Skip to Main Content

insightsarticles

Evolving compliance reporting: What financial institutions need to know

03.30.23 /

Read this if you are in senior management at a financial institution.

In the ever-evolving regulatory landscape for financial institutions and financial services, consumer behavior and expectations are primary catalysts for new or amended regulation. Consumers expect their data to be secure; they also expect their banks and financial partners to hold corporate values that reflect their own. 

Reporting requirements are shifting to reflect this landscape. Banks and other financial institutions should pay close attention to changing reporting requirements related to data privacy and Environmental, Social, and Governance (ESG): two key areas where the industry will see clear calls for action in the months and years ahead. Those financial services companies that devote resources to implementing best practices and robust compliance programs will position themselves for continued growth and customer loyalty. Here are areas of focus that can contribute to that growth.

Data privacy protection

New reporting requirements follow mounting pressure from customers and shareholders, as well as increased scrutiny from regulators such as the Securities and Exchange Commission. 

Data privacy protection: Banks have long been popular targets for cyberattacks and breaches and the frequency with which these incidents occur is increasing. As a result, the cost of cyberattacks has also increased substantially. 

Digital banking: The growing use of technology-enabled processes exposes banks to new data privacy risks and responsibilities. As most consumers, especially younger customers, opt for online banking, financial institutions must protect their clients’ personally identifiable information. This will require iterating on current processes and programs—as hackers’ tactics evolve, so should a bank’s defenses. 

At the same time, lawmakers are addressing privacy concerns at the state and federal levels. In 2021, the Federal Trade Commission announced updates to the Safeguards Rule, which put enhanced parameters in place for financial institutions’ cybersecurity programs. In April 2022, the SEC proposed new disclosure rules that would reduce the time in which companies must disclose a breach.

Chief Information Security Officers (CISOs) have more recently focused on “corporate data and systems impacts.” But under the proposed SEC disclosure rule, CISOs will need to maintain open lines of communication with their boards, disclosing any breach to the board within one to two days of discovery to “determine whether the incident is material.” If so, disclosing the breach within that four-day window becomes paramount for compliance. 

Additionally, a new rule regarding notification requirements for FDIC-supervised banks and their service providers was issued at the end of 2021 by the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve, and the Office of the Comptroller of the Currency. Under this rule, which went into effect in May of 2022, the FDIC must be notified as soon as possible (no later than 36 hours) if a computer security incident occurs that has been elevated to the status of a notification incident. A notification incident is a computer-security incident that has already or is reasonably likely “to disrupt or degrade” banking services. 

As regulators increase their focus and propose new rules such as these, banking executives should consider whether their data breach response program is sufficiently robust, accurate and timely.

Environmental, Social, and Governance (ESG)

A demonstrable commitment to ESG is quickly becoming essential for banks. Though lawmakers are working on standardized rules and reporting requirements, one unified reporting framework for US banks does not yet exist. Banks must wade through a sea of rules and reporting frameworks, most of which are voluntary in nature. 

Many financial institutions opt in to ESG reporting because corporate ESG initiatives are closely tied to expectations of key stakeholders, long-term profitability, greater access to capital, improved resilience, and risk mitigation. Some banks—like those with B Corp status and the newly chartered Walden Mutual Bank in New Hampshire—already have key aspects of what now falls under ESG as part of their mission. While other banks, such as Bank of America and Citi Bank, have joined together in the Net-Zero Banking Alliance to demonstrate their commitment to reducing emissions.

Financial institutions expect disparate frameworks will converge over time, as a result of the efforts of standard setters such as the International Sustainability Standards Board, to offer corporate guidance on ESG reporting, planning, and decision-making. Of note, in March 2022, the SEC proposed a new rule that would establish mandatory climate-related disclosures, with a focus on environmental impact, for public companies to report on their climate-related risks. The rule, which is expected to be finalized this year, would include disclosure of a registrant’s greenhouse gas emissions. Further, the SEC is expected to issue a proposed disclosure standard on human capital in the ensuing months. 

Don’t forget about FASB

Outside of the priority areas of data privacy and ESG, private financial institutions are also expected to maintain a keen focus on rule changes from the Financial Accounting Standards Board (FASB). Private companies should be aware of additional reporting requirements, such as the ASC 842 update on lease accounting that went into effect in early 2022. 

