LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label HMDA. Show all posts
Showing posts with label HMDA. Show all posts

Thursday, November 6, 2025

Blind Spots in Mortgage Compliance

QUESTION 

Our compliance department is being downsized. Apparently, I am one of the first to be fired–oh, excuse me, I mean downsized. Suppose I sound like I have a chip on my shoulder. In that case, I suppose I do, since this is my fourth compliance job that, through no fault of my own, is being downsized. It especially bothers me that the Chief Compliance Officer asks me, before I leave at the end of the month, to provide a list of compliance blind spots that we have encountered over the last few years. 

Anyway, I have been working on the list. However, the list is only involved with our company's blind spots. How about everyone else? I want to highlight some potential blind spots that may or may not be occurring in our company, but which could happen elsewhere. Since you have many clients across the country, I wonder if you could share the types of compliance blind spots that your clients encounter. 

Thank you in advance! By the way, I have read your articles for years. I will continue to subscribe wherever I go. I have my résumé out, but many companies are not hiring. So wish me well! 

What are some compliance blind spots in mortgage banking? 

SOLUTION 

We recommend the following Compliance Tune-up®! 

CMS Tune-up®

Compliance Management System 

The Compliance Tune-up® series assesses the overall strengths and weaknesses of departments, functions, and regulatory compliance, regardless of a financial institution’s size, regulator, complexity, or risk profile. 

ANSWER 

I am sorry that you are being downsized or, as you put it, fired. The tendency to use terms that mask the reality of circumstances can be infuriating. To be downsized means your position is eliminated as part of your company's permanent reduction of its workforce. It usually happens to cut costs or restructure. This is a business decision, not a reflection of your performance, and can be a response to economic downturns, technological changes, mergers, or a need for greater efficiency. I wish you all the best. Wherever you go, please stay in touch! 

Working with many clients provides an advantage because we can share our knowledge and experience with each client. The fact is, these days, no individual compliance department can master all the diverse issues associated with mortgage compliance. After a while, a company begins to form a rather parochial, narrow, and lopsided view of compliance challenges, as its understanding of compliance is specific to its particular experience. This model is problematic because a company faces numerous risks, and therefore, it can be blindsided by a lack of knowledge relating to compliance issues affecting other companies. 

I will share some blind spots that we have come across over the years. After nearly two decades, many compliance challenges have changed. But there are some perennials. My feedback here is certainly not comprehensive. I hope it helps! 

Fair Lending BLIND SPOTS 

First up in blind spots is fair lending. Many compliance managers are familiar with the basics of fair lending and rely on various types of reviews. The blind spots become a veritable regulatory minefield if they manifest themselves. Blind spots in areas such as prohibited practices, equal access to credit, loan applications compliance – including advertising, inquiries, reviews, loan disbursement, ongoing servicing, to name but a few – are areas that have massive legal consequences. However, I think this blind spot may be boiled down to at least these components.

 

·       Data Analysis Limitations

 Lenders sometimes fail to prepare quality Home Mortgage Disclosure Act (HMDA) data or view it in a narrow context, which tends to blind them to disparities in outcomes for minority groups.

 

·       Marketing and Outreach Bias 

Marketing materials may inadvertently exclude or discourage certain demographic groups, for instance, by not featuring diverse imagery or targeting underserved communities. For example, financial institutions risk bias when renting mailing lists based on criteria that skew toward specific neighborhoods.

Thursday, February 8, 2024

HMDA: Procedures & Internal Controls

QUESTION 

I am a compliance analyst in our compliance department. We are getting ready to file our HMDA-LAR. Yesterday, our internal auditor requested an outline of the steps we take to evaluate our HMDA policies and procedures. 

Our compliance manager has put together a few bullet points. However, we need some procedures and internal controls that tell the internal auditors adequate measures are in place to ensure compliance. 

Mostly, our procedures are informal. We follow the HMDA guide and use HMDA reporting software. 

I am reaching out to you for guidance in putting together a list of HMDA procedures. 

