CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Compliance Management System. Show all posts
Showing posts with label Compliance Management System. Show all posts

Thursday, January 9, 2025

Policy & Procedures and Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

Customized Compliance Library

Policies Tune-up®

CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

Monday, January 30, 2017

Production Incentives: Protecting the Consumer, plus Compliance Checklist for Production Incentives

Jonathan Foxx
Managing Director

Production incentives have been around since the dawn of modern capitalism. They are not going anywhere. Incentives have been called sales incentives, sales bonuses, compensation bonuses, and take into account any additional remuneration that tends to be transactionally based. All such incentives can be grouped into business objectives where a transaction may be tied to certain benchmarks, met by employees or service providers, the achievement of which leads to an increase in wage or reward for the party achieving the stated goal. For the sake of discussion, let’s call forms of such economic inducement, collectively, as “incentives.”

Typical incentives include cross-selling, where sales or referrals of new products or services are pitched to existing consumers; sales of products or services to new customers; sales at higher prices where pricing discretion exists; quotas for customer calls completed; and collections benchmarks.

Some of these incentives are very complex in the way they are achieved and applied, whether optionally or required. The incentive challenge is one of the usual conundrums arising when money and capital formation meet: the opportunity for harm to the consumer. Obviously, incentives offer a way to further enhance revenue for the seller of services and products. Indeed, in our market economy, an incentive can reveal the economic interest of market participants in a particular service or product, which is extrapolated from consumers’ responses to the offerings. Like so much in finance, incentives are not inherently good or bad, but how they are applied makes them so!

The Consumer Financial Protection Bureau (“Bureau”) has decided to weigh in with guidance on production incentives. I am going to provide my reading of the Bureau’s most recent bulletin on this topic, entitled “Detecting and Preventing Consumer Harm from Production Incentives” (Bulletin 2016-03, November 28, 2016, hereinafter “Bulletin”). It is an interesting read, because it endeavors not only to compile guidance that the Bureau had provided in other contexts but also draws on the Bureau’s supervisory and enforcement experience in which incentives contributed to substantial consumer harm. Importantly, the Bulletin offers some actions that supervised entities should take to mitigate risks posed by incentives.

This White Paper article is an adjunct to an earlier published web article (December 2016), with further elaboration herein, plus now including a "Compliance Checklist for Production Incentives," which provides some helpful guidelines to creating production incentive plans. The full White Paper, Article, and Compliance Checklist may be downloaded from our firm's website at LendersComplianceGroup.com

RISKS

The most obvious risk of incentives to the consumer is a sales program that includes an enhanced economic motivation for employees or service providers to pursue overly aggressive marketing, sales, servicing, or collections tactics. These kinds of incentives are and always have been features of sales tactics that do not meet regulatory scrutiny. Consequently, it is the case that the Bureau has taken enforcement action against financial institutions that have expected or required employees to open accounts or enroll consumers in services without consent or where employees or service providers have misled consumers into purchasing products the consumers did not want, were unaware would harm them financially, or came with an unexpected ongoing periodic fee.

One or more regulatory violations may be triggered as a result of such incentives. To name but a few of the more salient regulatory frameworks that can be violated, impermissible incentives can cause violations of unfair, deceptive, and/or abusive acts or practices (UDAAP) (Dodd-Frank Act, §§ 1031 & 1036(a), codified at 12 USC §§ 5531 & 5536(a), the Electronic Fund Transfer Act (EFTA), as implemented by Regulation E (15 USC § 1693 et seq.; 12 CFR Part 1005); the Fair Credit Reporting Act, as implemented by Regulation V (15 USC § 1681-1681x; 12 CFR Part 1022); the Truth in Lending Act (TILA), as implemented by Regulation Z (15 USC § 1601 et seq.; 12 CFR Part 1026); and the Fair Debt Collection Practices Act (15 USC § 1692-1692p). And to this the Bureau itself notes that violations can stir up public enforcement, supervisory actions, private litigation, reputational harm, and potential alienation of existing and future customers.

Although not meant to be comprehensive, here are some impermissible incentives that surely trigger regulatory violations:
  • Opening Accounts: sales goals that encourage employees, either directly or indirectly, to open accounts or enroll consumers in services without their knowledge or consent, which may result in improperly incurred fees, improper collections activities, and/or negative effects on consumer credit scores;
  • Benchmarks: sales benchmarks that encourage employees or service providers to market a product deceptively to consumers who may not benefit from or even qualify for it;
  • Terms or Conditions: paying compensation based on the terms or conditions of transactions (such as interest rate) that encourages employees or service providers to overcharge consumers, to place them in less favorable products than they qualify for, or to sell them more credit or services than they had requested or needed;
  • Tiered Compensation: paying more compensation for some types of transactions than for others that were or could have been offered to meet consumer needs, which could lead employees or service providers to steer consumers to transactions not in their interests; and 
  • Quotas: unrealistic quotas to sign consumers up for financial services may incentivize employees to achieve this result without actual consent or by means of deception.

