CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts

Monday, January 13, 2025

What to Expect from a Fannie MORA audit?

Request Article 

Request MORA Tune-up® Information 

QUESTION 

Last month, you answered a question about doing an internal audit in advance of Fannie’s MORA audit. We did not pay much attention to it because (A) we never had a MORA audit, and (B) we did not expect a MORA audit anytime soon. Then, all hell broke loose! 

Yesterday, we got a letter from Fannie Mae telling us that they will be scheduling a date for an on-site audit. They are requesting policies, procedures, and many other documents. There are due dates. This review makes a state banking exam look like child’s play. But I’m a QC manager, so I don’t have the whole picture of our risks. However, I do know one thing: we are not ready for this MORA audit. 

The CEO called a team meeting in the conference room. Our compliance manager is in charge, and everyone reports to her. I got your name at the meeting because she said we are going to use you to do a MORA Tune-up®. I just wish they would have done this sooner. 

What I need – and I think they need it too – is some idea of what we can expect from the MORA exam. I hope you don’t wait to reply. The compliance manager and others in management read your articles. They pass them around to us all the time. Please tell us what to expect about the MORA process. 

What is the audit process of a Fannie MORA audit? 

SOLUTION 

MORA Tune-up® 

RESPONSE 

If you want a copy of this article, please contact us here. 

We realize your question is urgent. Accordingly, we are prioritizing a response. You only have a few weeks to get ready for the MORA audit, the purpose of which is for Fannie Mae to evaluate your company’s compliance with Fannie guidelines as well as assess the operational risks. 

For those who don’t know, Mortgage Origination Risk Assessment (MORA) is a Fannie Mae review of a Fannie Seller/Servicer. It is intended to be a collaborative engagement led by the review team with the active participation of your organization.[i]

Getting our MORA Tune-up® engaged is one of several readiness activities you must undertake as soon as possible. Ours is the pioneer of the Compliance Tune-up, a unique review that provides a risk assessment and self-evaluation to satisfy the Second Line of Defense. I am grateful that your compliance manager chose Lenders Compliance Group. Nevertheless, to all our subscribers, please know that a few compliance and law firms offer to prepare you for the MORA review. Pick one you trust and get it done! 

There are seven phases in the MORA review process, and I will outline them for you. My outline will give you a high-level view. You should not delay! 

Here are the seven phases of a MORA review: 

Phase 1: Selecting the Organization 

Phase 2: Confirmation and Engagement 

Phase 3: Document Request and Receipt 

Phase 4: Process Evaluation 

Phase 5: Interviews 

Phase 6: Final Assessment 

Phase 7: Remediation 

I am going to provide a brief overview of each phase. However, numerous contingencies can affect the process and outcome. Take this review as a deep dive, one that will make your company stronger and its relationship with Fannie more durable. It is not too late to get started immediately. 

PHASE 1: SELECTING THE ORGANIZATION 

Fannie Mae selects organizations for a review using risk-based inclusion criteria and provides advance notice to the organization prior to scheduling the review. A member of the review team begins the process by compiling the organization’s pertinent contact information to start the review before moving to Phase 2. 

We are often asked if there is a way to predict whether and when the selection takes place. The short answer is No. The best answer is Soon. In other words, always be prepared.

PHASE 2: Confirmation and Engagement 

There are obviously two parts to this phase: the first part involves confirmation, and the second part involves scheduling. These two parts are interfaced. What happens is your point person – in your case, the compliance manager – will discuss Fannie’s BAMS team, that is, its Business Account Management Solutions team, to discuss some basics. The MORA team is independent of the BAMS team. This is a sort of Question and Answer format where the BAMS team gathers the following information:

Thursday, January 9, 2025

Policy & Procedures and Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

Customized Compliance Library

Policies Tune-up®

CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

Thursday, December 12, 2013

Social Media: Consumer Compliance Risk Management Guidance

On December 11, 2013, the Federal Financial Institutions Examination Council (FFIEC) released final guidance (“Guidance”) on the applicability of consumer protection and compliance laws, regulations, and policies to activities conducted via social media by banks, savings associations, and credit unions, as well as nonbank entities supervised by the Consumer Financial Protection Bureau (collectively, “financial institutions”). The Guidance was issued final on behalf of the Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve (Board), Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), the Consumer Financial Protection Bureau (CFPB) (collectively, the “Agencies”), and the State Liaison Committee (SLC).

The Guidance is intended to help financial institutions understand potential consumer compliance and legal risks, as well as related risks, such as reputation and operational risks associated with the use of social media, along with expectations for managing those risks. It also provides considerations that financial institutions may find useful in conducting risk assessments and crafting and evaluating policies and procedures regarding social media. Although this Guidance does not impose any new requirements on financial institutions, as with any process or product channel, financial institutions are expected to manage potential risks associated with social media usage and access.

