Category Archives: Regulatory Updates

Inside the CFPB’s 2026 Regulatory Agenda: 5 Mortgage Rules Compliance Officers Must Track This Fall

The CFPB’s 2026 regulatory agenda, published August 14, 2026, is the clearest signal yet of how far the mortgage deregulation push triggered by Executive Order 14393 is going to reach — and it names five specific rulemakings that belong on every compliance officer’s Q4 calendar, not just a general sense that “things are changing.” The agenda itself is technically the delayed Fall 2025 edition, and the Bureau’s own preamble notes the timelines should be read as approximations given the Bureau is currently operating under interim leadership pending confirmation of a permanent director. Approximate or not, these are the items driving actual rulemaking activity right now, and waiting for a final rule to publish before you start tracking it means you’re always reacting instead of preparing.

The Executive Order Driving All of This

Executive Order 14393, “Promoting Access to Mortgage Credit,” signed March 13, 2026, directs the CFPB, FDIC, OCC, Federal Reserve, NCUA, and FHFA to review and reduce regulatory requirements that the administration argues have increased mortgage origination and servicing compliance costs and discouraged bank participation in the mortgage market. The order specifically calls out ability-to-repay and qualified mortgage requirements, TRID disclosure timing, and points-and-fees thresholds for small-balance loans as areas ripe for reform. Nearly every mortgage-related item on the CFPB’s 2026 agenda traces back to this directive.

Five Items for Your Q4 Compliance Calendar

1. Ability-to-Repay and Qualified Mortgage Reconsideration

The CFPB upgraded its review of ATR requirements and QM definitions from a long-term action item on the prior agenda to an active pre-rule item, with anticipated activity in August 2026. This is early-stage — pre-rule status means no proposed text yet — but it’s the most consequential item on the entire agenda if it moves, since ATR/QM standards touch every conventional mortgage originated in the country. Compliance officers should not wait for a proposed rule to start scenario-planning; the general direction (reducing compliance costs and expanding the QM safe harbor) is already signaled by the executive order.

2. TRID Disclosure Timing Review

EO 14393 specifically flags TRID disclosure timing as a target for reform. No proposed rule text has published as of this writing — verify current status before making operational assumptions — but any change to Loan Estimate or Closing Disclosure delivery timelines has direct systems and workflow implications for origination and closing teams. This is worth flagging to your loan origination system vendor now so you’re not waiting on a vendor update queue once a rule actually publishes.

3. Points-and-Fees Threshold Adjustments for Small-Balance Loans

The executive order directs regulators to consider adjusting points-and-fees thresholds specifically for small-balance loans — a longstanding industry concern, since fixed origination costs make small loans disproportionately likely to trip QM points-and-fees caps regardless of actual borrower cost. If your institution originates smaller-balance loans in lower-cost markets, this is the item most likely to directly expand your lending box if finalized.

4. The Regulation X Mortgage Servicing Overhaul

Still in the final rule stage as of the August 2026 agenda, this is the most mature item in the pipeline — proposed back in July 2024, with a comment period that closed in September 2024. It’s covered in depth elsewhere in this issue, but it belongs on this list because it’s the mortgage rulemaking most likely to actually finalize before year-end.

5. Larger Participant NPRMs Touching Consumer Reporting

Following advance notices of proposed rulemaking issued in August 2025, the Bureau anticipates proposed rules in September 2026 reconsidering the “larger participant” tests across four markets — automobile financing, consumer debt collection, consumer reporting, and international money transfers. The consumer reporting market item is the one mortgage lenders should watch most closely: it governs which consumer reporting agencies fall under CFPB supervisory authority, which has downstream implications for how your credit report and tri-merge vendors are regulated and examined.

A Smaller Item Worth Noting: The 2026 HPML Appraisal Threshold

Separate from the agenda items above, the CFPB, Federal Reserve, and OCC jointly announced that the 2026 threshold for higher-priced mortgage loans subject to special appraisal requirements increased from $33,500 to $34,200. It’s a routine annual CPI-based adjustment, not a policy shift, but it’s exactly the kind of housekeeping item that gets missed when compliance attention is consumed by the bigger rulemakings above — confirm your HPML appraisal exemption logic in your LOS reflects the current threshold.

Building a Q4 Regulatory Change Calendar

With this many moving parts, ad hoc tracking doesn’t work. A structured approach:

  • Assign one owner per agenda item — not one owner for “CFPB rulemaking” generally — so accountability doesn’t diffuse across a broad topic no one fully covers.
  • Set a recurring monthly check against the CFPB’s regulatory agenda and final rules pages, since the Bureau itself has flagged that its own timelines are approximate under current leadership transitions.
  • Separate “monitor” items (ATR/QM, TRID timing, points-and-fees — all pre-rule or undetermined) from “prepare now” items (Regulation X servicing, which is in the final rule stage and could publish with limited notice).
  • Brief your board quarterly on cumulative regulatory exposure, not just individual rules, so governance understands the scale of change moving through the pipeline simultaneously.

The Supervisory Backdrop

All of this rulemaking activity is happening against a CFPB operating with constrained resources. The Bureau’s acting leadership told Congress it needs $279.6 million just to maintain statutorily required operations through the end of fiscal year 2026, which closes September 30, 2026. Reduced Bureau capacity doesn’t mean reduced compliance obligations — it likely means more reliance on state regulators and other federal prudential agencies for exam coverage, and it means final rules, once issued, may carry less accompanying implementation guidance than lenders have historically relied on. Build your own interpretive documentation accordingly.

Frequently Asked Questions

What is Executive Order 14393?

Signed March 13, 2026, and titled “Promoting Access to Mortgage Credit,” it directs the CFPB and other federal financial regulators to review and reduce mortgage origination and servicing regulatory requirements, specifically naming ATR/QM standards, TRID disclosure timing, and points-and-fees thresholds for small-balance loans as reform targets.

Which item on the CFPB’s agenda is most likely to finalize first?

The Regulation X mortgage servicing overhaul, since it’s already in the final rule stage with a proposal and closed comment period dating back to 2024. ATR/QM and TRID timing reforms are still at the pre-rule stage, meaning no proposed text has published yet.

What is the 2026 HPML appraisal threshold?

The threshold for higher-priced mortgage loans subject to special appraisal requirements increased from $33,500 to $34,200 for 2026, under the routine annual CPI-based adjustment jointly announced by the CFPB, Federal Reserve, and OCC.

Why does CFPB funding matter for compliance planning?

The Bureau’s acting leadership has told Congress it needs $279.6 million to maintain required operations through the end of fiscal year 2026 (September 30, 2026), signaling constrained resources. That can mean less implementation guidance accompanying new final rules and shifted exam capacity toward state regulators and other prudential agencies — lenders should document their own interpretive positions more thoroughly than they might have in years with fuller Bureau guidance.

Five active rulemakings, one executive order, and a Bureau operating with constrained resources — that’s a lot to track manually. Synergy helps mortgage banks build regulatory change management processes that catch items like these before they become exam findings — see our compliance services and mortgage loan closing support, or book a 30-minute call to build your Q4 regulatory calendar.

The CFPB’s Regulation X Servicing Overhaul Could Drop Any Week: How Servicers Should Prepare Now

The Regulation X final rule that would rewrite how servicers handle loss mitigation is still sitting at the CFPB as of its August 14, 2026 regulatory agenda, which means it could publish next week, next month, or slip further — and that uncertainty is exactly the problem. The proposal, first issued July 10, 2024 under the title “Streamlining Mortgage Servicing for Borrowers Experiencing Payment Difficulties,” would eliminate the “complete application” framework that’s anchored 12 C.F.R. § 1024.41 loss mitigation procedures for more than a decade. Servicers who wait for the final rule to publish before touching their loss mitigation workflow will be doing emergency implementation on a compressed timeline. Servicers who start now will have a working head start.

What the Proposed Rule Would Actually Do

The proposal reflects a genuine structural shift, not a set of tweaks. Understanding the mechanics matters because the operational build is substantial regardless of exactly when the final rule lands.

Removing the Complete Application Trigger

Under current Regulation X, most loss mitigation protections — including the prohibition on dual tracking toward foreclosure — hinge on the borrower submitting a “complete” loss mitigation application. That completeness threshold has long been a source of servicer-borrower disputes and litigation risk: borrowers claim they submitted enough information, servicers claim the application was incomplete, and foreclosure timelines hang in the balance. The proposed rule would remove most of the application-based provisions from § 1024.41 entirely, replacing the completeness gate with a continuous “loss mitigation review cycle” triggered simply by a borrower’s request for assistance.

Foreclosure Safeguards Attach Earlier

Instead of waiting for a complete application to trigger foreclosure procedural protections, the proposal would require servicers to provide those safeguards as soon as a borrower requests loss mitigation assistance — a meaningfully earlier trigger point than current rules. For servicers, this means foreclosure referral holds and early intervention procedures need to activate off a borrower’s initial contact, not off a completed document package.

New Notice and Explanation Requirements

Early intervention notices would need to include phone and website contact information covering all available loss mitigation options — not just the general servicer contact info many templates currently use. Servicers would also be required to provide detailed explanations for loss mitigation decisions, moving away from boilerplate denial language toward decision-specific reasoning that borrowers (and examiners, and plaintiffs’ attorneys) can actually evaluate. The proposal also introduces Spanish-language requirements for certain borrower communications.

Why This Rule Is Likely to Move — and Why It Might Not Track the 2024 Draft Exactly

Executive Order 14393, signed March 13, 2026, directly instructs the CFPB and prudential regulators to simplify loss mitigation requirements as part of a broader push to reduce mortgage origination and servicing compliance costs. Finalizing the Regulation X overhaul is widely read as the Bureau’s direct response to that instruction, which is why it remains an active final-rule-stage item on the August 2026 agenda even as other, lower-priority rulemakings have been pushed to long-term status.

That said, don’t assume the final rule will track the 2024 proposal word for word. Industry commenters, including the Conference of State Bank Supervisors, raised specific concerns during the comment period that closed September 9, 2024 — particularly around state law preemption, since several states independently require a complete loss mitigation application before foreclosure protections attach, creating a potential conflict between a federal rule eliminating that requirement and state statutes that still impose it. Expect the final rule to address preemption more explicitly than the proposal did, and expect at least some revision from the original draft in response to comments. Treat the specific provisions above as directional, not final, until the rule publishes — verify current text against the Federal Register release when it lands.

