LENDERS COMPLIANCE GROUP® is the country's first full-service mortgage risk management firms in the United States, devoted to offering a full suite of services in residential mortgage banking, respectively, to banks and nonbanks, independent mortgage professionals, and mortgage servicers. We also provide state-of-the-art mortgage quality control auditing and loan analytics.
CREATORS OF THE COMPLIANCE TUNE-UP®
AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB
Thursday, December 12, 2013
Social Media: Consumer Compliance Risk Management Guidance
The Guidance is intended to help financial institutions understand potential consumer compliance and legal risks, as well as related risks, such as reputation and operational risks associated with the use of social media, along with expectations for managing those risks. It also provides considerations that financial institutions may find useful in conducting risk assessments and crafting and evaluating policies and procedures regarding social media. Although this Guidance does not impose any new requirements on financial institutions, as with any process or product channel, financial institutions are expected to manage potential risks associated with social media usage and access.
The Final Rule is meant to highlight and manage potential risks to financial institutions and consumers; however, financial institutions should ensure their risk management programs provide oversight and controls commensurate with the risks presented by the types of social media in which the financial institution is engaged, including, but not limited to, the risks outlined within the Guidance.
In this article, I will set forth an outline of the Guidance along with suggestions to manage the risks associated with the use of social media.* I have also published a helpful article on this topic, entitled Social Media and Networking Compliance, which may be downloaded from our Library.
WHAT IS SOCIAL MEDIA?
For purposes of the Guidance, messages sent via traditional email or text message, standing alone, do not constitute social media, although such communications may be subject to a number of laws and regulations discussed in the Guidance. However, messages sent through social media channels are social media. According to the Guidance, social media is considered to be a form of interactive online communication in which users can generate and share content through text, images, audio, and/or video. Social media can take many forms, including, but not limited to, micro-blogging sites; forums, blogs, customer review web sites and bulletin boards; photo and video sites; sites that enable professional networking; virtual worlds; and social games. Social media can be distinguished from other online media in that the communication tends to be more interactive.
RISK MANAGEMENT PROGRAM
The Guidance suggests that a financial institution should have a risk management program that allows it to identify, measure, monitor, and control the risks related to social media. The size and complexity of the risk management program should be commensurate with the breadth of the financial institution’s involvement in this medium.
For instance, a financial institution that relies heavily on social media to attract and acquire new customers should have a more detailed program than one using social media only to a very limited extent. An observation made in the Guidance, and worth noting, is though a financial institution’s own risk assessment indicates that it has chosen not to use social media, nevertheless, it should “still consider the potential for negative comments or complaints that may arise within the many social media platforms”, and, when appropriate, evaluate what, if any, action it will take to monitor for such comments and determine if a response is needed.
FEATURES OF A RISK MANAGEMENT PROGRAM
The risk management program should be designed with participation from specialists in compliance, technology, information security, legal, human resources, and marketing. Financial institutions should also provide guidance and training for employee official use of social media.
The Guidance stipulates at least seven components of a risk management program. These include, but are not limited to:
1. A governance structure with clear roles and responsibilities whereby the board of directors or senior management direct how using social media contributes to the strategic goals of the institution (for instance, through increasing brand awareness, product advertising, or researching new customer bases) and establishes controls and ongoing assessment of risk in social media activities;
2. Policies and procedures (either stand-alone or incorporated into other policies and procedures) regarding the use and monitoring of social media and compliance with all applicable consumer protection laws and regulations, and incorporation of guidance as appropriate. Further, policies and procedures should incorporate methodologies to address risks from online postings, edits, replies, and retention;
3. A risk management process for selecting and managing third-party relationships in connection with social media;
4. An employee training program that incorporates the institution’s policies and procedures for official, work-related use of social media, and potentially for other uses of social media, including defining impermissible activities;
5. An oversight process for monitoring information posted to proprietary social media sites administered by the financial institution or a contracted third party;
6. Audit and compliance functions to ensure ongoing compliance with internal policies and all applicable laws and regulations, and incorporation of guidance as appropriate; and
7. Parameters for providing appropriate reporting to the financial institution’s board of directors or senior management that enable periodic evaluation of the effectiveness of the social media program and whether the program is achieving its stated objectives.
WHAT ARE THE RISKS?
The use of social media to attract and interact with customers can impact a financial institution’s risk profile, including:
· Risk of harm to consumers
· Compliance and legal risks
· Operational risks, and
· Reputation risks.
