LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Quality Assurance. Show all posts
Showing posts with label Quality Assurance. Show all posts

Thursday, October 2, 2025

Quality Control: Threat of Downsizing

QUESTION 

I am the manager of our quality control department. We do our own quality control and use an outside auditor. We originate high production and have multiple channels. And we are in 30 states. Our CEO told me that he wants to downsize my department and also pull production audits from the outside auditor. He says our defect ratios show we are doing well and don’t need to maintain quality control to the same extent. 

I tried to tell him that he is seeing the positive effect of quality control, and that downsizing it and removing the outside auditor will cause the defect ratio to worsen. If anything, he should be maintaining or even increasing my staff and external auditor because our production is rapidly increasing. Frankly, I couldn’t change his mind. 

So, I am appealing to you. Our CEO passes your articles out at almost every management meeting. He uses them as ways to encourage discussion. I want him to read your reply. I have been reading your articles for years, and I am familiar with your stance on maintaining a strong quality control department. 

How does mortgage quality control protect the lender? 

SOLUTIONS 

Quality Control Audits 

QC Tune-up 

ANSWER 

Your question comes as a surprise to me, since compliance in general and quality control in particular should be the very last departments to be downsized. If there are mitigating circumstances for the cutback, such as a substantial drop in production or a change in the company's configuration, then I suppose reducing quality control may be warranted. But, even then, it must be done carefully, slowly, judiciously, and with full awareness of any impact on investor due diligence and contractual requirements. 

Lenders Compliance Group offers quality control auditing. But, unlike most quality control companies that veered into mortgage compliance, morphing into a compliance firm, we began as a compliance firm and subsequently established a fully staffed quality control affiliate, carefully managed by an executive director, experienced personnel, compliance professionals, and attorneys. LCG Quality Control, our quality control auditing group, oversees the entire audit process, from the smallest to the largest production, and delivers reports in accordance with GSE and portfolio guidelines, pursuant to timing requirements. We know whereof we speak when it comes to quality control.  

MORE THAN JUST DEFECT RATIOS

Quality Control is far more than just maintaining defect ratios. Wherever you got that impression, get rid of it. You are putting your mortgage company at considerable risk, a risk that is so high that your company will likely implode in a matter of days if you fail to maintain the necessary departmental and auditing staff levels. Cut elsewhere, but do not cut the operational needs of quality control! 

Mortgage quality control (“QC”) protects lenders by mitigating financial risk through the identification and correction of process errors, ensuring compliance with regulations, and maintaining the quality of loan portfolios. This, in turn, prevents costly buybacks from investors, such as the GSEs, and reduces the likelihood of loan defaults. 

Indeed, QC is a component of the Second Line of Defense; in fact, its exact placement depends on the financial institution's structure, as QC functions can also be embedded within the First Line of Defense. The Second Line of Defense typically comprises risk management and compliance functions that provide oversight, develop policies, and monitor activities to ensure adherence to regulations and internal standards. Therefore, when a QC function is established within or aligned with these oversight departments, it serves as a "second-line control." 

QC is crucial for identifying and preventing errors; the specific placement of the QC function determines whether it serves as a First or Second Line of Defense. Regardless of its placement, QC plays a detective role in identifying issues after they occur and provides an early warning mechanism to management, thereby strengthening the overall control structure. 

Consider how quality control impacts the following risk categories. 

RISK MITIGATION 

Let’s start with mitigating risk. Two specific areas that QC impacts are default rates and loan buybacks. QC confirms that loans adhere to federal, state, local, and investor regulations (for instance, Fannie Mae guidelines), thereby avoiding penalties, legal issues, and breaches of contract.

Thursday, April 11, 2024

Policy Statement for Artificial Intelligence

QUESTION 

You have been writing about Artificial Intelligence since it became popular. Most of us in my company only have a superficial understanding of AI. As the Compliance Manager, I surveyed those who were using it. It turns out that it’s only used in chats and searches. Meanwhile, our Board wants to introduce it into our loan origination procedures. 

Several companies are now pitching Senior Management and the Board regarding their AI capabilities. Frankly, I see a massive training, monitoring, and auditing future—and they have tasked me with writing a risk/benefit outline for using AI. They plan to use my outline as a scorecard to vet potential AI partners. 

To complicate matters, they want me to present the outline as a policy statement they can adopt. From it, full policies and procedures are supposed to be based on the policy statement. Overnight, I am supposed to be an expert in Artificial Intelligence involving mortgage banking! 

