3 | 2 | | *ANS120* 02/12/2025 2:18:59 PM ANS120 |
---|
4 | 3 | | State of Arkansas 1 |
---|
5 | 4 | | 95th General Assembly A Bill 2 |
---|
6 | 5 | | Regular Session, 2025 HOUSE BILL 1466 3 |
---|
7 | 6 | | 4 |
---|
8 | 7 | | By: Representative Achor 5 |
---|
9 | 8 | | By: Senator J. Boyd 6 |
---|
10 | 9 | | 7 |
---|
11 | 10 | | For An Act To Be Entitled 8 |
---|
12 | 11 | | AN ACT TO AMEND THE FAIR MORTGAGE LENDING ACT; AND 9 |
---|
13 | 12 | | FOR OTHER PURPOSES. 10 |
---|
14 | 13 | | 11 |
---|
15 | 14 | | 12 |
---|
16 | 15 | | Subtitle 13 |
---|
17 | 16 | | TO AMEND THE FAIR MORTGAGE LENDING ACT. 14 |
---|
18 | 17 | | 15 |
---|
19 | 18 | | BE IT ENACTED BY THE GENERAL ASSEMBLY OF THE STATE OF ARKANSAS: 16 |
---|
20 | 19 | | 17 |
---|
21 | 20 | | SECTION 1. Arkansas Code § 23 -39-502 is amended to read as follows: 18 |
---|
22 | 21 | | 23-39-502. Definitions. 19 |
---|
23 | 22 | | As used in this subchapter: 20 |
---|
24 | 23 | | (1) "Affiliate" means a person that directly or indirectly 21 |
---|
25 | 24 | | through one (1) or more intermediaries controls, is controlled by, or is 22 |
---|
26 | 25 | | under common control with the person; 23 |
---|
27 | 26 | | (2)(A) "Allowable assets for liquidity" means assets that may be 24 |
---|
28 | 27 | | used to satisfy liquidity requirements under this subchapter. 25 |
---|
29 | 28 | | (B) "Allowable assets for liquidity" includes without 26 |
---|
30 | 29 | | limitation: 27 |
---|
31 | 30 | | (i) Unrestricted cash and cash equivalents; and 28 |
---|
32 | 31 | | (ii) Unencumbered investment -grade assets held for 29 |
---|
33 | 32 | | sale or trade; 30 |
---|
34 | 33 | | (3) "Applicant" means a person that has applied to become 31 |
---|
35 | 34 | | licensed under this subchapter as a loan officer, transitional loan officer, 32 |
---|
36 | 35 | | mortgage broker, mortgage banker, or mortgage servicer; 33 |
---|
37 | 36 | | (4) "Authorized user" means an employee, contractor, agent, or 34 |
---|
38 | 37 | | other person that participates in a financial institution’s business 35 |
---|
39 | 38 | | operations and is authorized to access and use a financial institution’s 36 HB1466 |
---|
40 | 39 | | |
---|
41 | 40 | | 2 02/12/2025 2:18:59 PM ANS120 |
---|
42 | 41 | | information systems and data; 1 |
---|
43 | 42 | | (5) "Board of directors" means a formal body that is responsible 2 |
---|
44 | 43 | | for corporate governance and compliance with this subchapter; 3 |
---|
45 | 44 | | (2)(6) "Branch manager" means the individual who is in charge of 4 |
---|
46 | 45 | | the business operations of one (1) or more branch offices of a mortgage 5 |
---|
47 | 46 | | broker, mortgage banker, or mortgage servicer; 6 |
---|
48 | 47 | | (3)(7) "Branch office" means a location that is separate and 7 |
---|
49 | 48 | | distinct from the licensee's principal place of business and includes any 8 |
---|
50 | 49 | | location from which business is conducted under the license or in the name of 9 |
---|
51 | 50 | | the mortgage broker, mortgage banker, or mortgage servicer: 10 |
---|
52 | 51 | | (A) The address of which appears on business cards, 11 |
---|
53 | 52 | | stationery, or advertising used by the licensee in connection with business 12 |
---|
54 | 53 | | conducted under this subchapter at the branch office; 13 |
---|
55 | 54 | | (B) At which the licensee's name, advertising, promotional 14 |
---|
56 | 55 | | materials, or signage suggests that mortgage loans are originated, solicited, 15 |
---|
57 | 56 | | accepted, negotiated, funded, or serviced or from which mortgage loan 16 |
---|
58 | 57 | | commitments or interest rate guarantee agreements are issued; or 17 |
---|
59 | 58 | | (C) Which, due to the actions of any employee, associate, 18 |
---|
60 | 59 | | loan officer, or transitional loan officer of the licensee, may be construed 19 |
---|
61 | 60 | | by the public as a branch office of the licensee where mortgage loans are 20 |
---|
62 | 61 | | originated, solicited, accepted, negotiated, funded, or serviced or from 21 |
---|
63 | 62 | | which mortgage loan commitments or interest rate guarantee agreements are 22 |
---|
64 | 63 | | issued; 23 |
---|
65 | 64 | | (4)(8) "Commissioner" means the Securities Commissioner and 24 |
---|
66 | 65 | | includes the commissioner's designees; 25 |
---|
67 | 66 | | (9) "Consumer" means an individual or that individual's legal 26 |
---|
68 | 67 | | representative who obtains or has obtained a financial product or service 27 |
---|
69 | 68 | | from a financial institution that is to be used primarily for personal, 28 |
---|
70 | 69 | | family, or household purposes; 29 |
---|
71 | 70 | | (5)(A)(10)(A) “Control” means the power, directly or indirectly, 30 |
---|
72 | 71 | | to direct the management or policies of a company, whether through ownership 31 |
---|
73 | 72 | | of securities, by contract, or otherwise. 32 |
---|
74 | 73 | | (B) A person is presumed to control a company if the 33 |
---|
75 | 74 | | person: 34 |
---|
76 | 75 | | (i) Is a director, general partner, or executive 35 |
---|
77 | 76 | | officer of the company; 36 HB1466 |
---|
78 | 77 | | |
---|
79 | 78 | | 3 02/12/2025 2:18:59 PM ANS120 |
---|
80 | 79 | | (ii) Directly or indirectly has the right to vote 1 |
---|
81 | 80 | | twenty-five percent (25%) or more of a class of a voting security of the 2 |
---|
82 | 81 | | company or has the power to sell or direct the sale of twenty -five percent 3 |
---|
83 | 82 | | (25%) or more of a class of voting securities of the company; 4 |
---|
84 | 83 | | (iii) In the case of a limited liability company, is 5 |
---|
85 | 84 | | a managing member of the limited liability company; or 6 |
---|
86 | 85 | | (iv) In the case of a partnership, has the right to 7 |
---|
87 | 86 | | receive upon dissolution or has contributed ten percent (10%) or more of the 8 |
---|
88 | 87 | | capital of the partnership; 9 |
---|
89 | 88 | | (6)(11) “Control affiliate” means a partnership, corporation, 10 |
---|
90 | 89 | | trust, limited liability company, or other organization that directly or 11 |
---|
91 | 90 | | indirectly controls or is controlled by the applicant; 12 |
---|
92 | 91 | | (7)(12) “Control person” means an individual who directly or 13 |
---|
93 | 92 | | indirectly exercises control over the applicant; 14 |
---|
94 | 93 | | (13)(A) "Corporate governance" means the structure of and how 15 |
---|
95 | 94 | | the licensee is managed. 16 |
---|
96 | 95 | | (B) "Corporate governance" includes the corporate rules, 17 |
---|
97 | 96 | | policies, processes, and practices used to oversee and manage a licensee; 18 |
---|
98 | 97 | | (14)(A) "Covered institution servicer” means a nonbank mortgage 19 |
---|
99 | 98 | | servicer that: 20 |
---|
100 | 99 | | (i) As reported in the mortgage call report, 21 |
---|
101 | 100 | | services: 22 |
---|
102 | 101 | | (a) Portfolios of two thousand (2,000) or more 23 |
---|
103 | 102 | | of one (1) to four (4) unit residential mortgage loans serviced or 24 |
---|
104 | 103 | | subserviced for others, excluding whole loans owned; and 25 |
---|
105 | 104 | | (b) Loans being interim serviced before sale 26 |
---|
106 | 105 | | as of the most recent calendar year end; and 27 |
---|
107 | 106 | | (ii) Operates in two (2) or more states, districts, 28 |
---|
108 | 107 | | or territories of the United States either currently or as of the prior 29 |
---|
109 | 108 | | calendar year end. 30 |
---|
110 | 109 | | (B) "Covered institution servicer" does not include: 31 |
---|
111 | 110 | | (i) A person exempt from mortgage servicer licensing 32 |
---|
112 | 111 | | requirements under this subchapter; 33 |
---|
113 | 112 | | (ii) A mortgage servicer that has the status of a 34 |
---|
114 | 113 | | tax-exempt organization under 26 U.S.C. § 501(c)(3), as in effect on January 35 |
---|
115 | 114 | | 1, 2025; or 36 HB1466 |
---|
116 | 115 | | |
---|
117 | 116 | | 4 02/12/2025 2:18:59 PM ANS120 |
---|
118 | 117 | | (iii) A mortgage servicer solely owning or conducting 1 |
---|
119 | 118 | | reverse mortgage servicing, or both, or the reverse mortgage portfolio 2 |
---|
120 | 119 | | administered by a large mortgage servicer; 3 |
---|
121 | 120 | | (15) "Customer" means a consumer who has a customer relationship 4 |
---|
122 | 121 | | with a financial institution; 5 |
---|
123 | 122 | | (16) "Customer information" means a record containing nonpublic 6 |
---|
124 | 123 | | personal information about a customer of a financial institution, whether in 7 |
---|
125 | 124 | | paper, electronic, or other form, that is handled or maintained by or on 8 |
---|
126 | 125 | | behalf of a financial institution or the financial institution’s affiliates; 9 |
---|
127 | 126 | | (17) "Customer relationship" means a continuing relationship 10 |
---|
128 | 127 | | between a consumer and a financial institution under which the financial 11 |
---|
129 | 128 | | institution provides to the consumer one (1) or more financial products or 12 |
---|
130 | 129 | | services that are used primarily for personal, family, or household purposes; 13 |
---|
131 | 130 | | (8)(18) "Employee" means an individual who is licensed with or 14 |
---|
132 | 131 | | employed by a mortgage broker, mortgage banker, or mortgage servicer, whether 15 |
---|
133 | 132 | | by employment contract, agency, or other arrangement and regardless of 16 |
---|
134 | 133 | | whether the individual is treated as an employee for purposes of compliance 17 |
---|
135 | 134 | | with the federal income tax laws; 18 |
---|
136 | 135 | | (19) "Encryption" means the transformation of data into a form 19 |
---|
137 | 136 | | that results in a low probability of assigning meaning without the use of a 20 |
---|
138 | 137 | | protective process or key, consistent with current cryptographic standards 21 |
---|
139 | 138 | | and accompanied by appropriate safeguards for cryptographic key material; 22 |
---|
140 | 139 | | (9)(A)(20)(A) “Exempt person” means a person not required to be 23 |
---|
141 | 140 | | licensed as a mortgage broker, mortgage banker, mortgage servicer, loan 24 |
---|
142 | 141 | | officer, or transitional loan officer under this subchapter. 25 |
---|
143 | 142 | | (B) “Exempt person” includes any of the following: 26 |
---|
144 | 143 | | (i) An employee of a licensee whose responsibilities 27 |
---|
145 | 144 | | are limited to clerical and administrative tasks for his or her employer and 28 |
---|
146 | 145 | | who does not solicit borrowers, accept applications, or negotiate the terms 29 |
---|
147 | 146 | | of loans on behalf of the employer; 30 |
---|
148 | 147 | | (ii) An agency or corporate instrumentality of the 31 |
---|
149 | 148 | | federal government or any state, county, or municipal government granting 32 |
---|
150 | 149 | | mortgage loans under specific authority of the laws of any state or of the 33 |
---|
151 | 150 | | United States; 34 |
---|
152 | 151 | | (iii) A trust company or industrial loan company 35 |
---|
153 | 152 | | chartered under the laws of Arkansas; 36 HB1466 |
---|
154 | 153 | | |
---|
155 | 154 | | 5 02/12/2025 2:18:59 PM ANS120 |
---|
156 | 155 | | (iv) A small-business investment corporation licensed 1 |
---|
157 | 156 | | under the Small Business Investment Act of 1958, 15 U.S.C. § 661 et seq., as 2 |
---|
158 | 157 | | it existed on January 1, 2011 January 1, 2025; 3 |
---|
159 | 158 | | (v) A real estate investment trust as defined in 26 4 |
---|
160 | 159 | | U.S.C. § 856, as it existed on January 1, 2011 January 1, 2025; 5 |
---|
161 | 160 | | (vi) A state or federally chartered bank, an 6 |
---|
162 | 161 | | operating subsidiary of a state -chartered bank regulated by the State Bank 7 |
---|
