LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Banking Exams. Show all posts
Showing posts with label Banking Exams. Show all posts

Thursday, January 8, 2026

Staying Ahead of Regulatory Changes

YOUR QUESTION 

We are a small broker in the West. There are only four people in our company. We are licensed in three states. Every year, we get slammed with new compliance requirements from state and federal agencies. It's too much! Sometimes I think compliance is first and sales are second. Every year it gets worse and worse. 

Surely there is a way to keep track of these regulations without spending a ton of money on search engines and lawyers. I don't know what I don't know, and that is the problem. You don't have to give me every chapter and verse about what to do. I just need some advice on what I can do, given my limited means and staff. 

I need to get back to sales, but too much of my day is consumed by compliance. 

So, please let me know how to stay ahead of changing regulations. 

A Frustrated Broker 

OUR COMPLIANCE SOLUTION 

We recommend: 

BROKERS COMPLIANCE GROUP, the first full-service, mortgage risk management firm in the United States, specializing exclusively in outsourced mortgage compliance and offering a full suite of services to mortgage brokers, mini-correspondents, and independent mortgage professionals. 

OUR ANSWER 

I understand how you feel. It's the main reason why I started Lenders Compliance Group twenty years ago. 

Our Brokers Compliance Group supports the unique compliance needs of mortgage brokers. We have hundreds of brokers who let us handle their compliance so they can focus on sales and operations. 

Let me say this: there was a time, ages ago, when sales and compliance were separate activities, though they continually overlapped and coalesced. Now sales and compliance are cemented together. I know that's not what you want to hear, but it's true. 

Our industry is highly regulated, but given the tally of federal and state restrictions, it is not as regulated as others. Mortgage banking is categorically grouped within the finance and banking industries. It is certainly amongst the most highly regulated industries in the country. 

So, you will need to stay alert and proactive. However, there are several things you can do to reduce the time you give to monitoring and implementing regulations. It may seem daunting, but once you build momentum, you will be able to focus much more on sales. 

To prepare for regulatory changes, you should develop a proactive framework. By "framework," I mean a plan to closely monitor regulatory changes and, where needed, assess their impact on your origination processes. This plan should include feedback to update policies, provide training, test the loan flow process, maintain documentation, use methods to track changes, and audit ongoing compliance. You'll continually tweak the plan over the years. 

I'm going to break it down for you so that you get a feel for what I'm suggesting.

 

MONITOR

 

Develop a means to monitor court cases, enforcement actions, and regulatory bulletins. Because you have a small office, designate colleagues to track these early signals.

 

RESEARCH

 

Join, subscribe, or partner with industry associations and compliance advisors, such as Brokers Compliance Group. These resources usually provide content, updates, and specialized training.

 

TECHNOLOGY

 

Reduce research costs by using a cloud-based platform to alert you to regulatory changes. If you do not have the resources, you can partner with our compliance firm to get real-time feedback.

 

ASSESS & EVALUATE

 

Determine which business areas (for instance, lending, technology, operations) are affected by new rules (such as digital signage and AVMs). Identifying the impact strengthens compliance.

 

CONDUCT AUDITS

 

Perform internal audits or external audits to review your compliance management system. For a close look at a department, function, or regulation, use our inexpensive Compliance Tune-up.

Thursday, January 30, 2025

Guilty Until Proven Innocent?

QUESTION 

I am the Chief Executive Officer of a lender and servicer. Last week, the CFPB hit us with a Civil Investigative Demand. Our in-house lawyer has put a team together from various departments to respond to it. And you kindly referred us to an attorney who specializes in this process. We are retaining the attorney you recommended. 

At this point, many people in the company are aware that we received the Civil Investigative Demand, and I am very concerned about reputation risk. We have built a fantastic company, yet rumors have already started that we did something to violate laws and regulations. I need a way to calm everyone down and not worry. 

Because of the rumors, some employees now think we are guilty of wrongdoing. We intend to fight any such charges! I need to issue a statement that explains the process in plain and simple language. I need your help in providing information that helps them to understand the process. 

What is the CFPB’s Civil Investigative Demand? 

Are we guilty until proven innocent? 

COMPLIANCE SOLUTION 

CMS Tune-up®  

RESPONSE 

Rumour doth double, like the voice and echo,

The numbers of the feared.

