The full text on this page is automatically extracted from the file linked above and may contain errors and inconsistencies.
Board Oversight Plan of Risk Management, Internal Audit, and COPS Programs Date Prepared: June 27, 2011 EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 1 The Order states: Within ninety (90) days of this Order, the Board shall submit to the Regional Director an acceptable written plan to strengthen the Board’s oversight of the Association’s risk management, internal audit, and compliance programs concerning the residential mortgage loan servicing, Loss Mitigation, and foreclosure activities conducted by the Association. Response In order to ensure effective oversight of risk management, compliance and internal audit at EverBank, the Board of Directors (the Board) at EverBank Financial Corp oversees the establishment and maintenance of an environment that facilitates independent oversight and review of EverBank’s residential mortgage servicing, mortgage modification, mortgage foreclosure, and related mortgage loss mitigation activities (collectively, Mortgage Servicing Activities). In furtherance of that oversight responsibility, EverBank has implemented the following changes in its Risk Management, Compliance Oversight and Process Support (COPS), and Internal Audit Departments: 1. Establishment of a centralized compliance oversight function through the merger of the Compliance and Quality Control Departments. Response: EverBank initiated an enterprise-wide effort to expand and enhance its compliance and regulatory oversight functions in April 2010. At the core of this initiative was the creation of the centralized Compliance Oversight and Process Support (“COPS”) Department, which merged EverBank’s Compliance and Quality Control (“QC”) Departments into a centralized department reporting to EverBank’s General Counsel. In October 2010 EverBank appointed a dedicated Director of Regulatory Compliance responsible for the management of Compliance. Compliance engaged the firms of Buckley Sandler, LLC and Treliant Risk Advisors, LLC in April 2010 to consult with EverBank on the construct of compliance functionality. In addition, Compliance oversight of mortgage production and Residential Mortgage Loan Servicing, Loss Mitigation and Foreclosure activities was expanded to include other key areas of the bank. 2. Establishment of reporting structures to ensure that Risk Management, COPS, and Internal Audit have appropriate authority and independence to conduct their required reviews and oversight. Response: EverBank has established an organizational structure that supports the independence of Risk Management, Internal Audit and Compliance programs and provides requisite authority for execution of departmental responsibilities. x The Risk Management function is headed by EverBank’s Chief Risk Officer and holds the title Vice Chairman. The Chief Risk Officer reports indirectly to the Chairman of the Board. Risk Management operations are segregated from business unit functions thereby facilitating independent oversight of risks. EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 2 x Internal Audit reports directly to the Board of Directors’ Audit Committee and reports to the Chief Risk Officer for administrative functions. x Compliance management reports directly to EverBank’s General Counsel and routinely submit reports to the Regulatory Compliance Committee. Compliance is completely segregated from business units and as such maintains the necessary independence to execute its role without interference. 3. Development of policies and enhancements to the compliance program to formalize roles and responsibilities within the compliance function and provide a framework for monitoring and testing compliance with legal and supervisory requirements. Response: EverBank Executive Management previously identified that a formal Compliance Management System needed to be adopted by the organization. In response, EverBank engaged various outside firms to assess the organizations compliance management practices. As a result of the engagements and identification of the need for a formalized Compliance Management System, EverBank’s Compliance Management Program Policy (the “Policy”) was presented and approved by EverBank’s Board of Directors on October 25, 2011. This document specifies the practices, roles and responsibilities for the COPS Department in management of compliance oversight and reporting to EverBank’s Management, Committees and Board of Directors. 4. Development of detailed testing procedures to address specific legal and supervisory requirements related to Mortgage Servicing Activities. Response: While testing procedures have been enhanced to include regulatory components, a formal project is underway to conduct a full review of testing protocols. The plan associated with the initiative is scheduled for delivery in January, 2012 and will be provided to the Consent Order Office for monitoring. Reporting against progress will be incorporated into EverBank’s CTR. 5. Enhancement of Internal Audit’s oversight of mortgage servicing by increasing the frequency of audits, strengthening the standards by which audits are conducted, and adding staff, technology resources, and training. Response: EverBank’s 2012/2013 Internal Audit Plan, as well as periodic updates to the Oversight Committee, addresses the added emphasis toward audit of Mortgage Servicing activities. To support increased frequency of audits, the Plan presents a proposal to increase the staff complement of the Financial/Operations (Fin/Ops) Team, which has the lead responsibility for these Mortgage Servicing audits and those of other areas with responsibilities identified in the corrective action plan for the Consent Order. 