Showing posts with label vendor management. Show all posts
Showing posts with label vendor management. Show all posts

Sunday, October 31, 2021

Crucial Conversations All Debt Collectors Should Have with their Creditors

 

With the CFPB having decided to leave the effective date of the Debt Collection Rule as November 30th, the push is on for debt collectors to ensure their compliance with the Rule by that date. As debt collectors make the final push towards implementation, there are crucial conversations debt collectors should be having with creditors to ensure a smooth transition.

Referral of the Account.  Debt collectors should be discussing the referral process with their clients to ensure a clear understanding of the amount of the debt and what new or additional information creditors will need to provide for the debt collector to initiate collections. 

As we all know by now, the Rule introduces as a new concept the “itemization date.”  Because the Rule requires the debt collector identify an “itemization date” and provide an itemization of the debt from that itemization date through the validation notice, it’s important both the creditor and the debt collector understand what comprises the balance being sent for collection and upon which “itemization date” it is based. 

Section 1006.34(b) of the Rule allows debt collectors to choose one of five specified reference dates as their “itemization date:”

· the last statement date, which is the date of the last periodic statement or written account statement or invoice provided to the consumer by the creditor;

·  the charge-off date, which is the date the creditor charged off the account;

 ·   the last payment date, which is the date the last payment was applied to the debt; 

 ·   the transaction date, which is the date of the transaction that gave rise to the debt; or

·   the judgment date, which is the date of a final court judgment that determines the amount of the debt owed by the consumer.

 12 C.F.R. 1006.34(b)(3) (effective November 30, 2021).

Selection of an itemization date will necessarily require the debt collector have a clear understanding of how the creditor arrives at the balance and conversely, that the creditor understand that its balance needs to relate back to one of the five itemization dates.  Moreover, the creditor will need to include with the balance an itemization of the interest, fees, payments, and credits which have accrued since the itemization date.

 Communication Channels.  One of the hallmarks of the Rule is its attempt to implement the use of more modern communication channels within the limitations of the Fair Debt Collection Practices Act.  The Rule provides for the use of email and text communications and provides specific procedures which, if followed, provide the debt collector with a safe harbor with respect to electronic communications and unintentional third-party electronic communications.  To the extent the creditor or debt collector want to take advantage of these options, a conversation should be had as to how consent from the consumer will be obtained.  One of the options provided is based upon prior communications with the creditor.  For debt collectors who want to take advantage of this option, conversations should be had with creditors to ascertain what notices are being provided to consumers so the debt collector can ascertain their sufficiency for compliance with the Rule. 

Adjust Expectations of the Creditor.  With the introduction of a more robust debt validation notice, creditors should understand that delays are likely in the collection process.  By providing an understanding to the creditor (and adjusting expectations accordingly), creditors are more likely to have a better appreciation of the collection process and the challenges facing debt collectors.  Debt collectors should be examining their adjusted policies and procedure to ascertain what changes might impact or delay their collection efforts.

Here are a couple of examples of changes debt collectors may consider explaining and discussing with their creditor clients.  First, the validation period will be prolonged by the addition of at least five business days to the validation period. See 12 CFR 1006.34(b)(5)  (effective November 30, 2021) (which states that the validation period ends 30 days after receipt and allows the debt collector to assume the consumer received the validation notice any date that is “at least five days (excluding legal public holidays … Saturdays, and Sundays) after the debt collector provides it.  By its very nature, the first communication is now less of a demand for payment and more of a statutorily required notice.  If this impacts the collection processes, consider making creditor clients aware so they can adjust their expectations and have a better understanding of the challenges you (and the rest of the industry) face.  

Secondly, the validation notice’s inclusion of the dispute form (with convenient boxes to be checked) will likely increase the number of disputes and requests for validation that debt collectors receive, as well as the corollary requests for information to creditors.  Creditors will benefit from understanding the anticipated increase in requests for additional information either at the validation/dispute stage or at the  initial forwarding stage.

