Skip to content

Form SSA-89 for mortgage lenders

Form SSA-89 is the borrower consent that lets a lender ask the Social Security Administration whether a name, Social Security number and date of birth match. It is a narrow control, and it is routinely asked to prove more than it can.

What the operating record should preserve

Preserve the source

Keep the population, file evidence, and controlling guidance available beside the review.

Reperform the control

Store the inputs, method, rule version, and result another qualified reviewer would need.

Own the conclusion

Keep materiality, rationale, disposition, and corrective action with the accountable reviewer.

Confirm the current form and consent period before you use this. SSA republishes the SSA-89 periodically and the validity language sits on the form itself. Your fraud policy, not this page, decides when the control is required.

What the form is for

The SSA-89 is the number holder’s written authorization for SSA to release a Social Security number verification to a named company. The company submits the name, SSN and date of birth it has on file. SSA responds with whether those elements match its records, and whether its records show the number holder as deceased.

That is the whole product. There is no earnings statement, no benefit amount, no address history. Two service channels exist: Consent Based Social Security Number Verification for enrolled companies, and the electronic eCBSV service established for permitted entities. Most lenders reach one of them through a credit reporting or verification vendor rather than directly.

Completing the form

BlockWhat it holdsWhere it goes wrong
Company name and addressThe company authorized to receive the verificationLeft blank, or naming the broker when the vendor of record is the enrolled company
Number holder nameName as shown on the Social Security cardA current married name where SSA still holds the former name
Social Security numberThe full nine digitsTransposed digits, or a number taken from a document rather than the card
Date of birthNumber holder date of birthA typo that produces a no-match on an otherwise clean file
Reason for requestWhy the verification is being soughtGeneric wording that does not describe the actual transaction
Signature and dateNumber holder signature, datedUndated, or dated outside the consent window at the time of submission
WitnessRequired where the number holder signs by markOmitted on a mark signature

The signature must belong to the number holder. Where someone signs on the number holder’s behalf, the authority for that has to be documented in the file, and the acceptable evidence for it is a policy question, not a form question.

Reading the response

Three outcomes matter operationally.

  • Match. The submitted elements agree with SSA records. This closes the specific control and nothing more.
  • No match. One or more elements disagree. The usual cause is a clerical difference, a former name, or a date of birth typo. Resolve and resubmit before treating it as a fraud signal.
  • Deceased indicator. SSA records show the number holder as deceased. This is a stop, not a condition, and it should route to the lender’s fraud escalation path rather than to a processor.

Whatever the outcome, the response itself is the evidence. A vendor screen reporting that a verification was ordered is not the same artifact and should not be filed as if it were.

What post-closing QC tests

  • Policy consistency. The lender’s written policy says when an SSA-89 is required. QC tests whether the loans that met the trigger actually have one, not whether every loan does.
  • Consent validity. Signed, dated, and submitted inside the period stated on the form.
  • Element match to the file. The name, SSN and date of birth submitted are the ones on the application, the credit report and the note. A verification of the wrong data proves nothing.
  • Resolution of a no-match. Where the first response was a no-match, the file shows what changed and what the corrected submission returned.
  • Escalation of a deceased or fraud indicator. Documented, routed to an authorized reviewer, and dispositioned by a person.
  • Red flags linkage. Where the identity theft prevention program treats an SSN discrepancy as a red flag, the file shows the program’s required response, not just the verification.

Common defects

ConditionTypical severityWhy
Trigger met under lender policy, no SSA-89 in fileMaterialA control the lender committed to was skipped
No-match response with no resolution documentedMaterialAn unresolved identity discrepancy at closing
Consent signed outside the validity windowModerateThe verification may not be a valid authorization
Verification run on data that differs from the applicationModerateThe control was performed on the wrong subject
Vendor status screen retained instead of the responseLow to moderateThe result cannot be reperformed from the file

Privacy handling

An SSA-89 is a page with a full Social Security number, a date of birth and a signature on it. It deserves stricter handling than most of the file. Keep it inside role-limited storage, do not reproduce the number in finding text, and make sure the retention schedule that governs it is the one counsel approved rather than a vendor default.

For how a verification like this is tracked from request to response, read the reverification workflow guide, and for the surrounding cycle, the post-closing QC checklist.

Reviewed against primary sources

Keep decisions human and evidence explicit.

Translate guidance into a review record that preserves what happened, who decided, and which source controlled.

Primary references

Confirm requirements against current source material.

Requirements and vendor capabilities change. These sources were reviewed July 31, 2026. Confirm current source material, product scope, commercial terms, and your approved QC plan before changing a production process.

Common questions

What mortgage teams usually ask.

What does Form SSA-89 authorize?

It is the number holder's written consent for the Social Security Administration to verify, to a named company, whether a submitted name, Social Security number and date of birth match SSA records. It authorizes a verification, not a release of the borrower's earnings or benefit history.

Does a match on SSA-89 prove the borrower is who they say they are?

No. A match confirms that the name, SSN and date of birth submitted agree with SSA records. It does not establish that the person presenting them is the number holder. Identity verification is a separate control.

How long is a signed SSA-89 valid?

SSA limits how long consent stays usable after signature, a period commonly cited as 90 days. Confirm the current period on the form itself before submitting an aged authorization, because SSA has changed the wording across revisions.

Is an SSA-89 required on every mortgage loan?

No agency requires it universally. Lenders use it where their own policy, an investor overlay, a red flag identified during processing, or a fraud finding calls for independent SSN verification. What matters in QC is whether the lender followed its own written policy consistently.

From evidence to conclusion

We are building QC software for small lenders.

ExactClose is in development. Tell us how your post-close cycle runs and what it has to produce.

Contact the team See exact pricing