Fraud Protection
| By Swedberg, Jamie | |
| Proquest LLC |
Make sure your policy is well thought out and appropriately executed so your CU-and its regulators-can rest more easily.
Its not every day that a credit union CEO embezzles millions of dollars, caches weapons and ammunition, and goes on the lamalthough, as we've seen in the dramatic collapse of
But it is every day that some kind of fraud, either internal or external, happens to a financial institution somewhere. Fraud affects credit unions large and small, and represents both a financial risk and a reputation risk. If the fraud is large enough, it can scupper the institution's finances or cost it its charter.
That's why
"The fundamental issue for boards is the federal law called the Bank Secrecy Act, or BSA," says attorney
Keeney says if a credit union lacks a fraud policy, or if the policy seems hastily made, it's a red flag for examiners.
"They will probably expand their analysis and exam," he says. "If a board does not pay attention to BSA, they're probably not paying attention to other critical details within the credit union's governance, policies, and direction."
Recently,
"It's funny, the behavior of the examiners," he laughs. "If they come in and they feel like you've presented them with a good policy that has controls and has thought of things, they really seem to kind of back off and move on to the next thing. But if they come in and you have very little or no policy, or just a poorly written policy, then they seem to pull out all the stops and really dive deeper. If somebody were to take the time right now-if they can be a little bit proactive about it-they may be able to dodge the full depths of that."
But compliance and examinations aren't the only reasons to have a strong fraud policy. As
"It gives you an outline of things that the credit union feels are dishonest, things that you do not want to happen," she explains. "It sets the tone for management. You have the employee's signature on it. Our recommendation is that it be signed annually and that, by having them sign it annually, it reminds them of the situations that the credit union believes are dishonest acts. Hopefully that will keep them aware that these are things that definitely will not be tolerated."
Experts and Stakeholders
"Operations management are going to have the best handle on what's going to be required," Turner says. "The board has every right to say, 'Why do we need to do this?' and 'Why does it look this way?' It's management's job to explain why."
Turner says the IT manager should probably be involved, considering that a very large proportion of both internal and external frauds are electronic. And the credit union's lawyer or lawyers should be involved to make sure the procedures set in place are actually legal.
"The working committee is usually the subject matter experts," he says. "That would range across the board from compliance experts, security experts, the anti-money-laundering people. They would most likely be the ones to draft the policy. Your stakeholder committee is usually your senior people: your chief compliance officer, your general counsel, somebody from line management, usually. The stakeholders ultimately have to have a sense of ownership of the policy, because if they don't, then it's going to make implementation very difficult. So you have to include them in the process. And then ultimately, because you need the imprimatur of the most senior governing body for your policies, you'd want them to be approved by the board."
Turner believes there should be a dedicated security committee at every credit union, distinct from the supervisory committee and headed by the credit union's security officer, to manage security processes and create relevant policies.
"On that committee, too, if you do it right, you've got the president or a designate, the head of HR, head of operations, audit, legal," he says, and "one board member, a different one every year."
Once the board approves the policy, Keeney believes it should review it annually.
"Fraud is getting to be more and more sophisticated," he says. "The bad guys are figuring it out, and it's tough to keep up with them. The board needs to review their fraud policies annually to make sure that they're current, that they're actually not just on a shelf someplace, but that the credit union is really following them and implementing them. The adoption of the policy should be reflected in the minutes so that the NCUA examiner has some comfort [in that documentation]."
In addition to reviewing the policy annually, Sachse says the board should review it any time significant instances of fraud occur.
"Each incident needs to be reviewed and understood to see if there are new aspects that need to be added to the fraud policy," he says.
"Unfortunately, you can't think of everything. Something's going to come out next year that none of us have thought to include in that fraud policy, and that's probably got to be looked at."
In addition, he says, at least one board member should be poring over news items throughout the year, watching for new types of fraud behavior and bringing them to the attention of directors and managers.
"There needs to be somebody who's paying attention to the outside world," he says, "because there are new and creative ways to commit fraud on a regular basis. You just want to feel that your policy protects you."
The Letter of the Law
Fraud is abroad term, Turner points out. In general, it means using deception to gain an unfair advantage. But there's no way a credit union's fraud policy can address every possible type of fraud. What should be included, at minimum?
The law provides a starting point.
"Your policy has to be linked to the law, obviously," says Turner. "You can't enact a policy if it isn't based on some legal concept. So you'd want to start with which ones are governed by a SAR [a Suspicious Activity Report, mandated by the BSAJ. That would mean any embezzlement because SAR regulations read that you'll file one on an employee even if there is no loss-and any fraud involving manipulation of the credit union's IT system. If there is a compromise of data or the system itself, then you have to file a SAR." The fraud policy should lay out a course of action for various types of fraud. If it's addressed in a regulation, the credit union investigates and prosecutes. It should also set thresholds. For instance, SARs must be filed on losses of
But Keeney says there's no need for a policy to be limited to incidents that require a SAR.
"If the credit union has the capabilities, either through reading articles or through training, they'll be much more aware of the various frauds that are occurring and expand their policies," he says. "Credit unions will use a BSA policy as the foundation and then they will just expand the BSA policy to say, 'Our fraud policy is the following, including but not limited to...' and they start a check list."