Thirdly,  credit reporting cannot occur until after the debt collector communicates with the consumer (usually by the debt validation notice) and waits a reasonable period of time to receive a notice of undeliverability (which the Official Interpretation identifies as being 14 days).  To the extent collection agencies are credit reporting and will be changing when they initiate credit reporting, collection agencies should discuss this change with their clients and make any necessary adjustments to the Collection Services Agreement or performance standards that are necessary.

Review Your Collection Services Agreement. Finally, now is a good time to revisit Collection Services Agreements to ensure they are consistent with the Debt Collection Rule, particularly regarding such things as validation and disputes, credit reporting and communication frequency.  To the extent there are inconsistencies, now is the time to have that discussion with your creditors and amend those agreements.

As Joseph Grenny, the author of Crucial Conversations, once said “[a]t the core of every successful conversation lies the free flow of relevant information.”  Make time to have those crucial conversations with your clients regarding the Rule to ensure a smooth transition.

 

Friday, January 22, 2021

The CFPB Publishes the Remainder of its Final Debt Collection Rule – Here’s What You Need to Know

 By Caren D. Enloe

On December 18, 2020, the CFPB published the remainder of its Final Debt Collection Rule (the “Rule”) highlighting its crown jewel -  the provisions centering around debt validation notices.  While the bulk of Part 2 addresses the parties’ obligations under Section 1692g of the FDCPA, the remainder of Part 2 ties up other loose ends, including time-barred debt, credit reporting, and communications where the consumer is deceased. The entire Rule (both Parts 1 and 2) takes effect November 30, 2021.

Aside from Debt Validation, What’s Included in Part 2 of the Rule?

            Deceased Consumers

The FDCPA defines a consumer as any natural person obligated or allegedly obligated to pay a consumer debt.  Section 1006.2(c) of the Rule interprets 1692a(3) to include deceased natural persons.  This definition dovetails with 1006.6 (Communications in Connection with Debt Collection) to allow debt collectors to communicate with the deceased consumer’s spouse, parent (if the consumer is a minor), legal guardian, executor or administrator, and confirmed successor in interest (as defined Regulation X).  Additionally, Section 1006.34 makes provision for sending debt validation notices when the consumer is deceased.

Collection of Time-Barred Debt

Perhaps the biggest surprise in Part 2 of the Rule is the CFPB’s seeming abandonment of time-barred debt and revival disclosures.  Debt collectors, however, should not assume that those disclosures will not be forthcoming at a later date.  Instead, the CFPB notes that it determines only that the specific disclosure requirements proposed “may not sufficiently accommodate the concerns raised by different stakeholders.” 

Section 1006.26 of the Rule prohibits legal actions or threats of legal actions against a consumer to collect time-barred debts.  The Rule defines “time-barred debt” to mean a debt for which the statute of limitations has expired. “Statute of limitations,” in turn, is defined as the period prescribed by applicable law for bringing a legal action against a consumer to collect a debt. Notably, Section 1006.26 differs from the proposed version of the Rule in that it implements a strict liability standard rather than the proposed “know or has reason to know”  which was originally proposed.  As finalized the Rule additionally makes clear that the filing of a proof of claim is not a legal action subject to this provision.

Credit Reporting Restrictions

The CFPB published the majority of Rule’s catch-all section, §1006.30, in Part 1 of the Rule.  The CFPB, however, held back the provisions regarding passive debt collection through credit reporting until Part 2.  While Section 1692d(3) of the FDCPA allows for credit reporting, the Section 1006.30(a) of the Rule now limits the circumstances and timing for credit reporting and prohibits the practice of passive debt collection through credit reporting.

Section 1006.30(a) prohibits debt collectors from furnishing information to a consumer reporting agency about a debt before the debt collector either speaks to the consumer about the debt in person or by telephone or sends its validation notice and then waits for a reasonable period of time to receive a notice of undeliverability. Comment 30(a)(1)-2 provides a presumption that a reasonable period of time is 14 consecutive days after the date that the communication is sent. As an exception to the Rule, 1006.30(a) additionally allows for debt collector’s immediate furnishing to a specialty consumer reporting agency that compiles and maintains a consumer’s check writing history.

