Private mortgage note servicing carries federal and state regulatory exposure that most self-managing lenders underestimate. TILA, RESPA, GLBA, FDCPA, and state licensing laws apply simultaneously—and a gap in any one of them creates liability that survives even a clean payment history. This guide identifies the exact exposure points and the steps that eliminate them.

Which Federal Regulations Apply to Private Mortgage Note Servicing

Federal law covers private mortgage note servicing across four primary statutes, and each one carries independent enforcement risk.

Truth in Lending Act (TILA) and Regulation Z

TILA requires accurate disclosure of loan terms before and at closing. For servicers, the post-origination obligations are equally serious: periodic statement requirements, interest-rate change notices, and payoff statement accuracy. A miscalculated payoff figure is a TILA exposure. Private lenders who serviced their own notes for years without periodic statements have faced borrower claims under this statute even when no payment was ever late.

Real Estate Settlement Procedures Act (RESPA)

RESPA Section 6 governs the transfer of servicing rights and the handling of qualified written requests. If a borrower submits a written dispute or information request, the servicer has specific acknowledgment and response windows. Missing those windows—even by one business day—creates a private right of action. The statute’s escrow account rules also apply when a private note includes tax and insurance impounds, requiring annual escrow analyses and strict disbursement timing.

Gramm-Leach-Bliley Act (GLBA)

GLBA requires servicers to protect nonpublic personal information and deliver annual privacy notices to borrowers. Most private lenders storing payment histories in spreadsheets or unencrypted email chains are in direct violation. The FTC’s Safeguards Rule—updated and now enforced—sets specific technical and administrative controls for financial institutions, including private mortgage servicers who meet the covered-entity threshold.

Fair Debt Collection Practices Act (FDCPA)

FDCPA applies when a third party services a loan that was in default at the time of transfer—and in some circuits, to servicers who acquired the note after origination regardless of default status. Written collection notices and payment demand letters carry FDCPA requirements around timing, content, and the required debt-validation notice. A single non-compliant collection letter is an actionable violation.

State Licensing Requirements Private Note Holders Routinely Miss

State law adds a compliance layer that changes by jurisdiction and changes frequently—and ignorance of it is not a defense.

Most states require a mortgage servicer license for anyone collecting payments on a secured residential loan, regardless of whether the loan was originated by a bank or a private individual. Some states exempt portfolio lenders who hold their own notes, but that exemption evaporates the moment the note is sold, transferred, or serviced by an agent.

California’s Department of Financial Protection and Innovation requires a California Financing Law license for most private note servicers. Texas requires a Mortgage Servicer license under Chapter 158 of the Finance Code. Florida, New York, and Illinois each have independent frameworks with annual renewal, bonding, and examination requirements.

Operating without the required state license while collecting payments on a residential mortgage note is a criminal violation in most jurisdictions—not merely an administrative penalty.

For a detailed breakdown of disclosure obligations by transaction type, see 7 Mandatory Disclosures for Private Mortgage Lenders.

Where Compliance Exposure Hides in Day-to-Day Servicing Operations

The highest-risk compliance gaps are embedded in routine servicing tasks that appear administrative but carry direct legal consequences.

Payment Application and Allocation

Payments must be applied in the order specified by the loan documents—typically: interest first, then principal, then escrow, then fees. Applying a partial payment to fees before interest is a TILA violation and can invalidate the default basis for a foreclosure. Servicers running manual ledgers in spreadsheets make this error regularly without detecting it.

Late Fee Assessment

Late fees must be assessed only after the grace period expires, must not exceed the contractual cap, and must not be assessed on a payment received timely but processed late due to servicer error. Charging a late fee during a grace period or on a disputed payment is an actionable FDCPA and TILA violation.

Payoff Statement Accuracy

A payoff statement must include an accurate per-diem figure, a clear expiration date, and a complete accounting of all fees and charges. A statement that omits a fee or miscalculates per-diem interest exposes the servicer to a TILA claim and delays or invalidates a closing.

Default Notices and Cure Periods

Default notices must cite the specific default, state the cure amount with mathematical precision, and provide the contractually required cure period. A notice that misstates the cure amount or shortens the statutory cure period voids the notice and restarts the clock—adding weeks or months to a foreclosure timeline.

