Change Management Policy
How the Company identifies, assesses, approves, implements, and validates material changes to its products, systems, vendors, policies, and organization, and how it keeps the sponsor bank informed of them.
| Field | Value |
|---|---|
| Document | Change Management Policy |
| Version | 1.0 |
| Owner | Compliance Officer |
| Review | Annual, or on material program change |
Authorities
This policy implements, within the sponsor bank's program:
- The sponsor bank's program agreement, which requires advance notice of material program changes, the bank's prior written approval of critical service provider relationships, and a comment window on modifications the bank initiates.
- Interagency Guidance on Third-Party Relationships: Risk Management (June 2023), issued by the OCC, Federal Reserve, and FDIC, under which the bank must oversee changes in the activities its partners perform on its behalf.
- OCC guidance on new products and services risk management, which expects a documented review of compliance, operational, and customer impact before a new or materially changed product launches, and a review after launch.
- CFPB Supervision and Examination Manual, Compliance Management Review, which treats a working change management process as part of an effective compliance management system.
1. Purpose and Scope
This policy establishes the process by which the Company identifies, assesses, approves, and implements material changes to its products, services, systems, policies, vendors, and organizational structure. Every change in scope is reviewed for regulatory implications, operational risk, customer impact, and consistency with the Company's strategy before it is approved. Changes are classified by impact level, and the approval authority and the notice owed to the sponsor bank vary with the classification. The sponsor bank is notified of material changes under the governance terms of the program agreement.
2. Definition of a Change
A change is any modification, addition, or discontinuation that materially affects one of the following:
| Category | Examples |
|---|---|
| Product | A new or modified product, service, or feature offered to customers, such as a new lending product, a changed pricing structure, a new payment rail, or support for a new asset type |
| System or operations | A material modification to IT systems, infrastructure, data flows, or core operational processes, such as a new customer relationship system, a change to transaction processing logic, a new API endpoint, or a migration to a new banking partner |
| Vendor | Addition of a new vendor, a material change to a vendor's scope or contract terms, or discontinuation of a vendor. Critical service provider changes carry the enhanced requirements in Section 3 |
| Policy | A material change to a compliance, operational, or financial policy that affects employee conduct, customer treatment, or regulatory obligations |
| Organization | Addition or removal of a key role, such as the Compliance Officer, or a material change to reporting lines that affects compliance governance |
| Regulation | A material change in federal or state law or regulation that requires the Company to modify its policies, procedures, or operations |
Routine administrative updates, bug fixes that do not alter functionality, non-material policy clarifications, and hiring or departures below the executive level are not changes under this policy.
3. Critical Service Providers
3.1 Definition
A critical service provider is any vendor, contractor, or service provider whose failure or material change in service would significantly disrupt the program or pose significant compliance, operational, or reputational risk to the Company or the sponsor bank. Critical service providers include payment processors, banking infrastructure providers, compliance and fraud detection technology vendors, and data security providers.
3.2 Sponsor Bank Approval and Notice
The Company does not enter into an agreement with a critical service provider without the sponsor bank's prior written approval.
- New relationships. The Company notifies the sponsor bank in writing at least 30 days before entering into an agreement with a proposed critical service provider. The notice describes the proposed services, scope of work, pricing, term, and the key terms on data security, confidentiality, regulatory compliance, and termination rights.
- Termination. The Company notifies the sponsor bank in writing at least 60 days before terminating an existing critical service provider relationship.
- Material changes in scope. A material change to an existing critical service provider agreement, including an expansion of scope, a significant price increase, or a change in key personnel or governance, requires the sponsor bank's prior written approval.
- Required terms. Every critical service provider agreement includes step-in rights that allow the sponsor bank to assume the relationship if the Company fails to perform, and direct reporting rights that require the provider to deliver compliance and operational reports to the sponsor bank on request.
4. Change Request Process
4.1 Intake and Registration
Any employee or contractor may initiate a change by submitting a change request form to the Compliance Officer. The form describes the proposed change and its business rationale; the affected product lines, systems, and customer segments; the proposed timeline; the change owner and implementation lead; and a preliminary assessment of customer, operational, compliance, and system impact. The Compliance Officer registers the request in the change management log and assigns it a unique change identifier.
4.2 Preliminary Risk Triage
Within three business days of intake, the Compliance Officer performs a preliminary triage to decide whether the change is material and requires formal approval. The triage considers whether the change affects a regulated activity or a disclosure; whether it materially affects the customer experience or imposes new obligations on customers; whether it introduces data privacy, fair lending, unfair or deceptive practice, or other compliance risk; whether it requires system changes, process redesign, or new controls; and whether it requires engagement with the sponsor bank or other vendors. A change found not material is logged as low impact and may proceed on Compliance Officer notification alone. A material change proceeds to compliance review.
4.3 Compliance Review
For a material change, the Compliance Officer completes a detailed compliance review within five business days. The review covers compliance with applicable federal and state law; whether disclosures must be updated and by when; fair lending and unfair or deceptive practice risk; new data collection, use, or sharing; vendor governance, including whether a new vendor has been vetted under Section 5 and whether the sponsor bank's approval applies; the policy updates, process documentation, and customer communications the change requires; and whether affected employees need training. The Compliance Officer records the findings in a compliance review memo and recommends approval, conditional approval, or rejection.
