Picture the moment the file lands on the aggregator's desk. The loan looks fine. Mid-balance borrower, two years of tax returns, a business narrative letter that nobody has reason to distrust. The due diligence vendor has already graded it, found nothing worth pulling into the sample, and moved on. Somewhere upstream, an error is settling into the pool like sediment, and every hand the loan passes through is, in its own way, looking at the wrong thing.

That is the quiet problem at the centre of wholesale mortgage securitisation: the chain of hands a loan passes through before it reaches a bond investor does not merely move credit risk along. It actively filters what any single auditor in that chain is positioned to see. The errors that survive are not the ones that slipped through a crack. They are the ones the architecture was never built to catch.

The chain, briefly, before we get to what breaks inside it

Wholesale mortgage origination begins not with a bank's own loan officers but with an independent broker or correspondent lender. The broker takes the application, collects the documents, and often performs an initial underwrite. That file then moves to a wholesale lender, which funds the loan, applies its own credit overlay, and books the asset on its balance sheet, sometimes for a matter of weeks. From there, an aggregator (often a large bank or mortgage company) purchases pools of loans from multiple wholesale lenders, performs its own diligence, and sells those pools into a securitisation trust. The trust issues tranched bonds to capital market investors. A servicer, who may be entirely separate from every other party, then handles collections and loss mitigation for the life of the bonds.

Five entities, sometimes more. Each with its own compliance function, its own audit scope, its own contractual definition of what it bought and sold.

That last detail is where it starts to get interesting.

What each auditor's contract actually lets them look at

Every transfer in the chain is governed by a purchase and sale agreement that defines representations and warranties: the seller's promises about the quality of what it sold. Auditors at each stage are, in practice, checking compliance with those representations. They are not conducting a free-ranging investigation of the loan's history. They are verifying that the thing they received matches the description on the label.

Consider a specific scenario. A broker submits a borrower's income as self-employment income, supported by two years of tax returns. The wholesale lender's underwriter approves the loan under guidelines that require a two-year self-employment history. What the underwriter does not catch, because the file presents cleanly on its face, is that the borrower incorporated the business eleven months before the application date and backdated the start of operations in the narrative letter. The tax returns are genuine. The business history is not.

The wholesale lender sells the loan to an aggregator. The aggregator's due diligence vendor re-underwrites a sample of the pool, typically ten to twenty-five percent of loans by count, weighted toward higher-balance or flagged files. This loan is mid-balance, unremarkable, and it falls outside the sample. The aggregator's representations to the trust state that the loans were originated in material compliance with the originator's guidelines. That representation is technically supportable: the wholesale lender did follow its own guidelines, because the guidelines only required verified tax returns, not independent corroboration of business inception dates.

The trust's auditor, reviewing pool-level data tapes for the bond offering, sees a performing loan with a clean origination code. There is nothing to flag. The error, which was always a fraud risk, has now passed through four sets of eyes and been laundered into a performing asset.

The sampling problem is worse than the industry admits

Due diligence sampling in securitisation is not random in the statistical sense most people assume. Vendors typically grade each loan on an A-through-C scale and report kick-out rates (loans rejected from the pool for material defects) as a percentage of sampled loans. A pool with a two-percent kick-out rate on a twenty-percent sample is generally considered clean. But that math embeds a significant assumption: that the sampled loans are representative of the unsampled ones.

They are not, structurally. Aggregators and their due diligence vendors use risk-based sampling, which means higher-scrutiny loans get sampled at higher rates. A loan with a high loan-to-value ratio, a borrower with a thin credit file, or a property in a flagged geography is more likely to be pulled into the sample. A mid-balance, apparently clean loan with a subtle documentation problem in an unremarkable market is the one most likely to stay in the unsampled seventy-five percent. The errors that survive are not random. They are systematically the errors that look like clean loans from the outside.

There is a compounding factor. Kick-out rates are reported to the issuer, not to the ultimate bond investor in any granular form. The offering documents disclose that due diligence was performed and that a certain percentage of loans were reviewed. The specific defect categories, the geographic clustering of exceptions, the identity of the brokers who originated the kicked loans: none of that typically appears in the prospectus. An investor buying the senior tranche has no way to infer where the remaining risk is concentrated. This is not a technical oversight. It is a disclosure framework that was designed around the interests of issuers, and it shows.

