compliance in mortgage marketing checklist for loan officers

Short answer: compliance in mortgage marketing means three things done consistently — you have documented consent before you call or text a lead (TCPA), your ads and landing pages don’t misstate loan terms (Regulation N, the MAP Rule), and you can produce records showing both if the CFPB, FTC, or a plaintiff’s attorney ever asks. None of it is complicated in isolation. It gets missed because marketing moves fast and compliance paperwork doesn’t feel urgent — until a $500-per-text TCPA claim shows up from a list you bought without checking how consent was collected.

What does “compliance in mortgage marketing” actually cover?

For a loan officer, it boils down to two federal regimes that touch almost everything you do to generate and follow up with leads: the Telephone Consumer Protection Act (TCPA), which governs calls and texts, and Regulation N (the CFPB/FTC “MAP Rule,” 12 CFR Part 1014), which governs what your ads, landing pages, and social posts are allowed to claim about rates, terms, and savings. A third layer — state-level telemarketing and do-not-call rules — can be stricter than the federal floor in states like Florida, Washington, Oklahoma, and California, so “federally compliant” isn’t automatically “compliant everywhere you market.”

None of this requires a compliance department. It requires knowing which channel you’re using, what consent or disclosure that channel requires, and keeping a record of both.

Do you need consent before calling or texting a lead?

Yes for texts and most automated or prerecorded calls — and the rules here shifted in a way a lot of vendor marketing hasn’t caught up to. The FCC’s 2023 “one-to-one consent” rule, which would have required a separate signed consent for every individual company contacting a lead, was vacated by the Eleventh Circuit in January 2025 and the FCC did not appeal. That means the standard reverted to the prior prior express written consent framework: a signed (including e-signed) agreement naming the seller who may contact the lead, at the number given, using an autodialer or prerecorded voice.

The practical takeaway for a loan officer buying leads: “one-to-one consent” is no longer the bar the FCC enforces, but it’s still worth asking your lead vendor exactly what consent language the consumer agreed to and whether it names you (or lenders “like you”) specifically. Vague or recycled consent is still the single most common source of TCPA exposure — violations commonly run $500 to $1,500 per call or text, and they add up fast on a list of a few hundred numbers. Scrubbing new numbers against the National Do Not Call Registry before a live cold call is a second, separate check — DNC and TCPA consent are not the same requirement.

What can’t you say in a mortgage ad?

Regulation N prohibits any “material misrepresentation” about a mortgage credit product in a commercial communication — and it’s broader than most loan officers assume. It covers your website, paid ads, social posts, direct mail, and email, not just formal rate sheets. The most common violations aren’t outright lies; they’re omissions:

Each misstatement is independently actionable — meaning one ad with two problems can be two violations. The CFPB and FTC share enforcement and coordinate under a formal agreement, and Regulation N requires covered persons to keep copies of materially different ad content and the product terms behind it for 24 months from last use (12 CFR Part 1014). If you can’t produce the ad and the rate sheet that supported it two years later, that’s its own gap.

Are purchased and trigger leads still fair game?

Purchased internet leads are still standard practice and not a compliance problem by themselves — the consent question above is what matters, not the fact that you bought the list. Credit-bureau trigger leads are a different story: as covered in our trigger-leads breakdown, the sale of trigger leads to anyone other than the consumer’s current lender or servicer is now banned under the Homebuyers Privacy Protection Act. If a vendor is still offering to sell you “prescreened” trigger leads pulled mid-application, that’s the flag to walk away, not negotiate price on.

What records do you actually need to keep?

Three things, in practice: (1) the consent language and timestamp for every number you call or text, tied to the source that generated the lead; (2) a copy of every materially different ad or landing page, next to the loan terms it referenced, kept for at least 24 months; and (3) a DNC-scrub log for cold outbound calling. A CRM that timestamps lead source and every call/text automatically is doing most of this by default — that’s baseline CRM hygiene worth confirming your platform actually does, not a mortgage-specific feature to shop for separately.

Quick-reference: what applies where

Channel Governing rule What it requires Typical exposure if you skip it
Texting a purchased lead TCPA Prior express written consent naming the sender Commonly quoted $500–$1,500 per text
Cold calling TCPA + DNC Number not on the National DNC Registry (or an established relationship exception applies) Per-call penalties, DNC complaint exposure
Rate/payment ads, landing pages, social posts Regulation N (MAP Rule) No material misrepresentation of terms; required disclosures present CFPB/FTC enforcement action, per-violation
Ad archives Regulation N recordkeeping Keep materially different ads + underlying terms 24 months Inability to defend a claim on request
Credit-bureau trigger leads Homebuyers Privacy Protection Act Sale restricted to the consumer’s current lender/servicer List itself may now be an illegal product

How does the CRM keep you honest by default?

The least glamorous compliance win is also the most reliable one: use the CRM as your system of record instead of a mix of spreadsheets, a dialer app, and your phone’s native texting. When lead capture, call logs, and text history all live in one place tied to the lead’s original source, you’re not reconstructing consent and contact history from memory when a question comes up — it’s already there. That matters most for loan officers generating leads across several channels at once, where it’s easy to lose track of which list came with which consent language.

The same discipline applies before you commit budget to a source. If you’re evaluating whether to keep buying mortgage leads from a given vendor, ask for their consent language in writing before the first purchase, not after a complaint. For the rest of your channel mix, the loan officer marketing hub breaks down compliance considerations by channel — social, email, direct mail, and referrals each have their own wrinkle, and the full playbook is the faster way to check yours than re-deriving it channel by channel.

Key takeaways

FAQ

Do I need a compliance officer to market legally as a loan officer?

No. Most compliance failures in mortgage marketing come from missing consent records or an ad that overstates terms — both are process fixes (consistent CRM logging, a second read on ad copy before it runs), not a hire.

Is it illegal to text a lead who filled out a form on a lead-generation website?

Not by itself — it depends on what consent language they agreed to and whether it names the companies that may contact them. Ask your lead vendor for that language before you buy, and keep a copy.

Can I say “as low as X%” in an ad?

Only with the required disclosures for the terms behind that rate — Regulation N treats a rate claim without its qualifying terms as a potential material misrepresentation. When in doubt, quote your own current, verified numbers only and skip competitor rate comparisons entirely.

Are trigger leads the same thing as purchased internet leads?

No. Trigger leads come from a credit bureau flagging that a consumer applied for credit elsewhere; their sale to anyone but the consumer’s existing lender or servicer is now banned. Ordinary purchased internet leads (someone filled out a form) are a separate, still-legal category — consent is the question there, not the source itself.

Do state rules ever override the federal TCPA floor?

Yes — several states, including Florida, Washington, Oklahoma, and California, have telemarketing or consent rules stricter than federal TCPA. If you market across state lines, the strictest rule that applies to a given lead’s state is the one to follow for that lead.