All posts by Synergy

CFPB Section 1071 Small Business Lending Data Collection

The CFPB’s Section 1071 rule reshapes how mortgage lenders collect, store, and report data on credit applications from small businesses. For Tier 1 filers — the largest originators — the compliance date is July 1, 2026. For most mortgage lenders operating in the small business and commercial space, this is the most consequential data collection rule since HMDA.

On October 2, 2025, the CFPB finalized an interim final rule extending compliance dates for Section 1071 of the Dodd-Frank Act. Under the revised schedule, Tier 1 filers — those originating 2,500 or more covered small business credit transactions in each of 2024 and 2025 — must begin collecting and reporting data on or before July 1, 2026, with first filings due June 1, 2027.

For mortgage lenders, this is a meaningful expansion of the data collection perimeter. Until now, HMDA has been the dominant data regime. Section 1071 extends a parallel reporting requirement to small business lending, and the two regimes are designed to work together — examiners will increasingly look for consistency between them.

This guide walks through what Tier 1 status means for mortgage lenders, what counts as a covered application, the data points required, and how to build a Section 1071 program that holds up under CFPB examination.

Who Counts as a Tier 1 Filer

The CFPB’s tier structure is based on originator volume, not portfolio or servicing. Under the 2025 interim final rule, tiers are:

Tier 1: 2,500+ covered transactions in each of 2024 and 2025 — compliance date July 1, 2026 — first filing June 1, 2027.

Tier 2: 500–2,499 covered transactions in each of 2024 and 2025 — compliance date January 1, 2027 — first filing June 1, 2028.

Tier 3: 100–499 covered transactions in each of 2024 and 2025 — compliance date October 1, 2027 — first filing June 1, 2029.

Exempt: Fewer than 100 covered transactions in each year — not required to file.

Volume is measured at the legal entity level, not the holding-company level — though there are aggregation rules for commonly controlled entities. The CFPB has signaled that aggregation will follow Regulation B’s control-person framework, with limited exceptions for certain minority-owned institutions and CDFIs.

The threshold applies to covered credit transactions, not portfolio or servicing. If your institution has any commercial or small business lending activity and your overall originator volume puts you in any tier, you must include that activity in your Section 1071 count. The threshold is firm-wide, not line-of-business.

What Applications and Loans Are Covered

Section 1071 covers applications for credit from a small business. The CFPB’s definition of “small business” is the SBA’s size standard for the applicant’s industry — generally a business with $5 million or less in gross annual revenue (calculated across the applicant’s three most recent fiscal years) and 500 or fewer employees.

A “covered credit transaction” is a closed-end or open-end credit product originated for a small business, including:

  1. Commercial mortgages and refinances
  2. Commercial real estate loans
  3. Working capital lines of credit
  4. SBA-guaranteed loans
  5. Equipment financing
  6. Business credit cards (with limited exceptions for corporate cards)
  7. Merchant cash advances (treated as credit under the rule)

Key exclusions include trade credit (credit extended for the purchase of goods and services from the creditor itself), public utilities, securities transactions, credit to financial institutions, credit to governments, and credit extended to a business with gross revenue above the size standard.

The 19 Data Points You Must Collect

For every covered application, the rule requires collection of 19 data points organized into three categories.

Applicant-Identifying Data

1. Legal name

2. Trade name (if different)

3. Address (physical, not PO Box)

4. Taxpayer Identification Number (TIN / EIN)

5. Application date

6. Application method (in-person, phone, online, mail)

7. Application recipient (where the application was submitted)

Application Characteristics

1. Application type (covered application, prequalification, or incomplete)

2. Action taken (approved, denied, withdrawn, incomplete)

3. Action date

4. Denial reason(s) — enumerated list (main reason + up to four additional)

5. Credit type (closed-end vs. open-end)

6. Credit purpose (working capital, equipment, real estate, etc.)

7. Amount applied for

8. Amount approved or originated

9. Term

Pricing Data

1. Interest rate

2. Total origination charges

3. Broker fees and lender compensation

Demographic data on the applicant’s principal owners (race, ethnicity, sex) is collected on a voluntary basis, consistent with the rule’s fair-lending intent.

Pricing data sensitivity: The pricing fields (interest rate, origination charges, broker fees) are the most contested parts of the rule. For mortgage lenders, these overlap with HMDA rate spread reporting. Treat 1071 pricing data as separate and validate at the loan level — examiners will compare 1071 pricing against HMDA LAR, internal loan files, and the closing disclosure.

Where Section 1071 Meets Mortgage Lending

For most residential mortgage lenders, Section 1071 will be a peripheral obligation. But the rule applies where the lines blur — and for diversified lenders, the overlap is significant.

