Alston & Bird Consumer Finance Blog

Bank Regulatory

FHFA Announces UDAP Compliance Expectations

What Happened?

On November 29, 2024, the Federal Housing Finance Agency (“FHFA”) released Advisory Bulletin AB 2024-06 (the “Advisory Bulletin”), which sets forth FHFA’s expectations and guidance for Fannie Mae and Freddie Mac (the “GSEs”) and the Federal Home Loan Banks (collectively, the “Regulated Entities”) regarding compliance with the prohibition against unfair and deceptive acts or practices under Section 5 of the Federal Trade Commission Act (“FTC Act”). The Advisory Bulletin follows the FHFA Final Rule on Fair Lending, Fair Housing, and Equitable Housing Finance Plans published in the Federal Register in May 2024 (“Final Rule”).

Why It Is important?

While the Advisory Bulletin applies directly to the Regulatory Entities, any company that does business with the GSEs or the Federal Home Loan Banks should take note, as there likely will be downstream implications. The Regulated Entities are required to certify compliance with Section 5 of the FTC Act.  The Advisory Bulletin, however, raises several concerns.

First, the Advisory Bulletin conflates Section 5 UDAP compliance and fair lending principles. The Bulletin cautions that Regulated Entities are not only subject to the prohibition in Section 5 of the FTC Act against “unfair or deceptive acts or practices in or affecting commerce” but also the Fair Housing Act, the Equal Credit Opportunity Act (“ECOA”) and implementing regulations. To that end, the Final Rule requires the Board of Directors of Regulated Entities to bring their operations into compliance with these obligations in their “oversight of the [R]egulated [E]ntity and its business activities.” However, while the stated intent of the Advisory Bulletin is to provide guidance to the Regulated Entities consistent with the FTC Act, the Advisory Bulletin lumps together UDAP and discrimination, reminiscent of the CFPB’s similar attempt in 2022. In carefully worded language, FHFA states that its UDAP expectations “complement FHFA’s expectations regarding compliance with applicable fair lending laws.” And, specifically with respect to “unfairness,” FHFA states that its “duty to affirmatively further fair housing” may be considered when determining whether an act or practice is unfair. Yet any rule or bulletin by the FHFA providing that a violation of Section 5 of the FTC Act may be a violation of other federal and state laws (including fair housing, fair lending, and other consumer protection laws) undoubtedly extends fair lending laws beyond the bounds carefully set by Congress. See American Bankers Association, Unfairness and Discrimination: Examining the CFPB’s Conflation of Distinct Statutory Concepts (June 2022).

Second, the Advisory Bulletin suggests various theories of liability for violations of Section 5 of the FTC Act. In particular, the Advisory Bulletin points out that, in addition to direct liability for UDAP violations, the Regulated Entities may be held vicariously liable for UDAPs resulting from the conduct of their employees, agents, or third parties (depending on the Entity’s control or other legal responsibility over the third party’s conduct) regardless of whether such Entity knew or should have known of that conduct consistent with agency law. Moreover, the Regulated Entity may be liable for failing to take prompt action to correct UDAP violations in certain circumstances. Here again, the Advisory Bulletin conflates UDAP with fair lending, as the Bulletin delves into liability principles typically applicable to the Fair Housing Act and ECOA.

Finally, given the potential liability to the Regulated Entities for the conduct of its agents or other third parties, the Advisory Bulletin may serve to further incentivize the Agencies to act as de facto regulators in their oversight of single-family and multi-family seller servicer relationships. Not surprisingly, the Advisory Bulletin reminds the Regulated Entities of the importance of “assessing, monitoring, and taking corrective action related to legal, compliance, and reputation risks associated with potential sellers and servicers, including risks associated with compliance programs, records of compliance, and other relevant information related to compliance with all applicable laws.” Yet, if the GSEs were to exit conservatorship, it remains uncertain what kind of authority they would have to enforce and remediate compliance deficiencies.

What Do I Need To Do?

The Regulated Entities are directed to identify, assess, monitor, and mitigate risks associated with UDAP, including legal, compliance, operational, strategic and reputational risks. Given that the Regulated Entities are required to certify compliance with Section 5 of the FTC Act, companies should expect downstream implications and should work to ensure it has sufficient controls in place to mitigate UDAP risks and avoid unwelcome repurchase demands or rep and warrant breaches.

CFPB’s “Overdraft Lending” Rule Faces Immediate Legal Challenge

What Happened?

On December 12, 2024, the Consumer Financial Protection Bureau (CFPB) issued its final “overdraft lending” rule aimed at curbing overdraft fees charged by banks and credit unions with more than $10 billion in assets, also known as very large financial institutions (VLFIs). The CFPB characterized the rule as closing “an outdated overdraft loophole that exempted overdraft loans from lending laws.” This is the most recent development in the CFPB’s effort to address so-called junk fees.

That same day, a group of banks and financial trade associations—including the Mississippi Bankers Association, the Consumer Bankers Association, the American Bankers Association, and America’s Credit Unions—filed a lawsuit against the CFPB challenging the rule and seeking an injunction.

Why Does it Matter?

