LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Self-Assessments. Show all posts
Showing posts with label Self-Assessments. Show all posts

Tuesday, December 17, 2024

Policy and Procedure links to Change Management

QUESTION 

We need an overhaul of our policies and procedures. Our company merged with another company, and our policies are different in many ways, from the text itself to the format. It is tough enough to have the merging of two cultures, we are now banging into one another over what policy applies and what procedures to follow. 

As the Compliance Officer and General Counsel, I am involved in harmonizing these documents, and the task is almost overwhelming. Every project impacts our policies. We have had to update our Change Management policy five times in the last six months just to adapt to the merging of documents. 

What I need is some kind of checklist that I can get stakeholders to agree to or at least accept by consensus. I consulted with experts in policy development, but it was frustrating. If they knew the regulatory requirements, they disagreed on the text, and if they knew the formatting requirements, they disagreed on the best format. They seem oblivious to the implications of Change Management. 

A member of our Board of Directors referred me to you. She believes you can help resolve these issues. So, I'm writing you for guidance. I also want to schedule a call with you to discuss your services. 

Can you help us understand how our policies and procedures are linked to our Change Management requirements? 

SOLUTIONS 

·       Customized Compliance Library

·       Policies Tune-up®

·       CMS Tune-up®

RESPONSE 

There are a few aspects to your circumstances. Not only do you mention the issue of merging policies and procedures resulting from a merger and the impact on projects, but you also note how many times you have had to update your Change Management requirements because of this debacle. We have handled and resolved matters such as yours many times. Your situation often happens. 

Many clients come to us for our customized compliance library. Since you are new to our services, it is worth knowing that we pioneered the effective drafting and implementation of a compliance library. So, you have come to the right place! I'm sure we can help! 

Let's start with Change Management. What is it? Essentially, it is the governing methodology that provides an infrastructure to support and sustain change throughout multiple phases in your financial institution while focusing on achieving a set of defined and desired business results. 

There is a good reason why you mention Change Management. That is because your policies and procedures are an intrinsic part of it. 

To clarify, a financial institution is under pressure from regulators, borrowers, shareholders, and investors to improve its business continuously. These pressures lead to companies initiating a wide range of company projects, including small, targeted updates, process enhancements, large, complex system implementations, and major business process re-engineering initiatives. Thus, an institution's ability to standardize its process and project management practices mitigates the risk of project failures and maximizes the value delivered to its organizational processes. 

Therefore, you have hit on the two primary purposes of Change Management: 

·       Process Management, and

·       Project Management. 

I am going to offer a way to think about Process Management and Project Management and how they link to Change Management. Merged policies and procedures will be given their due consideration. 

BUILDING A CHANGE MANAGEMENT FRAMEWORK 

Before understanding the operational framework of Change Management, its two primary purposes, and its derivative structures, such as policies and procedures, you must determine:

1. Define and describe what changes will be implemented.

2. How to coordinate the input from stakeholders.

3. What will constitute a formal change plan.

4. The resources and data that will be used and available.

5. The overall communication strategy at all operational levels.

6. A review of budget risks associated with change. 

CHANGE MANAGEMENT METHODOLOGY 

As the company's Compliance Officer, it would be your responsibility to establish controls to ensure a viable Change Management methodology is applied consistently between individuals and work groups. 

I recommend that your methodology contain the following guidelines. 

·     Determination of business ownership and governance responsibilities.

·     An impact analysis prior to the implementation of process changes.

·     Communication of new or revised processes to impacted business units or areas.

·     A process that ensures policies, procedures, and processes are updated to reflect remediated control deficiencies.

·     A procedure for approving new or revised processes.

·     A procedure for managing and introducing process revisions.

·     The identification of training needs based on creating or updating policies and procedures.

·     The validation of new or revised policies and procedures prior to implementation. 

PROCESS MANAGEMENT 

Once the Change Management framework is completed, you can move on to interfacing them with Process Management and Project Management.

The primary purpose of process management is to group specific operational components for implementing interlocking institutional bases and contributing to an institution's activities. This means, in theory and practice, the setting up of the requirements needed to effectuate change throughout the company. 

Our reviews of Process Management have shown that there are at least eight structures needed for executing efficient institutional activities. This is a list that we use to ensure the stability of Process Management.

 

1.     There should be a centralized repository for all policies and procedures. In our work, we keep our clients' Masters in an encrypted, secure extranet.

