INSIGHTS for Financial Institutions Winter 2015 | Page 10

Policies and procedures provide the link between regulatory requirements, the institution’s goals and vision, and its day-to-day operations Achieving Compliance through Effective Policies and Procedures How do policies and procedures affect compliance? Policies and procedures are the first step to achieve compliance. In an ever changing regulatory environment, policies and procedures can help ensure a financial institution addresses regulations and provides necessary information to employees. Policies define the “rules,” whereas procedures provide information on the “how” and “who”. to employees. Policies, in combination with effective monitoring systems and other procedures, are an effective tool to ensure familiarity with laws and regulations. Why do ineffective policies and procedures contribute to non-compliance? In many institutions, policies are created, but not reviewed and updated timely to reflect changes in business, products or regulatory environment. Employees rely on policies and procedures to be up to date and accurate to ensure they perform their duties as required. If policies and procedures are not updated or are wrong, actual practices may not adequately address compliance. Non-compliance with laws and regulations is often a result from management’s unfamiliarity with governing statutes or regulations, misinterpretation of statutory or regulatory requirements or prohibitions, or ineffective communication How can an organization develop effective policies and procedures? Developing policies and procedures can be a difficult and daunting task, but the following approach can help keep the process on target. INSIGHTS for Financial Institutions Policies and procedures provide the link between regulatory requirements, the institution’s goals and vision, and its day-to-day operations. 1. Identify all applicable regulations that require policies and procedures – For each business line and department, identify applicable laws and regulations; then determine which require policies and procedures. 2. Define the audience – When thinking about the development of policies and procedures, it is important to determine the users and what the institution wants to accomplish. This will 9 help focus the scope and depth of each policy along with the detailed procedures. of employees will not ensure that they are followed. Employee training is an integral part of having effective policies and procedures. 3. Gap assessment – Usually, some policies and procedures already exist. Performing a gap assessment between “what is” and “what should be” in the policy can help to minimize the time spent developing policies and procedures. 9. Update schedules – Financial institutions should review and update policies on a defined schedule. This will help ensure policies and procedures address applicable laws and regulations. 4. Use clear, concise simple language – It is important for policies and procedures to be clear and concise to reduce the “noise” found within policies. Short, simple and structured procedures will be easier to read and understand. 5. Policies: The rules – Policies often are confused with procedures, resulting in too much detail. Policies should outline the rules, what is to be done, who has responsibility, and what is permitted and what is not. 6. Procedures: Tie to policies – It is important to make this relationship explicit. Procedures should be written in an active style and provide guidance on how to achieve policy compliance. 7. Have an “Owner” – Every set of policies and procedures should have an