CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Mortgage Risk Management. Show all posts
Showing posts with label Mortgage Risk Management. Show all posts

Monday, March 9, 2020

Announcement: Interagency Statement on Pandemic Planning

PRINT THIS

FFIEC has issued guidance on pandemic planning, entitled Interagency Statement on Pandemic Planning (“Guidance”). This issuance is meant to heighten the response of financial institutions to the coronavirus pandemic. The Guidance identifies actions that financial institutions should take to minimize the potential adverse effects of a pandemic. Specifically, the institution’s business continuity plan (BCP) should address pandemics and provide for a preventive program, a documented strategy scaled to the stages of a pandemic outbreak, a comprehensive framework to ensure the continuance of critical operations, a testing program and an oversight program to ensure that the plan is reviewed and updated.
We have been notifying you on how to protect your companies, customers, employees, families, and communities HERE. Please review those articles and act accordingly. 
If you want to discuss your specific pandemic preparation requirements, please contact us at compliance@lenderscompliancegroup.com.
We believe that Disaster Recovery and Business Continuity should be combined, but, as the Guidance states “pandemic planning activities should involve senior business management from all functional, business and product areas, including administrative, human resources, legal, IT support functions, and key product lines.”

The pandemic segment of the BCP must be "sufficiently flexible to address a wide range of possible effects that could result from a pandemic," and also be reflective of the institution’s size, complexity, and business activities. 

Our position is that there are two types of BCPs: standard and enhanced. 

The standard version lacks due diligence and independent risk assessment but does provide a basic outline to follow to ensure business continuity. 

The enhanced version is preferred by regulators because it contains due diligence and independent risk assessment. The enhanced version is obviously preferable to the standard version, because it provides specific due diligence, auditing done by subject matter experts, and leads to an independent risk assessment. The risk assessment reveals strengths and weaknesses further provides actionable recommendations. The standard version is less expensive to draft than the latter, but can be used as a baseline to ensure that your company is taking some affirmative actions to contain the spread of the coronavirus.

The Guidance is unequivocal in its directives: 
The adverse economic effects of a pandemic could be significant, both nationally and internationally. Due to their crucial financial and economic role, financial institutions should have plans in place that describe how they will manage through a pandemic event. Sound planning should minimize the disruptions to the local and national economy and should help the institution maintain the trust and confidence of its customers. [Emphasis in original.]
According to the Guidance, “pandemic planning presents unique challenges to financial institution management. Unlike natural disasters, technical disasters, malicious acts, or terrorist events, the impact of a pandemic is much more difficult to determine because of the anticipated difference in scale and duration.”
The following constitute the actions that management should be undertaking, per the Guidance:
1. A preventive program to reduce the likelihood that an institution’s operations will be significantly affected by a pandemic event, including the monitoring of potential outbreaks, educating employees, communicating and coordinating with critical service providers and suppliers, in addition to providing appropriate hygiene training and tools to employees.
2. A documented strategy that provides for scaling the institution’s pandemic efforts so they are consistent with the effects of a particular stage of a pandemic outbreak, such as first cases of humans contracting the disease overseas, first cases within the United States, and first cases within the organization itself. The strategy will also need to outline plans that state how to recover from a pandemic wave and proper preparations for any following wave(s).
3. A comprehensive framework of facilities, systems, or procedures that provide the organization the capability to continue its critical operations in the event that large numbers of the institution’s staff are unavailable for prolonged periods. Such procedures could include social distancing to minimize staff contact, telecommuting, redirecting customers from branch to electronic banking services, or conducting operations from alternative sites. The framework should consider the impact of customer reactions and the potential demand for, and increased reliance on, online banking, telephone banking, ATMs, and call support services. In addition, consideration should be given to possible actions by public health and other government authorities that may affect critical business functions of a financial institution.
4. A testing program to ensure that the institution’s pandemic planning practices and capabilities are effective and will allow critical operations to continue.
5. An oversight program to ensure ongoing review and updates to the pandemic plan so that policies, standards, and procedures include up-to-date, relevant information provided by governmental sources or by the institution’s monitoring program.
The Guidance provides helpful and important links to information resources, as follows:
1. The National Strategy for Pandemic Influenza (National Strategy) and the Implementation Plan for the National Strategy for Pandemic Influenza  (National Implementation Plan) issued by the federal government provide a complete guide to pandemic planning. 

