between HMDA and the MCR — often by a percentage that doesn’t match the count difference. This is a red flag for examiners because it suggests inconsistent loan-level data across regimes.

Common causes include: rounding differences (HMDA reports in thousands, MCR reports in dollars); purchased loan amount handling (HMDA includes premium, MCR may not); and treatment of construction loans (HMDA reports the permanent financing amount, MCR may report a different basis).

How to fix it: Document the reporting basis for each regime. Convert both totals to the same unit (whole dollars) before comparison. Reconcile at the loan level, not the aggregate level.

3. Geographic Distribution Differences

The state-level distribution of originations differs between HMDA and the MCR. This is a higher-risk mismatch because it can imply different operational footprints or different definitions of where business is conducted.

Common causes include: property location vs. branch location reporting (HMDA uses property location, MCR uses branch location); treatment of loans originated through remote channels; and treatment of wholesale loans (whose branch is the loan attributed to).

How to fix it: Document the geographic attribution rule for each filing. Make sure your internal operating data uses a single attribution rule and that both filings are built from that single rule.

4. Loan Purpose Mismatches

The split between purchase, refinance, and home improvement differs between HMDA and the MCR. This is one of the more revealing mismatches because it can point to inconsistencies in how your team classifies loans.

Common causes include: cash-out refinance vs. rate-and-term refinance classification; home equity loans treated as home improvement in one regime but not the other; and construction-to-permanent loan staging.

How to fix it: Build a single loan-purpose classification matrix that maps to both HMDA and MCR definitions. Train your origination team on the matrix. QC a sample of loans against the matrix before each filing.

5. Servicing Portfolio Mismatches

The MCR Expanded filers report servicing portfolio volumes. HMDA does not, but examiners pull servicing data from other filings (servicing system reports, investor remittances, custodial accounts). When the MCR servicing figure doesn’t reconcile against these other sources, it generates findings.

Common causes include: portfolio transfer timing (loans sold during the reporting quarter); treatment of subserviced loans (the subservicer vs. the portfolio owner); and treatment of loans in forbearance.

How to fix it: Build a servicing data lineage that ties MCR reporting to your servicing system and your investor reporting. Reconcile monthly, not just at filing time.

6. Reporting Period Mismatches

HMDA is filed annually with a March 1 deadline covering the prior calendar year. The MCR is filed quarterly. When examiners compare a quarterly MCR to the corresponding quarter of the HMDA LAR, the numbers should match — but they often don’t.

Common causes include: cut-off date differences (HMDA uses application date, MCR uses settlement date); treatment of loans that crossed quarter-end; treatment of loans that were withdrawn after cut-off but before settlement; and amendment timing.

How to fix it: Document the cut-off convention for each filing. Make sure both filings use the same cut-off when reconciliation is the goal, or document the adjustment needed to reconcile.

7. Reporting Entity Mismatches

The legal entity reporting differs between HMDA and the MCR. HMDA is filed by the institution as defined in Regulation C. The MCR is filed by each licensed entity on NMLS. When a single holding company has multiple licensed entities, the aggregation can produce different totals.

This is one of the most common sources of mismatch and one of the most difficult to remediate, because the regulatory definitions don’t fully align.

How to fix it: Maintain a legal entity mapping that ties each HMDA reporting unit to the corresponding MCR filing entities. Adjust each total to a common scope before comparison. Document the adjustment methodology.

Building a Reconciliation Process That Works

A defensible HMDA–MCR reconciliation process has five elements.

1. Common Source of Truth

Both HMDA and MCR should be built from a single loan-level data store. This is the architectural foundation. If your HMDA pipeline and MCR pipeline are built separately from the operating system, you will always have reconciliation friction.

2. Documented Scope Rules

Write down the scope rules for each filing: who is in, who is out, what is included, what is excluded. The rules should be detailed enough that an examiner could replicate your filing from your operating data.

3. Pre-Filing Reconciliation Step

Build a pre-filing reconciliation step into both pipelines. For HMDA, this means reconciling your draft LAR against the MCR for the corresponding quarters (if available) and against your operating system totals. For the MCR, this means reconciling your draft MCR against the prior HMDA LAR (if available) and against your operating system totals.

4. Reconciliation Tolerance and Exception Documentation

Set a reconciliation tolerance (we recommend 0.5% or tighter at the aggregate level) and document any exceptions. Exceptions should be tied to specific loans or categories, with a written explanation of why the difference exists.

