Pandemic Darlings The pandemic economy, in original documents
Home Court filings Bofa Ca Unemployment In re: Bank of America California Unemployment Benefits Litigation — S.D. Cal., No. 21-md-02992 Exhibit 111 — In re Bank of America California Unemployment Benefits Litigation (Dkt. 350-112, S.D. Cal. No. 3:21-md-02992)

Court filing

Exhibit 111 — In re Bank of America California Unemployment Benefits Litigation (Dkt. 350-112, S.D. Cal. No. 3:21-md-02992)

Filed October 24, 2024 in In re Bank of America California Unemployment Benefits Litigation; one of 1415 filings from this case.

Record facts

CourtU.S. District Court for the Southern District of California
Filed2024-10-24

U.S. District Court for the Southern District of California · No. 3:21-md-02992-GPC-MSB · Doc. 350-112 · 2024-10-24 · Docket on CourtListener

Full text

EXHIBIT 111 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12028 
Page 1 of 14

Comptroller’s Handbook
Consumer Compliance (CC)
CC-CMS
Compliance Management 
Systems 
Version 1.0, June 2018
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12029 
Page 2 of 14

Version 1.0 
Comptroller’s Handbook 
6 
Compliance Management Systems 
CMS Components 
 
CMS is the method by which a bank manages consumer compliance risk, supports 
compliance with consumer protection-related laws and regulations, and prevents consumer 
harm. The complexity of the compliance risk environment presents challenges for banks. The 
volume and complexity of consumer protection-related laws and regulations coupled with 
changing technologies and earnings pressures increase the importance of a bank’s CMS. 
Each bank should develop and maintain an effective CMS that is appropriate for the size, 
complexity, and risk profile of its operations. The CMS should consist of board and 
management oversight and a compliance program that includes all applicable consumer 
compliance-related laws and regulations. 
  
The consumer compliance rating takes into account the effectiveness of the bank’s CMS and 
factors relating to violations of law and consumer harm. Refer to the “Violations of Law and 
Consumer Harm” section and appendix A of this booklet for additional information.  
 
Board and Management Oversight  
 
Board and management oversight should be commensurate with the bank’s size, complexity, 
and risk profile. Oversight should factor in all applicable consumer protection-related laws 
and regulations and include consumer compliance expectations for third-party relationships. 
It is important for the board and management to understand the potential consequences of 
violations of laws and regulations that may result in customer reimbursements, financial 
losses, reputation risks, and legal risks, including enforcement actions (including CMPs). In 
relation to their respective roles, board and management oversight should include the 
following:  
 
• Oversight of and a commitment to the bank’s CMS, including oversight of third parties. 
• Effective change management processes, which include responding in a timely and 
satisfactory manner to any change, internal or external, to the bank. 
• Comprehension, identification, and management of risks arising from the bank’s 
products, services, or activities. 
• Self-identification of consumer compliance issues and timely correction of such issues. 
 
Oversight and Commitment 
 
The board and management should demonstrate a commitment to and oversight of the bank’s 
CMS.12 The board should oversee, and management should implement, a consumer 
compliance program with effective resources, including 
 
                                                 
12 Refer to the “Corporate and Risk Governance” booklet of the Comptroller’s Handbook for additional 
information regarding the roles of the board and management in establishing an appropriate compliance culture 
that incorporates all applicable laws and regulations, including consumer protection-related laws and 
regulations. 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12030 
Page 3 of 14

Version 1.0 
Comptroller’s Handbook 
7 
Compliance Management Systems 
• systems, capital, and human resources commensurate with the bank’s size, complexity, 
and risk profile. 
• knowledgeable staff who are appropriately trained, empowered, and held accountable for 
compliance with consumer protection-related laws and regulations. 
 
Board of Directors 
 
The board should create a culture that places a priority on compliance and holds management 
accountable. The board plays a pivotal role in the effective governance of the bank, including 
oversight of the bank’s CMS. The board should oversee management, provide organizational 
leadership, and establish core corporate values. The board should oversee management’s 
implementation of the bank’s CMS and hold management accountable for implementing a 
CMS that is consistent with the bank’s strategic direction, risk culture, and risk appetite.  
 
