• Home
  • About Us
    • History
    • Meet Us
      • David A. Dickinson, President
      • Denise Wiese, Consultant
      • Jerod Moyer, Consultant
      • Amy Kudlacek, Consultant
      • Steve Doty, Consultant
      • Deb Jost, Consultant
      • Bob Sutton, Consultant
    • Contact Us
  • Services
  • Reviews
  • Products
    • Seminars
    • Compliance Manuals
    • Other Products
  • Seminars
  • Compliance Resources
    • Compliance Links
    • Free Downloads
  • Banking on BCC
  • Contact Us
  • Blog
    • HMDA - Reporting GMI for "Entities"
    • CFPB Regs Issued
    • 2012 CRA Threshold Updated
    • 2012 HOEPA
    • Reg Z & Reg M Thresholds Effective January 1
    • NFIP Extended Again - Are You Getting Tired of This Yet?
    • OFAC Search Tool

Blog

Compliance Officers - Risk Rating & Prioritizing

David Dickinson

By David Dickinson

I'm still providing you with my notes from the ABA's Regulatory Compliance Conference.  I attended a session on Risk Rating and Prioritizing tasks as a Compliance Officer.  Below are my notes from this session:

Gone are the days of checking off tasks.  Now you must risk assess everything.  Apply a risk approach to everything.  What issues are facing your bank?

Getting Organized:

Design a "Issues Status Report"

Be sure to list the responsible office and responsible officer/manager. (These people will want their name off the list - so it becomes a priority for them).

            If past due, change the color (yellow or red).  This will get a faster response.

Design a "Project Status Report"

Showing the schedule, process and completion status of tasks.  This is a great way to report to senior management and/or Board.

Risk Rating/Prioritizing:

Lower risk = lower priority

For example, check some disclosures once per year (such as the Cosigner notice) to make sure verbiage hasn't changed.

"Don't let the Compliance Tail wag the Banking Dog" time vs moneytime vs money

            If you under manage, issues will arise.

            If you over manage, you risk profits.time vs. money

It's not a "compliance culture". It's a "Risk Culture."

            Risk management starts at the top.

            Many senior people don't like the term "compliance". Use "risk".

Auditing & Risk Rating: 

For example, not all of Reg E is a high risk: 

Issuing access device (205.5) vs. initial disclosures (205.7) vs. error resolutions procedures (205.11). 

Same with Reg D, yet Reg D doesn't have the same monetary penalties or seems to receive less examiner scrutiny.

 

 

 

This entry was posted on August 13th, 2008 at 2:37 pm. RSS | Back to Blog Homepage.


View this document online at: http://www.bankerscompliance.com/blog/compliance-officers-risk-rating-prioritizing.htm
© 2012 Bankers Compliance Consulting
All Rights Reserved.