Debt Validation Notices Under the Final Rule

The crown jewel of Part 2 of the Rule is Section 1006.34 which takes on section 1692g(a) of the FDCPA.  Section 1006.34 provides new delivery requirements and concepts while expanding the information required in the debt collector’s validation notice.  

    Delivery Methods

Consistent with the Rule’s stated goal to allow for technological advances, Section 1006.34 allows for the notice to be provided in writing and orally, as well as electronically.  

    Deceased Consumers           

Section 1006.34 additionally recognizes the consumer to include deceased consumers. Comment 1006.34(a)(1)-1 makes clear that if the debt collector knows or should know that the consumer is deceased, and if the debt collector has not previously provided the validation notice to the deceased consumer, the debt collector must provide the debt validation notice to a person authorized to act on behalf of the deceased consumer’s estate.

The Itemization Date

The Rule introduces a new concept that is not present in the FDCPA – the “itemization date.”  The Rule now requires the debt collector identify an “itemization date” and provide an itemization of the debt from that date forward.  Section 1006.34(b) of the Rule allows debt collectors to choose one of five specified reference dates as their “itemization date:” 

  • the last statement date, which is the date of the last periodic statement or written account statement or invoice provided to the consumer by the creditor;
  • the charge-off date, which is the date the creditor charged off the account;'
  • the last  payment date, which is the date the last payment was applied to the debt;  
  • the transaction date, which is the date of the transaction that gave rise to the debt; or 
  • the judgment date, which is the date of a final court judgment that determines the amount of the debt owed by the consumer.

 The Rule’s Official Comments provide a couple of key clarifications as to the itemization date. For debt collectors choosing to use the last payment date, the Comments clarify that the last payment includes a third party payment applied to the debt.  This means that last payment date includes the date when sales proceeds were applied or when insurance reimbursements were applied to the debt. For debt collectors choosing to use the last statement date, the Comments clarify that it is the date of the last statement provided by the creditor and may include those provided by a third party acting on the creditor’s behalf, such as a servicer.  Finally, for those debt collectors relying upon a transaction date, if a debt has more than one transaction date, the debt collector may use any such date as the transaction date so long as they use it consistently. Finally, while the Rule requires the debt collector to choose an itemization date and disclose it, the Rule does not require the debt collector to disclose the itemization date category upon which it relies.

Content of the Validation Notice

Section 1006.34 expands upon the requirements of the FDCPA and requires a debt collector provide additional information about the debt in its validation notice.  Under the Rule, the validation notice requires debt collectors provide: (a) information to help consumers identify the debt; (b) information about consumer protections; and (c) information to help consumers exercise their rights.  The Rule additionally allows for and identifies certain optional disclosures.

        Information to Help Consumers Identify the Debt

While the FDCPA only requires the debt collector provide the amount of the debt and the name of the creditor to whom the debt is owed, the Rule is far more expansive.  Section 1006.34(c) of the Rule requires the validation notice include: 

  • the debt collector’s name and the mailing address at which it accepts disputes and requests for original creditor information;
  • the consumer's name and mailing address; 
  • the identity of the “itemization date” creditor for debt related to consumer financial products or services;
  • the identity of the current creditor; 
  • the account number or a truncated version of the same;
  • the "itemization date;"
  • the amount of the debt on the itemization date;
  • an itemization of the debt since the itemization date; and
  • the current amount of the debt.

Residential mortgage debt subject to the mortgage servicing rules and their periodic statement requirements may be excepted from certain itemization requirements if the debt collector furnishes a copy of the most recent periodic statement provided to the consumer with the validation notice.  Section 1006.34(d) of the Rule provides the option, but does not require, a debt collector to provide its telephone contact information, a reference code the debt collector uses to identify the debt or the consumer, and the merchant brand, affinity brand or facility name for the debt.