6. Internal Audit’s evaluation of the frequency and depth of audit plans in all Mortgage Servicing Activities, with adjustments to its audit schedule and scope made accordingly if external or internal events indicate such a need. Response: Internal Audit’s 2012/2013 was developed with an increased focus on Residential Mortgage Loan Servicing, Loss Mitigation and Foreclosure activities. In communication with the Audit Committee, Internal Audit continues to convey the fluidity of annual plans, as well as the necessity of scheduling agility to address events of a sudden or urgent nature. The status of this effort is 100% complete and evidenced in the Internal Audit Plan. EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 3 7. Internal Audit’s ongoing analyses of key performance indicators and other trending data between scheduled audits, with an initiative to perform such data analyses relating to Default Servicing. Response: Internal Audit’s Investigations/Support team has begun a continuous auditing initiative, and is working on its pilot project, a review of Foreclosure’s Key Performance Indicators (KPIs). The status of this effort is ongoing. Tracking of progress for this initiative will be integrated into the Consent Order Office CTR. 8. Internal Audit’s evaluation, and ultimately selection, of audit software tools for data mining and analysis, anticipated to be in place by year-end 2011. Response: An initiative is underway to evaluate continuous auditing software for usage by EverBank’s Internal Audit Department. The timeline for completing an evaluation and software selection is second quarter 2012. In the interim, a pilot project is underway to evaluate and trend Foreclosure KPI data to determine how EverBank might employ such software. Tracking of progress for this initiative will be integrated into the Consent Order Office CTR. 9. Hiring of additional subject matter expertise, from an audit perspective, for Default, Foreclosure, and Loss Mitigation, with additional staffing additions expected in 2011. Response: The search for qualified staff with requisite subject matter expertise is ongoing. Resources were added in October 2011 with loss recovery / mitigation experience and the department is actively recruiting for others. Funding has been established in the 2012 budget for supplementing staff resources as needed through the engagement of consultants/SMEs as necessary. This effort is ongoing. 10. Implementation of a Board-level Risk Committee providing strategic oversight to EverBank’s risk management. Response: EverBank created a board level Risk Committee on July 26, 2011. 11. Formalization of a Chief Risk Officer position that reports to the Risk Committee. Response: EverBank created a Chief Risk Officer position on July 26, 2011. The Chief Risk Officer reports indirectly to the Chairman of the Board. 12. Formalization and addition of resources to an Enterprise Risk Management (ERM) Team that will provide framework and governance enterprise-wide. Response: Formalization of an Enterprise Risk Management program within EverBank began includes the designation of a Chief Risk Officer and board level Risk Committee which has been implemented. In addition, resourcing a senior executive level leader for operational management of the ERM program has been completed. Staffing of the ERM initiative has been facilitated by the addition of five additional resources with supplemental staffing gained through outsourcing of certain functions to a third party vendor. As ERM functions evolve, staffing will be reviewed on an ongoing basis to assure resource adequacy. 13. Adoption of standards and categorizations related to risks, controls and associated training for all officers. Response: EverBank has adopted a Risk Taxonomy and has presented same in officer training sessions conducted throughout EverBank. In addition to the Risk Taxonomy, the training sessions covered how risk management is viewed within EverBank, usage of EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 4 common language, and how to mitigate risks within business units. Training was conducted in March, April and June of 2011. 14. Enhancement of the annual risk assessment process and a quarterly update of any changes made to a high or critical risk or control reported to the ERM office. Response: Annual Risk Assessments were in existence for several years under FDICIA programs within EverBank. The program has been enhanced through the implementation of a formal review facilitated by the ERM Team. An additional enhancement is migration of the risk assessment to the platform which will enable reporting and mapping against EverBank’s Risk Taxonomy. The migration to the platform is scheduled for first quarter 2012 and is 80% complete. Tracking of progress for this initiative will be integrated into the Consent Order Office CTR. 15. Development of a process for all significant general ledger accounts to be tested and reported on a quarterly basis to the ERM office. Response: The review of significant GLs has been enhanced through the addition of dedicated ERM staff with an accounting background. The review process has been formalized and is 100% complete. 16. Centralization of reporting for the Consent Order Compliance Tracking Report. Response: In response to the Consent Order, EverBank created a Consent Order Office to oversee activities committed to in EverBank’s Consent Order response, to monitor progress against plan, and report on these activities to EverBank’s Board Oversight Committee, Senior Management, and Regulators. 