Residential Mortgages That Touch 1071

  1. Investment property mortgages held in the name of a small business entity (LLC, corporation, partnership) — not in the borrower’s personal name. These are commercial loans, even if secured by 1–4 family residential property.
  2. Mixed-use property loans where the borrower is a small business.
  3. Construction loans to small business developers, including single-purpose entity (SPE) borrowers.
  4. Diversified lenders with both consumer mortgage and commercial / small business lending arms, where total originator volume pushes the institution into a tier.

Residential Mortgages That Do NOT Touch 1071

  1. Personal mortgages on a borrower’s primary residence (HMDA-only)
  2. Personal second homes and vacation homes (HMDA-only)
  3. Refinances of personal mortgages (HMDA-only)
  4. Reverse mortgages for individuals (HMDA-only)

The test is who the applicant is, not what the property is. Loans to individuals — even on non-owner-occupied investment property — are generally HMDA territory. Loans to small business entities are 1071 territory.

HMDA and 1071: The Overlap You’ll Want to Plan For

This is the part of Section 1071 that gives mortgage compliance officers heartburn — and the part examiners will look at most closely.

HMDA and Section 1071 both collect credit-application data. For the small (but growing) population of loans that could plausibly be reported under either regime, you need a clear written policy on which regime applies and why. Examiners will compare:

  1. Total application counts under HMDA vs. 1071
  2. Volume consistency between HMDA LAR and 1071 data
  3. Denial reason patterns across both regimes
  4. Pricing data, where both regimes capture rate-related fields
  5. Demographic data handling (both are voluntary but collected separately)

The CFPB and prudential regulators have signaled that cross-regime consistency will be a supervisory priority beginning in 2027. Build the policy now, while you have time.

Building a Single Source of Truth

For institutions in scope for both HMDA and 1071, the right architecture is a single application-level data store that feeds both regimes — not two parallel pipelines. This reduces data integrity risk, simplifies examiner requests, and improves your ability to identify and remediate discrepancies.

Building a Defensible Compliance Program

A Section 1071 program that will survive CFPB examination has five moving parts.

1. Written Policies and Procedures

Your 1071 policy should document tier classification and how it was determined; scope (which products, which channels, which entities are included); application intake process; data storage and retention (3 years from application date); reporting process; quality control; exception handling; training requirements; and oversight and audit cadence.

2. Application Intake Controls

Capture the data points at the point of application, not after origination. The intake controls should include LOS / origination system integration that captures the data at submission, validation rules at the field level, required-field enforcement on the controlled fields, and a demographic data collection workflow.

3. Data Quality Controls

Pre-submission QC is the single biggest determinant of exam-readiness. At minimum: reconciliation against origination system totals, reconciliation against HMDA LAR (for any overlap), denial reason accuracy check on a sample basis, pricing data validation against closing disclosures, and edit checks before submission.

4. Filing Platform Readiness

The CFPB is building a dedicated filing platform for Section 1071 (parallel to the HMDA Platform). Confirm your institution’s readiness to integrate with the platform ahead of your first filing deadline.

5. Exam-Readiness Documentation

Maintain an exam binder that includes the Section 1071 written policy, tier classification analysis with supporting data, data lineage documentation (where each field comes from), QC results for the most recent filing, reconciliation against HMDA LAR for overlap period, and any voluntary demographic data collection materials.

Compliance Timeline and What to Do by July 1

If you’re a Tier 1 filer with a July 1, 2026 compliance date, the clock is short. Here’s the practical action sequence:

  1. Now: Confirm tier classification using 2024 and 2025 originator volume.
  2. Now – end of month: Stand up the written policy and get it approved by compliance committee.
  3. Next 60 days: Map current data capture against the 19 data points; identify gaps.
  4. Next 90 days: Update LOS / origination systems to capture missing fields.
  5. Next 120 days: Train intake and operations staff.
  6. By July 1, 2026: Begin collecting all 19 data points on every covered application.
  7. By Q4 2026: Run your first pre-submission QC cycle.
  8. By Q1 2027: Validate the full pipeline end-to-end with test data.
  9. June 1, 2027: First filing due.

Frequently Asked Questions

Do I Have to Collect Demographic Data on the Applicant’s Owners?

No — demographic data (race, ethnicity, sex) is collected on a voluntary basis. You must offer the applicant the opportunity to provide it, but you cannot require it, and you must clearly disclose that providing the information is voluntary.

What If My Institution’s Originator Volume Was Above the Tier 1 Threshold in 2024 but Below in 2025?

You must meet the threshold in both years to qualify for Tier 1. If you drop below in either year, you move down a tier (or become exempt).

How Does Section 1071 Interact With State-Level Small Business Reporting?

Several states have their own small business lending reporting requirements (notably California and New York). Section 1071 is federal and preempts conflicting state requirements. You still need to file state reports, but Section 1071 is the floor, not the ceiling.

