Showing posts with label Credit Union Compliance. Show all posts
Showing posts with label Credit Union Compliance. Show all posts

Tuesday, May 18, 2021

Credit Union Compliance Keep Your Guard Up

Keep Guard Up on Credit Union Compliance
Credit Union Compliance Keep Your Guard Up

As dry subjects go, there aren’t many topics arider than regulatory compliance. It’s virtually the Mojave Desert of subject matter. Just like a real desert, though, it isn’t wise to try to navigate the compliance landscape without knowing what you’re doing or where you’re going. When it comes to Credit Union Compliance Keep Your Guard Up!

The unprecedented volume of regulatory changes that were generated during the past decade has financial institutions of all types looking for a break in the action, for a chance to get their bearings. So, when serious talk of regulatory relief holds out hope that help may be forthcoming, it’s only natural for those shouldering the burden to breathe a sigh of relief, and to take time to attend to other matters. However, just because efforts are underway to ease the regulatory load, it’s not the time for credit unions to drop their guard.

Between the alphabet soup of federal regulations overseen by the CFPB and the regulations issued by the NCUA and other state and federal regulators, credit unions are subject to dozens of complex regulatory requirements that are designed to shape the way they conduct business. The federal Truth in Lending Act and Equal Credit Opportunity Act, together with the CFPB’s Regulations Z and B, are just a few of the regulations that dictate how credit unions meet their members’ credit needs. As for share accounts and other deposit products, the federal Expedited Funds Availability Act and the federal Truth in Savings Act have given us Regulation CC and the NCUA regulations in 12 C.F.R. Part 707, and the Electronic Fund Transfer Act has spawned Regulation E. Of course, there’s also the federal Bank Secrecy Act, the Flood Disaster Protection Act, and the SAFE Act, all of which have been implemented through NCUA regulations. Other NCUA regulations govern business operations and naturally, state laws and regulations are also in the mix. Together, these laws and regulations create a complex web of requirements that must be taken into account by credit unions to effectively manage both operational and reputation risk, and to safeguard against potentially costly civil liability.

Over time, each credit union has developed a variety of policies, procedures, systems, and tools that establish the framework for the way that credit union does its business. Whether developed in response to regulatory changes, business objectives, or as new products have been added to the mix, this “compliance management system” (CMS) is itself a system that needs monitoring. To better manage the compliance risks that every credit union faces, senior management and the credit union’s board of directors must periodically revisit each of the policies and procedures that comprise that credit union’s unique CMS. Just another way for Credit Union Compliance, Keep Your Guard Up!

To think of it another way, if each credit union is a dynamic and evolving operation, then it only makes sense that the CMS policies and procedures that guide that credit union’s day-to-day operations must also adapt and change over time to ensure they remain appropriate for the way that credit union conducts its business. Compliance violations happen, and stale policies and procedures are often the culprits. There’s no getting around the fact that when employees focus on the day-to-day business of running the credit union – making loans to members, assisting them with their share accounts, and providing the ever-expanding range of financial products that seem to develop overnight – every employee is constantly making real-time decisions about what to do and how to do it.

Although wandering off the path of strict compliance is rarely a conscious decision, without careful consideration of the compliance implications of a particular process or procedure, what may seem like an expedient solution to a day-to-day operational problem may turn out to be a shortcut to a compliance violation. Like an impulsive decision to leave the trail on a desert hike, not understanding the compliance implications of a policy change or an adjustment to a longstanding procedure can be fraught with risk. This common dilemma, faced by credit unions and financial institutions of all sizes and types, has been the subject of recent efforts by the Federal Government to stay abreast of the changing compliance landscape.

Evaluating Compliance Risk

As part of a joint project with other federal financial regulators under the auspices of the Federal Financial Institutions Examination Council (FFIEC), the NCUA released Supervisory Letter No. 17-01, Evaluating Compliance Risk – Updated Compliance Risk Indicators. It discusses the recently updated criteria that NCUA examiners will use when assessing how well a credit union meets its compliance obligations. The updated list of compliance risk indicators makes it clear that regulators will be looking not only for compliance with specific regulations but also at the overall effectiveness of each credit union’s compliance management system. Examiners assessing compliance risk will evaluate each credit union’s CMS with respect to: 

  • Oversight Commitment – How well do the credit union’s management and board of directors understands all aspects of compliance risk; and how strong a commitment do they show to providing sufficient compliance resources, staff, and training to ensure that the credit union will meet its due diligence obligations?
  • Change Management – How well does the credit union’s management anticipate and respond to changes in applicable laws and regulations; how well does it react to changes in market conditions; and how thoroughly does it consider compliance implications when it implements changes to its products and services?
  • Comprehension, Identification, and Management of Risk – Does the credit union have a strong culture of compliance management designed to minimize the likelihood of serious compliance violations; does management effectively identify compliance risks posed by the credit union’s products, services, and other activities; and does management effectively manage those risks through comprehensive self-assessments?
  • Corrective Action and Self-Identification – Does the credit union proactively identify and promptly respond to compliance risk management deficiencies and violations of laws and regulations, including taking corrective action?

