LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Compliance Tune-up. Show all posts
Showing posts with label Compliance Tune-up. Show all posts

Thursday, January 8, 2026

Staying Ahead of Regulatory Changes

YOUR QUESTION 

We are a small broker in the West. There are only four people in our company. We are licensed in three states. Every year, we get slammed with new compliance requirements from state and federal agencies. It's too much! Sometimes I think compliance is first and sales are second. Every year it gets worse and worse. 

Surely there is a way to keep track of these regulations without spending a ton of money on search engines and lawyers. I don't know what I don't know, and that is the problem. You don't have to give me every chapter and verse about what to do. I just need some advice on what I can do, given my limited means and staff. 

I need to get back to sales, but too much of my day is consumed by compliance. 

So, please let me know how to stay ahead of changing regulations. 

A Frustrated Broker 

OUR COMPLIANCE SOLUTION 

We recommend: 

BROKERS COMPLIANCE GROUP, the first full-service, mortgage risk management firm in the United States, specializing exclusively in outsourced mortgage compliance and offering a full suite of services to mortgage brokers, mini-correspondents, and independent mortgage professionals. 

OUR ANSWER 

I understand how you feel. It's the main reason why I started Lenders Compliance Group twenty years ago. 

Our Brokers Compliance Group supports the unique compliance needs of mortgage brokers. We have hundreds of brokers who let us handle their compliance so they can focus on sales and operations. 

Let me say this: there was a time, ages ago, when sales and compliance were separate activities, though they continually overlapped and coalesced. Now sales and compliance are cemented together. I know that's not what you want to hear, but it's true. 

Our industry is highly regulated, but given the tally of federal and state restrictions, it is not as regulated as others. Mortgage banking is categorically grouped within the finance and banking industries. It is certainly amongst the most highly regulated industries in the country. 

So, you will need to stay alert and proactive. However, there are several things you can do to reduce the time you give to monitoring and implementing regulations. It may seem daunting, but once you build momentum, you will be able to focus much more on sales. 

To prepare for regulatory changes, you should develop a proactive framework. By "framework," I mean a plan to closely monitor regulatory changes and, where needed, assess their impact on your origination processes. This plan should include feedback to update policies, provide training, test the loan flow process, maintain documentation, use methods to track changes, and audit ongoing compliance. You'll continually tweak the plan over the years. 

I'm going to break it down for you so that you get a feel for what I'm suggesting.

 

MONITOR

 

Develop a means to monitor court cases, enforcement actions, and regulatory bulletins. Because you have a small office, designate colleagues to track these early signals.

 

RESEARCH

 

Join, subscribe, or partner with industry associations and compliance advisors, such as Brokers Compliance Group. These resources usually provide content, updates, and specialized training.

 

TECHNOLOGY

 

Reduce research costs by using a cloud-based platform to alert you to regulatory changes. If you do not have the resources, you can partner with our compliance firm to get real-time feedback.

 

ASSESS & EVALUATE

 

Determine which business areas (for instance, lending, technology, operations) are affected by new rules (such as digital signage and AVMs). Identifying the impact strengthens compliance.

 

CONDUCT AUDITS

 

Perform internal audits or external audits to review your compliance management system. For a close look at a department, function, or regulation, use our inexpensive Compliance Tune-up.

Tuesday, December 2, 2025

Non-Delegated Lenders: Quality Control for Non-QM Loans

Podcast | Substack

QUESTION 

I am one of the underwriters for a non-delegated lender. We received a request from an investor to conduct quality control. My boss says we do not have to do quality control. His position is that, at most, we need only a limited quality control audit. I came from another non-delegated lender, and they always did QC. 

He says we do not have to perform most aspects of QC audits, including credit analysis, re-verifications, credit reports, appraisal reviews, adverse action reviews, EPD issues, and GSE/FHA-VA underwriting reviews. Because we originate non-QM loans, he says QC is minimal. I read your Bulletin 2017-12, and it clearly shows that non-delegated lenders should do QC. 

I would like you to discuss QC requirements for non-delegated lenders. 

Does a non-delegated lender have to do quality control for non-QM loans? 

OUR COMPLIANCE SOLUTIONS 

We recommend the following compliance solutions for quality control support: 

Quality Control Audits

Our audits focus on risk mitigation, compliance, error correction, process improvement, verification, and ongoing monitoring. 