Can I Use Third-Party Vendors to Handle Section 1071 Compliance?

Yes — most lenders will use LOS providers, compliance platforms, or specialized 1071 vendors to handle data capture, validation, and filing. Vendor selection and oversight is itself an exam topic, so document your due diligence and ongoing monitoring.

What Records Must I Retain?

Three years from the date of application. Records must be sufficient to reconstruct the application data as it was reported, including the response to any voluntary demographic question.

Ready to review your Section 1071 readiness before July 1? Synergy supports mortgage lenders with policy drafting, data-mapping, QC buildout, and pre-filing readiness reviews. Book a 30-minute readiness call.

Mortgage Call Report Q&A: Build a Defensible MCR Process

Q1: What Is the Long-Term Regulatory Risk of a Pattern of Inaccurate MCR Filings?

This is the question compliance officers don’t ask until they’ve already had the problem.

A single late or inaccurate MCR filing is a clerical issue. A pattern is a compliance management system failure — and that’s the framing that triggers elevated examination activity, enhanced oversight requirements, and in some states, mandatory remediation plans.

Regulators have access to longitudinal MCR data across your entire licensing history. When they see a company with:

  1. Four consecutive quarters of rounded loan count figures
  2. Consistent mismatches between RMLA origination volume and HMDA LAR submissions
  3. Servicing portfolio data that tracks below industry benchmarks for similar portfolio sizes

…that company gets placed on the active examination list. The cost of an examination — in staff time, legal fees, and regulatory relationship risk — far exceeds the cost of building a defensible filing process.

Q2: How Does Synergy’s Approach to MCR Compliance Differ From Generic Regulatory Software?

Most MCR compliance solutions treat the filing as a data entry problem. Synergy treats it as a data integrity problem — and there’s a meaningful difference.

Data entry solutions give you a form to fill out. Data integrity solutions audit your entire loan origination, servicing, and financial reporting ecosystem to ensure that the numbers flowing into the form are accurate before you ever open the submission window.

Our MCR compliance process includes:

  1. Quarterly pre-reconciliation — we identify and resolve data inconsistencies across your LOS, servicing platform, accounting system, and HMDA LAR before the NMLS window opens
  2. FV7 category mapping — we maintain current NMLS field definitions and state-specific requirements (including the Texas supplemental filing) and verify your internal taxonomy aligns before each submission
  3. Examiner-ready documentation — every filing is supported by source system reconciliation reports and internal review records
  4. Proactive regulatory monitoring — as state regulators update their MCR examination focus areas, we adjust your data collection and validation processes to stay ahead of where examiners are looking

Q3: Ready to Build a Defensible MCR Process?

If your current mortgage call reporting process lives in a spreadsheet, gets assembled in the last week of the filing window, and has never been cross-referenced against your HMDA data — that’s the process an examiner will find when they review your licensing history.

The good news: MCR compliance doesn’t require rebuilding your entire technology stack. It requires disciplined reconciliation, documented procedures, and a compliance partner who understands how regulators actually use the data.

Synergy works with lenders and servicers to build MCR processes that hold up under regulatory scrutiny — from data validation through submission and audit documentation.

Contact us to discuss your current MCR compliance posture or book a demo at simplifyqc.com.

Mortgage Call Report Q&A: Servicing Data and Expanded Filers

Q1: What Is the Actual Enforcement Pattern for MCR Non-Compliance Across Major States?

Enforcement varies significantly by state regulator — which is one of the most underappreciated aspects of MCR risk management for multi-state lenders.

The SAFE Act mandates MCR filing as a condition of license maintenance, but the enforcement mechanisms are state-designed:

California (DFPI): DFPI has been increasingly active in examining MCR data against branch license activity. We’ve seen examination findings issued where branch-level MCR submissions showed activity inconsistent with the company’s NMLS licensing map.

New York (DFS): DFS takes a hard line on late or missing filings, and has included MCR non-compliance as a factor in consent order negotiations with mortgage servicers — even when the underlying issue was unrelated to call reporting.

Texas (SML): The new Q1 2026 supplemental filing requirement has caught several mid-sized servicers off guard. SML has signaled through industry communications that they will be actively validating supplemental submissions against RMLA data.

Washington (DFI): Washington DFI has issued fines for incomplete MCR filings — not just late ones — where companies filed but left required fields blank or submitted obviously rounded figures that suggested incomplete data collection.

The pattern across all states: regulators are using MCR data as a primary source for examination planning. A clean MCR history doesn’t just avoid penalties — it shapes which companies get examined and how intensively.

Q2: How Should Servicers Handle Loss Mitigation and Workout Data in the Expanded MCR?

