The Compliance 911 Show
Dean Stockford - Len Suzio
0
The Compliance 911 Show is a bi-weekly podcast for bank and credit union compliance professionals. It covers regulatory topics like CRA, HMDA, Fair Lending, and Anti Money Laundering in quick 5-10 minute episodes. The show aims to provide concise, no-nonsense information to help busy professionals stay updated. Hosted by Dean Stockford and Len Suzio, it is associated with M&M Consulting and GeoDataVision.
Episódios
-
Community Development Benchmarks 15.07.2026 12minIn this episode of Compliance 911, Dean Stockford and Len Suzio discuss the OCC’s proposed Community Development benchmarks for CRA performance, focusing on why community development has historically been difficult for banks to measure and plan. Len explains how the proposed benchmarks are organized by activity type—CD lending, qualified investments, services, and combined lending/investment activity—as well as by performance rating, bank size, and annual measures such as Tier 1 capital, assets, and volunteer service hours. The episode highlights how these benchmarks may give community banks a clearer framework for setting CRA goals and evaluating satisfactory or outstanding community development performance. Listeners can also download GeoDataVision’s special PDF recap containing all 67 proposed Community Development lending, investing, and service benchmarks from the GeoDataVision website.https://geodatavision.com/content/occ-proposed-elective-goals-for-cra-strategic-planning/ Brought to you by GeoDataVision and M&M Consulting -
Unpacking FDIC Consumer Compliance 2026 Supervisory Highlights 25.06.2026 13minIn this episode of Compliance 911, Len Suzio and Dean Stockford unpack the FDIC’s 2026 Consumer Compliance Supervisory Highlights, noting that while 98% of FDIC-supervised institutions earned satisfactory or better ratings, weaknesses in compliance management systems continue to create risk. The discussion focuses on the most common violation areas, including Truth in Lending, Electronic Fund Transfers, Flood, Truth in Savings, HMDA, and third-party oversight, emphasizing that disclosure accuracy, timely error resolution, operational discipline, and vendor management remain critical priorities for banks. Brought to you by GeoDataVision and M&M Consulting -
CRA: The Importance of Assessment Areas 17.06.2026 11minThe episode “CRA: The Importance of Assessment Areas” explains why a bank’s CRA assessment area is one of the most important decisions it makes, because it directly affects both performance results and the benchmarks examiners use during CRA reviews. Len explains that while CRA rules require banks to include whole census tracts, deposit-taking facility areas, surrounding lending areas, and avoid excluding low- or moderate-income tracts, banks still have flexibility to define the area they can reasonably be expected to serve. The discussion emphasizes that overly large assessment areas can set banks up for poor CRA performance, even when the area is technically compliant, because the bank may be compared against markets it cannot realistically serve. Len gives an example of a one-branch bank in Los Angeles County that improved its CRA position by narrowing its assessment area to nearby census tracts where it actually lent and served customers. The episode concludes that banks should regularly review their CRA assessment areas, especially after branch changes or acquisitions, using mapping tools and performance data to ensure their areas are compliant, realistic, and aligned with their actual community lending activity. Brought to you by GeoDataVision and M&M Consulting -
AI Integration Into Compliance 10.06.2026 13minThe episode “AI Integration Into Compliance” explains how artificial intelligence is already becoming a practical tool for bank compliance teams as regulatory expectations rise, data volumes grow, and manual compliance processes become harder to sustain. Dean highlights three major areas where AI is creating value: transaction monitoring and AML, where machine learning can reduce false positives and detect suspicious activity more effectively; regulatory change management, where AI can scan updates and map them to internal policies and controls; and risk assessments/reporting, where AI can aggregate data to give management and boards clearer insights. However, the episode emphasizes that AI is not a plug-and-play replacement for compliance professionals. Banks must maintain strong governance, transparency, explainability, data controls, model validation, documentation, human oversight, and clear escalation paths. The key message is that AI should support compliance judgment—not replace it—and institutions should start with low-risk, high-pain use cases, clean and govern their data, collaborate across departments, and be ready to explain their AI tools to regulators. Brought to you by GeoDataVision and M&M Consulting -
CRA: Other Ways in which banks help meet the needs of the community 27.05.2026 11minThis podcast explains that banks can strengthen their CRA exam performance by presenting additional lending activity that examiners may not otherwise consider, beyond the usual focus on small business, small farm, and community development loans. Len Suzio highlights several examples, including technically disqualified small business loans such as asset-based lines of credit, standby letters of credit for contractors, multifamily and small rental property financing reflected in HMDA data, affordable housing units supported by those loans, auto loans that help low-income borrowers access employment, and small business expansion loans that create jobs. The key point is that these activities can help paint a fuller, more favorable picture of how a bank is meeting community credit needs, but to receive consideration, banks must properly geocode the loans, collect relevant data, and ensure the information is reliable.Brought to you by GeoDataVision and M&M Consulting -
