While the Consumer Financial Protection Bureau plans to step up enforcement action in the lending sector, the federal watchdog has yet to implement measures laid out in its own information security audits dating back to 2014.
At a consumer rights conference Oct. 26, CFPB Enforcement Director Eric Halperin unveiled a three-pronged approach aimed at protecting consumers amid rising debt burdens and high interest rates that are impeding access to capital. Halperin noted that the agency intends to hire 75 additional enforcement staffers to achieve its agenda.
Specifically, the CFPB plans to probe how companies use consumer data and whether they appropriately investigate disputes about data accuracy. Further, the agency expects to bolster its scrutiny of predatory lending and monitor the risk to consumers created by financial institutions’ reliance on “opaque algorithms” and other types of automation that replace human judgment in dispute resolution, Halperin said.
In a nutshell, Halperin noted that “the consumer economy continues to get more complex and less transparent every day.”
Yet, the CFPB appears to be lagging in efforts to shore up its own information security measures, according to the Office of Inspector General’s 2023 audit of the CFPB’s information security, or infosec, program. Despite notching a “level 4” — of a possible 5 — rating for its infosec operations, the CFPB was deemed “level 3” or below in three of five information security functions. In fact, the agency’s rating since 2021 has worsened in two categories graded by the audit: data-loss prevention and contingency planning.
Interestingly, the Sept. 29 report makes no mention of the data breach that occurred at the watchdog agency this year. The incident allegedly involved an employee who forwarded spreadsheets with names and transaction-related numbers for the accounts of 256,000 consumers, as well as confidential supervisory information for more than 40 financial institutions, to a personal email account. The OIG performance audit started in March — just one month after the CFPB data breach.

Even so, this year’s audit includes only one new recommendation for infosec improvement, namely, to maintain a comprehensive schedule for documenting, testing and updating contingency plans. The CFPB’s contingency planning function was rated a “level 2,” the score given for a system that is documented but not consistently implemented.
Contingency planning, also referred to in the audit as the “recover” function, relates to the restoration of systems that are compromised or breached. The audit noted that the CFPB failed to test in accordance with annual testing requirements.
“Specifically, the CFPB had not tested one Executive Order (EO) critical system since FY 2021, and it had scheduled testing for two other systems but had not yet completed the testing,” according to the report. A footnote states that “CFPB officials indicated that administrative changes prevented the CFPB from performing its annual testing for this contingency plan.”
A unique element of the report is that it includes the CFPB’s responses to the OIG’s findings and guidance. On the topic of contingency planning, the CFPB’s chief information officer Chris Chilbert notes that the agency expects to develop the requisite policies and supporting procedures, along with the contingency plan testing schedule, by the fourth quarter of fiscal 2025.
Aside from the new recommendation, the report mentions that a pair of contingency planning instructions from previous audits remain outstanding. In fact, those issues are among several that have been languishing. While an appendix in the report describes four open recommendations that the CFPB completed this year, it details nine unresolved issues — five from last year, two from 2018, one from 2017 and one from 2014.
The oldest open recommendation in the audit calls for the CFPB to strengthen its vulnerability management practices by implementing an automated solution and process to periodically assess and manage database and application-level security configurations. So far, the CFPB has completed the latter task, implementing an application-level scanner. As for the database security component, the CFPB bought the scanning tool but won’t likely implement it until early 2024.
Meanwhile, one of the outstanding recommendations from the 2018 audit may not reach completion until the end of 2024. The task calls for the CFPB to determine whether established processes and procedures for management of user access are effective.
Over the years, the CFPB has called out companies for data breaches. In July 2019, the agency reached a deal with Equifax to pay $700 million for violating the Consumer Financial Protection Act because of a data breach. In August 2022, CFPB Director Rohit Chopra said that “financial firms that cut corners on data security put their customers at risk of identity theft, fraud and abuse.”
Further, the CFPB typically assigns deadlines to consent orders with financial services companies. For instance, when now-defunct auto lender Security National Automotive Acceptance Co. failed to comply with a 2015 consent order related to illegal debt collection tactics, the CFPB tacked on another $1.25 million penalty.
Perhaps the CFPB should hire staffers to bolster its infosec practices before it steps up enforcement actions against financial services companies.
Editor’s note: This article first appeared on Auto Finance News, a sister publication to Bank Automation News.






