LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Compliance Management System. Show all posts
Showing posts with label Compliance Management System. Show all posts

Thursday, January 8, 2026

Staying Ahead of Regulatory Changes

YOUR QUESTION 

We are a small broker in the West. There are only four people in our company. We are licensed in three states. Every year, we get slammed with new compliance requirements from state and federal agencies. It's too much! Sometimes I think compliance is first and sales are second. Every year it gets worse and worse. 

Surely there is a way to keep track of these regulations without spending a ton of money on search engines and lawyers. I don't know what I don't know, and that is the problem. You don't have to give me every chapter and verse about what to do. I just need some advice on what I can do, given my limited means and staff. 

I need to get back to sales, but too much of my day is consumed by compliance. 

So, please let me know how to stay ahead of changing regulations. 

A Frustrated Broker 

OUR COMPLIANCE SOLUTION 

We recommend: 

BROKERS COMPLIANCE GROUP, the first full-service, mortgage risk management firm in the United States, specializing exclusively in outsourced mortgage compliance and offering a full suite of services to mortgage brokers, mini-correspondents, and independent mortgage professionals. 

OUR ANSWER 

I understand how you feel. It's the main reason why I started Lenders Compliance Group twenty years ago. 

Our Brokers Compliance Group supports the unique compliance needs of mortgage brokers. We have hundreds of brokers who let us handle their compliance so they can focus on sales and operations. 

Let me say this: there was a time, ages ago, when sales and compliance were separate activities, though they continually overlapped and coalesced. Now sales and compliance are cemented together. I know that's not what you want to hear, but it's true. 

Our industry is highly regulated, but given the tally of federal and state restrictions, it is not as regulated as others. Mortgage banking is categorically grouped within the finance and banking industries. It is certainly amongst the most highly regulated industries in the country. 

So, you will need to stay alert and proactive. However, there are several things you can do to reduce the time you give to monitoring and implementing regulations. It may seem daunting, but once you build momentum, you will be able to focus much more on sales. 

To prepare for regulatory changes, you should develop a proactive framework. By "framework," I mean a plan to closely monitor regulatory changes and, where needed, assess their impact on your origination processes. This plan should include feedback to update policies, provide training, test the loan flow process, maintain documentation, use methods to track changes, and audit ongoing compliance. You'll continually tweak the plan over the years. 

I'm going to break it down for you so that you get a feel for what I'm suggesting.

 

MONITOR

 

Develop a means to monitor court cases, enforcement actions, and regulatory bulletins. Because you have a small office, designate colleagues to track these early signals.

 

RESEARCH

 

Join, subscribe, or partner with industry associations and compliance advisors, such as Brokers Compliance Group. These resources usually provide content, updates, and specialized training.

 

TECHNOLOGY

 

Reduce research costs by using a cloud-based platform to alert you to regulatory changes. If you do not have the resources, you can partner with our compliance firm to get real-time feedback.

 

ASSESS & EVALUATE

 

Determine which business areas (for instance, lending, technology, operations) are affected by new rules (such as digital signage and AVMs). Identifying the impact strengthens compliance.

 

CONDUCT AUDITS

 

Perform internal audits or external audits to review your compliance management system. For a close look at a department, function, or regulation, use our inexpensive Compliance Tune-up.

Thursday, November 6, 2025

Blind Spots in Mortgage Compliance

QUESTION 

Our compliance department is being downsized. Apparently, I am one of the first to be fired–oh, excuse me, I mean downsized. Suppose I sound like I have a chip on my shoulder. In that case, I suppose I do, since this is my fourth compliance job that, through no fault of my own, is being downsized. It especially bothers me that the Chief Compliance Officer asks me, before I leave at the end of the month, to provide a list of compliance blind spots that we have encountered over the last few years. 

Anyway, I have been working on the list. However, the list is only involved with our company's blind spots. How about everyone else? I want to highlight some potential blind spots that may or may not be occurring in our company, but which could happen elsewhere. Since you have many clients across the country, I wonder if you could share the types of compliance blind spots that your clients encounter. 

Thank you in advance! By the way, I have read your articles for years. I will continue to subscribe wherever I go. I have my résumé out, but many companies are not hiring. So wish me well! 

What are some compliance blind spots in mortgage banking? 

SOLUTION 

We recommend the following Compliance Tune-up®! 

