LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label MORA. Show all posts
Showing posts with label MORA. Show all posts

Thursday, January 9, 2025

What to Expect from a Fannie MORA audit?

Request Article 

Request MORA Tune-up® Information 

QUESTION 

Last month, you answered a question about doing an internal audit in advance of Fannie’s MORA audit. We did not pay much attention to it because (A) we never had a MORA audit, and (B) we did not expect a MORA audit anytime soon. Then, all hell broke loose! 

Yesterday, we got a letter from Fannie Mae telling us that they will be scheduling a date for an on-site audit. They are requesting policies, procedures, and many other documents. There are due dates. This review makes a state banking exam look like child’s play. But I’m a QC manager, so I don’t have the whole picture of our risks. However, I do know one thing: we are not ready for this MORA audit. 

The CEO called a team meeting in the conference room. Our compliance manager is in charge, and everyone reports to her. I got your name at the meeting because she said we are going to use you to do a MORA Tune-up®. I just wish they would have done this sooner. 

What I need – and I think they need it too – is some idea of what we can expect from the MORA exam. I hope you don’t wait to reply. The compliance manager and others in management read your articles. They pass them around to us all the time. Please tell us what to expect about the MORA process. 

What is the audit process of a Fannie MORA audit? 

SOLUTION 

MORA Tune-up® 

RESPONSE 

If you want a copy of this article, please contact us here. 

We realize your question is urgent. Accordingly, we are prioritizing a response. You only have a few weeks to get ready for the MORA audit, the purpose of which is for Fannie Mae to evaluate your company’s compliance with Fannie guidelines as well as assess the operational risks. 

For those who don’t know, Mortgage Origination Risk Assessment (MORA) is a Fannie Mae review of a Fannie Seller/Servicer. It is intended to be a collaborative engagement led by the review team with the active participation of your organization.[i]

Getting our MORA Tune-up® engaged is one of several readiness activities you must undertake as soon as possible. Ours is the pioneer of the Compliance Tune-up, a unique review that provides a risk assessment and self-evaluation to satisfy the Second Line of Defense. I am grateful that your compliance manager chose Lenders Compliance Group. Nevertheless, to all our subscribers, please know that a few compliance and law firms offer to prepare you for the MORA review. Pick one you trust and get it done! 

There are seven phases in the MORA review process, and I will outline them for you. My outline will give you a high-level view. You should not delay! 

Here are the seven phases of a MORA review: 

Phase 1: Selecting the Organization 

Phase 2: Confirmation and Engagement 

Phase 3: Document Request and Receipt 

Phase 4: Process Evaluation 

Phase 5: Interviews 

Phase 6: Final Assessment 

Phase 7: Remediation 

I am going to provide a brief overview of each phase. However, numerous contingencies can affect the process and outcome. Take this review as a deep dive, one that will make your company stronger and its relationship with Fannie more durable. It is not too late to get started immediately. 

PHASE 1: SELECTING THE ORGANIZATION 

Fannie Mae selects organizations for a review using risk-based inclusion criteria and provides advance notice to the organization prior to scheduling the review. A member of the review team begins the process by compiling the organization’s pertinent contact information to start the review before moving to Phase 2. 

We are often asked if there is a way to predict whether and when the selection takes place. The short answer is No. The best answer is Soon. In other words, always be prepared.

PHASE 2: Confirmation and Engagement 

There are obviously two parts to this phase: the first part involves confirmation, and the second part involves scheduling. These two parts are interfaced. What happens is your point person – in your case, the compliance manager – will discuss Fannie’s BAMS team, that is, its Business Account Management Solutions team, to discuss some basics. The MORA team is independent of the BAMS team. This is a sort of Question and Answer format where the BAMS team gathers the following information:

Wednesday, December 11, 2024

Fannie’s MORA Review: Internal Audits

QUESTION 

Although approved by Fannie Mae, we have not set up an internal audit schedule. This issue came up in a recent discussion with our Fannie representative. They want us to be ready for the MORA audit, and the audit schedule is going to be required. We haven’t even done an internal audit yet. This got us thinking about what we don’t know for preparing for the MORA visit. 

We know your company is well-known for independent risk assessments and self-evaluations, which are called the Compliance Tune-up®. I spoke to one of your Directors this morning about several of them that could help us get prepared for the Fannie audit. We need to know which policies and procedures will be reviewed, and we need to know so much more. Our first MORA audit is coming soon. So, we’re somewhat intimidated. 

