Showing posts with label BSA. Show all posts
Showing posts with label BSA. Show all posts

Wednesday, August 13, 2014

Culture of Compliance: FinCEN’s View

I have been promoting the concept of a Culture of Compliance (“Compliance Culture”) for some time. Indeed, I have written rather extensively about it and lectured on the subject. As recently as February 2014, I published a full length article entitled “Creating a Culture of Compliance.” This article covers most of the need-to-know information to establish a Compliance Culture.

Every company has its own culture, of course; but firms should also recognize the need for maintaining a certain attitude and commitment to compliance. In my own firm's client relationships, we continually reinforce the importance of the Compliance Culture, both through our policy and procedures documents, compliance management system reviews, quality assurance monitoring, examination readiness, due diligence and audit engagements, and also through our overall regulatory compliance support. The need to monitor a client’s dedication to a Culture of Compliance is central to our mission.

Do federal and state regulatory agencies want their supervised entities to adopt a Culture of Compliance? Most certainly! Within minutes of a regulator entering a financial institution’s premises, the Compliance Culture there presents itself. Even emails sent to regulators may disclose a company’s Compliance Culture, as signatures that lack protective disclosure may be indicative of compliance defects. Regulators are used to looking at actions and attitude, by-passing the words and smiling affirmations.

The most recent example of the regulator’s view comes to us from the Financial Crimes Enforcement Network (FinCEN). Issued on August 11, 2014, FinCEN published its “Advisory to U.S. Financial Institutions on Promoting a Culture of Compliance” (“Advisory”).[i] The Advisory is remarkable for its insights and recommendations. Although predicated on actualizing BSA/AML requirements, the Advisory may be applied to any regulatory compliance implementation.

FinCEN boldly declares at the very top of the Advisory:

“BSA/AML shortcomings have triggered recent civil and criminal enforcement actions - FinCEN seeks to highlight the importance of a strong culture of BSA/AML compliance for senior management, leadership and owners of all financial institutions subject to FinCEN’s regulations regardless of size or industry sector.”[ii]

The word “shortcomings” is the operative word in this preamble. It is precisely in the area of shortcomings that a Culture of Compliance may act as a safety net, preemptively catching potential regulatory violations. As FinCEN states, “regardless of its size and business model, a financial institution with a poor culture of compliance is likely to have shortcomings in its BSA/AML program.”[iii]

For the words “BSA/AML” in the remainder of this article, substitute any regulatory framework.

The message is the same!

Components of a Culture of Compliance

FinCEN suggests that a financial institution can strengthen its BSA/AML Compliance Culture by ensuring that:

(1) Its leadership actively supports and understands compliance efforts;
(2) Efforts to manage and mitigate BSA/AML deficiencies and risks are not compromised by revenue interests;
(3) Relevant information from the various departments within the organization is shared with compliance staff to further BSA/AML efforts;
(4) The institution devotes adequate resources to its compliance function;
(5) The compliance program is effective by, among other things, ensuring that it is tested by an independent and competent party; and
(6) Its leadership and staff understand the purpose of its BSA/AML efforts and how its reporting is used.[iv] (My emphases.)

Let’s take each of the ways, enumerated above, that a preeminent regulatory agency such as FinCEN understands the components of a Culture of Compliance.

Leadership Should Be Engaged[v]

FinCEN places the performance of regulatory compliance requirements at the core of management’s responsibilities. The best way to understand this core feature is by the term ‘leadership’ – which is like the “Tone at the Top” concept used by accounting firms for many years.[vi] Leadership includes the board of directors, senior and executive management, owners and operators.

The leaders are “responsible for understanding an institution’s responsibilities regarding compliance with the BSA and creating a culture of compliance at that institution.”[vii] The key to the attitude and commitment of an organization’s leaders is to be visible, because “such commitment influences the attitudes of others within the organization.”[viii]

If there is no “demonstrable support” from the leadership for the compliance program, it will not be effective. An example of demonstrable support would be where an institution’s leaders receive periodic BSA/AML training that is “tailored to their roles,”[ix] which should include an appropriate understanding of BSA/AML obligations and compliance needs. In this way, the leadership may make informed decisions with regards to the allocation of resources to the BSA/AML function. So, regarding BSA/AML, the leaders of an organization should be informed of the state of BSA/AML compliance within the institution, and, to broaden this point, they should also be given regular updates of all pertinent matters handled by the compliance department.

