LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label FRB. Show all posts
Showing posts with label FRB. Show all posts

Thursday, February 8, 2024

HMDA: Procedures & Internal Controls

QUESTION 

I am a compliance analyst in our compliance department. We are getting ready to file our HMDA-LAR. Yesterday, our internal auditor requested an outline of the steps we take to evaluate our HMDA policies and procedures. 

Our compliance manager has put together a few bullet points. However, we need some procedures and internal controls that tell the internal auditors adequate measures are in place to ensure compliance. 

Mostly, our procedures are informal. We follow the HMDA guide and use HMDA reporting software. 

I am reaching out to you for guidance in putting together a list of HMDA procedures. 

What are some procedures and internal controls needed to comply with filing HMDA data? 

ANSWER 

Compliance Solution: HMDA, CRA, Fair Lending

The Home Mortgage Disclosure Act (HMDA) requires certain financial institutions to collect, report, and disclose information about their mortgage lending activity. HMDA was enacted by Congress in 1975 and implemented by Regulation C.[i] Over the years, there have been numerous amendments, updates, and linkages to other Acts. HMDA is a disclosure law that relies upon public scrutiny for its effectiveness. 

Contrary to what some people think, HMDA does not prohibit any specific activity of lenders, nor does it establish a quota system for mortgage loans to be made in any geographic area. The federal supervisory agencies use HMDA data to support a variety of activities.[ii] For instance, some federal supervisory agencies use HMDA data as part of their fair lending examination process,[iii] and other agencies use HMDA data in conducting Community Reinvestment Act (CRA) performance evaluations.[iv] 

HMDA disclosures provide the public with information on the home mortgage lending activities of particular reporting entities and activity in their communities. These disclosures are used by local, state, and federal officials to evaluate housing trends and issues and by community organizations to monitor financial institutions' lending patterns. Because HMDA data serve numerous important purposes, validating the accuracy of HMDA data is a key element of the federal supervisory agencies' examination activities. 

For the purpose of this article, I will use the term "institution" to refer to an institution that is either a depository financial institution or a non-depository financial institution that is subject to Regulation C. An institution is required to comply with Regulation C only if it is a financial institution as that term is defined in Regulation C. The definition of financial institution includes depository and non-depository financial institutions, as those terms are separately defined in Regulation C.[v] It is beyond the scope of this response to delve into the method to identify whether an institution meets the definition. An institution utilizes certain coverage tests and thresholds to determine whether a financial institution is required to comply with Regulation C.[vi] 

If your internal auditor plans to review your procedures and internal controls, I suggest you let them know that Regulation C requires an institution to record the data about a covered loan or application on a Loan Application Register (LAR), hereinafter "HMDA-LAR," within 30 calendar days after the end of the calendar quarter in which the financial institution takes final action on the covered loan or application.[vii] An institution is not required to record all its HMDA data for a quarter on a single HMDA-LAR. Rather, it may record data on a single HMDA-LAR or may record data on one or more HMDA-LARs for different branches or different loan types (such as home purchase loans, home improvement loans, or loans on multifamily dwellings). State or federal regulations may require an institution to record its data on a HMDA-LAR more frequently. 

Depending on various criteria, under Regulation C, an institution must submit its annual HMDA-LAR in electronic format to its appropriate federal supervisory agency by March 1 of the year following the calendar year for which the data are collected.[viii] Certain institutions must file their HMDA-LAR quarterly and annually,[ix] where the institution reported at least 60,000 originated covered loans and applications (combined) for the preceding calendar year. 

Guidelines for Procedures and Internal Controls 

for HMDA Recording and Reporting 

I will provide a list of some procedures and internal controls to ensure compliance with HMDA and Regulation C. The list is not meant to be comprehensive. 

·       Whether the individual assigned responsibility for the institution's compliance with HMDA and Regulation C possesses an adequate level of knowledge and has established a method for staying abreast of changes to laws and regulations. 

·       If the institution ensures that individuals assigned compliance responsibilities receive adequate training to ensure compliance with the requirements of the regulation. 

·       Whether the individuals assigned responsibility for the institution's compliance with HMDA and Regulation C know whom to contact, at the financial institution or their supervisory agency, if they have questions not answered by the written materials. 

·       If the institution has established and implemented adequate controls to ensure separation of duties exists (i.e., data entry, review, oversight, and approval). 

·       Any internal reports or records documenting policy and procedure revisions and any informal self-assessment of the institution's compliance with the regulation. 

·       If the institution offers preapprovals, whether the institution's preapproval program meets the specifications detailed in the HMDA regulation. If so, whether the institution's policies and procedures provide adequate guidance for reporting preapproval requests that are approved or denied in accordance with the regulation. 

·       Whether the institution's policies and procedures address the reporting of (1) non-dwelling secured loans that are originated in whole or in part for home improvement and classified as such by the institution, and (2) dwelling-secured loans that are originated in whole or in part for home improvement, whether or not classified as such. 

