View original document

The full text on this page is automatically extracted from the file linked above and may contain errors and inconsistencies.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000951

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000952

Response to Consent Order No. 11·029·B·HC
Confidential

....
~

BankofAmerica
July 12, 2011

Ms. Usa A. White
Vice President
Federal Reserve Bank of Richmond
P.O. Box 27622
Richmond , Virginia 23261-7622
Mr. Stephen Meyer
Assistant General Counsel
Mail Stop 13
Board of Govemors of the Federal Reserve System
th
20 and C Street. NW
Washington, DC 20551

Ms. Gail K. Jensen
Special Counsel (Manager)
Federal Reserve Bank of Richmond
P.O. Box 27622
Richmond, Virginia 23261 -7622

RE: Response to Consent Order No. 11·029-B-HC, Dated April 13, 2011: Submission of Written
Plans

Dear Ms. White, Mr. Meyer, and Ms. Jensen :
I am writing on behalf of the Board of Directors (the ~ Board ") of Bank of America Corporation ("BAC in
response to requirements of the Consent Order No. 11·029·B·HC, dated April 13, 2011 , (the ~ Order" ) of the
Board of Govemors of the Federal Reserve System (the ~ Federal Reserve"). The Order followed
identification of supervisory concems in the Home Loans business (" HL~) of Bank of America, National
Association (the ~ Bank") during an examination of residential mortgage servicing practices at a number of
regulated institutions. This letter summarizes what we have done in response to the Order and our plans
for strengthening BAC's control functions associated with mortgage servicing activities, particularly, in our
default residential mortgage servicing operations which were segregated into a separate line of business,
Legacy Asset Servicing ("LAS"), in February 2011 , as well as our oversight of those control functions. We
note that there is significant separate work for a risk assessment of our residential mortgage servicing
activities that is underway pursuant to the Office of the Comptroller of the Currency (~ OCC" ) Consent Order
No. AA-EC·11-12 , dated April 13, 2011 , (the "OCC Orden, Article X , that may augment and supplement
our conclusions herein.
W

)

We recognize the growing responsibilities in mortgage servicing control functions, which we believe
represent long-term change in the requirements for conducting the residential mortgage servicing business.
These changes are due in large part to:

1

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000779

Response to Consent Order No. 11-029-B-HC
Confidential
•

A credit cycle which has spawned an enormous need to change the business model , from one of
operating a servicing platform constructed for origination , to one that must operate as a special
servicing platform and address activities related to rising delinquency and defaults;

•

A rapidly changing legal and regulatory landscape; and,

•

A myriad of changing standards and practices in the mortgage servicing business.

These factors highlight the Board's need to enhance its oversight. The main areas of improvement relate to
gaining greater visibility in these areas and thus being able to provide direction to manage the strategic
risks presented by the breadth of changes in residential mortgages. Strengthening the effectiveness of the
Enterprise Risk Management ("ERM-), Internal Audit, and Compliance programs, we believe, will move us
toward this goal.
We are submitting as Appendices to this letter the four written plans, pursuant to the Order: Parag raph 2.
Board Oversight; Paragraph 3. Risk Management; Paragraph 4. Compliance Program; and Paragraph 5.
Audit.
We wish to assure you of our commitment and that of BAC's executive management to accomplish the
actions required by the Order. We appreciate fully the seriousness of the issues we face in the residential
mortgage business and the significant resources and effort that will be necessary to resolve those issues
promptly and effectively. We will continue to provide those resources and to make every effort to ensure
that our residential mortgage activities are properly staffed, sustainably managed , and carefully governed.
We describe below our approach for complying with the Order, developing the plans, and the key action
steps contained relating to the requirements of the Paragraphs.

Our Approach
Following the execution of the Order, the Board determined to use an established governance framework
created under the OCC Order to deliver its obligations under the Order. The following organization chart
(Figure 1) reflects this framework.

2

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000780

Response to Consent Order No. 11-029-B-HC
Confidential

,
Comphance CommIttee

!

I
Figure 1

The Board 's Compliance Committee, a subcommittee of its Enterprise Risk
of
Board members, monitors the actions and
of BAC
serves as Chairman of the Compliance Committee.
comprise the other Compliance Committee members. The
Compliance Committee meets regularly to review the status of the four plans required under the Order and
to monitor BAC 's compliance with the Order.
The Board , through the Compliance Committee: (1) requires timely reporting by senior management of the
actions directed by the Board and the Compliance Committee to be taken under the Order; (2) follows up
on any non-compliance with these actions in a timely and appropriate manner; and (3) requires corrective
action be taken in a timely manner for any non-compliance with these actions.
Upon submission of the plans, the Board will continue to use this governance structure to facilitate its
continued compliance with Paragraphs 6 and 7 of the Order, including submitting within 30 days after the
end of each quarter thereafter, to the Federal Reserve Bank of Richmond (the ~ Federal Reserve Bank"), a
written progress report setting forth detail actions taken to comply with each Paragraph of the Order and
the results and status of those actions. The Board will receive reports at its previously scheduled full
meetings from the Compliance Committee or the Enterprise Risk Committee on the progress of the action
plans.
Special Advisor on Remediation Strategies. In order to oversee development of the four plans with respect
to residential mortgage servicing and foreclosure processes and to provide
to senior
management and the Board, BAC named Global
as Special
Advisor on Remediation Strategies (the "Special Advisor").
works with the Independent
Consultant on Remediation Strategies (defined below) to support the Compliance Committee in executing

3

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000781

Response to Consent Order No. 11-029-B-HC
Confidential
to strengthen Board oversight of those functions. In the case of the plans to enhance Risk Management,
Compliance, and Internal Audit, the Order requires that they be based on an evaluation of the effectiveness
of current practices with respect to residential mortgage servicing activities.
Despite a number of recent internal assessments of our control functions operating in the mortgage
business and relevant self-identified audit issues, on April 13, 2011, we retained Promontory Financial
Group, LLC ("Promontory") as Independent Consultant on Remediation Strategies. Promontory's role was
to assist the Compliance Committee and the Special Advisor in overseeing BAC's efforts to comply with the
requirements of the Order and the various plans and submissions prepared and approved pursuant to the
Order. Promontory periormed independent effectiveness evaluations of Risk Management, Compliance,
and Internal Audit relative to residential mortgage servicing activities. These efforts supplemented and built
on BAC's prior efforts, which began in late 2009 and early 2010, including management Transformation
Plans in Compliance and Risk Management to strengthen these core control functions and formed the
basis for many of the actions identified in our plans.
In conducting their reviews, Promontory evaluated our programs against relevant supervisory guidance
published by the Federal Reserve and other recognized U.S. and international authorities. Promontory's
evaluation also encompassed our Global Risk Management's Risk Framework (URisk Framework-),
adopted by the Board in 2009 and updated in December 201 O. Because Promontory considered the Risk
Framework to reflect effectively the applicable regulatory guidance and to be suitable for an institution of
BAC's size and complexity, they evaluated our control functions against the Risk Framework as well.
Our Risk Framework specifies roles and responsibilities for the Risk Management and Compliance
functions that are critical to BAC's ability to manage its activities within our established risk appetite.
Providing independent oversight of lines of business requires not just sufficient numbers of Risk
Management and Compliance personnel , but risk and compliance professionals with the stature
appropriate to the critical roles in which they serve.

4

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000782

Response to Consent Order No. 11-029-B-HC
Confidential
Accordingly, staffing the Risk Management and Compliance functions in the default mortgage servicing
business in LAS with the number and quality of individuals required is one of wo issues that deserve close
oversight by the Board. Building out the Risk Framework and the Global Compliance Program in HL and
LAS is the other. In this regard, HL and LAS have adopted a framework for risk and control as outlined
below in Figure 2.
The plans to enhance our control functions reflect the incomplete portions of management's own plans to
strengthen our Risk Management, Compliance and Internal Audit programs affecting residential mortgage
servicing activities and amended with Promontory's recommendations.

Paragraph 2. Plan to Strengthen Board Oversight
Pursuant to Paragraph 2 of the Order, our plan to strengthen Board oversight of the control functions
concerning mortgage servicing activities shall address and include:
•

Board-adopted policies to ensure that Risk Management provides proper risk management

HL and LAS Risk and Control Framework: Overview of Approach
Objective:
To ensure compliance with the Order, the following el ements of the Riskand Control Framew o r1<; must be in place within 120
days for all processes that are in scope of the Order.

"'./Cam.w....

_-_-

......

.. Dol\oo4d ....

......................
.~-

--LC ... _

. ...

o

.

.
... . . . .............
...... ..

c

B

A

~

.......

E

.

.
..
-.............-

F

.

.

IMMR

..._.......-_
. ............ .....
.......... ....__
... .... ......... ........-_ _,- ......_.........
.,_. ...... -. .......- .. _,
.. ,_
_
".-......
'-_
......
..
.._"
....
................._.. .
,_'"--" ,_
....
......--...............
.......
....
..........
....
....
...... ..
...,-. . .. --..'".-- ....- .....................
....- _
..
......
... . .
-..
.........
....__...................-....
_
...
---

_

u .. o• • ""_

..... ""...

•._ ...... _01.........
...... ,,,_......
...... .
_...................
.......... . . to._

Figure 2 ::::::';:"''':...
, ..-

U •• oI ...... _

""' """'

,,",••11.

,~.-

-.~
T...... QC ... " ..

-..

-,..
......

_
_
-_

>.-...................

,

.. ..-d ......

u. ....., ..........

-.....,

.......
_'._..........,..-...
.................
_
.............-.,....
'_
..................
..................
.... .
... -'...................
......... ....
,-'

Qoo .....

c ........

11_..... ..........

.

~

""

,

l~_

_
_
---_.
.,
....

..... "
,""""

,

••

, .-

~-

,,_
>f._"'. ,

.... _

_
_ __.M
u. ............

.- ,

...., -,,'.......

-~

.....- .....
.
-.-

.-

..-."".-~

,,~

K . y _ ..I~II·~d M<>fII..J"n
~_M

•. _ ....... 0_.-.,'

I

...........

"""" . . . .
,- . . . . Q ..........
.

5

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000783

Response to Consent Order No. 11 -029-B-HC
Confidential
oversight;
•

Policies and procedures to ensure that Risk Management provides proper risk management of third
party service providers;

•

Steps to ensure that the control functions have adequate levels and types of officers and staff; and

•

Steps to improve the information the Board reviews regarding residential mortgage servicing
activities.

Our Plan to Strengthen Board Oversight (attached as Appendix 1) addresses each of the foregoing
elements and identifies remedial measures with respect to them, including the Board's consideration of an
overarching Board policy andlor policy statement to provide specifically the Board 's guidance, direction ,
and expectation for implementing risk management in the residential mortgage business. The Plan to
Strengthen Board Oversight also provides for the Board to consider launching an internal communication
process and strategy to draw attention to such a new policy to reiterate appropriate tone at the top.
With regard to ERM, Internal Audit, and Compliance there is a range of progress under the respective
Transformation Plans to implement the Risk Framework: Internal Audit has achieved greater progress;
Risk and Compliance are at earlier stages in their development. The successful execution of these
Transformation Plans, and some additional enhancements, are critical to the effectiveness of the ERM ,
Internal Audit, and Compliance programs. Due to the sheer breadth of developments that are underway
across the three areas and the potential for a lack of cohesive execution, Promontory has recommended
that we also perfonn a review to identify duplication~ and ensure successful achievement of the
Board 's objective to develop a strong and cohesive internal control framework.
Audit, Risk Management, and Compliance playa critical role in the success of BAC and we intend to
provide oversight of them reflective of that criticality. We consider the information and reports that Risk
Management and Compliance provide to the Board with respect to risk and compliance conditions affecting
the residential mortgage servicing business to be clear, actionable, and timely. However, we intend to seek
more information to enable us to judge the health and fitness of the Risk Management and Compliance
functions overseeing those mortgage-related activities. Therefore , over the remainder of this year, we will
evaluate how we oversee the development, maturation, and overall fitness of the Risk Management and
Compliance functions. We will also review whether there are best practices in this area, such as Audit's
annual assessment of its sufficiency of staff hours to complete the Audit Plan that may be implemented in
other areas of Risk Management and Compliance. We believe that the profound changes affecting the
mortgage servicing business and the associated increase in the responsibilities of our control functionsparticularly Risk Management and Compliance - require that we consider enhancing our ability to provide
the level of oversight we desire.
in many cases these issues had already been self-identified by management and the efforts
had begun under the Transformation Plans, there is substantial work yet to be completed
to implement effectively the Risk Framework and the Global Compliance Program . This work is critical and
urgent, given the current risk profile of mortgage servicing activities. We will continue to evaluate closely
how we oversee these important issues. Specifically, we will conduct a review to determine whether there
are other improvements in our structure that are worthy of additional consideration . The Plan will serve to
provide adequate oversight of the control functions pending completion of our organizational deliberations.

6

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000784

Response to Consent Order No. 11-029-B-HC
Confidential
Paragraph 3. Plan to Enhance the Enterprise-wide Risk Management Program
Promontory reviewed the HL and LAS Risk Management function to evaluate its effectiveness and to
determine whether its practices comport with regulatory guidance and BAC's Risk Framework.
Promontory's review notes that, in the months preceding the Order and Promontory's evaluation, BAC
changed the
of the HL and LAS Risk Management function. HL and LAS Risk Management
i
I
between the existing Risk Management program and the practices required by
BAC's Risk Framework. In order to address those" , Risk Management developed and implemented a
Risk Transformation Plan.
At the time of Promontory's evaluation, management had developed a number of task forces and work
streams to focus on and develop the processes , tools, and reporting necessary to perform the
requirements ascribed to the Risk Management Function by the Risk Framework. While Promontory noted
progress toward building out the Risk Framework, much work remains. Pursuant to Paragraph 3 of the
Order, we have developed a Plan to Enhance the Enterprise-Wide Risk Management Program (attached
as Appendix 2).
High Level Observations

•

Under the Risk Framework, the Risk Management function includes development of business level
policies, prescribing parameters under which business activities are to be conducted. At the time
of Promontory's review, Risk Management had established a work stream under the Risk
Transformation Plan devoted to policy
I
That work stream documented ~~~::!

Ii

Risk Mar1aoemr,n!.

•

The Risk Framework contemplates that the Risk Function will monitor and test the effectiveness of
business controls, compliance with policies, successful remediation of regulatory issues, including
satisfaction of actions required by consent orders, among others. The monitoring and testing capability
remains a key component that will need continued efforts to complete.
Associated Recommendations

•

While Risk Management progresses on its build out of the Risk Framework, Promontory
recommended that management should adjust its mix of activities to focus greater attention on
completing the plans and processes that will be necessary to support its on-going activities under
the Risk Framework. The elevated risk conditions and high priority regulatory issues associated
with residential mortgage servicing activities understandably are requiring management attention .
Promontory recommends that building the capability to implement the Risk Framework more

7

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000785

Response to Consent Order No. 11-029-B-HC
Confidential
rapidly, as contemplated in management's Risk Transformation Plan, be established as
management's highest priority.

High Level Observations

•

Ma.naQelTlentstaff who have worked in HL and LAS for some time
to that of the rigorous and independent oversight and
escalation of significant issues contemplated by the Risk Framework.

