LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Service Provider. Show all posts
Showing posts with label Service Provider. Show all posts

Thursday, May 16, 2024

Regulatory Mandate: Third-Party Risk Management

QUESTION 

I am the Compliance Manager of a bank. We have a mortgage banking platform. I handle our legal and regulatory compliance. Our new Chief Risk Officer wants to review our Third-Party Risk Management policy and procedures. The problem is that we do not have such a policy and procedures. 

We have vendor management procedures, which our regulator has accepted. Like me, the CRO is an attorney but he can’t fathom how we could have functioned for so long without this policy, irrespective of the regulator’s evaluation. I respect his view, and he has discussed case law and regulatory requirements with me. But, the fact is, we simply have never created a comprehensive policy just for third-party risk management. 

I understand now that a policy for Third-Party Risk Management is an essential requirement that must be drafted and ratified by our Board. The policy must extend to other banks and nonbanks with which we do business. We need some guidance in drafting this policy. The CRO follows your articles, and he asked me to write to you. I have subscribed and encouraged our staff to subscribe. 

What are some key features of a policy focused on Third-Party Risk Management? 

COMPLIANCE SOLUTION 

TPRM Tune-up®

Third-Party Risk Management

Policy and Procedures 

ANSWER 

Thank you for subscribing, and I appreciate your Chief Risk Officer reading our articles. We have been publishing these articles for many years, and it is humbling when our subscribers express their gratitude. 

Our research of public enforcement actions shows that approximately 25% of them - that’s one in four enforcement actions! - against banks and nonbanks have specifically noted deficiencies in how the target institution managed third-party service provider risks. 

If any financial institution does not have a Third-Party Risk Management policy and procedures, it is surely currying legal and regulatory risk. Your CRO is correct! 

One other point before I proceed. When a company official tells me that their regulator has never mentioned a particular regulatory violation, though it is a regulatory violation, and thus they intimate that what they’re doing must be ‘acceptable to the regulator,’ the alarms go off. If an institution wants to wait for a regulator to find its policies skimpy, defective, sketchy, inadequate, incomplete, fragmentary, insufficient, and deficient, it will find itself in the midst of a very unpleasant, belated attempt at remediation and possibly even an administrative action. 

And remember to implement the procedures and monitor the implementation. A bank examiner will not only review the policy but also determine if the procedures are implemented. 

_____________________________________________________________ 

TPRM Tune-up® 

When we conduct our TPRM Tune-up®, which is a review of a company’s third-party risk management structure, we work with a set of audit tools that help us evaluate regulatory compliance, offer recommendations, and provide a risk rating. The TPRM Tune-up® is often in demand because third-party risk management is central to safety and soundness criteria. Contact us here, and we’ll send you the presentation.  

_____________________________________________________________ 

Board and Management Responsibility 

Financial institutions are still ultimately responsible for managing their third-party service provider relationships, activities, and associated risks. They must ultimately ensure that all of their operations, in-house or outsourced, are conducted safely and soundly and in compliance with applicable legal and regulatory requirements, including consumer protection and financial crimes laws and regulations, just as if the institution were performing the activities itself. 

Regulators look to the company’s Board of Directors as ultimately responsible for providing oversight for third-party risk management and holding management accountable for its role. Management is responsible for developing and implementing third-party risk management policies, procedures, and practices commensurate with the institution’s risk appetite and the level of risk and complexity of its third-party relationships. Internal controls, independent reviews, and documentation are critical components. 

Third-Party Risk Management POLICY 

There are essential requirements for a Third-Party Risk Management policy (“TPRM Policy”). 

The TPRM policy has four principal requirements, which I will outline below. It will be up to you to draft the policy language. Each requirement can have its section and subsections. I will offer some guidance to help with your considerations. 

The four TRPM Policy requirements can be elucidated as follows: 

1.       Risk Management 

2.       Third-Party Relationship Life Cycle 

3.       Governance 

4.       Appendix 

TPRM Policy Sections 

1. Risk Management 

Not all third-party relationships present the same level of risk. Indeed, not all such relationships require the same level of oversight. However, a financial institution should apply rigorous risk management practices throughout the third-party relationship life cycle for third parties that support higher-risk activities, including critical activities. 