Tuesday, December 1, 2015

Ten Core Competencies in a Compliance Management System

President & Managing Director
Lenders Compliance Group

In my view, there are ten core competencies to implementing a Compliance Management System, often referred to by its acronym CMS. The Consumer Financial Protection Bureau requires it, state regulators are now asking for it, and investors want assurance of its application.

I have written extensively about the CMS concept and its importance in mortgage risk management. For instance, see my article on Creating a Culture of Compliance. Also, other articles here. When I speak on the subject, it is often the case that some in the audience actually have no idea about what constitutes the CMS. They think it is no more than a compilation of policies and procedures. But, the fact is that a viable CMS is composed of several integral features, each of which contributes to the cohesiveness of the whole compliance function.

Here’s a brief synopsis of the Ten Core Competencies that should inform a CMS:

1)  Loan portfolio, secondary and capital market management processes, mortgage servicing.

2)  Loan flow process, from point of sale to securitization or secondary market transaction.

3)  Internal Audit and Control Plan, including calendrical reviews, reporting protocol, rank and file training in all departments, and testing.

4)  Consumer disclosures, all loan types, federal and state.

5)  Mortgage quality control, not only random sampling, but proactive audits that target criteria.

6)  Record retention and maintenance, securing against unauthorized alteration or destruction.

7)  Marketing and advertising, including use of third-party services.

8)  Vendor, settlement agent, closing agent, and third-party vetting and approvals.

9)  Safeguards for privacy protection of consumer records and information.

10)  Reporting mandates to agencies, both federal and state, investors, and third-party relationships.

The compliance framework is built on the foregoing competencies. Destabilize one of them and it is possible that the others will crash like a tottering stack of cards!

Also, it should be noted that there is a growing expectation amongst regulators for a residential mortgage lender or originator to have a business continuity plan.

It is not necessary to consolidate all compliance policies and procedures into a single document. Nor does it require compliance managers to memorialize every action that must be taken in order to remain in compliance with federal and state banking law. In some cases, it may be enough for the compliance policies and procedures to allocate responsibility within the organization for the timely performance of many obligations, such as the filing or updating of required forms.

However, observed instances in which compliance policies and procedures were not followed or the actual practices were not consistent with the description in the compliance manuals, will likely lead to an adverse banking examination finding. Observed practices in areas that are required to be reviewed in accordance with specific regulations and in areas that include policies and procedures, but are not expressly required to be reviewed by regulations, will come under significant regulatory scrutiny.

What good is a compliance management system if it is not continually reviewed and, where needed, updated? In our work with new clients, we have found the following issues happening often:

·         Critical areas not identified, thus certain compliance policies and procedures were not adopted.

·         Policies were adopted, but were not applicable to the businesses and operations.

·         Critical control procedures were not performed, or not performed as described in the CMS.

·         Annual Review of the compliance function was rarely, if ever, implemented.

During examinations, an examiner may observe certain compliance weaknesses. But examiners review periodically, not continually, in most cases. The rest of the time, the residential mortgage lender or originator should be self-assessing the compliance programs in order to spot weaknesses, particularly with respect to identifying applicable mortgage compliance risks, and thereby ensure that the compliance management system encompasses all relevant business activities.

Wednesday, March 26, 2014

Compliance Collaborative, Inc.

For some time I have been concerned about the way certain "cooperatives" seem to be crossing the line in providing compliance support services (via selected, alliance vendors) at the same time that they are providing underwriting, processing, loan products, and various operations functions. Although these cooperatives have (yet) to come under the scrutiny of regulators, I think they one day might, since compliance and underwriting (for example) should not occupy the same space.

I am sure that all the legal bases of their way of doing business have been fully explored and satisfied. And I get that lenders want to go to a cooperative and receive all the services they need, including compliance support. However, in my view, when it comes to compliance there should not be such an ostensibly unorthodox configuration. Indeed, in conversations I have had with regulators, they have pointed out to me that this is a concern of theirs.

Therefore, I have decided to start a new and additional way to serve the compliance needs of the mortgage banking community: the Compliance Collaborative, Inc. (CCI).

The Compliance Collaborative has been in the planning for some time and is already building alliances with well-established vendors that offer compliance - and exclusively compliance! - to residential mortgage lenders and originators.

CCI is now the first and only firm in the country exclusively devoted to mortgage banking compliance that provides a collaboration of the best and finest mortgage compliance providers. And the very first firm to join CCI is Lenders Compliance Group!

Many compliance vendors, consultants, risk management professionals, and law firms are joining CCI in order to provide their respective services to CCI clientele. Any member firm may always be retained separately. But member firms may also be individually retained through CCI or as part of a package of compliance solutions, thereby offering cost-effective and reasonable fees.