Key Provisions

Under the final rule, Regulation Z will apply to overdraft credit provided by VLFIs unless the VLFI provides such overdraft credit at or below costs and losses. As a result, VLFIs will have to choose one of the following options in connection with fees for overdraft credit: (1) capping fees for overdraft credit at the greater of $5 or at an amount that covers their costs and losses; or (2) disclosing the terms of overdraft credit in accordance with the Truth in Lending Act (TILA) and its implementing regulation, Regulation Z.

The CFPB’s final rule amends the definition and exemptions related to “Finance Charges” under Regulation Z and establishes new definitions related to “Overdraft Credit.” Currently, most overdraft fees are generally excluded from the definition of “Finance Charge”, and, therefore, overdraft services are not covered by TILA and Regulation Z The final rule amends this exclusion by creating a new defined term, “Above Breakeven Overdraft Credit,” and excludes such overdraft credit from the exemption for “charges imposed by a financial institution for paying items that overdraw an account.”

“Above Breakeven Overdraft Credit” is defined as “overdraft credit extended by a very large financial institution to pay a transaction on which, as an incident to or a condition of the overdraft credit, the very large financial institution imposes a charge or combination of charges exceeding the average of its costs and charge-off losses for providing non-covered overdraft credit.” The charges will be deemed to exceed the average costs and charge-off loses if they exceed the greater of: (1) the pro rata share of the very large financial institution’s total direct costs and charge-off losses for providing non-covered overdraft credit in the previous year; or (2) $5. A charge that exceeds this amount will be considered a finance charge and, therefore, imposing such charge on overdraft credit will result in the overdraft credit being considered “Covered Overdraft Credit.”

VLFIs should prepare to comply with this new rule by its effective date of October 1, 2025.

The Challenge to the Rule

A group of financial trade associations and banks filed suit in the Southern District of Mississippi challenging the final rule as improperly imposing an expansive and complex new regulatory regime on overdraft services offered by VLFIs, replete with de facto price caps and significant restrictions on the terms under which overdraft services can be offered.

The plaintiffs bring four challenges to the rule under the Administrative Procedure Act (APA), TILA, and the Consumer Financial Protection Act (CFPA).

First, they allege that the CFPB exceeded its statutory authority under TILA by interpreting “Credit” as encompassing overdraft services, and amending “Finance Charge” to include “Above Breakeven Overdraft Credit.” This, they argue, implicates the major questions doctrine—which bars agencies from making major policy decisions without clear congressional authorization—because the final rule will likely impact millions of Americans and billions of dollars of transactions.

Second, the plaintiffs allege the CFPB exceeded its statutory under TILA by imposing substantive credit restrictions when TILA is merely a disclosure statute. They argue this, too, implicates the major questions doctrine.

Third, the plaintiffs allege that the CFPB exceeded its statutory authority under the CFPA by imposing an unlawful fee cap on discretionary overdraft services because the CFPA itself expressly prohibits this kind of fee cap: the CFPB is prohibited from “establish[ing] a usury limit applicable to an extension of credit offered or made by a covered person to a consumer.”

Finally, the plaintiffs allege that the rule is arbitrary and capricious in violation of the APA because, among other things, it: (1) contains an inadequate cost-benefit analysis; (2) does not explain the change in the CFPB’s interpretation of TILA—namely, the CFPB’s reinterpretation of the definition of “Credit” as encompassing overdraft services; and (3) targets large institutions by imposing a $10 billion asset threshold, but ignores smaller financial institutions that similarly charge overdraft fees.

What Do I Need To Do?

VLFIs should consider what changes they need to make to their overdraft services to comply with the new rule by October 1, 2025, assuming that the new rule survives legal challenge.

That said, the legal challenge here has a meaningful chance of success. Recently, courts have been more willing to strike down rules under the major questions doctrine. It is also unclear how much genuine resistance the CFPB will put up in response to this challenge given the forthcoming change in administration. Assuming the new administration does not support this rule, it would likely be more efficient for the CFPB to allow the rule to be challenged and struck down than for it to attempt to repeal the rule, which will require a formal notice-and-comment rulemaking.

Financial Services Advisory: CFPB Finalizes Open Banking Rule on Consumer Financial Data Rights

Executive Summary
8 Minute Read

Our Financial Services Group unpacks the Consumer Financial Protection Bureau’s final rule on consumer financial data rights under Section 1033 of the Dodd–Frank Act.

  • The rule requires “data providers” to provide consumers and authorized third parties, upon request, with access to certain consumer financial data
  • “Data providers” include Regulation E banks and credit unions, Regulation Z card issuers, payment facilitators, and digital-wallet providers
  • Compliance deadlines are staggered based on institution size, with an exclusion for financial institutions with less than $850 million in assets

_______________________________________________________________

On October 22, 2024, the Consumer Financial Protection Bureau (CFPB) finalized its rule on personal financial data rights under Section 1033 of the Dodd–Frank Wall Street Reform and Consumer Protection Act. Known as the “open banking rule,” it permits consumers to access, control, and share their financial data with authorized third parties. The rule creates a significant shift in control over consumer data in the United States, and it is intended to provide consumers with greater control over financial data, foster competition, and stimulate innovation across the financial services industry. The rule applies broadly to banks, credit unions, and nonbank financial institutions, all of which must make consumer financial data available upon authorized request.

