Saturday, April 1, 2023

A Look at AML Audits - Can you Audit Without a Risk Assessment?

We deal with known risks by establishing a plan to mitigate them. In the case of AML plans for mortgage companies, we face the risk of allowing financial crimes to go undiscovered and enter the financial system through our business. 

We create compliance plans as multi-tiered tools to deal with the risk. The tiers are the four (or five, depending on your business) pillars of an AML plan 

  1. the plan itself - which identifies the risks your business encounters and how you mitigate them
  2. training - your employees learn how to identify and report red flags
  3. compliance officer - the person who implements the procedures, files reports, and ensures the activity, such as training, audits, risk assessments, etc., takes place 
  4. an audit or exam - reviews your plan, determines if it is sufficient for the risks you face, and identifies if you are following it
  5. ongoing review of accounts - if we are servicing, for instance

Static Plans DO NOT Address the Risks - Make Sure you know what they are


We conduct hundreds of AML audits, and the BIGGEST problem we see is that AML plans don't address the risks the business faces explicitly. Furthermore, the audits or tests we see focus on whether the AML plan contains arcane legal citations or reviews a sampling of closed loan files. This is not where the risk is.  

In the mortgage business, we are experts in looking for fraud - documenting sources of funds and ferreting out suspicious income and transactions. This doesn't mean that fraud and suspicious activity doesn't make it through (CoreLogic reports 1 in 131, or 0.76% of loans, are fraudulent). Still, it does mean that the MAJORITY of incidences probably aren't in the files that make it through to closing. So it makes sense to focus our efforts on loans that don't go through a complete underwriting process. 

None of the AML plans and audits we have reviewed focus on risk assessments. Hawaii is the only state we have encountered where they are requesting a specific AML risk assessment - (Bravo! Mahalo!). New York requires large-scale risk assessments of the entire operation, including AML. 

This leads me to conclude that people don't know what a risk assessment is or even why you do one. The purpose of the Risk Assessment is to look at YOUR business for areas of risk. Only then can you create a strategy to mitigate money laundering activity? 

How to Conduct a Risk Assessment?


Depending on the firm's scope, our risk assessments create a binary decision tree instead of a complex "relative risk rating" approach - e.g., low, medium, and high. We do it this way because the risk increases on an absolute basis. One red flag doesn't necessarily indicate fraud or money laundering activity; however, two levels of risk means that we should, at a minimum, document that we validated there were no red flags. We refer to this as "risk layering," where two or more inherent risks exist in a file. 

  • Higher risk components - Company-wide
    • Geography
    • Business model -
      • delegated, non-delegated, 
      • retail/wholesale, etc. 
    • Origination strategy - 
      • direct/indirect
      • relationship/transactional
  • Higher risk components - Loan Level
    • Loan Type
      • Gift Letter
      • ALT/Non-QM
      • Investment
    • Borrower Type
      • Self-employed
      • Real Estate
      • Medical
      • Cash Business
This allows us to have a methodical elevation of the review of the file. 

We do this because things that don't matter to the underwriter from an approval perspective (the loan meets guidelines) often matter for detecting and reviewing red flags. In our business, we review files for these elements, and it always surprises us how often these are overlooked. Examples include:

Deposits not needed for down payment or closing costs - the underwriter isn't concerned about whether a borrower has a $100,000 CD in one bank if he has the $20,000 he needs for closing seasoned in another account. The money has been there forever, and the account doesn't move. But does it make sense that someone who makes $60,000 a year has $100,000 stashed in an account they don't touch? Especially when they have a lot of debt? No, it doesn't. That's a SAR.

Income and Expenses from a side business - the underwriter doesn't include the borrower's side business which involves cash in the computation. He or she has enough income to qualify for the loan. The side job (documented by frequent small dollar cash deposits) is a compensating factor, and the borrower didn't need to provide tax returns because she was on salary. That makes perfect sense, except that if there is more than $5,000 of this kind of activity in the loan file (e.g., 2 months' bank statements), then that triggers a SAR report for "smurfing."

  • Focus on engagements/applications/rate quotes/pre-quals which do not complete
  • The greatest risk lies in loans or prospects not reviewed by underwriting/credit.


Tuesday, February 28, 2023

HMDA Data Reporting Process Changes - LOWER THRESHOLDS

Substantially lower reporting thresholds mean most LENDERS must report HMDA data - Implications for non-delegated correspondents

As you may be aware, a Federal District court ruling in September 2022 changed HMDA reporting thresholds. The previous lookback formula stated that if you made credit decisions on 100 mortgages in each of the previous 2 years, you were required to report in the current year. The ruling reduces the threshold for reporting based on the number of mortgages with credit decisions to 25 in each of the previous 2 years.
Section of manual describing threshold changes

Implications for Non-Delegated Correspondents


It has come to our attention that equal numbers of wholesalers do NOT report HMDA data on correspondent loans as those who do. The HMDA rules stipulate as the credit decision maker must report (in other words, the underwriter/approver), but not all companies follow this edict. Some believe that if your name is on the note, you are the lender of record, and so reporting is your responsibility. YOU MUST CHECK with each wholesaler to find our what their procedures are. If they do not report for you, and you have over 25 loans closed, you must report HMDA data. 

