Leela

Change Management Policy

How the Company identifies, assesses, approves, implements, and validates material changes to its products, systems, vendors, policies, and organization, and how it keeps the sponsor bank informed of them.

FieldValue
DocumentChange Management Policy
Version1.0
OwnerCompliance Officer
ReviewAnnual, or on material program change

Authorities

This policy implements, within the sponsor bank's program:

  • The sponsor bank's program agreement, which requires advance notice of material program changes, the bank's prior written approval of critical service provider relationships, and a comment window on modifications the bank initiates.
  • Interagency Guidance on Third-Party Relationships: Risk Management (June 2023), issued by the OCC, Federal Reserve, and FDIC, under which the bank must oversee changes in the activities its partners perform on its behalf.
  • OCC guidance on new products and services risk management, which expects a documented review of compliance, operational, and customer impact before a new or materially changed product launches, and a review after launch.
  • CFPB Supervision and Examination Manual, Compliance Management Review, which treats a working change management process as part of an effective compliance management system.

1. Purpose and Scope

This policy establishes the process by which the Company identifies, assesses, approves, and implements material changes to its products, services, systems, policies, vendors, and organizational structure. Every change in scope is reviewed for regulatory implications, operational risk, customer impact, and consistency with the Company's strategy before it is approved. Changes are classified by impact level, and the approval authority and the notice owed to the sponsor bank vary with the classification. The sponsor bank is notified of material changes under the governance terms of the program agreement.

2. Definition of a Change

A change is any modification, addition, or discontinuation that materially affects one of the following:

CategoryExamples
ProductA new or modified product, service, or feature offered to customers, such as a new lending product, a changed pricing structure, a new payment rail, or support for a new asset type
System or operationsA material modification to IT systems, infrastructure, data flows, or core operational processes, such as a new customer relationship system, a change to transaction processing logic, a new API endpoint, or a migration to a new banking partner
VendorAddition of a new vendor, a material change to a vendor's scope or contract terms, or discontinuation of a vendor. Critical service provider changes carry the enhanced requirements in Section 3
PolicyA material change to a compliance, operational, or financial policy that affects employee conduct, customer treatment, or regulatory obligations
OrganizationAddition or removal of a key role, such as the Compliance Officer, or a material change to reporting lines that affects compliance governance
RegulationA material change in federal or state law or regulation that requires the Company to modify its policies, procedures, or operations

Routine administrative updates, bug fixes that do not alter functionality, non-material policy clarifications, and hiring or departures below the executive level are not changes under this policy.

3. Critical Service Providers

3.1 Definition

A critical service provider is any vendor, contractor, or service provider whose failure or material change in service would significantly disrupt the program or pose significant compliance, operational, or reputational risk to the Company or the sponsor bank. Critical service providers include payment processors, banking infrastructure providers, compliance and fraud detection technology vendors, and data security providers.

3.2 Sponsor Bank Approval and Notice

The Company does not enter into an agreement with a critical service provider without the sponsor bank's prior written approval.

  • New relationships. The Company notifies the sponsor bank in writing at least 30 days before entering into an agreement with a proposed critical service provider. The notice describes the proposed services, scope of work, pricing, term, and the key terms on data security, confidentiality, regulatory compliance, and termination rights.
  • Termination. The Company notifies the sponsor bank in writing at least 60 days before terminating an existing critical service provider relationship.
  • Material changes in scope. A material change to an existing critical service provider agreement, including an expansion of scope, a significant price increase, or a change in key personnel or governance, requires the sponsor bank's prior written approval.
  • Required terms. Every critical service provider agreement includes step-in rights that allow the sponsor bank to assume the relationship if the Company fails to perform, and direct reporting rights that require the provider to deliver compliance and operational reports to the sponsor bank on request.

4. Change Request Process

4.1 Intake and Registration

Any employee or contractor may initiate a change by submitting a change request form to the Compliance Officer. The form describes the proposed change and its business rationale; the affected product lines, systems, and customer segments; the proposed timeline; the change owner and implementation lead; and a preliminary assessment of customer, operational, compliance, and system impact. The Compliance Officer registers the request in the change management log and assigns it a unique change identifier.

4.2 Preliminary Risk Triage

Within three business days of intake, the Compliance Officer performs a preliminary triage to decide whether the change is material and requires formal approval. The triage considers whether the change affects a regulated activity or a disclosure; whether it materially affects the customer experience or imposes new obligations on customers; whether it introduces data privacy, fair lending, unfair or deceptive practice, or other compliance risk; whether it requires system changes, process redesign, or new controls; and whether it requires engagement with the sponsor bank or other vendors. A change found not material is logged as low impact and may proceed on Compliance Officer notification alone. A material change proceeds to compliance review.

4.3 Compliance Review

For a material change, the Compliance Officer completes a detailed compliance review within five business days. The review covers compliance with applicable federal and state law; whether disclosures must be updated and by when; fair lending and unfair or deceptive practice risk; new data collection, use, or sharing; vendor governance, including whether a new vendor has been vetted under Section 5 and whether the sponsor bank's approval applies; the policy updates, process documentation, and customer communications the change requires; and whether affected employees need training. The Compliance Officer records the findings in a compliance review memo and recommends approval, conditional approval, or rejection.