In a move away from traditional GAAP reporting, ASC 842 will largely eliminate off-balance sheet reporting. This will likely lead to more liabilities on a company’s balance sheet. The goal, according to FASB, is to establish more transparency related to leasing transactions and augment disclosure requirements. Because ASC 842 is still fairly new, impacted institutions should regularly reassess their compliance with the new requirements.

Other compliance reporting mandates to consider throughout 2023 include Know Your Customer and Anti-Money Laundering programs and processes. 

Moving from LIBOR to SOFR

Finally, it is worth noting one other regulatory change banks have been working on for some time: the move from the London Interbank Offered Rate (LIBOR) to the Secured Overnight Financing Rate (SOFR). The most notable difference between these two rates is how they are produced. While LIBOR is based on panel bank input, SOFR is a broad measure of the cost of borrowing cash overnight, collateralized by US Treasury securities, in the repurchase agreement market. By the end of the second quarter of 2023, banks will no longer have to submit the information that has traditionally been required to calculate USD LIBOR.

Reporting Best Practices 

Data Privacy Protection 

  • Document data breach response programs and reassess them often to ensure programs are robust and current with the latest regulatory requirements coming from multiple regulatory bodies.
  • Develop customer notification programs and processes that adhere to strict reporting compliance guidelines and allow the banking organization to quickly identify those impacted by a breach and efficiently contact them with pertinent details.
  •  Communicate new and/or shifting regulatory expectations and reporting requirements to all stakeholders, which should and often does include the CFO, CISO, CCO, CLO/General Counsel, and/or the board.

ESG

  • Implement specific ESG policies and related reporting processes
    • These could include climate-risk disclosures, sustainability reports and/or human capital disclosures, pending updated reporting guidelines 
  • Assess internal resources needed to incorporate ESG practices into annual reports and other regulatory disclosures. These steps may include:
    • Developing a cross-departmental process 
    • Conducting an ESG risk assessment
    • Amending financial statement and earnings impacts 

Preparing for the regulatory road ahead

As regulators continue to scrutinize the financial services and banking industry, companies must prioritize data privacy protection and ESG reporting to maintain regulatory compliance. Amid new reporting expectations and complex compliance requirements, financial institutions are rising to the occasion. More and more banks are meeting the moment to capture new market share, meet shifting customer expectations, embrace transparency, and increase sustainability. As always, please don’t hesitate to reach out to BerryDunn’s Financial Services team if you have any questions. We’re here to help.
 

Related Industries

Related Professionals

Leaders

BerryDunn experts and consultants

LIBOR is leaving—is your financial institution ready to make the most of it?

In July 2017, the UK’s Financial Conduct Authority announced the phasing out of the London Interbank Offered Rate, commonly known as LIBOR, by the end of 20211. With less than two years to go, US federal regulators are urging financial institutions to start assessing their LIBOR exposure and planning their transition. Here we offer some general impacts of the phasing out, some specific actions your institution can take to prepare, and, finally, background on how we got here (see Background at right).

How will the phase-out impact financial institutions?

The Federal Reserve estimates roughly $200 trillion in LIBOR-indexed notional value transactions in the cash and derivatives market2. LIBOR is used to help price a variety of financial services products,  including $3.4 trillion in business loans and $1.3 trillion in consumer loans, as well as derivatives, swaps, and other credit instruments. Even excluding loans and financial instruments set to mature before 2021—estimated by the FDIC at 82% of the above $200 trillion—LIBOR exposure is still significant3.

A financial institution’s ability to lend money is largely dependent on the relative stability of its capital position, or lack thereof. For institutions with a significant amount of LIBOR-indexed assets and liabilities, that means less certainty in expected future cash flows and a less stable capital position, which could prompt institutions to deny loans they might otherwise have approved. A change in expected cash flows could also have several indirect consequences. Criticized assets, assessed for impairment based on their expected future cash flows, could require a specific reserve due to lower present value of expected future cash flows.