17. Increased staffing of both COPS and Legal Departments to accommodate increased reviews and workloads. Response: The Legal Department has hired several attorneys and support staff within the last year to help support EverBank’s growth company-wide. Currently, EverBank has two attorneys dedicated Servicing, loss mitigation and foreclosure activities, one of which also supports company-wide, risk management issues. It has other attorneys that provide corporate governance and reporting support to the Oversight Committee and Board of Directors. The COPS department has created an organization structure that significantly increases staffing to support EverBank and specifically Residential Mortgage Loan Servicing, Loss Mitigation, and Foreclosure activities. In the Servicing unit, COPS has increased staff to include two managers and eleven staff members to provide compliance oversight. Open positions exist in the Servicing structure and are anticipated to be filled in the first quarter 2012. Tracking of progress in completing the staffing structure will be integrated into the Consent Order Office CTR. 18. Enhancement of governance by the ERM Team of all categories of risks to meet requirements as defined by our current and future regulatory agencies, and will continue to enhance the process for independent testing and monitoring of enterprise wide risks and controls. Response: Development of the ERM structure has been implemented within EverBank and is reviewed on an ongoing basis in response to changing industry and market requirements. While risk assessments were in existence, a significant effort is underway to review and EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 5 evaluate risks across the company and to identify/affirm mitigating controls. This effort is scheduled for completion in first quarter 2012 and is 90% complete. 19. Development of a roadmap to lay out the framework, structure and major milestones of how EverBank will continue to improve and sustain the governance of risks and controls. Response: EverBank’s ERM team has developed an ERM Roadmap which identifies and prioritizes risk management initiatives which will be undertaken over the next several years. The ERM Roadmap was included in the updated Risk Management Plan. 20. Implementation of a new risk tracking and reporting system, to provide enhanced tracking, monitoring and reporting from the aggregate to the individual control levels, to ensure decisions makers have the relevant information to make appropriate decisions. Response: EverBank’s ERM Team is in the process of rolling out a Governance, Risk and Compliance (GRC) application titled to the bank. is a robust and respected risk management application which is highly rated by Gartner’s Magic Quadrant review of similar software. The application has several modules and the Vendor Management function is in production. The controls module is staged and awaiting population. The content to be used in populating the application is being developed and is 90% complete. The system will be populated and in production in the first quarter 2012. To strengthen Board oversight of Risk Management, Internal Audit, and COPS programs related to mortgage servicing, the Board will ensure that teams and departments are conducting independent testing, and monitoring enterprise-wide risks and controls in an effective and timely manner across Mortgage Servicing Activities including those that are newly developed or have been recently enhanced. The Board will oversee functions, reporting structures, policies, procedures, and enhancements, specifically related to Mortgage Servicing Activities, to ensure adequacy. The Board will utilize enhanced reporting that incorporates information from Mortgage Servicing Activities to ensure its understanding of EverBank’s activities and the exposure these activities pose to EverBank and EverBank Financial Corp. To specifically strengthen EverBank’s risk management process, the ERM Team will implement governance to cover all areas of risk as defined by regulatory examination standards for large banks. Deficiencies in, or non-compliance with, laws, rules, regulations or policies relating to Mortgage Servicing Activities (collectively, Deficiencies) identified by Risk Management, COPS, or Internal Audit, are communicated promptly to the appropriate business unit, executive management or Board Committee, including the Regulatory Compliance Committee and the Operational Risk Committee. All deficiency findings are reported to the Board’s Audit Committee, with material deficiencies, to the extent applicable, reported to the full Board. EverBank has established reporting structures to ensure that Risk Management, COPS, and Internal Audit have appropriate authority and independence to conduct their required reviews and oversight. EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 6 The Director of COPS reports directly to EverBank’s General Counsel, and chairs and regularly submits written reports to the Regulatory Compliance Committee. COPS operates wholly independent of EverBank’s business operations. The Director of Internal Audit issues directly to the Board’s Audit Committee certain audit reports documenting any Deficiencies and corrective actions necessary to remediate any such Deficiencies. EverBank’s Chief Risk Officer exercises direct control of Risk Management, holds the title of Vice Chairman of the Board, and reports indirectly to the Chairman of the Board. Risk Management’s operations are segregated from EverBank’s business operations, thereby facilitating independent oversight of risks to EverBank and help identify and mitigate Deficiencies. Risk Management, COPS and Internal Audit have the authority to conduct appropriate oversight and reviews of business processes and identify potential Deficiencies, direct corrective actions relating to Deficiencies, and ensure remediation in connection therewith. The Board is kept abreast of Deficiencies and remediation related to these Deficiencies through regular Board reporting. Any enhancements, developments, and/or material changes to EverBank’s processes, procedures, and polices are provided to the Board through regular Board reporting to ensure the Board remains aware and involved in the oversight of EverBank’s activities, whether existing, enhanced, or newly developed, related to Mortgage Servicing Activities. The Board of EverBank Financial Corp is committed to full compliance with the Consent Order. Additional details on Risk Management, Internal Audit, and COPS