Regulatory compliance for financial services

Regulatory requirements are growing more complex as expectations rise. Wipfli helps financial services organizations improve compliance, mitigate risk and support operational effectiveness.

How we help you

From new technologies to new generations of customers, financial services organizations are facing a variety of ways they can increase efficiency and grow. But as the industry changes, so do regulatory requirements and expectations.

Strengthen compliance audit and monitoring.

Mitigate fair lending risks.

Get comprehensive support for BSA/ AML.

Access compliance specialists and resources on demand.

Simplify your compliance

Resource-intensive processes and evolving regulatory priorities make compliance more challenging than ever. Let Wipfli’s regulatory risk and compliance team help with our risk-based solutions, real-world best practices and responsive support.

Explore our regulatory compliance services for the financial services industry

Insights and resources

  • Teamwork in Technology Laboratory.

    ARTICLE

    Is hiring a vCISO the most cost-effective way for financial institutions to mitigate cybersecurity risks?

    While financial institutions have long needed to guard against cybersecurity threats, today’s threat environment grows ever more complex. AI has created a wave of new dangers — not just in the hands of attackers, but also when used by your own team ­— while longstanding risks like phishing scams, ransomware attacks and third-party data breaches remain present. To protect themselves from this web of cybersecurity challenges, more financial institutions are turning to a fractional or virtual chief information security officer (vCISO) as a more cost-effective alternative to a full-time CISO. Could this make sense for your institution as well? Keep reading to learn more. Financial institutions must mitigate cybersecurity risks like phishing, third-party data breaches and AI Financial institutions must manage cybersecurity risks stemming from both external attackers and internal mistakes. Key risk areas include: Business email compromise: During this type of attack, often called a phishing scam, an attacker will attempt to gain unauthorized access to your systems via fraudulent email messages. Ransomware attack: Business email compromise can sometimes lead to a ransomware attack, during which a hacker is able to block you from accessing your core systems or critical data until you pay a ransom. Business continuity disaster recovery: As financial institutions increasingly transition onto cloud-based systems, many have not yet adapted their disaster recovery strategies to adjust to this change. AI risks: Some of the biggest AI-related risks are actually about how your own team uses it , like poor governance or shadow AI use that can lead to your private data being fed into public AI models, with unpredictable consequences. Also watch for SaaS vendors who add AI features into platforms you already use before your IT team can vet them for operational or security risks. Third-party data risks: A data breach at one of your software or IT vendors can expose any data you shared with that vendor — even if your own security remains fully intact. Financial institutions are more likely to suffer from this kind of data breach than experience a successful direct cyberattack. Managing these risks in a proactive, strategic way is beyond the purview of your regular IT team. That’s why some institutions hire a CISO. How does a vCISO help you defend your financial institution from cyberthreats? A vCISO is a C-suite-level fractional executive who leads your cybersecurity and cyber risk management efforts. Your vCISO’s primary responsibility is to mitigate your everyday and strategic risks in areas like data security, technology and AI, while also serving as a bridge between your IT team and your other executives. Look to a vCISO to: Bolster your cybersecurity: A vCISO takes the lead on cybersecurity inside your C-suite. vCISO responsibilities