LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Change Management. Show all posts
Showing posts with label Change Management. Show all posts

Monday, March 10, 2025

Free Market Dogma

QUESTION 

I am a former employee of a lender whose president is a hard-core hater of the CFPB. He believes that our government is out of control and the CFPB has been overreaching for years. He is glad that the CFPB is being shut down. I was a paralegal in the legal department. After having to put up with his railing and cursing about the government in general and the CFPB in particular, I decided to resign. Since then, I have been with a law firm and continue to attend law school. 

It's not as if his mortgage company has been in trouble with the CFPB. It complies with all the rules and regulations, and every audit by states and the CFPB itself has shown that the company complies adequately. There have been no administrative actions or fines. 

From what I can tell, the CFPB is a kind of anti-scam police. They are also involved in protecting consumers' financial interests with respect to financial products and services. I can't figure out why this is such a bad thing that it should be destroyed. I thought regulating on behalf of consumers is what good government is supposed to do. We can debate what overreach and unnecessary regulations are, but destroying the agency that actually helps consumers seems really dangerous. 

My former boss takes the position that any government involvement in the free market is an attack on free enterprise, which to him means running his business the way he wants to run it. And, any agency, like the CFPB, that regulates his company is an attack on its survival. I think that's really very extreme. I got tired of trying to convince him otherwise. 

I know this is controversial. I want to widen the lens a bit. You have always been willing to discuss controversial subjects. My former president reads every post you've written for years. I'm sure he will recognize me as the questioner, though I didn't tell you his name or company name. It may bother him that I am writing to you. Fortunately, I am no longer an employee. 

He often discusses your views and interpretations of the law. I have subscribed for years. I think you are a reliable resource for regulatory guidance. I want to know your view. It would really help! 

Is government involvement in free markets justifiable? 

COMPLIANCE SOLUTION 

Management Tune-up 

RESPONSE 

I respond to controversial subjects as they may relate to many aspects of regulatory compliance. I make no apologies. I know they are controversial because we predictably get a small tranche of unsubscribes whenever I discuss a topic that bugs the unsubscribers. Sometimes, the unsubscribers write to me, and we have enjoyable correspondence. 

We offer this newsletter as a labor of love. It's free! All are welcome. However, I discuss the regulatory landscape with all its ups and downs, controversies, and wrangling, and always try to ensure that compliance with the law is clarified. My goal is to educate and offer some helpful guidance. 

Anyone who does not recognize that the government partners with markets, be it mortgage or any other economic market, exhibits a view that borders on willful ignorance. I have taught graduate classes on market action relating to mortgage origination, and one obvious factor we discuss is the "free market" concept, which is the thesis that markets should not allow government involvement (often framed as "government interference"). 

"Free market" lingo wears several masks, such as "free trade" and "free enterprise," but the notion that any economic market is free of government involvement is belied by the fact that the government must be involved in ensuring and monitoring its legal and regulatory framework. 

Now, for a dose of reality: 

There has never been a free market in the history of the world.

Never. Nowhere. Not now. Not ever. 

The concept indirectly stems from an economic theory called "laissez-faire" – which, in French, means "allow to do" – which is a financial concept that purports to inform free markets and capitalism. In that scenario, the government does not regulate business, taxes, or tariffs. Instead, it proposes that a market self-regulates through the economic mechanism of supply and demand of products and services. And, it asserts that individuals drive markets through self-interest, which, somehow, leads to social and economic benefits.

Tuesday, December 17, 2024

Policy and Procedure links to Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

·       Customized Compliance Library

·       Policies Tune-up®

·       CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

·     A procedure for approving new or revised processes.

·     A procedure for managing and introducing process revisions.

·     The identification of training needs based on creating or updating policies and procedures.

·     The validation of new or revised policies and procedures prior to implementation. 

PROCESS MANAGEMENT 

Once the Change Management framework is completed, you can move on to interfacing them with Process Management and Project Management.

The primary purpose of process management is to group specific operational components for implementing interlocking institutional bases and contributing to an institution's activities. This means, in theory and practice, the setting up of the requirements needed to effectuate change throughout the company. 

Our reviews of Process Management have shown that there are at least eight structures needed for executing efficient institutional activities. This is a list that we use to ensure the stability of Process Management.

 

1.     There should be a centralized repository for all policies and procedures. In our work, we keep our clients' Masters in an encrypted, secure extranet.

 

2.     A dedicated group that oversees changes related to processes, systems, and policies. You must have a point person or persons involved in oversight. The contact information should be in writing and ratified by the board and/or management.

 

3.     Policies, procedures, and support documents are "mission-critical" key processes. They must be continually evaluated and updated with current revisions.

