WISP for mortgage brokers
Mortgage brokers need a WISP when the business is covered by the FTC Safeguards Rule category mortgage broker. The practical coverage trigger is that the firm brokers loans for consumers or routes mortgage applications to lenders. Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system.
Key facts
- Mortgage brokers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: brokers loans for consumers or routes mortgage applications to lenders.
- The data map should be vertical-specific: Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system.
- Small broker shops may fall below 5,000 consumers, but retained leads, denied applications, and old loan files count toward the data footprint the firm should evaluate. The 16 CFR 314.6 exception removes four listed obligations only.
Key takeaways
- Mortgage brokers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: brokers loans for consumers or routes mortgage applications to lenders.
- The data map should be vertical-specific: Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system.
- Small broker shops may fall below 5,000 consumers, but retained leads, denied applications, and old loan files count toward the data footprint the firm should evaluate. The 16 CFR 314.6 exception removes four listed obligations only.
- We only broker the loan and never fund it. The Safeguards Rule definition expressly names brokering loans; the broker's lack of balance-sheet lending does not remove the need to safeguard borrower information.
Why mortgage brokers are covered
Mortgage brokers are covered when their business activity fits mortgage broker. 16 CFR 314.2(h)(2)(xi) names mortgage brokers because brokering loans is a financial activity.
The coverage test is factual. For this vertical, Policywright treats the trigger as: brokers loans for consumers or routes mortgage applications to lenders. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.
The page does not invent a coverage theory beyond the cited category and factual trigger.
Where customer information lives
Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system.
That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.
A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.
Common objection
We only broker the loan and never fund it. The Safeguards Rule definition expressly names brokering loans; the broker's lack of balance-sheet lending does not remove the need to safeguard borrower information.
Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.
Under-5,000-consumer analysis
Small broker shops may fall below 5,000 consumers, but retained leads, denied applications, and old loan files count toward the data footprint the firm should evaluate. The 16 CFR 314.6 exception removes four listed obligations only.
16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.
A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.
| Question | Vertical-specific answer | Source |
|---|---|---|
| Coverage trigger | brokers loans for consumers or routes mortgage applications to lenders | 16 CFR 314.2(h)(2)(xi) |
| Customer data flow | Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system. | Document in WISP data inventory |
| Common objection | We only broker the loan and never fund it. The Safeguards Rule definition expressly names brokering loans; the broker's lack of balance-sheet lending does not remove the need to safeguard borrower information. | 16 CFR 314.2(h)(2)(xi) |
| Small-firm exception | Small broker shops may fall below 5,000 consumers, but retained leads, denied applications, and old loan files count toward the data footprint the firm should evaluate. The 16 CFR 314.6 exception removes four listed obligations only. | 16 CFR 314.6 |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
What makes mortgage brokers different from tax preparers?
The data flow and objection pattern are different. Mortgage brokers need a WISP that follows Borrower data moves through lead intake, loan-origination systems, credit pulls, document-upload portals, income and asset verification, lender submissions, and broker email. The WISP should name both the LOS and the lender/vendor portals where nonpublic personal information leaves the broker's direct system.
Does Policywright cover related non-Safeguards obligations?
No separate related obligation is claimed on this page. Policywright is focused on the Safeguards Rule policy packet and does not replace counsel.
Sources
Build a WISP for mortgage brokers.
Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.
Build my plan