Departments can be found within EverBank’s plans, programs, policies, procedures and processes on the enclosed CD. EverBank Financial Corp Risk Management, Internal Audit, and COPS Plan Page 7 RiskManagementPlan DatePrepared: June27,2011 DateRevised:December6,2011 ͳʹȀȀʹͲͳͳͷǣͳͲ ͳ The Order states: Within ninety (90) days of this Order, the Holding Company shall submit to the Regional Director an acceptable written plan to evaluate the effectiveness of, and strengthen, the Association’s risk management program addressing residential mortgage loan servicing, Loss Mitigation, and foreclosure activities and operations, and make recommendations to strengthen the Association’s risk management program in these areas. Response: The Board of Directors of EverBank Financial Corp (the Board) recognizes the importance of having effective risk management throughout the organization. To accomplish this, the Board has overseen changes and enhancements to the Risk Management Program. An enterprise assessment of risk management was performed by an independent consultant, KPMG, LLC. Recommendations were made to enhance the risk management in several areas, including residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations. The excerpt from the assessment is attached with the recommendations. The recommendations have been prioritized as evidenced by the ERM Roadmap attached. All risk management projects related to the Consent Order will be tracked in the Compliance Tracking Report that is provided to the Board Oversight Committee. Internal and external events continue to drive change, and the Board is committed to responding to these events and monitoring the evolvement of the Risk Management Department. The following actions have also been taken in response to the EFC Consent Order: Formed a Consent Order Oversight Committee that performed the following functions. x x Reviewed the plan for monitoring the Consent Order at the Bank level. Approved the monitoring tool that provides a status of each of the Plans for all areas of servicing, including residential mortgage loan servicing, Loss Mitigation and foreclosure activities and operations. Ongoing monitoring of the Consent Order Compliance Tracking Report occurs on a quarterly basis. Additions to the original plan include adding the monitoring of the Compliance, Internal Audit and Risk plans into the Compliance Tracking Report. Enterprise Risk Management (ERM) is defined by the Board to include all functions within the organization, including mortgage servicing, Loss Mitigation, and foreclosure activities and operations. Changes to EverBank’s risk management oversight include the enhancement of the Enterprise Risk Committee, additional staffing, and the review of enterprise-wide functions, such as Internal Audit, Compliance Operations and Process Support (COPS), and ERM. ͳʹȀȀʹͲͳͳͷǣͳͲ ʹ The following list includes existing or updated program elements and recommended enhancements implemented as a result of both internal and external reviews. x x x x x x x x x x x x The implementation of a Board-level Risk Committee providing strategic oversight to EverBank’s enterprise risk management including residential mortgage servicing, Loss Mitigation and foreclosure activities and operations, effective July 26, 2011 The formalization of a Chief Risk Officer position that reports to the Risk Committee, effective July 26, 2011. The formalization and addition of resources to an ERM team that will provide framework and governance enterprise-wide, including residential mortgage servicing, Loss Mitigation and foreclosure activities and operations, effective June 28, 2011. Adoption of standards and categorizations related to risks, controls and associated training for all officers, including residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations, completed June 2011 Enhancement of the annual risk assessment process and a quarterly update of any changes made to a high or critical risk or control for residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations reported to the ERM office will be performed within the risk monitoring and tracking system, January, 2012. A process for all significant general ledger accounts to be tested and reported on a quarterly basis to the ERM office for residential mortgage servicing, Loss Mitigation and foreclosure activities and operations, implemented and ongoing each quarter Centralized reporting for the Consent Order Compliance Tracking Report which includes tracking all Compliance, Internal Audit and Risk Management program components relating to residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations, implemented in September 2011 and ongoing. The COPS and Legal Departments are increasing staff to accommodate increased reviews and workload, ongoing Regulatory training is required and tracked for all employees in all areas related to residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations, ongoing and tracked in the EverBank Learning Management System A formalized committee structure exists that addresses various risk categories, such as Credit and Operational Risk which include residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations. Internal Audit performs the organization’s risk management, control and governance processes to determine adequacy and report all findings to the Board’s Audit Committee as part of its routine audit schedule which includes residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations. (See Internal Audit Plan for 2012) COPS performs regularly scheduled reviews of regulatory requirements, including residential mortgage servicing, Loss Mitigation, and foreclosure activities and operations. (See COPS Audit Plan for 2012) In addition to the above governance, the mortgage servicing unit has implemented the following processes: ͳʹȀȀʹͲͳͳͷǣͳͲ ͵ x x x A rigorous control process for any changes that impact systems, processes, procedures, and customer