CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Identity Theft. Show all posts
Showing posts with label Identity Theft. Show all posts

Monday, November 19, 2018

Identity Theft Prevention: How to Catch a Thief


Chairman & Managing Director

Here are four scenarios involving identity theft that mortgage originators encounter from time to time. Read them and then keep them in mind as I discuss how to ask for additional information in order to prevent identity theft.
1.       A law enforcement report containing detailed information about the identity theft and the signature, badge number, or other identification information of the individual law enforcement official taking the report should be sufficient on face value to support a victim’s request.
Question: Without an identifiable concern, such as an indication that the report was fraudulent, would it be reasonable for an information furnisher or Consumer Reporting Agency (CRA) to request additional information or documentation?
Answer: It would not be reasonable.
2.       A consumer might provide a law enforcement report similar to the above report, but certain important information such as the consumer’s date of birth or Social Security number may be missing because the consumer chose not to provide it.
Question: The information furnisher or CRA could accept this report, but would it be reasonable to require that the consumer provide the missing information?
Answer: It would be reasonable.
3.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for a tradeline block or cessation of information furnishing.
Question: Would it be reasonable for an information furnisher or CRA to ask that the consumer fill out and have notarized the Commission’s ID Theft Affidavit or a similar form and provide some form of identification documentation?
Answer: It would be reasonable.
4.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for an extended fraud alert.
Question: Would it be reasonable for a consumer reporting agency to require additional documentation or information, such as a notarized affidavit?
Answer: It would not be reasonable.
In these scenarios, a financial institution should be responsive in accordance with certain guidelines. Specificity of action must be appropriate, reasonable and proportional to the challenge. However, total reliance on the CRA is inappropriate.

Tuesday, September 18, 2018

Mortgage Fraud Challenges: How to Catch a Crook


Chairman & Managing Director

Two of our Directors will be attending the MBA’s “Risk Management, QA & Fraud Prevention Forum,” held in Los Angeles, in September. Attending this venue will be Brandy George, who is the Executive Director of LCG Quality Control and Michael Pfeifer, who is a Director of Legal and Regulatory Compliance. I remember attending the first forum many years ago. The attendance was modest. Although risk management was strengthening, I felt the term risk management was much too broad, as it could be (and was) applied to many industries. So, I coined the term “Mortgage Risk Management” and it caught on! My view has been that mortgage banking poses a unique set of risks that require significant knowledge, experience, and expertise. Turns out, this insight has been reinforced over the years. Now, this event is highly attended and is brimming with new ways to handle quality assurance, mortgage fraud prevention, and risk management oversight.

As I contemplated this forthcoming conference, I thought of the difficulties that mortgage originators have in handling the challenges of mortgage fraud in particular. This is a nasty business and not for the faint hearted! When my firm conducts audits of the loan flow process, it is not unusual to find gaps – perhaps ‘chasms’ is a better word! – in a company’s procedures for managing mortgage fraud risk. It still surprises me, after so many decades in mortgage banking compliance and financial institution management, that the fraudsters seem to have no limit to their scheming, conniving, crafty, wily, and underhanded cunning. These guys are as slippery as a darkly oleaginous grease slick.

Maybe I can’t stop these swindlers and shysters from doing what they do, but I can let you know some of the lessons my firm, Lenders Compliance Group®, has learned in knowing how to identify and trap them. I may not have all the answers, but I sure do have a lot of experience in hooking the crook. So, come with me on a brief walk through the mortgage fraud maze, as I jot down some of my reflections, and perhaps you should consider using some of my ideas to fine-tune your own mortgage fraud prevention procedures.

Let’s start with a simple outline of what fraudsters do!


During the mortgage lending process, a fraudster is a person who knowingly does any of the following:

  • Makes, uses, or facilitates any deliberate misstatement, misrepresentation, or omission with the intention that it be relied upon by a mortgage lender, borrower, or any other party to the mortgage lending process;
  • Receives any proceeds or any other funds in connection with a closing involving mortgage fraud; or
  • Files or causes to be filed with the county recorder, any document that contains a deliberate misstatement, misrepresentation, or omission.

In my view, there are two types of mortgage fraud: the first is fraud for property, and the second is fraud for profit.

Thursday, February 14, 2013

Anti-Money Laundering–Red Flags and the SAR Narrative

Even though AML compliance for nonbanks has been in effect since August 13, 2012, many Residential Mortgage Lenders and Originators (RMLO) still seem to have considerable difficulty in two specific areas: how to determine when a Suspicious Activity Report (SAR) should be filed, and which suspicious activity events or features may trigger the SAR filing requirement.
In one article, entitled Anti-Money Laundering Debuts for Nonbanks, I unpack the AML Program in a way that will provides some familiarity with the AML Compliance scope, while perhaps also making its implementation a bit less daunting than it might otherwise seem to be.
In another article, entitled Anti-Money Laundering Program: Preparation is Protection, I outlined many of the so-called Red Flags and other triggering events. In addition, I offered a way to construct a SAR narrative - the description to FinCEN about the alleged suspicious activity - that, based on years of experience auditing and implement AML compliance on behalf of our clients, best meets FinCEN's expectations of an informative statement.
To give you an idea of the size and complexity of a well-constructed AML Program, my firm’s AML Program is well over fifty pages – which consists of a policy statement and numerous appendices for applicable procedures. This should give you some idea of the depth and detail needed for properly implementing AML compliance. The absence of or any inaccuracies in required program components may indicate a defective policy and procedures – the very tools needed to assist in detecting and preventing money laundering or other illegal activities conducted through mortgage banking conduits.
So, a word of caution is due: do not take the chance of buying an abbreviated or defective AML Program, in the hope of merely satisfying the “basic” FinCEN requirements. Obtaining a boilerplate document with your company’s name on it is regressive, and it is a tactic that Examiners are now regularly criticizing in adverse findings.
These days, regulators are fully aware of this ‘short cut’ to compliance. An insufficient AML Program may cause adverse examination findings. Indeed, in some cases, template-driven policy and procedures may cause Examiners to escalate their regulatory review of an RMLO’s anti-money laundering implementation.
AML compliance is a specialized area of mortgage compliance, necessitating genuine, practical, hands-on, regulatory compliance and experiential knowledge, and an AML Program must reflect precise policies and procedures that not only implement the SAR regulations but also conform to a company’s way of doing business.
Therefore, an AML Program is one policy statement and set of procedures where the purchase price should not be an operative consideration. Caveat Emptor!
This is why I want to further outline the descriptive process of completing the SAR narrative, emphasizing a simple method I call The 5 W's and the How, and I will also provide details regarding both so-called Red Flags and triggering events. So, even if a company has a skimpy or defective AML policy and procedures, at least those who implement AML Compliance may be offered some rudimentary guidelines to consider in the practical experience of actually filing a SAR.
_________________________________________________________
IN THIS ARTICLE
The 5 W's and the How
Triggering Events
Documentation Red Flags
Applicant Red Flags
RMLO's Employee Red Flags
Library Resources
_________________________________________________________
The 5 W's and the How
If I were to choose the central feature of the SAR, I would select the SAR narrative.
Each SAR requires a narrative to be provided by the SAR filer.
Over time, my firm has compiled numerous examples of common patterns of suspicious activities from our audit and due diligence reviews. Based on our experience and FinCEN’s own stated guidance, we believe that there are five interrogative categories to be considered when writing a SAR narrative: who? what? when? where? and why?