Key Provisions

The rule requires a “data provider” to make available, without charge, “covered data” about consumer financial products and services to consumers and certain “authorized third parties,” in electronic form, upon request by the consumer. The rule requires the provision of such data in standardized, machine-readable formats to promote consistency between financial institutions and third parties. The CFPB will name standard-setting bodies to develop consensus standards to assess compliance with the rule.

Who is a “data provider”?

The CFPB has said its definition of “data provider” will continue to evolve, but it has prioritized financial institutions and card issuers. The rule defines a “data provider” as:

  • A financial institution – that is, a bank or credit union – as defined in Regulation E, 12 CFR 1005.2(i), excluding those with less than $850 million in assets.
  • A card issuer as defined in Regulation Z, 12 CFR 1026.2(a)(7), including buy now/pay later providers.
  • Any other person that “controls or possesses information concerning a covered consumer financial product or service that the consumer obtained” from that person, including providers offering payment facilitation products and services such as digital-wallet providers.

What is “covered data”?

The rule defines “covered data” as essential consumer financial information, including:

  • At least 24 months of transaction information in the control or possession of the data provider.
  • Account balance information.
  • Information to initiate payment to or from a Regulation E account directly or indirectly held by the data provider, including an account and routing number that can be used to initiate an Automated Clearing House transaction.
  • Terms and conditions, or agreements evidencing the terms of the legal obligation between a data provider and a consumer for a covered consumer financial product or service, including pricing information such as APRs and other pricing terms.
  • Upcoming bill payment information.
  • Basic information needed for account verification, limited to name, address, email address, and phone number associated with the covered consumer financial product or service.

Data providers will not have to provide confidential commercial information, including proprietary algorithms that might be used to derive credit or risk scores and information that is used solely for the purpose of fraud detection, money laundering, or other unlawful behavior.

Who is an “authorized third party”?

Fintech apps and data aggregators that offer services to consumers using their data are included as third parties. Authorized sharing with these entities must be based on informed consent that is to be renewed annually.

  • A “third party” means any person that is not the consumer about whom the covered data pertains or the data provider that controls or possesses the consumer’s covered data.
  • To access a consumer’s data, the third party must (1) provide the consumer with an authorization disclosure containing key terms of the data access; (2) provide a statement to the consumer in the authorization disclosure certifying that the third party agrees to obligations set forth in the final rule; and (3) obtain the consumer’s express informed consent to access covered data on behalf of the consumer by obtaining an authorization disclosure that is signed by the consumer electronically or in writing.
  • Third parties are limited in the collection, use, and retention of covered data to what is “reasonably necessary” to provide a product or service to a customer. Use of the data for targeted advertising, cross-selling of other products or services, or the sale of covered data are prohibited.

Stakeholder Perspectives and Compliance Considerations

Reactions to the final rule have been split. Consumer advocates have voiced support for the rule and the empowerment of consumers to control how and where their data can be used, as well as the ability to switch banks more easily. Just hours after the final rule was released, however, the Bank Policy Institute, the Kentucky Bankers Association, and Forcht Bank, a community bank in Kentucky, filed a joint lawsuit in the Eastern District of Kentucky requesting injunctive relief. The plaintiffs allege that the CFPB overstepped its statutory authority (in that Section 1033 relates to a consumer’s right to access their own information and does not speak to access by authorized third parties) and will expose banks to unreasonable liability risk. Forcing banks to share customers’ sensitive financial information while handcuffing banks from managing the risks of doing so, they allege, will increase fraud and the misuse of customer data.

Some of this concern stems from the allocation of responsibility for data security and accountability in the rule. It allows that data providers can deny access to data, but only if the denial is (1) directly related to a specific risk of which the data provider is aware, such as a failure of a third party to maintain adequate data security; and (2) applied in a consistent and nondiscriminatory manner. Data providers must keep a record of when a consumer or third-party request is refused. In the event of a security breach, data providers must notify affected consumers and the CFPB promptly. Notably, the rule requires data providers to verify that third parties uphold data privacy and security standards, but it places limited regulatory obligations on third parties themselves, leaving accountability for data security largely with the data providers. Data providers argue that the rule essentially forces them to subsidize third-party access to consumer data without sharing the cost burden.

During the rule comment period, a range on commentators raised concerns about potential overlaps and compliance complexities with other existing consumer financial laws, and the CFPB has attempted to address those issues in the final rule. Many comments focused on the need for clarity on how the rule interacts with laws such as the Electronic Fund Transfer Act (EFTA), Fair Credit Reporting Act (FCRA), and Gramm–Leach–Bliley Act (GLBA).