          Information About Consumer Protections

In addition to advising the consumer of his or her rights pursuant to section 1692g(a) of the FDCPA, Section 1006.34(c) now requires the debt collector provide the end date for the validation period.  To allow for delivery of the validation notice, Section 1006.34(b)(5) of the Rule provides that a debt collector may assume that a consumer receives the validation information on any date that is at least five business days (excluding certain public holidays identified in 5 U.S.C. §6103(a), Saturdays and Sunday) after the debt collector provides the notice. Debt collectors should therefore provide at least  40 calendar days in calculating their end date of the validation period in order to account for the five business date rule.

In addition to the traditional disclosures required by the FDCPA, the Rule requires: inclusion of the Mini-Mirada disclosure, and if the debt is related to a consumer financial product or service, a statement that additional information regarding consumer protections for debt collection is available on the CFPB’s website and provide the website link.  Finally, if the validation notice is being sent electronically, a statement explaining the consumer can dispute the debt or request original creditor information electronically.

Information to Help Consumers Exercise Their Rights

To help consumers exercise their rights under 1692g(a), Section 1006.34(c) requires debt collectors provide the consumer with a response section that includes dispute prompts under the headings “How do you want to respond?” and “Check all that apply.” The dispute response must include the following prescribed dispute statements and list them in the following order:

  • "I want to dispute the debt because I think:”;
  •  “This is not my debt.”; 
  •  “The amount is wrong.”; and 
  •  “Other (please describe on reverse or attach additional information.)”

The Rule additionally requires the following additional prompt: “I want you to send me the name and address of the original creditor.” 


This tear off section must additionally include the debtor’s name and address, as well as the debt collector’s name and the address at which it receives debt validation requests.  The Rule also allows as optional certain payment disclosures but makes clear that any payment disclosures must appear below the mandated prompts.


State Law and Other Applicable Law Disclosures

Section 1006.34(d) recognizes and allows for state mandated disclosures among the “optional” disclosures. The Rule allows for these to be placed on the reverse side of the validation notice.  For such disclosures, however, the debt collector must place a statement on the front of the validation notice referring to those disclosures.  Importantly, the Rule specifies that such disclosures on the reverse side of the notice must appear above the tear off section. 

The Rule also recognizes that certain jurisdiction require or provide a safe-harbor as long as a disclosure is provided.  For those disclosures, the Rule requires that they be disclosed on the front of the validation notice.

Other Optional Disclosures

Section 1006.34(d) allows for certain other optional disclosures.  In addition to those already noted, The Rule allows for disclosures regarding a consumer’s ability to request a Spanish-language translation of a validation notice.  Likewise, a debt collector may send its validation notice completely and accurately translated in another language so long as certain additional conditions are met. 

In addition, the Rule allows a debt collector to disclose its website and email address.  Finally, if the validation notice is not provided electronically, the Rule allows a debt collector to provide a statement explaining how a consumer can dispute the debt or request original-creditor information electronically.

Safe Harbor Provisions.

The Rule includes a model form and a safe harbor for those that use the model form. Deviations are allowed, provided that the content, format, and placement of information are substantially similar to the model form. Debt collectors should not that deviations may at least in part negate the safe harbor protections.

What’s Next?

Collection agencies should begin preparing for the November 30, 2021 effective date.  Among other things:

  • All compliance teams should begin a thorough review of the Rule and Comments to assess what changes will need to be made to the agency’s practice and procedures;
  • All policies and procedures should be similarly updated and training programs should be undertaken with staff to ensure their understanding of the Rule;
  • All scripts should be reviewed and adjusted to comply with the Rule;
  • All letters should be reviewed and adjusted to comply with the Rule and the agencies should begin coordinating with their letter vendors to ensure a smooth transition on November 30, 2021;
  • Agencies should begin reviewing and assessing their ability and desire to use electronic communications, keeping in mind other statutory requirements that may also be in play, including the Telephone Consumer Protection Act, as well as their clients’ use of electronic communication consents;
  • Agencies should begin discussing and coordinating with their first party clients the itemization date and what additional information will need to be provided to the agency at placement to ensure compliance with Section 1006.34’s new validation requirements;
  • Agencies should begin reviewing and assessing applicable state disclosure requirements to ascertain their impact on the agency’s ability to use the Safe Harbor Validation Notice and what adjustments, if any, will need to be made to address the same; and
  • Agencies should begin assessing and adjusting their credit reporting practices to ensure compliance with new requirements.