The Final Rule is meant to highlight and manage potential risks to financial institutions and consumers; however, financial institutions should ensure their risk management programs provide oversight and controls commensurate with the risks presented by the types of social media in which the financial institution is engaged, including, but not limited to, the risks outlined within the Guidance.

In this article, I will set forth an outline of the Guidance along with suggestions to manage the risks associated with the use of social media.* I have also published a helpful article on this topic, entitled Social Media and Networking Compliance, which may be downloaded from our Library. 

WHAT IS SOCIAL MEDIA?

For purposes of the Guidance, messages sent via traditional email or text message, standing alone, do not constitute social media, although such communications may be subject to a number of laws and regulations discussed in the Guidance. However, messages sent through social media channels are social media. According to the Guidance, social media is considered to be a form of interactive online communication in which users can generate and share content through text, images, audio, and/or video. Social media can take many forms, including, but not limited to, micro-blogging sites; forums, blogs, customer review web sites and bulletin boards; photo and video sites; sites that enable professional networking; virtual worlds; and social games. Social media can be distinguished from other online media in that the communication tends to be more interactive. 

RISK MANAGEMENT PROGRAM

The Guidance suggests that a financial institution should have a risk management program that allows it to identify, measure, monitor, and control the risks related to social media. The size and complexity of the risk management program should be commensurate with the breadth of the financial institution’s involvement in this medium.

For instance, a financial institution that relies heavily on social media to attract and acquire new customers should have a more detailed program than one using social media only to a very limited extent. An observation made in the Guidance, and worth noting, is though a financial institution’s own risk assessment indicates that it has chosen not to use social media, nevertheless, it should “still consider the potential for negative comments or complaints that may arise within the many social media platforms”, and, when appropriate, evaluate what, if any, action it will take to monitor for such comments and determine if a response is needed. 

FEATURES OF A RISK MANAGEMENT PROGRAM

The risk management program should be designed with participation from specialists in compliance, technology, information security, legal, human resources, and marketing. Financial institutions should also provide guidance and training for employee official use of social media.

The Guidance stipulates at least seven components of a risk management program. These include, but are not limited to:

1. A governance structure with clear roles and responsibilities whereby the board of directors or senior management direct how using social media contributes to the strategic goals of the institution (for instance, through increasing brand awareness, product advertising, or researching new customer bases) and establishes controls and ongoing assessment of risk in social media activities;

2. Policies and procedures (either stand-alone or incorporated into other policies and procedures) regarding the use and monitoring of social media and compliance with all applicable consumer protection laws and regulations, and incorporation of guidance as appropriate. Further, policies and procedures should incorporate methodologies to address risks from online postings, edits, replies, and retention;

3. A risk management process for selecting and managing third-party relationships in connection with social media;

4. An employee training program that incorporates the institution’s policies and procedures for official, work-related use of social media, and potentially for other uses of social media, including defining impermissible activities;

5. An oversight process for monitoring information posted to proprietary social media sites administered by the financial institution or a contracted third party;

6. Audit and compliance functions to ensure ongoing compliance with internal policies and all applicable laws and regulations, and incorporation of guidance as appropriate; and

7. Parameters for providing appropriate reporting to the financial institution’s board of directors or senior management that enable periodic evaluation of the effectiveness of the social media program and whether the program is achieving its stated objectives. 

WHAT ARE THE RISKS?

The use of social media to attract and interact with customers can impact a financial institution’s risk profile, including:

· Risk of harm to consumers
· Compliance and legal risks
· Operational risks, and
· Reputation risks.

In our own reviews on behalf of our clients, we have found that the foregoing risks are increased due to poor due diligence, oversight, or control on the part of the financial institution.

Let us now give consideration to each of the Risk Areas, with respect to the risks posed by Social Media. Suggestions are emboldened in each synopsis.

