In legal review — not indexed
This page is drafted and readable, and is excluded from search until an attorney has cleared it. Anything still to be checked is marked inline.
How banks audit their collection law firms
A bank remains accountable for the conduct of the law firms collecting its charged-off accounts. Federal guidance on third-party risk management expects oversight proportionate to that risk — which for consumer debt litigation means examining conduct, documentation and complaint handling, not only receiving an annual attestation.
Key facts
- Accountability for a law firm's conduct does not transfer to the firm with the placement.
- Sampling reviews a fraction of accounts, months after the conduct occurred.
- A self-reported attestation is evidence of a claim, not evidence of a control.
- Continuous visibility means the same record the firm works from, not a report generated for the review.
What do regulators expect of a bank supervising a collection law firm?
Interagency guidance on third-party relationships frames the expectation as risk-proportionate, and it is worth quoting rather than paraphrasing. The Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (June 9, 2023), issued jointly by the Federal Reserve, the FDIC and the OCC, states that "the guidance does not suggest that all relationships require the same level or type of oversight or risk management, since different relationships present varying levels of risk", and provides that banking organizations "engage in more comprehensive and rigorous oversight and management of third-party relationships that support higher-risk activities, including critical activities". Among the characteristics of a critical activity it lists one that could "[c]ause a banking organization to face significant risk if the third party fails to meet expectations" or "[h]ave significant customer impacts". Consumer debt litigation sits high on that scale — the firm contacts the bank's former customers, files suit in the bank's name, and furnishes to credit bureaus. Oversight sized for a stationery vendor does not meet it. Two limits on that paragraph, both taken from the documents themselves rather than added by us. The first is legal effect: this is supervisory guidance addressed to banking organizations, and its footnote 2 states that "Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations" — it reaches a law firm through the bank's contract rather than directly, and the guidance never uses the words "law firm". The second is that the classification is the bank's own to make: "It is up to each banking organization to identify its critical activities and third-party relationships that support these critical activities." What does not depend on the guidance at all is where responsibility lands. CFPB Compliance Bulletin and Policy Guidance 2016-02, Service Providers, states that "the mere fact that a supervised bank or nonbank enters into a business relationship with a service provider does not absolve the supervised bank or nonbank of responsibility for complying with Federal consumer financial law to avoid consumer harm".
What should an oversight review actually examine?
Conduct, documentation, and complaints — in that order. Conduct means contact records against the applicable frequency and time-of-day rules. Documentation means whether the evidence supporting a filed suit existed before it was filed. Complaints means whether disputes stopped collection when they arrived, and how fast. Each of those is answerable from records the firm already holds; the difficulty is assembling them across systems that were never joined.
Where does manual oversight fail?
Three places, and they compound. Sampling: a review of fifty accounts from a portfolio of fifty thousand tells you about fifty accounts. Lag: an annual or quarterly cycle finds conduct months after it happened, when the remedy is remediation rather than prevention. Self-reporting: the firm assembles the evidence of its own compliance, so the review tests the firm's assembly process as much as its conduct.
What does continuous visibility look like instead?
The oversight team reads the same record the firm works from, as it is written, rather than a package assembled for the review. That changes what a finding means: a rule that blocks an action leaves a record of the block, so the absence of a violation is evidenced rather than asserted. TODO: attorney review of how this is framed — it must not read as a compliance guarantee.
Run the review on yourself first
The same review, as a 28-item self-assessment a firm can work through before a client does: the law firm audit readiness checklist. It prints, it needs no sign-up, and nothing you tick is sent anywhere.
Primary sources
-
Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920
Final guidance, June 9, 2023 — risk-proportionate oversight
the guidance does not suggest that all relationships require the same level or type of oversight or risk management, since different relationships present varying levels of risk
-
Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920, footnote 2
Statement of legal effect — the guidance is not a rule and imposes no new requirement
Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations.
-
Who decides whether a collections firm is a critical activity
It is up to each banking organization to identify its critical activities and third-party relationships that support these critical activities. Notably, an activity that is critical for one banking organization may not be critical for another.
-
Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (ongoing monitoring)
What ongoing monitoring is for, and that a bank may test the third party's own controls
In certain circumstances, based on risk, a banking organization may also perform direct testing of the third party's own controls.
-
CFPB Compliance Bulletin and Policy Guidance; 2016-02, Service Providers, 81 FR 74410
October 26, 2016 — responsibility does not transfer with the placement
the mere fact that a supervised bank or nonbank enters into a business relationship with a service provider does not absolve the supervised bank or nonbank of responsibility for complying with Federal consumer financial law to avoid consumer harm
-
CFPB Compliance Bulletin and Policy Guidance 2016-02, Service Providers (Bureau PDF)
Due diligence is not a shield, and the bulletin is a non-binding statement of policy
This Compliance Bulletin and Policy Guidance is a non-binding general statement of policy articulating considerations relevant to the Bureau's exercise of its supervisory and enforcement authority.
-
April 25, 2016 — the documentation an oversight review asks about. Binds those respondents only.
Original Account-Level Documentation reflecting, at a minimum, the Consumer's name, the last four digits of the account number associated with the Debt at the time of Charge-off ..., the claimed amount, excluding any post Charge-off payments
-
CFPB Examination Procedures — Debt Collection (March 2022)
What an examiner is directed to look for, which is what a bank reviewer copies
Determine whether the information received is sufficient to substantiate representations made to consumers regarding the debt and the consumer's liability for the debt.
This is an informational reference, not legal advice, and using it creates no attorney-client relationship. Limitations periods turn on facts this page cannot know — which state's law governs, the contract type, when the claim accrued, and whether anything tolled or revived it. Confirm against the primary source and your own counsel before acting.