Alston & Bird Consumer Finance Blog

Banking Regulatory

CFPB Touts 2023 Greatest Hits and Casts a Line for Enforcement Hires

What Happened?

Earlier this week, the Consumer Financial Protection Bureau (“CFPB” or “Bureau”) released a blog post touting its 2023 successes in safeguarding “household financial stability” through the levying of fines and filing of lawsuits. The Bureau highlighted seven enforcement cases:

  • Protecting Servicemembers from Illegal High-Interest Loans and False Advertising: In February 2023, the CFPB ordered an auto title loan lender and several affiliated entities to pay a total of $15 million in penalties and consumer redress to resolve allegations that the entities violated the Military Lending Act. That same month, the CFPB permanently banned a California-based mortgage lender from the mortgage lending industry and imposed a $1 million penalty on the lender for repeatedly violating a 2015 consent order by, among other things, allegedly continuing to send advertisements to military families that led recipients to believe the company was affiliated with the U.S. government.
  • Taking Action for Illegally Charging Junk Fees, Withholding Credit Card Rewards, and Operating Fake Bank Accounts: In July 2023, the CFPB ordered a national bank to pay a more than $190 million in penalties and consumer redress to resolve allegations that the bank double dipped on insufficient funds fees imposed on customers, withheld reward bonuses promised to credit card customers, and misappropriated sensitive personal information to open accounts without customer knowledge or authorization. The Office of the Comptroller of the Currency (“OCC”) also found that the bank’s double-dipping on insufficient funds fees was illegal and ordered the bank to pay $60 million in penalties.
  • Intentional Illegal Discrimination Against Armenian Americans: In November 2023, the CFPB ordered a national bank to pay $25.9 million in fines and consumer redress for allegedly “intentionally and illegally discriminating against credit card applicants the bank identified as Armenian American.” 
  • Taking Action to Stop Loan Churning: In August 2023, the CFPB sued a high-cost installment loan lender and several of its wholly owned, state-licensed subsidiaries, for allegedly violating the Consumer Financial Protection Act by “illegally churning loans to harvest hundreds of millions in loan costs and fees.”
  • Illegal Rental Background Check and Credit Reporting Practices: In October 2023, the CFPB and the Federal Trade Commission (“FTC”) sued a rental screening subsidiary of a national consumer credit reporting agency for allegedly violating the Fair Credit Reporting Act by failing to take steps to ensure the rental background checks that landlords use to decide who gets housing were accurate and withholding from renters the names of third parties that were providing the inaccurate information. The resulting court order required the company to pay $15 million in penalties and make significant improvements to how it reports evictions. Separately, the CFPB ordered the national consumer reporting agency to pay $8 million in consumer redress and penalties for failing to timely place or remove security freezes and locks on consumer credit reports and for falsely telling certain consumers that their requests were processed.
  • Stopping unlawful junk advance fees for credit repair services: In August 2023, the CFPB entered into a settlement with a credit repair service conglomerate that imposed a $2.7 billion judgment and banned the companies from telemarketing credit repair services for 10 years.

The CFPB touted that in 2023 it secured over $3.5 billion in total fines and compensation from financial services “lawbreakers” in 2023.  The CFPB largely attributed these cases to the creation of a “team of technologists” working on emerging technologies to “enforce the law when emerging technologies harm consumers.”

Why is this Important?

The CFPB filed 29 enforcement actions in 2023 but selected the seven highlighted above, possibly signaling that junk fees, fair lending, servicemember protections, and credit reporting, among others, remain on the Bureau’s radar. We do not expect the CFPB to issue any sort of accounting covering enforcement cases which it dropped in 2023.

Interestingly, the CFPB also used this post to recruit new “cross-disciplinary” employees (both attorneys and non-attorneys) for its Office of Enforcement and reiterated that the Bureau is “significantly expanding [its] enforcement capacity in 2024 to build on [its] achievements so far.” The roles are located in the Bureau’s Washington, D.C. headquarters and its regional offices in Atlanta, Chicago, New York and San Francisco.  The last of the associated employment information virtual sessions occurred on January 30, 2024.  Strangely, the CFPB only released this blog post the day before the last of these three sessions and it is not known how that late notice may impact application numbers.

What Do You Need to Do?

Given that the CFPB is telegraphing those issues that are top of mind for the Bureau as well as its emphasis on ramping up enforcement in 2024, now is a good time for companies to review their compliance management programs and make any necessary enhancements to policies, procedures, processes, and systems to ensure compliance with all applicable consumer financial laws and regulations. In particular, institutions should revisit their compliance monitoring programs to determine whether any updates are needed to minimize enforcement risk.