Caren Enloe is a partner with Smith Debnam in Raleigh, NC and leads the firm’s Consumer Financial Services Litigation and Compliance Group.  Caren additionally serves as the Chair of the American Bar Association’s Debt Collection and Bankruptcy Subcommittee.  Active in a number of trade groups, Caren serves as the Member Attorney Program State Chair for ACA International and as a member of the National Creditors Bar Association’s Defense Bar.      

 

Thursday, October 26, 2017

CFPB Issues “Principles” for the Protection of Consumer Authorized Data Sharing and Aggregation


By Caren Enloe
October 26, 2017


With the growth of technology and the development of the fintech market, an unprecedented amount of consumer financial data has become available.  While protections through the FTC Safeguard Rule and EFTA provide certain consumer protections, there are coverage gaps as the regulatory scheme has struggled to keep up with technological advancements. 

In recognition of these competing forces and this growing market of consumer services, the CFPB issued a Request for Information in November of 2016 inquiring as to market practices related to consumer access to financial information and related data aggregation services.  Last week, the CFPB published their findings, as well as their Consumer Protection Principles which are designed to “reiterate the importance of consumer interests to all stakeholders in the developing market for services based on the consumer-authorized use of financial data.”  While the Principles are “not intended to alter, interpret, or otherwise provide guidance on the scope” of existing consumer protections under existing statutes and regulations or establish binding requirements or obligations relevant to the Bureau’s exercise of its rulemaking, supervisory or enforcement authority”, they appear to be the first step in filling some of the current regulatory gaps.

The CFPB Principles address nine general areas of concern:

  • Access.  The Principles recognize the right of consumers to be “able, upon request, to obtain information about their ownership or use of a financial product or service” from the product or service provider.  The Principles also support the consumer’s right to “authorize trusted third parties to obtain such information from account providers to use on behalf of consumers, for consumers benefit, and in a safe manner.”   
  • Data Scope and Usability.  The Principles set forth that the scope of data that may be made available should be broad; however, the data available to “third parties with authorized access” should be limited to that which is “necessary to provides the product(s) or service(s) selected by the consumer and only maintain such data as long as necessary.”
  • Control and Informed Consent.  The Principles emphasize the consumer’s right to control data access and the need for terms as to access, storage, use and disposal to be clearly communicated and understood by the consumer.  The Principles additionally emphasize the importance that the consumer understand and be provided with data sharing revocation terms that can readily and simply be invoked as to access, use and storage of data.
  • Authorizing Payments.  The Principles advocate for separate and distinct authorizations for data access and payment authorization.
  • Security.  The Principles recognize the gaps that potentially exist in the FTC Safeguard Rules and whether or not certain data aggregation providers are required to comply (as they may fall into a gap between covered financial service providers and vendors).  With regard to security, the Principles recognize the need for market participants to securely access, store, use, and distribute data in formats and manners which protect against security breaches.  The Principles further advocate for secure access credentials and effective processes that “mitigate the risks of, detect, promptly respond to, and resolve and remedy data breaches, transmission errors, unauthorized access, and fraud, and transmit data only to third parties that also have such protections and processes” in place.
  • Access Transparency.  Consumers should be informed of or able to readily ascertain “which third parties that they have authorized are accessing or using information regarding the consumers’ accounts or other consumer use of financial services.”  The Principles emphasize the ability of consumers to ascertain the “identity and security of each such party, the data they access, their use of such data, and the frequency at which they access the data.”
  • Accuracy.  The Principles express the expectation that data that consumers access or authorize others to access is current.
  • Ability to Dispute and Resolve Unauthorized Access.  The Principles set forth the expectation that consumers “have reasonable and practical means to dispute and resolve instances of unauthorized access and data sharing, unauthorized payments conducted in connection with or as a result of either authorized or unauthorized data share access, and failures to comply with other obligations , including the terms of consumer authorizations.”
  • Efficient and Effective Accountability Mechanisms.  Commercial participants are held accountable for “the risks, harms and costs they introduce to consumers” and are “incentivized and empowered effectively to prevent, detect and resolve unauthorized access and data sharing, unauthorized payments” and “failures to comply with other obligations, including terms of consumer authorizations.

