In mortgage servicing, the regulatory exam doesn't ask which vendors you hired. It asks whether you can demonstrate that the work they do on your behalf meets your servicing standards. Those are different questions, and the gap between them is where most third-party findings live.
A vendor can have an excellent pitch deck, a strong implementation track record, and a team that responds promptly to your account manager's calls. None of that appears in your exam file. What appears in your exam file is evidence, or the absence of it, that the processes running on your behalf are controlled, documented, and consistent with your obligations to borrowers and investors.
The questions that uncover whether that's actually true are not the ones most mortgage servicers think to ask. And most of the time, they don't find out they missed them until someone else asks first.
The Third-Party Risk Problem Has a Scale Problem
Ncontracts' 2026 State of Third-Party Risk Management Survey quantified something most servicers already sense: TPRM programs are dramatically under-resourced relative to the exposure they're managing.
The survey also found that organizations relying on manual TPRM processes (spreadsheets, email follow-ups, periodic one-way reviews) were 71% more likely to receive exam findings related to third-party oversight. That's not a technology argument. It's a documentation and consistency argument. When oversight is manual, it's also uneven. The vendors that got a thorough annual review are fine. The ones that slipped to every 18 months aren't, and when an examiner asks to see the oversight cadence, there's no good answer.
Source: Ncontracts, 2026 State of Third-Party Risk Management Survey. Relative risk is indexed to TPRM software users.
The irony is that the servicers with the strongest risk from undermanaged vendor oversight are usually the ones who also have the fewest internal resources to address it. Two people managing 300+ vendor relationships can't conduct meaningful operational reviews. They can track certifications, collect questionnaire responses, and log renewal dates. What they can't do is understand whether the actual work flowing through those vendors is being done the way the servicer's procedures require it to be done.
What Regulators Have Been Saying
Regulatory expectations around vendor oversight in mortgage servicing have been tightening for several years. Two specific updates from 2025 and 2026 are worth having on your radar.
Fannie Mae Lender Letter LL-2026-04 (effective August 2026) explicitly requires servicers to establish governing policies for vendor use of artificial intelligence in any process touching servicing decisions, including borrower-facing communication, loss mitigation triage, and document classification. This isn't an aspiration; it's a requirement that needs to be reflected in vendor contracts and oversight protocols for applicable third parties.
Freddie Mac Bulletin 2025-16 (effective March 2026) similarly expanded servicer accountability for AI governance across vendor-executed processes. It specifically references situations where a vendor uses AI-assisted workflows to support Freddie Mac loan servicing, and requires servicers to demonstrate they have governance in place, not merely that they asked the vendor if they're using AI.
This matters in practical terms because 72% of mortgage organizations are currently only partially aware of how their vendors use AI. That's not a comfortable posture against either of those guidelines. An examiner who asks to see your AI governance documentation for a vendor that turns out to be using AI-assisted document review has a finding. The vendor's assurances are not the servicer's documentation.
What 'Documented Operations' Actually Means for a BPO Partner
When servicers think about vendor oversight, the tendency is to focus on what the vendor can show: questionnaires completed, reviews submitted, incident reports on file. That's a starting point, not an answer.
Documented operations at the process level means something different. It means the vendor can show you how a specific workflow is executed: step by step, with defined decision points, defined quality checks, and defined escalation criteria. Not as a policy document that describes intentions, but as working procedures that reflect what actually happens.
A few examples of what that looks like in mortgage back-office contexts:
- Document review procedures: A written step-by-step that covers what gets checked on each document type, what constitutes a deficiency, who makes the call on borderline items, and how exceptions are logged and routed. Not a training deck. An operational procedure that an agent follows and a QC analyst checks against.
- Error handling and escalation: A defined taxonomy of error types, with documented thresholds for escalation. If an agent makes an error on a loan modification form, what happens next? Who reviews it? How is it logged? What's the correction path? If the answer is "the account manager follows up," the procedure doesn't exist at the operational level.
- AI use documentation: If the vendor uses any AI-assisted tools in their workflow, whether for classification, routing, quality scoring, or anything else, servicers now need to know about it, and need to have asked specifically about it. That means the question has to be in your vendor review process, not just sitting in a contract addendum that no one checked.
- Data handling: How is borrower data handled within the vendor's environment? Where does it sit, who accesses it, how are access logs maintained, and how does the vendor notify you if that changes? These are operational questions, not legal ones. They need answers from the operations team, not just from the contract.
The distinction between a vendor who has documented operations and one who doesn't shows up immediately when you ask for procedure-level detail. A vendor with real documentation answers your questions with specifics. One without it answers with capabilities statements like "we have robust QC" that describe the intention without showing the practice.