CMS Tune-up®

Compliance Management System 

The Compliance Tune-up® series assesses the overall strengths and weaknesses of departments, functions, and regulatory compliance, regardless of a financial institution’s size, regulator, complexity, or risk profile. 

ANSWER 

I am sorry that you are being downsized or, as you put it, fired. The tendency to use terms that mask the reality of circumstances can be infuriating. To be downsized means your position is eliminated as part of your company's permanent reduction of its workforce. It usually happens to cut costs or restructure. This is a business decision, not a reflection of your performance, and can be a response to economic downturns, technological changes, mergers, or a need for greater efficiency. I wish you all the best. Wherever you go, please stay in touch! 

Working with many clients provides an advantage because we can share our knowledge and experience with each client. The fact is, these days, no individual compliance department can master all the diverse issues associated with mortgage compliance. After a while, a company begins to form a rather parochial, narrow, and lopsided view of compliance challenges, as its understanding of compliance is specific to its particular experience. This model is problematic because a company faces numerous risks, and therefore, it can be blindsided by a lack of knowledge relating to compliance issues affecting other companies. 

I will share some blind spots that we have come across over the years. After nearly two decades, many compliance challenges have changed. But there are some perennials. My feedback here is certainly not comprehensive. I hope it helps! 

Fair Lending BLIND SPOTS 

First up in blind spots is fair lending. Many compliance managers are familiar with the basics of fair lending and rely on various types of reviews. The blind spots become a veritable regulatory minefield if they manifest themselves. Blind spots in areas such as prohibited practices, equal access to credit, loan applications compliance – including advertising, inquiries, reviews, loan disbursement, ongoing servicing, to name but a few – are areas that have massive legal consequences. However, I think this blind spot may be boiled down to at least these components.

 

·       Data Analysis Limitations

 Lenders sometimes fail to prepare quality Home Mortgage Disclosure Act (HMDA) data or view it in a narrow context, which tends to blind them to disparities in outcomes for minority groups.

 

·       Marketing and Outreach Bias 

Marketing materials may inadvertently exclude or discourage certain demographic groups, for instance, by not featuring diverse imagery or targeting underserved communities. For example, financial institutions risk bias when renting mailing lists based on criteria that skew toward specific neighborhoods.

Thursday, October 16, 2025

Transition: Subservicing to In-House Servicing

QUESTION 

We have used a subservicer for many years. Recently, we decided to bring servicing in-house. The committee we formed to shepherd the transition has determined that several guidelines must be developed to ensure a smooth transition. 

One problem we discovered is that some processes and procedures were not documented and approved. Relevant policies need some updating. The change management area needs further fulfillment. But we are overcoming these issues well as we get ready for the transition. 

Handling a smooth transition from subservicing to in-house servicing requires considerable attention to process, procedures, policies, and risk evaluations. I would like to know a few pointers I can take to the committee to assist in our plans. 

What tips can you give us to ensure a smooth transition from subservicing to in-house servicing? 

SOLUTION 

Servicing Platform Development 

Monthly Servicing Compliance

ANSWER 

Transitioning from a subservicer to a servicer is a complex process that involves gaining approval from investors and significantly expanding operational capacity. A subservicer performs the day-to-day duties of servicing a loan, but the master servicer holds the ultimate contractual responsibility to the investor. The transition to a servicer requires a company to develop the robust infrastructure and oversight capabilities of servicing, which go far beyond the monitoring of typical subservicer functions. 

To transition from a subservicer to a servicer conducting the servicing of its own loan portfolio, a financial institution must assume greater responsibilities and risks, which requires building significant internal capacity and obtaining approval from investors. The transition involves expanding operations, upgrading technology, and shifting legal obligations. 

As a master servicer, you own the right to perform servicing and may choose to service loans yourself or through subservicers. In the agency mortgage market, master servicers typically outsource the day-to-day functions to subservicers and assume a high-level oversight role. You do not state whether your in-house servicing will be exclusively for your own portfolio or if you plan to service both your own portfolio and also offer subservicing. For purposes of this article, I will assume the latter is the case. 

Key challenges when transitioning to servicing include meeting certain capital requirements, managing complex data migration, navigating intense regulatory scrutiny, and controlling operational costs while scaling the business. 

In the development of servicing platforms, we have outlined a step-by-step approach, consisting of five essential transition categories. Every one of these categories is essential to the smooth transition to in-house servicing. If your committee does not take these categories into account, the success of your transition may be in peril. 