The Bureau’s Report as to the November RFI reflects consensus amongst stakeholders that market participants need to work together to develop data access and use practices that are based upon a shared set of standards and expectations that address consumer protection.  Those engaged in fintech should carefully monitor developments in this area, as well as the CFPB’s developing position as to their role in regulating the same.

Wednesday, November 30, 2016

CFPB Issues Compliance Bulletin as to Incentives in Wake of Wells Fargo Consent Order


In the wake of the Wells Fargo debacle, the CFPB has issued a Compliance Bulletin which addresses employee incentives and the consumer risks associated with them.  CFPB Compliance Bulletins are non-binding general statements of CFPB policy.  The Bulletin notes that while businesses and consumers alike may benefit from the use of incentives when properly implemented and monitored, incentives may also lead to significant consumer harm when effective controls for risk are not in place. 

Key to the Bulletin is the CFPB’s articulation of its vision for an effective compliance management system addressing employee incentives.  While effective compliance management systems are not contemplated to be a one size fits all proposition, they should take into account the risk, nature and significance of the incentive program.  The Bulletin describes an effective compliance management system as generally addressing the following:

  • Board of Directors and Management Oversight.  An effective compliance management system will foster strong customer service and should take into account the following components:
    • Board members and senior management should take into account not only the outcomes their incentive programs seek to achieve but also how they may incentivize outcomes that are harmful to consumers;
    • Board members and senior management should authorize compliance personnel to design and implement compliance management elements which anticipate both intended and unintended outcomes and provide compliance personnel with sufficient resources to do so; and
    • Board members and senior management should foster an environment that empowers employees to report suspected improper behavior.
       
  • Policies and Procedures. The CFPB notes that policies and procedures regarding incentives should provide:
    • Sales/collection quotas tied to employee incentives should be reasonably attainable and transparent;
    • Clear controls managing the risk inherent in each cycle of a product’s life including marketing, opening of the account, servicing the account and collection of the account;
    • Mechanisms to identify conflicts of interest presented by supervisory employees who are covered by incentives but tasked with monitoring the quality of consumer treatment and satisfaction; and
    • Fair and independent processes for investigating issues of suspected improper behavior.
       
  • Training.  Training should be implemented and should:
    • Address the institution’s expectations for incentives;
    • Address the institution’s expectations and standards of ethical behavior;
    • Identify and address common risky behaviors;
    • Foster a greater awareness of areas for risk;
    • Educate employees and service providers as to the terms and conditions of the institution’s products and services;
    • Address regulatory and business requirements, including requirements for documenting consent (a point of emphasis in the wake of the Wells Fargo enforcement action)
       
  • Monitoring.  Overall monitoring systems should track key metrics and outliers that may be indicative of abuse.  Examples provided by the CFPB include:
    • Employee turnover;
    • Employee complaint rates;
    • Analysis of termination statistics for trends and root causes;
    • Spikes or trends in sales associated with an individual, group or product;
    • Financial incentive payouts;
    • Account opening/enrollment statistics by group and individual; and
    • Account closures/product cancellation by group and individual.
       
  • Corrective Action.  The Compliance Management Systems should provide for the prompt identification and implementation of corrective actions addressing any areas of weakness.  The CFPB expects corrective actions to include:
    • Termination of bad actor employees (including managers) and service providers;
    • Changes in the structures of incentive programs and training of affected employees;
    • Remediation in the form of refunds to affected consumers;
    • Identification, analysis and resolution of root causes of deficiencies; and
    • Escalation to the Board and Senior Management, particularly where there is risk of significant harm to consumers.
       
