Showing posts with label OCC. Show all posts
Showing posts with label OCC. Show all posts

Tuesday, October 4, 2016

OCC Lays Out SCRA Compliance Management System Expectations in New Wells Fargo Consent Order


They say bad news comes in threes and Wells Fargo capped off September entering into its third Consent Order in roughly a month. This time, the Consent Order resolved issues with the bank’s compliance with the Servicemembers Civil Relief Act (“SCRA”). According to the OCC, the bank violated three separate provisions of the SCRA by failing to provide the 6% interest rate limit to servicemembers’ obligations or liabilities incurred before military service, failing to accurately disclose servicemembers’ active duty status to courts via affidavits prior to evictions and by failing to obtain proper court orders prior to repossessing vehicles. The Order comes a year have the OCC re-emphasized its focus on bank compliance with the SCRA and its intentions to ramp up on enforcement. In 2015, regulators took corrective actions against both JP Morgan Chase and Bank of America regarding the SCRA. The Wells Fargo Consent Orders require the bank to pay a $20 million civil monetary penalty, provide restitution to affected consumers, and establish an enterprise wide SCRA compliance program.
 
As is often the case, the consent orders provide guidance for other regulated entities as to the elements of a robust compliance management system. Among other things, the Consent Orders, which do not include any admission of wrongdoing, requires the bank establish a written program to ensure the bank’s compliance with the SCRA. At a minimum, regulated entities should review their own SCRA Compliance program to ensure it meets regulator’s expectations. According to the Consent Order entered into by Wells Fargo, a SCRA Compliance Program should:
  • Include written policies and procedures which provide:
    • Uniform standards and processes for identifying customers eligible for SCRA benefits and protections;
    •  Uniform standards and processes for determining whether a servicemember who submits a request for SCRA benefits and protections is eligible for such benefits and protections not only for the requested account, but for all accounts (including commercial accounts) for which the servicemember is personally liable;
    • Processes for notifying servicemembers of the bank’s denial of SCRA benefits and protections;
    • Processes to insure affidavits filed by or on behalf of the bank are accurate, complete and reliable;
    • Procedures for when searches of the Department of Defense database must be conducted before filing and obtaining a default judgment and for making a determination of the servicemembers eligibility for SCRA benefits and protections;
    • Procedures for initiating and obtaining waiver of rights under the SCRA; and
    • Procedures for applying relevant state laws which provide more benefits or procedures than those provided by the SCRA;
  • Include written policies and procedures regarding record retention including:
    • Written procedures and processes requiring the Bank obtain and maintain sufficient documentation to support:
      • The dates of military service for servicemembers who request SCRA benefits and protections;
      • The method, date, and results of military status verifications prior to seeking or obtaining a default judgment;
      • Dates of any correspondence with any servicemember covered by the SCRA; and
      • The calculation of benefits and protections provided to the servicemember by the SCRA.
    • Written procedures and processes for documenting the basis for the bank’s determination of an account’s eligibility for SCRA benefits or protections or the bank’s denial of benefits and protections;
  • The development of internal guidance, guidelines and formats that convey general information regarding the SCRA to bank employees;
  • Written policies and procedures for conducting periodic reviews and updating;
  • Written policies and procedures to ensure deficiencies in SCRA policies, procedures or processes are identified and corrected;
  • Establishment of an ongoing system of monitoring and testing within all potentially affected lines of business to ensure compliance with the SCRA and ensure policies and procedures are being followed and are effective;
  • Establishment of an enterprise-wide customer complaint management program designed to capture, identify and address SCRA-related complaints; and
  • Establishment of a written program to ensure all relevant personnel (including compliance, management, loan officers and customer service) are trained periodically regarding the SCRA and related state laws.
Banks and other financial service providers should also keep in mind that amendments to the Military Lending Act began to take effect October 3, 2016.

Thursday, September 22, 2016

Wells Fargo is Not the End of the Incentive Compensation Discussion

Prepared remarks and testimony of Thomas J. Curry, the Comptroller of the Currency, to the Senate Committee on Banking, Housing and Urban Affairs make it imminently clear that cross-selling, sales practices and related incentive compensation will be a focal point for examinations of banks of all sizes and that the OCC continues to review the Wells Fargo matter for "individual misconduct and culpability."  Curry stated that he has ordered examiners to "review the sales practices of all large and midsize banks we supervise and assess the sufficiency of controls with respect to sales practices." Oral Statement of Thomas J. Curry (Sept. 20, 2016). Logic dictates that the FDIC has issued a similar  directive to its examiners, as well. 