 

2.     A dedicated group that oversees changes related to processes, systems, and policies. You must have a point person or persons involved in oversight. The contact information should be in writing and ratified by the board and/or management.

 

3.     Policies, procedures, and support documents are "mission-critical" key processes. They must be continually evaluated and updated with current revisions.

 

4.     All policies, procedures, and support documents should evaluated for completeness and accuracy. Inactive, dormant, and inoperative policies should be formally retired. Abeyant and suspended policies should be mothballed.

 

5.     Quality assurance reviews should be conducted periodically to ensure the actual performance of employee work processes is consistent with process flows and descriptions.

 

6.     The oversight team should draft a change management manual or tool to manage and track process updates. The board or management must ratify the manual.

 

7.     A standardized template should be modeled for policies and procedures throughout the organization.


8.     Be sure that the appropriate staff responsible for change management processes is well-trained or has the necessary skills to perform these functions.

PROJECT MANAGEMENT 

There are many ways and means to build project management structures. We have project managers who are credentialed in this task; however, you can create basic elements that interface with the Change Management framework. 

You don't need to be overwhelmed by this undertaking. Everything can be accomplished gradually so long as you have a logistical approach. A generic outline of project management should contain at least the following components: 

·       A project management manual or tool to track and manage projects.

·       Referenced policies, procedures, and systems affected by a project.

·       Project management tracking reports.

·       Centralization of project activities in an oversight group.

·       Training of relevant staff for project participation and management.

·       Periodic project tracking reports are communicated to stakeholders.

·       Updates to the inventory of projects subject to tracking. 

I also recommend that your project management methodology include: 

·       Communication of project goals and status.

·       Milestone reviews and approvals.

·       Identification and mitigation of project risk.

·       Identifying stakeholders, including their operational relevance.

·       Documenting procedures for change control documentation.

·       An escalation process for projects where there are tracking errors.

·       Log of activities with a column for remediation information and implementation. 


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Wednesday, December 11, 2024

Fannie’s MORA Review: Internal Audits

QUESTION 

Although approved by Fannie Mae, we have not set up an internal audit schedule. This issue came up in a recent discussion with our Fannie representative. They want us to be ready for the MORA audit, and the audit schedule is going to be required. We haven’t even done an internal audit yet. This got us thinking about what we don’t know for preparing for the MORA visit. 

We know your company is well-known for independent risk assessments and self-evaluations, which are called the Compliance Tune-up®. I spoke to one of your Directors this morning about several of them that could help us get prepared for the Fannie audit. We need to know which policies and procedures will be reviewed, and we need to know so much more. Our first MORA audit is coming soon. So, we’re somewhat intimidated. 

I am the compliance manager. I have never handled a MORA audit before. And I have never been involved in an internal audit. I need some guidance about what Fannie expects for internal audits and a “heads-up” for their requirements.


·       What are Fannie’s expectations for internal audits?

 

·       Can you please provide a “heads-up” for the internal audit requirements?


·       What have you found that shows your clients were not prepared for an internal audit? 

SOLUTION 

Compliance Tune-up® List

MORA Tune-up® Fannie's Mortgage Origination Risk Assessment (MORA)

CMS Tune-up® Compliance Management System

RESPONSE 

Anyone who has an interest in our Compliance Tune-up®, in general, or our MORA Tune-up®, in particular, can contact us here. The Compliance Tune-up® is an extensive series of mini-audits that targets departments, functions, and regulations. It is a self-identification and risk assessment review that complies with the second line of defense.[i] The review provides a report and risk rating. It shows the strengths and weaknesses of the area subject to review. 

Fannie Mae conducts regular reviews to evaluate seller/servicer compliance with its guidelines and assess operational risks. Reviews are conducted by a team that operates independently of the Business Account Management Solutions team. 

You will need to establish an independent internal audit function. During the MORA process, Fannie Mae examines the lender's internal audit plan and the latest independent internal audit. A financial institution may outsource its internal audit process; however, it remains responsible for the findings that show compliance (or lack thereof) with Fannie's requirements.

An internal audit is the central feature of the third line of defense. From Fannie’s perspective, management control is itself a function. Indeed, establishing a professional internal audit activity should be a governance requirement for all organizations. 

Management is supposed to rely on the internal audit to validate a financial institution’s governance, risk management, and control processes to help it achieve strategic, operational, financial, and compliance objectives. This compliance framework is meant to ensure a risk-based approach, and the internal audit function evaluates and improves the effectiveness, exigencies, and readiness of risk management, control, and governance processes. 