Recordkeeping Gaps

Federal and state law require servicers to retain specific records for defined periods—typically three to seven years depending on the statute. Servicers who cannot produce a complete payment history, copies of all borrower communications, and a transaction ledger on demand are in violation even if every payment was processed correctly. See 10 Record-Keeping Requirements for Private Mortgage Note Servicers for the complete list.

Borrower Communication Failures

Annual escrow analyses, privacy notices, and periodic statements all carry specific delivery windows and required content. Servicers who skip these because the borrower knows the terms are accumulating a violation record with every missed notice cycle.

For a full inventory of the most frequent compliance failures, see 7 Compliance Mistakes Private Lenders Make.

Practical Steps to Eliminate Regulatory Risk

Eliminating compliance exposure requires systematic action across four areas: documentation, process controls, technology, and oversight.

Step 1: Conduct a Compliance Self-Audit

Map every servicing function against its regulatory requirement. Payment application, late fee assessment, notice delivery, recordkeeping, and payoff calculations each need a documented procedure with a named owner and a verification step. The 7 Steps to Streamlined Compliance: A Private Lender’s Self-Audit Guide provides a repeatable framework for this process.

Step 2: Build Written Standard Operating Procedures

Every compliance-sensitive process needs a written SOP that a new employee executes without interpretation. Verbal institutional knowledge is not a compliance control. SOPs must specify the regulatory basis for each step, the required documentation, and the escalation path when an exception occurs. For the core SOPs every servicer needs, see 10 Critical SOPs Every Hard Money Lender Needs for Compliance and Growth.

Step 3: Implement a Compliance Calendar

Annual privacy notices, escrow analyses, and license renewals all have fixed calendar windows. A missed window is an automatic violation regardless of intent. Build a compliance calendar with advance alerts at 60, 30, and 7 days before each required action.

Step 4: Verify State Licensing Status for Every Active Loan

For each note in the portfolio, confirm whether the state of the property requires a servicer license. If it does, confirm the license is active, bonded, and current. A license obtained years ago is not automatically still valid—many states impose annual renewal requirements with continuing education components.

Step 5: Establish a Qualified Written Request Protocol

RESPA’s QWR response requirements are among the most frequently triggered borrower claims in private mortgage servicing. Build a written intake process for any borrower request submitted in writing, a logging system that timestamps receipt, and a response workflow that meets the statutory deadlines without exception.

Step 6: Run Periodic Compliance Checkpoints

Compliance is not a one-time fix. Build a quarterly review process that checks payment application accuracy, notice delivery logs, fee assessment records, and state licensing status. For a structured checkpoint framework, see 9 Compliance Checkpoints for Private Mortgage Loan Servicers in 2026.

When to Transfer Servicing to a Specialized Servicer

Self-managed servicing reaches a compliance breaking point when portfolio size, geographic spread, or operational complexity exceeds what an in-house team executes within regulatory requirements.

The indicators that a transfer is warranted include: notes secured by properties in more than two states (triggering multiple licensing regimes simultaneously), portfolios with more than fifteen active loans (where manual recordkeeping error rates become statistically certain), any loan that has entered default or cure proceedings (where FDCPA, TILA, and state foreclosure notice requirements converge), and any situation where the servicer lacks a documented SOP for each required function.

A specialized private mortgage servicer brings active licenses across multiple states, purpose-built servicing software with audit trails, and institutional compliance programs built around the specific regulations that apply to private notes. The transfer eliminates the servicer’s personal regulatory exposure and produces a more accurate payment record than any manual system.

For an overview of how automation within a specialized servicing environment addresses these risks, see Achieving Compliant Growth: How Automation Transforms Private Lending Servicing.

Building Policies That Sustain Compliance Over Time

Compliance policies require a written governance structure—not just individual procedures—to survive staff turnover, portfolio growth, and regulatory change.

A compliant servicing policy manual covers: borrower communication standards and response timelines, payment processing and allocation rules, late fee and default notice procedures, escrow administration and analysis schedules, data security and GLBA Safeguards Rule controls, and recordkeeping retention schedules tied to each applicable statute.

Policies that exist only in email chains or in a single employee’s memory are not policies—they are undocumented practices that do not survive a regulatory examination or a borrower lawsuit. For the essential policy components, see Achieve Rock-Solid Compliance: 8 Essential Policies for Private Lenders and 7 Essential Policies for New Private Lender Compliance Manuals.