•

Promontory considers the more difficult challenge with staffing to be getting Risk Management Staff
with the qualifications to perform effectively. At a minimum, those qualifications include solid
knowledge of risk management principles and practices , understanding of Risk Management's role
under the Risk Framework and knowledge of the business activities conducted in HL and LAS.

•

In a business as usual environment, orienting and developing new staff members can frequently be
accomplished without undue difficulty. Given the current risk profile of the HL and LAS mortgage
servicing activities, however, and the significant number of new Risk Management Staff required,
management faces a particularly significant challenge in fielding a team whose members have the
requisite knowledge and stature necessary to perform risk management oversight effectively.

Related Recommendations
•

Develop staffing plans based on estimates of the number of personnel and the skills necessary to
perform the responsibilities of Risk Management in HL and LAS.

•

Recruit for risk professionals and persons with mortgage servicing knowledge.

•

Enlist the Global Learning Organization to develop training programs specific to the needs of the
new Risk Management organization.

•

Prior to deploying new personnel into lines of business , evaluate whether they possess basic
understanding of the relevant business activities and know the risk protocols for which they are
responsible.

Paragraph 4. Plan to Enhance the Enterprise-wide Compliance Program
Promontory reviewed the Compliance function in our mortgage servicing business to evaluate its
effectiveness and to determine whether its practices comport with regulatory guidance and BAC's Risk
Framework, as embodied in the Global Compliance Program. As was the case in Risk Management,
Promontory's evaluation of Compliance notes that the Compliance organization undertook to perform its
own evaluation of the Compliance Program in HL and LAS in the Fall of 2010. That evaluation noted
between the Compliance practices in our mortgage servicing area and those required by

8

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000786

Response to Consent Order No. 11-029-B-HC
Confidential
the Global Compliance Program. Those findings, in turn, prompted changes in HL and
responsibilities and development of a Compliance Transformation Plan
Pursuant to Paragraph 4 of the Order, we have developed a Plan to Enhance the Enterprisewide Compliance Program (attached as Appendix 3).

High Level Observations
•

Promontory's evaluation reported that, while Compliance staff has been increased significantly over
the past two quarters, staffing levels are still challenged by the volume of compliance obligations
that the Compliance function is responsible to oversee.

•

Staff increases have been made on the basis of the judgment of Compliance Officers aligned to
specific lines of business in HL and LAS, but staffing plans should be evaluated further based on
analyses of:
o

Existing and emerging compliance issues affecting the business;

o

Progress on the Compliance Transformation Plan ;

o

The increased inventory of requirements that must now be managed as compliance
obligations;

o

The need to eliminate the compliance testing backlog and expand testing to encompass
preventive controls; and

o

The need to align compliance risk levels with the Board's risk appetite.

Related Recommendations
•

Increase the analytic rigor underpinning Compliance staffing needs. A large number of mortgage
servicing requirements must now, pursuant to the OCC Order, be managed with the rigor required
for compliance obligations triggers. This will require that, the processes required by the Global
Compliance Program-risk assessments, policy development, procedures reviews, monitoring and
testing-be performed more urgently and on a much broader scale. These additions to the
inventory of risk obligations will necessitate additional Compliance personnel.

High Level Observations
•

The compliance risk report provided to senior management and the Board focuses on line of
business compliance and does not report issues or weaknesses potentially affecting or
compromising the ability of the Compliance function to perform its responsibilities under the Global
Compliance Program .

Related Recommendations
•

For the period before completion of the Compliance Transformation Plan , augment HL and LAS
compliance reporting with information about the status of the Compliance function , including status
of key milestones in the Compliance Transformation Plan. Establish "health of Compliance

9

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000787

Response to Consent Order No. 11-029-8-HC
Confidential
function" metrics that are routinely reported to the Board committee responsible for compliance
oversight.

High Level ObseNations
•

Under the Global Compliance program, the Compliance function is required to escalate significant
compliance issues that arise in the line of business. The Compliance Executive for HL and LAS
has discretion with regard to escalation of compliance issues. Due to the limited period of
operations under the Global Compliance Program , there is not sufficient understanding of the sort
of issues that warrant escalation and the factors that distinguish those issues from issues that do
not warrant escalation.

Related Recommendations

•

Develop written guidance that will inform the Compliance Executive's exercise of discretion with
regard to escalation of issues. Written guidelines, identifying the factors that influence the
escalation decision and providing contrasting scenarios will assist management in establishing
common values among the Compliance team and inform expectations among line of business and
Compliance personnel alike.

Paragraph 5. Plan to Enhance the Internal Aud it Program
Promontory evaluated the effectiveness of the Internal Audit program in HL and LAS, comparing its
elements to published Federal Reserve and other regulatory guidance as well as to standards established
by the Institute for Internal Auditors. After completing its review, Promontory concluded that the Internal
Audit program was generally sound. More specifically, Promontory found that: Internal Audit appeared to
meet standards for independence; the audit staff was experienced and reasonably credentialed; and audit
planning, reporting , issue tracking and escalation were effectively managed.
Promontory recommended that Internal Audit develop standards (from published regulatory guidance,
among other sources) for its forthcoming audits of the Compliance and Risk Management functions
providing oversight to residential mortgage servicing activities. Promontory recommended additional
matters to promote what it believes would constitute modest improvements to the existing Internal Audit
program.
Pursuant to Paragraph 5_of the Order, we have developed a Plan to Enhance the Internal Audit Program
(attached as Appendix 4), including , among others, recommendations to:
•

Develop the standards against which the Risk and Compliance programs will be evaluated and the
procedures and testing that will form the basis for conclusions;

•

Consider augmenting the risk measuring methodology to incorporate the duration associated with
identified risks; and ,

•

10

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000788

Response to Consent Order No. 11-029-8-HC
Confidential
While we do not believe major changes in the existing Internal Audit function are warranted , the plan will
help strengthen the overall capability.

Conclusion
We believe that the plans we enclose will strengthen the control functions in their oversight and audit
activities with respect to mortgage servicing activities. We view the effectiveness of those functions - and
their counterparts throughout BAC - to be vital to our success. We intend to strengthen and support them
and to monitor their health and fitness on a regular basis.
We look forward to your response to our plans and to discussing them with you in the near future.

cc:

Enclosures.

11

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000788A

Confidential

Appendix 1.1

FRB Consent Order
BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
Action Steps
Status as of June 30, 2011 for July 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

Posted on 7/8/11 for the Compliance Committee

Final as of July 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000815

Confidential
BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011

Area
Paragraph 2. Board Oversight

1. Board Policies

Requirement

Action Steps

Policies to be adopted by the board of directors that are designed 1.1 Consider developing a Board Oversight policy/statement providing Board guidance and direction with regard to risk management program in residential
to ensure that the ERM program provides proper risk
mortgage activities.
management oversight with respect to the Bank’s residential
mortgage loan servicing, Loss Mitigation, and foreclosure
1.2 Consider an internal communication process and strategy to draw attention to such a new policy and underline further the Board’s resolve to do everything in
activities, particularly with respect to compliance with the Legal
its power to ensure appropriate oversight in the residential mortgage business and further reiterate appropriate tone at the top.
Requirements, and supervisory standards and guidance of the
Board of Governors as they develop.
1.3 Continue to perform periodic monitoring of Risk Management Framework to ensure maintains design and operation for proper risk management oversight in
the Bank’s residential mortgage business.
1.4 Implement clear remediation protocols and guidelines to address
appetite to accommodate heightened risk environments.
1.5 Consider performing a review to identify duplications
internal control framework.

2. Risk Oversight of Third
Parties

Executive
Owner

Status

Target Date

In Process

08/30/11

Not Started

08/30/11

In Process

12/30/11

In Process

12/30/11

In Process

08/30/11

In Process

10/30/11

In Process

08/30/11

In Process

Ongoing

of risk limits to either bring risk levels within established limits or realign risk

and ensure successful achievement of the Board’s objective to develop a strong and cohesive

Policies and procedures to ensure that the ERM program
2.1 Continue extensive build-out of oversight of third parties.
provides proper risk management of independent contractors,
consulting firms, law firms, or other third parties who are
engaged to support residential mortgage loan servicing, Loss
Mitigation, or foreclosure activities or operations, including their
compliance with the Legal Requirements and BAC’s internal
policies and procedures, consistent with supervisory guidance of
the Board of Governors.

2.2 Ensure build-out is coordinated and reported in the Review identified in Action Step 1.5 of this Plan.

3. Staffing Enhancements to
ERM, Compliance, and
Internal Audit

4. Board Reports

Steps to ensure that BAC’s ERM, audit, and compliance
programs have adequate levels and types of officers and staff
dedicated to overseeing the Bank’s residential mortgage loan
servicing, Loss Mitigation, and foreclosure activities, and that
these programs have officers and staff with the requisite
qualifications, skills, and ability to comply with the requirements
of this Order.

3.1 Ensure budgetary protections to Internal Audit’s annual budget that is approved annually by the Audit Committee including requests for additional resources to
its staffing levels.
3.2 Implement annual staff sufficiency reviews as a portion of the annual budgeting process from well-developed staffing plans tied to BAC’s strategy and goals.

In Process

11/01/11

3.3 Commission Global Human Resources to develop and implement a robust staffing process for Risk Management that at a minimum.
• Ensures alignment to BAC strategy.
• Ensures integration of goals and objectives with Risk Management’s Business Plan.
• Fully analyzes and determines positions and functions necessary to meet these established goals and objectives, including:
• Creating job profiles around measurable criteria related to ideal performance behaviors.
• Benchmarking job performance using BAC’s Risk Framework as well as other best practice standards.
• Maximizing our existing resources.
• Determining the gaps in current resources.
• Plans staffing requirements based on business plan.
• Develops recruiting, hiring, retention strategies to fill additional roles identified as part of the staffing plan.
• Hires proactively based on planned needs and expected attrition.
• Engages Global Learning in comprehensive training for Risk Management.

In Process

11/01/11

3.11 Commission Global Human Resources to develop and implement a robust staffing process for Compliance that at a minimum.
• Ensures alignment to BAC strategy.
• Ensures integration of goals and objectives with Compliance Program and the Business Plan.
• Fully analyzes and determines positions and functions necessary to meet these established goals and objectives, including:
• Creating job profiles around measurable criteria related to ideal performance behaviors.
• Benchmarking job performance using BAC’s Global Compliance Program well as other best practice standards.
• Maximizing our existing resources.
• Determining the gaps in current resources.
• Plans staffing requirements based on business plan.
• Develops recruiting, hiring, retention strategies to fill additional roles in plan.
• Hires proactively based on planned needs and expected attrition.
• Engages Global Learning in comprehensive training for Compliance Program.

In Process

11/01/11

In Process

09/01/11

In Process

Ongoing

Steps to improve the information and reports that will be regularly 4.1 Improve consistency in board reporting. At a minimum, ensure current and emerging risks are fully addressed and the root cause or potential underlying
reviewed by the board of directors or authorized committee of the issues identified.
board of directors regarding residential mortgage loan servicing,
Loss Mitigation, and foreclosure activities and operations,
including compliance risk assessments and the status and
4.2 As remediation efforts continue to make significant changes in mortgage servicing business it may be necessary for more targeted reporting on status,
results of measures taken, or to be taken, to remediate
progress, and emerging issues to be reported to the Board. Explore methods to present clear, streamlined, and effective information to the Board on these issues
deficiencies in residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities, and to comply with this
Order.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1

Final as of July 12, 2011
BAC Consent Order Submission 0000816

Confidential

Appendix 1.1

FRB Consent Order (the "Order")
BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight Action Steps

Action Plan as of November 30, 2011 for December 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

The Plan and the corresponding action steps do not describe all the core elements of the Board’s oversight of BAC’s
enterprise-wide risk management, internal audit, and compliance programs concerning the residential mortgage loan
servicing, loss mitigation, and foreclosure activities conducted through the Bank. Prior to the issuance of the Order, BAC
had made significant progress in enhancing the Board’s oversight of these programs in accordance with supervisory
guidance and expectations. The Plan was based on an evaluation of the effectiveness of the Board’s oversight of these
programs, which was completed in May 2011. Action steps presented in Appendix 1.1 reflect activity as of November 30,
2011. The action steps in the Plan are supplemental to the enhancements BAC had already implemented or had begun
implementing and contribute to safe, sound, and compliant residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities.

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000953

Confidential

BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 2. Board Oversight

1. Board Structure

Requirement

No specific requirement under Paragraph 2.

Action Steps

A. Existing and Ongoing Practices

A.1 The Board’s current structure is comprised of six committees: Audit, Compensation and Benefits, Corporate Governance, Credit, Enterprise Risk and Executive Committees. All Board
committees (with the exception of the Executive Committee) have charters, designated chairpersons, hold regularly scheduled meetings and keep minutes. The Executive Committee has a
charter, a designated chairperson and keeps minutes when it meets. According to its charter, the Executive Committee meets only in an emergency when the full Board is unable to convene

A 2 The Audit Committee provides strong oversight of and direction to the Internal Audit function. The Committee regularly receives and reviews information necessary to gauge both the
capability and the effectiveness of Internal Audit.

A 3 Risk Management reports into the Enterprise Risk Committee and Compliance reports into the Audit Committee. These committees receive substantial documents, information, and
reports on the enterprise-wide operations and all lines of business.

A.4 With respect to Risk Management and Compliance reporting, the Board receives regular reports from these functions the focus of which is the risk and compliance positions, respectively,
in the HL and LAS businesses.

A 5 Board continues to ensure effective governance and oversight over BAC, including through enhanced issue escalation processes via the Audit Committee, Credit Committee, and
Enterprise Risk Committee.

B. Completed Action Steps

B.1 The Board has designated a Compliance Committee to provide governance and oversight of the activities and remediation required under the Order.

B 2 The Bank appointed a Special Advisor on Remediation Strategies to oversee and drive progress of the Action Steps and provide recommendations to senior management and the Board.

B 3 Since its inception in March 2011, the Compliance Committee has met regularly to discuss and monitor the development of the Consent Order Remediation Plans and track BAC’s
progress in implementing them. Through their monthly meeting, the Compliance Committee has strengthened BAC’s risk management through their review of the Consent Order
requirements.

B.4 The Compliance Committee has provided regular progress reports this year to the Enterprise Risk Committee and the Board. These reports cover both BAC’s compliance with the
requirements under the OCC and FRB Consent Orders and the progress made in implementing remediation plans.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000954

Confidential

BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 2. Board Oversight

2. Board Policies

Requirement

Action Steps

Policies to be adopted by the board of directors that are designed to ensure A. Existing and Ongoing Practices
that the ERM program provides proper risk management oversight with
respect to the Bank’s residential mortgage loan servicing, Loss Mitigation,
and foreclosure activities, particularly with respect to compliance with the
Legal Requirements, and supervisory standards and guidance of the Board A.1 Since 2005, BAC has had a risk framework document that sets forth its enterprise risk management and culture. The Board enhanced this risk framework with the adoption in October
of Governors as they develop.
2009 of an expanded risk document and a risk appetite statement (the “Risk Framework Documents”) together with the institution of a risk reporting routine developed by management for the
Board to consolidate in a consistent manner risk reporting across the organization.

