The ITRE Review / Mortgage
Protecting Borrower Data: Security for Mortgage Brokers
How mortgage brokers can safeguard income, identity and credit information while keeping applications moving quickly.
Mortgage brokers hold some of the most sensitive information that any professional collects: income documents, tax returns, identification, credit data and details of a client's financial life. They also work to short timelines and exchange documents constantly with lenders, appraisers and lawyers. This article outlines a practical approach to protecting borrower information without slowing the file down.
Stop sending documents as ordinary attachments
The most common weakness is also the easiest to fix. Borrowers email photographs of identification and statements, and brokers forward them. Each copy lives in several mailboxes, indefinitely. A secure document-request portal lets the borrower upload once, directly into an access-controlled file, with a record of what was received.
The portal need not be elaborate. Many existing platforms, including Microsoft 365, offer secure file-request features, and some origination systems include portals. The decisive step is to choose one and make it the default.
Control the devices that hold files
Brokers work from laptops and phones in cafes, cars and borrowers' kitchens. Every device that touches client files should be encrypted, protected by a screen lock and enrolled in management so that it can be locked or wiped if lost. Keep client files in the managed cloud, not in downloads folders.
For brokerages with independent agents using personal devices, app protection on phones separates client data from personal content without intrusive control.
Phishing aimed at the lending chain
Brokers are a convenient route to lenders, and lenders are a convenient route to funds. Criminals send convincing messages that appear to come from underwriters, lawyers or appraisers, often with updated payment or document instructions. Multi-factor authentication, mail filtering and a habit of verifying unusual requests by phone are the main defences.
Treat lender portals with the same care as bank accounts. Individual credentials, not shared ones, and immediate removal of access when a staff member leaves, are non-negotiable.
Know your obligations and record them
Mortgage brokers in British Columbia operate under the Mortgage Brokers Act and BCFSA oversight, and certain brokers have FINTRAC obligations. Privacy law, including BC PIPA, requires reasonable safeguards for personal information. We do not give legal advice, but we implement the systems your counsel or compliance lead specifies.
A written retention schedule, followed in practice, is the simplest way to demonstrate care. Application records should be retained for the period required and then securely disposed of, with a record of disposal.
Prepare for the bad day
Have a short incident plan. It should list who to call, how to isolate a compromised account, which lenders and clients to notify and how to preserve evidence. The plan fits on one page, and it is worth rehearsing once a year.
Back up client files in a way that cannot be encrypted by ransomware, and test restoring a file. A broker who can restore a client's file in minutes after a laptop failure is a broker whose clients will not notice the incident.
Common mistakes we see
The most widespread mistake is leaving borrower documents in the inbox and downloads folder indefinitely. Months later, a laptop theft turns into a notifiable privacy incident. The remedy is a routine: documents go to the secure file, and the email is deleted or archived.
Another is shared logins for lender portals, which prevent anyone from showing who submitted what. Brokers also rely on personal phones without protection, then lose one. Finally, many brokers assume an email that looks like it came from an underwriter is genuine. A moment of verification by phone is slower than clicking, and faster than recovering from fraud.
Checklist to take to your next meeting
- Secure document-request portal as the default route
- Encrypted, managed devices with remote wipe
- Multi-factor authentication on mail and lender portals
- Call-back verification for unusual lender or payment requests
- Written retention and disposal schedule
- One-page incident plan rehearsed annually
Where this fits in your technology plan
Guidance works best as part of a coordinated programme rather than a one-off fix. These ITRE services address the subject directly.
- 01VoIP for Real Estate Teams
VoIP for Real Estate Teams replaces the aging office phone system with a cloud service that works on desk phones, laptops and agent mobiles, and integrates with your CRM so that every conversation is logged against the right contact.
- 02Device Management for Agents
Device Management for Agents establishes a respectful but firm standard for the equipment that touches brokerage data: enrolment, encryption, updates and remote wipe, with a clear separation between personal and brokerage content on agent-owned phones.
- 03Brokerage Cybersecurity Audits
A Brokerage Cybersecurity Audit examines identity, email, devices, backups, networks, vendors and people, and reports on where your brokerage stands relative to a defensible baseline. It is fixed in scope and price, and written so the managing broker or owner can act on it.
Further reading
- 01Strata Data Governance in BC: Records, Owners and Privacy
A practical guide for strata councils and managers on keeping records safe, accessible and handled in line with BC privacy law.
- 02When an Agent Leaves: An Offboarding Checklist for Brokerages
A step-by-step approach to ending access, recovering files and protecting client information when a licensee departs.
- 03FINTRAC Record Keeping for Real Estate Firms: The Technology Side
How brokerages and developers can build systems that make FINTRAC record keeping reliable, searchable and defensible.
Take it to your next leadership meeting
Guidance is only useful when someone acts on it. If this article raised questions about your own office, development or portfolio, bring the checklist above to your next leadership meeting and assign an owner to each item. ITRE offers a free thirty-minute consultation to help you decide what to do first and what can wait.
Speak with an advisor
To discuss any of this in the context of your business, call (604) 632-4959 or write to info@SAZ.ca. You will speak with a senior advisor, and the guidance on this site is reviewed by Ali Sedighi, MBA. There is no obligation, no lock-in and no sales script.
Questions and answers
- Can borrowers still email documents?
- They may, but a secure upload link is safer and often more convenient. Make it the default and discourage attachments in your onboarding messages.
- Do mortgage brokers need FINTRAC compliance?
- Obligations depend on the activity and registration of the business. Your compliance advisor or lawyer should confirm. We implement the supporting systems.
- What if an agent uses a personal phone?
- Use mobile application management to protect brokerage data on the phone without taking control of the whole device.
- How long do application records need to be kept?
- Retention depends on legal and regulatory requirements and on your own policy. We set up schedules to the periods you specify and log disposal.
- How much does a security review cost?
- A broker security assessment starts at $1,900 and includes a prioritised action list suitable for a brokerage owner.