  • In comments before the final rule, data providers requested that the CFPB extend the Regulation E error resolution requirements to third parties such as data aggregators. The CFPB reasoned, however, that consumers should address these concerns with their primary financial institution, in line with statutory error resolution rights under the EFTA. Furthermore, data providers and third parties that are Regulation E financial institutions will continue to have error resolution obligations in the event of data breaches.
  • During the comment period to the final rule, there was concern that it would expand FCRA compliance. In the final rule, the CFPB clarified that data providers sharing information at the consumer’s request “does not cause data aggregators to incur legal liability under the FCRA that they would not otherwise assume through their ordinary operations” and would not “alter the types of data, parties, or permissible purposes covered by the FCRA.”
  • Some commentors asked how the rule’s data limitations align with GLBA permissions. The CFPB states Section 1033’s data sharing requirements coexist with GLBA but do not override or replace its mandates, maintaining distinct protections under each law.

Compliance Tiers and Timeline

The rule provides compliance deadlines that are staggered based on institution size:

  • First Tier: Depository institution data providers that hold at least $250 billion in total assets and nondepository institution data providers that generated at least $10 billion in total receipts in either calendar year 2023 or calendar year 2024 must comply by April 1, 2026.
  • Second Tier: Depository institution data providers that hold at least $10 billion in total assets but less than $250 billion in total assets and nondepository institution data providers that generated less than $10 billion in total receipts in both calendar year 2023 and calendar year 2024 must comply by April 1, 2027.
  • Third Tier: Depository institution data providers that hold at least $3 billion in total assets but less than $10 billion in total assets must comply by April 1, 2028.
  • Fourth Tier: Depository institution data providers that hold at least $1.5 billion in total assets but less than $3 billion in total assets must comply by April 1, 2029.
  • Fifth Tier: Depository institution data providers that hold less than $1.5 billion in total assets but more than $850 million in total assets must comply by April 1, 2030.

Conclusion: Prioritizing Readiness

The CFPB’s Section 1033 rule represents a transformative shift in the U.S. financial regulatory landscape, centering consumer control over data rights and driving the industry to an open banking model. Fintech advocates view it as an essential step towards consumer empowerment, while banks and credit unions warn of risks to data security and have liability concerns. Even as the CFPB begins assessing applications for standard-setting bodies, legal and compliance teams from institutions and fintech companies alike should begin to look ahead, with a focus on data security, potential contractual updates with third parties, and regulatory alignment.


Originally published November 22, 2024.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.

If you have any questions, or would like additional information, please contact one of the attorneys on our Financial Services Team.

Financial Services Advisory: The UK Introduces a New Reimbursement and Compliance Monitoring Regime for Authorised Push Payment Scams

Our UK Financial Services Group examine the UK’s new mandatory reimbursement rules that will require payment service providers (PSPs) to reimburse victims of scam transactions.

  • The new rules will apply to all PSPs that participate in CHAPS and the Faster Payments Scheme and that operate ‘relevant accounts’
  • Consumers still have a responsibility to exercise caution before claiming a reimbursement, but PSPs will now have to be more vigilant when processing authorised push payments
  • Under the new requirements, PSPs could be required to reimburse consumers up to £85,000 per scam claim, consistent with the Financial Services Compensation Scheme reimbursement limit

___________________________________________________________________________

Payment service providers that participate in the Faster Payment Scheme in the UK and make payments on behalf of consumers from UK accounts will soon be subject to the Faster Payments Scheme Reimbursement Rules. The rules will require (subject to certain exceptions) payment services providers that send or receive funds on behalf of consumers to reimburse consumers when the payment was authorised by the consumer as a result of a scam.

The rules come into force on 7 October 2024, so payment service providers that participate in the Faster Payment Scheme must ensure that they are prepared. In addition to registering with the Faster Payments Operator, in-scope payment service providers must ensure that they have the relevant procedures and practices in place to monitor for scam transactions through the Faster Payments Scheme to avoid having to reimburse victims for scam transactions.

Authorised push payment (APP) scams happen when a person uses a fraudulent or dishonest course of conduct to manipulate, deceive, or persuade someone into sending money to an account outside their control.

With the aim of identifying and reducing the number of APP scams, the Financial Services and Markets Act 2023 (FSMA 2023) placed a statutory obligation on the UK Payment Systems Regulator (PSR) to introduce a Reimbursement Requirement for APP scam payments made over the Faster Payments Scheme (FPS) given that the PSR has oversight over payment systems in the UK (as opposed to payment services which are regulated by the Financial Conduct Authority).

The PSR decided to implement a policy that requires APP scam victims to be reimbursed by payment service providers (PSPs) because they provide services that enable the transfer of funds using the FPS. This is known as the FPS Reimbursement Requirement. The PSR decided to implement this policy by requiring the Faster Payments Operator to put the FPS Reimbursement Requirement into the Faster Payments Scheme rules. The resulting rules are known as the FPS Reimbursement Rules and will come into effect on 7 October 2024.

Application
The new FPS Reimbursement Requirement will apply to all PSPs that directly or indirectly participate in the Faster Payments Scheme and that operate ‘relevant accounts’, which are accounts that are held in the UK and can send or receive payments using the FPS, but they do not include accounts provided by credit unions, municipal banks, and national savings banks.
The FPS Reimbursement Requirements only apply to FPS APP scam payments, which are fraudulent or dishonest acts or courses of conduct to manipulate, deceive, or persuade a consumer into transferring funds from the consumer’s relevant account to a relevant account not controlled by the consumer, if:

  • The transfer is executed through the FPS.
  • The recipient is not who the consumer intended to pay.
  • The payment is not for the purpose the consumer intended.

