QUESTION
I hope you can help us. We are a bank in the southwest. I am the
compliance manager. Recently, we were notified that the FDIC took issue with
our compliance management system. I am not making excuses, but we do not have
much staff here – really, it’s mostly me! – and providing everything the
regulator is asking of us is kind of overwhelming. The CFPB also advised that
we show “significant weaknesses” in our compliance management. All of this has
to do with our readiness and overall compliance program. I have two questions.
First, I heard that you offer an inexpensive review of the compliance
management system. Can you please tell me about it and send me information?
And, secondly, I need to know what to read and how to get our compliance
program in shape. Where do I start? Our next review is in 90 days, and I want
to be ready. Any feedback you offer will be appreciated!
ANSWER
I understand your situation. We received your inquiry a few days ago and, considering the urgency, I have prioritized it for this week's FAQ. The CFPB has spent considerable resources
in the enforcement and examination of a financial institution’s Compliance Management
System (“CMS”). The Bureau has certainly gotten people’s attention with a
myriad of highly publicized consent orders. Since it began issuing such orders
in 2011, the CFPB has often used the “significant weaknesses” terminology to describe
the integrity of a compliance program, notwithstanding that these findings are
usually accompanied by alleged violations of certain federal consumer financial
laws. You do not mention a specific area, department, or function, but
deficiencies regularly are cited against entities engaged in credit card
lending, mortgage lending, auto lending, payday lending, check cashing
services, payment processing, collections, and other financial activities.
It can seem at times overwhelming, and even exasperating, to be sure
that your firm meets all the CMS compliance requirements – especially if
staffing, resources, and research depth may limit the fulfillment of the
regulator’s expectations. Whatever the case, you need to be ready to evaluate
three interdependent elements: Board and management oversight; the compliance
program itself; and the auditing of the compliance program.
So, to your first question about getting prepared for the CMS
examination, that is why we developed the CMS Tune-up!™ We pioneered this approach
because (1) it is cost-effective, (2) it provides actionable findings, and (3)
it is conducted quickly and concisely. You receive a report, with findings and
a risk rating. In fact, the CMS Tune-up!™ is designed to act like an actual
examination. This means you prepare for the forthcoming examination effectively.
Download the presentation for the CMS Tune-up!™ HERE or download it from the
sidebar on the right.
Indeed, considering the urgency, please schedule an appointment with me
HERE.
Or, send me an email HERE. Please do
not delay.
Your financial institution should establish a formal, written, ratified
compliance program, if you have not already done so. In addition to being a
planned and organized effort to guide compliance activities, the written
program represents an essential source document that serves as a training and
reference tool for all employees. A well-planned, implemented, and maintained
compliance program may prevent or at least reduce regulatory violations and
provide cost efficiencies. In any event, it is mandatory for safety and
soundness.
To be ready for the examination, you must be sure that you meet the examination
guidelines for policies and procedures, training, monitoring, and consumer
complaint response. The following questions should be at the forefront of your self-assessment.