In the next few weeks, you will be hearing more about CCI's new website and service plans. We recently issued a Press Release about it and our efforts are being picked up by the media, for instance, here and here and here.

In the meantime, if you want me to keep you in mind for a call or email and new information, please let me know.

We will be providing a suite of services soon and would welcome your feedback and requests. I'll be glad to contact you to ensure that you are given an early opportunity to retain the Compliance Collaborative for your compliance needs!

Best wishes,
Jonathan Foxx
President & Managing Director

Tuesday, November 6, 2012

CFPB: Compliance Management System

On October 31, 2012, the CFPB issued its first issue of Supervisory Highlights: Fall 2012, a newsletter to the public and the financial services industry about its examination program, including the concerns that it finds during the course of its completed work, and the remedies that it has obtained for consumers who have suffered financial or other harm.
It is written as an Executive Summary, and it will not refer to any specific institution. But it will "signal to all institutions the kinds of activities that should be carefully scrutinized for compliance with the law."
According to the CFPB, it has already taken non-public supervisory actions against financial institutions participating in the credit card, credit reporting, and mortgage markets, confirming "remedial relief" to 1.4 million consumers, and causing the affected financial institutions to correct illegal practices. Importantly, and in consequence to the CFPB's examinations and actions, financial institutions were required to adopt effective policies and procedures to ensure that violations do not recur and, especially, mandating that they implement a robust Compliance Management System (CMS). 
The CFPB maintains that an effective CMS is a "critical component of a well-run financial institution."
After a brief discussion about the CMS concept, I should like to outline these three significant findings derived from the CFPB's examinations:
- Comprehensive CMS Deficiencies Found Through CFPB Supervisory Activities
- Deficiencies Related to Failure to Oversee Affiliate and Third-party Service Providers
- Deficient Fair Lending Compliance Programs
___________________________________________________
IN THIS ARTICLE
Compliance Management System
Comprehensive CMS Deficiencies
Failure to Oversee Affiliate and Third-party Service Providers
Deficient Fair Lending Compliance Programs
Library
___________________________________________________
Compliance Management Systems
I consider the term Compliance Management System to be a proxy for the term mortgage risk management. Our firm was founded on the premise that such risk management was the best way to ensure a financial institution's safety and soundness with respect to mortgage banking. At the time, there was only the term "risk management", a catch-all term that was overly broad. So I coined the term "mortgage risk management" to bring mortgage compliance into greater focus, expertise, and application.
Over the years, the prudential regulators and state banking departments have included much guidance in preparedness for their mortgage banking examinations. And now the CFPB has further elaborated the crucial and central importance of managing risk and examination readiness. As recently as July 2012, I published a magazine article about The Rules of Operational Risk, in order to bring into strong relief the practical matters and unique circumstances of mortgage risk management.
The CFPB's conception of a well-conceived CMS is certainly consistent with the foundational features of mortgage risk management.
Both the CFPB and mortgage risk management require effective internal controls and oversight, training, internal monitoring, consumer complaint response, independent testing and audit, third-party service provider oversight, recordkeeping, product development and business acquisition, and marketing practices.
Mortgage risk management and the CMS both expect the development, maintenance, and integration of mortgage compliance practices across a financial institution's framework and applied to its entire loan product and service lifecycle.
As the CFPB states:
"Without such a system, serious and systemic violations of Federal consumer financial law are likely to occur. Further, a financial institution with a deficient CMS may be unable to detect its own violations. As a result, it will be unaware of resulting harm to consumers, and will be unable to adequately address consumer complaints."
__________________________
Comprehensive CMS Deficiencies
The CFPB has issued findings for financial institutions lacking an effective CMS across the entire consumer financial portfolio, or in which the company failed to adopt and follow comprehensive internal policies and procedures. In these instances, the finding held that this condition resulted in "a significant breakdown in compliance and numerous violations of Federal consumer financial law."
The corrective action required an adopting of appropriate policies and procedures, and establishing an effective CMS to ensure legal compliance, which had to include the "enhancement" of financial institutional regulatory knowledge and expertise to help ensure proper monitoring of business activities and prompt identification of potential risks to consumers.
In this regards, educating about and training employees in a company's policies and procedures should be fully implemented and routinely followed. I suggest a schedule of on-going education and training modules, given to both new hires and all active, affected personnel.
Keep in mind that the CFPB will exam not only the policies and procedures and their communication to employees but also management's inclination to be proactive or passive, preemptive or complacent, knowledgeable or disinterested. According to the CFPB, a financial institution’s CMS is “inadequate” where appropriate policies have been adopted, but management fails to take measures to ensure compliance with those policies.
In a typical CMS examination, the CFPB evaluates both the understanding and application of the financial institutions’ compliance management program by its managers and employees. The CFPB has stated that it has found "one or more situations in which the financial institution had articulated many elements of an appropriate compliance policy, but the policy was not followed."