Retroactively Effective



Since the ruling reverses a previous regulation it now applies retroactively. If you were previously not a reporter because you made fewer than 100 loans in each of the previous 2 years, you most likely are now. If you’re a broker, you’re not making credit decisions, so this does not impact you, UNLESS you are denying loans. The CFPB has stated that it will not penalize those organizations which now must report due to the change who are now implementing the new reporting.

We have updated our HMDA Policy to reflect these changes. You may download it here:


Download Updated HMDA Policy


Insert it in your Section 2-42 of your 2-0 Compliance Module

Download Updated HMDA Policy

Wednesday, January 18, 2023

How much information can I share with a real estate agent?

As we get into a more competitive real estate environment, where all-cash offers aren't the only way for a buyer to make an offer that might be accepted by a seller, these questions surface again. Specifically, how much about a customer can we share with a listing or selling agent? 

Understanding Real Estate Agent's Role

First, understand that real estate agents, for the most part, have a fiduciary responsibility to the seller. While selling agents (who work with buyers) say they work for the buyer - and may even have the buyer brokerage disclosure or contract signed - the real estate agent is paid by the seller. So information about a customer's profile, the likelihood of getting financing, and other transactional information a loan originator may possess can be pretty valuable to a seller. 

Loan originators often pass this information out to the agent who referred them to the transaction as a way of currying favor with the agent. You must carefully monitor and limit this data flow for many reasons. For example

  • While negotiating a contract, a seller wants to obtain the highest price and net proceeds. The buyer wants the opposite. If a loan originator offers a prequalification or pre-approval letter, the seller wants to know if the buyer can afford more. The loan originator capitulates and says, "well, he can afford another $200,000 in the loan amount," the seller may counter-offer a higher amount. The buyer, however, asked for prequalification for a certain amount, and the originator's disclosure took away the buyer's leverage. 
  • While processing a transaction, the seller accepts backup contracts, perhaps more favorable than the current contract. With the information that financing is still pending or in question, the seller may act in ways that further diminish the buyer's ability to consummate the transaction to obtain a more favorable sale.
  • The loan is denied, and the seller wants to know "why?" The seller is trying to figure out if the borrower did something wrong - acted in bad faith, perpetrated fraud, or another scheme - that kept the property off the market during the financing contingency period. The seller wants to keep the buyer's deposit because they needed to actively pursue financing. 

Pre-Qualification is NOT an Approval; it's an Opinion

A buyer asks for your opinion on how much he or she can afford by asking to be prequalified. You should address that pre-qualification letter, certificate, or other documents to the prospect, not the real estate agent. Then, if the real estate agent has questions about the customer's qualifications, such as where is the money for the down payment coming from, what their monthly debts are, how they receive their income, etc., the agent should address it to the prospect. 

Prospects should be careful about what information they provide to a real estate agent because they risk exposing their Personally Identifiable Information or their Non-Public Information to identity thieves. Real estate firms generally are not regulated by entities that insist on secure data because most real estate-specific information is public knowledge. 

On the other hand, the agent will likely communicate the information to the seller in support of an offer to purchase, so a prospect may feel compelled to share more information than prudent to advance their home purchase. 

To avoid disclosing this information, a prospect should actually obtain the financing in question via a loan application, loan underwriting, and loan commitment, subject to a final property selection; a pre-approval. With this in hand, the customer does not have to provide additional documentation supporting an offer contingent on financing because the financing has already been obtained. 

How Much Can You Share?

Technically, none. Your customer has a right to limit the information you share and under what circumstances the information is shared. To share any information a prospect gives you, you should review a copy of the sales contract (offer) to see if the customer has already authorized the lender to share information on loan status. Otherwise, you should obtain authorization to release information to the agent(s) or builders; Consent to deliver loan status updates, generally. 




Loan Status vs. Personally Identifiable Information or Non-Public Information

Loan status simply details what is in and out on a loan file and provides dates when certain tasks have been performed on a transaction. This is a good example of how this information could be shared (Source: AZ Association of Realtors). There is no NPI or PII in any of this material. 

When the loan originator provides Non-Public Information or Personal Financial Information, such as credit scores, payment history, or any other information gathered during transacting business or in conjunction with a loan application, this is a clear violation of the Gramm-Leach-Bliley Privacy Act. It MAY be permissible in a situation where there is an affiliated business and the sharing of information would be NECESSARY to conduct business. 

So, NO. Don't Share Private Information

In other words, a customer may share their own information, but you, as a financial service provider, may not provide any non-public private information. 