·       Whether the institution established a method for determining and reporting the lien status for all originated loans and applications. 

·       Whether the institution's policies and procedures contain guidance for collecting ethnicity, race, and sex for all loan applications, including applications made by telephone, mail, and Internet. 

·       Whether the institution's policies and procedures address the collection of the rate spread (the difference between the APR and the average prime offer rate for a comparable transaction as of the date the interest rate is set) and whether the institution has established a system for tracking rate lock dates and calculating the rate spread. 

·       Whether the institution's policies and procedures address determining if a loan is subject to the Home Ownership and Equity Protection Act and the reporting of applications involving manufactured home loans. 

·       Whether the HMDA-LAR is updated within 30 days after the end of each calendar quarter. 

·       Whether data are collected at all branches, and if so, whether the appropriate personnel are sufficiently trained to ensure that all branches are reporting data under the same guidelines. 

·       Whether the institution's loan officers, including loan officers in the commercial loan department who may handle loan applications reportable under HMDA (including loans and applications for multifamily or mixed-use properties and small business refinances secured by residential real estate), are informed of the reporting requirements necessary to assemble the information. 

·       Whether the Board of Directors has established an independent review of the policies, procedures, and HMDA data to ensure compliance and accuracy and is advised each year of the accuracy and timeliness of the financial institution's data submissions. 

·       What procedures the institution has put in place to comply with the requirement to submit data in machine-readable form, and whether the institution has some mechanism in place to ensure the accuracy of the data that are submitted in machine-readable form. 

·       Whether the institution's loan officers are familiar with the disclosure, reporting, and retention requirements associated with the loan application registers and the FFIEC public disclosure statements. 

·       Whether the institution's loan officers are familiar with the disclosure statements that will be produced from the data. 

·       Whether the institution's loan officers and affected staff know that civil money penalties may be imposed when an institution has submitted erroneous data and has not established adequate procedures to ensure the accuracy of the data. 

·       Whether the institution's loan officers and affected staff know that correction and resubmission of erroneous data may be required when data are incorrectly reported for at least 5 percent of the loan application records. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

[i] 12 CFR Part 1003

[ii] Home Mortgage Disclosure Act (HMDA), Consumer Financial Protection Bureau, September 2021. Also see 12 USC 2801–2810.

[iii] 15 USC 1691–1691f, 42 USC 3605, a nd 12 CFR 1002

[iv] 12 USC 2901–2908, and 12 CFR 25, 195, 228, and 345

[v] 12 CFR 1003.2(g)

[vi] HMDA Data Collection and Reporting: Keys to an Effective Program, Consumer Compliance Outlook, Fourth Issue 2020, published by the Philadelphia FRB, provides a good overview of coverage tests and thresholds, among other things.

[vii] 12 CFR 1003.4(f)

[viii] 12 CFR 1003.5(a)(1)(i)

[ix] Effective January 1, 2020.

Thursday, September 28, 2023

Artificial Intelligence: Benefits and Risks

QUESTION 

There has been a lot of news about artificial intelligence. I have to admit, I do not know anything about it. Yet my company has just announced that it is linking up with an artificial intelligence provider. 

Now, we are scrambling to understand how artificial intelligence will impact our jobs, loan process, and compliance requirements. Last year, nobody cared about AI. This year, it’s all they can talk about! 

I would like you to tell us some ways that AI is used by banks and nonbanks, since providing compliance to us is your specialty. We need some basic understanding of how AI will be a part of originating and servicing loans. 

What are some ways that financial institutions are using AI? 

ANSWER 

I sense your frustration, and you are not alone. Whenever a new technology or innovation enters the marketplace, there is a perfectly normal tendency to be a bit suspicious and even worried about its implications. In time, these concerns often become resolved, sometimes with less than optimum impact on society, sometimes with far-reaching positive impact. The challenge is anticipating change and preparing proactively to mitigate unwanted outcomes. 

I don’t think financial institutions should rush into Artificial Intelligence (“AI”) without first considering compliance. But, there are good reasons to implement AI as a tool in the quest for a strong compliance program. When planning to partner with an AI vendor, it is important to bring in a firm such as ours to provide reliable due diligence to ensure the compliance component is integral to the plan. This creates a “baseline” that serves to enhance policies and procedures, training, and ongoing improvements in the technological application. 

Many banking agencies have been vetting AI for a few years. They're still in the early stages of drafting the rulemaking, but there has been an increase in regulatory guidance issuances. As a provider of customized compliance libraries, we are updating our clients’ policies for such guidance. And when rulemaking is determined, we will provide an AI policy, specific to a client's needs, and prior to a promulgated effective compliance date. 

Five banking agencies (OCC, FRB, FDIC, CFPB, and NCUA) have sought information and comments on the use of AI, including machine learning, by financial institutions. The caveat thus far is that they support responsible innovation as long as it includes identifying and managing associated risks. 

