View original document

The full text on this page is automatically extracted from the file linked above and may contain errors and inconsistencies.

Board Oversight Plan of Risk
Management, Internal Audit,
and COPS Programs

Date Prepared: June 27, 2011

EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 1

The Order states:
Within ninety (90) days of this Order, the Board shall submit to the Regional Director an
acceptable written plan to strengthen the Board’s oversight of the Association’s risk
management, internal audit, and compliance programs concerning the residential mortgage loan
servicing, Loss Mitigation, and foreclosure activities conducted by the Association.
Response
In order to ensure effective oversight of risk management, compliance and internal audit at
EverBank, the Board of Directors (the Board) at EverBank Financial Corp oversees the
establishment and maintenance of an environment that facilitates independent oversight and
review of EverBank’s residential mortgage servicing, mortgage modification, mortgage
foreclosure, and related mortgage loss mitigation activities (collectively, Mortgage Servicing
Activities).
In furtherance of that oversight responsibility, EverBank has implemented the following changes
in its Risk Management, Compliance Oversight and Process Support (COPS), and Internal Audit
Departments:
1. Establishment of a centralized compliance oversight function through the merger of the
Compliance and Quality Control Departments.
Response: EverBank initiated an enterprise-wide effort to expand and enhance its
compliance and regulatory oversight functions in April 2010. At the core of this initiative
was the creation of the centralized Compliance Oversight and Process Support (“COPS”)
Department, which merged EverBank’s Compliance and Quality Control (“QC”)
Departments into a centralized department reporting to EverBank’s General Counsel. In
October 2010 EverBank appointed a dedicated Director of Regulatory Compliance
responsible for the management of Compliance. Compliance engaged the firms of Buckley
Sandler, LLC and Treliant Risk Advisors, LLC in April 2010 to consult with EverBank on
the construct of compliance functionality. In addition, Compliance oversight of mortgage
production and Residential Mortgage Loan Servicing, Loss Mitigation and Foreclosure
activities was expanded to include other key areas of the bank.
2. Establishment of reporting structures to ensure that Risk Management, COPS, and
Internal Audit have appropriate authority and independence to conduct their required
reviews and oversight.
Response: EverBank has established an organizational structure that supports the
independence of Risk Management, Internal Audit and Compliance programs and provides
requisite authority for execution of departmental responsibilities.
x The Risk Management function is headed by EverBank’s Chief Risk Officer and holds
the title Vice Chairman. The Chief Risk Officer reports indirectly to the Chairman of the
Board. Risk Management operations are segregated from business unit functions thereby
facilitating independent oversight of risks.
EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 2

x

Internal Audit reports directly to the Board of Directors’ Audit Committee and reports to
the Chief Risk Officer for administrative functions.
x Compliance management reports directly to EverBank’s General Counsel and routinely
submit reports to the Regulatory Compliance Committee. Compliance is completely
segregated from business units and as such maintains the necessary independence to
execute its role without interference.
3. Development of policies and enhancements to the compliance program to formalize
roles and responsibilities within the compliance function and provide a framework for
monitoring and testing compliance with legal and supervisory requirements.
Response: EverBank Executive Management previously identified that a formal
Compliance Management System needed to be adopted by the organization. In response,
EverBank engaged various outside firms to assess the organizations compliance
management practices. As a result of the engagements and identification of the need for
a formalized Compliance Management System, EverBank’s Compliance Management
Program Policy (the “Policy”) was presented and approved by EverBank’s Board of
Directors on October 25, 2011. This document specifies the practices, roles and
responsibilities for the COPS Department in management of compliance oversight and
reporting to EverBank’s Management, Committees and Board of Directors.
4. Development of detailed testing procedures to address specific legal and supervisory
requirements related to Mortgage Servicing Activities.
Response: While testing procedures have been enhanced to include regulatory
components, a formal project is underway to conduct a full review of testing protocols.
The plan associated with the initiative is scheduled for delivery in January, 2012 and will
be provided to the Consent Order Office for monitoring. Reporting against progress will
be incorporated into EverBank’s CTR.
5. Enhancement of Internal Audit’s oversight of mortgage servicing by increasing the
frequency of audits, strengthening the standards by which audits are conducted, and
adding staff, technology resources, and training.
Response: EverBank’s 2012/2013 Internal Audit Plan, as well as periodic updates to the
Oversight Committee, addresses the added emphasis toward audit of Mortgage Servicing
activities. To support increased frequency of audits, the Plan presents a proposal to increase
the staff complement of the Financial/Operations (Fin/Ops) Team, which has the lead
responsibility for these Mortgage Servicing audits and those of other areas with
responsibilities identified in the corrective action plan for the Consent Order.
6.
Internal Audit’s evaluation of the frequency and depth of audit plans in all Mortgage
Servicing Activities, with adjustments to its audit schedule and scope made accordingly
if external or internal events indicate such a need.
Response: Internal Audit’s 2012/2013 was developed with an increased focus on Residential
Mortgage Loan Servicing, Loss Mitigation and Foreclosure activities. In communication
with the Audit Committee, Internal Audit continues to convey the fluidity of annual plans, as
well as the necessity of scheduling agility to address events of a sudden or urgent nature.
The status of this effort is 100% complete and evidenced in the Internal Audit Plan.

EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 3

7. Internal Audit’s ongoing analyses of key performance indicators and other trending
data between scheduled audits, with an initiative to perform such data analyses relating
to Default Servicing.
Response: Internal Audit’s Investigations/Support team has begun a continuous auditing
initiative, and is working on its pilot project, a review of Foreclosure’s Key Performance
Indicators (KPIs). The status of this effort is ongoing.
Tracking of progress for this initiative will be integrated into the Consent Order Office CTR.
8. Internal Audit’s evaluation, and ultimately selection, of audit software tools for data
mining and analysis, anticipated to be in place by year-end 2011.
Response: An initiative is underway to evaluate continuous auditing software for usage by
EverBank’s Internal Audit Department. The timeline for completing an evaluation and
software selection is second quarter 2012. In the interim, a pilot project is underway to
evaluate and trend Foreclosure KPI data to determine how EverBank might employ such
software.
Tracking of progress for this initiative will be integrated into the Consent Order Office CTR.
9. Hiring of additional subject matter expertise, from an audit perspective, for Default,
Foreclosure, and Loss Mitigation, with additional staffing additions expected in 2011.
Response: The search for qualified staff with requisite subject matter expertise is ongoing.
Resources were added in October 2011 with loss recovery / mitigation experience and the
department is actively recruiting for others. Funding has been established in the 2012 budget
for supplementing staff resources as needed through the engagement of consultants/SMEs as
necessary. This effort is ongoing.
10. Implementation of a Board-level Risk Committee providing strategic oversight to
EverBank’s risk management.
Response: EverBank created a board level Risk Committee on July 26, 2011.
11. Formalization of a Chief Risk Officer position that reports to the Risk Committee.
Response: EverBank created a Chief Risk Officer position on July 26, 2011. The Chief
Risk Officer reports indirectly to the Chairman of the Board.
12. Formalization and addition of resources to an Enterprise Risk Management (ERM)
Team that will provide framework and governance enterprise-wide.
Response: Formalization of an Enterprise Risk Management program within EverBank
began includes the designation of a Chief Risk Officer and board level Risk Committee
which has been implemented. In addition, resourcing a senior executive level leader for
operational management of the ERM program has been completed. Staffing of the ERM
initiative has been facilitated by the addition of five additional resources with supplemental
staffing gained through outsourcing of certain functions to a third party vendor. As ERM
functions evolve, staffing will be reviewed on an ongoing basis to assure resource adequacy.
13. Adoption of standards and categorizations related to risks, controls and associated
training for all officers.
Response: EverBank has adopted a Risk Taxonomy and has presented same in officer
training sessions conducted throughout EverBank. In addition to the Risk Taxonomy, the
training sessions covered how risk management is viewed within EverBank, usage of
EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 4

common language, and how to mitigate risks within business units. Training was conducted
in March, April and June of 2011.
14. Enhancement of the annual risk assessment process and a quarterly update of any
changes made to a high or critical risk or control reported to the ERM office.
Response: Annual Risk Assessments were in existence for several years under FDICIA
programs within EverBank. The program has been enhanced through the implementation of
a formal review facilitated by the ERM Team. An additional enhancement is migration of
the risk assessment to the
platform which will enable reporting and mapping against
EverBank’s Risk Taxonomy. The migration to the
platform is scheduled for first
quarter 2012 and is 80% complete.
Tracking of progress for this initiative will be integrated into the Consent Order Office CTR.
15. Development of a process for all significant general ledger accounts to be tested and
reported on a quarterly basis to the ERM office.
Response: The review of significant GLs has been enhanced through the addition of
dedicated ERM staff with an accounting background. The review process has been
formalized and is 100% complete.
16. Centralization of reporting for the Consent Order Compliance Tracking Report.
Response: In response to the Consent Order, EverBank created a Consent Order Office to
oversee activities committed to in EverBank’s Consent Order response, to monitor progress
against plan, and report on these activities to EverBank’s Board Oversight Committee, Senior
Management, and Regulators.
17. Increased staffing of both COPS and Legal Departments to accommodate increased
reviews and workloads.
Response: The Legal Department has hired several attorneys and support staff within the last
year to help support EverBank’s growth company-wide. Currently, EverBank has two
attorneys dedicated Servicing, loss mitigation and foreclosure activities, one of which also
supports company-wide, risk management issues. It has other attorneys that provide
corporate governance and reporting support to the Oversight Committee and Board of
Directors.
The COPS department has created an organization structure that significantly increases
staffing to support EverBank and specifically Residential Mortgage Loan Servicing, Loss
Mitigation, and Foreclosure activities. In the Servicing unit, COPS has increased staff to
include two managers and eleven staff members to provide compliance oversight. Open
positions exist in the Servicing structure and are anticipated to be filled in the first quarter
2012. Tracking of progress in completing the staffing structure will be integrated into the
Consent Order Office CTR.
18. Enhancement of governance by the ERM Team of all categories of risks to meet
requirements as defined by our current and future regulatory agencies, and will
continue to enhance the process for independent testing and monitoring of enterprise
wide risks and controls.
Response: Development of the ERM structure has been implemented within EverBank and
is reviewed on an ongoing basis in response to changing industry and market requirements.
While risk assessments were in existence, a significant effort is underway to review and
EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 5