Key Factors in Evaluating Compliance Risk

The Supervisory Letter outlines other key factors that examiners will look at when evaluating a credit union’s compliance program: 

  • Policies and Procedures – Are the credit union’s compliance policies and procedures and third-party relationship management programs adequate to manage the compliance risk posed by the credit union’s products such as forms and disclosures, services, and activities?
  • Training – Does the credit union’s compliance training adequately outline staff responsibilities, and is training provided in a timely manner in connection with changes in laws and regulations and the rollout of new products and services?
  • Monitoring and/or Audit – Are the credit union’s compliance monitoring practices, management information systems, reporting, compliance audit, and internal control systems adequate to address compliance risks throughout the credit union?
  • Consumer Complaint Response – Are the credit union’s processes and procedures for addressing and monitoring consumer complaints adequate, and does the credit union conduct consumer complaint investigations promptly and thoroughly?

Examiners will also determine the extent to which compliance violations result in harm to consumers. Compliance violations will be evaluated in terms of: 

  • Root Cause – To what extent are violations the result of weaknesses or deficiencies in the credit union’s CMS?
  • Severity – Do the violations cause serious and considerable harm to consumers?
  • Duration – How extensive is the time frame during which a violation occurred?
  • Pervasiveness – How widespread and numerous are the violations?

Effective March 31, 2017, the FFIEC updated its Uniform Interagency Consumer Compliance Rating System. The five-level rating system that has long been used to rank a credit union’s compliance with consumer compliance regulations evaluates three broad categories, the first two of which are focused on the credit union’s CMS: 

  • Board and Management Oversight
  • Compliance Program; and
  • Violations of Law and Consumer Harm

The consumer compliance rating (CC Rating) that a credit union receives is a critical measure of that credit union’s health. Compliance is measured on a scale of 1 to 5, with a CC Rating of 1 being the most coveted. A poor rating in the 3 to 5 range is a red flag that will not be ignored and will result in a credit union having to expend considerable time, effort, and resources taking the necessary measures to correct the problems revealed by the examination. Obviously, this renewed emphasis on compliance by federal regulators means that any efforts that a credit union takes to identify and correct compliance issues in advance of a consumer compliance examination will be beneficial. But waiting until an examination has been announced may be too late to do anything about it. The best approach is to instill a culture of self-assessment and to regularly evaluate each of the credit union’s products, policies, procedures, and processes for compliance. Like being properly prepared for a hike through the desert, it only makes good sense.

Credit Union Compliance, Keep Your Guard Up!

Take advantage of Oak Tree compliant forms and obtain compliance support for your credit union. Remember when it comes to Credit Union Compliance, Keep Your Guard Up! You don’t have to do it alone.

(note: this is an older blog entry and has been edited since originally posted.)

Monday, April 19, 2021

Checklist for Credit Union Compliance

Checklist for Credit Union Compliance article

It takes work to keep your credit union in compliance. It’s not easy, but there are a few basic things you can do. Read over our checklist and make sure you have these items covered. This will go a long way toward keeping you in compliance and out of the crosshairs of a potential regulatory audit, or other adverse events. Of course, there are so many things that come into play when keeping your credit union compliant, but this quick checklist for credit union compliance gives a good generalized overview.

Stay Current.

Make sure you stay in the loop regarding regulatory changes and other similar occurrences. Most vendors have websites devoted solely to timely information updates; and regulatory agencies such as the NCUA, Federal Reserve, Federal Financial Institutions Examine Council (FFIEC), and Consumer Financial Protection Bureau provide white papers and summaries to give perspective on updated laws and regulations. These help you stay up to date and informed.

Audit & Review Yourself.

Make sure you have a mechanism in place to review and audit your policies and procedures. The best way to think of these is as follows: they are always a work in progress. They should regularly be reviewed and tested to find shortcomings or problems that might be hidden from view.

Be Proactive.

Learn to anticipate regulatory changes. This is best accomplished by studying trends, and observing how other regulatory professionals in your industry are reacting. Speculate using past and current regulatory trends, then take all of this information and extrapolate a conclusion based on the inferences and present regulatory situation. Usually, you can align facts with trends to determine what will most naturally be the next course of action, and begin to position yourself accordingly.

Be Consistent.

Make sure you have a mechanism in place to maintain all current programs. This means reports should be submitted on a regular basis, updates should be regularly given, budgets should be maintained, and a plan for training staff should also be in the works. Oak Tree forms fit nicely into this category. All of our forms packages are kept current and up to date, providing you with the security and peace of mind needed to focus on other compliance issues.

Use the tips above as general guidelines. They are helpful with regard to perspective, and provide a broad-brush approach, allowing you to hone in on specifics as they relate to your institution.

Finally, if you are a compliance officer, set up a process for auditing yourself. This can be vital in preventing problematic instances in the long run. Maintaining compliance is a key part of credit union operation and management. It is a tough job with no guidebook or definitive set of rules. It takes everyone working together to ensure compliance is met and maintained. It is an ongoing necessity that must be upheld to meet members’ needs. We hope these tips and checklist for credit union compliance comes in handy for your credit union. Take advantage of Oak Tree compliant forms and obtain compliance support for your credit union.

Monday, April 12, 2021

What a CU Needs to Stay Compliant

What a CU Needs to Stay Compliant

While credit union compliance may have been under the radar just a decade ago, a recession, global pandemic, and going digital have all contributed to a multitude of new regulations and an emphasis on compliance. So let us look at what a CU needs to stay compliant because you need to keep your credit union compliant.