communications. Senior servicing managers, line of business managers, and process supervisors all participate as part of the approval body in the change control process. Key performance indicators are monitored to ensure that processes are completed timely and accurately. Monthly loss meetings to review root causes of losses within mortgage servicing. To strengthen the risk management process, the ERM team will enhance governance of all categories of risks to meet requirements as defined by our current and future regulatory agencies, and will continue to enhance the process for independent testing and monitoring of enterprise wide risks and controls. A roadmap has been developed (see attached) to lay out the framework, structure and major milestones of how EverBank will continue to improve and sustain the governance of risks and controls. A new risk tracking and reporting system, is being implemented that will provide enhanced tracking, monitoring and reporting from the aggregate to the individual control levels, to ensure decisions makers have the relevant information to make appropriate decisions. The Board understands the importance of the Risk Management function and will continue to oversee any changes or enhancements that are needed. The Board is committed to full compliance with EverBank Financial Corp’s Consent Order. Additional details on Risk Management can be found within Section 11(o) of EverBank’s Compliance Program on the enclosed CD. ͳʹȀȀʹͲͳͳͷǣͳͲ Ͷ OrganizationalDevelopment ReviewofCOPSPlan DatePrepared: June27,2011 ͳʹȀͻȀʹͲͳͳͻǣʹͶ ͳ TheOrderstates: Withinninety(90)daysofthisOrder,theHoldingCompanyshallsubmittotheRegionalDirector an acceptable written plan to evaluate the effectiveness of, and strengthen, the Association’s compliance program addressing residential mortgage loan servicing, Loss Mitigation, and foreclosureactivitiesandoperations,asdetailedintheAssociationOrder. Response EverBank Financial Corp recognizes the need for an effective compliance department. To ensure the compliance department remains effective, changes and enhancements to the ComplianceOversightandProcessSupport(COPS)Departmentfunctionsareevaluatedonan ongoing basis. EverBank began an enterprisewide effort to expand and enhance its compliance and regulatory oversight functions beginning in early 2010. The recentlyformed COPS Department merged EverBank’s Compliance and Quality Control Departments into a centralizeddepartmentreportingtoEverBank’sGeneralCounselinNovember2010.TheBoard of Directors (Board) of EverBank Financial Corp realizes the need for a structured and formalized compliance management program and an effective communication process to ensure the Board is made aware of any significant compliance matters that may affect the healthoftheorganization.Thestructureofcommitteesthatreportoncompliancematterswas addressed, and plans to enhance compliance reporting to the Board through the Regulatory Compliance Committee is in process. The Board is fully committed to oversight of the compliance management program and understands the increased regulatory scrutiny and importanceofadherencetoconsumerprotectionlaws. The Board of EverBank has approved the COPS Regulatory Compliance Program and the Compliance Monitoring and Testing Program with the submission of the documents in June 2011 pertaining to the EverBank Consent Order. The programs were a cumulative development effort of various outside legal firms, inhouse counsel, and compliance team membersandmanagerstoensureEverBankhasacompletecompliancemanagementprogram thataddressesthefullcycleofcompliancefromregulatorycommunicationsthroughcorrective action completion and documentation processes in all areas of EverBank, including Mortgage ServicingandLoanAdministration. Inadditiontothecurrentcomplianceoversightofmortgageproductionandservicingactivities, several key areas will have compliance oversight managed under the COPS Department that include: EverTrade/World Markets, EverBank Wealth Management, the various Banking Operations areas, an enhanced and centralized BSA/AML program, an enhanced Compliance MonitoringandTestingprogramandFairLendinganalyticsunit.TheFairLendinggroupwithin COPSalsomanagesHMDAandCRAreportingresponsibilities. ͳʹȀͻȀʹͲͳͳͻǣʹͶ ʹ TheBoardofEverBankhasreviewedandagreeswithplanstoleverageadditionaltechnology and staffing resources to implement several key compliance oversight initiatives identified in 2010and2011,andwillbemonitoringthescheduleforimplementationdatesforcompletionin 2011 and 2012. Some of these initiatives include, but are not limited to, the following enhancements: x StaffingandDevelopment; Ananalysiswasconductedbyoutsideconsultingfirmandinternalstafftoquantify appropriatestaffinglevelsforthecompliancefunctions. Subsequenttothe analysis,managementconcludedinNovember2010tocreateanintegratedCompliance andQualityControlprogram.Sincethattimethenumberofcompliancestaffdedicated toResidentialMortgageLoanServicing,LossMitigationsandForeclosurecompliance andmonitoringandtestingactivitieshasexpandedsignificantly.Intheorganization structureapprovedasofDecember2011,therearethirteenstaffmembersdedicatedto compliancefunctionsforthesebusinessunits.Openpositionsexistandareprojectedto befilledduringfirsthalfof2012. Intheinterim,outsidefirmsarebeingemployedtosupplementstaffinglevelsand providesubjectmatterexpertise. ReportingonstaffrecruitingwillbeincorporatedintoEverBank’sConsentOrderOffice CTRReporting. x Review of committee communications & formulation of a “Compliance Steering Committee”(reportingthroughtheRegulatoryComplianceCommittee); AspartoftheEnterpriseRiskManagement(“ERM”)formationananalysisofEverBank’s committeeandreportingstructurewasconducted.TheComplianceSteering CommitteewasdeterminedtoberedundanttotheRegulatoryComplianceCommittee (“RCC”).RCCreportingincludescompliancerelatedupdatesfrommembersand incorporatesanescalationprocesstotheOperationalRiskCommittee.RCCmembers, whoalsoserveasmanagementtobusinessunitsatEverBank,areactivelyinvolvedin