Skip to Main Content

insightsarticles

Bank governance best practices: Optimizing your board of directors

08.17.23 /

Read this if you are a financial institution.

In today’s turbulent banking environment, the importance of effective bank governance has arguably never been more important. Banks currently face an arsenal of risks, some of them longstanding and others relatively new to the scene. Bank boards play a critical role in monitoring these risks and monitoring bank management, who is ultimately responsible for overseeing the day-to-day management of these risks. In July 2023, Bank Director published its 2023 Governance Best Practices Survey. This survey included responses from 195 independent directors, chairs, and chief executives of US banks below $100 billion in assets. The survey was conducted in April and May 2023. In this article, we share three of our key takeaways.

Board of directors' composition—board members and expertise 

Board composition is integral to the effectiveness of any board. Given the various risks faced by banks, it is essential that boards include board members with diverse experience. Electing board members with expertise in all facets of your bank, such as accounting, risk management, compliance, and information technology, will help ensure that conversations between board members and management are robust and meaningful. Having board members with diversified backgrounds and experience will allow them to respectfully challenge management’s initiatives and strategies, which will only serve to strengthen these initiatives and strategies. These board members will also become a resource for management. A board member who knows the ins and outs of a specific banking function, for instance, information technology, gives management confidence in the board’s oversight and provides management a resource to contact when the need arises.

The survey found that boards are generally well covered when it comes to having board members with finance and accounting experience. Specifically, 95% of respondents had finance and accounting experience. The finances and accounting of a bank have long been focal points of discussion in board rooms and ineffective financial management and/or inappropriate accounting methods can be detrimental. Thus, it is reassuring that so many respondents had finance and accounting experience, especially with such a monumental accounting change upon us: the current expected credit loss (CECL) standard.

However, a relatively newly heightened focus for banks, cybersecurity, did not see as robust a result: only 33% of respondents had cybersecurity expertise. With the vast amounts of data held by banks, institutions are a prime target for hackers. Furthermore, the avenues in which an attack can occur are nearly infinite. Cybersecurity is not glamorous. In other words, bank management would likely prefer to allocate resources toward other, more strategic initiatives, such as digital banking, new branches, new products, etc. This is even more reason to have a board member with cybersecurity experience. It is this individual who will fully understand cybersecurity’s importance and the risk that even a single cybersecurity incident could pose to the bank. 

Board of directors’ composition—board members and tenure 

53% of survey respondents indicated they have one or two directors who are 55 or younger, implying the remainder of the directors are over the age of 55. 33% indicated they have three or more directors who are 55 or younger, and 14% indicated they don’t have any directors who are 55 or younger. The current interest rate environment is one that many younger management teams have not seen in their professional lifetimes. However, the US prime rate, a proxy for overall interest rates, hit a record high in December 1980 of 21.50%. More experienced board members could be an invaluable resource to management teams in navigating this environment, as they have the ability to share practical solutions that may have been implemented during the high interest rate environment seen in the late 1970s through the 1990s. Even in June 2006 the US prime rate hit  8.25%.

While having longer tenured board members is important, having younger board members is equally as important, especially given the fast-changing operating environment. Digital banking is not a “nice-to-have” anymore—it is a must have. And the digital banking space is evolving quickly, with new technologies, platforms, and vendors popping up frequently. It is a lot of information to sift through. But younger board members, who may have grown up with these technologies and use them on a day-to-day basis, generally are better equipped to advise on digital strategy. It is these board members that generally have the ability to understand the bank’s customer from a digital perspective.

Asset/liability management

Asset/liability management (ALM) at banks has been a hot topic ever since the onset of the COVID-19 pandemic. Although ALM is always seen as a crucial task, even during stable times, it has taken on an increasing level of importance given the rollercoaster ride that balance sheets and income statements have experienced over the past few years. Significant deposit growth resulted in substantial excess liquidity, followed by tightening liquidity and surging unrealized losses as a result of rising interest rates. It has been a whirlwind for those in charge of ALM. Bank boards have effectively responded: 83% of respondents noted their board or relevant committee has revisited the bank’s ALM policies, processes, and programs within the past 6 to 12 months. Regardless of recent whirlwinds, it is likely best practice for bank boards to revisit ALM policies, processes, and programs on at least an annual basis. Some questions to consider on an annual basis are:

  • Do our thresholds and ranges still make sense given the current economic environment?
  • How does our ALM policy tie into the bank’s larger strategic plan? Do they complement one another or are they contradictory? If the latter, is our strategic plan unreasonable or does our ALM policy need to change?
  • Who is in charge of monitoring ALM on a day-to-day basis? Is it one individual or a team?
  • What types of information are being reported to the ALM committee? How about to the board? What is the frequency of communication?
  • Are there new products that have been implemented or that are being considered? How could these products impact ALM?
  • What impact has digital banking had on ALM? How about branch openings or closures?