Utilizing a proactive mindset can prevent costly compliance litigation and fines. We have assembled a checklist to help you assess your CU’s compliance strengths and risks.

Regulations

It’s important to stay diligent. Implementing a plan to stay compliant is necessary to fulfill CU strategies for growth and longevity.

Regulatory agencies such as NCUA, Federal Reserve, Federal Financial Institutions Examination Council (FFIEC), and Consumer Financial Protection Bureau provide updated information on laws and compliance.

1.Study past and current trends.

Use the facts you have and projected trends to create a plan of action.

2.Execute a plan.

Create detailed reports, update budgets, and keep staff trained and informed on any changes.

3.Audit yourself.

As regulations change, so should your products and processes. Continuously think about how you can improve and decrease any weaknesses.


Good Partners

Networking with other credit unions to talk about compliance is important not only for your branch but CUs as a whole. By finding out how others view compliance issues and how they have resolved those same issues can save you from future costly mistakes. What a CU needs to stay compliant sometimes is a good partner to watch their back.

Plus, if you place importance on forming a network of CU executives, you will have someone to call. Picking up the phone is much easier than taking a deep dive into compliance blogs or manuals that might not even fully answer your specific question.

Once you foster a friendship with several local or regional CUs, consider forming a committee that focuses on compliance. That way when any regulatory changes are introduced, you can talk about them as a committee and forward that information to everyone involved. This collaboration is a hallmark of the CU world, an advantage over most banks that prefer to keep a corporate distance.

For example, Washington State Employees Credit Union (WSECU) organized a consumer protection compliance committee back in 2014 in response to the Dodd-Frank mortgage rules and state examinations. As CUs need to conform to a growing list of regulations, the committee provides oversight and guidance to the CU’s management of compliance.

Tools

The Federal Financial Institutions Examination Council (FFIEC) provides three compliance resources that are worth adding to your toolbox. These free resources are a great addition to your current setup and can fill gaps when your budget is minimal for data compliance. What a CU needs to stay compliant is the proper tools.

FFIEC Information Technology Examination Handbook

The FFIEC IT Exam Handbook is the main guide used to assess compliance by auditors. Although it offers an outline for audits, it does not include everything. An auditor may suggest changes that aren’t included in the handbook.

FFIEC IT Exam Handbook includes information on the following topics:

  • • Allocating staff and technology to information technology
  • •Organizing an established information security culture within your CU
  • •Defining risk identification processes
  • • Risk monitoring and reporting
  • •Consistent security operations

FFIEC Cybersecurity Assessment Tool (CAT)

Credit unions have access to the Automated Cybersecurity Examination Tool (ACET) which is based on the CAT. The ACET provides easy-to-interpret results that are easy to implement. This is an improvement over a standard PDF.

CIS Controls® (CIS)

For cyber-attack prevention, this free tool is a great addition to credit union cybersecurity programs, whether you build your own or use a third-party solution.

Online Security

Members of credit unions switch from traditional banks to experience an increase in personalized customer service, security, and trust. Online security is a key component of trust as members continue to lean toward digital products and processes.

As part of maintaining compliance, security monitoring is key in protecting your members’ information. By consistently following these three steps you can prevent future cyber-attacks.

1. Find Your weaknesses

Consistently check for weaknesses in your CU’s security monitoring. It is impossible to efficiently monitor your credit union logs manually. Using a security operations center (SOC) can provide cybersecurity 24/7.

2. Create a Plan

Once you start using a SOC, single out your vulnerabilities to see which ones need attention.

3. Fix Vulnerabilities

IT teams can benefit from a patch management system to fix vulnerabilities and keep them from creating a larger issue. This system saves man-hours by removing the task of manually determining which issues need a patch.

The Cloud

Cloud security is used by 75% of credit unions. The protocol of cloud security compared with traditional methods is virtually the same.

Involve Your Members

Keeping your members educated about their overall cybersecurity can help decrease cyber-attacks and even fraud. Over 80% of hacking-related breaches are due to weak or stolen passwords.

Simply adding password requirements to member accounts like character length, a mixture of both lowercase and uppercase letters, numbers, and special characters will help protect sensitive member information. You can also add multi-factor authentication as an additional layer of online protection.

ADA

Website and mobile apps should be secure, and also follow the Americans with Disabilities Act (ADA) guidelines.

Choose a web developer or ADA agency to audit your site to ensure that you are compliant on all devices including desktops, tablets, and mobile phones. They can also check to see if your site is accessible through text readers and audio scanners.

Post-Coronavirus World

As credit unions have catered to their members during coronavirus in the form of pandemic-specific products and processes, this new way of doing business has opened up a whole new set of regulatory changes and compliance issues.

New trends, such as digital notary signings, have changed the way credit unions complete the loan process. CUs also had to put a priority on the government-issued SBA Paycheck Protection Program to fully serve its members struggling to fund their small businesses during the pandemic. With the increase in remote member transactions, it’s important to protect members against fraud not only during the coronavirus but post COVID-19 as well.

The silver lining from coronavirus is the opportunity to test remote work among credit union employees and digital products and services for CU members. As credit unions set future risks, goals, and marketing strategies, compliance is at the forefront of success. All of these changes required swift compliance action from training, to sensitive advertising content, as well as reforming loan processes.

As the global pandemic continues to shape member preferences toward digital, it’s a great time for CUs to re-think strategies regarding member engagement and how that affects their brick and mortar world.