The Small Servicer Question

The proposal leaves the existing small servicer exemption in place for institutions servicing 5,000 or fewer mortgage loans, which are largely excused from Regulation X’s loss mitigation procedures already. If your institution qualifies as a small servicer, the direct rule impact is limited — but if your loss mitigation process is modeled on Regulation X’s structure even though you’re exempt (a common practice for consistency and investor requirements), you should still track how the final rule reshapes that structure, since your own internal policy references it.

How to Prepare Before the Rule Publishes

  1. Map your current loss mitigation workflow against the proposed continuous review cycle model — identify every process step currently gated by “complete application” status and flag it for redesign.
  2. Inventory your state-by-state loss mitigation requirements now, since several states impose completeness standards independent of federal law; a federal rule change won’t necessarily relieve those state obligations.
  3. Review early intervention notice templates and confirm whether your current contact information and loss mitigation option disclosures could be expanded to meet a “detailed explanation” standard without a full rebuild.
  4. Assess your Spanish-language communication capability across loss mitigation touchpoints — call center scripting, notice templates, and web content — so you’re not building translation infrastructure under a compressed compliance date once the rule finalizes.
  5. Brief your board and senior management now on the scope of this change, so budget and staffing conversations aren’t happening for the first time after the final rule publishes with a short effective date.

Why Waiting Is the More Expensive Option

CFPB final rules of this scale typically carry effective dates measured in months, not years, especially under an administration prioritizing rapid deregulatory implementation. A servicing shop that starts workflow redesign, vendor system updates, and staff retraining only after the Federal Register publication is compressing a multi-month project into whatever window the effective date allows. Given that the underlying policy direction — earlier foreclosure protections, continuous review cycles, detailed decision explanations — has been publicly known since July 2024, there’s no credible argument for treating this as a surprise when it lands.

Frequently Asked Questions

Has the CFPB’s Regulation X servicing rule been finalized yet?

Not as of the CFPB’s August 14, 2026 regulatory agenda, which still lists it as an active item in the final rule stage. Verify current status against the CFPB’s rules and policy page before making implementation decisions based on assumed timing.

What’s the biggest operational change in the proposal?

Removing the “complete application” framework and replacing it with a continuous loss mitigation review cycle triggered by a borrower’s request for assistance, rather than by a completed document package. This shifts when foreclosure procedural safeguards attach and changes how servicers need to track borrower engagement.

Does the small servicer exemption still apply?

Yes, under the proposal, servicers of 5,000 or fewer mortgage loans retain their existing exemption from most Regulation X loss mitigation procedures. Servicers near that threshold should confirm their current loan count and monitor whether the final rule adjusts the exemption.

Will state loss mitigation laws still require a complete application even after this rule?

Possibly, in states that independently codify a completeness requirement for foreclosure protections. State regulator groups flagged this preemption question directly during the comment period, so expect the final rule to address it — but until it publishes, servicers in those states should assume dual compliance obligations rather than assuming federal preemption.

A loss mitigation program built for the current rule isn’t ready for the one that’s coming. Synergy helps mortgage banks and servicers stress-test loss mitigation workflows against pending regulatory change — see our compliance services and mortgage loan fulfillment support, or book a 30-minute call to map your Regulation X readiness gaps now.

CFPB’s New ECOA Rule Eliminates Disparate Impact: What Lenders Must Fix in Fair Lending QC Now

The CFPB’s ECOA disparate impact rule has been the law of the land since July 21, 2026, which means it’s been sitting on your fair lending QC program for roughly two months — long enough that any gap between what your testing methodology assumes and what Regulation B now actually requires has already generated data you’ll have to explain to an examiner. On April 22, 2026, the Bureau finalized a rule that strips the “effects test” out of Regulation B and affirmatively states that the Equal Credit Opportunity Act does not recognize disparate-impact liability. If your QC team is still running fair lending testing built around the old effects-based framework, you’re not just behind — you’re generating findings against a legal standard that no longer exists.

What the Rule Actually Changed

The final rule amends Regulation B in three specific ways, and each one has direct operational consequences for a mortgage bank’s compliance management system.

Disparate Impact Is Out

The CFPB removed the “effects test” from Regulation B and stated plainly that ECOA does not recognize disparate-impact liability — a theory the Bureau had relied on for over a decade to pursue lenders whose facially neutral policies produced statistically disproportionate outcomes for a protected class, regardless of intent. Under the amended rule, ECOA claims require proof of disparate treatment: differential handling tied to a prohibited basis, not just a statistical gap in outcomes.

Discouragement Now Requires Intent

The rule also narrows the “discouragement” prohibition. Previously, a lender could face liability for statements or practices that merely created a negative impression and discouraged a reasonable person from applying, even absent any intent to discriminate. Under the amended standard, the Bureau is focused on statements of intent to discriminate — a materially higher bar. Marketing language, loan officer scripts, and website messaging that were previously scrutinized for “chilling effect” now get evaluated for actual discriminatory intent.

Special Purpose Credit Programs Get New Guardrails

If your institution runs — or is considering — a Special Purpose Credit Program (SPCP) under Regulation B § 1002.8, the rule now prohibits using race, color, national origin, or sex as common characteristics defining program eligibility, and it imposes additional documentation requirements on for-profit creditors that want to operate one. Programs designed around those characteristics need immediate legal review; this isn’t a phase-in situation.

Why Your Fair Lending QC Testing Needs to Change Now

Most mortgage banks built their fair lending monitoring programs — matched-pair analysis, marginal-effect regression testing, redlining geospatial review — around a dual-track standard: disparate treatment and disparate impact. That was the right architecture for the last decade of CFPB enforcement priorities. It’s the wrong architecture now, for one simple reason: your QC team is going to keep finding statistical disparities, because pricing and underwriting outcomes are never perfectly uniform across demographic groups, and none of those findings are actionable under the amended ECOA standard unless you can also show intent or differential treatment.

That doesn’t mean disparate-impact analysis is worthless — it doesn’t. Here’s why:

  • State fair lending laws in several states retain disparate-impact standards independent of federal ECOA, so multi-state lenders can’t simply drop the analysis.
  • Fannie Mae, Freddie Mac, and FHA/VA overlays and seller/servicer guides may still expect fair lending self-testing regardless of the federal liability standard.
  • A future administration or a future CFPB director could reverse this rule, and lenders who dismantled their testing infrastructure entirely will have to rebuild it from scratch.
  • Statistical disparity findings remain useful as an early-warning signal for underwriting or pricing drift, even when they’re no longer independently actionable under ECOA.

The right move isn’t to eliminate disparate-impact-style statistical monitoring — it’s to re-tier it. Keep it as an internal risk indicator that triggers deeper review, but stop treating a marginal-effect finding by itself as a fair lending violation requiring remediation under federal law. Reserve remediation resources for findings that show actual differential treatment or documented intent.

Updating Loan Officer Scripts and Marketing Under the New Discouragement Standard

The shift from “negative impression” to “intent to discriminate” changes what your marketing and pre-qualification review process should be looking for. Under the old standard, compliance reviewers flagged language that could plausibly discourage a protected class applicant even without any discriminatory intent — things like imagery, neighborhood targeting in geo-fenced digital ads, or loan officer talking points that emphasized certain buyer profiles. Under the amended rule, review should focus on whether language or conduct evidences an intent to discourage applicants on a prohibited basis.

This is a genuine loosening of compliance burden, but it comes with a practical trap: your marketing team may read this as a green light to revert to targeting practices that were curtailed years ago. Don’t let that happen without documented legal sign-off. The standard changed under federal law; state UDAP and mini-ECOA statutes did not necessarily move with it.

What to Do Before Your Next Fair Lending Exam

  1. Update your fair lending policy and QC testing plan to reflect the disparate-treatment-only standard, with a documented rationale for why (and how) you’re retaining statistical monitoring as a risk-tiering tool.
  2. Re-run your last two quarters of fair lending testing results through the new framework and document which findings would no longer independently trigger remediation — this becomes your baseline for board and examiner conversations.
  3. Audit any active SPCP for prohibited common characteristics and documentation gaps under the amended rule.
  4. Review loan officer scripts, ad targeting parameters, and pre-qualification messaging against the intent-based discouragement standard, with legal counsel sign-off on any changes.
  5. Confirm your state-level fair lending exposure hasn’t shifted — some states retained disparate-impact standards that federal deregulation doesn’t touch.

The Exam Risk of Doing Nothing

Examiners will not penalize you for having updated your testing methodology to reflect current law. They will absolutely ask questions if your QC files show you’re still applying — or worse, still citing — a legal standard the CFPB itself eliminated five months ago. A compliance management system that hasn’t been updated to reflect a final rule that’s been in effect since July signals to an examiner that your regulatory change management process isn’t working, and that finding tends to generate broader scope creep into other areas of the exam.

Frequently Asked Questions

Does this rule mean disparate impact claims are gone entirely?

Under federal ECOA and the amended Regulation B, yes — the effects test has been removed and the CFPB has stated ECOA does not recognize disparate-impact liability. But state fair lending and UDAP statutes in several states retain independent disparate-impact standards, so multi-state lenders still face exposure at the state level. Verify current state-level standards before assuming full relief.

Should we stop running statistical fair lending testing altogether?

No. Statistical testing remains a useful early-warning tool for pricing and underwriting drift, and it may still be expected under investor overlays or state law. The change is in how you classify and act on the results — a statistical disparity is now a signal for deeper review, not an independently actionable federal violation.

What happened to Special Purpose Credit Programs under this rule?

The rule prohibits using race, color, national origin, or sex as common characteristics defining SPCP eligibility, and adds documentation requirements for for-profit creditors operating one. Any active SPCP built around those characteristics needs immediate legal review — this took effect July 21, 2026, alongside the rest of the rule.

Could this rule be reversed under a future CFPB director?