QC Tune-up®

This is our Second Line of Defense review that focuses on predictable output, reliable data, investor confidence, and reduced production cost. 

RESPONSE TO YOUR QUESTION

The question about a non-delegated lender having to conduct quality control seems to be one of those perennial questions that pop up from time to time. There is no mystery to the requirement. I appreciate that you have been reading our Bulletins. Anyone who wants to subscribe to our free Bulletins, please sign up! 

Whether you are originating QM or non-QM loans, you should be conducting quality control audits. Fannie Mae's non-delegated quality control (QC) requirements include having a comprehensive written QC plan, a process for selecting loans for prefunding and post-closing reviews, and a system for reporting and taking corrective action. 

If you're a non-delegated lender originating QM loans, the QC plan should be independent of the production process, and, among other things, you must conduct a minimum number of prefunding and post-closing QC reviews each month, based on a percentage of total loan volume. 

If you're a non-delegated lender originating non-QM loans, you should have QC processes in place. Because non-QM loans do not meet the criteria for purchase by Fannie Mae or Freddie Mac, the lender assumes all the risk, making a robust QC program essential to manage the loan quality and potential defects. 

Let's look somewhat broadly at the QC requirements. You must have a written QC plan that outlines your QC philosophy, objectives, and risks, with a process for selecting loans for review using random and/or discretionary methods across all products. The QC function must be independent of the production process, or, at a minimum, reviews must be conducted by personnel not involved in underwriting the specific loans subject to audit. 

The QC plan for QM loans must cover both prefunding and post-closing reviews, ensuring compliance with the Fannie Mae Selling Guide, the lender contract, and applicable laws. You can check out Fannie's requirements in the Lender Quality Control Programs, Plans, and Processes section. 

With respect to pre-funding, a minimum number of prefunding reviews must be completed each month, with the loan selection meeting at least the lesser of 10% of the prior month's total loans, 10% of current month projections, or 750 loans. 

Regarding post-closing, loans must be selected for monthly reviews, and the entire QC cycle must be completed within 90 days of loan closing. 

You must have documented procedures for reporting QC findings to management, documenting loan level findings for resolution, and taking timely corrective actions. All QC-related documentation must be retained for at least three years. An internal audit of the QC process itself should be performed annually to ensure compliance with the lender's policies and procedures. Our QC Tune-up®, a Second Line of Defense function, provides such support.

Thursday, September 4, 2025

Artificial Intelligence Disclosure

QUESTION 

I am the General Counsel and Compliance Officer of a mortgage lender. Our footprint is currently in 35 states. Recently, we have begun to use Artificial Intelligence in our loan origination process. However, I have some concerns about proper consumer disclosure. 

In my view, we should be disclosing our specific use of AI to borrowers. We should disclose the role AI plays in our loan applications from the point of sale to close, and, if applicable, beyond. But I do not find much regulatory guidance to lean on. I would appreciate your views on AI disclosure and, if possible, which areas would be subject to such disclosure. 

Is there a requirement for a mortgage lender to issue an AI consumer disclosure? 

What regulatory areas are potentially impacted by AI, thereby causing AI disclosure? 

COMPLIANCE SOLUTIONS 

AI Tune-up® 

Artificial Intelligence Statement  

RESPONSE 

There is currently no broad legal requirement for lenders to disclose the general use of AI in loan applications. However, under existing consumer protection and fair lending laws, lenders are legally required to disclose specific, accurate reasons for adverse actions, such as a loan denial, even if a complex AI or algorithmic system made the decision. 

This transparency is mandated by the Equal Credit Opportunity Act (ECOA), and regulatory bodies like the Consumer Financial Protection Bureau (CFPB) have issued guidance emphasizing that the complexity of AI is not an excuse for failing to provide a clear explanation. 

Regulatory Mandates 

Take, for instance, the regulatory mandates involving adverse action disclosure. The CFPB has directly addressed the issue of "black-box" models, which are AI systems whose logic is not clear even to their developers. The CFPB emphasizes that lenders cannot point to a broad category from a checklist, such as "purchasing history," if a consumer is denied credit based on AI analysis. Instead, the lender must provide specific details, such as the types of goods or places that influenced the decision. 