include assessing your current defenses, finding gaps and implementing an up-to-date cybersecurity strategy. Lead AI governance and security efforts: Your vCISO will also take charge of your AI governance and security policies. Good AI governance can help ward off shadow AI risks , reducing the chance that team members unthinkingly share your business or customer data with unauthorized or public AI systems. Manage third-party data security risks: A skilled vCISO will also know how to map out your third-party data risks and assess whether your vendors are taking sufficient steps to secure the data you share with them. Bridge the gap between C-suite and IT: A vCISO serves as a crucial conduit between your executive offices and your frontline IT team, able to speak the language of both groups and advocate for the latter before the former. Now, if a vCISO is such an asset, shouldn’t you just hire a full-time CISO instead? Not always. Why should your financial institution hire a vCISO rather than a full-time CISO? If your financial institution wants stronger cybersecurity but doesn’t have the need (or budget) for a full-time CISO, a vCISO or fractional CISO can deliver the same level of insight, experience and strategic capability for a fraction of the cost. Onboarding a vCISO can also give you a broader perspective on how the financial services industry as a whole is tackling cybersecurity. Key benefits to hiring a vCISO include: Cost-effective security leadership Unless you actually need 40+ hours a week of strategic cybersecurity leadership — and most financial institutions don’t — it may not make sense to pay a mid-six-figure salary plus benefits to a full-time CISO. A vCISO typically costs dramatically less than a full-time hire, while providing the level of support your business requires. Scalable support You can hire a vCISO for two hours a week, or 20. If you’re growing your business, your vCISO support can grow along with it, and you can also choose to engage a vCISO on a per-project or time-limited basis. A vCISO can also go back and forth between providing strategic leadership and taking charge of implementing or executing on individual projects. Regulatory goodwill Financial regulators no longer want to see one IT director managing both your IT and cybersecurity. Hiring a vCISO eliminates this problem and also keeps most cybersecurity matters off your CFO’s or COO’s plate. (Some forward-thinking institutions are doubling down on this approach by hiring a full-time CIO to implement their overall technology strategy and working with a vCISO to manage cybersecurity.) Broad industry awareness An experienced vCISO will typically have worked with dozens of financial institutions. You’ll gain access to that big-picture awareness — which can’t be matched by someone who has worked only as an in-house CISO — to better understand how the financial services industry as a whole is solving cybersecurity challenges. Coaching and leadership development If you have promising in-house IT staff who want more responsibility but lack the strategic skills to take on a CISO role themselves, a vCISO can help prepare them to move up. This allows you to shore up your cybersecurity now while also creating a path forward for your top talent. What is the process for hiring a vCISO? Hiring a vCISO should be a relatively straightforward process. There are three major steps: 1. Find a cybersecurity and risk management advisory firm. 2. Assess your specific needs and develop a cybersecurity roadmap. 3. Onboard a vCISO (typically provided by the advisory firm) to oversee implementing your roadmap. As you consider which cybersecurity advisory firm to hire, make sure that you’ll only be paying for the level of vCISO service that you actually need. Don’t get locked into 15 hours a week of vCISO support if you only need five. Read more Minus a data strategy, financial institutions will fail at AI Financial institutions must be more proactive about general ledger certification Can traditional banking avoid losing Gen Z to fintech?