Henry IV, Part 2, Shakespeare 

Allow me to put the above lines into our modern idiom: An unconfirmed report expands like an echo growing louder and louder, magnifying the perceived size and threat. 

DO NOT IGNORE THE RUMORS! 

Perhaps you think that the truth will reduce the rumors. Sometimes, it does; sometimes, it does not. One of my favorite literary figures, Jonathan Swift, once said that “falsehood flies, and the truth comes limping after it.” He cautioned that by the time people become “undeceived,” the “jest” is over, and the “tale” has already had its effect.  

Reputation risk is real, and adverse issues can hobble a company financially, even when there’s nothing to the allegations of wrongdoing. Some rumors don’t have a scintilla of truth, but they thrive nonetheless. Like a garden of weeds, pull out one, and another takes its place. Your aim should be to control the message. However, do not ignore rumors! 

PEEKING BENEATH THE CFPB HOOD 

I am going to give you a peek into the CFPB’s Civil Investigative Demand process. The acronym is “CID,” and for brevity, I will use this acronym. If you’re wondering if the CFPB has coopted the authority to conduct CIDs, you might be interested in knowing that it certainly does have the authority pursuant to the Dodd-Frank Act.[i] A primary access point to the authority is Unfair, Deceptive, or Abusive Acts or Practices (UDAAP),[ii] which

 “…take any action . . . to prevent a covered person or service provider from committing or engaging in an unfair, deceptive, or abusive act or practice under Federal law in connection with any transaction with a consumer for a consumer financial product or service, or the offering of a consumer financial product or service…”[iii] 

Most CIDs are triggered by CFPB examination. However, the examination is not the only source of the CID. I’ll get back to examinations momentarily. 

NON-EXAMINATION SOURCES OF CIDs 

Other sources can trigger a CID, many of them being external to the company itself. For instance, the Office of Enforcement monitors the CFPB’s Consumer Complaint Database for potential violations.[iv]

Thursday, June 13, 2024

CFPB’s Repeat Offender Registry – Part Two

QUESTION 

Last week, you published an article about the Repeat Offender rule. The questioner was pretty upset about it. But I am not upset about it. After all, if a company repeats violations, why shouldn’t the public know about it? 

I also run a mortgage lender, just like the other guy. I’m the President and CEO. My company is almost 30 years old. We’ve made it through upturns and downturns, and we’re positioned well for the next upturn. Along the way, we have had violations cited on banking audits. We corrected them and moved on. I can’t think of a single instance when the violation that we corrected got repeated. Not once has that happened. 

So, my view is different. Companies that make the same violations over and over again make it harder for companies like mine to be trusted by the public. I want a level playing field where my loan officers are able to provide our services without having to worry that a competitor is getting away with repeat violations. Repeat offenders are bad for business and mess with the public trust. 

I learned a lot from your article. I printed it out and sent it to my mortgage bankers association as well as all our employees. I want people to know that our company supports the Repeat Offender rule because it is good for business and strengthens the public trust. 

You ended last week’s article by saying that Part Two would further discuss other aspects of the Repeat Offender requirements. I look forward to reading it soon. 

What are other essential aspects of the Repeat Offender requirements? 

COMPLIANCE SOLUTION 

CMS Tune-up®

(Compliance Management System)

ANSWER 

I appreciate your message. The response to Part One was enormous. 

Clearly, this is a controversial subject. But, in a sense, it shouldn’t be. After all, analogously, if you obey the speed limit, it is not unreasonable to want others to follow the speed limit, too. Do you enjoy being tailgated? Are you entertained by cars swerving in and out of fast-moving traffic? Do you feel safe when somebody races past your car at 80 MPH in a 50 MPH zone? About 11% of Americans have had at least one speeding ticket.[i] Repeat driving offenses risk increased insurance fees, loss of a driver’s license (a privilege, not a right), a hazard to safety, destruction of property, and a threat to life.    

Why should some people get bent out of shape by calling a company that continues to violate banking laws a “repeat offender?” What else should it be called? If the term “recidivist” is a proxy, then go for it – use “recidivist.” Both terms infer a tendency to relapse, and "repeat offender," in particular, does seem to be associated with criminal behavior. It is quite a stretch to imply that mortgage companies that repeat offenses of legal and regulatory mandates are criminals. They are certainly not criminals. The problem is the terminology. Perhaps the CFPB can come up with a less objectionable term. 