It’s possible — ECOA rulemaking has shifted with administration priorities before, and this rule itself reversed prior CFPB guidance. That’s exactly why lenders should retain their statistical testing infrastructure rather than dismantling it: rebuilding a fair lending monitoring program from scratch under exam pressure is far more expensive than maintaining a scaled-down version now.

Fair lending QC testing that’s still built on a standard the CFPB retired in April is a finding waiting to happen. Synergy helps mortgage banks and credit unions rebuild fair lending testing methodology, SPCP documentation, and QC frameworks to match current Regulation B requirements — read more about our fair lending compliance assessment services or book a 30-minute call to walk through where your program stands.

State AI/ML Enforcement for Mortgage Lenders: What You Need to Know in 2026

Federal AI/ML guidance for mortgage lending remains a patchwork. The CFPB has issued interpretive guidance, the GSEs have published AI governance frameworks, and Congress has considered — but not passed — federal AI legislation. In the absence of a unified federal standard, state regulators have moved ahead with their own rules.

For mortgage lenders operating in multiple states, the practical effect is a growing set of state-specific AI/ML obligations layered on top of federal and GSE requirements. This article walks through the state rules that affect mortgage lenders in 2026, how they interact with each other and with federal frameworks, and what a defensible multi-state AI compliance program looks like.

Why State AI/ML Regulation Matters for Mortgage Lenders

State AI/ML rules were not written with mortgage lending as the primary use case. Most originate in consumer protection, employment, or insurance contexts. But the definitions of “automated decision tool,” “high-risk AI system,” and “consumer” are broad enough to capture mortgage lending activity — and state regulators have signaled that they will apply their AI rules to financial services, not just to the originally-targeted industries.

The compliance exposure is not theoretical. State AGs have been active in 2025 and 2026, with several settlements against financial services firms involving AI/ML use. Mortgage lenders that treat state AI compliance as a low-priority “tech company” issue are misreading the landscape.

Colorado AI Act (SB 24-205)

The Colorado AI Act took effect on February 1, 2026. It is the most comprehensive state AI statute in the United States and the one most likely to set a template for other states.

Who It Applies To

The Act applies to “developers” and “deployers” of “high-risk AI systems” used in Colorado. A deployer is any entity that uses a high-risk AI system to make decisions that affect Colorado residents. Mortgage lenders that use AI/ML systems for Colorado residents — including in origination, servicing, marketing, or customer service — are deployers under the Act.

What Counts as a High-Risk AI System

The Act specifies categories of high-risk systems. The relevant categories for mortgage lenders include:

  • AI systems used to make decisions about access to financial services, including credit
  • AI systems used for employment decisions (relevant for HR, recruiting, and internal loan officer evaluation)
  • AI systems that materially affect access to housing

Automated underwriting systems, AI-driven pricing tools, lead scoring systems that influence credit decisions, and AI-driven appraisal valuation models are all high-risk under the Act.

What Deployers Must Do

Deployers must implement a risk management program and policy, complete an impact assessment for each high-risk system, provide notice to consumers that an AI system is being used, and allow consumers to request human review of an AI-driven decision. The impact assessment must be made available to the Colorado AG on request.

The Act also prohibits algorithmic discrimination — defined in ways that overlap significantly with federal fair lending law but include additional categories of protected activity.

California AI Rules

California does not yet have a comprehensive AI statute, but the state has a layered set of AI-related rules that affect mortgage lenders.

AB 2013 (Generative AI Training Data)

AB 2013 requires developers of generative AI systems to publish a summary of the training data used. The rule is targeted at generative AI providers, not at deployers. For mortgage lenders, the relevance is downstream: if you use a generative AI tool (e.g., for document drafting, customer service), the underlying provider’s compliance affects your vendor risk profile.

SB 942 (AI Transparency)

SB 942 requires AI providers to offer a free AI detection tool to users. The rule is targeted at AI providers, not at deployers. The relevance is the same as AB 2013 — vendor due diligence.

California Department of Financial Protection and Innovation (DFPI)

The California DFPI has been the most active state financial regulator on AI/ML. The DFPI has issued multiple guidance documents on AI use in lending, conducted examinations focused on AI/ML systems, and entered into consent orders with lenders involving AI/ML model risk management and fair lending testing.

The DFPI’s approach is consistent with the federal and GSE frameworks, but it includes California-specific requirements on consumer notification, model documentation, and the right to human review. For lenders operating in California, DFPI expectations are effectively a fourth layer of AI/ML governance on top of CFPB, GSE, and other state rules.

New York State and City

New York has not passed a comprehensive state AI statute, but the New York Department of Financial Services (DFS) has issued guidance on AI/ML use by regulated financial institutions. The DFS guidance is supervisory in nature — not a binding regulation — but it sets the expectation for AI/ML governance programs for insurers and banks under DFS jurisdiction.

For mortgage lenders operating in New York, the DFS guidance effectively requires an AI/ML governance program consistent with the GSE frameworks. Examiners will look for documentation of model risk management, fair lending testing, and consumer protection controls.

New York City Local Law 144 (automated employment decision tools) affects mortgage lenders that use AI in hiring — for loan officer recruiting, underwriting staff screening, or any other employment decision. The law requires an annual bias audit and public posting of the audit results.

Texas: UDAP Authority

Texas has not passed a state AI statute, but the Texas Attorney General and state financial regulators have used existing Unfair, Deceptive, or Abusive Acts or Practices (UDAP) authority to bring AI/ML-related actions. The state has been particularly active on AI-driven decisions that result in disparate impact on protected classes — using UDAP rather than a separate AI statute.

For Texas-licensed mortgage lenders, the practical implication is that AI/ML use is regulated — even without a specific AI statute. The compliance program that satisfies the Texas SML for the SSSF, the GSE AI/ML frameworks, and the federal fair lending rules is the foundation for UDAP defensibility.

Other State Activity

State AI/ML activity is moving fast. The states that have either passed AI rules or have active rulemaking in 2026 include Illinois, New Jersey, Virginia, Washington, and Oregon. The rules vary in scope and approach, but the direction is consistent: more state regulation, with mortgage lending in scope.

A practical approach for mortgage lenders operating nationally: design the AI/ML governance program to the strictest applicable state requirement, and apply it uniformly. The marginal cost of running a single, conservative program is much lower than the cost of running multiple state-specific programs.

How State AI Rules Interact with Federal and GSE Frameworks

A consolidated view of the AI/ML compliance landscape for mortgage lenders in 2026:

  • CFPB: interpretive guidance, focus on adverse action notices, fair lending, and accuracy of AI-driven decisions. Exam focus in 2026.
  • Fannie Mae LL-2026-04: AI/ML governance framework, effective August 6, 2026. Six governance obligations, annual attestation.
  • Freddie Mac Section 1302.8: companion AI/ML governance framework, effective March 3, 2026. Substantively similar to LL-2026-04.
  • Colorado AI Act: high-risk AI system requirements, impact assessments, consumer notice, right to human review. Effective February 1, 2026.
  • California DFPI: AI/ML supervisory guidance, focused on documentation, fair lending testing, and consumer protection.
  • New York DFS: supervisory guidance, treated as effective standard for New York-licensed institutions.
  • State AGs: UDAP authority, used to bring AI/ML-related actions in states without specific AI statutes.

These frameworks are additive. A lender that satisfies Fannie Mae LL-2026-04 still has separate Colorado, California, and New York obligations. The Colorado impact assessment is not a substitute for the LL-2026-04 attestation.

Building a Multi-State AI/ML Compliance Program

A defensible program has five components.

1. Unified AI/ML Use Case Inventory

Maintain a single inventory that flags which systems are in scope under which state rules. The inventory is the foundation — without it, you cannot determine your compliance obligations.

2. State-Overlay Documentation

For each state with AI/ML rules, maintain an overlay document that maps the state requirements to your existing governance program. The overlay identifies the gaps and the remediation work.

3. Consumer Notice and Human Review Workflows

Colorado and other state rules require consumer notice of AI use and a right to human review. The workflows should be designed to comply with the strictest applicable state requirement.

4. Impact Assessment Library

Maintain an impact assessment for each high-risk AI system, updated annually or after material model changes. The assessment is a state regulatory document, not a federal one — different states may require different formats.

5. Multi-State Vendor Oversight

Your vendor oversight program must cover state-specific requirements. A vendor providing AI/ML services in Colorado has different disclosure obligations than a vendor providing the same services in Texas.

Frequently Asked Questions

Does the Colorado AI Act Apply If We Don’t Have a Physical Office in Colorado?

Yes. The Act applies to any deployer that uses a high-risk AI system to make decisions affecting Colorado residents. If you originate or service a mortgage for a Colorado resident and use an AI/ML system in connection with that loan, the Act applies.

How Do State AI Rules Interact with Fair Lending Law?

State AI rules typically add anti-discrimination requirements that overlap with federal fair lending law but are not identical. A fair lending test that satisfies the CFPB may not satisfy the Colorado AI Act. The conservative approach is to test to the strictest applicable standard.

What If a Vendor Provides Our AI/ML System? Are We Still Liable?

Yes. Under the Colorado AI Act, the GSE frameworks, and most state-level approaches, the lender is the deployer and remains accountable for the system’s compliance. Vendor contracts can shift some financial risk, but not regulatory risk.

What Records Must We Retain?

Three years for most state requirements, but some state rules require longer retention for impact assessments. Document the retention requirement for each state in scope and apply the longest applicable period uniformly.

Need help designing or auditing your multi-state AI/ML compliance program? Synergy supports mortgage lenders with state overlay documentation, impact assessment design, and multi-state governance program reviews. Book a 30-minute program review.

Q2 2026 MCR Filing Cycle: What Went Right, What Went Wrong

The Q2 2026 NMLS Mortgage Call Report cycle closed on August 14, 2026. It was the second cycle under MCR Form Version 7 and the first full quarter where the Texas SML applied normal — not transitional — enforcement to the new State-Specific Supplemental Form. With the cycle now in the books, the data is clear about what worked, what didn’t, and where the gaps are heading into Q3.

This is a practitioner’s post-mortem. It walks through the most common filing issues observed in the Q2 cycle, the structural improvements that worked, and the priorities for the Q3 2026 filing window (deadline November 14).

