LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Affiliates. Show all posts
Showing posts with label Affiliates. Show all posts

Thursday, September 29, 2022

Higher Risk Areas of UDAAP

QUESTION

I am our company’s Compliance Manager and General Counsel. I am working with my team to identify high risk areas of numerous regulations. 

In reviewing the high risks associated with UDAAP, there were many. So, we had to find even higher risks. 

I would like to work with a small set of “higher risk” categories in our UDAAP analysis. We will use your higher risk areas to train all affected personnel. 

What are higher risk areas of UDAAP? 

ANSWER

The legal and regulatory requirements of Unfair, Deceptive, or Abusive Acts and Practices (“UDAAP”) are vast. Indeed, several regulatory frameworks interlock in an overall matrix of UDAAP mandates. 

However, providing a small set of higher risk categories is possible. I do not claim that my suggestions are comprehensive. That said, you should be able to pivot from them in the context of UDAAP training. 

There are at least three higher risk categories associated with UDAAP. I believe these would be the challenges posed by advertising, products, and third party relationships. 

Consider the following suggestions for higher risk areas of UDAAP.

Advertising, Disclosures, and Contract Terms 

Representations in advertising and terms of contracts and disclosures should be accurate, clear, and sufficiently informative. This also means that representations that go to the heart of a consumer’s decision to purchase a product or service, such as statements about costs, benefits, restrictions on use or availability, or qualification for a product, are especially material. Omitting important information or failing to properly qualify representations in advertising may represent UDAAP risk. 

Higher Risk Products 

Some products are generally identified as potentially having higher UDAAP risk, such as subprime loan and credit card products, overdraft protection services, rewards checking, and products marketed to the elderly or financially vulnerable or financially vulnerable unsophisticated. 

Third Party Relationships 

Use of affiliated or nonaffiliated third parties to provide products or services such as advertising or marketing, issuing credit cards, or offering products such as insurance or mortgage loans, and collection activity may raise potential UDAAP risk. Due diligence by a financial institution in selecting the third party provider and the extent of its monitoring and oversight of the activities of the third party, including disclosures and solicitations produced by the third party, are important factors. 

I suggest you discuss specific examples of FTC responses to UDAAP violations in your UDAAP training. Advertisements, particularly for mortgage loans, have attracted a great deal of regulatory scrutiny. The Federal Trade Commission has warned banks, mortgage brokers, lenders, mortgage servicers, and media outlets that carry their advertisements for home mortgages. Some advertising claims currently appearing on websites, newspapers, magazines, direct mail, and unsolicited email and faxes may violate federal law. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Friday, June 17, 2022

Adverse Action Conundrum

QUESTION 

I have been told conflicting advice about the adverse action notice. Supposedly, these are people who are in the know. However, I am a compliance manager with no staff and don’t have a clear answer to my concerns. 

First, I want to know what information I need from a credit bureau to issue an adverse action notice. 

Secondly, I want to know what information I need from third parties that are not credit bureaus for me to issue the adverse action notice. 

Third, and the biggest issue for me, I want to know who we should notify when multiple applicants are on a loan application. I say this is the biggest issue because this is the one on which I get a lot of conflicting advice. 

So, here are my questions. 

What is required for adverse action based on credit bureau information? 

What is required for adverse action based on third parties? 

And, who is supposed to get the adverse action notice when the loan is for multiple applicants? 

ANSWER 

You are not alone in feeling some consternation. Many compliance professionals express some confusion about the notification requirements of adverse action. Section 615 of the Fair Credit Reporting Act (FCRA)[i] requires lenders to provide adverse action notices in cases where information from a consumer reporting agency is used and instances where information from other third parties is used to make the adverse credit decision. 

If you use a consumer credit report to take any type of adverse action that is based at least in part on information contained in a consumer report, you are required by the FCRA[ii] to notify the consumer. The notification may be in writing, orally, or by electronic means. 

You may already be familiar with what the notice must contain, such as: 

·      A numerical credit score[iii] used in taking any adverse action based in whole or in part on any information in a consumer report along with the following related information:[iv] 

o   The range of possible credit scores under the model used;

o   All of the key factors that adversely affected the credit score of the consumer in the model used, not to exceed four;

o   The date on which the credit score was created; and

o   The name of the person or entity that provided the credit score or credit file upon which the credit score was created. 