  • Consumer Complaint Management Program.  As was noted in the Wells Fargo Order and confirmed by the Bulletin, the CFPB expects institutions to collect and analyze consumer complaints for indicators that incentives are leading to consumer harm or violations of law in order to identify and resolve the root causes of any such issues.
     
  • Independent Compliance Audit.  The CFPB expects Compliance Management Systems to provide for periodic independent compliance audits.  Institutions’ Compliance Management Systems should therefore:
    • Provide for and schedule audits for all products subject to incentives.  Audits should address incentives and potential consumer risks;
    • Insure audits are conducted independently of both the compliance program and business functions; and
    • Insure all necessary corrective actions are promptly implemented.
       

Financial institutions who use incentive programs should take some comfort in the fact that the CFPB acknowledges that incentive programs, when properly implemented, may be beneficial to the marketplace.  At the same, time, financial institutions should be aware that incentive programs are being carefully scrutinized.  It is therefore incumbent on financial institutions to carefully review their compliance management programs as to incentive programs.  The level of specificity provided by the CFPB Bulletin suggests that this will likely be the measuring stick used in current and upcoming examinations and that incentive programs will be a point of emphasis by regulators in general.

Saturday, November 12, 2016

CFPB Supervisory Highlights: Auto Loan Servicers Should Re-Examine their Repossession Fee Policies


Auto loan servicers need to pay careful attention to their repossession practices and particularly, their policies concerning repossession fees. The clear message from the CFPB’s Supervisory Highlights is that examiners are focused on repossession activities, “including whether property is being improperly withheld from consumers, what fees are charged, how they are charged, and the context of how consumers are being treated to determine whether the practices are lawful.” Supervisory Highlights, p. 6 (Issue 13, Fall 2016).

The Report makes clear that the CFPB’s position is that it is an unfair practice to detain or refuse to return personal property found in a repossessed vehicle where the consumer requests return of the property.  Similarly, it is an unfair practice to detain or refuse to return personal property until the consumer pays a fee. According to the CFPB, even when the consumer agreements and state law may support the imposition of a fee, there are no circumstances in which it is “lawful to refuse to return the property until after the fee…[is] paid, instead of simply adding the fee to the borrower’s balance as companies do with other repossession fees.” Id.    The Report also noted that in one or more examination, companies engaged in an unfair practice by charging a borrower for a storage fee for personal property found in the repossessed vehicle when the consumer agreement disclosed that the property would be stored, but not that a fee would be imposes for doing so.

Auto loan servicers need to examine their policies and procedures regarding their repossession practices to insure they are in line with the CFPB expectations.  Additionally, auto loan servicers should monitor their third party vendors’ practices for compliance with the CFPB examinations and make any adjustments necessary as to repossession fees.

Friday, November 11, 2016

CFPB Supervisory Highlights: It’s all about the Compliance Management System


The CFPB published its Fall Supervisory Highlights last week, highlighting its examination observations across various financial products for examinations conducted between May and August 2016.  The Report highlights key findings made by the CFPB and provides insight into the current focus of the examiners.  The current edition of Highlights reveals a heavy focus on compliance management systems across product types. Because of the volume of information in the Report, we will break down the Report over several blog posts in the coming week. 

There’s a country song that says “it’s all about that bass”.  In the case of regulatory compliance, it’s all about that compliance management system.   Nowhere is that more evident than in this issue of the CFPB’s Supervisory Highlights.  Throughout the report, the CFPB highlights and defines what constitutes a strong compliance management system (“CMS”) and what does not.  It is clear that the CFPB is honing in on a theme which has become prevalent throughout many of its enforcement actions: “beneficial practices centered on good compliance management systems” go a long way.