A consumer who has made one or more FPS APP scam payments is defined as a ‘victim’. Note that for these purposes, consumer includes micro-enterprises and charities.

FPS Reimbursement Requirement
The FPS Reimbursement Requirement requires a ‘sending PSP’ (the PSP that operates the account from which the FPS APP scam payment was made) to reimburse the victim of an FPS APP scam payment, subject to certain exceptions.

Reimbursable FPS APP Scam
An FPS APP scam is only reimbursable if the sending PSP determines that:

  • The Consumer Standard of Caution Exception does not apply or the victim was a vulnerable consumer when the APP scam payment was authorised.
  • The victim is not party to the fraud.
  • The victim is not claiming fraudulently or dishonestly.
  • The victim is not claiming for an amount which is the subject of a private civil dispute.
  • The victim is not claiming for an amount which the victim paid for an unlawful purpose.

Exceptions to the Reimbursement Requirement
PSPs are not required to reimburse an FPS APP scam payment when the Consumer Standard of Caution applies. The Consumer Standard of Caution Exception applies when a sending PSP can demonstrate that a consumer who has made an FPS APP scam claim has, as a result of gross negligence, not complied with one or more of the following standards (the Consumer Standard of Caution):

  • The consumer should have regard to any intervention made by their sending PSP or a competent national authority (CNA).
  • The consumer should, upon learning or suspecting that they have fallen victim to an APP scam, report the FPS APP scam claim promptly to their sending PSP.
  • The consumer should respond to any reasonable and proportionate requests for information made by their sending PSP.
  • The consumer should, after making an FPS APP scam claim, consent to the sending PSP reporting to the police on the consumer’s behalf or request they directly report the details of an APP scam to a CNA.

Note that the Consumer Standard of Caution Exception does not apply if the victim was a vulnerable consumer when they made at least one of the FPS APP scam payments in the FPS APP scam claim and this had a material impact on their ability to protect themselves from the scam.

Guidance on what is a ‘vulnerable customer’ is set out in the Financial Conduct Authority ‘Guidance for firms on the fair treatment of vulnerable customers’, which states that all customers are at risk of becoming vulnerable and this risk is increased by characteristics of vulnerability related to four key drivers:

  • Health – health conditions or illnesses that affect the ability to carry out day-to-day tasks.
  • Life events – life events such as bereavement, job loss, or relationship breakdown.
  • Resilience – low ability to withstand financial or emotional shocks.
  • Capability – low knowledge of financial matters, low confidence in managing money (financial capability), or low capability in other relevant areas such as literacy or digital skills.

The guidance also provides specific examples.

In its consultation paper, the PSR describes ‘gross negligence’ as a ‘very high bar which will critically depend on the individual circumstances of each case’. It interprets gross negligence to be ‘a higher standard than the standard of negligence under common law’, with the consumer having to have shown a ‘very significant degree of carelessness’.

Time Limits to Claim Reimbursement
PSPs are not required to reimburse FPS APP scam payments reported more than 13 months after the date of the final FPS APP scam payment of the claim (consistent with the timeframes for reimbursement for unauthorised payments under the Payment Services Regulations 2017) or FPS APP scam payments that occurred before 7 October 2024.

Maximum Amount of Reimbursement
PSPs are not required to reimburse APP scam victims above the maximum level of reimbursement, even if the consumer was assessed as vulnerable. The PSR had previously set the maximum level at £415,000 in line with the Financial Ombudsman maximum reimbursement limit. However, after a brief consultation, the PSR recently decided to lower this amount to £85,000 per FPS APP scam claim, in line with the maximum level of reimbursement set under the Financial Services Compensation Scheme.

Assessment of FPS APP Scams
Once a sending PSP receives a reported FPS APP scam, the sending PSP must notify the receiving PSP (the PSP providing the relevant account into which APP scam payments are received) within two hours of the claim being reported. The receiving PSP then has the opportunity to respond to the sending PSP with any information it believes to be relevant to the FPS APP scam claim, up to a maximum of three business days after the notification from the sending PSP of the claim being raised.

The sending PSP cannot complete its assessment of the FPS APP scam claim until either the opportunity to respond has elapsed or all receiving PSPs have responded to the notification.

Payment of the Reimbursable Amount
If the sending PSP determines that the reported FPS APP scam payments are reimbursable, it must pay the reimbursable amount to the victim of the scam within five business days of the claim being raised.
Sending PSPs may pause the five-business-day reimbursement timescale by using the ‘stop the clock provision’ only when it has requested further information to assess the reported FPS APP scam claim. However, in any case, the sending PSP must complete the assessment, decide whether the FPS APP scam claim is to be reimbursed or not, and close the claim before the end of the thirty-fifth business day following the reporting of the FPS APP scam claim.

