Affiliate disclosure
Book titles on this page link to Amazon. As an Amazon Associate, DataField.Dev earns from qualifying purchases — at no additional cost to you.
Chapter 36 — Further Reading
Technology: LOS Systems, CRM, Pricing Engines, AI, and the Digital Mortgage
A note before the list. This chapter's subject changes faster than any other in the book, and it is the one place where a printed source is most likely to be stale. Almost everything worth reading here is free, published by an agency or a standards body, and revised. Read the current version, not a summary of it — including not this one.
If you read only one thing
The Consumer Financial Protection Bureau's circulars on adverse action notification where credit decisions rest on complex algorithms — the 2022 circular on the requirement itself, and the 2023 circular on the proper use of the Bureau's sample forms.
They are short. They are written in plain English. And between them they establish the sentence that governs this entire subject: a creditor must provide the specific principal reasons for adverse action, and the complexity of the decisioning technology is not an exception. Everything else in §36.8 and §36.9 — what AI can do, what it may not decide, why explainability is a compliance requirement rather than an engineering preference — follows from that.
Read them alongside Regulation B's adverse action provisions so you can see what the circulars are interpreting. Two hours, total, and you will understand the constraint better than most people currently selling software into this industry.
Tier 1 — Verified canonical
Statutes, regulations, agencies, and standards we can stand behind.
On electronic records, signatures, and notes
- Electronic Signatures in Global and National Commerce Act (E-SIGN), 2000 — the federal rule that a record or signature may not be denied legal effect solely because it is electronic, and the consumer consent requirement for information a law requires to be provided in writing. Read the consumer consent section specifically; it is the part loan officers are asked about.
- Uniform Electronic Transactions Act (UETA), 1999 — the uniform state act, adopted in some form by nearly every state, with a few states enacting their own analogous statutes. Find out which applies in your state.
- The transferable record provisions of E-SIGN and UETA — the legal invention that makes an electronic promissory note possible, built on a single authoritative copy and the concept of control.
- MISMO (Mortgage Industry Standards Maintenance Organization) — the industry data standards body affiliated with the Mortgage Bankers Association. Its published standards, including the tamper-evident document format used for eNotes, are what makes systems from different vendors read each other's output.
- MERS eRegistry — the industry system of record identifying the controller and location of the authoritative copy of an eNote. Its published procedures, and the agency requirements for registration, are the operational rules.
- Fannie Mae Selling Guide and Freddie Mac Seller/Servicer Guide — the authorities on eNote eligibility, delivery, digital verification programs, and representation and warranty relief. Continuously updated; the guides are the answer, not a training deck about the guides.
On adverse action, fair lending, and models
- Equal Credit Opportunity Act (ECOA) and Regulation B — the adverse action notification requirements, including the statement of specific principal reasons and the timing. The single most load-bearing authority in this chapter.
- Fair Credit Reporting Act (FCRA) — the separate adverse action obligation where a consumer report is used, the risk-based pricing rule, and the credit-score disclosure required for residential mortgage applicants. Different notices, different triggers; do not merge them.
- Fair Housing Act — and your regulator's fair lending examination procedures, which show you what is actually looked at.
- Home Mortgage Disclosure Act (HMDA) and Regulation C — the data your LOS produces, and the data that makes outcome testing possible in the first place.
- Supervisory guidance on model risk management, Federal Reserve and OCC, 2011 — development, implementation, and use; independent validation; governance, inventory, documentation, and ongoing monitoring. Written for banks; the concepts are the practical standard everywhere.
- Joint statement on enforcement efforts against discrimination and bias in automated systems (CFPB, DOJ Civil Rights Division, EEOC, FTC, 2023) — four agencies stating that existing law applies to automated decision-making without a technology exception.
On data security and fraud
- Gramm-Leach-Bliley Act (GLBA) — the privacy half and the safeguards half. Know which regulator enforces which against your employer.
- The Federal Trade Commission's Safeguards Rule — the information security program requirements applicable to non-bank financial institutions, including mortgage brokers and lenders. Substantially amended, with elements including a designated qualified individual, risk assessments, access controls, encryption, multi-factor authentication, vendor oversight, incident response, and a notification requirement for certain security events. Verify the current text; this rule has been amended more than once.
- Financial Crimes Enforcement Network (FinCEN) advisories on email compromise fraud schemes — the 2016 advisory and its later update. The typology, the red flags, and the reporting expectations.
- FBI Internet Crime Complaint Center (IC3),
ic3.gov— public service announcements on business email compromise and real estate transactions, the annual internet crime report, and current guidance on reporting and the recovery process. Report immediately; the criteria and thresholds have been revised over time. - NIST Cybersecurity Framework — the vocabulary your security team uses. You do not need to implement it. You should be able to follow a conversation about it.