What are some procedures and internal controls needed to comply with filing HMDA data? 

ANSWER 

Compliance Solution: HMDA, CRA, Fair Lending

The Home Mortgage Disclosure Act (HMDA) requires certain financial institutions to collect, report, and disclose information about their mortgage lending activity. HMDA was enacted by Congress in 1975 and implemented by Regulation C.[i] Over the years, there have been numerous amendments, updates, and linkages to other Acts. HMDA is a disclosure law that relies upon public scrutiny for its effectiveness. 

Contrary to what some people think, HMDA does not prohibit any specific activity of lenders, nor does it establish a quota system for mortgage loans to be made in any geographic area. The federal supervisory agencies use HMDA data to support a variety of activities.[ii] For instance, some federal supervisory agencies use HMDA data as part of their fair lending examination process,[iii] and other agencies use HMDA data in conducting Community Reinvestment Act (CRA) performance evaluations.[iv] 

HMDA disclosures provide the public with information on the home mortgage lending activities of particular reporting entities and activity in their communities. These disclosures are used by local, state, and federal officials to evaluate housing trends and issues and by community organizations to monitor financial institutions' lending patterns. Because HMDA data serve numerous important purposes, validating the accuracy of HMDA data is a key element of the federal supervisory agencies' examination activities. 

For the purpose of this article, I will use the term "institution" to refer to an institution that is either a depository financial institution or a non-depository financial institution that is subject to Regulation C. An institution is required to comply with Regulation C only if it is a financial institution as that term is defined in Regulation C. The definition of financial institution includes depository and non-depository financial institutions, as those terms are separately defined in Regulation C.[v] It is beyond the scope of this response to delve into the method to identify whether an institution meets the definition. An institution utilizes certain coverage tests and thresholds to determine whether a financial institution is required to comply with Regulation C.[vi] 

If your internal auditor plans to review your procedures and internal controls, I suggest you let them know that Regulation C requires an institution to record the data about a covered loan or application on a Loan Application Register (LAR), hereinafter "HMDA-LAR," within 30 calendar days after the end of the calendar quarter in which the financial institution takes final action on the covered loan or application.[vii] An institution is not required to record all its HMDA data for a quarter on a single HMDA-LAR. Rather, it may record data on a single HMDA-LAR or may record data on one or more HMDA-LARs for different branches or different loan types (such as home purchase loans, home improvement loans, or loans on multifamily dwellings). State or federal regulations may require an institution to record its data on a HMDA-LAR more frequently. 

Depending on various criteria, under Regulation C, an institution must submit its annual HMDA-LAR in electronic format to its appropriate federal supervisory agency by March 1 of the year following the calendar year for which the data are collected.[viii] Certain institutions must file their HMDA-LAR quarterly and annually,[ix] where the institution reported at least 60,000 originated covered loans and applications (combined) for the preceding calendar year. 

Guidelines for Procedures and Internal Controls 

for HMDA Recording and Reporting 

I will provide a list of some procedures and internal controls to ensure compliance with HMDA and Regulation C. The list is not meant to be comprehensive. 

·       Whether the individual assigned responsibility for the institution's compliance with HMDA and Regulation C possesses an adequate level of knowledge and has established a method for staying abreast of changes to laws and regulations. 

·       If the institution ensures that individuals assigned compliance responsibilities receive adequate training to ensure compliance with the requirements of the regulation. 

·       Whether the individuals assigned responsibility for the institution's compliance with HMDA and Regulation C know whom to contact, at the financial institution or their supervisory agency, if they have questions not answered by the written materials. 

·       If the institution has established and implemented adequate controls to ensure separation of duties exists (i.e., data entry, review, oversight, and approval). 

·       Any internal reports or records documenting policy and procedure revisions and any informal self-assessment of the institution's compliance with the regulation. 

·       If the institution offers preapprovals, whether the institution's preapproval program meets the specifications detailed in the HMDA regulation. If so, whether the institution's policies and procedures provide adequate guidance for reporting preapproval requests that are approved or denied in accordance with the regulation. 