Excess
The sending PSP may apply a single claim excess to each FPS APP scam claim, up to the maximum claim excess value set by the PSR (£100). However, sending PSPs may not apply an excess if the victim was a vulnerable consumer.

Payment of the Reimbursable Contribution Amount
Once a sending PSP has paid the reimbursable amount to the victim of the FPS APP scam, then the reimbursable contribution amount shall become payable by the receiving PSP. The result is that both sending PSPs and receiving PSPs must be vigilant when processing payments through the Faster Payments Scheme.

The reimbursable contribution amount owed by the receiving PSP to the sending PSP is half the reimbursable amount and would be proportioned if there is more than one receiving PSP. The reimbursable contribution amount is payable within five business days following notice from the sending PSP.

Key Milestones
The FPS Reimbursement Rules set out certain key milestones:

  • By 20 August 2024, all in-scope PSPs must have registered with the Faster Payments Operator for the purposes of identification within the FPS reimbursement directory, reporting data, and compliance monitoring and management.
  • By 20 September 2024, all in-scope PSPs must have been onboarded to the Reimbursement Claims Management System (RCMS) Core for the purposes of accessing the FPS reimbursement directory, reporting data, and compliance monitoring and management.
  • From the proposed date of 1 May 2025, all in-scope PSPs must be onboarded to the RCMS Core + Claims and using the system to complete all actions required of them as defined by the FPS Reimbursement Rules to manage FPS APP scam claims, communicate with PSPs about FPS APP scam claims, and comply with the information collation, retention, and provision obligations.

Extension to CHAPS Payments
The Bank of England, as the operator of CHAPS, also published its draft of the CHAPS Reimbursement Rules in May 2024 and updated them in August 2024.

The intention of the new requirements is to mirror the protections set to be afforded to victims of APP scams who lose money via the FPS and to provide consistent outcomes, as well as consistent processes for firms, across both payment systems.

The PSR also published a policy statement and Specific Direction 21 on 6 September 2024. The Specific Direction requires banks and other PSPs participating in CHAPS to comply with the Bank of England’s new CHAPS Reimbursement Rules. It also confirmed that the CHAPS Reimbursement Rules will also come into force on 7 October 2024 in line with the FPS Reimbursement Requirements.


Originally published October 2, 2024.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.

If you have any questions, or would like additional information, please contact one of the attorneys on our Financial Services Team.

Financial Services / Antitrust Advisory: FDIC, OCC, and DOJ Update Guidance on Bank Merger Evaluations

Executive Summary
12 Minute Read
Last week, each of the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), and the Department of Justice Antitrust Division (DOJ) revised how they will review bank mergers. Our Financial Services and Antitrust teams highlight what banks considering mergers should know about the changes.

  • Bank Merger Act (BMA) filers should anticipate increased scrutiny and a broader analysis from the FDIC, OCC, and DOJ
  • Competitive-effects considerations will extend beyond deposit concentrations to nontraditional sources of competition, although the FDIC stopped short of considering certain nonbank competition, such as fintechs
  • BMA filers should underscore their proposed merger’s net positive impact on the convenience and needs of the community
  • The FDIC has expanded its interpretation of the BMA to encompass transactions that would not have previously required a filing
  • The Board of Governors of the Federal Reserve System, the third primary federal banking regulator, did not release updated guidelines

______________________________________________________________________

On September 17, 2024, the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), and the Department of Justice Antitrust Division (DOJ) each adopted revised approaches to their reviews of bank mergers.

In separate releases, the FDIC and OCC updated and expanded their existing guidance, signaling more in-depth, holistic strategies in evaluating mergers involving insured depository institutions (IDIs) under the Bank Merger Act (BMA). The OCC simultaneously adopted a final rule eliminating its expedited review and streamlined application processes for certain bank merger applications. The DOJ, which plays a complementary role in the banking regulators’ analysis of anticompetitive effects, likewise updated its competitive-effects guidelines for reviewing mergers under the BMA and the Bank Holding Company Act of 1956 (BHC Act).

The FDIC’s final policy statement on bank merger transactions supersedes its existing policy statement first published in 1997 and last revised in 2008. In a coordinated effort, the OCC’s final rule and policy statement on business combinations amended its procedures for reviewing applications under the BMA and provides guidance for its review process. Meanwhile, the DOJ withdrew from its 1995 bank merger guidelines, opting instead to evaluate bank mergers using the general 2023 merger guidelines applicable to other industries, as described in a newly issued 2024 banking addendum to the 2023 merger guidelines.

The Board of Governors of the Federal Reserve System, which also evaluates merger applications under the BMA and the BHC Act, did not participate in this coordinated undertaking or otherwise publicly alter its existing precedent-based approach.

The DOJ will apply its standard merger analysis to all transactions subject to the BMA and the BHC Act, whereas the banking regulators’ releases apply only to mergers under the BMA. The policy statement by the FDIC, the primary federal regulator for state-chartered IDIs that are not members of the Federal Reserve System, will apply only to such IDIs. Under the updated guidance, however, FDIC-regulated institutions will now need to notify the FDIC of a broader range of transactions, including acquisitions of nonbanking assets or entities that did not previously merit a filing. While not all such transactions will require a formal BMA application, the FDIC will now determine whether such transactions constitute a “merger in substance” on a case-by-case basis. The OCC’s final rule will apply only to those institutions under its supervision, i.e., national banks and federal savings associations.