I need help drafting a risk/benefit outline and a policy statement. 

What AI benefits and risks can be listed in the outline? 

What elements constitute a policy statement about AI? 

COMPLIANCE SOLUTION 

Policies and Procedures 

ANSWER 

Virtually since the inception of the Artificial Intelligence (AI) craze, I have been writing and speaking on its pros and cons. Here are some articles. Although I see numerous benefits, I also see numerous risks. Do the benefits outweigh the risks? 

A new technology is often unpredictable with respect to its consequences. Currently, self-driving trucks are promoted as the future of delivery methods. As I write, about two dozen states specifically allow driverless operations of vehicles, and another 16 states have no regulations at all specific to “autonomous vehicles.” Only ten states place limits on autonomous vehicles.[i] 

Now, let's hold the self-driving trucks up to the light of the risks/benefits type thinking. I’m sure there are plenty of benefits, as is the case with new technologies, but the risks can be catastrophic in view of the fact that the livelihoods of human truckers are at stake. Long-haul truckers are estimated to lose at least 500,000 jobs. That amounts to a financial catastrophe for their families. Add in the maintenance and support staff, truck stop employees, and all their families, and the overall consequence is devastating on nearly every level – except it does provide benefits to the self-driving companies since their robotic trucks do not need to feed their families, can be readily replaced, and can drive 24 hours a day, 7 days a week. Millions of lives are impacted adversely. So, you tell me, what are the foreseeable consequences of new technology? Some consequences are “known-known.” The consequences of the self-driving truck are a known-known. 

Artificial intelligence has a few known-known consequences, and I will mention some of them. However, the vast area of the unknown consequences is not entirely apprehended at this early stage of its implementation. When drafting the risk outline and policy statement, I suggest you insert a proviso that the known-known is incomplete and the unknown vastly overwhelms the known. 

Regulators have expressed concern about how we use AI, so you need to be aware of the measures to take to ensure an understanding of its risks. I will provide a brief risk outline in the context of a policy statement because they cannot and should not be separate aspects of AI. Each policy statement must reflect a company's size, products, services, complexity, risk profile, and business strategy. My generic synopsis is not and is not meant to be comprehensive. 

RISK OUTLINE AND POLICY STATEMENT 

Flagging Unusual Transactions 

AI may identify potentially suspicious, anomalous, or outlier transactions (i.e., fraud detection and financial crime monitoring). This involves using different forms of data (i.e., emails and audio data – both structured[ii] and unstructured) to identify fraud or anomalous transactions with greater accuracy and timeliness. It also includes identifying transactions for the Bank Secrecy Act’s Anti-Money Laundering investigations, monitoring employees for improper practices, and detecting data anomalies. 

Personalization of Customer Services 

AI technologies, such as voice recognition and Natural Language Processing (NLP),[iii] may improve the customer experience and increase efficiency in allocating financial institution resources. One example is using chatbots[iv] to automate routine customer interactions, including account opening activities and general customer inquiries. AI is leveraged at call centers to process and triage customer calls to provide customized service. These technologies may be implemented to target marketing efforts better. 

Credit Decisions 

AI may inform credit decisions to enhance or supplement existing techniques. This application of AI may use traditional data or employ alternative data[v] (such as cash flow transactional information from a bank account). 

Risk Management 

AI may be used to augment risk management and control practices. For instance, AI may provide a resource to complement and provide a check on another, more traditional credit model. It may also enhance credit monitoring (including through early warning alerts), payment collections, loan restructuring and recovery, and loss forecasting. AI can assist internal audit and independent risk management functions to increase sample size (such as for testing), evaluate risk, and refer higher-risk issues to human analysts. AI can be used in liquidity risk management, for example, to enhance monitoring of market conditions or real estate collateral management. 

Textual Analysis 

Textual analysis refers to using NLP to handle unstructured data (generally text) and obtain insights from that data or improve existing processes' efficiency. Applications could include analysis of regulations, news flow, earnings reports, consumer complaints, analyst rating changes, and legal documents. 

Cybersecurity 

AI may be able to detect threats and malicious activity, reveal attackers, identify compromised systems, and support threat mitigation. For instance, it could monitor real-time investigation of potential attacks, use behavior-based detection to collect network metadata, flag and block new ransomware and other malicious attacks, identify compromised accounts and files involved in exfiltration, and conduct deep forensic analysis of malicious files. 

KNOWN RISKS 

Several risks are particular to AI: explainability, data usage, and dynamic updating. These are the top three known risks. 

