What Mortgage Servicers Never Ask Their Outsourcing Vendor (Until the Examiner Does)

7 min read | Published by NTS Editorial Team | June 2026

In mortgage servicing, the regulatory exam doesn't ask which vendors you hired. It asks whether you can demonstrate that the work they do on your behalf meets your servicing standards. Those are different questions, and the gap between them is where most third-party findings live.

A vendor can have an excellent pitch deck, a strong implementation track record, and a team that responds promptly to your account manager's calls. None of that appears in your exam file. What appears in your exam file is evidence, or the absence of it, that the processes running on your behalf are controlled, documented, and consistent with your obligations to borrowers and investors.

The questions that uncover whether that's actually true are not the ones most mortgage servicers think to ask. And most of the time, they don't find out they missed them until someone else asks first.

The Third-Party Risk Problem Has a Scale Problem

Ncontracts' 2026 State of Third-Party Risk Management Survey quantified something most servicers already sense: TPRM programs are dramatically under-resourced relative to the exposure they're managing.

63%
of mortgage TPRM programs have just 1–2 dedicated employees
53%
manage 300+ vendors simultaneously with those same teams
52%
experienced a third-party cybersecurity incident (up from 46% the year prior)
72%
only partially aware of how their vendors are using AI in servicing-related work

The survey also found that organizations relying on manual TPRM processes (spreadsheets, email follow-ups, periodic one-way reviews) were 71% more likely to receive exam findings related to third-party oversight. That's not a technology argument. It's a documentation and consistency argument. When oversight is manual, it's also uneven. The vendors that got a thorough annual review are fine. The ones that slipped to every 18 months aren't, and when an examiner asks to see the oversight cadence, there's no good answer.

Relative likelihood of third-party exam findings by oversight approach, Ncontracts 2026
Manual / ad hoc oversight Hybrid (structured + manual) Structured, documented oversight 71% Moderate risk Baseline

Source: Ncontracts, 2026 State of Third-Party Risk Management Survey. Relative risk is indexed to TPRM software users.

The irony is that the servicers with the strongest risk from undermanaged vendor oversight are usually the ones who also have the fewest internal resources to address it. Two people managing 300+ vendor relationships can't conduct meaningful operational reviews. They can track certifications, collect questionnaire responses, and log renewal dates. What they can't do is understand whether the actual work flowing through those vendors is being done the way the servicer's procedures require it to be done.

What Regulators Have Been Saying

Regulatory expectations around vendor oversight in mortgage servicing have been tightening for several years. Two specific updates from 2025 and 2026 are worth having on your radar.

Fannie Mae Lender Letter LL-2026-04 (effective August 2026) explicitly requires servicers to establish governing policies for vendor use of artificial intelligence in any process touching servicing decisions, including borrower-facing communication, loss mitigation triage, and document classification. This isn't an aspiration; it's a requirement that needs to be reflected in vendor contracts and oversight protocols for applicable third parties.

Freddie Mac Bulletin 2025-16 (effective March 2026) similarly expanded servicer accountability for AI governance across vendor-executed processes. It specifically references situations where a vendor uses AI-assisted workflows to support Freddie Mac loan servicing, and requires servicers to demonstrate they have governance in place, not merely that they asked the vendor if they're using AI.

This matters in practical terms because 72% of mortgage organizations are currently only partially aware of how their vendors use AI. That's not a comfortable posture against either of those guidelines. An examiner who asks to see your AI governance documentation for a vendor that turns out to be using AI-assisted document review has a finding. The vendor's assurances are not the servicer's documentation.

"The examiner doesn't ask your vendor what they do. They ask you what you know about what your vendor does, and whether you can prove it."

What 'Documented Operations' Actually Means for a BPO Partner

When servicers think about vendor oversight, the tendency is to focus on what the vendor can show: questionnaires completed, reviews submitted, incident reports on file. That's a starting point, not an answer.

Documented operations at the process level means something different. It means the vendor can show you how a specific workflow is executed: step by step, with defined decision points, defined quality checks, and defined escalation criteria. Not as a policy document that describes intentions, but as working procedures that reflect what actually happens.

A few examples of what that looks like in mortgage back-office contexts:

The distinction between a vendor who has documented operations and one who doesn't shows up immediately when you ask for procedure-level detail. A vendor with real documentation answers your questions with specifics. One without it answers with capabilities statements like "we have robust QC" that describe the intention without showing the practice.

The Five Questions Examiners Ask About Your Vendors

Based on OCC, CFPB, and GSE examination patterns in mortgage servicing, the following questions consistently appear in vendor-related exam inquiries. They're included here not as a checklist, but as a diagnostic: if you can answer each one about your current outsourcing partners, your posture is solid. If several of them are unclear, the gap is worth closing before the next review cycle.

