LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label NCUA. Show all posts
Showing posts with label NCUA. Show all posts

Thursday, September 28, 2023

Artificial Intelligence: Benefits and Risks

QUESTION 

There has been a lot of news about artificial intelligence. I have to admit, I do not know anything about it. Yet my company has just announced that it is linking up with an artificial intelligence provider. 

Now, we are scrambling to understand how artificial intelligence will impact our jobs, loan process, and compliance requirements. Last year, nobody cared about AI. This year, it’s all they can talk about! 

I would like you to tell us some ways that AI is used by banks and nonbanks, since providing compliance to us is your specialty. We need some basic understanding of how AI will be a part of originating and servicing loans. 

What are some ways that financial institutions are using AI? 

ANSWER 

I sense your frustration, and you are not alone. Whenever a new technology or innovation enters the marketplace, there is a perfectly normal tendency to be a bit suspicious and even worried about its implications. In time, these concerns often become resolved, sometimes with less than optimum impact on society, sometimes with far-reaching positive impact. The challenge is anticipating change and preparing proactively to mitigate unwanted outcomes. 

I don’t think financial institutions should rush into Artificial Intelligence (“AI”) without first considering compliance. But, there are good reasons to implement AI as a tool in the quest for a strong compliance program. When planning to partner with an AI vendor, it is important to bring in a firm such as ours to provide reliable due diligence to ensure the compliance component is integral to the plan. This creates a “baseline” that serves to enhance policies and procedures, training, and ongoing improvements in the technological application. 

Many banking agencies have been vetting AI for a few years. They're still in the early stages of drafting the rulemaking, but there has been an increase in regulatory guidance issuances. As a provider of customized compliance libraries, we are updating our clients’ policies for such guidance. And when rulemaking is determined, we will provide an AI policy, specific to a client's needs, and prior to a promulgated effective compliance date. 

Five banking agencies (OCC, FRB, FDIC, CFPB, and NCUA) have sought information and comments on the use of AI, including machine learning, by financial institutions. The caveat thus far is that they support responsible innovation as long as it includes identifying and managing associated risks. 

We can glean the areas of scrutiny being reviewed for supervision, examination, and enforcement by taking note of the following ways financial institutions use or may use AI. Though not meant to be a comprehensive outline, based on our interactions with regulators and published issuances, I’m sure these areas are under review for AI compliance. 

ARTIFICAL INTELLIGENCE: BENEFITS

Flagging Unusual Transactions 

Many institutions use AI to identify potentially suspicious, anomalous, or outlier transactions (for instance, fraud detection and financial crime monitoring). This involves using different forms of data (i.e., email, texts, audio data – both structured and unstructured)[i] to identify fraud or anomalous transactions with greater accuracy and timeliness. It also includes identifying transactions for Bank Secrecy Act/Anti-Money Laundering activities, monitoring employees for improper practices, and detecting data anomalies. 

Personalization of Customer Services 

Institutions use AI technologies, such as voice recognition and Natural Language Processing (NLP),[ii] to improve the customer experience and increase efficiency in allocating financial institution resources. 

One example is using chatbots[iii] to automate routine customer interactions, including account opening activities and general customer inquiries. AI is leveraged at call centers to process and triage customer calls to provide customized service. Institutions also use these technologies to target marketing better and customize trade recommendations. 

Credit Decisions 

Some institutions use AI to inform credit decisions to enhance or supplement existing techniques. This application of AI may use traditional data or employ “alternative data”[iv] (such as cash flow transactional information from a bank account). 

Risk Management 

Institutions may use AI to augment risk management and control practices. For example, an AI approach might be used to complement and provide a check on another, more traditional credit model. Financial institutions may also use AI to enhance credit monitoring (including through early warning alerts), payment collections, loan restructuring and recovery, and loss forecasting. 

AI can assist internal audit and independent risk management to increase sample size (such as for testing), evaluate risk, and refer higher-risk issues to human analysts. Indeed, AI may also be used in liquidity risk management, for example, to enhance monitoring of market conditions or collateral management. 

