What Does It Cost to Build a Loan Origination Platform
For: A founder or COO at a non-bank lender, CDFI, or specialty finance company with $5M–$50M in annual originations who has outgrown a spreadsheet-and-email workflow and is deciding whether to license an LOS like Encompass or build a custom platform — without understanding what the compliance surface (TILA, RESPA, ECOA, state licensing) actually adds to a custom build
A custom loan origination platform for a non-bank lender running $5M–$50M in annual originations typically lands in a wide range: $500K to $2M+ to reach production, on an 18–36 month timeline, with three-year total cost of ownership commonly running $2M–$5M once maintenance and compliance updates are priced in. The reason quotes vary by 3x for the same brief is almost always the disclosure and document generation layer — TILA, RESPA, HMDA, state licensing, and now Section 1071 — which most vendors either exclude or bury in a one-line 'compliance module.' That layer alone tends to consume 30–40% of the build.
This post breaks down where the money actually goes, why the range is a range, and what specifics you need to have decided before any quote you receive is worth comparing.
Why the number is a range, not a figure
Two lenders can describe what sounds like the same platform — borrower portal, decisioning engine, servicing handoff — and get quotes that differ by a factor of three. The gap almost never comes from the parts you can point at. It comes from four things buyers rarely scope up front:
- Which loan products. A single-product consumer installment platform is a different animal from one that has to handle small business term loans, lines of credit, and merchant cash advances in the same origination flow. Each product carries its own disclosure set and its own underwriting model.
- Which states. Lending in five states is not five times the compliance work of lending in one — the first state is the expensive one, but every additional state adds licensing rules, rate caps, and disclosure variants that the document engine has to know about.
- Which regulatory regimes apply today, and which apply in 24 months. A platform designed in 2025 that ignores the CFPB's Section 1071 compliance date of January 1, 2028 will need a data-collection retrofit before it goes live.
- How much of the existing stack has to keep running. Migrating an active loan tape from a legacy servicer or spreadsheet system, without breaking payment schedules or reporting continuity, is often 15–25% of the whole engagement.
The upshot: the honest answer to "what does it cost" is a shape, not a number. Below is the shape.
The seven cost drivers, in order of impact
1. The disclosure and document generation layer (30–40% of build cost)
This is the component most vendors underprice. A production-grade disclosure engine has to:
- Generate the Loan Estimate and Closing Disclosure under TRID (for mortgage) or the equivalent TILA disclosures for consumer installment products, with per-state variants and the correct tolerances on APR and finance charges
- Produce ECOA adverse action notices with the correct reason codes, tied to whatever decisioning logic drove the decline
- Handle RESPA-mandated servicing disclosures and escrow statements where applicable
- Version every template, retain every generated document for the retention period each regulator requires, and produce a defensible audit trail of which template version was used for which borrower on which date
- Accommodate state-specific addenda — high-cost loan disclosures, military lending disclosures, and the licensing footer variants each state requires
The reason this eats 30–40% of the build is not that any single disclosure is hard to draft. It is that the engine has to treat disclosures as versioned, auditable, per-jurisdiction artifacts rather than PDFs generated from a template. The fact that Asurity launched RegCheck as a standalone SaaS TRID compliance product in 2024 tells you the market's own view: disclosure compliance is a specialized module, not a feature.
The ongoing cost is real too. Each compliance update cycle on a custom LOS typically runs $15K–$80K per sprint, covering TILA, ECOA, Fair Lending, KYC/AML, and state changes. Budget for four to six of those a year.
2. Decisioning engine and underwriting workflow (15–25%)
The credit decisioning layer — pulling bureau data, running scorecards, applying policy rules, routing exceptions to human underwriters — is the part most founders overestimate the cost of. Off-the-shelf rules engines (Camunda, DecisionRules, in-house rules DSLs) get you most of the way. What drives cost here is not the engine, it is:
- How many external data sources feed it (bureaus, bank data via Plaid/MX, KYC vendors, fraud tools, alternative data)
- Whether you are running an ML-based scoring model that needs its own training, monitoring, and Fair Lending explainability layer
- How many exception paths a human underwriter can take, because each one needs a UI, an audit log, and a permission model
A rules-only decisioning layer for a single product with three data integrations is a small piece of the build. A multi-model, alternative-data underwriting stack with adverse-action explainability is a project on its own.
3. Integrations (10–20%)
Every integration is a small subproject: sandbox access, contract negotiation, error handling, monitoring, and a re-test every time the vendor updates their API. Typical LOS integrations:
- Credit bureaus (Experian, Equifax, TransUnion) — soft and hard pulls, prescreen
- KYC/KYB and identity (Alloy, Persona, Socure, Middesk for business)
- Bank data (Plaid, MX, Finicity)
- eSignature (DocuSign, Dropbox Sign)
- Payment rails and funding (Dwolla, Modern Treasury, or direct ACH)
- Core servicing or downstream loan management system
- Accounting/GL for booking the loan
Rule of thumb: budget two to four engineering weeks per integration for a first pass, more if the vendor's sandbox is thin or the contract requires certification.