The following are essential factors in the development of an in-house servicing platform. 

five Essential Transition Categories 

1. Investor approval 

Obtain approval from appropriate investors to function as a master servicer that services its own portfolio. 

Application Submission 

The process requires a detailed business background, financial health, policies, and operational procedures. 

Onsite Review 

An investor's risk team may conduct an on-site operational review to evaluate the company's servicing capabilities. 

Financial and Operational Assessment 

Investors may review the company's financial and operational metrics to ensure it has the capacity to handle the full range of servicing responsibilities. 

Compliance with Guidelines 

The company must meet all applicable eligibility requirements set forth in the investor's servicing and selling guides, announcements, formal issuances, and Best Practice expectations.

Thursday, September 4, 2025

Artificial Intelligence Disclosure

QUESTION 

I am the General Counsel and Compliance Officer of a mortgage lender. Our footprint is currently in 35 states. Recently, we have begun to use Artificial Intelligence in our loan origination process. However, I have some concerns about proper consumer disclosure. 

In my view, we should be disclosing our specific use of AI to borrowers. We should disclose the role AI plays in our loan applications from the point of sale to close, and, if applicable, beyond. But I do not find much regulatory guidance to lean on. I would appreciate your views on AI disclosure and, if possible, which areas would be subject to such disclosure. 

Is there a requirement for a mortgage lender to issue an AI consumer disclosure? 

What regulatory areas are potentially impacted by AI, thereby causing AI disclosure? 

COMPLIANCE SOLUTIONS 

AI Tune-up® 

Artificial Intelligence Statement  

RESPONSE 

There is currently no broad legal requirement for lenders to disclose the general use of AI in loan applications. However, under existing consumer protection and fair lending laws, lenders are legally required to disclose specific, accurate reasons for adverse actions, such as a loan denial, even if a complex AI or algorithmic system made the decision. 

This transparency is mandated by the Equal Credit Opportunity Act (ECOA), and regulatory bodies like the Consumer Financial Protection Bureau (CFPB) have issued guidance emphasizing that the complexity of AI is not an excuse for failing to provide a clear explanation. 

Regulatory Mandates 

Take, for instance, the regulatory mandates involving adverse action disclosure. The CFPB has directly addressed the issue of "black-box" models, which are AI systems whose logic is not clear even to their developers. The CFPB emphasizes that lenders cannot point to a broad category from a checklist, such as "purchasing history," if a consumer is denied credit based on AI analysis. Instead, the lender must provide specific details, such as the types of goods or places that influenced the decision. 

Also, there is no "AI exemption." A lender's use of AI or machine learning does not create a special exemption from fair lending laws. The CFPB has made it a priority to ensure that the use of technology does not allow lenders to circumvent established consumer protection regulations. In addition to the CFPB, regulators and the Federal Trade Commission have warned that there is no "AI exemption" for existing fair lending and consumer protection laws. Therefore, undisclosed AI could be found to violate these laws, leading to enforcement actions. 

The Colorado Artificial Intelligence Act 

Some state laws specifically address AI disclosure. For example, the Colorado Artificial Intelligence Act (CAIA) requires developers to test for algorithmic discrimination in consequential decisions, and some state consumer protection statutes allow for prosecution if an AI's biased outcomes cause consumer harm. This is a landmark act in many ways. If you are originating loans in Colorado, you should review the relevant regulations. However, you would do well to conduct a statewide review of AI legislation in all states where you are licensed to originate mortgage loans. 

CAIA may be a model for the direction states are going with respect to AI disclosure. The Act defines algorithmic discrimination, which is the unlawful differential treatment that disfavors an individual or group on the basis of protected characteristics. The algorithmic discrimination would be caused by high-risk artificial intelligence systems, defined as any system that, when deployed, makes — or is a substantial factor in making — a "consequential decision," which generally relates to those involving education, employment, financial services, housing, health care, or legal services. 

Under the CAIA, there are stipulated requirements for developers to clearly display on their website or in public use an up-to-date disclosure of any high-risk AI systems they have developed and make available how they manage known or reasonably foreseeable risks of algorithmic discrimination. Any determination that the AI system has caused or is reasonably likely to cause algorithmic discrimination must be brought to the attention of the Colorado attorney general, among others.