  • Image of business people discussing financial plans.

    ARTICLE

    Avoiding adjustable-rate mortgage loan compliance challenges

    Adjustable-rate mortgage (ARM) loans can present compliance challenges throughout the entire loan life cycle. From application disclosures to rate adjustment notices, even minor errors can result in regulatory violations, customer confusion and operational risk. Keep reading to learn about several common ARM compliance errors and for guidance on avoiding them. Timing of early disclosures A common mistake is the timing of early ARM disclosures, including the Consumer Handbook on Adjustable-Rate Mortgages or a suitable substitute and a loan program disclosure for each variable-rate program in which the consumer expresses an interest. These do not always allow you three business days from the application date to provide the disclosures, like other early disclosures. Regulation Z states that these disclosures must be provided at the time an application form is provided or before the consumer pays a non-refundable fee, whichever is earlier (except that the disclosures may be delivered or placed in the mail not later than three business days following receipt of a consumer’s application when the application reaches the creditor by telephone, or through an intermediary agent or broker). Based on that requirement, an in-person application request requires the disclosures to be provided on the date of application and cannot be mailed later. Common mistakes with loan program disclosures Other common issues include incorrect information in the ARM loan program disclosure. If the initial interest rate is a discounted or premium rate (not based on the index and margin in effect), this fact must be disclosed in the early disclosure, but it is often missing. If using the optional 15-year historical example, make sure the disclosure identifies the month and day being used for each year in the table, verify the indexes disclosed are correct, and the margin used was one in effect within the prior six months. Often, the table is not updated properly or quickly enough. When disclosing the initial interest rate and payment example for a $10,000 loan, make sure a current rate is being used. Also, when updating the index and margin, make sure the example payment reflects the newly disclosed rate. Avoiding violations with ARM rate changes ARM rate changes and notification requirements probably cause the most errors. Using the wrong index is a common mistake. For example, an index that specifies a weekly average may be inaccurately disclosed with the daily version of the index. The weekly average is calculated on Friday and is generally published the following Monday, but the daily index is often used instead of the weekly average, resulting in errors and incorrect interest rates being assigned to borrowers. Make sure the index is pulled from the correct source and matches what was disclosed in the promissory note. Another common issue involves periodic caps. Institutions should verify that the caps disclosed in the promissory note match those being used to calculate rate adjustments. It is common to have different caps for the first-rate change than for subsequent rate changes. The system might be set up for those initial caps, but not updated for the caps that will follow for any subsequent rate changes. Errors in rate change notices are common Rate change notices present additional challenges. An example of an error is failing to provide sufficient detail when describing the index used to determine the new rate. Some systems limit the number of characters, so it takes a bit of creativity to fit the required details, especially when trying to spell out the “X”-year weekly average constant maturity U.S. treasury securities index, which is quite lengthy. The weekly average part is often omitted when truncating, but it is an important distinction in the index used and should be included. Also, the estimated balance and projected new payment must be based on the projected balance and number of remaining payments due at the time the rate will be changed. But some notices include the current balance at the time the notice is generated rather than a projected balance, which also results in the new payment being inaccurately calculated on the notice. In addition, the requirement to disclose rate limits and foregone interest rate increases can be confusing, as the disclosures required by § 1026.20(c)(2)(iv) regarding foregone interest rate increases apply only to transactions permitting interest rate carryover. Usually, a promissory note does not include such a provision, yet the foregone interest disclosure is being included anyway. Even though the interest rate was not increased fully due to a limit or cap percentage, there is no foregone interest when the note does not allow for such carryover of interest. Another issue is the required timing of the ARM adjustment notices. An initial notice must be sent at least 210 days, but no more than 240 days, before the new payment at the adjusted rate is due. The subsequent notices must be sent at least 60 days, but no more than 120 days, before the new payment at the adjusted rate is due. Occasionally, the credit agreement for an ARM originated AFTER January 1, 2015 (the date Regulation Z ARM notice requirements were effective) does not have an adequate lookback period for selecting the index prior to the change date (at least 45 days), resulting in issues with meeting the timing requirements for the ARM adjustment notices. For example, if the credit agreement does not contain a lookback period and requires the index to be selected on the change date, it is not possible to send an ARM adjustment notice at least 60 days before the new payment at the new rate is due, because the index will not yet have been published. Remaining compliant While ARM loans present numerous compliance challenges, many of the most common errors can be prevented through strong procedures, staff training and periodic quality-control reviews. Regular validation of disclosures, rate calculations and notice content can help institutions remain compliant while providing accurate information to borrowers. Read more FDICIA requirements: How banks approaching $1 billion should prepare for FDICIA compliance Tips for mastering accurate CECL regulatory reporting 6 steps to strengthen your financial institution’s call report preparation process

  • Financial services professionals reviewing business data and collaborating during a corporate meeting in a modern office.