Moving forward, the regulatory agencies are also being scrutinized for their part in the Wells Fargo incident.  Congressional leaders are questioning whether the agencies acted quickly enough.  Curry stated in his Testimony that "the actions against Wells Fargo highlight that we must continue our efforts to improve and refine the agency's supervisory program, to sharpen our early warning processes, and to enhance our supervisory capabilities, particularly with respect to our largest, most complex banks."  Testimony of Thomas J. Curry Comptroller of the Currency before the Committee on Banking, Housing, and Urban Affairs (Sept. 20, 2016). 


Banks and credit unions of all sizes should carefully review their sales incentive packages and relevant risk management and audit practices.  As we indicated last week, the Wells Fargo Orders provides guidance as to the expectations of examiners.  Supervised entities should review their product lines, perform independent risk management and internal audits to identify any weaknesses in their compliance management and review their policies and procedures to insure they are consistent with the expectations of examiners..

Wednesday, September 14, 2016

What Can We Learn from the Wells Fargo Consent Orders?





By now, most have read about the consent orders issued last week by the CFPB and the OCC concerning Wells Fargo. The consent orders ordered Wells Fargo to pay a total of $185 million in civil monetary penalties ($100 million to the CFPB, $50 million to the OCC and $35 million to the City and County of Los Angeles), as well as reimbursing customers an estimated $5 million because Wells Fargo employees, in an effort to boost sales figures and earn bonuses: (a) opened deposit and credit card accounts without customer consent; (b) moved funds from authorized accounts to the new deposit accounts without customer consent; (c) enrolled customers in online banking services they did not request; and (d) ordered and activated debit cards business customer information again, without customer consent. The consent orders shine a large spotlight on the problems that can occur when employees are provided incentive compensation without adequate compliance management systems in place to insure bad things don’t happen. The CFPB is quick to say that they are not prohibiting incentive compensation, but “companies need to pay very close attention to make sure they have effective monitoring in place to ensure that consumers are protected.” Prepared Remarks of Richard Cordray (Sept. 8, 2016).

As with many of the Consent Orders issued by the CFPB and other federal regulators, the Consent Orders issued as to Wells Fargo are an excellent place for others in the financial industry to begin in assessing whether their compliance management systems regarding incentive compensation are adequate.

 
Here are Our Takeaways:

  • Banks and Credit Unions should take a hard look at incentive compensation structures across all business lines to insure they do not provide a heightened risk of unfair or abusive practices;
  • Banks and Credit Unions should require ongoing training of all sales personnel reasonably designed to prevent improper sales practices (in the case of Wells Fargo, the opening of accounts without customer consent, etc.) and such training should be repeated and assessed for adequacy at recurring intervals.  Training records should be maintained.
  • Banks and Credit Unions should implement a system to report sales integrity issues internally and provide training to employees as to the use of the same;
  • Banks and Credit Unions should proactively monitor their sales practices on a regular basis, hire adequate personnel and resources to do so, and implement policies and procedures insuring the same. 
  • Banks and Credit Unions should maintain adequate policies and procedures for:
    • Receiving, retaining and addressing customer inquiries or complaints and escalating the same;
    • Receiving, retaining and addressing internal allegations of improper sales practices or other sales integrity violations and escalating the same;
    • Identifying, tracking and addressing indicators of improper sales practices or other sales integrity violations;
    • Addressing improper sales practices and other sales integrity violations, both internally and externally;
  • Banks and Credit Unions should review their policies and procedures regarding sales of deposit accounts, credit cards, unsecured lines of credit, and related products and services (both internally and with associated vendors) to insure they are reasonably designed to procure and document customer consent;
  • Banks and Credit Unions should assess whether their performance-management, sales goals and incentive compensation are reasonably designed to prevent improper sales practices or other sales integrity violations;
  • Similarly, Banks and Credit Unions should review their risk management and oversight programs to insure they include policies and procedures for reporting and escalating sales practice information in a timely manner;
  • Banks and Credit Unions should review their risk management and oversight protocols to insure they establish key risk indicator metrics to monitor for unsafe and unsound sales practices.  In the case of Wells Fargo, the OCC Order provided that, at a minimum, this information should include customer surveys, customer complaints, bank employee ethics allegations or complaints and Corporate Investigation metrics;
  • Banks and Credit Unions should employ a comprehensive written assessment of any new or materially revised incentive structures prior to implementation to ensure that risks are controlled.