4.4 Classification and Approval Authority
Each change is classified by overall impact, incorporating the compliance review:
| Classification | Impact | Approval authority | Approval clock and notice |
|---|---|---|---|
| Low | Minor operational or administrative change with no regulatory implication | Compliance Officer, with a monthly summary to the CEO | Compliance Officer approval within five business days; implementation may proceed immediately on approval |
| Medium | Product or process change with compliance implications; a vendor change; a policy clarification affecting several areas | Compliance Officer | Compliance Officer approval within five business days; ten business days' advance notice to the sponsor bank unless expressly waived; implementation proceeds after notice |
| High | Major product change; a significant system or vendor change affecting several product lines; a policy change affecting regulatory obligations; an organizational change affecting compliance governance | Compliance Officer and CEO jointly | Joint approval within ten business days; 30 business days' advance notice to the sponsor bank unless expressly waived; board notification where applicable |
4.5 Sponsor Bank Notification
The sponsor bank is notified of medium and high impact changes under the program agreement. A medium change requires ten business days' advance notice before implementation. A high change requires 30 business days' advance notice. Where immediate implementation is operationally necessary because of a security event or critical incident, notice is given within one business day after implementation with full documentation and, for high changes, a root cause explanation. The notice package includes the change request form, the compliance review memo, and the implementation plan. The sponsor bank may request further information or raise concerns within the notice period; if it objects, the Company and the sponsor bank work to resolve the concern before implementation. The Company does not implement a high impact change over the sponsor bank's objection without escalation to the Company's leadership.
4.6 Sponsor Bank-Initiated Program Modifications
The sponsor bank may modify the program on written notice. The Company has ten business days to review and comment on a proposed modification. The sponsor bank may modify the program on shorter notice where necessary to prevent a violation of applicable law. Implementation timelines and the sponsor bank's support for a modification follow the notification and implementation process in the program agreement.
5. Vendor Due Diligence for Changes
Where a change introduces a new vendor or materially modifies a vendor's scope, the Compliance Officer completes vendor due diligence before approval. Due diligence verifies the vendor's licensing and regulatory approvals where applicable; reviews its security and data privacy practices, including a SOC 2 attestation or equivalent; reviews its compliance program and regulatory history for open enforcement actions or outstanding issues; assesses its fit with the Company's standards for data security, confidentiality, and regulatory compliance; and confirms the service agreement carries the appropriate terms, including service levels, a data processing agreement where applicable, compliance obligations, and termination rights. For a critical service provider, due diligence also confirms that the agreement includes the sponsor bank step-in and direct reporting rights required by Section 3.2. The results are recorded in the compliance review memo with a recommendation on suitability. A high-risk vendor, or one with significant compliance or security concerns, is escalated to the CEO before approval.
6. Implementation Planning and Testing
On approval, the change owner prepares an implementation plan covering the detailed scope and timeline; the affected systems, processes, and teams; the testing approach, including what will be tested, by whom, and the success criteria; a rollback plan for reverting the change if critical issues appear; a communications plan for customers, employees, and the sponsor bank; and the post-implementation validation approach. The Compliance Officer reviews the implementation plan before execution. Testing results are documented and reviewed by the Compliance Officer before the change is deployed to production.
7. Post-Implementation Validation
Within 30 days after a material change is implemented, the Compliance Officer validates that the change operates as intended; that there are no unintended side effects or downstream impacts; that all required disclosures and communications have been delivered; that compliance controls are functioning; and that customers and employees have adjusted. The validation results are recorded in the change management log. Where issues are found, a remediation plan is developed and tracked to closure.
8. Change Documentation and Tracking
Every change is documented in the change management log, a centralized record maintained by the Compliance Officer. Each entry carries the change identifier; the description and business rationale; the compliance review findings and recommendation; the approval status and date; the sponsor bank notification, where applicable, and the bank's response; the implementation status and timeline; and the testing results and post-implementation validation. Change documentation is retained for seven years under the Company's recordkeeping policy. The change management log is reviewed quarterly as part of compliance monitoring and reported to the CEO, and high impact changes are reported to the board annually.
9. Emergency Changes
In urgent circumstances, such as a security incident, a critical system failure, or a regulatory mandate with an immediate deadline, the change process may be accelerated with the approval of the Compliance Officer and the CEO. An emergency change requires an immediate Compliance Officer review of its regulatory and compliance implications; an expedited approval decision within one business day; notice to the sponsor bank within one business day of implementation with full documentation; post-implementation validation and monitoring; and a root cause analysis and process review once the urgent situation is resolved, to prevent recurrence.
10. Regulatory Change
Changes in applicable federal and state law and regulation are monitored through the Compliance Officer's regulatory surveillance process. When a new requirement obliges the Company to modify its practices, the Compliance Officer assesses the impact, develops a remediation plan covering policy updates, disclosure changes, and training, and classifies the remediation as a change requiring approval under this policy. Regulatory compliance deadlines take precedence over routine change timelines, and the emergency procedure in Section 9 applies where needed.
11. Effective Date and Approval
This policy is approved by the Compliance Officer, reviewed annually or on any material program change, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team.