5. Continuous Reconciliation, Not Filing-Window Reconciliation

The worst time to discover a reconciliation issue is during the filing window. Run reconciliation monthly (or more frequently for high-volume originators). The reconciliation should be a standing report, not a filing-day activity.

What Examiners Actually Look At

In a typical MCR examination, examiners will:

  1. Pull your MCR for the period under exam
  2. Pull the corresponding HMDA LAR
  3. Compare aggregate origination count and dollar volume at the legal entity level
  4. Compare state-level geographic distribution
  5. Compare loan purpose distribution
  6. Compare servicing portfolio volume (for Expanded MCR filers) against your servicing system
  7. Sample loan-level records and compare the HMDA record, the MCR record, and the loan file
  8. Ask you to explain any mismatch with supporting documentation

The conversation escalates from a procedural question to a substantive finding when the explanation is unsatisfactory. “We didn’t reconcile” is a process finding. “We reconciled but the difference is real and we don’t know why” is a substantive finding. “We reconciled, here’s the documented reason, and here’s how we’re fixing it” is a defensible answer.

What an Examiner-Ready Reconciliation Binder Looks Like

When the examiner asks for your reconciliation documentation, you should be able to produce:

  1. The current period MCR and the current period HMDA LAR (or the most recent filed LAR)
  2. Reconciliation worksheets showing aggregate count, volume, geographic distribution, and loan purpose at the legal entity level
  3. Identified variances with root cause and remediation status
  4. Documented scope rules for each filing
  5. Loan-level reconciliation samples for high-risk categories (large loans, geographic outliers, loan purpose transitions)
  6. Evidence that reconciliation runs on a continuous basis, not just at filing

A binder that can be produced within an hour of an examiner request is a defensible binder. A binder that takes a week to assemble is a process finding waiting to happen.

The Role of the MCR Form Version 7 Transition

FV7 introduced structural changes to the MCR that materially affect reconciliation. Three changes in particular require attention.

Consolidated filing structure: FV6’s separate Standard and Expanded MCR forms were replaced with a single filing with conditionally required fields. Companies that haven’t updated their internal mappings are reporting data under old category assumptions.

New Ginnie Mae Issuer fields: FV7 introduced new conditional fields for Ginnie Mae Issuers that did not exist in FV6. If your compliance team built your FV7 template from FV6 documentation, these fields may be missing.

Texas supplemental filings: The Texas SSSF is a separate filing from the NMLS MCR but captures related data. Texas-licensed companies need to reconcile SF600 and SF610 against their MCR origination volume to avoid a different set of mismatches.

Frequently Asked Questions

How Often Should We Run Reconciliation?

Monthly at minimum. Quarterly is acceptable for low-volume originators, but monthly is better. Continuous reconciliation is the gold standard.

What Tolerance Should We Set?

Tighter is better. We recommend 0.5% at the aggregate level. Any variance above that should be documented with a root cause and a remediation plan.

What If Our Operating System Doesn’t Have a Single Source of Truth?

This is a common problem, especially for lenders that have grown through acquisition or operate multiple legacy systems. The first step is to map each filing pipeline back to its underlying data source and identify where the divergence occurs. Then prioritize a single source of truth for the highest-risk data elements first.

What If We Discover a Mismatch After Filing?

File an amendment. For HMDA, submit a revised LAR. For the MCR, file an amended MCR through NMLS. Document the amendment internally. Self-discovered and promptly amended errors are treated more favorably by examiners than errors discovered during an examination.

Need help building a reconciliation process or preparing for an upcoming exam? Synergy supports mortgage lenders with reconciliation design, pre-filing QC, and exam-readiness reviews for HMDA, MCR, and the Texas SSSF. Book a 30-minute reconciliation review.

Texas Mortgage Call Report Supplemental Filing

Texas mortgage companies engaged in third-party loan processing or underwriting have a new quarterly filing requirement on top of the NMLS Mortgage Call Report. The Supplemental Submission for SML Independent Loan Processors — SSSF — took effect with the Q1 2026 filing window, due May 15, 2026, and it introduced four new data fields that require careful reconciliation against your existing origination data.

This article explains what the SSSF requires, who must file, what each of the four fields captures, how to avoid the most common filing errors, and how the Texas SML has signaled it will approach enforcement of the new requirement.