We can glean the areas of scrutiny being reviewed for supervision, examination, and enforcement by taking note of the following ways financial institutions use or may use AI. Though not meant to be a comprehensive outline, based on our interactions with regulators and published issuances, I’m sure these areas are under review for AI compliance. 

ARTIFICAL INTELLIGENCE: BENEFITS

Flagging Unusual Transactions 

Many institutions use AI to identify potentially suspicious, anomalous, or outlier transactions (for instance, fraud detection and financial crime monitoring). This involves using different forms of data (i.e., email, texts, audio data – both structured and unstructured)[i] to identify fraud or anomalous transactions with greater accuracy and timeliness. It also includes identifying transactions for Bank Secrecy Act/Anti-Money Laundering activities, monitoring employees for improper practices, and detecting data anomalies. 

Personalization of Customer Services 

Institutions use AI technologies, such as voice recognition and Natural Language Processing (NLP),[ii] to improve the customer experience and increase efficiency in allocating financial institution resources. 

One example is using chatbots[iii] to automate routine customer interactions, including account opening activities and general customer inquiries. AI is leveraged at call centers to process and triage customer calls to provide customized service. Institutions also use these technologies to target marketing better and customize trade recommendations. 

Credit Decisions 

Some institutions use AI to inform credit decisions to enhance or supplement existing techniques. This application of AI may use traditional data or employ “alternative data”[iv] (such as cash flow transactional information from a bank account). 

Risk Management 

Institutions may use AI to augment risk management and control practices. For example, an AI approach might be used to complement and provide a check on another, more traditional credit model. Financial institutions may also use AI to enhance credit monitoring (including through early warning alerts), payment collections, loan restructuring and recovery, and loss forecasting. 

AI can assist internal audit and independent risk management to increase sample size (such as for testing), evaluate risk, and refer higher-risk issues to human analysts. Indeed, AI may also be used in liquidity risk management, for example, to enhance monitoring of market conditions or collateral management. 

Textual Analysis 

Textual analysis refers to using NLP for handling unstructured data (generally text) and obtaining insights from that data or improving the efficiency of existing processes. Applications include analysis of regulations, news flow, earnings reports, consumer complaints, analyst ratings changes, and legal documents. 

Cybersecurity 

Institutions may use AI to detect threats and malicious activity, reveal attackers, identify compromised systems, and support threat mitigation. Examples abound, including real-time investigation of potential attacks, the use of behavior-based detection to collect network metadata, flagging and blocking of new ransomware and other malicious attacks, identifying compromised accounts and files involved in exfiltration, and deep forensic analysis of malicious files. 

There are risks, too, which I’ll explain shortly. But, it should be obvious that the agencies recognize that AI has the potential to offer improved efficiency, enhanced performance, and cost reduction for financial institutions, as well as benefits to consumers and businesses. AI can identify relationships among variables that are not intuitive or not revealed by more traditional techniques. And it can better process certain forms of information, such as text, that may be impractical or difficult to process using traditional methods. 

AI also facilitates processing significantly large and detailed datasets, both structured and unstructured, by identifying patterns or correlations that would be impracticable to ascertain otherwise.

In general, other potential AI benefits include more accurate, lower-cost, and faster underwriting and expanded credit access for consumers and small businesses that may not have obtained credit under traditional credit underwriting approaches. AI applications may also enhance an institution’s ability to provide products and services with greater customization. 

ARTIFICAL INTELLIGENCE: RISKS

But there are risks. The agencies have emphasized that financial institutions should have processes to identify and manage the potential risks associated with AI. Many of the risks associated with using AI are not unique to AI. For example, using AI could result in operational vulnerabilities, such as internal process or control breakdowns, cyber threats, information technology lapses, risk associated with using third parties, and model risks, all of which could affect an institution’s safety and soundness. 

Furthermore, the use of AI could also create or increase consumer protection risks, such as risks of unlawful discrimination, unfair, deceptive, or abusive acts or practices (UDAAP) under the Dodd-Frank Act, unfair or deceptive acts or practices regulation (UDAP) under the FTC Act, or privacy concerns.

The agencies have identified three risks particular to AI: 

  • Explainability, 
  • Data Usage, and 
  • Dynamic Updating. 

Here’s a brief explanation of each risk. 

Explainability 

“Explainability” refers to how an AI approach uses inputs to produce outputs. In other words, some AI approaches can exhibit a “lack of explainability” for their overall functioning (sometimes known as global explainability) or how they arrive at an individual outcome in a given situation (sometimes referred to as local explainability). 

Lack of explainability can pose different challenges in different contexts. Lack of explainability can also inhibit a management’s understanding of the conceptual soundness of an AI approach (that is, the quality of the theory, design, methodology, data, developmental testing, and confirmation that an approach is appropriate for the intended use) which, then, can increase uncertainty around the AI approach’s reliability, and increase risk when used in new contexts. 

Lack of explainability can also inhibit independent review and audit and make compliance with laws and regulations, including consumer protection requirements, more challenging. 