The servicer sees everything, reports almost none of it

The servicer's position in the chain is genuinely underappreciated by everyone outside the industry, and by a surprising number of people inside it. Worth dwelling on.

The servicer is the only party in the entire securitisation structure that maintains a live relationship with the borrower after closing. When a loan goes sixty days delinquent, the servicer's loss mitigation team calls the borrower, requests updated financial documents, and begins building a workout file. In doing so, it frequently discovers things the origination chain never surfaced: the borrower's actual income at the time of application, the real ownership history of the property, whether the stated occupancy was ever genuine.

A servicer working a defaulted loan on a pool originated through a particular wholesale channel may find, across dozens of files, that a consistent pattern of income overstatement traces back to two or three brokers. It has, in effect, discovered a systemic origination defect. What does it do with that information?

The answer depends entirely on who owns the servicing rights and what the pooling and servicing agreement requires. Most such agreements require the servicer to notify the trust's trustee of any discovered breach of representation and warranty that it believes is material and that it believes has not been cured. The servicer is also generally required to act in the best interests of the certificateholders. But the servicer is not required to conduct an affirmative audit of its own portfolio to discover breaches. Its obligation is reactive, not investigative.

So the pattern sits in the servicer's loss mitigation files, visible to workout analysts who have no mandate to escalate it as a systemic origination finding, and invisible to the trustee who has no visibility into individual workout conversations. A diligent servicer with good internal governance might connect those dots. A servicer operating under cost pressure, handling hundreds of thousands of loans across dozens of trusts, almost certainly will not. The structure, in this respect, functions less like a compliance system and more like a filing cabinet that nobody is required to open.

There is a name for the mechanism that is supposed to catch this: the representations and warranties repurchase process, under which a trust can force the originator to buy back a defective loan at par. But repurchase demands require the trustee to have specific, documented evidence of a breach. The evidence is in the servicer's files. The servicer reports to the trustee. The trustee does not know to ask for the specific files. The loop does not close.

Senior tranche investors are insulated. Everyone below them is not.

The tranching structure of a mortgage-backed security provides real protection to senior bondholders, and genuinely weaker protection to mezzanine and subordinate investors than the offering documents tend to communicate. Origination errors that cluster in the bottom twenty percent of a pool by credit quality will eat through subordinate tranches before they touch the AAA certificates. Those subordinate tranches are also, not coincidentally, the ones held by investors with the least legal firepower to pursue repurchase claims.

Ask yourself: what does a diligent junior investor actually do? The honest answer is that the tools available, loan-level data tapes, servicer reports, trustee remittance reports, are sufficient to identify anomalies in aggregate performance but rarely sufficient to prove a specific origination breach. You can see that a pool is underperforming its initial credit model by thirty percent. Proving that underperformance is attributable to a specific, contractually actionable misrepresentation rather than to macroeconomic factors requires access to original loan files that only the servicer and trustee hold.

The structure places the evidence with the party that has the weakest incentive to surface it, and the legal standing with the party that lacks the evidence. This is not an accidental symmetry.

The audit that would actually work

A genuinely effective audit of a wholesale mortgage securitisation chain would need to span the entire origination-to-servicing lifecycle, with access rights that follow the loan rather than stopping at each contractual boundary. It would require sampling logic designed to find clean-looking errors, not just flagged ones: sampling by originating broker concentration, by geographic cluster, by the variance between application-stated income and post-default verified income across matched cohorts.

None of that is standard. Some of it is technically possible under existing pooling and servicing agreement frameworks, if a sufficiently large certificateholder demanded it. The reason it does not happen routinely is the same reason most structural problems persist across many industries and many eras: the cost of the audit falls on the party demanding it, and the benefit accrues to the pool as a whole.

That is not a scandal. It is a collective action problem dressed in legal documentation. The errors do not hide because anyone is hiding them. They hide because the structure was designed to move loans efficiently, and efficiency, in document chains as in plumbing, tends to mean that what flows through fastest is whatever encounters the least resistance. The question of who eventually pays for that efficiency is, as ever, answered only after the pressure builds somewhere downstream.