Wednesday, July 2, 2025

Safeguards Rule: Information Security Program

QUESTION 

We are a mortgage broker in the Midwest. In our last state audit, the examiner told us that we did not comply with the Safeguards Rule. It's my understanding that it's required by the GLBA, which behooves us to have an information security program. 

Well, we have one! Never had a problem before with it, yet now we've got an examiner saying that our information security plan is no good. I got it from a reputable manual company – at least I thought they were reputable until the banking department told me it was not in compliance. 

Now we've got to figure out what this Safeguards Rule is all about! I hope you can enlighten me. My office manager tried to find something on it, but it reads like a bunch of legal mumbo-jumbo. And, anyway, I don't know how to change the information security plan. I will contact your company to get help. Here's my question!

What does the Safeguards Rule cover? 

SOLUTION 

PRIVACY TUNE-UP®

INFORMATION SECURITY PLAN 

PRIVACY POLICY

RESPONSE 

Thanks for writing me. I will try to get you past the legalese. I'll provide citations in case you or your office manager wants them. That said, you can contact me and we'll get you back on track! 

Keep in mind that regularly assessing the Information Security Program, Plan, or Policy (ISP) is a function of the Second Line of Defense. A self-assessment or self-evaluation should be conducted at least once a year. If you have not already done so, you should conduct a risk assessment immediately. Alternatively, you can contact us for our Privacy Tune-up®, an audit that meets regulatory scrutiny. Or ask for our comprehensive Information Security Plan or the Privacy Policy.

The Federal Trade Commission's (FTC) Safeguards Rule, implemented under the Gramm-Leach-Bliley Act (GLBA), requires financial institutions to establish and maintain a comprehensive Information Security Program (ISP) to protect customer data. This includes developing written security plans with administrative, technical, and physical safeguards. The rule requires financial institutions to safeguard customer information against threats and unauthorized access. 

A few years ago, a mortgage broker contacted us to find out if her company was required to comply with the GLBA. The short answer is yes, indeed. A wide range of financial institutions is covered. A "financial institution,"[i] for our purposes, means an entity that provides real estate settlement services (because providing real estate settlement services is a financial activity)[ii], and the statute specifically denotes a mortgage broker as a financial institution.[iii] 

I'll get to your compliance responsibilities shortly. But first, you need to know what constitutes the Safeguards Rule ("Rule"). If your ISP does not have these key components textualized in some way, an examiner may find it defective. 

Five Key Components 

There are five Safeguards, as follows: 

1. Administrative Safeguards 

These involve policies and procedures for managing and overseeing the information security program. 

2. Technical Safeguards 

These include measures like firewalls, encryption, and access controls to protect data. 

3. Physical Safeguards 

These involve physical security measures to protect data storage locations and access to sensitive information. 

4. Oversight of Affiliates and Service Providers 

The Rule also mandates that financial institutions ensure their affiliates and service providers safeguard customer information.

Tuesday, December 17, 2024

Policy and Procedure links to Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

·       Customized Compliance Library

·       Policies Tune-up®

·       CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

·     A procedure for approving new or revised processes.

·     A procedure for managing and introducing process revisions.

·     The identification of training needs based on creating or updating policies and procedures.

·     The validation of new or revised policies and procedures prior to implementation. 

PROCESS MANAGEMENT 

Once the Change Management framework is completed, you can move on to interfacing them with Process Management and Project Management.

The primary purpose of process management is to group specific operational components for implementing interlocking institutional bases and contributing to an institution's activities. This means, in theory and practice, the setting up of the requirements needed to effectuate change throughout the company. 

Our reviews of Process Management have shown that there are at least eight structures needed for executing efficient institutional activities. This is a list that we use to ensure the stability of Process Management.

 

1.     There should be a centralized repository for all policies and procedures. In our work, we keep our clients' Masters in an encrypted, secure extranet.

 

2.     A dedicated group that oversees changes related to processes, systems, and policies. You must have a point person or persons involved in oversight. The contact information should be in writing and ratified by the board and/or management.

 

3.     Policies, procedures, and support documents are "mission-critical" key processes. They must be continually evaluated and updated with current revisions.

 

4.     All policies, procedures, and support documents should evaluated for completeness and accuracy. Inactive, dormant, and inoperative policies should be formally retired. Abeyant and suspended policies should be mothballed.

 

5.     Quality assurance reviews should be conducted periodically to ensure the actual performance of employee work processes is consistent with process flows and descriptions.