4. Borrower and originator UIs (10–15%)
The borrower portal — application, document upload, status tracking, e-sign, funding confirmation — is usually the smallest surprise. The originator/underwriter console is where scope creeps: queue management, exception handling, decision override with reason capture, portfolio views, and reporting. If you have loan officers or brokers, add a partner portal with commission tracking.
5. Reporting and regulatory data layer (10–15%)
HMDA reporting (if you do mortgage), call reports, state examination reports, and — starting January 2028 — Section 1071 small business lending data. The SBA Office of Advocacy estimated that roughly 1,500 smaller financial institutions face $58,400–$95,200 in annual 1071 compliance costs just for data collection and reporting. That is a recurring operational cost, but the platform work to make that data collection clean, complete, and auditable is a build-time cost you will pay once.
If you build the reporting layer as an afterthought — bolting HMDA fields onto an application form that was not designed for them — you will pay for that decision every quarter for the life of the platform.
6. Data migration from your current system (5–15%)
If you are moving off a spreadsheet-and-email workflow with a few hundred active loans, this is small. If you are moving off a legacy LOS or a servicer with five years of active loan history, escrow balances, and payment schedules — and you need continuity of borrower statements the day you cut over — this is a project. The cost driver is not the volume of data, it is the number of edge cases in the source system that no one documented.
7. SOC 2, penetration testing, and infrastructure (5–10%)
A production lending platform needs SOC 2 Type II (or a defensible equivalent) before most bank partners, warehouse lenders, or capital providers will touch it. Budget for the audit itself, the readiness work (policies, access controls, logging, vulnerability management), an annual penetration test, and the infrastructure to support all of it — encryption at rest and in transit, key management, segregated environments, immutable audit logs.
An illustrative worked example
The following is illustrative only. Every number depends on assumptions stated in the same breath, and none of it is a CodeNicely quote.
Scenario: A non-bank consumer installment lender, licensed in eight states, doing $18M/year in originations. Single product (unsecured installment loans, $2K–$25K, 24–60 month terms). Migrating off a hosted LOS they have outgrown. No mortgage, no small business, so no HMDA and (for now) no 1071. Four integrations at launch: one bureau, Plaid, Alloy for KYC, DocuSign. Rules-based decisioning with human underwriter review on exceptions. Migrating ~4,000 active loans with payment history.
On the industry benchmarks — $500K–$2M and 18–36 months for a custom LOS — a build like this sits toward the middle of the range on cost and the shorter end on timeline, because the product surface is narrow and the state footprint is contained. The disclosure and document layer is still the largest single line item because eight state variants and per-state rate/fee rules are real work, even for one product. Data migration is meaningful because active loans with payment history cannot break on cutover.
Change any assumption and the shape moves:
- Add small business lending → 1071 data collection layer, business KYC integration, different disclosures. Add meaningful scope.
- Expand to 40 states → the disclosure engine and licensing rules layer grows substantially, not linearly.
- Add ML-based underwriting with adverse-action explainability → new project inside the project.
- Keep the existing LOS running in parallel for six months → integration and reconciliation work you would not otherwise do.
What pushes cost up, what pulls it down
| Pushes cost up | Pulls cost down |
|---|---|
| Multiple loan products (installment + LOC + SBA + mortgage) | Single product, single borrower type |
| Nationwide licensing (all 50 states + DC) | Fewer than 10 states, contiguous footprint |
| Mortgage (TRID, HMDA, RESPA servicing rules) | Consumer installment or commercial only |
| Small business lending after Jan 2028 (Section 1071 data collection) | Consumer-only, no 1071 obligation |
| ML-based underwriting with Fair Lending explainability | Rules-based decisioning with human review |
| Migrating active loans with payment history from a legacy system | Starting fresh, or migrating only closed loans as a data archive |
| Broker/partner channel with commission tracking | Direct-to-borrower only |
| Building the disclosure engine from scratch | Licensing a disclosure module (e.g., Asurity RegCheck) and integrating |
| SOC 2 Type II required at launch for capital partners | SOC 2 as a year-two milestone |
| 10+ third-party integrations at launch | 3–5 integrations, phased |
Build vs. buy: the honest tradeoff
A licensed LOS — Encompass, nCino, LoanPro, defi, TurnKey Lender — gets you to production in 8 to 14 weeks and takes the disclosure engine off your hands. That is not a small thing. The reason Encompass processes over 40% of U.S. residential mortgage applications is that the compliance surface for mortgage is genuinely hard to replicate, and Ellie Mae has been maintaining it for two decades.