Also, there is no "AI exemption." A lender's use of AI or machine learning does not create a special exemption from fair lending laws. The CFPB has made it a priority to ensure that the use of technology does not allow lenders to circumvent established consumer protection regulations. In addition to the CFPB, regulators and the Federal Trade Commission have warned that there is no "AI exemption" for existing fair lending and consumer protection laws. Therefore, undisclosed AI could be found to violate these laws, leading to enforcement actions. 

The Colorado Artificial Intelligence Act 

Some state laws specifically address AI disclosure. For example, the Colorado Artificial Intelligence Act (CAIA) requires developers to test for algorithmic discrimination in consequential decisions, and some state consumer protection statutes allow for prosecution if an AI's biased outcomes cause consumer harm. This is a landmark act in many ways. If you are originating loans in Colorado, you should review the relevant regulations. However, you would do well to conduct a statewide review of AI legislation in all states where you are licensed to originate mortgage loans. 

CAIA may be a model for the direction states are going with respect to AI disclosure. The Act defines algorithmic discrimination, which is the unlawful differential treatment that disfavors an individual or group on the basis of protected characteristics. The algorithmic discrimination would be caused by high-risk artificial intelligence systems, defined as any system that, when deployed, makes — or is a substantial factor in making — a "consequential decision," which generally relates to those involving education, employment, financial services, housing, health care, or legal services. 

Under the CAIA, there are stipulated requirements for developers to clearly display on their website or in public use an up-to-date disclosure of any high-risk AI systems they have developed and make available how they manage known or reasonably foreseeable risks of algorithmic discrimination. Any determination that the AI system has caused or is reasonably likely to cause algorithmic discrimination must be brought to the attention of the Colorado attorney general, among others.

Wednesday, July 2, 2025

Safeguards Rule: Information Security Program

QUESTION 

We are a mortgage broker in the Midwest. In our last state audit, the examiner told us that we did not comply with the Safeguards Rule. It's my understanding that it's required by the GLBA, which behooves us to have an information security program. 

Well, we have one! Never had a problem before with it, yet now we've got an examiner saying that our information security plan is no good. I got it from a reputable manual company – at least I thought they were reputable until the banking department told me it was not in compliance. 

Now we've got to figure out what this Safeguards Rule is all about! I hope you can enlighten me. My office manager tried to find something on it, but it reads like a bunch of legal mumbo-jumbo. And, anyway, I don't know how to change the information security plan. I will contact your company to get help. Here's my question!

What does the Safeguards Rule cover? 

SOLUTION 

PRIVACY TUNE-UP®

INFORMATION SECURITY PLAN 

PRIVACY POLICY

RESPONSE 

Thanks for writing me. I will try to get you past the legalese. I'll provide citations in case you or your office manager wants them. That said, you can contact me and we'll get you back on track! 

Keep in mind that regularly assessing the Information Security Program, Plan, or Policy (ISP) is a function of the Second Line of Defense. A self-assessment or self-evaluation should be conducted at least once a year. If you have not already done so, you should conduct a risk assessment immediately. Alternatively, you can contact us for our Privacy Tune-up®, an audit that meets regulatory scrutiny. Or ask for our comprehensive Information Security Plan or the Privacy Policy.

The Federal Trade Commission's (FTC) Safeguards Rule, implemented under the Gramm-Leach-Bliley Act (GLBA), requires financial institutions to establish and maintain a comprehensive Information Security Program (ISP) to protect customer data. This includes developing written security plans with administrative, technical, and physical safeguards. The rule requires financial institutions to safeguard customer information against threats and unauthorized access. 

A few years ago, a mortgage broker contacted us to find out if her company was required to comply with the GLBA. The short answer is yes, indeed. A wide range of financial institutions is covered. A "financial institution,"[i] for our purposes, means an entity that provides real estate settlement services (because providing real estate settlement services is a financial activity)[ii], and the statute specifically denotes a mortgage broker as a financial institution.[iii] 

I'll get to your compliance responsibilities shortly. But first, you need to know what constitutes the Safeguards Rule ("Rule"). If your ISP does not have these key components textualized in some way, an examiner may find it defective. 

Five Key Components 

There are five Safeguards, as follows: 

1. Administrative Safeguards 

These involve policies and procedures for managing and overseeing the information security program. 

2. Technical Safeguards 

These include measures like firewalls, encryption, and access controls to protect data. 