evaluate risks across the company and to identify/affirm mitigating controls. This effort is
scheduled for completion in first quarter 2012 and is 90% complete.
19. Development of a roadmap to lay out the framework, structure and major milestones of
how EverBank will continue to improve and sustain the governance of risks and
controls.
Response: EverBank’s ERM team has developed an ERM Roadmap which identifies and
prioritizes risk management initiatives which will be undertaken over the next several years.
The ERM Roadmap was included in the updated Risk Management Plan.
20. Implementation of a new risk tracking and reporting system,
to provide
enhanced tracking, monitoring and reporting from the aggregate to the individual
control levels, to ensure decisions makers have the relevant information to make
appropriate decisions.
Response: EverBank’s ERM Team is in the process of rolling out a Governance, Risk and
Compliance (GRC) application titled
to the bank.
is a robust and respected
risk management application which is highly rated by Gartner’s Magic Quadrant review of
similar software. The application has several modules and the Vendor Management function
is in production. The controls module is staged and awaiting population. The content to be
used in populating the application is being developed and is 90% complete. The
system will be populated and in production in the first quarter 2012.
To strengthen Board oversight of Risk Management, Internal Audit, and COPS programs related
to mortgage servicing, the Board will ensure that teams and departments are conducting
independent testing, and monitoring enterprise-wide risks and controls in an effective and timely
manner across Mortgage Servicing Activities including those that are newly developed or have
been recently enhanced. The Board will oversee functions, reporting structures, policies,
procedures, and enhancements, specifically related to Mortgage Servicing Activities, to ensure
adequacy. The Board will utilize enhanced reporting that incorporates information from
Mortgage Servicing Activities to ensure its understanding of EverBank’s activities and the
exposure these activities pose to EverBank and EverBank Financial Corp. To specifically
strengthen EverBank’s risk management process, the ERM Team will implement governance to
cover all areas of risk as defined by regulatory examination standards for large banks.
Deficiencies in, or non-compliance with, laws, rules, regulations or policies relating to Mortgage
Servicing Activities (collectively, Deficiencies) identified by Risk Management, COPS, or
Internal Audit, are communicated promptly to the appropriate business unit, executive
management or Board Committee, including the Regulatory Compliance Committee and the
Operational Risk Committee. All deficiency findings are reported to the Board’s Audit
Committee, with material deficiencies, to the extent applicable, reported to the full Board.
EverBank has established reporting structures to ensure that Risk Management, COPS, and
Internal Audit have appropriate authority and independence to conduct their required reviews
and oversight.

EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 6

™ The Director of COPS reports directly to EverBank’s General Counsel, and chairs and
regularly submits written reports to the Regulatory Compliance Committee. COPS
operates wholly independent of EverBank’s business operations.
™ The Director of Internal Audit issues directly to the Board’s Audit Committee certain
audit reports documenting any Deficiencies and corrective actions necessary to remediate
any such Deficiencies.
™ EverBank’s Chief Risk Officer exercises direct control of Risk Management, holds the
title of Vice Chairman of the Board, and reports indirectly to the Chairman of the Board.
Risk Management’s operations are segregated from EverBank’s business operations,
thereby facilitating independent oversight of risks to EverBank and help identify and
mitigate Deficiencies.
Risk Management, COPS and Internal Audit have the authority to conduct appropriate oversight
and reviews of business processes and identify potential Deficiencies, direct corrective actions
relating to Deficiencies, and ensure remediation in connection therewith. The Board is kept
abreast of Deficiencies and remediation related to these Deficiencies through regular Board
reporting. Any enhancements, developments, and/or material changes to EverBank’s processes,
procedures, and polices are provided to the Board through regular Board reporting to ensure the
Board remains aware and involved in the oversight of EverBank’s activities, whether existing,
enhanced, or newly developed, related to Mortgage Servicing Activities.
The Board of EverBank Financial Corp is committed to full compliance with the Consent
Order. Additional details on Risk Management, Internal Audit, and COPS Departments can be
found within EverBank’s plans, programs, policies, procedures and processes on the enclosed
CD.

EverBank Financial Corp
Risk Management, Internal Audit, and COPS Plan
Page 7














RiskManagementPlan













DatePrepared: June27,2011
DateRevised:December6,2011



˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‹•ƒƒ‰‡‡–ŽƒͳʹȀ͹ȀʹͲͳͳͷǣͳͲ






ƒ‰‡ͳ

The Order states:
Within ninety (90) days of this Order, the Holding Company shall submit to the Regional
Director an acceptable written plan to evaluate the effectiveness of, and strengthen, the
Association’s risk management program addressing residential mortgage loan servicing, Loss
Mitigation, and foreclosure activities and operations, and make recommendations to strengthen
the Association’s risk management program in these areas.
Response:
The Board of Directors of EverBank Financial Corp (the Board) recognizes the importance of
having effective risk management throughout the organization. To accomplish this, the Board
has overseen changes and enhancements to the Risk Management Program. An enterprise
assessment of risk management was performed by an independent consultant, KPMG, LLC.
Recommendations were made to enhance the risk management in several areas, including
residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations. The
excerpt from the assessment is attached with the recommendations. The recommendations have
been prioritized as evidenced by the ERM Roadmap attached. All risk management projects
related to the Consent Order will be tracked in the Compliance Tracking Report that is provided
to the Board Oversight Committee. Internal and external events continue to drive change, and
the Board is committed to responding to these events and monitoring the evolvement of the Risk
Management Department.
The following actions have also been taken in response to the EFC Consent Order:
Formed a Consent Order Oversight Committee that performed the following functions.
x
x

Reviewed the plan for monitoring the Consent Order at the Bank level.
Approved the monitoring tool that provides a status of each of the Plans for all
areas of servicing, including residential mortgage loan servicing, Loss Mitigation
and foreclosure activities and operations.