The board should receive sufficient consumer compliance-related information including 
management information systems (MIS) reports, risk assessments, and monitoring and 
independent audit reports to assess the effectiveness of the bank’s CMS and, when 
appropriate, provide credible challenge to management. Applicable board or board 
committee minutes should reflect the board’s or committee’s receipt and deliberation of 
information related to the bank’s consumer compliance risk management practices and the 
effectiveness of those practices to manage consumer compliance risk, support compliance 
with consumer protection-related laws and regulations, and prevent consumer harm. The 
board should understand its roles and responsibilities related to consumer compliance, and 
periodically assess directors’ consumer compliance skills and competencies relative to the 
bank’s size, complexity, and risk profile. Management can support the board by instituting an 
ongoing education and training program that includes consumer compliance to keep the 
board informed and current on general industry trends and regulatory developments, 
particularly regarding issues that pertain to the bank. 
 
Bank Management  
 
The board generally delegates authority to management for directing and overseeing day-to-
day operations of the bank, including developing and implementing the bank’s CMS 
consistent with the board’s strategic objectives and risk appetite. Management should 
monitor the performance of the compliance program, including 
 
• third-party risk management processes that include due diligence and ongoing monitoring 
of third parties (i.e., third-party risk management processes). 
• change management. 
• comprehension, identification, and management of risk. 
• self-identification of compliance risk management deficiencies and corrective action. 
 
Management may use committees to facilitate oversight of day-to-day banking activities, 
including consumer compliance-related activities. Management should determine which 
committees are appropriate for the bank and how formal each committee’s structure should 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12031 
Page 4 of 14

Version 1.0 
Comptroller’s Handbook 
8 
Compliance Management Systems 
be. Examples of consumer compliance-related committees may include compliance risk 
management and fair banking.  
 
Management also should establish and clearly communicate compliance-related roles and 
responsibilities. Regardless of the form of the compliance function, management should 
provide it with appropriate resources, including systems, capital, and human resources. Many 
banks establish a separate compliance function headed by a compliance officer. In such 
banks, the compliance officer should have the authority and independence to facilitate 
compliance throughout the bank and sufficient time and resources, including staff, to execute 
assigned duties. The compliance officer should have the appropriate skills and knowledge of 
the consumer protection-related laws and regulations applicable to the bank. Compliance 
officers should oversee the compliance training for all bank employees. For banks with 
limited staff or overlapping compliance and other responsibilities, training and development 
is particularly important to conduct continuous and consistent operations. Additionally, the 
compliance officer should be afforded opportunities for external training to maintain or 
refresh his or her subject matter expertise pertinent to overseeing the bank’s compliance 
program.  
 
Third-Party Risk Management 
 
There can be certain benefits to banks engaging in relationships with third parties, including 
gaining operational efficiencies or an ability to deliver additional products and services. 
Third-party relationships may expose the bank to risks, if not managed effectively. While 
management may make the business decision to outsource some or all of the operational 
aspects of a product or service, the bank cannot outsource the responsibility for complying 
with consumer protection-related laws and regulations or managing the consumer compliance 
risks associated with products or services offered by the third party. Management should 
implement third-party risk management processes commensurate with the level of risk and 
complexity presented by the third-party relationships. The bank’s third-party risk 
management process should include the following specific to consumer compliance:  
 
• Due diligence and ongoing monitoring of third parties to assess compliance with 
consumer protection-related laws and regulations. 
• Oversight of third parties’ consumer compliance-related policies, procedures, internal 
controls, and training.  
 
Refer to OCC Bulletin 2013-29, “Third-Party Relationships: Risk Management Guidance,” 
OCC Bulletin 2017-21, “Third-Party Relationships: Frequently Asked Questions to 
Supplement OCC Bulletin 2013-29,” and OCC Bulletin 2017-7, “Third-Party Relationships: 
Supplemental Examination Procedures,” for additional information regarding third-party risk 
management. 
 