The importance of fallback language in loan agreements

Fallback language in loan agreements plays a pivotal role in financial institutions’ ability to manage their LIBOR-related financial results. Most loan agreements include language that provides guidance for determining an alternate reference rate to “fall back” on in the event the loan’s original reference rate is discontinued. However, if this language is non-existent, contains fallbacks that are no longer adequate, or lacks certain key provisions, it can create unexpected issues when it comes time for financial institutions to reprice their LIBOR loans. Here are some examples:

  • Non-existent or inadequate fallbacks
    According to the Alternative Reference Rates Committee, a group of private-market participants convened by the Federal Reserve to help ensure a successful LIBOR transition, "Most contracts referencing LIBOR do not appear to have envisioned a permanent or indefinite cessation of LIBOR and have fallbacks that would not be economically appropriate"4.

    For instance, industry regulators have warned that without updated fallback language, the discontinuation of LIBOR could prompt some variable-rate loans to become fixed-rate2, causing unanticipated changes in interest rate risk for financial institutions. In a declining rate environment, this may prove beneficial as loans at variable rates become fixed. But in a rising rate environment, the resulting shrink in net interest margins would have a direct and adverse impact on the bottom line.

  • No spread adjustment
    Once LIBOR is discontinued, LIBOR-indexed loans will need to be repriced at a new reference rate, which could be well above or below LIBOR. If loan agreements don’t provide for an adjustment of the spread between LIBOR and the new rate, that could prompt unexpected changes in the financial position of both borrowers and lenders3. Take, for instance, a loan made at the Secured Overnight Financing Rate (SOFR), generally considered the likely replacement for USD LIBOR. Since SOFR tends to be lower than three-month LIBOR, a loan agreement using it that does not allow for a spread adjustment would generate lower loan payments for the borrower, which means less interest income for the lender.

    Not allowing for a spread adjustment on reference rates lower than LIBOR could also cause a change in expected prepayments—say, for instance, if borrowers with fixed-rate loans decide to refinance at adjustable rates—which would impact post-CECL allowance calculations like the weighted-average remaining maturity (WARM) method, which uses estimated prepayments as an input.

What can your financial institution do to prepare?

The Federal Reserve and the SEC have urged financial institutions to immediately evaluate their LIBOR exposure and expedite their transition. Though the FDIC has expressed no intent to examine financial institutions for the status of LIBOR planning or critique loans based on use of LIBOR3, Federal Reserve supervisory teams have been including LIBOR transitions in their regular monitoring of large financial institutions5. The SEC has also encouraged companies to provide investors with robust disclosures regarding their LIBOR transition, which may include a notional value of LIBOR exposure2.

Financial institutions should start by analyzing their LIBOR exposure beyond 2021. If you don’t expect significant exposure, further analysis may be unnecessary. However, if you do expect significant future LIBOR exposure, your institution should conduct stress testing using LIBOR as an isolated variable by running hypothetical transition scenarios and assessing the potential financial impact.

Closely examine and assess fallback language in loan agreements. For existing loan agreements, you may need to make amendments, which could require consent from counterparties2. For new loan agreements maturing beyond 2021, lenders should consider selecting an alternate reference rate. New contract language for financial instruments and residential mortgages is currently being drafted by the International Securities Dealers Association and the Federal Housing Finance Authority, respectively3—both of which may prove helpful in updating loan agreements.

Lenders should also consider their underwriting policies. Loan underwriters will need to adjust the spread on new loans to accurately reflect the price of risk, because volatility and market tendencies of alternate loan reference rates may not mirror LIBOR’s. What’s more, SOFR lacks abundant historical data for use in analyzing volatility and market tendencies, making accurate loan pricing more difficult.

Conclusion: Start assessing your LIBOR risk soon

The cessation of LIBOR brings challenges and opportunities that will require in-depth analysis and making difficult decisions. Financial institutions and consumers should heed the advice of regulators and start assessing their LIBOR risk now. Those that do will not only be better prepared―but also better positioned―to capitalize on the opportunities it presents.

Need help assessing your LIBOR risk and preparing to transition? Contact BerryDunn’s financial services specialists.