A 2 The Board’s efforts beginning in 2009 have formed a strong foundation for the Board to exercise its oversight responsibilities in a systematic and comprehensive manner. The adoption of
the Risk Framework Documents has strengthened BAC's enterprise risk management program and provided definitive guidance in identifying, measuring, mitigating, controlling, monitoring,
testing and reporting risks throughout the enterprise. The Risk Framework Documents are reviewed and approved by the Board at least once within each calendar year.

B. Completed Action Steps

B.1 In light of the Order and as part of its annual review, the Board, through its Credit Committee and Enterprise Risk Committee, has reviewed and provided feedback to updated versions of
the Risk Framework Documents, and these committees, together with the full Board, plan to review and approve the Risk Governance Documents at their next regular meetings. Several
enhancements were made to the Risk Framework Documents during this review cycle that reflect strong Board oversight directly tied to key businesses including consumer real estate
services. These enhancements include:
• Expanded description of key businesses and their related risks, including consumer real estate services and its risks related to credit, liquidity, operational and reputational matters.
• Enhanced emphasis on assessment of risk on key business models and performance drivers with transparency in reporting of this information to the Board.
• Updated credit risk management practices including expanded steps to set forth loss mitigation processes.
• Setting forth as an example to illustrate the design approach to risk management dictated by the Risk Framework Documents the recent inclusion of well-defined quality assurance and
quality control functions related to the mortgage services business to support quality and risk management goals across a large number of manual operations that are subject to a broad range
of laws, regulations and policies.
The Board established, through the Risk Framework Documents, its expectation that each key business will develop appropriate policies to address critical risks. As a result, the consumer
real estate services business has adopted unique policies across numerous high-risk processes as identified through application of the principles in the Risk Framework Documents.

B 2 The consumer real estate services business has established multiple new programmatic procedures and extensive desktop procedures.

B 3 The Board, through its outline of expectations of risk management and its drive for a culture of risk control and accountability as established by the Risk Framework Documents, has
overseen the consumer real estate services business’s effective management of key controls integral to compliance with legal requirements and supervisory standards and guidance of the
Federal Reserve.

B.4 In order to establish clear channels for oversight and escalation of issues and emerging risks, management committees have been developed or reconstituted in the consumer real estate
services business to provide close supervision to each of the areas of key risks identified through the Risk Framework Documents. This governance structure establishes a strong foundation
for the identification, management and escalation, if necessary, to the Enterprise Risk Committee or the full Board, of developments in the risk profile of the business.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000955

Confidential

BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 2. Board Oversight

Requirement

Action Steps

B 5 To ensure this culture of controls and risk management is spread throughout the organization on an individual level, critical populations of Bank of America associates must read the Risk
Framework Documents and complete a comprehension test with a passing score.

C. Remaining Action Steps

C.1 The Board will continue its periodic review of the Risk Framework Documents to ensure that these critical tools continue to reflect the Board’s view of the appropriate risk culture for all key
Bank of America businesses including its consumer real estate services business. To more fully implement the risk parameters of the current Risk Framework Documents, the consumer real
estate services business continues its development of additional policies to manage critical risks.

3. Risk Oversight of Third Parties

Policies and procedures to ensure that the ERM program provides proper
A. Existing and Ongoing Practices
risk management of independent contractors, consulting firms, law firms, or
other third parties who are engaged to support residential mortgage loan
servicing, Loss Mitigation, or foreclosure activities or operations, including
their compliance with the Legal Requirements and BAC’s internal policies
A.1 Audit Committee receives periodic updates on vendor management.
and procedures, consistent with supervisory guidance of the Board of
Governors.

B. Completed Action Steps

B.1 BAC’s programs and processes for selecting, managing, and providing risk oversight to third party vendors are undergoing enhancements. The changes affecting third party service
providers in the residential mortgage business include:
• Expanding the scope of third party suppliers and processes managed centrally, promoting consistent risk-based vendor management as well as clear standards and accountabilities for all
outsourced business processes – including oversight of operational, compliance, and reputational risk;
• Expanding the responsibilities of the control environment – enhanced risk tolerances, monitoring, testing, and consequence-based control and escalation processes;
• Addressing consumer-specific vendor issues raised in the HL business and the LAS business of the Bank and under the Order;
• Enhancing further procedures for vendors to adhere to the Bank’s policies;
• Executing new complaints processes and procedures that include training materials for suppliers, standards for suppliers on how to handle complaints, complaint escalation procedures and
inspection routines to ensure compliance to new complaints procedures;
• Implementing new business continuity standards for key vendors; and
• Enhancing the Attorney Network Firm Management program.
B 2 Risk Management oversight of third party service providers is also being enhanced in HL and LAS Risk, including, in furtherance of the guidance outlined in the Risk Framework
Documents, the implementation of a comprehensive third-party management policy.

B 3 At each regular meeting of the Audit Committee since the Order was issued, the General Corporate Auditor has reported on vendor management issues. The Global Compliance
Executive reports to the Audit Committee on vendor related compliance risks, summary materials related to continued monitoring and testing regarding vendor management, and actions to
sustain vendor assessment and remediation efforts.
C. Remaining Action Steps

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000956

Confidential

BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 2. Board Oversight

Requirement

Action Steps

C.1 As remediation efforts continue to make significant changes in the mortgage servicing vendor management, it may be necessary for more targeted reporting to the Board on status,
progress, and emerging issues.

A. Existing and Ongoing Practices
4. Staffing Enhancements to ERM, Steps to ensure that BAC’s ERM, audit, and compliance programs have
adequate levels and types of officers and staff dedicated to overseeing the
Compliance, and Internal Audit
Bank’s residential mortgage loan servicing, Loss Mitigation, and foreclosure
activities, and that these programs have officers and staff with the requisite
qualifications, skills, and ability to comply with the requirements of this
A.1 In its independent role the Audit Committee receives regular updates on Audit staffing to ensure it is sufficiently staffed and has the capacity to access additional skills and resources when
Order.
necessary. This role includes review and approval of Audit's annual budget and the periodic approval of additional resources when required.
B. Completed Action Steps

B.1 At each regular meeting of the Audit Committee since the Order was issued, the General Corporate Auditor has reported on Internal Audit staffing and resource allocation, including cosourcing and staffing and talent development. Similarly, the Global Compliance Executive reports to the Audit Committee on regulatory matters related to staffing and recently began
discussing the staffing allocations for the Compliance organization.

B 2 The Audit Committee also receives periodic updates on staffing for Compliance.

C. Remaining Action Steps

C.1 Beginning in 2012 the Enterprise Risk Committee will receive regular updates on the staffing for Risk.

5. Board Reports

Steps to improve the information and reports that will be regularly reviewed A. Existing and Ongoing Practices
by the board of directors or authorized committee of the board of directors
regarding residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities and operations, including compliance risk assessments
and the status and results of measures taken, or to be taken, to remediate A.1 Enhancements of management reports to the Board and at the committee level also increased in 2009 with the following developments. The Board and each committee began to use a
deficiencies in residential mortgage loan servicing, Loss Mitigation, and
secure online portal for more timely delivery of reports and meeting packages to each director. The portal enables quick and secure review of materials by directors from any location at which
foreclosure activities, and to comply with this Order.
they have internet access. Use of the portal also increases transparency among the committees because each committee’s materials are available for review by all directors. This level of
access promotes, in particular, a holistic view of all risks facing the enterprise across the Audit, Credit and Enterprise Risk Committees.

A 2 The approach in Board and committee reporting of including an executive summary, a more detailed set of materials, and a full set of back-up data has been applied consistently across
committees with continued efforts at clarity and transparency of information presented. This common framework and consistency make information more user-friendly for the directors and
facilitates more productive discussion in Board and committee meetings.
B. Completed Action Steps

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000957

Confidential

BANK OF AMERICA CORPORATION
Paragraph 2. Plan to Strengthen Board Oversight
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 2. Board Oversight

Requirement

Action Steps

B.1 In March 2011, the Board constituted a subcommittee of the Enterprise Risk Committee (the “Compliance Committee”) to oversee the Order and designated a management advisor to
support directly the directors’ ongoing work under the Order and to coordinate the responsibilities of Bank of America management in this area. The Compliance Committee meets at least
monthly, and the special advisor and his team, working with Internal Audit and key businesses, are tracking and validating the implementation of action steps. Since its inception, the
Compliance Committee has met regularly and at least monthly.
B 2 To ensure reporting transparency of the actions undertaken by the Compliance Committee, all of its meetings are open to attendance by the full Board. Notices of the meetings are sent to
all directors at least a week in advance of the meeting to enable them to arrange to attend. Director participation of non-members of the Compliance Committee has occurred. Additionally,
the materials for the meetings of the Compliance Committee are distributed through the online portal described above, so that all directors are made aware of their availability and can review
their content whether they choose to attend the Compliance Committee meetings or not. Compliance Committee materials employ the consistent approach of including an executive
summary, a more detailed set of materials, and a full set of back-up data used with other Board reporting.
The chairman of the Compliance Committee makes reports of the Compliance Committee at each regular meeting of the Enterprise Risk Committee and the full Board. In addition to these
reports of the Compliance Committee activities, management has enhanced its reporting more generally on matters related to consumer real estate services.
B 3 As appropriate, the Credit Committee has requested reports on issues particular to its risk management oversight that arise in the consumer real estate services business. The Credit
Committee, the Enterprise Risk Committee and the full Board leverage the summary risk reporting routine as a consistent means to remain updated on the current risk environment and
trends.
B.4 To improve reporting to the Board overall, the online portal for electronic information delivery was updated to an enhanced version of the delivery application, and transition to this platform
commenced in October 2011.

C. Remaining Action Steps

C.1 Overall, reports which the Board currently receives are thorough, comprehensive and clear. Information has been appropriately summarized for effective decision-making. Consideration
should be given to the reporting of current and emerging risks to ensure these topics are featured in the executive summaries. Where appropriate, reports should identify future actions
expected from the Board and timelines to ensure adequate engagement in advance of key decisions.
C.2 The Board also should consider whether the current approach to reporting of risk levels against the risk appetite adequately highlights remediation efforts to either bring risk levels within
established limits or realign risk appetite to accommodate heightened risk environments.
C.3 As remediation efforts continue to make significant changes in the mortgage servicing business, it may be necessary for more targeted reporting to the Board on status, progress, and
emerging issues.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000958

Confidential

APPENDIX 1
Bank of America Corporation

Plan to Strengthen Board Oversight Submission, Dated July 12, 2011
Pursuant to
Paragraph 2 of the Consent Order of the Board of Governors of the Federal Reserve System,
Dated April 13, 2011.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000789



Plan to Strengthen Board Oversight
Confidential

Plan to Strengthen Board Oversight
Introduction
This Plan to Strengthen Board Oversight of the Bank of America Corporation (“BAC”), is developed
pursuant to the provision of Paragraph 2 of the Consent Order No. 11-029-B-HC of the Board of
Governors of the Federal Board System (the “Federal Reserve”), dated April 13, 2011 (the “Order”). It
describes the action steps by which the Board will strengthen its oversight of BAC’s enterprise-wide risk
management (“ERM”), internal audit, and compliance programs concerning the residential mortgage loan
servicing, Loss Mitigation, and foreclosure activities conducted through Bank of America, N.A. (the
“Bank”).
In developing this Plan, the Board’s goal is to build on the work of earlier remediation efforts and find
opportunities to enhance further processes for effective oversight. Under remediation efforts, beginning
in 2009, the Board undertook broad-reaching steps to strengthen its composition, restructure its
committees, charters, and governance processes. Further, we implemented material improvements to
our oversight by revamping management reporting to the Board, adopting a Global Risk Management
Framework (“Risk Framework”), and strengthening our internal control functions. We believe that, as a
result of enhancements over the past several years, the current Board oversight framework is effective.
Nevertheless, we engaged Promontory Financial Group, LLC (“Promontory”) to conduct an independent
assessment of ERM, Compliance, and Internal Audit programs concerning our residential mortgage
business, as well as our oversight of those control functions. Promontory considered our oversight of
ERM, Compliance, and Audit in the mortgage business to be largely sound and recommended two areas
for improvement. Specifically, we face a critical need in staffing our ERM and Compliance functions and
our management reports to the Board on mortgage servicing could be improved. We have included
efforts to implement those recommendations in this Plan.
The Plan also addresses those elements required by the Order: (a) polices to be adopted by the Board to
ensure that the ERM program provides proper risk management oversight; (b) policies and procedures to
ensure proper risk management of third party suppliers engaged with residential mortgage servicing and
foreclosure activities; (c) staffing of ERM, Compliance and Internal Audit resources; and (d) reports to the
Board regarding the Bank’s residential mortgage servicing business and foreclosure activities.
It is our goal to implement these actions promptly and effectively in order to achieve and maintain a
robust internal control system over the consolidated organization. We believe that the actions required by
the Plan will contribute materially to safe, sound, and compliant operations in our residential mortgage
business.
Paragraph 2 Requirements
Within 60 days of this Order, the board of directors shall submit to the Reserve Bank a written plan to
strengthen the board’s oversight of BAC’s ERM, internal audit, and compliance programs concerning the
residential mortgage loan servicing, Loss Mitigation, and foreclosure activities conducted through the
Bank. The plan shall, at a minimum, address, consider, and include:
(a) Policies to be adopted by the board of directors that are designed to ensure that the ERM
program provides proper risk management oversight with respect to the Bank’s residential
mortgage loan servicing, Loss Mitigation, and foreclosure activities, particularly with respect to
compliance with the Legal Requirements, and supervisory standards and guidance of the Board
of Governors as they develop;


Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1
BAC Consent Order Submission 0000790

Plan to Strengthen Board Oversight
Confidential

(b) policies and procedures to ensure that the ERM program provides proper risk management of
independent contractors, consulting firms, law firms, or other third parties who are engaged to
support residential mortgage loan servicing, Loss Mitigation, or foreclosure activities or
operations, including their compliance with the Legal Requirements and BAC’s internal policies
and procedures, consistent with supervisory guidance of the Board of Governors;
(c) steps to ensure that BAC’s ERM, audit, and compliance programs have adequate levels and
types of officers and staff dedicated to overseeing the Bank’s residential mortgage loan servicing,
Loss Mitigation, and foreclosure activities, and that these programs have officers and staff with
the requisite qualifications, skills, and ability to comply with the requirements of this Order; and
(d) steps to improve the information and reports that will be regularly reviewed by the board of
directors or authorized committee of the board of directors regarding residential mortgage loan
servicing, Loss Mitigation, and foreclosure activities and operations, including compliance risk
assessments and the status and results of measures taken, or to be taken, to remediate
deficiencies in residential mortgage loan servicing, Loss Mitigation, and foreclosure activities, and
to comply with this Order.
Summary of Current State
Promontory concluded that the Board’s remediation efforts beginning in 2009 have formed a strong
foundation for the Board to exercise its oversight responsibilities in a systematic and comprehensive
manner. The adoption of the Risk Framework has sufficiently strengthened its ERM program and
provided definitive guidance in identifying, measuring, mitigating, and reporting risks through the
enterprise. As a result, the Plan currently does not contemplate enhancements to the Risk Framework.
Nonetheless, the Board in determining to do everything in its power to ensure appropriate risk
management oversight in residential mortgage servicing is committed to adopting an overarching policy
providing its guidance for the engagement of risk management in mortgage serving activities. Further,
the Board also is committed to ensuring that it is appropriately organized to determine if the Compliance
and Risk Management functions are operating in a manner conducive to determining not only the
operation but also the effectiveness of the functions in the residential mortgage servicing, loss mitigation
and default servicing area.
Particular to Promontory’s evaluation of the Board’s oversight under the Order, Promontory identified that:
Enterprise Risk Management Oversight
x

BAC’s programs and processes for selecting, managing, and providing risk oversight to third
party vendors are undergoing material revision. The changes affecting third party service
providers in the residential mortgage business include:
o

Expanding the scope of third party suppliers and processes managed within the Global
Sourcing Program, promoting consistent risk-based vendor management as well as clear
standards and accountabilities for all outsourced business processes – including oversight of
operational, compliance, and reputational risk;

o

Expanding the responsibilities of the control environment – enhanced risk tolerances,
monitoring, testing, and consequence-based control and escalation processes;

o

Addressing consumer-specific vendor issues raised in the Home Loans business (“HL”)




Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

2

BAC Consent Order Submission 0000791

Plan to Strengthen Board Oversight
Confidential

Legacy Asset Servicing (“LAS”) business of the Bank and Consent Orders;

x

x

o

Enhancing further procedures for vendors to adhere to the Bank’s document retention and
return policies so that legally significant documents are subject to document custody and
retention policies;

o

Executing new complaints processes and procedures that include training materials for
suppliers, standards for suppliers on how to handle complaints, complaint escalation
procedures and inspection routines to ensure compliance to new complaints procedures;

o

Implementing new business continuity standards for MERS; and

o

Enhancing materially the Attorney Network Firm Management program.