For Expanded MCR filers — those approved by Fannie Mae, Freddie Mac, or Ginnie Mae — the servicing data section is where most reconciliation errors occur. With FHA’s revised loss mitigation waterfall (effective October 2025 under ML 2025-06 and subsequent revisions) adding new workout options including Payment Supplements and modified COVID-era relief transitions, the MCR servicing categories are under pressure to reflect activity that previous form versions didn’t anticipate.

Specifically:

  1. Payment supplement activity needs to be properly categorized — this is a relatively new tool in the FHA servicing waterfall, and companies that haven’t updated their internal reporting taxonomies are classifying it inconsistently
  2. COVID-era loss mitigation transitions are winding down under the updated permanent waterfall, but the activity is still appearing in MCR data under legacy categories, creating inconsistencies
  3. Modifications vs. forbearance re-defaults — there is genuine ambiguity in how to report certain workout scenarios, and companies making conservative assumptions may be underreporting while aggressive classifications create regulatory exposure

The practical recommendation: before each quarterly filing, your servicing data team and your compliance team need to review the categorization decisions together — not hand off data in a one-way process.

Q3: How Does MCR Data Interact With HMDA LAR — and Where Do the Reconciliations Break Down?

The intersection of MCR and HMDA reporting is where experienced compliance teams still make errors — not because the concepts are difficult, but because the two datasets use different segmentation logic and deadlines that create plenty of room for inconsistency.

Key reconciliation challenge: loan count segmentation. HMDA requires reporting of originated loans, purchased loans, and in some cases applications that didn’t close. The MCR RMLA captures origination activity by product type and purpose. When a company is active in both HMDA-reportable and business-purpose lending, the segmentation of the MCR data must align with the same population that drives HMDA reporting.

The “no activity” problem. Companies that originate no HMDA-reportable loans in a quarter still have MCR filing obligations — but the RMLA data must reflect zero origination activity consistent with what HMDA would show. If the company had any activity at all and is claiming zero in both, regulators will cross-reference and find the discrepancy.

Annual LAR reconciliation. HMDA’s annual submission deadline (March 2 for 2025 data) creates a natural reconciliation point with the four quarterly MCR submissions. Companies that perform this reconciliation annually rather than quarterly frequently discover errors that have compounded across multiple quarters.

Q4: What Documentation Do You Need to Survive an MCR Examination?

State examiners don’t just ask for your NMLS submission. They ask for the supporting documentation — and if you can’t produce it, the filing itself becomes a compliance issue.

The audit trail for a defensible MCR filing should include:

  1. Source system reconciliation reports showing how origination, servicing, and accounting data fed into each MCR field
  2. Data classification logic — documented rationale for how you categorized each loan type, product, and activity line
  3. Internal review sign-off — a named compliance officer or CFO who reviewed and approved the filing before submission
  4. Correction log — if prior quarters were amended, the documentation of what changed and why
  5. State-specific supplemental data — stored separately from the NMLS submission with its own supporting documentation

For Expanded MCR filers, the documentation burden is higher. Servicing portfolio data should tie to investor statements; loss mitigation figures should tie to your loss mitigation workflow system; delinquency and default data should tie to your default management reporting.

Mortgage Call Report Q&A: What Examiners Want to See

The Mortgage Call Report is one of the most examined regulatory filings in mortgage lending — and most compliance teams are treating it like a simple data submission exercise. Regulators are treating it as a risk signal. Here’s what every Mortgage Call Report filer needs to understand about how examiners actually review your submission.

Q1: What Are Examiners Actually Looking for When They Review Our MCR?

Most compliance teams treat the MCR as a data submission exercise. Regulators treat it as a risk signal.

State financial examiners don’t just check whether you filed — they cross-reference your MCR data against your HMDA submissions, your BSA/AML filings, your licensed MLO count on NMLS, and your audited financial statements. When those numbers don’t reconcile, you get an examination finding — not a conversation, a finding.

Specifically, examiners are flagging:

  1. Servicing portfolio totals that don’t match investor reporting — the most common Expanded MCR trigger
  2. MLO headcount that diverges from state licensing records — particularly after a layoff round or MLO migration
  3. Denial rate spikes without accompanying explanation — regulators are acutely focused on adverse action patterns
  4. Origination volume that doesn’t correlate with your stated product mix — a lender claiming $200M in originations but only two loan products raises questions

The takeaway: your MCR shouldn’t be assembled in the filing window. It should be reconciled continuously against your other regulatory outputs throughout the quarter.

Q2: What Actually Changed With MCR Form Version 7 — and What Filers Are Getting Wrong?

Starting Q1 2026, MCR FV7 replaced FV6 as the mandatory submission format. The headline change was structural consolidation — FV6 eliminated the separate Standard and Expanded MCR forms in favor of a single filing with conditionally required fields based on company type and license profile. But the practical implications run deeper than the form redesign.