163 | 162 | | Department, a savings bank, a savings and loan association, or a credit 8 |
---|
164 | 163 | | union, the accounts of which are insured by the Federal Deposit Insurance 9 |
---|
165 | 164 | | Corporation or the National Credit Union Administration; 10 |
---|
166 | 165 | | (vii) An agricultural loan organization that is 11 |
---|
167 | 166 | | subject to licensing, supervision, or auditing by the United States Farm 12 |
---|
168 | 167 | | Service Agency, Commodity Credit Corporation, Rural Development Housing and 13 |
---|
169 | 168 | | Community Facilities Programs United States Department of Agriculture Rural 14 |
---|
170 | 169 | | Development, United States Farm Credit Administration, or the United States 15 |
---|
171 | 170 | | Department of Agriculture; 16 |
---|
172 | 171 | | (viii) A nonprofit corporation that: 17 |
---|
173 | 172 | | (a) Qualifies as a nonprofit entity under § 18 |
---|
174 | 173 | | 501(c)(3) of the Internal Revenue Code; 19 |
---|
175 | 174 | | (b) Is not primarily in the business of 20 |
---|
176 | 175 | | soliciting or brokering mortgage loans; and 21 |
---|
177 | 176 | | (c) Makes or services mortgage loans to 22 |
---|
178 | 177 | | promote home ownership or home improvements for the disadvantaged; 23 |
---|
179 | 178 | | (ix)(a) A licensed real estate agent or broker who 24 |
---|
180 | 179 | | is performing those activities subject to the regulation of the Arkansas Real 25 |
---|
181 | 180 | | Estate Commission. 26 |
---|
182 | 181 | | (b) Notwithstanding subdivision (9)(B)(ix)(a) 27 |
---|
183 | 182 | | subdivision (20)(B)(ix)(a) of this section, "exempt person" does not include 28 |
---|
184 | 183 | | a real estate agent or broker who receives compensation of any kind in 29 |
---|
185 | 184 | | connection with the referral, placement, or origination of a mortgage loan; 30 |
---|
186 | 185 | | (x) A person who engages in seller -financed 31 |
---|
187 | 186 | | transactions or who as a seller of real property receives mortgages, deeds of 32 |
---|
188 | 187 | | trust, or other security instruments on real estate as security for a 33 |
---|
189 | 188 | | purchase money obligation if: 34 |
---|
190 | 189 | | (a) The person does not receive from or hold 35 |
---|
191 | 190 | | on behalf of the borrower any funds for the payment of insurance or taxes on 36 HB1466 |
---|
192 | 191 | | |
---|
193 | 192 | | 6 02/12/2025 2:18:59 PM ANS120 |
---|
194 | 193 | | the real property; and 1 |
---|
195 | 194 | | (b) The seller does not sell the liens or 2 |
---|
196 | 195 | | mortgages in the secondary market other than to affiliated or subsidiary 3 |
---|
197 | 196 | | persons; 4 |
---|
198 | 197 | | (xi) An individual or husband and wife married 5 |
---|
199 | 198 | | couple who provide funds for investment in loans secured by a lien on real 6 |
---|
200 | 199 | | property on his or her or their own account and who do not: 7 |
---|
201 | 200 | | (a) Charge a fee or cause a fee to be paid for 8 |
---|
202 | 201 | | any service other than the normal and scheduled rates for escrow, title 9 |
---|
203 | 202 | | insurance, and recording services; and 10 |
---|
204 | 203 | | (b) Collect funds to be used for the payment 11 |
---|
205 | 204 | | of any taxes or insurance premiums on the property securing the loans; 12 |
---|
206 | 205 | | (xii) An attorney licensed in Arkansas rendering 13 |
---|
207 | 206 | | legal services to his or her client, when the conduct that would subject the 14 |
---|
208 | 207 | | attorney to the jurisdiction of this subchapter is ancillary to the provision 15 |
---|
209 | 208 | | of the legal services offered; 16 |
---|
210 | 209 | | (xiii) A person performing any act under order of 17 |
---|
211 | 210 | | any court; 18 |
---|
212 | 211 | | (xiv) A person acting as a mortgage broker, mortgage 19 |
---|
213 | 212 | | banker, or mortgage servicer for any person located in Arkansas, if the 20 |
---|
214 | 213 | | mortgage broker, mortgage banker, or mortgage servicer has no office or 21 |
---|
215 | 214 | | employee in Arkansas and the real property that is the subject of the 22 |
---|
216 | 215 | | mortgage is located outside of Arkansas; 23 |
---|
217 | 216 | | (xv) An officer or employee of an exempt person 24 |
---|
218 | 217 | | described in subdivisions (9)(B)(ii) -(xiv) subdivisions (20)(B)(ii) -(xiv) of 25 |
---|
219 | 218 | | this section if acting in the scope of employment for the exempt person; and 26 |
---|
220 | 219 | | (xvi) A manufactured or modular home retailer and 27 |
---|
221 | 220 | | its employees if: 28 |
---|
222 | 221 | | (a) The manufactured or modular home retailer 29 |
---|
223 | 222 | | or its employees perform only administrative or clerical tasks on behalf of a 30 |
---|
224 | 223 | | person required to be licensed under this subchapter; or 31 |
---|
225 | 224 | | (b) The manufactured or modular home retailer 32 |
---|
226 | 225 | | and its employees: 33 |
---|
227 | 226 | | (1) Do not receive compensation or 34 |
---|
228 | 227 | | financial gain for engaging in loan officer activities that exceeds the 35 |
---|
229 | 228 | | amount of compensation or financial gain that could be received in a 36 HB1466 |
---|
230 | 229 | | |
---|
231 | 230 | | 7 02/12/2025 2:18:59 PM ANS120 |
---|
232 | 231 | | comparable cash transaction for a manufactured home; 1 |
---|
233 | 232 | | (2) Disclose to the consumer in writing 2 |
---|
234 | 233 | | any corporate affiliation with a mortgage banker; 3 |
---|
235 | 234 | | (3) Provide referral information for at 4 |
---|
236 | 235 | | least one (1) unaffiliated creditor if the manufactured or modular home 5 |
---|
237 | 236 | | retailer has a corporate affiliation with a mortgage banker and the mortgage 6 |
---|
238 | 237 | | banker offers a recommendation; and 7 |
---|
239 | 238 | | (4)(A) Do not directly negotiate loan 8 |
---|
240 | 239 | | terms with the consumer or lender. 9 |
---|
241 | 240 | | (B) As used in subdivision 10 |
---|
242 | 241 | | (9)(B)(xvi)(b)(4)(A) subdivision (20)(B)(xvi)(b)(4)(A) of this section, “loan 11 |
---|
243 | 242 | | terms” includes rates, fees, and other costs; 12 |
---|
244 | 243 | | (21) "External audit" means a formal report prepared by an 13 |
---|
245 | 244 | | independent certified public accountant expressing an opinion on whether 14 |
---|
246 | 245 | | financial statements are: 15 |
---|
247 | 246 | | (A) Presented fairly, in all material aspects, according 16 |
---|
248 | 247 | | to the applicable financial reporting framework; and 17 |
---|
249 | 248 | | (B) Inclusive of an evaluation of the adequacy of a 18 |
---|
250 | 249 | | company’s internal control structure; 19 |
---|
251 | 250 | | (22) "Financial institution" means a mortgage broker, mortgage 20 |
---|
252 | 251 | | banker, or mortgage servicer licensed under this subchapter; 21 |
---|
253 | 252 | | (23)(A) "Financial product or service" means a product or 22 |
---|
254 | 253 | | service that a financial holding company could offer by engaging in a 23 |
---|
255 | 254 | | financial activity under section 4(k) of the Bank Holding Company Act of 24 |
---|
256 | 255 | | 1956, 12 U.S.C. § 1843(k), as it existed on January 1, 2025. 25 |
---|
257 | 256 | | (B) "Financial product or service" includes a financial 26 |
---|
258 | 257 | | institution’s evaluation or brokerage of information that a financial 27 |
---|
259 | 258 | | institution collects in connection with a request or an application from a 28 |
---|
260 | 259 | | consumer for a financial product or service; 29 |
---|
261 | 260 | | (24) "Information security program" means the administrative, 30 |
---|
262 | 261 | | technical, or physical safeguards a financial institution uses to access, 31 |
---|
263 | 262 | | collect, distribute, process, protect, store, use, transmit, dispose of, or 32 |
---|
264 | 263 | | otherwise handle customer information; 33 |
---|
265 | 264 | | (25) "Information system" means a discrete set of electronic 34 |
---|
266 | 265 | | information resources organized for the collection, processing, maintenance, 35 |
---|
267 | 266 | | use, sharing, dissemination, or disposition of electronic information, 36 HB1466 |
---|
268 | 267 | | |
---|
269 | 268 | | 8 02/12/2025 2:18:59 PM ANS120 |
---|
270 | 269 | | including any specialized system, such as industrial controls system or a 1 |
---|
271 | 270 | | process controls system, a telephone switching and private branch exchange 2 |
---|
272 | 271 | | system, and an environmental control system, that contain customer 3 |
---|
273 | 272 | | information or that is connected to a system that contains customer 4 |
---|
274 | 273 | | information; 5 |
---|
275 | 274 | | (26) "Interim serviced before sale" means the activity of 6 |
---|
276 | 275 | | collecting a limited number of contractual mortgage payments immediately 7 |
---|
277 | 276 | | after origination on loans held for sale but before the loans have been sold 8 |
---|
278 | 277 | | into the secondary market; 9 |
---|
279 | 278 | | (27) "Internal audit" means the internal activity of performing 10 |
---|
280 | 279 | | independent, objective assurance, and consulting to evaluate and improve the 11 |
---|
281 | 280 | | effectiveness of company operations, risk management, internal controls, and 12 |
---|
282 | 281 | | governance processes; 13 |
---|
283 | 282 | | (28)(A) "Key individual" means an individual who is ultimately 14 |
---|
284 | 283 | | responsible for establishing or directing policies and procedures of a 15 |
---|
285 | 284 | | licensee. 16 |
---|
286 | 285 | | (B) "Key individual" includes without limitation: 17 |
---|
287 | 286 | | (i) An executive officer; 18 |
---|
288 | 287 | | (ii) A manager; 19 |
---|
289 | 288 | | (iii) A director; 20 |
---|
290 | 289 | | (iv) A trustee; or 21 |
---|
291 | 290 | | (v) A control person; 22 |
---|
292 | 291 | | (10)(29) “Licensee” means a loan officer, transitional loan 23 |
---|
293 | 292 | | officer, mortgage broker, mortgage banker, or mortgage servicer that is 24 |
---|
294 | 293 | | licensed under this subchapter; 25 |
---|
295 | 294 | | (11)(A)(30)(A) "Loan officer" means an individual other than an 26 |
---|
296 | 295 | | exempt person described in subdivision (9) subdivision (20) of this section 27 |
---|
297 | 296 | | who in exchange for compensation as an employee of or who otherwise receives 28 |
---|
298 | 297 | | compensation or remuneration from a mortgage broker or a mortgage banker: 29 |
---|
299 | 298 | | (i) Solicits or offers to solicit an application for 30 |
---|
300 | 299 | | a mortgage loan; 31 |
---|
301 | 300 | | (ii) Accepts or offers to accept an application for 32 |
---|
302 | 301 | | a mortgage loan; 33 |
---|
303 | 302 | | (iii) Negotiates or offers to negotiate the terms or 34 |
---|
304 | 303 | | conditions of a mortgage loan; 35 |
---|
305 | 304 | | (iv) Issues or offers to issue a mortgage loan 36 HB1466 |
---|
306 | 305 | | |
---|
307 | 306 | | 9 02/12/2025 2:18:59 PM ANS120 |
---|
308 | 307 | | commitment or interest rate guarantee agreement; or 1 |
---|
309 | 308 | | (v) Provides or offers to provide modification of a 2 |
---|
310 | 309 | | mortgage loan. 3 |
---|
311 | 310 | | (B) “Loan officer” does not include: 4 |
---|
312 | 311 | | (i) An individual who performs clerical or 5 |
---|
313 | 312 | | administrative tasks in the processing of a mortgage loan at the direction of 6 |
---|
314 | 313 | | and subject to the supervision and instruction of a licensed loan officer; 7 |
---|
315 | 314 | | (ii) An underwriter if the individual performs no 8 |
---|
316 | 315 | | activities under subdivision (11)(A) subdivision (30)(A) of this section; or 9 |
---|
317 | 316 | | (iii) An individual who is solely involved in 10 |