Compliance Should Not Be Compromised By Revenue Interests

It is FinCEN’s view that compliance staff should be “empowered with sufficient authority and autonomy to implement an institution’s AML program.”[x]

When it comes to compliance, don’t cut corners! Specifically, “an institution’s interest in revenue should not compromise efforts to effectively manage and mitigate BSA/AML deficiencies and risks.” In actuality, the BSA/AML compliance function should work independently, in order to take “take any appropriate actions to address and mitigate any risks that may arise from an institution’s business line and to file any necessary reports.”[xi] If compliance staff is compromised by the loss of autonomy, the data provided to management may be inaccurate or unreliable. Furthermore, removing autonomy from the compliance department may lead to significant failures in compliance implementation throughout a company.

Thursday, July 24, 2014

Bitcoins and SAR Narratives


You probably know about Bitcoin, unless you have been living in total seclusion for the last few years. The big controversy usually centers on determining if it is legal tender. But imagine if you are confronted with a transaction involving Bitcoin. Do you file a Suspicious Activity Report (“SAR”)?  

It so happens that the Financial Crimes Enforcement Network (“FinCEN”) has been giving that very concern laser-like attention! In July 2014’s “SAR Stats,” FinCEN observed that therapid adoption and price fluctuation of Bitcoin” has put convertible virtual currencies in the spotlight over the past year.[1] The same attributes of virtual currencies that attract lawful users, such as the capacity for anonymity as well as their speed and global reach, attract criminal actors engaged in illicit financing. FinCEN is observing a rise in the number of SARs flagging virtual currencies as a component of suspicious activity. Bitcoin is considered one of the “emerging payment methods.” Consequently, it is important to understand virtual currencies in order to properly complete the SAR Narrative. 

So let’s define Bitcoin. 

Bitcoin is a type of virtual currency. It is also known as a crypto-currency or a math-based currency or digital currency. A virtual currency is considered “decentralized” because it allows users to conduct transactions peer-to-peer without a central administrator. It is a software-based payment system described by one Satoshi Nakamoto in 2008,[2] and introduced as open-source software in 2009. Payments are recorded in a “public ledger” using its own unit of account, which naturally is also called Bitcoin. Payments work peer-to-peer without a central repository or single administrator - which has led the US Treasury to call Bitcoin a “decentralized virtual currency.”[3]  

In keeping with the general architecture of the Internet, transactions and new currency issuances are conducted without a central administrator or trusted third party. Instead, as an open-source software, its protocol links users into a network that: (1) secures the network from attack; (2) broadcasts transactions; (3) verifies and settles transactions; (4) issues new currency; and (5) publishes new transactions to a shared, “distributed ledger of all transactions” called the “block chain.”[4] The rate of coin creation, the total Bitcoin to be created (say, 21 million), and other variables (viz., network difficulty adjustments), are also in the software protocol. Other crypto-currencies may differ on the basis of these and other variables.[5] 

Besides “mining,” Bitcoins can be obtained in exchange for fiat money, products, and services. Users send and receive Bitcoins electronically for an optional transaction fee using wallet software on a personal computer, mobile device, or a web application.[6] Mining is the maintaining of the block chain, and those who do so are rewarded with newly created Bitcoins and transaction fees. Miners may be located anywhere in the world; they process payments by verifying each transaction as valid and adding it to the block chain.[7]

FinCEN’s view of SAR data and Bitcoin transactions 

Financial institutions, including, but not limited to, Virtual Currency Exchangers, other Money Transmitters, other types of Money Services Businesses, and Depository Institutions may all be involved in the chain of transactions making up the lifecycle of a user’s purchase, use and sale of Bitcoin for currency of legal tender.[8] FinCEN regards SAR data “crucial in assessing transactions involving Bitcoin or other virtual currencies.”[9] Indeed, any financial institution that is required to file a SAR and accepts transactions in Bitcoin should be giving consideration not only to the SAR filing mandates but also sharing information relating to such virtual currency transactions. FinCEN encourages the use of information sharing under 314(b) in this context.[10] 

Bitcoin has seen its share of black market activity. There has been increasing FinCEN and law enforcement scrutiny regarding the use of Bitcoin for illegal activities.[11] In October 2013 the FBI shut down the “Silk Road”, allegedly an online black market, and seized 144,000 Bitcoins worth $28.5 million at the time.[12] Although the United States is still considered “Bitcoin-friendly” compared to other governments, in China buying Bitcoins with Yuan is subject to restrictions, and Bitcoin exchanges are not allowed to hold bank accounts.[13] 

Different financial institutions are more likely to see different elements of the same suspicious activity due to their participation in and perspective on the transaction chain.  