We believe the following outline provides the guardrails and requirements of an internal audit. It would be best if you considered them collectively so that you prepare adequately for the development of this function. In other words, don’t cut corners. Be sure you comply with all these criteria. 

Internal Audit Function: Guardrails and Requirements


·       Be sure that the internal audit manager is free from any responsibility over any business unit.

 

·       Be sure the internal audit is independent of all key functions of the loan origination and servicing processes.

 

·       Draft internal audit and management control procedures for evaluating and monitoring the overall quality of loan production.


·       Ensure that your organization chart shows that the internal audit function reports directly to the senior management and, if applicable, the Board of Directors. (By the way, we know from experience that Fannie will permit exceptions in situations in which the size of the organization is insufficient to support adequate resources to allow for the separation of these functions. In those situations, your audit plan must include the rationale for the lack of separation of controls in place to mitigate risks associated with the lack of separation of these functions.)


·       Be especially careful that internal audit lines of reporting reflect the independence of the audit process at all levels so that the activities are conducted in an unbiased manner and without compromises that may result from internal influences or conflicts of interest.


·       Be especially careful that the internal audit function does not share any reporting lines with the functional areas that it reviews.


·       Create a reliable and scaleable reporting procedure to ensure that the written findings provide methodologies that derive recommendations that management can use to accomplish actionable objectives through a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control, and governance processes. 

Adverse Findings and Required Document Preparation 

There are a few other things I would like you to consider. I’ll get to them in a moment. You had asked about how some clients show that they are not ready for an internal audit. By this point, I think we’ve seen just about everything there is to see about internal audit findings and preparation. However, most challenges can be overcome if you have robust plans. 

We have an extensive database of common findings from independent internal audits and Compliance Tune-up®. I have picked seven of them that I think are virtually non-negotiable. 

Adverse Findings


1)    There is no comprehensive written plan to direct the internal audit process across all loan manufacturing and servicing business functions.

 

2)    There is no internal audit function.


3)    MBS Trust compliance is not included in the internal audit review plan and testing.


4)    The internal audit process has not been initiated.


5)    There is no internal audit function that is independent of the business functions subject to review.


6)    An internal audit schedule has not been established to specify the areas of review, and there’s no timeframe for conducting them.


7)    The internal audit plan does not include all required components. 

Required Document Preparation 

Each financial institution differs and is unique in terms of size, products, services, complexity, risk profile, and business strategy. Keep that in mind as I outline the document preparation needed to be ready for a MORA review. You can tighten up preparation by using the appropriate Compliance Tune-up® tool, such as a MORA Tune-up® or a CMS Tune-up®. 

A Compliance Tune-up® report provides recommendations indicating what should be done now and in the future to ensure readiness, but you can’t undo mistakes of the past. Willingness to correct errors, however, is a sign of good management and governance. So, it would be best if you got ready immediately to prevent a lookback that discloses unmitigated adverse findings. 

·       Organization chart reflecting the internal audit department

·       Internal audit policies and procedures.

·       Current year’s testing schedule and internal audit plan.

·       Current year’s Compliance Tune-up®. (Second Line of Defense).       

·       Current year’s independent internal audit. (Third Line of Defense).

·       Ability to identify any significant findings for the past 12-month period.

·       Management and tracking reports for monitoring performance in operational areas. 

WordS to the Wise should be Sufficient! 

I stated above that there are a few other things I want you to consider. I list them in no order of importance because they are all equally important. Let’s group these remarks in the category of “words to the wise should be sufficient!” 

·       An internal audit plan should be risk-based, updated annually, and include a review of all controls and key functions in each origination and servicing department. 

·       Applying a risk rating for each key process area of the originations and servicing platforms is critical to implementing a continuous internal audit schedule. 

·       A second line of defense review, such as the Compliance Tune-up®, should be initiated for specific departments, functions, and regulations in anticipation of performing the internal audit. (This ensures that the internal audit, the third line of defense, may present accurate and reliable findings.) 

·       A process should be in place to define the scope and frequency of audits to be performed based on the specific risk rating for all key functions. (This ensures that the functions that represent the highest risk are audited on at least an annual basis.) 

·       An internal audit schedule should be in place, reflect current activity, and be reviewed on a regular basis to incorporate any emerging risks in operational areas. 

·       Adverse internal or external audit findings pertaining to key functions or regulatory compliance should be reviewed by the audit committee for remediation. 