Explainability 

“Explainability” refers to an AI approach using inputs to produce outputs. 

Some AI approaches can exhibit a “lack of explainability” for their overall functioning (sometimes referred to as “global explainability”) or how they arrive at an individual outcome in a given situation (sometimes referred to as “local explainability”). Lack of explainability can pose different challenges in different contexts. 

Lack of explainability can also inhibit management's understanding of the conceptual soundness of an AI approach (that is, the quality of the theory, design, methodology, data, developmental testing, and confirmation that an approach strategy is appropriate for the intended use) which can increase uncertainty around the AI approach's reliability, and increase risk when used in new contexts. 

And, importantly, lack of explainability can also inhibit independent review and audit and make compliance with laws and regulations, including consumer protection requirements, more challenging. 

Broader or More Intensive Data Usage 

Data plays a particularly important role in AI. 

AI algorithms identify patterns and correlations in training data without human context or intervention and then use that information to generate predictions or categorizations. Because the AI algorithm depends on the training data, an AI system generally reflects dataset limitations. As a result, AI may perpetuate or even amplify bias or inaccuracies inherent in the training data or make incorrect predictions if that data set is incomplete or non-representative. 

Dynamic Updating 

Some AI approaches can update on their own, sometimes without human interaction, often known as “dynamic updating.” 

Monitoring and tracking an AI approach that evolves independently can present challenges in review and validation, particularly when changes in external circumstances may cause inputs to vary materially from the original training data. An example would be changes relating to economic downturns and financial crises. 

Dynamic updating techniques can produce changes ranging from minor adjustments to existing model elements to the introduction of entirely new elements. 

POTENTIALS FOR AI 

AI has the potential to offer improved efficiency, enhanced performance, and cost reduction, as well as benefits to customers. It can identify relationships among variables that are not intuitive or not revealed by more traditional techniques. Furthermore, it may also help to process certain forms of information, such as text, that may be impractical or difficult to process using conventional methods. 

AI also facilitates processing significantly large and detailed datasets, both structured and unstructured, by identifying patterns or correlations that would be impracticable to ascertain otherwise. 

Other potential AI benefits include more accurate, lower-cost, and faster underwriting and expanded credit access for customers who may not have obtained credit under traditional credit underwriting approaches. AI applications may also enhance the ability to provide products and services with greater customization. 

ready for artificial intelligence? 

Does a financial institution have adequate processes in place to identify and manage the potential risks associated with AI? I don’t think so, certainly not at this early stage of AI development. 

Many of the risks associated with using AI are not unique to AI. For instance, using AI could result in operational vulnerabilities, such as internal process or control breakdowns, cyber threats, information technology lapses, risks associated with using third parties, and model risks, all of which could affect safety and soundness protocols. 

The use of AI could also create or increase consumer protection risks, such as risks of unlawful discrimination, unfair, deceptive, or abusive acts or practices, or privacy concerns. 

We may know some known-known risks and benefits. 

But we simply do not know the unknown consequences. 

And therein lies the test of time! 

As Banquo said to the witches in Macbeth:[vi] 

If you can look into the seeds of time,
and say which grain will grow and which will not,
speak then unto me.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] Ready or Not, Self-driving Semi-trucks are Coming to America’s Highways, Thadani, Trisha, March 31, 2024. The Washington Post

[ii] “Structured data” generally refers to a set of data that has been systematically organized or arranged.

[iii]  “Natural Language Processing” (“NLP”) generally refers to the use of computers to understand or analyze natural language text or speech.

[iv] The term “chatbot” generally refers to a software application used to conduct an on-line chat conversation via text or text-to-speech, in lieu of providing direct contact with a live human agent.

[v] “Alternative data” means information not typically found in the consumer's credit files of the nationwide consumer reporting agencies or customarily provided by consumers as part of applications for credit.

[vi] Macbeth, Act 1, Scene 3

Thursday, August 17, 2023

Servicing Quality Control: System and Procedures

QUESTION 

We are a mortgage lender in the Midwest. We were doing portfolio retention through a servicer, but now we are bringing servicing in-house and doing our own servicing. 

The plan is to launch the new servicing department in the next ninety days. We need a full complement of servicing policies and procedures. 

In addition, we need to know about the system requirements for servicing quality control and the basic servicing quality control procedures. 

Your firm provides a servicing policies and procedures library, so we hoped you could provide the information we need. Please note we contacted your office recently for assistance. 

What are the system requirements for quality control servicing? 

What are some quality control procedures involved in servicing? 