A quick recap:

On Monday, June 3rd, the Consumer Financial Protection Bureau (“CFPB” or “Bureau”) issued a Final Rule[ii] (“Rule”) requiring nonbank consumer financial services companies to register court orders or government agency orders in a new Nonbank Registry (“Registry”). This Rule is the “Repeat Offender” registration requirement. The effective compliance date is September 16, 2024. 

In Part One, I outlined the following areas: 

·       Repeat Offender Unit; 

·       Risk Profile; 

·       Agency and Court Orders; 

·       Registration; and 

·       Attestation. 

In Part Two, I will discuss[iii] optional alternative registration, timing requirements, the written statement requirement, and when the registration requirement comes to an end. Also, I provide tables for the submission periods and registration protocols. 

Optional Alternative Registration Requirements 

The Rule provides a limited one-time, alternative registration option for covered orders that are published on the Nationwide Multistate Licensing System (NMLS) Consumer Access website.[iv] 

As a covered nonbank, you may alternatively choose to file a special one-time registration for NMLS-published covered orders that were not issued or obtained, at least in part, by the CFPB. By “covered orders,” the CFPB means court orders or government agency orders.[v] 

If the alternative option is chosen, the nonbank must submit certain required information. After such submission, the nonbank has no further obligations to register any changes to or expiration of the order or to file written statements with respect to that order (if applicable). 

The alternative option is not available for any order issued or obtained at least in part by the CFPB, regardless of whether it is published on the NMLS Consumer Access website. 

Timing Requirements 

The timing requirements are a little bit tricky, so stay with me as I elaborate on them. I suggest you work with a compliance professional to ensure the filing and timing requirements are adhered to meticulously. 

Initially, the Rule has a phased-in implementation. During the implementation submission period, nonbanks are categorized into three institutional types, as follows:

 1)    Larger Participant CFPB-Supervised Covered Nonbanks;

 

2)    Other CFPB-Supervised Covered Nonbanks (i.e., CFPB-supervised covered nonbanks that do not meet the definition of a larger participant under the CFPB’s regulations); and

 

3)    All Other Covered Nonbanks (i.e., covered nonbanks that the CFPB does not supervise).

 

For each category, the final rule provides a 90-day window for covered nonbanks to register all covered orders with effective dates from January 1, 2017, until the start of that implementation submission period.

 

The table below identifies registration submission periods based on the Rule’s effective date of September 16, 2024. 

Implementation Submission Periods[vi]

 

Covered Nonbank
Type
Registration
Submission Period
Registration
Deadline

Larger Participant CFPB-Supervised Covered Nonbanks

October 16, 2024
through
January 14, 2025

January 14, 2025

Other CFPB-Supervised Covered Nonbanks

January 14, 2025 
through
April 14, 2025

April 14, 2025

All Other Covered Nonbanks

April 14, 2025
through
July 14, 2025

July 14, 2025

Any dates that fall on a Saturday, Sunday, or Federal holiday should be converted to the next day that is not a Saturday, Sunday, or Federal holiday. Accordingly, the Bureau has adjusted the submission period dates, as listed above.

Two orders are subject to registration: orders that 

1.     Have an effective date from January 1, 2017, through the start of the nonbank’s submission period, and 

2.     For orders issued prior to September 16, 2024, the order remains effective as of September 16, 2024. 

Here’s how this works. I will use the institutional category two (above)—Other CFPB-Supervised Covered Nonbanks—to illustrate the protocol. It reflects the Bureau’s example.[vii] My protocol table shows how to determine the analysis. 

Protocol for Registration of Covered Orders - Example

 

Order Types
Order
Timeframe
Registration
Disposition

First Order

Order takes effect[viii] on January 1, 2016, and expires on January 1, 2026.

Do not register (effective January 1, 2016) because it takes effect before January 1, 2017.

Second Order

Order takes effect on January 1, 2017, and expires on October 30, 2025.

Register (effective January 1, 2017) because it takes effect on or after January 1, 2017 (and prior to the start of the applicable submission period) and remains in effect as of September 16, 2024.

Third Order

Order that becomes effective on January 1, 2025, and expires on January 1, 2031.

Register (effective January 1, 2025) because it takes effect on or after September 16, 2024, and prior to the start of the applicable submission period.