Avoid excess anxiety about compliance by networking with other CUs, taking advantage of free resources, and investing in online tools that will keep your CU compliant and your members’ information secure.

Tuesday, October 10, 2017

The Equifax Breach & Your Credit Union

The Equifax Breach and Your Credit Union

In a commentary article posted on American Banker (formerly the CU Journal), our CEO, Richard Gallagher discusses how important cybersecurity is for credit unions or anyone in the financial industry. Specifically, he looked at the Equifax breach and your credit union as far as how it can be affected by this breach and similar exploits.

The world of identity theft shifted a bit on Sept. 7, when news broke that hackers had infiltrated the Equifax consumer database. It’s estimated that somewhere around 143 million consumers were affected. This means vital information like names, dates of birth, social security numbers, and credit card information could potentially be up for grabs. And while it’s sobering to think that all of this data could be sold to the highest bidder, the response by Equifax seemed to further complicate the matter.

The website, www.equifaxsecurity2017.com, was set up by the credit bureau to assist consumers with ascertaining whether or not their information had been compromised. However, the official Equifax corporate Twitter account redirected consumers to a fake phishing site for a while before the tweets were noticed and removed. Once the mistake was realized by Equifax, the phishing site was taken down. It was a step by an engineer to bring perspective to the issue of just how dangerous and unnerving the security breach is.

Richard Gallagher

To read more about cybersecurity and your credit union go check out the American Banker article and then check out our compliant lending documents for your credit union.

(note: this is an older blog entry and has been edited since originally posted.)

Tuesday, August 22, 2017

Maintain Compliance

Maintain Compliance for Credit Unions

In a commentary article posted on Credit Union Times, our CEO, Richard Gallagher discusses the importance of credit union forms being up to date to maintain compliance.

Maintaining Compliance: A Lesser Burden, a Real Threat
Don’t let out-of-date forms be the elephant in the room at your credit union.

Credit Union Compliance: Always Changing

Compliance always seems to be the elephant in the room among credit union discussions. It can be found in just about every board meeting, conference, and executive luncheon. There is good reason, too. Just a few years ago, compliance threatened to close down many credit unions.

The Elephant, or Grim Reaper, in the Room?

In 2013, more than 800 credit unions had closed their doors over a four-year span. Contribution to this was partially the Dodd-Frank Act, which many institutions found to be cumbersome. The regulatory burden was too much for them. Other credit unions were swallowed up in mergers, just so they could survive. Times were scary and uncertain. During this time, compliance was not an elephant in the room; instead, it was the Grim Reaper.

Even today, compliance has a big impact on credit unions, according to Utah Credit Union Advocacy and many other credit unions. Here is how regulatory compliance is impacting credit unions:

Richard Gallagher

To read more about how your credit union can increase its lending growth opportunities go check out the CU Times article and then check out our lending documents for your credit union.

(note: this is an older blog entry and has been edited since originally posted.)

Friday, May 20, 2016

MLA Changes & Their Effect on Credit Unions

MLA Changes & Their Effect on Credit Unions
MLA Changes & Their Effect on Credit Unions

Last year’s revisions to the Military Lending Act (MLA) regulations have generated quite a bit of buzz in recent days. You might be wondering how these changes will affect your forms, and what action you need to take. The good news is that if you are currently using Oak Tree forms for the types of credit that will be covered by the MLA, then your current forms are compliant, despite the revisions made to the MLA. It is important to be aware of the MLA changes & their effect on credit unions if you are running a credit union.

When the United States Department of Defense (DoD) revised their MLA regulations, they expanded the protections provided to active-duty service members and their families under the Military Lending Act (MLA). For the first time, loan products of the type normally offered by credit unions and other depository institutions are covered by the MLA regulations. While the new requirements took effect October 1, 2015, the mandatory compliance date is October 3, 2016 (and not until October 3, 2017 – and possibly later – for credit card accounts).

What is the MLA?

The current MLA regulations were issued in 2007 and were designed to protect active-duty members and their families (“Covered Borrowers”) from the most egregious forms of predatory lending. Whether a person is a Covered Borrower is determined by a service member’s active-duty military status. The MLA protections presently apply only to credit extended to service members and their immediate family members while the service member is on active duty and focus exclusively on: (i) payday loans of $2,000 or less with terms of 91 days or less; (ii) vehicle title loans (non-purchase money loans with terms of 181 days or less secured by a motor vehicle’s title); and (iii) tax refund anticipation loans. These loans are referred to as “Consumer Credit” transactions under current MLA regulations.

The MLA regulations limit the amount that a lender may charge a Covered Borrower for a Consumer Credit transaction. This limitation comes in the form of the unique “Military Annual Percentage Rate” (MAPR). Creditors are prohibited from charging an MAPR that exceeds thirty-six percent (36.0%).

When current regulations proved less than effective at curbing lending abuses, the DoD changed its strategy by expanding the scope of what constitutes a Consumer Credit transaction. Instead of targeting specific loan products, the revised MLA regulations now specify that all consumer loans subject to Regulation Z (both closed-end and open-end) would be covered, with limited exceptions granted for certain types of “mainstream” consumer loans. Under the new rules, only the following credit transactions are not subject to the MLA regulations (and thus, are not “Consumer Credit” transactions for purposes of the amended MLA regulations):

  • Dwelling-secured loans, including loans to finance the purchase or initial construction of the dwelling, refinance transactions, home equity loans, home equity lines of credit, and reverse mortgages;
  • Loans to finance the purchase of a motor vehicle when the loan is secured by that vehicle; and
  • Loans to finance the purchase of other types of personal property when the loan is secured by that property.

