Over two decades, Bridgeforce has taken on more than 900 projects covering regulatory compliance and control, plus providing support in the areas of operations, strategy, and risk management. Our clients have successfully achieved regulatory exam readiness, responded to regulatory supervisory letters, managed large-scale remediation efforts and everything in-between. In most cases, our clients already know what needs to be done, but knowing “how” to do it and do it effectively can be challenging.
At a high level, to prepare for regulatory examinations, organizations should adopt a proactive and informed approach. Staying abreast of regulatory changes and updates is crucial, and the bank should establish a robust Compliance Management System (CMS) that encompasses policies, procedures and controls aligned with current regulatory requirements. Regular internal audits and risk assessments must be conducted to identify and rectify compliance gaps, with a commitment to promptly address any deficiencies discovered.
Clients often ask, “We have an upcoming exam and are not sure where to start – what do we do? There are certainly some common standards, but our answer often varies by client, based on many factors that must be considered before planning readiness activities. These factors include:
We ask these questions before we begin to construct a readiness plan. While the most logical starting point always varies, there are several steps that can be taken to prepare. Start with identifying high-risk functions that are likely to be the focus areas of the exam. Then, compare the current state against known regulatory expectations for compliance/control. Identification of high-risk functions will help streamline readiness efforts and result in a prioritized list of impacted processes.
Identifying high-risk functions will guide all readiness activities. Typically, once you’re aware of an upcoming exam, there isn’t time to check, double-check and triple-check every process. So, prioritization is a must. These steps can get you ready:
1. Determine Regulatory Applicability and Compare Expectations to What You Currently Do
You must first understand the applicability of all regulations to job functions, as well as regulators’ expectations for compliance and control to compare to current operations.
2. Analyze Complaints to Identify Potential Root Cause Weakness
Important in advance of any exam—but especially so for CFPB exams. This should not be limited to “highest volume” complaint types, as we’ve seen a small handful of complaints be signs of significant errors.
3. Review Recent Enforcement Actions
Review public enforcement actions to gain insights into regulatory expectations and identify where other organizations have been most impacted. This helps pinpoint areas for greater reputational risk.
4. Re-Examine Past Internal Audits of Regulatory Exam Findings
Repeat exam findings must be avoided as should un-addressed internal audit findings. Any function with recent findings should be automatically flagged as a higher risk and prioritized.
We recommend performing risk assessments on any impacted processes. The risk assessment finds gaps and helps determine how to address gaps prior to the exam.
Typically, a risk assessment is completed in a format that allows for easy identification of gaps against a predefined expected state. Using a matrix with some well-defined fields to allow for a consistent prioritization methodology is encouraged. Regardless of approach, what is important is that the gaps identified during the risk assessment are prioritized, acted upon, and implemented in a way that tells a clear story.
Factors for prioritization may include the risk of customer or member harm, financial risk, implementation effort, implementation cost, time required for implementation, and process frequency. The resulting prioritization document should be designed for handoff to any stakeholder, whether internal or external, seeking clarification on why an identified gap may have remained unaddressed.
Demonstrating a thoughtful approach to prioritization can go a long way with a regulatory body.
Once prioritization is complete, it is time to develop the readiness plan. This activity should ensure that items to be executed prior to the exam are completed. The plan also provides a roadmap sharing when open gaps will be addressed in the future.
The most important components of the exam readiness plan are related to the project management that surrounds its execution.
Effective components of an exam readiness plan include the following:
While these items alone are not enough to ensure exam success, they do contribute to the creation of a highly structured, consistent narrative. It establishes the groundwork for clear likes of accountability, regular communication, and prompt identification of emerging risks.
If you are not sure of how regulator-ready your organization is, contact us. We can help you get started, assess your gaps and create a prioritized list and action plan to get you where you need to be prior to your exam. Our approach is based on collective background in operations leadership, which brings immediate value to assist clients through the stressful, sometimes daunting task of dealing with an exam.
Follow us on LinkedIn for more regulatory exam readiness tips.