Data Usage 

Broader or more intensive data usage plays a particularly important role in AI. In many cases, AI algorithms identify patterns and correlations in training data without human context or intervention and then use that information to generate predictions or categorizations. 

Because the AI algorithm depends on the training data, an AI system generally reflects any dataset limitations. As a result, as with other systems, AI may perpetuate or even amplify bias or inaccuracies inherent in the training data or make incorrect predictions if that data set is incomplete or non-representative. 

Dynamic Updating 

Some AI approaches have the capacity to update on their own, sometimes without human interaction, often known as dynamic updating. Monitoring and tracking an AI approach that evolves on its own can present challenges in review and validation, particularly when a change in external circumstances (i.e., economic downturns and financial crises) may cause inputs to vary materially from the original training data. 

Dynamic updating techniques can produce changes that range from minor adjustments to existing elements of a model to the introduction of entirely new elements. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] The term “structured data” generally refers to a set of data that has been systematically organized or arranged.

[ii] “Natural Language Processing” or “NLP” generally refers to the use of computers to understand or analyze natural language text or speech.

[iii] The term “chatbot” generally refers to a software application used to conduct an on-line chat conversation via text or text-to-speech, in lieu of providing direct contact with a live human agent.

[iv] “Alternative data” means information not typically found in the consumer’s credit files of the nationwide consumer reporting agencies or customarily provided by consumers as part of applications for credit.

Thursday, November 10, 2022

Prohibited Acts or Practices Violations in Advertisements

QUESTION 

Yesterday, we received the results of an examination. The part dealing with advertisement violations has our Chairman on a major warpath. The examiners found violations of prohibited acts or practices under Regulation Z. He’s already kicked out somebody in the marketing department. But the marketing people always submit their plans and disclosures to the Compliance Department for approval. I think letting go of her was unfair. 

I want to understand how prohibited acts and practices are involved in Regulation Z. I had always thought of it as a straight-out UDAAP issue. Apparently, there are also violations of Regulation Z based on prohibited acts and practices. I hope you can enlighten me since I am confused. 

What are prohibited acts or practices in advertisements under Regulation Z? 

ANSWER 

Getting an adverse report from a banking department can often feel disruptive. Once the corrective measures are put in place to the satisfaction of the regulator, you should be able to feel more sure about implementing protective policies and procedures. Sometimes, practices change over time without updating the process document, or procedures are not properly followed. 

Regulation Z, the implementing regulation of the Truth-in-Lending Act[i] (TILA), imposes restrictions on the advertising of closed-end consumer credit plans.[ii] I can’t tell from your question what aspect of Regulation Z caused your regulator to issue particular adverse findings relating to prohibited acts or practices. However, I think it is valuable to ensure we’re clear about certain aspects that could factor into the analysis. 

As provided in Regulation Z,[iii] all advertisements are subject to the same “clear and conspicuous” standard Regulation Z applies to all disclosures. In July 2008, the Federal Reserve Board amended Regulation Z to expand its standards for this clear and conspicuous standard. Still, TILA and Regulation Z do not prescribe specific rules for the format, such as type size or placement, of the necessary closed-end disclosures,[iv] other than the format requirements that apply to the disclosure of rates and payments.[v] 

Regulation Z addresses electronic advertisements[vi] Internet advertisements[vii] satisfy the clear and conspicuous disclosure standard if the required disclosures are not obscured by techniques such as graphical displays, shading, coloration, or other devices and comply with all the other requirements for clear and conspicuous disclosures applicable to closed-end advertisements generally. 

Television advertisements[viii] comply with the clear and conspicuous disclosure requirement if they are not obscured by techniques such as graphical displays, shading, coloration, or other devices, are displayed in a manner that allows a consumer to read the information required to be disclosed, and comply with all the other requirements for clear and conspicuous disclosures applicable to closed-end advertisements generally, as described in the materials that follow. For example, very fine print in a television advertisement would not meet the clear and conspicuous requirement if consumers cannot “see and read” the information required to be disclosed. 

This brings up the subject of oral advertisements. How the oral advertisement is delivered is critical: clear and conspicuous disclosure in the context of an oral advertisement, whether by radio, television, or other medium, means the required disclosures are given at a speed and volume sufficient for a consumer to hear and comprehend them.[ix] For instance, disclosure of information stated very rapidly at a low volume in a radio or television advertisement would not meet the clear and conspicuous standard if consumers cannot hear and comprehend the information required to be disclosed. 

A little more history is in order. In July 2008, the Federal Reserve Board turned to TILA[x] as the basis for additional authority (sometimes referred to as the Board’s – now the CFPB’s – “unfair trade practice” authority) to impose restrictions on the misleading and deceptive advertising of mortgage loans, including closed-end credit.[xi] The authority is broad,[xii] allowing the CFPB to prohibit acts or practices in connection with mortgage loans it finds unfair, deceptive, or designed to evade the provisions of TILA, and refinancing of mortgage loans it finds to be associated with abusive lending practices or otherwise not in the interest of the borrower. 

