LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label FFIEC. Show all posts
Showing posts with label FFIEC. Show all posts

Thursday, May 23, 2024

CFPB Examination: Failure to Conduct Self-Assessments

QUESTION 

We just received an MRA from the CFPB. We are a mid-size mortgage lender licensed in 30 states. This MRA hit us like a huge shock. Yesterday, we contacted your firm and spoke to a representative. I want to set up a conference call for my management and you to discuss how to proceed. Our counsel recommended that we bring you on board to assist them in handling the MRA demands. 

Here's the situation. The CFPB found that we failed their exam in various areas, one of which was that we did not do any self-assessments, which they call "self-identifications." 

First of all, I didn't even know that we were supposed to do these self-assessments. Secondly, we have a small compliance department, and we do not know how to do self-assessments. Third, our attorneys say they can only do a few of the self-assessments, but not all of them, and their fees are ridiculous. The bottom line is that we need an outside, independent firm to do self-assessments at an affordable cost. 

There are other areas of the MRA that we need to talk to you about, especially in the areas that our counsel wants to team up with you on. However, we need to take care of the CFPB's list of self-assessments, and we want to retain your firm to do them. 

Please get in touch with me as soon as possible to set up a call. In the meantime, please give us a clue about what goes into these self-identifications or self-assessments. 

What is self-identification? 

Why does the CFPB expect self-identification? 

COMPLIANCE SOLUTION 

Compliance Tune-up® 

ANSWER 

Our firm is the first and only firm in the country to provide self-assessment audits, a series denoted by the overall term Compliance Tune-up®. We deconstructed a mortgage company from the point of sale to secondary and beyond to derive audit criteria for each element and regulation. The Compliance Tune-up® is one of our Compliance Solutions and is often in considerable demand. 

I will discuss the Compliance Tune-up® at the conclusion of this article, as it is a means to be responsive to the expectations of the Consumer Financial Protection Bureau (CFPB or Bureau). I'll drop a contact link on the way if you want more information about the Compliance Tune-up®. 

First, I want to outline how self-identifications – or self-assessments – function in the context of the CFPB examination and the evaluation of the Compliance Management System (CMS). 

The CFPB's exam focuses on risks of harm to consumers, including the risk that a supervised entity will not comply with Federal consumer financial law. To get ready for the examination, you should do pre-review planning to collect the information necessary to determine the scope, resource needs, and work plan. The information and documentation should be assembled, given that an Examiner in Charge (EIC) will notify you that the examination team plans to conduct its work offsite and onsite during the review. Timing is critical, and you must be responsive. 

The fact that you received an MRA (Matters Requiring Attention) tells me that you are quite far along in a risk rating evaluation. The CFPB's risk evaluation procedures are extensive. The Bureau uses an MRA to communicate to an institution's Board of Directors, senior management, or both, specific goals to be accomplished in order to correct violations of Federal consumer financial law, remediate harmed consumers, and address related weaknesses in the CMS that the examiners found are directly related to violations of Federal consumer financial law. MRAs include timeframes for periodic reporting of efforts taken to address these matters, as well as expected timeframes for implementation.

___________________________________________________________

 Compliance Tune-up®

 Visit Us to Request Information

 ___________________________________________________________

Let's consider some features of the CPPB examination with an emphasis on self-identification. 

Prior to the examination, you will receive an Information Request. The Information Request is a list of specific information and documents that the supervised entity is asked to provide to the Bureau for offsite review or make available when the examiners arrive onsite. It may include a request for an electronic data upload. Our experience is that the pre-review planning process varies depending on the size, complexity, business model, products, systems, and risk profile of a particular supervised entity. 

Don't assume that the Bureau is only dealing with getting information from you; in fact, it gets quite a lot of information from both internal and external sources to aid in constructing the risk focus and scope of a review. The examiners gather as much information as possible from within the Bureau, other regulatory agencies, and third-party, public sources because the Bureau is required by statute to use, to the fullest extent possible, information available from other agencies or reported publicly.[i] 

The following key documents and information are relevant to understanding a supervised entity and its ability to manage its compliance responsibilities and risks to consumers. Not all documents will necessarily be available for a particular entity; however, you should anticipate that the Bureau's team will consider them. There are two categories: the Bureau's internal sources and regulatory agencies, as well as public information and third parties. 