What Went Right

The headline: most filers made the August 14 deadline with accurate data. The Q2 2026 cycle did not produce the wave of placeholder filings some state regulators had feared. Three factors drove the improvement.

FV7 Field Mappings Stabilized

The Q1 2026 cycle was the debut of FV7. Lenders that built their filing templates from FV6 documentation — or that did not have time to fully reconcile the new field structure before the May 15 deadline — produced filings with systematic field-mapping errors. The Q2 cycle showed a measurable improvement: most lenders had updated their internal mappings, retrained their teams, and validated against the current NMLS field definitions before the August 14 window opened.

Texas SSSF Transition Period Closed Cleanly

The Texas SML signaled in March 2026 that it would not actively pursue enforcement for Q1 2026 SSSF late filings absent other compliance concerns. The SML’s calibrated posture gave Texas-licensed lenders room to bring their SF600/SF610 data quality up to standard without the immediate risk of a violation.

By Q2 2026, normal enforcement was in effect. Filers had a clear deadline, a clear signal that the transition was over, and a quarter of operational experience. The result: clean SSSF submissions for most filers, with the SML reporting no widespread data quality issues at the cycle close.

Reconciliation Discipline Took Hold

Lenders that built HMDA-MCR reconciliation into their monthly close process — rather than scrambling at filing time — produced filings with materially fewer reconciliation gaps. The structural investment paid off.

What Went Wrong

Three categories of issues showed up repeatedly in the Q2 cycle.

1. Ginnie Mae Issuer Field Gaps

FV7 introduced new conditional fields for Ginnie Mae Issuers that did not exist in FV6. In Q1, the issue was that lenders were unaware of the fields. In Q2, the issue is that lenders are aware but have not fully populated them — particularly the fields that depend on data from upstream systems (e.g., pool composition, issuer monthly volume).

The fix is data lineage: trace each Ginnie Mae field back to its source system, validate the data, and document the lineage for examiner review.

2. Servicing Portfolio Segment Misclassification

FV7 restructured how servicing activity is reported across investors. The misclassification pattern in Q2 is the same as Q1: companies using FV6 mappings for FV7 data.

If your Q1 MCR was filed under FV6 mappings, the Q2 filing should have been the cycle to correct the issue. If it was not, the misclassification will be flagged in your next examination — and the longer it persists, the more filing periods you have to amend.

3. Origination Count Drift vs. HMDA LAR

Q2 origination counts in the MCR are being compared by examiners to Q2 origination counts in HMDA LAR. The most common drift comes from brokered-out loans (MCR typically excludes, HMDA may include) and from loans in process at quarter-end (MCR uses settlement date, HMDA uses application date).

The fix is documented scope rules plus a quarterly reconciliation. If the delta persists, the answer is not “we’re right” — it is “here is the documented scope difference and here is the supporting reconciliation.”

The Texas SSSF Normal-Enforcement Reality

Q2 2026 was the first SSSF cycle under normal enforcement. Three observations from the cycle.

SF600 and SF610 accuracy was the focus. The SML reviewed SSSF submissions for consistency with the NMLS MCR and with internal origination data. Filers with material variance received follow-up requests from the SML within a week of submission. Most variance was attributable to either scope-rule ambiguity (own-account vs. third-party processing) or timing (settled-file vs. application-based volume).

SF630 and SF660 stayed empty. The reserved fields remained reserved. Filers that entered data in SF630 or SF660 (a few did, by mistake) received validation errors. No enforcement action was taken in Q2 for SF630/SF660 errors, but the SML is treating these as validations to flag, not as substantive violations — yet.

Amended filings are working as designed. Several filers filed amended SSSFs after discovering post-filing errors. The SML accepted the amendments without enforcement action. The amendment process is functioning as a self-correction mechanism, which is the right outcome — but it requires filers to actually run post-filing QC, which not all do.

Three Things to Fix Before Q3 2026

The Q3 2026 MCR cycle closes on November 14. The window between mid-August and mid-November is the right time to address the most common Q2 issues.

1. Build or Refresh the FV7 Field Map

Pull the current NMLS MCR field definitions and instructions. Compare them against your internal mapping. Document the differences. Update your filing template.

The current field definitions are the only authoritative source. Documentation from FV6, third-party vendor field lists, and templates from prior cycles are not sufficient — they will replicate errors rather than fix them.

2. Run HMDA-MCR Reconciliation Monthly

Quarterly reconciliation is not enough. Monthly reconciliation catches drift early, when it is easy to remediate, rather than at filing time, when the remediation is an amendment.

Set a reconciliation tolerance (0.5% at the aggregate level is a reasonable starting point) and document any exceptions. The documentation is what examiners will ask for.

3. Tie MLO Headcount to NMLS Records

MLO headcount in the MCR should reconcile to NMLS licensing records for the reporting period. The Q2 cycle saw headcount drift in institutions that have had MLO turnover — particularly layoffs, acquisitions, or MLO migration to a different sponsor.

A monthly tie between HR data and NMLS licensing records catches the drift before it shows up in the MCR. The fix is process, not a one-time clean-up.

The Q3 Calendar

For the Q3 2026 MCR cycle, the key dates are:

  • October 1, 2026 — Q3 reporting period begins (the September 30 cutoff is the data boundary)
  • October 31, 2026 — internal books should be closed (recommended 14 days before the deadline)
  • November 7, 2026 — internal QC and pre-submission reconciliation (recommended hard stop)
  • November 14, 2026 — NMLS filing deadline

A common Q3 challenge: the November 14 deadline is three weeks after the federal election. Election years tend to compress close calendars at the back end of Q3 and Q4 — the Q3 close gets squeezed by election prep, holiday coverage planning, and year-end activity stacking up. Build the Q3 close calendar now to avoid the squeeze.

Frequently Asked Questions

Will the SML Provide Q2 2026 SSSF Feedback to All Filers?

The SML has signaled that it will provide substantive feedback on the first full normal-enforcement cycle. Filers should expect to receive follow-up requests if there are scope-rule ambiguities, data quality issues, or reconciliation gaps with the NMLS MCR. The window for resolving the feedback is typically 30 days.

What Happens If We Discover an MCR Error After the August 14 Filing?

File an amended MCR. The NMLS amendment process is the same as the original filing process. Self-discovered and promptly amended errors are treated more favorably by examiners than errors discovered during an examination. Maintain an internal amendment log so you can answer examiner questions about specific filings quickly.

How Should We Handle the FV6 Mappings in the Q3 Cycle?

If you are still using any FV6 mappings for FV7 data, the Q3 cycle is the right time to fix them. The longer the legacy mappings persist, the more filing periods you have to amend retrospectively. Build the corrected mapping now, validate it against the current NMLS field definitions, and document the change.

What Is the Examiner Focus for Q3 2026?

Based on Q1 and Q2 examination findings, the focus areas are FV7 field mapping (Ginnie Mae Issuer fields, servicing portfolio segments), HMDA-MCR reconciliation gaps, MLO headcount reconciliation, and Texas SSSF data quality. Q3 will likely see a continuation of these focus areas with a particular emphasis on the Q1-to-Q2-to-Q3 trend — examiners will be looking for whether issues are being remediated or persisting across cycles.

Need help hardening your Q3 2026 MCR process? Synergy supports mortgage lenders with FV7 field mapping reviews, monthly reconciliation design, and exam-readiness assessments. Book a 30-minute Q3 review.

Fannie Mae AI/ML Governance: What Lenders Must Do by August 6

Fannie Mae’s AI/ML governance framework — Lender Letter LL-2026-04 — took effect on August 6, 2026. For any single-family seller or servicer using artificial intelligence or machine learning in connection with mortgages sold to Fannie Mae, the framework is now in force. The compliance bar is no longer aspirational; it is operational.

LL-2026-04 is the companion to Freddie Mac’s Seller/Servicer Guide Section 1302.8, which took effect March 3, 2026. Together, the two frameworks establish the GSE position on AI/ML governance: lenders are accountable for the design, performance, and outcomes of any AI/ML system used in the mortgage lifecycle, regardless of whether the system is built in-house, provided by a third-party vendor, or accessed through a marketplace platform.

This guide walks through what LL-2026-04 requires, how it interacts with Freddie Mac Section 1302.8 and state-level AI rules, and what a defensible AI/ML governance program looks like for a mortgage lender as of August 2026.

What LL-2026-04 Actually Requires

LL-2026-04 is structured around six governance obligations. Each is a stand-alone compliance topic and each requires documentary evidence.

1. AI/ML Use Case Inventory

Lenders must maintain a complete inventory of every AI/ML system used in the mortgage lifecycle. The inventory should identify the system, the business function it supports, the data inputs, the model owner, the deployment date, and the underlying vendor (if third-party).

In scope: automated underwriting, appraisal valuation models, fraud detection, lead scoring, marketing optimization, customer service chatbots, document classification, income and asset verification, and any pricing or margin optimization tool that uses statistical learning.

Out of scope: rule-based decision engines that do not learn from data, simple statistical scoring (e.g., credit score lookups without model adjustment), and standard business intelligence dashboards.

2. Model Risk Management Framework

Each inventoried AI/ML system must be classified by risk tier based on its impact on loan decisions, borrower outcomes, and regulatory exposure. High-impact systems (underwriting, pricing, fraud, valuations) require the most rigorous controls.

The framework should document validation activities (pre-deployment testing, ongoing monitoring, periodic revalidation), performance thresholds, change management procedures, and override mechanisms for human review.

3. Fair Lending Testing

Each AI/ML system that affects loan decisions, pricing, or adverse action notices must be tested for fair lending impact. Testing should include disparate impact analysis across prohibited basis categories (race, national origin, sex, religion, familial status, age, disability), proxy variable analysis (identifying features that correlate with protected classes even when the protected class is not a direct input), and segment-level performance review.

The testing should occur before deployment, after material model changes, and at a defined cadence (typically annually for high-impact systems).

4. Governance Documentation

LL-2026-04 requires a written AI/ML governance policy that is approved at the board or senior committee level. The policy should cover roles and responsibilities, model lifecycle controls, escalation paths, exception handling, and incident response.