An institution may adjust and update its third-party risk-management practices commensurate with its size, complexity, and risk profile by periodically analyzing the risks associated with each third-party relationship. It is important to involve knowledgeable and skilled staff in each stage of the risk management life cycle. 

Therefore, your company would apply risk management practices in different stages of the third-party relationship life cycle. For instance, an important initial step is identifying third-party relationships that support higher-risk activities, including critical activities. 

Generally, to determine if an activity is higher risk, a company would assess various factors, such as if the third party has access to sensitive data (including customer data), processes transactions, or provides essential technology and business services. 

2. Third-Party Relationship Life Cycle 

Effective third-party risk management generally follows a continuous life cycle for third-party relationships. There are five stages of the TPRM life cycle, all responsive to governance in terms of  Oversight and Accountability, Independent Reviews, and Documentation and Reporting. 

Here is an outline of the five stages of the TPRM life cycle. 

Stage 1: Planning 


Careful planning enables a community bank to consider potential risks in the proposed third-party relationship. Managing third-party relationships allows the company to evaluate the extent of risk management resources and practices for effective oversight of the proposed third-party relationship throughout the subsequent stages of the third-party relationship life cycle. 

Stage 2: Due Diligence (Selecting the Third Party) 


Due diligence is the process by which a company assesses, prior to entering into a third-party relationship, a particular third party’s ability to, among other things, perform the activity as expected, adhere to company policies, comply with all applicable laws and regulations, and conduct the activity in a safe and sound manner.

 

The guidelines to develop in the policy is a clear definition of effective due diligence. We define effective due diligence as assistance with the selection of capable and reliable third parties to perform activities for, through, or on behalf of the company. If the company cannot obtain desired due diligence information from the third party, it will have to consider alternative information, details, controls, and monitoring; otherwise, it should consider abandoning the use of the third party.

 

Conducting due diligence on third parties before selecting and entering into third-party relationships is an important part of sound risk management. It provides management with the information needed about potential third parties to determine if a relationship would help achieve an organization’s strategic and financial goals. The due diligence process also provides the banking organization with the information needed to evaluate whether it can appropriately identify, monitor, and control risks associated with the particular third-party relationship. 

Stage 3: Contract Negotiation

 

Before entering into a contractual relationship with a third party, an institution should consider contract provisions that meet its business objectives, regulatory obligations, and risk management policies and procedures. If a company has limited negotiating power, management needs to understand any resulting limitations and consequent risks. It comes down to risk tolerance, such as whether the contract can still meet the company’s needs, whether the contract would result in increased risk to the company, and whether residual risks are acceptable.

Stage 4: Monitoring 


Monitoring cannot be overemphasized when managing third-party risk. A company’s ongoing monitoring of the third party’s performance enables management to determine if the third party is performing as required for the duration of the contract. Our clients use the results of monitoring to use the derived information to adapt and refine their risk management practices.

 

There are three aspects of this stage in the life cycle, whereby monitoring:

 

1)   Confirms the quality and sustainability of a third party’s controls and ability to meet contractual obligations;

2)   Escalates significant issues or concerns (i.e., material or repeat audit findings, deterioration in financial condition, security breaches, data loss, service interruptions, compliance lapses, or other indicators of increased risk; and

3)   Responds to such significant issues or concerns when and where identified. 

Stage 5: Termination 


Ending a relationship with a third party occurs for a variety of reasons, such as expiration or breach of the contract, the third party’s failure to comply with applicable laws or regulations, or a desire to seek an alternate third party, bringing the activity in-house, or discontinuing the activity. It is important for management to terminate relationships efficiently, whether the activities are transitioned to another third party, brought in-house, or discontinued. 

3. Governance 

As I noted above, the life cycle is governed by tripartite activities: Oversight and Accountability, Independent Reviews, and Documentation and Reporting. Here are some tips for each activity. 


(A) Oversight and Accountability

 

The Board of Directors has ultimate responsibility for providing oversight for third-party risk management and holding management accountable. The management is responsible for developing and implementing third-party risk management policies, procedures, and practices commensurate with the company’s risk appetite and the level of risk and complexity of its third-party relationships.

 

(B) Independent Review

 

The company must conduct periodic independent reviews to assess the adequacy of its third-party risk management processes. An institution may use the results of independent reviews to determine whether and how to adjust its third-party risk management process, including its policies, reporting, resources, expertise, and controls.