BUREAU INTERNAL SOURCES AND OTHER REGULATORY AGENCIES 

·       Monitoring information 

·       Any recent risk assessments, self-identifications, and self-assessments 

·       Prior Scope Summary, Supervision Plan, or similar document produced by state or prudential regulators 

·       Prior Examination Reports and Supervisory Letters, and supporting workpapers (internal and from the prudential regulator(s), state regulator(s), or other agencies) 

·       Information about prior supervisory actions, consumer remediation, and responses to Examination Reports and Supervisory Letters 

·       Information on enforcement or other public actions (if applicable) 

·       Correspondence from prudential or state regulator(s) and Bureau correspondence files 

·       State licensing information for the entity 

·       The CFPB Consumer Complaint database 

·       FTC Consumer Sentinel database 

·       Uniform Bank Performance Report (UBPR) and Call Reports, if applicable

·       Previous years' FFIEC Home Mortgage Disclosure Act Loan Application Registers (HMDA LARs) 

·       Home Affordable Modification Program data 

·       Fair lending analyses and supporting documentation 

·       Office of the Comptroller of the Currency (OCC) Federal Housing Home Loan Data System (FHHLDS) report, if applicable 

·       Mortgage Call Report (MCR) from the Nationwide Mortgage Licensing System (NMLS) 

·       Registration or licensing information for mortgage originators (Secure and Fair Enforcement for Mortgage Licensing Act (SAFE Act) 

PUBLIC SOURCES OF INFORMATION 

·       Institution securities filings, its offered securitizations, and similar public records 

·       Industry publications showing credit ratings, product performance, and areas of profitability 

·       Newspaper articles, web postings, or blogs that raise examination-related issues

·       Neighborhood Watch

·       Service providers and other third-party arrangements 

·       Content of the supervised entity's website

RATING SYSTEM CATEGORIES AND ASSESSMENT FACTORS 

The Bureau's rating system is organized under three broad categories: 

1.     Board and Management Oversight, 

2.     Compliance Program, and 

3.     Violations of Law and Consumer Harm. 

I will not outline the rating system here. Suffice it to say that it is complex and is used to reflect the implementation of assessment factors considered within each category, with some cross-referencing, along with narrative descriptions of performance. The first two categories, Board and Management Oversight and Compliance Program, are used to assess the strength of an institution's CMS. Examiners evaluate the assessment factors within these two categories commensurate with the institution's size, complexity, and risk profile. 

All institutions, regardless of size, should maintain an effective CMS. The sophistication and formality of the CMS typically will increase commensurate with the size, complexity, and risk profile of the entity. 

The Bureau's compliance expectations contained within the narrative descriptions of the foregoing two categories extend to third-party relationships[ii] utilized by the financial institution. There can be certain benefits to financial institutions engaging in relationships with third parties, including gaining operational efficiencies or an ability to deliver additional products and services. Still, such arrangements may expose financial institutions to risks if they are not managed effectively.

Thursday, February 8, 2024

HMDA: Procedures & Internal Controls

QUESTION 

I am a compliance analyst in our compliance department. We are getting ready to file our HMDA-LAR. Yesterday, our internal auditor requested an outline of the steps we take to evaluate our HMDA policies and procedures. 

Our compliance manager has put together a few bullet points. However, we need some procedures and internal controls that tell the internal auditors adequate measures are in place to ensure compliance. 

Mostly, our procedures are informal. We follow the HMDA guide and use HMDA reporting software. 

I am reaching out to you for guidance in putting together a list of HMDA procedures. 

What are some procedures and internal controls needed to comply with filing HMDA data? 

ANSWER 

Compliance Solution: HMDA, CRA, Fair Lending

The Home Mortgage Disclosure Act (HMDA) requires certain financial institutions to collect, report, and disclose information about their mortgage lending activity. HMDA was enacted by Congress in 1975 and implemented by Regulation C.[i] Over the years, there have been numerous amendments, updates, and linkages to other Acts. HMDA is a disclosure law that relies upon public scrutiny for its effectiveness. 

Contrary to what some people think, HMDA does not prohibit any specific activity of lenders, nor does it establish a quota system for mortgage loans to be made in any geographic area. The federal supervisory agencies use HMDA data to support a variety of activities.[ii] For instance, some federal supervisory agencies use HMDA data as part of their fair lending examination process,[iii] and other agencies use HMDA data in conducting Community Reinvestment Act (CRA) performance evaluations.[iv] 

HMDA disclosures provide the public with information on the home mortgage lending activities of particular reporting entities and activity in their communities. These disclosures are used by local, state, and federal officials to evaluate housing trends and issues and by community organizations to monitor financial institutions' lending patterns. Because HMDA data serve numerous important purposes, validating the accuracy of HMDA data is a key element of the federal supervisory agencies' examination activities. 