Indeed, Regulation Z[xiii] asserts both the CFPB’s authority under the specific advertising provisions of TILA and its unfair trade practice authority regarding mortgage loans under TILA.[xiv] 

The goals of the July 2008 amendments to the advertising requirements, as well as to the other requirements affected by the amendments, were to protect consumers in the mortgage market from unfair, abusive, or deceptive lending and servicing practices while preserving responsible lending and sustainable homeownership, ensure that advertisements for mortgage loans provide accurate and balanced information and do not contain misleading or deceptive representations, and provide consumers transaction-specific disclosures early enough to use while shopping. 

I have been asked about the fact that compliance with the July 2008 Regulation Z revisions was not required before specified effective dates raises an interesting question: If the Federal Reserve Board was saying certain practices are unfair or deceptive, presumably they were unfair from the start, were they not? Therefore, can an advertiser afford not to implement them as soon as possible? 

The Board said, in its preamble to the regulations: 

Accordingly, nothing in this rule should be construed or interpreted to be a determination that acts or practices restricted or prohibited under this rule are, or are not, unfair or deceptive before the effective date of this rule.[xv] 

Notice that the Board stated, “are, or are not, unfair or deceptive.” It was conceivable that, prior to the effective date, a court might be asked to consider whether any of the acts or practices were unfair or deceptive. In fact, it was conceivable that a regulatory agency might bring an enforcement action against a specific institution, alleging that the institution had acted unfairly or deceptively based on all the facts and circumstances surrounding that conduct. 

Presumably, in these situations, the Board (now, the CFPB) would be taken at its word, with its statement treated with deference, that is, its adoption of the Regulation Z amendments did not judge the acts or practices as unfair or deceptive prior to their implementation dates. Accordingly, acts or practices occurring before the effective dates of revised rules should be judged on the totality of the circumstances under other applicable laws or regulations, not under the Truth-in-Lending Act. 

Let’s turn to the prohibited acts or practices in advertisements. Seven prohibitions are foundational. 

Specifically, Regulation Z prohibits[xvi] the following seven acts or practices in advertisements for credit secured by a dwelling: 

1. Misleading advertising of “fixed” rates and payments. 

An advertisement for a variable-rate transaction or other transaction in which the payment will increase must not use the word “fixed” to refer to rates, payments, or the credit transaction, unless:

Friday, June 17, 2022

Adverse Action Conundrum

QUESTION 

I have been told conflicting advice about the adverse action notice. Supposedly, these are people who are in the know. However, I am a compliance manager with no staff and don’t have a clear answer to my concerns. 

First, I want to know what information I need from a credit bureau to issue an adverse action notice. 

Secondly, I want to know what information I need from third parties that are not credit bureaus for me to issue the adverse action notice. 

Third, and the biggest issue for me, I want to know who we should notify when multiple applicants are on a loan application. I say this is the biggest issue because this is the one on which I get a lot of conflicting advice. 

So, here are my questions. 

What is required for adverse action based on credit bureau information? 

What is required for adverse action based on third parties? 

And, who is supposed to get the adverse action notice when the loan is for multiple applicants? 

ANSWER 

You are not alone in feeling some consternation. Many compliance professionals express some confusion about the notification requirements of adverse action. Section 615 of the Fair Credit Reporting Act (FCRA)[i] requires lenders to provide adverse action notices in cases where information from a consumer reporting agency is used and instances where information from other third parties is used to make the adverse credit decision. 

If you use a consumer credit report to take any type of adverse action that is based at least in part on information contained in a consumer report, you are required by the FCRA[ii] to notify the consumer. The notification may be in writing, orally, or by electronic means. 

You may already be familiar with what the notice must contain, such as: 

·      A numerical credit score[iii] used in taking any adverse action based in whole or in part on any information in a consumer report along with the following related information:[iv] 

o   The range of possible credit scores under the model used;

o   All of the key factors that adversely affected the credit score of the consumer in the model used, not to exceed four;

o   The date on which the credit score was created; and

o   The name of the person or entity that provided the credit score or credit file upon which the credit score was created. 

However, the adverse action notice must also include the following: 

-  The name, address, and telephone number of the credit reporting agency (CRA) (including a toll-free telephone number, if it is a nationwide CRA) that provided the report;

-  A statement that the CRA did not make the adverse decision and cannot explain why the decision was made;

-  A statement setting forth the consumer’s right to obtain a free disclosure of the consumer’s file from the CRA if the consumer requests the report within 60 days; and

-  A statement setting forth the consumer’s right to dispute directly with the CRA the accuracy or completeness of any information provided by the CRA. 

I suggest you review the model adverse action forms in Appendix C of Regulation B, the implementing regulation of the Equal Credit Opportunity Act (ECOA), which include model language for making the above disclosures, including the credit score information. 