Tuesday, September 18, 2018

Mortgage Fraud Challenges: How to Catch a Crook


Chairman & Managing Director

Two of our Directors will be attending the MBA’s “Risk Management, QA & Fraud Prevention Forum,” held in Los Angeles, in September. Attending this venue will be Brandy George, who is the Executive Director of LCG Quality Control and Michael Pfeifer, who is a Director of Legal and Regulatory Compliance. I remember attending the first forum many years ago. The attendance was modest. Although risk management was strengthening, I felt the term risk management was much too broad, as it could be (and was) applied to many industries. So, I coined the term “Mortgage Risk Management” and it caught on! My view has been that mortgage banking poses a unique set of risks that require significant knowledge, experience, and expertise. Turns out, this insight has been reinforced over the years. Now, this event is highly attended and is brimming with new ways to handle quality assurance, mortgage fraud prevention, and risk management oversight.

As I contemplated this forthcoming conference, I thought of the difficulties that mortgage originators have in handling the challenges of mortgage fraud in particular. This is a nasty business and not for the faint hearted! When my firm conducts audits of the loan flow process, it is not unusual to find gaps – perhaps ‘chasms’ is a better word! – in a company’s procedures for managing mortgage fraud risk. It still surprises me, after so many decades in mortgage banking compliance and financial institution management, that the fraudsters seem to have no limit to their scheming, conniving, crafty, wily, and underhanded cunning. These guys are as slippery as a darkly oleaginous grease slick.

Maybe I can’t stop these swindlers and shysters from doing what they do, but I can let you know some of the lessons my firm, Lenders Compliance Group®, has learned in knowing how to identify and trap them. I may not have all the answers, but I sure do have a lot of experience in hooking the crook. So, come with me on a brief walk through the mortgage fraud maze, as I jot down some of my reflections, and perhaps you should consider using some of my ideas to fine-tune your own mortgage fraud prevention procedures.

Let’s start with a simple outline of what fraudsters do!


During the mortgage lending process, a fraudster is a person who knowingly does any of the following:

  • Makes, uses, or facilitates any deliberate misstatement, misrepresentation, or omission with the intention that it be relied upon by a mortgage lender, borrower, or any other party to the mortgage lending process;
  • Receives any proceeds or any other funds in connection with a closing involving mortgage fraud; or
  • Files or causes to be filed with the county recorder, any document that contains a deliberate misstatement, misrepresentation, or omission.

In my view, there are two types of mortgage fraud: the first is fraud for property, and the second is fraud for profit.

Thursday, December 14, 2017

Risk Management Principles

WHITE PAPER

Chairman and Managing Director

A number of years ago I coined the term “Mortgage Risk Management,” in order to differentiate managing mortgage risk from the many other types of risk management. At that time, risk management was associated mostly with such areas as pharmaceutical companies, stock brokers, and information technology firms. My view was that mortgage loan originations and mortgage servicing present a unique set of risks to consumers, loan originators, mortgage servicers, and those industries and individuals that depend on the foregoing for their financial well-being. The term became popular and is in now in commonplace use.

But I also realized that managing mortgage risk would require a strong commitment on the part of companies, because regulatory oversight would fluctuate, often prey to the prevailing politics, and that meant companies had to build out an environment where managing risk could be joined to complying with the regulations themselves. I felt that a company could be successful in managing its mortgage risk if it developed a “Culture of Compliance.”[i] I wrote articles on the Culture of Compliance and gave numerous talks on this subject. In due course, the term was picked up by regulators and made a feature of everyday parlance.

I think consumers, mortgage loan originators, and regulators read my articles and attend my lectures because I strive to give everyone a fair shake. I call it like I see it, without fear of whether some view or another is stepping on somebody’s sacred political toes. Sometimes there really is a right and a wrong, irrespective of the controversy surrounding a regulatory mandate.

My standard is simple: doing all we can to protect the consumer is the only way to protect the viability of the mortgage loan originator and mortgage servicer in the long run.