---|
318 | 317 | | extensions of credit relating to timeshare plans, as that term is defined in 11 |
---|
319 | 318 | | 11 U.S.C. § 101(53D), as it existed on January 1, 2011 January 1, 2025; 12 |
---|
320 | 319 | | (12)(31) "Make a mortgage loan" means to close a mortgage loan, 13 |
---|
321 | 320 | | to advance funds, to offer to advance funds, or to make a commitment to 14 |
---|
322 | 321 | | advance funds to a borrower under a mortgage loan; 15 |
---|
323 | 322 | | (13)(A)(32)(A) "Managing principal" means a person who meets the 16 |
---|
324 | 323 | | requirements of § 23 -39-508 and who agrees to be primarily responsible for 17 |
---|
325 | 324 | | the operations of a licensed mortgage broker, mortgage banker, or mortgage 18 |
---|
326 | 325 | | servicer. 19 |
---|
327 | 326 | | (B) "Managing principal" includes a qualifying individual; 20 |
---|
328 | 327 | | (14)(33) "Mortgage banker" means a person who engages in the 21 |
---|
329 | 328 | | business of making mortgage loans for compensation or other gain; 22 |
---|
330 | 329 | | (15)(34) "Mortgage broker" means a person who for compensation 23 |
---|
331 | 330 | | or other gain or in the expectation of compensation or other gain and, 24 |
---|
332 | 331 | | regardless of whether the acts are done directly or indirectly, through 25 |
---|
333 | 332 | | contact by telephone, by electronic means, by mail, or in person with the 26 |
---|
334 | 333 | | borrowers or potential borrowers: 27 |
---|
335 | 334 | | (A) Accepts or offers to accept an application for a 28 |
---|
336 | 335 | | mortgage loan; 29 |
---|
337 | 336 | | (B) Solicits or offers to solicit an application for a 30 |
---|
338 | 337 | | mortgage loan; 31 |
---|
339 | 338 | | (C) Negotiates or offers to negotiate the terms or 32 |
---|
340 | 339 | | conditions of a mortgage loan; or 33 |
---|
341 | 340 | | (D) Issues or offers to issue mortgage loan commitments or 34 |
---|
342 | 341 | | interest rate guarantee agreements to borrowers; 35 |
---|
343 | 342 | | (35) "Mortgage call report" means a quarterly or annual report 36 HB1466 |
---|
344 | 343 | | |
---|
345 | 344 | | 10 02/12/2025 2:18:59 PM ANS120 |
---|
346 | 345 | | of residential real estate loan origination, servicing, and financial 1 |
---|
347 | 346 | | information completed by a company licensed through the Nationwide Multistate 2 |
---|
348 | 347 | | Licensing System and Registry; 3 |
---|
349 | 348 | | (16)(36)(A) "Mortgage loan" means a loan primarily for personal, 4 |
---|
350 | 349 | | family, or household use that is secured by a mortgage, deed of trust, 5 |
---|
351 | 350 | | reverse mortgage, or other equivalent consensual security interest 6 |
---|
352 | 351 | | encumbering: 7 |
---|
353 | 352 | | (A)(i) A dwelling as defined in section 1602(w) of 8 |
---|
354 | 353 | | the Truth in Lending Act, 15 U.S.C. § 1601 et seq., as it existed on January 9 |
---|
355 | 354 | | 1, 2011 January 1, 2025; or 10 |
---|
356 | 355 | | (B)(ii) Residential real estate upon which is 11 |
---|
357 | 356 | | constructed or intended to be constructed a dwelling . 12 |
---|
358 | 357 | | (B) "Mortgage loan" includes a residential mortgage loan ; 13 |
---|
359 | 358 | | (17)(A)(37)(A) “Mortgage servicer” means : 14 |
---|
360 | 359 | | (i) An entity performing the routine administration 15 |
---|
361 | 360 | | of a residential mortgage loan on behalf of an owner of the related mortgage 16 |
---|
362 | 361 | | under the terms of a servicing contract; or 17 |
---|
363 | 362 | | (ii) a A person that receives or has the right to 18 |
---|
364 | 363 | | receive from or on behalf of a borrower: 19 |
---|
365 | 364 | | (i)(a) Funds or credits in payment for a 20 |
---|
366 | 365 | | mortgage loan; or 21 |
---|
367 | 366 | | (ii)(b) The taxes or insurance associated with 22 |
---|
368 | 367 | | a mortgage loan. 23 |
---|
369 | 368 | | (B) In the case of a home equity conversion mortgage or a 24 |
---|
370 | 369 | | reverse mortgage, "mortgage servicer" includes a person that makes a payment 25 |
---|
371 | 370 | | to the borrower; 26 |
---|
372 | 371 | | (38) "Mortgage servicing rights" means the contractual right to 27 |
---|
373 | 372 | | service residential mortgage loans on behalf of the owner of the associated 28 |
---|
374 | 373 | | mortgage in exchange for specified compensation according to a servicing 29 |
---|
375 | 374 | | contract; 30 |
---|
376 | 375 | | (39) "Multifactor authentication" means authentication through 31 |
---|
377 | 376 | | verification of at least two (2) of the following types of authentication 32 |
---|
378 | 377 | | factors: 33 |
---|
379 | 378 | | (A) Knowledge factors, including without limitation a 34 |
---|
380 | 379 | | password; 35 |
---|
381 | 380 | | (B) Possession factors, including without limitation a 36 HB1466 |
---|
382 | 381 | | |
---|
383 | 382 | | 11 02/12/2025 2:18:59 PM ANS120 |
---|
384 | 383 | | token; or 1 |
---|
385 | 384 | | (C) Inherence factors, including without limitation 2 |
---|
386 | 385 | | biometric characteristics; 3 |
---|
387 | 386 | | (40)(A) "Nonpublic personal information" means: 4 |
---|
388 | 387 | | (i) Personally identifiable financial information; 5 |
---|
389 | 388 | | and 6 |
---|
390 | 389 | | (ii) A list, description, or other grouping of 7 |
---|
391 | 390 | | consumers, and publicly available information pertaining to a consumer, that 8 |
---|
392 | 391 | | is derived using personally identifiable financial information that is not 9 |
---|
393 | 392 | | publicly available. 10 |
---|
394 | 393 | | (B) "Nonpublic personal information" includes without 11 |
---|
395 | 394 | | limitation a list of individuals’ names and street addresses that is derived 12 |
---|
396 | 395 | | in whole or in part using personally identifiable financial information that 13 |
---|
397 | 396 | | is not publicly available. 14 |
---|
398 | 397 | | (C) "Nonpublic personal information" does not include: 15 |
---|
399 | 398 | | (i) Publicly available information except as 16 |
---|
400 | 399 | | included on a list described in subdivision (40)(A)(ii) of this section; 17 |
---|
401 | 400 | | (ii) A list, description, or other grouping of 18 |
---|
402 | 401 | | consumers, and publicly available information pertaining to the list, 19 |
---|
403 | 402 | | description, or other grouping of consumers, that is derived without using 20 |
---|
404 | 403 | | personally identifiable financial information that is not publicly available; 21 |
---|
405 | 404 | | or 22 |
---|
406 | 405 | | (iii) A list of individuals’ names and addresses 23 |
---|
407 | 406 | | that contains only publicly available information and is not: 24 |
---|
408 | 407 | | (a) Derived, in whole or in part, using 25 |
---|
409 | 408 | | personally identifiable financial information that is not publicly available; 26 |
---|
410 | 409 | | and 27 |
---|
411 | 410 | | (b) Disclosed in a manner that indicates that 28 |
---|
412 | 411 | | any of the individuals on the list is a consumer of a financial institution; 29 |
---|
413 | 412 | | (41)(A) "Notification event" means acquisition of unencrypted 30 |
---|
414 | 413 | | customer information without the authorization of the customer to which the 31 |
---|
415 | 414 | | information pertains. 32 |
---|
416 | 415 | | (B) For purposes of subdivision (41)(A) of this section: 33 |
---|
417 | 416 | | (i) Customer information is considered unencrypted 34 |
---|
418 | 417 | | if the encryption key was accessed by an unauthorized person; and 35 |
---|
419 | 418 | | (ii) Unauthorized acquisition is presumed to include 36 HB1466 |
---|
420 | 419 | | |
---|
421 | 420 | | 12 02/12/2025 2:18:59 PM ANS120 |
---|
422 | 421 | | unauthorized access to unencrypted customer information unless a financial 1 |
---|
423 | 422 | | institution has reliable evidence showing that there has not been, or could 2 |
---|
424 | 423 | | not reasonably have been, unauthorized acquisition of the customer 3 |
---|
425 | 424 | | information; 4 |
---|
426 | 425 | | (42) "Operating liquidity" means the funds necessary to perform 5 |
---|
427 | 426 | | normal business operations, including payment of rent, salaries, interest 6 |
---|
428 | 427 | | expense, and other typical expenses associated with operating an entity; 7 |
---|
429 | 428 | | (18)(43) "Operating subsidiary" means a separate corporation, 8 |
---|
430 | 429 | | limited liability company, or similar entity in which a national or state 9 |
---|
431 | 430 | | bank, savings and loan association, or credit union, the accounts of which 10 |
---|
432 | 431 | | are insured by the Federal Deposit Insurance Corporation or the National 11 |
---|
433 | 432 | | Credit Union Administration, maintains more than fifty percent (50%) voting 12 |
---|
434 | 433 | | rights, a controlling interest, or otherwise controls the subsidiary and no 13 |
---|
435 | 434 | | other party controls more than fifty percent (50%) of the voting rights or a 14 |
---|
436 | 435 | | controlling interest in the subsidiary; 15 |
---|
437 | 436 | | (44) "Penetration testing" means a test methodology in which 16 |
---|
438 | 437 | | assessors attempt to circumvent or defeat the security features of an 17 |
---|
439 | 438 | | information system by attempting penetration of databases or controls from 18 |
---|
440 | 439 | | outside or inside a financial institution’s information system; 19 |
---|
441 | 440 | | (19)(45) "Person" means an individual, partnership, limited 20 |
---|
442 | 441 | | liability company, limited partnership, corporation, association, or other 21 |
---|
443 | 442 | | group engaged in joint business activities, however organized; 22 |
---|
444 | 443 | | (46)(A) "Personally identifiable financial information" means 23 |
---|
445 | 444 | | information: 24 |
---|
446 | 445 | | (i) A consumer provides to a financial institution 25 |
---|
447 | 446 | | to obtain a financial product or service from a financial institution; 26 |
---|
448 | 447 | | (ii) About a consumer resulting from a transaction 27 |
---|
449 | 448 | | involving a financial product or service between a financial institution and 28 |
---|
450 | 449 | | a consumer; or 29 |
---|
451 | 450 | | (iii) A financial institution otherwise obtains 30 |
---|
452 | 451 | | about a consumer in connection with providing a financial product or service 31 |
---|
453 | 452 | | to that consumer. 32 |
---|
454 | 453 | | (B) "Personally identifiable financial information" 33 |
---|
455 | 454 | | includes: 34 |
---|
456 | 455 | | (i) Information a consumer provides to a financial 35 |
---|
457 | 456 | | institution on an application to obtain a loan, credit card, or other 36 HB1466 |
---|
458 | 457 | | |
---|
459 | 458 | | 13 02/12/2025 2:18:59 PM ANS120 |
---|
460 | 459 | | financial product or service; 1 |
---|
461 | 460 | | (ii) Account balance information, payment history, 2 |
---|
462 | 461 | | overdraft history, and credit or debit card purchase information; 3 |
---|
463 | 462 | | (iii) The fact that an individual is or has been a 4 |
---|
464 | 463 | | financial institution's customer or has obtained a financial product or 5 |
---|
465 | 464 | | service from a financial institution; 6 |
---|
466 | 465 | | (iv) Information about a financial institution’s 7 |
---|
467 | 466 | | consumer if the information is disclosed in a manner that indicates that the 8 |
---|
468 | 467 | | individual is or has been the financial institution’s consumer; 9 |
---|
469 | 468 | | (v) Information that a consumer provides to a 10 |
---|
470 | 469 | | financial institution or that a financial institution or a financial 11 |
---|
471 | 470 | | institution’s agent otherwise obtains in connection with collecting on or 12 |