ANSWER 

We provide a policies and procedures compliance library for servicing (as well as one for mortgage loan originations). The compliance library is customized to your servicing platform. And we’ll maintain it for you. 

As a servicer, you must have fully documented, written policies and procedures that address all aspects of mortgage servicing. If you want to contact me directly, I would be glad to discuss your needs in detail. Contact me here. 

With respect to system requirements, I advise thinking ahead about the quality control system needs because how your system operates will determine its effectiveness and flexibility. 

There are numerous investor and legal requirements in each jurisdiction where you operate as a servicer. These must be well-documented and provide for a review of the following:

 

·       aspects of the delinquent mortgage loan servicing system;

 

·       the system to control and monitor bankruptcy proceedings; and

 

·       the foreclosure monitoring system.

The servicer must develop a quality control program addressing delinquency management and default prevention. Proper staffing and training are mandatory. And you must implement a strong business continuity and disaster recovery program. 

The servicer must audit quality control regularly at the loan level. (If you are subservicing, you must audit the servicer’s process at the loan level.) For loan level servicing quality control audits, contact us here. 

The servicer must implement certain primary system requirements for servicing quality control, as follows:

 

1.   Conduct regular testing of compliance with applicable laws in all jurisdictions in which it operates;

 

2.   Regularly review and assess the adequacy of internal controls;

 

3.   Keep a record of any activity under the applicable internal systems;

 

4.   Report comprehensive results of all testing to the senior management;

 

5.   Promptly take appropriate corrective action if these systems identify a problem area; and

 

6.   Make comprehensive testing results and any evidence of corrections available for review upon the investor’s request. 

With respect to servicing quality control procedures, there are a few themes that run throughout the written policies and procedures. As a servicer, you must monitor your compliance with the investor’s requirements and federal and state mandates through regular quality control procedures that are ratified, established, conducted, and monitored. 

The servicer must maintain adequate quality control procedures and systems. Implementing a self-assessment for various operational functions should be considered. At a high level, the servicer must be able to:

 

·      ensure that the mortgage loans are serviced under sound mortgage banking and accounting principles and in compliance with investor guidelines;

 

·      guard against misrepresentation and dishonest, fraudulent, or negligent acts by any parties involved in the mortgage loan servicing process;

 

·      protect against errors and omissions by officers, employees, or other authorized persons;

 

·      verify and audit the accuracy of the loan adjustment (i.e., ARM adjustments) and facilitation of timely responses to errors identified by the borrower, the servicer’s regulatory agency, or the investor; and

 

·      protect the investor’s investment in the security properties. 

Failure to maintain adequate servicing quality control standards may result in a servicer being in breach of its contact with investors. 

Furthermore, I urge you to perform annual quality control tests to ensure that all outsourcing firms and third-party vendors fully comply with investor guidelines and federal and state requirements. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, November 18, 2021

Pre-Funding & Post-Closing Quality Control – Discretionary Audits

QUESTION
We conduct pre-funding, post-closing, and discretionary quality control reviews. 

In an evaluation done in 2016, it was found that the quality control department had many auditing issues. The people who did the assessment are no longer with the company. Supposedly, the problems were corrected. 

However, now Fannie has come in and criticized us for our quality control sampling methodologies. We were cited for defective discretionary audits, in addition to other adverse results. 

So, now we’re writing you for some guidance. 

What are the sampling methodologies for pre-funding and post-closing quality control in terms of discretionary audits? 

ANSWER
Your question focuses on sampling strategies, so my response will concentrate on them. If you haven’t done an annual review of the rationale for selecting pre-funding and post-closing loans, it comes as no surprise that Fannie became concerned. Perhaps there was no attempt to evaluate trigger points, production volume changes, market conditions, and responsive procedures. Maybe your quality control department or your quality control vendor is insufficiently resourced to mitigate risk. 

Notwithstanding an annual review, you should be checking your quality control and loss mitigation risk factors at least quarterly. Reporting the QC findings to management should be ongoing. 

One of the mini-audits in our Compliance Tune-up series is the QC Tune-up. It is popular because it determines if you adequately meet GSE and investor guidelines, a mandate that virtually all mortgage loan originating entities must implement, excluding certain self-generated portfolio loan products. 

Click the link for information about the QC Tune-up. 

Let’s be clear about Fannie’s expectations with regard to selection sampling. There are two methodologies: (1) Random Sampling and (2) Discretionary Sampling. The random sample provides a high-level view of loan quality. The discretionary sample is a subset of loans within the total population that focuses on specific characteristics, such as high-risk loans, adverse findings, and so forth. 