And the only effective way to ensure that the originator or servicer is protected is to manage its risk. That is the basis for the formation of our firm so many years ago. Lenders Compliance Group®, which has grown to a national mortgage risk management firm over the years, has never lost its original mission to not only provide comprehensive risk management to mortgage industry participants but also offer ways and means to help build a Culture of Compliance for our clients.

Every loan originator and mortgage servicer should be a consumer advocate. Consumers will flock to the companies that present the very best standards of ethics and reliability. If any originating or servicing entity waits for a regulatory agency to tell it what to do on behalf of consumer financial protection, it has already lost the right to expect the consumer’s loyalty.

Wednesday, March 26, 2014

Compliance Collaborative, Inc.

For some time I have been concerned about the way certain "cooperatives" seem to be crossing the line in providing compliance support services (via selected, alliance vendors) at the same time that they are providing underwriting, processing, loan products, and various operations functions. Although these cooperatives have (yet) to come under the scrutiny of regulators, I think they one day might, since compliance and underwriting (for example) should not occupy the same space.

I am sure that all the legal bases of their way of doing business have been fully explored and satisfied. And I get that lenders want to go to a cooperative and receive all the services they need, including compliance support. However, in my view, when it comes to compliance there should not be such an ostensibly unorthodox configuration. Indeed, in conversations I have had with regulators, they have pointed out to me that this is a concern of theirs.

Therefore, I have decided to start a new and additional way to serve the compliance needs of the mortgage banking community: the Compliance Collaborative, Inc. (CCI).

The Compliance Collaborative has been in the planning for some time and is already building alliances with well-established vendors that offer compliance - and exclusively compliance! - to residential mortgage lenders and originators.

CCI is now the first and only firm in the country exclusively devoted to mortgage banking compliance that provides a collaboration of the best and finest mortgage compliance providers. And the very first firm to join CCI is Lenders Compliance Group!

Many compliance vendors, consultants, risk management professionals, and law firms are joining CCI in order to provide their respective services to CCI clientele. Any member firm may always be retained separately. But member firms may also be individually retained through CCI or as part of a package of compliance solutions, thereby offering cost-effective and reasonable fees.

In the next few weeks, you will be hearing more about CCI's new website and service plans. We recently issued a Press Release about it and our efforts are being picked up by the media, for instance, here and here and here.

In the meantime, if you want me to keep you in mind for a call or email and new information, please let me know.

We will be providing a suite of services soon and would welcome your feedback and requests. I'll be glad to contact you to ensure that you are given an early opportunity to retain the Compliance Collaborative for your compliance needs!

Best wishes,
Jonathan Foxx
President & Managing Director

Thursday, December 12, 2013

Social Media: Consumer Compliance Risk Management Guidance

On December 11, 2013, the Federal Financial Institutions Examination Council (FFIEC) released final guidance (“Guidance”) on the applicability of consumer protection and compliance laws, regulations, and policies to activities conducted via social media by banks, savings associations, and credit unions, as well as nonbank entities supervised by the Consumer Financial Protection Bureau (collectively, “financial institutions”). The Guidance was issued final on behalf of the Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve (Board), Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), the Consumer Financial Protection Bureau (CFPB) (collectively, the “Agencies”), and the State Liaison Committee (SLC).

The Guidance is intended to help financial institutions understand potential consumer compliance and legal risks, as well as related risks, such as reputation and operational risks associated with the use of social media, along with expectations for managing those risks. It also provides considerations that financial institutions may find useful in conducting risk assessments and crafting and evaluating policies and procedures regarding social media. Although this Guidance does not impose any new requirements on financial institutions, as with any process or product channel, financial institutions are expected to manage potential risks associated with social media usage and access.

The Final Rule is meant to highlight and manage potential risks to financial institutions and consumers; however, financial institutions should ensure their risk management programs provide oversight and controls commensurate with the risks presented by the types of social media in which the financial institution is engaged, including, but not limited to, the risks outlined within the Guidance.

In this article, I will set forth an outline of the Guidance along with suggestions to manage the risks associated with the use of social media.* I have also published a helpful article on this topic, entitled Social Media and Networking Compliance, which may be downloaded from our Library. 

WHAT IS SOCIAL MEDIA?