Risk Management oversight of third party service providers is also being strengthened in HL and
LAS Risk, including:
o

Implementing a new supplier management policy;

o

Building an on-site vendor inspection program; and

o

Monitoring and testing HL’s and LAS’ oversight programs to ensure that they:
ƒ

Manage the scorecard effectively (require improvements as appropriate);

ƒ

Execute their own on-site inspection programs;

ƒ

Select and onboard vendors appropriately; and

ƒ

Properly update and maintain their procedures.

Recognizing the risks in mortgage servicing and the need to enhance oversight and document
policies and procedures in this area Compliance and Risk, in consultation with HL and LAS, identified
12 policies to develop and/or enhance to conduct, oversee, and monitor mortgage servicing, Loss
Mitigation, and foreclosure operations. In March 2011, the Bank developed a single Integrated
Foreclosure Policy covering all foreclosure-related activities at LAS and, in June 2011 developed 11
other HL and LAS policies to meet the requirements of the Order relating to mortgage servicing and
Loss Mitigation.

Control Function Staffing
x

Compliance and Risk need additional focus and reporting on staff forecasting tied to strategic
goals and business objectives for determining appropriate staffing resources that help them
produce comprehensive staffing plans, which can keep pace with the volume of change in the
industry and can be periodically shared with the appropriate oversight committee.

x

The Internal Audit’s professional staff has particular strengths and acumen. Generally, the
Internal Audit staff has a reasonable level of education and industry experience to perform their
duties in mortgage loan servicing, Loss Mitigation, and foreclosure activities. It is sufficiently




Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

3

BAC Consent Order Submission 0000792

Plan to Strengthen Board Oversight
Confidential

staffed and has capability to access additional resources when necessary. HL and LAS Audit has
104 professional staff. The core HL and LAS team averages 13 years in the banking industry, 9
years in auditing, 6 years at BAC, and 2.5 years in BAC audit. Of the 104 staff, 46 self-report
having one or more professional certifications. Additionally, 20 of the 104 staff are dedicated to
audit high risk activities of default servicing, loan modification, loss mitigation, and real estate
owned (“REO”) management. HL and LAS Audit has increased resources considerably since
2007,

x

The Internal Audit function has effective and strong oversight by the Audit Committee.

x

In contrast to Internal Audit’s staffing, despite material recent additions to ERM staff, current risk
conditions in HL and LAS are straining existing resources. HL and LAS Risk has a current total of
165 professionals with a target population of 236 persons by year-end 2011 (increasing by more
than 30 percent).
The team has expertise in change management,
regulatory supervision and various types of risks including market, credit and operational risk in
mortgage servicing.

x

The HL and LAS Compliance staff will also need to be enhanced. It currently has 214 full-time
equivalents with a goal to increase its staffing to 308 persons by year-end 2011 (increasing by
more than 40 percent).
Its recent expansion of staff has been extensive onboarding
persons from seven different financial institutions and ranges of backgrounds including regulatory
relations, six sigma, and project and issues management.

Board Reporting
x

Overall, reports which the Board currently receives appeared thorough, comprehensive and clear.
Information appeared appropriately summarized for effective decision-making. Promontory found
that there were some differences in the reports that made some reports more informative than
others. For example, current and emerging risks were not always fully addressed in the reports
reviewed. Not all the reports reviewed addressed the analysis done to identify root cause of
issues identified or the underlying actions steps being taken to address the root cause.

x

Reporting of risk levels against Board-risk appetite does not highlight sufficiently remediation
efforts to either bring risk levels within established limits or realign risk appetite to accommodate
heightened risk environments. The compliance risk level has
its established risk
appetite for extended periods of time. Risk reduction options selected by management need to
align better compliance activities with Board guidance and direction.

x

As remediation efforts continue to make significant changes in the mortgage servicing business, it
may be necessary for more targeted reporting on status, progress, and emerging issues to be
reported to the Board.




Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

4

BAC Consent Order Submission 0000793

Plan to Strengthen Board Oversight
Confidential

We are confident that action steps we have recommended in the Plan to Strengthen Board Oversight
(attached as Appendix 1.1) will address noted deficiencies and substantially enhance oversight of the
control functions in the mortgage business. We recognize the significant effort, time, and resources
necessary to implement the Plan and to verify its consistency and rigor once implemented. As a result,
we plan on commissioning an independent validation and report on the progress of the Plan at the critical
junctures in this effort. Moreover, due to the sheer breath of developments that are underway across
ERM, Compliance, and Internal Audit and the potential for a lack of cohesive execution, we will perform a
review to identify duplications
and ensure successful achievement of the Board’s objective to
develop a strong and cohesive internal control framework.




Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

5

BAC Consent Order Submission 0000794

Confidential

Appendix 2.1

FRB Consent Order
BANK OF AMERICA CORPORATION
Paragraph 3. Plan to Enhance Enterprise-wide Risk Management Program
Action Steps
Status as of June 30, 2011 for July 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

Posted on 7/8/11 for the Compliance Committee

Final as of July 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000822

Confidential

BANK OF AMERICA CORPORATION
Paragraph 3. Plan to Enhance Enterprise-wide Risk Management Program
FRB Consent Order Effective April 13, 2011
Area
Requirement
Paragraph 3. Risk Management Program

Identify and Measure

Monitor and Test

Action Steps

1.1 Develop and implement an Operational Risk Coverage Model that results in comprehensive and consistent Risk coverage to Servicing which includes:
- A technology platform to support the model that includes analytical tools and data repositories
- An ongoing risk assessment process
- The identification of key controls requiring Risk oversight
- A process to assess the adequacy of Risk coverage (defined as monitoring, testing and general oversight)
- A testing environment including results repository
- Comprehensive, independent Risk reporting that is based upon accurate and timely data

a. Monitoring reports are continuously produced and distributed 1.2 Complete the build-out of the testing program for Servicing:
to appropriate management levels to prompt action when
- Complete the build-out of the centralized testing team
needed.
- Evaluate off-shore opportunities to improve efficiency and compress cycle times
- Design LOB Risk team testing in coordination with the centralized team
b. Program assessments are performed by Global Risk
- Develop procedures to periodically re-evaluate testing priorities
Management and Enterprise Control Functions to assure that
risk management programs (e.g., Compliance Program
Assessment) are implemented correctly within the Lines of
Business.

Executive
Owner

Status

Target Date

In Process

12/31/11

In Process

12/31/11

In Process

12/31/11

In Process

09/30/11

In Process

09/30/11

In Process

10/30/11

In Process

12/31/11

c. Independent control assessments are performed by Line of
Business Risk Teams. Corporate Audit independently tests
control and mitigation plans according to a prioritized, riskbased schedule.
Mitigate and Control

a. Risk limits and controls are established and communicated
through policies, standards and procedures that define
responsibility and authority for risk taking. Such processes
include a well-defined escalation process and risk response
plan.
b. Policies and procedures are developed in accordance with
the Company’s Policy Framework to address key risk issues
and provide the appropriate boundaries and control
environment for the Lines of Business and Enterprise Control
Functions to conduct their daily activities.
c. Written policies and procedures are updated on a regular
b
i and
d provide
id clear
l
di
i to associates
i
f meeting
i the
h
basis
direction
for
control requirements for which they are accountable.
d. The governance and control function designs and
implements a system of controls and supervision routines to
ensure business activities are conducted within the boundaries
of stated limits and policies.
e. Associate training and awareness is required to assure all
associates understand their job duties and risk management
responsibilities. Lines of Business and Enterprise Control
Functions are responsible for ensuring that associates meet
training requirements in a timely manner.

Report & Review

1.3 Develop and implement comprehensive Policies for HL and LAS:
- Develop a prioritization of required Policies
- Create a schedule for Policy implementation
- Design, document and implement a Policy maintenance process
1.4 Develop and implement training and a culture of Risk independence for the Servicing environment.
- Include Risk Framework ongoing training for Risk and the Servicing LOB organization.
- Include ongoing communication with the Servicing LOB organization.
- Include education on role clarity – between Risk, Compliance, Quality Control, LOB.
1.5 Complete an analysis to determine staffing needs for Risk for Servicing including staff size and skill sets:
- Include an assessment of desired Risk locations
1.6 Develop a comprehensive on-boarding program for Risk associates

a. Appropriate metrics to measure risk and performance are in 1.7 Focus Risk feedback on LOB management performance on compliance with the Risk Framework:
place and reported to senior management on a timely basis.
- Focus feedback on demonstrated performance in reducing risk in the organization (via Risk Reduction Plans)
b. Risks and issues are reported to appropriate levels of
management in a timely manner and in accordance with the
level of operational risks.
c. Reports that are required to be filed with regulators are
accurate, complete and filed in a timely manner.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1

Final as of July12, 2011

BAC Consent Order Submission 0000823

Confidential

Appendix 2.1

FRB Consent Order (the "Order")
BANK OF AMERICA CORPORATION
Paragraph 3. Plan to Enhance Enterprise-wide Risk Management Program Action Steps

Action Plan as of November 30, 2011 for December 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

The Plan and the corresponding action steps do not describe all the core elements of BAC’s Enterprise-wide Risk
Management ("ERM") program with respect to its oversight of residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities and operations. Prior to the issuance of the Order, BAC had made significant progress in
enhancing its ERM program over these activities and operations in accordance with supervisory guidance and
expectations. As required by the Order, the Plan was based on an evaluation of the effectiveness of the ERM program,
which was completed in May 2011. Action steps presented in Appendix 2.1 reflect activity as of November 30, 2011. The
action steps in the Plan are supplemental to the enhancements BAC had already implemented or had begun
implementing and contribute to safe, sound, and compliant residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities and operations.

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000959

Confidential

BANK OF AMERICA CORPORATION
Paragraph 3. Plan to Enhance Enterprise-wide Risk Management Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 3. Risk Management Program

1. Risk Management Program
Fundamental Elements

Requirement

Ensure that the fundamental elements of the risk management program
and any enhancements or revisions thereto, including a comprehensive
annual risk assessment, encompass residential mortgage loan servicing,
Loss Mitigation, and foreclosure activities.

Action Steps

A. Existing and Ongoing Practices

A.1 The Board-approved Bank of America Corporation (BAC) Risk Management Framework articulates the bank's risk management goals. The Framework:
• States the Board’s desire to maintain a strong and comprehensive risk management culture as well as governance and controls to implement that culture.
• Informs all employees that they are responsible for understanding what risks impact BAC, are responsible for managing those risks, and ensuring an appropriate risk reward balance.
• Highlights the risks inherent in BAC’s businesses.
• Identifies the processes for managing risk.
• Describes the governance structure.
• Defines roles and accountabilities for the business and oversight functions.
A.2 The Risk Management Framework provides that Risk Management is responsible for developing business level policies.

A.3 The Risk Management Framework provides that Risk Management conducts risk assessments on the business activities it oversees.

A.4 As part of its implementation of the Risk Management Framework, Risk Management continues to enhance its risk coverage model to provide comprehensive and consistent risk coverage of
mortgage servicing.
A.5 As part of its implementation of the Risk Management Framework, Risk Management continues to enhance its monitoring and testing program to assess the effectiveness of business controls, and
compliance with policies, including satisfaction of actions required by the Order.
A.6 Management level committees provide oversight and monitor a broad range of topics.

A.7 Risk Management continues to provide risk training to employees and leaders.

B. Completed Action Steps

B.1 Risk Management worked with Compliance to enhance the governance framework for oversight of the mortgage business.

B.2 Risk Management enhanced the process for escalation of residential mortgage loan servicing, loss mitigation, and foreclosure activities topics to appropriate oversight committees.

B.3 The Risk Management group strengthened end-to-end coverage across risk functions.

B.4 Risk Management continues to provide risk training to employees and leaders and deployed a Risk learning plan which includes mandatory enterprise, compliance and new hire training.

B.5 A staffing assessment focused on mortgage servicing (mortgage loan servicing, loss mitigation, and foreclosure activities) was completed. The assessment included an analysis of staff size, skill sets,
and staff locations.
B.6 To provide enhanced guidance for mortgage servicing practices, Risk Management updated existing policies.

B.7 Risk Management deployed the initial version of a new technology platform to provide enhanced quality and consistency of execution of the risk coverage model that includes analytical tools and data
repositories. Development continues on the target state technology model.
B.8 Risk Management has enhanced key testing resources and infrastructure, implemented a new testing platform and launched a new monitoring platform.

C. Remaining Action Steps

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000960

Confidential

BANK OF AMERICA CORPORATION
Paragraph 3. Plan to Enhance Enterprise-wide Risk Management Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 3. Risk Management Program

Requirement

Action Steps

C.1 Risk Management continues to implement a process to assess its monitoring, testing, and general oversight or “coverage.”

C.2 Risk Management continues to enhance existing policies and implement new policies for the mortgage business.

See Risk Management Program Fundamental Elements Above for Existing Practices, Completed Action Steps, and Remaining Action Steps under this FRB Requirement.

2. Compliance with Supervisory
Guidance

Ensure that the risk management program complies with supervisory
guidance of the Board of Governors, including, but not limited to, guidance
entitled, “Compliance Risk Management Programs and Oversight at Large
Banking Organizations with Complex Compliance Profiles,” dated October
16, 2008.

3. Establish and Review Risk Limits

Establish limits for compliance, legal, and reputational risks and provide for A. Existing and Ongoing Practices
regular review of risk limits by appropriate senior management and the
board of directors or authorized committee of the board of directors.
A.1 Risk Management reports regularly on results compared to targets, tolerances, and limits as well as the business' risk culture.

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000961

Confidential

APPENDIX 2
Bank of America Corporation

Plan to Enhance Enterprise-wide Risk Management Program Submission, Dated July 12, 2011
Pursuant to
Paragraph 3 of the Consent Order of the Board of Governors of the Federal Reserve System,
Dated April 13, 2011.


Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


BAC Consent Order Submission 0000795

Plan to Enhance Enterprise-wide Risk Management Program
Confidential

Plan to Enhance Enterprise-wide Risk Management Program
Introduction
This Plan to Enhance Enterprise-wide Risk Management Program of the Bank of America Corporation
(“BAC”), is developed pursuant to the provision of Paragraph 3 of the Consent Order No. 11-029-B-HC of
the Board of Governors of the Federal Board System (the “Federal Reserve”), and dated April 13, 2011
(“the Order”). It describes the action steps and timeline by which BAC will enhance its enterprise-wide
risk management (“ERM”) program with respect to oversight of residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities and operations.
In 2009, BAC adopted the Global Risk Management, Risk Framework Document (“Risk Framework”).
The Risk Framework embodies BAC’s comprehensive approach to enterprise risk management and
constitutes BAC’s definitive risk policy statement at the enterprise level. The Risk Framework:
x

Highlights the risks inherent in the Company’s businesses;

x

Identifies the processes for managing risk;

x

Describes the risk governance structure;

x

Defines roles and accountabilities for the lines of business; and

x

Governance and Control Functions and Corporate Audit.

The Risk Framework satisfies the requirements for an effective risk management program as set forth in
CommitteeofSponsoringOrganizationsoftheTreadwayCommission’s (“COSO’s”) Enterprise Risk
Management – Integrated Framework; the guidance provided by the Federal Reserve Board Supervisory
Letter SR 08-08 on the need for effective firm-wide compliance risk management and oversight at large,
complex banking organizations; the Basel Committee’s Guidance on Risk Management Programs; and
other applicable regulatory directives. BAC intends to align the risk processes in its residential mortgage
business conducted through Bank of America, N.A., (the “Bank”) to its Risk Framework. This alignment
facilitates a consistent approach to the identification, assessment, control, monitoring and reporting of
risks arising in the mortgage business. Further, full implementation of the Risk Framework will enable
BAC to improve its oversight of residential mortgage servicing activities at the Bank.
The Order requires that the plan be based on an evaluation of the effectiveness of BAC’s current ERM
program. We engaged Promontory Financial Group, LLC (“Promontory”) to provide an independent
evaluation of the Risk Management Framework and of our risk program for residential mortgage loan
servicing, Loss Mitigation and foreclosure activities and operations as conducted through Home Loans
(“HL”) and Legacy Asset Servicing (“LAS”).
In the months preceding the Order and Promontory’s evaluation, we updated the Risk Framework (Fall
2010) and management in HL and LAS Risk Management self-identified a number of shortcomings in the
Risk Management function and program operating in residential mortgage servicing. Those shortcomings
led the Risk Management organization to develop a comprehensive Transformation Plan to align Risk
Management within HL and LAS with BAC’s Risk Framework.

The Risk Management Transformation Plan in HL and LAS has resulted in a number of enhancements to


Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1
BAC Consent Order Submission 0000796


Plan to Enhance Enterprise-wide Risk Management Program

Confidential



date, including a sizeable increase in Risk Management resources. The Transformation Plan
contemplates significant additional enhancements that are in process of implementation. This Plan builds
on the Risk Transformation Plan, already under way, supplemented by the additional recommendations
for improvement reflected in Promontory’s evaluation.
It is BAC’s goal to implement these actions promptly and effectively in order to achieve and maintain a
robust internal control system over the consolidated organization. We believe that the actions required by
the Plan will contribute materially to safe, sound and compliant operations in our residential mortgage
business.
Paragraph 3 Requirements
Within 60 days of this Order, BAC shall submit to the Reserve Bank an acceptable written plan to
enhance its ERM program with respect to its oversight of residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities and operations. The plan shall be based on an evaluation of the
effectiveness of BAC’s current ERM program in the areas of residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities and operations, and recommendations to strengthen the risk
management program in these areas. The plan shall, at a minimum, be designed to:
(a) Ensure that the fundamental elements of the risk management program and any enhancements
or revisions thereto, including a comprehensive annual risk assessment, encompass residential
mortgage loan servicing, Loss Mitigation, and foreclosure activities;
(b) Ensure that the risk management program complies with supervisory guidance of the Board of
Governors, including, but not limited to, guidance entitled, “Compliance Risk Management
Programs and Oversight at Large Banking Organizations with Complex Compliance Profiles,”
dated October 16, 2008 (SR 08-08/CA 08-11); and
(c) Establish limits for compliance, legal, and reputational risks and provide for regular review of risk
limits by appropriate senior management and the board of directors or authorized committee of
the board of directors.
Summary of Current State
Promontory’s evaluation reflects that implementation of the Risk Framework in HL and LAS is in the early
stages. Management in HL and LAS Risk identified, in the fourth quarter of 2010 that risk management
practices in the Home Loans business did not align fully with BAC’s Risk Framework and moved
aggressively to staff and build out the processes required by the Framework.
Implementation of the Risk Framework in the residential mortgage business will require an organizational
transformation of the Risk Management function during a period when the risk profile of the business is
severely elevated and both Risk Management and business management are attempting to satisfy a
large number of high priority regulatory requirements stemming from conditions in the business.
Promontory’s overall evaluation is that building out the Risk Management Program to the point where it is
fully effective is the appropriate goal for HL and LAS Risk management. Promontory’s evaluation also
notes that while HL and LAS Risk Management is moving aggressively to implement its Risk
Transformation Plan, much work remains. Among the high level observations and recommendations
emerging from Promontory’s evaluation are:

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


2



BAC Consent Order Submission 0000797


Plan to Enhance Enterprise-wide Risk Management Program

Confidential


High Level Observations: Risk Framework Implementation
x

Under the Risk Framework, the Risk Management function includes development on business
level policies, prescribing parameters under which business activities are to be conducted. At the
time of Promontory’s review, Risk Management had established a work stream under its Risk
Transformation Plan devoted to policy development. That work stream documented processes
for policy development by Risk Management.

x

The Risk Framework specifies that Risk Management should conduct risk assessments on the
business activities that it oversees.

x

The Risk Framework contemplates that the Risk Function will monitor and test the effectiveness
of business controls, compliance with policies, successful remediation of regulatory issues,
including satisfaction of actions required by consent orders. The number of consent order issues
at the time of Promontory’s review was crowding out other tests, reducing the value of tests as a
mechanism for gauging the effectiveness of risk management activities.

High Level Observations: Staffing
x

Many of the Risk Management staff who have worked in HL and LAS Risk Management for some
time are having to adjust
to the rigorous and independent
oversight and escalation of significant issues contemplated by the Risk Framework.

x

Promontory considers the more difficult challenge with staffing to be getting Risk Management
Staff with the qualifications to perform effectively. At a minimum, those qualifications include solid
knowledge of risk management principles and practices, understanding of Risk Management’s
role under the Risk Framework and knowledge of the business activities conducted in Home
Loans.

x

In a business as usual environment, orienting and developing new staff members can frequently
be accomplished without undue difficulty. Given the current risk profile of the mortgage servicing
activities in the Home Loans business, however, and the significant number of new Risk
Management Staff required, management faces a particularly significant challenge in fielding a
team whose members have the knowledge and stature necessary to perform risk management
oversight effectively.

We are confident that the actions steps we have developed in our Plan to Enhance Enterprise-wide Risk
Management Program (attached as Appendix 2.1) will address these noted deficiencies and
substantially enhance the risk management function within the mortgage business. We recognize the
significant effort, time, and resources necessary to implement our Plan and to verify its consistency and

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


3



BAC Consent Order Submission 0000798


Plan to Enhance Enterprise-wide Risk Management Program

Confidential



rigor once implemented. As a result, we plan on commissioning an independent validation and report on
the progress of the Plan at the critical junctures in this effort.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


4



BAC Consent Order Submission 0000799

Confidential

Appendix 3.1

FRB Consent Order
BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
Action Steps

Status as of June 30, 2011 for July 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approva

Posted on 7/8/11 for the Compliance Committee

Final as of July 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000829

Confidential
BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order Effective April 13, 2011
Area
Requirement
Paragraph 4. Compliance Program

1. Commitment and
Accountability

Governance processes are clear and in place, with the
appropriate structure, clear lines of authority and defined
escalation paths to manage significant compliance risk
and processes.
Compliance programs adhere to all enterprise operating
requirements and are maintained and updated at least
annually, but more frequently as needed to reflect the
current business environment.
Management consistently demonstrates commitment to
compliance through resource allocation and planning and
by ensuring that roles, responsibilities and
accountabilities are clear and enforced.

Action Steps

Executive
Owner

Status

Target Date

In Process

08/31/11

In Process

08/31/11

In Process

08/31/11

In Process

08/31/11

Completed

06/15/11

In Process

12/31/11

In Process

08/31/11

In Process

Semi Annual

In Process

9/31/11

In Process

08/01/11

I Process
In
P

09/12/11

3.1 Expand reporting on compliance risk to include a review of the effectiveness of the business controls assessed by HL/LAS Compliance through ongoing
testing and monitoring activities.

In Process

08/31/11

3.2 Develop guidelines for overriding calculated compliance risk levels when necessary to ensure ratings reported to senior management and the Board are
accurate.

In Process

08/01/11

In Process

12/31/11

In Process

12/31/11

In Process

08/31/11

In Process

12/31/11

In Process

09/01/11

In Process

09/01/11

In Process

12/01/11

1.1 Continue efforts to enhance the culture of compliance in HL and LAS, including business units and the compliance function.

1.2 Evaluate increasing the presence of the Compliance personnel in mortgage processing sites as a means of enhancing the compliance culture in those
locations.
1.3 Continue to emphasize the importance of independence as part of the transformation project to enhance and clarify compliance roles and responsibilities.

1.4 Monitor progress in transitioning all levels of compliance staff to strong independent oversight of compliance with rules and standards in the business
line.
1.5a Obtain final approval for the February identified Phase 3 staffing needs.

1.5b Increase staffing beyond Phase 3 request

1.6 Factor into HL/LAS Compliance staffing analyses: existing/emerging compliance issues in the business line; progress on the compliance transformation
plan; new inventory of legal requirements and related policies/procedures; ability to eliminate the compliance testing backlog and to expand testing to cover
preventive controls; and the need to align compliance risk levels with the Board’s risk appetite.
1.7 Perform a periodic staffing adequacy review and respond to identified gaps in a timely and appropriate manner.
1.8 Finalize the guidelines and process to reduce the level of overall (composite) compliance risk to the Board- approved level.

1.9 Define the criteria for issues that should be escalated directly to the Head of Global Compliance in a prompt manner and the process to be followed.

2. Policies and Procedures

3. Controls and Supervision

2.1 Formal compliance procedures to be developed for processes related to inventory and regulatory change management, monitoring, testing, risk
Compliance-specific policies and related procedures are
developed, approved, communicated and updated to reflect the assessment, governance & reporting, training, and issues management.
current business and regulatory environment and emerging
compliance risks.
All policies and procedures include appropriate compliance
requirements and are easily accessible to associates.

Controls to mitigate compliance risks are in place and are
enhanced as necessary. A compliance risk assessment
process, considering both inherent risk and mitigating controls,
is in place to identify and evaluate both existing and emerging
compliance risks.
Compliance risks and issues are documented, updated,
aggregated and tracked, including accountabilities, to ensure
timely resolution.

3.3 Enhance KRIs used by HL/LAS to calculate the HL/LAS Compliance Composite Score.

3.4 Enhance HL/LAS Specific KRIs to calculate Compliance Key Risk Indicators including the severity of testing exceptions and adequacy of controls.

3.5 Review list of regulations listed in the enterprise risk assessment against the inventory of Legal Requirements held within HL/LAS; adjust as needed.

3.6 Assess controls across the business processes and determine residual risks at a process and rule level; report in line with step 3.1 of this Enhancement
Plan.
3.7 The Board should take steps to better align its compliance risk appetite with current and expected levels of compliance risk in the residential mortgage
business. The material changes in the compliance landscape affecting residential mortgage activities may warrant consideration of a temporary increase in
the compliance risk appetite. The Board and management should also consider interim risk reduction options and increases to risk monitoring, pending
completion of the compliance transformation plan.
3.8 The Board should provide direction to management when risk conditions exceed its established risk appetite for more than a temporary period. Consider
establishing guidelines for permissible periods and circumstances when risk conditions may temporarily exceed the Board’s established risk appetite.

3.9 The Board should review an annual comprehensive compliance risk assessment.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1

Final as of July 12, 2011
BAC Consent Order Submission 0000830

Confidential
BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order Effective April 13, 2011
Area
4. Regulatory Oversight

Requirement

Action Steps

Executive
Owner

Status

Target Date

In Process

08/31/11

In Process

08/31/11

In Process

12/31/11

In Process

08/31/11

In Process

08/31/11

In Process

08/31/11

In Process

08/31/11

In Process

09/12/11

In Process

08/01/11

In Process

08/31/11

In Process

08/31/11

In Process

08/31/11

In Process

08/01/11

5.3 Develop a process for escalating significant testing and monitoring findings directly to the HL Compliance Executive and the appropriate governance
channel in a timely manner.

In Process

08/01/11

5.4 Develop a methodology for determining testing to be included in the Annual Compliance Testing Plan considering inherent risk of the regulations;
effectiveness of controls; and other risk-related information reported in the State of Compliance Report.

In Process

08/01/11

In Process

09/30/11

In Process

08/31/11

In Process

08/01/11

A risk-ranked inventory of applicable rules and standards is
4.1 Reconcile the criteria and process proposed for the HL/LAS inventory of Legal Requirements to the enterprise-wide requirements.
maintained and reflects the current business environment.
Proposed and final regulatory changes and emerging
compliance risks are identified, appropriately addressed and
4.2 Finalize the criteria/process for risk ranking the Legal Requirements ensuring that the risk ranking is updated periodically or when significant changes
communicated to associates as appropriate.
Management meets with regulators and provides accurate and occur in the rating criteria.
timely information requested as part of ongoing supervision,
examinations or investigations.
4.3 Validate that models/system used in the risk ranking of individual Legal Requirements, as applicable, operate as intended.

4.4 Revise the compliance risk assessment process/methodology to reflect the expanded inventory of Legal Requirements.

4.5 Evaluate the “downstream” impact of the significant number of Legal Requirements, e.g., creation/revision of policies and procedures, expansion of the
compliance testing plan, creation/revision of testing scripts, performing compliance risk assessments, training, etc. Adjust staffing budget (discussed in
paragraph 3.4.2 above) to ensure that the number and skill sets of staff are adequate for this significant undertaking. The compliance risk assessment
process should contemplate levels of testing for the compliance-testing group, especially as it relates to change management processes.
4.6 Finalize the project to connect regulatory change management to the inventory of rules and standards.

4.7 Identify steps to accelerate the establishment of controls, and subsequent validation, to ensure timely compliance of regulatory changes. Include specific
steps to be taken when readiness is not achieved by the effective date of the regulatory change.
4.8 Establish a process to ensure that vendors comply with regulatory changes, as applicable.

4.9 Ensure the HL and LAS Compliance Officers understand the applicable Rules and Standards for the LOB to which they are aligned and oversee
compliance risk management with respect to Rules and Standards.
4.10 Create and enhance one common inventory of rules and standards; including all sources outside of private investor requirements.