Change Management 
 
Specific to consumer compliance, management should anticipate and respond in a timely 
manner to changes in applicable consumer protection-related laws and regulations, market 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12032 
Page 5 of 14

Version 1.0 
Comptroller’s Handbook 
9 
Compliance Management Systems 
conditions, and products and services offered by evaluating the change and implementing 
responses across affected lines of business. Management should have a process to identify 
laws and regulations applicable to the bank’s activities and stay abreast of evolving 
regulatory requirements. The formality of the change management process should be 
commensurate with the bank’s size, complexity, and risk profile.  
 
Management should conduct due diligence in advance of engaging in new, modified, or 
expanded products or services, consider the entire lifecycle of a product or service in 
implementing change, and review the change after implementation to determine that actions 
taken have achieved planned results. The compliance function should be involved in the due 
diligence and monitoring of new, modified, or expanded products or services. Refer to OCC 
Bulletin 2017-43, “New, Modified, or Expanded Bank Products and Services: Risk 
Management Principles,” for additional information. 
 
Comprehension, Identification, and Management of Risk 
 
Management should comprehend, identify, and manage consumer compliance risks, 
including existing and emerging risks to the bank’s products, services, and other activities.  
 
The sophistication of risk management should be proportionate to the risks present and the 
bank’s size and complexity. Regardless of the bank’s size and complexity, sound 
management of consumer compliance risk should do the following: 
 
Identify risk: The board and management should identify existing risks and risks that may 
arise from new business initiatives, including risks that originate in nonbank subsidiaries, 
affiliates, and third-party relationships and those that arise from external market forces or 
regulatory or statutory changes. Risk identification should be a continual process and should 
occur at the transaction, portfolio, and enterprise levels. For larger, more complex banks, the 
board and management also should identify interdependencies and correlations across 
portfolios and lines of business that may amplify risk exposures. Proper risk identification is 
important for banks to determine that risks are addressed appropriately.  
 
Measure risk: Accurate and timely measurement of risks is important to effective risk 
management systems. A bank that does not have a risk measurement system has limited 
ability to control or monitor risk levels. Further, the bank should have more sophisticated 
measurement tools as the complexity of the risk increases. Management should periodically 
conduct tests to verify that the bank’s measurement tools are accurate. Sound risk 
measurement systems assess the risks at the individual transaction, portfolio, and enterprise 
levels. Larger, more complex companies should pay particular attention to assessing the 
effect of increased transaction volumes across all risk categories. 
 
Monitor risk: Management should monitor risk levels to confirm timely review of risk 
positions and exceptions, including throughout business combination and reorganization 
activities. Management-developed and -implemented monitoring reports should be timely 
and accurate and should be distributed to appropriate individuals, including the board, to 
initiate action, when appropriate. For larger, more complex banks, monitoring is important to 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12033 
Page 6 of 14

Version 1.0 
Comptroller’s Handbook 
10 
Compliance Management Systems 
confirm that management’s decisions are implemented for all geographies, products and 
services, and legal entities. Well-designed monitoring systems allow the board to hold 
management accountable for operating within established risk appetites. 
 
Control risk: The board should determine that risk limits are communicated through 
policies, standards, and procedures that define responsibility and authority. These limits 
should serve as a means to control exposures to the various risks associated with the bank’s 
activities. The limits should be tools that, based on board approval, can be adjusted when 
conditions or risk appetites change. Management should have a process to document 
adherence to established limits, and to authorize, document, and report to the board 
exceptions to risk limits. Large, diversified banks should have strong risk controls covering 
all geographies, products and services, and legal entities to prevent undue exposure from 
concentrations of risk. 
 
Risk Assessment 
 
The bank’s CMS should include a consumer compliance risk assessment process 
commensurate with the size, complexity, and risk profile of the bank. Completing risk 
assessments helps management identify current and emerging consumer compliance risks in 
order to prevent, self-identify, and address potential consumer compliance issues. A well-
designed risk assessment process should be supported by appropriate methodology that 
includes quantitative and qualitative data and evaluates risk across all products, services, and 
lines of business. An effective risk assessment process helps the board and management 
address emerging risks at an early stage and allows them to proactively develop and 
implement appropriate strategies to mitigate the risks before the risks have an adverse effect 
on the bank’s condition or risk profile. 
 
