July 22, 2021|CFPB, Mortgage Industry, Professionalism, Regulation by Enforcement, UDAAP, Vendor Management

I often feel like I am Dr. Rick from the Progressive Insurance commercials when he provides guidance. Admittedly, I have kind of been obsessing over the Dr. Rick character for months now, since I also mentioned that in a prior Musings. I really think he would make the ideal trainer for financial service compliance. I like him so much, I’m going to make him come to life (in a manner of speaking) at one or more of my next speaking engagements (I’ve got a bunch of in-person events scheduled this fall).[1] More on Dr. Rick later.
Praise where due
In the regulatory compliance field, guidance is something that helps the firm or compliance professional comply with the law or regulation. Contrary to the implications of former CFPB director and current student loan guru Richard Cordray[2], regulatory guidance is not, an enforcement action that seeks to change the interpretation of a law to fit the regulator’s preferred outcomes. Changing the law through stretching interpretations in enforcement actions is not the same thing as guidance; that requires another process entirely.[3]
Now given my attitude above and most of my prior Musings, it might come as a surprise that a couple federal unfair and deceptive enforcement actions against financial services companies are about to get praised by this normally critical industry blogger. But, as far as I am concerned, the cases I discuss below are exactly the kind of enforcement against consumer abuses that the CFPB and FTC were set up to address. Moreover, in each instance, the regulator did not stretch the law or regulation to arrive at any new interpretations of any unfair and deceptive standard. They merely pointed out what should have been blatantly obvious from the beginning. Kudos to CFPB and FTC for getting it right on the mark in the two cases below. I’m also glad that in both these instances, it wasn’t a mortgage industry company acting irresponsibly vis[4]consumers.
UDAAP for dummies
Before I get into specifics, I really don’t understand why some financial service companies seem to need so much guidance about what is an unfair, deceptive or abusive[5]practice. It’s really not that hard. Behave like ethical professionals who have the consumer’s best interests at heart and don’t do unfair or deceptive things, especially to vulnerable or minority consumers. If you are trying to trick the consumer instead of helping them, that’s unfair and deceptive (and illegal). Yet, over and again, these simple truths seem to be difficult to grasp for some lenders and/or the people that run them.
No Hidden Fees-LendingClub
It would seem the financial services industry needs a Dr. Rick of unfair and deceptive practices. For example, consider this Dr. Rick-worthy question coming from an executive: “Is it ok to say ‘No Hidden Fees’ in all of your marketing, but then hide a huge hidden fee where the consumer won’t know to look for it?” Dr. Rick would quickly say, “the answer is no”.
Think no one would be that stupid? You’d be wrong. Take a look at these guys: LendingClub Agrees to Pay $18 Million to Settle FTC Charges | Federal Trade Commission. Of course, LendingClub’s own compliance people even told them it was a problem to do that[6]. But, literally, that is exactly what they did. LendingClub’s ads promoted “No hidden fees” everywhere but they went right ahead and charged a hidden fee anyway.[7] There are probably some executive(s) at Lending Club who said, “show me exactly where it says we can’t do that.” They all need a hug from Dr. Rick.[8]
Third party oversight-CFPB Green Sky action
As Ron Popeil often said of his Ronco products, “but wait, there’s more” [9]. It shouldn’t come as a surprise to anyone that opening an unauthorized account for a consumer is an unfair and deceptive practice. For example, I imagine someone at Wells Fargo back around 2010-2015 must have asked, “Can we ask a new deposit account customer if they want a credit card and if they say no, just sign them up anyway?”
Well, my Dr. Rick of financial services compliance would understand what professional ethics are about. Upon hearing that fictional Wells employee, Dr. Rick might respond to think about the consumer, “You’re not helping”. Then, after discussing Well’s account opening scandal, Dr. Rick might ask his students, “how about letting a third-party merchant open accounts for you so they can sell more of their stuff, is that a good idea?” Of course, that’s a bad idea, but that’s exactly what this recent CFPB Consent Order against Green Sky described. I think you get my point, but even with Wells Fargo’s issues in the rear-view mirror, apparently, Dr. Rick is still needed to gently provide awareness for some people that opening unauthorized consumer accounts is not ok.