·       Whether the institution's policies and procedures address the reporting of (1) non-dwelling secured loans that are originated in whole or in part for home improvement and classified as such by the institution, and (2) dwelling-secured loans that are originated in whole or in part for home improvement, whether or not classified as such. 

·       Whether the institution established a method for determining and reporting the lien status for all originated loans and applications. 

·       Whether the institution's policies and procedures contain guidance for collecting ethnicity, race, and sex for all loan applications, including applications made by telephone, mail, and Internet. 

·       Whether the institution's policies and procedures address the collection of the rate spread (the difference between the APR and the average prime offer rate for a comparable transaction as of the date the interest rate is set) and whether the institution has established a system for tracking rate lock dates and calculating the rate spread. 

·       Whether the institution's policies and procedures address determining if a loan is subject to the Home Ownership and Equity Protection Act and the reporting of applications involving manufactured home loans. 

·       Whether the HMDA-LAR is updated within 30 days after the end of each calendar quarter. 

·       Whether data are collected at all branches, and if so, whether the appropriate personnel are sufficiently trained to ensure that all branches are reporting data under the same guidelines. 

·       Whether the institution's loan officers, including loan officers in the commercial loan department who may handle loan applications reportable under HMDA (including loans and applications for multifamily or mixed-use properties and small business refinances secured by residential real estate), are informed of the reporting requirements necessary to assemble the information. 

·       Whether the Board of Directors has established an independent review of the policies, procedures, and HMDA data to ensure compliance and accuracy and is advised each year of the accuracy and timeliness of the financial institution's data submissions. 

·       What procedures the institution has put in place to comply with the requirement to submit data in machine-readable form, and whether the institution has some mechanism in place to ensure the accuracy of the data that are submitted in machine-readable form. 

·       Whether the institution's loan officers are familiar with the disclosure, reporting, and retention requirements associated with the loan application registers and the FFIEC public disclosure statements. 

·       Whether the institution's loan officers are familiar with the disclosure statements that will be produced from the data. 

·       Whether the institution's loan officers and affected staff know that civil money penalties may be imposed when an institution has submitted erroneous data and has not established adequate procedures to ensure the accuracy of the data. 

·       Whether the institution's loan officers and affected staff know that correction and resubmission of erroneous data may be required when data are incorrectly reported for at least 5 percent of the loan application records. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

[i] 12 CFR Part 1003

[ii] Home Mortgage Disclosure Act (HMDA), Consumer Financial Protection Bureau, September 2021. Also see 12 USC 2801–2810.

[iii] 15 USC 1691–1691f, 42 USC 3605, a nd 12 CFR 1002

[iv] 12 USC 2901–2908, and 12 CFR 25, 195, 228, and 345

[v] 12 CFR 1003.2(g)

[vi] HMDA Data Collection and Reporting: Keys to an Effective Program, Consumer Compliance Outlook, Fourth Issue 2020, published by the Philadelphia FRB, provides a good overview of coverage tests and thresholds, among other things.

[vii] 12 CFR 1003.4(f)

[viii] 12 CFR 1003.5(a)(1)(i)

[ix] Effective January 1, 2020.

Friday, November 24, 2023

Posting the HMDA Notice on a Website

QUESTION 

Our banking department has sent us a letter directing us to post our HMDA availability notice on our website. I do not believe we are required to do so. 

As the General Counsel, I am responsible for ensuring that our website has all appropriate consumer notices for our online business channel. I cannot find any regulation or statute requiring us to post the HMDA notice on our website. I want a second opinion. 

Are we required to post the HMDA notice on our website? 

ANSWER 

Financial institutions are required to post several different kinds of public notices on their premises. One type of required notice announces compliance with certain regulations. For example, the rules requiring highly visible Equal Housing Lender posters are well known. 

__________________________

For information about our 

HMDA Compliance Services,

please contact us here.

__________________________

To re-state your question, in part, if an institution conducts transactions online, where should such notices be posted? 