Management should perform or update the bank’s consumer compliance risk assessment 
periodically, based on the bank’s size, complexity, and risk profile. The sophistication of the 
risk assessment process should be commensurate with the bank’s size, complexity, and risk 
profile. In less complex banks, it may be appropriate to have a single compliance risk 
assessment evaluating all products, services, and business lines. In more complex banks, the 
risk assessment process may involve completing multiple compliance risk assessments, with 
results of individual risk assessments aggregated into an overall compliance risk assessment 
that considers and evaluates consumer compliance risk at the enterprise level. While an 
effective risk assessment process may look different across banks, each risk assessment 
should evaluate and make determinations regarding the following:13 
 
• Inherent risk, which is the risk that an activity would pose if no controls or mitigating 
factors were in place. 
• Residual risk, which is the level of risk after controls are taken into account.  
 
                                                 
13 Refer to the “Corporate and Risk Governance” booklet of the Comptroller’s Handbook for more information 
regarding risk assessments.  
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12034 
Page 7 of 14

Version 1.0 
Comptroller’s Handbook 
11 
Compliance Management Systems 
Self-Identification and Corrective Action 
 
Management should identify, respond to, and remediate violations of laws or regulations and 
deficient practices in a timely manner. Moreover, self-identification and prompt correction of 
violations and deficient practices may reflect strengths in the bank’s CMS and could indicate 
management’s and the board’s commitment to address responsibly underlying consumer 
compliance risk. Appropriate corrective action should remedy harmed parties, correct 
programmatic weaknesses related to the violation, and prevent violations from occurring in 
the future.  
 
Issues Management 
 
Issues management refers to processes for tracking, escalating, and resolving issues (e.g., 
deficient practices, violations, or other weaknesses) identified across the bank. Traditionally, 
internal audit has been responsible for maintaining formal processes to track and follow up 
on issues identified through audits and regulatory examinations. Issues can also surface from 
other sources, however, including quality control and quality assurance processes, 
monitoring and testing by the compliance function, control gaps identified through the risk 
assessment process, management’s self-identification of issues, and adverse trends identified 
from monitoring of consumer complaints. Management should design and implement an 
issues management process that incorporates all sources of risk and issue identification. The 
issues management process should include identification of root causes of issues and 
determining whether issues are related to a specific product, service, or business line or if 
issues are systemic. The board should be apprised of material issues and resolution strategies, 
and hold management accountable for correcting issues and validating corrective actions. 
 
Consumer Compliance Program 
 
An effective consumer compliance program should include the following: 
 
• Policies and procedures that are appropriate to the complexity and risk in the bank’s 
products, services, and activities, including an appropriate third-party risk 
management process. 
• Consumer compliance training that is current and tailored to risk and staff 
responsibilities. 
• Monitoring and, if applicable, audit that encompass consumer compliance risks 
throughout the bank. 
• A responsive and effective consumer complaint resolution process. 
 
Policies and Procedures 
 
Consumer compliance policies and procedures, including those for the bank’s third-party risk 
management process, should provide standards for managing consumer compliance risk in 
the bank’s products, services, and activities. 
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12035 
Page 8 of 14

Version 1.0 
Comptroller’s Handbook 
12 
Compliance Management Systems 
Policies are statements of actions that the bank adopts to pursue certain objectives. Policies 
guide decisions and often set standards (on risk limits, for example) and should be consistent 
with the bank’s underlying mission, strategy, risk appetite, and core values. 
 
The scope and detail of those policies should vary depending on the bank’s size, complexity, 
and risk profile. A smaller, noncomplex bank with management that is heavily involved in 
the bank’s day-to-day operations should have basic policies addressing the significant areas 
of consumer compliance risk. Larger, more complex banks, where senior management relies 
on a widely dispersed staff to manage consumer compliance risks associated with complex or 
varied products, services, and activities, should have more detailed policies. Appropriate 
policies should be in place and approved by the board before the bank engages in any new or 
significantly changed consumer compliance-related activities. 
 
Procedures define how the bank is to carry out its policies. Management should consider the 
complexity and risk associated with products, services, and activities when determining the 
level of formality needed for consumer compliance-related procedures. Procedures should be 
consistent with related bank policies.  
 