I am the compliance manager. I have never handled a MORA audit before. And I have never been involved in an internal audit. I need some guidance about what Fannie expects for internal audits and a “heads-up” for their requirements.


·       What are Fannie’s expectations for internal audits?

 

·       Can you please provide a “heads-up” for the internal audit requirements?


·       What have you found that shows your clients were not prepared for an internal audit? 

SOLUTION 

Compliance Tune-up® List

MORA Tune-up® Fannie's Mortgage Origination Risk Assessment (MORA)

CMS Tune-up® Compliance Management System

RESPONSE 

Anyone who has an interest in our Compliance Tune-up®, in general, or our MORA Tune-up®, in particular, can contact us here. The Compliance Tune-up® is an extensive series of mini-audits that targets departments, functions, and regulations. It is a self-identification and risk assessment review that complies with the second line of defense.[i] The review provides a report and risk rating. It shows the strengths and weaknesses of the area subject to review. 

Fannie Mae conducts regular reviews to evaluate seller/servicer compliance with its guidelines and assess operational risks. Reviews are conducted by a team that operates independently of the Business Account Management Solutions team. 

You will need to establish an independent internal audit function. During the MORA process, Fannie Mae examines the lender's internal audit plan and the latest independent internal audit. A financial institution may outsource its internal audit process; however, it remains responsible for the findings that show compliance (or lack thereof) with Fannie's requirements.

An internal audit is the central feature of the third line of defense. From Fannie’s perspective, management control is itself a function. Indeed, establishing a professional internal audit activity should be a governance requirement for all organizations. 

Management is supposed to rely on the internal audit to validate a financial institution’s governance, risk management, and control processes to help it achieve strategic, operational, financial, and compliance objectives. This compliance framework is meant to ensure a risk-based approach, and the internal audit function evaluates and improves the effectiveness, exigencies, and readiness of risk management, control, and governance processes. 

We believe the following outline provides the guardrails and requirements of an internal audit. It would be best if you considered them collectively so that you prepare adequately for the development of this function. In other words, don’t cut corners. Be sure you comply with all these criteria. 

Internal Audit Function: Guardrails and Requirements


·       Be sure that the internal audit manager is free from any responsibility over any business unit.

 

·       Be sure the internal audit is independent of all key functions of the loan origination and servicing processes.

 

·       Draft internal audit and management control procedures for evaluating and monitoring the overall quality of loan production.


·       Ensure that your organization chart shows that the internal audit function reports directly to the senior management and, if applicable, the Board of Directors. (By the way, we know from experience that Fannie will permit exceptions in situations in which the size of the organization is insufficient to support adequate resources to allow for the separation of these functions. In those situations, your audit plan must include the rationale for the lack of separation of controls in place to mitigate risks associated with the lack of separation of these functions.)


·       Be especially careful that internal audit lines of reporting reflect the independence of the audit process at all levels so that the activities are conducted in an unbiased manner and without compromises that may result from internal influences or conflicts of interest.


·       Be especially careful that the internal audit function does not share any reporting lines with the functional areas that it reviews.


·       Create a reliable and scaleable reporting procedure to ensure that the written findings provide methodologies that derive recommendations that management can use to accomplish actionable objectives through a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control, and governance processes. 

Adverse Findings and Required Document Preparation 

There are a few other things I would like you to consider. I’ll get to them in a moment. You had asked about how some clients show that they are not ready for an internal audit. By this point, I think we’ve seen just about everything there is to see about internal audit findings and preparation. However, most challenges can be overcome if you have robust plans. 

We have an extensive database of common findings from independent internal audits and Compliance Tune-up®. I have picked seven of them that I think are virtually non-negotiable. 

Adverse Findings


1)    There is no comprehensive written plan to direct the internal audit process across all loan manufacturing and servicing business functions.

 

2)    There is no internal audit function.


3)    MBS Trust compliance is not included in the internal audit review plan and testing.


4)    The internal audit process has not been initiated.


5)    There is no internal audit function that is independent of the business functions subject to review.


6)    An internal audit schedule has not been established to specify the areas of review, and there’s no timeframe for conducting them.


7)    The internal audit plan does not include all required components. 

Required Document Preparation 

Each financial institution differs and is unique in terms of size, products, services, complexity, risk profile, and business strategy. Keep that in mind as I outline the document preparation needed to be ready for a MORA review. You can tighten up preparation by using the appropriate Compliance Tune-up® tool, such as a MORA Tune-up® or a CMS Tune-up®. 