What Is the SSSF and Why Was It Created

The SSSF is a quarterly supplemental filing required by the Texas Department of Savings and Mortgage Lending (SML) for state-licensed mortgage companies operating in Texas. It was developed under the authority of 7 TAC § 56.205 (for residential mortgage lenders) and 7 TAC § 57.205 (for mortgage bankers), with input from industry trade associations and a public comment period that closed in late 2025.

The SSSF responds to a long-standing supervisory gap. Texas is the second-largest mortgage market in the United States by origination volume, and the state has historically had a higher-than-average concentration of independent third-party processors and underwriters serving non-bank lenders and credit unions. The NMLS Mortgage Call Report captures loan-level origination and servicing activity at the company level, but it does not separately identify the activity performed by third-party service providers. The SSSF closes that gap.

For examiners, the SSSF creates visibility into which entities are doing the actual processing and underwriting work, how much of it, and on behalf of which investors or counterparties. For lenders, it adds a quarterly reporting burden — and a new exam risk if the data is not reconciled against other regulatory outputs.

Who Must File the SSSF

The SSSF filing requirement applies to Texas-licensed mortgage companies that, during the reporting quarter, either:

  1. Performed third-party loan processing services for another mortgage company, OR
  2. Performed third-party loan underwriting services for another mortgage company, OR
  3. Contracted with a third party to provide loan processing or underwriting services on the filer’s behalf.

The test is functional, not structural. A company that performs no processing or underwriting for any other party and does not contract with any third-party processor or underwriter is not required to file the SSSF.

For most licensed mortgage companies in Texas, this means the SSSF is mandatory — even if your third-party processing activity is modest. The SSSF threshold is qualitative (any third-party activity at all during the quarter), not quantitative.

The Four SSSF Fields

The SSSF adds four new fields to the existing SML quarterly reporting framework. Two of the fields are mandatory; two are reserved for future use.

SF600 — Third-Party Loan Processing Volume

SF600 reports the dollar volume of loans processed on behalf of third parties during the reporting quarter. The reporting basis is settled loan file volume — loans that reached clear-to-close during the quarter — not application volume. The field is reported in whole dollars.

What counts: Loans where your company performed processing functions on behalf of another licensed mortgage entity. Loans where your company is both the lender and the processor (i.e., you processed your own loan) are excluded — those are reported on the standard MCR.

Common error: Reporting gross origination volume instead of processing volume. SF600 is processing-specific.

SF610 — Third-Party Loan Underwriting Volume

SF610 reports the dollar volume of loans underwritten on behalf of third parties during the reporting quarter. Same settled-file reporting basis as SF600. Loans underwritten for your own portfolio are excluded.

Common error: Counting loans where your underwriting decision was overridden by the investor. The field captures loans for which your company issued the underwriting decision, regardless of whether the loan was ultimately purchased by the investor.

SF630 — Reserved

SF630 is reserved for future use. The SML has indicated this field will capture third-party servicing activity in a future filing cycle. Do not report data in SF630 until the SML publishes the field instructions.

SF660 — Reserved

SF660 is also reserved. The SML has indicated this field will capture investor concentration metrics for third-party-processed or -underwritten loans in a future filing cycle. Do not report data in SF660 until the SML publishes the field instructions.

Filing Mechanics

The SSSF is filed through the existing SML portal — not through NMLS. The filing window is the same as the NMLS Mortgage Call Report, with a due date of May 15 for Q1, August 14 for Q2, November 14 for Q3, and February 14 for Q4 (subject to calendar adjustments for weekends and holidays).

For each quarter:

  1. Q1 (Jan–Mar) — due May 15
  2. Q2 (Apr–Jun) — due August 14
  3. Q3 (Jul–Sep) — due November 14
  4. Q4 (Oct–Dec) — due February 14

The SSSF is a separate filing from the NMLS Mortgage Call Report, even though the data sources may overlap. Submit the NMLS MCR through the NMLS portal as usual, and submit the SSSF through the SML portal.

There is no grace period. A late filing is a violation. There is no extension request mechanism for routine quarterly filings.

How the SML Has Signaled It Will Approach Enforcement

The SML has been clear that it understands the Q1 2026 SSSF will be a transition cycle, but it has not offered a blanket grace period for the first filing.

In its March 2026 industry advisory, the SML stated that it will not actively pursue enforcement action against lenders who file late Q1 2026 SSSFs unless the late filing is paired with other compliance concerns or an examiner identifies risk factors that warrant accelerated attention. That is a calibrated posture, not a free pass.