Textual Analysis 

Textual analysis refers to using NLP for handling unstructured data (generally text) and obtaining insights from that data or improving the efficiency of existing processes. Applications include analysis of regulations, news flow, earnings reports, consumer complaints, analyst ratings changes, and legal documents. 

Cybersecurity 

Institutions may use AI to detect threats and malicious activity, reveal attackers, identify compromised systems, and support threat mitigation. Examples abound, including real-time investigation of potential attacks, the use of behavior-based detection to collect network metadata, flagging and blocking of new ransomware and other malicious attacks, identifying compromised accounts and files involved in exfiltration, and deep forensic analysis of malicious files. 

There are risks, too, which I’ll explain shortly. But, it should be obvious that the agencies recognize that AI has the potential to offer improved efficiency, enhanced performance, and cost reduction for financial institutions, as well as benefits to consumers and businesses. AI can identify relationships among variables that are not intuitive or not revealed by more traditional techniques. And it can better process certain forms of information, such as text, that may be impractical or difficult to process using traditional methods. 

AI also facilitates processing significantly large and detailed datasets, both structured and unstructured, by identifying patterns or correlations that would be impracticable to ascertain otherwise.

In general, other potential AI benefits include more accurate, lower-cost, and faster underwriting and expanded credit access for consumers and small businesses that may not have obtained credit under traditional credit underwriting approaches. AI applications may also enhance an institution’s ability to provide products and services with greater customization. 

ARTIFICAL INTELLIGENCE: RISKS

But there are risks. The agencies have emphasized that financial institutions should have processes to identify and manage the potential risks associated with AI. Many of the risks associated with using AI are not unique to AI. For example, using AI could result in operational vulnerabilities, such as internal process or control breakdowns, cyber threats, information technology lapses, risk associated with using third parties, and model risks, all of which could affect an institution’s safety and soundness. 

Furthermore, the use of AI could also create or increase consumer protection risks, such as risks of unlawful discrimination, unfair, deceptive, or abusive acts or practices (UDAAP) under the Dodd-Frank Act, unfair or deceptive acts or practices regulation (UDAP) under the FTC Act, or privacy concerns.

The agencies have identified three risks particular to AI: 

  • Explainability, 
  • Data Usage, and 
  • Dynamic Updating. 

Here’s a brief explanation of each risk. 

Explainability 

“Explainability” refers to how an AI approach uses inputs to produce outputs. In other words, some AI approaches can exhibit a “lack of explainability” for their overall functioning (sometimes known as global explainability) or how they arrive at an individual outcome in a given situation (sometimes referred to as local explainability). 

Lack of explainability can pose different challenges in different contexts. Lack of explainability can also inhibit a management’s understanding of the conceptual soundness of an AI approach (that is, the quality of the theory, design, methodology, data, developmental testing, and confirmation that an approach is appropriate for the intended use) which, then, can increase uncertainty around the AI approach’s reliability, and increase risk when used in new contexts. 

Lack of explainability can also inhibit independent review and audit and make compliance with laws and regulations, including consumer protection requirements, more challenging. 

Data Usage 

Broader or more intensive data usage plays a particularly important role in AI. In many cases, AI algorithms identify patterns and correlations in training data without human context or intervention and then use that information to generate predictions or categorizations. 

Because the AI algorithm depends on the training data, an AI system generally reflects any dataset limitations. As a result, as with other systems, AI may perpetuate or even amplify bias or inaccuracies inherent in the training data or make incorrect predictions if that data set is incomplete or non-representative. 

Dynamic Updating 

Some AI approaches have the capacity to update on their own, sometimes without human interaction, often known as dynamic updating. Monitoring and tracking an AI approach that evolves on its own can present challenges in review and validation, particularly when a change in external circumstances (i.e., economic downturns and financial crises) may cause inputs to vary materially from the original training data. 

Dynamic updating techniques can produce changes that range from minor adjustments to existing elements of a model to the introduction of entirely new elements. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] The term “structured data” generally refers to a set of data that has been systematically organized or arranged.

[ii] “Natural Language Processing” or “NLP” generally refers to the use of computers to understand or analyze natural language text or speech.

[iii] The term “chatbot” generally refers to a software application used to conduct an on-line chat conversation via text or text-to-speech, in lieu of providing direct contact with a live human agent.