Bank boards play an invaluable role in overseeing and monitoring the operations and risks of a bank. If the right individuals are put in place, a board can almost feel as if it is an extension of a bank’s management team, serving as a resource well beyond the board room. Although implementing ALM discussions into board conversations can happen immediately, our other key takeaways, namely board expertise and tenure, cannot change overnight. But as the Chinese proverb goes: “The best time to plant a tree was 20 years ago. The second-best time is now.” As board members either retire or term out, now may be the time to rethink your board recruiting strategy. Think about your bank’s strategic plan and consider if there are gaps in your board in the context of your strategic plan. If there are, what causes these gaps? Asking these questions will allow you to be more strategic in your board recruiting efforts, ultimately maximizing the effectiveness of your board in light of your institution’s intended strategy.

As always, please don’t hesitate to reach out to the BerryDunn financial services team or visit our Ask the Advisor page if you have any questions. 

Related Industries

Related Services

Accounting and Assurance

Related Professionals

Leaders

BerryDunn experts and consultants

In auditing, the concept of professional skepticism is ubiquitous. Just as a Jedi in Star Wars is constantly trying to hone his understanding of the “force”, an auditor is constantly crafting his or her ability to apply professional skepticism. It is professional skepticism that provides the foundation for decision-making when conducting an attestation engagement.

A brief definition

The professional standards define professional skepticism as “an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to fraud or error, and a critical assessment of audit evidence.” Given this definition, one quickly realizes that professional skepticism can’t be easily measured. Nor is it something that is cultivated overnight. It is a skill developed over time and a skill that auditors should constantly build and refine.

Recently, the extent to which professional skepticism is being employed has gained a lot of criticism. Specifically, regulatory bodies argue that auditors are not skeptical enough in carrying out their duties. However, as noted in the white paper titled Scepticism: The Practitioners’ Take, published by the Institute of Chartered Accountants in England and Wales, simply asking for more skepticism is not a practical solution to this issue, nor is it necessarily always desirable. There is an inevitable tug of war between professional skepticism and audit efficiency. The more skeptical the auditor, typically, the more time it takes to complete the audit.

Why does it matter? Audit quality.

First and foremost, how your auditor applies professional skepticism to your audit directly impacts the quality of their service. Applying an appropriate level of professional skepticism enhances the likelihood the auditor will understand your industry, lines of business, business processes, and any nuances that make your company different from others, as it naturally causes the auditor to ask questions that may otherwise go unasked.

These questions not only help the auditor appropriately apply professional standards, but also help the auditor gain a deeper understanding of your business. This will enable the auditor to provide insights and value-added services an auditor who doesn’t apply the right degree of skepticism may never identify.

Therefore, as the white paper notes, audit committees, management, and investors should be asking “How hard do our auditors get pushed on fees, and what effect does that have on the quality of the audit?” If your auditor is overly concerned with completing the audit within a fixed time budget, professional skepticism and, ultimately, the quality of the audit, may suffer.

Applying skepticism internally

By its definition, professional skepticism is a concept that specifically applies to auditors, and is not on point when it comes to other audit stakeholders. This is because the definition implies that the individual applying professional skepticism is independent from the information he or she is analyzing. Other audit stakeholders, such as members of management or the board of directors, are naturally advocates for the organizations they manage and direct and therefore can’t be considered independent, whereas an auditor is required to remain independent.

However, rather than audit stakeholders applying professional skepticism as such, these other stakeholders should apply an impartial and diligent mindset to their work and the information they review. This allows the audit stakeholder to remain an advocate for his or her organization, while applying critical skills similar to those applied in the exercise of professional skepticism. This nuanced distinction is necessary to maintain the limited scope to which the definition of professional skepticism applies: the auditor.

Specific to the financial statement reporting function, these stakeholders should be assessing the financial statements and ask questions that can help prevent or detect flaws in the financial reporting process. For example, when considering significant estimates, management should ask: are we considering all relevant information? Are our estimates unbiased? Are there alternative accounting treatments we haven’t considered? Can we justify our selected accounting treatment? Essentially, management should start by asking itself: what questions would we expect our auditor to ask us?