Clear and Helpful Guidance
As I read the CFPB’s Green Sky Consent Order, however, I saw some clear and helpful guidance for mortgage compliance professionals beyond identifying the specific unfair practice of opening unauthorized accounts (that should have been obvious). Green Sky’s Order also highlights the negligent oversight of third parties who were interacting directly with Green Sky’s consumers. There was little or poor compliance training and oversight with those third parties and most processes were geared solely towards generating volume without much regard for compliance. Moreover, the consumer complaint process was deficient in that there was no feedback loop to take hundreds of complaints and use them to realize they had a problem and what to do about it.
Meanwhile, the federal banking regulators (OCC, FDIC and the Fed) just issued proposed guidance on managing risks associated with third-party relationships. That proposal is the first time that the three banking agencies have proposed third-party risk management guidance on an interagency basis. That kind of guidance along with the CFPB’s Consent Order are important, not because any interpretation of the law has changed, but rather, the regulators identified an issue for compliance professionals to assess, manage and control: specifically, the risk posed by third parties to compliant consumer interactions. This includes both the use of third parties to generate sales (consider lessons for wholesalers) as well as other vendor management oversight concerns about system access and control over product and service delivery. That’s guidance on how to do the compliance job better, not guidance about what the law is; guidance that I appreciate and applaud.
[1] I’ll be at NS3 in Naples FL talking RESPA with Mitch Kider on September 1, and the MBA Regulatory Conference in DC talking RESPA with Holly Bunting on September 14. But for a definite Dr. Rick RESPA riff, check me and Mark (Dr. Mark) Meyer out at RESPRO’s fall seminar in Scottsdale in October 4-6. I am so glad to be getting back in person!
[2] In 2016 Cordray told a financial trade association that it would be “compliance malpractice” not to follow the “guidance” of the CFPB’s Consent Orders. Yet, the PHH decision concluded that if you had followed the RESPA “guidance” in the CFPB’s enforcement action against PHH, you would have actually misinterpreted RESPA just as Mr. Cordray and CFPB had. Sure, consent orders can tell you what the CFPB’s enforcement priorities are and how they might be interpreting something, but there is no constitutional, legal or malpractice basis to take a consent order’s “guidance” as an official interpretation of the law.
[3]Like notice and comment rulemaking or actual legislation.
[4]Use of the word, “vis” in lieu of “in relation to” is another instance where that high school French comes in handy (short for vis-à-vis: literally, face to face). Sorry, did that French thing again with “in lieu”. As Steve Martin says, “I hate the French. They have a different word for everything.”
[5]The “abusive” standard doesn’t seem to add much to unfair or deceptive except maybe to add an element of meanness. Still, CFPB is identifying examples that should be obvious as it develops meaning around “abusive” (see e.g., Focus on Fintech: CFPB settles claim against debt settlement company SettleIt for $1.4 Million, finding “a clear example” of abusiveness in the company’s self-interested deals with affiliates – Eversheds Sutherland (eversheds-sutherland.com)
[6] Saying “I told ya’ so”, doesn’t make the boss any happier. Apparently, counsel for one of their investors also raised this as an issue.
[7]The full FTC Complaint can be found here LendingClub Corporation Complaint, April 25, 2018 (ftc.gov)
[8] If you are a mortgage executive who thinks competing with the rest of the industry by being willing to “bend” compliance is a good idea, or asks your compliance person to “show me where it is written” on every issue, you need a hug from Dr. Rick too.
[9]The Pocket Fisherman was my favorite Popeil/Ronco product (fishing fun for the whole family-must have been the alliteration I liked). What was your favorite?