The Five Questions Examiners Ask About Your Vendors
Based on OCC, CFPB, and GSE examination patterns in mortgage servicing, the following questions consistently appear in vendor-related exam inquiries. They're included here not as a checklist, but as a diagnostic: if you can answer each one about your current outsourcing partners, your posture is solid. If several of them are unclear, the gap is worth closing before the next review cycle.
| What the examiner asks | What good looks like | Red flag |
|---|---|---|
| "How do you verify that the vendor is following your servicing procedures, not just their own?" | Documented periodic procedure reviews; a formal change management process when servicer procedures update; QC sampling results reviewed by servicer | "We have SLA metrics in our contract." Monitoring output only, not process adherence. |
| "What is your oversight cadence for this vendor, and what does each review cover?" | Defined review schedule (monthly performance, quarterly operational, annual full), documented agenda, stored review records | Ad hoc reviews triggered by issues; no documented review records from the prior 12 months |
| "Does this vendor use AI or automated decision tools in processing your loans? How do you know?" | AI use disclosure in contract and confirmed in most recent vendor review; governance documentation on file | "Our contract prohibits unapproved tools." Restriction without verification. |
| "When a borrower complaint involves this vendor's work, what is the triage and resolution path?" | Written complaint-routing SOP that includes vendor-originated issues; defined response timeline that maps to RESPA requirements; complaint log that distinguishes vendor-related findings | Complaints handled through general intake with no vendor attribution in logging |
| "If this vendor had a data incident involving borrower information, what would you know and when?" | Contractual breach notification timeline (typically 24–72 hours); tested incident response playbook; documented point of contact at vendor for security events | "Our contract has a notification clause." Contractual right without operational readiness. |
What to Ask Before Your Next Vendor Review
The questions in the table above are examiner questions. The version of those questions that mortgage servicers should be asking their vendors, before an exam and as part of normal oversight, looks slightly different in tone but covers the same ground.
A useful framing: instead of asking vendors what they have, ask them to show you how it works. "Can you show me the step-by-step procedure your team follows for [specific process]?" surfaces real operational documentation. "Do you have documented procedures?" produces a yes.
A few questions that tend to reveal more than their surface-level counterparts:
- "Walk me through what happens when an exception arises in [specific process]: who makes the call, how is it documented, and how does it get to me?" This tests whether exception handling is proceduralized or ad hoc. Ad hoc exception handling is the single most common source of loan-level errors in outsourced mortgage operations.
- "How would I know if your team's procedures for our account changed?" This tests whether there's a change management process. Vendors with real change management have a formal notification step. Vendors without it typically say "we'd let you know," which means someone might think to send an email, or might not.
- "Does any part of your workflow for our account use AI-assisted tools? This includes routing, classification, quality scoring, or communication drafting." This is now a required question under Fannie Mae LL-2026-04 for applicable vendors. Asking it specifically rather than asking about "unapproved tools" or "technology" generally produces a more accurate answer.
- "What's in the most recent performance report you have for our account? Not summary numbers. The error-level detail." Vendors with structured QC can produce error breakdowns by type, volume, and trend. Vendors without it produce aggregated accuracy rates that obscure where problems actually sit.
See how NTS approaches documented operations and client oversight for financial services accounts. BPO Services →
What This Means Operationally for Servicers
None of this requires overhauling a vendor relationship. Most of it is documentation work: building the right oversight cadence, asking the right questions at each review, and making sure what the vendor does is actually visible to the people who would need to explain it to an examiner.
The specific operational steps that matter:
- Add AI use explicitly to your annual vendor disclosure requirements. The generic technology questionnaire that asks about "third-party tools" won't surface AI use specifically. Add a direct question, require a response for each applicable workflow, and store the response with a date.
- Build procedure-level oversight into at least one review cycle per year. The operational review that looks at how work is done, not just what was produced, is different from the performance review that looks at metrics. Both matter. Most servicers only have the latter.
- Establish a defined complaint attribution process. If a borrower complaint is traceable to vendor-executed work, that should appear in your complaint log with vendor attribution. Examiners look at complaint logs for patterns. A complaint log that doesn't distinguish vendor-related issues from internal issues makes pattern analysis impossible, and with it your ability to demonstrate proactive oversight.
Frequently Asked Questions
Key Takeaway
Regulatory exposure from third-party vendors doesn't come from using them. It comes from not being able to demonstrate that you understand what they do and have oversight in place to catch it when something goes wrong. The questions that protect servicers aren't certification questions. They're operational questions. Ask them before the examiner does.