Showing posts with label FDIC. Show all posts
Showing posts with label FDIC. Show all posts

Wednesday, August 3, 2016

FDIC Seeks to Supplement Vendor Management FIL with Third Party Lending Guidelines


As vendor management continues to be a key issue for regulators, the FDIC has issued its Proposed Guidelines for Third-Party Lending. The deadline to comment was originally September 12, 2016 and was extended through October 27, 2016 in response to several requests for an extension of time. 
In its proposal, the FDIC outlines the risks associated with third party lending, sets forth its minimum expectations for associated risk management systems, its supervisory considerations and the examination procedures related to third party lending.  Here are the highlights:

  • The Proposed Guidelines defines third-party lending as being an arrangement that relies on a third party to perform a significant aspect of the lending process.  It includes situations where the insured institution originates loans for third parties, situations where the insured institution originates loans through third party lenders or jointly with third party lenders and situations where the institution originates loans using third party platforms.
  • The Guidelines make clear that an institution’s board of directors and senior management are ultimately responsible for managing third party lending arrangements and cannot divest itself of liability.
  • The Proposed Guidelines reiterate much of what is set forth in FIL-44-2008 regarding third party risk management.
  • Specifically, the proposal makes clear that risk management programs should consider the following risks: strategic, operational, transaction, pipeline and liquidity, model, credit, lending compliance, consumer compliance, and BSA/AML.
  • In that regard, the Proposal  requires that institutions engaged in third-party lending develop a risk management program that incorporates:
    • Strategic planning which establishes the risk tolerance limits and ensures necessary management, staffing and expertise to properly manage, oversee and audit third party lending relationships.  Strategic planning should also address and incorporate exit strategies and back up plans for third-party lending arrangements that do not go as planned;
    • Third-Party Lending Policies that at a minimum:
      • Limits the total capital for each third party arrangement and for the program overall;
      • Establishes policies and additional requirements for selecting and establishing third-party lending relationships;
      • Establishes minimum performance criteria, requirements for independent review of each third party and oversight management for each third-party relationship;
      • Establishes monitoring to identify, assess and mitigate risk including fair lending;
      • Establishes reporting processes including board reporting;
      • Requires access to data and other program information;
      • Defines permissible loan types;
      • Establishes underwriting, administration and quality standards;
      • Establishes a consumer complaint process;
      • Addresses capital and liquidity support and allowance for loan and lease concerns;
      • Ensures the compliance officer has adequate authority, resources, accountability and knowledge to insure compliance with relevant consumer protection laws and regulations that apply to each third-party lending arrangement; and
      • Maintains an appropriate training program for the institution and insure that third party personnel maintains and institutes the same.


  • The Proposed Guidelines also make it clear that all proposed third-party lending arrangements should fit within the institution’s strategic plan and business model. 
  • Additionally, third-party lending relationships require ongoing oversight and due diligence and sets forth the FDIC’s minimum expectations which include such matters as :
    • Policies and procedures;
    • Credit quality of loans solicited or underwritten;
    • Management information systems;
    • Compliance management systems;
    • Consumer complaints;
    • Litigation or enforcement actions;
    • Information security programs;
    • Compliance with relevant guidance, regulations and laws regulating the loans; and
    • Repurchase activity and volume.

  • The Proposal sets forth the minimum expectation that institutions understand the models used by third-party lenders to insure they are consistent with the institution’s underwriting and loan policies and compliance with applicable consumer protection laws, among other things.
  • Like other third party relationships, third-party lending relationships should be memorialized by a contractual agreement establishing the parties’ rights and the lender’s expectations.  The Proposed Guidelines reiterate that contractual agreements should address:
    • Indemnification, representations, warranties, recourse and other protections to limit the institution’s exposure;
    • Termination rights;
    • The Institution’s right to require the third party to implement policies and procedures for any function or activity it outsources to the third party; and
    • Allow the institution full access to information or data necessary to perform its risk and compliance management responsibilities.