New York DFS to Impose Climate Change Safety and Soundness Expectations on Mortgage Lenders, Servicers, and other Regulated Organizations

What Happened?

On December 21, 2023, the New York Department of Financial Services (“NYDFS”) published an 18-page guidance document (the “Guidance”) on managing material, financial and operational risks due to climate change. The NYDFS issued the Guidance after considering feedback it received on proposed guidance it issued in December 2022 on the same topic. The Guidance applies to New York State regulated mortgage lenders and servicers, as well as New York State regulated banking organizations, licensed branches and agencies of foreign banking organizations (collectively, “Regulated Organizations”).

Why Is It Important?

The NYDFS has set forth its expectations, replete with examples, for Regulated Organizations to strategically manage climate change-related financial and operational risks and identify necessary actions proportionate to their size, business activities and risk profile.  Such expectations include:

  • Corporate Governance: An organization’s board of directors should establish a risk management framework, including its overall business strategy and risk appetite, which include climate related financial and operational risks, and holding management accountable for implementation. Such framework should be integrated within an organization’s three lines of defense – quality assurance, quality control and internal audit. Recognizing that low and moderate income (“LMI”) communities may be adversely impacted from climate change, the NYDFS expects an organization’s board of directors to direct management to “minimize and affirmatively mitigate disproportionate impacts” which could violate fair lending and other consumer finance laws. On that note, the NYDFS reminds organizations to consider opportunities to mitigate financial risk through financing or investment opportunities which enhance climate resiliency and are eligible for credit under the New York Community Reinvestment Act.
  • Internal Control and Risk Management: Regulated Organizations should also consider and incorporate climate related financial risks when identifying and mitigating all types of risks, including credit, liability, market, legal/compliance risk, and operational and strategic risk. The NYDFS defines financial risks from climate change to include physical risks from more intense weather events as well as transition risks, resulting from “economic and behavior changes driven by policy and regulation, new technology, consumer and investor preferences and changing liability risks.” The NYDFS recognizes that insurance is an important mitigant to climate change risk but cautions that the availability of such insurance in the future is not guaranteed.
  • Data Aggregation and Reporting: Regulated Organizations should establish systems to aggregate data and internally report its efforts to monitor climate related financial risk to facilitate board and senior management decision making. Such organizations also should consider developing and implementing climate scenario analyses.

What Do You Need to Do?

The NYDFS stresses that organizations should not let “uncertainty and data gaps justify inaction.” Although the NYDFS has not issued a timeline for implementation of the Guidance or begun incorporating such expectations into examinations (which will be coordinated with the prudential regulators to align with joint supervisory processes), now is the time to begin integrating climate-related financial and operational risks into your company’s organizational structure, business strategies and risk management operations.  This will help you prepare for when your organization is required to respond to the request for information which the NYDFS anticipates sending out later this year.  It is anticipated that the NYDFS will ask for information on the steps your organization has taken or will take within a specified period to manage financial and operational climate-related risks, including government structure, business strategy, risk management, operational resiliency measures, and metrics to measure risks.

OCC Issues Guidance on “Buy Now, Pay Later” Lending

A&B Abstract:

On December 6, 2023, the Office of the Comptroller of the Currency (OCC) issued a bulletin aimed at providing guidance to national banks and federal savings associations (“Financial Institutions”) involved in “buy now, pay later” (BNPL) lending. The advisory emphasizes the need for these Financial Institutions to carefully manage risks associated with BNPL, focusing on aspects such as underwriting, repayment terms, pricing, and safeguards to protect customers. Additionally, the OCC stresses the importance of clear and prominent marketing materials and disclosures.

The Bulletin

While BNPL products may vary, the bulletin focuses on BNPL loans which involve four or fewer installments without finance charges, and that are commonly offered at the point of sale. Such BNPL products are distinguished from more traditional installment loans with payment terms greater than four installments or that charge interest or carry other finance charges. These loans have become increasingly popular, especially among younger individuals and those with limited credit history.

The OCC identifies various risks related to BNPL loans for both lenders and consumers, including credit, compliance, operational, strategic, and reputational risks. Specific concerns include potential borrower overextension, limited applicant credit history, unclear disclosure language, challenges with merchandise returns and merchant disputes, operational and compliance risks related to third-party relationships, and increased operational risk due to the highly automated nature of BNPL lending.