Note 1: Continue to comply with the ongoing registration requirements for these orders until they expire or are terminated.

Note 2: If a new order is issued and effective on or after the start date of the implementation submission period, follow the ongoing registration timing requirements.

 

Understanding the Ongoing Registration Timing Requirements 

After the start of a nonbank’s implementation submission period, it must begin complying with the Rule’s ongoing registration timing requirements to register new orders and submit changes or updates related to previously registered covered orders. 

The nonbank should access the CFPB’s Nonbank Registry and provide a registration submission within the identified 90-day window for each of the following events: 

1.     Within 90 days after the date of updates or changes to the nonbank’s identifying information or administrative information. 

2.     Within 90 days after the date of any amendments made to previously registered orders, including changes to submitted order information. 

3.     Within 90 days after the effective date of any new order(s) applicable to the nonbank (with effective dates on or after the start of the applicable implementation period). 

4.     Within 90 days after the effective date of termination or expiration, submit a revised filing of a previously registered covered order. 

Written Statement – Attestation 

In Part One, I discussed the annual filing requirement of the written statement. It is, in effect, an attestation.[ix] 

·       For CFPB-Supervised Covered Nonbanks, these written statements must be submitted annually on or before March 31 of each year. 

·       For Larger Participant CFPB-Supervised Covered Nonbanks that register by December 31, 2024, the first written statement submission is required by March 31, 2025. It would cover all applicable orders registered with an effective date from October 16, 2024 to December 31, 2024. 

·       For Other CFPB-Supervised Covered Nonbanks, the first written statement submission is required on March 31, 2026. It will cover all applicable orders registered with an effective date on or after the beginning of their implementation submission period, January 14, 2025 to December 31, 2025. 

As I pointed out in Part One, the written statement is where governance plays a role because the designated executive must provide:

Thursday, June 6, 2024

CFPB’s Repeat Offender Registry – Part One

QUESTION 

We just learned from our lawyers about the possibility that our firm will need to file as a Repeat Offender. I am really angry about this, and I am turning to you for feedback. This type of filing could crush our business reputation. I am the President and have built this company for over twenty years. Now, because we had a few violations, we are going to be considered repeat offenders. And the whole world is going to view us as repeat offenders. 

I am outraged. I had a conference call with other company owners, and they wanted me to ask you for your understanding of this nasty situation. I mean, really, repeat offenders are felons, sex perverts, murderers, crooks, and criminals of all sorts and stripes. It is insulting to say we are Repeat Offenders. We are not hardened criminals. We are not crooks. 

We are hardworking business people who do the best we can in a highly regulated industry. If we make mistakes, we try to fix them. Sometimes, we make the same mistake, but not out of malice. We’re licensed, and the last thing we want to do is call regulators down on our company for repeating a mistake. We don’t run from our responsibilities. 

Our lawyers are telling us how to manage the situation legally. But all I’m hearing is there’s nothing we can do but accept that we are going to be called “repeat offenders.” One of our lawyers used a fancy word, saying we are a “recidivist” company. Is that word supposed to make me feel better? Whatever. We are going to be burned on the “repeat offender” stake. 

Thank you for letting me rant. I am just so pissed off. Please give me and others some basic understanding of what this new set of regulatory shackles is all about. 

What is the Repeat Offender requirement? 

How does the Repeat Offender filing work? 

Why is my firm being singled out? 

COMPLIANCE SOLUTION 


CMS Tune-up®
(Compliance Management System)

ANSWER 

For the last few days, we’ve gotten so many calls on this subject that we had to double up the reception team. The emails to us were peaking each day. That’s because, on Monday, June 3rd, the Consumer Financial Protection Bureau (“CFPB” or “Bureau”) issued a Final Rule[i] (“Rule”) requiring nonbank consumer financial services companies to register court orders or government agency orders in its Nonbank Registry (“Registry”). This Rule is the “Repeat Offender” registration requirement that you’re referring to. The effective compliance date is September 16, 2024. 

Given the complexity of the Rule, my answer today constitutes Part One. We’ll publish Part Two next week, which will be a continuation of today’s answer and will also contain a chart and another checklist outline. Furthermore, since we have received so many inquiries on this topic, I may include some of those questions in Part Two. 