However, the adverse action notice must also include the following: 

-  The name, address, and telephone number of the credit reporting agency (CRA) (including a toll-free telephone number, if it is a nationwide CRA) that provided the report;

-  A statement that the CRA did not make the adverse decision and cannot explain why the decision was made;

-  A statement setting forth the consumer’s right to obtain a free disclosure of the consumer’s file from the CRA if the consumer requests the report within 60 days; and

-  A statement setting forth the consumer’s right to dispute directly with the CRA the accuracy or completeness of any information provided by the CRA. 

I suggest you review the model adverse action forms in Appendix C of Regulation B, the implementing regulation of the Equal Credit Opportunity Act (ECOA), which include model language for making the above disclosures, including the credit score information. 

Your second question is about adverse action notices based on information obtained from third parties that are not CRAs. I would add affiliates to that category. When a lender denies (or increases the charge for) credit for personal, family, or household purposes based either wholly or partly on information from a person other than a consumer reporting agency (such as a credit bureau), the FCRA[v] requires that the institution clearly and accurately discloses to the consumer their right to obtain disclosure of the nature of the information that was relied on by making a written request within 60 days of notification. The financial institution must provide the disclosure within a reasonable period of time following the consumer’s written request. 

You may take an adverse action involving insurance, employment, or a credit transaction initiated by the consumer, based on information of the type covered by the FCRA. If this information was obtained from an entity affiliated with the institution by common ownership or control, the FCRA[vi] requires the financial institution to notify the consumer of the adverse action. The notification must inform the consumer that they may obtain a disclosure of the nature of the information relied on by making a written request within 60 days of receiving the adverse action notice. And if the consumer makes such a request, the financial institution must disclose the nature of the information no later than 30 days after receiving the request. The applicable section of the FCRA[vii], however, does not cover information obtained directly from an affiliated entity relating solely to its transactions or experiences with the consumer and information from a consumer report obtained from an affiliate. 

Finally, you wanted to know about disclosing the adverse action notice where multiple applicants are on a loan application. The answer invokes both Regulation B as well as the Fair Trade Commission’s interpretation of the FCRA. In some cases, the rules of Regulation B regarding who must be provided the adverse action notice will differ from the rules under the FCRA. This is due to a Federal Trade Commission interpretation of Section 615(a) of the FCRA. The explanation is going to be a bit nerdy, but hang in there! 

Section 615(a) of the FCRA requires that “any consumer,” with respect to whom adverse action is taken, must receive the disclosures mandated by this section if that action is based “in whole or in part” on information from a consumer report. In the FTC’s view, the plain language “any consumer” includes a co-applicant. Neither the applicable section of Regulation B[viii] nor the combined disclosure permitted in Appendix C remove or modify that requirement for co-applicants. The objective of the combined disclosures permitted by the Federal Reserve Board in Appendix C to Regulation B is only to simplify the paperwork involved in making ECOA and FCRA notifications to a single applicant, where both are required – for instance, where the action by the creditor is both adverse to the applicant (ECOA) and is based in whole or in part on information from that applicant’s consumer report (FCRA).

Friday, November 26, 2021

Affiliate Marketing: Information Sharing

QUESTION
We are a lender with several affiliates. We have been cross-marketing with the affiliates for a long time. However, our regulator now is examining us and our affiliates to find out if we have “information sharing” violations. A complaint to the CFPB triggered the examination. 

Their main concern seems to center on potential violations of the Fair Credit Report Act. 

So, our question is, are there restrictions on using our affiliates’ information for marketing purposes? 

ANSWER
A word of caution at the outset: work with a compliance professional for guidance on information sharing between affiliates. Information sharing is a very challenging area of compliance and involves several regulations. Your question specifies the Fair Credit Report Act (FCRA), so I will respond exclusively in the context of the FCRA. 

It is important to know what information is subject to affiliate marketing. The provisions apply to the use of “eligibility information” of consumers, where you receive such information from your affiliate for purposes of marketing products or services to those consumers. 

“Eligibility information” means any information that, if communicated by a consumer reporting agency, would be a consumer report but for the exclusions set forth under the definition of “consumer report” in the FCRA for 

(1) transaction or experience information regarding a consumer, or 

(2) non-transaction or experience information regarding a consumer that affiliates may share with one another if notice and opt-out procedures are followed and the consumer does not opt out. 

It is worth noting that eligibility information excludes aggregate or blind data that does not contain personal identifiers, such as account numbers, names, or addresses. 