The change to the DOJ’s process became effective upon its release. The FDIC’s policy statement will take effect 30 days after its publication in the Federal Register. The OCC’s final rule will become effective on January 1, 2025.

How Will the FDIC’s, OCC’s, and DOJ’s Revised Policies Impact Merger Reviews? 

In assessing an application under the BMA, federal banking regulators have long had to consider, among other things: (1) the transaction’s monopolistic or anticompetitive effects; (2) the institutions’ financial and managerial resources and future prospects; (3) the convenience and needs of the community to be served; (4) the risk to the stability of the U.S. banking or financial system; and (5) the effectiveness of combating money laundering activities. However, banking regulators have discretion in interpreting and applying the factors. In the FDIC’s policy statement and the OCC’s final rule, the regulators clarified how they intend to construe those factors going forward.

While the DOJ technically retains the ability to independently challenge bank mergers, it has rarely done so. However, banking regulators are required to consider the DOJ’s assessment of the monopolistic or anticompetitive effects. Following its review, the DOJ’s views are provided to bank regulators in a nonpublic competitive-factors report. For many years, the DOJ conducted this analysis under the 1995 bank merger guidelines. After withdrawing from those guidelines, the DOJ will now use the same standards and theories of harm it applies to other industries, as explained by a clarifying banking-specific addendum.

Monopolistic or anticompetitive effects

Under the 1995 bank merger guidelines, the DOJ and the federal banking regulators focused primarily on commercial bank deposit concentrations of the geographic markets in which the transaction parties operated and how the proposed combination would affect the same. The DOJ, FDIC, and OCC have each indicated a move to a more multifactored approach, considering additional products and sources of competition, including nontraditional sources of competition. In prior public statements discussing the need to revisit its guidance on bank merger reviews, the DOJ had cited changes in the banking system, including “the popularization of interstate banking, financial conglomeration, online and mobile banking, and the digital transformation of the economy.”

Issued in late 2023 and substantially broader and more complex than the 1995 bank merger guidelines, the DOJ’s 2023 merger guidelines provide a robust framework with which to assess proposed mergers. The DOJ’s 2024 banking addendum highlights a number of 2023 guidelines that the DOJ views as particularly relevant to IDI mergers. For example, the addendum emphasizes those guidelines that describe the DOJ’s approach to transactions involving vertical integration, a pattern or series of acquisitions by the same buyer, and deals involving multisided platforms.

The FDIC stated that it will look at all relevant geographic markets (local, regional, and national) based on where the merging entities operate, consider all relevant market participants and their total deposits, and consider the size and competitive effects of the resulting IDI. Both the FDIC and OCC clarified that this factor is considered in combination with the convenience and needs of the community. The FDIC elaborated that this balancing may be particularly relevant in rural communities, where the needs of the community may outweigh interests in increased competition. The FDIC also expanded its competition analysis to consider credit unions, thrifts, and Farm Credit System institutions, though it declined industry participants’ requests to include fintechs and other nonbank financial services companies.

The OCC did not provide further detail on how it will evaluate competition factors, citing the complexity of the competition factor review and the involvement of the DOJ in its deliberations.

Financial resources, managerial resources, and future prospects

The FDIC separately addresses the considerations relevant to the BMA’s financial-resources, managerial-resources, and future-prospects criteria. In addition to an individual review of each of the foregoing factors, the OCC also considers all three in combination, noting their relatedness. In particular, the OCC looks at these factors in the context of the economic and operating environment and in light of the size, complexity, and risk of the institutions (a sentiment echoed by the FDIC). The OCC is less likely to approve a transaction when the resulting IDI would be less than adequate in any of these three categories. Moreover, the OCC will consider whether the acquiring institution has experienced rapid growth, a factor also considered by the FDIC, or has engaged in multiple acquisitions with overlapping integration periods, and how that may impact these factors.

Financial Resources. Achieving a resulting IDI with less financial risk than that posed by the institutions individually underpins the FDIC’s financial resources considerations. The FDIC walked back its original use of “weaker” in response to comments so as not to dissuade financially sound IDIs from acquiring less-stable institutions. Unsurprisingly, both the FDIC and OCC emphasized the resulting institution’s ability to meet capital standards. Notably, the FDIC also reiterated its ability to condition approval upon entry into written agreements specifying enhanced capital requirements.

Managerial Resources. The FDIC and OCC each dedicated substantial attention to the managerial-resources factor. Both regulators will look to management’s perceived ability to integrate the IDIs and, at a structural level, the IDIs’ compliance management systems. Among other considerations, the FDIC will evaluate the proposed management’s existing responsiveness to regulatory questions, its record of managing and overseeing rapid growth, and individuals’ backgrounds and experience (including the performance and supervisory records of IDIs in which they’ve played a role). The FDIC will also specifically consider consumer compliance ratings and Community Reinvestment Act (CRA) ratings, along with the performance of parent companies and their ability to provide support. The OCC emphasized due diligence to assess the target’s weaknesses and an analysis of the acquirer’s ability to offset such weaknesses.

