2026 AARMR Conference Recap
The American Association of Residential Mortgage Regulators (AARMR) held its annual conference in Seattle this year. Sessions ran in both directions: regulators presenting for the industry’s benefit, and industry feedback flowing back to regulators. The most useful format, as always, was the Meet Your Regulator breakfast, where you sit down with a specific state’s table and ask the questions you can’t get answered anywhere else.
I want to preface this article with a comment on how thankful I am for our state regulators for all they do for consumers and for their willingness to be true partners to the industry. This conference inevitably comes with some industry scrutiny, tough questions & conversations, and the occasional airing of grievances.
The conference acts as a barometer of where exam findings will likely occur for the next year and where financial institutions should be investing in their Compliance Management System (CMS).
The Strategic Read
Before the state-by-state detail below, the five things worth changing about how you prepare for next year’s exam cycle:
- AI governance is still exploratory almost everywhere: put a documented framework in place now, while the compliance bar is still being set, rather than waiting for a formal exam checklist to exist.
- Social media is the fastest path to a RESPA or advertising finding: event flyers, reused reviews, and “preferred” licensee posts are already being read by examiners as advertising.
- NMLS Consumer Access enforcement is inconsistent state to state: document a defensible, good-faith approach rather than chasing every state’s exact template.
- Falling consumer complaint counts are not a green light: they likely reflect reduced awareness of federal recourse, not fewer underlying problems.
- Centralization is coming through the State Examination System and the Mortgage Compliance Dataset: get ahead of standardized, loan-level exam data by understanding the MCD, or joining its development workgroup, now.
Themes That Spanned Multiple Sessions
Anything raised once at a regulator conference is a topic. Anything raised three times is a supervisory priority forming in real time. By that measure, the following topic themes dominated the time in Seattle:
- Offshore operations: a top theme across the Industry Roundtable, Examination Trends, & Rapid-Fire sessions. Likely the most-discussed policy issue of the conference due to North Carolina’s hard stance on the practice (N.C.G.S. §53-244). In speaking with lenders, many were instead evaluating the use of AI for the same operations functions, such as verification of employment.
- RESPA and Kickbacks: Texas, Minnesota, and North Carolina named RESPA as a current exam focus. North Carolina NCCOB showcased multiple RESPA case exhibits in 2026, including a focus on individual licensees attending realtor events, providing goods or services (including CE courses), with no Marketing Services Agreements (MSA) in place. The states mentioned social media as some of easiest ways to find RESPA concerning relationships. They found event flyers featuring “preferred” licensees, where food & refreshments were offered, and even promotions of free professional headshots.
- Team names, trade names, and DBAs (two sessions): A major Roundtable segment that truly dominated the allotted time that very likely could have been a standalone session. Industry stakeholders noted this was a needlessly complex issue with vast variation from state to state. Regulators, like Ohio, noted that they felt their hands were tied since decisions about business names are truly within the purview of the Secretary of State office. There were discussions around industry committees tackling this issue this year.
- Fraud: noted in both the Examination Trends and Rapid Fire sessions, with insider participation named as what makes current trends most concerning, fraud continued to be a concern for regulators at the state level. It was estimated that 1 in 129 mortgage applications showed signs of fraud in Q1 2026 (source: NCCOB). One case focused on an MLO collecting funds for “credit repair services”.AI was a consistent buzzword at the conference, but mostly appeared not as a governance question but as a fraud vector – such as the sheer number of online companies that advertise altered bank statements as a service.
- Consumer Complaints: quite a few states outlined that uniquely consumer complaints were down compared to years past. When I asked why some regulators thought this was the case, their response was “more stringent state guardrails”. This may be more likely a symptom of the current federal administration – the very public reduction in regulator funding at the federal level has likely reduced education on consumer rights & signals that complaints they report may go unanswered.
The MCD
The Examination Trends panel described the One Company One Exam initiative as expanding and credited the State Examination System (SES) with improving scheduling, communication, and turnaround. Exams were described as increasingly collaborative, but budget pressure was a recurring theme. Agencies under staffing constraints are leaning harder on SES, using multi-state coordination where possible. For example, states known to have more resources and expertise in cybersecurity were a resource to other less well-endowed states.
Underneath all of it sits the Mortgage Compliance Dataset (MCD), whose stated goal is to replace manual file review and random sampling with standardized loan-level data and targeted testing. The MCD is a MISMO (Mortgage Industry Standards Maintenance Organization, a subsidiary of the Mortgage Bankers Association) standard developed in partnership with CSBS (Conference of State Bank Supervisors). Panelists encouraged conference attendees to participate in the Mortgage Compliance Dataset Development Workgroup, which meets twice monthly.