·       An established framework for interaction between internal audit functions, business units, and management exists to ensure open communications regarding risk and control management, including the adoption and implementation of self-assessment methodologies.

 

Jonathan Foxx, Ph.D., MBA

Chairman & Managing Director

Lenders Compliance Group



[i] Three Lines of Defense in Effective Risk Management and Control, Institute of Internal Auditors (IIA), January 2013. The Lines of Defense (LOD) model assigns and coordinates risk and control responsibilities across business functions.

Thursday, June 13, 2024

CFPB’s Repeat Offender Registry – Part Two

QUESTION 

Last week, you published an article about the Repeat Offender rule. The questioner was pretty upset about it. But I am not upset about it. After all, if a company repeats violations, why shouldn’t the public know about it? 

I also run a mortgage lender, just like the other guy. I’m the President and CEO. My company is almost 30 years old. We’ve made it through upturns and downturns, and we’re positioned well for the next upturn. Along the way, we have had violations cited on banking audits. We corrected them and moved on. I can’t think of a single instance when the violation that we corrected got repeated. Not once has that happened. 

So, my view is different. Companies that make the same violations over and over again make it harder for companies like mine to be trusted by the public. I want a level playing field where my loan officers are able to provide our services without having to worry that a competitor is getting away with repeat violations. Repeat offenders are bad for business and mess with the public trust. 

I learned a lot from your article. I printed it out and sent it to my mortgage bankers association as well as all our employees. I want people to know that our company supports the Repeat Offender rule because it is good for business and strengthens the public trust. 

You ended last week’s article by saying that Part Two would further discuss other aspects of the Repeat Offender requirements. I look forward to reading it soon. 

What are other essential aspects of the Repeat Offender requirements? 

COMPLIANCE SOLUTION 

CMS Tune-up®

(Compliance Management System)

ANSWER 

I appreciate your message. The response to Part One was enormous. 

Clearly, this is a controversial subject. But, in a sense, it shouldn’t be. After all, analogously, if you obey the speed limit, it is not unreasonable to want others to follow the speed limit, too. Do you enjoy being tailgated? Are you entertained by cars swerving in and out of fast-moving traffic? Do you feel safe when somebody races past your car at 80 MPH in a 50 MPH zone? About 11% of Americans have had at least one speeding ticket.[i] Repeat driving offenses risk increased insurance fees, loss of a driver’s license (a privilege, not a right), a hazard to safety, destruction of property, and a threat to life.    

Why should some people get bent out of shape by calling a company that continues to violate banking laws a “repeat offender?” What else should it be called? If the term “recidivist” is a proxy, then go for it – use “recidivist.” Both terms infer a tendency to relapse, and "repeat offender," in particular, does seem to be associated with criminal behavior. It is quite a stretch to imply that mortgage companies that repeat offenses of legal and regulatory mandates are criminals. They are certainly not criminals. The problem is the terminology. Perhaps the CFPB can come up with a less objectionable term. 

A quick recap:

On Monday, June 3rd, the Consumer Financial Protection Bureau (“CFPB” or “Bureau”) issued a Final Rule[ii] (“Rule”) requiring nonbank consumer financial services companies to register court orders or government agency orders in a new Nonbank Registry (“Registry”). This Rule is the “Repeat Offender” registration requirement. The effective compliance date is September 16, 2024. 

In Part One, I outlined the following areas: 

·       Repeat Offender Unit; 

·       Risk Profile; 

·       Agency and Court Orders; 

·       Registration; and 

·       Attestation. 

In Part Two, I will discuss[iii] optional alternative registration, timing requirements, the written statement requirement, and when the registration requirement comes to an end. Also, I provide tables for the submission periods and registration protocols. 

Optional Alternative Registration Requirements 

The Rule provides a limited one-time, alternative registration option for covered orders that are published on the Nationwide Multistate Licensing System (NMLS) Consumer Access website.[iv] 

As a covered nonbank, you may alternatively choose to file a special one-time registration for NMLS-published covered orders that were not issued or obtained, at least in part, by the CFPB. By “covered orders,” the CFPB means court orders or government agency orders.[v] 

If the alternative option is chosen, the nonbank must submit certain required information. After such submission, the nonbank has no further obligations to register any changes to or expiration of the order or to file written statements with respect to that order (if applicable). 

The alternative option is not available for any order issued or obtained at least in part by the CFPB, regardless of whether it is published on the NMLS Consumer Access website. 

Timing Requirements 

The timing requirements are a little bit tricky, so stay with me as I elaborate on them. I suggest you work with a compliance professional to ensure the filing and timing requirements are adhered to meticulously. 