regularbusinessactivitiesandareaccountableforreportingcompliancerelatedissues totheRCC.TheChairpersonoftheRCCistheManagingMortgageRegulatoryDirector ofCOPS,withfullresponsibilitiesforreportingcomplianceissuesandensuring correctiveactionsareaddressed. ͳʹȀͻȀʹͲͳͳͻǣʹͶ ͵ TheRCCCharterwasreviewedtoensureproperpoliciesandprocessesareinplaceto monitorandreportonallnewormodifiedcompliancematters;toensurethataction plansaremonitoredandreportedon,withescalationasappropriate. TheServicingChangeControlCommitteemeetstwicepermonthwithLegalandCOPS staffinattendance.AgendaitemsfocusonResidentialMortgageLoanServicing,Loss MitigationandForeclosureservicinginitiatives,changestoregulationsandplansto remediatesystems,policiesandprocedureswherenecessary.TheServicingRisk CommitteealsomeetsquarterlywithLegalandCOPSstaffinattendance.Themeetings focusonsimilaragenda,however,arestrategicandriskfocusedinnature.Thestatusof thiseffortiscompleteandongoing. x Creationofthe“RegulatoryAccountabilityandCommunicationsMatrix”toensureall regulatorycompliancemattersarecommunicatedandhavetheproperoversightin COPS; Regulatorymatriceshavebeendevelopedtoidentifythelawsandregulations associatedwithResidentialMortgageLoanServicing,LossMitigationandForeclosure forwhichtheCOPSdepartmentisaccountable.Thespecificregulationsaredefinedin theRegulatoryComplianceCommitteeCharter(attached)as“CoveredLaws”.While initialmatricesarecomplete,theprocessofmaintenanceisongoing. x CreationoftheComplianceLibraryandProcedures; COPShasdevelopedandimplementedareadilyaccessiblesharepointsitetohouseall sourcedocumentsforcorporatereview.Thesiteismaintainedtoincludeallupdated materialsandisavailabletoallEverBankemployees. Complianceproceduresarebeingreviewedforcompletenessandaccuracy. Enhancementswillbeincorporateintorevisedproceduresaswarrantedthroughthe reviewprocess.BuckleySandlerhasbeenengagedtoconductthereviewofprocedures andmatrices.ProjectplansareindevelopmentinconjunctionwithBuckleySandler Oncetheprojectplanshavebeenapprovedandimplementationbegun,trackingof progresstoplanwillbeincorporatedintotheConsentOrderOfficeCTR. x EnhancementoftheRegulatoryComplianceTrainingProgramfornewDoddFrankrules; COPSinitiatedareviewofcompliancetrainingdeliverymechanismsandtoolsinearly 2011.Thepurposewastoevaluatethebestmethodfordeliveringcompliancetraining ͳʹȀͻȀʹͲͳͳͻǣʹͶ Ͷ touserswithgreatestunderstandingandretentionasevidencedbyposttraining evaluations.AteamcomprisedofemployeesfromLearning&Organizational Development,MortgageLoanProductionTraining,MortgageLoanServicingTraining, andBranchOperationsTrainingwasformedandreviewedvendorsprovidingonline training.ThevendorselectedfordeliveryofEverBank’scompliancetrainingoffers onlinevideoandknowledgeexercisesimbeddedwithincoursestoactivelyengagethe employeeaboveandbeyondfinalexamsforeachcourse.EverBankbeganusingthenew vendorforonlinecompliancecourseassignmentsonJuly1,2011.COPSdetermines appropriatecoursesbasedonthebusinessunitareasofresponsibilitywhilethe LearningandOrganizationalDevelopmentdepartmentmanagethelearning managementsystemandassignsthecoursestothetargetedemployees. Duringthereviewoftrainingpractices,theRegulatoryComplianceTrainingPolicywas reviewedandenhanced.TherevisedpolicywassubmittedandapprovedbytheRCC. Whilethenewtrainingprogramisinproduction,curriculumisunderongoingrevisionto reflectchangessuchasDoddFrank. x Review and enhancement of complaint management processes and reporting and analysisoftrends; In the time prior to October 2011, EverBank maintained a process for complaint monitoringthatincorporateddesignatedstaffinvariousbusinessunitstocaptureand report complaints in spreadsheets, and submission of those spreadsheets to COPS for monitoringandtestingpurposes.InOctober2011,COPSreleasedaComplaintTracking Systemthatusersinbusinessunitsemploytoenterspecificdatarelatedtocomplaint intake.Thesystemallowsformorerobustreportingandincorporatesspecificquestions relative to Residential Mortgage Loan Servicing, Loss Mitigation and Foreclosure. In addition, the system maintains information and indicators which allow for ready trackingofcomplaintsrelatedtothirdpartyvendors.ReportsareprovidedtotheCOPS monitoring and testing units, business units and Third Party Review Committee on a regularschedule.TheComplaintTrackingSystemhasbeendeployedandisinuse. Enhancements to the Complaint Tracking System are underway and include reporting enhancements scheduled for production in first quarter 2012. Monitoring of the reportingenhancementswillbeincorporatedintotheConsentOrderOfficeCTR. x Reviewofbusinessunitpolicyandproceduredocumentationtoensurecomplianceand consistencywithactualbusinesspractices; ͳʹȀͻȀʹͲͳͳͻǣʹͶ ͷ AsaresultoftheConsentOrder,COPSengagedsubjectmatterexpertsfromKPMGto evaluatetheMonitoringandTestingprocessasitrelatedtoResidentialMortgageLoan Servicing,LossMitigationandForeclosureactivities.MonitoringandTestingprotocols wereenhancedbaseduponthereviewtoincorporateConsentOrderrequirements. Treliant Risk Advisors has been engaged to assist EverBank COPS management in performing a Compliance Risk Assessment of all business units. The assessment will includeareviewofpoliciesandprocedureswithinthebusinessunitsandcomparisonto practices. x ReportingonprogresstoplanwillbeincorporatedintoEverBank’sConsentOrderOffice CTR. Enhancement and creation of efficiencies in managementand committee reporting of ComplianceTestingresultsandloanleveltrending; EverBank has engaged the firm Buckley Sandler to assist in a review and design enhancement of its Monitoring and Testing program. The review will incorporate all requisite operational, regulatory and agency checkpoints to ensure a rigorous MonitoringandTestingprogramthatsupportsEverBank’sComplianceprogram.Project Plansareindevelopmentandaredueinearly2012forEverBankreview.Reportingon progresstoplanwillbeincorporatedintoEverBank’sConsentOrderOfficeCTR. x Enhancementofservicingcomplianceandinvestormonitoringandtesting; AchievementofthiscomponentofEverBank’sresponsewillbefacilitatedthroughthe