The communication of transaction or experience information among companies related by common ownership or affiliated by corporate control is not considered sharing consumer report information. 

Furthermore, companies related by common ownership or affiliated by corporate control may communicate among one another information regarding a consumer that 

(1) is not transaction or experience information, and

(2) would otherwise be considered consumer report information, if a notice and opt-out procedure are followed and the consumer does not opt out. 

However, even though such information may be shared among affiliates, the information is subject to FCRA affiliate marketing provisions, including affiliate marketing rules adopted by the federal financial institution regulators and the Federal Trade Commission (FTC). 

The rules impose restrictions on the use of consumer report information regarding a consumer whom a company receives from an affiliate for the purpose of the company marketing its products or services to the consumer. Therefore, the affiliate marketing provisions impose restrictions on the use, not the sharing of information. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, July 8, 2021

Large Bank Cybersecurity Challenges

QUESTION
We purchased your new Ransomware Policy and Procedures. It is very comprehensive. We alread
y have a policy for Ransomware; however, we are going to incorporate your policy into ours. 

I am the Chief Compliance Officer and an attorney. In our case, we are a large bank with multiple business units, hundreds of branches, thousands of loan officers, a substantial online presence, and several affiliated entities. 

We have an Information Security Office, an Information Technology Operations Center, and an Information Privacy Office. Our CISO and CPO oversee cybersecurity issues involving the network architecture, operating system architecture, business applications, online sales, and internal auditing. 

As a large company, we have unique compliance needs. I would like your answers to several questions that we constantly ask one another. We would appreciate your feedback on these questions. 

Who are the stakeholders of an incident response team? 

What are the responsibilities of the incident response team? 

What are the suggested notification levels of escalation involving a cyberattack? 

ANSWER
Your mentio
ning of the offices under the CISO’s oversight in itself tells me that you have a challenging and highly articulated risk profile. You provided supporting information to your questions, which I have not included herewith. For the sake of the readership, some of your terminology may be new to them, so I will define certain nomenclature in the course of responding to your questions. 

Let’s begin with the definition of a security breach. For the sake of brevity, I define a security breach as an unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information. Ransomware endeavors to monetize that breach, where a hacker stealthily gets into a system and puts encryption controls in place that lock users out. Once that succeeds, the hacker demands money to "unlock" the data. 

In a large company, protection from a security breach is guarded by various stakeholders. These individuals constitute a matrix of responsibilities, often through a “chain of command” configuration. Critical to countering a triggering event such as a ransomware demand is developing and maintaining an Incident Response Plan (“Plan”). 

I define a Plan as a documented, clearly outlined, organized approach for handling any potential threat to computers and data, even, where necessary, taking appropriate action when the source of the intrusion or incident at a third party is traced back to the organization. 

The Plan should identify and describe the roles and responsibilities of the Incident Response Team (“Team”). And the Team is responsible for putting the Plan into action. 

The Team is established to provide a quick, effective and orderly response to computer-related incidents, such as virus infections, hacker attempts and break-ins, improper disclosure of confidential information to others, system service interruptions, ransomware attacks, breach of personal information, and other events with serious information security implications. In short, the Team’s mission is to prevent a severe loss of profits, public confidence, or information assets by providing an immediate, effective and skillful response to any unexpected event involving computer information systems, networks, or databases. 

The kinds of security breaches that trigger the Plan include a breach of personal information, Denial of Service and Distributed Denial of Service, excessive port scans, ransomware attacks, firewall breaches, and virus outbreaks. 

The Plan arrangement that you describe is consistent with large companies. It is the case that many large companies have a Plan that contains the personnel of the following offices, departments, and functions (“Stakeholders”): 

- Information Security Office (“ISO”) (“Chief Information Security Officer” or “CISO”)

- Information Technology Operations Center (“ITOC”)

- Information Privacy Office (“IPO”) (“Chief Privacy Officer” of “CPO”)

- Network Architecture

- Operating System Architecture (“Operations Center”)

- Business Applications

- Online Sales

- Internal Auditing 

So, based somewhat on your description, your Plan seems consistent with similar arrangements by large companies. 

The Board or executive management must give the Team the requisite authority to take appropriate steps deemed necessary to identify, contain, mitigate, and resolve an adverse cybersecurity incident. Also, the Team is responsible for investigating suspected intrusion attempts or other security incidents in a timely, cost-effective manner and reporting its findings to management and the appropriate authorities as necessary. The CISO coordinates the Team. 