 

4.     All policies, procedures, and support documents should evaluated for completeness and accuracy. Inactive, dormant, and inoperative policies should be formally retired. Abeyant and suspended policies should be mothballed.

 

5.     Quality assurance reviews should be conducted periodically to ensure the actual performance of employee work processes is consistent with process flows and descriptions.

 

6.     The oversight team should draft a change management manual or tool to manage and track process updates. The board or management must ratify the manual.

 

7.     A standardized template should be modeled for policies and procedures throughout the organization.


8.     Be sure that the appropriate staff responsible for change management processes is well-trained or has the necessary skills to perform these functions.

PROJECT MANAGEMENT 

There are many ways and means to build project management structures. We have project managers who are credentialed in this task; however, you can create basic elements that interface with the Change Management framework. 

You don't need to be overwhelmed by this undertaking. Everything can be accomplished gradually so long as you have a logistical approach. A generic outline of project management should contain at least the following components: 

·       A project management manual or tool to track and manage projects.

·       Referenced policies, procedures, and systems affected by a project.

·       Project management tracking reports.

·       Centralization of project activities in an oversight group.

·       Training of relevant staff for project participation and management.

·       Periodic project tracking reports are communicated to stakeholders.

·       Updates to the inventory of projects subject to tracking. 

I also recommend that your project management methodology include: 

·       Communication of project goals and status.

·       Milestone reviews and approvals.

·       Identification and mitigation of project risk.

·       Identifying stakeholders, including their operational relevance.

·       Documenting procedures for change control documentation.

·       An escalation process for projects where there are tracking errors.

·       Log of activities with a column for remediation information and implementation. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, April 6, 2023

Risk Ratings of the Compliance Management System

QUESTION 

We have retained your firm for several of your Compliance Tune-ups. It has been amazing to find out the strengths and weaknesses of our departments and the implementation of regulatory compliance. We began with the CMS Tune-up almost two years ago, which told us how strong our Compliance Management System was in real time. Your risk ratings gave us a way to gauge our risk. 

As the Compliance Officer and General Counsel, I've come to appreciate that certain elements reflect a strong Compliance Management System. We are now planning another CMS Tune-up to see how effectively we have improved overall since the last CMS Tune-up. 

I understand the features of the Compliance Management System. What I would like to zero in on is the core elements themselves, the ones that are the foundation on which the CMS edifice sits. 

What are the core elements of a strong Compliance Management System? 

ANSWER 

When we developed and pioneered the CMS Tune-up® seven years ago, our goal was to provide a way for financial institutions to respond to the CFPB's position regarding the Compliance Management System (CMS). The Bureau found that there were

 

"… one or more situations in which an effective CMS was lacking across the financial institution's entire consumer financial portfolio, or in which the financial institution failed to adopt and follow comprehensive internal policies and procedures." 

So, our goal was to identify the strengths and weaknesses of a financial institution's Compliance Management System. We wanted to provide a cost-effective tool to evaluate five areas of interest to determine if a company: 

1.   Establishes its compliance responsibilities;

2.   Communicates those responsibilities to employees;

3.   Ensures that responsibilities for meeting legal and regulatory requirements, and internal policies, are incorporated into business processes;

4.   Reviews operations to ensure responsibilities are effectuated, with legal requirements met; and

5.   Takes corrective action and updates tools, systems, and materials as necessary. 

In the CMS Tune-up®, we assess whether an effective CMS accomplishes these four interdependent control components: 

1.   Board and management oversight;

2.   Compliance program;

3.   Response to consumer complaints; and

4.   Compliance audit. 

When all four control components are strong and well-coordinated, a financial institution should successfully manage its compliance responsibilities and risks. Bringing the analytics together can be extrapolated into an overall risk rating of the Compliance Management System. 

In fact, the Federal Financial Institutions Examination Council (FFIEC) endeavored to provide a compliance risk rating system all the way back in 2016.[i] FFIEC called it the CC Rating System. 

Our firm believes that providing risk ratings offers a financial institution the means to measure its compliance with rules; laws; regulations; guidelines; Best Practices; policy and procedure requirements; federal, state, and investor expectations. Each review in the Compliance Tune-up® series provides an independent risk rating defined and fully disclosed in our reports. 

___________________________________________________



The Compliance Tune-up® is an exclusive review
provided by Lenders Compliance Group.
If you want information about the Compliance Tune-up® series, 
please contact us HERE.