[iv] “Alternative data” means information not typically found in the consumer’s credit files of the nationwide consumer reporting agencies or customarily provided by consumers as part of applications for credit.

Thursday, November 17, 2022

Snollygosters and Throttlebottoms

QUESTION 

I have been reading about the CFPB coming under attacks as being unconstitutional. If it is found to be unconstitutional, we are concerned about everything it has done all these years, such as whether we are going to still be required to follow all its rules and regulations. 

It seems to me the politicians who created the CFPB should have thought of its constitutionality before setting it up in the first place. We send them to Congress, they create the CFPB, and then it is found to be unconstitutional years later. I think that could affect the whole shebang of policies my company put in place for years at a huge expense. 

I'm no lawyer but most of these Congress critters are lawyers. They should know how to write a constitutional law. I am frustrated. I am concerned about CFPB enforcement, too. Especially at this time, I do not have the money to reset our policies to pre-CFPB conditions if the CFPB's authority is destroyed. 

I have read your articles for years. I know you can explain what is going on. 

What are the implications of the CFPB being considered unconstitutional? 

ANSWER 

I have received many questions along the lines of your inquiry. Quit paying so much attention to snollygosters who prey on your fears. Fear gets people fired up, which is the point of it all. Then they get all charged up, go out to vote, and, lo and behold, they elect the fearmongering throttlebottoms who proceed to screw up the machinery with anfractuous, circuitous, serpentine, and tortuous crepitations of impending apocalypse. 

Let's dispense with the realm of signs, portents, and omens. 

So, first and foremost, take a deep breath. The CFPB's rules are not going anywhere for now. However, there are some litigation challenges along the way that will need to be vetted. 

A few weeks ago, on October 19, 2022, three judges in the Fifth Circuit Court of Appeals ruled that the funding mechanism of the Consumer Financial Protection Bureau (CFPB) is unconstitutional.[i] Specifically, the court found it was a violation of the Appropriations Clause[ii] of the Constitution for the CFPB to receive funds upon the CFPB Director's request to the Federal Reserve instead of through Congressional appropriations. 

The instant case involves a challenge to the validity of the payment provisions of the CFPB's 2017 Payday Lending Rule ("Rule"). Under the Rule, lenders are prohibited from making payment transfers from consumer accounts after two consecutive failed attempts due to insufficient funds unless the consumer authorizes such attempts. 

The district court granted summary judgment in favor of the CFPB. But, on appeal, the plaintiffs challenged the CFPB's promulgation of the Rule, alleging that the Rule was promulgated by a Director who could not be removed, which means the Director is "insulated" from removal. (I'll come back to the implications of the Director being "insulated" momentarily.) The plaintiffs further alleged that the CFPB's rulemaking itself is violative of the non-delegation doctrine and that the CFPB's means of receiving funds violates the Appropriations Clause. 

The non-delegation doctrine stems from the Constitution's vesting clause and separation of powers. The doctrine is an interpretation derived from Article I, Section I of the Constitution that declares all legislative power granted by the Constitution is vested in the Congress, the legislative branch. Thus, it's a principle in administrative law that holds Congress cannot delegate its legislative powers to other entities, such as delegating its power to administrative agencies or private organizations. 

The court said that the way the CFPB receives funds allows the CFPB to have a "double insulation" from the Congressional appropriation power: the CFPB Director's requesting funds from the Federal Reserve, which the Director deems "to be reasonably necessary," violates Congress's appropriations power. 

Furthermore, the court reasoned that the Federal Reserve itself falls outside of Congress's appropriations power because it receives funds from bank assets not subject to review by the House or Senate Committee on Appropriations. 

Therefore, the court found that Congress's authorization of the CFPB to promulgate the Rule was not unconstitutional, but the CFPB improperly used unappropriated funds to engage in the rulemaking process. In its reasoning, the court clarified that the CFPB lacked the ability to exercise the power to promulgate the Rule through constitutionally appropriated funds. 

In my view, this ruling will not have much or any impact on the structure of the CFPB. The court's ruling focuses on how the CFPB receives its funding and its violation of the Appropriations Clause. I think it's unlikely that this case will have any effect on the CFPB's enforcement powers as a regulatory agency. 