Pre-Funding Selection

For pre-funding, you might be interested to know that Fannie does not have a minimum required sample size for pre-funding QC, nor does it require random selections for loans sampled in the pre-funding QC review. However, Fannie does require that the pre-funding sample size be relevant to the loan production volume. 

The pre-funding selection sampling is discretionary, and there are two types of discretionary methodologies: Full and Component. Whether Full or Component, you will want to incorporate them into your Clear to Close procedures. 

The full file selection is usually conducted on only a part of the loan population. In practice, there are multiple risk factors in a population of loans, so the full file selection leads to increasing certainty on the loan quality. Before our firm conducts a pre-funding audit, many clients first have selected specific characteristics, such as unique underwriting guidelines and documentation requirements or newly hired loan officers, processors, underwriters, or new third-party originators. Some clients focus on loans with multiple layers of credit risk, such as high loan-to-value ratios, low credit scores, and high debt-to-income ratios (DTI). 

The component file selection focuses on a particular element(s) of the loan file itself that has the potential for elevated risk or loan characteristics identified with defects in a post-closing QC review. For instance, we have clients who target loans with a higher risk profile, focusing on likely areas that impact eligibility (i.e., higher DTIs, where, say, an undisclosed liability could affect eligibility). 

Sometimes, a client will select on the component file basis to validate succinct procedures, such as loans that evinced process failures identified in the post-closing random sample (i.e., Form 4506-C execution rates). Another validation may be on internal exception policies and procedures to confirm all requirements are consistently followed. We’ve had clients select to validate the accuracy of loan quality tools used by their organization (i.e., fraud monitoring tools or undisclosed debt monitoring). 

Many clients select loans on the component file basis that contain top trending defects identified in their post-closing random sample (i.e., gift funds or excessive interested party contributions). The goal is to test internal controls around each defect and the effectiveness of the corrective action plans and remediation efforts. 

Post-Closing Selection

Ideally, pre-funding and post-closing are intrinsically interfaced. But post-closing QC takes us to the entirety of the loan transaction, including closing and legal documents that are not available during the pre-funding reviews. Most lenders choose random 10% sampling, though some go onto the statistical sampling method for the post-closing QC selection process. Loan quality results are reflective of the sampling method chosen. 

Lenders generally use the random 10% sampling method with an annual production of 3,500 or fewer loans. The statistical sampling method is generally advantageous for lenders with an annual production of more than 3,500 loans. 

Keeping it simple, lenders prefer the 10% sample selection because there is no need to manage a statistical calculation process. Also, it does not require a periodic evaluation to ensure the sample size is valid. However, the statistical sample selection produces statistically valid results that can be used to extrapolate loan quality conclusions. In that regard, for lenders with a consistent defect rate, it produces a predictable monthly sample that does not vary due to large swings in production volume. 

Whether 10% random or statistical, a full file review must be completed on all loans selected for the post-closing QC process, with reverifications on all the data relied upon to qualify the borrower. In addition, all selections require a comprehensive collateral risk assessment of the appraisal used to support the value of the subject property. 

Discretionary Audits

Because Fannie cited you for “defective discretionary audits,” I will provide a few extra guidelines for discretionary reviews. Keep in mind that discretionary selections allow you to optimize the reviews and target certain loan features (i.e., high-risk loan characteristics) identified in the pre-funding and post-closing random selections. This is why I mentioned the importance of regularly reviewing the selection criteria to ensure you effectively manage risk and your QC resources. Always keep the risk factors current! 

To recapitulate, discretionary reviews may be full file reviews or targeted component reviews, which should allow you to increase the overall number of reviews or the ability to evaluate the risks. 

Full file reviews require reverification of all components, whereas targeted reviews allow for reverification of only those elements being audited. In addition, targeted or component reviews are an effective way to narrow in on a particular risk element, product, or process within the loan origination process without completing a full file review. 

Breaking this down further, there are two types of sampling methods used, one type for full file reviews and the other for component file reviews. 

You would want to use the full file sampling method when selecting loans to review new hires, new products, or newly implemented processes. In this context, use discretionary reviews to ensure at least one loan from each third-party originator is pulled for a review annually. 

Selections should be based on those risk attributes that are identified as top trending defects from pre-funding and investor review results. The goal is to analyze the root causes when developing action plans to prevent future defects from occurring or test the effectiveness of an implemented corrective action. 