Documentation must be maintained for the life of each model plus a defined retention period. The retention floor is generally three years post-decommissioning, consistent with other mortgage compliance records.

5. Third-Party Vendor Oversight

Lenders remain accountable for AI/ML systems provided by third parties. The oversight program should include vendor due diligence (model documentation review, validation access, audit rights), ongoing monitoring (performance reports, incident notification, regulatory change tracking), and contractual protections (indemnification, data security, model decommissioning rights).

A common gap: lenders that treat vendor systems as “off the shelf” and skip validation. LL-2026-04 treats this as a compliance failure. The lender is responsible for validating the model in the context of its own use, even if the vendor provides the validation methodology.

6. Annual Attestation

Lenders must attest annually to Fannie Mae that they have an AI/ML governance program in place that meets LL-2026-04 requirements. The attestation is a senior officer certification, not a procedural check-the-box. Officers signing the attestation should expect to defend the substance of the program if challenged.

How LL-2026-04 Interacts with Freddie Mac Section 1302.8

If your institution sells to both GSEs, you do not need to maintain two separate AI/ML governance programs. A unified program that satisfies both frameworks is acceptable, and Fannie Mae and Freddie Mac have signaled that they will accept each other’s attestations in most cases.

The two frameworks differ in three operational details:

  • Effective dates: Freddie Mac Section 1302.8 took effect March 3, 2026. Fannie Mae LL-2026-04 took effect August 6, 2026. If you implemented a Section 1302.8 program in the spring, you should be in good shape on the substance of LL-2026-04. The remaining work is typically attestation timing and documentation reconciliation.
  • Attestation cadence: Freddie Mac requires annual attestation. Fannie Mae requires annual attestation. The two attestations can be filed separately even if the underlying program is the same.
  • High-impact system definition: The two frameworks use slightly different definitions of “high-impact.” Where they differ, the more conservative definition should govern.

If your institution sells to only one of the two GSEs, you only need to meet that GSE’s framework. But state-level AI rules may still apply regardless of GSE relationship — see the August 2026 article on state AI/ML enforcement.

What “In Connection With Mortgages Sold to Fannie Mae” Means

LL-2026-04 applies to AI/ML systems used in connection with mortgages sold to Fannie Mae. The phrase is interpreted broadly. If a system touches a loan that may eventually be sold to Fannie Mae, the governance obligations apply.

In practice, this covers:

  • Systems used at the point of application (lead scoring, prequalification)
  • Systems used during origination (automated underwriting, fraud detection, document processing)
  • Systems used post-closing (servicing decisioning, loss mitigation, default management)
  • Marketing and customer service systems if they influence the loan pipeline that includes Fannie Mae-sold loans

A practical approach: inventory every AI/ML system in your mortgage technology stack. If any of them touch a loan that may be sold to Fannie Mae, the system is in scope.

The Fair Lending Layer

The fair lending testing requirement under LL-2026-04 is the area where most lenders are least prepared. Standard model risk management covers performance, drift, and stability. Fair lending testing is a separate discipline with its own methodology, its own tooling, and its own documentation requirements.

If your institution has not yet built a fair lending testing program for AI/ML, the August 6 effective date is the trigger to either build it or engage external support. The testing cadence is at least annual for high-impact systems, and the documentation must be available for Fannie Mae review on request.

Two common testing approaches:

  • Outcomes-based testing: Compare actual loan decisions, pricing, or other outcomes across demographic segments. Identifies disparate impact at the output level.
  • Input-based testing: Audit model features for proxies that correlate with protected classes. Identifies structural risk before the model produces an outcome.

The most defensible approach is both. Outcomes-based testing identifies what the model is doing. Input-based testing identifies how the model could produce a problematic outcome before it happens.

Action Steps for August 2026

If your institution has not yet built a LL-2026-04 program, the immediate priorities are:

This month: Inventory every AI/ML system in the mortgage technology stack. Identify model owners, deployment dates, and vendors. This is the foundation for everything else.

This quarter: Classify each system by risk tier. Document the validation activities already performed. Identify gaps relative to LL-2026-04 requirements.

By year-end: Complete the governance policy. Establish fair lending testing for high-impact systems. Build the vendor oversight program. Stand up the annual attestation process.

By Q1 2027: Complete the first attestation cycle. Document the validation work performed. Build the exam-ready binder.

Frequently Asked Questions

We Don’t Use AI/ML Anywhere. Does LL-2026-04 Still Apply?

If you genuinely use no AI/ML systems in connection with mortgages sold to Fannie Mae, the framework does not impose substantive obligations. The annual attestation, however, is still required — you attest that you have no in-scope systems. Document the basis for that conclusion (the inventory and the analysis) so the attestation is defensible.

What About AI Tools Used by Individual Loan Officers?

If a loan officer uses a third-party AI tool (e.g., a ChatGPT-style assistant) in connection with a loan, the tool is in scope. The lender’s vendor oversight program must cover the tool, including the data security and confidentiality controls.

How Does LL-2026-04 Interact With State AI Laws?

LL-2026-04 is a GSE framework. State AI laws are separate obligations. In most cases, the state law is additive — you must satisfy both. See the August 2026 article on state AI/ML enforcement for the specific state rules that apply to mortgage lenders.

What Records Must We Retain?

Three years post-decommissioning for each model, consistent with other mortgage compliance records. The retention applies to model documentation, validation results, fair lending testing, governance decisions, vendor contracts, and attestation records.

Ready to build or audit your AI/ML governance program? Synergy supports mortgage lenders with model inventory design, governance policy drafting, fair lending testing frameworks, and AI/ML exam-readiness reviews. Book a 30-minute governance review.

HMDA and Mortgage Call Report Cross-Referencing

Examiners are no longer treating the HMDA LAR and the NMLS Mortgage Call Report as independent filings. State financial regulators, the CFPB, and the prudential regulators now run cross-regime reconciliation as a standard exam procedure — and the findings they generate are some of the most common compliance deficiencies in mortgage lending today.

When your HMDA data and your MCR data tell different stories about the same loan portfolio, examiners treat the discrepancy as a risk signal. The conversation becomes about why your data is inconsistent, not whether you have a process at all.

This guide walks through the seven most common HMDA–MCR mismatches we see in mortgage compliance examinations, why each one happens, and how to build a reconciliation process that catches the issue before the examiner does.

Why Cross-Referencing Has Become a Supervisory Priority

Three forces have converged to make HMDA–MCR reconciliation an exam focus.

First, the data quality of HMDA filings has improved substantially since 2018, when the Bureau clarified its position that HMDA data is used for enforcement purposes. Examiners now trust HMDA as a reliable baseline.

Second, the MCR Form Version 7 (FV7) transition effective Q1 2026 has changed how origination and servicing data is structured, which creates natural reconciliation friction with HMDA fields that have not changed.

Third, the CFPB’s 2025–2026 supervisory priorities explicitly call out cross-regime data consistency as a focus area. Examiners have been directed to test HMDA–MCR reconciliation as a matter of routine.

The Seven Most Common Mismatches

1. Origination Count Differences

The single most common mismatch. Your HMDA LAR reports X originations; your MCR reports Y. The delta can be small (a handful of loans) or large (hundreds).

The root causes are usually scope differences: which legal entity is reporting (HMDA is at the institutional level, MCR is at the licensed-entity level); whether purchased loans are included (HMDA includes purchased loans, MCR typically does not); whether brokered-out loans are included (HMDA may include, MCR typically excludes); and how prequalifications are handled.

How to fix it: Document the scope rules for each filing. Build a reconciliation that adjusts each total to a common basis before comparison. If the adjusted totals still don’t tie, the difference is a data integrity issue.

2. Dollar Volume Mismatches

Origination dollar volume differs between HMDA and the MCR — often by a percentage that doesn’t match the count difference. This is a red flag for examiners because it suggests inconsistent loan-level data across regimes.

Common causes include: rounding differences (HMDA reports in thousands, MCR reports in dollars); purchased loan amount handling (HMDA includes premium, MCR may not); and treatment of construction loans (HMDA reports the permanent financing amount, MCR may report a different basis).

How to fix it: Document the reporting basis for each regime. Convert both totals to the same unit (whole dollars) before comparison. Reconcile at the loan level, not the aggregate level.

3. Geographic Distribution Differences

The state-level distribution of originations differs between HMDA and the MCR. This is a higher-risk mismatch because it can imply different operational footprints or different definitions of where business is conducted.

Common causes include: property location vs. branch location reporting (HMDA uses property location, MCR uses branch location); treatment of loans originated through remote channels; and treatment of wholesale loans (whose branch is the loan attributed to).

How to fix it: Document the geographic attribution rule for each filing. Make sure your internal operating data uses a single attribution rule and that both filings are built from that single rule.

4. Loan Purpose Mismatches

The split between purchase, refinance, and home improvement differs between HMDA and the MCR. This is one of the more revealing mismatches because it can point to inconsistencies in how your team classifies loans.

Common causes include: cash-out refinance vs. rate-and-term refinance classification; home equity loans treated as home improvement in one regime but not the other; and construction-to-permanent loan staging.

How to fix it: Build a single loan-purpose classification matrix that maps to both HMDA and MCR definitions. Train your origination team on the matrix. QC a sample of loans against the matrix before each filing.

5. Servicing Portfolio Mismatches

The MCR Expanded filers report servicing portfolio volumes. HMDA does not, but examiners pull servicing data from other filings (servicing system reports, investor remittances, custodial accounts). When the MCR servicing figure doesn’t reconcile against these other sources, it generates findings.

Common causes include: portfolio transfer timing (loans sold during the reporting quarter); treatment of subserviced loans (the subservicer vs. the portfolio owner); and treatment of loans in forbearance.

How to fix it: Build a servicing data lineage that ties MCR reporting to your servicing system and your investor reporting. Reconcile monthly, not just at filing time.

6. Reporting Period Mismatches

HMDA is filed annually with a March 1 deadline covering the prior calendar year. The MCR is filed quarterly. When examiners compare a quarterly MCR to the corresponding quarter of the HMDA LAR, the numbers should match — but they often don’t.