---|
472 | 471 | | servicing a credit account; 13 |
---|
473 | 472 | | (vi) Information a financial institution collects 14 |
---|
474 | 473 | | through an internet cookie or an information collecting device from a 15 |
---|
475 | 474 | | computer server; and 16 |
---|
476 | 475 | | (vii) Information from a consumer report. 17 |
---|
477 | 476 | | (C) "Personally identifiable financial information" does 18 |
---|
478 | 477 | | not include: 19 |
---|
479 | 478 | | (i) A list of names and addresses of customers of an 20 |
---|
480 | 479 | | entity that is not a financial institution; and 21 |
---|
481 | 480 | | (ii) Information that does not identify a consumer, 22 |
---|
482 | 481 | | including aggregate information or blind data that does not contain personal 23 |
---|
483 | 482 | | identifiers such as account numbers, names, or addresses; 24 |
---|
484 | 483 | | (20)(47) "Principal place of business" means a stationary 25 |
---|
485 | 484 | | construction consisting of at least one (1) enclosed room or building in 26 |
---|
486 | 485 | | which negotiations of mortgage loan transactions of others may be conducted 27 |
---|
487 | 486 | | in private or in which the primary business functions of the licensee are 28 |
---|
488 | 487 | | conducted; 29 |
---|
489 | 488 | | (48)(A) "Publicly available information" means information that 30 |
---|
490 | 489 | | a financial institution has a reasonable basis to believe is lawfully made 31 |
---|
491 | 490 | | available to the public from: 32 |
---|
492 | 491 | | (i) Federal, state, or local government records; 33 |
---|
493 | 492 | | (ii) Widely distributed media; or 34 |
---|
494 | 493 | | (iii) Disclosures to the public that are required to 35 |
---|
495 | 494 | | be made by federal, state, or local law. 36 HB1466 |
---|
496 | 495 | | |
---|
497 | 496 | | 14 02/12/2025 2:18:59 PM ANS120 |
---|
498 | 497 | | (B) "Publicly available information" includes without 1 |
---|
499 | 498 | | limitation: 2 |
---|
500 | 499 | | (i) Information in government records, including 3 |
---|
501 | 500 | | information in government real estate records and security interest filings; 4 |
---|
502 | 501 | | and 5 |
---|
503 | 502 | | (ii)(a) Information from widely distributed media, 6 |
---|
504 | 503 | | including information from a telephone book, television or radio program, 7 |
---|
505 | 504 | | newspaper, or website that is available to the public on an unrestricted 8 |
---|
506 | 505 | | basis. 9 |
---|
507 | 506 | | (b) A website is not restricted under 10 |
---|
508 | 507 | | subdivision (48)(B)(ii)(a) of this section merely because an internet service 11 |
---|
509 | 508 | | provider or a site operator requires a fee or a password, so long as access 12 |
---|
510 | 509 | | is available to the public. 13 |
---|
511 | 510 | | (C) For purposes of this subdivision (48), a financial 14 |
---|
512 | 511 | | institution has a reasonable basis to believe that: 15 |
---|
513 | 512 | | (i) Information is lawfully made available to the 16 |
---|
514 | 513 | | public if the financial institution has taken steps to determine: 17 |
---|
515 | 514 | | (a) That the information is of the type that 18 |
---|
516 | 515 | | is available to the public; and 19 |
---|
517 | 516 | | (b) Whether an individual can direct that the 20 |
---|
518 | 517 | | information not be made available to the public and, if so, that the 21 |
---|
519 | 518 | | financial institution’s consumer has not directed that the information not be 22 |
---|
520 | 519 | | made available to the public; 23 |
---|
521 | 520 | | (ii) Mortgage information is lawfully made available 24 |
---|
522 | 521 | | to the public if the financial institution determines that the information is 25 |
---|
523 | 522 | | of the type included on the public record in the jurisdiction where the 26 |
---|
524 | 523 | | mortgage would be recorded; and 27 |
---|
525 | 524 | | (iii) An individual’s telephone number is lawfully 28 |
---|
526 | 525 | | made available to the public if the financial institution has located the 29 |
---|
527 | 526 | | telephone number in a telephone directory or the consumer has informed the 30 |
---|
528 | 527 | | financial institution that the telephone number is not unlisted; 31 |
---|
529 | 528 | | (49) "Qualified individual" means an individual designated by a 32 |
---|
530 | 529 | | financial institution to oversee, implement, and enforce the financial 33 |
---|
531 | 530 | | institution’s information security program; 34 |
---|
532 | 531 | | (50) "Residential mortgage loans serviced" means a specific 35 |
---|
533 | 532 | | portfolio or portfolios of residential mortgage loans for which a licensee is 36 HB1466 |
---|
534 | 533 | | |
---|
535 | 534 | | 15 02/12/2025 2:18:59 PM ANS120 |
---|
536 | 535 | | contractually responsible to the owner or owners of the mortgage loans for 1 |
---|
537 | 536 | | the defined servicing activities; 2 |
---|
538 | 537 | | (21)(51) "Reverse mortgage" means a nonrecourse loan that pays a 3 |
---|
539 | 538 | | homeowner loan proceeds drawn from accumulated home equity; 4 |
---|
540 | 539 | | (52) "Risk management assessment" means the functional 5 |
---|
541 | 540 | | evaluations performed under the risk management program and reports provided 6 |
---|
542 | 541 | | to a board of directors under a relevant governance protocol; 7 |
---|
543 | 542 | | (53) "Risk management program" means the policies and procedures 8 |
---|
544 | 543 | | designed to identify, measure, monitor, and mitigate risk sufficient for the 9 |
---|
545 | 544 | | level of sophistication of a covered institution servicer; 10 |
---|
546 | 545 | | (54) "Security event" means an event resulting in unauthorized 11 |
---|
547 | 546 | | access to, or disruption or misuse of: 12 |
---|
548 | 547 | | (A) An information system or information stored on the 13 |
---|
549 | 548 | | information system; or 14 |
---|
550 | 549 | | (B) Customer information held in physical form; 15 |
---|
551 | 550 | | (55) "Service provider" means a person or entity that receives, 16 |
---|
552 | 551 | | maintains, processes, or otherwise is permitted access to customer 17 |
---|
553 | 552 | | information through its provision of services directly to a financial 18 |
---|
554 | 553 | | institution that is subject to this subchapter; 19 |
---|
555 | 554 | | (56) "Servicing liquidity" means the financial resources 20 |
---|
556 | 555 | | necessary to manage liquidity risk arising from servicing functions required 21 |
---|
557 | 556 | | in acquiring and financing mortgage servicing rights, hedging costs, and 22 |
---|
558 | 557 | | margin calls associated with the mortgage servicing rights asset and 23 |
---|
559 | 558 | | financing facilities and advances or costs of advance financing for 24 |
---|
560 | 559 | | principal, interest, taxes, insurance, and any other servicing related 25 |
---|
561 | 560 | | advances; 26 |
---|
562 | 561 | | (22)(57) "Sponsor" means a mortgage broker or mortgage banker 27 |
---|
563 | 562 | | licensed under this subchapter that has assumed the responsibility for and 28 |
---|
564 | 563 | | agrees to supervise the actions of a loan officer or transitional loan 29 |
---|
565 | 564 | | officer; 30 |
---|
566 | 565 | | (58) "Tangible net worth" means the total equity less: 31 |
---|
567 | 566 | | (A) The receivables due from related entities; 32 |
---|
568 | 567 | | (B) Goodwill and other intangibles; and 33 |
---|
569 | 568 | | (C) Pledged assets; 34 |
---|
570 | 569 | | (23)(59) "Transitional loan officer" means an individual who, in 35 |
---|
571 | 570 | | exchange for compensation as an employee of, or who otherwise receives 36 HB1466 |
---|
572 | 571 | | |
---|
573 | 572 | | 16 02/12/2025 2:18:59 PM ANS120 |
---|
574 | 573 | | compensation or remuneration from, a mortgage broker or a mortgage banker, is 1 |
---|
575 | 574 | | authorized to act as a loan officer subject to a transitional loan officer 2 |
---|
576 | 575 | | license; 3 |
---|
577 | 576 | | (24)(60) "Transitional loan officer license" means a license 4 |
---|
578 | 577 | | that: 5 |
---|
579 | 578 | | (A) Is issued to an individual who is employed and 6 |
---|
580 | 579 | | sponsored by a mortgage banker or mortgage broker licensed under this 7 |
---|
581 | 580 | | subchapter; 8 |
---|
582 | 581 | | (B) Is limited to a term of no more than one hundred 9 |
---|
583 | 582 | | twenty (120) days; and 10 |
---|
584 | 583 | | (C) Is not subject to reapplication, renewal, or extension 11 |
---|
585 | 584 | | by the commissioner; and 12 |
---|
586 | 585 | | (25)(61) "Unique identifier" means a number or other identifier 13 |
---|
587 | 586 | | assigned by protocols established by the automated licensing system approved 14 |
---|
588 | 587 | | by the commissioner; and 15 |
---|
589 | 588 | | (62) "Whole loans" mean those loans in which a mortgage and the 16 |
---|
590 | 589 | | underlying credit risk is owned and held on the balance sheet of an entity 17 |
---|
591 | 590 | | with all ownership rights . 18 |
---|
592 | 591 | | 19 |
---|
593 | 592 | | SECTION 2. Arkansas Code § 23 -39-504 is amended to read as follows: 20 |
---|
594 | 593 | | 23-39-504. Rulemaking authority Authority. 21 |
---|
595 | 594 | | (a) The Securities Commissioner may adopt any rules that he or she 22 |
---|
596 | 595 | | deems necessary to: 23 |
---|
597 | 596 | | (1) Carry out the provisions of this subchapter; 24 |
---|
598 | 597 | | (2) Provide for the protection of the borrowing public; and 25 |
---|
599 | 598 | | (3) Provide any requirements necessary for the State of Arkansas 26 |
---|
600 | 599 | | to participate in a multistate automated licensing system; and 27 |
---|
601 | 600 | | (4) Instruct mortgage brokers, mortgage bankers, mortgage 28 |
---|
602 | 601 | | servicers, loan officers, and transitional loan officers in interpreting this 29 |
---|
603 | 602 | | subchapter. 30 |
---|
604 | 603 | | (b) The commissioner may: 31 |
---|
605 | 604 | | (1) If risk is determined by a formal review of a specific 32 |
---|
606 | 605 | | covered institution servicer to be extremely high, order or direct the 33 |
---|
607 | 606 | | covered institution servicer to satisfy additional conditions necessary to 34 |
---|
608 | 607 | | ensure that the covered institution servicer will continue to operate in a 35 |
---|
609 | 608 | | safe and sound manner and be able to continue to service loans in compliance 36 HB1466 |
---|
610 | 609 | | |
---|
611 | 610 | | 17 02/12/2025 2:18:59 PM ANS120 |
---|
612 | 611 | | with state law or rule and federal law or regulations; 1 |
---|
613 | 612 | | (2) If risk is determined by a formal review of a specific 2 |
---|
614 | 613 | | covered institution servicer to be extremely low, provide notice that all or 3 |
---|
615 | 614 | | part of this subchapter is not applicable to the covered institution 4 |
---|
616 | 615 | | servicer; and 5 |
---|
617 | 616 | | (3) If economic, environmental, or societal events are 6 |
---|
618 | 617 | | determined to be of severity to warrant a temporary suspension of all or 7 |
---|
619 | 618 | | certain sections of this subchapter, provide public notice of the temporary 8 |
---|
620 | 619 | | suspension. 9 |
---|
621 | 620 | | 10 |
---|
622 | 621 | | SECTION 3. Arkansas Code § 23 -39-505(f), concerning the surety bond 11 |
---|
623 | 622 | | under the Fair Mortgage Lending Act, is amended to read as follows: 12 |
---|
624 | 623 | | (f)(1) Each mortgage broker, mortgage banker, and mortgage servicer 13 |
---|
625 | 624 | | shall post a surety bond in an amount: 14 |
---|
626 | 625 | | (A) Based upon loan activity during the previous year; 15 |
---|
