Compliance Management System (CMS) Flashcards
What are the 3 types of supervisory activities/ strategies conducted by the FDIC?
Examinations, visitations, and investigations.
Purpose of a visitation?
Targeted event aimed at specific operational areas, or entire compliance management systems previously identified as significantly deficient.
Purpose of an investigation?
Conducted to follow-up on specific consumer inquiries or complaints, including fair lending complaints.
Purpose of examination? (3)
• assess the quality of an FDIC-supervised institution’s CMS for implementing federal consumer protection statutes and regulations;
• review compliance with relevant laws and regulations; and
• initiate effective supervisory action when elements of an institution’s CMS are deficient and/or when violations of law are found.
What does risk-focusing involve? (3)
Developing a compliance risk profile for a bank using Products, Services, or Regulations (PSRs), and the bank’s organizational structure, operations, and past performance.
Assessing quality of CMS in light of inherent risks from the level and complexity of business operations, products, and services.
Transaction testing based on residual risk.
What is reviewed under Board and Management oversight? (7)
Commitment and oversight of CMS.
Third party due diligence
Change management
Due diligence from product or service changes (pre and post)
Comprehension and identification of compliance risks including emerging risks in the bank’s products, services, etc.
Management of risk (self-assessments)
Identification and responsiveness to CMS deficiencies, violations, and remediation.
What is reviewed under the compliance program?
Policies and procedures
Third-party management
Monitoring & audit
Consumer complaint response.
What should be considered when evaluating a bank’s CMS?
The size, level complexity of the bank.
A bank is not required to have all elements of a CMS. Conclusions about the adequacy of a bank’s CMS must be based on the
effectiveness of those elements that are in place, taken as a whole, for that bank’s particular operations.
What is the purpose of the ROE?
The Report of Examination
provides an account of the strengths and weaknesses of a CMS to the Board.
What is Supervisory Guidance?
Unlike a law or regulation, supervisory guidance does not have the force and effect of law, and the agencies do not take enforcement actions based on supervisory guidance. Rather, supervisory guidance outlines the agencies’ supervisory expectations or priorities and articulates the agencies’ general views regarding appropriate
practices for a given subject area.
What is Consumer Harm?
Actual or Potential injury or loss to a consumer whether such injury or loss is economically quantifiable (ex: overcharge) or non-quantifiable (ex: discouragement). May be caused by activities through a third-party.
What is quantifiable harm?
Economic harm to a consumer where the injury or loss can be measured.
What type of consumer harm is this?
Deceptive marketing
practices that entices a consumer to purchase a product without having accurate information regarding the benefits,
costs, or terms of the product in violation of Section 5 of the Federal Trade Commission Act.
Quantifiable Harm
What type of consumer harm is this?
Bank employs a pricing structure that allows significant discretion, without effective monitoring or controls, resulting in a protected class of borrowers being charged higher prices on average than similarly situated non-protected borrowers in violation of the Equal Credit Opportunity Act
Quantifiable harm
What is non-quantifiable harm?
Injury or loss to the consumer that cannot be measured, or is very difficult to measure, yet the consumer may suffer some form of economic or other harm.
What type of consumer harm is this?
Financial institution unfairly denies the consumer
credit or discourages an application on a prohibited basis in violation of the Equal Credit Opportunity Act
Non-quantifiable harm
Consumer was injured economically; however, calculating the monetary value for the injury would be challenging.
What type of consumer harm is this?
Unlawful requirements on consumers before the bank is willing to consider the consumers’ billing disputes or requirements that are not accurately divulged in the bank’s error resolution disclosures.
Non-quantifiable harm
The practice could discourage a customer from filing a dispute, but would be difficult to identify or quantify.
What is potential harm?
Involves financial institution activities (or failure to take action) that create the possibility that a consumer may be harmed.
What type of harm is this?
Violation of the regulations that implement the National Flood Insurance Act of 1968 where the financial institution failed to require flood insurance on a residence at loan closing.
Potential harm
The consumer has not suffered actual loss but is exposed to potential economic loss should a flood occur.
What is the supervisory approach to consumer harm?
Identifying, addressing, and preventing consumer harm.
How to examiners identify consumer harm?
Identification of inherent risk that may occur in a bank’s business activities.
What is inherent risk?
Example?
Compliance risk associated with product and service offerings, practices, or other activities that could directly or indirectly result in significant consumer harm or noncompliance with rule or regulations, if no other controls or mitigating factors were in place.
Ex: new loan product, change in deposit account terms, presence of third party relationships.
How do examiners address consumer harm?
When inherent risks are identified, examiners will ensure the bank takes appropriate action to address or mitigate the risks.
How do examiner’s prevent consumer harm?
Example?
Mitigating factors are the strength of the CMS to mitigate inherent risk.
Ex: Strong management controls, effective training, on-going monitoring efforts.