Tuesday, December 20, 2022

Planned Refinances - Compliance Minefield

Buyer refi program:  "If you use us for your purchase loan and you refinance within 3 years, we will credit back at the close of your refinance, appraisal fee, and certain other fees......"  

Can this be done as a Broker, and if so, how is it disclosed?






These are popping up all over the place. Of course, you CAN do them (and lots of people do informally), but creating a program around this and advertising this runs afoul of the "planned refinance" rules of the agencies.

Pricing from the lenders is based on actuarial tables that include estimates of how long a loan will stay on the books. Further, many servicers offer a "loan modification" element to retain the servicing on a loan while moving the underlying loan from one security to another. 

To understand why this is a big deal, the cash value of mortgage-backed securities for mortgage lenders is small and gets capitalized as an income stream. Even when retained as a swap or other secondary marketing asset or hedge, the secondary market for mortgage-backed securities' primary use for lenders is a tool to achieve equilibrium - you might make money in secondary in a falling rate environment, but you intend to break even or just not lose money. So a lender makes money by building a servicing platform and collecting monthly payments for a small spread. That small spread, multiplied by thousands of loans, creates a solid cash flow model. Planned refinances disrupt that model. 

Further, creating an agreement to refinance out of a higher rate loan runs into the UDAAP higher cost loan rules and makes it look like a predatory lending strategy: Take this higher cost loan today, and we'll give you a lower cost loan in the future..." Regulators, particularly those interested in enforcing anti-predatory lending practices, have a keen interest in these types of arrangements when they surface. It's not the kind of attention most lenders want. 

Finally, the practical considerations of a planned refinance agreement create a minefield of legal issues. How do you guarantee that you will be in a position to provide the cost credit? What provisions do you make if the company goes out of business or is shut down? How do you create an independent index that a reasonable consumer can follow to trigger the rate, and what if rates end up going lower than the refinance trigger? 

There is nothing wrong with a loan officer creating a database of past customers and discussing a possible future refinance. "I'll call you when rates get to x.00%" And you could market that as a personal service: "The Rate Watch." 

 

Tuesday, November 15, 2022

The Buzz on Cyber Security

Federal Rules Expand the Scope of Your Customer's Data Protection

In case you were wondering about the onslaught of regulator or investor requests for cybersecurity plans, risk assessments, and MFA certifications, it all has to do with FTC regulations passed last year that go into effect December 9, 2022. The FTC has extended the deadline for compliance for 6 months, making the new deadline 6/9/2023.

eCFR :: 16 CFR Part 314 -- Standards for Safeguarding Customer Information

In a nutshell, our customers have all of the tools to meet these requirements in the 2-90 IT Security Plan. These include:

  • Employee Training
  • Risk Assessment
  • Third-Party Vendor Reviews
  • Data Breach Response and Remediation

Small companies - responsible individual

For small firms, you should assign a responsible individual who is knowledgeable about the technology aspects of your firm. They do not need to have a degree in cybersecurity. However, they should know all the firm's tech and communications infrastructure and have the capability to completely answer the cybersecurity questionnaire. If the individual is NOT able to answer the questionnaire, you MAY designate a third party, such as an IT consultant. We caution small companies against signing big contracts if the firm's technology consists mostly of leased cloud computing assets, such as LOS, document storage, and email. Even third-party apps, like online 1003s, should come with some tech support, and you can designate a 3rd party (even the vendor) specifically for those types of risks. 

Don't "Build Castles" - Use the Tools you Have

We really try to avoid creating additional work in the form of a separate workflow for compliance-related matters. That's why you should use some of the resources you already have to meet some or all of the requirements. 

  • Credit Bureau Audits - If you have the ability to pull credit reports yourself (instead of just through your investor/wholesaler directly) you likely have a credit bureau service provider. This firm is responsible for evaluating your firm (usually annually) and providing a risk assessment based on that evaluation. That should be a foundation. Review their report against the overall questionnaire to see how many items are covered.
    • By the way, bureaus are conducting these audits furiously as a part of the new rule's implementation
  • State Certifications - keep a copy of any questionnaire you complete to assess your technology. THIS COUNTS AS AN AUDIT or RISK ASSESSMENT
  • When you sign up with a tech provider, get their SOC or ISO certification information. Use the vendor's reviews as your own.
  • When getting training, make sure you keep a copy
  • Read your policies and procedures - if they don't make sense, get a plain English translation!

Speaking of Plain English - here's our summary of the IT/Cyber Security Plan requirements that you can use as a checklist. 



New York Cybersecurity Certification

The Section NYSDFS 500 updates that went around earlier this year include the updates from the FTC's rule. The changes do not represent a departure from current best practices but memorialize the requirements in the FTC's Safeguarding rule.

Remember that the certification only captures information on what you are doing. Policies and procedures should reflect this information; they don't replace your implementation. 

You can request help completing your Cybersecurity Certification here