For purposes of the Guidance, messages sent via traditional email or text message, standing alone, do not constitute social media, although such communications may be subject to a number of laws and regulations discussed in the Guidance. However, messages sent through social media channels are social media. According to the Guidance, social media is considered to be a form of interactive online communication in which users can generate and share content through text, images, audio, and/or video. Social media can take many forms, including, but not limited to, micro-blogging sites; forums, blogs, customer review web sites and bulletin boards; photo and video sites; sites that enable professional networking; virtual worlds; and social games. Social media can be distinguished from other online media in that the communication tends to be more interactive. 

RISK MANAGEMENT PROGRAM

The Guidance suggests that a financial institution should have a risk management program that allows it to identify, measure, monitor, and control the risks related to social media. The size and complexity of the risk management program should be commensurate with the breadth of the financial institution’s involvement in this medium.

For instance, a financial institution that relies heavily on social media to attract and acquire new customers should have a more detailed program than one using social media only to a very limited extent. An observation made in the Guidance, and worth noting, is though a financial institution’s own risk assessment indicates that it has chosen not to use social media, nevertheless, it should “still consider the potential for negative comments or complaints that may arise within the many social media platforms”, and, when appropriate, evaluate what, if any, action it will take to monitor for such comments and determine if a response is needed. 

FEATURES OF A RISK MANAGEMENT PROGRAM

The risk management program should be designed with participation from specialists in compliance, technology, information security, legal, human resources, and marketing. Financial institutions should also provide guidance and training for employee official use of social media.

The Guidance stipulates at least seven components of a risk management program. These include, but are not limited to:

1. A governance structure with clear roles and responsibilities whereby the board of directors or senior management direct how using social media contributes to the strategic goals of the institution (for instance, through increasing brand awareness, product advertising, or researching new customer bases) and establishes controls and ongoing assessment of risk in social media activities;

2. Policies and procedures (either stand-alone or incorporated into other policies and procedures) regarding the use and monitoring of social media and compliance with all applicable consumer protection laws and regulations, and incorporation of guidance as appropriate. Further, policies and procedures should incorporate methodologies to address risks from online postings, edits, replies, and retention;

3. A risk management process for selecting and managing third-party relationships in connection with social media;

4. An employee training program that incorporates the institution’s policies and procedures for official, work-related use of social media, and potentially for other uses of social media, including defining impermissible activities;

5. An oversight process for monitoring information posted to proprietary social media sites administered by the financial institution or a contracted third party;

6. Audit and compliance functions to ensure ongoing compliance with internal policies and all applicable laws and regulations, and incorporation of guidance as appropriate; and

7. Parameters for providing appropriate reporting to the financial institution’s board of directors or senior management that enable periodic evaluation of the effectiveness of the social media program and whether the program is achieving its stated objectives. 

WHAT ARE THE RISKS?

The use of social media to attract and interact with customers can impact a financial institution’s risk profile, including:

· Risk of harm to consumers
· Compliance and legal risks
· Operational risks, and
· Reputation risks.

In our own reviews on behalf of our clients, we have found that the foregoing risks are increased due to poor due diligence, oversight, or control on the part of the financial institution.

Let us now give consideration to each of the Risk Areas, with respect to the risks posed by Social Media. Suggestions are emboldened in each synopsis.

Friday, June 15, 2012

The Rules of Operational Risk

Recently, I spoke with several clients who had attended mortgage industry conferences. Each one of them pointed out the very same fact: operational risk and regulatory compliance are the most prominent subjects being discussed. Thinking of learning more about new loan products and services, they left these conferences wondering about how they would ever be able to implement all the regulatory requirements being placed on them. As an old friend who runs a mid-tier, mortgage banking company said to me, "I came as a mortgage company and left as a compliance company!"
One of them said, "you know, Jonathan, you're sort of in the 'cat-bird seat' now, since you were among the first to predict that mortgage compliance would oneday dominate how we originate loans." I'm not sure if that was a back-handed compliment, but I appreciate the sentiment, nonetheless. At least LCG tries to lift some of the regulatory burden borne by our clients and free up their time to do what they do best: originate loans.
That said, let's acquaint ourselves with operational risk and how to put some structure into risk management.*
IN THIS ARTICLE
Framework
Controlling Credit Risk
Four Basic Rules
Six Even More Basic Rules
Articles and Newsletters
_______________________________________
Framework
First and foremost, compliance decisions should be made not only on the basis of sound policy and regulatory mandates but also on the basis of how compliance procedures are viewed by regulators. Examiners want to see a financial institution enforcing existing regulatory requirements. However, they also are not antagonists on a witch hunt. They honestly want to product the kind of findings - good or bad - that will help a company to thrive. They do not get a thrill out of putting forth adverse findings.
Building a solid framework begins with cataloging the company's people, processes and technology, and continues on into deriving the means by which a stable policy is designed to formalize the way the company tracks operational risk and identifies those risks within the organization's personnel and departments. Tasking, tracking, and managing risk are central features of governance.
Companies large and small should implement operational risk frameworks that formalize their operational risk management. There really is no excuse, in this day and age - especially with ready access to information and guidance - that any size financial institution cannot position operational risk practices into the loan flow process.