The SML also stated explicitly that placeholder filings — submissions containing inaccurate, estimated, or placeholder data intended to meet the deadline — are not acceptable. If you cannot finalize your SSSF data by the deadline, the right move is to file late with a written explanation, not to file on time with bad data.

For Q2 2026 onward, expect normal enforcement. Late filings will be treated as violations, and inaccurate filings are themselves a violation regardless of when they are submitted.

If You Discover an Error After Filing

The SML has indicated that it expects lenders to file amended SSSFs when errors are discovered post-filing, and that self-discovered and promptly amended errors will generally not be the basis for enforcement action. The amendment process is the same as the original filing process — submit a corrected SSSF through the SML portal with a brief written explanation of the change.

What examiners will look at is whether you have a process for identifying and amending errors, not whether your first filing is perfect. Document your amendment process internally so the file is ready when an examiner asks.

Reconciling the SSSF Against Other Regulatory Outputs

The SSSF should reconcile against the NMLS Mortgage Call Report. Specifically:

  1. SF600 + own-account processing volume should equal total processing activity reflected in your internal operating data.
  2. SF610 + own-account underwriting volume should equal total underwriting activity reflected in your internal operating data.
  3. SF600 + SF610 should not exceed the dollar volume of loans reflected in your company’s origination system for the same period.
  4. The SSSF should reconcile against your internal list of third-party processor/underwriter relationships for the quarter.

If these reconciliations don’t tie, examiners will ask why. Build the reconciliation into your pre-submission QC.

The Most Common SSSF Filing Errors

In our work with Texas-licensed lenders preparing for the Q1 2026 SSSF, the recurring errors are:

1. Filing With Placeholder or Estimated Data

The single biggest risk. The SML has said this is not acceptable. If your books aren’t closed by the deadline, file late with a written explanation rather than file on time with bad numbers.

2. Including Own-Account Processing in SF600

SF600 captures only third-party processing volume. Loans you process for your own portfolio or on your own behalf are not in SF600.

3. Reporting Application Volume Instead of Settled File Volume

SF600 and SF610 are settled-file metrics — loans that reached clear-to-close during the quarter. Application volume is a different number.

4. Treating the SSSF as Part of the NMLS MCR

The SSSF is a separate filing through the SML portal. Submitting SSSF data through the NMLS MCR portal is not a valid filing.

5. Missing the SF630 and SF660 Reserved Fields

Do not enter data in SF630 or SF660. They are reserved for future use. Entering data there will trigger a validation error and may be flagged as an attempted misrepresentation.

Building a Sustainable SSSF Process

A defensible SSSF process has three core elements.

Quarter-End Data Snapshot

Take a clean snapshot of third-party processing and underwriting activity at the end of the reporting quarter. The snapshot should include loan-level data: counterparty, dollar volume, settled file vs. application status.

Pre-Filing Reconciliation

Before submission, reconcile SF600 and SF610 against your internal operating data and against the NMLS MCR for the same period. Any unresolved difference needs an explanation and a documented path to resolution.

Documented Amendment Procedure

Write down how you will identify, document, and file amendments when errors are discovered post-filing. This is the process examiners will ask about, and it is the process that turns a one-off error into a tolerable compliance event rather than an enforcement trigger.

Frequently Asked Questions

I Had No Third-Party Processing Activity in the Quarter. Do I Still File the SSSF?

Yes — but with zeros in SF600 and SF610. The SSSF is a quarterly filing requirement that applies to all Texas-licensed mortgage companies that had any third-party activity in the most recent four quarters, regardless of whether the current quarter had activity.

I Contract With a Third-Party Processor but Perform No Processing for Third Parties. Am I in Scope?

Yes. The SSSF captures both inbound (you contract for third-party services) and outbound (you provide services to third parties) activity. If you contracted with a third party during the quarter, you file the SSSF.

How Does the SSSF Interact With the MCR Examination Process?

The SML has stated that SSSF data will be incorporated into the standard MCR examination work. Examiners will reconcile SSSF data against the NMLS MCR, your internal origination data, and your third-party counterparty records.

What If I File Late and Self-Report?

For Q1 2026 specifically, the SML has indicated it will not actively pursue enforcement for late filings absent other concerns. For Q2 2026 onward, late filings are violations regardless of whether they are self-reported. Self-reporting is still the right move, but expect standard enforcement treatment.