4.11 Map the LOB core processes to the inventory or rules.

5. Monitoring and Testing

Monitoring and testing activities are mapped to rules and
standards, Compliance Risk Categories and policies.
Compliance program owners manage monitoring and testing
activities to determine adherence to applicable rules and
standards and related policies and mitigate identified risks.
Compliance monitoring and testing activities are reviewed and
updated at least annually to address business and regulatory
changes and emerging risks and to reflect Compliance Risk
Assessment results.

5.1 Develop a process to perform ongoing compliance monitoring.

5.2 Develop a methodology to estimate the number of testing staff and management necessary to eliminate the testing backlogs, to cover an expanded
number of Legal Requirements, and to expand the testing plan to include testing of preventive controls in a timely manner. Include an assessment of the
skill sets needed to effectively perform testing of preventive controls.

5.5 Complete review of business controls in the lines of business to determine what monitoring/reporting and KPIs/KRIs are available for monitoring.

5.6 Assess current testing and monitoring coverage model to ensure thoroughness and effectiveness.

5.7 Align testing gap analysis to the enhanced inventory of rules and standard.

5.8 Align testing frequency to related monitoring plans.

6. Training and Awareness

Appropriate compliance requirements are included in annual
associate learning goals, training and communications.
Learning and communication needs are identified by evaluating
key compliance information, including compliance issues and
risks, regulatory changes, compliance policies and procedures,
monitoring and testing results

In Process

08/01/11

6.1 Consider appointing a position reporting directly to the HL/LAS Reporting and Governance Compliance Executive responsible for the overall coordination
and development of training consistent with requirements under the Global Compliance Program for line of business and Compliance training.

Completed

08/31/11

6.2 Assess the adequacy of personnel devoted to HL/LAS Compliance training considering impact of the HL/LAS Compliance transformation project,
expansion of Legal Requirements, and overall high risk environment.

In Process

08/01/11

In Process

08/31/11

In Process

10/31/11

6.3 Develop a compliance training policy/procedures for HL that fully complies with the Global Compliance Program training requirements.

6.4 Provide training metrics for the HL/LAS Compliance Score as reflected in the monthly State of Compliance Report.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

2

Final as of July 12, 2011
BAC Consent Order Submission 0000831

Confidential
BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order Effective April 13, 2011
Area

Requirement

Action Steps
6.5 Enhance the Regulatory Change Management processes to ensure timely training on the new requirements for applicable compliance and business line
personnel.

7. Reporting

Appropriate metrics to measure compliance risk and
performance are in place and reported to senior management
on a timely basis.
Compliance risks and issues are reported to appropriate levels
of management in a timely manner and in accordance with the
level of compliance risks.
Reports that are required to be filed with regulators are
accurate, complete and filed in a timely manner.

Executive
Owner

Status

Target Date

In Process

12/31/11

7.1 Management should present an annual comprehensive compliance risk assessment to the Board.
In Process

12/31/11

7.2 Management should consider expanding the quarterly report to the Audit Committee to include significant issues identified in the HL Compliance function
and progress toward fully satisfying the Global Compliance Program in HL/LAS.

In Process

12/31/11

7.3 Perform independent validation of Enhancement Plan and report status periodically to the Compliance Committee, subcommittee of the Board, until full
implementation of the Plan is achieved.

In Process

Ongoing

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

3

Final as of July 12, 2011
BAC Consent Order Submission 0000832

Confidential

Appendix 3.1

FRB Consent Order (the "Order")
BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program Action Steps

Action Plan as of November 30, 2011 for December 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

The Plan and the corresponding action steps do not describe all the core elements of BAC’s Enterprise-wide Compliance
Program with respect to its oversight of residential mortgage loan servicing, loss mitigation, and foreclosure activities and
operations. Prior to the issuance of the Order, BAC had made significant progress in enhancing its enterprise-wide
compliance program over these activities and operations in accordance with supervisory guidance and expectations. As
required by the Order, the Plan was based on an evaluation of the effectiveness of the enterprise-wide compliance
program, which was completed in May 2011. Action steps presented in Appendix 3.1 reflect activity as of November 30,
2011. The action steps in the Plan are supplemental to the enhancements BAC had already implemented or had begun
implementing and contribute to safe, sound, and compliant residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities and operations.

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000962

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

1. Fundamental Elements

Requirement

Action Steps

Ensure that the fundamental elements of the ECP and any enhancements A. Existing and Ongoing Practices
or revisions thereto, including a comprehensive annual risk assessment,
encompass residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities.
A.1 Global Compliance Program establishes an enterprise-wide standard for compliance monitoring and testing that meets regulatory expectations, defining operating requirements for
monitoring and testing. Monitoring and testing activities are mapped to rules and standards, Compliance risk categories and policies. Compliance program owners manage monitoring
and testing activities to determine adherence to applicable rules and standards and related policies that mitigate identified risks. Compliance monitoring and testing activities are
reviewed and updated at least annually to address business and regulatory changes and emerging risks and to reflect Compliance risk assessment results.
A 2 Global Compliance conducted a review of the compliance risk management program in HL/LAS and recommended enhancements. Resources were aligned to execute
enhancement plans defined.
A 3 HL/LAS Compliance, Risk and the Line of Business developed and continues to deploy the HL and LAS risk and control framework.

A.4 Lines of business and enterprise control functions are responsible for developing business-specific training based on business-specific regulatory requirements.

A 5 HL/LAS Compliance Executive reports directly to the Global Compliance Risk Executive.

A 6 Compliance and Risk develop policies for review and approval as part of the HL and LAS risk and control framework.

A.7 HL and LAS compliance maintain a compliance program document describing the risk and control framework under which HL and LAS operates and the specific operating
requirements for Compliance oversight in relation to the HL and LAS business units.
A 8 HL/LAS has in place a committee to review new products and manage reputational risk.

A 9 The HL/LAS risk and compliance governance was redefined in alignment with the enterprise risk framework and new/modified committee charters were completed.

A.10 Bank conducts the HL/LAS Compliance Risk Committee (chaired by the HL/LAS Compliance Executive) to oversee the HL/LAS compliance program, and associated processes,
and review (and escalate as required) significant compliance issues and risks affecting HL/LAS and decide disposition of escalated issues.
A.11 Governance committees overseeing compliance and operational risk related to the HL/LAS businesses are co-chaired by the HL/LAS Compliance Executive and HL/LAS
Operational Risk Executive. These committees report and escalate compliance and operational risk to Board level committees through the Bank's governance structure.

A.12 Management produces a monthly compliance risk report (state of compliance report) that reports the overall level of HL/LAS Compliance risk.

A.13 The HL/LAS state of compliance report and the HL and LAS Key Risk Indicators (KRIs) are presented monthly at the HL/LAS Compliance Risk Committee. Significant compliance
risks and KRIs exceeding established limits are escalated through governance routines.
A.14 Global Compliance Executive reports and escalates the KRIs through the compliance composite score to the Board and/or appropriate Board level committees.

A.15 Compliance employs monitoring and testing-based KRIs covering key regulatory areas. HL/LAS KRIs are reported in the HL/LAS compliance report on a monthly basis.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000963

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

Requirement

Action Steps

A.16 Compliance has partnered with Risk to ensure the use and continued development of risk reduction plans within HL and LAS for high risk thematic areas that require action and
remediation.
A.17 Senior management communicates the importance of compliance using a number of channels, e g., town halls, online forums, personnel training, virtual live sessions, and key
leadership meetings, including the CEO and his direct reports with their subordinates.
A.18 Management has emphasized that Compliance has ultimate authority on compliance-related matters.

A.19 HL/LAS Compliance Executive has the appropriate authority over personnel decisions affecting compliance management and staff. The HL/LAS Compliance executive is not
required to solicit input from the business on evaluating compliance staff and the Compliance function’s performance, the recruiting efforts, and compensation of Compliance staff and
management.
A 20 HL/LAS Compliance testing has a well-defined process for tracking and the validation of the resolution of compliance issues.

A 21 The Audit Committee, on behalf of the Board, reviews an enterprise-wide compliance risk report (which clearly identifies the compliance risk level for major business lines)
prepared by Global Compliance and presented by the Global Compliance Executive on a quarterly basis.
A 22 Global Compliance Program requires that training provide timely compliance information and relevant training to support personnel in effectively fulfilling their compliance
obligation.
A 23 Global Compliance has dedicated enterprise compliance training resources to develop and drive compliance training standards, requirements, and processes.

A 24 Processes for tracking of training requirements/attendance and training waivers are established by the Global Compliance Program.

B. Completed Action Steps

B.1 Enhancement of the culture of compliance in HL and LAS, including business units and the compliance function, has occurred.

B 2 Management has developed risk reduction plans and increased risk monitoring.

B 3 Board established a Compliance Committee, a subcommittee of the Enterprise Risk Committee consisting solely of independent directors, to monitor the actions and obligations of
the Bank under the OCC and FRB orders. The Compliance Committee meets at least monthly to review the status of compliance with the OCC and FRB orders.

B.4 Board increased its oversight of the Bank’s mortgage servicing practices, including more frequent reporting and review of supervisory Matters Requiring Attention (MRAs)
remediation activity at the Audit Committee.
B 5 Bank appointed a Special Advisor on Remediation Strategies to oversee and coordinate all aspects of the Bank’s Action Plans in response to the supervisory orders and to
provide independent, comprehensive actions plans, reports, and recommendations to management and to the Board.

B 6 Bank named a new Compliance Executive for HL and LAS.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000964

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

Requirement

Action Steps

B.7 Executive management announced the creation of a new function, Global Legal and Compliance, directly reporting to the CEO. The Global Compliance Executive reports directly
to the Global Legal and Compliance head.
B 8 HL/LAS Compliance named a new senior leader to manage the Rules and Standards Inventory.
B 9 Factored into HL/LAS Compliance staffing analyses: existing/emerging compliance issues in the business line; progress on the compliance transformation plan; inventory of legal
requirements and related policies/procedures; the expansion of compliance testing to cover preventive controls; and the alignment of compliance risk levels with the Board’s risk
appetite.
B.10 Obtained approval for identified staffing needs. Compliance initiated and executed phases of staffing additions since March 2011.

B.11 Processes established to perform a periodic staffing adequacy review and respond to identified needs in a timely and appropriate manner.

B.12 Evaluated the “downstream” impact of the significant number of Legal Requirements, e.g., creation/revision of policies and procedures, expansion of the compliance testing plan,
creation/revision of testing scripts, performing compliance risk assessments, training, etc. Adjust staffing budget to ensure that the number and skill sets of staff are adequate for this
significant undertaking. The compliance risk assessment process now contemplates levels of testing for the compliance-testing group, especially as it relates to change management
processes.
B.13 Developed a methodology to estimate the number of testing staff and management necessary to cover an expanded number of Legal Requirements, and to expand the testing
plan to include testing of preventive controls in a timely manner. Included an assessment of the skill sets needed to effectively perform testing of preventive controls.

B.14 Compliance enhanced job descriptions to highlight skills and experience needed for key roles in Compliance.

B.15 Continued to emphasize the importance of independence as part of the transformation project to enhance and clarify compliance roles and responsibilities.

B.16 Monitored progress in transitioning all levels of compliance staff to strong independent oversight of compliance with rules and standards in the business line.

B.17 HL/LAS Compliance established a centralized Compliance testing team, appointing an experienced team leader.

B.18 Compliance executed the semi-annual line of business Compliance risk assessment.

B.19 Developed guidelines for overriding calculated compliance risk levels and when necessary reporting to senior management.

B 20 Compliance management presents an annual comprehensive compliance risk assessment.

B 21 Enhanced KRIs used by HL/LAS to calculate the HL/LAS compliance composite score.

B 22 Provided training metrics for the HL/LAS compliance composite score as reflected in the monthly HL/LAS state of compliance report.

B 23 Completed review of business controls in the lines of business to determine what monitoring/reporting and KPIs/KRIs are available for monitoring.

B 24 Defined the criteria for issues that should be escalated to the Head of Global Compliance in a prompt manner and the process to be followed.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000965

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

Requirement

Action Steps

B 25 Expanded reporting on compliance risk to include a review of the effectiveness of the business controls assessed by HL/LAS Compliance through ongoing testing and monitoring
activities.
B 26 Reviewed list of regulations listed in the enterprise risk assessment against the inventory of Legal Requirements held within HL/LAS.

B 27 Enhanced the regulatory change management process to ensure timely training on the new requirements for applicable compliance and business line personnel.

B 28 Finalized the guidelines and process to reduce the level of overall (composite) compliance risk to the Board-approved level.

B 29 HL/LAS Compliance testing has enhanced the testing function by, among other things, developing an updated operating procedure manual and a methodology for determining
testing to be included in the Annual Compliance Testing Plan considering inherent risk of the regulations; effectiveness of controls; and other risk-related information reported in the
HL/LAS state of compliance report. Compliance has embedded this methodology within the revised Compliance testing procedures.

B 30 Aligned testing gap analysis to the enhanced inventory of rules and standards.

B 31 Developed a process to perform ongoing compliance monitoring.

B 32 Developed a process for escalating significant testing and monitoring findings directly to the HL/LAS Compliance Executive and the appropriate governance channel in a timely
manner.
B 33 Developed a compliance training policy/procedures for HL/LAS that fully complies with the Global Compliance Program training requirements.

B 34 Appointed a position reporting directly to the HL/LAS Reporting and Governance Compliance Executive responsible for the overall coordination and development of training
consistent with requirements under the Global Compliance Program for line of business and Compliance training.
B 35 Assessed the adequacy of personnel devoted to HL/LAS Compliance training considering impact of the HL/LAS Compliance transformation project, expansion of Legal
Requirements, and overall high risk environment.
B 36 Enhanced HL/LAS Specific KRIs to calculate Compliance key risk indicators including the severity of testing exceptions and adequacy of controls.

C. Remaining Action Steps

C.1 Management should consider expanding the quarterly report to the Audit Committee to include significant issues identified in the HL/LAS Compliance function and progress toward
fully satisfying the Global Compliance Program in HL/LAS.
C.2 Assess controls across the business processes and determine residual risks at a process and rule level.

C.3 Evaluate increasing the presence of the Compliance personnel in mortgage processing sites as a means of enhancing the compliance culture in those locations.

C.4 Assess current testing and monitoring coverage model to ensure thoroughness and effectiveness.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000966

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

Requirement

Action Steps

C.5 Align testing frequency to related monitoring plans.

C.6 Perform independent validation of Enhancement Plan and report status periodically to the Compliance Committee, subcommittee of the Board, until full implementation of the Plan
is achieved.
2. Compliance with Legal
Requirements and Supervisory
Guidance

Ensure compliance with the Legal Requirements and supervisory
guidance of the Board of Governors.

A. Existing and Ongoing Practices

A.1 Compliance has established processes for risk ranking the rules and standards inventory and developed enhanced regulatory change management processes and procedures.

B. Completed Action Steps

B.1 Compliance further developed the rules and standards inventory.

B 2 Created and enhanced one common inventory of rules and standards; including all sources outside of private investor requirements.

B 3 Reconciled the criteria and process proposed for the HL/LAS inventory of legal requirements to the enterprise-wide requirements.

B.4 Finalized the criteria/process for risk ranking the legal requirements ensuring that the risk ranking is updated periodically or when significant changes occur in the rating criteria.

