Vendor Assurance – NMP Skip to main content

Vendor Assurance

Apr 04, 2014

When a mortgage lender outsources services to a vendor, whether it is for account management, mortgage application processing, software development or system management, the lender expects and relies on the vendor to manage related risks. Those risks may center around privacy and the protection of sensitive customer data (i.e. Social Security Numbers), unauthorized employee access, outside intrusions or hacking, assurance of fully functioning systems (in the event of natural disaster or corruption to software during development), and finally, data backup and business continuity. Unfortunately, no single manual exists when it comes to ensuring vendors having all the right controls in place, or meeting regulators’ expectations. Though this brief column won’t be able to provide the full manual, we can certainly cover some essentials that lenders need to understand in regard to vendor assurance. Let us begin with how vendors can expose mortgage lenders to risks. Lenders are ultimately responsible for ensuring that the external services procured do not have an adverse impact on their operations. As such, any impact arising from unmanaged risks can have a variety of negative consequences, including lost revenues, lawsuits, negative publicity and penalties for non-compliance. How can lenders be assured that their vendors properly manage the risks associated with outsourced services? Lenders can request information regarding a vendor’s practices by asking vendors to complete and submit a Request for Information questionnaire (RFI), perform audits of their vendors themselves, and/or request independent audit reports such as the “SSAE 16” and “FISMA” compliance audits. RFIs are inherently less reliable, since the vendors attest to their own internal controls without the verification of an independent party. Audits conducted by the lender or an independent third-party are more reliable, but can be expensive. In order to be strategic in their vendor assurance efforts, lenders should assess the potential risks and identify vendors to be audited. Those insights should then be used to determine the type and frequency of the audits required. Some vendors may have previously participated in an independent audit and be able to furnish a recent audit report as an external source of validation. Lenders may be familiar with the term “SAS-70.” This term was replaced in 2011 with “Standards for Attestation Engagements No. 16,” or SSAE 16. SSAE 16 audits of service organizations exist in two forms: Type I provides limited assurance and is based on a single point in time, whereas Type II audits cover a range of time and provide the highest level of assurance that proper controls, procedures and process operating as management intends. Due to the increased regulatory oversight of the Sarbanes-Oxley Act, many lenders are taking the wise approach in requiring their vendors to demonstrate SSAE 16 compliance. With an understanding of the risks and vendor assurance practices, lenders can protect their business against lost revenue, system downtime, security threats and other issues resulting from non-compliance. As a final word of caution, lenders should be careful not to “set and forget.” It’s important to routinely evaluate compliance needs and ensure that vendors continue to live up to expectations over the life of the business relationship. Henry Bagdasarian is compliance and audit director at Veros Real Estate Solutions. For more information, call (714) 415-6300 or visit Veros.com.
About the author
Published
Apr 04, 2014
Jobs Report Comes In Weak After Mortgage Rates Surge

Employers added just 29,000 jobs in September, sending Treasury yields lower and offering a potential counterweight to the recent rise in mortgage rates

Oct 02, 2026
Price Cuts Hit Four-Year High As Mortgage Rates Top 7%

More than one in five listings took a price cut in September, but pending sales still posted their sharpest annual decline since March 2025

Oct 01, 2026
Serious Mortgage Delinquencies Rise 19% After Five Months Of Improvement

ICE data shows 574,000 mortgages were at least 90 days past due in August, while early-stage delinquencies remained below year-ago levels

Sep 29, 2026
Smaller Down Payments Give Buyers More Room, But Rates Limit The Savings

The typical down payment fell 9% from a year ago, while shifting market conditions are giving originators different affordability conversations across the country

Sep 25, 2026
Mortgage Rates Break 7% Just As Builders Find A Way To Move Buyers

New-home sales rose 6.4% in August as builders cut prices, offered incentives, and sold more lower-priced homes. Now mortgage rates are moving against buyers again

Sep 25, 2026
Borrowers Want Digital Closings, But Some Originators Remain Hesitant

ServiceLink finds 45% of surveyed LOs cite borrower reluctance as a barrier, even though most recent buyers say digital options would influence their choice of mortgage provider

Sep 23, 2026