A Compliance Tune-up® report provides recommendations indicating what should be done now and in the future to ensure readiness, but you can’t undo mistakes of the past. Willingness to correct errors, however, is a sign of good management and governance. So, it would be best if you got ready immediately to prevent a lookback that discloses unmitigated adverse findings. 

·       Organization chart reflecting the internal audit department

·       Internal audit policies and procedures.

·       Current year’s testing schedule and internal audit plan.

·       Current year’s Compliance Tune-up®. (Second Line of Defense).       

·       Current year’s independent internal audit. (Third Line of Defense).

·       Ability to identify any significant findings for the past 12-month period.

·       Management and tracking reports for monitoring performance in operational areas. 

WordS to the Wise should be Sufficient! 

I stated above that there are a few other things I want you to consider. I list them in no order of importance because they are all equally important. Let’s group these remarks in the category of “words to the wise should be sufficient!” 

·       An internal audit plan should be risk-based, updated annually, and include a review of all controls and key functions in each origination and servicing department. 

·       Applying a risk rating for each key process area of the originations and servicing platforms is critical to implementing a continuous internal audit schedule. 

·       A second line of defense review, such as the Compliance Tune-up®, should be initiated for specific departments, functions, and regulations in anticipation of performing the internal audit. (This ensures that the internal audit, the third line of defense, may present accurate and reliable findings.) 

·       A process should be in place to define the scope and frequency of audits to be performed based on the specific risk rating for all key functions. (This ensures that the functions that represent the highest risk are audited on at least an annual basis.) 

·       An internal audit schedule should be in place, reflect current activity, and be reviewed on a regular basis to incorporate any emerging risks in operational areas. 

·       Adverse internal or external audit findings pertaining to key functions or regulatory compliance should be reviewed by the audit committee for remediation. 

·       An established framework for interaction between internal audit functions, business units, and management exists to ensure open communications regarding risk and control management, including the adoption and implementation of self-assessment methodologies.

 

Jonathan Foxx, Ph.D., MBA

Chairman & Managing Director

Lenders Compliance Group



[i] Three Lines of Defense in Effective Risk Management and Control, Institute of Internal Auditors (IIA), January 2013. The Lines of Defense (LOD) model assigns and coordinates risk and control responsibilities across business functions.

Thursday, December 7, 2023

Quality Control Challenges – Defect Rates and Trendlines

QUESTION 

During a MORA review, Fannie determined that several areas were problematic. We thought we were mostly ready until we got the MORA results. Fannie required us to revise a list of issues. 

It was too late for us to use your Fannie Tune-up. So we mustered through as best as we could. One area that the MORA team criticized us for was that we did not establish a "methodology for identifying, categorizing, and measuring defects and trends against an established target defect rate." 

They found our Quality Control Plan was defective, and we could not show that we followed a methodology to uncover defects and trends. Our QC Manager discussed this with our QC auditor, but they became defensive. They did not want to update their Quality Control Plan or provide their procedures for Fannie to evaluate. So, on top of everything else, we need to get another QC auditor. 

We need your help in understanding some basics about defects and trendlines. 

What methodology is used for "identifying, categorizing, and measuring defects and trends against an established target defect rate?" 

ANSWER 

It's unfortunate that you did not contact us soon enough for the Fannie Tune-up. It takes 60 days to complete, and it is inexpensive. Most clients use the Fannie Tune-up to comply with Fannie guidelines and stay ready or get ready for a Mortgage Origination Risk Assessment (MORA) visit. 

_____________________________________________ 

Anyone interested in the Fannie Tune-up can request information here. 

_____________________________________________ 

I thought it would be a good idea for you to get some feedback from Brandy George, the Executive Director of LCG Quality Control

There are few professionals in mortgage banking with Brandy's credentials and depth of experience. Her group audits small and large loan production into the thousands of units. Importantly, Brandy works hands-on with clients to ensure their quality control meets Fannie's guidelines. So, I asked her to join me in answering your question. 

_____________________________________________

 Brandy also offers a free Quality Control Plan (terms apply)

that meets GSE and regulatory scrutiny. 

If anyone wants to talk to Brandy about their Quality Control needs,

you can contact her here. 

_____________________________________________ 

I asked Brandy to give a brief but useful answer to your question. The following outline is reflective of my notes from my conversation with her. 