It is also important to be critical of your own work, and never become complacent. This may be the most difficult type of skepticism to apply, as most of us do not like to have our work criticized. However, critically reviewing one’s own work, essentially as an informal first level of review, will allow you to take a step back and consider it from a different vantage point, which may in turn help detect errors otherwise left unnoticed. Essentially, you should both consider evidence that supports the initial conclusion and evidence that may be contradictory to that conclusion.

The discussion in auditing circles about professional skepticism and how to appropriately apply it continues. It is a challenging notion that’s difficult to adequately articulate. Although it receives a lot of attention in the audit profession, it is a concept that, slightly altered, can be of value to other audit stakeholders. Doing so will help you create a stronger relationship with your auditor and, ultimately, improve the quality of the financial reporting process—and resulting outcome.

Article
Professional skepticism and why it matters to audit stakeholders

Do you know what would happen to your company if your CEO suddenly had to resign immediately for personal reasons? Or got seriously ill? Or worse, died? These scenarios, while rare, do happen, and many companies are not prepared. In fact, 45% of US companies do not have a contingency plan for CEO succession, according to a 2020 Harvard Business Review study.  

Do you have a plan for CEO succession? As a business owner, you may have an exit strategy in place for your company, but do you have a plan to bridge the leadership gap for you and each member of your leadership team? Does the plan include the kind of crises listed above? What would you do if your next-in-line left suddenly? 

Whether yours is a family-owned business, a company of equity partners, or a private company with a governing body, here are things to consider when you’re faced with a situation where your CEO has abruptly departed or has decided to step down.  

1. Get a plan in place. First, assess the situation and figure out your priorities. If there is already a plan for these types of circumstances, evaluate how much of it is applicable to this particular circumstance. For example, if the plan is for the stepping down or announced retirement of your CEO, but some other catastrophic event occurs, you may need to adjust key components and focus on immediate messaging rather than future positioning. If there is no plan, assign a small team to create one immediately. 

Make sure management, team leaders, and employees are aware and informed of your progress; this will help keep you organized and streamline communications. Management needs to take the lead and select a point person to document the process. Management also needs to take the lead in demeanor. Model your actions so employees can see the situation is being handled with care. Once a strategy is identified based on your priorities, draft a plan that includes what happens now, in the immediate future, and beyond. Include timetables so people know when decisions will be made.  

2. Communicate clearly, and often. In times of uncertainty, your employees will need as much specific information as you can give them. Knowing when they will hear from you, even if it is “we have nothing new to report” builds trust and keeps them vested and involved. By letting them know what your plan is, when they’ll receive another update, what to tell clients, and even what specifics you can give them (e.g., who will take over which CEO responsibility and for how long), you make them feel that they are important stakeholders, and not just bystanders. Stakeholders are more likely to be strong supporters during and after any transition that needs to take place. 

3. Pull in professional help. Depending on your resources, we recommend bringing in a professional to help you handle the situation at hand. At the very least, call in an objective opinion. You’ll need someone who can help you make decisions when emotions are running high. Bringing someone on board that can help you decipher what you have to work with and what your legal and other obligations may be, help rally your team, deal with the media, and manage emotions can be invaluable during a challenging time. Even if it’s temporary. 

4. Develop a timeline. Figure out how much time you have for the transition. For example, if your CEO is ill and will be stepping down in six months, you have time to update any existing exit strategy or succession plan you have in place. Things to include in the timeline: 

  • Who is taking over what responsibilities? 
  • How and what will be communicated to your company and stakeholders? 
  • How and what will be communicated to the market? 
  • How will you bring in the CEO's replacement, while helping the current CEO transition out of the organization? 

If you are in a crisis situation (e.g., your CEO has been suddenly forced out or asked to leave without a public explanation), you won’t have the luxury of time.  

Find out what other arrangements have been made in the past and update them as needed. Work with your PR firm to help with your change management and do the right things for all involved to salvage the company’s reputation. When handled correctly, crises don’t have to have a lasting negative impact on your business.   

5. Manage change effectively. When you’re under the gun to quickly make significant changes at the top, you need to understand how the changes may affect various parts of your company. While instinct may tell you to focus externally, don’t neglect your employees. Be as transparent as you possibly can be, present an action plan, ask for support, and get them involved in keeping the environment positive. Whether you bring in professionals or not, make sure you allow for questions, feedback, and even discord if challenging information is being revealed.  

6. Handle the media. Crisis rule #1 is making it clear who can, and who cannot, speak to the media. Assign a point person for all external inquiries and instruct employees to refer all reporter requests for comment to that point person. You absolutely do not want employees leaking sensitive information to the media. 
 