For most types of Consumer Credit, only those transactions or accounts consummated or established on and after October 3, 2016, will be subject to the new requirements. For open-end (not home-secured) credit card accounts, only those accounts established on or after October 3, 2017, will have to comply with the MLA. The current requirements will remain in effect for affected closed-end credit products until October 3, 2016.

Under the new MLA regulations, a creditor is not required to disclose the MAPR as a numerical value (which is a requirement under the 2007 regulations), but is required to provide “a statement of the MAPR applicable to the extension of credit” (a text explanation of the MAPR rules). A Model Statement that may be provided to satisfy the MAPR disclosure requirements is provided in the new regulations and is currently available through Oak Tree. This disclosure must be provided both orally and in writing.

The 36.00% MAPR limitation remains, but will soon apply to both open-end credit and closed-end credit. For open-end credit accounts, the MAPR limitations are imposed on each billing cycle. Creditors may not impose fees and charges during a billing cycle if those fees and charges would result in the MAPR for that billing cycle exceeding 36.00%.

The new regulations contain essentially the same limitations on loan practices and the same administrative penalties that are provided in the 2007 regulations, but, because of Congressional amendments to the MLA in 2013, including civil liability provisions for the first time. Violations of the MLA and DoD regulations will now subject creditors to civil liability for actual damages (not less than $500 per violation), punitive damages, and equitable relief, among other provisions.

Credit Union Forms Requirements

Because of the significant civil liability provisions, credit unions must familiarize themselves with the requirements of the MLA and DoD regulations as revised, to ensure compliance by the effective dates. The MAPR limitations must be taken into account when credit is furnished to Covered Borrowers in order to avoid this potentially costly civil liability. It is strongly recommended that an MLA due diligence process be incorporated into application procedures in order to take advantage of certain safe harbor provisions contained in the new regulations.

How Does This Impact Your Forms?

Here is where the good news comes in. Although the credit union’s consumer lending operations are clearly affected by the new requirements, your forms remain compliant. Again, Oak Tree’s counsel has advised that Oak Tree’s current forms will not require revisions. The reason for this? Chat with us to find out why.

(note: this is an older blog entry and has been edited since originally posted.)

Tuesday, February 23, 2016

Credit Unions Changing Insurance Carriers

Credit Unions Changing Insurance Carriers
Credit Unions Changing Insurance Carriers

If you’ve been keeping up with the news, you might have noticed that certain insurance carriers are leaving the credit union market. Transamerica was the first to make the announcement, and others are sure to follow suit. This is certain to create waves. Changing insurance carriers is a big deal after all. There is a lot involved, and the process can be daunting. While this might affect some credit unions, causing much stress and mild panic, it will not affect you. By using forms from Oak Tree Business Systems, Inc., you are protected. Credit Unions Changing Insurance Carriers also have options.

Let me explain:

Use Oak Tree and Transition with Confidence

The key is compliance. When a credit union decides to switch insurance carriers, or in this case, has to switch insurance carriers, they can do so confidently with Oak Tree. Our forms are always up to date and compliant. They will easily translate through the insurance carrier transition because they can be customized with the information you need. This makes Oak Tree forms easy to work with. You can customize them to work with your current insurance carrier or any insurance carrier you may choose to work with in the future.

The freedom to customize your forms to be used with your insurance carrier, or switch insurance carriers and continue using the same lending forms, is one of the advantages of using forms from Oak Tree Business Systems, Inc. A compliance issue involving lending forms should not be the deciding factor when it comes to switching insurance providers. No, on the contrary, it should be the least of concerns. Things like benefits, coverage, and discounts should be the determinants.

How Oak Tree Forms Help

All Oak Tree forms follow state and federal guidelines. We work diligently to make sure that each regulatory measure is met and constantly in compliance. This means you always have the most accurate, up-to-date lending forms and disclosure notices at your disposal. And yes, we can keep up with the changes. We deal with the changes occurring on a state and federal level every day and make sure the appropriate language is printed on your forms. The constant barrage of regulatory changes is more than enough to drive any compliance expert crazy. At Oak Tree, we do the work for you so you don’t have to think about it.

Furthermore, our other services dovetail nicely and promote the most efficient access to our compliant forms. For instance, we offer data linking in-house for many data processors, our forms are linked directly to your system. This provides ease of use, cost savings, and convenience – not to mention efficiency! We also provide electronically generated forms. The fact that they are electronically generated means they are the most current, up-to-date, compliant version on hand. We have laser-generated forms as well, for those instances where you need to customize certain items and require the capability to print them on demand.

Having different form options is convenient, efficient, and necessary. They speed up the process of doing business, which helps promote healthy customer relationships. It also helps you put your best foot forward regarding presentation, since customers are not waiting on you to find or fill out forms. Form options from Oak Tree make you look great.