Consumer Compliance Training  
 
Consumer compliance training should be timely, and specifically tailored to employees’ job 
functions and the bank’s products, services, and level of risks. Training should span the 
entire organization, including staff responsible for product development, marketing, and 
customer service. Banks should train business line employees on consumer compliance 
requirements and bank procedures. The compliance and audit functions should have access to 
more advanced or specialized training, including emerging risks, trends, and industry 
developments, and training on compliance-related policies and procedures. Training for the 
board and management is generally focused on the their individual responsibilities to oversee 
and govern the bank’s CMS. 
 
Standards for the frequency, method (e.g., formal, on-the-job, external), and documentation 
of training should be addressed in policies and procedures. For example, some laws impose 
mandatory training requirements. Periodic training increases the likelihood of adherence to 
the bank’s policies and procedures and to changing legal requirements. Records, including 
training content, attendees, and completion dates, should be maintained to demonstrate the 
effectiveness of the bank’s training program. The method and documentation of training may 
vary depending on the size of the bank or department, established time frames for training, 
and the significance and complexity of the subject matter. 
 
The consumer compliance training program should be updated in advance of the introduction 
of new products, services, activities, or the effective date of new consumer protection-related 
laws and regulations to ensure that all staff are aware of compliance requirements before 
such changes occur. 
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12036 
Page 9 of 14

Version 1.0 
Comptroller’s Handbook 
13 
Compliance Management Systems 
Monitoring and Audit 
 
Monitoring of consumer compliance risk is a key aspect of an effective CMS that involves 
both the evaluation and reporting of risks. Consumer compliance risk identification and 
assessment activities, such as risk control self-assessments, quality assurance, and quality 
controls, are integral to monitoring by providing ongoing or periodic evaluation of the bank’s 
consumer compliance risk environment. To facilitate monitoring of consumer compliance 
risk, the bank’s CMS should include bank-wide monitoring inclusive of the bank’s products, 
services, and activities.   
 
Management’s assessment of consumer compliance risk associated with the bank’s products, 
services, activities, and processes may assist the bank in determining the extent, depth, 
frequency, and focal points of independent consumer compliance audits. For instance, 
monitoring may be appropriate for products, services, activities, or processes that are less 
complex or demonstrate less risk. The board may require an independent consumer 
compliance audit to determine the bank’s compliance with consumer protection-related laws 
and regulations, particularly for more complex, higher-risk products, services, activities, or 
processes. Additionally, a periodic and independent audit of the bank’s CMS should provide 
the board with information to determine the effectiveness of the bank’s CMS. 
 
Monitoring and audit activities should be timely and should identify and measure material 
consumer compliance risk throughout the bank. Monitoring and audit of the bank’s 
compliance program should be proactive in identifying procedural or training weaknesses to 
preclude consumer protection-related violations. Compliance program modifications made to 
address identified weaknesses should be implemented expeditiously to minimize consumer 
compliance risk. 
 
Monitoring  
 
Effective monitoring and testing include quality control and quality assurance14 and identify 
violations of consumer protection-related laws or regulations or non-compliance with bank 
policies and procedures. Effective monitoring also provides timely identification of CMS 
deficiencies or weaknesses and can limit the size and scope of consumer harm by providing 
for timely corrective action.  
 
Monitoring is generally more frequent and less formal than the independent review 
performed by the audit function. The plan and schedule for monitoring activities, however, 
should be risk-based, documented, and updated at least annually. Management, in 
consultation with the board, should determine the frequency, scope, and formality of 
monitoring and testing. Depending on the size, complexity, and risk of the bank, staff 
responsible for monitoring and testing may have less independence than the audit function’s 
staff. Management should clearly outline roles and responsibilities so that monitoring by the 
various groups is complementary and not duplicative.  
                                                 
14 Refer to the “Corporate and Risk Governance” booklet of the Comptroller’s Handbook for additional 
information regarding quality control and quality assurance. 
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12037 
Page 10 of 14

Version 1.0 
Comptroller’s Handbook 
14 
Compliance Management Systems 
Transaction testing is an important component of monitoring. A bank’s sampling 
methodology should incorporate appropriate sampling techniques. Transaction testing may 
be conducted by compliance staff or within business lines. Other forms of monitoring may 
include employee interviews, policy and procedure review, assessing training effectiveness, 
and comparison of actual practices with disclosures provided in connection with transactions. 
 