Brandy confirmed that a financial institution must have a set of policies and procedures documented in its Quality Control Plan, establishing a target defect rate and the methodology for "identifying, categorizing, and measuring defects and trends" against that rate. 

According to Brandy, 

the target defect rate is the final net defect rate your firm has established as an acceptable percentage rate of open defects in any given audit period and the year-to-date percentage rate of open defects. 

That led to our discussion about calculating the defect rate. I like Brandy's response: 

Calculating and tracking the actual defect rate against your target defect rate is how you assess your credit and financial risk performance and measure progress in meeting your quality control goals. Managing gross and net defect rates is critical to understanding the financial exposure revealed during the QC process. 

The gross defect rate is calculated by dividing the number of all defects noted by the number of loans reviewed in the audit period, and the final net defect rate is calculated by dividing the number of open defects by the number of loans reviewed in the audit period. 

To provide a granular description that brings in threat levels, having a target defect rate is required for the top severity level – which, by the way, is ineligible for delivery to Fannie Mae – and enables the lender to regularly evaluate and measure progress in meeting its loan quality standards. 

The lender must define lower severity levels as appropriate for its organization, and different target defect rates may be established for different severity levels (if applicable). Note that the target defect rate is a Fannie Mae requirement!

With respect to calculating the target defect rate, I would like to add my observation to Brandy's guidance. Calculating a defect rate is how you measure against your target defect rate. Some lenders use only a gross or a net calculation when determining their monthly defect rate, while others use both. 

  • The gross defect rate is the defect rate based on the initial findings prior to any rebuttal activity. 
  • The net defect rate is the defect rate based on the final findings after the rebuttal activity. 

Understanding the root cause of the issues resolved during the rebuttal process may provide insight into how the defects can be prevented. 

Concerning the severity level, if a loan has both the highest-severity level defect and a lower-severity level defect, Fannie directs that the lender should only count the loan once – in the highest-severity category – in a defect rate calculation. Calculations should be done for your two most severe defect types (i.e., Significant and Moderate). 

My conversation with Brandy concluded with discussing the methodology for identifying defects and trendlines. Her insight here is helpful. She said: 

The methodology for identifying defects and trends lies within the audit process. How loan defects are identified and categorized leads to the final reporting results. Meaning, exceptions and defects need to be categorized in such a way that puts the defects in risk rating categories, such as Minor, Moderate, and Significant, compliance and regulatory, or by area of responsibility, such as Loan Officer, Processor, Underwriter, or Closer.  

Categorizing into risk rating categories is essential to the mission of the quality control project. Once initial (gross) defects are cured, it is important to determine root causes, analyze issues, and reconcile the difference between your gross and net defects and action plan accordingly. Be sure to analyze the cause between the gross and net defect rates! The goal is to identify and remediate the issues to narrow the gap between gross and net defect rates. 

A final word about targets and defect rates. An effective way to establish loan quality targets is to model the financial exposure created at a certain defect level. The concept of "zero defects" generally will be considered challenging to achieve. And, in any event, Fannie Mae does not evaluate lenders by a zero-defect-rate standard. 

Fannie Mae expects lenders to set defect rate targets as reasonably low as possible based on a formal cost-benefit analysis of meeting that target. The MORA team expects lenders to demonstrate to Fannie how they manage loan quality to meet their established target. 

_____________________________________________ 

Brandy also offers a free Quality Control Plan (terms apply)

that meets GSE and regulatory scrutiny. 

If anyone wants to talk to Brandy about their Quality Control needs,

you can contact her here. 

_____________________________________________ 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, June 8, 2023

Fidelity Bond and Errors & Omissions Insurance – Fannie Mae Requirements

QUESTION

We are a mortgage lender in the northeast. We've been a Fannie Mae Seller/Servicer for many years. Our recent MORA audit found some problems handling our Fidelity Bond and Errors and Omissions Insurance. For example, we don't have a process to notify Fannie about losses that exceed $250,000. 

Another procedure issue is we do not have a process to evaluate the insurance regularly. We were criticized for not having sufficient documentation to ensure that all insurance requirements are maintained. 

MORA found several issues with the insurance itself, such as the deductible not meeting Fannie's requirements and the coverage not meeting Fannie's guidelines. 

We now have a few days to correct these findings and convince MORA that this situation is fixed. However, we want to be sure we're on track to give them what they want. So, we're coming to you for some basic guidance on the requirements. 