In our own reviews on behalf of our clients, we have found that the foregoing risks are increased due to poor due diligence, oversight, or control on the part of the financial institution.
Let us now give consideration to each of the Risk Areas, with respect to the risks posed by Social Media. Suggestions are emboldened in each synopsis.
Monday, January 9, 2012
OCC - Correcting Foreclosure Practices
- Independent Foreclosure Review
- Mailings to Consumers
- Deadline for Review Requests
- Independent Foreclosure Auditor
- Eligibility for Review
- Notifying the Public
- Engagement Letters
- Interim Report
- Library
Wednesday, November 30, 2011
OCC: Fixing Deficient Foreclosure Practices
President & Managing Director
Lenders Compliance Group
Interim Report
Engagement Letters
Correcting Foreclosure Deficiencies
Professional Assistance
Library
Pursuant to 12 C.F.R. § 4.12(c), the listing order of the engagement letters at the OCC's election has no precedential significance.
Limited proprietary and personal information has been redacted from the engagement letters.
Requests for review must be received by April 30, 2012.
November 2011
April 2011
Tuesday, October 18, 2011
FRB Issues Flood Insurance FAQs and Proposed Revisions
- Effective Date - Final questions and answers: October 17, 2011.
- Effective Date for Comments: December 1, 2011.
Loans in Areas Having Special Flood Hazards
Interagency Questions and Answers Regarding Flood
Federal Register - 76/200
October 17, 2011
Tuesday, February 1, 2011
Agencies: Commence NMLS Registration
Interagency Announcement
January 31, 2011
Friday, January 21, 2011
Privacy & GLBA: Model Forms
On January 12, 2011, the Office of Thrift Supervision (OTS) published information intended to help small thrifts comply with the obligation to send initial and annual privacy notices to their customers. The agency's Small Entity Compliance Guide for the Model Privacy Notice is aimed at helping small thrifts use the model privacy notice form established by the bank and thrift regulatory agencies in December 2009. Proper use of the model forms provides a safe harbor for compliance with the privacy notice duties.
On December 1, 2009, the agencies published the final rule relating to the model privacy notice. Financial institutions that elect to use the model privacy form may rely on the model privacy form as a safe harbor to comply with the GLBA disclosure requirements.
The effective date of the amendments was December 31, 2009, except for the amendments eliminating the sample clauses and associated guidance, which become effective for notices sent after December 31, 2010.
Timing and Safe Harbor
A model privacy form that meets the privacy regulations' notice content requirements, which institutions may voluntarily rely on as a safe harbor in providing privacy notices as of December 31, 2009, appears in Appendix A to the regulations.
[Sample clauses also relating to the privacy regulations' notice content requirements, applicable in connection with privacy notices provided on or before December 31, 2010, appear in Appendix B to the regulation through December 31, 2011 (and thereafter will be deleted).]
The regulatory agencies have created an on-line form builder that thrifts can use to develop customized versions of the model notices. Although all financial institutions may model forms, they are not required to do so. Other forms, including those that rely on the sample clauses that will be replaced by the model forms, can be used if they comply with the notice requirements. However, only using the model forms will provide a safe harbor after December 31, 2010.
Privacy Notice - Form Requirements
The model privacy form has several versions:
1. If opt out is provided and include affiliate marketing.
2. If opt out is provided and do not include affiliate marketing.
3. If opt out is not provided and include affiliate marketing.
4. If opt out is not provided and do not include affiliate marketing.
5. If opt out is provided and include affiliate marketing, and mail-back form.
6. If opt out is provided and do not include affiliate marketing, and mail-back form.
To prevent identity theft, institutions should use a truncated form of an account number other than a Social Security Number on privacy notices.
Specific disclosure requirements are mandatory, if a financial institution wants to customize the privacy notice. However, the following features are permitted:
- Print the form on both sides of a single sheet of paper (or on two pages)
- Incorporate the form in another document or with other notices, and include additional documents or information so long as the form is presented in a clear and conspicuous manner
- Provide a single form jointly with other affiliated institutions (including affiliated institutions regulated by different agencies), as long as each institution is clearly identified in the correct space of the form
- Include color and logos to create visual interest, provided they do not interfere with the readability of the form
- Use different sizes of paper, provided the paper is large enough to meet the minimum 10-point font size and provide sufficient white space around the model form text
- Include certain information on state and international privacy law in the blank spaces provided
- Include a mail-in version of the opt-out form as described in the rule
- Translate the form into languages other than English
Online Form Builder - Quick Links
On April 15, 2010, the Agencies released an Online Form Builder that financial institutions can download and use to develop and print customized versions of the model consumer privacy notice.