The most common FV7 filing errors we’re seeing:

Servicing portfolio segment misclassification. FV7 restructured how servicing activity is reported across investors. Companies that didn’t update their internal data mappings before the Q1 2026 window opened are reporting data under old categories — meaning the numbers don’t align with what state regulators are now expecting to see.

Ginnie MaeIssuer-specific data gaps. FV7 introduced new conditional fields for Ginnie Mae Issuers that weren’t present in FV6. If your compliance team built your FV7 filing template from FV6 documentation rather than the current NMLS field definitions and instructions, you’re almost certainly missing required fields.

State-specific supplemental attachments. Texas’s new supplemental filing requirement — effective Q1 2026 for companies engaged in third-party processing or underwriting — is a separate submission from the NMLS MCR. Several lenders treated it as part of the MCR filing and either missed it entirely or submitted incomplete data.

Q3: How Do You Handle MCR Reporting When You Have both State-Licensed and Federally Chartered Entities?

This is one of the most complex MCR scenarios in the industry, and it’s becoming more common as large bank mortgage subsidiaries and credit union service organizations navigate dual chartering structures.

When a company operates both state-licensed entities and federally chartered affiliates, the MCR reporting obligations do not consolidate at the parent level — they file separately through NMLS for each licensed entity. The data must reflect only that entity’s activity, not the consolidated group.

The practical compliance challenge is cost allocation and data allocation. State regulators have increasingly scrutinizing whether shared services (compliance technology, QC staff, accounting functions) are being allocated appropriately across entities — particularly when one entity appears unprofitable while the parent is profitable. examiners are beginning to ask for supporting documentation on cost allocation methodologies.

Additionally, if your state-licensed entity services loans for your federally chartered affiliate, you may have MCR servicing data that needs to be reconciled against a separate federally required reporting framework — and the numbers must match.

FHA Appraisal Policy Changes 2025: What the Rollback of Bias Guidelines Means for Mortgage Lenders

What FHA Rolled Back — and Why It Matters Now

FHA appraisal policy changes in 2025 have fundamentally altered what lenders are required to do — and haven’t done — when it comes to monitoring for appraisal bias. For years, FHA-appraised properties carried explicit federal guidance requiring lenders to implement specific bias monitoring protocols. That framework is now gone. Here’s what the rollback means for your compliance posture.

In two separate moves during 2025, HUD revised its appraisal requirements in ways that significantly change the compliance landscape for FHA lenders.

On March 19, 2025, FHA issued Mortgagee Letter 2025-08, rescinding three policy documents:

  1. ML 2021-27 — the Appraisal Fair Housing Compliance letter, which had required lenders to implement protocols for identifying and addressing potential appraisal bias
  2. ML 2024-07 — the Reconsideration of Value (ROV) guidance, which established formal borrower-initiated ROV procedures
  3. ML 2024-16 — related appraisal review and reconsideration requirements

HUD’s stated reason: the policies were duplicative of existing professional standards (USPAP already addresses fair housing competency), and the rescissions were part of a broader regulatory reform effort under Executive Orders 14192 and 14219, aimed at reducing compliance burdens.

Then, on June 27, 2025, HUD issued Mortgagee Letter 2025-18 — “Rescission of Outdated and Costly FHA Appraisal Protocols” — eliminating additional appraisal requirements including the economic life estimate mandate for appraisers and additional appraisal requirements for Section 223(e) mortgages. The stated goal was cost reduction and streamlining.

The Compliance Gap This Creates

Here’s where the situation gets complicated for lenders.

When FHA rescinded the fair housing compliance letter (ML 2021-27), it removed the explicit federal guidance that told lenders specifically what their appraisal bias monitoring obligations were. HUD’s position: appraisers are already bound by USPAP and Fair Housing Act obligations, so the FHA-specific guidance was unnecessary.

That’s a reasonable argument at the individual appraiser level. But it doesn’t fully address what lenders need to do internally.

Consider the exposure:

The Fair Housing Act has not changed. Lenders still have obligations to ensure their appraisal processes don’t result in discriminatory outcomes — regardless of whether FHA publishes specific monitoring guidance.

Other regulators are still watching. State attorneys general, the CFPB, and HUD’s own FHEO office can still investigate appraisal bias claims against lenders. The rescission of FHA guidance doesn’t shield lenders from fair lending enforcement; it just removes the explicit floor FHA had previously established.

State regulators may fill the vacuum. Several states — including California and New York — have been actively expanding fair housing enforcement. Lenders operating in those markets may face stricter expectations than the rescinded FHA guidance ever imposed.