1 https://www.washingtonpost.com/business/2017/07/27/acdd411c-72bc-11e7-8c17-533c52b2f014_story.html?utm_term=.856137e72385
2 Thomson Reuters Checkpoint Newsstand April 10, 2019
3 https://www.fdic.gov/regulations/examinations/supervisory/insights/siwin18/si-winter-2018.pdf
4 https://bankingjournal.aba.com/2019/04/libor-transition-panel-recommends-fallback-language-for-key-instruments/
5 https://www.reuters.com/article/us-usa-fed-libor/fed-urges-u-s-financial-industry-to-accelerate-libor-transition-idUSKCN1RM25T

Article
When one loan rate closes, another opens

In auditing, the concept of professional skepticism is ubiquitous. Just as a Jedi in Star Wars is constantly trying to hone his understanding of the “force”, an auditor is constantly crafting his or her ability to apply professional skepticism. It is professional skepticism that provides the foundation for decision-making when conducting an attestation engagement.

A brief definition

The professional standards define professional skepticism as “an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to fraud or error, and a critical assessment of audit evidence.” Given this definition, one quickly realizes that professional skepticism can’t be easily measured. Nor is it something that is cultivated overnight. It is a skill developed over time and a skill that auditors should constantly build and refine.

Recently, the extent to which professional skepticism is being employed has gained a lot of criticism. Specifically, regulatory bodies argue that auditors are not skeptical enough in carrying out their duties. However, as noted in the white paper titled Scepticism: The Practitioners’ Take, published by the Institute of Chartered Accountants in England and Wales, simply asking for more skepticism is not a practical solution to this issue, nor is it necessarily always desirable. There is an inevitable tug of war between professional skepticism and audit efficiency. The more skeptical the auditor, typically, the more time it takes to complete the audit.

Why does it matter? Audit quality.

First and foremost, how your auditor applies professional skepticism to your audit directly impacts the quality of their service. Applying an appropriate level of professional skepticism enhances the likelihood the auditor will understand your industry, lines of business, business processes, and any nuances that make your company different from others, as it naturally causes the auditor to ask questions that may otherwise go unasked.

These questions not only help the auditor appropriately apply professional standards, but also help the auditor gain a deeper understanding of your business. This will enable the auditor to provide insights and value-added services an auditor who doesn’t apply the right degree of skepticism may never identify.

Therefore, as the white paper notes, audit committees, management, and investors should be asking “How hard do our auditors get pushed on fees, and what effect does that have on the quality of the audit?” If your auditor is overly concerned with completing the audit within a fixed time budget, professional skepticism and, ultimately, the quality of the audit, may suffer.

Applying skepticism internally

By its definition, professional skepticism is a concept that specifically applies to auditors, and is not on point when it comes to other audit stakeholders. This is because the definition implies that the individual applying professional skepticism is independent from the information he or she is analyzing. Other audit stakeholders, such as members of management or the board of directors, are naturally advocates for the organizations they manage and direct and therefore can’t be considered independent, whereas an auditor is required to remain independent.

However, rather than audit stakeholders applying professional skepticism as such, these other stakeholders should apply an impartial and diligent mindset to their work and the information they review. This allows the audit stakeholder to remain an advocate for his or her organization, while applying critical skills similar to those applied in the exercise of professional skepticism. This nuanced distinction is necessary to maintain the limited scope to which the definition of professional skepticism applies: the auditor.

Specific to the financial statement reporting function, these stakeholders should be assessing the financial statements and ask questions that can help prevent or detect flaws in the financial reporting process. For example, when considering significant estimates, management should ask: are we considering all relevant information? Are our estimates unbiased? Are there alternative accounting treatments we haven’t considered? Can we justify our selected accounting treatment? Essentially, management should start by asking itself: what questions would we expect our auditor to ask us?

It is also important to be critical of your own work, and never become complacent. This may be the most difficult type of skepticism to apply, as most of us do not like to have our work criticized. However, critically reviewing one’s own work, essentially as an informal first level of review, will allow you to take a step back and consider it from a different vantage point, which may in turn help detect errors otherwise left unnoticed. Essentially, you should both consider evidence that supports the initial conclusion and evidence that may be contradictory to that conclusion.

The discussion in auditing circles about professional skepticism and how to appropriately apply it continues. It is a challenging notion that’s difficult to adequately articulate. Although it receives a lot of attention in the audit profession, it is a concept that, slightly altered, can be of value to other audit stakeholders. Doing so will help you create a stronger relationship with your auditor and, ultimately, improve the quality of the financial reporting process—and resulting outcome.