What should we expect a MORA review to examine with regard to the documentation needed for a MORA review of the Fidelity Bond and Error and Omissions insurance? 

ANSWER

You have mentioned several common findings involving Fidelity Bond and Error and Omissions insurance. Fannie Mae's Mortgage Origination Risk Assessment,[i] known by its acronym "MORA," is an audit team that conducts reviews, usually on-site, which is tasked with assessing the operational capabilities, governance, and compliance with Fannie Mae's Selling Guide ("Guide") requirements. 

In addition to the findings you mention, there are other results, such as the insurance not including appropriate provisions to protect Fannie's interests, as outlined in the Guide. 

A Fannie Seller/Servicer must always be prepared for a MORA audit, which means that the Seller/Servicer must continually monitor and document its compliance with Fannie guidelines. 

We are keenly aware of the requirements reviewed in a MORA audit. Many companies use our Fannie Tune-up® as a tool to prepare for the audit and ensure that they comply with many Fannie guidelines. If interested, you can request information HERE about the Fannie Tune-up®. 

As a Seller/Servicer, you must have a blanket Fidelity Bond and Error and Omissions insurance policy in effect at all times in an amount sufficient to meet Fannie's minimum coverage requirements, maximum deductible requirements, and provision requirements.[ii] 

A fidelity bond is a form of insurance protection that covers policyholders for losses they incur due to fraudulent acts by specified individuals. Errors and omissions insurance is a type of professional liability insurance that protects companies, their workers, and other professionals against claims of inadequate work or negligent actions.

You mentioned that MORA found that your fidelity bond coverage did not meet Fannie's guidelines. Although you requested information specifically about documentation needed for a MORA review of the insurance, I will caution you to be sure that your fidelity bond coverage is equal to a percentage of the greater of your annual total Unpaid Principal Balance ("UPB") of single-family and multifamily annual mortgage loan originations or the highest monthly total UPB of single-family and multifamily servicing of mortgage loans that you own, including mortgage loans owned by you and serviced by others. Coverage must be determined using Fannie's precise formulas.[iii] With certain limitations, errors and omissions coverage must equal the amount of your fidelity bond coverage.[iv] 

Given the foregoing, at minimum you should have: 

·      a process to monitor that coverage is consistent with Fannie requirements and to note that the maximum UPB definitions are based on an annual basis, not just a point in time; 

·      a process to validate that deductibles are consistent with Fannie requirements; 

·      a process to validate annually that coverage includes required provisions; and 

·      a designated individual who maintains evidence of the fidelity bond and errors and omissions coverages. 

Now, onto your question about the documentation expectations! 

You should be able to provide at least nine types of documentation to MORA. Any defects in these categories may lead to an adverse finding on a MORA audit. I will outline them, though please understand that I must be brief, respecting the article's length and the complexity of the subject.[v] 

Documentation Required by Fannie Mae: Fidelity Bond and Errors and Omissions Insurance[vi] 

1)    Provide the total UPB of single-family and multifamily annual mortgage loan originations (this should not be exclusive to the Fannie servicing portfolio held by your institution and should include the entire serviced portfolio). 

2)    Provide the highest monthly total UPB of single-family and multifamily servicing of mortgage loans that the seller owns, including mortgage loans owned by the seller and serviced by others. 

3)    Indicate if multifamily mortgage loans are serviced in addition to servicing single-family mortgage loans. 

4)    Indicate if there have been any occurrences within the past 12 months of a single fidelity bond or errors and omissions policy loss that is mortgage-related and the amount exceeds the lesser of $250,000 or the policy's deductible. If yes, you should describe in detail the nature of the claims and if they were mortgage-related. 

5)    Describe the process in place to notify Fannie Mae of a fidelity bond or errors and omissions policy loss that is mortgage-related within 30 days of discovery. 

6)    Describe the coverage review process, such as how often coverage is evaluated, how adequate coverage is determined, and who within your organization performs this task. 

7)    Fidelity bond policy has the following:

a.   The insurer's name on the insurance certificate;

b.   The policy and/or bond number;

c.   The named insured;

d.   The type and amount of coverage (should specify whether the insurer's liability limits are an aggregate loss or per-mortgage basis);

e.   The effective date of the insurance coverage;

f.    The expiration date of the insurance coverage; and

g.   The deductible amount of the insurance coverage. 