Cyber Phishing 14.05.2026 12minCyber phishing remains one of the most significant and rapidly growing cybersecurity threats, accounting for the vast majority of successful cyberattacks and impacting both individuals and organizations on a daily basis. As highlighted by Dean Stockford and Len Suzio, phishing schemes exploit human trust—rather than technical vulnerabilities—through increasingly sophisticated tactics, many now powered by generative AI, which has driven a dramatic surge in highly convincing and personalized attacks. Real-world incidents, including major corporate breaches and multimillion-dollar fraud cases, demonstrate the severe financial and operational consequences. Given this evolving threat landscape, organizations must prioritize continuous employee training, strengthen email authentication and filtering systems, adopt AI-driven detection tools, and implement multi-factor authentication, all while tailoring their defenses to their specific risk profiles to effectively mitigate phishing risks. Brought to you by GeoDataVision and M&M Consulting -
CFPB NPR Section 1071 Compliance Dates 04.05.2026 11minIn this episode, Len Suzio and Dean Stockford discuss the CFPB’s November 2025 proposed rulemaking on Section 1071 and explain how it could dramatically scale back the current small business lending data-collection requirements. Len highlights the biggest proposed changes, including moving to a single compliance date of January 1, 2028, sharply reducing the number of required data points, raising the reporting threshold from 100 to 1,000 small business loans in each of the prior two years, narrowing the definition of a small business from $5 million to $1 million in gross annual revenue, and excluding certain products like merchant cash advances, agricultural loans, and transactions of $1,000 or less. He argues that the most significant impact would come not from fewer data fields, but from the much smaller pool of covered lenders and loans, while also warning that the revised definition could create confusion with CRA reporting standards and increase the risk of errors.Brought to you by GeoDataVision and M&M Consulting -
Compliance Risk Management in 2026 10.04.2026 11minIn this episode, Dean Stockford and Len Suzio discuss what compliance risk management should look like in 2026 as financial institutions face rising fraud, cyber threats, AI-related risks, third-party exposure, and an uncertain regulatory environment. Dean argues that compliance functions can no longer remain purely advisory and instead must evolve into active risk management and oversight roles, with stronger risk assessments, enhanced monitoring, root-cause analysis, more targeted training, better frontline tools, and closer alignment between risks, controls, and institutional risk appetite. He emphasizes that a strong compliance culture begins with understanding the organization’s structure, risk tolerance, and operational realities, then building a more robust compliance management system around those insights. The episode closes with Dean’s view of the biggest compliance risk areas in 2026, including data privacy and cybersecurity, AML/CTF, digital banking, AI compliance, third-party risk, regulatory fragmentation, and the growing cost of top-tier compliance talent.Brought to you by GeoDataVision and M&M Consulting -
Important CRA Lesson from OCC proposal for all Intermediate-Small and Large Banks 25.03.2026 11minLen explains that the OCC issued a December 18, 2025 proposal to create a “Simplified Plan Process for Community Banks” to make the CRA strategic plan option easier, but he believes its real value extends beyond banks using strategic plans because it reveals how regulators think about “Satisfactory” and “Outstanding” performance under normal CRA standards. The proposal distinguishes between “custom” bank-specific goals (which Len says offers little practical guidance) and “elective” goals, which are quantifiable targets drawn from approved plans and OCC supervisory experience. Len highlights that the most useful—and historically murky— CRA test is Community Development. The OCC's proposal provides explicit benchmarks for CD lending, investing, combined lending/investing, and CD services, using ratios tied to Tier 1 capital or total assets (including notably lower investment thresholds when a bank relies heavily on donations, acknowledging their significance). He notes the proposal also introduces measurable expectations for CD service hours per employee, while offering little new insight on traditional lending tests. Although the OCC states elective goals are not “safe harbors” and not formal benchmarks outside the simplified process, Len argues they align with what regulators historically expect and can help CRA officers set internal performance targets; this is where you would provide a link to the 67 tests, performance standards and ratings. https://geodatavision.com/content/occ-proposed-elective-goals-for-cra-strategic-planning/Brought to you by GeoDataVision and M&M Consulting -
Cyber Fraud Risk 12.03.2026 7minThis podcast episode discusses the alarming rise of cyber fraud in financial institutions, highlighting that global losses exceeded $1 trillion in 2025 and AI-powered attacks increased by 93%, including deepfake videos, voice cloning, and sophisticated phishing campaigns. The hosts explain that financial institutions are investing heavily in fraud prevention technologies such as AI fraud detection, predictive analytics, Open APIs with Agentic AI, and solutions like Glassbox that analyze user sessions for anomalies. They emphasize that combating this crisis requires a collaborative approach between financial institutions, tech companies, law enforcement, regulators, and third-party providers—noting that no single entity can win this fight alone and that information sharing, best practices, and enhanced training are essential for protecting customers while maintaining a positive user experience.Brought to you by GeoDataVision and M&M Consulting -