3. Physical Safeguards 

These involve physical security measures to protect data storage locations and access to sensitive information. 

4. Oversight of Affiliates and Service Providers 

The Rule also mandates that financial institutions ensure their affiliates and service providers safeguard customer information.

Monday, June 16, 2025

Raided by ICE - Employees Detained

QUESTION 

Our company was raided by ICE last week. Two of our loan officers were taken away in handcuffs. They were not read any rights. They were just taken from their desks, put in cuffs, and walked out. Our HR Department notified their families. 

It was a shock to all of us. I am a loan officer and asked our lawyer for permission to write to you about it. We have no guidelines on what to do if ICE shows up, but we’re trying to figure out what to do if ICE shows up. We do not want any trouble, and there is a lot of fear. 

Our lawyer, compliance people, and HR manager are putting together some guidelines. But many of us here get your newsletter, and we would like you to provide a few guidelines to follow if ICE comes back. 

What should we do if ICE raids our company? 

Do our employees have any rights? 

SOLUTION 

ICE Tune-up® 

RESPONSE 

If ICE raids your company, remain calm and cooperate with the agents. However, you can protect your legal rights and those of your employees. The first action to take is to immediately contact legal counsel and have a designated employee accompany ICE agents during the raid. If you have not selected such an employee liaison, do so now. 

Document everything, including the names of agents, areas searched, and items seized. But, do not obstruct or interfere with the search, and also do not provide false information or hide employees. 

I will offer some suggestions for immediate actions and a few things to consider. The following list is not meant to be comprehensive (and I am not providing legal advice). Facts and circumstances often dictate the response and appropriate legal actions. If you have questions, you can contact us. 

If you want to be prepared for an ICE visit, you should consider our ICE Tune-up®, a mini-audit that determines whether you are ready for such a visit. Our pioneering Compliance Tune-up is in considerable demand. If you need this audit soon, I urge you to contact us to schedule it. 

IMMEDIATE ACTIONS


·    Contact Counsel

I suggest you notify legal counsel about the raid.

 

·    ICE Team

Designating an ICE Team is essential. Whoever has first contact with ICE agents should know to contact the company’s designated ICE Team members so they can start implementing the ICE raid protocols.

 

·    Document

Designate an employee to take detailed notes, including agent names, badge numbers, areas searched, and persons or items seized.

 

·    Stay with the Agents

Select an employee to accompany ICE agents during the search to observe and document.

 

·    Verify Warrants

Request and review any warrants presented by ICE agents. Many ICE raids are being conducted using administrative warrants. Ensure they are judicial warrants (viz., signed by a judge) and understand their scope.


o   Court Warrant – A federal or state court judge issues a judicial (or court) warrant. It gives ICE access to non-public spaces of the facility in accordance with the terms of the warrant. Even if ICE has a court warrant, it is important to review the warrant to ensure it has the correct company name and address, is properly signed and dated by a judge, includes a timeframe within which the search must be conducted, any restrictions, and contains a description of the premises to be searched and a list of items or people to be seized (i.e., equipment, records, workers).

o   Administrative (or No Warrant) – If ICE has no warrant or only an administrative warrant (i.e., signed by ICE on Forms I-200 or I-205), the warrant does not permit ICE to access non-public spaces.


But if ICE proceeds, do not argue with or impede ICE. Instead, document your objections, which can be used later in a court challenge.

Wednesday, May 28, 2025

Endorsements and Testimonials - FTC Rules

QUESTION 

I am the Director of Marketing at a mortgage lender in the Northwest. We are developing a marketing campaign using endorsements and testimonials on social media, social media influencers, press, radio, YouTube, and TV. While our compliance and legal departments are happy to review these promotions, they are not giving us clear guidelines to follow. 

Our legal department tells us that, because of the wide distribution of our campaign channels, some of the rules we must follow are based on the Federal Trade Commission's rules. I don't know if this is so, but I do know those rules can be kind of strict. I need to find out about some of the FTC's regulations involving endorsements and testimonials. 

What are some FTC guidelines for endorsements and testimonials? 