Article
Professional skepticism and why it matters to audit stakeholders

Do you know what would happen to your company if your CEO suddenly had to resign immediately for personal reasons? Or got seriously ill? Or worse, died? These scenarios, while rare, do happen, and many companies are not prepared. In fact, 45% of US companies do not have a contingency plan for CEO succession, according to a 2020 Harvard Business Review study.  

Do you have a plan for CEO succession? As a business owner, you may have an exit strategy in place for your company, but do you have a plan to bridge the leadership gap for you and each member of your leadership team? Does the plan include the kind of crises listed above? What would you do if your next-in-line left suddenly? 

Whether yours is a family-owned business, a company of equity partners, or a private company with a governing body, here are things to consider when you’re faced with a situation where your CEO has abruptly departed or has decided to step down.  

1. Get a plan in place. First, assess the situation and figure out your priorities. If there is already a plan for these types of circumstances, evaluate how much of it is applicable to this particular circumstance. For example, if the plan is for the stepping down or announced retirement of your CEO, but some other catastrophic event occurs, you may need to adjust key components and focus on immediate messaging rather than future positioning. If there is no plan, assign a small team to create one immediately. 

Make sure management, team leaders, and employees are aware and informed of your progress; this will help keep you organized and streamline communications. Management needs to take the lead and select a point person to document the process. Management also needs to take the lead in demeanor. Model your actions so employees can see the situation is being handled with care. Once a strategy is identified based on your priorities, draft a plan that includes what happens now, in the immediate future, and beyond. Include timetables so people know when decisions will be made.  

2. Communicate clearly, and often. In times of uncertainty, your employees will need as much specific information as you can give them. Knowing when they will hear from you, even if it is “we have nothing new to report” builds trust and keeps them vested and involved. By letting them know what your plan is, when they’ll receive another update, what to tell clients, and even what specifics you can give them (e.g., who will take over which CEO responsibility and for how long), you make them feel that they are important stakeholders, and not just bystanders. Stakeholders are more likely to be strong supporters during and after any transition that needs to take place. 

3. Pull in professional help. Depending on your resources, we recommend bringing in a professional to help you handle the situation at hand. At the very least, call in an objective opinion. You’ll need someone who can help you make decisions when emotions are running high. Bringing someone on board that can help you decipher what you have to work with and what your legal and other obligations may be, help rally your team, deal with the media, and manage emotions can be invaluable during a challenging time. Even if it’s temporary. 

4. Develop a timeline. Figure out how much time you have for the transition. For example, if your CEO is ill and will be stepping down in six months, you have time to update any existing exit strategy or succession plan you have in place. Things to include in the timeline: 

  • Who is taking over what responsibilities? 
  • How and what will be communicated to your company and stakeholders? 
  • How and what will be communicated to the market? 
  • How will you bring in the CEO's replacement, while helping the current CEO transition out of the organization? 

If you are in a crisis situation (e.g., your CEO has been suddenly forced out or asked to leave without a public explanation), you won’t have the luxury of time.  

Find out what other arrangements have been made in the past and update them as needed. Work with your PR firm to help with your change management and do the right things for all involved to salvage the company’s reputation. When handled correctly, crises don’t have to have a lasting negative impact on your business.   

5. Manage change effectively. When you’re under the gun to quickly make significant changes at the top, you need to understand how the changes may affect various parts of your company. While instinct may tell you to focus externally, don’t neglect your employees. Be as transparent as you possibly can be, present an action plan, ask for support, and get them involved in keeping the environment positive. Whether you bring in professionals or not, make sure you allow for questions, feedback, and even discord if challenging information is being revealed.  

6. Handle the media. Crisis rule #1 is making it clear who can, and who cannot, speak to the media. Assign a point person for all external inquiries and instruct employees to refer all reporter requests for comment to that point person. You absolutely do not want employees leaking sensitive information to the media. 
 
With your employees on board with the change management action plan, you can now focus on external communications and how you will present what is happening to the media. This is not completely under your control. Technology and social media changed the game in terms of speed and access to information to the public and transparency when it comes to corporate leadership. Present a message to the media quickly that coincides with your values as a company. If you are dealing with a scandal where public trust is involved and your CEO is stepping down, handling this effectively will take tact and most likely a team of professionals to help. 