 

(C) Documentation and Reporting

 

Documentation and reporting, key elements that assist those within or outside the company who conduct control activities, will vary among financial institutions depending on the risk and complexity of their third-party relationships.

4. Appendix 

Consider including an appendix that lists resources. The resources do not have to be comprehensive. Keep adding to the Appendix as you come across resources that help to manage third-party risk management. Of course, there are Acts, regulations, and rules. However, other sources of information may be available, particularly on specific topics.

The use of third parties, especially those using new technologies, may present elevated risks to a financial institution and its customers, including operational, compliance, and strategic risks. Importantly, the use of third parties does not diminish or remove the institution's responsibilities to ensure that activities are performed in a safe and sound manner and in compliance with applicable laws and regulations.

Request Information: TPRM Tune-up®.


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, August 25, 2022

Digital Marketing: Artificial Intelligence and Behavioral Analytics

QUESTION 

Our company has signed up marketing people who offer digital marketing. Our CEO is adding experts in artificial intelligence and behavioral analytics to our marketing department. As the Compliance Manager, I am concerned. 

I came here from an online lender, so I am not naïve about online marketing tools. Digital marketing is mostly a fancy name for online marketing, meaning the leverage of numerous channels such as resources for behavioral modeling, search engines, social media, all kinds of websites, emails, text messages, and a host of multimedia. This is a veritable forest of minefields governed by regulations. 

I get it! We need digital marketing for brand awareness and to generate business. Most consumers these days expect a branded, online presence. But the stakes are high, especially because the ability to police digital marketers is ridiculously labor intensive. 

However, the CFPB has recently been making lots of noise about digital marketing providers. It is going to hold digital marketing providers liable for UDAAP violations – and now we’re going to employ these people right here in my company! I’m worried about the implications. I need some insight into what to expect. 

What are the implications for hiring digital marketers or using digital marketing providers? 

ANSWER 

On August 10, 2022, the Consumer Financial Protection Bureau (CFPB) issued an interpretive rule that addresses when digital marketing providers who commingle the targeting and delivery of advertisements to consumers are covered by the Consumer Financial Protection Act of 2010 (CFPA). 

Under the interpretive rule,[i] when digital marketing providers are materially involved in a covered person’s content targeting, the digital marketing provider does not meet the time or space exception to the service provider definition. As a result, those digital marketing providers would typically meet the definition of service provider under the CFPA and be subject to that law’s consumer protections. 

Let me dig a little deeper and provide some background and context. 

Section 1002 of the CFPA defines the term "service provider" and sets forth two exceptions to that definition. Our focus is on the time and space exception. 

            Time and Space Exception 

Under one of those exceptions, a person is not a service provider solely by virtue of such person offering or providing to a covered person time or space for an advertisement for a consumer financial product or service through print, newspaper, or electronic media. 

When digital marketing providers go beyond traditional advertising, such as by using algorithmic models or other analytics, they are typically covered by the CFPA as service providers. The interpretive rule explains that the time or space exception does not cover digital marketing firms that are materially involved in developing content strategy. 

Many digital marketing providers play a dramatically different role in consumer advertising than traditional media sources like print newspapers or radio stations. Many digital marketers target and deliver ads to specific consumers using sophisticated analytical techniques, including machine learning (i.e., artificial intelligence, or “AI”) and behavioral analytics, to process large amounts of consumer data. In other words, many digital marketers aggregate and analyze immense amounts of granular consumer data and then use that data to determine what advertisements to provide to specific consumers at what times. 

The CFPB’s interpretive rule explains that digital marketing providers commingle the service of targeting and delivering advertisements with the activities of traditional media sources in providing airtime or physical space. 

Digital marketing providers obtain data from various sources, including, but not limited to, data collected directly from consumers, for instance, when registering for an account or conducting a search query into a search bar. 

Furthermore, digital marketers may harvest a wide variety of consumer data by monitoring and tracking a consumer’s web activity, including their browsing history, online activity, and even geolocation. There is a scary term for this type of marketing: surveillance advertising. 