With your employees on board with the change management action plan, you can now focus on external communications and how you will present what is happening to the media. This is not completely under your control. Technology and social media changed the game in terms of speed and access to information to the public and transparency when it comes to corporate leadership. Present a message to the media quickly that coincides with your values as a company. If you are dealing with a scandal where public trust is involved and your CEO is stepping down, handling this effectively will take tact and most likely a team of professionals to help. 

Exit strategies are planning tools. Uncontrollable events occur and we don’t always get to follow our plan as we would have liked. Your organization can still be prepared and know what to do in an emergency situation or sudden crisis.  Executives move out of their roles every day, but how companies respond to these changes is reflective of the strategy in place to handle unexpected situations. Be as prepared as possible. Own your challenges. Stay accountable. 

BerryDunn can help whether you need extra assistance in your office during peak times or interim leadership support during periods of transition. We offer the expertise of a fully staffed accounting department for short-term assignments or long-term engagements―so you can focus on your business. Meet our interim assistance experts.

Article
Crisis averted: Why you need a CEO succession plan today

Best Practices for Educating Your Financial Institution’s Board of Directors on Cybersecurity

According to Cybersecurity Ventures, cybercrime will account for $6 trillion annually by 2021—that’s more than the global trade of all major illegal drugs combined. Data breaches and other information security events adversely impact organizations through significant losses in revenue, erosion of customer trust, substantial remediation costs, increased insurance premiums, and more.

The financial services industry has always led the way with internal controls, vendor management, and now with cybersecurity for one simple reason—you are in the business of money and it is critical to protect it.

That said, cybersecurity controls require more than just a strong IT department—an effective cybersecurity program, much like ethical behavior, depends on culture. Since your organization’s leadership plays a key role in driving your cybersecurity culture, boards of directors and senior management need a solid understanding of cybersecurity risks and impacts.

According to a 2018 Technology Survey of bank directors by Bank Director, 79% say they need to enhance their level of technology expertise. Many board members come from non-technology backgrounds and careers, and though they are able to support their institution’s mission and drive growth, they may not be able to provide direction in the areas of information technology and security. They may also not recognize what attractive targets they make for phishing and other cybercrimes due to their high level of access to valuable information, their ability to send and receive data from financial institution personnel, and their potential exemption from certain employee policies.

Keeping board members up-to-date on the evolving landscape of cybersecurity risks can present a serious challenge due to board members’ time constraints. To help, here are some best practices you can follow to make educating your institution’s board and senior management a relatively simple and sustainable process.

Leverage Existing Cybersecurity Training Resources

In most cases, you already provide and require cybersecurity training for employees, typically through internal IT experts, third-party vendors, or self-paced courses available online. Board members should complete the same training at least annually.

Require Board Members to Comply with Information Security Policies

Despite their high-risk profile, board members are often exempted from policies applicable to employees, including password requirements and other critical information security policies. Given the sensitive information and levels of access board members have, it is imperative that they fully comply with all information security policies.

Facilitate Regular Review of Information Security Audits and Assessments

Information security audits and assessments provide valuable insights into areas for improvement. Keep your board members aware of any findings, recommendations, or potential risks noted in recent audits and assessments. Provide a regular status report to the board of ongoing efforts and progress to resolve or mitigate findings and risks. Use these regular communications as an opportunity to provide cybersecurity education to the board, and don’t hesitate to speak up about any specific areas and emerging risks you may be concerned about.

Regular Cybersecurity Updates and Discussions

Keep the board and senior management updated on cybersecurity threats, incidents, and any changes to the bank’s cybersecurity program. Provide this information on a quarterly basis and include the cause of and any remediation for such events, as well as any trends in incidents. Regular updates to the board and senior management provide guidance for budgets, goals, and overall strategic direction. With more awareness of security incidents and events, trends in occurrences, and potential risks, the board and senior management are more likely to support greater investments in the bank’s security efforts.

Annual Board Approval of Information Security Plans and Policies

The board should review and approve all information security policies and relevant procedures on an annual basis, as these board-approved policies will establish the financial institution’s directive for effective internal control and cybersecurity programs. Important examples include Information Security and Acceptable Use Policies, Cybersecurity Policy, Incident Response Plan, Business Continuity Plan, and Disaster Recovery Plan.

Knowing your current position and having a plan are key. Through continuous assessment of your board’s fluency with cybersecurity and establishing a process of ongoing education that’s both effective and manageable, your financial institution can improve its culture of cybersecurity awareness—helping reduce the likelihood of future security incidents and events that could adversely impact your board, your financial institution’s employees, and your customers.