Finally, we are one of the few in the industry that offers compliance support and training. This may not seem like much of an offering the first time you need forms, yet, wait until something happens, like a visit from an examiner. The support and training from Oak Tree are invaluable at that moment. Also, transitioning from one carrier to another can be very stressful, and there can be a tendency for details to fall through the cracks. However, unlike most instances in life where missed details rarely make a big impact; when it comes to forming compliance, details are everything. One missed clause or omitted disclosure statement can spell big trouble for your credit union. Our compliance support and training will make sure you transition your forms with ease.

So, while insurance carriers may come and go, Oak Tree Business Systems, Inc. will remain. No matter what challenges the industry may face, we stand at the ready to provide you with the best compliant forms available on the market. With that variable out of the equation, you can focus and choose the best insurance carrier to meet your credit union’s needs. Credit Unions changing insurance carriers is not a problem for Oak Tree.

(note: this is an older blog entry and has been edited since originally posted.)

Friday, November 20, 2015

NCUA’s Proposed Commercial Lending Rules 2015

NCUA Commercial Lending Rules for Credit Unions 2015

Change may be ahead for credit union commercial lending as the NCUA has proposed a rule in an effort to allow for more business loan approvals. Business Lending is a growing interest to many credit unions, but it is currently limited by statute and regulation. One type of commercial loan, member business loans, in particular, has strict regulations that may soon change. Let’s take a look at NCUA’s Proposed Commercial Lending Rules 2015.

Currently, credit union commercial loans are limited to “1.75 times the actual net worth of the credit union,” or “1.75 times the minimum net worth required . . . for a credit union to be well-capitalized.” The CUMAA required a net worth ratio of 7% in order to be well-capitalized, This effectively created an MBL limit of 12.25% of a credit union’s total assets (1.75 x 7% = 12.25%). The 12.25% limit was explicitly codified the following year by NCUA regulations, which, among other provisions, also created a waiver application process through which borrowers could petition an NCUA Regional Director for relief from the various MBL requirements.”

In July, the NCUA proposed new rules to MBL requirements. These proposed rules would eliminate “prescriptive risk management by loan-to-value ratios, minimum equity investments, portfolio concentration limits for types of loans, and personal guarantees from the principal of the borrower. The need for credit unions to petition for waivers of these requirements would thus also be abrogated.” Instead, the new rule will require credit unions that offer a member business loan to “create a comprehensive written commercial loan policy and establish procedures for commercial lending.” This rule also states that credit unions who have both “assets less than $250 million and total commercial loans less than 15% of net worth, that are not regularly originating and selling or participating out commercial loans, would not be required to create such a commercial loan policy at all.”

The current limit set to credit unions approving a loan is 15% of the credit union’s net worth. With the new proposed rule, a borrower is allowed an additional 10% of a credit union’s net worth as long as the “15% general limit is fully secured at all times with a perfected security interest by readily marketable collateral”.

The National Federal Credit Union states that the “end of the prescribed limit on the non-MBL commercial loans would not only provide necessary regulatory relief for the industry but also allow credit unions much-needed flexibility in their diversification strategies.”

If your credit union is currently processing MBL’s or is considering adding business loans to the mix, Oak Tree Business Systems, Inc. is the best solution for your business lending forms. We have the expertise and the programs to put you into this highly profitable lending area. Visit our Business/Commercial Lending forms page or chat with a forms expert today.

Source: Stephenson, H. Grant, and Hoying, Steven D. “NCUA’s Proposed Rules Concerning Credit Union Commercial Loans” Porter Wright Morris & Arthur LLP, Lexology, 16 Nov. 2015. Web. 20 Nov 2015.

(note: this is an older blog entry and has been edited since originally posted.)

Tuesday, November 10, 2015

The Telephone Consumer Protection Act

The Telephone Consumer Protection Act
The Telephone Consumer Protection Act

The Telephone Consumer Protection Act (TCPA) was passed in 1991 by the United States in order to protect consumers from solicitations. This act limits “automatic dialing systems, artificial or prerecorded voice messages, SMS text messages, and fax machines.” Although this is not a new act, new guidelines have been provided and it is important for your credit union to know these to avoid legal litigation. In July, the FCC added new guidelines to this act, such as a new definition to autodialers, and exceptions for pro-consumer messages regarding time-sensitive financial information.

The TCPA has a new expanded definition of autodialers. This broadens the scope of what is considered an autodialer to be, as: “equipment which has the capacity (A) to store or produce telephone numbers to be called, using a random or sequential number generator; and (B) to dial such number.” The FCC has exceptions for pro-consumer messages regarding time-sensitive financial matters. The commission granted financial services permissions to provide consumers with “beneficial, time-sensitive information.”

The FCC approved a  petition that was submitted by ABA, which “sought an exemption for financial-related calls or messages concerning:
(1) fraud and identity theft;
(2) data security breaches of consumers’ personal information;
(3) steps taken to prevent or remedy the harm of identity theft or a data breach; and
(4) money transfers.

Financial institutions will have to “work with a wireless carrier and third-party service providers to ensure that recipients are not charged for these messages.” The FCC also defines when financial institutions (and, presumably, agents working on behalf of financial institutions) can initiate voice calls or text messages without obtaining prior express consent.