Digital marketers may also obtain data from third-party data brokers or second-party partnerships with other companies. Using these tools and others, digital marketers collect granular consumer data that they analyze to develop insights about consumers’ behavior more broadly. 

The ways in which digital marketing providers specifically target ads are varied and evolve over time. Ultimately, the digital marketer may decide which group(s) the consumer belongs in and which financial services companies want to advertise to that group. Then they select the specific ad to display to that consumer and/or when to display the ad based on other factors (i.e., the amount a firm is willing to pay to display the ad). 

Thus, many digital marketing providers are materially involved in developing content strategy by identifying or selecting prospective customers and/or selecting or placing content to affect consumer engagement, including purchasing or adopting behavior. These activities go well beyond the activities of traditional media sources, such as print newspapers or radio, that only passively provide airtime or physical space for advertisements. 

The interpretive rule[ii] sets forth delineations for digital marketing being (1) a material service and (2) liable for UDAAP violations. 

As the interpretive rule explains: 

Digital marketers provide material services to financial firms. 

A material service is one that is significant or important. Digital marketing providers are typically materially involved in the development of content strategy when they identify or select prospective customers or select or place content to encourage consumer engagement with advertising. Digital marketers engaged in this type of ad targeting and delivery are not merely providing ad space and time, and they do not qualify under the time or space exception. 

The CFPB, states, and other consumer protection enforcers can sue digital marketers to stop violations of consumer financial protection law. 

Service providers are liable for unfair, deceptive, or abusive acts or practices under the CFPA. When digital marketers act as service providers, they are liable for consumer protection law violations 

A company is subject to the CFPA, including its prohibition on unfair, deceptive, or abusive acts or practices, if it offers or provides a financial product or service for use by consumers primarily for personal, family, or household purposes.[iii] And a “service provider” is also subject to the CFPA, including its UDAAP prohibition.[iv] 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] CFPB Warns that Digital Marketing Providers Must Comply with Federal Consumer Financial Protections, Press Release, Consumer Financial Protection Bureau, August 10, 2022

[ii] Limited Applicability of Consumer Financial Protection Act’s “Time or Space” Exception to Digital Marketers, Interpretative Rule, August 10, 2022

[iii] See 12 U.S.C. 5481(5), (6), (15)(A); 5531; 5536.

[iv] See 12 U.S.C. 5481(26); 5531; 5536.

Thursday, August 5, 2021

Material Risk from Vendors

QUESTION
Our vendor
management policy covers a lot of review criteria to decide if a service provider presents a risk to our company. As the Chief Compliance Officer, I have thought that we are weak in handling such risks. 

Recently, this issue came to a head when I determined that a vendor’s system was failing and posed a material risk. After considerable review, I decided the relationship must end. Although I thought we were adequately covered for responding to material risks, it seems otherwise. 

And I have also gotten a huge amount of pushback from one of our departments since they claim to be dependent on this vendor. They are demanding that I keep the relationship and allow this service provider to stay active. 

What type of review is involved in determining material risk? 

In the face of substantial material risk, what should I do to keep the relationship active? 

ANSWER
I understand the challenge. I really do. You may have gotten pushback, but compliance and diplomacy are sometimes at odds. There is a diplomatic way of enforcing compliance. The best way is to present the evidence in support of your decision. Most people can recognize a threat, especially a material risk, which could affect the company's overall risk profile. You can take the position that an explanation is not needed. But that won’t work in the long run. Your colleagues, both rank and file, are your eyes and ears, and you want them to keep you informed. You want them to recognize your total commitment to complying with banking law.
 

Our Vendors Compliance Group (VCG) gets calls all the time from clients who are confronted with the potential for significant material risk posed by service providers. Our approach to vendor due diligence is hands-on, which means we actually do the actual work of personally reviewing each vendor’s documents and history, and then we issue a report. So, clients intuitively come to us to discuss their concerns, knowing that we are already familiar with their level of risk tolerance. If you want to discuss your vendor due diligence needs, please click here. We will contact you promptly. 

I could write a treatise on the definition of “material risk.” Often, the term is defined in the relationship agreements between an organization and the vendor. Let’s keep the definition short for the sake of brevity: “material risk” as a designation in the regulatory context means anything that has a substantive impact on an organization's overall risk profile, such that the risk criteria are significant enough for the source of the risk to be managed deliberatively. Well, I guess that was not so brief, but I did say I could write a treatise on just the definition itself! 