627 | 626 | | (B) Not less than one hundred thousand dollars ($100,000); 16 |
---|
628 | 627 | | and 17 |
---|
629 | 628 | | (C) As prescribed by rule or order of the commissioner. 18 |
---|
630 | 629 | | (2) The surety bond shall : 19 |
---|
631 | 630 | | (A) be Be in a form satisfactory to the commissioner ; and 20 |
---|
632 | 631 | | (B) Run to the State of Arkansas for benefit of a claimant 21 |
---|
633 | 632 | | against the licensee to secure the faithful performance of the obligations of 22 |
---|
634 | 633 | | the licensee under this subchapter . 23 |
---|
635 | 634 | | (3)(A) A party having a claim against a licensee may bring suit 24 |
---|
636 | 635 | | directly on the surety bond of the licensee under this subsection or the 25 |
---|
637 | 636 | | commissioner may bring suit on behalf of a claimant in one (1) action or in 26 |
---|
638 | 637 | | successive actions. 27 |
---|
639 | 638 | | (B) A consumer claim shall be given priority in recovering 28 |
---|
640 | 639 | | from the surety bond. 29 |
---|
641 | 640 | | (C) Every bond shall provide for suit on the bond by any 30 |
---|
642 | 641 | | person who has a cause of action under this subchapter. 31 |
---|
643 | 642 | | (4) The aggregate liability of the surety shall not exceed the 32 |
---|
644 | 643 | | principal sum of the bond. 33 |
---|
645 | 644 | | (5) A surety bond shall cover claims for at least five (5) years 34 |
---|
646 | 645 | | after the licensee ceases to provide mortgage services in this state or 35 |
---|
647 | 646 | | longer if required by the commissioner. 36 HB1466 |
---|
648 | 647 | | |
---|
649 | 648 | | 18 02/12/2025 2:18:59 PM ANS120 |
---|
650 | 649 | | (6)(A) A surety bond shall remain in effect until cancellation. 1 |
---|
651 | 650 | | (B) The cancellation of a surety bond shall occur only 2 |
---|
652 | 651 | | after sixty (60) days' written notice to the commissioner. 3 |
---|
653 | 652 | | (C) The cancellation of a surety bond shall not affect 4 |
---|
654 | 653 | | liability incurred or accrued during the sixty -day period under subdivision 5 |
---|
655 | 654 | | (f)(6)(B) of this section. 6 |
---|
656 | 655 | | (7)(A) If an action is commenced on a licensee's surety bond, 7 |
---|
657 | 656 | | the commissioner may require the filing of a new surety bond. 8 |
---|
658 | 657 | | (B) If a new surety bond is required under subdivision 9 |
---|
659 | 658 | | (f)(7)(A) of this section, the licensee shall file a replacement surety bond 10 |
---|
660 | 659 | | in the required amount specified under subdivision (f)(1)(B) of this section 11 |
---|
661 | 660 | | within thirty (30) days. 12 |
---|
662 | 661 | | (C) Immediately upon recovery of an action on the surety 13 |
---|
663 | 662 | | bond, the licensee shall file a new surety bond. 14 |
---|
664 | 663 | | 15 |
---|
665 | 664 | | SECTION 4. Arkansas Code § 23 -39-505(g), concerning audited financial 16 |
---|
666 | 665 | | statements under the Fair Mortgage Lending Act, is amended to read as 17 |
---|
667 | 666 | | follows: 18 |
---|
668 | 667 | | (g)(1) An applicant filing for licensure as a mortgage banker or 19 |
---|
669 | 668 | | mortgage servicer shall file with the commissioner as part of his or her 20 |
---|
670 | 669 | | application audited financial statements that reflect that the applicant has 21 |
---|
671 | 670 | | a net worth of at least twenty -five thousand dollars ($25,000) and are:. 22 |
---|
672 | 671 | | (1) Prepared by an independent certified public accountant: 23 |
---|
673 | 672 | | (2) Prepared according to: 24 |
---|
674 | 673 | | (A) Generally accepted accounting principles as 25 |
---|
675 | 674 | | promulgated by the Financial Accounting Standards Board; or 26 |
---|
676 | 675 | | (B) International financial reporting standards 27 |
---|
677 | 676 | | promulgated by the International Financial Reporting Standards Foundation and 28 |
---|
678 | 677 | | the International Accounting Standards Board; 29 |
---|
679 | 678 | | (3) Accompanied by an opinion acceptable to the commissioner; 30 |
---|
680 | 679 | | and 31 |
---|
681 | 680 | | (4) For purposes of complying with subdivision (g)(1) of this 32 |
---|
682 | 681 | | section, the financial statement shall be: 33 |
---|
683 | 682 | | (A) Determined according to: 34 |
---|
684 | 683 | | (i) Generally accepted accounting principles as 35 |
---|
685 | 684 | | promulgated by the Financial Accounting Standards Board; or 36 HB1466 |
---|
686 | 685 | | |
---|
687 | 686 | | 19 02/12/2025 2:18:59 PM ANS120 |
---|
688 | 687 | | (ii) The international financial reporting standards 1 |
---|
689 | 688 | | promulgated by the International Financial Reporting Standards Foundation and 2 |
---|
690 | 689 | | the International Accounting Standards Board; and 3 |
---|
691 | 690 | | (B) Accompanied by an opinion acceptable to the 4 |
---|
692 | 691 | | commissioner; 5 |
---|
693 | 692 | | (C) Dated within fifteen (15) months preceding the date on 6 |
---|
694 | 693 | | which the application is filed. 7 |
---|
695 | 694 | | 8 |
---|
696 | 695 | | SECTION 5. Arkansas Code § 23 -39-505, concerning qualifications for a 9 |
---|
697 | 696 | | license under the Fair Mortgage Lending Act, is amended to add additional 10 |
---|
698 | 697 | | subsections to read as follows: 11 |
---|
699 | 698 | | (p)(1) An applicant filing for licensure as a mortgage servicer but 12 |
---|
700 | 699 | | that does not operate as a covered institution servicer shall file with the 13 |
---|
701 | 700 | | commissioner as part of his or her application audited financial statements 14 |
---|
702 | 701 | | that reflect that the applicant has a net worth of at least one hundred 15 |
---|
703 | 702 | | thousand dollars ($100,000). 16 |
---|
704 | 703 | | (2) For the purposes of complying with subdivision (p)(1) of 17 |
---|
705 | 704 | | this section, the financial statement shall be: 18 |
---|
706 | 705 | | (A) Determined according to: 19 |
---|
707 | 706 | | (i) Generally accepted accounting principles as 20 |
---|
708 | 707 | | promulgated by the Financial Accounting Standards Board; or 21 |
---|
709 | 708 | | (ii) The international financial reporting standards 22 |
---|
710 | 709 | | promulgated by the International Financial Reporting Standards Foundation and 23 |
---|
711 | 710 | | the International Accounting Standards Board; 24 |
---|
712 | 711 | | (B) Accompanied by an opinion acceptable to the 25 |
---|
713 | 712 | | commissioner; and 26 |
---|
714 | 713 | | (C) Dated within fifteen (15) months preceding the date on 27 |
---|
715 | 714 | | which the application is filed. 28 |
---|
716 | 715 | | (3)(A) An applicant applying to service Arkansas residential 29 |
---|
717 | 716 | | mortgage loans may apply to the commissioner to waive or adjust one (1) or 30 |
---|
718 | 717 | | more of the net worth requirements under subdivision (p)(1) or subdivision 31 |
---|
719 | 718 | | (p)(2) of this section. 32 |
---|
720 | 719 | | (B)(i) In reviewing a request to waive or adjust one (1) 33 |
---|
721 | 720 | | or more of the net worth requirements under subdivision (p)(1) or subdivision 34 |
---|
722 | 721 | | (p)(2) of this section, the commissioner may consider the number and types of 35 |
---|
723 | 722 | | loans being serviced and whether the licensee has a positive net worth and 36 HB1466 |
---|
724 | 723 | | |
---|
725 | 724 | | 20 02/12/2025 2:18:59 PM ANS120 |
---|
726 | 725 | | adequate operating reserves. 1 |
---|
727 | 726 | | (ii) As used in this subdivision (p)(3)(B), 2 |
---|
728 | 727 | | “operating reserves” means the funds set aside in anticipation of future 3 |
---|
729 | 728 | | payments or obligations and are included in servicing liquidity. 4 |
---|
730 | 729 | | (q)(1) An applicant filing for licensure as a mortgage servicer that 5 |
---|
731 | 730 | | operates as a covered institution servicer shall file with the commissioner 6 |
---|
732 | 731 | | as part of his or her application proof that the applicant is in compliance 7 |
---|
733 | 732 | | with: 8 |
---|
734 | 733 | | (A) The Federal Housing Finance Agency's Eligibility 9 |
---|
735 | 734 | | Requirements for Enterprise Single -Family Seller/Servicers for minimum 10 |
---|
736 | 735 | | capital ratio; and 11 |
---|
737 | 736 | | (B) The net worth and servicing liquidity requirements, 12 |
---|
738 | 737 | | whether or not the mortgage servicer is approved for government -sponsored 13 |
---|
739 | 738 | | enterprise servicing. 14 |
---|
740 | 739 | | (2) For the purposes of complying with subdivision (q)(1) of 15 |
---|
741 | 740 | | this section, the financial data shall be: 16 |
---|
742 | 741 | | (A) Determined according to: 17 |
---|
743 | 742 | | (i) Generally accepted accounting principles as 18 |
---|
744 | 743 | | promulgated by the Financial Accounting Standards Board; or 19 |
---|
745 | 744 | | (ii) The international financial reporting standards 20 |
---|
746 | 745 | | promulgated by the International Financial Reporting Standards Foundation and 21 |
---|
747 | 746 | | the International Accounting Standards Board; 22 |
---|
748 | 747 | | (B) Accompanied by an opinion acceptable to the 23 |
---|
749 | 748 | | commissioner; and 24 |
---|
750 | 749 | | (C) Dated within fifteen (15) months preceding the date on 25 |
---|
751 | 750 | | which the application is filed. 26 |
---|
752 | 751 | | 27 |
---|
753 | 752 | | SECTION 6. Arkansas Code § 23 -39-506(f), concerning audited financial 28 |
---|
754 | 753 | | statements under the Fair Mortgage Lending Act, is amended to read as 29 |
---|
755 | 754 | | follows: 30 |
---|
756 | 755 | | (f)(1) A mortgage banker or a mortgage servicer shall submit audited 31 |
---|
757 | 756 | | financial statements to the commissioner within ninety (90) days after the 32 |
---|
758 | 757 | | end of the mortgage banker's or mortgage servicer's fiscal year. 33 |
---|
759 | 758 | | (2) The audited financial statements submitted to the 34 |
---|
760 | 759 | | commissioner under subdivision (f)(1) of this section shall: 35 |
---|
761 | 760 | | (A) Reflect that the mortgage banker or mortgage servicer 36 HB1466 |
---|
762 | 761 | | |
---|
763 | 762 | | 21 02/12/2025 2:18:59 PM ANS120 |
---|
764 | 763 | | has a net worth of at least twenty -five thousand dollars ($25,000); and 1 |
---|
765 | 764 | | (B) Comply with the requirements of § 23 -39-505(g)(1)-(3). 2 |
---|
766 | 765 | | (3)(A) Failure to timely submit audited financial statements to 3 |
---|
767 | 766 | | the commissioner shall result in a late fee of two hundred fifty dollars 4 |
---|
768 | 767 | | ($250). 5 |
---|
769 | 768 | | (B) All or part of the late fee may be waived by the 6 |
---|
770 | 769 | | commissioner for good cause. 7 |
---|
771 | 770 | | 8 |
---|
772 | 771 | | SECTION 7. Arkansas Code § 23 -39-506, concerning license renewal under 9 |
---|
773 | 772 | | the Fair Mortgage Lending Act, is amended to add additional subsections to 10 |
---|
774 | 773 | | read as follows: 11 |
---|
775 | 774 | | (g)(1) A mortgage servicer subject to § 23 -39-505(p) or § 23-39-505(q) 12 |
---|
776 | 775 | | shall submit audited financial statements to the commissioner within ninety 13 |
---|
777 | 776 | | (90) days after the end of the mortgage servicer's fiscal year. 14 |
---|
778 | 777 | | (2) The audited financial statements submitted to the 15 |
---|
779 | 778 | | commissioner under subdivision (g)(1) of this section shall reflect that the 16 |
---|
780 | 779 | | mortgage servicer has a net worth that remains in compliance with § 23-39-17 |
---|
781 | 780 | | 505(p) or § 23-39-505(q), as applicable. 18 |
---|
782 | 781 | | (3)(A) A licensee servicing Arkansas residential mortgage loans, 19 |
---|
783 | 782 | | other than a covered institution servicer, may apply to the commissioner to 20 |
