Built by SpreadRunBeta

UAD 3.6 Appraisal Report Validator

Check a UAD 3.6 URAR appraisal file from your own code. Send the XML, or the whole UAD 3.6 ZIP package, and get a PASS, WARN or FAIL report against the GSE-published delivery specification and compliance rules, with an XPath, a rule ID and a message for every finding.

Where this fits. Appraisal software already runs the GSE compliance rules while a report is written, and the Uniform Collateral Data Portal (UCDP) runs them again when the lender submits it, at no fee to lenders. Fannie Mae also offers a UAD Compliance API to technology vendors. SpreadRun is the programmatic option for everyone else who handles the XML: lenders, AMCs and QC teams checking files at intake, and developers testing a UAD 3.6 export, with no portal login and no vendor agreement. UAD 3.6 is required for new UCDP submissions from November 2, 2026 (UCDP FAQ).

A PASS does not mean UCDP acceptance. These are structural checks, not legal, compliance or underwriting advice. 143 of the 728 published URAR compliance rules are not implemented (listed below), UCDP also runs GSE proprietary checks, and only the XML is checked.

Personal data. Appraisal reports name the borrower, the property owner and the seller and give the property address. Under the Terms, files sent to this validator may contain that personal data: it is processed in memory only to produce the report and is not stored, and no value from your file is repeated in the report. You confirm you are permitted to share the file with SpreadRun as a service provider. The sample files on this page use invented names and addresses.

What it checks

  • XML and MISMO 3.6. Well-formed XML with no DOCTYPE or entity declarations, a MESSAGE root in the MISMO residential namespace, MISMOReferenceModelIdentifier 3.6.0366, and a URAR report type.
  • Known structure. Every element sits at a location the URAR Delivery Specification defines (810 data points and attributes). Anything else is a warning.
  • Allowed values. Enumerated fields hold only supported values: condition and quality ratings C1 to C6 and Q1 to Q6, lowercase true or false, property types, valuation use types and the rest.
  • Formats. ISO dates (YYYY, YYYY-MM or YYYY-MM-DD as specified), datetimes, number precision and sign, and text length limits.
  • Required data. Data points the specification always requires in a container that is present, and container repeat limits.
  • Compliance rules. 585 of the 728 URAR compliance rules (480 fatal, 105 warning): required and conditionally required data for the subject, each comparable, each unit, room, level and component; cross-field comparisons such as contract date against effective date; instance counts; unique comparable numbers; ZIP and state code formats; report dates.

Fatal rules and delivery specification violations are errors and make the report FAIL. Warning rules make it WARN. Each property is checked in its own scope, so a finding names the exact comparable, unit or room.

Who it's for

  • Lenders and AMCs: check every appraisal XML at intake, before it reaches underwriting or UCDP.
  • QC and review teams: run the same checks on a batch of files from a script.
  • Software teams: test a UAD 3.6 export or import in CI with a structured JSON report.
  • AI agents and automation: a plain REST endpoint with a file in and JSON out.

Not checked

  • 143 compliance rules: date arithmetic, sums or nested conditions (69); wording without one unambiguous machine reading (47); row-by-row comparison across all comparables (4); links between parts of the report (relationship / xlink) (20); names a data point or container the delivery specification does not define at that location (3). Their IDs are in every report.
  • Appraisal Update and Completion Reports (rejected, not charged).
  • Schema validation against the MISMO XSD, GSE proprietary findings, Collateral Underwriter, and the PDF and photos in a package.
  • Whether the values are true, or the appraisal is credible.

Input and output

  1. Send

    POST the UAD 3.6 URAR XML file, or the UAD 3.6 ZIP package, as the request body. Up to 4.4 MB. The whole file is checked: no sampling.

  2. Validate

    Structure, allowed values and formats from the delivery specification, then each implemented compliance rule for every property and container it applies to.

  3. Report

    JSON with status (PASS, WARN or FAIL), findings (severity, ruleId, XPath-style path, message), counts, the report type and the coverage: which rules ran and which are not implemented.

Full request and report schema in the API docs.

Try it now

Free demo, no account: files up to 1.0 MB, 10 runs a day. For full validations from this form, sign in and buy credits: $1.00 per completed report, packs from $5.

A UAD 3.6 URAR XML file, or the UAD 3.6 ZIP package (only its XML is checked).