From the regulatory point of view, certain kinds of material risks are dauntingly threatening to a financial institution. I think there are at least four ways to respond to this threat level, and especially when a vendor presents high material risk, to wit: 

1. Assessing the vendor's capacity to perform the assigned task in a compliant fashion;   

2. Seeking representations and warranties from the vendor regarding compliance with applicable laws and regulations;   

3. Seeking the right to audit the vendor's compliance with applicable laws and regulations; and,

4. As appropriate, engaging in training or other activities designed to inform vendors about compliance issues of the organization.

I am going to each of these responses in numerical order. 

1. Assess the vendor's capacity to perform the assigned task in a compliant fashion. 

Outsourcing arrangements, such as vendor relationships, are central to many business activities. While these arrangements can be highly beneficial, they also present significant compliance risks. The vendor's activities may be attributed to the organization, resulting in it being exposed to regulatory sanctions. 

Vendors may also have access to nonpublic information (NPI) obtained from an organization, exposing the organization to the risk that the vendor will commit data breaches or violations of privacy requirements. 

Sometimes, there are business partnerships involved that are technically vendor relationships too. Valuable as such partnerships can be, they also expose organizations to significant risks of compliance breakdowns caused by the business partner. Accordingly, business partner relationships present critical compliance challenges for organizations. 

An essential step in dealing with these challenges is to assess the vendor's capacity to perform the assigned task effectively and reliably. This assessment process involves both a review of the counterparty's potential vulnerabilities and the organization's vulnerabilities. In my experience, a compliance breakdown is most likely when the shortcomings of both parties create gaps in controls that allow violations to occur. 

In assessing a proposed vendor in the context of material risk, you can review a variety of information, including on-site due-diligence examinations; checklists and evaluation tools: interviews with a proposed counterparty's key personnel; analysis of the proposed counterparty's information-security plans and procedures; and review of audit reports and certifications maintained by the proposed counterparty. Always maintain records of this vetting process and the reasons for selecting a vendor or business partner. 

2. Seek representations and warranties from the vendor regarding compliance with applicable laws and regulations. 

Your organization should, as appropriate, seek representations and warranties concerning the vendor's compliance with applicable laws and regulations. These may include representations regarding the vendor's compliance policy and program, internal controls, compliance training programs, and other matters. The representations can include affirmations by the counterparty that it complies with applicable laws and regulations and commitments to notify the organization if the vendor is charged with violations in the future. You may also want to seek an obligation by the counterparty to promptly repair or remediate failures in the vendor's system that may subject the organization to compliance liability. 

3. Seek the right to audit the vendor's compliance with applicable laws and regulations. 

The organization confronted with significant material risk issues may seek the right to monitor the vendor's compliance with applicable laws and regulations. The subject matter to be observed - and the monitoring methodology - depends on the facts and circumstances and should be designed according to a compliance risk assessment. If you do not have such a risk assessment, my firm provides such assistance. Please click here for information. 

In certain cases, it is sufficient for an organization to require the counterparty to keep books and records of services rendered and make these available for review. In other cases, the organization may need to engage in more intensive monitoring, for example, by obtaining the right to receive reports of auditors of the counterparty. And there are cases where an organization may seek the right to perform on-site audits of the provider's internal controls and procedures. 

Whether the organization needs and can obtain such contractual commitments depends on factors such as the criticality of the vendor's services, the costs of complying with the contractual terms, the risks to the organization of a breakdown in the vendor's internal controls, the requirements imposed by the organization's regulators, and the size and bargaining power of the organization. 

It is possible, though, that difficult questions may arise when your organization discovers shortcomings or failures in the vendor's internal controls that pose a risk of potential compliance exposure to your company. A vendor’s system failures can adversely impact a company’s operations and financial stability and immediately reach regulatory scrutiny. In these cases, an organization may be entitled to treat these failures as a material breach, thus terminating the contract. 

But the organization may not be able to terminate the contract, either because the breach is not material or because the vendor's services are critical to the organization's activities and no alternative provider is available. In such cases, the organization may elect to allow the vendor time to repair the problem. Still, it should exercise continual scrutiny to confirm that the repairs are effective and completed quickly. 