Article
Creating a culture of cybersecurity awareness

Good fundraising and good accounting do not always seamlessly align. While they all feed the same mission, fundraisers work to meet revenue goals while accountants focus on recording transactions in compliance with accounting standards. We often see development department totals reported to boards that are not in line with annual financial statements, causing confusion and concern. To bridge this information gap, here are five accounting concepts every not-for-profit fundraiser should know:

1.

GAAP Accounting: Generally Accepted Accounting Principles (GAAP) refers to a common set of accounting standards and procedures. There are as many ways for a donor to structure a gift as there are donors?GAAP provides a common foundation for when and how you should record these gifts.

2.

Pledges: Under GAAP, if there is a true, unconditional “promise to give,” you should record the total pledge as revenue in the current year (with a little present value discounting thrown in the mix for payments expected in future periods). A conditional pledge relies on a specific event happening in the future (think matching gift) and is not considered revenue until that condition is met. (See more on pledges and matching gifts here.) 

3.

Intentions: We sometimes see donors indicating they “intend” to donate a certain amount in the future. An intention on its own is not considered a true unconditional promise under GAAP, and isn’t recorded as revenue. This has a big impact with planned giving as we often see bequests recorded as revenue by the development department in the year the organization is named in the will of the donor—while the accounting guidance specifically identifies bequests as intentions to give that would generally not be recorded by the finance team until the will has been declared valid by the probate court.

4.

Restrictions: Donors often impose restrictions on some contributions, limiting the use of that gift to a specific time, program, or purpose. Usually, a gift like this arrives with some explicit communication from donors, noting how they want to apply the gift. A gift can also be considered restricted to a specific project if it is made in direct response to a solicitation for that project. The donor restriction does not generally determine when to record the gift but how to record it, as these contributions are tracked separately.

5. Gifts vs. Exchange: New accounting guidance has been released that provides more clarity on when a gift or grant is truly a contribution and when it might be an exchange transaction. Contact us if you have any questions.


Understanding the differences in how the development department and finance department track these gifts will allow for better reporting to the board throughout the year—and fewer surprises when you present financial statements at the end of the year. Stay tuned for parts two and three of our contribution series. Have questions? Please contact Emily Parker of Sarah Belliveau.

 

Article
Accounting 101 for development directors: Five things to know

Reading through the 133-page exposure draft for the Proposed Statement on Auditing Standards (SAS) Forming an Opinion and Reporting on Financial Statements of Employee Benefit Plans Subject to ERISA, issued back in April 2017, and then comparing it to the final 100+ page standard approved in September 2018, may not sound like a fun way to spend a Sunday morning sipping a coffee (or three), but I disagree.

Lucky for you, I have captured the highlights here. And it really is exciting. Our feedback was incorporated into the final standard both through written comments on the exposure draft and a voice via our firm’s Director of Quality Assurance, who holds a seat on the Auditing Standards Board.

"Limited scope" audits will no longer exist

The debate over the “limited scope” audit has been going on for years. The new standard is designed to help auditors clearly understand their responsibilities in performing an audit, and provide plan sponsors, plan participants, the Department of Labor (DOL), and other interested parties with more information about what auditors do in situations when audits are limited in scope by the plan’s management, which is permitted by DOL reporting and disclosure rules.

Once effective, Audit Committee and Board of Director meetings in which plan financial statements are presented will include more clarity into what an employee benefit plan audit entails, based on revisions to the auditor’s report. I know I would frequently kick off meetings covering the auditor’s report opinion by explaining what a “limited scope” audit was. As a “limited scope” audit will no longer exist, the revised auditor’s report language clearly articulates what the auditor is, and is not, opining on.

When is the new standard effective?

The effective date is “to be determined” as it will be aligned with the new overall auditor’s reporting standard once that is finalized, and the standard does not permit early adoption. So there is still time to educate and prepare all parties involved.

Probably the biggest conversation piece around the water cooler for the new standard is the lingo. The “limited scope” audit language will be going away and now the auditor’s report and all related language will refer to an “ERISA section 103(a)(3)(C)” audit. I know, it’s a mouthful?try and say that one three times fast!

The auditor's report will look much different

The auditor’s report under an ERISA section 103(a)(3)(C) audit will look significantly different from the old “limited scope” auditor’s report, once the standard is effective. There are several illustrative examples of reports included in the standard to refer to. One thing you will immediately notice?the auditor’s report is getting longer and not shorter. Some highlights:

The Opinion section will include two bullets that explicitly state, in basic summarized terms: (1) the certified information agrees to the financial statements, and (2)  the auditor’s opinion on everything else, which the auditor has audited.

