Newsroom

July 29, 2015

IG finds deficiencies in CFPB consumer complaint database

The Federal Reserve and CFPB Office of Inspector General has identified seven control deficiencies related to CFPB's consumer complaint database, underscoring privacy and risk concerns NAFCU raised earlier this year.

While the OIG said that CFPB has taken steps to secure its complaint database in accordance with the Federal Information Security Modernization Act and the bureau's own information security policies and procedures, the OIG review found deficiencies related to configuration management, access control, and audit logging and review.

"Specifically, we identified improvements that are needed in the timely installation of database-level patches, the enforcement of password expiration and user access requirements, and the logging and review of security events," the OIG's report said.

In a comment letter to the bureau in May, NAFCU Director of Regulatory Affairs Alicia Nealon said the CFPB's existing complaint database "poses serious concerns that personal information may be inadvertently released jeopardizing an individual's secure financial information. Also, the CFPB employs no mechanism to validate a consumer's comments, which creates harmful reputational risks to credit unions and other financial institutions."

The OIG said that CFPB's chief information officer had agreed with its recommendations and outlined actions that have or will be taken to address its concerns.