8)    Errors and omissions policy has the following:

a.   The insurer's name on the insurance certificate;

b.   The policy and/or bond number;

c.   The named insured;

d.   The type and amount of coverage (should specify whether the insurer's liability limits are an aggregate loss or per-mortgage basis);

e.   The effective date of the insurance coverage;

f.    The expiration date of the insurance coverage; and

g.   The deductible amount of the insurance coverage. 

9)    Contains evidence of the following provisions for both the fidelity bond and errors and omissions policy:

a.   Fannie is named as a "loss payee" on drafts the insurer issues to pay for covered losses incurred by Fannie;

b.   Fannie has the right to file a claim directly with the insurer if the lender fails to file a claim for a covered loss incurred by Fannie Mae (if available);

c.   Fannie will be notified at least 30 days before the insurer cancels, reduces, declines to renew, or imposes a restrictive modification to the lender's coverage for any reason other than partial or full exhaustion of the insurer's limit of liability under the policy; and

d.   Fannie will be notified within 10 days after the insurer receives a lender's request to cancel or reduce any coverage. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

________________________

[i] A Fannie team may also audit for compliance with Servicer Total Achievement and Rewards (STAR) requirements
[ii] Fidelity Bond and Errors and Omissions Coverage, Selling Guide, A3-5-01, Fannie Mae, July 25, 2017
[iii] Fidelity Bond Policy Requirements, Selling Guide, A3-5-02, Fannie Mae, July 25, 2017
[iv] Errors and Omissions Policy Requirements, Selling Guide, A3-5-03, Fannie Mae. July 25, 2017
[v] Seller/Servicer Risk Self-Assessment, Fidelity Bond and Errors and Omissions Insurance, Fannie Mae, 2020
[vi] See also Fidelity Bond and Errors and Omissions Coverage Provisions, Selling Guide, A3-5-01 Fannie Mae, July 25, 2017

Thursday, March 23, 2023

Fannie's Mandate for Servicing Quality Control

QUESTION 

We are a mortgage servicer. We subservice about $8 billion. I am on the staff of the compliance department. Our servicing quality control audits have been picking up compliance issues, particularly overcharging late fees and charging consumers fees that should have been waived per the CARES Act. 

The CFPB's recent Supervisory Highlights specifically mention these two issues in their examination audits. We have no wish to have CFPB examiners identify such findings in their audits. 

We have been through three audit firms for servicing quality control. But only the current one picked up on these issues. Little good it does us since we've been making these mistakes for years! And our clients are going through MORA reviews. Some did not do servicing quality control, so they did not pick up on the problem. Others have, and now they are threatening to leave us. 

We know you offer servicing quality control, so you have expertise in this area. We read your article on servicing QC and found it very helpful. Our concern now is to get a description of the implications of these process issues. 

What are the compliance implications of overcharging late fees in loan servicing? 

What regulatory issues arise when we charge consumers fees that should have been waived per the CARES Act? 

ANSWER 

The article you refer to is Servicing Quality Control: Why's and Wherefore's. That article dealt with a mortgage lender that did not conduct servicing quality control of the subservicer. Interestingly, like some of your clients, that lender seemed to indulge in the philosophy of "unknown knowns;" that is, because it did not do the audits, it was unaware of the risks. Being unaware of known risks – certainly when the risk are knowable – is a recipe for failure. 

Your clients should be conducting servicing quality control of their portfolio being serviced by you.[i] This is an oversight function. They cannot evade liability by pushing it to the servicer. If you are a Fannie Seller/Servicer, it is a relationship mandate that the Fannie's MORA team will check. The MORA team evaluates how well a mortgage company meets Fannie Mae's guidelines and gauges operational risks.

Lenders who use subservicers retain my firm to conduct Servicing Quality Control. A high level of expertise is needed; not just any quality control auditor can do these reviews, and most do not. Interested lenders and servicers can download our Servicing QC presentation HERE. Or contact me HERE, and we'll arrange a call. 

I think you will have a hard time holding onto clients, not only the clients who did the servicing QC audits but also those who did not do them. Especially those clients that did not conduct servicing quality control audits and are involved in Fannie Mae MORA audits,[ii] as they now face a double-barreled issue: (1) they did not do the oversight requirement of servicing quality control, so MORA will write them up for not doing so, and (2) as their subservicer, you are going to give them servicing QC reports that show ostensible compliance issues that the CFPB has identified to be regulatory violations.

