Covered vertical

WISP for mortgage lenders

Mortgage lenders need a WISP when the business is covered by the FTC Safeguards Rule category mortgage lender. The practical coverage trigger is that the firm extends, arranges, purchases, or services consumer mortgage credit outside a banking regulator's Safeguards jurisdiction. Borrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.

Key facts

  • Mortgage lenders should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: extends, arranges, purchases, or services consumer mortgage credit outside a banking regulator's Safeguards jurisdiction.
  • The data map should be vertical-specific: Borrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.
  • A small lender may still cross 5,000 consumers quickly through leads, denied files, originated loans, and servicing records. Under 16 CFR 314.6, the threshold analysis changes only the listed subparts, not coverage.

Key takeaways

  • Mortgage lenders should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: extends, arranges, purchases, or services consumer mortgage credit outside a banking regulator's Safeguards jurisdiction.
  • The data map should be vertical-specific: Borrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.
  • A small lender may still cross 5,000 consumers quickly through leads, denied files, originated loans, and servicing records. Under 16 CFR 314.6, the threshold analysis changes only the listed subparts, not coverage.
  • Our licensing exams already check compliance. Licensing or mortgage-law obligations are separate; the Safeguards Rule asks whether customer information is protected by a written security program and actual safeguards.

Why mortgage lenders are covered

Mortgage lenders are covered when their business activity fits mortgage lender. FTC guidance lists mortgage lenders among the financial institutions covered by the Safeguards Rule, and 16 CFR 314.2 ties lending activities to the financial-institution definition.

The coverage test is factual. For this vertical, Policywright treats the trigger as: extends, arranges, purchases, or services consumer mortgage credit outside a banking regulator's Safeguards jurisdiction. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.

The page does not invent a coverage theory beyond the cited category and factual trigger.

Where customer information lives

Borrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.

That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.

A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.

Common objection

Our licensing exams already check compliance. Licensing or mortgage-law obligations are separate; the Safeguards Rule asks whether customer information is protected by a written security program and actual safeguards.

Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.

Under-5,000-consumer analysis

A small lender may still cross 5,000 consumers quickly through leads, denied files, originated loans, and servicing records. Under 16 CFR 314.6, the threshold analysis changes only the listed subparts, not coverage.

16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.

A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.

Mortgage lenders WISP fit check
QuestionVertical-specific answerSource
Coverage triggerextends, arranges, purchases, or services consumer mortgage credit outside a banking regulator's Safeguards jurisdictionFTC Safeguards Rule business guidance
Customer data flowBorrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.Document in WISP data inventory
Common objectionOur licensing exams already check compliance. Licensing or mortgage-law obligations are separate; the Safeguards Rule asks whether customer information is protected by a written security program and actual safeguards.FTC Safeguards Rule business guidance
Small-firm exceptionA small lender may still cross 5,000 consumers quickly through leads, denied files, originated loans, and servicing records. Under 16 CFR 314.6, the threshold analysis changes only the listed subparts, not coverage.16 CFR 314.6

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

What makes mortgage lenders different from tax preparers?

The data flow and objection pattern are different. Mortgage lenders need a WISP that follows Borrower files include credit, income, tax transcript, bank, employment, appraisal, title, underwriting, and closing data. Information usually crosses a loan-origination system, warehouse or investor portal, settlement vendors, and servicing handoff records.

Does Policywright cover related non-Safeguards obligations?

No separate related obligation is claimed on this page. Policywright is focused on the Safeguards Rule policy packet and does not replace counsel.

Sources

Build a WISP for mortgage lenders.

Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.

Build my plan
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.