On a website, the absence of a physical location in which to post regulatory notices raises two questions: 

1) Which, if any, of the posting requirements apply to a website? 

2) If a posting is required on a website, where should it appear? 

We may gain some insight into these questions by examining the specific regulations. For example, HMDA (for institutions with an office located in a metropolitan area) requires a notice of availability of HMDA data. 

However, the applicable regulation does not specifically address whether the required notices must be posted on a website. Therefore, the language of the regulation must be consulted to determine if a particular notice should be posted on the website. 

With respect to the HMDA Notice,[i] the general requirements for posting are as follows: 

“A financial institution shall post a general notice about the availability of its HMDA data in the lobby of its home office and of each branch office physically located in each MSA and each MD.”   

An MSA is a metropolitan statistical area. An MD is a metropolitan division.[ii] 

According to these requirements, the HMDA notice must be posted in an institution’s main office and each branch office. Because a website is neither a main office nor a branch, it would seem that these notices would not be required on a website. 

This interpretation of the rules also seems to be the view of the regulatory agencies. In the publication entitled Federal Financial Institutions Examination Council Guidance on Electronic Financial Services and Consumer Compliance, the agencies discuss the various compliance regulations and their applicability to Internet banking. The publication does not mention HMDA notices at all. 

Although the HMDA Notice may not be required, financial institution management may consider including it as a precaution or provide internet consumers with the same information available to customers in the institution’s lobby. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

___________________________

[i] 12 CFR 1003.5(e)

[ii] “For purposes of HMDA, the term is interchangeable with "metropolitan area." The underlying concept of an MSA is that of a core area containing a large population nucleus, together with adjacent communities having a high degree of economic and social integration with that core. MSAs are composed of entire counties or county equivalents. Every MSA has at least one urbanized area with a population of 50,000 or more. A metropolitan division is a subset of an MSA having a single core with a population of 2.5 million or more. For reporting and disclosure purposes of HMDA, an MD is the relevant geography, not the MSA of which it is a division.” See HMDA Glossary provided by FFIEC.

Thursday, September 15, 2022

Investor Owned Residential Loans: Risk Assessment

QUESTION

We are a mid-sized mortgage lender focused on investor-owned 1-4 family residential properties. Our underwriting and procedures are risk-based. In the last few years, we have grown considerably. I came on two years ago as the compliance manager. 

Last year, I retained a law firm to handle an audit to evaluate our procedures and overall risk-based audit program. In the end, I do not feel they did not consider important areas, such as underwriting standards, portfolio monitoring, capital treatment, and several qualitative factors. The audit objectives were not clearly defined. 

I am looking for some guidelines and remedies. If we have to do another audit, we do not want to spend as much money as we spent previously. Our policies and procedures are good, but I want more depth, especially because we are scaling up quickly. 

What audit objects and procedures should I consider in a risk assessment? 

ANSWER

There are lenders in the country whose sole or primary loan product involves financing investor-owned, 1-4 family residential properties. Our firm has such clients, and we work closely with them on their specific compliance needs. Most of them have risk-based programs that set up audit objectives and procedures. 

I suggest you contact us to discuss our IORR Tune-up®. The acronym “IORR” stands for “Investor Owned Residential Real Estate.” The intended purpose of the IORR Tune-up® is to promote consistent risk management practices for residential properties where the primary repayment source for the loan is rental income. The fee is probably a fraction of the cost you spent previously. The IORR Tune-up® will likely tell you the information you sought and does it in 60 days. 

For information about the IORR Tune-up®, Contact Us Here.

Lenders are authorized to make loans to investors to purchase or refinance 1-4 family residential real estate (“RRE”) properties for rental to others. Many lenders manage IORR financing like owner-occupied 1-4 family residential loans. However, the credit risk presented by IORR lending is more similar to that associated with loans for income-producing commercial real estate. Because of this similarity, regulators expect lenders to use the same types of credit risk management practices for IORR used for commercial real estate lending. (For banks, this expectation does not change the regulatory capital, regulatory reporting, or HOLA requirements for IORR.[i]) 

Your review should include at least the following audit objectives: 

·    Evaluate whether loan underwriting standards incorporate risks related to IORR loans. 

