Quality Control vs. Compliance Audits in Mortgage Lending

Quality Control vs. Compliance Audits in Mortgage Lending

Quality control and compliance audits are vital to any mortgage originator business, including banks and brokers. Although the two may have slight similarities, they do not overlap much. QC audits are meant to ascertain the accuracy of your underwriting according to investor standards, while compliance reviews help determine whether you are compliant with relevant consumer protection laws. In this post, we explain more about these two crucial components of any mortgage process.

What is a Quality Control Audit?

QC is an investor requirement that involves checking the accuracy of the underwriting. It focuses on credit risk, tax evaluation, verification of third parties, and any undisclosed liabilities. Moreover, QC audits must be done at the pre-and post-funding stages. Other characteristics of quality control audits include:

It must be independent of the lending process: the same staff tasked with originating and closing the mortgage cannot conduct the audit.

Re-verification and re-underwriting: the borrower’s employment, income, assets and liabilities are re-verified, and the verification is underwritten, including any errors identified during this process.

Field review appraisal: the documents go through the appraisal desk to review any elements the underwriter may have left out. During field review appraisal, a sample of 10% is tested to verify that the underwriting was completed correctly.

Done periodically: depending on your investor requirements, QC reviews may be conducted bimonthly, monthly, quarterly, biannually, or annually.

The verifications mandated during QC audits help validate that the underwriting was done correctly, which is key to avoiding legal issues in the future. These audits also provide opportunities to identify weaknesses in the process and offer additional training to your staff where necessary. Otherwise, habitual errors in the process could lead to loan buybacks and unfavorable pricing.

Some elements of QC auditing overlap with compliance, including documentation of joint intent, confirming that timing requirements were met, comparing APR values and tolerance limits, and checking that the right of rescission was obtained (more on compliance later).

What is a Compliance Audit?

Mortgage lenders are required to comply with many federal and state laws, which call for occasional audits. A compliance audit establishes whether a lender complies with these federal and state consumer protection laws stipulated in the Code of Federal Regulations (CFR).

You want to conduct compliance audits to confirm that you comply with federal consumer regulations in readiness for federal compliance examinations. That way, you will have a shot at remediation before the examinations.

There are two main regulation categories that the majority of mortgage audits focus on, including Regulation Z (Truth in Lending Act, abbreviated as TILA) and Regulation X (Real Estate Settlement Procedures, abbreviated as RESPA). Other laws that may apply include the following:

  • The Equal Credit Opportunity Act (Regulation B)
  • Fair Credit Reporting Act (Regulation V)
  • Home Mortgage Disclosure Act (Regulation C)
  • Flood Disaster Protection Act
  • Homeowners’ Protection Act


TILA protects consumers against unfair or inaccurate credit practices. For example, lenders must provide borrowers with information on the loan, which can be used for comparison shopping. Some of the information specified under the act include loan term, the APR, and total costs. However, TILA does not apply to loans intended for commercial or business purposes.


The main aim of RESPA is to prevent kickbacks, limit the use of escrow, and minimize malpractices in real estate settlements. Additionally, the act stipulates that homebuyers be provided with disclosures on settlement services and costs. Unlike TILA, RESPA does not exclude non-natural persons — like commercial buyers or businesses.

Additionally, compliance regulation is governed by various agencies, including the following:

  • CFPB: Consumer Financial Protection Bureau
  • OCC: the Office of the Comptroller of the Currency
  • FDIC: the Federal Deposit Insurance Corporation
  • The Federal Reserve
  • OCC: the Office of the Controller of the Currency
  • HUD: the Department of Housing and Urban Development
  • NCUA: the Department of Housing and Urban Administration

Also worth mentioning is that depending on the nature of your business, many other acts not mentioned in this document may apply to your loans.

Summary of Mortgage QC vs. Compliance Audit

Although some parts of quality control audit overlap with compliance, the two are different right from their purposes. QC audits can be viewed as protecting the lender, while compliance is more inclined towards protecting the consumer. Quality control is meant to confirm the accuracy of the underwriting according to investor standards, while compliance refers to consumer protection laws.

Additionally, compliance audits involve many higher risk calculations compared to QC. Still, both audits are vital to avoiding expensive legal issues and for the success of your business.