Disparate Impact 05.03.2026 13minLen Suzio explains that although President Trump’s Executive Order 14281 aims to limit disparate impact liability, the legal status of disparate impact remains unsettled. The Supreme Court upheld disparate impact under the Fair Housing Act in Inclusive Communities but imposed strict limits requiring a clear causal link between a specific practice and disparities—limits often downplayed by regulators in recent enforcement actions. Despite legal uncertainty and shifting enforcement priorities between administrations, Len advises compliance professionals to continue using disparate impact statistical analysis as a risk-management tool. Regardless of its legal future, it remains a practical way to identify potential discrimination, prompt further review, and demonstrate good-faith compliance.Brought to you by GeoDataVision and M&M Consulting -
2025 Recap 27.01.2026 14minThis episode provides a high-level recap of the major regulatory compliance themes covered in 2025. Dean highlights intense regulatory volatility, especially around CRA and Section 1071, including rule freezes, proposed repeals, litigation, delayed compliance dates, and the CFPB’s move toward an interim final rule for small-business lending data collection. The discussion also revisits key fair lending, redlining, and data-analysis topics, along with rising operational risks such as BSA/AML/KYC modernization, third-party risk management, and expanding concerns around AI, data governance, cybersecurity, and privacy. Consumer protection issues featured prominently, particularly Regulation E error-resolution failures, elder financial exploitation, and recurring flood compliance violations. The takeaway for compliance and risk officers: conduct a CMS health check, document lessons learned from 2025, and proactively brief senior management and the board with a clear 2026 risk and compliance plan focused on these evolving priorities.Brought to you by GeoDataVision and M&M Consulting -
Electronic Funds Transfers Issues 18.12.2025 13minThis episode focuses on common compliance problems under Regulation E, which governs electronic fund transfers and is designed to protect consumers using electronic channels such as ATMs, debit cards, online banking, and phone-initiated transfers. As electronic usage and fraud increase, regulators are finding frequent violations—especially around how financial institutions handle error resolution and consumer liability. A key issue is the improper application of liability limits when consumers report unauthorized transactions, particularly misunderstanding the 60-day rule tied to periodic statements, which can expose consumers to unlimited liability for later transactions if they delay reporting. Another major concern is failures in the provisional credit process—institutions often delay investigations beyond allowed timeframes without issuing timely provisional credit (including interest), despite clear requirements to begin investigations promptly and credit the consumer if more time is needed. The takeaway is that financial institutions must have clear, accurate procedures and well-trained staff to ensure timely investigations, proper liability determinations, and full compliance with Regulation E’s consumer protections. Brought to you by GeoDataVision and M&M Consulting -
The New Section 1071 01.12.2025 13minThis podcast highlights sweeping changes proposed for Section 1071 Rule that would dramatically shrink the volume of reportable small business lending and the number of institutions required to report in comparison to the lenders reporting under the CRA Rule. The most significant shift is redefining a “small business” from $5 million to $1 million in gross annual revenue, a change that would eliminate nearly half of currently reported (compared to CRA reporters) small business loans, which is magnified even further when combined with the proposal to exclude renewals (unless the loan amount increases). The Section 1071 Rule's reporting threshold for "covered" lenders would jump from 100 to 1,000 small business originations in each of the prior two calendar years. Under the current CRA Rule about 700 lenders are required to report. In comparison, under the proposed Section 1071 Rule only about 80 of those lenders have enough loan volume to be required to report under that Rule. In fact, among those potential Section 1071 lenders, the top10 would generate more than 91% of the reported small business lending activity under Section 1071. The Section 1071 proposal would also drop agricultural loans from being reported and eliminate dozens of discretionary data points, greatly reducing transparency and regulatory insight. With such far-reaching implications, the presenters urge stakeholders to actively comment before the December 15, 2025 deadline rather than remain passive.Brought to you by GeoDataVision and M&M Consulting -