Other Matter—Supplemental Schedules Required by ERISA section will include two bullets that explicitly state, in basic summarized terms, (1) the certified information agrees to the financial statements and (2) the auditor’s opinion on everything else, which the auditor has audited in relation to the financial statements. Sound similar to the Opinion section? Well, that’s because it is!).

Other key takeaways

  • Auditors will be required to make inquiries of management to gain assurance they performed procedures to determine the certifying institution is qualified for the ERISA section 103(a)(3)(C) audit, as it is management’s responsibility to make that determination.
  • Fair value disclosures included within the plan’s financial statements are also included under the certification umbrella and subject to the same audit procedures. As an auditor, if anything comes to our attention that does not meet expectations, we would further assess as necessary.
  • The auditor is required to obtain and read a draft Form 5500 prior to issuance of the auditor’s report.

The final standard also removed some highly debated provisions included in the draft proposal as follows:

  • There is no report on findings required, but the auditor is required to follow AU-C 250, AU-C 260 and AU-C 265. Should anything arise that warrants communication to those charged with governance, those findings must be communicated in writing. Be sure to grab another coffee and refresh yourself on AU-C 250, AU-C 260 and AU-C 265!
  • The new required procedures section for an audit was scrapped and replaced with an Appendix A for recommended audit procedures based on risk assessments. There are some great tools there to look at.
  • The required emphasis-of-matter section paragraph section of the auditor’s report was also scrapped.

Questions about the new employee benefit audit standard or employee benefit plan audits

At BerryDunn, we perform over 200 employee benefit plan audits each year. If you have any questions, we would love to help. And we’ll keep the acronyms to a minimum. Please reach out with any questions.

Article
Auditing standards board approves new employee benefit plan auditing standard: What you need to know

Banks often provide awards to lure new customers or to strengthen customer loyalty. Awards can take the form of a simple gift (cash or non-cash) or can be more complex, such as a sweepstakes involving some element of chance, or a reward points program.

If you have received an award from a bank, the IRS, always ready to claim the government’s share, may come knocking on your door. Taxation is dependent on how you receive the awards, what the award is, and its value. In certain situations, banks are required to, and may send a Form 1099, which reports the award value to the IRS and the award recipient. Here are some different award scenarios and corresponding actions to take.

Awards for Opening an Account
Awards for opening accounts are generally considered interest income and are taxable to the account holder. If an award is paid in cash, the amount of interest income is the amount of cash paid. However, an award may also be non-cash, such as a gift card or a specified item (e.g., an item of merchandise from a rewards brochure). Gift cards are normally valued at the amount of the gift on the card and merchandise at retail value. Once the value of all rewards are tallied, the value should be added to any other interest earned on the account. If the total is at least $10, the IRS requires you to file a Form 1099-INT.

Cash awards are generally easier to administer as the award can be deposited to the customer’s account and credited as interest. In-kind awards often present additional complexity when filing Forms 1099. These awards are often purchased in bulk, and given to customers when they open an account. Therefore, you don’t include the value in the customer account and you can only capture it in the 1099 reporting processes using manual intervention. To ensure these values are captured, you should develop procedures to address any manual processes.

Miscellaneous Awards Programs
Awards provided for something other than the use of money (e.g., opening an account) may also be taxable. For example: amounts provided under a birthday gift program could be taxable. Assume, under a birthday gift program, all customers under the age of 19 receive a $5 gift on their birthday. As the amounts do not appear to be for the use of money (no new account necessary and no specified account balance necessary), these payments would NOT be included on Form 1099-INT.

However, the government still wants their portion. Oftentimes, amounts under these types of programs are very low and do not require tax reporting. If reporting is required, amounts would be included on Form 1099-MISC rather than Form 1099-INT.

You need to consider these payments under the 1099-MISC reporting rules. These rules, different than the 1099-INT rules, only require reporting when the aggregate payments during the year exceed $600. Therefore, no IRS reporting would be required under this program unless payments under this program and any other program which would require a 1099-MISC, exceed $600.

Account Opening Sweepstakes
Occasionally, an incentive program may take the form of a sweepstakes or similar give-away. Winners are chosen randomly, from a pool consisting of customers opening a new checking account during a specified time period and, perhaps, non-customers if a no-purchase required entry option is available. As these prizes are limited and determined by luck (not by skill or by virtue of having an account, other than it qualified them for entry) this is more properly reported as a gambling winning. Gambling winnings are reported on Form W-2G (when in excess of $600).