___________________________________________________

Our risk rating system consists of five levels of risk, based on an institution's size, complexity, and risk profile. Risk Rating 1 is the strongest; Risk Rating 5 is the weakest. Generally, depending on the category subject to review, a 1-rating is strong, a 2-rating is satisfactory, a 3-rating is deficient, a 4-rating is seriously deficient, and a 5-rating is critically deficient. We support our risk ratings by providing the appropriate citations and review analyses. Our reports contain recommendations and remediation guidance. 

Now, you put your finger on the importance of identifying the "core elements" on which rest risk ratings and evaluation of the strengths and weaknesses of the CMS. In my view, three fundamental elements secure the edifice of the Compliance Management System. 

The three elements of risk rating in evaluating a CMS are: 

1.       Change Management;

2.       Comprehending, identifying, and managing risk; and

3.       Corrective action and self-identification. 

Let's call this the Three "C" Approach to CMS Risk Rating. 

Change Management 

The first "C" stands for change management. The financial institution that receives our 1-rating is committed to a strong CMS that anticipates and responds promptly to changes in applicable laws and regulations, market conditions, and products and services offered. Management prepares for such changes by defining and providing examples of what constitutes a change, including new and changed vendor relationships and regulatory updates. To get our top rating, the company must demonstrate strong change management through proactive measures in advance of upcoming changes; for instance, management requires the compliance department and impacted business lines to review and approve changes before they take effect to ensure compliance with applicable consumer protection laws and regulations. 

Due diligence is an important activity in our risk rating because it should be conducted before product changes, taking into consideration the entire life cycle of a product or service, and conducting a post-implementation review to determine whether the actions taken have achieved the expected results. For example, as a part of its due diligence on a new product, the institution should develop and follow approval processes associated with implementing the new product and require a post-implementation review. 

Comprehending, Identifying, and Managing Risk 

The second "C" stands for comprehending, identifying, and managing risk. We give our 1-rating to financial institutions that evince a solid comprehension of risks, effectively identifies compliance risks, and actively manages those risks. Indeed, these institutions complete comprehensive risk assessments at established frequencies. 

In our experience, we have found that risk identification and evaluation processes generally become increasingly formal and extensive as an institution's size, complexity, and risk profile increase. For instance, an annual risk assessment may be appropriate for a small, non-complex institution. Completing a risk assessment at a large, complex institution may be an ongoing, collaborative effort among senior management, the compliance department, and the internal and external audit functions. 

Furthermore, institutions with a strong CMS maintain comprehensive risk assessments, including business lines, relevant rules and regulations, and a breakdown of associated inherent risk, risk controls, and residual risk. 

Corrective Action and Self-Identification 

The third "C" stands for corrective action and self-identification. In our view, a financial institution merits the 1-rating because it proactively identifies issues and promptly responds to compliance risk management deficiencies and violations. Such responsiveness invariably reflects a strong CMS. 

We have conducted a CMS Tune-up® that found the institution completed a root cause analysis of deficiencies and violations to ensure that remediation is timely, appropriate, and comprehensive. This is what proactive management does! An institution that completes a root cause analysis of a self-identified violation may find that written policies and procedures do not include sufficient information to ensure that staff complies with relevant regulatory requirements. Thus, the root cause analysis helps to inform appropriate and comprehensive remediation. 

Self-identification and self-assessment are reflections of proactive management. We often find that these institutions may also contact their primary regulator to determine whether their remediation efforts are sufficient. Consequently, we assign a 1-rating to institutions that proactively identify issues and promptly respond to deficiencies and violations, including remediation.

Jonathan Foxx, Ph.D., MBA

Chairman & Managing Director 
Lenders Compliance Group


[i] Uniform Interagency Consumer Compliance Rating System, Final Guidance, Federal Financial Institutions Examination Council, November 14, 2016, Federal Register, Vol. 81, No. 219, Notices

Thursday, October 20, 2022

Imperative of Pre-Funding Quality Control

QUESTION

My problem is that I have a CEO who does not want to do pre-funding quality control. When I insist on it, then we do it for a while. But he cuts it off again and again. He says our investors only care about post-closing quality control. 

Last month, one of our investors wanted to see our pre-funding quality control reports and checklists. Well, we had the checklists, but we only had a few pre-funding QC reports. Somehow, the word got out, and other investors are now asking for these things. 

Yesterday, we got a letter from Fannie Mae that singled out that we did not do pre-funding QC. The CEO called us into his office, showed us the letter, and admitted he was wrong. In the meantime, he's telling us to put pre-funding QC into action immediately. 

I am so frustrated I could scream! This was all avoidable. I want you to write something that I can show the CEO so that he understands what has happened and I don't have to deal with him again on this issue. 

Why is pre-funding quality control important, useful, and required? 