Exit strategies are planning tools. Uncontrollable events occur and we don’t always get to follow our plan as we would have liked. Your organization can still be prepared and know what to do in an emergency situation or sudden crisis.  Executives move out of their roles every day, but how companies respond to these changes is reflective of the strategy in place to handle unexpected situations. Be as prepared as possible. Own your challenges. Stay accountable. 

BerryDunn can help whether you need extra assistance in your office during peak times or interim leadership support during periods of transition. We offer the expertise of a fully staffed accounting department for short-term assignments or long-term engagements―so you can focus on your business. Meet our interim assistance experts.

Article
Crisis averted: Why you need a CEO succession plan today

Best Practices for Educating Your Financial Institution’s Board of Directors on Cybersecurity

According to Cybersecurity Ventures, cybercrime will account for $6 trillion annually by 2021—that’s more than the global trade of all major illegal drugs combined. Data breaches and other information security events adversely impact organizations through significant losses in revenue, erosion of customer trust, substantial remediation costs, increased insurance premiums, and more.

The financial services industry has always led the way with internal controls, vendor management, and now with cybersecurity for one simple reason—you are in the business of money and it is critical to protect it.

That said, cybersecurity controls require more than just a strong IT department—an effective cybersecurity program, much like ethical behavior, depends on culture. Since your organization’s leadership plays a key role in driving your cybersecurity culture, boards of directors and senior management need a solid understanding of cybersecurity risks and impacts.

According to a 2018 Technology Survey of bank directors by Bank Director, 79% say they need to enhance their level of technology expertise. Many board members come from non-technology backgrounds and careers, and though they are able to support their institution’s mission and drive growth, they may not be able to provide direction in the areas of information technology and security. They may also not recognize what attractive targets they make for phishing and other cybercrimes due to their high level of access to valuable information, their ability to send and receive data from financial institution personnel, and their potential exemption from certain employee policies.

Keeping board members up-to-date on the evolving landscape of cybersecurity risks can present a serious challenge due to board members’ time constraints. To help, here are some best practices you can follow to make educating your institution’s board and senior management a relatively simple and sustainable process.

Leverage Existing Cybersecurity Training Resources

In most cases, you already provide and require cybersecurity training for employees, typically through internal IT experts, third-party vendors, or self-paced courses available online. Board members should complete the same training at least annually.

Require Board Members to Comply with Information Security Policies

Despite their high-risk profile, board members are often exempted from policies applicable to employees, including password requirements and other critical information security policies. Given the sensitive information and levels of access board members have, it is imperative that they fully comply with all information security policies.

Facilitate Regular Review of Information Security Audits and Assessments

Information security audits and assessments provide valuable insights into areas for improvement. Keep your board members aware of any findings, recommendations, or potential risks noted in recent audits and assessments. Provide a regular status report to the board of ongoing efforts and progress to resolve or mitigate findings and risks. Use these regular communications as an opportunity to provide cybersecurity education to the board, and don’t hesitate to speak up about any specific areas and emerging risks you may be concerned about.

Regular Cybersecurity Updates and Discussions

Keep the board and senior management updated on cybersecurity threats, incidents, and any changes to the bank’s cybersecurity program. Provide this information on a quarterly basis and include the cause of and any remediation for such events, as well as any trends in incidents. Regular updates to the board and senior management provide guidance for budgets, goals, and overall strategic direction. With more awareness of security incidents and events, trends in occurrences, and potential risks, the board and senior management are more likely to support greater investments in the bank’s security efforts.

Annual Board Approval of Information Security Plans and Policies

The board should review and approve all information security policies and relevant procedures on an annual basis, as these board-approved policies will establish the financial institution’s directive for effective internal control and cybersecurity programs. Important examples include Information Security and Acceptable Use Policies, Cybersecurity Policy, Incident Response Plan, Business Continuity Plan, and Disaster Recovery Plan.

Knowing your current position and having a plan are key. Through continuous assessment of your board’s fluency with cybersecurity and establishing a process of ongoing education that’s both effective and manageable, your financial institution can improve its culture of cybersecurity awareness—helping reduce the likelihood of future security incidents and events that could adversely impact your board, your financial institution’s employees, and your customers.