·    Understand methods for setting loan identification and portfolio monitoring expectations. 

·    Determine whether ALLL[ii] estimation procedures incorporate IORR loan risks and related qualitative factor adjustments, if applicable. 

·    Evaluate the adequacy of internal risk assessment and rating systems to monitor IORR credit risks effectively. 

·    Evaluate continued compliance with regulatory reporting, HOLA[iii], and risk-based capital treatment, if applicable. 

We spend considerable time keeping our clients aware of the federal and state laws and regulations relating to IORR transactions, especially the regulations that implement consumer protection laws, including ECOA, the Fair Housing Act, the Fair Credit Reporting Act, the Home Mortgage Disclosure Act, RESPA, HOEPA, TILA, and the Bank Secrecy Act. Management’s lending processes and origination platforms should ensure compliance with all applicable laws and regulations and provides timely and accurate disclosures to mortgage applicants. Mortgage loan originators and the lender’s staff must be diligent in safeguarding applicants’ and borrowers’ confidential information. 

Lenders and loan officers should provide sufficient information to customers so they fully understand material terms, costs, and risks of the loan products offered. Communication with customers, including advertisements, oral statements, and promotional materials, should provide clear and balanced information about the relative benefits and risks of mortgage loan products. 

Lenders Compliance Group has identified eighteen categories and questions that act as criteria for audit procedures. I will list them, so you can get a sense of how to build a due diligence assessment. The drill-down analysis is extensive. 

1.   Evaluate the institution’s credit risk management expectations for IORR loans. 

Know the risks! IORR has distinct and very different risks involved from traditional 1- to 4-family lending, such as the loans generally being repaid by rent and possibly some of the investor’s personal income, the investor possibly owning multiple properties, vacancies leading to lower revenue, and increased credit risk. 

Thus, it is essential to ensure appropriate policies and procedures suitable for the risks specific to IORR lending. These policies and processes should cover loan underwriting standards; loan identification and portfolio monitoring expectations; allowance for loan and lease losses (“ALLL”) methodologies, if applicable; and internal risk assessment and rating systems. 

2.   Identify if regulatory reporting, HOLA, and risk-based capital treatment are carried out properly.[iv] 

3.   Determine if IORR loans have been classified as residential or commercial. (If they are classified as residential, are they effectively managed as commercial loans?) 

4.   Does the institution exercise prudent underwriting due diligence similar to that required for commercial real estate loans? 

5.   Has an income producing property analysis been conducted? 

6.   Determine if loan structuring documents incorporate commercial-type provisions. 

7.   Are credit and administration issues being handled in a manner consistent with commercial real estate loans? 

8.   Is commercial real estate amortization guidance being followed? What guidelines are used? 

9.   Is guidance on multiple properties being followed? 

10.  Are subordination, non-disturbance, and attornment agreements obtained to cover the following issues? 

11.   Is subrogation considered in the loan agreement? 

12.  Are commercial vs. residential title issues adequately addressed? 

13.  Are loan identification and portfolio monitoring expectations adequately addressed? 

14.  Do internal risk assessment and rating systems include special consideration for IORR loans? 

15.  Does loan monitoring consider critical IORR loan issues, such as higher overall costs, smaller loan size, competition pricing like residential loans, appraisal timing, and environmental testing? 

16.  Have the IORR loans been factored into allowance for loan and lease losses considerations, if applicable? 

17.  Have IORR regulatory exam issues been adequately addressed, such as improper classification, risk rating reviews, LO monitoring, appraisal requirements, and borrower types? 

18.  Have secondary market issues been adequately addressed?

Wednesday, December 29, 2021

Fair Lending: Pricing Discrimination

QUESTION

We have a fair lending examination that is going to start in mid-January. Our state banking department is doing it. However, our General Counsel has told us that the CFPB is also interested in our case. Everyone is getting anxious. We’ve been working over the holidays to prepare for the examination. 