Common causes include: cut-off date differences (HMDA uses application date, MCR uses settlement date); treatment of loans that crossed quarter-end; treatment of loans that were withdrawn after cut-off but before settlement; and amendment timing.

How to fix it: Document the cut-off convention for each filing. Make sure both filings use the same cut-off when reconciliation is the goal, or document the adjustment needed to reconcile.

7. Reporting Entity Mismatches

The legal entity reporting differs between HMDA and the MCR. HMDA is filed by the institution as defined in Regulation C. The MCR is filed by each licensed entity on NMLS. When a single holding company has multiple licensed entities, the aggregation can produce different totals.

This is one of the most common sources of mismatch and one of the most difficult to remediate, because the regulatory definitions don’t fully align.

How to fix it: Maintain a legal entity mapping that ties each HMDA reporting unit to the corresponding MCR filing entities. Adjust each total to a common scope before comparison. Document the adjustment methodology.

Building a Reconciliation Process That Works

A defensible HMDA–MCR reconciliation process has five elements.

1. Common Source of Truth

Both HMDA and MCR should be built from a single loan-level data store. This is the architectural foundation. If your HMDA pipeline and MCR pipeline are built separately from the operating system, you will always have reconciliation friction.

2. Documented Scope Rules

Write down the scope rules for each filing: who is in, who is out, what is included, what is excluded. The rules should be detailed enough that an examiner could replicate your filing from your operating data.

3. Pre-Filing Reconciliation Step

Build a pre-filing reconciliation step into both pipelines. For HMDA, this means reconciling your draft LAR against the MCR for the corresponding quarters (if available) and against your operating system totals. For the MCR, this means reconciling your draft MCR against the prior HMDA LAR (if available) and against your operating system totals.

4. Reconciliation Tolerance and Exception Documentation

Set a reconciliation tolerance (we recommend 0.5% or tighter at the aggregate level) and document any exceptions. Exceptions should be tied to specific loans or categories, with a written explanation of why the difference exists.

5. Continuous Reconciliation, Not Filing-Window Reconciliation

The worst time to discover a reconciliation issue is during the filing window. Run reconciliation monthly (or more frequently for high-volume originators). The reconciliation should be a standing report, not a filing-day activity.

What Examiners Actually Look At

In a typical MCR examination, examiners will:

  1. Pull your MCR for the period under exam
  2. Pull the corresponding HMDA LAR
  3. Compare aggregate origination count and dollar volume at the legal entity level
  4. Compare state-level geographic distribution
  5. Compare loan purpose distribution
  6. Compare servicing portfolio volume (for Expanded MCR filers) against your servicing system
  7. Sample loan-level records and compare the HMDA record, the MCR record, and the loan file
  8. Ask you to explain any mismatch with supporting documentation

The conversation escalates from a procedural question to a substantive finding when the explanation is unsatisfactory. “We didn’t reconcile” is a process finding. “We reconciled but the difference is real and we don’t know why” is a substantive finding. “We reconciled, here’s the documented reason, and here’s how we’re fixing it” is a defensible answer.

What an Examiner-Ready Reconciliation Binder Looks Like

When the examiner asks for your reconciliation documentation, you should be able to produce:

  1. The current period MCR and the current period HMDA LAR (or the most recent filed LAR)
  2. Reconciliation worksheets showing aggregate count, volume, geographic distribution, and loan purpose at the legal entity level
  3. Identified variances with root cause and remediation status
  4. Documented scope rules for each filing
  5. Loan-level reconciliation samples for high-risk categories (large loans, geographic outliers, loan purpose transitions)
  6. Evidence that reconciliation runs on a continuous basis, not just at filing

A binder that can be produced within an hour of an examiner request is a defensible binder. A binder that takes a week to assemble is a process finding waiting to happen.

The Role of the MCR Form Version 7 Transition

FV7 introduced structural changes to the MCR that materially affect reconciliation. Three changes in particular require attention.

Consolidated filing structure: FV6’s separate Standard and Expanded MCR forms were replaced with a single filing with conditionally required fields. Companies that haven’t updated their internal mappings are reporting data under old category assumptions.

New Ginnie Mae Issuer fields: FV7 introduced new conditional fields for Ginnie Mae Issuers that did not exist in FV6. If your compliance team built your FV7 template from FV6 documentation, these fields may be missing.

Texas supplemental filings: The Texas SSSF is a separate filing from the NMLS MCR but captures related data. Texas-licensed companies need to reconcile SF600 and SF610 against their MCR origination volume to avoid a different set of mismatches.

Frequently Asked Questions

How Often Should We Run Reconciliation?

Monthly at minimum. Quarterly is acceptable for low-volume originators, but monthly is better. Continuous reconciliation is the gold standard.

What Tolerance Should We Set?

Tighter is better. We recommend 0.5% at the aggregate level. Any variance above that should be documented with a root cause and a remediation plan.

What If Our Operating System Doesn’t Have a Single Source of Truth?

This is a common problem, especially for lenders that have grown through acquisition or operate multiple legacy systems. The first step is to map each filing pipeline back to its underlying data source and identify where the divergence occurs. Then prioritize a single source of truth for the highest-risk data elements first.

What If We Discover a Mismatch After Filing?

File an amendment. For HMDA, submit a revised LAR. For the MCR, file an amended MCR through NMLS. Document the amendment internally. Self-discovered and promptly amended errors are treated more favorably by examiners than errors discovered during an examination.

Need help building a reconciliation process or preparing for an upcoming exam? Synergy supports mortgage lenders with reconciliation design, pre-filing QC, and exam-readiness reviews for HMDA, MCR, and the Texas SSSF. Book a 30-minute reconciliation review.

Texas Mortgage Call Report Supplemental Filing

Texas mortgage companies engaged in third-party loan processing or underwriting have a new quarterly filing requirement on top of the NMLS Mortgage Call Report. The Supplemental Submission for SML Independent Loan Processors — SSSF — took effect with the Q1 2026 filing window, due May 15, 2026, and it introduced four new data fields that require careful reconciliation against your existing origination data.

This article explains what the SSSF requires, who must file, what each of the four fields captures, how to avoid the most common filing errors, and how the Texas SML has signaled it will approach enforcement of the new requirement.

What Is the SSSF and Why Was It Created

The SSSF is a quarterly supplemental filing required by the Texas Department of Savings and Mortgage Lending (SML) for state-licensed mortgage companies operating in Texas. It was developed under the authority of 7 TAC § 56.205 (for residential mortgage lenders) and 7 TAC § 57.205 (for mortgage bankers), with input from industry trade associations and a public comment period that closed in late 2025.

The SSSF responds to a long-standing supervisory gap. Texas is the second-largest mortgage market in the United States by origination volume, and the state has historically had a higher-than-average concentration of independent third-party processors and underwriters serving non-bank lenders and credit unions. The NMLS Mortgage Call Report captures loan-level origination and servicing activity at the company level, but it does not separately identify the activity performed by third-party service providers. The SSSF closes that gap.

For examiners, the SSSF creates visibility into which entities are doing the actual processing and underwriting work, how much of it, and on behalf of which investors or counterparties. For lenders, it adds a quarterly reporting burden — and a new exam risk if the data is not reconciled against other regulatory outputs.

Who Must File the SSSF

The SSSF filing requirement applies to Texas-licensed mortgage companies that, during the reporting quarter, either:

  1. Performed third-party loan processing services for another mortgage company, OR
  2. Performed third-party loan underwriting services for another mortgage company, OR
  3. Contracted with a third party to provide loan processing or underwriting services on the filer’s behalf.

The test is functional, not structural. A company that performs no processing or underwriting for any other party and does not contract with any third-party processor or underwriter is not required to file the SSSF.

For most licensed mortgage companies in Texas, this means the SSSF is mandatory — even if your third-party processing activity is modest. The SSSF threshold is qualitative (any third-party activity at all during the quarter), not quantitative.

The Four SSSF Fields

The SSSF adds four new fields to the existing SML quarterly reporting framework. Two of the fields are mandatory; two are reserved for future use.

SF600 — Third-Party Loan Processing Volume

SF600 reports the dollar volume of loans processed on behalf of third parties during the reporting quarter. The reporting basis is settled loan file volume — loans that reached clear-to-close during the quarter — not application volume. The field is reported in whole dollars.

What counts: Loans where your company performed processing functions on behalf of another licensed mortgage entity. Loans where your company is both the lender and the processor (i.e., you processed your own loan) are excluded — those are reported on the standard MCR.

Common error: Reporting gross origination volume instead of processing volume. SF600 is processing-specific.

SF610 — Third-Party Loan Underwriting Volume

SF610 reports the dollar volume of loans underwritten on behalf of third parties during the reporting quarter. Same settled-file reporting basis as SF600. Loans underwritten for your own portfolio are excluded.

Common error: Counting loans where your underwriting decision was overridden by the investor. The field captures loans for which your company issued the underwriting decision, regardless of whether the loan was ultimately purchased by the investor.

SF630 — Reserved

SF630 is reserved for future use. The SML has indicated this field will capture third-party servicing activity in a future filing cycle. Do not report data in SF630 until the SML publishes the field instructions.

SF660 — Reserved

SF660 is also reserved. The SML has indicated this field will capture investor concentration metrics for third-party-processed or -underwritten loans in a future filing cycle. Do not report data in SF660 until the SML publishes the field instructions.

Filing Mechanics

The SSSF is filed through the existing SML portal — not through NMLS. The filing window is the same as the NMLS Mortgage Call Report, with a due date of May 15 for Q1, August 14 for Q2, November 14 for Q3, and February 14 for Q4 (subject to calendar adjustments for weekends and holidays).

For each quarter:

  1. Q1 (Jan–Mar) — due May 15
  2. Q2 (Apr–Jun) — due August 14
  3. Q3 (Jul–Sep) — due November 14
  4. Q4 (Oct–Dec) — due February 14

The SSSF is a separate filing from the NMLS Mortgage Call Report, even though the data sources may overlap. Submit the NMLS MCR through the NMLS portal as usual, and submit the SSSF through the SML portal.

There is no grace period. A late filing is a violation. There is no extension request mechanism for routine quarterly filings.