I understand your concerns. Before I get into some of the details and answer your questions, please relax. If you have competent counsel, they should be responsive and provide helpful guidance. 

You can contact me personally here if you want us to discuss your compliance needs. We have a range of compliance services that will likely mitigate your risk management challenges. When risk management is not functioning well, repeated violations may happen, and regulations can become a minefield. 

REPEAT OFFENDER UNIT 

You seem surprised by the terminology of “Repeat Offender.” You might like to know that the CFPB has had a Repeat Offender Unit since 2022. It was set up specifically to focus[ii] on these four activities: 

1)    reviewing and monitoring the activities of repeat offenders;

2)    identifying the root cause of recurring violations;

3)    pursuing and recommending solutions and remedies that hold entities accountable for failing to comply with Federal consumer financial law consistently; and

4)    designing a model for order review and monitoring that reduces the occurrences of repeat offenders.

The Repeat Offender Unit is equipped with a national supervision team that is responsible for designing and executing comprehensive oversight of supervised entities subject to CFPB law enforcement orders.[iii] In effect, it is a deterrence strategy that actively ensures a company, its senior management, and its board of directors are not treating any orders as mere suggestions.

Thus, the Bureau is taking several steps to identify specific individuals and entities responsible for repeat offenses. 

And you are correct: the CFPB will make the Registry publicly accessible. The Bureau states in the Rule that a public registry will enable other Federal, state, and local regulators to “realize many of the same market-monitoring benefits that the Bureau anticipates obtaining from this rule.”[iv] The plan here is to facilitate the ability of consumers to identify the entities that are registered with the Bureau, with the goal of enhancing “the ability of investors, research organizations, firms conducting due diligence, and the media to locate, review, and monitor orders enforcing the law.”[v]  

RISK PROFILE 

Your firm is not being singled out, though it may feel that way. Don’t develop a persecution complex when dealing with regulators. I have even admonished lawyers who presumably know how to interact with regulators but come at them with righteous indignation. They should know better. 

You’ve spent decades building your business, but compliance issues are always traceable and never erasable. Like it or not, your firm has established a risk profile with the Bureau and likely with state banking departments. Your goal must be to prevent, reduce, and mitigate legal and regulatory risks. 

If you want to be proactive, do a self-assessment, such as our CMS Tune-up®which will help you to get a better understanding of the strengths and weaknesses in your Compliance Management System. Get our report. Fix the weaknesses. Conduct an annual review.  

Contact us for more information about the CMS Tune-up® 

We have a Compliance Tune-up® audit for virtually all areas of mortgage banking. Whatever you do, stay focused on ensuring the resiliency of your overall compliance program. 

As you know, we only work in the mortgage compliance space. If you are a covered nonbank providing consumer financial products or services, such as residential mortgage loans, you are probably covered by the Rule.[vi] 

AGENCY AND COURT ORDERS 

As I said above, the Rule requires the covered nonbank to register court orders or government agency orders into a new Registry. Let me discuss this requirement because it is mandated due to investigations, proceedings, administrative matters and actions, consent orders, agency orders, and court orders. 

Since your lawyers have notified you that you need to register, my guess is that your risk profile contains some of the requirements that mandate registration. Given that you may need to register with the Registry, let’s drill down into the types of orders that can trigger the filing requirement. 

Here’s a helpful outline to help you identify whether you may need to file with the Registry. If any of these orders have happened, you certainly may be subject to registration.[vii]

An order[viii] is covered by the Rule if it:

  • Is a final public order issued by an agency or court. 
  • Identifies a covered nonbank by name as a party subject to the order;
  • Was issued at least in part in any action or proceeding brought by any Federal agency, state agency, or local agency; 
  • Contains public provisions that impose obligations on the covered nonbank to take certain actions or to refrain from taking certain actions;
  • Imposes obligations on the covered nonbank based on an alleged violation of a covered law, which includes Federal consumer financial laws, other laws enforced by the CFPB, and certain unfair, deceptive, or abusive acts or practices laws at both Federal and state levels identified in the final rule; and
  • Has an effective date on or after January 1, 2017. An order is effective on the date specified in the order. If an order does not have an effective date identified, the date of issuance is the effective date. If the issuing agency or a court stays or otherwise suspends an order’s effectiveness, the order’s effective date for purposes of the final rule is delayed until the stay or suspension is lifted.[ix]

The Bureau casts a wide net with respect to the laws covered by the Rule. The Rule covers a federal consumer financial law or any other law the CFPB enforces; Section 5 of the FTC Act (UDAP); state UDAAP laws; and specific state laws identified by the Rule. 