That word "unlikely" is doing a lot of work there. I happen to think the CFPB's funding mechanism is constitutional under the Appropriations Clause; in fact, the CFPB must ask Congress for any money it receives out of the Treasury, which goes for several other federal agencies operating similarly, including the FDIC

The court must recognize the potentially devastating consequences that could result from interfering with the funding practices of all independently funded government agencies. We know this because the court specifically limited its reasoning to the CFPB. It did this juridical prestidigitation by claiming that the CFPB's authority is unlike those of other federal regulators and that its funding independence "goes a significant step further." How it goes a "significant step further" is somewhat of a mystery. 

I fail to see the difference. And if there is a difference, the court does not bother to explain why those differences are constitutionally significant, as far as I can tell. 

As the Constitutional Accountability Center has stated:


"Despite the court's attempt to carve out a special rule for the CFPB, its reasoning would seemingly apply to the host of other financial regulators that are independently funded, including the Federal Reserve Board, which supervises and regulates numerous banking institutions."[iii]

So, the court has put the CFPB and many similarly funded agencies into a reductio ad absurdum conundrum since it now calls into question the rules, guidance, and orders that the CFPB and the other agencies have issued, inasmuch as they are similarly funded like the CFPB. For instance, agencies similarly funded outside the congressional appropriations process are the Federal Reserve, Federal Deposit Insurance Corp (FDIC), Office of the Comptroller of the Currency (OCC), National Credit Union Administration (NCUA), and Federal Housing Finance Agency (FHFA). 

The ruling attempts a surgical clip but winds up taking a machete to many agencies. 

Indeed, the CFPB has already stated that the Fifth Circuit's decision is "neither controlling nor correct" and "mistaken." The CFPB has stated, "there is nothing novel or unusual about Congress's decision to fund the CFPB outside of annual spending bills."[iv] 

This past Monday, November 14th, the CFPB petitioned for a writ of certiorari to the U. S. Supreme Court, saying that the Fifth Circuit’s decision "threatens to inflict immense legal and practical harms on the CFPB, consumers, and the nation’s financial sector.”[v] 

The CFPB should now request a stay from the Fifth Circuit pending the Supreme Court decision, or, if denied by the Fifth Circuit, it should ask for a stay from the Supreme Court. If the CFPB doesn’t get a stay, it is not unreasonable to conclude that the Fifth Circuit’s decision could impede the CFPB’s litigating of current cases while also potentially impacting past enforcement actions and rulemaking.[vi]

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director

Lenders Compliance Group


[i] Community Financial Services Association of America, Limited; Consumer Service Alliance of Texas v Consumer Financial Protection Bureau; Rohit Chopra, in his official capacity as Director, Consumer Financial Protection Bureau, United States Court of Appeals for the Fifth Circuit, Case 21-50826

[ii] Article I, Section 9, Clause 7, U. S. Constitution: “No Money shall be drawn from the Treasury, but in Consequence of Appropriations made by Law; and a regular Statement and Account of the Receipts and Expenditures of all public Money shall be published from time to time.”

[iii] As Wrong as It is Dangerous: The Fifth Circuit’s Decision Holding the CFPB Funding Structure Unconstitutional, Constitutional Accountability Center, https://www.theusconstitution.org/blog/blog-as-wrong-as-it-is-dangerous-the-fifth-circuits-decision-holding-the-cfpb-funding-structure-unconstitutional

[iv] Appeals court finds CFPB funding unconstitutional, Katy O'Donnell, October 19, 2022, statement to Politico from CFPB spokesperson Sam Gilford. https://www.politico.com/news/2022/10/19/appeals-court-cfpb-unconstitutional-00062626

[v] Consumer Financial Protection Bureau, Et Al, v Community Financial Services Association of America, Limited, Et Al, Petition for a Write of Certiorari, November 14, 2022, section Reasons for Granting the Petition, p. 10

[vi] Ibid. Reasons for Granting the Petition, Section B. The Decision Below Warrants Review, And The Court Should Hear The Case This Term, p. 28

Thursday, June 2, 2022

Risk Factors and Risk Ratings

QUESTION

I am our company’s Compliance Manager. We enjoy reading your weekly FAQs. In fact, we use them in our weekly sales and compliance meetings. Over the years, we have kept them together in a companywide folder for everyone to read. 