Friday, June 15, 2012

The Rules of Operational Risk

Recently, I spoke with several clients who had attended mortgage industry conferences. Each one of them pointed out the very same fact: operational risk and regulatory compliance are the most prominent subjects being discussed. Thinking of learning more about new loan products and services, they left these conferences wondering about how they would ever be able to implement all the regulatory requirements being placed on them. As an old friend who runs a mid-tier, mortgage banking company said to me, "I came as a mortgage company and left as a compliance company!"
One of them said, "you know, Jonathan, you're sort of in the 'cat-bird seat' now, since you were among the first to predict that mortgage compliance would oneday dominate how we originate loans." I'm not sure if that was a back-handed compliment, but I appreciate the sentiment, nonetheless. At least LCG tries to lift some of the regulatory burden borne by our clients and free up their time to do what they do best: originate loans.
That said, let's acquaint ourselves with operational risk and how to put some structure into risk management.*
IN THIS ARTICLE
Framework
Controlling Credit Risk
Four Basic Rules
Six Even More Basic Rules
Articles and Newsletters
_______________________________________
Framework
First and foremost, compliance decisions should be made not only on the basis of sound policy and regulatory mandates but also on the basis of how compliance procedures are viewed by regulators. Examiners want to see a financial institution enforcing existing regulatory requirements. However, they also are not antagonists on a witch hunt. They honestly want to product the kind of findings - good or bad - that will help a company to thrive. They do not get a thrill out of putting forth adverse findings.
Building a solid framework begins with cataloging the company's people, processes and technology, and continues on into deriving the means by which a stable policy is designed to formalize the way the company tracks operational risk and identifies those risks within the organization's personnel and departments. Tasking, tracking, and managing risk are central features of governance.
Companies large and small should implement operational risk frameworks that formalize their operational risk management. There really is no excuse, in this day and age - especially with ready access to information and guidance - that any size financial institution cannot position operational risk practices into the loan flow process.

Risk can't be managed if there is no framework through which to manage it.
Reviewing and formalizing an operational risk framework does not need to be a complicated exercise. The size, complexity, and risk profile of the financial institution will dictate the ways and means by which risk is managed.
Controlling Credit Risk
At the start of this year, I published an article about Controlling Credit Risk [PDF]. In the article I pointed out that risk is identifiable and measurable - and it can be controlled. To get a sense of how my firm goes about evaluating credit risk and the concurrent role played by risk management, I outlined two features of managing risk: Quantity of Risk and Quality of Risk Management.
And I concluded with a section, entitled Implementing Risk Management, in which I offered some guidance about how to use credit risk information effectively to fortify a financial institution.
I urge you to download and read it. [PDF] In formalizing a framework to manage operational risk, you need to get some idea of how firms like mine work with clients to ensure appropriate risk management strategies.
Four Basic Rules
(1) Analyze Processes. This requires creating a catalogue of the company's operational processes. This is always the first step. It can be presented like a flow chart or nested folders or in any form that makes sense to management, so long as it makes logistical and experiential sense. In effect, the analysis must reflect the way that the company actually conducts its business.
(2) Identify Risks. Now that processes have been analyzed, each process should be considered on the basis of efficiency, data integrity, and potential risks. This is accomplished through an internal audit, external audit, or designating a competent employee to conduct a generic self-assessment. Whatever the choice, be sure to standardize the evaluation method.
(3) Centralize Policies. Bring together all the company's policies and procedures. Take inventory and determine which policy statements are missing, which ones are outdated, and which ones may be redundant. The requirements of disparate policy statements may conflict with one another, so gather them all together and assess them as a group.
(4) Establish a Master Policy. At this point - having analyzed processes, identified risks, and centralized policies - we are able to draft a master policy. Such an approach is reflective of 'best practices' governance. The master policy sets forth the overarching set of policies and rules that govern the company's management of operational risk. It is the "map" that serves as a guide to the operational risk framework. Be sure that the master policy also provides 'track-back' features and identifies the "owners" of each risk area.
Six Even More Basic Rules
I mentioned above that the master policy is the "map" to the operational risk framework. But, as the philosopher Alfred Korzybski noted, the map is not the territory. Working through the four basic rules takes time and resources. Sometimes we can't even get to the Four Basic Rules, because we have not taken into consideration the Six Even More Basic Rules.
Here follows those six rules, without which an operational risk framework is not really attainable.
(1) Assemble the Management Team. Bring together the company's executive and senior management. Start a conversation about operational risk and how to create a top-down approach toward risk management. Do this at least annually.
(2) Make Lists. Before the management meeting, each member of the management team should draft a list - long or short - of not only the known operational risks but the potential or unexpected risks. Assume that "Black Swans" do happen! Managers should offer insights relating to their own operational area as well as any other areas of the company. An unaccounted for risk, actual or potential, could cause massive financial, strategic, legal, and regulatory damage.
(3) Detail the Risk. Specify the risk in as much detail as possible. State the consequences of risk failure. And, where possible, always provide a solution. If a risk is perceived, seek a way to mitigate or remove it. Don't waste time on solutions seeking a risk; concentrate on risks seeking a solution.
(4) Discuss Risk. In an open and conversational way, discuss the lists. Determine if there are coinciding or divergent perceptions of risk. Identify where there are gaps in knowledge or implementation. And encourage a discussion regarding perceived risk, to be sure that there is some general understanding about the levels of risk tolerance.
(5) Draft a Master List. Now build a consensus amongst the assembled management team. Create priorities to the various lists of risks provided by each participant. Determine the mitigation strategies that are acceptable, given the company's risk profile and risk tolerance.
(6) Work the List. Implement the Master List, which may include the Four Basic Rules outlined above, but may just form sufficient guidelines and directives to establish appropriate means to manage operational risk. Appoint a member of the management team to monitor the Master List and update the list for those risks that have been resolved or mitigated.
Articles and Newsletters
Articles - Newsletters
_______________________________________
* Jonathan Foxx is the President & Managing Director of Lenders Compliance Group

