consumer loan act and mortgage broker practices act …

237
Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use 1 / 237 Q1 1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop, tablet, etc.) Respondent skipped this question Q2 1a. How are patches or security updates pushed out to remote devices? Respondent skipped this question Q3 1b. How are company resources returned upon employee termination? (What happens to company issued equipment?) Respondent skipped this question Q4 2. Does your company keep physical records at any branch? Yes Q5 3. Does the company use a cloud-based repository? If yes, answer 3a. If no, skip to 4. Respondent skipped this question Q6 3a. If yes, do the MLOs conduct business directly into the cloud? Respondent skipped this question Q7 4. Does the company have written policies and procedures governing the use of electronic data? Yes #1 #1 COMPLETE COMPLETE Collector: Collector: Web Link 1 Web Link 1 (Web Link) (Web Link) Started: Started: Friday, July 05, 2019 8:32:05 AM Friday, July 05, 2019 8:32:05 AM Last Modified: Last Modified: Friday, July 05, 2019 8:34:05 AM Friday, July 05, 2019 8:34:05 AM Time Spent: Time Spent: 00:02:00 00:02:00 IP Address: IP Address: Page 1

Upload: others

Post on 07-Nov-2021

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

1 / 237

Q1

1. Describe what type of devices the Company providesemployees to use for remote work. (laptop, phone,desktop, tablet, etc.)

Respondent skipped this question

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Respondent skipped this question

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#1#1COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 8:32:05 AMFriday, July 05, 2019 8:32:05 AMLast Modified:Last Modified: Friday, July 05, 2019 8:34:05 AMFriday, July 05, 2019 8:34:05 AMTime Spent:Time Spent: 00:02:0000:02:00IP Address:IP Address:

Page 1

Page 2: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

2 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a riskassessment of its information security systems?

Respondent skipped this question

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Respondent skipped this question

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Page 3: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

3 / 237

Q17

11a. If yes, describe what types of records MLOs keep

all

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 4: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

4 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

CELLPHONE AND DESKTOP

Q2

1a. How are patches or security updates pushed out to remote devices?

AUTOMATIC. ALL DEVICE MUST LOGIN TO A PORTAL TYPE SOFTWARE

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

RETURNED DURING EXIT INTERVIEW

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#2#2COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 8:34:40 AMFriday, July 05, 2019 8:34:40 AMLast Modified:Last Modified: Friday, July 05, 2019 8:43:46 AMFriday, July 05, 2019 8:43:46 AMTime Spent:Time Spent: 00:09:0600:09:06IP Address:IP Address:

Page 1

Page 5: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

5 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

PRESIDENT. UNDERSTANDING WE ARE A SMALL BROKER THAT ONLY ORIGINATES MFG HOME PERSONAL PROPERTY LOANS

Q10

6. How often does the company conduct a risk assessment of its information security systems?

ONGOING

Q11

7. How many MLOs do you employ?

1 FOR WA

Q12

8. How many of your MLOs conduct business from a branch location?

NONE

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

NONE

Q14

9. How many of your MLOs conduct business otherwise remotely?

NONE

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 6: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

6 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 7: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

7 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops.

Q2

1a. How are patches or security updates pushed out to remote devices?

Emailed links.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Physically in office.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

#3#3COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 8:32:37 AMFriday, July 05, 2019 8:32:37 AMLast Modified:Last Modified: Friday, July 05, 2019 8:43:58 AMFriday, July 05, 2019 8:43:58 AMTime Spent:Time Spent: 00:11:2000:11:20IP Address:IP Address:

Page 1

Page 8: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

8 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CEO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

We do not

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 9: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

9 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Borrowers elect to communicate this way. We do advise it or offer it. Borrowers choose to send pictures of documents via text and ask questions via text. Instead of our requested and preferred method that is emailed PDF's or uploading documents directly into our system through our secured server. This way requires they create a password and log in and is very safe. unfortunately the average borrower dose not cares about security.

Q20

12b. Does your company use an API that captures those text messages?

No. Do not know what that is.