Your second question is about adverse action notices based on information obtained from third parties that are not CRAs. I would add affiliates to that category. When a lender denies (or increases the charge for) credit for personal, family, or household purposes based either wholly or partly on information from a person other than a consumer reporting agency (such as a credit bureau), the FCRA[v] requires that the institution clearly and accurately discloses to the consumer their right to obtain disclosure of the nature of the information that was relied on by making a written request within 60 days of notification. The financial institution must provide the disclosure within a reasonable period of time following the consumer’s written request. 

You may take an adverse action involving insurance, employment, or a credit transaction initiated by the consumer, based on information of the type covered by the FCRA. If this information was obtained from an entity affiliated with the institution by common ownership or control, the FCRA[vi] requires the financial institution to notify the consumer of the adverse action. The notification must inform the consumer that they may obtain a disclosure of the nature of the information relied on by making a written request within 60 days of receiving the adverse action notice. And if the consumer makes such a request, the financial institution must disclose the nature of the information no later than 30 days after receiving the request. The applicable section of the FCRA[vii], however, does not cover information obtained directly from an affiliated entity relating solely to its transactions or experiences with the consumer and information from a consumer report obtained from an affiliate. 

Finally, you wanted to know about disclosing the adverse action notice where multiple applicants are on a loan application. The answer invokes both Regulation B as well as the Fair Trade Commission’s interpretation of the FCRA. In some cases, the rules of Regulation B regarding who must be provided the adverse action notice will differ from the rules under the FCRA. This is due to a Federal Trade Commission interpretation of Section 615(a) of the FCRA. The explanation is going to be a bit nerdy, but hang in there! 

Section 615(a) of the FCRA requires that “any consumer,” with respect to whom adverse action is taken, must receive the disclosures mandated by this section if that action is based “in whole or in part” on information from a consumer report. In the FTC’s view, the plain language “any consumer” includes a co-applicant. Neither the applicable section of Regulation B[viii] nor the combined disclosure permitted in Appendix C remove or modify that requirement for co-applicants. The objective of the combined disclosures permitted by the Federal Reserve Board in Appendix C to Regulation B is only to simplify the paperwork involved in making ECOA and FCRA notifications to a single applicant, where both are required – for instance, where the action by the creditor is both adverse to the applicant (ECOA) and is based in whole or in part on information from that applicant’s consumer report (FCRA).

Friday, December 4, 2020

Guidance versus Regulations

QUESTION
We appreciate your weekly FAQs. It is printed and handed out to staff in our Monday compliance meetings. Thank you for your dedication to our compliance needs.

In one of our meetings recently, there was quite a bit of discussion about the difference between regulations and guidance. The consensus was that regulations must be followed, but guidance is not required to be followed.

The thinking was that regulatory guidance would become regulations, so we should just follow them anyway.

Our question is, what’s the difference between regulations and guidance?

ANSWER
First and foremost, thank you for reading our FAQs. We have provided this labor of love for many years because of our philosophy to serve our clients and the mortgage community more broadly. In fact, our very motto – Creating a Culture of Compliance® – is reflective of our commitment and vision.

Your question is a good one. Regulations and guidance are not synonyms, but they are closely aligned. I will offer some insight into the difference by considering a current regulatory proposal. 

The Federal Reserve, Consumer Financial Protection Bureau, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency are asking for comment on a proposal that outlines and confirms the agencies' use of supervisory guidance for regulated institutions.

The proposal would codify the 2018 Interagency Statement Clarifying the Role of Supervisory Guidance (“2018 Statement”) that clarified the differences between regulations and guidance. The 2018 Statement reiterated well-established law by stating that, unlike a law or regulation, supervisory guidance does not have the force and effect of law. 

The agencies do not take enforcement actions or issue supervisory criticisms based on noncompliance with supervisory guidance. Instead, supervisory guidance outlines supervisory expectations and priorities or articulates views regarding appropriate practices for a given subject area.

Thus, in contrast to supervisory guidance, regulations do have the force and effect of law, and enforcement actions can be taken if regulated institutions violate the regulations. Regulations are also generally required to go through a notice and comment process.

To amplify this outline further, the agencies had issued the 2018 Statement on September 11, 2018, to explain the role of supervisory guidance and describe the agencies’ approach to supervisory guidance. An interesting feature of the 2018 Statement was its view that agencies issue various supervisory guidance types to their respective supervised institutions, including, but not limited to, interagency statements, advisories, bulletins, and policy statements, questions and answers, and frequently asked questions.

To be clear, supervisory guidance outlines the agencies’ supervisory expectations or priorities and articulates the agencies’ general views regarding appropriate practices for a given subject area. Supervisory guidance often provides examples of practices that mitigate risks or that the agencies generally consider to be consistent with safety and soundness standards or other applicable laws and regulations, including those designed to protect consumers.

It is also worth noting that the agencies stated in the 2018 Statement that supervised institutions sometimes request supervisory guidance. That guidance is essential to providing clarity to these institutions in a transparent way that ensures consistency in the supervisory approach.