Further details on risks include the potential for elevated first payment default risk, additional fees for borrowers due to overextension, and the possibility that credit reporting agencies may lack visibility into BNPL activity.

The OCC’s guidance advises Financial Institutions engaged in BNPL lending to establish robust risk management systems, including prudent lending policies for risk identification, measurement, monitoring, and control. Regarding credit risk, the bulletin emphasizes the importance of sound charge-off practices, allowances for credit losses, and timely reporting of comprehensive information to credit bureaus under the Fair Credit Reporting Act.

The guidance also provides recommendations for operational risk management. It encourages Financial Institutions to assess and mitigate fraud risks, subject BNPL lending process models to sound model risk management and integrate BNPL lending into broader compliance management systems. Additionally, it highlights the need for Financial Institutions engaging third parties in BNPL lending to incorporate such relationships into their third-party risk management protocols.

Takeaway:

Given the OCC’s focus on the risks associated with BNPL products, now is a good time for Financial Institutions engaged in BNPL Lending to ensure that their compliance management programs are robust enough to ensure compliance with the OCC’s guidance.

CFPB’s Message to Mortgage Servicers: Make Sure You Comply with RESPA’s Force-Placed Insurance Requirements

A&B Abstract:

In Case You Missed It:  At the recent Federal Housing Finance Agency’s Symposium on Property Insurance, CFPB Director Rohit Chopra spoke about force-placed insurance and conveyed the following message: “The CFPB will be carefully monitoring mortgage market participants, especially mortgage servicers to ensure they are meeting all of their obligations to consumers under the law.”

The CFPB’s servicing rules set forth in RESPA’s Regulation X specifically regulate force-placed insurance. For purposes of those requirements, the term “force-placed insurance” means hazard insurance obtained by a servicer on behalf of the owner or assignee of a mortgage loan that insures the property securing such loan. In turn, “hazard insurance” means insurance on the property securing a residential mortgage loan that protects the property against loss caused by fire, wind, flood, earthquake, falling objects, freezing, and other similar hazards for which the owner or assignee of such loan requires assistance. However, force-placed insurance excludes, for example, hazard insurance required by the Flood Disaster Protection Act of 1973, or hazard insurance obtained by a borrower but renewed by a company in accordance with normal escrow procedures.

Given the Bureau’s announcement, now is a good time to confirm that your company has adequate controls in place to ensure compliance with all of the technical requirements of RESPA’s force-placed insurance provisions.  Set forth below are some of the many questions to consider:

Escrowed Borrowers:

  • When a borrower maintains an escrow account and is more than 30 days past due, does the company ensure that force-placed insurance is only purchased if the company is unable to disburse funds from the borrower’s escrow account?
    • A company will be considered “unable to disburse funds” when the company has a reasonable basis to believe that (i) the borrower’s hazard insurance has been canceled (or was not renewed) for reasons other than nonpayment of premium charges; or (ii) the borrower’s property is vacant.
    • However, a company will not be “unable to disburse funds” only because the escrow account does not contain sufficient funds to pay the hazards insurance charges.

Required Notices:

  • Does the company ensure that the initial, reminder, and renewal notices required for force-placed insurance strictly conform to the timing, content, format, and delivery requirements of Regulation X?

Charges and Fees:

  • Does the company ensure that no premium charge or fee related to force-placed insurance will be assessed to the borrower unless the company has met the waiting periods following the initial and reminder notices to the borrower that the borrower has failed to comply with the mortgage loan contract’s requirements to maintain hazard insurance, and sufficient time has elapsed?
  • Are the company’s fees and charges bona fide and reasonable? Fees and charges should:
    • Be for services actually performed;
    • Bear a reasonable relationship to the cost of providing the service(s); and
    • Not be prohibited by applicable law.
  • Does the company have an adequate basis to assess any premium charge or fee related to force-placed insurance, meaning that the company has a reasonable basis to believe that the borrower has failed to comply with the mortgage loan contract’s requirement to maintain hazard insurance because the borrower’s coverage is expiring, has expired or is insufficient?
  • Does the company have appropriate controls in place to ensure that the company will not assess any premium charge or fee related to force-place insurance to the borrower if the company receives evidence that the borrower has maintained continuous hazard insurance coverage that complies with the fee requirements of the loan contract prior to the expiration of the waiting periods (at least 45 days have elapsed since the company delivered the initial notice and at least 15 days have elapsed since the company delivered the reminder notice)?
  • Will the company accept any of the following as evidence of continuous hazard insurance coverage:
    • A copy of the borrower’s hazard insurance policy declarations page;
    • The borrower’s insurance certificate;
    • The borrower’s insurance policy; or
    • Another similar form of written confirmation?
  • Does the company recognize that the borrower will be considered to have maintained continuous coverage despite a late payment when applicable law or the borrower’s policy contemplates a grace period for the payment of the hazard insurance premium and a premium payment is made within that period and accepted by the insurance company with no lapse in coverage?
  • Within 15 days of receiving evidence (from any source) demonstrating that the borrower has maintained hazard insurance coverage that complies with the hazard insurance requirements in the loan contract, does the company:
    • Cancel any force-placed insurance that the company has purchased to insure the borrower’s property; and
    • Refund to the borrower all force-placed insurance premium charges and related fees paid by such borrower for any period of overlapping insurance coverage and remove from the borrower’s account all force-placed insurance charges and related fees that the company assessed to the borrower for such period?

