Issues Management Policy
How the Company identifies, records, classifies, investigates, remediates, and closes compliance and control issues, and how it reports them to leadership, the board, and the sponsor bank.
| Field | Value |
|---|---|
| Document | Issues Management Policy |
| Version | 1.0 |
| Owner | Compliance Officer |
| Review | Annual, or on material program change |
Authorities
This policy implements, within the sponsor bank's program:
- CFPB Supervision and Examination Manual, Compliance Management Review, which treats corrective action as a component of a compliance management system: deficiencies found by monitoring, audit, or complaints are tracked, remediated, and validated.
- OCC guidance on compliance management, including the Comptroller's Handbook booklet on compliance management systems, which sets the bank's expectations for how a partner identifies, escalates, and remediates issues and how management and the board oversee that work.
- FFIEC BSA/AML Examination Manual, for findings that relate to AML controls, which expects independent testing and quality assurance findings to be tracked and corrected.
- The sponsor bank's program agreement, which governs what the Company must report to the bank, and how quickly, when an issue affects the program.
1. Purpose and Scope
This policy establishes one central process for identifying, documenting, escalating, investigating, and resolving compliance issues and control gaps across the Company. Issues arrive from many places: monitoring and testing findings, complaints, regulatory inquiries, audit results, employee reports, sponsor bank feedback, self-identified non-compliance, and material data integrity failures. Every issue is classified by severity, assigned for investigation and remediation, tracked to closure, and reported to leadership and the board.
The policy covers both non-AML compliance issues, which sit under the Compliance Management System, and AML compliance issues, which sit under the AML Program. One issues management framework serves both so that leadership and the sponsor bank see a single, integrated picture.
2. What Counts as an Issue
An issue is any of the following:
- Control deficiency. A finding from monitoring, testing, or audit that a control did not operate as designed or was not tested.
- Regulatory violation or potential violation. Identified non-compliance with federal or state law, regulation, or regulatory guidance.
- Regulatory criticism. An adverse communication from a regulator relating to the program. The sponsor bank is notified within 5 business days, sooner if the matter is material, and the bank has final approval over any response to the regulator.
- Complaint pattern or escalation. Repeated complaints about the same matter, or a single complaint that points to systemic customer harm.
- Monitoring or testing exception. A transaction, process, or system output that does not comply with policy.
- Audit finding. A finding from internal or external audit.
- Regulatory inquiry or examination. A request from a federal or state regulator that requires investigation or a response.
- Employee report. A report from an employee or contractor of a suspected violation or control gap.
- Sponsor bank feedback. Notice from the sponsor bank of a concern, audit finding, area for improvement, or identified issue affecting the program, whether raised through the bank's oversight monitoring, its audits, or regulatory feedback it has received. A bank-identified issue enters intake like any other and follows the same severity classification, root cause, and remediation process.
- Self-identified non-compliance. The Company's own discovery that it has not complied with applicable law, the sponsor bank's policies, or the program agreement. The Company reports such non-compliance to the sponsor bank promptly.
- Material data integrity failure. Systemic data defects, or defects affecting compliance-critical data fields. These are escalated to the sponsor bank immediately.
- Data security or privacy incident. Unauthorized access, a data breach, or a privacy violation.
- Vendor or third-party issue. A deficiency caused by, or related to, a vendor or service provider.
Minor, isolated process inefficiencies or documentation gaps that do not indicate systemic risk may be logged as low-severity issues and handled administratively without formal escalation.
3. Intake and Registration
Issues reach the process through several channels:
- Direct identification. The Compliance Officer identifies issues through monitoring, testing, or routine oversight.
- Internal reporting. Employees and contractors report suspected issues to the Compliance Officer directly or through an anonymous reporting channel.
- Monitoring and testing. Findings from the Compliance Monitoring and Testing Program are escalated into this process.
- Complaints. Complaints that indicate a systemic issue or a pattern are escalated from the complaint handling process.
- Regulatory inquiry. Regulatory requests and inquiries are logged as issues and investigated.
- Audit results. Internal and external audit findings are received and escalated.