This is the first time we’ve written to you. Our problem is that we need guidance in determining risk ratings for our risk assessments. We conduct internal risk assessments but are unsure how to arrange a risk rating. Each regulation is broken down into its major requirements in our risk assessment procedures. Each of these requirements is then assessed for its risk by determining if it is affected by any risk factors that present increased compliance risk. 

The matrix we use is not broken down to the level of detail contained in the checklists, so we may need to refine our risk ratings further when they are entered into the checklists. For example, under Regulation Z, the matrix includes one item for section 1026.18, the content of disclosures. However, not all items in 1026.18 will carry the same risk level; the requirement that the disclosure contains the name of the creditor will carry a lower risk than the requirement that the annual percentage rate and finance charge be accurate. 

What are the primary risk factors that we can use in our matrix? Also, how should we provide the risk ratings? 

ANSWER 

I reviewed the documents you sent me as specimens of your assessment matrix. There are many types of risk assessments and many areas of risk in a financial institution. A risk assessment should be designed to evaluate consistently the extent of risk to consumers arising from the activities of a particular entity and to identify the sources of that risk. 

One way to conceptualize risk is to view it through the backdrop of risk to consumers; specifically, the potential for consumers to suffer economic loss or other legally-cognizable injuries due to a violation of Federal or state consumer financial law. To determine the risk to consumers, the risk assessment should consider the interaction of two broad sets of factors: (1) inherent risks in a particular line of business or the entity as a whole and (2) the quality of controls implemented by the entity to manage and mitigate those risks. 

Let’s start with inherent risk. Inherent risk includes factors that increase the potential for unfair, deceptive, or abusive acts or practices, discrimination, or violations of other Federal consumer financial laws. It also includes factors that increase compliance management challenges and thereby increase the risk of various legal and regulatory violations. 

Then there’s the quality of risk controls, which includes factors related to managing and mitigating specific inherent risks and the strength of an entity’s overall Compliance Management System (“CMS”). 

The most affordable and quickest means to check the viability of your Compliance Management System is our CMS Tune-up, a mini-audit that reviews the CMS, provides recommendations, and issues a risk rating. I note that your company is already on our list to conduct a CMS Tune-up in August. I think this is a prudent decision. If others want more information about the CMS Tune-up, contact us HERE

In my view, there are six factors to include in a risk assessment. 

The six factors are penalties, litigation, examiner scrutiny, new areas, internal violations, and exam violations. 

Let’s take a brief look at each of these factors. 

Penalties 

The regulatory agencies can impose additional penalties for violations of regulations, notwithstanding the general penalties they can impose as part of their broad enforcement powers. Most of these penalties are criminal and civil monetary penalties, but one exception is the Community Reinvestment Act, where the penalty for violation can involve the denial of bank applications for expansion, merger, and so forth; or the savings account/MMDA transaction limitations, where the penalty can involve the recalculation of reserve requirements. Within these areas, the penalties for noncompliance can be severe. The Bank Secrecy Act and Regulation O are two such areas. As another example, finance charge and annual percentage rate (APR) calculation violations under Regulation Z require mandatory reimbursement. 

Litigation 

There is often a significant risk of customer litigation. Within these areas, violations can lead to substantial risks of civil liability to customers. In many cases, the law provides for additional damages beyond those suffered by the customer, such as specific, additional monetary damages, attorneys’ fees, class action status, and so forth. For instance, violation of the right of rescission under Regulation Z can lead to customer litigation, resulting in the loss of the security interest and income from the loan. 

Examiner Scrutiny 

Numerous regulatory areas receive increased scrutiny during regulatory examinations. For example, BSA and Regulation O receive increased scrutiny during almost every examination. Also, compliance with flood insurance requirements is an area that is currently experiencing increased scrutiny by some agencies in some areas. 

New Areas 

There are relatively new compliance requirements. Also, there are areas in which the financial institution only recently introduced products that require compliance with a particular existing or new requirement. To assist you in identifying new compliance requirements, your matrix should include the effective date for any new regulations. 