Ongoing monitoring of the Consent Order Compliance Tracking Report occurs on a quarterly
basis.
Additions to the original plan include adding the monitoring of the Compliance, Internal Audit
and Risk plans into the Compliance Tracking Report.
Enterprise Risk Management (ERM) is defined by the Board to include all functions within the
organization, including mortgage servicing, Loss Mitigation, and foreclosure activities and
operations. Changes to EverBank’s risk management oversight include the enhancement of the
Enterprise Risk Committee, additional staffing, and the review of enterprise-wide functions, such
as Internal Audit, Compliance Operations and Process Support (COPS), and ERM.
˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‹•ƒƒ‰‡‡–ŽƒͳʹȀ͹ȀʹͲͳͳͷǣͳͲ


ƒ‰‡ʹ

The following list includes existing or updated program elements and recommended
enhancements implemented as a result of both internal and external reviews.
x
x
x
x
x

x
x

x
x
x
x

x

The implementation of a Board-level Risk Committee providing strategic oversight to
EverBank’s enterprise risk management including residential mortgage servicing, Loss
Mitigation and foreclosure activities and operations, effective July 26, 2011
The formalization of a Chief Risk Officer position that reports to the Risk Committee,
effective July 26, 2011.
The formalization and addition of resources to an ERM team that will provide
framework and governance enterprise-wide, including residential mortgage servicing,
Loss Mitigation and foreclosure activities and operations, effective June 28, 2011.
Adoption of standards and categorizations related to risks, controls and associated
training for all officers, including residential mortgage servicing, Loss Mitigation, and
foreclosure activities and operations, completed June 2011
Enhancement of the annual risk assessment process and a quarterly update of any
changes made to a high or critical risk or control for residential mortgage servicing, Loss
Mitigation, and foreclosure activities and operations reported to the ERM office will be
performed within the risk monitoring and tracking system,
January, 2012.
A process for all significant general ledger accounts to be tested and reported on a
quarterly basis to the ERM office for residential mortgage servicing, Loss Mitigation and
foreclosure activities and operations, implemented and ongoing each quarter
Centralized reporting for the Consent Order Compliance Tracking Report which includes
tracking all Compliance, Internal Audit and Risk Management program components
relating to residential mortgage servicing, Loss Mitigation, and foreclosure activities and
operations, implemented in September 2011 and ongoing.
The COPS and Legal Departments are increasing staff to accommodate increased
reviews and workload, ongoing
Regulatory training is required and tracked for all employees in all areas related to
residential mortgage servicing, Loss Mitigation, and foreclosure activities and
operations, ongoing and tracked in the EverBank Learning Management System
A formalized committee structure exists that addresses various risk categories, such as
Credit and Operational Risk which include residential mortgage servicing, Loss
Mitigation, and foreclosure activities and operations.
Internal Audit performs the organization’s risk management, control and governance
processes to determine adequacy and report all findings to the Board’s Audit Committee
as part of its routine audit schedule which includes residential mortgage servicing, Loss
Mitigation, and foreclosure activities and operations. (See Internal Audit Plan for 2012)
COPS performs regularly scheduled reviews of regulatory requirements, including
residential mortgage servicing, Loss Mitigation, and foreclosure activities and
operations. (See COPS Audit Plan for 2012)

In addition to the above governance, the mortgage servicing unit has implemented the following
processes:

˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‹•ƒƒ‰‡‡–ŽƒͳʹȀ͹ȀʹͲͳͳͷǣͳͲ


ƒ‰‡͵

x

x
x

A rigorous control process for any changes that impact systems, processes, procedures,
and customer communications. Senior servicing managers, line of business managers,
and process supervisors all participate as part of the approval body in the change control
process.
Key performance indicators are monitored to ensure that processes are completed timely
and accurately.
Monthly loss meetings to review root causes of losses within mortgage servicing.

To strengthen the risk management process, the ERM team will enhance governance of all
categories of risks to meet requirements as defined by our current and future regulatory agencies,
and will continue to enhance the process for independent testing and monitoring of enterprise
wide risks and controls. A roadmap has been developed (see attached) to lay out the framework,
structure and major milestones of how EverBank will continue to improve and sustain the
governance of risks and controls. A new risk tracking and reporting system,
is being
implemented that will provide enhanced tracking, monitoring and reporting from the aggregate
to the individual control levels, to ensure decisions makers have the relevant information to make
appropriate decisions.
The Board understands the importance of the Risk Management function and will continue to
oversee any changes or enhancements that are needed. The Board is committed to full
compliance with EverBank Financial Corp’s Consent Order. Additional details on Risk
Management can be found within Section 11(o) of EverBank’s Compliance Program on the
enclosed CD.

˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‹•ƒƒ‰‡‡–ŽƒͳʹȀ͹ȀʹͲͳͳͷǣͳͲ


ƒ‰‡Ͷ






OrganizationalDevelopment
ReviewofCOPSPlan




DatePrepared: June27,2011






































˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ




ƒ‰‡ͳ

TheOrderstates:
Withinninety(90)daysofthisOrder,theHoldingCompanyshallsubmittotheRegionalDirector
an acceptable written plan to evaluate the effectiveness of, and strengthen, the Association’s
compliance program addressing residential mortgage loan servicing, Loss Mitigation, and
foreclosureactivitiesandoperations,asdetailedintheAssociationOrder.
Response
EverBank Financial Corp recognizes the need for an effective compliance department.  To
ensure the compliance department remains effective, changes and enhancements to the
ComplianceOversightandProcessSupport(COPS)Departmentfunctionsareevaluatedonan
ongoing basis.  EverBank began an enterprisewide effort to expand and enhance its
compliance and regulatory oversight functions beginning in early 2010. The recentlyformed
COPS Department merged EverBank’s Compliance and Quality Control Departments into a
centralizeddepartmentreportingtoEverBank’sGeneralCounselinNovember2010.TheBoard
of Directors (Board) of EverBank Financial Corp realizes the need for a structured and
formalized compliance management program and an effective communication process to
ensure the Board is made aware of any significant compliance matters that may affect the
healthoftheorganization.Thestructureofcommitteesthatreportoncompliancematterswas
addressed, and plans to enhance compliance reporting to the Board through the Regulatory
Compliance Committee is in process.  The Board is fully committed to oversight of the
compliance management program and understands the increased regulatory scrutiny and
importanceofadherencetoconsumerprotectionlaws.
The Board of EverBank has approved the COPS Regulatory Compliance Program and the
Compliance Monitoring and Testing Program with the submission of the documents in June
2011 pertaining to the EverBank Consent Order.   The programs were a cumulative
development effort of various outside legal firms, inhouse counsel, and compliance team
membersandmanagerstoensureEverBankhasacompletecompliancemanagementprogram
thataddressesthefullcycleofcompliancefromregulatorycommunicationsthroughcorrective
action completion and documentation processes in all areas of EverBank, including Mortgage
ServicingandLoanAdministration.
Inadditiontothecurrentcomplianceoversightofmortgageproductionandservicingactivities,
several key areas will have compliance oversight managed under the COPS Department that
include: EverTrade/World Markets, EverBank Wealth Management, the various Banking
Operations areas, an enhanced and centralized BSA/AML program, an enhanced Compliance
MonitoringandTestingprogramandFairLendinganalyticsunit.TheFairLendinggroupwithin
COPSalsomanagesHMDAandCRAreportingresponsibilities.
˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡ʹ

TheBoardofEverBankhasreviewedandagreeswithplanstoleverageadditionaltechnology
and staffing resources to implement several key compliance oversight initiatives identified in
2010and2011,andwillbemonitoringthescheduleforimplementationdatesforcompletionin
2011 and 2012.  Some of these initiatives include, but are not limited to, the following
enhancements:
x

StaffingandDevelopment;
Ananalysiswasconductedbyoutsideconsultingfirmandinternalstafftoquantify
appropriatestaffinglevelsforthecompliancefunctions.
Subsequenttothe
analysis,managementconcludedinNovember2010tocreateanintegratedCompliance
andQualityControlprogram.Sincethattimethenumberofcompliancestaffdedicated
toResidentialMortgageLoanServicing,LossMitigationsandForeclosurecompliance
andmonitoringandtestingactivitieshasexpandedsignificantly.Intheorganization
structureapprovedasofDecember2011,therearethirteenstaffmembersdedicatedto
compliancefunctionsforthesebusinessunits.Openpositionsexistandareprojectedto
befilledduringfirsthalfof2012.
Intheinterim,outsidefirmsarebeingemployedtosupplementstaffinglevelsand
providesubjectmatterexpertise.
ReportingonstaffrecruitingwillbeincorporatedintoEverBank’sConsentOrderOffice
CTRReporting.

x

Review of committee communications & formulation of a “Compliance Steering
Committee”(reportingthroughtheRegulatoryComplianceCommittee);
AspartoftheEnterpriseRiskManagement(“ERM”)formationananalysisofEverBank’s
committeeandreportingstructurewasconducted.TheComplianceSteering
CommitteewasdeterminedtoberedundanttotheRegulatoryComplianceCommittee
(“RCC”).RCCreportingincludescompliancerelatedupdatesfrommembersand
incorporatesanescalationprocesstotheOperationalRiskCommittee.RCCmembers,
whoalsoserveasmanagementtobusinessunitsatEverBank,areactivelyinvolvedin
regularbusinessactivitiesandareaccountableforreportingcompliancerelatedissues
totheRCC.TheChairpersonoftheRCCistheManagingMortgageRegulatoryDirector
ofCOPS,withfullresponsibilitiesforreportingcomplianceissuesandensuring
correctiveactionsareaddressed.

˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡͵

TheRCCCharterwasreviewedtoensureproperpoliciesandprocessesareinplaceto
monitorandreportonallnewormodifiedcompliancematters;toensurethataction
plansaremonitoredandreportedon,withescalationasappropriate.
TheServicingChangeControlCommitteemeetstwicepermonthwithLegalandCOPS
staffinattendance.AgendaitemsfocusonResidentialMortgageLoanServicing,Loss
MitigationandForeclosureservicinginitiatives,changestoregulationsandplansto
remediatesystems,policiesandprocedureswherenecessary.TheServicingRisk
CommitteealsomeetsquarterlywithLegalandCOPSstaffinattendance.Themeetings
focusonsimilaragenda,however,arestrategicandriskfocusedinnature.Thestatusof
thiseffortiscompleteandongoing.
x

Creationofthe“RegulatoryAccountabilityandCommunicationsMatrix”toensureall
regulatorycompliancemattersarecommunicatedandhavetheproperoversightin
COPS;

