Leela

Compliance Monitoring and Testing Program

Framework for ongoing monitoring and periodic testing of the Company's non-AML compliance controls.

FieldValue
DocumentCompliance Monitoring and Testing Program
Version1.0
OwnerCompliance Officer
ReviewAnnual, or on material program change

Authorities

This program implements, within the sponsor bank's program:

  • CFPB Supervision and Examination Manual, Compliance Management Review, which expects monitoring and independent testing as components of a compliance management system.
  • OCC guidance on compliance management and bank-fintech partnerships, which sets the bank's expectations for how a partner demonstrates that its controls operate.
  • FFIEC BSA/AML Examination Manual, the independent testing section, for the AML controls covered by the program.
  • The sponsor bank's program agreement, which sets the testing cadence and the reports the bank receives.

1. Purpose and Scope

This program establishes how the Company verifies that its compliance policies and procedures operate as designed and that it meets its obligations under federal consumer financial laws and applicable regulations. It is distinct from, and runs in parallel to, the AML quality assurance program.

Monitoring is ongoing, real-time or near-real-time review of transactions, processes, and communications. Testing is sample-based, retrospective examination of completed activity. Together they provide evidence of control effectiveness and surface exceptions and deficiencies for escalation and remediation.

The sponsor bank may conduct its own monitoring of the Company's customer-facing practices through on-site review, random call sampling, mystery calls, or other reasonable means. The Company provides reports and recordings of customer interactions to the sponsor bank on request.

2. Control Inventory and Risk Areas

The Company maintains a documented control inventory organized by compliance risk area. The primary areas are:

  • Marketing and advertising. Pre-publication review of all marketing materials for accuracy, comparison claims, disclosures, and unfair or deceptive practices; retention of marketing copies for audit.
  • Disclosure and onboarding. Verification that required disclosures are delivered to customers within regulatory timeframes and that required documentation is collected and retained.
  • Complaint handling. Monitoring of intake channels, verification that complaints are logged and investigated, and confirmation that responses go out within required timeframes.
  • Vendor governance. Ongoing monitoring of vendor service levels, security attestations, and regulatory status, with escalation of vendor issues.
  • Change management. Verification that material changes to products, systems, policies, and organization are reviewed for compliance impact, approved, tested, and documented.
  • Data privacy and security. Review of access logs, security incident reports, and adherence to data-handling policies; verification of vendor information security practices.
  • Customer data handling. Monitoring of the Company's handling of customer data owned by the sponsor bank against security, privacy, and authorized-use restrictions.
  • Sponsor bank approval status. Verification that customer-facing and consumer-facing materials carry the sponsor bank approval the program agreement requires.
  • Regulatory reporting and inquiries. Tracking of regulatory requests, confirmation that responses are accurate and timely, and documentation of sponsor bank coordination.
  • Operating procedures. Monitoring of compliance with the sponsor bank's operating procedures, with monitoring scope adjusted whenever the bank updates them.
  • Recordkeeping. Spot checks of transaction records, policy acknowledgments, training documentation, and compliance file completeness.

3. Monitoring Activities and Cadence

Monitoring is continuous and embedded in day-to-day operations:

  • Marketing approval. All marketing materials are reviewed by the Compliance Officer, or a designee under the Compliance Officer's oversight, for accuracy and legal compliance before publication, with same-day turnaround. Approved materials are filed.
  • Disclosure delivery. Logs of disclosures sent to customers are reviewed at least monthly to confirm timely delivery and accuracy.
  • Complaint receipt. All complaint channels are monitored and received complaints are logged within one business day.
  • Vendor performance. Service-level metrics are reviewed periodically; compliance status and security attestations at least annually.
  • Data access and security. Access logs to customer data systems are sampled quarterly; security incident reports are reviewed immediately on receipt.
  • Regulatory update tracking. New federal and state regulations are monitored continuously through subscription services, alerts, and sponsor bank notifications, with a formal quarterly impact assessment.

4. Testing Activities and Sampling Methodology

Testing is periodic and sample-based, combining risk-based and random sampling.