Risk can't be managed if there is no framework through which to manage it.
Reviewing and formalizing an operational risk framework does not need to be a complicated exercise. The size, complexity, and risk profile of the financial institution will dictate the ways and means by which risk is managed.
Controlling Credit Risk
At the start of this year, I published an article about Controlling Credit Risk [PDF]. In the article I pointed out that risk is identifiable and measurable - and it can be controlled. To get a sense of how my firm goes about evaluating credit risk and the concurrent role played by risk management, I outlined two features of managing risk: Quantity of Risk and Quality of Risk Management.
And I concluded with a section, entitled Implementing Risk Management, in which I offered some guidance about how to use credit risk information effectively to fortify a financial institution.
I urge you to download and read it. [PDF] In formalizing a framework to manage operational risk, you need to get some idea of how firms like mine work with clients to ensure appropriate risk management strategies.
Four Basic Rules
(1) Analyze Processes. This requires creating a catalogue of the company's operational processes. This is always the first step. It can be presented like a flow chart or nested folders or in any form that makes sense to management, so long as it makes logistical and experiential sense. In effect, the analysis must reflect the way that the company actually conducts its business.
(2) Identify Risks. Now that processes have been analyzed, each process should be considered on the basis of efficiency, data integrity, and potential risks. This is accomplished through an internal audit, external audit, or designating a competent employee to conduct a generic self-assessment. Whatever the choice, be sure to standardize the evaluation method.
(3) Centralize Policies. Bring together all the company's policies and procedures. Take inventory and determine which policy statements are missing, which ones are outdated, and which ones may be redundant. The requirements of disparate policy statements may conflict with one another, so gather them all together and assess them as a group.
(4) Establish a Master Policy. At this point - having analyzed processes, identified risks, and centralized policies - we are able to draft a master policy. Such an approach is reflective of 'best practices' governance. The master policy sets forth the overarching set of policies and rules that govern the company's management of operational risk. It is the "map" that serves as a guide to the operational risk framework. Be sure that the master policy also provides 'track-back' features and identifies the "owners" of each risk area.
Six Even More Basic Rules
I mentioned above that the master policy is the "map" to the operational risk framework. But, as the philosopher Alfred Korzybski noted, the map is not the territory. Working through the four basic rules takes time and resources. Sometimes we can't even get to the Four Basic Rules, because we have not taken into consideration the Six Even More Basic Rules.
Here follows those six rules, without which an operational risk framework is not really attainable.
(1) Assemble the Management Team. Bring together the company's executive and senior management. Start a conversation about operational risk and how to create a top-down approach toward risk management. Do this at least annually.
(2) Make Lists. Before the management meeting, each member of the management team should draft a list - long or short - of not only the known operational risks but the potential or unexpected risks. Assume that "Black Swans" do happen! Managers should offer insights relating to their own operational area as well as any other areas of the company. An unaccounted for risk, actual or potential, could cause massive financial, strategic, legal, and regulatory damage.
(3) Detail the Risk. Specify the risk in as much detail as possible. State the consequences of risk failure. And, where possible, always provide a solution. If a risk is perceived, seek a way to mitigate or remove it. Don't waste time on solutions seeking a risk; concentrate on risks seeking a solution.
(4) Discuss Risk. In an open and conversational way, discuss the lists. Determine if there are coinciding or divergent perceptions of risk. Identify where there are gaps in knowledge or implementation. And encourage a discussion regarding perceived risk, to be sure that there is some general understanding about the levels of risk tolerance.
(5) Draft a Master List. Now build a consensus amongst the assembled management team. Create priorities to the various lists of risks provided by each participant. Determine the mitigation strategies that are acceptable, given the company's risk profile and risk tolerance.
(6) Work the List. Implement the Master List, which may include the Four Basic Rules outlined above, but may just form sufficient guidelines and directives to establish appropriate means to manage operational risk. Appoint a member of the management team to monitor the Master List and update the list for those risks that have been resolved or mitigated.
Articles and Newsletters
Articles - Newsletters
_______________________________________
* Jonathan Foxx is the President & Managing Director of Lenders Compliance Group