ANSWER

You deserve a badge of honor for warning your management all along. Sometimes, management thinks it is smarter and wiser than those handling the departments and functions. Good managers listen, learn, and are open to staff suggestions; bad managers pontificate and dictate. So, I am going to respond as if I were talking to your CEO. 

Mr. CEO, listen up! 

I have no skin in the game, but you do – and you have put your enterprise at risk. When you start to cut corners with investors, they will cut you out. Trust me, I've seen it happen many times. First, it's a letter. Then it's a per-file audit. Then it's a warning to restrict loan originations, putting you on a tight leash. The repurchase threats will accumulate. Keep it up and you're out. If Fannie gets burned, expect other investors to drop you. Game over! 

So let me give you some guidance. I suggest you give it your undivided attention. 

Think of pre-funding QC as a process, a tool to obtain real-time loan quality information about the loan you want to sell to investors. Without pre-funding reviews, you cannot proactively gauge the risk in advance while the loan is being originated. Post-closing and investor audits are "look-backs;" pre-funding QC reviews are "look-forwards." 

Read your Reps and Warrants – are you really sure you meet them without a pre-funding check? The fact is, an ineligible loan can lead to repurchase risk and impact your bottom line due to the time and effort needed to remediate defects. Get it right in the pre-funding stage, given that eligible loans are ostensibly eligible because they pass positively through pre-funding, notwithstanding that you have some confidence that the borrowers are in a sustainable home loan. 

And there are derivative benefits to your company. For instance, From point of sale to closing, insights are gained into the loan flow process – the very process in which specific risk elements, such as income calculation opportunities, appraisal quality, and fraud – can be identified early. Furthermore, pre-funding reviews allow management to implement initiatives to prevent recurring systemic or incidental errors. 

You need to keep pre-funding quality control separate from operations. Obviously, the purpose of pre-funding can be thwarted if the underwriters are evaluating their own decision process. How will a good understanding of loan quality be obtained if the pre-funding review does not provide independently derived information? 

Perhaps your organization's reporting structure doesn't have the capacity to separate these duties. That means you are exposed to increased risk, leading to potential conflict of interest, which can cause a failure to maintain an impartial view of your loan origination performance. If you can't provide internally independent personnel, you should use externally independent resources. Many audit firms, including mine, provide this service. Our LCG Quality Control pre-funding reviews are reasonably priced and cost-effective. You can contact us HERE. And visit our pre-funding QC audit overview HERE. We are very hands-on, as that is the only effective way of conducting pre-funding QC reviews. 

Whatever the case, you should deploy guardrails. For example, adverse pre-funding QC findings should not be overridden without conclusive and appropriate documentation. The Quality Control Plan needs to reflect an audit process that includes the pre-funding reviews, whether conducted internally or externally, to ensure that quality control procedures are performed correctly and independent from undue influence. 

As a CEO, you must ask the right questions if you are going to get useful answers. Here are four questions that I want you to discuss with your QC staff.

 

1. Does the pre-funding QC process lead to decisions that drive organizational change?

 

2. Does our Quality Control Plan detail the pre-funding process, setting expectations for all relevant stakeholders, departments, functions, and investors?

 

3. How confident are you that your pre-funding department operates independently from outside influence?

 

4. Is your QC plan compliant with Fannie Mae guidelines, such as:

·       Timing of the review,

·       Loan selection process,

·       Verification of data and documents, and

·       Reporting. 

These are the actions you should take in concert with your staff:

 

·     Review your Quality Control Plan to ensure all required pre-funding elements are included.

 

·     Determine if an audit process is in place to confirm that pre-funding QC is fully independent.

 

·     Review your pre-funding reporting to confirm it complies with investor guidelines regarding timing, process flow, and content.

 

·     Review your pre-funding QC reporting to improve the information provided to management.

A good suggestion is for you to use our QC Tune-up, which will let you know if your QC department and plan are properly interfaced internally and externally. For more information, contact us HERE. 

Finally, I will share with you some of the recurring findings that occur in our pre-funding QC reports. If you haven't been doing pre-funding reviews continually, you may have only a sparse understanding of these risks (and other risks) to which you have needlessly exposed your company. 

Untimely Selection of the Loan. This is a weak link because the timing of the pre-funding QC significantly affects the amount of information in the file. You should choose loans early enough in the origination process to complete all review steps but also at a point when sufficient information validates a correct credit decision. Your threshold metric must be a process that meets both the criteria for timing and validation. Ensuring the proper evaluation (i.e., timing and validation) is the basis for implementing a detailed remediation process. And, without exception, if the loan is acquired from a Third Party Originator (TPO), the pre-funding review should be performed pre-purchase. 