What area of fair lending should we expect the banking department to audit?

ANSWER

First and foremost, as the year 2021 draws to a close, I want to express my thanks to our readership for their interest in our weekly Mortgage FAQs newsletter. The questions you have asked throughout the year show a deep and devoted concern for strong, steadfast compliance initiatives. May the coming year bring you good health, joy, and prosperity!

Many companies get anxious about a forthcoming banking examination. The fair lending examination is no exception, and, like most such audits, preparation is essential. When it comes to banking or CFPB examinations, it is best to be as prepared as possible.

You may be unprepared for a fair lending examination if you are not periodically getting a fair lending review, such as we offer, thereby ensuring that potential fair lending violations are noted. Please contact us for fair lending assistance.

For fair lending examinations, generally, state banking departments are aligned with the CFPB’s assessment criteria in its fair lending supervision program, to wit, among other things, compliance with the Equal Credit Opportunity Act (ECOA)[i] and its implementing regulation, Regulation B,[ii] as well as the Home Mortgage Disclosure Act (HMDA)[iii] and its implementing regulation, Regulation C.[iv]

In preparing for the fair lending examination, I suggest you carefully review the potential for pricing discrimination. Let’s look at this examination subject.

The ECOA prohibits a creditor from discriminating against any applicant with respect to any aspect  of a credit transaction based on race or sex. [v]

It is a “known known” that regulators have observed that mortgage lenders have violated ECOA and Regulation B by discriminating against African American and female borrowers in granting pricing exceptions based upon competitive offers from other institutions. Pricing disparities may be found in the failure of a lender’s loan officers to follow the lender’s policies and procedures concerning pricing exceptions for competitive offers, the lender’s lack of oversight and control over their loan officers’ use of such exceptions, and management’s failure to take appropriate corrective action surrounding self-identified risks.

There have been examination findings where lenders maintained policies and procedures permitting their mortgage loan officers to provide pricing exceptions for consumers – including pricing exceptions for competitive offers – but did not specifically address the circumstances where a loan officer could provide pricing exceptions in response to competitive offers. Instead, the lenders relied on managers to promulgate a verbal policy that a consumer must initiate or request a competitor price match exception.

In particular, examiners have identified certain lenders that show statistically significant disparities for the incidence of pricing exceptions for African American and female applications compared to similarly situated non-Hispanic white and male borrowers. It is worth noting that examiners have not identified evidence explaining the disparities observed in the statistical analysis. Rather, examiners identified instances where lenders provided pricing exceptions for a competitive offer to non-Hispanic white and male borrowers with no evidence of customer initiation.

Furthermore, examiners have noted that lenders fail to retain documentation to support pricing exceptions. Our firm has drafted policies, procedures, and forms for maintaining appropriate documentation for all pricing exceptions. You should do so! If you need compliance support, contact us HERE.

During the examination, examiners may determine that a lender’s fair lending monitoring reports and even the business line personnel raise fair lending concerns relating to the lack of documentation to support pricing exception decisions. We know this because, despite such concerns, lenders have been cited for not improving the processes or documenting customer requests to match competitor pricing during the review period. When that happens, the banking department and the CFPB expect the lender to undertake remedial and corrective actions regarding these violations.

Jonathan Foxx, Ph.D., MBA
Chairman and Managing Director
Lenders Compliance Group

_________________________

[i] 15 U.S.C. §§ 1691-1691f
[ii] 12 C.F.R. pt. 1002
[iii] 12 U.S.C. §§ 2801-2810
[iv] 12 C.F.R. pt. 1003
[v] 15 U.S.C. § 1691(a)(1). The ECOA also prohibits a creditor from discriminating against any applicant, with respect to any aspect of a credit transaction, on the basis of color, religion, national origin, marital status, or age (provided the applicant has the capacity to contract), because all or part of the applicant’s income derives from any public assistance program, or because the applicant has in good faith exercised any right under the Consumer Credit Protection Act, 15 U.S.C. § 1691(a).