4.4 Classification and Approval Authority

Each change is classified by overall impact, incorporating the compliance review:

ClassificationImpactApproval authorityApproval clock and notice
LowMinor operational or administrative change with no regulatory implicationCompliance Officer, with a monthly summary to the CEOCompliance Officer approval within five business days; implementation may proceed immediately on approval
MediumProduct or process change with compliance implications; a vendor change; a policy clarification affecting several areasCompliance OfficerCompliance Officer approval within five business days; ten business days' advance notice to the sponsor bank unless expressly waived; implementation proceeds after notice
HighMajor product change; a significant system or vendor change affecting several product lines; a policy change affecting regulatory obligations; an organizational change affecting compliance governanceCompliance Officer and CEO jointlyJoint approval within ten business days; 30 business days' advance notice to the sponsor bank unless expressly waived; board notification where applicable

4.5 Sponsor Bank Notification

The sponsor bank is notified of medium and high impact changes under the program agreement. A medium change requires ten business days' advance notice before implementation. A high change requires 30 business days' advance notice. Where immediate implementation is operationally necessary because of a security event or critical incident, notice is given within one business day after implementation with full documentation and, for high changes, a root cause explanation. The notice package includes the change request form, the compliance review memo, and the implementation plan. The sponsor bank may request further information or raise concerns within the notice period; if it objects, the Company and the sponsor bank work to resolve the concern before implementation. The Company does not implement a high impact change over the sponsor bank's objection without escalation to the Company's leadership.

4.6 Sponsor Bank-Initiated Program Modifications

The sponsor bank may modify the program on written notice. The Company has ten business days to review and comment on a proposed modification. The sponsor bank may modify the program on shorter notice where necessary to prevent a violation of applicable law. Implementation timelines and the sponsor bank's support for a modification follow the notification and implementation process in the program agreement.

5. Vendor Due Diligence for Changes

Where a change introduces a new vendor or materially modifies a vendor's scope, the Compliance Officer completes vendor due diligence before approval. Due diligence verifies the vendor's licensing and regulatory approvals where applicable; reviews its security and data privacy practices, including a SOC 2 attestation or equivalent; reviews its compliance program and regulatory history for open enforcement actions or outstanding issues; assesses its fit with the Company's standards for data security, confidentiality, and regulatory compliance; and confirms the service agreement carries the appropriate terms, including service levels, a data processing agreement where applicable, compliance obligations, and termination rights. For a critical service provider, due diligence also confirms that the agreement includes the sponsor bank step-in and direct reporting rights required by Section 3.2. The results are recorded in the compliance review memo with a recommendation on suitability. A high-risk vendor, or one with significant compliance or security concerns, is escalated to the CEO before approval.

6. Implementation Planning and Testing

On approval, the change owner prepares an implementation plan covering the detailed scope and timeline; the affected systems, processes, and teams; the testing approach, including what will be tested, by whom, and the success criteria; a rollback plan for reverting the change if critical issues appear; a communications plan for customers, employees, and the sponsor bank; and the post-implementation validation approach. The Compliance Officer reviews the implementation plan before execution. Testing results are documented and reviewed by the Compliance Officer before the change is deployed to production.

7. Post-Implementation Validation

Within 30 days after a material change is implemented, the Compliance Officer validates that the change operates as intended; that there are no unintended side effects or downstream impacts; that all required disclosures and communications have been delivered; that compliance controls are functioning; and that customers and employees have adjusted. The validation results are recorded in the change management log. Where issues are found, a remediation plan is developed and tracked to closure.

8. Change Documentation and Tracking

Every change is documented in the change management log, a centralized record maintained by the Compliance Officer. Each entry carries the change identifier; the description and business rationale; the compliance review findings and recommendation; the approval status and date; the sponsor bank notification, where applicable, and the bank's response; the implementation status and timeline; and the testing results and post-implementation validation. Change documentation is retained for seven years under the Company's recordkeeping policy. The change management log is reviewed quarterly as part of compliance monitoring and reported to the CEO, and high impact changes are reported to the board annually.

9. Emergency Changes

In urgent circumstances, such as a security incident, a critical system failure, or a regulatory mandate with an immediate deadline, the change process may be accelerated with the approval of the Compliance Officer and the CEO. An emergency change requires an immediate Compliance Officer review of its regulatory and compliance implications; an expedited approval decision within one business day; notice to the sponsor bank within one business day of implementation with full documentation; post-implementation validation and monitoring; and a root cause analysis and process review once the urgent situation is resolved, to prevent recurrence.

10. Regulatory Change

Changes in applicable federal and state law and regulation are monitored through the Compliance Officer's regulatory surveillance process. When a new requirement obliges the Company to modify its practices, the Compliance Officer assesses the impact, develops a remediation plan covering policy updates, disclosure changes, and training, and classifies the remediation as a change requiring approval under this policy. Regulatory compliance deadlines take precedence over routine change timelines, and the emergency procedure in Section 9 applies where needed.

11. Effective Date and Approval

This policy is approved by the Compliance Officer, reviewed annually or on any material program change, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team.