Defective Loan Selection Process and Quality Control Plan. You must document the pre-funding loan selection process and set forth the selection criteria in the Quality Control Plan, meaning you should:

·       Establish a process for loan selection,

·       Determine how often the selection criteria are revisited, and

·       Determine who is responsible for changing the selection criteria. 

Loans with a greater chance of errors, misrepresentation, or fraud should be selected in the pre-funding sample. Essentially, experience has shown that by tracking errors, the lender can select high risk loans and loans with a greater chance of having a defect. This is the reason behind discretionary sampling. A word about discretionary sampling is in order. The pre-funding sample method based on certain selection criteria includes emerging risks, testing of action plans, validation of employee, TPO performance, or targeting a specific component, such as complex income calculations. The discretionary pre-funding QC, therefore, leads to improved loan quality. 

Thursday, July 7, 2022

There’s Nothing Permanent Except Change

QUESTION 

You have written about something called “change management.” When I first read it, I thought it was some kind of a joke. I know we’re highly regulated, but how can you make us change our management? Then I read on, and I guess it’s no joke. 

Apparently, change management is a thing. It has to do with managing change, not changing management. That was the extent of my interest until an examiner asked for our change management policy. Say what? 

Anyway, we scrambled and put one together. The examiner accepted it. Problem solved. But maybe not. It is missing something I would dearly like to have: a checklist! I want a basic checklist for change management. 

Can you provide a checklist for change management? 

ANSWER 

As Lao Tzu said, ‘if you do not change direction, you may end up where you are heading.’ 

Yes, change management is about managing change. 

But would you know change if you encountered it? 

Would you recognize change after the change has already happened? 

Can you anticipate how to manage change if you realize its necessity? 

As the title of this article says, quoting Heraclitus, “there’s nothing permanent except change.” Are you ready for it? 

Change management is a method for providing an infrastructure to support and sustain change throughout multiple phases. Broadly speaking, it is based on achieving desired business results. If you are a financial institution, you will experience pressure from regulators, borrowers, shareholders, and investors to improve your business continuously. 

Although you don’t need pressure to manage change, it does tend to focus the mind! These pressures tend to lead toward initiating a wide range of company projects, including minor targeted updates, process enhancements, large complex system implementations, and significant business process adjustments and strategic initiatives. 

To the extent that a company standardizes its process and project management practices – the two prongs of change management – there should be improved optimization of organizational processes and mitigation of project failure risks. 

So, I will provide checklists for the two components: process management and project management. I will finish with a high-level, self-assessment checklist, which should be required for senior management and governance objectives. If you want a free copy of these checklists, request it HERE.

Process Management – Checklist

A centralized repository for all policies and procedures.

A dedicated group oversees processes, systems, and policy changes.

Key processes (i.e., policies, procedures, and support documents) are evaluated for completeness and accuracy. 

Key processes (i.e., policies, procedures, and support documents) are evaluated for current revisions.

Regular quality assurance reviews are conducted to ensure the actual performance of employee work processes is consistent with process flows and descriptions.

A change management tool to manage and track process updates. For instance, a standard policy/procedure template across the organization.

Staff responsible for the change management process is well trained or has the necessary skills to perform these functions.

Change management methodology that includes:

Business ownership and governance responsibilities.

An impact analysis before process changes are implemented.

Communication of new or revised processes to impacted business units or areas.

A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

A procedure for approving new or revised processes.

A procedure for managing and introducing process revisions.

Identification of training based on creating or updating policies and procedures.

Validation of new or revised policies and procedures prior to implementation.

Established controls are in place to ensure the change management methodology is applied consistently between individuals and work groups.

Project Management – Checklist 

Project management tool to track and manage projects.

Project management tracking reports.

Regular project tracking/inventory reports that are communicated to stakeholders. 

Project management methodology that includes:

Communication of project goals and status.

Milestone reviews and approvals.

Identification and mitigation of project risk.

Identification of stakeholders.

Change control documentation.

Escalation process for projects/steps determined to be off track.

Documentation of lessons learned.

Projects across the organization are managed under a central group.

Staff responsible for managing projects is trained and qualified to perform the function.

Finally, here’s a checklist that senior management should review.

Self Assessment Checklist

Description of the prospective change.

Input from stakeholders.

Formal change plan.

Identification of resources and data to be used. 

Communication strategy.

Review of budget risks associated with the change.

If you want a free copy of these checklists, request it HERE.

Jonathan Foxx, Ph.D., MBA

Chairman & Managing Director
Lenders Compliance Group