And let’s not forget that companies must continue to comply with the above requirements if the company is a debt collector under the Fair Debt Collection Practices Act (“FDCPA”) with respect to a borrower and that borrower has exercised a “cease communication” right under the FDCPA.  Of course, failure to comply with the Regulation X requirements could also result in violations of UDAAP and FDCPA provisions.

Takeaway:

Given that the CFPB is telegraphing its upcoming review of servicers’ force-placed insurance practices, now is a good time for companies to ensure that their compliance management programs are robust enough to ensure compliance with all the technical requirements of RESPA’s force-placed insurance requirements. Alston & Bird’s Consumer Financial Services team is happy to assist with such a review.

Correspondent Lending on the Rise: Increasing Gains Point to Increasing Risk

A&B Abstract:

According to a recent edition of Inside Mortgage Finance, correspondent lending is the only lending channel that posted gains in Q3 2023. While it is always nice to see gains, it should also serve as a reminder to take a fresh look at your risk management program to ensure it is calibrated to address the unique risks of correspondent lending.

To level set, we define a correspondent lender as one who performs the activities necessary to originate a mortgage loan, i.e., takes and processes applications, provides required disclosures, and often, but not always, underwrites loans and makes the final credit decision. The correspondent lender closes loans in its name, funds the loans (often through a warehouse line of credit), and sells them to an investor by prior agreement.

The risk that correspondent misconduct poses to an investor falls broadly into three categories:  legal risk, reputational risk, and credit risk. Legal risk refers to the risk that the investor will be subject to legal claims based on the misconduct of the correspondent, or that the correspondent misconduct somehow will impair the investor’s rights under the loan agreements. Reputational risk refers to the risk of damage to the company’s reputation among investors, regulators, the public at large, counterparties, etc. Credit risk refers to the risk that correspondents will fail to conform to the investor’s underwriting guidelines or credit standards. We include fraud within this category.

In this post, we provide, in our assessment, an overview of the types of claims that pose the greatest legal risks, as well as best practices to mitigate such risks.

Theories of Liability on Assignees

The following laws and/or legal theories, in our assessment, pose the greatest risk of either vicarious liability or economic risk to assignees for the misconduct of correspondents:

  • Holder in Due Course:  Under the Uniform Commercial Code, if an assignee or “holder” of a mortgage loan rises to the level of a Holder in Due Course, it can enforce the borrower’s obligations notwithstanding certain defenses to repayment or claims in recoupment that the borrower may have against the original payee. If Holder in Due Course status is never attained or is lost, the purchaser of a mortgage loan will be subject to certain defenses to payment and claims in recoupment that the mortgagor may have against the original payee.
  • Truth-in-Lending Act (TILA): An assignee may be exposed to civil liability for a TILA violation that is apparent on the face of the disclosure statement.  In addition, for certain violations of TILA, a consumer may have an extended right to rescind a loan for up to three years from consummation. The consumer may exercise this right against an assignee. Moreover, amendments to TILA pursuant to the Dodd-Frank Wall Street Reform and Consumer Protection Act (the “Dodd-Frank Act”) expand the liability of assignees in connection with certain TILA violations, including violations relating to the TILA-RESPA Integrated Disclosure or TILA’s ability to repay, loan originator compensation, and anti-steering provisions.
  • Home Ownership and Equity Protection Act (“HOEPA”) / Section 32 “High Cost” Loans: Subject to certain exceptions, an assignee of a HOEPA loan is subject to all claims and defenses with respect to the mortgage that the consumer could assert against the original creditor.
  • Equal Credit Opportunity Act (“ECOA”): ECOA’s broad definition of “creditor” may place liability on assignees for the statute’s anti-discrimination and disclosure requirements where the assignee “regularly participates” in the credit decision.
  • State and Local Anti-Predatory Lending Laws: A number of states have passed anti-predatory lending laws that contain assignee liability provisions similar to those found in HOEPA with triggers that may differ from HOEPA. An assignee of a loan covered by such a state law will be subject to certain claims and defenses with respect to the mortgage that the consumer could assert against the original creditor.
  • Aiding and Abetting: Under the common law theory of aiding and abetting, loan purchasers and other parties can be held responsible for the acts of the lender that originated the loan, particularly if they (i) knew that the originating lender was engaged in “predatory” practices, and (ii) gave substantial assistance or encouragement to the originating lender. The Dodd-Frank Act also imposes aiding and abetting liability.
  • State and Federal Defenses to Foreclosure: Certain state laws expressly provide that a violation of the law may be asserted by a borrower as a defense against foreclosure, either as a bar to foreclosure or as a claim for recoupment or setoff. In addition, courts may invoke UDAP or UDAAP statutes or equitable remedies to prevent an originator or assignee from foreclosing on a loan that the court views as abusive or unfair.  Finally, as noted above, violations of TILA’s ability to repay, loan originator compensation, and anti-steering provisions may also be raised defensively to delay or prevent foreclosure.
  • State Licensing and Usury Laws: Certain state laws provide for the impairment of the mortgage loan if the originating lender was not properly licensed or the loan exceeded state usury limits.
  • Challenges to Ownership: Plaintiffs are increasingly raising concerns about investors’ or servicers’ authority to foreclose when the investor cannot produce original loan documents or otherwise verify ownership of the loan, although this risk is lessened when an investor acquires the loan directly from the original creditor.

The list above reflects the laws and legal theories that are most commonly used to impose liability on assignees and/or that we believe will be of increasing prominence going forward. There are other federal and state laws that might also expose assignees to liability, either expressly or by implication. There are also claims against an assignee based on the assignee’s own misconduct in connection with the origination of the loan. An example of a direct claim against an assignee related to loan origination would be a claim under fair lending laws that the underwriting criteria that the assignee established and provided to its correspondents violated fair lending laws. Of course, there are plenty of other risks that the assignee may need to manage, such as the risk of loss from fraud perpetrated against the assignee by borrowers or correspondents; the risk of correspondents’ non-compliance with the investor’s underwriting criteria; or the risk of liability from servicing violations.

Best Practices to Mitigate Correspondent Lending Risk

A financial institution should consider adopting the following best practices to mitigate against the legal, reputational, and credit risks presented by correspondent lending relationships, to the extent the institution has not done so already:

  • Ensure that its compliance management system reflects the legal and regulatory requirements relevant to correspondent lending activity and the risks presented by correspondent lending relationships, that the company has in place monitoring, testing, and audit processes commensurate with such risks, and that the company’s compliance training includes material relevant to the management of correspondent lending relationships and their associated risks.
  • Prepare written policies and procedures that explain comprehensively the steps the company takes to minimize the risk that it will be subjected to liability for violations by correspondents.
  • Conduct due diligence reviews to ensure that correspondents are properly licensed, particularly in those states in which the failure to be licensed could impair the enforceability of the loan.
  • Conduct company-level due diligence reviews of correspondents to assess whether the correspondent is willing and able to comply with applicable laws and avoid engaging in practices that might be considered predatory. This might involve reviewing the company’s policies and procedures, examination reports prepared by regulators (to the extent that such reports are not confidential), repurchase demands made against the correspondent, internal quality control reports, complaints received from consumers and regulators, and information about litigation in which the company is involved.
  • Interview correspondents regarding their policies and procedures designed to prevent predatory sales tactics and other predatory lending practices.
  • Question correspondents regarding the measures they use to oversee and monitor the brokers with whom they do business.
  • Perform loan-level reviews to ensure that loans (1) do not exceed HOEPA and state/local high cost loan law thresholds, (2) exceed state usury limits (particularly in states in which the failure to comply can impair the enforceability of the loan), (3) either are not covered by state or local anti-predatory lending laws or comply with the applicable restrictions under those laws, (4) comply with state usury restrictions, and (5) do not contain other illegal terms or predatory features.

Takeaway

With correspondent lending volume on the rise, now is a good time to review and possibly refresh your risk management approach to ensure it is commensurate with the risks presented by correspondent lending relationships.