What the examiner asks What good looks like Red flag
"How do you verify that the vendor is following your servicing procedures, not just their own?" Documented periodic procedure reviews; a formal change management process when servicer procedures update; QC sampling results reviewed by servicer "We have SLA metrics in our contract." Monitoring output only, not process adherence.
"What is your oversight cadence for this vendor, and what does each review cover?" Defined review schedule (monthly performance, quarterly operational, annual full), documented agenda, stored review records Ad hoc reviews triggered by issues; no documented review records from the prior 12 months
"Does this vendor use AI or automated decision tools in processing your loans? How do you know?" AI use disclosure in contract and confirmed in most recent vendor review; governance documentation on file "Our contract prohibits unapproved tools." Restriction without verification.
"When a borrower complaint involves this vendor's work, what is the triage and resolution path?" Written complaint-routing SOP that includes vendor-originated issues; defined response timeline that maps to RESPA requirements; complaint log that distinguishes vendor-related findings Complaints handled through general intake with no vendor attribution in logging
"If this vendor had a data incident involving borrower information, what would you know and when?" Contractual breach notification timeline (typically 24–72 hours); tested incident response playbook; documented point of contact at vendor for security events "Our contract has a notification clause." Contractual right without operational readiness.

What to Ask Before Your Next Vendor Review

The questions in the table above are examiner questions. The version of those questions that mortgage servicers should be asking their vendors, before an exam and as part of normal oversight, looks slightly different in tone but covers the same ground.

A useful framing: instead of asking vendors what they have, ask them to show you how it works. "Can you show me the step-by-step procedure your team follows for [specific process]?" surfaces real operational documentation. "Do you have documented procedures?" produces a yes.

A few questions that tend to reveal more than their surface-level counterparts:

See how NTS approaches documented operations and client oversight for financial services accounts. BPO Services →

What This Means Operationally for Servicers

None of this requires overhauling a vendor relationship. Most of it is documentation work: building the right oversight cadence, asking the right questions at each review, and making sure what the vendor does is actually visible to the people who would need to explain it to an examiner.

The specific operational steps that matter:

Frequently Asked Questions

How does regulatory liability actually work when a third-party vendor makes a servicing error?
The servicer remains the responsible party to both the borrower and the GSE or regulator. A vendor's error doesn't transfer liability. It adds a layer of cause. The question regulators ask is whether the servicer had adequate oversight to either prevent the error or detect it quickly. If oversight was inadequate, the finding is against the servicer. The vendor's own practices are evaluated separately if the regulator investigates the vendor directly, but that's a separate process from your exam.
What does "structured vendor oversight" mean in practice for a servicer with limited TPRM resources?
Structured oversight doesn't require a large team. It requires consistency and documentation. Define what each review covers, how often it happens, and how the results are stored. A two-person TPRM team can conduct meaningful oversight on a portfolio of critical vendors if the review process is standardized and every review produces a stored record. What creates exam risk isn't having a small team. It's having a team that operates inconsistently and can't demonstrate what they've reviewed and when.
Does Fannie Mae LL-2026-04 require me to get AI governance documentation from every vendor?
The requirement applies to vendors involved in processes that touch servicing decisions: loan modifications, loss mitigation, document review, borrower communications. Vendors who handle purely administrative or IT-support functions are not the primary target. That said, the most defensible position is to add AI use disclosure to your standard annual vendor questionnaire for all vendors and let the vendor's response determine whether deeper governance documentation is warranted.
What's the difference between an SLA review and an operational review?
An SLA review asks whether the vendor met the numbers in the contract: turnaround time, accuracy rate, uptime. An operational review looks at how the work is being done: are the procedures current, are exceptions being handled consistently, is the error taxonomy showing any emerging patterns, is the team stable or experiencing attrition that could affect quality? Both matter, and they require different information. Most vendors will readily provide SLA performance data. An operational review requires more structured access (a process walkthrough, error-level reporting, QC documentation), which is exactly why it surfaces more.
Is borrower data handling a compliance issue or an operational one?
Both. Contractually, it's a compliance and information-security issue. Operationally, it's about whether the actual practices in your vendor's environment match what the contract says. A contract that requires data encryption and access logging doesn't tell you whether those controls are actually in place. That requires operational verification. Examiners increasingly ask for evidence of verification, not just the contractual requirement. If you haven't verified it, the contractual right to do so doesn't substitute for having done it.

Key Takeaway

Regulatory exposure from third-party vendors doesn't come from using them. It comes from not being able to demonstrate that you understand what they do and have oversight in place to catch it when something goes wrong. The questions that protect servicers aren't certification questions. They're operational questions. Ask them before the examiner does.

Know What Your Examiner Will Ask Before They Do

NTS works with mortgage servicers and financial institutions who need documented operations, not just capable ones. Our back-office teams are built with structured QC, defined escalation paths, and operational records you can show rather than just describe.