Tuesday, September 20, 2011

Lenders Compliance Group Adds Two New Directors

I am pleased to inform you that Lenders Compliance Group, Inc. today joined forces with Abrams Garfinkel Margolis Bergson, LLP
Together, our two firms will build on existing tools, processes, risk assessment analyticals, and resources to provide a "best practices" approach to residential mortgage compliance.
This strategic alliance will offer the most comprehensive, hands-on, mortgage risk management guidance to the mortgage industry. 
I would like to tell you more about this exciting alliance.
Strategic Alliance
Lenders Compliance Group (LCG) is a nationwide risk management firm, and Abrams Garfinkel Margolis Bergson (AGMB) is a national law firm.
Both firms offer regulatory guidance to members of the real estate and banking industries.  
LCG is a national company that is widely known to be a pioneer in outsourcing and auditing solutions for residential mortgage compliance. The organization consists of Directors, Group Administrators, Attorneys, Compliance Consultants, Former Federal and State Regulators, Credentialed Auditors, and Subject Matter Experts in all areas of mortgage risk management.
And Lenders Compliance Group provides a suite of services for all areas of mortgage banking, such as loan audit analytics, research, regulatory compliance guidance, loan origination channel and product development, mortgage quality control, and due diligence reviews.
AGMB has extensive experience in representing its clients in all aspects of residential and commercial real estate and lending transactions.  A significant portion of AGMB's practice is dedicated to advising its clients on compliance, licensing and regulatory issues. In particular, Abrams Garfinkel Margolis Bergson represents mortgage banks, mortgage brokers, and real estate brokers on the vast array of laws and regulations which affect their businesses.
Two New Directors
Neil Garfinkel, named partner of AGMB and the head of its real estate and banking practices, is joining LCG as a Director of Legal and Regulatory Compliance and Real Estate Brokerage Compliance.
Michael G. Barone, head of regulatory compliance for AGMB, is joining LCG as a Director of Legal and Regulatory Compliance.
Comments: Neil Garfinkel
"After working with Jonathan Foxx on a variety of matters through the years it is clear that Jonathan and LCG provide a wealth of information and unprecedented access to mortgage risk management support within the mortgage banking and mortgage brokerage industries.
The procedures and requirements for originating residential mortgage loans are experiencing enormous changes and will continue to do so for many years to come. This alliance ensures that AGMB and its clients are well versed and represented, with respect to all regulatory compliance issues affecting their businesses.
We are excited to bring together our resources and provide the mortgage industry with 'best practices' solutions that strengthen our clients and the industry."
Comments: Jonathan Foxx
"Abrams Garfinkel is a well-respected leader in providing legal and regulatory counsel.
The mortgage banking and mortgage brokerage industries have needed appropriate, affordable resources to implement compliance solutions that reflect reliable and accurate best practices.
So this kind of alliance is somewhat unique to mortgage banking and mortgage brokerage. It offers a 'best practices' approach for our respective clients: top legal talent at AGMB who are experienced in mortgage banking and mortgage brokerage combined with top risk management professionals at LCG who are experienced in all areas of regulatory and mortgage banking compliance.
Our suite of auditing and due diligence services further supports these cost-effective efforts."
Some Thoughts on Best Practices
We all know that best practices are used to maintain excellence through self-assessment or benchmarking. But it is far more than that: to effectuate change a cultural shift often must take place within a business. Our clients respect best practices and seek ways to implement them. Compliance support and best practices are at the basis of bringing about a healthy and vibrant business environment.
However, the mortgage banking industry should continue to invigorate its commitment to best practices with respect to compliance solutions. It was with this purpose in mind that I founded the Association of Residential Mortgage Compliance Professionals, now at over 325 members. The ARMCP provides a forum for advocacy as well as a means to strengthen the mortgage industry from within. And I developed the CORE® matrix, now an industry standard that is used to evaluate the effectiveness of a financial institution's regulatory compliance implementation.
In this new stage in the continuing growth of Lenders Compliance Group, I am pleased to join forces with Abrams Garfinkel Margolis Bergson, and I welcome Neil Garfinkel and Michael Barone, our two new Directors.
Together, we will continue to work toward providing the most reliable, residential mortgage compliance support to our clientele as well as to support the growth and stability of the mortgage industry.
Press Release
Press Release-1
Jonathan Foxx is the President and Managing Director of Lenders Compliance Group.