BuckleySandlerandTreliantengagements. x Alignmentofcompliancereviewswithinternalauditreviews. Testing of adherence to regulatory requirements was formerly bifurcated between Internal AuditandQualityControl.WiththecreationofCOPS,allCoveredLawsasdefinedintheRCC Charter are under the purview of the combined organization, COPS. Several wellqualified employeeshavebeenhiredstartinginlate2010uptothepresentdateforthebuildoutofthe COPSDepartment.ThreeCOPSManagers(inadditiontotheManagingDirectorofRegulatory Compliance) and five Compliance Analysts (seven more staff are planned for hire in the next two months) have been added to the COPS Department. All of the managers and four staff membersarededicatedtomortgageservicingcomplianceoversightandmonitoringandtesting reviews. ͳʹȀͻȀʹͲͳͳͻǣʹͶ A formal “Change Control Procedure and Checklist” has been implemented to document changes in business practices and ensure COPS management and the Legal Department authorizeschangesaffectingcompliancewithlawsandregulations.Thechangecontrolprocess willalsoensurethatscheduledcompliancereviewsareperformedascorporateorregulatory environments change. A thorough compliancerisk assessment of the COPS Department is in processtoensureadequatestaffingandresourcesareallocatedtocompliancemanagement. The Legal Department will retain the responsibilities of examination management oversight; however, COPS will coordinate the document gathering and business area support of agency audits.Correctiveactionplanswillbedocumentedandcompletedefficientlywitharecordof thefollowupperformedbytheCOPSDepartment. TheBoardofEverBankFinancialCorpiscommittedtofullcompliancewiththeConsentOrder. Additional details on the COPS Department can be found within Section 11(o) of EverBank’s ComplianceProgramontheenclosedCD. ͳʹȀͻȀʹͲͳͳͻǣʹͶ Internal Audit Plan Date Prepared: June 27, 2011 Date Revised: December 7, 2011 2nd Date Revised: December 15, 2011 3rd Date Revised: December 22, 2011 4th Date Revised: January 12, 2012 EverBank Financial Corp Page 1 The Order states: Within ninety (90) days of this Order, the Holding Company shall submit to the Regional Director an acceptable written plan to evaluate the effectiveness of, and strengthen, the Association’s current internal audit program in the areas of residential mortgage loan servicing, Loss Mitigation, and foreclosure activities and operations, as detailed in the Association Order. Response The Board of Directors (Board) of EverBank Financial Corp believes the Internal Audit function, which operates within EverBank, is effective.1 The Internal Audit Department is committed to providing EverBank an effective, independent resource for the ongoing evaluation of residential loan processing. Internal Audit is enhancing its oversight of mortgage servicing by increasing the frequency of audits, strengthening the standards by which audits are conducted, and adding staff, technology resources, and training. The Audit Committee and Internal Audit identified Default Servicing, which includes Foreclosure and Loss Mitigation, as a key audit area in its 2010 Plan. Internal Audit has begun the process of evaluating the frequency and depth of audit plans in all Mortgage Loan Servicing. Additionally, Internal Audit will adjust its audit schedule/scope accordingly if external or internal events indicate such a need. Audit Plan Presently, the 2011 Plan includes the already-completed Foreclosure Audit (report issued 4/26/11); other servicing audits in the 2011 Plan, and their scheduled commencement dates, are: x x x Default Accounting – 3Q11; Asset Management (REO) - 4Q11; and Portfolio Development - Loans Serviced by Others (LSBO) – 4Q11. Loss Mitigation activities were most recently reviewed during the Default Servicing Audit (report issued 12/9/10). In 2012 and beyond, Default Servicing will be an annual audit, ensuring that Foreclosure, Loss Mitigation and its other key activities are audited frequently and thoroughly. Refer also to the 2012/2013 Internal Audit Plan, to be presented to, and approved by, the Audit Committee of the Board of Directors at its December 8, 2011 meeting. This provides additional 1 In support of the Board’s own assessment, in 2010 the Audit Committee approved an independent third party to conduct an initial Quality Assurance Review. This review served as an independent assessment of Internal Audit’s compliance with the International Standards of the Institute of Internal Auditors (IIA). In its final report, the independent third party noted that the Internal Audit Department complied with these Standards. EverBank Financial Corp Page 2 details regarding the timing of Servicing-related audits over the next two years, and summarizes the 2011 Plan results to date. The final report for Default Accounting has been issued. Both the Asset Management and LSBO audits were moved into the 2012 Plan, primarily because of the time sensitivity to complete the Loss Share and MERS audits within 2011. In addition, Internal Audit will be conducting its initial audit of the new Compliance Oversight and Process Support (COPS) unit this year, and is scheduled for 4Q11. Because COPS also has a key role in evaluating Servicing’s operational and compliance processes, this will be an annual audit going forward. The Board anticipates this will be a broad, comprehensive audit, and will include a review of the five COPS units: (1) Compliance Program, (2) Lending Compliance, (3) Deposit Compliance, (4) Reporting & Analytics, and (5) Monitoring & Testing. COPS will be regularly conducting compliance and operational testing and reporting in Default Services and other Mortgage Loan Servicing areas, so Internal Audit will evaluate the adequacy and effectiveness of these reviews. The initial COPS is now underway, to be completed and the final report issued likely in late January 2012. Like Default Services, this is now scheduled as an annual internal audit. Internal Audit also recognizes the need for ongoing