B 5 Mapped the LOB core processes to the inventory of rules and standards.

B 6 Finalized the project to connect regulatory change management to the inventory of rules and standards.

B.7 Identified steps to accelerate the establishment of controls, and subsequent validation, to ensure timely compliance with regulatory changes. Include specific steps to be taken
when readiness is not achieved by the effective date of the regulatory change.
B 8 Technology investments made related to infrastructure supporting the rules and standards inventory and the regulatory change management process.

B 9 Ensured the HL and LAS Compliance Officers understand the applicable rules and standards for the LOB to which they are aligned and oversee compliance risk management with
respect to rules and standards.
B.10 Revised the compliance risk assessment process/methodology to reflect the expanded inventory of legal requirements.

C. Remaining Action Steps

C.1 Validate that models/system used in the risk ranking of individual Legal Requirements, as applicable, operate as intended.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000967

Confidential

BANK OF AMERICA CORPORATION
Paragraph 4. Plan to Enhance Enterprise-wide Compliance Program
FRB Consent Order (the "Order") Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 4. Compliance Program

3. Updating Policies, Procedures,
and Processes

Requirement

Ensure that policies, procedures, and processes are updated on an
ongoing basis as necessary to incorporate new or changes to the Legal
Requirements and supervisory guidance of the Board of Governors.

Action Steps

A. Existing and Ongoing Practices

A.1 Compliance partners with Legal and Public Policy to execute the regulatory change process.

A 2 Regulatory change management process includes monitoring and review activities and communications to affected personnel.

A 3 Key contacts representing each line of business or enterprise control function must ensure that regulatory change information is disseminated to the appropriate personnel and
that impacts are appropriately assessed and implemented.
B. Completed Action Steps

B.1 Compliance and Risk have approved and published enhanced mortgage servicing-related policies mapped to the rules and standards inventory and to business processes.

B 2 HL and LAS implemented enhanced procedures for regulatory change management, which outline the requirements for the rules and standards change process and its alignment
with the HL and LAS risk and control framework.
B 3 HL/LAS Compliance conducted employee readiness on the updated procedures for regulatory change management.

B.4 Formal compliance procedures developed for processes related to inventory and regulatory change management, monitoring, testing, risk assessment, governance & reporting,
training, and issues management.
B 5 Established a process to ensure that vendors comply with regulatory changes, as applicable.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000968

Confidential




APPENDIX 3
Bank of America Corporation

Plan to Enhance Enterprise-wide Compliance Program Submission, Dated July 12, 2011
Pursuant to
Paragraph 4 of the Consent Order of the Board of Governors of the Federal Reserve System,
Dated April 13, 2011.



Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000800

Plan to Enhance Enterprise-wide Compliance Program
Confidential



Plan to Enhance Enterprise-wide Compliance Program
Introduction
This Plan to Enhance Enterprise-wide Compliance Program of the Bank of America Corporation (“BAC”),
is developed pursuant to the provision of Paragraph 4 of the Consent Order No. 11-029-B-HC of the
Board of Governors of the Federal Board System (the “Federal Reserve”), dated April 13, 2011 (the
“Order”). It describes the action steps and timeline by which BAC will enhance its enterprise-wide
compliance program with respect to oversight of residential mortgage loan servicing, Loss Mitigation, and
foreclosure activities and operations.
After significant analysis and review, BAC is moving to enhance its current Global Compliance Program
with respect to residential mortgage loan servicing and related operations conducted through Bank of
America, N.A. (the “Bank”). BAC intends to align the Bank’s mortgage compliance processes, to its
Global Compliance Program, a component of BAC’s Global Risk Framework. The Risk Management
Framework mandates sound disciplines, proven effective in the management of risks, including: (1)
identify and measure; (2) mitigate and control; (3) monitor and test; and (4) report and review.
The Global Compliance Program establishes a common framework and expectation for compliance
across BAC. It consists of seven elements and 18 standard operating requirements. The seven
elements are:
x

Commitment and Accountability – sets “tone at the top” to drive a culture of compliance;

x

Policies and Procedures – outlines parameters of responsibilities;

x

Controls and Supervision – identify, assess and control compliance risks;

x

Regulatory Oversight – effectively manage regulatory environment and build constructive
regulatory relationships;

x

Monitoring and Testing – evaluates effectiveness of compliance controls in lines of business;

x

Training and Awareness – timely compliance information and relevant training; and

x

Reporting – robust, actionable and timely information to manage compliance risks.

Further, the Global Compliance Program satisfies the requirements for an effective compliance program
as set forth in the U.S. Federal Sentencing Guidelines; the guidance provided by the Federal Reserve
Board Supervisory Letter, SR 08-08 on the need for effective firm-wide compliance risk management and
oversight at large, complex banking organizations; the Basel Committee’s Guidance on Compliance
Programs; and other applicable regulatory directives. Aligning the Bank’s compliance in the mortgage
business to BAC’s Global Compliance Program will provide a comprehensive compliance risk
management process and facilitate a consistent approach to identify and measure, mitigate and control,
monitor and test and report and review mortgage servicing compliance risks. This alignment enhances
BAC’s Global Compliance Program in mortgage servicing and strengthens BAC’s’ oversight of the
program as well.
The Order provided that the plan be based on an evaluation of the effectiveness of BAC’s current
enterprise compliance program. We engaged Promontory Financial Group, LLC (“Promontory”) to assist

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


1



BAC Consent Order Submission 0000801

Plan to Enhance Enterprise-wide Compliance Program
Confidential



us in conducting and providing an independent evaluation of the Global Compliance Program and the
compliance program of the residential mortgage loan servicing, Loss Mitigation and foreclosure activities
and operations as conducted through Home Loans (“HL”) and Legacy Asset Servicing (“LAS”).
In the months preceding the Order and Promontory’s evaluation, management of BAC’s Compliance
organization self-identified a number of
in the Compliance function and program operating
in residential mortgage lending. Those
led the Compliance organization to develop a
comprehensive Compliance Transformation Plan to align the Bank’s mortgage business with BAC’s
Global Compliance Program and Standard Operating Requirements. The Compliance Transformation
Plan has resulted in a number of enhancements to date. This Plan required under the Order builds on
the Compliance Transformation Plan, already under way, supplemented by the additional
recommendations for improvement reflected in Promontory’s evaluation.
It is BAC’s goal to implement these actions promptly and effectively in order to achieve and maintain a
robust internal control system over the consolidated organization. We believe that the actions required by
the Compliance Plan will contribute to safe, sound and compliant operations in the residential mortgage
business.
Paragraph 4 Requirements
Within 60 days of this Order, BAC shall submit to the Reserve Bank an acceptable written plan to
enhance its enterprise-wide compliance program (“ECP”) with respect to its oversight of residential
mortgage loan servicing, Loss Mitigation, and foreclosure activities and operations. The plan shall be
based on an evaluation of the effectiveness of BAC’s current ECP in the areas of residential mortgage
loan servicing, Loss Mitigation, and foreclosure activities and operations, and recommendations to
strengthen the ECP in these areas. The plan shall, at a minimum, be designed to:
(a) Ensure that the fundamental elements of the ECP and any enhancements or revisions thereto,
including a comprehensive annual risk assessment, encompass residential mortgage loan
servicing, Loss Mitigation, and foreclosure activities;
(b) Ensure compliance with the Legal Requirements and supervisory guidance of the Board of
Governors; and
(c) Ensure that policies, procedures, and processes are updated on an ongoing basis as necessary
to incorporate new or changes to Legal Requirements and supervisory guidance of the Board of
Governors.

SummaryofCurrentState
Overall, Promontory found that the Bank’s compliance program and activities in mortgage servicing are
not yet mature and require additional build-out to fully implement the requirements of the Global
Compliance Program.
The
Compliance Transformation Plan of HL and LAS Compliance is designed to address weaknesses
identified and move the compliance program into alignment with the Global Compliance Program.
However, with the heightened risk environment, the relatively short time since the Compliance
Transformation Plan’s implementation, and the current level of resources, the Compliance Transformation

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


2



BAC Consent Order Submission 0000802

Plan to Enhance Enterprise-wide Compliance Program
Confidential



Plan has not yet produced a fully developed compliance program in the mortgage business. Accordingly,
Promontory noted the following: 
x

While the HL and LAS Compliance function has added to its staff in recent quarters, it remains
understaffed. Compliance personnel lack sufficient visibility within the HL and LAS organization
and require enhanced skills to execute the Global Compliance Program effectively amid
increased complexity in the regulatory environment. Compliance professionals need to have the
stature necessary to provide the independent oversight and monitoring of business activities
required.
o

Promontory identified that while Compliance management is adding resources; the number of
requested positions has been based on the professional judgment of the compliance officers
and is neither determined on a defined methodology/metrics nor tied to HL or LAS strategy.

o
Efforts to strengthen the team by hiring individuals with strong compliance and mortgage
servicing experience as well as upgrading the level of some of the positions are important
and necessary.
x

HL and LAS Compliance professionals require refresher and/or initiation training to reinstate the
appropriate role and meet the regulatory expectation of the independent nature of the compliance
function. Traces of legacy compliance “partnership” and compliance “consultative” roles are
evident in the current environment. Moreover, role clarity among Compliance, Risk and business
control functions needs to be enhanced.

x

Ownership of policies previously resided in the line of business and only recently was centralized
with Risk and Compliance with clear identified risk owners for each policy.

The Compliance staff faced further inefficiencies as many
policies and procedures involved manual applications, which are not only difficult to review, but
also introduce additional operational and compliance risk from human error. HL and LAS
Compliance management has developed significant processes in addressing these issues
including, initial inventory collection has been delivered and reviewed; policy control and business
process mapping activities are underway in an effort to align it to the inventory and detailed and
scheduled phases of actions commencing in February 2011 through the fourth quarter of 2011
with the finalization of the inventory, have begun. These are substantial efforts; however, formal
processes for mitigating interim risk may be needed for additional compliance assurance.
x

A Compliance risk assessment process is not fully developed. The HL and LAS Compliance
Executive and the HL and LAS Risk Executive are working together to define an effective risk
assessment process. HL and LAS Compliance management self-identified that compliance was
not proactively assessing risks in the business, nor were they resourced to do so.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


3



BAC Consent Order Submission 0000803

Plan to Enhance Enterprise-wide Compliance Program
Confidential


x

x

Current reporting should be enhanced to provide key risks and actions needed to remediate
compliance risks in HL and LAS. Where possible, reporting should also identify emerging trends
and regulatory flashpoints as well as identification of what weaknesses in the businesses are
driving the risks and what actions are needed to mitigate the risks. Further, compliance reporting
should address known weaknesses in the Compliance organization that pose threats to its ability
to perform the roles contemplated by the Global Compliance Program.

We are confident that the action steps we have developed in the Plan to Enhance the Enterprise-wide
Compliance Program (attached as Appendix 3.1) will address these noted deficiencies and substantially
enhance the compliance function within the mortgage business. We recognize the significant effort, time,
and resources necessary to implement the Plan and to verify its consistency and rigor once
implemented. As a result, we plan on commissioning an independent validation and report on the
progress of the Plan at the critical junctures in this effort. 


Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


4



BAC Consent Order Submission 0000804

Confidential

Appendix 4.1

FRB Consent Order
BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance Internal Audit Program
Action Steps

Status as of June 30, 2011 for July 12, 2011 Submission

Subject to Federal Reserve Board/Reserve Bank Review and Approval

Posted on 7/8/11 for the Compliance Committee

Final as of July 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000837

Confidential
BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance the Internal Audit Program
FRB Consent Order Effective April 13, 2011
Area
Paragraph 5. Internal Audit

1. Internal Audit Program of Residential
Mortgage Servicing

2. Periodic Compliance and Risk
Management Review

Requirement

Action Steps

Ensure that the internal audit program encompasses residential 1.1 Develop scopes and work programs for each of Audit’s responsibilities on the Work Detail and Accountability Chart.
mortgage loan servicing, Loss Mitigation, and foreclosure
activities;
1.2 In the Corporate Audit 2011 HL and LAS Audit Approach Playbook dated April 1, 2011, in the “Strategic Planning Session” phases, in the “Inputs” column
add:
- Regulatory Guidance
- All Issues relevant to the business in the OCC and FRB Consent Orders,
- MRAs and other issues being tracked relevant to the business to be audited,
- Lessons learned from the last audit performed and
- Particular attention to customer-facing activities.
Periodically review compliance with the effectiveness of the ECP 2.1 Develop the standards against which the Risk and Compliance programs will be evaluated and the procedures and testing that will form the basis for
conclusions. In this regard, we recommend that Audit develop procedures to determine whether the Risk and Compliance functions are meeting the
and ERM with respect to residential mortgage loan servicing,
Loss Mitigation, and foreclosure activities, and compliance with requirements in published regulatory guidance and expectations stated or implied in either the OCC or FRB Consent Order.
the Legal Requirements and supervisory guidance of the Board
of Governors;
2.2 Develop and document a methodology to perform interim evaluations of Risk Management and Compliance during their respective transformation
processes.

Executive
Owner

Status

Target Date

In Process

12/30/11

In Process

08/30/11

In Process

10/30/11

In Process

09/30/11

Not Started

10/30/11

Not Started

09/30/11

In Process

08/30/11

In Process

12/30/11

In Process

08/30/11

In Process

09/30/11

Not Started

10/30/11

Not Started

Ongoing

2.3 Conduct an independent validation of Internal Audit’s completion of corrective actions in response to OCC-identified deficiencies.

2.4 Evaluate and confirm the effectiveness of Internal Audit’s reviews of the Compliance and Risk Management functions in HL and LAS.

3. Adequate Qualified Audit Staff

4. Resolution of Internal Audit Findings

5. Comprehensive Documentation,
Tracking and Reporting

Ensure that adequate qualified staffing of the audit function is
3.1 Consider whether additional Audit staff should be dedicated to Default related activities. Ensure that the resources dedicated to Default related activities
provided for residential mortgage loan servicing, Loss Mitigation, grows proportionately to increases in the associated business activities.
and foreclosure activities;
3.2 Continue funding initiatives to automate testing to ensure coverage of the broad and constantly-changing universe of Legal requirements, and to permit
continuous monitoring to help drive audit planning. Continue to expand use of automation to identify more comprehensively and assess risk throughout the
business.

Ensure timely resolution of audit findings and follow-up reviews 4.1 Consider whether certain types of audit-related issues, including disagreements between audit staff and management concerning findings and
to ensure completion and effectiveness of corrective measures; recommendations, should be brought to the Enterprise Risk Committee for resolution.

Ensure timely resolution of audit findings and follow-up reviews 5.1 Consider augmenting the risk measuring methodology to incorporate the duration associated with identified risks.
to ensure completion and effectiveness of corrective measures;
5.2 Consider including in audit reports a summary of residual risks and the direction of risk i.e., decreasing, stable or increasing.