Furthermore, your company may also determine whether the counterparty has brought the shortcomings or failures to the attention of the counterparty's regulator and, if so, what the regulator has done in response. At the same time, you will want to consider whether your company is obligated to inform your regulator of the issue or, indeed, whether it would be advisable to notify the regulator even if such disclosure is not legally required. 

4. As appropriate, engage in training or other activities designed to inform vendors about compliance issues of the organization. 

Finally, it may be advisable for the organization to provide training to the vendor's employees. Training by the organization is likely to be more effective than training by the counterparty because it is aware of its risk profile and specific concerns. The costs of such training would be allocated between the parties under the terms of their contract or master agreement.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, April 16, 2015

RESPA’s “Required Use”

QUESTION
Our state banking department has cited us for a violation of RESPA, because we did not comply with RESPA’s “Required Use” provisions. What is “Required Use” and how can we avoid this violation in the future?

ANSWER 
The Real Estate Settlement Procedures Act (RESPA) contains a certain definition relating to the use of a settlement service provider. Under RESPA, “required use” occurs when a loan applicant must use a particular provider of a settlement service in order to have access to some distinct service or property, and the applicant will pay for the settlement service of the particular provider or will pay a charge attributable, in whole or in part, to the settlement service. [24 CFR § 3500.2(b)]

The following two caveats should be followed in order to avoid causing a violation of RESPA if, for instance, the lender offers a package, or a combination of settlement services, or offers discounts or rebates to consumers for the purchase of multiple settlement services:
  1. Any package or discount is optional to the purchaser; and,
  2. The discount is a true discount below the prices that are otherwise generally available, and must not be made up by higher costs elsewhere in the settlement process.
Jonathan Foxx
President & Managing Director
Lenders Compliance Group

Thursday, October 16, 2014

Defining a Settlement Service Provider


QUESTION
We continually hear about the importance of the “Settlement Service Provider” in originating residential mortgage loans. But it seems sometimes that almost everybody involved in a loan transaction is such a company. Is there a list that we can go by to determine who is and who is not a Settlement Service Provider?

ANSWER
There is a list of sorts, in RESPA, but it is not meant to be exhaustive. RESPA provides quite a broad definition of a settlement service, starting with the meaning of a “Settlement Service.” That is, whoever provides a settlement service is obviously a settlement service provider. With regards to your language of “loan transaction,” in context, this is a process, called a “settlement,” or a “closing,” or “escrow,” that has procedures for executing legally binding documents relating to a lien on a property that is subject to a federally related mortgage loan.

Any provider of a settlement service is, mutatis mutandis, a settlement service provider. The following list is a guide, certainly not meant to be exclusive, that forms a basis for RESPA’s broad way of defining a settlement service. [24 CFR § 3500.2(b)]
  1. Origination of a federally related mortgage loan (including, but not limited to, the taking of loan applications, loan processing, and the underwriting and funding of such loans);
  2. Rendering of services by a mortgage broker (including counseling, taking of applications, obtaining verifications and appraisals, and other loan processing and origination services, and communicating with the borrower and lender);
  3. Provision of any services related to the origination, processing or funding of a federally related mortgage loan;
  4. Provision of title services, including title searches, title examinations, abstract preparation, insurability determinations, and the issuance of title commitments and title insurance policies;
  5. Rendering of services by an attorney;
  6. Preparation of documents, including notarization, delivery, and recordation;
  7. Rendering of credit reports and appraisals;
  8. Rendering of inspections, including inspections required by applicable law or any inspections required by the sales contract or mortgage documents prior to transfer of title;
  9. Conducting of settlement by a settlement agent and any related services;
  10. Provision of services involving mortgage insurance;
  11. Provision of services involving hazard, flood, or other casualty insurance or homeowner's warranties;
  12. Provision of services involving mortgage life, disability, or similar insurance designed to pay a mortgage loan upon disability or death of a borrower, but only if such insurance is required by the lender as a condition of the loan;
  13. Provision of services involving real property taxes or any other assessments or charges on the real property;
  14. Rendering of services by a real estate agent or real estate broker; and
  15. Provision of any other services for which a settlement service provider requires a borrower or seller to pay.
Jonathan Foxx
President & Managing Director
Lenders Compliance Group