---|
784 | 783 | | waive or adjust one (1) or more of the net worth requirements. 21 |
---|
785 | 784 | | (B) In considering a request to waive or adjust one (1) or 22 |
---|
786 | 785 | | more of the net worth requirements, the commissioner shall consider the 23 |
---|
787 | 786 | | number and types of loans being serviced and whether the licensee has a 24 |
---|
788 | 787 | | positive net worth and adequate operating reserves. 25 |
---|
789 | 788 | | (C) For purposes of this section, “operating reserves” 26 |
---|
790 | 789 | | means the funds set aside in anticipation of future payments or obligations 27 |
---|
791 | 790 | | and are included in liquidity. 28 |
---|
792 | 791 | | (4)(A) Failure to timely submit audited financial statements to 29 |
---|
793 | 792 | | the commissioner shall result in a late fee of two hundred fifty dollars 30 |
---|
794 | 793 | | ($250). 31 |
---|
795 | 794 | | (B) All or part of the late fee may be waived by the 32 |
---|
796 | 795 | | commissioner for good cause. 33 |
---|
797 | 796 | | (h) A covered institution servicer shall remain in compliance with the 34 |
---|
798 | 797 | | requirements of § 23 -39-505(q) and § 23-39-519. 35 |
---|
799 | 798 | | 36 HB1466 |
---|
800 | 799 | | |
---|
801 | 800 | | 22 02/12/2025 2:18:59 PM ANS120 |
---|
802 | 801 | | SECTION 8. Arkansas Code Title 23, Chapter 39, Subchapter 5, is 1 |
---|
803 | 802 | | amended to add additional sections to read as follows: 2 |
---|
804 | 803 | | 23-39-519. Prudential standards for covered institution servicers — 3 |
---|
805 | 804 | | Financial condition. 4 |
---|
806 | 805 | | (a) A covered institution servicer shall meet or exceed the minimum 5 |
---|
807 | 806 | | financial requirements of the Federal Housing Finance Agency's Eligibility 6 |
---|
808 | 807 | | Requirements for Enterprise Single -Family Seller/Servicers in order to 7 |
---|
809 | 808 | | maintain the capital and servicing liquidity as required by this section and 8 |
---|
810 | 809 | | § 23-39-505(q). 9 |
---|
811 | 810 | | (b) All financial data shall be determined according to generally 10 |
---|
812 | 811 | | accepted accounting principles or the international financial reporting 11 |
---|
813 | 812 | | standards promulgated by the International Financial Reporting Standards 12 |
---|
814 | 813 | | Foundation and the International Accounting Standards Board. 13 |
---|
815 | 814 | | (c) A covered institution servicer that meets the Federal Housing 14 |
---|
816 | 815 | | Finance Agency's Eligibility Requirements for Enterprise Single -Family 15 |
---|
817 | 816 | | Seller/Servicers for capital, net worth ratio, and servicing liquidity, 16 |
---|
818 | 817 | | whether or not the servicer is approved for government -sponsored enterprises 17 |
---|
819 | 818 | | servicing, or Federal National Mortgage Association servicing, or Federal 18 |
---|
820 | 819 | | Home Loan Mortgage Corporation servicing, satisfies the requirements of 19 |
---|
821 | 820 | | subsection (a) and subsection (b) of this section. 20 |
---|
822 | 821 | | (d)(1) A covered institution servicer shall maintain written policies 21 |
---|
823 | 822 | | and procedures implementing the capital and servicing liquidity requirements. 22 |
---|
824 | 823 | | (2) The policies and procedures under subdivision (d)(1) of this 23 |
---|
825 | 824 | | section shall include a sustainable written methodology for satisfying the 24 |
---|
826 | 825 | | requirements of subsection (a) of this section and be available to the 25 |
---|
827 | 826 | | Securities Commissioner upon request. 26 |
---|
828 | 827 | | (e)(1) A covered institution servicer under this subchapter shall: 27 |
---|
829 | 828 | | (A) Maintain sufficient allowable assets for liquidity in 28 |
---|
830 | 829 | | addition to the amounts required for servicing liquidity to cover normal 29 |
---|
831 | 830 | | business operations; and 30 |
---|
832 | 831 | | (B) Have in place sound cash management and business 31 |
---|
833 | 832 | | operating plans that match the size and sophistication of the covered 32 |
---|
834 | 833 | | institution servicer to ensure normal business operations. 33 |
---|
835 | 834 | | (2)(A) The management or key individual of a covered institution 34 |
---|
836 | 835 | | servicer shall develop, establish, and implement plans, policies, and 35 |
---|
837 | 836 | | procedures for maintaining operating liquidity sufficient for the ongoing 36 HB1466 |
---|
838 | 837 | | |
---|
839 | 838 | | 23 02/12/2025 2:18:59 PM ANS120 |
---|
840 | 839 | | needs of the covered institution servicer. 1 |
---|
841 | 840 | | (B) The plans, policies, and procedures under subdivision 2 |
---|
842 | 841 | | (e)(2)(A) of this section shall: 3 |
---|
843 | 842 | | (i) Contain sustainable, written methodologies for 4 |
---|
844 | 843 | | maintaining sufficient operating liquidity; and 5 |
---|
845 | 844 | | (ii) Be available to the commissioner upon request. 6 |
---|
846 | 845 | | 7 |
---|
847 | 846 | | 23-39-520. Corporate governance for covered institution servicers. 8 |
---|
848 | 847 | | (a) A covered institution servicer shall establish and maintain a 9 |
---|
849 | 848 | | board of directors who are responsible for the oversight of the covered 10 |
---|
850 | 849 | | institution servicer. 11 |
---|
851 | 850 | | (b) For a covered institution servicer that is not approved to service 12 |
---|
852 | 851 | | loans by a government -sponsored enterprise, the Federal National Mortgage 13 |
---|
853 | 852 | | Association and the Federal Home Loan Mortgage Corporation, or the Government 14 |
---|
854 | 853 | | National Mortgage Association, or when these federal agencies have granted 15 |
---|
855 | 854 | | approval for a board alternative, a covered institution servicer may 16 |
---|
856 | 855 | | establish a similar body constituted to exercise oversight and fulfill the 17 |
---|
857 | 856 | | board of directors’ responsibilities under subsection (c) of this section. 18 |
---|
858 | 857 | | (c) The board of directors shall be responsible for: 19 |
---|
859 | 858 | | (1) Establishing a written corporate governance framework, 20 |
---|
860 | 859 | | including appropriate internal controls designed to monitor corporate 21 |
---|
861 | 860 | | governance and assess compliance with the corporate governance framework, 22 |
---|
862 | 861 | | available to the Securities Commissioner upon request; 23 |
---|
863 | 862 | | (2) Monitoring and ensuring the covered institution servicer's 24 |
---|
864 | 863 | | compliance with the corporate governance framework and this subchapter; and 25 |
---|
865 | 864 | | (3) Accurate and timely regulatory reporting, including without 26 |
---|
866 | 865 | | limitation the requirements for filing the mortgage call report. 27 |
---|
867 | 866 | | (d)(1) The board of directors shall establish internal audit 28 |
---|
868 | 867 | | requirements that are appropriate for the size, complexity, and risk profile 29 |
---|
869 | 868 | | of the covered institution servicer, with appropriate independence to provide 30 |
---|
870 | 869 | | a reliable evaluation of the covered institution servicer’s internal control 31 |
---|
871 | 870 | | structure, risk management, and governance. 32 |
---|
872 | 871 | | (2) Internal audit requirements established by the board of 33 |
---|
873 | 872 | | directors and the results of internal audits shall be made available to the 34 |
---|
874 | 873 | | commissioner upon request. 35 |
---|
875 | 874 | | (e)(1) A covered institution servicer shall receive an external audit, 36 HB1466 |
---|
876 | 875 | | |
---|
877 | 876 | | 24 02/12/2025 2:18:59 PM ANS120 |
---|
878 | 877 | | including audited financial statements and audit reports, conducted by an 1 |
---|
879 | 878 | | independent certified public accountant annually. 2 |
---|
880 | 879 | | (2) The external audit required under subdivision (e)(1) of this 3 |
---|
881 | 880 | | section shall: 4 |
---|
882 | 881 | | (A) Be available to the commissioner upon request; and 5 |
---|
883 | 882 | | (B) Include at a minimum: 6 |
---|
884 | 883 | | (i) Annual financial statements including a balance 7 |
---|
885 | 884 | | sheet, statement of operations income statement and cash flows, notes, and 8 |
---|
886 | 885 | | supplemental schedules, prepared according to generally accepted accounting 9 |
---|
887 | 886 | | principles; 10 |
---|
888 | 887 | | (ii) An assessment of the internal control 11 |
---|
889 | 888 | | structure; 12 |
---|
890 | 889 | | (iii) A computation of tangible net worth; 13 |
---|
891 | 890 | | (iv) Validation of mortgage servicing rights 14 |
---|
892 | 891 | | valuation and reserve methodology, if applicable; 15 |
---|
893 | 892 | | (v) Verification of adequate fidelity and errors and 16 |
---|
894 | 893 | | omissions insurance; and 17 |
---|
895 | 894 | | (vi) Testing of controls related to risk management 18 |
---|
896 | 895 | | activities, including compliance and stress testing, if applicable. 19 |
---|
897 | 896 | | (f)(1) A covered institution servicer shall establish a risk 20 |
---|
898 | 897 | | management program under the oversight of the board of directors that is 21 |
---|
899 | 898 | | available to the commissioner upon request that identifies, measures, 22 |
---|
900 | 899 | | monitors, and controls risk sufficient for the level of sophistication of the 23 |
---|
901 | 900 | | covered institution servicer. 24 |
---|
902 | 901 | | (2) The risk management program required under subdivision 25 |
---|
903 | 902 | | (f)(1) of this section shall: 26 |
---|
904 | 903 | | (A) Have appropriate processes and models in place to 27 |
---|
905 | 904 | | measure, monitor, and mitigate financial risks and changes to the risk 28 |
---|
906 | 905 | | profile of the covered institution servicer and assets being serviced; and 29 |
---|
907 | 906 | | (B) Be scaled to the complexity of the covered institution 30 |
---|
908 | 907 | | servicer, but be sufficiently robust to manage risks in several areas, 31 |
---|
909 | 908 | | including without limitation: 32 |
---|
910 | 909 | | (i) Credit risk, including the potential that a 33 |
---|
911 | 910 | | borrower or counterparty will fail to perform on an obligation; 34 |
---|
912 | 911 | | (ii) Servicing liquidity risk, including the 35 |
---|
913 | 912 | | potential that the covered institution servicer will be unable to meet the 36 HB1466 |
---|
914 | 913 | | |
---|
915 | 914 | | 25 02/12/2025 2:18:59 PM ANS120 |
---|
916 | 915 | | covered institution servicer's obligations as the obligations come due 1 |
---|
917 | 916 | | because of an inability to liquidate assets or obtain adequate funding or 2 |
---|
918 | 917 | | that it cannot easily unwind or offset specific exposures; 3 |
---|
919 | 918 | | (iii) Operational risk, including the risk resulting 4 |
---|
920 | 919 | | from inadequate or failed internal processes, people, and systems or from 5 |
---|
921 | 920 | | external events; 6 |
---|
922 | 921 | | (iv) Market risk, including the risk to the covered 7 |
---|
923 | 922 | | institution servicer’s condition resulting from adverse movements in market 8 |
---|
924 | 923 | | rates or prices; 9 |
---|
925 | 924 | | (v) Compliance risk, including the risk of 10 |
---|
926 | 925 | | regulatory sanctions, fines, penalties, or losses resulting from failure to 11 |
---|
927 | 926 | | comply with laws, rules, regulations, or other supervisory requirements 12 |
---|
928 | 927 | | applicable to a covered institution servicer; 13 |
---|
929 | 928 | | (vi) Legal risk, including the potential that 14 |
---|
930 | 929 | | actions against the covered institution servicer that result in unenforceable 15 |
---|
