E3
Compliance and regulation

Government Lending: Where the Severity of a Defect Depends on the Quality of Your Review

Shailesh Bhujbal·5 min read·Published 7 September 2026·Last reviewed 8 September 2026


Government lending programmes are usually explained by their eligibility rules, who qualifies for FHA, what a VA entitlement covers, which areas USDA serves. Those rules matter, and they are documented at length elsewhere.

FIGURE 1Government lending requirements stackEach layer narrows what applies, and the narrowest layer is the least visible.Federal consumer complianceTRID · ATR/QM · HOEPA · HMDA · RESPA · Reg BAgency programme requirementsFHA · VA · USDA eligibility and documentationProduct-level logic203(k) · manual underwrite · streamline refinanceConditional requirementsapply only when two or more conditions holdstack,they do notreplaceThe bottom layer is where checklists fail: a requirement in scope only because two other conditions are both true.Which rules a file brings into scope is a function of programme, property, occupancy and borrower characteristics.
Figure 1 Government lending requirements stack

There is a more consequential feature of government lending that receives far less attention, and it sits inside FHA's approach to defects. It is worth understanding because it inverts a common assumption: in government lending, the severity assigned to a defect is not determined solely by the defect. It is determined partly by what your process should have caught.

That has a direct implication for how a lender's quality control programme is valued, and it is not an implication most vendors discuss.

The taxonomy, and the words that carry the weight

FHA's Defect Taxonomy, Appendix 8.0 of Handbook 4000.1, in the version effective for Title II loan reviews initiated on or after 15 January 2025: draws a distinction that is easy to read past. A defect is any deviation from HUD policy requirements by a mortgagee or other participant, regardless of severity. A finding is FHA's determination that a defect exists. [1]

Underwriting loan reviews are organised into nine defect areas spanning origination, underwriting, closing and endorsement. [1] Each finding is then assigned one of four severity tiers, based on the size and nature of the deviation.

The tier definitions are where it becomes interesting.

A Tier 1 finding, in the fraud and material misrepresentation context, is one the mortgagee knew or should have known about. A Tier 4 finding is one the mortgagee did not know and could not have known about. Tiers 2 and 3 occupy the space between, defined by reference to specific examples of mortgagee conduct. Tier 1 and Tier 2 findings are unacceptable, require a mortgagee response, and generally align with the definition of a material finding. [1]

Why "should have known" changes the calculus

Read those two poles together. The same underlying defect: the same misrepresented fact in the same file: can be a Tier 1 finding or a Tier 4 finding depending on whether the mortgagee should have detected it.

"Should have known" is a standard about process. It asks what a reasonably diligent review would have surfaced. A lender whose review process would plainly have caught something, had it been performed properly, is in a materially different position from a lender facing something genuinely undetectable at origination.

This means a government lender's quality control programme is not only a control against defects. It is part of how the consequences of a defect are determined once one is found.

Two lenders can originate identically flawed loans and be in different evidentiary positions, because one can demonstrate a documented, consistently applied review and the other cannot demonstrate anything about how the file was reviewed at all.

Be careful about how far that goes. Documentation does not by itself determine the remedy. Tier assignment turns on the nature of the defect and on what the mortgagee knew or should have known; evidence of a sound review is relevant to that assessment, not decisive in it, and a well-documented process does not convert a Tier 1 finding into a Tier 4 one. What good evidence reliably does is let you participate in the determination rather than concede it. This framework is also specific to FHA, VA and USDA operate their own review and remedy structures, and nothing here transfers to them automatically. [1]

What "demonstrate" requires in practice

If process quality bears on tier, then the process must be evidenced. That is a higher bar than performing the review.

Rules must be written and versioned. Showing that a file was assessed under the requirements in force at the time is only possible if the rules were recorded with effective dates. "We have always checked that" is not a demonstration.

Findings must carry their reasoning. Which documents were compared, which values were read from each, which rule was applied, why it failed. A finding that cannot be reconstructed cannot evidence diligence.

Coverage must be describable. Which files were reviewed, under which sampling approach, and what was examined in each. A lender arguing that a defect could not have been detected needs to show what its review actually looked at.

Absences must be as legible as findings. Where a rule was applied and passed, that should be recorded. Demonstrating that a check ran and produced no finding is the substance of an argument that the process was sound, and it is precisely what most review programmes fail to retain.

The categories most exposed

Compliance findings sit awkwardly here. Legal, Regulatory and Compliance is currently the leading critical defect category across the wider industry at 24.66% of findings. [2] These are largely relational tests, a date against a date, a figure against a tolerance, which means they are both highly detectable by a process designed to look for them and, by the same token, difficult to characterise as something a diligent reviewer could not have found.

Put plainly: a relational compliance defect is a poor candidate for the argument that nobody could reasonably have caught it. The test was mechanical. Either the process performed it or it did not.

The borrower behind the taxonomy

Government lending programmes exist to extend credit to borrowers who would otherwise struggle to obtain it: lower down payments, more flexible qualifying, and in VA's case an entitlement earned through service.

That population has the least margin for a loan that should not have closed on those terms. The defect taxonomy is, read one way, an accountability mechanism between FHA and its mortgagees. Read another way, it is the mechanism by which someone is answerable for whether a borrower with limited alternatives was placed in a loan correctly.

A quality control programme that can show its work serves both readings at once.

Sources

  1. FHA Defect Taxonomy, Appendix 8.0 to Handbook 4000.1, attachment to Mortgagee Letter 2025-01, for Title II loan reviews initiated on or after 15 January 2025. HUD now lists that letter as incorporated into superseding handbook policy: verify tier definitions against the current Single Family Housing Policy Handbook 4000.1. These definitions are specific to FHA review and differ from Fannie Mae remedies terminology.
  2. ACES Quality Management, Mortgage QC Industry Trends Report, Q4 and CY 2025. Critical defect rate 1.50% for CY 2025 against 1.52% for CY 2024. Category figures are shares of critical defects, not defect incidence, and are drawn from the report's sample of reviewed loans.

See a finding taken apart.

See how each value was read, which rule was applied, and what the record looks like later.