The Online Form Builder, based on the model form regulation published in the Federal Register on December 1, 2009, under the GLB Act, is available with several options. Easy-to-follow instructions for the form builder guide an institution to select the version of the model form that fits its practices.
QUICK LINKS
Thursday, December 9, 2010
New Appraisal and Evaluation Guidelines
On December 2, 2010, the federal financial regulatory agencies issued new Appraisal and Evaluation Guidelines, the purpose of which is to reflect changes in appraisal and evaluation practices.
The Guidelines replace the 1994 guidelines and explain the agencies' minimum regulatory standards for appraisals, incorporating the agencies' recent supervisory issuances on appraisal practices, addressing advancements in information technology used in collateral valuation practices, and clarifying standards for the industry's appropriate use of analytical methods and technological tools in developing evaluations.
The Guidelines clarify that:
(1) an analytical method or technological tool, such as an automated valuation model, cannot be substituted for an appraisal when the transaction requires an appraisal, and (2) there are "enhanced" requirements for collateral valuation methods for transactions that permit the use of an evaluation.
![]()
Review appraisal and evaluation programs to ensure they are consistent with the Guidelines.
GUIDELINES
- Recognize that while borrowers' ability to repay real estate loans according to reasonable terms remains the primary consideration in a lending decision, sound collateral valuation practices are an integral part of the loan underwriting process.
- Update and replace existing supervisory guidance to reflect developments regarding appraisals and evaluations as well as changes in appraisal standards and advancements in regulated institutions' collateral valuation methods.
- Clarify that collateral valuation methods that use an analytical method or technological tool, such as an automated valuation model, cannot be substituted for an appraisal when the transaction requires an appraisal.
- Enhance the requirements for collateral valuation methods for transactions that permit the use of an evaluation and specify that valuation methods that do not provide a property's market value, such as a broker price opinion, are not acceptable as an evaluation.
- Instruct institutions to file a complaint with the appropriate state appraiser regulatory officials when they suspect that a state certified or licensed appraiser fails to comply with the Uniform Standards of Professional Appraisal Practices, applicable laws, or engages in other unethical or unprofessional conduct, and to file a suspicious activity report (SAR) with the Financial Crimes Enforcement Network when the suspicious activity meets the SAR filing criteria.
APPENDICES
The appendices are particularly interesting and relevant to appraisal and evaluation practices. It is important to become familiar with the guidelines and implement them accordingly.
Appendix A
Appraisal Exemptions
1. Appraisal Threshold
2. Abundance of Caution
3. Loans Not Secured by Real Estate
4. Liens for Purposes Other Than the Real Estate's Value
5. Real Estate-Secured Business Loans
6. Leases
7. Renewals, Refinancings, and Other Subsequent Transactions Loan Workouts or Restructurings.
8. Transactions Involving Real Estate Notes
9. Transactions Insured or Guaranteed by a U.S. Government Agency or U.S. Government-sponsored Agency
10. Transactions that Qualify for Sale to, or Meet the Appraisal Standards of, a U.S. Government Agency or U.S. Government-sponsored Agency
11. Transactions by Regulated Institutions as Fiduciaries
12. Appraisals Not Necessary to Protect Federal Financial and Public Policy Interests or the Safety and Soundness of Financial Institutions
Appendix B
Evaluations Based on Analytical Methods or Technological Tools
Automated Valuation Models (AVMs)
Selecting an AVM(s)
Determining AVM Use
Validating AVM Results
Tax Assessment Valuations (TAVs)
Appendix C
Deductions and Discounts
Proposed Construction or Renovation
Partially Leased Buildings
Non-market Lease Terms
Tract Developments with Unsold Units: Raw Land, Developed Lots, Attached or Detached Single-family Homes, Condominiums
Appendix D
Glossary of Terms
Visit Library for Issuance
Appraisal and Evaluation Guidelines
Interagency
December 2, 2010
LENDERS COMPLIANCE GROUP is the first full-service, mortgage risk management firm in the country, specializing exclusively in mortgage compliance and offering a full suite of hands-on and automated services in residential mortgage banking.