REGISTRATION

Unfortunately, filing is going to add an administrative burden on management and governance. There’s no getting around it; registration will require you to file information and documentation.[x] The Bureau will provide the Registry format and filing instructions. And, the Rule requires you to submit revised filings within 90 days if any information outlined above changes or the covered order is amended, terminated, rescinded, or abrogated. 

So, it’s clear you will need to do the following: 

1) Covered Nonbank Identity Information 

As specified in the CFPB’s filing instructions, a covered nonbank must submit identifying information about itself, such as its legal name and the address of its principal place of business. 

2) Administrative Information 

As specified in the CFPB’s filing instructions, a covered nonbank must submit certain additional administrative information. For example, administrative information may include information regarding a registered entity’s affiliates that are registered with respect to the same order. 

3) Covered Order Information 

To register a covered order, a covered nonbank must submit at least the following to the CFPB:

  • A fully executed, accurate, and complete copy of the covered order in a PDF format.[xi]
  • The applicable agency(ies) and court(s) that issued or obtained the covered order.[xii]
  • The effective date of the covered order.[xiii]
  • The date of expiration, if any, of the covered order or a statement that there is none.

Thursday, May 23, 2024

CFPB Examination: Failure to Conduct Self-Assessments

QUESTION 

We just received an MRA from the CFPB. We are a mid-size mortgage lender licensed in 30 states. This MRA hit us like a huge shock. Yesterday, we contacted your firm and spoke to a representative. I want to set up a conference call for my management and you to discuss how to proceed. Our counsel recommended that we bring you on board to assist them in handling the MRA demands. 

Here's the situation. The CFPB found that we failed their exam in various areas, one of which was that we did not do any self-assessments, which they call "self-identifications." 

First of all, I didn't even know that we were supposed to do these self-assessments. Secondly, we have a small compliance department, and we do not know how to do self-assessments. Third, our attorneys say they can only do a few of the self-assessments, but not all of them, and their fees are ridiculous. The bottom line is that we need an outside, independent firm to do self-assessments at an affordable cost. 

There are other areas of the MRA that we need to talk to you about, especially in the areas that our counsel wants to team up with you on. However, we need to take care of the CFPB's list of self-assessments, and we want to retain your firm to do them. 

Please get in touch with me as soon as possible to set up a call. In the meantime, please give us a clue about what goes into these self-identifications or self-assessments. 

What is self-identification? 

Why does the CFPB expect self-identification? 

COMPLIANCE SOLUTION 

Compliance Tune-up® 

ANSWER 

Our firm is the first and only firm in the country to provide self-assessment audits, a series denoted by the overall term Compliance Tune-up®. We deconstructed a mortgage company from the point of sale to secondary and beyond to derive audit criteria for each element and regulation. The Compliance Tune-up® is one of our Compliance Solutions and is often in considerable demand. 

I will discuss the Compliance Tune-up® at the conclusion of this article, as it is a means to be responsive to the expectations of the Consumer Financial Protection Bureau (CFPB or Bureau). I'll drop a contact link on the way if you want more information about the Compliance Tune-up®. 

First, I want to outline how self-identifications – or self-assessments – function in the context of the CFPB examination and the evaluation of the Compliance Management System (CMS). 

The CFPB's exam focuses on risks of harm to consumers, including the risk that a supervised entity will not comply with Federal consumer financial law. To get ready for the examination, you should do pre-review planning to collect the information necessary to determine the scope, resource needs, and work plan. The information and documentation should be assembled, given that an Examiner in Charge (EIC) will notify you that the examination team plans to conduct its work offsite and onsite during the review. Timing is critical, and you must be responsive. 

The fact that you received an MRA (Matters Requiring Attention) tells me that you are quite far along in a risk rating evaluation. The CFPB's risk evaluation procedures are extensive. The Bureau uses an MRA to communicate to an institution's Board of Directors, senior management, or both, specific goals to be accomplished in order to correct violations of Federal consumer financial law, remediate harmed consumers, and address related weaknesses in the CMS that the examiners found are directly related to violations of Federal consumer financial law. MRAs include timeframes for periodic reporting of efforts taken to address these matters, as well as expected timeframes for implementation.