Need help preparing your first SSSF filing? Synergy supports Texas mortgage lenders with data mapping, reconciliation, and pre-filing QC for both the NMLS MCR and the SSSF. Book a 30-minute compliance call.

CFPB Section 1071 Small Business Lending Data Collection

The CFPB’s Section 1071 rule reshapes how mortgage lenders collect, store, and report data on credit applications from small businesses. For Tier 1 filers — the largest originators — the compliance date is July 1, 2026. For most mortgage lenders operating in the small business and commercial space, this is the most consequential data collection rule since HMDA.

On October 2, 2025, the CFPB finalized an interim final rule extending compliance dates for Section 1071 of the Dodd-Frank Act. Under the revised schedule, Tier 1 filers — those originating 2,500 or more covered small business credit transactions in each of 2024 and 2025 — must begin collecting and reporting data on or before July 1, 2026, with first filings due June 1, 2027.

For mortgage lenders, this is a meaningful expansion of the data collection perimeter. Until now, HMDA has been the dominant data regime. Section 1071 extends a parallel reporting requirement to small business lending, and the two regimes are designed to work together — examiners will increasingly look for consistency between them.

This guide walks through what Tier 1 status means for mortgage lenders, what counts as a covered application, the data points required, and how to build a Section 1071 program that holds up under CFPB examination.

Who Counts as a Tier 1 Filer

The CFPB’s tier structure is based on originator volume, not portfolio or servicing. Under the 2025 interim final rule, tiers are:

Tier 1: 2,500+ covered transactions in each of 2024 and 2025 — compliance date July 1, 2026 — first filing June 1, 2027.

Tier 2: 500–2,499 covered transactions in each of 2024 and 2025 — compliance date January 1, 2027 — first filing June 1, 2028.

Tier 3: 100–499 covered transactions in each of 2024 and 2025 — compliance date October 1, 2027 — first filing June 1, 2029.

Exempt: Fewer than 100 covered transactions in each year — not required to file.

Volume is measured at the legal entity level, not the holding-company level — though there are aggregation rules for commonly controlled entities. The CFPB has signaled that aggregation will follow Regulation B’s control-person framework, with limited exceptions for certain minority-owned institutions and CDFIs.

The threshold applies to covered credit transactions, not portfolio or servicing. If your institution has any commercial or small business lending activity and your overall originator volume puts you in any tier, you must include that activity in your Section 1071 count. The threshold is firm-wide, not line-of-business.

What Applications and Loans Are Covered

Section 1071 covers applications for credit from a small business. The CFPB’s definition of “small business” is the SBA’s size standard for the applicant’s industry — generally a business with $5 million or less in gross annual revenue (calculated across the applicant’s three most recent fiscal years) and 500 or fewer employees.

A “covered credit transaction” is a closed-end or open-end credit product originated for a small business, including:

  1. Commercial mortgages and refinances
  2. Commercial real estate loans
  3. Working capital lines of credit
  4. SBA-guaranteed loans
  5. Equipment financing
  6. Business credit cards (with limited exceptions for corporate cards)
  7. Merchant cash advances (treated as credit under the rule)

Key exclusions include trade credit (credit extended for the purchase of goods and services from the creditor itself), public utilities, securities transactions, credit to financial institutions, credit to governments, and credit extended to a business with gross revenue above the size standard.

The 19 Data Points You Must Collect

For every covered application, the rule requires collection of 19 data points organized into three categories.

Applicant-Identifying Data

1. Legal name

2. Trade name (if different)

3. Address (physical, not PO Box)

4. Taxpayer Identification Number (TIN / EIN)

5. Application date

6. Application method (in-person, phone, online, mail)

7. Application recipient (where the application was submitted)

Application Characteristics

1. Application type (covered application, prequalification, or incomplete)

2. Action taken (approved, denied, withdrawn, incomplete)

3. Action date

4. Denial reason(s) — enumerated list (main reason + up to four additional)

5. Credit type (closed-end vs. open-end)

6. Credit purpose (working capital, equipment, real estate, etc.)

7. Amount applied for

8. Amount approved or originated

9. Term

Pricing Data

1. Interest rate

2. Total origination charges

3. Broker fees and lender compensation

Demographic data on the applicant’s principal owners (race, ethnicity, sex) is collected on a voluntary basis, consistent with the rule’s fair-lending intent.