IRS rules require mandatory withholding for certain gambling prizes. IRS rules also require income tax withholding for proceeds of more than $5,000. The IRS provided an example in their rules that states when no wager is placed, withholding is not required. The example concerns those entered into the sweepstakes simply by virtue of purchasing a magazine subscription for which they paid the regular subscription price. As new checking account customers generally are not paying additional amounts or receiving different terms than the regular terms an account holder receives, they are not considered to have made a wager. Therefore, we believe withholding is not required because there is a withholding exception if no wager is placed.

Reward Points Programs
Benefits from reward points programs are more complex and may not be subject to tax and reporting, depending on the provisions of the program.

The IRS has ruled that a program that is not transferable and is not convertible into cash or cash equivalents should not create gross income to the enrollees. Therefore, amounts earned and collected under a similar program would not be subject to information reporting rules, and not included on Form 1099-MISC.

Furthermore, in some circumstances cash-back options do not create gross income because the cash-back options are treated as a discount on the purchase or a rebate. In short, you have actually paid less for your merchandise because of the discount/rebate provided by the credit card.

However, if there is an award or cash provided simply for signing up for the card (no purchase necessary) the benefit may be taxable and includible on Form 1099-MISC, if the minimum threshold of $600 is satisfied.

Incentive programs to acquire and retain customers may result in taxable income to the customer. Additionally, information reporting may be required if the aggregate amount of all benefits provided exceeds certain thresholds.

We recommend banks review their procedure with regard to incentive programs to ensure proper tax reporting. We also suggest developing a customer-facing communication plan when incentives involve a significant benefit, so that customers are informed of their obligations and not surprised by hidden and unexpected tax costs. We are happy to assist in this area.

Article
The hidden tax cost of bank incentive rewards

When last we blogged about the Financial Accounting Standards Board’s (FASB) new “current expected credit losses” (CECL) model for estimating an allowance for loan and lease losses (ALLL), we reviewed the process for developing reasonable and supportable forecasts for use in establishing the ALLL. Once you develop those forecasts, how does that information translate into amounts to set aside for loan losses?

A portion of the ALLL will continue to be based on specifically identified loans you’re concerned about. For those loans, you will continue to establish a specific component of the ALLL based on your estimate of the loss ultimately expected on the loans.

The tricky part, of course, is estimating an ALLL for the other 99% of the loan portfolio. This is where the forecasts come in. The new rules do not prescribe a particular methodology, and banking regulators have indicated community banks will likely be able to continue with their current approach, adjusted to use appropriate inputs in a manner that complies with the CECL model. One of the biggest challenges is the expectation in CECL that the ALLL will be estimated using the institution’s historical information, to the extent available and relevant.

Following is just one of many ways  you can approach it. I’ve also included a link at the end of this article to an example illustrating this approach.

Step One: Historical Loss Factors

  1. First, for a given subset of the loan portfolio (e.g., the residential loan pool), you might first break down the portfolio by the number of years remaining until expected payoff (via maturity or refinancing). This is important because, on average, a loan with seven years remaining until expected payoff will have a higher level of remaining lifetime losses than a loan with one year remaining. It therefore generally wouldn’t be appropriate to use the same loss factor for both loans.
     
  2. Next, decide on a set of drivers that tend to correlate with loan losses over time. FASB has indicated it doesn’t expect highly mathematical correlation models will be necessary, especially for community banks. Instead, select factors in your bank’s experience indicative of future losses. These may include:
    • External factors, such as GDP growth, unemployment rates, and housing prices
    • Internal factors such as delinquency rates, classified asset ratios, and the percentage of loans in the portfolio for which certain policy exceptions (e.g., loan-to-value ratio or minimum credit score) were granted
       
  3. Once you select this set of drivers, find an historical loss period — a period of years corresponding to the estimated remaining life of the portfolio in question — where the historical drivers best approximate those you’re expecting in the future, based on your forecasts. For that historical loss period, determine the lifetime remaining loss rates of the loans outstanding at the beginning of that period, broken down by the number of years remaining until payoff. (This may require significant data mining, especially if that historical loss period was quite a few years ago.
     
  4. Apply those loss rates to the breakdown derived in (a) above, by years remaining until maturity.

    Step Two: Adjustments to Historical Loss Rates

    The CECL model requires we adjust historical loss factors for conditions that may not be adequately captured by the historical loss period analysis we’ve just described. Let’s say a particular geographical subset of your market area is significantly affected by the economic fortunes of a large employer in that area.  Based on economic trends or recent developments, you might expect that employer to have a particularly bright – or dim – future over the forecast period; accordingly, you forecast loans to borrowers in that area will have losses that differ significantly from the rest of the portfolio.

