Recently the CFPB announced an enforcement action against a large U.S. Bank alleging that a number of their employees improperly opened consumer accounts without them having been applied for, or authorized by, the customers. The reports are very concerning, but are other banks doing this? In this particular instance, a number of accounts were purportedly opened and then closed within a brief period of time. In other cases, the [unauthorized] accounts remained opened. The stated motivation behind this activity were aggressive sales goals on the part of the bank and resultant pressure to meet those goals.
To date, the bank has been ordered to pay fines approximating $185 million, a portion of which will be used to compensate impacted customers. Media reports also indicate that approximately 5,300 employees have been let go.
Moreover, the case has sparked a large number of related actions including:
- Congressional hearings where the CEO of the company has been compelled to testify;
- The announcement that various federal and state prosecutors are “looking into” the matter;
- Calls for the Department of Labor to look into possible wage and hour violations;
- A recent announcement that “claw back” provisions will be invoked for executives that had oversight for the bank’s sales practices, including the CEO;
The significant regulatory, congressional, and public response to this matter demonstrate that bank compensation practices can potentially expose the company to significant regulatory, reputational, and financial risks.
As in all enforcement cases, not all of the facts are made public and it appears evident that management has taken significant action on its own to address this matter. This writing is not meant to opine on the facts at hand, the bank, or any other matter pertaining to this case.
However, as in all public enforcement actions, there are important “lessons learned” to be had and actions other banks should consider in response.
The Guidance on Sound Incentive Compensation Policies:
The regulators issued the “Guidance on Sound Incentive Compensation Policies”, the “guidance”) in June of 2010. . The guidance was applicable to all banks, however, initial supervisory efforts were directed towards the large banks where their activities posed greater systemic risk. Smaller banks were deemed to be less risky and the general view was that their incentive compensation practices would be less complex and easier to manage.
There are several key elements of the Guidance:
- As noted above, they apply to all regulated financial institutions;
- By design, the Guidance does not mandate any specific types of plans or practices and is designed to provide a framework in which financial institutions should operate; it does not limit compensation nor define acceptable forms of incentive compensation;
- The Guidance applies to employees who individually or as part of a group that have the ability to expose the bank to material amounts of risk;
- There are certain exemptions such as 401K programs;
The Guidance has three key principals:
- Incentive compensation arrangements should balance risks and rewards and not expose the bank to undue or imprudent risks;
- Incentive compensation arrangements should be compatible with effect controls, risk management, and oversight;
- Incentive compensation arrangements must be supported by strong corporate governance and with effective oversight by boards of directors;
Boards should be aware of certain “red flags” with respect to incentive compensation plans and direct management to take corrective action as needed:
- Poorly written or vaguely worded plans;
- Failure to incorporate clear risk guidelines and metrics;
- Volume based incentive programs without corresponding quality or compliance requirements;
- Lack of central oversight, administration and approval;
- Lack of Board oversight or committee review;
- Inadequate second and third line of defense engagement and oversight;
- Failure to react to red flags such as customer complaints or litigation;
Boards should consider taking a holistic look at the both the specific incentive compensation practices as well as the corresponding risk management controls at their respective banks:
- Ensure the incentive compensation guidance is incorporated into your compliance management program, regardless of bank size;
- Centralize administration of incentive compensation plans in one area (such as Human Resources) to ensure consistency and sound administration;
- Ensure that risk, compliance and quality metrics are incorporated into the plans to ensure risk and rewards are properly balanced. Sufficient data should be available to ensure these criteria can be met;
- Add board oversight of incentive compensation practices. Perform an annual review of all the plans with periodic updates on performance, compliance, and audits;
- Conduct periodic testing and review by the second and third lines of defense;
- Conduct macro level statistical testing to identify possible anomalies and signs of people “gaming the system” (for example, if the average payout is $1,000 take a hard look at the person earning $3,000);
- Exercise claw-back provisions for any instance of material non-compliance and ensure risk provisions in the plans are enforced;
- Monitor for signs of program failures via complaints, litigation, etc.
- Take note of employee comments or concerns that may identify possible exposures;
- Move quickly to remediate identified problems.
 Guidance on Sound Incentive Compensation Programs, FR Vol 175, #122, page 36396, June 25, 2010
Matthew Neels is the Senior Managing Director for Compliance for Strategic Risk Associates. He has a 30 year career in banking, having served as Chief Compliance Officer for two large banking institutions and as an OCC National Bank Examiner. He holds certifications in compliance, anti-money laundering, and privacy. He may be reached at firstname.lastname@example.org, 302-540-1441.