10 Tips for Banks Responding To Regulatory Requests
Responding to regulatory requests for additional information is a normal part of a bank’s operations. A request can come from any of the various agencies — such as the Office of the Comptroller of the Currency, the Federal Reserve Board or the Federal Deposit Insurance Corp. — responsible for areas where financial institutions may need to improve their processes, mitigate risk or take other actions.
However, while general requests for additional information may be common, they can never be treated as routine. A poorly written or confusing response may cause a regulatory agency to make assumptions about a bank that may not be true, such as:
- It has an inadequate understanding of its business risks
- It does not have the right resources and/or expertise to respond appropriately
- It does not appreciate the importance of the request
- It may be poorly managed
- It is not cooperating fully
Here are 10 ways financial institutions can avoid sending these types of negative messages in their responses.1. Put Senior Leadership Front and Center
It is crucial to demonstrate in your response that your C-suite and board members are thoroughly involved in the issue at hand; top-level involvement indicates how important the regulators’ concerns are to the bank. Describing in detail the roles and actions of C-suite officers illustrates that the bank’s leadership is engaged and committed to resolving the issues raised in the request. Wherever possible, highlight senior leaders’ part in developing, overseeing and approving policies and procedures. Indeed, putting a senior leader in charge of the process is the best way to ensure it is followed rigorously.2. Ensure Everyone Involved Understands the Request Thoroughly and Deeply
The entire request, along with the related regulatory guidance and FAQ section (if applicable), must be read and re-read — not just by the person overseeing the response but by everyone who will be contributing to it. Every person should highlight anything they find confusing or about which they have questions. If the team is unclear or uncertain about any items in the request, the bank should request clarification from the regulators before preparing a response. If appropriate, ask for — and send appropriate C-suite representatives to — an in-person meeting with regulators to gain clarification.3. Write a Strong Executive Summary
For many reasons, an executive summary is a critical component of the response, not the least of which is it may be the only section that senior regulatory executives read. The summary also is an opportunity for the bank to frame, from its perspective, the issues being examined, as well as highlight the actions it has taken to remediate any problems and the potential difficulties or holdups that could affect its remediation plan.
A good executive summary doesn’t just state facts; it articulates a position and describes how the institution arrived there. Simply put, an executive summary that merely focuses on what is being done is inadequate. Done right, the summary lets the regulators know who was engaged in the remediation effort, what the process was, how options were chosen and when the plan is expected to be implemented.4. Follow the Regulators Lead
Make your response as easy as possible for recipients to follow and understand. That means reflecting the structure and language the regulators used to express their concerns in the request. To avoid confusion, respond to information requests in the order in which they were listed in the original communication. This will make it easier for requestors to quickly find the information they are looking for and demonstrates your understanding of the request. Using the language, acronyms and jargon used by the writers of the request helps prevent misunderstandings.5. Provide a Road Map
In addition to the executive summary and table of contents, provide a road map or chart to guide the reader to the response to each information request. This will make it clear that every issue the request raised has been addressed. Double- and triple-check the road map to ensure its accuracy. An incorrect road map will irritate your reader and potentially invite questions about the overall accuracy of your response.6. Respond Directly to Each Request
Take everything in the request literally and respond accordingly. Do not interpret or extrapolate. Do not provide superfluous information. If something is not clear to you, ask the regulators for clarification. As mentioned in no. 2, understanding the request is vital to responding accurately to their concerns, and having a senior officer responsible for overseeing the entire response process can ensure that no part of the request is omitted or forgotten.7. Make Sure Each Section Can Stand on Its Own
While your response must be a coherent whole, each individual section must be able to stand on its own. In a lengthy response, it is unreasonable to assume that every person will read the entire document; rather it’s likely that each section will be reviewed by different individuals. Consequently, restate information when appropriate. It is better to be redundant than to confuse the regulator or, worse, appear nonresponsive.8. Show Your Work
The processes the bank uses to address issues raised by the regulator is just as important as the results the bank achieves, and they must be explained fully. No response should conflate actions or skip processes. A response along the lines of “When an alarm goes off, we answer the alarm” is inadequate. The response should describe how the bank knows when an alarm has been triggered, who is answering it, when it is answered, what the bank does when it answers it, and how the bank can answer it in a specified time frame. In other words, responses should contain the who (is doing), when (they’re doing it), what (they’re doing), where (what department is doing it), and how (the process they use to accomplish it). Include descriptions of the bank’s policies, procedures, guidelines, governance, escalation protocols and organizational information wherever appropriate. It is better to include too much documentation than too little.9. Describe the Status of the Bank’s Efforts
It is essential to tell regulators the status of everything the bank is doing to respond to their concerns. To that end, be very clear in your response about what actions have been completed, what is still in process, what has not yet been addressed and when they will be addressed.
Include timelines showing when goals and milestones will be reached. Also, list any foreseeable problems that might arise to cause delays, and describe how those delays will be mitigated. This is another instance where thorough documentation of every person’s and department’s efforts will help you.10. Before the Letter Goes Out the Door, Check Your Work
Call this the quality assurance step. Seemingly minor mistakes or omissions can easily undermine all the hard work you’ve put into your response. Therefore, it must be reviewed as often and as thoroughly as a contract.
Check, and check again:
- The definition of all acronyms
- Pagination for the entire document, including the table of contents and any cross-references
In addition, have the final draft of your response reviewed by at least one person not involved in its creation. Frequently, a fresh set of eyes will catch things that everyone else missed.
Follow these steps regardless whether the issue raised is large or small. All responses must be crafted with care and deliberation to show that the bank is taking the requestor’s concerns seriously and is committed to addressing them purposefully. The best way to ensure all 10 of these recommendations are followed is to put one senior officer in charge of the entire response process. Remember: simple mistakes can lead to complex problems, and the time and effort you invest to prepare a thorough and accurate response will pay off in the future.This article first appeared in Law360 on August 30, 2017.