Article
Creating a culture of cybersecurity awareness

Reading through the 133-page exposure draft for the Proposed Statement on Auditing Standards (SAS) Forming an Opinion and Reporting on Financial Statements of Employee Benefit Plans Subject to ERISA, issued back in April 2017, and then comparing it to the final 100+ page standard approved in September 2018, may not sound like a fun way to spend a Sunday morning sipping a coffee (or three), but I disagree.

Lucky for you, I have captured the highlights here. And it really is exciting. Our feedback was incorporated into the final standard both through written comments on the exposure draft and a voice via our firm’s Director of Quality Assurance, who holds a seat on the Auditing Standards Board.

"Limited scope" audits will no longer exist

The debate over the “limited scope” audit has been going on for years. The new standard is designed to help auditors clearly understand their responsibilities in performing an audit, and provide plan sponsors, plan participants, the Department of Labor (DOL), and other interested parties with more information about what auditors do in situations when audits are limited in scope by the plan’s management, which is permitted by DOL reporting and disclosure rules.

Once effective, Audit Committee and Board of Director meetings in which plan financial statements are presented will include more clarity into what an employee benefit plan audit entails, based on revisions to the auditor’s report. I know I would frequently kick off meetings covering the auditor’s report opinion by explaining what a “limited scope” audit was. As a “limited scope” audit will no longer exist, the revised auditor’s report language clearly articulates what the auditor is, and is not, opining on.

When is the new standard effective?

The effective date is “to be determined” as it will be aligned with the new overall auditor’s reporting standard once that is finalized, and the standard does not permit early adoption. So there is still time to educate and prepare all parties involved.

Probably the biggest conversation piece around the water cooler for the new standard is the lingo. The “limited scope” audit language will be going away and now the auditor’s report and all related language will refer to an “ERISA section 103(a)(3)(C)” audit. I know, it’s a mouthful?try and say that one three times fast!

The auditor's report will look much different

The auditor’s report under an ERISA section 103(a)(3)(C) audit will look significantly different from the old “limited scope” auditor’s report, once the standard is effective. There are several illustrative examples of reports included in the standard to refer to. One thing you will immediately notice?the auditor’s report is getting longer and not shorter. Some highlights:

The Opinion section will include two bullets that explicitly state, in basic summarized terms: (1) the certified information agrees to the financial statements, and (2)  the auditor’s opinion on everything else, which the auditor has audited.

Other Matter—Supplemental Schedules Required by ERISA section will include two bullets that explicitly state, in basic summarized terms, (1) the certified information agrees to the financial statements and (2) the auditor’s opinion on everything else, which the auditor has audited in relation to the financial statements. Sound similar to the Opinion section? Well, that’s because it is!).

Other key takeaways

  • Auditors will be required to make inquiries of management to gain assurance they performed procedures to determine the certifying institution is qualified for the ERISA section 103(a)(3)(C) audit, as it is management’s responsibility to make that determination.
  • Fair value disclosures included within the plan’s financial statements are also included under the certification umbrella and subject to the same audit procedures. As an auditor, if anything comes to our attention that does not meet expectations, we would further assess as necessary.
  • The auditor is required to obtain and read a draft Form 5500 prior to issuance of the auditor’s report.

The final standard also removed some highly debated provisions included in the draft proposal as follows:

  • There is no report on findings required, but the auditor is required to follow AU-C 250, AU-C 260 and AU-C 265. Should anything arise that warrants communication to those charged with governance, those findings must be communicated in writing. Be sure to grab another coffee and refresh yourself on AU-C 250, AU-C 260 and AU-C 265!
  • The new required procedures section for an audit was scrapped and replaced with an Appendix A for recommended audit procedures based on risk assessments. There are some great tools there to look at.
  • The required emphasis-of-matter section paragraph section of the auditor’s report was also scrapped.

Questions about the new employee benefit audit standard or employee benefit plan audits

At BerryDunn, we perform over 200 employee benefit plan audits each year. If you have any questions, we would love to help. And we’ll keep the acronyms to a minimum. Please reach out with any questions.

Article
Auditing standards board approves new employee benefit plan auditing standard: What you need to know

Banks often provide awards to lure new customers or to strengthen customer loyalty. Awards can take the form of a simple gift (cash or non-cash) or can be more complex, such as a sweepstakes involving some element of chance, or a reward points program.