They are allowed to do this so long as:

  • The communications are sent only to the wireless telephone number that the customer provided to the financial institution;
  • The communications state the name and contact information of the financial institution (these disclosures must be made at the beginning of a voice call);
  • The communications do not contain any telemarketing, cross-marketing, solicitation, debt collection, or advertising content;
  • The purpose of the communication is to alert the customer of (1) fraud and identity theft; (2) data security breaches of consumers’ personal information; (3) steps taken to prevent or remedy the harm of identity theft or a data breach; or (4) money transfers;
  • The communications are short (one minute or less for voice calls and 160 characters or fewer for text messages);
  • Financial institutions cannot send more than three communications (voice calls or text messages) per event over a three-day period;
  • Financial institutions must provide customers with an “easy” means to opt-out of receiving the communication (i.e., an interactive voice or key press-activated opt-out mechanism for voice calls); and
  • Financial institutions must immediately honor opt-out requests.

(information taken from abovethelaw.com)

In regard to marketing-related calls, credit unions must comply with the following rules before contacting a member:

  • Members must provide prior express written consent to receive marketing calls, texts, and faxes.
  • The written consent must clearly disclose that the member is giving consent to receiving the calls, text, or fax and that they are not required to agree to this in order to receive a loan or service from the credit union.
  • Credit unions cannot use “prior express consent in making telemarketing calls to members.” A credit union must receive new consent from its members as of 2013.
  • Members have the right to revoke their consent “at any reasonable way and time.”

To read the full rule please visit https://transition.fcc.gov/cgb/policy/TCPA-Rules.pdf or if you have any questions about how we can help your credit union, please email clientservices@oaktreebiz.com

(note: this is an older blog entry and has been edited since originally posted.)

Tuesday, October 6, 2015

New Military Lending Act Regulations

New Military Lending Act Regulations for Oct 2015

New Military Lending Act Regulations Recent Changes Regarding Military Lending At Oak Tree Business Systems, Inc., we pride ourselves in maintaining forms that are up to date and compliant across all federal and state guidelines. Well, it is time for us to “up the ante” with this latest regulatory change. Protections have been expanded for active-duty service members and their families according to the revised regulations of the Military Lending Act. Now, loan products offered by credit unions and other depository institutions are covered by these regulations. The new requirements will take effect on October 1 of this year. The mandatory compliance date is October 3, 2016 (and not until October 3 of the following year, and possibly later for credit card accounts).

Why Did The Regulations Change?

The reason for the regulatory change has to do with why the MLA was enacted, to begin with. In 2006, Congress discovered that most active-duty members often looked to subprime lending sources to help them get relief during a financial crisis. Even though the loan provided short-term relief, the high-interest costs associated with carrying the new loan would throw these families into a cycle of unsustainable debt. This added to the stress that service members already feel in general, and this added stress would trickle down to their spouses and children. Therefore,  the MLA was established in 2007 to protect service members from predatory lending. The act was specific in that it only applies to active-duty members, and focuses on the following:

  • Payday loans of under $2000 with terms of 91 days or fewer
  • Non-purchase money loans with terms of 181 days or fewer secured by a motor vehicle title
  • Tax refund anticipation loans

The MLA protects the consumer by limiting the interest amount that an institution may charge for these services. This limitation comes in the form of what is known as a Military Annual Percentage Rate, or MAPR. Creditors may not charge more than 36% MAPR. This differs from APR significantly, because finance charges normally excluded under Regulation Z are included under MAPR. The New Changes The new regulation changes extend to all consumer loans, not just short-term payday or tax refund anticipation loans. Under the new rules, the only types of transactions not subject to MLA regulations are:

  • Dwelling secured loans, including loans to finance the purchase or initial construction of the dwelling, refinance transactions, home equity loans, home equity lines of credit, and first mortgages
  • Loans to finance the purchase of a motor vehicle when the loan is secured by the vehicle
  • Loans to finance the purchase of other types of personal property when the loan is secured by the property

So, What Does This Mean?

Essentially, it means that all of your forms must be updated to reflect the new changes, and kept up to date as each phase-in level date is established. You must be familiar with the new regulations to make sure that they are reflected in all of your applicable lending forms. Oak Tree Business Systems, Inc. will do just that. We will make sure that all of your lending forms are correct, include appropriate verbiage, and accurate, up-to-date MAPR so they are in compliance. Oak Tree is a leader in the industry with a proven track record of producing a compliant product every time. Give us a call if you have any questions regarding your forms, or if you are wondering how the new MLA regulations will affect your institution.

(note: this is an older blog entry and has been edited since originally posted.)

Friday, June 19, 2015

TRID Enforcement Grace Period

CFPB Allows for Grace Period for TRID Enforcement

color spray, dancing lights, mage hand, minor illusion, mirror image, suggestion
2015 TRID Enforcement Grace Period

TILA-RESPA Integrated Disclosure requirements go into effect August 1, 2015, but now there will be a good-faith enforcement grace period. The CFPB will be allowing for a TRID enforcement grace period. Stevens said that the grace period allows for institutions that are working in good faith to implement the rule, “the regulatory framework in this country will use what they can to provide instructive guidance during this delay period.” This goes beyond lenders, including “service companies, real estate companies, and third-party vendors” who need to make their systems compliant according to Stevens. This grace period is open-ended and will go to at least the end of 2015. However, this grace period timeline could be extended if needed, depending on how disruptive the new regulatory implementation is.