- Sponsor bank notification. The sponsor bank identifies or reports an issue affecting the program.
On receipt, the Compliance Officer registers the issue in the Issues Log, the Company's central tracking record, assigns it a unique identifier, and records the description of the issue; its source (monitoring, complaint, audit, regulatory, sponsor bank, and so on); the date identified; the area of the business affected (product line, process, system, or vendor); and its type (control deficiency, violation, complaint pattern, and so on).
4. Severity Classification
Each issue is classified on a four-level scale. The classification sets the escalation path, the investigation clock, and the remediation window.
| Severity | Definition | Examples | Initial escalation |
|---|---|---|---|
| Critical | A material violation of law or regulation; an immediate and serious risk to customers, the sponsor bank, or the Company; or a matter affecting the safety and soundness of the program or the bank | Disclosure of customer data outside authorization; discriminatory lending or pricing; a complaint handled outside the required timeframe that draws regulatory notice; a system failure affecting transaction integrity; employee fraud; a violation discovered during a regulatory examination | Immediately, within 1 business day, to the Chief Executive Officer and the sponsor bank by phone or email |
| High | A significant control deficiency or violation affecting multiple transactions or an ongoing process, or multiple customer segments, or creating material compliance or operational risk | Systematically incomplete onboarding documentation; vendor non-compliance with security requirements; marketing material with a material misstatement; repeated late delivery of disclosures; a pattern of late complaint responses; missing compliance testing | Within 5 business days to the Chief Executive Officer in writing |
| Moderate | A control gap of limited scope or affecting a small number of transactions, creating localized compliance or operational risk, or an isolated process inefficiency | A single transaction with missing documentation; a one-time pricing error corrected immediately; isolated employee non-compliance with policy; a vendor service-level miss corrected the following month | Within 15 business days to the Compliance Officer for investigation and resolution; reported to the Chief Executive Officer in the quarterly summary |
| Low | A minor process inefficiency or documentation gap with no regulatory implication, or an administrative record-keeping gap | A late compliance review; a missing signature on a training attestation corrected immediately | Logged in the Issues Log; no formal escalation; included in quarterly reporting |
5. Investigation and Root Cause Analysis
On registration, the Compliance Officer, or a team member working under the Compliance Officer's direction, opens an investigation on a clock set by severity:
- Critical: immediately, the same business day.
- High: within 1 to 2 business days.
- Moderate: within 5 business days.
- Low: at the Compliance Officer's discretion, typically within 15 to 30 days.
The investigation gathers the relevant facts through interviews, document review, system logs, and transaction records; determines scope, meaning how many transactions, customers, or areas are affected; identifies the root cause, whether a training gap, a system failure, a policy gap, or individual non-compliance; assesses the harm or risk to customers, the Company, and the sponsor bank; and determines whether a violation occurred and whether regulatory notification is required. Findings are documented in an Issues Investigation Report.
6. Remediation Planning
When the investigation concludes, the Compliance Officer develops a remediation plan that records:
- Root cause. A summary of what the investigation found.
- Corrective action. The specific steps that will correct the issue, such as a policy update, training, a system change, a process redesign, or individual counseling.
- Timeline. When each corrective action will be complete. Windows depend on severity: Critical, interim mitigation within 1 business day and full remediation within 5 to 30 days; High, 10 to 30 business days; Moderate, 30 to 60 business days; Low, 60 to 90 business days.
- Owner. The person responsible for carrying out each corrective action.
- Success criteria. How the Company will verify that the corrective action worked.
- Preventive measures. The steps that will keep the issue from recurring.
The plan is recorded in the Issues Log and shared with the affected parties and stakeholders.
7. Escalation and Reporting by Severity
7.1 Critical Issues
- Immediate escalation. Reported to the Chief Executive Officer by phone within 1 business day of identification, and to the sponsor bank by phone or in person within the same 1 business day.
- Written summary. A critical issue summary is shared in writing within 2 business days.
- Interim mitigation. Immediate steps are taken to limit harm, such as halting the process, notifying affected customers, or securing exposed data.