For the purpose of this article, I will use the term "institution" to refer to an institution that is either a depository financial institution or a non-depository financial institution that is subject to Regulation C. An institution is required to comply with Regulation C only if it is a financial institution as that term is defined in Regulation C. The definition of financial institution includes depository and non-depository financial institutions, as those terms are separately defined in Regulation C.[v] It is beyond the scope of this response to delve into the method to identify whether an institution meets the definition. An institution utilizes certain coverage tests and thresholds to determine whether a financial institution is required to comply with Regulation C.[vi] 

If your internal auditor plans to review your procedures and internal controls, I suggest you let them know that Regulation C requires an institution to record the data about a covered loan or application on a Loan Application Register (LAR), hereinafter "HMDA-LAR," within 30 calendar days after the end of the calendar quarter in which the financial institution takes final action on the covered loan or application.[vii] An institution is not required to record all its HMDA data for a quarter on a single HMDA-LAR. Rather, it may record data on a single HMDA-LAR or may record data on one or more HMDA-LARs for different branches or different loan types (such as home purchase loans, home improvement loans, or loans on multifamily dwellings). State or federal regulations may require an institution to record its data on a HMDA-LAR more frequently. 

Depending on various criteria, under Regulation C, an institution must submit its annual HMDA-LAR in electronic format to its appropriate federal supervisory agency by March 1 of the year following the calendar year for which the data are collected.[viii] Certain institutions must file their HMDA-LAR quarterly and annually,[ix] where the institution reported at least 60,000 originated covered loans and applications (combined) for the preceding calendar year. 

Guidelines for Procedures and Internal Controls 

for HMDA Recording and Reporting 

I will provide a list of some procedures and internal controls to ensure compliance with HMDA and Regulation C. The list is not meant to be comprehensive. 

·       Whether the individual assigned responsibility for the institution's compliance with HMDA and Regulation C possesses an adequate level of knowledge and has established a method for staying abreast of changes to laws and regulations. 

·       If the institution ensures that individuals assigned compliance responsibilities receive adequate training to ensure compliance with the requirements of the regulation. 

·       Whether the individuals assigned responsibility for the institution's compliance with HMDA and Regulation C know whom to contact, at the financial institution or their supervisory agency, if they have questions not answered by the written materials. 

·       If the institution has established and implemented adequate controls to ensure separation of duties exists (i.e., data entry, review, oversight, and approval). 

·       Any internal reports or records documenting policy and procedure revisions and any informal self-assessment of the institution's compliance with the regulation. 

·       If the institution offers preapprovals, whether the institution's preapproval program meets the specifications detailed in the HMDA regulation. If so, whether the institution's policies and procedures provide adequate guidance for reporting preapproval requests that are approved or denied in accordance with the regulation. 

·       Whether the institution's policies and procedures address the reporting of (1) non-dwelling secured loans that are originated in whole or in part for home improvement and classified as such by the institution, and (2) dwelling-secured loans that are originated in whole or in part for home improvement, whether or not classified as such. 

·       Whether the institution established a method for determining and reporting the lien status for all originated loans and applications. 

·       Whether the institution's policies and procedures contain guidance for collecting ethnicity, race, and sex for all loan applications, including applications made by telephone, mail, and Internet. 

·       Whether the institution's policies and procedures address the collection of the rate spread (the difference between the APR and the average prime offer rate for a comparable transaction as of the date the interest rate is set) and whether the institution has established a system for tracking rate lock dates and calculating the rate spread. 

·       Whether the institution's policies and procedures address determining if a loan is subject to the Home Ownership and Equity Protection Act and the reporting of applications involving manufactured home loans. 

·       Whether the HMDA-LAR is updated within 30 days after the end of each calendar quarter. 

·       Whether data are collected at all branches, and if so, whether the appropriate personnel are sufficiently trained to ensure that all branches are reporting data under the same guidelines. 

·       Whether the institution's loan officers, including loan officers in the commercial loan department who may handle loan applications reportable under HMDA (including loans and applications for multifamily or mixed-use properties and small business refinances secured by residential real estate), are informed of the reporting requirements necessary to assemble the information. 

·       Whether the Board of Directors has established an independent review of the policies, procedures, and HMDA data to ensure compliance and accuracy and is advised each year of the accuracy and timeliness of the financial institution's data submissions. 