According to FinCEN, while Depository Institutions do not currently interact directly with the Bitcoin economy (i.e., accepting deposits in Bitcoin, conducting transactions in Bitcoin, and so forth), they may see cash, ACH, or Wire and Funds Transfer deposits and withdrawals associated with the following entities, as outlined in the SAR Stats. 

Thursday, June 28, 2012

Mortgage Fraud in California, Nevada, and Florida

The Financial Crimes Enforcement Network (FinCEN) released its First Quarter 2012 on June 26, 2012, entitled Mortgage Loan Fraud Update - Suspicious Activity Report Filings in 1st Quarter 2012.*

This update of mortgage loan fraud suspicious activity reports, known as MLF SARs, shows that California, Nevada, and Florida lead the nation in the number of MLF SAR subjects per capita.

Of the 50 most populous Metropolitan Statistical Areas (MSAs) ranked by the number of MLF SAR subjects reported, the top nine are MSAs located in California, Nevada, and Florida. The Californian cities of Los Angeles, Long Beach, and Santa Ana ranked first in the nation for mortgage loan fraud SARs.

A closer look indicates that 19% of Q1 MLF SARs report activity that occurred within the past two years. Of this more recent activity, there were sharp increases in debt elimination schemes: comparatively, 14% reported in Q1-2012 versus 9% in Q1-2011. Foreclosure rescue scams show a dramatic increase: comparatively, 8% of these Q1-2012 filings versus less than 2% in Q1-2011.

In total, financial institutions filed 17,651 MLF SARs in the first quarter of 2012, which is down from 25,485 filed in the same quarter of 2011. According to the report, previous record levels were attributable to mortgage loan repurchase demands prompting reviews of dated mortgages. I would expect this trend to continue, inasmuch as 72% of Q1 filings are still reporting suspicious activity that occurred more than four years ago.

An interesting statistic is the extent to which mortgage fraud was prevented: 41% of the mortgage loan transactions were spotted and stopped before completion, up slightly from 40% in the CY 2011. However, that also means 59% of the subject transactions were not prevented before completion.

Let's look at some charts, sourced from the FinCEN report.

IN THIS ARTICLE

CHART 1:
Quarterly MLF Filings, Q1 2006 through Q1 2012
CHART 2:
Mortgage Loan Fraud - MLF SAR
CHART 3:
Mortgage Loan Fraud SAR Subjects-Top 20 States & Territories 
CHART 4:
Categories of Fraud Addressed in MLF SAR Narratives

New Fraud Patterns

____________________________________________

MLF-Chart 1
FinCEN reported an unusual spike in MLF SAR filings during 2011 Q1 through Q3, primarily due to mortgage repurchase demands on banks. Those repurchase demands prompted review of mortgage loan origination and refinancing documents, where filers discovered fraud, which was then reported on SARs.

Chart 2: Mortgage Loan Fraud - MLF SARs
MLF-Chart 2
During both 2012 and 2011 Q1, a majority of reported activities actually began during or before 2008.

Chart 3: Mortgage Loan Fraud SAR Subjects - Top 20 States and Territories
MLF-Chart 3
Based on per capita rankings, California remained the top ranked state, as it was in Q4 and CY 2011. Nevada ranked 2nd, rising from its 5th place ranking in 2011 Q4. Florida's 3rd ranking was consistent with its showings between 2nd and 4th in the 2011 quarterly reports. Arizona and New York rounded out the top five per capita rankings. Arizona jumped into 4th from rankings in the 6th through 11th range during 2011, while New York jumped into 5th from rankings in the low to mid-teens during 2011.

Chart 4: Categories of Fraud Addressed in MLF SAR Narratives
MLF-Chart 4
Some noteworthy changes from CY 2011 include an increase in debt elimination schemes, which were addressed in 14% of 2012 Q1 sample SARs, up from 9% in CY 2011. In addition, foreclosure rescue scams (other than debt elimination) were noted in 8% of 2012 Q1 sample SARs, but had been described in less than 2% of CY 2011 reports. Appraisal fraud was described in 3% of 2011 Q1 reports, down from 12% of CY 2011 reports.
 