Meacham would prefer to see credit unions draft two separate policies for clarity's sake.
"One of the most important aspects to any policy is that it be clear, unambiguous, and that it only deals with one thing at a time," he explains. "Internal fraud is a different beast when you're dealing with financial service organizations than external fraud-very different. So you should really have separate policies for internal fraud and external fraud."
It's uncommon for a credit union to actually have two separate fraud policies, he admits; but it's considered a best practice at many large corporations, so he suggests it for CUs as well.
Credit unions don't have to start from scratch when they create fraud policies. Turner recommends visiting bankersonline.com and checking out the security forums (of which he is a volunteer moderator).
"We've got a big credit union presence in there," he says. "Anyone can go in and post on the forums, 'Hey, I need a fraud policy, anybody got one?' And they'll get deluged with sample policies, and they're free. There's also a section there called Banker Tools that has about 300 different free sample policies, procedures, forms, and spreadsheets."
Another potential source is ffiec.gov, the website for the
Giving it Teeth
Having a policy is well and good, says Sachse, but perhaps even more important is the control aspect of the policy-the way the policy is enforced.
"I've heard [in some credit unions'] exams that the policies are fine, but if you don't have the controls in place, that's really what the NCUA seems to be hitting on this year," he says. "They want to see controls for all policies, but fraud is obviously one of the headliners."
By "controls," Sachse means the creation of monitoring systems and reporting mechanisms to prevent and keep track of breaches and suspicious activities. These can and should be expressly defined in the fraud policy.
"Whether reports are handed to the board itself, or whether the executive team is reviewing the reports and providing an executive summary really depends on the individual policy," he says. "Some of the behaviors and movements of data that may trigger a potential fraud report would probably be so numerous that you wouldn't want to hand that entire report to the board, but rather an executive summary. But in any event, these reports would go to the board. The satisfaction that the board is getting is, not only do they get to see the highlights of these, but it also shows that the appropriate people are watching over the credit union in the appropriate manner. So it's kind of validation of the controls on a monthly basis."
The board is responsible for making sure the credit union doesn't allow fraud to happen when it could easily have been foreseen and forestalled. Directors need to make sure they're seeing the kind of information that will enable them to meet their responsibilities.
At
Elevations CU's risk management department delivers copies of actual SARs that are filed, plus a summary of overall enterprise risk trends (interest rate risk management, credit risk management, corporate risk management) to the board as part of its monthly packet, notes CFO/Chief Risk Officer
"They are expected to monitor actual SAR reports to be able to see what the trends in that activity are, and to be in a position where they can ask questions if it appears adverse," Calcóte says.
Implementing controls-basically, "operationalizing" the principles laid out in the policy-is also the responsibility of the supervisory committee.
"I would like to see the supervisory committee do some discreet checks to make sure that the policy is being followed," says Keeney. "[I'd like] an internal auditor to pull some files, to do some mystery shopping, do some confirmation that there is compliance with the fraud policy, so that it's not just something that sits there; it's something that really is alive and well."
Most credit unions don't fall short when it comes to monitoring their fraud policy compliance because there's a lot of BSA-related staff training, he says. But it's critical to be sure, because fraud does happen. Tellers pocket cash. MSRs write fraudulent loans. Members kite checks. Caregivers for the elderly steal retirement funds. When it happens, the fraud policy is there to make sure the credit union knows exactly what to do.
Resources
Read about the role your supervisory committee could play in overseeing fraud risk at your CU in the sidebar on p. 40.
CUES Members Share offers several sample fraud policies. CUES members can access them by logging in at cues.org,choosing "Members Share" from the upper left and searching for "fraud." If you need help with your members-only password, please email [email protected].
Learn more about the enterprise risk management offering of CUES Supplier member and strategic provider
| Copyright: | (c) 2014 Credit Union Executives Society |
| Wordcount: | 2431 |


A Refreshing Option
Internal Watchdog…Plus
Advisor News
- Advisors await SEC decision on Vanguard fair fund distribution
- What to do when adult children become the client
- Judge rules insurers not liable for Newport Group’s AME Church pension lawsuit
- Why vacation homes are becoming a major blind spot for advisors
- The rise of the ‘gray divorce’ insurance client
More Advisor NewsAnnuity News
- Best’s Market Segment Report: Global Life/Annuity Reinsurers Remained Poised for Steady Growth
- When technology becomes easy to rent, what still separates life and annuity carriers?
- Legacy Marketing Group® and Malibu Life USA Announce Distribution Partnership for New Fixed Indexed Annuity Platform
- Empower Annuity Insurance Company of America Trademark Application for “EMPOWER WHAT’S NEXT” Filed: Empower Annuity Insurance Company of America
- Industry pushes back on linking ‘financial strength’ to annuity illustrations
More Annuity NewsHealth/Employee Benefits News
Life Insurance News
- AM Best Affirms Credit Ratings of Life Insurance Company Centras Life JSC
- AM Best Withdraws Credit Ratings of New Providence Life Insurance Company
- When technology becomes easy to rent, what still separates life and annuity carriers?
- St. Paul & Minnesota Foundation invests $15M to help revive downtown St. Paul
- Legacy Marketing Group® and Malibu Life USA Announce Distribution Partnership for New Fixed Indexed Annuity Platform
More Life Insurance News