Meet Your Regulator Breakfast
The breakfast format let me move between state tables to pick their brains on specific topics and questions lender partners had sent to me ahead of time to ask on their behalf. I also made it a point to ask the same core questions with each state I spoke to: what marketing gets requested in exams, what the state expects on remote work oversight, and where AI governance stands. For a few select states (WA, VA, IL), I also asked how the at times conflicting NMLS Consumer Access link would be enforced across states. What follows is what each state said.
The individual answers below are the raw data. Read them for the pattern first: four of the six responding states called AI governance exploratory, and only Texas described anything resembling a formal review path, folding it into the cybersecurity portion of its exams. Washington and Virginia also show why the “conflicting states” problem is real: Washington requires no disclosure language beyond the NMLS Consumer Access link, while Virginia layers on a prefix disclosure, though Virginia signaled it will accept a consistent, good-faith format even if it does not match its prescribed layout exactly.
- Washington: Requests marketing used during a typical two-year lookback, and accepts PDFs, screenshots, spreadsheets with URLs, or any organized format. Currently focused on Yelp reviews repurposed as advertising, on the principle that a consumer review becomes an advertisement once reused prominently on a website. Requires the NMLS Consumer Access link, no state specific disclosure language required alongside it. On DBAs and team branding, corporate identity must be more conspicuous than team branding. AI governance remains exploratory, no prescriptive guidance at this time.
- Texas: Performs a review of a sample of social media in exams, but expects lenders to produce names and links for all licensees on request. Incorporates AI governance review through cybersecurity portion of their examinations. On remote work, Texas is not prescriptive about supervision methods but expects lenders to demonstrate supervision for both cybersecurity and physical security, such as expectations that no mail should be received at home offices. Texas uniquely noted that they are using vendor technology as part of their cyber security and AI oversight exam efforts.
- Oregon: Requires remote work oversight for anyone holding a license, regardless of job title, or anyone who touches an OR loan file. Also, anyone with a physical presence in Oregon, including unlicensed staff. Oregon conducts on-site branch visits for new licenses. Recurring findings for marketing include missing NMLS Consumer Access link & SAFE Act disclosures. They warn to be particularly mindful of any unresolved prior exam issues carried into the next cycle – these will come with monetary punitive actions.
- Massachusetts: Runs dedicated targeted CRA examinations on roughly a three-year cycle with a note that many successful lenders partner with a CRA vendor. We discussed marketing tracking for events to demonstrate community outreach. Findings cluster around financial condition, CMS gaps, AML testing lapses, and post-COVID back-to-basics oversight failures. MSAs have been a focus in the past, but they’ve seen a decrease in reporting on this practice. AI governance remains exploratory, no prescriptive guidance at this time.
- Virginia: Requires a prefix disclosure in addition to the standard NMLS Consumer Access requirement. Virginia noted that if the spirit of the law is abided (the same disclosures are presented closely together even if the prescribed layout if slightly different) they would find that acceptable for licensees in conflicting states. AI governance remains exploratory, no prescriptive guidance at this time.
- Kentucky: Performs a review of a sample of social media in exams, but expects lenders to produce names and links for all licensees on request. The state outlined remote work oversight for anyone physically located in Kentucky. AI governance remains exploratory, no prescriptive guidance at this time.
- Arizona and New York: Neither state attended the conference. For lenders licensed in either state, that absence should be treated as a gap in intelligence rather than as agreement with the positions other states took.
Conclusion
Returning home from the AARMR conference, I am reminded that the gap between states is widening in the details, and not the compliance fundamentals. In presenting some of the same questions among states, I received at times different answers on prescribed expectations and even felt distinctions in comfort on specific topics, such as AI governance. Seattle made clear that the next exam cycle will be shaped less by new rules than by sharper attention to old ones. RESPA, fraud, marketing, and remote work oversight are not novel, but regulators are getting better at finding problems, and social media has become their most efficient starting point.
My advice to lenders is to treat these state-by-state answers as a checklist against your own CMS: confirm you can produce a state-divided marketing inventory on demand, document your remote work supervision before someone asks for it, and solidify your AI governance framework while the majority of states are still in the exploratory phase. The regulators in the room were open, candid, and willing to partner. That openness is an invitation to get ahead of these issues, not a reason to assume you already have.