- Ongoing updates. The Chief Executive Officer and the sponsor bank are updated daily until remediation is under way or complete.
- Regulatory notification. The Compliance Officer assesses whether the issue triggers a regulatory notification obligation, such as a data breach notice, a suspicious activity report, or a regulatory notice, and starts the notification where required.
- Board notification. Critical issues are reported to the board at its next scheduled meeting, and ad hoc if the board meets less often than quarterly.
7.2 High Issues
- Escalation. Reported to the Chief Executive Officer in writing within 5 business days, with an investigation summary and a proposed remediation plan.
- Ongoing updates. The Chief Executive Officer is updated weekly until remediation is under way; the issue closes once corrective actions are complete and validated.
- Quarterly reporting. Summarized in the quarterly compliance report.
- Board reporting. A summary of high issues is included in the annual compliance report to the board.
7.3 Moderate and Low Issues
- Escalation. Logged in the Issues Log; no formal escalation to the Chief Executive Officer unless a pattern emerges or the issue recurs.
- Investigation and remediation. The Compliance Officer owns investigation and remediation and reports progress in the quarterly report.
- Reporting. Summarized in the quarterly and annual compliance reports.
8. Tracking and Closure
Every issue stays in the Issues Log until it is closed. For each issue the log holds the identifier and severity; the description and source; the investigation findings and root cause; the remediation plan and its owner; the remediation status (open, in progress, pending validation, or closed); the timeline for completion; and the closure validation date and result.
An issue is closed only when the remediation plan has been fully implemented; the success criteria have been met and confirmed through testing, re-monitoring, or observation; the Compliance Officer has reviewed and approved closure; and no residual control gap or violation remains.
An issue still open past its remediation timeline is escalated to the Chief Executive Officer. Where an issue cannot be fully remediated within a reasonable period, a timeline extension is documented with the reason and a new target closure date.
9. Closure Validation
Before closing an issue, the Compliance Officer confirms that the remediation worked:
- Compliance review. The corrective actions comply with applicable law and Company policy.
- Testing or monitoring. The affected process or transaction type is re-tested or re-monitored to verify there has been no recurrence.
- Evidence of implementation. Documentation shows the corrective action was in fact carried out, such as an updated policy, training completion records, or verification of a system change.
- Adequacy of preventive measures. The preventive measures will reduce the risk of recurrence.
Closure validation is recorded in the Issues Log.
10. Quarterly and Annual Reporting
10.1 Quarterly Report to the Chief Executive Officer
The Compliance Officer prepares a quarterly issues summary, due in the month after each quarter ends, covering the count of new issues in the quarter by severity; the status of each critical and high issue (open, in progress, pending validation, or closed); a short summary of each critical or high issue with its description, status, and timeline; the count of closed issues with confirmation that closure was validated; and trends, such as a rising count in one area or a recurring root cause.
10.2 Annual Report to the Board
The Compliance Officer prepares an annual issues summary for the board covering the count of issues by severity over the year; a summary of critical issues and their remediation status; trend analysis of whether issues are rising or falling and whether root causes are shifting; a root cause summary showing whether issues stem from training gaps, process gaps, system limitations, or other causes; an assessment of whether the issues management process is effective; and recommendations for process improvements or additional controls.
10.3 Ad Hoc Reporting
Critical issues are reported immediately to the Chief Executive Officer and the sponsor bank under section 7.1. High issues may be reported ad hoc when they need immediate executive attention or a decision.
11. AML-Related Issues
Issues arising from AML compliance and AML quality assurance work follow the same severity classification and escalation procedures as non-AML issues. The AML quality assurance procedures may apply a preliminary classification specific to AML controls, such as customer due diligence exceptions or sanctions and suspicious activity reporting exceptions. Any AML issue that the AML quality assurance framework escalates is treated as at least High severity under this policy. One integrated process keeps AML and non-AML issues tracked, escalated, and remediated on the same terms.
12. Recordkeeping
All issues, together with their investigation, remediation, and closure documentation, are retained for at least seven years.
13. Effective Date and Approval
This policy is approved by the Compliance Officer, reviewed annually or on any material program change, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team.