Processed in memory and not stored. Reports never repeat values from your file.
Leave empty for today. Two rules compare the report's dates with this date: not in the future, not more than 367 days old.
Sample report
Synthetic URAR file with six deliberate errors
FAIL
Report URAR8 other properties7 errors1 warning585 compliance rules run
SeverityRuleWhere and what
ErrorA1-ENUM…/VALUATION_ANALYSIS/PROPERTIES/PROPERTY[1]/PROPERTY_DETAIL/NativeAmericanLandsIndicator
NativeAmericanLandsIndicator is not a supported UAD value. Supported: false, true.
ErrorA1-ENUM…/VALUATION_ANALYSIS/PROPERTIES/PROPERTY[1]/PROPERTY_DETAIL/OverallConditionRatingCode
OverallConditionRatingCode is not a supported UAD value. Supported: C1, C2, C3, C4, C5, C6.
ErrorA1-FORMAT…/VALUATION_ANALYSIS/VALUATION_REPORT/VALUATION_RECONCILIATION/VALUATION_RECONCILIATION_SUMMARY/VALUATION_RECONCILIATION_SUMMARY_DETAIL/AppraisalReportEffectiveDate
AppraisalReportEffectiveDate must be a date in YYYY-MM-DD format.
ErrorA1-REQUIRED…/VALUATION_ANALYSIS/PROPERTIES/PROPERTY[1]/ADDRESS/PostalCode
PostalCode is required in every ADDRESS by the delivery specification.
ErrorUAD1004…/VALUATION_ANALYSIS/PROPERTIES/PROPERTY[1]/ADDRESS/PostalCode
Provide the ZIP code for the subject property physical address.
ErrorUAD1260…/VALUATION_ANALYSIS/VALUATION_REPORT/VALUATION_RECONCILIATION/VALUATION_RECONCILIATION_SUMMARY/VALUATION_RECONCILIATION_SUMMARY_DETAIL/AppraisalReportEffectiveDate
The 'Effective Date of Appraisal' must include year, month and day.
ErrorUAD1263…/VALUATION_ANALYSIS/VALUATION_REPORT/VALUATION_RECONCILIATION/VALUATION_RECONCILIATION_SUMMARY/VALUATION_RECONCILIATION_SUMMARY_DETAIL/OpinionOfValueAmount
'Opinion Of Market Value' must be at least one dollar, and cannot be negative.
WarningA1-UNKNOWN…/VALUATION_ANALYSIS/PROPERTIES/PROPERTY[1]/PROPERTY_DETAIL/LegacyGrossLivingArea
LegacyGrossLivingArea is not part of the UAD 3.6 URAR delivery specification at this location. UCDP may reject or ignore it.

Date rules evaluated as of 2019-09-20.

Pricing

$1.00 per completed report. One file, one full report.

  • Billed when a report is produced, PASS, WARN or FAIL. Invalid input is never billed: not XML, not MISMO 3.6, not a URAR, a ZIP without exactly one UAD XML file.
  • Paid from the same prepaid credits as every SpreadRun API. A $5 pack covers 5 reports. Credits never expire. All pricing
  • Checking thousands of appraisals a month? Talk to us first so we can tell you honestly whether this fits.

Call it from code

Parameters, the report format, rule IDs, error codes and limits are in the API docs.

curl -X POST "https://www.spreadrun.com/api/v1/uad-36-appraisal-validator" \
  -H "Authorization: Bearer $SPREADRUN_API_KEY" \
  -H "Content-Type: application/xml" \
  --data-binary @appraisal.xml

Questions

Does a PASS mean UCDP will accept the report?

No. A PASS means the file passed the checks this validator runs: the delivery specification checks and 585 of the 728 published URAR compliance rules. UCDP also runs the rules not implemented here, GSE proprietary checks and its own system checks, and it reviews the whole package, not just the XML. These are structural checks. They are not legal, compliance or underwriting advice.

Our appraisal software already checks the report. Why use this?

Your appraisal software runs the GSE compliance rules while the report is written, and UCDP runs them again when the lender submits it. Those are the right checks for an appraiser finishing a report. This API is for the systems around them: a lender or AMC checking every file at intake, a QC tool, or a developer testing a UAD 3.6 export, from code, with no portal login.

What about Fannie Mae's UAD Compliance API?

Fannie Mae offers a UAD Compliance API to technology vendors, arranged through Fannie Mae. If you have access to it, it is the authoritative source and you should use it. SpreadRun is for teams that do not: anyone with an API key and credits can call it.

Which reports are supported?

The Uniform Residential Appraisal Report (URAR), checked against Appendix A-1, the URAR Delivery Specification (v1.4), and Appendix H-1, the URAR compliance rules (v1.5). Appraisal Update and Completion Reports are not supported yet: they are rejected with a clear message and not charged.

Can I send the whole UAD 3.6 ZIP package?

Yes. Send the ZIP as the request body and the validator checks the one UAD XML file inside it. The PDF and photos in the package are not checked. The 4.4 MB request limit applies to the ZIP, so for packages with many photos, send the XML file on its own.

Which compliance rules are not implemented?

143 of the 728 rules. Each one needs interpretation the published rule text does not settle, such as links between parts of the report, date arithmetic and sums, or row-by-row comparisons across comparables. Every report lists their rule IDs, and the API docs give the reason for each. A rule that is not implemented never produces a finding, so it can never make a report fail.

Is the appraisal data stored?

No. Files are processed in memory for the length of the request and are not stored or shared. Appraisal reports contain personal data such as borrower, owner and seller names and property addresses; the Terms allow it for this validator only, on that basis. Findings name the location, the rule and the problem, never a value from your file. For billing and usage we log the time, endpoint, result status, upload size and duration, never the file contents.

Where do the rules come from?

From the appendices the GSEs publish for UAD 3.6: the URAR Delivery Specification and the URAR compliance rules. They are translated into a machine-readable rule table by a script, and the translation is tested against the GSE sample scenarios. Where this validator and the Delivery Specification differ, the Delivery Specification controls. SpreadRun is not affiliated with or endorsed by Fannie Mae or Freddie Mac.

When is a run charged?

When the validator finishes and returns a report, whether it says PASS, WARN or FAIL: $1.00 per report. Requests rejected before a report exists are free: not XML, not a MISMO 3.6 file, not a URAR, a ZIP without exactly one UAD XML file, or DOCTYPE and entity declarations.

Why does a valid older report get a WARN?

Two compliance rules compare the report's dates with today: the effective date cannot be in the future or more than 367 days old, and the same for the signature date. To check an older report as of the date it was signed, pass asOf=YYYY-MM-DD.

Rules from the GSE-published UAD 3.6 appendices A-1 and H-1. SpreadRun is not affiliated with or endorsed by Fannie Mae or Freddie Mac. Where this validator and the Delivery Specification differ, the Delivery Specification controls.

More validators: Hospital MRF Validator | the full catalog