What Is a Mortgage Compliance Audit?

Introduction

Provincial regulators are watching mortgage brokerages more closely than ever. Mortgage administrators, brokers, and lenders now fall under FINTRAC’s AML regime as well.

For most firms, that raises an immediate question: what exactly counts as a "compliance audit," and is it the same thing as a regulatory examination?

Many industry professionals struggle here. Terms like "compliance audit," "internal audit," "regulatory examination," and "AML effectiveness review" get used as if they mean the same thing. They don't. Mixing them up leaves a firm exposed when the wrong process shows up—and the findings, remediation, or licensing consequences are real.

This article breaks down what a mortgage compliance audit covers, how the process unfolds, what it tends to cost, and how to prepare, with specific attention to Canada's provincial licensing rules and FINTRAC's AML requirements.

Key Takeaways

  • Mortgage compliance audits verify brokerages, lenders, and administrators meet licensing, legal, and policy requirements.
  • Audits may be self-initiated, investor-driven, or triggered by a regulator such as FINTRAC.
  • Scope typically covers licensing and disclosure, AML/ATF obligations, fraud controls, and audit governance.
  • Findings range from minor paperwork gaps to material violations that require formal remediation.
  • Regular self-assessment and senior advisory support catch problems before a regulator does.

What Is a Mortgage Compliance Audit?

A mortgage compliance audit is a systematic review of whether a brokerage, lender, or administrator's operations, documentation, and controls hold up against applicable laws, licensing conditions, and internal policy. Auditors pull files, test transactions, and interview staff to test whether policy matches practice on the ground. Weak or missing reviews leave firms exposed to licensing findings, FINTRAC issues, or both.

These reviews aren't one-size-fits-all. They can be run:

  • Internally, through a self-assessment or a dedicated internal audit function
  • Externally, by independent specialists engaged to provide an objective view
  • By investors or regulators, who bring their own scope and enforcement authority

In Canada, this creates layered obligations. Mortgage entities are typically regulated at the provincial level for licensing and consumer protection, often by a financial services regulator such as FSRA in Ontario. They're also regulated federally by FINTRAC for anti-money laundering and terrorist financing compliance.

So when someone says "mortgage compliance audit," they could mean a licensing review, an AML effectiveness review, or something else entirely, depending on which obligation is being tested.

Mortgage Compliance Audit vs. Regulatory Examination vs. Internal Audit

These three terms get blurred together constantly, but they're not interchangeable.

  • Internal audit is an ongoing governance function that reports to the board. It's continuous, not a single event.
  • Compliance audit is a point-in-time adherence check, run internally or by an outside firm. It asks a narrower question: are we meeting specific requirements right now?
  • Regulatory examination is conducted directly by a regulator with enforcement power, such as FINTRAC. It carries the weight of potential penalties or corrective orders.

Findings from a proactive compliance audit often mirror what a regulator looks for during an examination. Running your own review first is both due diligence and rehearsal for the real thing.

What Does a Mortgage Compliance Audit Typically Cover?

Scope depends on which obligations are being tested, but most mortgage compliance audits touch four core areas.

Licensing, Disclosure & Consumer Protection Requirements

Auditors verify licensing status, mandatory borrower disclosures, record-keeping, and advertising practices against provincial standards-of-practice rules. In Ontario, FSRA publishes checklists covering brokerage management, broker and agent conduct, and administrator record-keeping and trust accounts.

Required disclosures generally must be written, clear, and delivered on time, often no later than two business days before key transaction events. Auditors check for:

  • Prescribed investor and lender forms
  • Conflict-of-interest and material-risk disclosures
  • Cost-of-borrowing disclosures
  • Identity verification for borrowers, lenders, and investors

This matters because the gaps regulators find are often basic.

FSRA's 2023-24 supervision review found no documentary evidence of a borrower-suitability assessment in 81% of files examined. It also found that 65% of brokerages had inadequately disclosed material risks—both figures worse than the prior year—according to the FSRA Mortgage Brokering Sector Supervision Plan 2024-25.

AML & FINTRAC (Anti-Money Laundering) Obligations

Canadian mortgage administrators, brokers, and lenders have been subject to FINTRAC's listed reporting entity requirements since October 2024. That means maintaining a documented AML/ATF compliance program built on prescribed program components:

  1. A designated compliance officer
  2. Senior-officer-approved written policies and procedures
  3. A documented business risk assessment
  4. Ongoing training and a training plan
  5. A periodic, documented effectiveness review

Five pillars of FINTRAC AML compliance program for mortgage entities

That last piece, the effectiveness review, is itself a specialized form of mortgage compliance audit. It tests whether the AML program is appropriately designed and actually working, not just written down. FINTRAC requires this review at least every two years, and the next review must start no later than 24 months after the previous one began.

The legal obligation is the periodic effectiveness review. Independent challenge and testing methods (document review, interviews, walkthroughs, file sampling) are how AlphaDelta delivers that review as a service model; independent testing is not itself a universal statutory component that every mortgage effectiveness review must include in a prescribed form. AlphaDelta's Independent AML Effectiveness Review uses those methods to test whether controls operate in practice, not just on paper.

Every engagement includes one optional findings clarification session within 90 days of the final report. If FINTRAC formally initiates a compliance examination within 12 months of the final report, AlphaDelta will provide up to 10 hours of review-related senior advisory support at no additional cost.