SOLUTION 

Advertising Tune-up

Marketing Tune-up

Advertising Manual

Advertising Compliance  

RESPONSE 

The Federal Trade Commission's (FTC) regulations are essential to follow for marketing campaigns. Indeed, the FTC implemented the Mortgage Acts and Practices – Advertising (MAP) rules![i] MAP rules are designed to prohibit misrepresentations regarding mortgage products. Yes, there are other Acts, regulations, and laws – federal and state – such as the following (to name a few salient ones): 

·       Fair Housing Act,

·       Equal Credit Opportunity Act,

·       Truth-in-Lending Act,

·       FHA/HUD, VA, USDA Regulations,

·       Real Estate Settlement Procedures Act,

·       State Regulations,

·       Fair Lending,

·       Unfair, Deceptive, or Abusive Acts or Practices, and

·       Federally required logos and disclosures. 

The Federal Trade Commission's MAP rules must be implemented in your marketing campaign. 

Advertising and marketing compliance is a highly complex area that requires very careful consideration prior to launching a marketing campaign. If you do not handle endorsements and testimonials appropriately, you can easily cause legal disputes and attract regulators. 

I have listed a few compliance solutions above. You can always contact me to discuss your particular marketing plan. We have worked for years with banks and nonbanks on their marketing campaigns. Here are just a few articles we've published on advertising compliance. 

The FTC requires endorsers to clearly and conspicuously disclose their sponsorship by the advertiser and requires that endorsements reflect the honest experience or opinion of the endorser and not contain representations that would be deceptive or unsubstantiated if the advertiser made them directly.[ii] Therefore, if an endorsement represents that the endorser uses the advertiser's product, the endorser must actually use the product at the time they endorse it.[iii] 

Advertisers using "consumer endorsements" must make clear whether the endorser's experience reflects the actual experience of typical consumers who use the product rather than the experience of a few individuals.[iv] Ensuring this clarity is critical because, in 2009, the FTC revised its guidance regarding consumer endorsements to eliminate the safe harbor previously provided for the use of disclaimers in conjunction with non-representative consumer testimonials, such as "results not typical" and "not all consumers will get this result." In other words, these disclaimers are no longer acceptable because the FTC believes they are not sufficient to overcome the misleading implication that a non-representative result depicted in an advertisement is what consumers will generally experience.

Thursday, January 9, 2025

What to Expect from a Fannie MORA audit?

Request Article 

Request MORA Tune-up® Information 

QUESTION 

Last month, you answered a question about doing an internal audit in advance of Fannie’s MORA audit. We did not pay much attention to it because (A) we never had a MORA audit, and (B) we did not expect a MORA audit anytime soon. Then, all hell broke loose! 

Yesterday, we got a letter from Fannie Mae telling us that they will be scheduling a date for an on-site audit. They are requesting policies, procedures, and many other documents. There are due dates. This review makes a state banking exam look like child’s play. But I’m a QC manager, so I don’t have the whole picture of our risks. However, I do know one thing: we are not ready for this MORA audit. 

The CEO called a team meeting in the conference room. Our compliance manager is in charge, and everyone reports to her. I got your name at the meeting because she said we are going to use you to do a MORA Tune-up®. I just wish they would have done this sooner. 

What I need – and I think they need it too – is some idea of what we can expect from the MORA exam. I hope you don’t wait to reply. The compliance manager and others in management read your articles. They pass them around to us all the time. Please tell us what to expect about the MORA process. 

What is the audit process of a Fannie MORA audit? 

SOLUTION 

MORA Tune-up® 

RESPONSE 

If you want a copy of this article, please contact us here. 

We realize your question is urgent. Accordingly, we are prioritizing a response. You only have a few weeks to get ready for the MORA audit, the purpose of which is for Fannie Mae to evaluate your company’s compliance with Fannie guidelines as well as assess the operational risks. 

For those who don’t know, Mortgage Origination Risk Assessment (MORA) is a Fannie Mae review of a Fannie Seller/Servicer. It is intended to be a collaborative engagement led by the review team with the active participation of your organization.[i]

Getting our MORA Tune-up® engaged is one of several readiness activities you must undertake as soon as possible. Ours is the pioneer of the Compliance Tune-up, a unique review that provides a risk assessment and self-evaluation to satisfy the Second Line of Defense. I am grateful that your compliance manager chose Lenders Compliance Group. Nevertheless, to all our subscribers, please know that a few compliance and law firms offer to prepare you for the MORA review. Pick one you trust and get it done! 

