Due Diligence and Ongoing Monitoring

 View Only
Expand all | Collapse all

Mortgage company describes themselves as an investor and not a critical vendor.

  • 1.  Mortgage company describes themselves as an investor and not a critical vendor.

    This message was posted by a user wishing to remain anonymous
    Posted 20 days ago
    This message was posted by a user wishing to remain anonymous

    I have recently been asked to vet out a Mortgage broker for the secondary market. When I asked for their due diligence documents, they replied with a certification document and financials. They told us they do not provide SOC reports because they are an investor and not required to share their SOC reports. 

    Has anyone encountered this from a vendor, and if so, how did you vet them out, and what comments did you get from examiners?

    Thanks for your input.



  • 2.  RE: Mortgage company describes themselves as an investor and not a critical vendor.

    This message was posted by a user wishing to remain anonymous
    Posted 6 days ago
    This message was posted by a user wishing to remain anonymous

    I've run into companies that don't have SOCs but not ones that won't share. Even if legally not mandatory, it's good business. If they won't share, it seems a red flag. This is your member data and you should know if and how it is being protected. 

    When a company doesn't have one, we get as much info as we can and make an educated decision depending on the relationship and our risk appetite. 

    I've offered NDA's and asked my C Suite to step in when certain vendors will not release what we feel we need. If you don't feel you can properly vet them, finding a broker that you can vet and feel more comfortable with is probably the safer path.

    If you can get them to agree to share it, try to get that information/data sharing standard added into the contract so you don't run into this again when doing ongoing reviews.