Wednesday, January 18, 2012

Controlling Credit Risk

We begin 2012 with the certain knowledge that many new regulations and responsibilities have made significant and costly demands on lenders, servicers, mortgage brokers, banks, investors, and mortgage securitizers to revise and strengthen plans to assure their economic survival. Many compliance departments throughout the country have set forth robust compliance calendars in order to monitor, test for, and implement federal and state guidelines. [*]
The primary source of revenue for the aforementioned companies (collectively, “financial institutions”) is the negotiating, extending, administering, and packaging of credit. Extension of credit and credit risk are really inseparable features of mortgage loan originations – one does not exist without the other.
Credit risk is quite measurable, especially with respect to any activity that poses a risk to earnings and capital. It is no secret that inadequate risk management is a leading cause of the failure of financial institutions. Just as credit risk and extension of credit are inseparable, so also are they inseparable from risk management. Only to the extent that credit risk and appropriate risk management procedures are identified, analyzed, established, and implemented may financial institutions claim to have safe and sound lending practices.
Risk management (often referred to, generically, as Compliance) should not formally come under the rubric of the so-called “Best Practices” section of corporate governance. In my view, risk management is not an elective, a negotiable issue, a good operating practice, a mere technique consistently providing superior results, a Six Sigma template, or a business management strategy. Rather, risk management is, and ought to be, an inherent and essential, evaluative and ministerial function reaching to virtually all intrinsic aspects of a financial institution’s business model. This is why I coined the term “Mortgage Risk Management,” because it stands on its own, a specialization that provides a firm foundation to the residential mortgage loan flow process – from point of sale to securitization. Put otherwise, it is the one and only “fail-safe” means by which a board of directors may ensure that management effectively implements internal processes designed to identify, measure, monitor, and control credit risk. [†]
Close consideration of appropriate risk management practices is vital to a financial institution’s stability, most especially in the outset of a new year and at all other times. But what is risk management? And, how does risk management affect a financial institution’s way of doing business?
In this article I will provide a brief outline of two key areas where credit risk review and risk management conjoin directly to impact a financial institution’s capability to conduct business and manage a thicket of regulations. Drawing on my own experience in working with our clients, I will offer an overview of what risk management entails, whether conducted internally or through external resources.
To get a sense of a typical approach involved in evaluating credit risk and the concurrent role played by risk management, I will outline the following areas: Quantity of Risk and Quality of Risk Management.
In a penultimate section, entitled Implementing Risk Management, I will offer some guidance about how to use credit risk information effectively to fortify a financial institution.
Quantity of Risk
I define quantity of risk as the level of credit risk associated with the credit portfolio of a financial institution.
Generally, there are three levels for quantity of risk: low, moderate, or high.
In evaluating credit risk, there are nine areas of review that should be undertaken.
1) Risk Level
  • Consider in the analysis the size of the exposure associated with each of the areas bulleted below, their risk profiles, credit quality indicators, amounts, volatility, and trends:
    • delinquencies
    • criticized and classified loans
    • nonaccrual or nonperforming loans
    • losses
    • other credit quality metrics used by the financial institution (i.e., weighted average: risk grade or default probability)
    • underwriting standards
    • exceptions to policy
2) Risk Implications
  • There are two areas in particular that are determinative with respect to risk implications:
    • Significant growth in the size of a credit risk exposure, including whether such growth might be masking deterioration in credit quality indicators, and
    • Material changes in policies, procedures, or underwriting standards.