  • The FDIC expects that credit underwriting and administration guidelines will be established by the institution and not the third party. 
  • Partnering with third parties does not relieve the institution from ultimate responsibility for compliance with all applicable laws and regulations, including consumer protection and fair lending.  “Third parties that have direct contact with borrowers, develop customer-facing documents, or provide new, complex, or unique loan products require enhanced compliance-related due diligence and oversight by the institution to ensure areas of potential consumer harm are identified and mitigated…and should be particularly attuned to potential elevated fair lending risks.”
  • Institutions engaged in significant lending activities through third parties will received increased supervisory attention, including concurrent and more frequent examinations.

The proposal should come as no surprise to lenders who have been monitoring the recent enforcement actions and continued focus on third party vendor management issues from all regulators. As the FIL will apply to all FDIC-supervised institutions engaged in third-party lenders, FDIC institutions should reassess their risk management programs and compliance management systems to insure they are in compliance with the proposed guidelines.

Tuesday, July 12, 2016

FDIC Launches Survey Regarding Small Business Lending Practices


The FDIC has launched a web based survey of roughly 2,000 randomly selected FDIC-insured banks regarding their small business lending practices.  This comes on the heals of the CFPB revelation that small business lending is also on their rulemaking agenda.  In May, the CFPB announced that it was in the very early stages of implementing Section 1071 of the Dodd Frank Act which amends the Equal Credit Opportunity Act to require financial institutions to report information concerning credit applications made by women owned, minority owned and small businesses. 

At the end of June, the FDIC issued a press release announcing their survey.  As its  rationale, the FDIC states that “[s]mall business lending is an important way that banks help meet their communities' needs, especially for the many banks that primarily focus on commercial rather than consumer lending…Despite the importance of small businesses to the U.S. economy and the importance of bank lending to small businesses, there is little high quality data on small business lending by banks. The FDIC Small Business Lending Survey (SBLS) is designed to help fill in this information gap.”  The survey also includes questions concerning consumer transactions which are responsive to a Congressional mandate to learn more about bank efforts to bring unbanked individuals into the conventional finance system. Responses to the survey are due August 10th.

The purpose of the survey is the provide insight into many aspects of small business lending, including nationally representative information on the general characteristics of small business borrowers, the types of credit sought and offered, and the relative importance of small business lending to banks of different sizes, business models and location.  The survey is broken down into six sections; (a) questions concerning the 2015 small business borrowers at the surveyed institution; (b) questions concerning the 2015 total loan originations of the surveyed institution; (c) questions concerning commercial and industrial loan originations of the institution in 2015; (d) questions concerning outstanding commercial and industrial  loans reported on the institutions call report in 2015; (e) questions concerning the small business “commercial and industrial lending competition, practices and applications” for the surveyed institution; and (f) consumer account offerings and policies.



Thursday, May 19, 2016

Federal Regulators Issue Interagency Guidelines Regarding Deposit Reconciliation Practices


The CFPB and four federal financial regulatory agencies have issued Interagency Guidance Regarding Deposit Reconciliation Practices.  The Guidance comes as a follow up to the consent orders entered into last fall against Citizens Bank N.A., Citizens Bank of Pennsylvania and their parent company, Citizens Financial Group, Inc. regarding deposit discrepancies.   The Guidance makes clear that the agencies have a zero tolerance policy as to deposit discrepancies and expect “financial institutions to adopt deposit reconciliation policies and practices that are designed to avoid or reconcile discrepancies, or designed to resolve discrepancies such that customers are not disadvantaged.”  The agencies expect financial institutions to:

  • Effectively manage their deposit reconciliation practices;
  • Insure that information provided to customers as to their deposit reconciliation policies is accurate;
  • Implement effective compliance management systems that include appropriate policies, procedures, internal controls, training and oversight; and
  • Review processes to ensure compliance with applicable laws and regulations.