931 | 930 | | contracts, lawsuits, legal sanctions, or adverse judgments can disrupt or 16 |
---|
932 | 931 | | otherwise negatively affect the operations or condition of the covered 17 |
---|
933 | 932 | | institution servicer; and 18 |
---|
934 | 933 | | (vii) Reputation risk, including the risk to 19 |
---|
935 | 934 | | earnings and capital arising from negative publicity regarding the covered 20 |
---|
936 | 935 | | institution servicer’s business practices. 21 |
---|
937 | 936 | | (g)(1) A covered institution servicer shall conduct a risk management 22 |
---|
938 | 937 | | assessment on an annual basis concluding with a formal report to the board of 23 |
---|
939 | 938 | | directors and be available to the commissioner upon request. 24 |
---|
940 | 939 | | (2) Evidence of risk management activities throughout the year 25 |
---|
941 | 940 | | shall be maintained and made part of the report, including findings of issues 26 |
---|
942 | 941 | | and the response to address the findings made in the report. 27 |
---|
943 | 942 | | 28 |
---|
944 | 943 | | 23-39-521. Standards for safeguarding customer information. 29 |
---|
945 | 944 | | (a) A financial institution shall develop, implement, and maintain a 30 |
---|
946 | 945 | | comprehensive information security program. 31 |
---|
947 | 946 | | (b) The information security program under subsection (a) of this 32 |
---|
948 | 947 | | section shall: 33 |
---|
949 | 948 | | (1) Be written in one (1) or more readily accessible parts; and 34 |
---|
950 | 949 | | (2) Contain administrative, technical, and physical safeguards 35 |
---|
951 | 950 | | that are appropriate to the financial institution’s size and complexity, the 36 HB1466 |
---|
952 | 951 | | |
---|
953 | 952 | | 26 02/12/2025 2:18:59 PM ANS120 |
---|
954 | 953 | | nature and scope of the financial institution’s activities, and the 1 |
---|
955 | 954 | | sensitivity of any customer information at issue. 2 |
---|
956 | 955 | | (c) The information security program shall include the information 3 |
---|
957 | 956 | | required under § 23-39-522. 4 |
---|
958 | 957 | | 5 |
---|
959 | 958 | | 23-39-522. Information security program required elements. 6 |
---|
960 | 959 | | (a) In order for a financial institution to develop, implement, and 7 |
---|
961 | 960 | | maintain an information security program, the financial institution shall 8 |
---|
962 | 961 | | comply with this section. 9 |
---|
963 | 962 | | (b)(1) A financial institution shall designate a qualified individual 10 |
---|
964 | 963 | | responsible for overseeing and implementing the financial institution’s 11 |
---|
965 | 964 | | information security program and enforcing an information security program. 12 |
---|
966 | 965 | | (2)(A) The qualified individual may be employed by the financial 13 |
---|
967 | 966 | | institution, an affiliate, or a service provider. 14 |
---|
968 | 967 | | (B) If a financial institution designates an individual 15 |
---|
969 | 968 | | employed by an affiliate or a service provider, the financial institution 16 |
---|
970 | 969 | | shall: 17 |
---|
971 | 970 | | (i) Retain responsibility for compliance with this 18 |
---|
972 | 971 | | section; 19 |
---|
973 | 972 | | (ii) Designate a senior member of the financial 20 |
---|
974 | 973 | | institution’s personnel to be responsible for direction and oversight of the 21 |
---|
975 | 974 | | qualified individual; and 22 |
---|
976 | 975 | | (iii) Require the service provider or affiliate to 23 |
---|
977 | 976 | | maintain an information security program that protects the financial 24 |
---|
978 | 977 | | institution in accordance with the requirements of this section. 25 |
---|
979 | 978 | | (c)(1) A financial institution shall base the financial institution’s 26 |
---|
980 | 979 | | information security program on a risk assessment that: 27 |
---|
981 | 980 | | (A) Identifies reasonably foreseeable internal and 28 |
---|
982 | 981 | | external risks to the security, confidentiality, and integrity of customer 29 |
---|
983 | 982 | | information that could result in the unauthorized disclosure, misuse, 30 |
---|
984 | 983 | | alteration, destruction, or other compromise of the information; and 31 |
---|
985 | 984 | | (B) Assesses the sufficiency of any safeguards in place to 32 |
---|
986 | 985 | | control these risks. 33 |
---|
987 | 986 | | (2) The risk assessment shall be written and include: 34 |
---|
988 | 987 | | (A) Criteria for the evaluation and categorization of 35 |
---|
989 | 988 | | identified security risks or threats the financial institution faces; 36 HB1466 |
---|
990 | 989 | | |
---|
991 | 990 | | 27 02/12/2025 2:18:59 PM ANS120 |
---|
992 | 991 | | (B) Criteria for the assessment of the confidentiality, 1 |
---|
993 | 992 | | integrity, and availability of the financial institution’s information 2 |
---|
994 | 993 | | systems and customer information, including the adequacy of the existing 3 |
---|
995 | 994 | | controls in the context of the identified risks or threats the financial 4 |
---|
996 | 995 | | institution faces; and 5 |
---|
997 | 996 | | (C) Requirements describing how identified risks will be 6 |
---|
998 | 997 | | mitigated or accepted based on the risk assessment and how the information 7 |
---|
999 | 998 | | security program will address the risks. 8 |
---|
1000 | 999 | | (3) A financial institution shall periodically perform 9 |
---|
1001 | 1000 | | additional risk assessments that: 10 |
---|
1002 | 1001 | | (A) Reexamine the reasonably foreseeable internal and 11 |
---|
1003 | 1002 | | external risks to the security, confidentiality, and integrity of customer 12 |
---|
1004 | 1003 | | information that could result in the unauthorized disclosure, misuse, 13 |
---|
1005 | 1004 | | alteration, destruction, or other compromise of the customer information; and 14 |
---|
1006 | 1005 | | (B) Reassess the sufficiency of any safeguards in place to 15 |
---|
1007 | 1006 | | control these risks. 16 |
---|
1008 | 1007 | | (d) A financial institution shall design and implement safeguards to 17 |
---|
1009 | 1008 | | control the risks the financial institution identifies through the risk 18 |
---|
1010 | 1009 | | assessment as required under subsection (c) of this section, including 19 |
---|
1011 | 1010 | | without limitation: 20 |
---|
1012 | 1011 | | (1) Implementing and periodically reviewing access controls, 21 |
---|
1013 | 1012 | | including technical and, as appropriate, physical controls, to: 22 |
---|
1014 | 1013 | | (A) Authenticate and permit access only to authorized 23 |
---|
1015 | 1014 | | users to protect against the unauthorized acquisition of customer 24 |
---|
1016 | 1015 | | information; and 25 |
---|
1017 | 1016 | | (B) Limit authorized users’ access only to customer 26 |
---|
1018 | 1017 | | information that the authorized user needs to perform the authorized user’s 27 |
---|
1019 | 1018 | | duties and functions, or in the case of customers, to access the customer’s 28 |
---|
1020 | 1019 | | own customer information; 29 |
---|
1021 | 1020 | | (2) Identifying and managing the data, personnel, devices, 30 |
---|
1022 | 1021 | | systems, and facilities that enable the financial institution to achieve 31 |
---|
1023 | 1022 | | business purposes according to the financial institution's relative 32 |
---|
1024 | 1023 | | importance to business objectives and the financial institution’s risk 33 |
---|
1025 | 1024 | | strategy; 34 |
---|
1026 | 1025 | | (3)(A) Protecting by encryption all customer information held or 35 |
---|
1027 | 1026 | | transmitted by the financial institution both in transit over external 36 HB1466 |
---|
1028 | 1027 | | |
---|
1029 | 1028 | | 28 02/12/2025 2:18:59 PM ANS120 |
---|
1030 | 1029 | | networks and at rest. 1 |
---|
1031 | 1030 | | (B) To the extent the financial institution determines 2 |
---|
1032 | 1031 | | that encryption of customer information, either in transit over external 3 |
---|
1033 | 1032 | | networks or at rest, is infeasible, the financial institution may instead 4 |
---|
1034 | 1033 | | secure the customer information using effective alternative compensating 5 |
---|
1035 | 1034 | | controls reviewed and approved by the financial institution’s qualified 6 |
---|
1036 | 1035 | | individual; 7 |
---|
1037 | 1036 | | (4) Adopting secure development practices for in -house developed 8 |
---|
1038 | 1037 | | applications utilized by the financial institution for transmitting, 9 |
---|
1039 | 1038 | | accessing, or storing customer information and procedures for evaluating, 10 |
---|
1040 | 1039 | | assessing, or testing the security of externally developed applications the 11 |
---|
1041 | 1040 | | financial institution utilizes to transmit, access, or store customer 12 |
---|
1042 | 1041 | | information; 13 |
---|
1043 | 1042 | | (5) Implementing multifactor authentication for an individual 14 |
---|
1044 | 1043 | | accessing an information system, unless the financial institution’s qualified 15 |
---|
1045 | 1044 | | individual has approved in writing the use of reasonably equivalent or more 16 |
---|
1046 | 1045 | | secure access controls; 17 |
---|
1047 | 1046 | | (6) Developing, implementing, and maintaining procedures for the 18 |
---|
1048 | 1047 | | secure disposal of customer information in any format no later than two (2) 19 |
---|
1049 | 1048 | | years after the last date the customer information is used in connection with 20 |
---|
1050 | 1049 | | the provision of a financial product or service to the customer, unless the 21 |
---|
1051 | 1050 | | customer information is: 22 |
---|
1052 | 1051 | | (A) Necessary for business operations or for other 23 |
---|
1053 | 1052 | | legitimate business purposes; 24 |
---|
1054 | 1053 | | (B) Otherwise required to be retained by state law or 25 |
---|
1055 | 1054 | | rule, or federal law or regulation; or 26 |
---|
1056 | 1055 | | (C) Where targeted disposal is not reasonably feasible due 27 |
---|
1057 | 1056 | | to the manner in which the information is maintained; 28 |
---|
1058 | 1057 | | (7) Periodically reviewing the financial institution’s data 29 |
---|
1059 | 1058 | | retention policy to minimize the unnecessary retention of data; 30 |
---|
1060 | 1059 | | (8) Adopting procedures for change management; and 31 |
---|
1061 | 1060 | | (9) Implementing policies, procedures, and controls designed to 32 |
---|
1062 | 1061 | | monitor and log the activity of authorized users and detect unauthorized 33 |
---|
1063 | 1062 | | access or use of, or tampering with, customer information by these users. 34 |
---|
1064 | 1063 | | (e)(1) A financial institution shall regularly test or otherwise 35 |
---|
1065 | 1064 | | monitor the effectiveness of the safeguards' key controls, systems, and 36 HB1466 |
---|
1066 | 1065 | | |
---|
1067 | 1066 | | 29 02/12/2025 2:18:59 PM ANS120 |
---|
1068 | 1067 | | procedures of the safeguards' required under this section, including those to 1 |
---|
1069 | 1068 | | detect actual and attempted attacks on, or intrusions into, information 2 |
---|
1070 | 1069 | | systems. 3 |
---|
1071 | 1070 | | (2)(A) For information systems, monitoring and testing shall 4 |
---|
1072 | 1071 | | include continuous monitoring or periodic penetration testing and 5 |
---|
1073 | 1072 | | vulnerability assessments. 6 |
---|
1074 | 1073 | | (B) Absent effective continuous monitoring or other 7 |
---|
1075 | 1074 | | systems to detect, on an ongoing basis, changes in information systems that 8 |
---|
1076 | 1075 | | may create vulnerabilities, the financial institution shall conduct: 9 |
---|
1077 | 1076 | | (i) Annual penetration testing of a financial 10 |
---|