 

6.     The oversight team should draft a change management manual or tool to manage and track process updates. The board or management must ratify the manual.

 

7.     A standardized template should be modeled for policies and procedures throughout the organization.


8.     Be sure that the appropriate staff responsible for change management processes is well-trained or has the necessary skills to perform these functions.

PROJECT MANAGEMENT 

There are many ways and means to build project management structures. We have project managers who are credentialed in this task; however, you can create basic elements that interface with the Change Management framework. 

You don't need to be overwhelmed by this undertaking. Everything can be accomplished gradually so long as you have a logistical approach. A generic outline of project management should contain at least the following components: 

·       A project management manual or tool to track and manage projects.

·       Referenced policies, procedures, and systems affected by a project.

·       Project management tracking reports.

·       Centralization of project activities in an oversight group.

·       Training of relevant staff for project participation and management.

·       Periodic project tracking reports are communicated to stakeholders.

·       Updates to the inventory of projects subject to tracking. 

I also recommend that your project management methodology include: 

·       Communication of project goals and status.

·       Milestone reviews and approvals.

·       Identification and mitigation of project risk.

·       Identifying stakeholders, including their operational relevance.

·       Documenting procedures for change control documentation.

·       An escalation process for projects where there are tracking errors.

·       Log of activities with a column for remediation information and implementation. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Wednesday, December 11, 2024

Fannie’s MORA Review: Internal Audits

QUESTION 

Although approved by Fannie Mae, we have not set up an internal audit schedule. This issue came up in a recent discussion with our Fannie representative. They want us to be ready for the MORA audit, and the audit schedule is going to be required. We haven’t even done an internal audit yet. This got us thinking about what we don’t know for preparing for the MORA visit. 

We know your company is well-known for independent risk assessments and self-evaluations, which are called the Compliance Tune-up®. I spoke to one of your Directors this morning about several of them that could help us get prepared for the Fannie audit. We need to know which policies and procedures will be reviewed, and we need to know so much more. Our first MORA audit is coming soon. So, we’re somewhat intimidated. 

I am the compliance manager. I have never handled a MORA audit before. And I have never been involved in an internal audit. I need some guidance about what Fannie expects for internal audits and a “heads-up” for their requirements.


·       What are Fannie’s expectations for internal audits?

 

·       Can you please provide a “heads-up” for the internal audit requirements?


·       What have you found that shows your clients were not prepared for an internal audit? 

SOLUTION 

Compliance Tune-up® List

MORA Tune-up® Fannie's Mortgage Origination Risk Assessment (MORA)

CMS Tune-up® Compliance Management System

RESPONSE 

Anyone who has an interest in our Compliance Tune-up®, in general, or our MORA Tune-up®, in particular, can contact us here. The Compliance Tune-up® is an extensive series of mini-audits that targets departments, functions, and regulations. It is a self-identification and risk assessment review that complies with the second line of defense.[i] The review provides a report and risk rating. It shows the strengths and weaknesses of the area subject to review. 

Fannie Mae conducts regular reviews to evaluate seller/servicer compliance with its guidelines and assess operational risks. Reviews are conducted by a team that operates independently of the Business Account Management Solutions team. 

You will need to establish an independent internal audit function. During the MORA process, Fannie Mae examines the lender's internal audit plan and the latest independent internal audit. A financial institution may outsource its internal audit process; however, it remains responsible for the findings that show compliance (or lack thereof) with Fannie's requirements.

An internal audit is the central feature of the third line of defense. From Fannie’s perspective, management control is itself a function. Indeed, establishing a professional internal audit activity should be a governance requirement for all organizations. 

Management is supposed to rely on the internal audit to validate a financial institution’s governance, risk management, and control processes to help it achieve strategic, operational, financial, and compliance objectives. This compliance framework is meant to ensure a risk-based approach, and the internal audit function evaluates and improves the effectiveness, exigencies, and readiness of risk management, control, and governance processes. 

We believe the following outline provides the guardrails and requirements of an internal audit. It would be best if you considered them collectively so that you prepare adequately for the development of this function. In other words, don’t cut corners. Be sure you comply with all these criteria. 

Internal Audit Function: Guardrails and Requirements


·       Be sure that the internal audit manager is free from any responsibility over any business unit.

 

·       Be sure the internal audit is independent of all key functions of the loan origination and servicing processes.

 

·       Draft internal audit and management control procedures for evaluating and monitoring the overall quality of loan production.