How the SML Has Signaled It Will Approach Enforcement

The SML has been clear that it understands the Q1 2026 SSSF will be a transition cycle, but it has not offered a blanket grace period for the first filing.

In its March 2026 industry advisory, the SML stated that it will not actively pursue enforcement action against lenders who file late Q1 2026 SSSFs unless the late filing is paired with other compliance concerns or an examiner identifies risk factors that warrant accelerated attention. That is a calibrated posture, not a free pass.

The SML also stated explicitly that placeholder filings — submissions containing inaccurate, estimated, or placeholder data intended to meet the deadline — are not acceptable. If you cannot finalize your SSSF data by the deadline, the right move is to file late with a written explanation, not to file on time with bad data.

For Q2 2026 onward, expect normal enforcement. Late filings will be treated as violations, and inaccurate filings are themselves a violation regardless of when they are submitted.

If You Discover an Error After Filing

The SML has indicated that it expects lenders to file amended SSSFs when errors are discovered post-filing, and that self-discovered and promptly amended errors will generally not be the basis for enforcement action. The amendment process is the same as the original filing process — submit a corrected SSSF through the SML portal with a brief written explanation of the change.

What examiners will look at is whether you have a process for identifying and amending errors, not whether your first filing is perfect. Document your amendment process internally so the file is ready when an examiner asks.

Reconciling the SSSF Against Other Regulatory Outputs

The SSSF should reconcile against the NMLS Mortgage Call Report. Specifically:

  1. SF600 + own-account processing volume should equal total processing activity reflected in your internal operating data.
  2. SF610 + own-account underwriting volume should equal total underwriting activity reflected in your internal operating data.
  3. SF600 + SF610 should not exceed the dollar volume of loans reflected in your company’s origination system for the same period.
  4. The SSSF should reconcile against your internal list of third-party processor/underwriter relationships for the quarter.

If these reconciliations don’t tie, examiners will ask why. Build the reconciliation into your pre-submission QC.

The Most Common SSSF Filing Errors

In our work with Texas-licensed lenders preparing for the Q1 2026 SSSF, the recurring errors are:

1. Filing With Placeholder or Estimated Data

The single biggest risk. The SML has said this is not acceptable. If your books aren’t closed by the deadline, file late with a written explanation rather than file on time with bad numbers.

2. Including Own-Account Processing in SF600

SF600 captures only third-party processing volume. Loans you process for your own portfolio or on your own behalf are not in SF600.

3. Reporting Application Volume Instead of Settled File Volume

SF600 and SF610 are settled-file metrics — loans that reached clear-to-close during the quarter. Application volume is a different number.

4. Treating the SSSF as Part of the NMLS MCR

The SSSF is a separate filing through the SML portal. Submitting SSSF data through the NMLS MCR portal is not a valid filing.

5. Missing the SF630 and SF660 Reserved Fields

Do not enter data in SF630 or SF660. They are reserved for future use. Entering data there will trigger a validation error and may be flagged as an attempted misrepresentation.

Building a Sustainable SSSF Process

A defensible SSSF process has three core elements.

Quarter-End Data Snapshot

Take a clean snapshot of third-party processing and underwriting activity at the end of the reporting quarter. The snapshot should include loan-level data: counterparty, dollar volume, settled file vs. application status.

Pre-Filing Reconciliation

Before submission, reconcile SF600 and SF610 against your internal operating data and against the NMLS MCR for the same period. Any unresolved difference needs an explanation and a documented path to resolution.

Documented Amendment Procedure

Write down how you will identify, document, and file amendments when errors are discovered post-filing. This is the process examiners will ask about, and it is the process that turns a one-off error into a tolerable compliance event rather than an enforcement trigger.

Frequently Asked Questions

I Had No Third-Party Processing Activity in the Quarter. Do I Still File the SSSF?

Yes — but with zeros in SF600 and SF610. The SSSF is a quarterly filing requirement that applies to all Texas-licensed mortgage companies that had any third-party activity in the most recent four quarters, regardless of whether the current quarter had activity.

I Contract With a Third-Party Processor but Perform No Processing for Third Parties. Am I in Scope?

Yes. The SSSF captures both inbound (you contract for third-party services) and outbound (you provide services to third parties) activity. If you contracted with a third party during the quarter, you file the SSSF.

How Does the SSSF Interact With the MCR Examination Process?

The SML has stated that SSSF data will be incorporated into the standard MCR examination work. Examiners will reconcile SSSF data against the NMLS MCR, your internal origination data, and your third-party counterparty records.

What If I File Late and Self-Report?

For Q1 2026 specifically, the SML has indicated it will not actively pursue enforcement for late filings absent other concerns. For Q2 2026 onward, late filings are violations regardless of whether they are self-reported. Self-reporting is still the right move, but expect standard enforcement treatment.

Need help preparing your first SSSF filing? Synergy supports Texas mortgage lenders with data mapping, reconciliation, and pre-filing QC for both the NMLS MCR and the SSSF. Book a 30-minute compliance call.

CFPB Section 1071 Small Business Lending Data Collection

The CFPB’s Section 1071 rule reshapes how mortgage lenders collect, store, and report data on credit applications from small businesses. For Tier 1 filers — the largest originators — the compliance date is July 1, 2026. For most mortgage lenders operating in the small business and commercial space, this is the most consequential data collection rule since HMDA.

On October 2, 2025, the CFPB finalized an interim final rule extending compliance dates for Section 1071 of the Dodd-Frank Act. Under the revised schedule, Tier 1 filers — those originating 2,500 or more covered small business credit transactions in each of 2024 and 2025 — must begin collecting and reporting data on or before July 1, 2026, with first filings due June 1, 2027.

For mortgage lenders, this is a meaningful expansion of the data collection perimeter. Until now, HMDA has been the dominant data regime. Section 1071 extends a parallel reporting requirement to small business lending, and the two regimes are designed to work together — examiners will increasingly look for consistency between them.

This guide walks through what Tier 1 status means for mortgage lenders, what counts as a covered application, the data points required, and how to build a Section 1071 program that holds up under CFPB examination.

Who Counts as a Tier 1 Filer

The CFPB’s tier structure is based on originator volume, not portfolio or servicing. Under the 2025 interim final rule, tiers are:

Tier 1: 2,500+ covered transactions in each of 2024 and 2025 — compliance date July 1, 2026 — first filing June 1, 2027.

Tier 2: 500–2,499 covered transactions in each of 2024 and 2025 — compliance date January 1, 2027 — first filing June 1, 2028.

Tier 3: 100–499 covered transactions in each of 2024 and 2025 — compliance date October 1, 2027 — first filing June 1, 2029.

Exempt: Fewer than 100 covered transactions in each year — not required to file.

Volume is measured at the legal entity level, not the holding-company level — though there are aggregation rules for commonly controlled entities. The CFPB has signaled that aggregation will follow Regulation B’s control-person framework, with limited exceptions for certain minority-owned institutions and CDFIs.

The threshold applies to covered credit transactions, not portfolio or servicing. If your institution has any commercial or small business lending activity and your overall originator volume puts you in any tier, you must include that activity in your Section 1071 count. The threshold is firm-wide, not line-of-business.

What Applications and Loans Are Covered

Section 1071 covers applications for credit from a small business. The CFPB’s definition of “small business” is the SBA’s size standard for the applicant’s industry — generally a business with $5 million or less in gross annual revenue (calculated across the applicant’s three most recent fiscal years) and 500 or fewer employees.

A “covered credit transaction” is a closed-end or open-end credit product originated for a small business, including:

  1. Commercial mortgages and refinances
  2. Commercial real estate loans
  3. Working capital lines of credit
  4. SBA-guaranteed loans
  5. Equipment financing
  6. Business credit cards (with limited exceptions for corporate cards)
  7. Merchant cash advances (treated as credit under the rule)

Key exclusions include trade credit (credit extended for the purchase of goods and services from the creditor itself), public utilities, securities transactions, credit to financial institutions, credit to governments, and credit extended to a business with gross revenue above the size standard.

The 19 Data Points You Must Collect

For every covered application, the rule requires collection of 19 data points organized into three categories.

Applicant-Identifying Data

1. Legal name

2. Trade name (if different)

3. Address (physical, not PO Box)

4. Taxpayer Identification Number (TIN / EIN)

5. Application date

6. Application method (in-person, phone, online, mail)

7. Application recipient (where the application was submitted)

Application Characteristics

1. Application type (covered application, prequalification, or incomplete)

2. Action taken (approved, denied, withdrawn, incomplete)

3. Action date

4. Denial reason(s) — enumerated list (main reason + up to four additional)

5. Credit type (closed-end vs. open-end)

6. Credit purpose (working capital, equipment, real estate, etc.)

7. Amount applied for

8. Amount approved or originated

9. Term

Pricing Data

1. Interest rate

2. Total origination charges

3. Broker fees and lender compensation

Demographic data on the applicant’s principal owners (race, ethnicity, sex) is collected on a voluntary basis, consistent with the rule’s fair-lending intent.

Pricing data sensitivity: The pricing fields (interest rate, origination charges, broker fees) are the most contested parts of the rule. For mortgage lenders, these overlap with HMDA rate spread reporting. Treat 1071 pricing data as separate and validate at the loan level — examiners will compare 1071 pricing against HMDA LAR, internal loan files, and the closing disclosure.

Where Section 1071 Meets Mortgage Lending

For most residential mortgage lenders, Section 1071 will be a peripheral obligation. But the rule applies where the lines blur — and for diversified lenders, the overlap is significant.

Residential Mortgages That Touch 1071

  1. Investment property mortgages held in the name of a small business entity (LLC, corporation, partnership) — not in the borrower’s personal name. These are commercial loans, even if secured by 1–4 family residential property.
  2. Mixed-use property loans where the borrower is a small business.
  3. Construction loans to small business developers, including single-purpose entity (SPE) borrowers.
  4. Diversified lenders with both consumer mortgage and commercial / small business lending arms, where total originator volume pushes the institution into a tier.