Pricing data sensitivity: The pricing fields (interest rate, origination charges, broker fees) are the most contested parts of the rule. For mortgage lenders, these overlap with HMDA rate spread reporting. Treat 1071 pricing data as separate and validate at the loan level — examiners will compare 1071 pricing against HMDA LAR, internal loan files, and the closing disclosure.

Where Section 1071 Meets Mortgage Lending

For most residential mortgage lenders, Section 1071 will be a peripheral obligation. But the rule applies where the lines blur — and for diversified lenders, the overlap is significant.

Residential Mortgages That Touch 1071

  1. Investment property mortgages held in the name of a small business entity (LLC, corporation, partnership) — not in the borrower’s personal name. These are commercial loans, even if secured by 1–4 family residential property.
  2. Mixed-use property loans where the borrower is a small business.
  3. Construction loans to small business developers, including single-purpose entity (SPE) borrowers.
  4. Diversified lenders with both consumer mortgage and commercial / small business lending arms, where total originator volume pushes the institution into a tier.

Residential Mortgages That Do NOT Touch 1071

  1. Personal mortgages on a borrower’s primary residence (HMDA-only)
  2. Personal second homes and vacation homes (HMDA-only)
  3. Refinances of personal mortgages (HMDA-only)
  4. Reverse mortgages for individuals (HMDA-only)

The test is who the applicant is, not what the property is. Loans to individuals — even on non-owner-occupied investment property — are generally HMDA territory. Loans to small business entities are 1071 territory.

HMDA and 1071: The Overlap You’ll Want to Plan For

This is the part of Section 1071 that gives mortgage compliance officers heartburn — and the part examiners will look at most closely.

HMDA and Section 1071 both collect credit-application data. For the small (but growing) population of loans that could plausibly be reported under either regime, you need a clear written policy on which regime applies and why. Examiners will compare:

  1. Total application counts under HMDA vs. 1071
  2. Volume consistency between HMDA LAR and 1071 data
  3. Denial reason patterns across both regimes
  4. Pricing data, where both regimes capture rate-related fields
  5. Demographic data handling (both are voluntary but collected separately)

The CFPB and prudential regulators have signaled that cross-regime consistency will be a supervisory priority beginning in 2027. Build the policy now, while you have time.

Building a Single Source of Truth

For institutions in scope for both HMDA and 1071, the right architecture is a single application-level data store that feeds both regimes — not two parallel pipelines. This reduces data integrity risk, simplifies examiner requests, and improves your ability to identify and remediate discrepancies.

Building a Defensible Compliance Program

A Section 1071 program that will survive CFPB examination has five moving parts.

1. Written Policies and Procedures

Your 1071 policy should document tier classification and how it was determined; scope (which products, which channels, which entities are included); application intake process; data storage and retention (3 years from application date); reporting process; quality control; exception handling; training requirements; and oversight and audit cadence.

2. Application Intake Controls

Capture the data points at the point of application, not after origination. The intake controls should include LOS / origination system integration that captures the data at submission, validation rules at the field level, required-field enforcement on the controlled fields, and a demographic data collection workflow.

3. Data Quality Controls

Pre-submission QC is the single biggest determinant of exam-readiness. At minimum: reconciliation against origination system totals, reconciliation against HMDA LAR (for any overlap), denial reason accuracy check on a sample basis, pricing data validation against closing disclosures, and edit checks before submission.

4. Filing Platform Readiness

The CFPB is building a dedicated filing platform for Section 1071 (parallel to the HMDA Platform). Confirm your institution’s readiness to integrate with the platform ahead of your first filing deadline.

5. Exam-Readiness Documentation

Maintain an exam binder that includes the Section 1071 written policy, tier classification analysis with supporting data, data lineage documentation (where each field comes from), QC results for the most recent filing, reconciliation against HMDA LAR for overlap period, and any voluntary demographic data collection materials.

Compliance Timeline and What to Do by July 1

If you’re a Tier 1 filer with a July 1, 2026 compliance date, the clock is short. Here’s the practical action sequence:

  1. Now: Confirm tier classification using 2024 and 2025 originator volume.
  2. Now – end of month: Stand up the written policy and get it approved by compliance committee.
  3. Next 60 days: Map current data capture against the 19 data points; identify gaps.
  4. Next 90 days: Update LOS / origination systems to capture missing fields.
  5. Next 120 days: Train intake and operations staff.
  6. By July 1, 2026: Begin collecting all 19 data points on every covered application.
  7. By Q4 2026: Run your first pre-submission QC cycle.
  8. By Q1 2027: Validate the full pipeline end-to-end with test data.
  9. June 1, 2027: First filing due.

