Board compliance reporting is the periodic delivery of information about the state of an organization's compliance program to its board of directors or a board committee, so that the board can carry out its oversight duty. At a bank, the board approves the BSA/AML program (31 CFR 1020.210) and receives regular reports from the BSA officer on the status of compliance. A typical report covers program status, metrics and key risk indicators, findings and remediation, regulatory changes, and examination status, and the board's review is recorded in its minutes.
Board compliance reporting is the periodic delivery of information about an organization's compliance program to its board of directors, or to a committee the board designates, so that the board can oversee the program it is responsible for. The report is the main channel through which directors, who do not run the program, learn whether it is working. Its counterpart is the board minute: the written record that the board received the information, discussed it, and acted where action was needed.
The board's responsibility
Board oversight of compliance rests on regulation, supervisory guidance, and corporate law.
- BSA/AML program approval. The bank program rule, 31 CFR 1020.210, requires an anti-money laundering program approved by the board of directors or an equivalent governing body. The FFIEC BSA/AML Examination Manual states that the program must be written, approved by the board, and noted in the board minutes, and that the board is responsible for setting a culture of compliance and for overseeing senior management and the BSA compliance officer.
- Regular reporting from the BSA officer. The FFIEC manual states that the BSA compliance officer should regularly report the status of ongoing compliance to the board and senior management so they can make informed decisions about risk exposure and the program, including the required notification of suspicious activity report filings. For national banks, 12 CFR 21.11(h) requires management to promptly notify the board, or a designated committee, of SAR filings; the other federal banking agencies have parallel rules.
- State certification. In New York, 3 NYCRR 504.4 requires each regulated institution to submit an annual board resolution or senior officer compliance finding on its transaction monitoring and filtering programs by April 15.
- Corporate law. Under Delaware law, directors have a duty to make a good-faith effort to ensure that a reporting system exists through which information about legal compliance reaches the board (In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996)). The Delaware Supreme Court applied that duty in Marchand v. Barnhill, 212 A.3d 805 (Del. 2019), where the complaint alleged that the board had no reporting system for the company's central compliance risk.
Supervisory guidance on board information
The Federal Reserve's Supervisory Guidance on Board of Directors' Effectiveness (SR 21-3, February 26, 2021) applies to domestic bank holding companies and savings and loan holding companies with $100 billion or more in total consolidated assets and to certain designated nonbank companies. It describes five attributes of an effective board, one of which is that the board directs senior management regarding the information the board needs. Its formal scope is limited to those firms.
For national banks and federal savings associations, the OCC's Director's Book: Role of Directors for National Banks and Federal Savings Associations (November 2020) describes directors' responsibilities and management's role. The companion Director's Reference Guide to Board Reports and Information (November 2020) states that sound board decisions depend on information that is timely, accurate, relevant, and complete, and gives examples of measures, questions, and warning signs across planning, operations, and risk management.
Contents of a compliance report
A compliance report to the board is normally organized around the following sections. The depth of each varies with the institution's size and risk.
| Section | What it covers |
|---|---|
| Program status | Whether the program operates as approved; changes to policies, staffing, systems, or the risk assessment; items requiring board approval. |
| Metrics and key risk indicators | Measures of program activity and risk against thresholds, with trends over prior periods. |
| Findings and remediation status | Open findings from examinations, independent testing, internal audit, and self-identification, with severity, owner, due date, and status, including items past due. |
| Regulatory changes | New or amended laws, rules, and guidance that affect the program, and the planned response. |
| Examination status | Upcoming or ongoing examinations, open supervisory matters, and progress on any enforcement action. |
| Required notifications | Items that must reach the board by rule, such as notice of SAR filings. |
Management information and key risk indicators
Management information (MI) is the regular data that describes how a program operates. A key risk indicator (KRI) is a metric chosen because a change in it signals a change in risk, and it is reported against a threshold that triggers attention or escalation when breached. The Basel Committee's Principles for the Sound Management of Operational Risk (revised 2021) list key risk and performance indicators among the tools used to monitor operational risk, which the Basel Framework defines to include legal risk.
Common compliance KRIs include the following:
- Age and size of the monitoring alert backlog, and the share of alerts closed past the internal service level.
- Number of suspicious activity reports filed and the share filed within the regulatory deadline.
- Number of customers overdue for periodic due diligence review, by risk tier.
- Sanctions screening hits pending review beyond a set period.
- Training completion rates for required staff.
- Open findings past their remediation due date, by severity.
MI is most useful to a board when each metric is compared with a threshold and a prior period, when exceptions are explained rather than only counted, and when the report states what management is doing about each breach. A report that presents large volumes of undifferentiated data can obscure the items that require a decision; the OCC's reference guide and SR 21-3 both address the board's role in defining the information it needs.
Examiner packs
An examiner pack is the set of materials an institution assembles in response to an examination request. It is distinct from routine board reporting, but it draws heavily on board records. The FFIEC BSA/AML Examination Manual's Appendix H (Request Letter Items) asks for, among other things, the most recent written BSA/AML program approved by the board, with the date of approval noted in the minutes, and the results of independent tests performed since the prior examination, including management's responses and access to the workpapers. Examiners commonly review board and committee minutes and reports to assess whether the board received adequate information and exercised oversight. Consistency between what the board was told and what the program records show is therefore a practical test of reporting quality. Preparation practices are covered in the BSA/AML exam preparation article.
Who prepares and receives the report
The BSA officer or chief compliance officer prepares the compliance report, often with input from risk, legal, and internal audit. Many boards delegate detailed review to a risk, audit, or compliance committee, which reports to the full board. Internal audit and independent testers report their findings to the board or a committee directly, separately from management, so that the board receives an assessment of the program from a source independent of the people who run it. Reporting frequency is set by the board and by the institution's risk profile; quarterly reporting to a committee, with an annual review of the program by the full board, is a common arrangement.
Primary sources
- 31 CFR 1020.210: Bank AML program rule, including approval by the board of directors.
- FFIEC BSA/AML Examination Manual, BSA Compliance Officer: Board oversight, and the BSA officer's regular reporting to the board and senior management.
- FFIEC BSA/AML Examination Manual, Appendix H (Request Letter Items): Materials requested for an examination, including the board-approved program and independent testing results.
- 12 CFR 21.11(h): OCC rule requiring management to notify the board or a designated committee of SAR filings.
- Federal Reserve SR 21-3, Supervisory Guidance on Board of Directors' Effectiveness (February 26, 2021): Five attributes of effective boards at large holding companies, including directing management on information needs.
- OCC, The Director's Book: Role of Directors for National Banks and Federal Savings Associations (November 2020): Directors' responsibilities and management's role.
- OCC, Director's Reference Guide to Board Reports and Information (November 2020): Characteristics of useful board information and example measures and warning signs.
- 3 NYCRR 504.4: Annual board resolution or senior officer compliance finding for New York regulated institutions.
- In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996): Delaware Court of Chancery on the board's duty to attempt in good faith to ensure a reporting system exists.
- Marchand v. Barnhill, 212 A.3d 805 (Del. 2019): Delaware Supreme Court applying the oversight duty where no board-level reporting system existed for a central compliance risk.
- Basel Committee, Revisions to the Principles for the Sound Management of Operational Risk (March 2021): Key risk and performance indicators as operational risk monitoring tools.