Buy is the right answer when:
- Your loan product is standard and your differentiation is in acquisition, pricing, or servicing — not the origination workflow itself
- You need to be in market in under six months
- You are okay with the vendor's decisioning model, borrower experience, and integration set
- Per-loan or per-seat pricing works at your volume
Build starts to make sense when:
- Your product does not fit standard LOS templates (non-standard collateral, unusual underwriting inputs, embedded lending inside another product)
- Per-loan SaaS pricing becomes punitive at your originations volume — the crossover is usually somewhere between $50M and $150M annual originations depending on the vendor
- Your competitive moat is in the underwriting model or borrower experience, and you cannot express it inside a licensed platform
- You need to own the data and the workflow end-to-end for reasons of capital partner requirements or M&A optionality
A hybrid is often the right answer: license the LOS for the disclosure and document engine, build the decisioning and borrower experience yourself, and integrate the two. That protects you from the 30–40% cost sink while preserving the differentiation you actually care about. Teams doing similar hybrid builds in adjacent fintech categories — for example, Cashpo's KYC and AI credit scoring stack — tend to concentrate custom engineering on the parts that are proprietary and license the parts that are commodity compliance.
The three questions that turn a range into a quote
Before any vendor quote is worth comparing to another, you need to have answered these:
- Exactly which loan products, in exactly which states, under which regulatory regimes? "Consumer installment in eight states, no mortgage, no small business until 2027" is a scoped answer. "Lending products for SMBs" is not.
- Are you building the disclosure engine or licensing it? This single decision moves the budget by 20–30%. If a vendor's quote does not name the answer, they have not scoped it.
- What has to migrate from your current system on day one, and what can wait? Active loans with payment continuity is a hard requirement. Historical closed-loan archives can often move as a data warehouse job post-launch. The difference is months of work.
If a vendor quotes you before these three are answered in writing, the quote is a starting number, not a budget. If you are trying to pressure-test a quote you have already received — or scope one from scratch — a scoping conversation with an engineering team that has built lending infrastructure is worth more than another RFP round.
Frequently Asked Questions
How long does it take to build a custom loan origination platform?
Published industry benchmarks put custom LOS builds at 18 to 36 months to reach production, versus 8–14 weeks for a licensed SaaS platform. The timeline is driven mostly by the compliance surface — number of states, number of loan products, and whether you are building or licensing the disclosure engine — not by the borrower portal or the decisioning logic. Turning a range into a real timeline requires a scoped product and jurisdiction footprint.
Why do vendor quotes for the same LOS build vary by 3x?
Almost always because of what is excluded from the low quote. The disclosure and document generation layer (TILA, RESPA, state variants), HMDA or Section 1071 reporting, SOC 2 readiness, and active-loan data migration are the four line items most commonly omitted or hidden in a vague 'compliance module.' Ask each vendor to price those four items explicitly before comparing.
Is it cheaper to license Encompass or a similar LOS than to build custom?
Almost always cheaper on day one, and often cheaper on a three-year TCO basis too — custom builds commonly run 60–80% higher on three-year TCO than an equivalent SaaS subscription. Build becomes cost-competitive when per-loan SaaS pricing becomes punitive at high volume, or when your product does not fit standard LOS templates. Below roughly $50M annual originations, the math usually favors buy or hybrid.
What does Section 1071 mean for a lending platform being built today?
The CFPB Final Rule sets a compliance date of January 1, 2028 for small business lending data collection and reporting under ECOA. Any custom LOS built today that touches small business lending needs the 1071 data-collection fields, storage, and reporting layer designed in from the start — retrofitting it later is meaningfully more expensive than building it in. Your compliance counsel should confirm which of your products fall in scope.
Do we need SOC 2 before we can go live?
Usually yes, in practice — most bank partners, warehouse lenders, and capital providers require SOC 2 Type II (or a defensible equivalent) before they will fund loans originated on your platform. It is not a legal requirement to originate, but it is a commercial requirement to operate at scale. Your auditor should confirm which trust services criteria apply to your specific setup.
Sources & further reading
- Loan Origination Software Market Size & Forecast to 2030 — Research and Markets
- Loan Origination Software Market Size, Share and Report Analysis to 2033 — Straits Research
- Loan Origination Software Market Size, Share, Forecast [2032] — Astute Analytica
- Build vs Buy a Loan Origination System — defi SOLUTIONS (June 2026)
- Best Loan Origination Software 2026: Top 10 LOS Compared — TIMVERO
- Loan Origination Software: Build vs Buy Cost Analysis (2026) — LendFoundry
- Loan Origination Software Market Size, Share, Trends 2025-2033 — Reports and Insights (Asurity/RegCheck citation)
- Small Business Lending Under the Equal Credit Opportunity Act (Regulation B) — Federal Register Final Rule, May 2026
Building something in Fintech?
CodeNicely partners with founders and tech teams to ship AI-native products that move metrics. Tell us about the problem you're solving.
Talk to our team Book a 30-min call_1751731246795-BygAaJJK.png)