New Fraud Patterns
 
Homeowners' Insurance Fraud
FinCEN noted two SARs describing homeowners' insurance fraud related to mortgage fraud in the aftermath of home fires. In one instance, a home with two mortgages burned down. The borrower asked that the insurance check be payable to him instead of the mortgage lender, and did repay the first mortgage. But the subject ignored payment requests and subsequent demand letters from the filer on the second mortgage. In the other case, the filer suspected arson on a rental property insured for several times the mortgaged value. This subject repaid his mortgage loan with insurance proceeds and pocketed the additional insurance money.
Keys for Cash
One filer was notified by local law enforcement, based on a confirmed lead from a local realtor, about persons illegally occupying bank owned properties ("REOs"). The subjects moved into various bank owned properties claiming to have long term leases. However, the subjects' true objective appeared to be inducing lenders into paying them to vacate the premises.
Library
Law Library Image
Financial Crimes Enforcement Network
Mortgage Loan Fraud Update -
Suspicious Activity Report Filings in 1st Quarter 2012

June 26, 2012
____________________________________________
* Jonathan Foxx is the President & Managing Director of Lenders Compliance Group

Wednesday, March 28, 2012

Anti-Money Laundering Program for RMLOs

A new era in filing requirements is about to begin. For the first time, the Financial Crimes Enforcement Network, known as “FinCEN,” will require nonbank mortgage lenders and originators to implement an Anti-Money Laundering program (“AML Program”) and file Suspicious Activity Reports (“SARs”) for certain loan transactions.[i] FinCEN is establishing this AML program in accordance with the Bank Secrecy Act (“BSA”).[ii] The guidelines relating to the AML requirement become effective on April 16, 2012, and the AML Program’s effective compliance date is August 13, 2012.[iii] The AML program and SAR filing regulations, which I will refer to as “FinCEN’s rule,” are considered to be “the first step in an incremental approach to implementation of regulations for the broad loan or finance company category of financial institutions.” [iv]
 
The Bank Secrecy Act defines the term "financial institution" to include, in part, a loan or finance company. This terminology, however, can reasonably be construed to extend to any business entity that makes loans to or finances purchases on behalf of consumers and businesses. Thus, nonbank residential mortgage lenders and originators, and mortgage brokers, are grouped into the "loan or finance company" category.[v] However, the term ‘‘loan or finance company’’ is actually not concisely defined in any FinCEN regulation, and there is no legislative history on the term itself. Nevertheless, FinCEN is applying this term to extend to any business entity that makes loans to or finances purchases on behalf of consumers and businesses. [vi] Therefore, residential mortgage lenders and originators (“RMLOs”) are covered by the scope of the ‘‘loan or finance company’’ term. I will use the acronym “RMLO” in this article, inasmuch as my principal focus herein relates to residential mortgage lenders and originators.
 
FinCEN can issue regulations requiring financial institutions to keep records and file reports that are determined to have a high degree of usefulness in criminal, tax, or regulatory investigations or proceedings, or in the conduct of intelligence or counterintelligence activities, including analysis, to protect against international terrorism. Federally regulated depository institutions have been required to have AML Programs,[vii] and now, as of the aforementioned effective compliance date, RMLOs must also comply with FinCEN’s regulations relating to implementing an AML Program and the filing of SARs.
 
Over the last few years,[viii] FinCEN has issued studies and analyses that used SARs to discover suspected mortgage fraud and money laundering that involved both banks and residential mortgage lenders and originators.[ix] According to FinCEN, these reports “underscore[d] the potential benefits of AML and SAR regulations for a variety of businesses in the primary and secondary residential mortgage markets.”[x]
 
Residential mortgage lenders and originators, the RMLOs, are considered to be the primary providers of mortgage finance, and have a unique position with respect to direct contact with the consumer. Thus, they are presumably able to assess and identify money laundering risks and fraud.[xi] At this time, FinCEN is not proposing a definition of “loan or finance company’’ that would encompass other types of consumer or commercial finance companies, or real estate agents and other entities involved in real estate closings and settlements.
 
In this article, I am going to unpack the AML Program for you in a way that will give you some familiarity with its scope, while perhaps also making its implementation a bit less daunting than it might otherwise seem to be. Nevertheless, many RMLOs will find that setting up the AML Program will be a challenging endeavor. Information, issuances, and relevant documentation are available in the FinCEN section of my firm’s website Library.
 
Please keep in mind that, as is the case with many applications of legal and regulatory compliance, there are aspects and nuances that will require recourse to a competent risk management professional to obtain comprehensive guidance and reliable information.[xii]
 
AML PROGRAM
 
Residential mortgage lenders and originators, the RMLOs, are required to establish an AML Program that includes, at a minimum:
 
(1) Development of internal policies, procedures, and controls.
(2) Designation of a compliance officer.
(3) Ongoing employee training program.
(4) Independent audit function to test for compliance.