5.3 Perform independent validation of Enhancement Plans and report status periodically to the Audit Committee of the Board until full implementation of the Plan
is achieved.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

1

Final as of July 12, 2011
BAC Consent Order Submission 0000838

Confidential

Appendix 4.1

FRB Consent Order (the "Order")
BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance Internal Audit Program Action Steps

Action Plan as of November 30, 2011 for December 12, 2011 Submission
Subject to Federal Reserve Board/Reserve Bank Review and Approval

The Plan and the corresponding action steps do not describe all the core elements of BAC’s internal audit program with
respect to residential mortgage loan servicing, loss mitigation, and foreclosure activities and operations. Prior to the
issuance of the Order, BAC had made significant progress in enhancing its internal audit program over these activities
and operations in accordance with supervisory guidance and expectations. As required by the Order, the Plan was
based on an evaluation of the effectiveness of the internal audit program, which was completed in May 2011. The action
steps presented in Appendix 4.1 reflect activity as of November 30, 2011. The action steps in the Plan are supplemental
to the enhancements BAC had already implemented or had begun implementing and contribute to safe, sound, and
compliant residential mortgage loan servicing, Loss Mitigation, and foreclosure activities and operations.

Final as of December 12, 2011

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000969

Confidential

BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance the Internal Audit Program
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 5. Internal Audit

Requirement

Action Steps

1. Internal Audit Program
Ensure that the internal audit program encompasses residential mortgage A. Existing and Ongoing Practices
Encompasses Residential Mortgage loan servicing, loss mitigation, and foreclosure activities.
Servicing, Loss Mitigation, and
A.1 The Corporate General Auditor reports directly to the Audit Committee of the Board, which is responsible for:
Foreclosure Activities
• Approving the risk-based audit plan annually.
• Receiving communications from the General Auditor on Corporate Audit's performance relative to its plan and other matters.
• Approving decisions regarding the appointment and removal of the General Auditor.
• Making appropriate inquiries of management and the General Auditor.
A.2 Corporate Audit utilizes a risk-based approach to identify areas for Audit coverage including HL and LAS business activities and Enterprise Compliance/Enterprise Risk
Management areas (as they pertain to HL and LAS). Corporate Audit uses a Risk and Frequency Model to assess inherent risks, control effectiveness, and residual risks; the risk
assessment drives the frequency of audits and allocation of resources, resulting in an annual Audit plan that is updated quarterly.

B. Completed Action Steps
B.1 Foreclosure testing was expanded in 2011 to continuously test key foreclosure controls and loans identified through automated dashboards designed to proactively identify
foreclosure sale issues.
B.2 A comprehensive Corporate Audit Test Program was developed related to the Consent Orders. Testing has begun to validate foreclosure processes and activities related to
remediation of matters identified in the Orders.
B.3 Individual Audit Planning was enhanced in April 2011 to drive improved scoping of audits to consider strategic change, emerging risks, tail risks and reputation risk. Changes
include expanded planning sessions required for each audit and formalization of interviews with executives and Audit subject matter experts along with site visits prior to testing
decisions.
2. Review Compliance with the
Effectiveness of the ECP and ERM,
Legal Requirements, and
Supervisory Guidance

Periodically review compliance with the effectiveness of the ECP and
ERM with respect to residential mortgage loan servicing, loss mitigation,
and foreclosure activities, and compliance with the Legal Requirements
and supervisory guidance of the Board of Governors.

A. Existing and Ongoing Practices
A.1 Compliance and Risk functions will continue to be assessed as part of each audit. A section is included in the standard Audit report to address the effectiveness of these groups
in relation to the area under review.
B. Completed Action Steps

B.1 A dedicated team was established in March 2011 to provide coverage of transformation efforts in Risk Management and Compliance.

B.2 An ongoing approach was developed to evaluate the Risk Management and Compliance teams and their alignment with the Risk and Control Framework on a regular basis.

C. Remaining Action Steps
C.1 Conduct an independent validation of Internal Audit’s completion of corrective actions in response to OCC-identified deficiencies.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000970

Confidential

BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance the Internal Audit Program
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 5. Internal Audit

Requirement

Action Steps

C.2 Evaluate and confirm the effectiveness of Internal Audit’s reviews of Compliance and Risk Management functions.

3. Adequate Staffing

Ensure that adequate qualified staffing of the audit function is provided for A. Existing and Ongoing Practices
residential mortgage loan servicing, loss mitigation, and foreclosure
activities.
A.1 BAC’s Corporate Audit group includes specialized audit teams that align with major lines of business and conducts risk assessments, audit planning, audit testing, issue
identification and validation, issue escalation, and audit reporting of the businesses.

A.2 Corporate Audit conducts quarterly capacity planning to provide an ongoing evaluation of Audit’s staffing needs.
A.3 As needed, HL/LAS Audit may request additional resources from other audit groups and may engage external firms under co-sourcing agreements.

B. Completed Action Steps

B.1 Ensured that resources dedicated to Default related activities expanded proportionately to increases in the associated business activities.

B.2 The HL and LAS audit teams grew 70% from second quarter 2010, including additions of management positions, and effectively expanded coverage in the mortgage space.

C. Remaining Action Steps
C.1 Continue funding initiatives to automate testing to ensure coverage of the broad and evolving universe of Legal requirements and expand automation to provide more
comprehensive risk assessments/monitoring of the business.

4. Timely Resolution of Audit
Findings

Ensure timely resolution of audit findings and follow-up reviews to ensure
completion and effectiveness of corrective measures.

A. Existing and Ongoing Practices

A.1 BAC has an effective process for tracking progress of audit and regulatory issues. All issues are logged and tracked until corrective measures have been implemented, and
Internal Audit testing validates corrective measures are appropriate and sustainable.
A.2 Timely resolution of Audit issues is a part of the performance review process, and Audit provides input on the business managers’ control performance.

B. Completed Action Steps
B.1 The process was enhanced to escalate significant issues, including disagreements between audit staff and management concerning findings and recommendations, to the Audit
Committee for resolution.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000971

Confidential

BANK OF AMERICA CORPORATION
Paragraph 5. Plan to Enhance the Internal Audit Program
FRB Consent Order Effective April 13, 2011
Action Plan as of November 30, 2011 for December 12, 2011 Submission
Area
Paragraph 5. Internal Audit

Requirement

5. Documentation, Tracking, and
Ensure that comprehensive documentation, tracking, and reporting of the
Reporting of Status and Resolution status and resolution of audit findings are submitted to the audit
of Audit Findings to Audit Committee committee.

Action Steps

A. Existing and Ongoing Practices

A.1 BAC has an extensive issue escalation process for tracking and reporting significant audit issues and past due corrective actions to senior management and the Audit
Committee.
B. Completed Action Steps
B.1 An enhanced report was developed to provide comprehensive reporting of issue metrics and trends to senior management and the Audit Committee.
B.2 Considered augmenting the risk measuring methodology to incorporate the duration associated with identified risks. On a quarterly basis, the duration of risk associated with
each line of business is assessed and considered in the risk ratings assigned and presented to executive management, external regulators and the Audit Committee.
B.3 Considered inclusion of the direction of risk in Audit Reports. The direction of risk is incorporated into Audit’s assessment of inherent risk and control effectiveness on a quarterly
basis for each line of business, Risk Management and Compliance.
C. Remaining Action Steps
C.1 Perform independent validation of Enhancement Plans and report status periodically to the Audit Committee of the Board until full implementation of the Plan is achieved.

6. Escalation of Audit Exceptions and Establish escalation procedures for resolving any differences of opinion
between audit staff and management concerning audit exceptions and
Recommendations
recommendations, with any disputes to be resolved by the BAC’s
Enterprise Risk Committee.

A. Existing and Ongoing Practices
A.1 BAC has an extensive issue escalation process for reporting significant audit issues and past due corrective actions to senior management and the Audit Committee. Reports
are prepared by BAC’s General Auditor with breakdowns by business segment.

B. Completed Action Steps
B.1 Corporate Audit enhanced issue escalation routines and components of the risk assessment methodology in 2011. Specific enhancements include:
• Creation of executive reporting which highlights issues requiring management’s attention. The report is produced monthly and distributed to the Executive Management Team and
Audit Committee. Business executives are asked to present to the Audit Committee when there are risks and issues that require escalation.
• Thematic issue analyses are performed periodically to highlight trends for executive management and the Audit Committee. Based on the trends, action plans are created to
address the root cause and provide appropriate escalation routines.
• Audit’s opinion on Compliance is presented to the Audit Committee semi-annually.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/ Attorney Work Product
Submitted Under 12 USC 1828(x)

Final as of December 12, 2011
BAC Consent Order Submission 0000972

Confidential




APPENDIX 4
Bank of America Corporation

Plan to Enhance Internal Audit Program Submission, Dated July 12, 2011
Pursuant to
Paragraph 5 of the Consent Order of the Board of Governors of the Federal Reserve System,
Dated April 13, 2011.

Confidential Treatment Requested by Bank of America
Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)

BAC Consent Order Submission 0000805

Plan to Enhance Internal Audit Program
Confidential
Plan to Enhance Internal Audit Program
Introduction
This Plan to Enhance Internal Audit Program of the Bank of America Corporation (“BAC”), is developed
pursuant to Paragraph 5 of the Consent Order No. 11-029-B-HC of the Board of Governors of the Federal
Board System (the “Federal Reserve”), dated April 13, 2011 (the “Order”). It describes the action steps
and timeline by which BAC will enhance its internal audit program with respect to oversight of residential
mortgage loan servicing, Loss Mitigation, foreclosure activities, and operations conducted through Bank
of America, N.A. (the “Bank”).
The Order provided that the plan be based on an evaluation of the effectiveness of BAC’s current internal
audit program. We engaged Promontory Financial Group (“Promontory”) to assist us in conducting and
providing an independent evaluation of the Global Internal Audit Program and the internal audit program
of our residential mortgage loan servicing, Loss Mitigation and foreclosure activities and operations as
conducted through Home Loans (“HL”) and Legacy Asset Servicing (“LAS”).
In the months preceding the Order and Promontory’s evaluation, HL and LAS Internal Audit performed a
self analysis of its program and commissioned an evaluation of its practices by another audit function
within BAC. Those analyses, in turn prompted a number of enhancements to the audit program as it
affects residential mortgage servicing activities within HL and LAS. Further, Promontory’s evaluation
found sound audit planning, management, reporting, issue tracking and follow-up processes in place.
They stated that the overall audit program, as recently enhanced by Internal Audit management, appears
sound and appropriate for HL and LAS activities. Accordingly, the Internal Audit Plan provides
incremental improvements to maintain the caliber of the current program.
It is our goal to implement these actions promptly and effectively in order to achieve and maintain a
robust internal control system over the consolidated organization. We believe that the actions required by
the plan will contribute to safe, sound and compliant operations in our residential mortgage business.
Paragraph 5 Requirements
Within 60 days of this Order, BAC shall submit to the Reserve Bank an acceptable written plan to
enhance the internal audit program with respect to residential mortgage loan servicing, Loss Mitigation,
and foreclosure activities and operations. The plan shall be based on an evaluation of the effectiveness
of BAC’s current internal audit program in the areas of residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities and operations, and shall include recommendations to strengthen the
internal audit program in these areas. The plan shall, at a minimum, be designed to:
(a) Ensure that the internal audit program encompasses residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities;
(b) Periodically review compliance with the effectiveness of the ECP and ERM with respect to
residential mortgage loan servicing, Loss Mitigation, and foreclosure activities, and compliance
with the Legal Requirements and supervisory guidance of the Board of Governors;
(c) Ensure that adequate qualified staffing of the audit function is provided for residential mortgage
loan servicing, Loss Mitigation, and foreclosure activities;



Confidential
Treatment Requested by Bank of America

Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


1

BAC Consent Order Submission 0000806

Plan to Enhance Internal Audit Program
Confidential
(d) Ensure timely resolution of audit findings and follow-up reviews to ensure completion and
effectiveness of corrective measures;
(e) Ensure that comprehensive documentation, tracking, and reporting of the status and resolution of
audit findings are submitted to the audit committee; and
(f)

Establish escalation procedures for resolving any differences of opinion between audit staff and
management concerning audit exceptions and recommendations, with any disputes to be
resolved by the BAC’s Enterprise Risk Committee.

Summary of Current State
Promontory’s evaluation concluded that the current Internal Audit program in residential mortgage is
sound overall. Specifically, they found:



x

HL and LAS Internal Audit’s universe includes sustainable processes for identifying coverage for
audit review including HL and LAS businesses and activities. It operates on a three-year audit
cycle, reflected in an annual audit plan which is updated quarterly. Internal Audit planning
employs a Risk and Frequency Model, which includes a methodology for assessing inherent
risks, control environments, and residual risks. The resulting assessments drive resource
management and audit scopes and frequency.

x

BAC has an extensive issues escalation process for reporting significant audit issues and past
due corrective actions to senior management and the Audit Committee. Reports are prepared by
the General Auditor for the entire corporation with breakdowns by business segments. Reports
go to the Audit Committee quarterly and senior management monthly.

x

HL and LAS Audit has an effective process for tracking and follow-up on audit and regulatory
issues.
o

Issues are logged on the
Audit, and given a severity rating.

o

Issues are tracked until corrective measures have been implemented and Audit testing
validates that the corrective measures are appropriate and sustainable.

o

MRAs are tracked on
and, following validation of correctives measures, are tested
monthly by Audit until the MRA is lifted by the supervisor.

system, maintained by Internal

x

BAC has placed a heavy reliance on self-identified audit issues. Managers are expected to selfidentify 50 percent of the issues that are placed on the
and their performance against this
expectation is measured. Timely resolution of Audit issues are a part of the performance review
process and Audit provides input on the business managers’ control performance.

x

Audit Committee reporting is generally easy to comprehend the purpose, scope, and issues in
reports. The reports are well written, precise, and clear.

x

Recently, Internal Audit redesigned its practice of reviewing Risk Management and Compliance
functions. The new arrangement will allow Internal Audit to focus on Risk Management,
Compliance, compliance with requirements of regulatory and legal requirements, consent orders,

Confidential
Treatment Requested by Bank of America

Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


2

BAC Consent Order Submission 0000807

Plan to Enhance Internal Audit Program
Confidential
outstanding issue and MRA resolution-validation and testing in residential mortgage servicing.
The plan, which is currently being enhanced to address requirements of the Orders, will identify
any gaps between the current plan and requirements imposed by regulators and include them in
the audit coverage.
x

Internal Audit’s professional staff has particular strengths and acumen. Generally, Internal Audit’s
staff has a reasonable level of education and industry experience to perform their duties in
mortgage loan servicing, Loss Mitigation, and foreclosure activities.

Accordingly, Promontory made incremental suggestions for improvement as reflected in the Plan to
Enhance Internal Audit Program (attached as Appendix 4.1) including, among others, recommendations
to:
x

Develop the standards against which the Risk and Compliance programs will be evaluated and
the procedures and testing that will form the basis for conclusions;

x

Consider augmenting the risk measuring methodology to incorporate the duration associated with
identified risks; and,

x

Conduct an independent validation of Internal Audit’s completion of corrective actions in response
to OCC-identified deficiencies.

We are confident that these action steps will enhance substantially the internal audit function within the
mortgage business. We recognize the significant effort, time, and resources necessary to implement our
Plan and to verify its consistency and rigor once implemented. As a result, we plan on commissioning an
independent validation and report on the progress of the Plan at the critical junctures in this effort.





Confidential
Treatment Requested by Bank of America

Attorney Client Privilege/Attorney Work Product
Submitted Under 12 USC 1828(x)


3

BAC Consent Order Submission 0000808