Frequently Asked Questions

Do I Have to Collect Demographic Data on the Applicant’s Owners?

No — demographic data (race, ethnicity, sex) is collected on a voluntary basis. You must offer the applicant the opportunity to provide it, but you cannot require it, and you must clearly disclose that providing the information is voluntary.

What If My Institution’s Originator Volume Was Above the Tier 1 Threshold in 2024 but Below in 2025?

You must meet the threshold in both years to qualify for Tier 1. If you drop below in either year, you move down a tier (or become exempt).

How Does Section 1071 Interact With State-Level Small Business Reporting?

Several states have their own small business lending reporting requirements (notably California and New York). Section 1071 is federal and preempts conflicting state requirements. You still need to file state reports, but Section 1071 is the floor, not the ceiling.

Can I Use Third-Party Vendors to Handle Section 1071 Compliance?

Yes — most lenders will use LOS providers, compliance platforms, or specialized 1071 vendors to handle data capture, validation, and filing. Vendor selection and oversight is itself an exam topic, so document your due diligence and ongoing monitoring.

What Records Must I Retain?

Three years from the date of application. Records must be sufficient to reconstruct the application data as it was reported, including the response to any voluntary demographic question.

Ready to review your Section 1071 readiness before July 1? Synergy supports mortgage lenders with policy drafting, data-mapping, QC buildout, and pre-filing readiness reviews. Book a 30-minute readiness call.

Mortgage Call Report Q&A: Build a Defensible MCR Process

Q1: What Is the Long-Term Regulatory Risk of a Pattern of Inaccurate MCR Filings?

This is the question compliance officers don’t ask until they’ve already had the problem.

A single late or inaccurate MCR filing is a clerical issue. A pattern is a compliance management system failure — and that’s the framing that triggers elevated examination activity, enhanced oversight requirements, and in some states, mandatory remediation plans.

Regulators have access to longitudinal MCR data across your entire licensing history. When they see a company with:

  1. Four consecutive quarters of rounded loan count figures
  2. Consistent mismatches between RMLA origination volume and HMDA LAR submissions
  3. Servicing portfolio data that tracks below industry benchmarks for similar portfolio sizes

…that company gets placed on the active examination list. The cost of an examination — in staff time, legal fees, and regulatory relationship risk — far exceeds the cost of building a defensible filing process.

Q2: How Does Synergy’s Approach to MCR Compliance Differ From Generic Regulatory Software?

Most MCR compliance solutions treat the filing as a data entry problem. Synergy treats it as a data integrity problem — and there’s a meaningful difference.

Data entry solutions give you a form to fill out. Data integrity solutions audit your entire loan origination, servicing, and financial reporting ecosystem to ensure that the numbers flowing into the form are accurate before you ever open the submission window.

Our MCR compliance process includes:

  1. Quarterly pre-reconciliation — we identify and resolve data inconsistencies across your LOS, servicing platform, accounting system, and HMDA LAR before the NMLS window opens
  2. FV7 category mapping — we maintain current NMLS field definitions and state-specific requirements (including the Texas supplemental filing) and verify your internal taxonomy aligns before each submission
  3. Examiner-ready documentation — every filing is supported by source system reconciliation reports and internal review records
  4. Proactive regulatory monitoring — as state regulators update their MCR examination focus areas, we adjust your data collection and validation processes to stay ahead of where examiners are looking

Q3: Ready to Build a Defensible MCR Process?

If your current mortgage call reporting process lives in a spreadsheet, gets assembled in the last week of the filing window, and has never been cross-referenced against your HMDA data — that’s the process an examiner will find when they review your licensing history.

The good news: MCR compliance doesn’t require rebuilding your entire technology stack. It requires disciplined reconciliation, documented procedures, and a compliance partner who understands how regulators actually use the data.

Synergy works with lenders and servicers to build MCR processes that hold up under regulatory scrutiny — from data validation through submission and audit documentation.

Contact us to discuss your current MCR compliance posture or book a demo at simplifyqc.com.

Mortgage Call Report Q&A: Servicing Data and Expanded Filers

Q1: What Is the Actual Enforcement Pattern for MCR Non-Compliance Across Major States?