·       What procedures the institution has put in place to comply with the requirement to submit data in machine-readable form, and whether the institution has some mechanism in place to ensure the accuracy of the data that are submitted in machine-readable form. 

·       Whether the institution's loan officers are familiar with the disclosure, reporting, and retention requirements associated with the loan application registers and the FFIEC public disclosure statements. 

·       Whether the institution's loan officers are familiar with the disclosure statements that will be produced from the data. 

·       Whether the institution's loan officers and affected staff know that civil money penalties may be imposed when an institution has submitted erroneous data and has not established adequate procedures to ensure the accuracy of the data. 

·       Whether the institution's loan officers and affected staff know that correction and resubmission of erroneous data may be required when data are incorrectly reported for at least 5 percent of the loan application records. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

[i] 12 CFR Part 1003

[ii] Home Mortgage Disclosure Act (HMDA), Consumer Financial Protection Bureau, September 2021. Also see 12 USC 2801–2810.

[iii] 15 USC 1691–1691f, 42 USC 3605, a nd 12 CFR 1002

[iv] 12 USC 2901–2908, and 12 CFR 25, 195, 228, and 345

[v] 12 CFR 1003.2(g)

[vi] HMDA Data Collection and Reporting: Keys to an Effective Program, Consumer Compliance Outlook, Fourth Issue 2020, published by the Philadelphia FRB, provides a good overview of coverage tests and thresholds, among other things.

[vii] 12 CFR 1003.4(f)

[viii] 12 CFR 1003.5(a)(1)(i)

[ix] Effective January 1, 2020.

Friday, November 24, 2023

Posting the HMDA Notice on a Website

QUESTION 

Our banking department has sent us a letter directing us to post our HMDA availability notice on our website. I do not believe we are required to do so. 

As the General Counsel, I am responsible for ensuring that our website has all appropriate consumer notices for our online business channel. I cannot find any regulation or statute requiring us to post the HMDA notice on our website. I want a second opinion. 

Are we required to post the HMDA notice on our website? 

ANSWER 

Financial institutions are required to post several different kinds of public notices on their premises. One type of required notice announces compliance with certain regulations. For example, the rules requiring highly visible Equal Housing Lender posters are well known. 

__________________________

For information about our 

HMDA Compliance Services,

please contact us here.

__________________________

To re-state your question, in part, if an institution conducts transactions online, where should such notices be posted? 

On a website, the absence of a physical location in which to post regulatory notices raises two questions: 

1) Which, if any, of the posting requirements apply to a website? 

2) If a posting is required on a website, where should it appear? 

We may gain some insight into these questions by examining the specific regulations. For example, HMDA (for institutions with an office located in a metropolitan area) requires a notice of availability of HMDA data. 

However, the applicable regulation does not specifically address whether the required notices must be posted on a website. Therefore, the language of the regulation must be consulted to determine if a particular notice should be posted on the website. 

With respect to the HMDA Notice,[i] the general requirements for posting are as follows: 

“A financial institution shall post a general notice about the availability of its HMDA data in the lobby of its home office and of each branch office physically located in each MSA and each MD.”   

An MSA is a metropolitan statistical area. An MD is a metropolitan division.[ii] 

According to these requirements, the HMDA notice must be posted in an institution’s main office and each branch office. Because a website is neither a main office nor a branch, it would seem that these notices would not be required on a website. 

This interpretation of the rules also seems to be the view of the regulatory agencies. In the publication entitled Federal Financial Institutions Examination Council Guidance on Electronic Financial Services and Consumer Compliance, the agencies discuss the various compliance regulations and their applicability to Internet banking. The publication does not mention HMDA notices at all. 

Although the HMDA Notice may not be required, financial institution management may consider including it as a precaution or provide internet consumers with the same information available to customers in the institution’s lobby. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

___________________________

[i] 12 CFR 1003.5(e)

[ii] “For purposes of HMDA, the term is interchangeable with "metropolitan area." The underlying concept of an MSA is that of a core area containing a large population nucleus, together with adjacent communities having a high degree of economic and social integration with that core. MSAs are composed of entire counties or county equivalents. Every MSA has at least one urbanized area with a population of 50,000 or more. A metropolitan division is a subset of an MSA having a single core with a population of 2.5 million or more. For reporting and disclosure purposes of HMDA, an MD is the relevant geography, not the MSA of which it is a division.” See HMDA Glossary provided by FFIEC.