Here’s the important takeaway: the 2018 Statement restates existing law and reaffirms the agencies’ understanding that supervisory guidance does not create binding, enforceable legal obligations. Furthermore, it reaffirms that the agencies do not issue supervisory criticisms for violations of supervisory guidance, and the appropriate use of supervisory guidance by the agencies.

Specifically, in this particular interagency statement, the agencies also expressed their intention to (1) limit the use of numerical thresholds in guidance; (2) reduce the issuance of multiple supervisory guidance on the same topic; (3) continue efforts to make the role of supervisory guidance clear in communications to examiners and supervised institutions; and (4) encourage supervised institutions to discuss their concerns about supervisory guidance with their appropriate agency contact.

Financial institutions must use regulatory guidance constructively to be prepared for regulatory scrutiny. Implementing guidance provides certainty and transparency to financial institutions. 

In effect, by following regulatory guidance, a financial institution anticipates the agencies’ supervisory criticisms relating to identifying the practices, operations, financial conditions, or other matters that could have a negative effect on the safety and soundness of the financial institution; could cause harm to consumers; or could cause violations of laws, regulations, final agency orders, or other legally enforceable conditions.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Friday, November 27, 2020

Who owns the loan?

QUESTION
We came under an audit by our regulator a few months ago. Today we received their report.

The report shows a few issues that we’ll need to resolve. One of them involves the Notice of Loan Ownership. We were cited for failing to disclose the Transfer of Loan Ownership. 

Since we are now redrafting our policies and procedures, we want to know about the responsibility to issue this disclosure. 

Who is responsible for this disclosure, the company transferring the loan or the company receiving the loan?

ANSWER

Sometimes an action that seems intuitively correct is wrong as it relates to the law, Best Practices, and regulatory requirements. If I were to put your question to a large group of people, many of them would say that the transferring company is responsible, and many will say that the receiving company is responsible.

Section 131(g) of the Helping Families Save Their Homes Act, which was enacted in 2009, amended the Truth-in-Lending Act (TILA) to require a “creditor” who acquires a mortgage loan to disclose that fact to the borrower not more than 30 days after the date on which the loan is sold or otherwise transferred or assigned to a third party. In my view, the statute abuses the term “creditor” because TILA ascribes a specific meaning to that word. TILA defines “creditor” to mean a person who regularly extends consumer credit that is subject to a finance charge or is payable by a written agreement in more than four installments (not including a down payment) and to whom the obligation is initially payable, either on the face of the note or contract or by agreement if there is no note or contract.

The situation contemplated by § 131(g), to wit, the acquisition of a mortgage loan, attempts to impose a disclosure obligation on someone to whom the obligation is not initially payable, that is, on someone who subsequently acquires an already originated loan and does not meet TILA’s definition of creditor.

Regulation Z, implementing § 131(g), does not make the same mistake. It specifically provides, in Comment 39(a)(1)-1, that “the fact that a person purchases or acquires mortgage loans and provides the disclosures under this section does not by itself make that person a ‘creditor’ as defined in the regulation.” Indeed, the Federal Reserve Board (FRB), and later, the CFPB, concluded that Congress did not intend the word “creditor” to have the same meaning as “creditor” under TILA and Regulation Z. I know; a bit confusing!

To give effect to the legislative purpose, the agencies construed it to refer to the owner of the debt following the sale, transfer, or assignment, without regard to whether that party would be a “creditor” for other purposes under TILA or Regulation Z; hence, the regulation uses the term “covered person” instead of “creditor” in its provision implementing TILA § 131(g).

Although § 131(g) became effective immediately upon enactment, the FRB chose to adopt interim regulations to implement the section, so parties subject to the TILA disclosure requirement would have prompt guidance on how to interpret and comply with the statutory requirements already in effect. To allow time for operational changes, the FRB made compliance with the Regulation Z change optional until January 19, 2010. That did not mean noncompliance with the statutory requirement would necessarily go unpunished until January 19, 2010, although perhaps one could argue that the FRB’s delayed compliance date was an exercise of its authority under TILA to provide for adjustments to the statutory requirements.

In any event, the delayed compliance date meant that noncompliance with any requirement in the regulation that extended beyond the minimum required by the statute could not be punished unless it occurred on or after January 19, 2010.

This requirement must not be confused with the requirements of the Real Estate Settlement Procedures Act (RESPA) regarding mortgage servicing transfers. Under Regulation X, the implementing regulation of RESPA, consumers must be notified when their mortgage loan servicer has changed. In contrast, § 131(g) was intended to provide consumers with information about the identities of the owners of their mortgage loans, partly so they know whom they may contact if they want to exercise a right to rescind the loan. The provision was not intended to require a notice when a transaction does not involve a change in the ownership of the physical note, such as when the note holder issues mortgage-backed securities but does not transfer legal title to the loan.

In reviewing recent court decisions as they relate to the scope of TILA § 131(g) and its implementing provisions in Regulation Z § 1026.39, certain observations can be construed. One case provides insight into the treatment of TILA § 131(g).