Regulatorymatriceshavebeendevelopedtoidentifythelawsandregulations
associatedwithResidentialMortgageLoanServicing,LossMitigationandForeclosure
forwhichtheCOPSdepartmentisaccountable.Thespecificregulationsaredefinedin
theRegulatoryComplianceCommitteeCharter(attached)as“CoveredLaws”.While
initialmatricesarecomplete,theprocessofmaintenanceisongoing.

x

CreationoftheComplianceLibraryandProcedures;
COPShasdevelopedandimplementedareadilyaccessiblesharepointsitetohouseall
sourcedocumentsforcorporatereview.Thesiteismaintainedtoincludeallupdated
materialsandisavailabletoallEverBankemployees.
Complianceproceduresarebeingreviewedforcompletenessandaccuracy.
Enhancementswillbeincorporateintorevisedproceduresaswarrantedthroughthe
reviewprocess.BuckleySandlerhasbeenengagedtoconductthereviewofprocedures
andmatrices.ProjectplansareindevelopmentinconjunctionwithBuckleySandler
Oncetheprojectplanshavebeenapprovedandimplementationbegun,trackingof
progresstoplanwillbeincorporatedintotheConsentOrderOfficeCTR.

x

EnhancementoftheRegulatoryComplianceTrainingProgramfornewDoddFrankrules;
COPSinitiatedareviewofcompliancetrainingdeliverymechanismsandtoolsinearly
2011.Thepurposewastoevaluatethebestmethodfordeliveringcompliancetraining

˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡Ͷ

touserswithgreatestunderstandingandretentionasevidencedbyposttraining
evaluations.AteamcomprisedofemployeesfromLearning&Organizational
Development,MortgageLoanProductionTraining,MortgageLoanServicingTraining,
andBranchOperationsTrainingwasformedandreviewedvendorsprovidingonline
training.ThevendorselectedfordeliveryofEverBank’scompliancetrainingoffers
onlinevideoandknowledgeexercisesimbeddedwithincoursestoactivelyengagethe
employeeaboveandbeyondfinalexamsforeachcourse.EverBankbeganusingthenew
vendorforonlinecompliancecourseassignmentsonJuly1,2011.COPSdetermines
appropriatecoursesbasedonthebusinessunitareasofresponsibilitywhilethe
LearningandOrganizationalDevelopmentdepartmentmanagethelearning
managementsystemandassignsthecoursestothetargetedemployees.
Duringthereviewoftrainingpractices,theRegulatoryComplianceTrainingPolicywas
reviewedandenhanced.TherevisedpolicywassubmittedandapprovedbytheRCC.
Whilethenewtrainingprogramisinproduction,curriculumisunderongoingrevisionto
reflectchangessuchasDoddFrank.
x

Review and enhancement of complaint management processes and reporting and
analysisoftrends;

In the time prior to October 2011, EverBank maintained a process for complaint
monitoringthatincorporateddesignatedstaffinvariousbusinessunitstocaptureand
report complaints in spreadsheets, and submission of those spreadsheets to COPS for
monitoringandtestingpurposes.InOctober2011,COPSreleasedaComplaintTracking
Systemthatusersinbusinessunitsemploytoenterspecificdatarelatedtocomplaint
intake.Thesystemallowsformorerobustreportingandincorporatesspecificquestions
relative to Residential Mortgage Loan Servicing, Loss Mitigation and Foreclosure.  In
addition, the system maintains information and indicators which allow for ready
trackingofcomplaintsrelatedtothirdpartyvendors.ReportsareprovidedtotheCOPS
monitoring and testing units, business units and Third Party Review Committee on a
regularschedule.TheComplaintTrackingSystemhasbeendeployedandisinuse.
Enhancements to the Complaint Tracking System are underway and include reporting
enhancements scheduled for production in first quarter 2012.  Monitoring of the
reportingenhancementswillbeincorporatedintotheConsentOrderOfficeCTR.

x


Reviewofbusinessunitpolicyandproceduredocumentationtoensurecomplianceand
consistencywithactualbusinesspractices;

˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡ͷ


AsaresultoftheConsentOrder,COPSengagedsubjectmatterexpertsfromKPMGto
evaluatetheMonitoringandTestingprocessasitrelatedtoResidentialMortgageLoan
Servicing,LossMitigationandForeclosureactivities.MonitoringandTestingprotocols
wereenhancedbaseduponthereviewtoincorporateConsentOrderrequirements.
Treliant Risk Advisors has been engaged to assist EverBank COPS management in
performing a Compliance Risk Assessment of all business units.  The assessment will
includeareviewofpoliciesandprocedureswithinthebusinessunitsandcomparisonto
practices.

x

ReportingonprogresstoplanwillbeincorporatedintoEverBank’sConsentOrderOffice
CTR.

Enhancement and creation of efficiencies in managementand committee reporting of
ComplianceTestingresultsandloanleveltrending;
EverBank has engaged the firm Buckley Sandler to assist in a review and design
enhancement of its Monitoring and Testing program.  The review will incorporate all
requisite operational, regulatory and agency checkpoints to ensure a rigorous
MonitoringandTestingprogramthatsupportsEverBank’sComplianceprogram.Project
Plansareindevelopmentandaredueinearly2012forEverBankreview.Reportingon
progresstoplanwillbeincorporatedintoEverBank’sConsentOrderOfficeCTR.

x

Enhancementofservicingcomplianceandinvestormonitoringandtesting;
AchievementofthiscomponentofEverBank’sresponsewillbefacilitatedthroughthe
BuckleySandlerandTreliantengagements.

x

Alignmentofcompliancereviewswithinternalauditreviews.