While the Guidance provides for a zero tolerance policy, financial institutions are reminded that they are not liable for “bona fide errors”.  To establish a bona fide error, a financial institution must establish that a violation was not intentional and resulted from a bona fide error notwithstanding the maintenance of procedures reasonably adapted to avoid any such error.  It is therefore imperative that financial institutions review their compliance management systems to insure they:

  • Provide proper vendor management to ensure their service providers and affiliates properly and accurately resolve deposit discrepancies;
  • Include written policies and procedures for conducting audits to insure deposits and deposit discrepancies are accurately handled, including the frequency, scope and depth of said audits;
  • Put in place compliance measures, as well as policies, procedures and practices, to ensure accurate processing of deposits and deposit discrepancies;
  • Incorporate sufficient monitoring and oversight of the processing of deposits and deposit discrepancies;
  • Incorporate training of personnel to insure accurate resolution of deposit discrepancies; and
  • Incorporate complaint procedures and processing to ensure deposit discrepancy complaints are identified, tracked and resolved in accordance with the Banks’ policies and procedures.

.

Tuesday, November 24, 2015

Guest Post: NARCA Supports Eliminating “Bad Players”

By: Mark Dobosz, Executive Director - NARCA
November 24, 2015


The Federal Trade Commission’s announcement of its coordinated efforts with other law enforcement agencies against deceptive and unscrupulous debt collectors is hailed by NARCA as a positive move to rid the industry of the “bad apples” that tarnish reputable and legal debt collection businesses.


 NARCA supports the efforts of both industry entities and other agencies to root out the businesses that harm consumers through truly deceptive practices. The industry and consumers are much better off by collaborative and complementary practices to insure that “bad players” are eliminated from practicing debt collection.


 NARCA has been at the forefront of insuring that its members abide by a Code of Ethics and Professional Conduct that is separate and in addition to the rules in their respective states which govern their law licenses. .  Harvey Moore, NARCA Board President commented, “Collaboration, communication and cooperation between industry groups and the regulatory bodies which enforce laws to eliminate those who consciously harm consumers through deceptive practices is key to keeping the credit eco-system for this country strong.”

About the Author:  Mark Dobosz currently serves as the Executive Director for NARCA – The National Creditors Bar Association. Mark is a one of NARCA’s speakers on many of the creditors rights issues impacting NARCA members. 

The National Creditors Bar Association (NARCA) is a trade association dedicated to creditors rights attorneys. NARCA's values are: Professional, Ethical, Responsible



Thursday, September 10, 2015

FDIC Consent Orders with Comenity Entities Provides Guidance to Effective Third Party Management Systems


The FDIC has entered into a settlement with Comenity Bank and Comenity Capital Bank regarding their servicing and marketing of credit card add-on products and once again emphasized the importance of effectively managing third party relationships.  The premise for liability was Section 5 of the FTC Act which prohibits unfair and deceptive practices and stems from the banks’ provision through third parties of payment protection/debt cancellation add on products.  As part of the settlement, both banks agreed to pay a total of approximately $61.5 million in restitution to consumers, as well as civil money penalties of approximately $2.5 million dollars. As part of the enforcement action leading to the consent order, the FDIC determined that the banks violated the FTC Act by:

  • Representing to consumers that there would be no fee associated with their payment protection/debt cancellation add-on products so long as the account had no balance but then charging a fee in those circumstances;
  • Making material misrepresentations or omissions as to the refund process for the consumers’ cancellation of the product during the first thirty days of enrollment; and
  • Making material misrepresentations or omissions to consumers regarding the condition of receipt of certain incentives for enrollment.