The compliance issues that the CPFB has found pervasive come under the regulatory categories of violations of UDAAP and Regulation Z, the latter triggering violations related to junk fees. 

Overall, the Bureau's examiners found that servicers overcharged junk fees that were unlawful, repeatedly charged for unnecessary property inspection visits, misrepresented that consumers owed PMI premiums, charged consumers fees that should have been waived, charged consumers for PMI after it should have been removed, and charged late fees after sending periodic statements listing a $0 late fee. 

I will address the two you mention, referencing the Supervisory Highlights[iii] you've noted. The CFPB's examiners found multiple servicing compliance failures relating to UDAAP and Regulation Z violations. 

What are the compliance implications of overcharging late fees in loan servicing? 

Overcharging late fees is assessing late fees in excess of the amounts allowed by their loan agreements. It is an unfair acts or practices violation. Specifically, where loan agreements included a maximum permitted late fee amount, the servicers failed to input these late fee caps into their systems. 

The servicers charged the maximum allowable late fees under the relevant state laws, which frequently exceeded the specific caps in the loan agreements. This happened because the systems did not reflect the maximum late fee amounts permitted by their loan agreements. Servicers cause substantial injury to consumers when they impose these excessive late fees. 

Consumers can not reasonably avoid injury because they do not control how servicers calculate late fees; indeed, they have no reason to anticipate that servicers would impose excessive late fees. The CFPB's position is that charging exorbitant late fees does not benefit consumers or the competition. Consequently, examiners concluded that servicers also violated Regulation Z by issuing periodic statements that included inaccurate late payment fees, since they exceeded the amounts allowed by the loan agreements.[iv] In general, if this is your situation, you can expect the CFPB to require you to waive or refund late fee overcharges to consumers and correct the periodic statements. 

What regulatory issues arise when we charge consumers fees that should have been waived per the CARES Act? 

The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) directs servicers of federally backed mortgages to grant consumers a forbearance from monthly mortgage payments if the consumer is experiencing financial hardship resulting from the COVID-19 emergency. 

During the time a consumer is in forbearance, no fees, penalties, or additional interest beyond scheduled amounts are to be assessed. While the CARES Act prohibits fees, penalties, or additional interest beyond scheduled amounts during a forbearance period, consumers sometimes accrue these amounts during periods when they are not in forbearance. 

For instance, a servicer is permitted to charge a late fee if a consumer was delinquent in May 2020 and then entered a forbearance in June 2020. 

In the case of FHA loans, when consumers exit CARES Act forbearance and enter certain permanent loss mitigation options, the HUD (Department of Housing and Urban Development) requires servicers in certain circumstances to waive late charges, fees, and penalties accrued outside of forbearance periods. 

The CFPB's examiners found that servicers engage in unfair acts or practices when they fail to waive certain late charges, fees, and penalties accrued outside forbearance periods, where required by HUD, upon a consumer entering a permanent COVID-19 loss mitigation option. 

This is not the first time the CFPB has cited UDAAP violations relating to charging fees to consumers during a CARES Act forbearance.[v] The CFPB's position is that the failure to waive the late charges, fees, and penalties constitutes a substantial injury to consumers. This injury is not reasonably avoidable by consumers because they have no reason to anticipate that their servicer would fail to follow HUD requirements, and consumers lacked reasonable means to avoid the charges. This harm outweighed any benefit to consumers or competition. You can expect the CFPB to require proof that you have improved your system controls. In addition, you'll need to waive all improper charges and provide refunds to consumers.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] Fannie Mae’s Quality Control Review, Chapter A2-4 Fannie Mae, Single Family, Servicing Guide, March 8, 2023

[ii] The Fannie Mae Mortgage Origination Risk Assessment (MORA) team conducts a comprehensive review, which includes an assessment of the operational capabilities, governance and compliance with Fannie Mae's Selling Guide requirements.

[iii] Supervisory Highlights – Junk Fees Special Edition, Consumer Financial Protection Bureau, March 2023, Issue 29, Winter 2023, pp 9-12; FR, Vol. 88, No. 54, March 21, 2023, Notices, pp 16945-16951

[iv] 12 CFR. § 1026.41(d)(1)(ii)

[v] See Supervisory Highlights, Issue 25, Fall 2021, available at:
https://files.consumerfinance.gov/f/documents/cfpb_supervisory-highlights_issue-25_2021-12.pdf.