What Still Applies After the Rollback

Even with ML 2021-27 gone, several core obligations remain fully in effect for every FHA lender:

The Fair Housing Act. This is federal law — it doesn’t get rescinded by a mortgagee letter. Lenders must not discriminate on the basis of race, color, national origin, religion, sex, familial status, or disability in any aspect of a dwelling-related transaction, including appraisals.

Lender appraisal review obligations. FHA still requires mortgagees to review appraisals for completeness and quality. ML 2025-08 removed the specific ROV protocol guidance — but lenders still need review processes that can catch problematic valuations.

Equal Credit Opportunity Act (ECOA) / Regulation B. Appraisal-related discrimination claims can be brought under ECOA as well. The CFPB’s updated Regulation B, with its new intent-based fair lending framework taking effect July 21, 2026, makes this particularly relevant.

QM and ability-to-repay considerations. Appraised value still matters for loan-to-value calculations, loan eligibility, and investor delivery requirements.

Why Internal QC Matters More Than Ever

Here’s the practical implication that too many lenders are underestimating: the removal of FHA’s appraisal bias guidance doesn’t reduce your risk — it shifts the burden of managing that risk entirely onto your internal quality control program.

Previously, lenders could point to specific FHA guidance as evidence of their compliance program. Now, without that explicit framework, lenders need to demonstrate that they have their own robust appraisal review processes — processes that can identify when an appraisal may reflect bias, discriminatory patterns, or valuation errors before the loan closes.

This means your QC program needs to do more than check for form completion. It needs to:

  1. Monitor appraisal outcomes for patterns — particularly across demographic lines, even without a specific FHA mandate to do so
  2. Document your internal review process so you have a defensible record if a fair lending claim ever arises
  3. Ensure ROV procedures are still in place even without the specific FHA protocol — borrowers can still request reconsiderations, and you need a consistent, fair process to handle them
  4. Update your policies and procedures to reflect that appraisal bias monitoring is now entirely an internal obligation, not an FHA-prescribed one

The Bottom Line

FHA’s 2025 appraisal policy rollbacks reduce some administrative burden — but they create a compliance gap that lenders ignore at their peril. The explicit framework for appraisal bias monitoring is gone. What remains is the broader Fair Housing Act, state enforcement trends, and the lender’s own internal QC program.

If your appraisal quality control process hasn’t been updated to reflect these changes, now is the time to do it.

At Synergy, we help lenders build appraisal QC programs that go beyond form-checking — including fair lending risk monitoring and documentation practices that hold up under regulatory scrutiny.

Want to review your current appraisal QC framework? Contact Synergy for a compliance consultation, or book a demo at SimplifyQC.com.

Fannie Mae & Freddie Mac AI Governance: What Lenders Must Do

Two GSEs, Two Deadlines, One Compliance Reality

The mortgage industry has entered a new era of AI governance — and this shift is coming from the two government-sponsored enterprises, not just federal agencies.

On March 3, 2026, Freddie Mac updated its Seller/Servicer Guide Section 1302.8, establishing formal governance requirements for any seller/servicer using artificial intelligence or machine learning in connection with mortgages sold to Freddie Mac. Then, on April 8, 2026, Fannie Mae issued Lender Letter LL-2026-04 — its own AI/ML governance framework for single-family sellers and servicers — effective August 6, 2026.

Together, these mandates create a dual-layer compliance obligation affecting virtually every lender operating in the conventional space. Whether you sell to Freddie Mac, Fannie Mae, or both, your AI governance infrastructure is now under regulatory scrutiny that didn’t exist twelve months ago.

What Freddie Mac Requires (Section 1302.8, Effective March 3, 2026)

Freddie Mac’s guidance, issued under Bulletin 2025-16, sets the baseline. Any seller/servicer using AI or ML in loan origination or servicing must establish a clear, documented governance framework covering:

  1. Policies, processes, and procedures governing AI/ML adoption and use throughout the loan lifecycle
  2. Risk management actions for AI/ML systems — how the lender identifies, assesses, and mitigates AI-related risk
  3. Senior management approval of AI/ML policies — a higher bar than simply documenting them
  4. Indemnification obligations — lenders assume full responsibility for AI-driven decisions, including outcomes from vendor-provided AI tools
  5. Compliance with applicable law and Freddie Mac Purchase Documents

The indemnification obligation deserves special attention. If a lender’s vendor supplies an AI-driven underwriting tool that produces a discriminatory outcome, the lender — not the vendor — bears accountability to Freddie Mac. Vendor due diligence is no longer optional.

What Fannie Mae Requires (LL-2026-04, Effective August 6, 2026)

Fannie Mae’s Lender Letter LL-2026-04 takes effect August 6, 2026 — giving lenders a longer runway than Freddie Mac’s mandate, but no less urgency.