Statistical Significance 12.11.2025 19minThis podcast explains how statistical significance is used in redlining allegations based on disparate impact, despite potential deemphasis under the Trump Administration, as regulators may shift accusations from disparate impact to disparate treatment while still relying on statistical analysis. The hosts clarify that statistical significance measures the probability that a bank's below-average performance in majority-minority census tracts occurred by chance rather than discriminatory practices, using a 5% significance threshold, and that larger banks with more loan volume must perform closer to market averages to avoid being flagged (ranging from 5% for 100 applications to 9.5% for 10,000 applications when the market average is 10%). However, the analysis emphasizes that statistically significant results can be misleading due to "lurking" or "confounding" variables, particularly when regulators use unrealistic market definitions (UREMAs) that include areas where banks lack branches or competitive presence, or when peer comparisons inappropriately mix different institution types like banks and mortgage companies—situations that have resulted in the majority of actual peer banks failing the statistical test, demonstrating the data was fundamentally skewed and making the statistical significance analysis unreliable. Brought to you by GeoDataVision and M&M Consulting -
Flood remains compliance challenge 20.10.2025 17minThis podcast discusses the persistent compliance challenges financial institutions face with flood insurance requirements. The hosts explain that while the statutory requirements seem straightforward—including determining if property is in a Special Flood Hazard Area (SFHA), providing proper notices, requiring adequate coverage, escrowing premiums, and force-placing insurance when necessary—many institutions struggle due to the lack of specific written regulations and varying interpretations from regulators. Key compliance issues include problems with contents coverage (especially when security documents contain blanket provisions securing all contents), timing delays in ordering determinations and notifications, failure to provide proper return receipt proof of notices, inadequate coverage calculations, insufficient ongoing monitoring, untimely force-placement, and improper vetting of private insurance policies. These violations can result in significant civil money penalties, making it essential for financial institutions to take flood insurance provisions seriously and ensure consistent compliance across all aspects of the program.Brought to you by GeoDataVision and M&M Consulting -
Disparate Impact Derailed? What EO 14-281 Means for Fair Lending 26.09.2025 16minHosts Dean Stockford and Len Suzio welcome back attorney Lori Sommerfield, a partner at Troutman Pepper Locke LLP, to continue their two-part discussion of Executive Order 14-281 and its effort to curb disparate impact theory in fair lending enforcement. The episode covers the legal landscape post-EO, including the Supreme Court’s history, lingering federal versus state authority, private litigation risks, and practical steps lenders should take—retain strong fair lending programs, document business justifications, test for less discriminatory alternatives, and prepare for future reversals. Listeners get clear, practical guidance for compliance teams navigating uncertainty as enforcement shifts between federal agencies, state regulators, and private plaintiffs. Brought to you by GeoDataVision and M&M Consulting -
Executive Order 14281: The End of Fair Lending Law Enforcement Through Use of the Disparate Impact Legal Theory? 04.09.2025 22minHosts Dean Stockford and Len Suzio welcome Lori Sommerfield, a partner at Troutman Pepper Locke LLP, to discuss and explain President Trump’s Executive Order 14281 (April 23, 2025), which directs federal agencies to limit use of the disparate impact theory in fair lending enforcement and to review existing guidance, pending matters, and consent orders that leverage that theory. The federal banking agencies are removing disparate impact references in their examination manuals and shifting toward intentional discrimination theories, while use of the disparate impact theory by state authorities and private litigants remain risks. Banks and financial services companies should continue to review policies and procedures for potential disparate impact, conduct rigorous fair lending monitoring and testing, and prepare for potential future shifts in enforcement. Brought to you by GeoDataVision and M&M Consulting -
Wild Times for the Community Reinvestment Act 31.07.2025 1h 23minJoin top CRA experts Doctor Ken Thomas, Len Suzio and Dean Stockford for a wide ranging discussion on the Community Reinvestment Act. The NPR for repeal of the 2023 Rule What to be learned from the 2023 Rule Do the examiners in the field reflect "deregulation"? Simple ideas to improve the CRA regulations and make them more effective for banks What banks should do ASAP - and more Brought to you by GeoDataVision and M&M Consulting -
Top challenges with Compliance Management 16.07.2025 22minIn this episode, Dean and Len focus on the top compliance management challenges financial institutions face in 2025, particularly in data privacy, cybersecurity, AI systems, and anti-money laundering/counter-terrorism financing (AML/CTF). They highlight how cyber threats—amplified by advances in AI—require robust encryption, advanced threat detection, and strict consent management. While AI and automation can streamline compliance, risk management, and customer service, they warn of the dangers of data bias and privacy concerns, stressing the need for strong governance and data quality controls. For AML/CTF, ongoing employee training, enhanced due diligence, and AI-driven transaction monitoring are crucial. The hosts recommend banks adopt clear, transparent, and unbiased AI policies with rigorous security, governance, and regulatory compliance frameworks to address these evolving risks and maintain customer trust. Brought to you by GeoDataVision and M&M Consulting
Popular em
Este podcast também aparece nas paradas de podcasts destes países.