·       Ensure that your organization chart shows that the internal audit function reports directly to the senior management and, if applicable, the Board of Directors. (By the way, we know from experience that Fannie will permit exceptions in situations in which the size of the organization is insufficient to support adequate resources to allow for the separation of these functions. In those situations, your audit plan must include the rationale for the lack of separation of controls in place to mitigate risks associated with the lack of separation of these functions.)


·       Be especially careful that internal audit lines of reporting reflect the independence of the audit process at all levels so that the activities are conducted in an unbiased manner and without compromises that may result from internal influences or conflicts of interest.


·       Be especially careful that the internal audit function does not share any reporting lines with the functional areas that it reviews.


·       Create a reliable and scaleable reporting procedure to ensure that the written findings provide methodologies that derive recommendations that management can use to accomplish actionable objectives through a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control, and governance processes. 

Adverse Findings and Required Document Preparation 

There are a few other things I would like you to consider. I’ll get to them in a moment. You had asked about how some clients show that they are not ready for an internal audit. By this point, I think we’ve seen just about everything there is to see about internal audit findings and preparation. However, most challenges can be overcome if you have robust plans. 

We have an extensive database of common findings from independent internal audits and Compliance Tune-up®. I have picked seven of them that I think are virtually non-negotiable. 

Adverse Findings


1)    There is no comprehensive written plan to direct the internal audit process across all loan manufacturing and servicing business functions.

 

2)    There is no internal audit function.


3)    MBS Trust compliance is not included in the internal audit review plan and testing.


4)    The internal audit process has not been initiated.


5)    There is no internal audit function that is independent of the business functions subject to review.


6)    An internal audit schedule has not been established to specify the areas of review, and there’s no timeframe for conducting them.


7)    The internal audit plan does not include all required components. 

Required Document Preparation 

Each financial institution differs and is unique in terms of size, products, services, complexity, risk profile, and business strategy. Keep that in mind as I outline the document preparation needed to be ready for a MORA review. You can tighten up preparation by using the appropriate Compliance Tune-up® tool, such as a MORA Tune-up® or a CMS Tune-up®. 

A Compliance Tune-up® report provides recommendations indicating what should be done now and in the future to ensure readiness, but you can’t undo mistakes of the past. Willingness to correct errors, however, is a sign of good management and governance. So, it would be best if you got ready immediately to prevent a lookback that discloses unmitigated adverse findings. 

·       Organization chart reflecting the internal audit department

·       Internal audit policies and procedures.

·       Current year’s testing schedule and internal audit plan.

·       Current year’s Compliance Tune-up®. (Second Line of Defense).       

·       Current year’s independent internal audit. (Third Line of Defense).

·       Ability to identify any significant findings for the past 12-month period.

·       Management and tracking reports for monitoring performance in operational areas. 

WordS to the Wise should be Sufficient! 

I stated above that there are a few other things I want you to consider. I list them in no order of importance because they are all equally important. Let’s group these remarks in the category of “words to the wise should be sufficient!” 

·       An internal audit plan should be risk-based, updated annually, and include a review of all controls and key functions in each origination and servicing department. 

·       Applying a risk rating for each key process area of the originations and servicing platforms is critical to implementing a continuous internal audit schedule. 

·       A second line of defense review, such as the Compliance Tune-up®, should be initiated for specific departments, functions, and regulations in anticipation of performing the internal audit. (This ensures that the internal audit, the third line of defense, may present accurate and reliable findings.) 

·       A process should be in place to define the scope and frequency of audits to be performed based on the specific risk rating for all key functions. (This ensures that the functions that represent the highest risk are audited on at least an annual basis.) 

·       An internal audit schedule should be in place, reflect current activity, and be reviewed on a regular basis to incorporate any emerging risks in operational areas. 

·       Adverse internal or external audit findings pertaining to key functions or regulatory compliance should be reviewed by the audit committee for remediation. 

·       An established framework for interaction between internal audit functions, business units, and management exists to ensure open communications regarding risk and control management, including the adoption and implementation of self-assessment methodologies.

 

Jonathan Foxx, Ph.D., MBA

Chairman & Managing Director

Lenders Compliance Group



[i] Three Lines of Defense in Effective Risk Management and Control, Institute of Internal Auditors (IIA), January 2013. The Lines of Defense (LOD) model assigns and coordinates risk and control responsibilities across business functions.