The framework requires single-family sellers and servicers to maintain a documented, actively maintained AI/ML governance program including:

  1. Written policies and procedures covering the full life cycle of any AI/ML system — from development to ongoing maintenance
  2. Annual policy reviews with a designated owner responsible for implementing, maintaining, and updating policies
  3. Trustworthy and ethical AI principles incorporated into the lender’s governance approach
  4. Information security compliance per Fannie Mae’s Information Security and Business Resiliency Supplement
  5. Vendor and subcontractor governance — AI/ML risk management standards must extend to any third-party tool, with protections no less robust than the lender’s own
  6. On-demand disclosure — upon request by Fannie Mae, lenders must promptly disclose AI/ML technologies deployed, their intended purposes, and risk safeguards in place

Fannie Mae’s requirements are less prescriptive than Freddie Mac’s in some areas — but they compensate with annual review obligations, designated ownership requirements, and explicit disclosure authority that gives Fannie Mae visibility into the AI tools lenders are using.

The Overlap With the New Fair Lending Framework

The timing is not coincidental. The CFPB’s April 2026 Regulation B final rule — shifting fair lending enforcement from a disparate impact to an intent-based standard — takes effect July 21, just weeks before Fannie Mae’s August 6 deadline.

If a lender uses AI-driven underwriting or pricing models and those tools produce discriminatory outputs, intentional use of that tool could constitute intentional discrimination under the new ECOA framework. Fannie Mae’s governance framework, with its emphasis on trustworthy and ethical AI, becomes a lender’s first line of defense — evidence that AI tools were deployed responsibly.

This means your AI governance documentation is no longer just a GSE compliance obligation. It is a fair lending defense. Quality control (QC) programs need to account for this intersection — reviewing whether AI tool outputs are defensible under the new intent-based standard.

Building a Compliant AI Governance Framework: Where to Start

Inventory your AI/ML tools. Identify every AI or machine learning system used in loan origination, underwriting, pricing, or servicing — including vendor-supplied tools.

Establish written policies and procedures. Both GSE frameworks require documented policies covering the full AI/ML lifecycle, reflecting legal requirements, ethical AI principles, and your institution’s risk tolerance.

Designate an owner. Fannie Mae requires a designated owner for annual reviews; Freddie Mac requires senior management approval. These establish internal accountability — and external defensibility.

Extend governance to vendors. Lenders bear responsibility for AI tool outcomes regardless of vendor involvement. Third-party AI vendors must be subject to the same governance standards.

Integrate AI governance into your quality control program. Quality control reviews should assess AI tool outputs, document governance compliance, and verify that AI-driven decisions are defensible under the new fair lending framework.

The Bottom Line: AI Governance Is Now Mortgage Compliance

Fannie Mae and Freddie Mac have made their position clear: AI governance is not a future consideration — it is a present obligation. With Freddie Mac’s deadline already passed and Fannie Mae’s approaching, lenders without established frameworks are exposed on multiple fronts.

The stakes go beyond GSE compliance. Ungoverned AI tools can expose lenders to fair lending liability, investor repurchase risk, and regulatory enforcement — particularly as the CFPB’s intent-based fair lending standard takes effect.

At Synergy, we help mortgage lenders build and maintain AI governance frameworks that satisfy GSE requirements and hold up under regulatory scrutiny. Our QC platform integrates AI governance assessment into your broader compliance program — so you’re covered on every front.

Need help building or reviewing your AI governance framework before the August 6 deadline? Contact Synergy to speak with a compliance specialist, or book a demo at simplifyqc.com.

CFPB Fair Lending Rule 2026: What Mortgage Lenders Must Do Before July 21 to Stay Compliant

What the CFPB Fair Lending Rule Means for Mortgage Lenders

The CFPB fair lending rule issued April 22, 2026, is one of the most consequential shifts in mortgage fair lending enforcement in decades — and it takes effect July 21. If your QC program hasn’t been updated to reflect the new intent-based standard, you’re behind.

For mortgage lenders, servicers, and quality control professionals, this is not a routine update. It is one of the most consequential regulatory shifts in fair lending enforcement in decades. And with the July 21 effective date approaching fast, lenders who haven’t begun adapting their compliance frameworks need to act immediately.

What Changed: Understanding the Regulation B Final Rule

The End of Disparate Impact Under Regulation B

The most significant change is the removal of the disparate impact standard from Regulation B. For years, lenders could be held liable under ECOA even without evidence of intentional discrimination — if a policy or practice had a “disproportionate adverse impact” on a protected class, and the lender couldn’t demonstrate “business necessity.”

The CFPB’s final rule eliminates this framework. ECOA, as interpreted through Regulation B, is now an intent-based statute. Liability will require showing that a lender intentionally discriminated on a prohibited basis.