Friday, July 16, 2021

Banking Exams: Meeting the Regulator’s Expectations

QUESTION
At this time, we are handling five banking examinations. The most we’ve handled at one time was seven exams.
 

We are stretched to the limit in working on them. We are in all the states, but this demand on us is daunting, to say the least. 

Over time we put together a process flow for dealing with examinations, which has worked out well, as far as it goes. But we keep having to tweak it because some examiners keep changing their processes. 

We need help in creating more procedural descriptions based on the regulator’s point of view. Our interest is in meeting the regulator’s expectations. 

What are the typical expectations of banking department examiners? 

ANSWER
You ask a very important question. Any financial institution that is not prepared procedurally for a banking examination exposes itself to potentially adverse findings. If you are dealing with multiple exams at one time, the task of handling them all effectively is really tough if you don’t have actionable procedures. The exposure climbs if you are not cognizant of the examiner’s expectations.
 

My firm provides readiness support and hands-on involvement in banking examinations. One feature we often encounter is a client’s lack of procedures in being responsive to bank audits. In effect, many companies seem to be passively waiting for regulatory scrutiny rather than being proactively getting ready for it. Although they do not really know what to expect, they also do not seem to understand what the examiner expects! 

I am going to answer your question with a generalized overview. Each financial institution varies in terms of its size, complexity, and risk profile. Each company’s procedures will reflect its business structure and risk tolerance. It is possible to provide some insight into the kind of procedures you should develop in light of a regulator’s expectations. Too often, though, companies provide procedures based on what they believe should be done without really understanding the regulatory review process. 

In determining risk, regulatory agencies usually review or perform the following tasks: 

·    Develop a compliance risk profile for the financial institution, considering its organization structure, business lines, operations, and past supervisory performance. 

·    Determine the level of a company’s compliance management system (CMS), including determining management’s level of knowledge and attitude toward compliance, management’s responsiveness to current issues, the company’s compliance organization structure, management information systems, policies and procedures, training, and monitoring and audit programs.

    Test transactions based on risks and management’s efforts and responses.

    Validate an institution’s HMDA data and conduct a fair lending review. 

As a matter of act, the FDIC uses a tool as its first step, the Assessment of Risk of Consumer Harm (ARCH). Other agencies and several state banking departments use a similar assessment for scoping a compliance examination in their pre-examination planning. 

There is a logic behind the pre-examination plans: managing the examination based on risk factors tends to reduce the overall on-site requirement and identifies areas requiring more supervisory attention. 

A central focus is a company’s compliance management system (CMS) because it enables examiners to identify causes of compliance deficiencies and suggest appropriate corrective action. If you have not used our CMS Tune-up support, you should get it done as soon as possible. It is cost-effective, hands-on, and quick. You need to know your firm’s compliance strengths and weaknesses in your compliance management system. So, contact us! 

The following is a generic and categorical outline of a mortgage lenders’ banking examination from a regulator’s point of view. 

Request Letter

Before arriving at the bank, the regulator will issue a request letter for information, specific responses to be sent to the examiner-in-charge before the on-site review, and other responses for review on site. The request letter may ask that the following material be gathered and made available: 

·     Work papers of all compliance audits performed since the last examination, including the audit reports issued, documentation of corrective action taken, and the response from management 

·     Copies of bank compliance policies and procedures 

·     Fair lending information 

·     HMDA-LAR (if applicable) 

·     Minutes of the compliance officer, committee, or board meetings regarding compliance issues 

·     Printouts or electronic files of loans and related files 

·     Tracking documentation, such as logs, pricing, and so forth 

·     Copies of compliance forms and disclosures 

·     Résumés of all compliance personnel 

The company’s chairman of the board or president usually receives this request letter and passes the information on to the compliance officer, who is then responsible for seeing that all of the information is compiled for the examiners and that key personnel responsible for these items are aware of the examiners’ arrival date. 