Residential Mortgages That Do NOT Touch 1071

  1. Personal mortgages on a borrower’s primary residence (HMDA-only)
  2. Personal second homes and vacation homes (HMDA-only)
  3. Refinances of personal mortgages (HMDA-only)
  4. Reverse mortgages for individuals (HMDA-only)

The test is who the applicant is, not what the property is. Loans to individuals — even on non-owner-occupied investment property — are generally HMDA territory. Loans to small business entities are 1071 territory.

HMDA and 1071: The Overlap You’ll Want to Plan For

This is the part of Section 1071 that gives mortgage compliance officers heartburn — and the part examiners will look at most closely.

HMDA and Section 1071 both collect credit-application data. For the small (but growing) population of loans that could plausibly be reported under either regime, you need a clear written policy on which regime applies and why. Examiners will compare:

  1. Total application counts under HMDA vs. 1071
  2. Volume consistency between HMDA LAR and 1071 data
  3. Denial reason patterns across both regimes
  4. Pricing data, where both regimes capture rate-related fields
  5. Demographic data handling (both are voluntary but collected separately)

The CFPB and prudential regulators have signaled that cross-regime consistency will be a supervisory priority beginning in 2027. Build the policy now, while you have time.

Building a Single Source of Truth

For institutions in scope for both HMDA and 1071, the right architecture is a single application-level data store that feeds both regimes — not two parallel pipelines. This reduces data integrity risk, simplifies examiner requests, and improves your ability to identify and remediate discrepancies.

Building a Defensible Compliance Program

A Section 1071 program that will survive CFPB examination has five moving parts.

1. Written Policies and Procedures

Your 1071 policy should document tier classification and how it was determined; scope (which products, which channels, which entities are included); application intake process; data storage and retention (3 years from application date); reporting process; quality control; exception handling; training requirements; and oversight and audit cadence.

2. Application Intake Controls

Capture the data points at the point of application, not after origination. The intake controls should include LOS / origination system integration that captures the data at submission, validation rules at the field level, required-field enforcement on the controlled fields, and a demographic data collection workflow.

3. Data Quality Controls

Pre-submission QC is the single biggest determinant of exam-readiness. At minimum: reconciliation against origination system totals, reconciliation against HMDA LAR (for any overlap), denial reason accuracy check on a sample basis, pricing data validation against closing disclosures, and edit checks before submission.

4. Filing Platform Readiness

The CFPB is building a dedicated filing platform for Section 1071 (parallel to the HMDA Platform). Confirm your institution’s readiness to integrate with the platform ahead of your first filing deadline.

5. Exam-Readiness Documentation

Maintain an exam binder that includes the Section 1071 written policy, tier classification analysis with supporting data, data lineage documentation (where each field comes from), QC results for the most recent filing, reconciliation against HMDA LAR for overlap period, and any voluntary demographic data collection materials.

Compliance Timeline and What to Do by July 1

If you’re a Tier 1 filer with a July 1, 2026 compliance date, the clock is short. Here’s the practical action sequence:

  1. Now: Confirm tier classification using 2024 and 2025 originator volume.
  2. Now – end of month: Stand up the written policy and get it approved by compliance committee.
  3. Next 60 days: Map current data capture against the 19 data points; identify gaps.
  4. Next 90 days: Update LOS / origination systems to capture missing fields.
  5. Next 120 days: Train intake and operations staff.
  6. By July 1, 2026: Begin collecting all 19 data points on every covered application.
  7. By Q4 2026: Run your first pre-submission QC cycle.
  8. By Q1 2027: Validate the full pipeline end-to-end with test data.
  9. June 1, 2027: First filing due.

Frequently Asked Questions

Do I Have to Collect Demographic Data on the Applicant’s Owners?

No — demographic data (race, ethnicity, sex) is collected on a voluntary basis. You must offer the applicant the opportunity to provide it, but you cannot require it, and you must clearly disclose that providing the information is voluntary.

What If My Institution’s Originator Volume Was Above the Tier 1 Threshold in 2024 but Below in 2025?

You must meet the threshold in both years to qualify for Tier 1. If you drop below in either year, you move down a tier (or become exempt).

How Does Section 1071 Interact With State-Level Small Business Reporting?

Several states have their own small business lending reporting requirements (notably California and New York). Section 1071 is federal and preempts conflicting state requirements. You still need to file state reports, but Section 1071 is the floor, not the ceiling.

Can I Use Third-Party Vendors to Handle Section 1071 Compliance?

Yes — most lenders will use LOS providers, compliance platforms, or specialized 1071 vendors to handle data capture, validation, and filing. Vendor selection and oversight is itself an exam topic, so document your due diligence and ongoing monitoring.

What Records Must I Retain?

Three years from the date of application. Records must be sufficient to reconstruct the application data as it was reported, including the response to any voluntary demographic question.

Ready to review your Section 1071 readiness before July 1? Synergy supports mortgage lenders with policy drafting, data-mapping, QC buildout, and pre-filing readiness reviews. Book a 30-minute readiness call.

FHA Appraisal Policy Changes 2025: What the Rollback of Bias Guidelines Means for Mortgage Lenders

What FHA Rolled Back — and Why It Matters Now

FHA appraisal policy changes in 2025 have fundamentally altered what lenders are required to do — and haven’t done — when it comes to monitoring for appraisal bias. For years, FHA-appraised properties carried explicit federal guidance requiring lenders to implement specific bias monitoring protocols. That framework is now gone. Here’s what the rollback means for your compliance posture.

In two separate moves during 2025, HUD revised its appraisal requirements in ways that significantly change the compliance landscape for FHA lenders.

On March 19, 2025, FHA issued Mortgagee Letter 2025-08, rescinding three policy documents:

  1. ML 2021-27 — the Appraisal Fair Housing Compliance letter, which had required lenders to implement protocols for identifying and addressing potential appraisal bias
  2. ML 2024-07 — the Reconsideration of Value (ROV) guidance, which established formal borrower-initiated ROV procedures
  3. ML 2024-16 — related appraisal review and reconsideration requirements

HUD’s stated reason: the policies were duplicative of existing professional standards (USPAP already addresses fair housing competency), and the rescissions were part of a broader regulatory reform effort under Executive Orders 14192 and 14219, aimed at reducing compliance burdens.

Then, on June 27, 2025, HUD issued Mortgagee Letter 2025-18 — “Rescission of Outdated and Costly FHA Appraisal Protocols” — eliminating additional appraisal requirements including the economic life estimate mandate for appraisers and additional appraisal requirements for Section 223(e) mortgages. The stated goal was cost reduction and streamlining.

The Compliance Gap This Creates

Here’s where the situation gets complicated for lenders.

When FHA rescinded the fair housing compliance letter (ML 2021-27), it removed the explicit federal guidance that told lenders specifically what their appraisal bias monitoring obligations were. HUD’s position: appraisers are already bound by USPAP and Fair Housing Act obligations, so the FHA-specific guidance was unnecessary.

That’s a reasonable argument at the individual appraiser level. But it doesn’t fully address what lenders need to do internally.

Consider the exposure:

The Fair Housing Act has not changed. Lenders still have obligations to ensure their appraisal processes don’t result in discriminatory outcomes — regardless of whether FHA publishes specific monitoring guidance.

Other regulators are still watching. State attorneys general, the CFPB, and HUD’s own FHEO office can still investigate appraisal bias claims against lenders. The rescission of FHA guidance doesn’t shield lenders from fair lending enforcement; it just removes the explicit floor FHA had previously established.

State regulators may fill the vacuum. Several states — including California and New York — have been actively expanding fair housing enforcement. Lenders operating in those markets may face stricter expectations than the rescinded FHA guidance ever imposed.

What Still Applies After the Rollback

Even with ML 2021-27 gone, several core obligations remain fully in effect for every FHA lender:

The Fair Housing Act. This is federal law — it doesn’t get rescinded by a mortgagee letter. Lenders must not discriminate on the basis of race, color, national origin, religion, sex, familial status, or disability in any aspect of a dwelling-related transaction, including appraisals.

Lender appraisal review obligations. FHA still requires mortgagees to review appraisals for completeness and quality. ML 2025-08 removed the specific ROV protocol guidance — but lenders still need review processes that can catch problematic valuations.

Equal Credit Opportunity Act (ECOA) / Regulation B. Appraisal-related discrimination claims can be brought under ECOA as well. The CFPB’s updated Regulation B, with its new intent-based fair lending framework taking effect July 21, 2026, makes this particularly relevant.

QM and ability-to-repay considerations. Appraised value still matters for loan-to-value calculations, loan eligibility, and investor delivery requirements.

Why Internal QC Matters More Than Ever

Here’s the practical implication that too many lenders are underestimating: the removal of FHA’s appraisal bias guidance doesn’t reduce your risk — it shifts the burden of managing that risk entirely onto your internal quality control program.

Previously, lenders could point to specific FHA guidance as evidence of their compliance program. Now, without that explicit framework, lenders need to demonstrate that they have their own robust appraisal review processes — processes that can identify when an appraisal may reflect bias, discriminatory patterns, or valuation errors before the loan closes.

This means your QC program needs to do more than check for form completion. It needs to:

  1. Monitor appraisal outcomes for patterns — particularly across demographic lines, even without a specific FHA mandate to do so
  2. Document your internal review process so you have a defensible record if a fair lending claim ever arises
  3. Ensure ROV procedures are still in place even without the specific FHA protocol — borrowers can still request reconsiderations, and you need a consistent, fair process to handle them
  4. Update your policies and procedures to reflect that appraisal bias monitoring is now entirely an internal obligation, not an FHA-prescribed one

The Bottom Line

FHA’s 2025 appraisal policy rollbacks reduce some administrative burden — but they create a compliance gap that lenders ignore at their peril. The explicit framework for appraisal bias monitoring is gone. What remains is the broader Fair Housing Act, state enforcement trends, and the lender’s own internal QC program.

If your appraisal quality control process hasn’t been updated to reflect these changes, now is the time to do it.

At Synergy, we help lenders build appraisal QC programs that go beyond form-checking — including fair lending risk monitoring and documentation practices that hold up under regulatory scrutiny.

Want to review your current appraisal QC framework? Contact Synergy for a compliance consultation, or book a demo at SimplifyQC.com.

Web Statistics