The Information Technology Operations Center is the central point of contact for reporting computer incidents or intrusions. The Operations Center notifies the CISO. 

All computer security incidents must be reported to the CISO. A preliminary analysis of the incident takes place by the CISO, determining whether the Incident Response Team activation is appropriate. 

With respect to the rules and responsibilities of the Team, I offer the following list based on the forgoing matrix of Stakeholders. It is certainly not meant to be comprehensive but suggestive. 

Information Security Office

- Determines the nature and scope of the incident

- Contacts qualified information security specialists for advice as needed

- Contacts members of the Incident Response Team

- Determines which Incident Response Team members play an active role in the investigation

- Provides proper training on incident handling

- Escalates to executive management as appropriate

- Contacts auxiliary departments as appropriate

- Monitors progress of the investigation

- Ensures evidence gathering, the chain of custody, and preservation is appropriate

- Prepares a written summary of the incident and corrective action taken 

Information Technology Operations Center 

- Central point of contact for all computer incidents

- Notifies Chief Information Security Office to activate computer incident response team 

Information Privacy Office 

- Coordinates activities with the Information Security Office

- Documents the types of personal information that may have been breached

- Provides guidance throughout the investigation on issues relating to the privacy of customer and employee personal information

- Assists in developing appropriate communication to impacted parties

- Assesses the need to change privacy policies, procedures, and practices as a result of the breach 

Network Architecture 

- Analyzes network traffic for signs of denial of service, distributed denial of service, or other external attacks

- Runs tracing tools such as “sniffers,”[i] Transmission Control Protocol (TCP)[ii] port monitors, and event loggers

- Looks for signs of a firewall breach

- Contacts external Internet service provider for assistance in handling the incident

- Takes action necessary to block traffic from a suspected intruder 

Operating Systems Architecture 

- Ensures all service packs and patches are current on mission-critical computers

- Ensures backups are in place for all critical systems

- Examines system logs of critical systems for unusual activity 

Business Applications 

- Monitors business applications and services for signs of attack

- Reviews audit logs of mission-critical servers for signs of suspicious activity

- Contacts the Information Technology Operations Center with any information relating to a suspected breach

- Collects pertinent information regarding the incident at the request of the Chief Information Security Office 

Online Sales 

- Monitors business applications and services for signs of attack

- Reviews audit logs of mission-critical servers for signs of suspicious activity

- Contacts the Information Technology Operations Center with any information relating to a suspected breach

- Collects pertinent information regarding the incident at the request of the Chief Information Security Office 

Internal Auditing 

- Reviews systems to ensure compliance with information security policy and controls

- Performs appropriate audit test work to ensure mission-critical systems are current with service packs and patches

- Reports any system control gaps to management for corrective action 

I found your question intriguing about escalating notification of a cybersecurity attack. Sometimes the path to the final decision maker is circuitous and time-consuming. During that interstitial period, the company may be unable to respond to the security threat effectively. 

Using the outline I have set forth hereinabove, I think the “chain of command” escalation for notification should consist of following layers. 

Escalation Notification 

Escalation - First Level 

- Chief Information Security Officer (CISO)

- Data Processing Operations

- IT Audit Director

- Network Architecture Manager

- Online Sales Director 

Escalation - Second Level 

- Chief Information Officer (CIO)

- Chief Privacy Officer (CPO)

- Chief Audit Executive 

Friday, June 26, 2020

Influencer Guidelines for Financial Institutions

QUESTION
We have affiliates that sell products and services. As the Compliance Manager, I was recently tasked by our CEO to make sure that we are not giving the impression that we’re recommending something being sold by our affiliates, even if our websites already mention their products and services. This seems like a contradiction. 

On the one hand, we are told to not recommend the affiliates’ products and services, and, on the other hand, we are told to make sure our websites mention them. 

Are there some guidelines we can follow to make sure we are not promoting the products and services while also mentioning them on our websites?

ANSWER
These days, there is a term for the power to affect the purchasing decisions of others. It’s called an “influencer.” You may have heard this term in the last few years. It is associated often with social media. The influencer is somebody who supposedly has the authority, knowledge, relationship, position, expertise, experience, and competence to “influence” somebody’s purchasing decisions. In fact, there are courses now available for people to learn how to be an influence!