___________________________________________________________

 Compliance Tune-up®

 Visit Us to Request Information

 ___________________________________________________________

Let's consider some features of the CPPB examination with an emphasis on self-identification. 

Prior to the examination, you will receive an Information Request. The Information Request is a list of specific information and documents that the supervised entity is asked to provide to the Bureau for offsite review or make available when the examiners arrive onsite. It may include a request for an electronic data upload. Our experience is that the pre-review planning process varies depending on the size, complexity, business model, products, systems, and risk profile of a particular supervised entity. 

Don't assume that the Bureau is only dealing with getting information from you; in fact, it gets quite a lot of information from both internal and external sources to aid in constructing the risk focus and scope of a review. The examiners gather as much information as possible from within the Bureau, other regulatory agencies, and third-party, public sources because the Bureau is required by statute to use, to the fullest extent possible, information available from other agencies or reported publicly.[i] 

The following key documents and information are relevant to understanding a supervised entity and its ability to manage its compliance responsibilities and risks to consumers. Not all documents will necessarily be available for a particular entity; however, you should anticipate that the Bureau's team will consider them. There are two categories: the Bureau's internal sources and regulatory agencies, as well as public information and third parties. 

BUREAU INTERNAL SOURCES AND OTHER REGULATORY AGENCIES 

·       Monitoring information 

·       Any recent risk assessments, self-identifications, and self-assessments 

·       Prior Scope Summary, Supervision Plan, or similar document produced by state or prudential regulators 

·       Prior Examination Reports and Supervisory Letters, and supporting workpapers (internal and from the prudential regulator(s), state regulator(s), or other agencies) 

·       Information about prior supervisory actions, consumer remediation, and responses to Examination Reports and Supervisory Letters 

·       Information on enforcement or other public actions (if applicable) 

·       Correspondence from prudential or state regulator(s) and Bureau correspondence files 

·       State licensing information for the entity 

·       The CFPB Consumer Complaint database 

·       FTC Consumer Sentinel database 

·       Uniform Bank Performance Report (UBPR) and Call Reports, if applicable

·       Previous years' FFIEC Home Mortgage Disclosure Act Loan Application Registers (HMDA LARs) 

·       Home Affordable Modification Program data 

·       Fair lending analyses and supporting documentation 

·       Office of the Comptroller of the Currency (OCC) Federal Housing Home Loan Data System (FHHLDS) report, if applicable 

·       Mortgage Call Report (MCR) from the Nationwide Mortgage Licensing System (NMLS) 

·       Registration or licensing information for mortgage originators (Secure and Fair Enforcement for Mortgage Licensing Act (SAFE Act) 

PUBLIC SOURCES OF INFORMATION 

·       Institution securities filings, its offered securitizations, and similar public records 

·       Industry publications showing credit ratings, product performance, and areas of profitability 

·       Newspaper articles, web postings, or blogs that raise examination-related issues

·       Neighborhood Watch

·       Service providers and other third-party arrangements 

·       Content of the supervised entity's website

RATING SYSTEM CATEGORIES AND ASSESSMENT FACTORS 

The Bureau's rating system is organized under three broad categories: 

1.     Board and Management Oversight, 

2.     Compliance Program, and 

3.     Violations of Law and Consumer Harm. 

I will not outline the rating system here. Suffice it to say that it is complex and is used to reflect the implementation of assessment factors considered within each category, with some cross-referencing, along with narrative descriptions of performance. The first two categories, Board and Management Oversight and Compliance Program, are used to assess the strength of an institution's CMS. Examiners evaluate the assessment factors within these two categories commensurate with the institution's size, complexity, and risk profile. 

All institutions, regardless of size, should maintain an effective CMS. The sophistication and formality of the CMS typically will increase commensurate with the size, complexity, and risk profile of the entity. 

The Bureau's compliance expectations contained within the narrative descriptions of the foregoing two categories extend to third-party relationships[ii] utilized by the financial institution. There can be certain benefits to financial institutions engaging in relationships with third parties, including gaining operational efficiencies or an ability to deliver additional products and services. Still, such arrangements may expose financial institutions to risks if they are not managed effectively.