The bank should complete root cause analyses to determine whether identified violations of 
law or regulation or failures to follow established policies and procedures are isolated events 
or systemic. Identified issues should be escalated and tracked in accordance with the bank’s 
issues management policies and procedures. Additionally, the root cause determination 
should identify whether existing controls should be enhanced or if new controls should be 
implemented. 
 
Audit 
 
The bank’s internal audit system15 should include risk-based independent reviews of the 
bank’s CMS to provide the board and management reasonable assurance of the bank’s 
consumer compliance-related risk management. Inclusion of CMS in the audit program 
substantially lessens the risk of a bank failing to detect potentially serious problems, such as 
non-compliance with consumer protection-related laws or regulations. The bank’s risk-based 
internal audit coverage over CMS should include the following: 
 
• Independent and qualified auditors who are knowledgeable of consumer protection-
related laws and regulations and can assess the appropriateness of the bank’s CMS. 
• Testing of internal controls to identify 
˗ 
inaccurate, incomplete, or unauthorized transactions. 
˗ 
violations of consumer protection-related laws or regulations. 
˗ 
deviations from the bank’s consumer compliance-related policies and procedures. 
˗ 
thematic consumer compliance control issues, including the root cause, across 
business activities or auditable entities. 
• Evaluating the adequacy of established consumer compliance-related policies and 
procedures and identifying non-compliance with the bank’s consumer compliance risk 
management processes. 
• Reviewing and validating management actions to address material consumer compliance-
related weaknesses. 
 
The bank’s audit risk assessment process should include identification of consumer 
compliance-related auditable entities, including third parties. The bank may perform a 
separate audit to evaluate the overall effectiveness of the bank’s CMS, while audit coverage 
for consumer protection-related laws and regulations may encompass several individual 
audits or continuous auditing activities.   
 
                                                 
15 Refer to 12 CFR 30, appendix A, II.A, “Operational and Managerial Standards,” and the “Internal and 
External Audits” booklet of the Comptroller’s Handbook for information regarding internal audit systems, 
including compliance audit systems.  
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12038 
Page 11 of 14

Version 1.0 
Comptroller’s Handbook 
15 
Compliance Management Systems 
The bank’s process to track, monitor, report, and follow up on audit issues should include 
consumer compliance-related audit issues.   
 
Consumer Complaint Resolution Process 
 
Consumer complaints can be an indicator of potential risk management weaknesses or other 
deficiencies, such as violations of laws or regulations. Complaints can reveal a weakness in a 
particular bank product, service, function, or department, or can identify opportunities to 
enhance customers’ experience and understanding of bank products or services. Complaints 
can help banks assess services performed by third parties. While the absence of complaints is 
not conclusive of a strong CMS, the presence of complaints, especially multiple complaints 
regarding the same or similar issue, may indicate a weakness in the bank’s CMS.  
 
Banks should have a process for identifying, managing, and analyzing complaints. The 
formality of the process should be commensurate with the bank’s size, complexity, and risk 
profile. An effective complaint resolution process should generally include the following: 
 
• How the bank defines a complaint and requirements for documentation of complaints. 
With changing technology, complaints can come in many forms or through various 
channels: letters, phone calls, in person, other regulators, third-party service providers, 
emails, and even social media. Bank policies and procedures should address how these 
various types of complaints are documented and tracked. 
• Responsibility and accountability for identifying, addressing, and escalating complaints. 
• Tracking of complaints and bank responses or actions. A centralized tracking process can 
improve the identification of trends or patterns. 
• Analysis of complaints to determine if a trend or pattern exists, and identifying the root 
cause of significant trends. 
• Reporting complaint data and trends to the board and management.  
 