Beyond the monetary implications, the orders contain remediation provisions which should provide guidance to other banks, particularly in their management of third party relationships. The Consent Orders require the implementation of an effective third party oversight program, which includes:

    • A review of all aspects of the banks’ agreements with third parties that provides services or products to or on behalf of the banks;
    • Procedures for effective monitoring, training, record-keeping, and audit of the banks’ third parties;
    • Access by the banks to all necessary systems of the banks’ third parties to insure compliance with all consumer protection laws;
    • Monitoring of all third party agreements to ensure they contain specific expectations, obligations, and consequences for compliance with all consumer protection laws;
    • Maintenance of records of all third party agreements and any marketing or solicitation materials developed by the banks’ third parties for add on products;
    • Prompt notification by the banks’ third parties regarding any regulatory inquiries, customer complaints and/or legal actions received by the banks’ third parties (“other than routine requests such as requests for cease and desist collection contact);
    • Procedures to address and resolve consumer complaints and inquiries regarding services or products provided by the banks’ third parties; and
    • Procedures to effectively analyze the root cause of complaints and identify any patterns or trends in complaints about specific products or practices.

Enforcement actions and the resulting consent orders should be reviewed carefully by other financial service companies not only to identify regulatory points of emphasis and prohibited practices, but also as guidance provided by regulators as to their expectations for effective compliance management systems. 

Thursday, August 13, 2015

Federal Regulators and the CFPB Fine Bank and Order Remediation as to Deposit Discrepancies


In a joint enforcement action, the CFPB, OCC and FDIC have entered into consent orders with Citizens Bank N.A., Citizens Bank of Pennsylvania and their parent company, Citizens Financial Group, Inc.  (the “Banks”). The consent orders allege the Banks engaged in unfair and deceptive practices between 2008 and 2013 with respect to their handling of deposit discrepancies.  In total, the Banks are being ordered to refund any deposit discrepancies which were not properly credited to customer accounts (estimated to be in excess of $16 million dollars) and pay over $20 million in penalties.  Additionally, the Banks are being ordered to remediate their practices and put compliance management programs and audit procedures in place to prevent further issues.

The consent orders allege that between January of 2008 and November of 2013, the banks violated §5 of the FTC Act and §1036 of Dodd Frank by engaging in unfair and deceptive practices regarding their deposit discrepancy policies.  The consent orders allege that the Banks’ violations were two fold.  The Consent Orders allege that the Banks told customers that deposits were subject to verification, suggesting that the banks would take steps to ensure deposits were accurately credited when a discrepancy arose between the deposit slip and the actual amount of the deposit.  Second, the Banks made no adjustments to the deposit amounts where deposit discrepancies were under a certain threshold ($50 from January 2008-September 2012 and $25 from September 2012 through November 2013). In other words, the deposits were credited for the amount on the deposit slip irregardless of the discrepancy.  The net effect was that if a customer miscalculated its deposit and the discrepancy was under the thresh hold, the deposit was never credited to reflect the discrepancy. 

The Orders require the Banks to:

  • Provide proper vendor management to ensure their service providers and affiliates properly and accurately resolve deposit discrepancies;
  • Establish a Compliance Committee to monitor and coordinate the Banks’ adherence with the consent orders;
  • Develop a written Consumer Compliance Internal Audit Program for the processing of deposits and deposit discrepancies which includes written policies and procedures for conducting audits to insure deposits and deposit discrepancies are accurately handled, including the frequency, scope and depth of said audits;
  • Submit a Compliance Plan which:
    • Puts in place compliance measures, as well as policies, procedures and practices, to ensure accurate processing of deposits and deposit discrepancies;
    • Incorporates sufficient monitoring and oversight of the processing of deposits and deposit discrepancies;
    • Incorporates training of personnel to insure accurate resolution of deposit discrepancies; and
    • Enhance or incorporate complaint procedures and processing to ensure despot discrepancy complaints are identified, tracked and resolved in accordance with the Banks’ policies and procedures.

The Orders additionally require the Banks to reimburse affected account holders for the amount of any funds not properly credited to their account as a result of the discrepancy, plus any bank charges resulting from the under-crediting (for instance, overdraft) and interest.  Additionally, the Orders require the following civil penalties: $7.5 million to the CFPB, $3 million to the FDIC and $10 million to the OCC.