The world of financial services has its own form of influencers. And the scenario you describe is one such instance where influence crosses into regulatory territory. That territory is the regulatory framework of the Federal Trade Commission (FTC). Using the FTC standards, it is possible to provide a set of guidelines that, hopefully, will make it possible for you to both mention the affiliates’ products and services without giving the impression that you are promoting them without proper disclosure.

The FTC has the power to issue trade regulation rules declaring acts, practices, and conduct in or affecting interstate commerce to be unfair or deceptive practices. As a point of reference, Dodd-Frank generally displaced the FTC with the CFPB as the coordinator of consumer complaints and principal regulator regarding consumer financial products or services provided by banks, federal savings association, and nonbank creditors (except for motor vehicle dealers).

Prior to the enactment of Dodd-Frank, the FTC Act required banking regulators to issue similar rules within 60 days after an FTC rule’s effective date, unless the banking agency found that similar acts and practices of depository institutions were not unfair or deceptive. Although, Dodd-Frank deleted this requirement, financial institutions may still find it worthwhile to understand FTC rules, if only to understand the rules with which their FTC-regulated competitors must comply.

So, the following is a brief list of guidelines that my firm would be considering if we were doing an audit your scenario. It is based on years of working with FTC standards and website reviews. If we were to do an audit, there would be many other moving parts to consider, including an influencer disclosure review, but I think this outline will give you a head start!

Influencer Guidelines for Financial Services Affiliates 
  • The institution (“influencer”) should clearly and conspicuously indicate the relationship between the influencer and its affiliate (i.e., “we’re affiliated companies owned by the same parent company”).
  • If the other company (the affiliate) gives the influencer a benefit in return for mentioning its products and services, the influencer should mention that benefit (i.e., “we receive [compensation/similar promotion by [the other firm]] in return for mentioning its products and services”).
  • The influencer should treat tags, likes, pins, and similar ways of showing the influencer likes a product or service as endorsements that require disclosures.
  • The influencer should place each disclosure so it’s hard to miss. A disclosure should appear along with the endorsement message and should not appear only if the viewer must click more to reach it.
  • The influencer should not mix the disclosure with a group of hashtags or links, although the disclosure could include a hashtag such as #ad or #sponsored.
  • If an endorsement appears in a picture on a platform like Snapchat or Instagram Stories, the disclosure should be superimposed over the picture in a way that ensures viewers have time to notice and read it.
  • If the endorsement appears in a video, a disclosure should appear both in audio and in video as part of the video and not just in a description uploaded with the video and not only in words superimposed on a video.
  • If the endorsement is made in a live stream, the disclosure should be repeated periodically so viewers who see only part of the stream will get the disclosure.
  • Disclosures should use simple and clear language, without vague or confusing terms such as uncommon abbreviations or shorthand.
  • A disclosure should be in the same language as the endorsement.
  • An influencer should not assume that a platform’s disclosure tool is sufficient, but should consider using that tool in addition to the influencer’s own, good disclosure.
  • An endorsement should be honest and truthful. For example, an influencer should not mention experience with a product the influencer has not tried, or say the product is terrific if the influencer thinks it’s terrible, or make up a claim that would require proof the influencer does not have.
  • The influencer should ensure its disclosures are made, not rely on someone else to make them.
Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, June 18, 2015

GLBA and Affiliates

QUESTION
We would like to know how to handle nonpublic personal information where our affiliates are involved. Do we both have the same restrictions on disclosure?

ANSWER
A financial institution may disclose nonpublic personal information (NPI) to its affiliates, but the affiliates are subject to the same restrictions on reusing or re-disclosing the information as the originating financial institution. [15 USC § 6802(c)]

The Gramm-Leach-Bliley Act (GLBA) defines an “affiliate” as “any company that controls, is controlled by, or is under common control with another company.” [15 USC § 6809(6)]

Subject to certain exceptions, GLBA prohibits disclosure of a consumer’s NPI to non-affiliates unless the disclosing financial institution has given the consumer a privacy notice and an opt-out notice, along with a reasonable opportunity to opt out, and the consumer does not opt out of the information sharing with non-affiliates. [16 CFR § 313.10]

The exceptions where financial institutions may share NPI with certain non-affiliated third parties without having to comply with the privacy notice and opt-out requirements are:

1.     Administering or enforcing transactions authorized by the consumer;
2.     Effectuating transactions with the consent of the consumer;
3.     Protecting the confidentiality of the financial institution’s records;
4.     Providing information to rating agencies;
5.     Disclosing data to law enforcement agencies to the extent required;
6.     Providing information to consumer reporting agencies as delineated in FCRA; and
7.     Complying with all federal, state or local laws or regulations.
[15 USC § 6802(e); 16 CFR §§ 313.14, 313.15]

Mention also should be given to the condition where an exemption is allowed for the opt-out requirements, but not the notice requirements. This condition exists for entities that market the financial institution’s products and services, and products or services “offered pursuant to joint agreements between two or more financial institutions.”
[15 USC § 6802(b)(2); 16 CFR § 313.13]

Jonathan Foxx
President & Managing Director
Lenders Compliance Group

Thursday, March 27, 2014

Pre-existing Business Relationships and Affiliate Marketing

QUESTION:
What is a “Pre-existing Business Relationship” and its effect on affiliate marketing? 

ANSWER:
At its core, the pre-existing business relationship is a relationship between a “person” or “persons” (i.e.,residential mortgage lender and originators) and consumers, based on these three rudimentary criteria:

1. A financial contract between the person and the consumer that is in force on the date a solicitation covered by the affiliate marketing provisions is sent to the consumer;

2. The consumer’s purchase, sale, or lease of the person’s goods or services, or a financial transaction (including holding an active account or a policy in force or having another continuing relationship) between the person and the consumer during the eighteen-month period immediately preceding the date a solicitation covered by the affiliate marketing provisions is sent to the consumer; or

3. An inquiry or application by the consumer regarding a product or service offered by the person during the three-month period immediately preceding the date a solicitation covered by the affiliate marketing provisions is sent to the consumer.

There are essentially two scenarios that come under scrutiny: (1) where there is a pre-existing business relationship, and (2) where there is no pre-existing business relationship. [16 CFR § 680.3(j)(i)-(iii); 16 CFR § 680.3(j)(2)-(3)]

A pre-existing business relationship is where a consumer:
  • Has an existing loan account with a creditor - the creditor has a pre-existing business relationship with the consumer and can use eligibility information it receives from its affiliates to make solicitations to the consumer about its products or services. (A solicitation is the intent to encourage the consumer to purchase or obtain products or services.)
  • Obtained a mortgage from a mortgage lender, but refinanced the mortgage loan with a different lender when the mortgage loan came due - the first mortgage lender has a pre-existing business relationship with the consumer and can use eligibility information it receives from its affiliates to make solicitations to the consumer about its products or services for 18 months after the date the outstanding balance of the loan is paid and the loan is closed.
  • Obtains a mortgage, the mortgage lender has a pre-existing business relationship with the consumer.
  • If the mortgage lender sells the consumer's entire loan to an investor, the mortgage lender has a pre-existing business relationship with the consumer and can use eligibility information it receives from its affiliates to make solicitations to the consumer about its products or services for 18 months after the date it sells the loan, and the investor has a pre-existing business relationship with the consumer upon purchasing the loan.
  • If the mortgage lender sells a fractional interest in the consumer's loan to an investor but also retains an ownership interest in the loan, the mortgage lender continues to have a pre-existing business relationship with the consumer, but the investor does not have a pre-existing business relationship with the consumer.
  • If the mortgage lender retains ownership of the loan, but sells ownership of the servicing rights to the consumer's loan, the mortgage lender continues to have a pre-existing business relationship with the consumer. (The purchaser of the servicing rights also has a pre-existing business relationship with the consumer as of the date it purchases ownership of the servicing rights, but only if it collects payments from or otherwise deals directly with the consumer on a continuing basis.)
  • Applies to a creditor for a product or service that it offers, but does not obtain a product or service from or enter into a financial contract or transaction with the creditor - the creditor has a pre-existing business relationship with the consumer and can therefore use eligibility information it receives from an affiliate to make solicitations to the consumer about its products or services for three months after the date of the application.
  • Makes a telephone inquiry to a creditor about its products or services and provides contact information to the creditor, but does not obtain a product or service from or enter into a financial contract or transaction with the creditor - the creditor has a pre-existing business relationship with the consumer and can therefore use eligibility information it receives from an affiliate to make solicitations to the consumer about its products or services for three months after the date of the inquiry.
  • Makes an inquiry to a creditor by e-mail about its products or services, but does not obtain a product or service from or enter into a financial contract or transaction with the creditor - the creditor has a pre-existing business relationship with the consumer and can therefore use eligibility information it receives from an affiliate to make solicitations to the consumer about its products or services for three months after the date of the inquiry.
  • Has an existing relationship with a creditor that is part of a group of affiliated companies, makes a telephone call to the centralized call center for the group of affiliated companies to inquire about products or services offered by the insurance affiliate, and provides contact information to the call center, the call constituting an inquiry to the insurance affiliate that offers those products or services - the insurance affiliate has a pre-existing business relationship with the consumer and can therefore use eligibility information it receives from its affiliated creditor to make solicitations to the consumer about its products or services for three months after the date of the inquiry.
A pre-existing business relationship does not occur where a consumer:
  • Makes a telephone call to a centralized call center for a group of affiliated companies to inquire about the consumer's existing account with a creditor - the call does not constitute an inquiry to any affiliate other than the creditor that holds the consumer's account and does not establish a pre-existing business relationship between the consumer and any affiliate of the account-holding creditor.
  • Has a loan account with a creditor, makes a telephone call to an affiliate of the creditor to ask about the affiliate's retail locations and hours, but does not make an inquiry about the affiliate's products or services - the call does not constitute an inquiry and does not establish a pre-existing business relationship between the consumer and the affiliate. (Also, the affiliate's capture of the consumer's telephone number does not constitute an inquiry and does not establish a pre-existing business relationship between the consumer and the affiliate.)
  • Makes a telephone call to a creditor in response to an advertisement that offers a free promotional item to consumers who call a toll-free number, but the advertisement does not indicate that creditor's products or services will be marketed to consumers who call in response - the call does not create a pre-existing business relationship between the consumer and the creditor because the consumer has not made an inquiry about a product or service offered by the creditor, but has merely responded to an offer for a free promotional item.
Jonathan Foxx
President & Managing Director
Lenders Compliance Group


