On the digital closing
- The Consumer Financial Protection Bureau's eClosing pilot report (2015) — the Bureau studied electronic closings and reported on measures of borrower understanding, efficiency, and empowerment, with explicit discussion of the pilot's design limits. Read the report rather than the headline anyone wrote about it.
- Your state's remote online notarization statute, and the Revised Uniform Law on Notarial Acts as a model. State law governs authorization, identity proofing, commissioning, and recording retention.
- Federal RON legislation has been introduced in Congress repeatedly. Verify its current status before you assume anything about it.
- Your county recorder's electronic recording policy. This is not a joke. Electronic recording is adopted county by county, and it is the last veto on a fully digital closing.
On marketing from the database
- Regulation Z advertising rules and Regulation N (Mortgage Acts and Practices — Advertising).
- Telephone Consumer Protection Act, the National Do Not Call Registry, and CAN-SPAM — plus any state analogues. Consent standards under the TCPA have been revised and are actively litigated.
Tier 2 — Attributed, specifics unverified
Real practice and real benchmarks whose current values we have not pinned down. Treat every figure in this tier as something to verify before you repeat it.
- Agency digital verification programs. Fannie Mae's certainty program and Freddie Mac's automated income and asset assessment tools allow components validated through the automated underwriting system, using reports from authorized report suppliers, to carry representation and warranty relief on the validated component. Which components are eligible, what data currency is required, and what the relief covers all change — the guides are the authority and they are updated continuously.
- Uniform data standards and delivery datasets. The agencies' uniform mortgage data program defines standardized datasets for loan delivery, closing data, and appraisal delivery. Structure is stable; specifications are versioned. Check the current specification before building anything against it.
- Undisclosed debt monitoring. Credit bureaus offer continuous monitoring between application and closing that alerts a lender to new inquiries and new tradelines. Real, widely available, and genuinely useful — but a bureau learns of an account only when the creditor reports it, and that lag is why §36.11 declines to claim monitoring would have saved the Linden Street file.
- State cybersecurity regulation of licensees. At least one state financial regulator maintains a detailed cybersecurity regulation with annual certification obligations reaching many mortgage companies, and other states have moved in the same direction. Ask your compliance department which regimes apply to your license.
- Retention periods. Regulation B, Regulation Z (including a longer period specific to the Closing Disclosure), and Regulation C each set their own. They are stable but they have been revised. Verify with compliance rather than trusting any secondary source, including this one.
- Vendor capability claims of every kind. Accuracy rates for document extraction, time savings, adoption percentages, closing-time reductions. This book prints none of them, on purpose. If a number matters to a decision, ask for the methodology and the sample.
Tier 3 — Illustrative / constructed
Everything in this chapter that carries a dollar sign or a screen layout.
- The Linden Street file — the running project. \$385,000 purchase, loan \$365,750, 706 representative score, 95% LTV, 6.625% with 0.500 point, 51 days, eleven conditions, the eleven dead days between day 33 and day 44. Constructed throughout.
- Figure 36.1, "The pipeline screen on day 37" — a constructed rendering. Screen layouts vary by system; the file's facts and dates are the book's frozen figures.
- Figure 36.2, "The deposit the report cannot explain" — a constructed asset verification report. Account numbers are fictional; balances and the \$4,900 deposit are the book's frozen figures.
- The day-12 pricing grid in §36.5 — a constructed teaching grid. Structure is what to learn; values are perishable. Verify current pricing at the source.
- The stack diagram, the seams table, and the "one field" cascade in §36.1 and §36.2 — constructed teaching diagrams.
- The composite in Case Study 36.1 — a constructed narrative assembled from the fact patterns described in the public advisories cited there. No real victim, party, or company is depicted.
- The composite in Case Study 36.2 — a constructed governance scenario. No real lender, vendor, model, or product is depicted.
Where to go next in this book
- Chapter 2 — the residential security maps, which §36.9 treats as the template for how a model fails.
- Chapter 15 — automated underwriting, findings, and what a recommendation is and is not. This chapter assumes it.
- Chapter 19 — conditions and the discipline of clearing them. The eleven dead days are a Chapter 19 failure that a Chapter 36 report would have caught.
- Chapter 22 — TRID, the disclosures your LOS generates, and the timing clocks it tracks.
- Chapter 23 — closing, funding, and the mechanics an eClosing implements.
- Chapter 25 — fair lending doctrine: disparate treatment, disparate impact, adverse action. Read it before you argue with anyone about a model.
- Chapter 27 — mortgage fraud generally, including business email compromise as a scheme.
- Chapter 29 — how a rate is actually built, which is what the pricing engine is implementing.
- Chapter 30 — rate locks, and the critique of the undersized lock that expired on day 42.
- Chapter 38 — business development, and what to actually do with the database §36.4 tells you to maintain.