The illustrative case is Kornea v. Fannie Mae,[i] in which a federal district court in Pennsylvania considered a consumer’s complaint that Fannie Mae had failed to disclose information about the ownership of his mortgage loan, in violation of § 131(g).

Kornea alleged that in June 2012 he received a letter from Chase, his loan servicer, explaining that his loan had been “sold into a public security managed by Fannie Mae” and that Chase was “authorized by the security to handle any related concerns” on its behalf. The letter provided the investor’s address, but not its name.

About seven years later, in May 2019, Kornea called Fannie Mae, seeking the loan holder’s identity. He was told the information could not be given to him over the phone. He then sent a registered letter to Fannie Mae requesting the owner’s name, address, and phone number. Fannie Mae did not respond. He sent a second letter, and again Fannie Mae did not answer. He sent a letter to Chase asking for the same information, to which Chase responded that Kornea’s loan could “be transferred between investors over its life, but its current investor [wa]s Fannie Mae.”

In October 2019, Kornea sued Fannie Mae under § 131(g)[ii]; however, the state court dismissed the claim as time-barred, though it allowed Kornea to file an amended complaint, in which he added Chase as a defendant. Chase removed the case to federal court.

The federal district court also dismissed the claim against Fannie Mae as time-barred, holding that claims under § 131(g) are subject to a 1-year limitation on actions. Because Kornea learned about the sale of his loan into a Fannie Mae security on June 19, 2012, his claim against Fannie Mae expired a year later, in 2013.

The court then turned to another TILA subsection, § 131(f)(2), because Kornea’s complaint included a claim against Chase under that subsection. That section requires a servicer, upon written request by a consumer obligor, to provide the obligor with the name, address, and telephone number of the owner of the obligation or the master servicer of the obligation.

TILA has a civil liability section[iii] that addresses a consumer’s right to sue for TILA violations. The section specifies that “any creditor who fails to comply with any requirement imposed under this part, including any requirement under § 125, subsection (f) or (g) of § 131, or part D or E of this subchapter” is liable. Accordingly, the creditor, not the servicer – unless, of course, the servicer also is the creditor or an assignee of the creditor – might be liable for violations of this requirement.

Kornea alleged only that Chase was the servicer of his loan, not that Chase was a “servicer-assignee.” As a result, according to the court, Kornea had not alleged “enough facts to show that Chase had any obligation to provide the information Section [131(f)(2)] requires.” The court continued, “And even if he had, Chase met TILA’s obligations in its June 3, 2019 letter responding to Kornea’s request for information by providing ‘the name, address, and telephone number of the owner of the obligation or the master servicer of the obligation.’”

From the foregoing matter, we can derive helpful guidance. Section 131(f)(2) seems quite clear that the servicer of a mortgage loan, whether a “servicer-assignee” or not, has an obligation to comply with its disclosure requirement. That subsection expressly refers to RESPA for the definition of a “servicer” as “the person responsible for servicing of a loan (including the person who makes or holds a loan if such person also services the loan).”

This definition does not incorporate the additional requirement that the servicer be an assignee, a fact various courts have overlooked.[iv] Chase appears to meet that definition. However, the court is right that Chase apparently satisfied its disclosure obligation and that TILA imposes liability for failure to meet that disclosure obligation only on the “creditor” of the loan, not the servicer (unless the servicer also meets the definition of creditor).

Thus, it may seem appropriate that if only servicers can violate TILA § 131(f)(2), Congress must have intended to create a cause of action for failing to comply with that section, whether it be against the servicer or the creditor with liability for the servicer’s failure.

To avoid rendering the subsection meaningless, some judges have applied agency principles to make the loan owner liable for violations by its servicer.[v]

And other courts have assumed liability without devoting attention to the distinction between a disclosure obligation under § 131(f)(2) and liability under § 130(a).[vi] 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

_______________________________________
[i] Kornea v. Fannie Mae, 2020 U.S. Dist. (E.D. Pa. Oct. 6, 2020)
[ii] 15 U.S.C. § 1641(g)
[iii] TILA § 130(a)
[iv] Including the U.S. Court of Appeals for the 9th Circuit in Gale v. First Franklin Loan Services, 701 F.3d 1240 (9th Cir. 2012).
[v] See, for instance, Montano v. Wells Fargo Bank, 2012 U.S. Dist. (S.D. Fla. Oct. 23, 2012); Galeano v. Fed. Home Loan Mortg. Corp., 2012 U.S. Dist. (S.D. Fla. Aug. 21, 2012); Kissinger v. Wells Fargo Bank, 888 F. Supp. 2d 1309 (S.D. Fla. 2012).
[vi] See Sam v. American Home Mortgage Servicing, 2010 U.S. Dist. (E.D. Cal. Mar. 3, 2010); Stephenson v. Chase Home Finance LLC, 2011 U.S. Dist. (S.D. Cal. May 23, 2011); and Erickson v. PNC Mortgage, 2011 U.S. Dist. (D. Nev. May 6, 2011).