1078 | 1077 | | institution’s information systems determined each given year based on 11 |
---|
1079 | 1078 | | relevant identified risks according to the risk assessment; and 12 |
---|
1080 | 1079 | | (ii) Vulnerability assessments, including a systemic 13 |
---|
1081 | 1080 | | scan or review of an information system reasonably designed to identify 14 |
---|
1082 | 1081 | | publicly known security vulnerabilities in the financial institution’s 15 |
---|
1083 | 1082 | | information systems based on the risk assessment, at least every six (6) 16 |
---|
1084 | 1083 | | months, and whenever there are: 17 |
---|
1085 | 1084 | | (a) Material changes to the financial 18 |
---|
1086 | 1085 | | institution’s operations or business arrangements; and 19 |
---|
1087 | 1086 | | (b) Circumstances the financial institution 20 |
---|
1088 | 1087 | | knows or has reason to know may have a material impact on the financial 21 |
---|
1089 | 1088 | | institution’s information security program. 22 |
---|
1090 | 1089 | | (f) A financial institution shall implement policies and procedures to 23 |
---|
1091 | 1090 | | ensure that personnel are able to enact the financial institution’s 24 |
---|
1092 | 1091 | | information security program by: 25 |
---|
1093 | 1092 | | (1) Providing the financial institution’s personnel with 26 |
---|
1094 | 1093 | | security awareness training that is updated as necessary to reflect risks 27 |
---|
1095 | 1094 | | identified by the risk assessment; 28 |
---|
1096 | 1095 | | (2) Utilizing qualified information security personnel employed 29 |
---|
1097 | 1096 | | by the financial institution or an affiliate or a service provider sufficient 30 |
---|
1098 | 1097 | | to manage the financial institution’s information security risks and to 31 |
---|
1099 | 1098 | | perform or oversee the information security program; 32 |
---|
1100 | 1099 | | (3) Providing information security personnel with security 33 |
---|
1101 | 1100 | | updates and training sufficient to address relevant security risks; and 34 |
---|
1102 | 1101 | | (4) Verifying that key information security personnel take steps 35 |
---|
1103 | 1102 | | to maintain current knowledge of changing information security threats and 36 HB1466 |
---|
1104 | 1103 | | |
---|
1105 | 1104 | | 30 02/12/2025 2:18:59 PM ANS120 |
---|
1106 | 1105 | | countermeasures. 1 |
---|
1107 | 1106 | | (g) A financial institution shall oversee service providers by: 2 |
---|
1108 | 1107 | | (1) Taking reasonable steps to select and retain service 3 |
---|
1109 | 1108 | | providers that are capable of maintaining appropriate safeguards for the 4 |
---|
1110 | 1109 | | customer information at issue; 5 |
---|
1111 | 1110 | | (2) Requiring the financial institution’s service providers by 6 |
---|
1112 | 1111 | | contract to implement and maintain the safeguards referenced under 7 |
---|
1113 | 1112 | | subdivision (g)(1) of this section; and 8 |
---|
1114 | 1113 | | (3) Periodically assessing the financial institution’s service 9 |
---|
1115 | 1114 | | providers based on the risk they present and the continued adequacy of their 10 |
---|
1116 | 1115 | | safeguards. 11 |
---|
1117 | 1116 | | (h) A financial institution shall evaluate and adjust the financial 12 |
---|
1118 | 1117 | | institution’s information security program to reflect: 13 |
---|
1119 | 1118 | | (1) The results of the testing and monitoring required by 14 |
---|
1120 | 1119 | | subsection (e) of this section; 15 |
---|
1121 | 1120 | | (2) Any material change to the financial institution’s 16 |
---|
1122 | 1121 | | operations or business arrangements or other circumstances; 17 |
---|
1123 | 1122 | | (3) The results of risk assessments performed under subdivision 18 |
---|
1124 | 1123 | | (c)(3) of this section; and 19 |
---|
1125 | 1124 | | (4) Any other circumstances that the financial institution knows 20 |
---|
1126 | 1125 | | or has reason to know may have a material impact on the financial 21 |
---|
1127 | 1126 | | institution's information security program. 22 |
---|
1128 | 1127 | | (i)(1) A financial institution shall establish a written incident 23 |
---|
1129 | 1128 | | response plan designed to promptly respond to, and recover from, any security 24 |
---|
1130 | 1129 | | event materially affecting the confidentiality, integrity, or availability of 25 |
---|
1131 | 1130 | | customer information in the financial institution’s control. 26 |
---|
1132 | 1131 | | (2) The incident response plan under subdivision (i)(1) of this 27 |
---|
1133 | 1132 | | section shall address: 28 |
---|
1134 | 1133 | | (A) The goals of the incident response plan; 29 |
---|
1135 | 1134 | | (B) The internal processes for responding to a security 30 |
---|
1136 | 1135 | | event; 31 |
---|
1137 | 1136 | | (C) The definition of clear roles, responsibilities, and 32 |
---|
1138 | 1137 | | levels of decision-making authority; 33 |
---|
1139 | 1138 | | (D) External and internal communications and information 34 |
---|
1140 | 1139 | | sharing; 35 |
---|
1141 | 1140 | | (E) Identification of requirements for the remediation of 36 HB1466 |
---|
1142 | 1141 | | |
---|
1143 | 1142 | | 31 02/12/2025 2:18:59 PM ANS120 |
---|
1144 | 1143 | | any identified weaknesses in information systems and associated controls; 1 |
---|
1145 | 1144 | | (F) Documentation and reporting regarding security events 2 |
---|
1146 | 1145 | | and related incident response activities; and 3 |
---|
1147 | 1146 | | (G) The evaluation and revision as necessary of the 4 |
---|
1148 | 1147 | | incident response plan following a security event. 5 |
---|
1149 | 1148 | | (j)(1) The financial institution’s qualified individual shall report 6 |
---|
1150 | 1149 | | in writing at least annually, to the financial institution’s board of 7 |
---|
1151 | 1150 | | directors or equivalent governing body. 8 |
---|
1152 | 1151 | | (2) If a board of directors or equivalent governing body does 9 |
---|
1153 | 1152 | | not exist, the report required under subdivision (j)(1) of this section shall 10 |
---|
1154 | 1153 | | be timely presented to a senior officer responsible for the financial 11 |
---|
1155 | 1154 | | institution’s information security program. 12 |
---|
1156 | 1155 | | (3) The report required under subdivision (j)(1) of this section 13 |
---|
1157 | 1156 | | shall include: 14 |
---|
1158 | 1157 | | (A) The overall status of the information security program 15 |
---|
1159 | 1158 | | and the financial institution’s compliance with this section and associated 16 |
---|
1160 | 1159 | | rules; and 17 |
---|
1161 | 1160 | | (B) Material matters related to the information security 18 |
---|
1162 | 1161 | | program, addressing issues such as risk assessment, risk management and 19 |
---|
1163 | 1162 | | control decisions, service provider arrangements, results of testing, 20 |
---|
1164 | 1163 | | security events or violations and management’s responses to security events 21 |
---|
1165 | 1164 | | or violations, and recommendations for changes in the information security 22 |
---|
1166 | 1165 | | program. 23 |
---|
1167 | 1166 | | (k) A financial institution shall provide notice to the Securities 24 |
---|
1168 | 1167 | | Commissioner about notification events according to subdivisions (l)(1) and 25 |
---|
1169 | 1168 | | (2) of this section. 26 |
---|
1170 | 1169 | | (l)(1) Upon discovery of a notification event as described in 27 |
---|
1171 | 1170 | | subdivision (l)(3) of this section, if the notification event involves the 28 |
---|
1172 | 1171 | | information of any consumers in this state, the financial institution shall 29 |
---|
1173 | 1172 | | notify the commissioner as soon as possible and no later forty -five (45) days 30 |
---|
1174 | 1173 | | after discovery of the notification event. 31 |
---|
1175 | 1174 | | (2) The notice required under subdivision (l)(1) of this section 32 |
---|
1176 | 1175 | | shall: 33 |
---|
1177 | 1176 | | (A) Be made in a format specified by the commissioner; and 34 |
---|
1178 | 1177 | | (B) Include the following information: 35 |
---|
1179 | 1178 | | (i) The name and contact information of the 36 HB1466 |
---|
1180 | 1179 | | |
---|
1181 | 1180 | | 32 02/12/2025 2:18:59 PM ANS120 |
---|
1182 | 1181 | | reporting financial institution; 1 |
---|
1183 | 1182 | | (ii)(a) A description of the types of information 2 |
---|
1184 | 1183 | | that were involved in the notification event. 3 |
---|
1185 | 1184 | | (b) If the information is possible to 4 |
---|
1186 | 1185 | | determine under subdivision (l)(2)(B)(ii)(a) of this section, the notice 5 |
---|
1187 | 1186 | | required under subdivision (l)(1) of this section shall contain the date or 6 |
---|
1188 | 1187 | | date range of the notification event; 7 |
---|
1189 | 1188 | | (iii) The number of consumers affected or 8 |
---|
1190 | 1189 | | potentially affected by the notification event; 9 |
---|
1191 | 1190 | | (iv) A general description of the notification 10 |
---|
1192 | 1191 | | event; and 11 |
---|
1193 | 1192 | | (v)(a) Whether a law enforcement official has 12 |
---|
1194 | 1193 | | provided the financial institution with a written determination that 13 |
---|
1195 | 1194 | | notifying the public of the notification event would impede a criminal 14 |
---|
1196 | 1195 | | investigation or cause damage to national security, and a means for the 15 |
---|
1197 | 1196 | | commissioner to contact the law enforcement official. 16 |
---|
1198 | 1197 | | (b) A law enforcement official under 17 |
---|
1199 | 1198 | | subdivision (l)(2)(B)(v)(a) of this section may request an initial delay of 18 |
---|
1200 | 1199 | | up to thirty (30) days following the date when notice was provided to the 19 |
---|
1201 | 1200 | | commissioner. 20 |
---|
1202 | 1201 | | (c) The delay under subdivision 21 |
---|
1203 | 1202 | | (l)(2)(B)(v)(b) of this section may be extended for an additional period of 22 |
---|
1204 | 1203 | | up to sixty (60) days if the law enforcement official seeks an extension in 23 |
---|
1205 | 1204 | | writing. 24 |
---|
1206 | 1205 | | (d) An additional delay beyond the delay under 25 |
---|
1207 | 1206 | | subdivision (l)(2)(B)(v)(b) of this section may be permitted only if the 26 |
---|
1208 | 1207 | | State Securities Department determines that public disclosure of a 27 |
---|
1209 | 1208 | | notification event continues to impede a criminal investigation or cause 28 |
---|
1210 | 1209 | | damage to national security. 29 |
---|
1211 | 1210 | | (3)(A) A notification event under this section shall be treated 30 |
---|
1212 | 1211 | | as discovered as of the first day on which the notification event is known to 31 |
---|
1213 | 1212 | | the financial institution. 32 |
---|
1214 | 1213 | | (B) The financial institution under subdivision (l)(3)(A) 33 |
---|
1215 | 1214 | | of this section shall be deemed to have knowledge of a notification event if 34 |
---|
1216 | 1215 | | the notification event is known to a person, other than the person committing 35 |
---|
1217 | 1216 | | the notification event, who is the financial institution’s employee, officer, 36 HB1466 |
---|
1218 | 1217 | | |
---|
1219 | 1218 | | 33 02/12/2025 2:18:59 PM ANS120 |
---|
1220 | 1219 | | or other agent. 1 |
---|
1221 | 1220 | | (m) A financial institution shall establish a written plan addressing 2 |
---|
1222 | 1221 | | business continuity and disaster recovery. 3 |
---|
1223 | 1222 | | 4 |
---|
1224 | 1223 | | 23-39-523. Exceptions. 5 |
---|
1225 | 1224 | | This subchapter does not apply to a financial institution that 6 |
---|
1226 | 1225 | | maintains customer information concerning fewer than five thousand (5,000) 7 |
---|
1227 | 1226 | | consumers. 8 |
---|
1228 | 1227 | | 9 |
---|
1229 | 1228 | | 10 |
---|