When the bank examiners arrive, they should be given adequate accommodations for their time at the company. A private room, such as a conference room, with Internet connectivity, is preferred. The information requested by the examiners should be made available immediately. The compliance officer should answer any questions examiners may have regarding the audit work papers, the company’s HMDA data, its public comment file, or any other requested compliance information. 

The following sections focus on each of the items the regulator may examine as outlined in the request letter. 

Audit Procedures Work Papers 

Examiners usually review the work papers of the company’s compliance auditor to determine what steps were followed in the audit of a particular area or regulation. If the auditor has thoroughly documented the results of an internal audit and kept detailed work papers, the examiner may review those work papers and not perform any additional procedures or testing. 

Policies and Procedures 

The examiners will review copies of the compliance policies and procedures in conjunction with the audit work papers and any compliance audit reports to determine if they are being followed. For instance, a company may have several policies regarding loan approvals. These policies may include the type of employment, length of employment, length of residence, credit history, and any other factors used to evaluate creditworthiness. The examiners may review loan approvals and denials to ensure that all customers are being treated equally based on the loan policies and procedures. Note the importance of a company following its own policies and procedures! 

Required Reporting 

In addition to the policies and procedures, its fair housing information and the HMDA data (if applicable) will be reviewed to make sure that the financial institution is not discriminating against any group of people with respect to home loan transactions. These transactions include home purchase loans, home improvement loans, and refinance loans. If the mortgage lender is also a department, division, or subsidiary of a bank that files CRA data, the HMDA information also will be analyzed in conjunction with that CRA data. 

Community Reinvestment Act (if applicable) 

Under the CRA, banks are strongly urged to take an active role in meeting the credit needs of their communities, not to exclude low- to moderate-income families. Examiners carefully review the HMDA report in connection with the CRA data. Bank examiners review a bank’s CRA program and internal documentation on the role it has taken in complying with the CRA as well as the bank’s CRA public comment file. Irrespective of the apparent compliance with Regulation C, the regulation that implements HMDA data collection and filing, if examiners feel that the bank is not meeting the requirements of the Community Reinvestment Act, they can impose stiff penalties, including ceasing any branching or merging by a bank. 

Compliance Management System 

A company’s compliance management system (CMS) comprises mainly three areas: board and management oversight, compliance program, and compliance audit. When your CMS is working well, and all parties are actively involved in the compliance system, the company’s compliance risks will be limited and the program strong. Examiners prioritize this central focus of a company’s risk profile. 

If you want to information about our CMS Tune-up, please let us know! 

Management and Board Involvement 

Regulators are now taking a “top-down” approach in their reviews, so examiners will focus on the amount of management and board involvement in the company’s compliance management system. I strongly urge management and the board to take an active role in compliance. Document the involvement. Management committee minutes and board minutes should reflect that management and the board: 

·     Demonstrate compliance expectations to employees. 

·     Adopt clear compliance policy statements. 

·     Appoint a compliance officer with authority and accountability. 

·     Allocate adequate resources in all areas. 

·     Review periodic audits. 

·     Discuss compliance activities, actions, strengths, and weaknesses in their meetings. 

Printouts, Online Access, Digital Reviews 

Printouts or electronic files of all loans are usually requested for a specified period. Examiners will need access to such information and documentation. They can also request additional information concerning selected items from the reports to choose an audit sample for further review. 

Compliance Forms and Disclosures 

Regulators review numerous forms and disclosures. These forms are sometimes developed internally or purchased from an outside vendor. The regulator will review all of the compliance forms used by the company to ensure that they satisfy applicable regulatory requirements. 

The compliance officer should review these forms and disclosures before submitting them to a regulator in order to ensure that they comply with the company’s policies and the latest regulatory requirements. Personnel should not change disclosure or reporting forms before the compliance officer has a chance to approve the changes. This procedure will minimize the regulatory examiner’s discovery of incorrect or inadequate disclosure.