4.1 Risk-Based Sampling

Higher-risk areas are tested more often:

  • Disclosure accuracy and timeliness. Quarterly, on a sample across all product lines and transaction types.
  • Complaint investigation quality. Quarterly, on a sample of closed complaints, verifying thorough investigation, complete documentation, and appropriate resolution.
  • Onboarding documentation. Semi-annually, on a sample of new customer onboardings, verifying that verification procedures were followed, documentation is complete, and disclosures were provided.
  • Marketing materials history. Semi-annually, on a sample of campaigns from the prior six months, verifying approval documentation and compliance with applicable standards.

4.2 Random Sampling

Lower-risk and routine areas are sampled randomly to confirm overall system integrity:

  • Recordkeeping. Quarterly random sample of closed transactions, verifying that records are complete, accessible, and retained per policy.
  • Data access controls. Quarterly random sample of access log entries, verifying that access is restricted to authorized personnel and documented.

4.3 Sample Size and Documentation

Sample sizes are risk-weighted and adjusted on prior results: an area with a high exception rate is sampled more heavily in the next cycle. Where a population is small, the whole population is tested rather than sampled. Every test is documented in a Testing Log maintained by the Compliance Officer, recording the control tested; the population, sample size, and selection method; the objectives and procedures; findings and exception counts; severity classification; root cause; and the remediation recommendation.

5. Finding Documentation and Severity Classification

Every exception, deficiency, or finding from monitoring or testing is documented and classified:

SeverityDefinitionExamples
CriticalA material violation of law or regulation, immediate harm to customers or the sponsor bank; immediate remediation and escalation to the CEO and the sponsor bankComplaint unresolved past a regulatory deadline; customer data disclosed outside authorized use; material marketing misstatement; discriminatory practice
HighA control deficiency that could become a violation if uncorrected, affecting multiple transactions or an ongoing processConsistently late complaint responses; incomplete onboarding documentation; vendor non-compliance with security requirements
ModerateA control gap affecting a limited number of transactions, or a process needing clarificationA single transaction missing documentation; a one-time marketing error corrected on discovery; isolated non-compliance with a policy
LowA minor inefficiency or documentation gap with no regulatory implicationA late annual policy review; a missing training attestation signature corrected on discovery

6. Escalation and Issues Management

All findings are recorded in the Issues Log and escalated under the Issues Management Policy: Critical findings immediately to the CEO and the sponsor bank; High findings to the CEO within 5 business days; Moderate and Low findings tracked, included in quarterly reporting, and escalated if a pattern emerges.

7. Quarterly and Annual Reporting

7.1 Quarterly Report to the CEO

Issued in the month following each quarter: monitoring and testing activities completed; count and severity breakdown of findings; status of remediation from prior quarters; emerging risk areas; and an assessment of staffing and resource adequacy.

7.2 Annual Report to the Board

Issued in the first quarter of each year: overall program effectiveness; annual testing results across all control areas; trend analysis of findings over the prior twelve months; an assessment of whether controls operate as designed; and recommendations for control or policy changes.

7.3 Ad Hoc Reporting

Critical findings identified between reporting periods are escalated immediately to the CEO and the sponsor bank.

8. Monitoring and Testing Tools

At current scale, monitoring and testing are performed by the Compliance Officer and documented in spreadsheets and the case management system. As volumes grow, automated monitoring may flag exceptions in real time; any tool adopted keeps the same control standards and documentation requirements.

9. Workpaper and Documentation Retention

Monitoring and testing workpapers, including test logs, sample documentation, findings analysis, and remediation tracking, are retained for seven years under the Recordkeeping Policy.

10. Relationship to AML Quality Assurance

The AML quality assurance procedures govern testing of AML controls. This program covers non-AML compliance. Findings may be shared between the two where relevant, but the frameworks and escalation paths are distinct.

11. Annual Review and Program Effectiveness

The Compliance Officer reviews this program annually: adequacy of the control inventory and risk classification; appropriateness of sampling method and frequency; effectiveness of testing at finding control gaps; resource adequacy; alignment with regulatory expectations; and recommended enhancements. The review is documented and folded into the compliance management system's annual review.

12. Effective Date and Approval

This program is approved by the Compliance Officer, reviewed annually or on any material program change, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team.