It is critical to note: this change applies specifically to Regulation B. Other federal fair lending laws — including the Fair Housing Act — retain their disparate impact frameworks. HUD’s separate rulemaking on the FHA’s disparate impact standard remains ongoing. Lenders must not conflate the two.

Narrowed Discouragement Standard

The rule also tightens what constitutes “discouragement” under Regulation B. The prior standard captured a broad range of statements, practices, and even inaction that could discourage applicants. The new rule limits discouragement to explicit exclusionary messaging — making it harder for regulators to pursue claims based on ambiguous or indirect conduct.

New Restrictions on Special Purpose Credit Programs

Special Purpose Credit Programs (SPCPs) — programs designed to address historical discrimination by extending credit to underserved borrowers — remain permitted but face new procedural requirements and limitations under the final rule.

Why the CFPB Issued This Fair Lending Rule

The CFPB under Acting Director Russell Vought framed the rule as a return to “core statutory principles,” arguing that disparate impact liability was not authorized by the text of ECOA. The regulatory relief narrative also fits within the broader policy direction of the March 13, 2026 Executive Order, “Promoting Access to Mortgage Credit,” which signaled an intent to reduce compliance burden on lenders, particularly smaller institutions.

What This Means for Your QC Program

The elimination of disparate impact does not mean fair lending compliance becomes optional — it becomes different.

From Statistical Scrutiny to Intent Review: Your QC processes likely include statistical analysis — HMDA data reviews, denial rate comparisons across demographics, pricing disparities. While these remain valuable compliance tools, the legal standard for liability has shifted. QC teams must pivot toward identifying specific discriminatory intent in individual transactions or clearly discriminatory policies.

Updated Policies and Procedures: Lender fair lending policies must be updated to reflect the new intent-based framework. Discouragement policies, in particular, need to be redrawn to reflect the narrowed standard. Failure to update internal guidance before July 21 creates immediate mortgage compliance risk.

Enhanced Documentation of Intent: When reviewing loan files for fair lending red flags, QC reviewers should document not just statistical patterns but evidence of intent. What was said, what was written, what policy decisions were made — these become the evidentiary basis under the new standard.

AI/ML Accountability Gains New Urgency: Freddie Mac’s AI/ML governance requirements, codified in Guide Section 1302.8 and effective March 3, 2026, remain firmly in force and gain new importance in this environment. If a lender’s AI-driven underwriting or pricing models produce discriminatory outputs, intentional use of that tool could constitute intentional discrimination — regardless of the removed disparate impact standard. Lenders bear full responsibility for AI-driven decisions affecting loan outcomes.

HUD Fair Housing Act Remains Separate: Don’t conflate the Regulation B change with the Fair Housing Act. HUD has signaled a narrower enforcement focus, but the FHA’s disparate impact standard is a separate legal question. Both laws remain active and enforceable.

Key Action Steps Before July 21, 2026

1.Audit your fair lending QC protocols. Identify where your current program is built around disparate impact analysis and adapt accordingly.

2.Update internal policies and procedures. Align policy language with the new intent-based standard and narrowed discouragement definition.

3.Retrain QC staff and underwriting teams. Ensure everyone understands the shift from statistical to intent-based review.

4.Review all SPCPs. Confirm that any special purpose credit programs your institution offers meet the new procedural requirements.

5.Stress-test your AI governance framework. If you use AI or ML in loan origination, underwriting, or servicing, confirm that your governance documentation satisfies Freddie Mac Section 1302.8 requirements.

6.Engage legal counsel. Given the scope of this change, legal review of your compliance program before the effective date is strongly recommended.

The CFPB Fair Lending Rule in the Context of 2026 Regulatory Changes

The Regulation B final rule is one piece of a broader reshaping of mortgage regulation. The March 13 executive order also directs the CFPB to reconsider ATR/QM requirements and potentially modify TRID disclosure rules. HUD has updated fair housing guidance. Annual Regulation Z threshold adjustments took effect January 1, 2026. The volume of change is significant, and lenders who adapt fastest — with sharp, well-informed QC programs — will be best positioned to navigate the months ahead.

Stay Ahead of the Compliance Curve

The mortgage regulatory landscape in 2026 is shifting faster than many anticipated. New fair lending standards, AI governance mandates, executive orders on credit access — the pace of change demands more than static compliance procedures. It demands a proactive, adaptive quality control partner.

At Synergy, we specialize in helping mortgage lenders and servicers stay ahead of these developments. Our quality control and compliance solutions are built to evolve as the regulatory environment shifts — so your team doesn’t have to manage it alone.

Ready to review your QC program ahead of the July 21 effective date? Contact Synergy today to speak with a compliance specialist or book a demo of our quality control platform at simplifyqc.com.

Web Statistics