Proactive disclosure practices—delivering required notices before borrowers ask—reduce litigation risk by establishing a documented compliance record before any dispute arises. For the data on how proactive disclosure changes borrower claims outcomes, see 30% Less Litigation Risk: Proactive Disclosure for Private Lenders.

Expert Take

The compliance risk in private mortgage note servicing is not theoretical—it materializes in real enforcement actions and borrower lawsuits, sometimes years after the original servicing error occurred. Most self-managing lenders are not aware of their exposure until they are in litigation or facing a state examination. The servicers who avoid that outcome treat compliance as an operational system, not a one-time checklist. That means written procedures, documented notices, accurate ledgers, and either the licensed infrastructure to back it up or a specialized servicer who already has it.

Frequently Asked Questions

Do federal mortgage regulations apply to private lenders who hold their own notes?

Federal mortgage regulations apply to private lenders who hold and service their own notes in most circumstances. TILA, RESPA, GLBA, and FDCPA each have coverage thresholds and definitions that reach private individuals and entities collecting payments on residential mortgage notes—not just banks and licensed mortgage companies. The specific exemptions are narrow and require careful legal analysis of each lender’s facts.

What triggers FDCPA liability in private mortgage servicing?

FDCPA liability in private mortgage servicing is triggered when a servicer acquires a loan in default at the time of transfer, or when a servicer uses collection communications—calls, letters, or notices—that do not comply with the statute’s content, timing, and validation requirements. The servicer’s intent is irrelevant; the statute imposes strict liability for covered communications.

How do state licensing requirements affect private mortgage note buyers?

State licensing requirements affect private mortgage note buyers by imposing servicing license obligations at the moment the buyer begins collecting payments—even a single payment—on a residential mortgage note secured by property in a licensing state. Purchasing the note does not transfer the prior servicer’s license; the buyer must hold its own active license for each state where a secured property is located.

What is a qualified written request and how long does a servicer have to respond?

A qualified written request is a written borrower correspondence that identifies the borrower, the loan, and a specific question or dispute about the servicing of that loan. Under RESPA Section 6, a servicer has five business days to acknowledge receipt and thirty business days to provide a substantive written response. The timelines are statutory and cannot be waived by contract.

When does it make sense to hire a third-party servicer for a private mortgage note?

Hiring a third-party servicer makes sense when a portfolio spans multiple states, when any loan enters default, when in-house recordkeeping cannot produce a complete and auditable payment history on demand, or when the volume of servicing functions exceeds what a self-managed team executes accurately and on schedule. The compliance infrastructure required for correct private note servicing—state licenses, purpose-built software, documented SOPs, trained staff—represents a fixed overhead that specialized servicers spread across many loans.

Share This Story, Choose Your Platform!

Disclaimer

The information provided in this article is for general educational and informational purposes only and does not constitute legal, financial, investment, tax, or professional advice. Note Servicing Center, Inc. is a licensed loan servicer and does not provide legal counsel, investment recommendations, or financial planning services. Reading this content does not create an attorney-client, fiduciary, or advisory relationship of any kind. Nothing in this article constitutes an offer to sell, a solicitation of an offer to buy, or a recommendation regarding any security, promissory note, mortgage note, fractional interest, or other investment product. Any references to notes, yields, returns, or investment structures are illustrative and educational only. Past performance is not indicative of future results, and all investments involve risk, including the potential loss of principal. Note investing, real estate transactions, and lending activities are subject to federal, state, and local laws that vary by jurisdiction and change over time. Before making any decision based on the information in this article, you should consult with a qualified attorney, licensed financial advisor, certified public accountant, or other appropriate professional who can evaluate your specific circumstances. Some articles on this site include hypothetical stories, examples, and scenarios created to illustrate concepts and demonstrate the types of situations Note Servicing Center, Inc. handles. Any names, companies, properties, and circumstances in these examples are fictitious or have been anonymized to protect confidentiality, and any resemblance to actual persons or entities is coincidental. These examples do not describe specific clients and do not guarantee any particular outcome. Some content may be created with the assistance of generative AI tools and may contain errors or omissions. While we make reasonable efforts to ensure the accuracy of the information presented, Note Servicing Center, Inc. makes no warranties or representations regarding the completeness, accuracy, or current applicability of any content. We disclaim all liability for actions taken or not taken in reliance on this article.