Procedures should identify who is responsible for addressing complaints and detail the 
escalation process, including an alternative process for complaints involving the employee(s) 
tasked in the standard escalation process. Analysis of complaint data should be reported to 
the board and management to  
 
• identify areas of concern relating to compliance management and consumer protection; 
and  
• enable the bank to take proactive steps to mitigate risk of violations, consumer harm, 
regulatory actions, and legal action.  
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12039 
Page 12 of 14

Version 1.0 
Comptroller’s Handbook 
16 
Compliance Management Systems 
Violations of Law and Consumer Harm 
 
A violation of law or regulation is an act (or failure to act) that deviates from, or fails to 
comply with, a statutory or regulatory requirement. Violations (or lack of violations) alone 
are not conclusive to determine the effectiveness of a bank’s CMS. Examiners should 
consider the nature, extent, severity, and root cause of violations when assessing the bank’s 
CMS. Also, a bank’s CMS can be weak when no violations are identified, if one or more 
components are absent or ineffective. 
 
Violations often result from deficient practices. The existence of violations can be indicative 
of weaknesses in the bank’s CMS. Violations that result from deficiencies in component(s) of 
the bank’s CMS may be indicative of weak or lax board oversight or lack of management 
involvement in day-to-day operations of the CMS.  
 
The bank’s CMS should include processes for timely self-identification and appropriate 
resolution of violations. Timely self-identification and correction may support a conclusion 
that monitoring and compliance audit activities are being carried out effectively. 
 
Refer to the “Bank Supervision Process” booklet of the Comptroller’s Handbook for 
additional information regarding the OCC’s policies and procedures regarding violations of 
laws and regulations. 
 
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12040 
Page 13 of 14

Version 1.0 
Comptroller’s Handbook 
17 
Compliance Management Systems 
Examination Procedures 
 
This booklet contains objectives and expanded procedures for assessing the effectiveness of a 
bank’s CMS in relation to consumer compliance risk management. Examiners decide which 
of these objectives and procedures are relevant to the scope of the examination during 
examination planning or after drawing conclusions during the compliance core assessment as 
outlined in the “Community Bank Supervision,” “Federal Branches and Agencies 
Supervision,” and “Large Bank Supervision” booklets of the Comptroller’s Handbook. 
 
Scope 
 
These procedures are designed to help examiners tailor the examination to each bank and 
determine the scope of the CMS examination. This determination should consider work 
performed by internal and external auditors and other independent risk control functions and 
by other examiners on related areas. Examiners need to perform only those objectives and 
examination procedures that are relevant to the scope of the examination as determined by 
the following objective.  
 
Objective: To determine the scope of the CMS examination and identify examination objectives 
and activities necessary to meet the needs of the supervisory strategy for the bank. 
 
1. Review, as applicable, the following sources of information and reports, and note any 
previously identified consumer compliance deficiencies related to CMS that require 
follow-up: 
 
• Supervisory strategy. 
• Examination scope memorandum. 
• The OCC’s supervisory information system. 
• Previous reports of examination, supervisory letters, and work papers. 
• Consumer compliance-related supervisory information obtained from other regulatory 
agencies. 
• Internal and external audit reports and work papers. 
• Bank management’s responses to previous reports of examinations, supervisory 
letters, and audit reports. 
• Customer complaint and litigation data, including data from the OCC CAG, the 
BCFP, and the bank. Coordinate with the examiner responsible for completing the 
compliance RAS and core assessment to avoid duplicating complaint data review. 
• Whistleblower referrals received by the OCC or internally within the bank. 
Coordinate with the examiner-in-charge (EIC), as the EIC may already possess this 
information. 
 
2. Obtain and review consumer compliance-related policies, procedures, and reports the 
board and bank management use to evaluate the effectiveness of the bank’s CMS. 
Examiners should consider  
 
Case 3:21-md-02992-GPC-MSB     Document 350-112     Filed 10/24/24     PageID.12041 
Page 14 of 14

File and source

File
gov.uscourts.casd.709615.350.112.pdf
Size
603,550 bytes
SHA-256
d52f00b2e2642ac7cc2f22b72d9c4a8c209a2d6f484db1b3cb20126cdf6ab90c
Our copy
gov.uscourts.casd.709615.350.112.pdf
Original
PACER (login required)
Back to top