Testing of adherence to regulatory requirements was formerly bifurcated between Internal
AuditandQualityControl.WiththecreationofCOPS,allCoveredLawsasdefinedintheRCC
Charter are under the purview of the combined organization, COPS.  Several wellqualified
employeeshavebeenhiredstartinginlate2010uptothepresentdateforthebuildoutofthe
COPSDepartment.ThreeCOPSManagers(inadditiontotheManagingDirectorofRegulatory
Compliance) and five Compliance Analysts (seven more staff are planned for hire in the next
two months) have been added to the COPS Department.  All of the managers and four staff
membersarededicatedtomortgageservicingcomplianceoversightandmonitoringandtesting
reviews.
˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡͸

A formal “Change Control Procedure and Checklist” has been implemented to document
changes in business practices and ensure COPS management and the Legal Department
authorizeschangesaffectingcompliancewithlawsandregulations.Thechangecontrolprocess
willalsoensurethatscheduledcompliancereviewsareperformedascorporateorregulatory
environments change.  A thorough compliancerisk assessment of the COPS Department is in
processtoensureadequatestaffingandresourcesareallocatedtocompliancemanagement.
The Legal Department will retain the responsibilities of examination management oversight;
however, COPS will coordinate the document gathering and business area support of agency
audits.Correctiveactionplanswillbedocumentedandcompletedefficientlywitharecordof
thefollowupperformedbytheCOPSDepartment.
TheBoardofEverBankFinancialCorpiscommittedtofullcompliancewiththeConsentOrder.
Additional details on the COPS Department can be found within Section 11(o) of EverBank’s
ComplianceProgramontheenclosedCD.


˜‡”ƒ ‹ƒ ‹ƒŽ‘”’
‘’Ž‹ƒ ‡ŽƒͳʹȀͻȀʹͲͳͳͻǣʹͶ


ƒ‰‡͹

Internal Audit Plan

Date Prepared: June 27, 2011
Date Revised: December 7, 2011
2nd Date Revised: December 15, 2011
3rd Date Revised: December 22, 2011
4th Date Revised: January 12, 2012

EverBank Financial Corp
Page 1

The Order states:
Within ninety (90) days of this Order, the Holding Company shall submit to the Regional
Director an acceptable written plan to evaluate the effectiveness of, and strengthen, the
Association’s current internal audit program in the areas of residential mortgage loan servicing,
Loss Mitigation, and foreclosure activities and operations, as detailed in the Association Order.
Response
The Board of Directors (Board) of EverBank Financial Corp believes the Internal Audit function,
which operates within EverBank, is effective.1 The Internal Audit Department is committed to
providing EverBank an effective, independent resource for the ongoing evaluation of residential
loan processing. Internal Audit is enhancing its oversight of mortgage servicing by increasing
the frequency of audits, strengthening the standards by which audits are conducted, and adding
staff, technology resources, and training. The Audit Committee and Internal Audit identified
Default Servicing, which includes Foreclosure and Loss Mitigation, as a key audit area in its
2010 Plan. Internal Audit has begun the process of evaluating the frequency and depth of audit
plans in all Mortgage Loan Servicing. Additionally, Internal Audit will adjust its audit
schedule/scope accordingly if external or internal events indicate such a need.
Audit Plan
Presently, the 2011 Plan includes the already-completed Foreclosure Audit (report issued
4/26/11); other servicing audits in the 2011 Plan, and their scheduled commencement dates, are:
x
x
x

Default Accounting – 3Q11;
Asset Management (REO) - 4Q11; and
Portfolio Development - Loans Serviced by Others (LSBO) – 4Q11.

Loss Mitigation activities were most recently reviewed during the Default Servicing Audit
(report issued 12/9/10). In 2012 and beyond, Default Servicing will be an annual audit, ensuring
that Foreclosure, Loss Mitigation and its other key activities are audited frequently and
thoroughly.
Refer also to the 2012/2013 Internal Audit Plan, to be presented to, and approved by, the Audit
Committee of the Board of Directors at its December 8, 2011 meeting. This provides additional

1

In support of the Board’s own assessment, in 2010 the Audit Committee approved an independent third party to
conduct an initial Quality Assurance Review. This review served as an independent assessment of Internal Audit’s
compliance with the International Standards of the Institute of Internal Auditors (IIA). In its final report, the
independent third party noted that the Internal Audit Department complied with these Standards.

EverBank Financial Corp

Page 2

details regarding the timing of Servicing-related audits over the next two years, and summarizes
the 2011 Plan results to date.
The final report for Default Accounting has been issued. Both the Asset Management and LSBO
audits were moved into the 2012 Plan, primarily because of the time sensitivity to complete the
Loss Share and MERS audits within 2011.
In addition, Internal Audit will be conducting its initial audit of the new Compliance Oversight
and Process Support (COPS) unit this year, and is scheduled for 4Q11. Because COPS also has
a key role in evaluating Servicing’s operational and compliance processes, this will be an annual
audit going forward. The Board anticipates this will be a broad, comprehensive audit, and will
include a review of the five COPS units: (1) Compliance Program, (2) Lending Compliance, (3)
Deposit Compliance, (4) Reporting & Analytics, and (5) Monitoring & Testing. COPS will be
regularly conducting compliance and operational testing and reporting in Default Services and
other Mortgage Loan Servicing areas, so Internal Audit will evaluate the adequacy and
effectiveness of these reviews.