Initially, the Rule has a phased-in implementation. During the implementation submission period, nonbanks are categorized into three institutional types, as follows:

 1)    Larger Participant CFPB-Supervised Covered Nonbanks;

 

2)    Other CFPB-Supervised Covered Nonbanks (i.e., CFPB-supervised covered nonbanks that do not meet the definition of a larger participant under the CFPB’s regulations); and

 

3)    All Other Covered Nonbanks (i.e., covered nonbanks that the CFPB does not supervise).

 

For each category, the final rule provides a 90-day window for covered nonbanks to register all covered orders with effective dates from January 1, 2017, until the start of that implementation submission period.

 

The table below identifies registration submission periods based on the Rule’s effective date of September 16, 2024. 

Implementation Submission Periods[vi]

 

Covered Nonbank
Type
Registration
Submission Period
Registration
Deadline

Larger Participant CFPB-Supervised Covered Nonbanks

October 16, 2024
through
January 14, 2025

January 14, 2025

Other CFPB-Supervised Covered Nonbanks

January 14, 2025 
through
April 14, 2025

April 14, 2025

All Other Covered Nonbanks

April 14, 2025
through
July 14, 2025

July 14, 2025

Any dates that fall on a Saturday, Sunday, or Federal holiday should be converted to the next day that is not a Saturday, Sunday, or Federal holiday. Accordingly, the Bureau has adjusted the submission period dates, as listed above.

Two orders are subject to registration: orders that 

1.     Have an effective date from January 1, 2017, through the start of the nonbank’s submission period, and 

2.     For orders issued prior to September 16, 2024, the order remains effective as of September 16, 2024. 

Here’s how this works. I will use the institutional category two (above)—Other CFPB-Supervised Covered Nonbanks—to illustrate the protocol. It reflects the Bureau’s example.[vii] My protocol table shows how to determine the analysis. 

Protocol for Registration of Covered Orders - Example

 

Order Types
Order
Timeframe
Registration
Disposition

First Order

Order takes effect[viii] on January 1, 2016, and expires on January 1, 2026.

Do not register (effective January 1, 2016) because it takes effect before January 1, 2017.

Second Order

Order takes effect on January 1, 2017, and expires on October 30, 2025.

Register (effective January 1, 2017) because it takes effect on or after January 1, 2017 (and prior to the start of the applicable submission period) and remains in effect as of September 16, 2024.

Third Order

Order that becomes effective on January 1, 2025, and expires on January 1, 2031.

Register (effective January 1, 2025) because it takes effect on or after September 16, 2024, and prior to the start of the applicable submission period.

Note 1: Continue to comply with the ongoing registration requirements for these orders until they expire or are terminated.

Note 2: If a new order is issued and effective on or after the start date of the implementation submission period, follow the ongoing registration timing requirements.

 

Understanding the Ongoing Registration Timing Requirements 

After the start of a nonbank’s implementation submission period, it must begin complying with the Rule’s ongoing registration timing requirements to register new orders and submit changes or updates related to previously registered covered orders. 

The nonbank should access the CFPB’s Nonbank Registry and provide a registration submission within the identified 90-day window for each of the following events: 

1.     Within 90 days after the date of updates or changes to the nonbank’s identifying information or administrative information. 

2.     Within 90 days after the date of any amendments made to previously registered orders, including changes to submitted order information. 

3.     Within 90 days after the effective date of any new order(s) applicable to the nonbank (with effective dates on or after the start of the applicable implementation period). 

4.     Within 90 days after the effective date of termination or expiration, submit a revised filing of a previously registered covered order. 

Written Statement – Attestation 

In Part One, I discussed the annual filing requirement of the written statement. It is, in effect, an attestation.[ix] 

·       For CFPB-Supervised Covered Nonbanks, these written statements must be submitted annually on or before March 31 of each year. 

·       For Larger Participant CFPB-Supervised Covered Nonbanks that register by December 31, 2024, the first written statement submission is required by March 31, 2025. It would cover all applicable orders registered with an effective date from October 16, 2024 to December 31, 2024. 

·       For Other CFPB-Supervised Covered Nonbanks, the first written statement submission is required on March 31, 2026. It will cover all applicable orders registered with an effective date on or after the beginning of their implementation submission period, January 14, 2025 to December 31, 2025. 

As I pointed out in Part One, the written statement is where governance plays a role because the designated executive must provide: