CFPB COMPLIANCE: Interaction Between Compliance Assessments and Systems Issues



Similar documents
Military Lending Basics

The CFPB and Medical Collections: Unknown Territory in the Face of Sweeping Regulatory Change

Mortgage Banking. Solutions in Compliance, Transactions, and Defense. Attorney Advertising

UNFAIR, DECEPTIVE, OR ABUSIVE ACTS OR PRACTICES (UDAAP)

Client Update CFPB Issues Final Auto Finance Larger Participant Rule and New Auto Finance Examination Procedures

REQUEST FOR PROPOSALS for Authorized Providers of Continuing Education Credits

CFPB Sues For-Profit College Chain ITT for Predatory Lending

CFPB Examination Procedures

Minimizing Legal and Compliance Risk for Credit Furnishers

Navigating Consumer Financial Protection Bureau ( CFPB ) Investigations and Enforcement Actions

CFPB Consumer Laws and Regulations

Board of Directors and Management Oversight

Fortifying the Three Lines of Defense to Combat Compliance Risk

CFPB Update: Regulatory and Enforcement Developments

Advertising Dos and Don'ts for Mortgage Lenders and Brokers

Regulatory Practice Letter December 2012 RPL 12-24

$28 Million FTC settlement with Bear Stearns/EMC Mortgage has significant impact on ARM Industry

CFPB and Medical Collections

RISK MANAGEMENT UPDATE Lessons [To Be] Learned from Recent Enforcement Actions

Supervisory Highlights. Summer 2013

Student Loan Servicing and the CFPB

Regulatory Practice Letter January 2013 RPL 13-01

Any business relationship between a bank and another entity, by contract or otherwise

Arthur Rotatori, McGlinchey Stafford, PLLC Jason Romrell, LeadsMarket.com Dustin Alonzo, McGlinchey Stafford, PLLC. #LEND360 LEND360.

Managing specialty finance compliance requirements with a compliance management system

Supervisory Highlights

What Lead Generators Need to Know About the Consumer Financial Protection Bureau (CFPB)

2014 Financial Services Industry Compliance Benchmark Study

Unfair or Deceptive Acts or Practices by State-Chartered Banks March 11, 2004

Examination Procedures

Compliance and Operational Services for Online Lenders

Short-Term, Small-Dollar Lending

Financial Services Update June 11, 2013

Greg Pulles. January 6, 2012 Attorney Articles

BANK & LENDER LIABILITY

How To Be Ethical With Lead Generation

Navigating the Consumer Financial Protection Bureau. kpmg.com

Consumer Financial Services. Industry-leading counsel in regulatory compliance, product development, and litigation. Attorney Advertising

CFPB Examination Resource Guide

Buying Smart / Selling Smart The 10 Biggest Legal Pitfalls in Lead Generation

Compliance Bulletin and Policy Guidance: Mortgage Servicing Transfers

The Fair Credit Reporting Act (FCRA) and the Fair Debt Collection Practices Act (FDCPA)

The final rule has expanded the scope of covered products how does this impact your business?

CFSA Compliance School, Part II: Implementing an Effective Compliance Management System

Payment Processing, Account Maintenance, and Optional Products. Collections, Debt Restructuring, Repossessions, and Accounts in Bankruptcy

Collections After Compliance. The Changing Landscape. An Experian Perspective

Reverse Due Diligence A New Trend In Financial M&A

UNFAIR, DECEPTIVE, OR ABUSIVE ACTS OR PRACTICES (UDAAP)

Unfair, Deceptive, or Abusive Acts or Practices

Table of Contents Chapter 1 Introduction Goals & Objectives Required Review Applicability...

VII 3.1. VII. Unfair and Deceptive Practices FDCPA. Fair Debt Collection Practices Act. Introduction. Communications Connected with Debt Collection

Putting the Management Back in Vendor Management February 20, 2014

Regulatory Practice Letter February 2014 RPL 14-05

Date: July 10, 2013 Subject: Prohibition of Unfair, Deceptive, or Abusive Acts or Practices in the Collection of Consumer Debts

FinTech Webinar Series: Vendor Management Principles

Fair Lending, UDAAP and CRA: Protecting Your Bank from Allegations of Fair and Responsible Lending Violations

What You Need to Know About the CFPB and Why You Should Care

2015 REGULATORY CHALLENGES FOR FINANCIAL INSTITUTIONS E L L IOT T DAVIS D E COSIMO R I S K MANAG E MENT

The Elements of a Consumer Financial Services Compliance Program by Gregory J. Pulles January 12, 2012

Payment Systems: Regulatory Interest in Payment Processors, Faster Payments, and Related Consumer Protections

THE LEAD GENERATION COMPANY: MANAGING THE RISKS. Jonathan Foxx *

Unfair, Deceptive or Abusive Acts or Practices Act (UDAAP)..It May Not Be What You Think

Credit Repair Organizations Act

CHAPTER 2--CREDIT REPAIR ORGANIZATIONS SEC REGULATION OF CREDIT REPAIR ORGANIZATIONS.

Regulatory Practice Letter January 2014 RPL 14-03

Supporting Effective Compliance Programs

Susan Costonis, C.R.C.M. Compliance Training & Consulting for Financial Institutions

Fair Debt Collection Practices Act 1

Regulatory Practice Letter November 2012 RPL 12-20

{Regulatory Compliance Update.} December 10, 2014

Federal Consumer Protection. Body of laws designed to protect the economic back bone of the country, credit.

GUIDANCE FOR MANAGING THIRD-PARTY RISK

Time to Revamp the Compliance Management System

Navigating Vendor Management Issues in Today s Regulatory Environment

CFPB Focus. Five Questions to Ask Before January 10, 2014

Goldman Sachs Residential Mortgage Servicing Vendor Management Policy Addendum U.S.-Based Program

KPMG LLP Credit Risk Management Practices 2014 Survey on Credit Bureau Reporting

Fair Debt Collection Practices Act

Section 10: Fair Credit Reporting Act (FCRA) Policy

Statement of the Office of the Comptroller of the Currency. Provided to the Subcommittee on Financial Institutions and Consumer Protection

Audit, Risk Management and Compliance Committee Charter

Overview of Financial Products and Consumer Protections

Takeaways From GE Capital's $225M Credit Card Settlement

Dealer Advertising: New Federal Compliance Mandates

2014 National Update: Service Contracts Ancillary Products

HALOZYME THERAPEUTICS, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS ORGANIZATION AND MEMBERSHIP REQUIREMENTS

CFPB Mortgage Servicing Standards

Examination Procedures

Social Media: Consumer Compliance Risk Management Guidance

Vendor Management: Who the CFPB is Watching and Who They Are Expecting You to be Watching

Company Name Vendor Management Policy and Procedure. Table of Contents

Preparing for the Outsourcing Challenge: Legal Due Diligence to Ensure a Winning Service Provider Relationship

WiFiAccessCode: LEADSPEDIA Follow at #leadscon Thursday, 4:00 4:45PM

#socialmediarisk Social Media and Consumer Marketing for Financial Services Organizations

Examination Procedures

Tip Sheet. Keep in mind we are not a law firm and this is not legal advice. All advertising should be reviewed by an attorney prior to distribution.

Joint Guidance on Overdraft Protection Programs. February 18,2005

Introduction. Contact rate Promise rate Kept rate and payment size Regulatory compliance Sustained ability to collect - 2 -

Importance of the Consumer Financial Protection Bureau

CFPB Examination Procedures

Transcription:

CFPB COMPLIANCE: Interaction Between Compliance Assessments and Systems Issues Presented by: Stefanie H. Jackman Consumer Financial Services Group 678.420.9490 jackmans@ballardspahr.com Trevor Salter Consumer Financial Services Group 202.661.2224 saltert@ballardspahr.com

2 GRC Software Applications Compliance and Ethics Training Hotline and Ethics Reporting Code of Conduct Services and Training Assessments Certifications and Attestations Advisory Services Compliance 360 GRC Software 2

3 About Compliance 360 GRC Solutions 250,000+ 000+ Active Users 900,000+ Regulations 400,000+ Policies 100,000+ Audits & Assessments 150,000+ Contracts ZERO Software Travelers 3

4 Compliance 360 Platform Surveys Assessments Policies Third Party Risk Mgt. ERM Internal Audits Dashboards & Reports Content Library Workflow Email Integration Search Tasks GRC PLATFORM Documents Projects Forums Meetings Virtual Evidence Room Laws, regulations and requirements Incidents Privacy Breaches Claims Audits Claims Denials SOX

Interaction Between Compliance Assessments and Systems Issues August 22, 2013 Stefanie Jackman Consumer Financial Services Group 678.420.9490 jackmans@ballardspahr.comcom Trevor Salter Consumer Financial Services Group 202.661.2224 saltert@ballardspahr.com Copyright 2013 by Ballard Spahr LLP

Agenda Developing A Compliance Management System - Considerations for assessing compliance - Reporting exceptions and document fixes - Importance of written policies and procedures and centralized access - Importance of documenting employee training and discipline Potential Risk Areas - UDAAP - Marketing and sales - Employee training and discipline - Complaint tracking and reporting - Third party supervision i - Record retention and information security 6

Developing a Comprehensive Compliance Management System 7

Who Is The CFPB Examining First? Companies identified by CFPB as presenting a heightened risk to consumers based on: Information received from other regulators Complaints Litigation Media Wb Web postings and social ilmedia 8

Purpose of Exam Process CFPB exams always have two objectives: (1) to determine the adequacy of internal procedures and controls; and (2) to assess substantive compliance. Comprehensive analysis of substantive compliance likely to touch every area of law impacting your company. The CFPB s approach is to request electronic copies of documents and other records, including recorded calls, which its examiners review in order to assess compliance with every potentially applicable statutory or regulatory provision and some issues may come as a bit of a surprise. 9

The need for a compliance management system CFPB has made it clear that lenders must have a written compliance management system. CFPB s 900+ page Exam Manual describes the policies and procedures comprising such a system in great detail. CFPB has instructed its examiners to request and review the exam target s t policies i and procedures. And the CFPB s First Day Letters confirm that they do so. 10

System should be risk based CFPB examiners should seek to determine whether the board ha[s]: Allocated resources to the compliance function commensurate with the size and complexity of the entity s operations and practices, the Federal consumer financial laws and regulations to which the entity is subject, and necessary to avoid the potential consumer harm associated with violations of such laws and regulations --CFPB Exam Manual 11

What should system cover? Consumer complaint response Training Monitoring and corrective action Compliance audits Third party service provider oversight Board oversight Policies and procedures addressing applicable consumer protection laws (e.g., TILA, ECOA, EFTA, UDAAP) 12

Compliance Management System Oversight Compliance Program Consumer Complaint Response Compliance Audit Define responsibilities of Board and compliance officer Assess training deficiencies Assess compliance program deficiencies Review audit reports Monitor new laws/regs Monitor complaint trends Revise compliance program Training Categorizing Performed by New employee Tracking disinterested staff or Refresher Resolving third parties Ad hoc (new laws/regs) Reporting Includes audits and due Testing (Includes complaints diligence of third-party Monitoring & Corrective Action lodged with or against third-parties) Test consumer loan files Listen to calls Monitor third parties Discipline employees Include monitoring rights in third party agreements service providers Policies & Procedures UDAAP ECOA Military issues (SCRA, Talent) TILA Collections/FDCPA Data security/document retention Bankruptcy EFTA Privacy Red flags TCPA ADA FCRA 13

Consumer complaint response Documenting Tracking Responding Observing trends Reporting trends to management Using complaint data to improve procedures, disclosures, training, i etc. 14

Monitoring and Corrective Action Listening to calls to consumers (marketing/servicing/collection, etc.) Auditing loan files Mystery shopping by phone or in branch/store Background checks on employees Corrective action Termination 15

16 Audience Polling Question How is your organization currently tracking consumer complaints? (select all that apply) 16

Employee Training and Discipline Compliance management system can be used to train employees throughout organization: - Branch/store employees (TILA, ECOA, UDAAP) - Collectors (FDCPA, UDAAP) - Marketing staff (TILA, UDAAP) - Operations (EFTA, TILA) - All employees (data security, privacy) Need to demonstrate that employees are required to perform according to policies and procedures 17

Third Party Service Provider Oversight Under the CFPB s service provider bulletin, potential exists that an entity may be held liable for UDAAP violations by a service provider Bulletin 2012-03 identifies several specific things that supervised entities must do with respect to service providers: - Initial due diligence - Review of policies, procedures and training (remote and on-site) - Include compliance-related provisions in contract - Monitoring i and controls to prevent/detect t t compliance violations - Taking remedial action as appropriate Special concerns for technology providers 18

Board Oversight Appoint chief compliance officer Review compliance reports Review audits Analyze complaints Monitor for new laws and regulations Revise compliance management system as needed 19

Compliance audits Conduct regular self assessments from consumer satisfaction/confusion perspective Performed by third parties/outside counsel or disinterested staff from another area of operations Report results to Board Using audit data to improve procedures, disclosures, training, etc. Pay attention to customer complaints and encourage customers to submit them to you, not the CFPB 20

Potential High Risk Areas 21

UDAAP Compliance - A practice does not need to be illegal/improper under applicable law or cause actual harm to be deemed a UDAAP violation - To evaluate for UDAAP, need to adopt consumer s perspective: How does the consumer encounter your products or process Who is the reasonable consumer? 22

Identifying UDAAP Risks Consumer complaints CFPB/regulatory consent orders Consumer blogs Consumer groups Attorneys General Private class action litigation Approaching compliance from the consumer s perspective 23

Marketing & Advertising Bank regulators want to know that all marketing has been reviewed for accuracy, truthfulness and that all claims have been substantiated When disclosures are necessary, then the disclosures must be at least clear and conspicuous the 4 Ps - PROMINENCE: Is the disclosure big and clear enough for consumers to notice and read? - PRESENTATION: Is the wording and format easy for consumers to understand? - PLACEMENT: Is the disclosure where consumers would expect it? - PROXIMITY: Is the disclosure within or close to the claim it qualifies? 24

Hot Issues in Marketing of Financial Products Introductory or teaser rates Up to claims Failing to put claims into proper context (i.e., UDAAP is determined dby looking at the totality of the ad) - Particular problem with social media Telemarketing - The demise of outbound - Scripting, scripting, scripting Ensuring disclosure standard is met across platforms (i.e., online, mobile, tablet, t etc.) 25

Add-on Products Add-on products have perennially been an area of regulatory focus The underlying themes in this area have been relatively constant across product lines (closed-end loans, credit card accounts, auto RISCs), and these areas form the basis for UDAAP compliance with respect to add-on products: Consumer not informed that product is voluntary Inadequate disclosure of cost of product Inadequate disclosure of cancellation rights (or resistance to cancellation through retention efforts) Statements made in connection with sales process Sale of products when consumers cannot realize benefits Price of products as compared to consumer utilization 26

Debt Collection Quality of account documentation used to collect on debt (AMEX, Asset Acceptance, FTC Debt Buying Report, subject of many CIDS) Failing to investigate accuracy of debts/verify debts Contract provisions i speaking to representations or warranties as to accuracy of account information purchased Internal handling of data to ensure accuracy and integrity y( (dual systems) Misleading statements of impact of payment on credit score/creditworthiness 27

Debt Collection Authentication of debts and account records under the business records rule Consumer complaints alleging inaccurate information, and responses to those complaints (including FCRA disputes) Threatening actions do not intend/do not take in regular course Failing to report debts as disputed to credit bureaus Failing to disclose convenience fees Recent bulletins re: FDCPA applies to first party collectors and service providers 28

Privacy UDAAP and Privacy - Practices that are inconsistent with privacy policy are deceptive - Practices that are consistent with privacy policy, but nevertheless cause substantial consumer harm that consumers cannot avoid, may be considered unfair. Website and mobile privacy policy - Due diligence is critical: Understand how site or app actually works and what information is collected - Be transparent about what information is being used Engagement in social media sites - Customer information posted on company social media pages/sites will be used/collected 29

Data Security UDAAP and Data Security - Not protecting information in a reasonable manner could be considered deceptive or unfair. - Avoid absolutes (e.g. 100% secure, always, etc.) Employee and management training - 3 Categories of Controls: administrative, physical, technical Special considerations when selecting and overseeing service providers and affiliates Considerations for managing system failures and breaches 30

Fair Lending Risks and Monitoring Advertising/marketing Product steering Discretion in underwriting/servicing/collection Employee/dealer/service provider incentive compensation Employee training on access options for disabled persons Service providers, especially in collections Exception reporting and tracking/monitoring 31

Role of Outside Counsel What should you consider retaining outside counsel? Reactive - Internal: when internal audit or fact-finding reveals policy or performance gaps - External: when customer complaints or regulator inquiry (e.g. exam) reveals policy or performance gaps Proactive - When creating a new or innovative financial product, channel, or marketing method - When a regulator signals areas of high-risk, such as those discussed in this presentation 32

33 Audience Polling Question Would you like to learn how Ballard Spahr LLP or SAI Global can assist with your compliance initiatives? (select all that apply) 33

Resources CFPB Monitor Subscribe to our ABA award-winning blog at www.cfpbmonitor.com. E-Alerts Subscribe at www.ballardspahr.com (click subscribe and choose Consumer Financial Services or Labor & Employment as your area of finterest). t) Mortgage Banking Update Subscribe at www.ballardspahr.com (click subscribe and choose Mortgage Banking as your area of interest). Questions? E-mail questions@ballardspahr.com. 34

35 Additional Resources Educational Webinars: www.compliance360.com/webinars Banking Demo Series: Part 1: CFPB / UDAAP Compliance Self-Assessments Automated in Compliance 360 Part 2: CFPB / UDAAP Risk Assessments Automated in Compliance 360 Part 3: Complaint Management Automated in Compliance 360 Enterprise Risk Management for Banks - Automated in Compliance 360 www.compliance360.com/webdemos 35

CFPB COMPLIANCE: Interaction Between Compliance Assessments and Systems Issues Presented by: Stefanie H. Jackman Consumer Financial Services Group 678.420.9490 jackmans@ballardspahr.com Trevor Salter Consumer Financial Services Group 202.661.2224 saltert@ballardspahr.com