    The approach for these loans is the same as in the previous step. However:

    These loans would be segregated from the remainder of the portfolio, which would be subject to the general approach in step one. As you think through this approach, there are myriad variations and many decisions to make, such as:

    Our intent in describing this methodology is to help your CECL implementation team start the dialogue in terms of converting theoretical concepts in the CECL model to actual loans and historical experience.

    To facilitate that discussion, we’ve included a very simple example here that illustrates the steps described above. Analyzing an entire loan portfolio under the CECL model is an exponentially more complex process, but the concepts are the same — forecasting future conditions, and establishing an ALLL based on the bank’s (or, when necessary, peers’) lifetime loan loss experience under similar historical conditions.

    Given the amount of number crunching and analysis necessary, and the potentially significant increase in the ALLL that may result from a lifetime-of-loan loss model, it’s safe to say the time to start is now! If you have any questions about CECL implementation, please contact Tracy Harding or Rob Smalley.

    Other resources
    For more information on CECL, check out our other blogs:

    CECL: Where to Start
    CECL: Bank and Branch Acquisitions
    CECL: Reasonable and Supportable

    To sign up to receive notification of our next CECL update, click here.

    • In substep (c), you would focus on forecasted conditions (such as unemployment rate and changes in real estate values) in the geographical area in which the significant employer is located.
    • You would then select an historical loss period that had actual conditions for that area that best correspond to those you’ve just forecasted.
    • In substep (d), you would determine the lifetime remaining loss rates of loans outstanding at the beginning of that period.
    • In substep (e), you would apply those rates to loans in that geographic area.
    • How to break down the portfolio
    • Which conditions to analyze
    • How to analyze the conditions for correlation with historical loss periods
    • Which resulting loss factors to apply to which loans
Article
CECL implementation: So, you've developed reasonable and supportable forecasts — now what?

Recently, federal banking regulators released an interagency financial institution letter on CECL, in the form of a Q&A. Read it here. While there weren’t a lot of new insights into expectations examiners may have upon adoption, here is what we gleaned, and what you need to know, from the letter.

ALLL Documentation: More is better

Your management will be required to develop reasonable and supportable forecasts to determine an appropriate estimate for their allowance for loan and lease losses (ALLL). Institutions have always worked under the rule that accounting estimates need to be supported by evidence. Everyone knows both examiners and auditors LOVE documentation, but how much is necessary to prove whether the new CECL estimate is reasonable and supportable? The best answer I can give you is “more”.

And regardless of the exact model institutions develop, there will be significantly more decision points required with CECL than with the incurred loss model. At each point, both your management and your auditors will need to ask, “Why this path vs. another?” Defining those decision points and developing a process for documenting the path taken while also exploring alternatives is essential to build a model that estimates losses under both the letter and the spirit of the new rules. This is especially true when developing forecasts. We know you are not fortune tellers. Neither are we.

The challenge will be to document the sources used for forecasts, making the connections between that information and its effect on your loss data as clear as possible, so the model bases the loss estimate on your institution’s historical experience under conditions similar to those you’re forecasting, to the extent possible.

Software may make this easier… or harder.               

The leading allowance software applications allow for virtually instantaneous switching between different models, permitting users to test various assumptions in a painless environment. These applications feature collection points that enable users to document the basis for their decisions that become part of the final ALLL package. Take care to try and ensure that the support collected matches the decisions made and assumptions used.

Whether you use software or not there is a common set of essential controls to help ensure your ALLL calculation is supported. They are:

  • Documented review and recalculation of the ALLL estimate by a qualified individual(s) independent of the preparation of the calculation
  • Control over reports and spreadsheets that include data that feed into the overall calculation
  • Documentation supporting qualitative factors, including reasonableness of the resulting reserve amounts
  • Controls over loan ratings if they are a factor in your model
  • Controls over the timeliness of charge-offs

In the process of implementing the new CECL guidance it can be easy to focus all of your effort on the details of creating models, collecting data and getting to a reasonable number. Based on the regulators’ new Q&A document, you’ll also want to spend some time making sure the ALLL number is supportable.  

Next time, we’ll look at a lesser known section of the CECL guidance that could have a significantly negative impact on the size of the ALLL and capital as a result: off-balance-sheet credit exposures.

Article
CECL: Reasonable and supportable? Be ready to be ALLL in