The component file review provides an opportunity to sample loans with known risks. For instance, the component or targeted review allows, among other things, for the ability to ensure the borrower was employed at the time of closing, the income used to qualify was accurately calculated, the assets were adequately documented, and property eligibility and validation of data were supportive of the appraised value. If there are defects in the foregoing criteria, the component file review can identify a rationale for needing a full file selection. 

Click the links for information about quality control audits and the QC Tune-up. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, October 25, 2018

Property Inspection Waivers

QUESTION       
We have a loan in which the FNMA DU Findings indicated the subject is eligible for a Property Inspection Waiver. The Approve/Eligible results were achieved prior to a hurricane and declaration by the Federal Emergency Management Agency (FEMA) that the county where the subject property resides has been declared a natural disaster. The property did not sustain any damage due to the natural disaster, as evidenced by the consumer and a drive-by inspection by the Loan Officer. Can we move forward with the closing utilizing the PIW?

ANSWER
Sadly, the answer is no. Once the natural disaster has occurred, FNMA revokes offers of the Property Inspection Waiver ("PIV"). They do so by following the declared areas as set forth by FEMA. If the loan has not closed and funded prior to the occurrence and is located in the disaster-impacted area, FNMA will only accept the loan for delivery if a full appraisal is prepared after the disaster occurred to ensure it has not been damaged by fire, wind, falling or rising water, or other causes of loss and destruction. If a property is located in a condo or co-op project, both the condition of the unit and the condition of the building in which the unit is located must be assessed. Loan case files must be resubmitted to DU for refreshed AUS results.

In the case where the loan has closed but has not been delivered to FNMA, the lender must determine if the condition of the property has materially changed since the note date. The lender may exercise the appraisal waiver if the condition has not materially changed. 

In any event, the lender is expected to make prudent and reasonable actions to determine whether the conditions of the property may have materially changed. The lender is ultimately responsible for determining if an inspection of the property and/or a new appraisal is necessary to supports its representations.

Lenders should use the following criteria when determining if the mortgage loan can be delivered to Fannie Mae -
  • If the property has been damaged and the damage does not affect the safety, soundness, or structural integrity of the property and the repair items are covered by insurance, the lender may deliver the mortgage to Fannie Mae. In these circumstances, the lender must obtain documentation of the professional estimates of the repair costs and must ensure that sufficient insurance proceeds are available for the borrower's benefit to guarantee the completion of the repairs. 
  • If the property was damaged and the damage is uninsured or the damage affects the safety, soundness, or structural integrity of the property, the property must be repaired before the mortgage loan is delivered to Fannie Mae.
  • FNMA DU may not be current in relation to disaster-affected areas and could return allowable PIW AUS results. The lender, again, is responsible for determining if the subject property has been affected and how best to support and defend the collateral supporting the mortgage loan.


Brandy George, Six Sigma
Director/Underwriting Operations Compliance
Executive Director/LCG Quality Control

Thursday, March 30, 2017

Oversight: Three Lines of Defense

QUESTION
I’ve heard many different things about oversight of banks, non-banks and their related vendors. Some say it should be done, others say it isn’t that important. Can you tell me if there are any requirements regarding oversight and what they say?

ANSWER
We have noted over the last few years that the Federal Regulators refer to the Three Lines of Defense for oversight execution. Not only do they verbalize it, but this same verbiage can also be found on many of their First Day Letters.

These are as follows:

1st Line of Defense
At the business line level, Quality Assurance of business processes must be performed on a monthly basis. For their vendors, the business should also be completing scorecards on a monthly basis, all rolled up to management and into the 2nd line of defense.

2nd Line of Defense
This refers to both:

  1. Corporate Quality Control (not the same as Quality Assurance) that audits by a selection of loans through Statistically Valid Sampling or Stratified Sampling, and against GSE and FHA guidelines and best practices; and,
  2. Regulatory Compliance Audit, which compares the line of business work product execution and vendor management with the actual governing laws. These two groups have to perform testing independently of the business.

These audits and their findings must report through senior management, with all issues tracked by the business and second line for oversight until the remediation is complete.

3rd Line of Defense
This refers to the Internal Audit Structure that reports directly to the Board of Directors or to the highest level of senior management. This is totally independent of all other lines of defense. This group reviews everything bank-wide, including the first two lines of defense, and all processes of the business, end to end, the organizational structure, vendor and ensures remediation takes place on all that they discover.  

Michelle Leigh
Director/Internal Audits and Controls
Lenders Compliance Group
Executive Director
Servicers Compliance Group