To that end, the Report provides insight into what constitutes a strong CMS. Particularly, the Reports singles out the qualities of strong compliance management systems in automobile finance, debt collection, mortgage and fair lending.  Generally, what constitutes a compliance management system is dependent upon the size of the business, its risk profile and its operational complexity.   The Report noted, however, that that a strong compliance management system generally reflects:

  • Strong and active boards and management oversight.  The Report set forth the expectation that boards and management:
    • Demonstrate clear expectations about compliance;
    • Have an adequate compliance audit program;
    • Adopt clear policy statements regarding consumer compliance; and
    • Ensure that compliance-related issues are raised to the board of directors or management.
  • Policies and procedures to address compliance with all applicable consumer financial laws relating to the product;
  • Current and complete compliance training designed to reinforce policies and procedures that is tailored to job functions and updated as needed;
  • Adaptive internal controls and monitoring processes which provide for timely corrective actions where appropriate;
  • Policies and procedures setting forth clear expectations for timely handling and resolution of complaints;
  • Processes for appropriately escalating and resolving consumer complaints including analysis for root causes, patterns or trends;
  • Processes for escalating identified violation trends to management for proposed changes to policies and procedures;
  • Comprehensive audit programs that are independent of the compliance program and business functions; and
  • Strong oversight of service providers commensurate with the risk and complexity of the processes or services provided.

Institutions need to view their compliance management system as part of an eco-system that is always changing.  Compliance management systems should be reviewed on an ongoing basis and remain adaptive.  While a strong compliance management system may not prevent violations and regulatory irregularities, it certainly can mitigate the damage and the most recent Supervisory Highlights makes clear that the CFPB continues to make them a point of emphasis.

Wednesday, November 2, 2016

CFPB Amends its Vendor Management Guidance


The CFPB has amended its guidance on vendor management. According to the CFPB, the amendment was necessary to “clarify that the depth and formality of the risk management program for service vendors may vary depending upon the service being performed – its size, scope, complexity, importance and potential for consumer harm.”  CFPB Bulletin 2016-02.  The Bulletin, like its 2012 predecessor, makes clear that the supervised entities are responsible with their service providers for their service providers’ compliance with federal consumer financial laws. “While due diligence does not provide a shield against liability for actions by the service provider, it could help reduce the risk that the service provider will commit violations for which the supervised bank or nonbank may be liable...”  

 

The Bulletin set forth a number of nonexclusive steps it expects covered institutions to take in managing their service providers:

 

  • Doing due diligence to insure their service providers understand and are capable of complying with applicable consumer financial laws;
  • Requesting and reviewing their service providers’ policies, procedures, internal controls, and training materials to insure their service providers are providing adequate training and oversight to insure compliance with applicable consumer financial laws;
  • Providing contractual provisions in their vendor agreements that provide clear expectations of compliance, as well as appropriate and enforceable consequences for any failure to comply;
  • Insuring that service providers are prohibited from unfair, deceptive or abusive acts or practices, as well as violations of specific federal consumer financial laws;
  • Establishing internal controls and on-going audits and examinations of service providers to insure their continued compliance; and
  • Taking prompt action to address problems identified through the monitoring process, including termination of relationships, if appropriate.

 

Moreover, the Bulletin makes clear that the CFPB takes the position that it has supervisory and enforcement authority over bank and nonbank supervised service providers and “will exercise the full extent of its supervisory authority over supervised service providers, including its authority to examine for compliance with Title X’s prohibition on unfair, deceptive, or abusive acts or practices.”  Service providers and supervised entities alike can expect the CFPB to expand its enforcement net to include entities which are not otherwise covered by the CFPB. 

 

Supervised entities should review their vendor management policies and shore up any weaknesses in their compliance management systems with respect to their vendor management relationships.  Service providers, meanwhile, should be reviewing their own policies and procedures to insure compliance with all applicable consumer financial laws.  Both supervised entities and service providers should review the CFPB’s Supervision and Examination Manual: Compliance Management Review andUnfair, Deceptive and Abusive Acts or Practices.