Cynthia Lowman, president of United Bank Mortgage Corp., pointed out the impact these new rules will have on the entire mortgage-lending industry, and if it is not approached the right way that it “will have a negative impact on consumers, banks, and the recovery of the housing industry.” The main concern with this new rule is the lack of time to “test the new closing process in real-time.” The TRID rule does not provide lenders an opportunity to start using disclosures before August 1, and the fact that lenders are not able to test their systems and procedures ahead of time increases the risks of unanticipated disruptions. This argument leads to the TRID enforcement grace period. This grace period is to ensure that there is a successful implementation of the Rule.

According to Housing Wire, “in May, the House passed H.R. 2213, introduced by Congressman Steve Pearce, R-N.M., and co-sponsored by Congressman Brad Sherman, D-Calif., which prevents enforcement of the integrated disclosure requirements and the filing of any related lawsuit if (1) the person has made a good-faith effort to comply with the requirements, and (2) the conduct alleged to be in violation of the requirements occurred on or before Dec. 31, 2015, thus allowing stakeholders and the CFPB to test the effective operation of the rule.”

If you have further questions regarding the new RESPA-TILA integration or would like to know more about how Oak Tree can help your credit union, please email ClientServices@oaktreebiz.com.

Garrison, Trey “It’s official: CFPB will grant grace period on TRID enforcement.” Housing Wire., 3 June 2015.

(note: this is an older blog entry and has been edited since originally posted.)

Monday, April 27, 2015

2015 Integrated RESPA/TILA Disclosures

2015 New Integrated RESPA/TILA Disclosures
2015 New Integrated RESPA/TILA Disclosures

Implementation and Transition November of 2013 was a busy time for Federal regulators as they approved final rules combining some of the RESPA rules with other rules still required under The TILA. Congress’s intent is to create an entirely new set of disclosures that when in place, will provide consumers with information (both new & old) formatted in such a way that provides the utmost clarity and consumer understanding. Let’s discuss the New Integrated RESPA/TILA Disclosures.

The new integrated disclosures will fall into two categories (e.g. “Loan Estimate” and “Closing Disclosure”). The “Who, What, When, Where & Why” The new integrated disclosures will need to be provided by creditors or mortgage brokers that receive an application [Emphasis Added] from a consumer for a closed-end credit transaction secured by real property on or after August 1st, 2015. Creditors are prohibited from using the new disclosures for applications that are received prior to that August 1st date and will instead need to follow the current disclosure requirements under Regulations X and Z, and use the existing forms (e.g. Truth-In-Lending disclosures, GFE, Settlement Statements, etc.). The Federal regulators have built in a “transition period” or overlap of time, during which both sets of disclosures will need to be available and creditors will need to use the forms/disclosures that are appropriate to the specific transaction at hand. As applications received prior to August 1st, 2015 are consummated, withdrawn, or canceled, use of the existing GFE, Settlement Statements, and Truth-In-Lending forms will, for the most part, no longer apply. Closed-end reverse mortgages will still be subject to the current disclosure requirements under Regulations X and Z. As this particular “overlap” of disclosures can be particularly tricky, you really need to contact our Client Services Department for full details (Jenny@oaktreebiz.com – 800.537.9598). While August 1st may seem like a long way off, from a practical standpoint it isn’t, and for that reason, the construction of the new forms at Oak Tree is well underway to be certain of their availability in time for the new deadline. Given the size of the new documents and the scope of the transaction-specific information that must be mapped or otherwise programmed by your data processor, once you receive your proofs you will want to approve and return them as quickly as possible.

ELECTRONIC FUND TRANSFER AGREEMENT (REGULATION E) The Electronic Fund Transfer Act is a consumer protection statute that, among other things, limits a consumer’s potential liability for unauthorized transactions made with an approved account access device. The exact amount of the liability is for the most part, determined through the use of a tiered approach that is driven by the time within which a consumer notifies the financial institution. For example, when a consumer notifies a financial institution within two (2) business days after his learning of the loss or theft of the access device, the regulation provides that the consumer’s liability will be restricted to the lesser of $50.00 or the sum of the unauthorized transfers that occur before notice. In the event that the consumer fails to notify the financial institution within two (2) business days after learning of the loss or theft of the access device, the consumer’s liability will increase to the lesser of $500.00, or: (i) $50.00 or the amount of unauthorized transfers that occur within the two (2) business days, whichever is less plus (ii) The amount of unauthorized transfers that occur after the close of two (2) business days and before notice to the institution, provided the institution establishes that these transfers would not have occurred had the consumer notified the institution within that two-day period. The consumer may be liable for additional amounts, depending on the specific set of circumstances.

Since this regulation only establishes a consumer’s maximum liability, institutions are permitted to reduce these limits. Such is the case with the Zero Liability Rules that have been issued by both Visa and MasterCard. With respect to MasterCard, their revised zero liability rule now requires that the consumer use reasonable care in safeguarding the Card from loss or theft; and upon becoming aware of such loss or theft, promptly report that loss or theft to the Credit Union.

There’s more detail to be had here (“the fine print”) and we’re always available to pass it along to you. When you use Oak Tree for your credit union document needs, you can be sure we are keeping an eye on these kinds of changes to keep your forms compliant. We will ensure you are ready for the next “New Integrated RESPA/TILA Disclosures”.

(note: this is an older blog entry and has been edited since originally posted.)

Strength to Overcome

Humanitarian Highlight 8.12.21 This week, our focus for Humanitarian Highlight is on credit unions who are giving their community the streng...