Enforcement varies significantly by state regulator — which is one of the most underappreciated aspects of MCR risk management for multi-state lenders.

The SAFE Act mandates MCR filing as a condition of license maintenance, but the enforcement mechanisms are state-designed:

California (DFPI): DFPI has been increasingly active in examining MCR data against branch license activity. We’ve seen examination findings issued where branch-level MCR submissions showed activity inconsistent with the company’s NMLS licensing map.

New York (DFS): DFS takes a hard line on late or missing filings, and has included MCR non-compliance as a factor in consent order negotiations with mortgage servicers — even when the underlying issue was unrelated to call reporting.

Texas (SML): The new Q1 2026 supplemental filing requirement has caught several mid-sized servicers off guard. SML has signaled through industry communications that they will be actively validating supplemental submissions against RMLA data.

Washington (DFI): Washington DFI has issued fines for incomplete MCR filings — not just late ones — where companies filed but left required fields blank or submitted obviously rounded figures that suggested incomplete data collection.

The pattern across all states: regulators are using MCR data as a primary source for examination planning. A clean MCR history doesn’t just avoid penalties — it shapes which companies get examined and how intensively.

Q2: How Should Servicers Handle Loss Mitigation and Workout Data in the Expanded MCR?

For Expanded MCR filers — those approved by Fannie Mae, Freddie Mac, or Ginnie Mae — the servicing data section is where most reconciliation errors occur. With FHA’s revised loss mitigation waterfall (effective October 2025 under ML 2025-06 and subsequent revisions) adding new workout options including Payment Supplements and modified COVID-era relief transitions, the MCR servicing categories are under pressure to reflect activity that previous form versions didn’t anticipate.

Specifically:

  1. Payment supplement activity needs to be properly categorized — this is a relatively new tool in the FHA servicing waterfall, and companies that haven’t updated their internal reporting taxonomies are classifying it inconsistently
  2. COVID-era loss mitigation transitions are winding down under the updated permanent waterfall, but the activity is still appearing in MCR data under legacy categories, creating inconsistencies
  3. Modifications vs. forbearance re-defaults — there is genuine ambiguity in how to report certain workout scenarios, and companies making conservative assumptions may be underreporting while aggressive classifications create regulatory exposure

The practical recommendation: before each quarterly filing, your servicing data team and your compliance team need to review the categorization decisions together — not hand off data in a one-way process.

Q3: How Does MCR Data Interact With HMDA LAR — and Where Do the Reconciliations Break Down?

The intersection of MCR and HMDA reporting is where experienced compliance teams still make errors — not because the concepts are difficult, but because the two datasets use different segmentation logic and deadlines that create plenty of room for inconsistency.

Key reconciliation challenge: loan count segmentation. HMDA requires reporting of originated loans, purchased loans, and in some cases applications that didn’t close. The MCR RMLA captures origination activity by product type and purpose. When a company is active in both HMDA-reportable and business-purpose lending, the segmentation of the MCR data must align with the same population that drives HMDA reporting.

The “no activity” problem. Companies that originate no HMDA-reportable loans in a quarter still have MCR filing obligations — but the RMLA data must reflect zero origination activity consistent with what HMDA would show. If the company had any activity at all and is claiming zero in both, regulators will cross-reference and find the discrepancy.

Annual LAR reconciliation. HMDA’s annual submission deadline (March 2 for 2025 data) creates a natural reconciliation point with the four quarterly MCR submissions. Companies that perform this reconciliation annually rather than quarterly frequently discover errors that have compounded across multiple quarters.

Q4: What Documentation Do You Need to Survive an MCR Examination?

State examiners don’t just ask for your NMLS submission. They ask for the supporting documentation — and if you can’t produce it, the filing itself becomes a compliance issue.

The audit trail for a defensible MCR filing should include:

  1. Source system reconciliation reports showing how origination, servicing, and accounting data fed into each MCR field
  2. Data classification logic — documented rationale for how you categorized each loan type, product, and activity line
  3. Internal review sign-off — a named compliance officer or CFO who reviewed and approved the filing before submission
  4. Correction log — if prior quarters were amended, the documentation of what changed and why
  5. State-specific supplemental data — stored separately from the NMLS submission with its own supporting documentation

For Expanded MCR filers, the documentation burden is higher. Servicing portfolio data should tie to investor statements; loss mitigation figures should tie to your loss mitigation workflow system; delinquency and default data should tie to your default management reporting.

Web Statistics