Thursday, December 12, 2013

What is an Affiliate under the Qualified Mortgage rule?

QUESTION 
What is the definition of an “affiliate,” with respect to the QM 3% Points and Fees cap under the Ability-to-Repay and Qualified Mortgage rule?

ANSWER  
The CFPB’s Ability-to-Repay/Qualified Mortgage’s (QM) rule contains a cap or limit on points and fees to qualify as a QM loan. The calculation of points and fees includes certain charges paid to affiliates of creditors. To qualify as a QM, a loan over $100,000 is limited to points and fees up to 3% of the loan amount. The 3% limit is increased on a sliding scale for loans under $100,000. 

In the Small Entity Compliance Guide, the CFPB defines “affiliate” as “any company that controls, is controlled by, or is under common control with, your company” (Ability to Repay and QM Rule, Small Entity Compliance Guide, p. 34). The CFPB also issued “unofficial staff guidance” in a webinar on October 17, 2013, in which it was stated that the definition of an affiliate is any company that controls, is controlled by, or is under common control with, another company  as set forth in the Bank Holding Act of 1956 (the “Act”). 

The Act states that any company has control over a bank or over any company if -  

(A) the company directly or indirectly or acting through one or more other persons owns, controls, or has power to vote 25 per centum or more of any class of voting securities of the bank or company; 

(B) the company controls in any manner the election of a majority of the directors or trustees of the bank or company; or 

(C) the Board determines, after notice and opportunity for hearing, that the company directly or indirectly exercises a controlling influence over the management or policies of the bank or company. [12 USC Section 1841(a)(2)]

Although (A) and (B) are straightforward, (C) is vague and the “unofficial staff guidance” (hopefully “official guidance” will be available down the line”) is just as vague as terms such as “controlling influence” are not specifically defined and are subjective in nature.

It is noteworthy that the CFPB has not made any indication that the definition of “affiliate” will mirror the definition as set forth in RESPA. The RESPA definition is far broader in nature.

To determine whether there is an affiliate relationship under QM, the management and ownership interests of the creditor and the affiliate need to be analyzed in great detail. Only then can the specific facts be applied to the definition set forth in the Act and an answer to the question above determined. It is suggested that you spend the time required to perform an analysis, document your findings and reasoning for the determination. Most importantly, be aware of investor overlays as they may very well exceed the “unofficial guidance” provided by the CFPB.

Michael Barone
Director / Legal and Regulatory Compliance
Lenders Compliance Group