If you have received an award from a bank, the IRS, always ready to claim the government’s share, may come knocking on your door. Taxation is dependent on how you receive the awards, what the award is, and its value. In certain situations, banks are required to, and may send a Form 1099, which reports the award value to the IRS and the award recipient. Here are some different award scenarios and corresponding actions to take.

Awards for Opening an Account
Awards for opening accounts are generally considered interest income and are taxable to the account holder. If an award is paid in cash, the amount of interest income is the amount of cash paid. However, an award may also be non-cash, such as a gift card or a specified item (e.g., an item of merchandise from a rewards brochure). Gift cards are normally valued at the amount of the gift on the card and merchandise at retail value. Once the value of all rewards are tallied, the value should be added to any other interest earned on the account. If the total is at least $10, the IRS requires you to file a Form 1099-INT.

Cash awards are generally easier to administer as the award can be deposited to the customer’s account and credited as interest. In-kind awards often present additional complexity when filing Forms 1099. These awards are often purchased in bulk, and given to customers when they open an account. Therefore, you don’t include the value in the customer account and you can only capture it in the 1099 reporting processes using manual intervention. To ensure these values are captured, you should develop procedures to address any manual processes.

Miscellaneous Awards Programs
Awards provided for something other than the use of money (e.g., opening an account) may also be taxable. For example: amounts provided under a birthday gift program could be taxable. Assume, under a birthday gift program, all customers under the age of 19 receive a $5 gift on their birthday. As the amounts do not appear to be for the use of money (no new account necessary and no specified account balance necessary), these payments would NOT be included on Form 1099-INT.

However, the government still wants their portion. Oftentimes, amounts under these types of programs are very low and do not require tax reporting. If reporting is required, amounts would be included on Form 1099-MISC rather than Form 1099-INT.

You need to consider these payments under the 1099-MISC reporting rules. These rules, different than the 1099-INT rules, only require reporting when the aggregate payments during the year exceed $600. Therefore, no IRS reporting would be required under this program unless payments under this program and any other program which would require a 1099-MISC, exceed $600.

Account Opening Sweepstakes
Occasionally, an incentive program may take the form of a sweepstakes or similar give-away. Winners are chosen randomly, from a pool consisting of customers opening a new checking account during a specified time period and, perhaps, non-customers if a no-purchase required entry option is available. As these prizes are limited and determined by luck (not by skill or by virtue of having an account, other than it qualified them for entry) this is more properly reported as a gambling winning. Gambling winnings are reported on Form W-2G (when in excess of $600).

IRS rules require mandatory withholding for certain gambling prizes. IRS rules also require income tax withholding for proceeds of more than $5,000. The IRS provided an example in their rules that states when no wager is placed, withholding is not required. The example concerns those entered into the sweepstakes simply by virtue of purchasing a magazine subscription for which they paid the regular subscription price. As new checking account customers generally are not paying additional amounts or receiving different terms than the regular terms an account holder receives, they are not considered to have made a wager. Therefore, we believe withholding is not required because there is a withholding exception if no wager is placed.

Reward Points Programs
Benefits from reward points programs are more complex and may not be subject to tax and reporting, depending on the provisions of the program.

The IRS has ruled that a program that is not transferable and is not convertible into cash or cash equivalents should not create gross income to the enrollees. Therefore, amounts earned and collected under a similar program would not be subject to information reporting rules, and not included on Form 1099-MISC.

Furthermore, in some circumstances cash-back options do not create gross income because the cash-back options are treated as a discount on the purchase or a rebate. In short, you have actually paid less for your merchandise because of the discount/rebate provided by the credit card.

However, if there is an award or cash provided simply for signing up for the card (no purchase necessary) the benefit may be taxable and includible on Form 1099-MISC, if the minimum threshold of $600 is satisfied.

Incentive programs to acquire and retain customers may result in taxable income to the customer. Additionally, information reporting may be required if the aggregate amount of all benefits provided exceeds certain thresholds.

We recommend banks review their procedure with regard to incentive programs to ensure proper tax reporting. We also suggest developing a customer-facing communication plan when incentives involve a significant benefit, so that customers are informed of their obligations and not surprised by hidden and unexpected tax costs. We are happy to assist in this area.

Article
The hidden tax cost of bank incentive rewards