Navigating CFPB Examinations: Best Practices for Success

10 min

With the 2020 election in the books, and the Biden administration moving quickly to implement its priorities, banks, credit unions, and non-bank financial services providers should prepare for increased scrutiny. Throughout the election, the Biden team emphasized the need to reinvigorate federal enforcement of consumer financial protection laws. Now, with the pending nomination of Rohit Chopra to replace Kathleen Kraninger as director of the Consumer Financial Protection Bureau (CFPB), industry should expect a more aggressive CFPB. Mr. Chopra was most recently a Democratic commissioner of the Federal Trade Commission (FTC), where he lobbied for more aggressive efforts to seek consumer redress or injunctive relief from larger, more established businesses.

If the past is any guide to the future, expect the CFPB to leverage its supervision and examination authority to identify areas for potential enforcement. The CFPB has supervisory authority over banks, thrifts, and credit unions with over $10 billion in assets and their affiliates and service providers, mortgage originators and servicers, debt collectors, and various other non-bank providers of financial services. And while this article focuses on the CFPB, a number of states continue to allocate resources to financial services oversight. Just last year, for example, California launched the Department of Financial Protection and Innovation (DFPI), dubbed "the California mini-CFPB," to increase supervision of financial services providers. In other words, financial services companies should expect a significant uptick in federal and state supervision in the coming months.

This article provides an overview of the CFPB supervisory process and suggests best practices for putting your company in the best position to succeed in the event of an examination. Managing an examination can be a daunting task, but advanced preparation and an organized response can go a long way to ensuring a successful outcome. This is especially important when dealing with agency staff who are working remotely as a result of the pandemic, which can increase the risk of miscommunication or misunderstandings within a company or between the company and its regulator. And, of course, the practices addressed below are equally applicable to other federal or state regulatory examinations.

Preparing for an Examination

Navigating a supervisory examination takes significant time and effort, and usually involves the coordination of various departments within a company, the production of significant amounts of information and documentation in a short time frame, and numerous discussions with examiners.

The starting point in preparing for this process is to invest time and resources in a robust compliance management system that is tailored to the company's business activities, size, and regulatory requirements, and adequately accounts for consumer protection. Supervisory examinations are targeted at assessing a company's technical compliance with applicable consumer financial laws, but also at assessing a company's ability to self-identify and self-correct violations and risks to consumers. Companies that have the capacity to identify potential risk areas and make corrections when needed, and to monitor and account for changes in law, regulatory guidance, and policy, are in the best position to manage a CFPB examination.

Once a compliance program is in place, a good way to prepare for a CFPB examination is to conduct a detailed internal review of your company's compliance operations – a "mock exam" – prior to a formal examination. This effort can identify potential weaknesses or other areas that might draw examiners' attention. This exercise means more than buttoning up areas of potential weakness before an examination. The company should also familiarize itself with the unique aspects of CFPB supervision and train staff on how to respond to requests for information, interviews, and other exam activities in a timely and professional manner. Because the CFPB's mission statement, supervisory priorities, and jurisdiction differ from those of other state and federal regulators that supervised institutions may be used to dealing with, the CFPB examination experience is also different and requires extensive preparation. And remember, you never get a second chance to make a first impression.

What Happens During an Examination?

The purpose of the examination process is to assess a company's compliance with relevant consumer financial laws, obtain information about the company's activities and compliance systems or procedures, and detect and assess risks to consumers and to markets for consumer financial products and services. While examinations may remain "off-site" until the COVID pandemic subsides, even remote examinations can involve voluminous information and document requests with quick turnaround, several months of back-and-forth with examiners, and the potential for remediation and penalties in the event of identified deficiencies.

The CFPB identifies an entity for examination based on an assessment of its risk to consumers, including its size, volume of consumer financial transactions, and volume of complaints in CFPB's consumer complaint database. The CFPB usually provides an entity with 30 to 60 days' advance notice of an examination.

What are some of the industries that we expect to attract the CFPB's attention in 2021 and beyond? With the Biden administration's focus on fair lending, areas that are likely to receive heightened scrutiny include banks, credit unions, and larger participants in such markets as student lending, small dollar lending, auto lending, and mortgages. We also expect scrutiny of traditional areas of focus, such as debt collection, and potentially new areas involving fintech and data aggregation.

Depending on the nature of the examinee's operations, the CFPB will generally engage in the following during an exam:

  • Collect and review available information, from within CFPB, from other federal and state regulators, and from public sources about the company and its activities (including reported data such as Home Mortgage Disclosure Act (HMDA) Loan Application Registers).
  • Request and review documents and information from the entity, including, for example, policies and procedures, training materials, contracts, and audit findings.
  • Request high-level data about consumer accounts and transactions, and more targeted, detailed account-level data and documentation.
  • Conduct interviews (on-site or remotely) and review documents and information provided by the company.
  • Draw preliminary conclusions about the regulated entity's compliance management and its statutory and regulatory compliance.

The CFPB will generally close an exam by providing the examinee with a report providing a detailed summary of the exam, a discussion of areas of concern, and potential deficiencies and action items for remediation. (The latter are known as "Matters Requiring Attention.") The exam team also will assign a confidential consumer compliance rating to an entity as part of the exam. The rating system evaluates an entity's compliance with federal consumer financial law and the adequacy of its compliance systems. The rating is based on a scale of 1-5, with 1 representing the highest rating and lowest level of supervisory concern, and 5 representing need for "the strongest supervisory attention."