There are seven phases in the MORA review process, and I will outline them for you. My outline will give you a high-level view. You should not delay! 

Here are the seven phases of a MORA review: 

Phase 1: Selecting the Organization 

Phase 2: Confirmation and Engagement 

Phase 3: Document Request and Receipt 

Phase 4: Process Evaluation 

Phase 5: Interviews 

Phase 6: Final Assessment 

Phase 7: Remediation 

I am going to provide a brief overview of each phase. However, numerous contingencies can affect the process and outcome. Take this review as a deep dive, one that will make your company stronger and its relationship with Fannie more durable. It is not too late to get started immediately. 

PHASE 1: SELECTING THE ORGANIZATION 

Fannie Mae selects organizations for a review using risk-based inclusion criteria and provides advance notice to the organization prior to scheduling the review. A member of the review team begins the process by compiling the organization’s pertinent contact information to start the review before moving to Phase 2. 

We are often asked if there is a way to predict whether and when the selection takes place. The short answer is No. The best answer is Soon. In other words, always be prepared.

PHASE 2: Confirmation and Engagement 

There are obviously two parts to this phase: the first part involves confirmation, and the second part involves scheduling. These two parts are interfaced. What happens is your point person – in your case, the compliance manager – will discuss Fannie’s BAMS team, that is, its Business Account Management Solutions team, to discuss some basics. The MORA team is independent of the BAMS team. This is a sort of Question and Answer format where the BAMS team gathers the following information:

Tuesday, December 17, 2024

Policy and Procedure links to Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

·       Customized Compliance Library

·       Policies Tune-up®

·       CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

·     A procedure for approving new or revised processes.

·     A procedure for managing and introducing process revisions.

·     The identification of training needs based on creating or updating policies and procedures.

·     The validation of new or revised policies and procedures prior to implementation. 

PROCESS MANAGEMENT 

Once the Change Management framework is completed, you can move on to interfacing them with Process Management and Project Management.

The primary purpose of process management is to group specific operational components for implementing interlocking institutional bases and contributing to an institution's activities. This means, in theory and practice, the setting up of the requirements needed to effectuate change throughout the company. 

Our reviews of Process Management have shown that there are at least eight structures needed for executing efficient institutional activities. This is a list that we use to ensure the stability of Process Management.

 

1.     There should be a centralized repository for all policies and procedures. In our work, we keep our clients' Masters in an encrypted, secure extranet.

 

2.     A dedicated group that oversees changes related to processes, systems, and policies. You must have a point person or persons involved in oversight. The contact information should be in writing and ratified by the board and/or management.

 

3.     Policies, procedures, and support documents are "mission-critical" key processes. They must be continually evaluated and updated with current revisions.

 

4.     All policies, procedures, and support documents should evaluated for completeness and accuracy. Inactive, dormant, and inoperative policies should be formally retired. Abeyant and suspended policies should be mothballed.

 

5.     Quality assurance reviews should be conducted periodically to ensure the actual performance of employee work processes is consistent with process flows and descriptions.

 

6.     The oversight team should draft a change management manual or tool to manage and track process updates. The board or management must ratify the manual.

 

7.     A standardized template should be modeled for policies and procedures throughout the organization.


8.     Be sure that the appropriate staff responsible for change management processes is well-trained or has the necessary skills to perform these functions.

PROJECT MANAGEMENT 

There are many ways and means to build project management structures. We have project managers who are credentialed in this task; however, you can create basic elements that interface with the Change Management framework. 

You don't need to be overwhelmed by this undertaking. Everything can be accomplished gradually so long as you have a logistical approach. A generic outline of project management should contain at least the following components: 

·       A project management manual or tool to track and manage projects.

·       Referenced policies, procedures, and systems affected by a project.

·       Project management tracking reports.

·       Centralization of project activities in an oversight group.

·       Training of relevant staff for project participation and management.

·       Periodic project tracking reports are communicated to stakeholders.

·       Updates to the inventory of projects subject to tracking. 

I also recommend that your project management methodology include: 

·       Communication of project goals and status.

·       Milestone reviews and approvals.

·       Identification and mitigation of project risk.

·       Identifying stakeholders, including their operational relevance.

·       Documenting procedures for change control documentation.

·       An escalation process for projects where there are tracking errors.

·       Log of activities with a column for remediation information and implementation. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group