Fraud Prevention & Underwriting Controls

Auditors also test the controls built to catch mortgage fraud before it closes a deal. Canadian regulators, including FSRA, publish fraud-detection checklists that cover:

  • Identity and driver's licence verification
  • Employer and income verification
  • Down payment source checks, including gift letters and financial statements
  • Occupancy status and stated mortgage purpose
  • Appraisal review and "as is" versus completion value comparisons for construction lending

Red-flag protocols matter too. Auditors look for whether staff investigate inconsistencies, notify lenders in writing when documentation looks questionable, and escalate suspicions to a principal broker.

Internal Audit & Risk Governance Requirements

Lenders approved by investors often carry additional governance obligations. Many are expected to maintain a formal internal audit function, with a documented risk assessment and an audit plan spanning low, moderate, and high-risk areas over a rolling cycle. This layer sits above the individual compliance checks. It asks whether the organization's overall governance structure is sound enough to catch problems before they escalate.

Why Mortgage Compliance Audits Matter

Licensing and investor approval status are frequently contingent on proving an effective compliance program exists, not just claiming one does. When that proof is missing, the consequences show up fast.

FSRA's enforcement data makes this concrete. In 2023-24, the regulator recorded 18 mortgage-sector sanctions, including 8 AMPs totalling $454,388 (from $81,000 the prior year), per the FSRA Licensing and Market Conduct Enforcement Report 2022-2024.

Sanctions that year included suspensions, compliance orders, and licence revocations, not just fines.

Beyond the financial penalties, there's reputational fallout:

  • Investor confidence erodes when audit findings surface repeatedly
  • Remediation costs climb the longer a gap goes unaddressed
  • Regulatory relationships get harder to manage once trust is damaged

A compliance audit gives leadership the chance to find and fix gaps on their own timeline, rather than a regulator's.

The Mortgage Compliance Audit Process: What to Expect

Most audits, whether internal, external, or regulator-led, follow a similar arc.

  1. Scope & Planning — The audit team defines which areas (licensing, AML, fraud controls, servicing) will be assessed, based on a risk assessment and any prior findings.
  2. Document & File Review — Auditors examine policies, procedures, loan files, disclosures, training records, and past audit history for evidence that controls are actually applied.
  3. Testing & Interviews — Auditors test sample transactions against regulatory requirements and interview staff to confirm people understand and execute the controls they're supposed to follow.
  4. Findings & Reporting — Auditors document gaps, assign each a risk rating (low, moderate, or high), and present findings to management or the board.
  5. Remediation & Follow-up — The organization builds and executes a corrective action plan, then a follow-up review confirms the fix held before the next audit cycle.

5-step mortgage compliance audit process from scoping to remediation

That final step is where a lot of firms stumble. A finding that's identified but never fully remediated tends to resurface, often at a worse moment, like during a regulator's own examination.

How Much Does a Mortgage Compliance Audit Cost – and How to Prepare

Fees vary widely based on entity size, operational complexity, and whether the review covers a single area or the full compliance program.

A narrow file-review audit costs far less than a comprehensive AML effectiveness review spanning risk assessment, training, and transaction testing. In-house versus external delivery also shifts the price.

FINTRAC itself notes that review scope depends on:

  • Business complexity and transaction volume
  • Findings from previous reviews
  • Current money laundering and terrorist financing risk
  • The review period and testing methods used

Those same factors drive cost. Preparation on your side still cuts both expense and exposure:

Preparation tips that reduce both cost and risk:

  • Keep documentation organized and current, not scrambled together the week before
  • Run periodic self-assessments rather than waiting for the mandated cycle
  • Update policies as soon as regulatory requirements change
  • Track prior findings through to full remediation, not just partial fixes

Outside help often pays for itself when an AML effectiveness review is overdue or a FINTRAC examination is on the horizon.

AlphaDelta's Independent AML Effectiveness Review is a fixed-fee, defined-scope engagement, so organizations know the cost upfront rather than facing open-ended billing. For ongoing senior judgment, remediation planning, or examination readiness, Senior AML Advisory is available on retainer, defined-engagement, or hourly terms.

Between audit cycles, reporting entities can track regulatory developments through The Daily Delta and The Weekly Alpha, AlphaDelta's free Canadian AML briefings.

Frequently Asked Questions

How much does a mortgage compliance audit cost?

Cost depends on entity size, the audit's scope, and whether it's done internally or externally. A single-area review costs less than a full-program audit covering AML, licensing, and fraud controls together.

What does mortgage compliance do?

The compliance function ensures adherence to licensing, disclosure, AML/ATF, and consumer protection rules. It also manages regulatory relationships and maintains the internal controls that keep the business audit-ready.

What does it mean when your mortgage is being audited?

This usually refers to a file-level quality control check on an individual loan, typically an investor or QC review, not an enforcement action. It's distinct from a company-wide compliance audit of the lender or broker itself.

Who conducts a mortgage compliance audit?

Audits may be performed by internal audit staff, independent third-party specialists, or regulators themselves during a formal examination. Each brings a different scope and level of enforcement authority.

How often should mortgage compliance audits be conducted?

Frequency depends on regulatory requirements, risk profile, and past findings. Many firms run internal reviews at least annually, while FINTRAC requires AML effectiveness reviews at least every two years.

What happens if a mortgage compliance audit finds violations?

Firms typically must build and execute a remediation plan, with follow-up testing to confirm the fix worked. Material or unresolved findings can trigger regulatory reporting obligations and, in some cases, administrative penalties.