As explained below, if the exam team identifies any significant MRAs and depending on how the company responds to those concerns, a matter may be referred to Enforcement staff to conduct an investigation and/or bring a public enforcement action against the company.

Best Practices for Managing a CFPB exam

As discussed, the best way to survive a federal or state examination is to be prepared. This means investing in compliance management; reviewing your products, services, and operations for risk to consumers; and then working cooperatively with your regulator in the event of an examination. Once an examination notice is received, there are a number of steps that can help ensure a smooth process and, it is hoped, a positive outcome:

  • Appoint a central point of contact. Designate an employee (preferably within the legal or compliance functions) to serve as the point of contact for the CFPB examination team and the document collection and production process.
  • Prepare and train staff who will likely interface with CFPB examiners.
  • Set up an initial meeting with examiners to explain the company's business model and set appropriate expectations. The beginning of the exam is the best opportunity to demonstrate your "culture of compliance" and educate examiners on the company's structure and operations. This may include preparing briefings on the company's organizational structure and compliance framework.
  • Set aside dedicated office and workspace for CFPB examiners who are on-site.
  • Serve as exam liaison. Respond in a timely manner to examiner requests and work with examiners to identify their key areas of interest and how best to provide the requested information. At the same time it is important to manage examiner expectations and maintain clear lines of communication. Establishing boundaries early in the process can help conserve your staff's resources and ensure that you provide accurate and clear information.
  • Work with counsel to review all submissions to the CFPB for responsiveness, privilege, and consistency.
  • Address any identified areas of concern. Most importantly, if examiners identify areas of concern, work with counsel to assess the preliminary findings, and "self-correct" or resolve the issues prior to the CFPB's issuance of a final examination report (as appropriate). As part a corrective action plan, consider root causes for issues identified during reviews and develop timelines for completion.
  • Make sure you understand your strengths, weaknesses, and data before the examination. The CFPB does not expect institutions to be perfect, but it does expect that you have a firm handle on compliance and are aware of and take action to address any areas of weakness. Given the expected focus on fair lending, understanding your loan data and being prepared to present (and explain) any potential disparate impact and corresponding defenses to CFPB examiners will be critical in upcoming examinations.
What Happens after the Examination?

The CFPB exam process has often led to or supported public enforcement actions, resulting in millions of dollars in consumer remediation and civil money penalties. Given these risks, it is critical to try and resolve examiner concerns before they snowball into a full-fledged investigation. Taking steps to resolve examiner concerns in advance can result in a final examination report with a better rating (meaning less future scrutiny) and, in cases of serious identified deficiencies, limiting damages to a "matter requiring attention" instead of an "enforcement action."

However, if you are unable to resolve an examiner's concerns about potential deficiencies, you should be prepared to receive a Potential Action and Request for Response (PARR) letter. This communication will list the Bureau's preliminary findings of alleged violations and inform your company that the Bureau is considering an enforcement action. In many cases, providing a strong written response to the PARR letter is the last, best chance to avoid an adverse examination report or enforcement action. To be effective, the written response should aggressively argue the supporting facts and legal arguments. The response should highlight the steps taken to self-correct, and explain why an enforcement action is unnecessary.

If an exam matter is referred for enforcement, the CFPB has the authority to bring an administrative proceeding or file a civil complaint in federal district court. The Bureau can obtain legal or equitable relief for violations of federal consumer financial law, including, but not limited to, equitable monetary relief (e.g., restitution) and civil monetary penalties. (Civil money penalties range, depending on the severity of the challenged conduct, from $5,883 to $1,176,638 per violation.) As noted, it is expected that the CFPB will flex its enforcement muscles under director nominee Rohit Chopra.

Finally, adverse examination findings or a less than satisfactory compliance rating (a 3, 4, or 5) may be appealed by following the CFPB's appeal process, which establishes strict time frames, requires that submissions be in writing, and puts CFPB staff in the role of final arbiter of the appeal. The appeals process also does not allow appeals of findings that have been recommended for an enforcement action. This underscores the importance of challenging adverse findings as early as possible in the examination process.

Matters that are good candidates for appeal are those that are based on specific established facts and disputed interpretations of law that have been developed and preserved through the examination process. Thus, having a strong record of factual findings, including efforts to correct such findings, as needed, can be critical. The process is often difficult, but well worth it for supervised entities that are seeking to push back against the CFPB and preserve their ability to challenge findings in court.

* * * * *

Preparing and responding to a CFPB examination can be a daunting process. The key to surviving an examination is to understand and follow applicable laws, invest time and resources in your compliance management system and staff, and work closely with examiners to ensure a fair and accurate process.

* * * * *

Related Articles and Presentations

Fintech Guide to Bank Partnerships: A Practical and Legal Roadmap

CFPB Enforcement Settlement Principles Revealed

Online Lending Legal and Policy Issues Resources

President Biden Selects Rohit Chopra to Lead CFPB and Appoints Acting Director

Court Vacates Two Provisions of the Prepaid Rule

Final Debt Collection Rule Issued by CFPB

Understanding the CFPB Debt Collection Final Rule

Debt Collection Consumer Disclosure Rule

Five Common Consumer Financial Services Legal and Regulatory Due Diligence Mistakes to Avoid in M&A

Mini-CFPBs – What Increased Regulation, Enforcement, and Supervision by State Agencies Mean for the Financial Services Industry

For more information about this and related industry topics, see www.venable.com/cfs/publications.