Internal Violations

 These are areas where violations were found as a part of the financial institution’s own internal compliance monitoring.

Exam violations 

These are areas in which violations were found during a previous regulatory examination. 

Let’s move on to the risk rating itself!

Friday, December 4, 2020

Guidance versus Regulations

QUESTION
We appreciate your weekly FAQs. It is printed and handed out to staff in our Monday compliance meetings. Thank you for your dedication to our compliance needs.

In one of our meetings recently, there was quite a bit of discussion about the difference between regulations and guidance. The consensus was that regulations must be followed, but guidance is not required to be followed.

The thinking was that regulatory guidance would become regulations, so we should just follow them anyway.

Our question is, what’s the difference between regulations and guidance?

ANSWER
First and foremost, thank you for reading our FAQs. We have provided this labor of love for many years because of our philosophy to serve our clients and the mortgage community more broadly. In fact, our very motto – Creating a Culture of Compliance® – is reflective of our commitment and vision.

Your question is a good one. Regulations and guidance are not synonyms, but they are closely aligned. I will offer some insight into the difference by considering a current regulatory proposal. 

The Federal Reserve, Consumer Financial Protection Bureau, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency are asking for comment on a proposal that outlines and confirms the agencies' use of supervisory guidance for regulated institutions.

The proposal would codify the 2018 Interagency Statement Clarifying the Role of Supervisory Guidance (“2018 Statement”) that clarified the differences between regulations and guidance. The 2018 Statement reiterated well-established law by stating that, unlike a law or regulation, supervisory guidance does not have the force and effect of law. 

The agencies do not take enforcement actions or issue supervisory criticisms based on noncompliance with supervisory guidance. Instead, supervisory guidance outlines supervisory expectations and priorities or articulates views regarding appropriate practices for a given subject area.

Thus, in contrast to supervisory guidance, regulations do have the force and effect of law, and enforcement actions can be taken if regulated institutions violate the regulations. Regulations are also generally required to go through a notice and comment process.

To amplify this outline further, the agencies had issued the 2018 Statement on September 11, 2018, to explain the role of supervisory guidance and describe the agencies’ approach to supervisory guidance. An interesting feature of the 2018 Statement was its view that agencies issue various supervisory guidance types to their respective supervised institutions, including, but not limited to, interagency statements, advisories, bulletins, and policy statements, questions and answers, and frequently asked questions.

To be clear, supervisory guidance outlines the agencies’ supervisory expectations or priorities and articulates the agencies’ general views regarding appropriate practices for a given subject area. Supervisory guidance often provides examples of practices that mitigate risks or that the agencies generally consider to be consistent with safety and soundness standards or other applicable laws and regulations, including those designed to protect consumers.

It is also worth noting that the agencies stated in the 2018 Statement that supervised institutions sometimes request supervisory guidance. That guidance is essential to providing clarity to these institutions in a transparent way that ensures consistency in the supervisory approach.

Here’s the important takeaway: the 2018 Statement restates existing law and reaffirms the agencies’ understanding that supervisory guidance does not create binding, enforceable legal obligations. Furthermore, it reaffirms that the agencies do not issue supervisory criticisms for violations of supervisory guidance, and the appropriate use of supervisory guidance by the agencies.

Specifically, in this particular interagency statement, the agencies also expressed their intention to (1) limit the use of numerical thresholds in guidance; (2) reduce the issuance of multiple supervisory guidance on the same topic; (3) continue efforts to make the role of supervisory guidance clear in communications to examiners and supervised institutions; and (4) encourage supervised institutions to discuss their concerns about supervisory guidance with their appropriate agency contact.

Financial institutions must use regulatory guidance constructively to be prepared for regulatory scrutiny. Implementing guidance provides certainty and transparency to financial institutions. 

In effect, by following regulatory guidance, a financial institution anticipates the agencies’ supervisory criticisms relating to identifying the practices, operations, financial conditions, or other matters that could have a negative effect on the safety and soundness of the financial institution; could cause harm to consumers; or could cause violations of laws, regulations, final agency orders, or other legally enforceable conditions.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group