Thursday, May 19, 2016

Federal Regulators Issue Interagency Guidelines Regarding Deposit Reconciliation Practices


The CFPB and four federal financial regulatory agencies have issued Interagency Guidance Regarding Deposit Reconciliation Practices.  The Guidance comes as a follow up to the consent orders entered into last fall against Citizens Bank N.A., Citizens Bank of Pennsylvania and their parent company, Citizens Financial Group, Inc. regarding deposit discrepancies.   The Guidance makes clear that the agencies have a zero tolerance policy as to deposit discrepancies and expect “financial institutions to adopt deposit reconciliation policies and practices that are designed to avoid or reconcile discrepancies, or designed to resolve discrepancies such that customers are not disadvantaged.”  The agencies expect financial institutions to:

  • Effectively manage their deposit reconciliation practices;
  • Insure that information provided to customers as to their deposit reconciliation policies is accurate;
  • Implement effective compliance management systems that include appropriate policies, procedures, internal controls, training and oversight; and
  • Review processes to ensure compliance with applicable laws and regulations.

While the Guidance provides for a zero tolerance policy, financial institutions are reminded that they are not liable for “bona fide errors”.  To establish a bona fide error, a financial institution must establish that a violation was not intentional and resulted from a bona fide error notwithstanding the maintenance of procedures reasonably adapted to avoid any such error.  It is therefore imperative that financial institutions review their compliance management systems to insure they:

  • Provide proper vendor management to ensure their service providers and affiliates properly and accurately resolve deposit discrepancies;
  • Include written policies and procedures for conducting audits to insure deposits and deposit discrepancies are accurately handled, including the frequency, scope and depth of said audits;
  • Put in place compliance measures, as well as policies, procedures and practices, to ensure accurate processing of deposits and deposit discrepancies;
  • Incorporate sufficient monitoring and oversight of the processing of deposits and deposit discrepancies;
  • Incorporate training of personnel to insure accurate resolution of deposit discrepancies; and
  • Incorporate complaint procedures and processing to ensure deposit discrepancy complaints are identified, tracked and resolved in accordance with the Banks’ policies and procedures.

.

Thursday, August 13, 2015

Federal Regulators and the CFPB Fine Bank and Order Remediation as to Deposit Discrepancies


In a joint enforcement action, the CFPB, OCC and FDIC have entered into consent orders with Citizens Bank N.A., Citizens Bank of Pennsylvania and their parent company, Citizens Financial Group, Inc.  (the “Banks”). The consent orders allege the Banks engaged in unfair and deceptive practices between 2008 and 2013 with respect to their handling of deposit discrepancies.  In total, the Banks are being ordered to refund any deposit discrepancies which were not properly credited to customer accounts (estimated to be in excess of $16 million dollars) and pay over $20 million in penalties.  Additionally, the Banks are being ordered to remediate their practices and put compliance management programs and audit procedures in place to prevent further issues.

The consent orders allege that between January of 2008 and November of 2013, the banks violated §5 of the FTC Act and §1036 of Dodd Frank by engaging in unfair and deceptive practices regarding their deposit discrepancy policies.  The consent orders allege that the Banks’ violations were two fold.  The Consent Orders allege that the Banks told customers that deposits were subject to verification, suggesting that the banks would take steps to ensure deposits were accurately credited when a discrepancy arose between the deposit slip and the actual amount of the deposit.  Second, the Banks made no adjustments to the deposit amounts where deposit discrepancies were under a certain threshold ($50 from January 2008-September 2012 and $25 from September 2012 through November 2013). In other words, the deposits were credited for the amount on the deposit slip irregardless of the discrepancy.  The net effect was that if a customer miscalculated its deposit and the discrepancy was under the thresh hold, the deposit was never credited to reflect the discrepancy. 

The Orders require the Banks to:

  • Provide proper vendor management to ensure their service providers and affiliates properly and accurately resolve deposit discrepancies;
  • Establish a Compliance Committee to monitor and coordinate the Banks’ adherence with the consent orders;
  • Develop a written Consumer Compliance Internal Audit Program for the processing of deposits and deposit discrepancies which includes written policies and procedures for conducting audits to insure deposits and deposit discrepancies are accurately handled, including the frequency, scope and depth of said audits;
  • Submit a Compliance Plan which:
    • Puts in place compliance measures, as well as policies, procedures and practices, to ensure accurate processing of deposits and deposit discrepancies;
    • Incorporates sufficient monitoring and oversight of the processing of deposits and deposit discrepancies;
    • Incorporates training of personnel to insure accurate resolution of deposit discrepancies; and
    • Enhance or incorporate complaint procedures and processing to ensure despot discrepancy complaints are identified, tracked and resolved in accordance with the Banks’ policies and procedures.

The Orders additionally require the Banks to reimburse affected account holders for the amount of any funds not properly credited to their account as a result of the discrepancy, plus any bank charges resulting from the under-crediting (for instance, overdraft) and interest.  Additionally, the Orders require the following civil penalties: $7.5 million to the CFPB, $3 million to the FDIC and $10 million to the OCC.