The initial COPS is now underway, to be completed and the final report issued likely in late
January 2012. Like Default Services, this is now scheduled as an annual internal audit.

Internal Audit also recognizes the need for ongoing analyses of key performance indicators and
other trending data between scheduled audits, and now has an initiative to perform such data
analyses relating to Default Servicing. Internal Audit will begin by obtaining an understanding
of Default Servicing’s regular reporting requirements, and determine how it can augment these
reports with its data analyses from an audit perspective. Using the programming and
stratification features of Microsoft Excel, it will begin running analytical reports in 3Q11,
refining these by trial and error.
However, more robust tools will be needed, so Internal Audit and advisors from our Technology
Services Division are presently meeting with vendors to evaluate, and ultimately select, audit
software tools for data mining and analysis. Internal Audit anticipates having this software
selected and in place by YE11.
This project will eventually evolve into a broader, enterprise-wide continuous auditing and
monitoring approach that will sync with EverBank’s enterprise risk management process.
Internal Audit’s Investigations/Support Team has been assigned the lead responsibility for the
continuous auditing program. The pilot program, a review of Foreclosure KPIs (Key
Performance Indicators) is underway.

EverBank Financial Corp
Internal Audit Plan 2/16/2012 8:28 AM

Page 3

EverBank is meeting with outside vendors to select a possible automated software solution,
which will carry into 2012. However, EverBank has an interim plan that may prove of greater
benefit. It learned that one of its IT Auditors has extensive programming experience, and is
skilled with various query tools internally. She is taking the lead on the queries for the
Foreclosure KPI pilot.
Board Reporting
The Director of Internal Audit will present a progress report at each quarterly Audit Committee
Meeting, beginning with the July meeting. This report will include the following:
x

The results of Mortgage Loan Servicing Audit Reports issued since the last Committee
meeting;
x The status of related audits/projects in progress;
x Development and results of the aforementioned data analytics, continuous auditing
project; and
x Any other noteworthy developments.
Internal Audit now has a wealth of subject matter expertise, from an audit perspective, for
Default, Foreclosure, and Loss Mitigation, and will continue to develop these skills and
knowledge base as the Department grows to meet business and risk demands. Three additional
positions on the Financial/Operations Team will be filled in 2011.
This reporting process to the Audit Committee continues.
The team members have augmented their SME experience with additional related audits this year
(Loss Share, Default Accounting, MERS,etc.).
Two of the three open Fin/Ops positions have been filled, and the third will be by early January
(interviews are underway).
The Board of EverBank Financial Corp is committed to full compliance with the Consent Order.
Additional details on Internal Audit can be found within Section 11(o) of EverBank’s
Compliance Program on the enclosed CD.
Additional Comments Regarding Federal Reserve Follow-Up, Specific to Audit Plan
1. i. Staffing Levels – Excepting the continuous auditing initiative mentioned above, the
Financial/Operations (Fin/Ops) Team has the lead role in the execution of Mortgage
Operations, including the bulk of the Consent Order requirements. Included in the
2012/2013 Audit Plan to the Audit Committee are organization charts (on pp, 16-17 &
50-51) that present the proposed staff levels and alignments for the Fin/Ops Team for
2012 and 2013.
EverBank Financial Corp

Page 4

ii. How staffing levels will be met – Although Internal Audit does not rule out the use of
co-sourcing audits of a more complex nature, its plan is to hire and promote organically.
Internal Audit is building out its Staff and Senior levels, and will be looking within this
group to begin promotions to the Supervisor level as soon as mid-late 2012.
iii. Expertise of staff – Assignments of mortgage operations audits are shared between the
two Fin/Ops teams (
and
are the Audit Managers of each;
refer to aforementioned org charts) and based on which team conducted the audit the
prior year, to leverage the knowledge already acquired.
iv. How gaps on expertise will be resolved – Internal Audit is always seeking auditors
with financial services experience;
However, occasionally, Internal Audit can still find such
experience; for example, it recently hired a Staff Auditor with prior loss
recovery/mitigation operations experience. EverBank had a much higher profile locally
and regionally in recent years, so it is becoming a company of choice for many job
seekers. As mentioned earlier, if Internal Audit feels that its in-house experience is not
sufficient for a specific audit, it will look to outside consultants, and have funds
earmarked in its fiscal plan should the need arise.
v. How identification of all auditable entities was done – Attached is a document that was
a synthesis of the various audit universe matrices developed and updated as part of the
2012/2013 Audit Plan. It continues to be a work in progress. This document has been
shared with the Audit Committee, with the acknowledgment that further updates and
refinement will be forthcoming next year.
2. Reference to SR 03-5, Amended Interagency Guidance on the Internal Audit Function and
Its Outsourcing- EverBank’s reporting structure ensures that Internal Audit maintains
independence. The Director of Internal Audit reports directly to the Audit Committee of
the Board of Directors, and does not report to any other committee, officer or employee
of EverBank. In addition to overseeing and conducting Audit Committee duties, the
Chair of the Audit Committee will perform employee evaluations on the Director of
Internal Audit, and determine appropriate salaries, incentive compensation, equity
awards, and other compensation, with the support of the Human Resources Department.

EverBank Financial Corp

Page 5