Future Prospects. The FDIC and OCC will consider both internal and external factors. The FDIC will look closely at any changes being made to the resulting IDI, including to its operations, products, and services, whereas the OCC cited management’s ability to implement the resulting institution’s business plan as an important consideration. Both regulators will study the acquirer’s historical performance integrating merger targets. Both regulators will also evaluate the existing economic environment and competitive landscape.

Convenience and needs of the community

The FDIC and OCC provided additional insight into how they expect applicants to address the proposed merger’s impact on the convenience and needs of the community. Perhaps the most significant development is the FDIC’s analysis of whether an application can demonstrate that the resulting institution will better meet the convenience and needs of the community, including the filer’s commitment to doing so. While the OCC focused less on the resulting institution’s improvement in meeting the convenience and needs of the community, it notes a net positive impact is likely to satisfy this factor. Both the FDIC and OCC expect filers to provide specific examples of how the transaction will benefit the community, such as greater access to products and services, and reduced prices and fees. Both regulators emphasized consideration of the transaction’s impact on low- and moderate-income communities and will evaluate historical CRA ratings. Branch expansions, closings, and consolidations during the three years following the merger will play a role in the FDIC’s and the OCC’s analyses. The OCC also independently considers factors such as job losses and opportunities and efforts to support affordable housing initiatives.

Public input remains important because both regulators recognized the potential for public hearings and the need to consider public commentary when evaluating whether to hold a hearing. The FDIC will now presumptively require public hearings for transactions resulting in an institution with $50 billion or more in consolidated assets. Unlike the FDIC, the OCC did not adopt deal-size thresholds for presumptive hearings; instead, the OCC “will balance the public’s interest in the transaction with the value or harm of a public meeting to the decision-making process.”

Financial stability

When considering a post-merger institution’s risk to the stability of the market, the FDIC and OCC evaluate the size of the entities involved, the availability of substitute providers, the post-merger institution’s contributions to the complexity of the financial system, and the extent of cross-border activities. Both regulators will continue to analyze the institutions’ interconnectedness with the U.S. banking system. The OCC separately emphasized its consideration of the degree of difficulty of winding up the post-merger institution’s business in the event of failure or insolvency.

While the FDIC was careful to note that size alone is not dispositive, it adopted a $100 billion threshold, above which institutions will receive heightened scrutiny and can expect greater processing times. The FDIC stopped short of defining “additional scrutiny,” but noted such transactions are likely to involve additional information requests and more frequent communications with both regulators and community members. The OCC retained existing heightened standards for transactions resulting in an institution with consolidated assets of $50 billion or more and elected to not alter that threshold. The OCC also reinforced its ability to impose conditions on the approval of a merger posing financial stability risks, such as requiring asset divestitures or setting minimum capital requirements.

Combating money laundering activities

The FDIC expects that post-merger IDIs will implement effective programs to combat money laundering and the financing of terrorism. To determine this, the FDIC evaluates each institution’s general policies, procedures, and processes; anti-money laundering and counter-the-financing-of-terrorism programs; risk management programs; compliance with the Bank Secrecy Act; and remediation efforts pursuant to an outstanding corrective program. The OCC did not expand upon its policies for combating money laundering activities in its policy statement but did state that any open or pending anti-money laundering actions raised concerns for approving the merger.

How Will the OCC’s Final Rule Affect BMA Filers?

The OCC’s final rule and policy statement eliminated the streamlined application and expedited review provisions under Part 5 of Title 12 of the Code of Federal Regulations. The OCC historically accepted a “streamlined” BMA application under Section 5.33(j), which avoided open-ended prompts in favor of discrete questions. Filers eligible to file a streamlined application, along with transactions deemed a business reorganization, were subject to expedited review under Section 5.33(i), which deemed a filing approved on the fifteenth day after the applicable comment period expires (absent action to the contrary). The OCC does not expect this change to significantly alter the filing burden or timeline because, inter alia, it historically takes action on eligible filings within the 15-day expedited-review period.

The FDIC, which did not previously have a streamlined application option, has retained its unique expedited processing mechanism.

Final Thoughts and Key Takeaways

  • Though not an overhaul of its existing approach, filers should expect heightened scrutiny of proposed mergers from the FDIC, OCC, and DOJ.
  • The FDIC and OCC’s “new” considerations are consistent with our experience in seeking approval of transactions under the BMA.
  • Potential BMA filers should be cautious to infer a lack of interagency coordination from the Federal Reserve, which often prefers to rely on precedent than to issue guidance and is responsible for reviewing mergers under the BMA and BHC Act.
  • By announcing that it will apply its general 2023 merger guidelines to banking transactions, the DOJ has signaled that it intends to consider a broader range of competition theories and concerns when performing its competition review of bank deals.

Originally published September 26, 2024.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.

If you have any questions, or would like additional information, please contact one of the attorneys on our Financial Services Team or one of the attorneys on our Antitrust Team.