    ARTICLE

    Regulation E error resolution misconceptions and common errors

    Although the Electronic Fund Transfer Act and its implementing Regulation E were enacted in 1978 and have been amended only a handful of times over the past 48 years, compliance with the Act’s error resolution requirements continues to present challenges. Auditors and examiners still frequently identify violations related to these requirements. Confusion over the 60-day period One of the more common violations seen lately has been the practice of denying an error claim because it was submitted more than 60 days after the periodic statement was issued containing the transaction with the error. This violation appears to be the result of a passage in Regulation E, Section 1005.11, which states: “A financial institution shall comply with the requirements of this section with respect to any oral or written notice of error from the consumer that is received by the institution no later than 60 days after the institution sends the periodic statement or provides the passbook documentation required by section 1005.9 on which the alleged error is first reflected.” This sentence has caused a lot of confusion over the years. Many reading this sentence stop there, interpreting it to mean they do not need to investigate an error claim if it’s received more than 60 days after the date of the periodic statement with the error (late notice). Sending a letter denying an error claim because the consumer submitted the error claim late would violate liability requirements within section 1005.6 of Regulation E. The key words to focus on in the bolded paragraph above are “the requirements of this section ”. While you do not have to follow the provisions of section 1005.11 for a late error claim, which includes requirements for providing provisional credit, timing and communication requirements, you do have to follow the requirements of section 1005.6 of Regulation E, which limits the liability of consumers for unauthorized transactions. The commentary to section 1005.11 states that an institution: “… is not required to comply with the requirements of this section for any notice of error from the consumer that is received by the institution later than 60 days from the date on which the periodic statement first reflecting the error is sent. Where the consumer’s assertion of error involves an unauthorized EFT; however, the institution must comply with section 1005.6 before it may impose any liability on the consumer.” Section 1005.6 covers the liability of the consumer for unauthorized EFT transactions and explains that while consumers may be liable for transactions occurring more than 60 days after the first periodic statement containing the error, consumers have limited liability for errors that occurred within the first 60 days. Monetary liability limitations For electronic funds transfer errors related to an access device, liability is limited to the lesser of $50 or the amount of the transaction for losses reported to the financial institution within two business days of the consumer learning their access device was lost or stolen. It’s $500 when reported after the first two business days but prior to the 61 st day after the periodic statement containing the first error was sent. The consumer is liable for errors that occur beyond the 60-day period if the financial institution can show the errors would not have happened had the financial institution been notified. For electronic funds transfer errors that are not related to an access device, the above two tiers of liability ($50 second business day/$500 after the second business day) do not apply. The consumer has no liability for errors occurring during the first 60 days following the receipt of the periodic statement with the error. While this violation occurs frequently, root causes can vary. Written procedures may contain directions to deny claims received beyond 60 days from the statement date, or in some cases, it’s a misunderstanding of the regulation, resulting from ineffective training. Other common Regulation E violations Other common violations related to the Regulation E error resolution requirements include the following: Misunderstanding who is liable when a consumer is a victim of fraud. When a consumer is fraudulently induced into a transaction, the consumer is generally liable because they conducted the transaction themselves. Conversely, if a consumer is tricked into giving away information that allows the fraudster to access their account and conduct the transaction, the consumer is not liable. This is because the definition of an unauthorized electronic funds transfer states that it’s a transaction initiated by someone other than the consumer, without their authority and from which the consumer receives no benefit. Exceptions to this include consumers who initiate ATM transactions by force during a robbery. Requiring the consumer to provide the error claim in writing before investigating an error claim. Regulation E allows a financial institution to forego providing provisional credit if the consumer has not provided the error claim in writing. But it still requires the remaining provisions in section 1005.11 related to error resolution to be followed, including promptly investigating upon receipt of oral or written notice of an error claim. Many financial institutions confuse the requirements of other rules, such as ACH requirements, as being applied to Regulation E. Even if other rules require an affidavit or other written notice of error, Regulation E does not; therefore, error resolution requirements would still apply. Failing to promptly investigate an error claim or to provide the results to the consumer in a timely manner. Some financial institutions hold an error claim open for the full 45 days (90 days for point-of-sale) allowed by Regulation E. This would be a violation of Regulation E, which requires the investigation to begin promptly, make corrections within one business day and notification to consumers of the outcome of the investigation within 3 business days of concluding the investigation. Requiring the consumer to contact the merchant prior to conducting an investigation. Similar to the above, Regulation E requires the financial institution to promptly investigate an error claim and may not delay initiating or completing an investigation pending receipt of information from the consumer. While other rules, such as those from Mastercard or Visa, may require the consumer to first contact the merchant, Regulation E does not. Failing to consider an error related to a non-bank P2P transaction. If the transaction occurs through an account held by your financial institution belonging to a consumer, Regulation E error resolution requirements exist for the financial institution that holds the account; therefore, error resolution requirements under Regulation E are applicable. Read more: Stablecoin compliance: What you need to know about the GENIUS Act and PPSIs Could an outsourced CIO help your financial institution boost growth and manage cybersecurity risks? Financial services complaint management: How to handle compliance for customer or client complaints

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

From fair lending and BSA/AML compliance to compliance audits and monitoring, our professionals are ready to help.