analyses of key performance indicators and other trending data between scheduled audits, and now has an initiative to perform such data analyses relating to Default Servicing. Internal Audit will begin by obtaining an understanding of Default Servicing’s regular reporting requirements, and determine how it can augment these reports with its data analyses from an audit perspective. Using the programming and stratification features of Microsoft Excel, it will begin running analytical reports in 3Q11, refining these by trial and error. However, more robust tools will be needed, so Internal Audit and advisors from our Technology Services Division are presently meeting with vendors to evaluate, and ultimately select, audit software tools for data mining and analysis. Internal Audit anticipates having this software selected and in place by YE11. This project will eventually evolve into a broader, enterprise-wide continuous auditing and monitoring approach that will sync with EverBank’s enterprise risk management process. Internal Audit’s Investigations/Support Team has been assigned the lead responsibility for the continuous auditing program. The pilot program, a review of Foreclosure KPIs (Key Performance Indicators) is underway. EverBank Financial Corp Internal Audit Plan 2/16/2012 8:28 AM Page 3 EverBank is meeting with outside vendors to select a possible automated software solution, which will carry into 2012. However, EverBank has an interim plan that may prove of greater benefit. It learned that one of its IT Auditors has extensive programming experience, and is skilled with various query tools internally. She is taking the lead on the queries for the Foreclosure KPI pilot. Board Reporting The Director of Internal Audit will present a progress report at each quarterly Audit Committee Meeting, beginning with the July meeting. This report will include the following: x The results of Mortgage Loan Servicing Audit Reports issued since the last Committee meeting; x The status of related audits/projects in progress; x Development and results of the aforementioned data analytics, continuous auditing project; and x Any other noteworthy developments. Internal Audit now has a wealth of subject matter expertise, from an audit perspective, for Default, Foreclosure, and Loss Mitigation, and will continue to develop these skills and knowledge base as the Department grows to meet business and risk demands. Three additional positions on the Financial/Operations Team will be filled in 2011. This reporting process to the Audit Committee continues. The team members have augmented their SME experience with additional related audits this year (Loss Share, Default Accounting, MERS,etc.). Two of the three open Fin/Ops positions have been filled, and the third will be by early January (interviews are underway). The Board of EverBank Financial Corp is committed to full compliance with the Consent Order. Additional details on Internal Audit can be found within Section 11(o) of EverBank’s Compliance Program on the enclosed CD. Additional Comments Regarding Federal Reserve Follow-Up, Specific to Audit Plan 1. i. Staffing Levels – Excepting the continuous auditing initiative mentioned above, the Financial/Operations (Fin/Ops) Team has the lead role in the execution of Mortgage Operations, including the bulk of the Consent Order requirements. Included in the 2012/2013 Audit Plan to the Audit Committee are organization charts (on pp, 16-17 & 50-51) that present the proposed staff levels and alignments for the Fin/Ops Team for 2012 and 2013. EverBank Financial Corp Page 4 ii. How staffing levels will be met – Although Internal Audit does not rule out the use of co-sourcing audits of a more complex nature, its plan is to hire and promote organically. Internal Audit is building out its Staff and Senior levels, and will be looking within this group to begin promotions to the Supervisor level as soon as mid-late 2012. iii. Expertise of staff – Assignments of mortgage operations audits are shared between the two Fin/Ops teams ( and are the Audit Managers of each; refer to aforementioned org charts) and based on which team conducted the audit the prior year, to leverage the knowledge already acquired. iv. How gaps on expertise will be resolved – Internal Audit is always seeking auditors with financial services experience; However, occasionally, Internal Audit can still find such experience; for example, it recently hired a Staff Auditor with prior loss recovery/mitigation operations experience. EverBank had a much higher profile locally and regionally in recent years, so it is becoming a company of choice for many job seekers. As mentioned earlier, if Internal Audit feels that its in-house experience is not sufficient for a specific audit, it will look to outside consultants, and have funds earmarked in its fiscal plan should the need arise. v. How identification of all auditable entities was done – Attached is a document that was a synthesis of the various audit universe matrices developed and updated as part of the 2012/2013 Audit Plan. It continues to be a work in progress. This document has been shared with the Audit Committee, with the acknowledgment that further updates and refinement will be forthcoming next year. 2. Reference to SR 03-5, Amended Interagency Guidance on the Internal Audit Function and Its Outsourcing- EverBank’s reporting structure ensures that Internal Audit maintains independence. The Director of Internal Audit reports directly to the Audit Committee of the Board of Directors, and does not report to any other committee, officer or employee of EverBank. In addition to overseeing and conducting Audit Committee duties, the Chair of the Audit Committee will perform employee evaluations on the Director of Internal Audit, and determine appropriate salaries, incentive compensation, equity awards, and other compensation, with the support of the Human Resources Department. EverBank Financial Corp Page 5