Page 10: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

10 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Company does not provide any of these devices

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

n/a

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Respondent skipped this question

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

#4#4COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 8:41:12 AMFriday, July 05, 2019 8:41:12 AMLast Modified:Last Modified: Friday, July 05, 2019 8:44:42 AMFriday, July 05, 2019 8:44:42 AMTime Spent:Time Spent: 00:03:3000:03:30IP Address:IP Address:

Page 1

Page 11: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

11 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Broker

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Anually

Q11

7. How many MLOs do you employ?

3

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

2

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 12: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

12 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

communication on loan information

Q20

12b. Does your company use an API that captures those text messages?

no

Page 13: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

13 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop computer.

Q2

1a. How are patches or security updates pushed out to remote devices?

Through a VPN connection from our private server.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Employees must return any and all equipment to the home office. Equipment software is wiped by our IT and equipment is built out for new employees.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

#5#5COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 8:39:21 AMFriday, July 05, 2019 8:39:21 AMLast Modified:Last Modified: Friday, July 05, 2019 8:46:24 AMFriday, July 05, 2019 8:46:24 AMTime Spent:Time Spent: 00:07:0200:07:02IP Address:IP Address:

Page 1

Page 14: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

14 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The President/CEO.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

This is performed daily by our IT company.

Q11

7. How many MLOs do you employ?

8

Q12

8. How many of your MLOs conduct business from a branch location?

Only our CA MLO.

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

4

Page 15: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

15 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 16: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

16 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops remotely access secure servers in the licensed office via a secure VPN connection. All origination is conducted within the licensed location. We do not collect any physical documents, only electronic documents collected via the secure servers or encrypted email.

Q2

1a. How are patches or security updates pushed out to remote devices?

Updates are automatically installed before each login.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The company does not issue any physical equipment. Each LO is responsible to provide their own equipment. The company does provide secure servers and encrypted email service. When an employee leaves the company retains ownership of any data collected

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#6#6COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:07:21 AMFriday, July 05, 2019 9:07:21 AMLast Modified:Last Modified: Friday, July 05, 2019 9:18:45 AMFriday, July 05, 2019 9:18:45 AMTime Spent:Time Spent: 00:11:2300:11:23IP Address:IP Address:

Page 1

Page 17: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

17 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The President

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Security analysis conducted by a third party

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

2

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 18: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

18 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Simple communications that do not involve any of the borrowers PII

Q20

12b. Does your company use an API that captures those text messages?

No

Page 19: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

19 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop access to virtual network.

Q2

1a. How are patches or security updates pushed out to remote devices?

For the system, which operates on VM ware, all patches are internal/central.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Access is terminated. Desktop box is returned.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#7#7COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:30:27 AMFriday, July 05, 2019 9:30:27 AMLast Modified:Last Modified: Friday, July 05, 2019 9:36:18 AMFriday, July 05, 2019 9:36:18 AMTime Spent:Time Spent: 00:05:5000:05:50IP Address:IP Address:

Page 1

Page 20: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

20 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CISO. Counsel (internal) serves as DIrector of Security for internet based activity.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Bi-annually

Q11

7. How many MLOs do you employ?

-0-

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Respondent skipped this question

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 21: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

21 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

We are a servicer only. No origination

Q20

12b. Does your company use an API that captures those text messages?

The company uses API resources but not for this non-performed activity.

Page 22: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

22 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Automatic software updates or manually as needed by IT staff.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All company property must be returned upon termination.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#8#8COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:20:32 AMFriday, July 05, 2019 9:20:32 AMLast Modified:Last Modified: Friday, July 05, 2019 9:39:45 AMFriday, July 05, 2019 9:39:45 AMTime Spent:Time Spent: 00:19:1200:19:12IP Address:IP Address:

Page 1

Page 23: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

23 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Compliance Manager with IT Manager's input

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

30

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 24: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

24 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Basic communication with borrowers. No sending or receiving of personal information.

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 25: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

25 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop and Laptops

Q2

1a. How are patches or security updates pushed out to remote devices?

Automatic Updates

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All equipment are to be returned to the company upon employee termination. The computers are backed up, then data removed and the clean computer is reassigned to new hires.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#9#9COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:42:44 AMFriday, July 05, 2019 9:42:44 AMLast Modified:Last Modified: Friday, July 05, 2019 9:48:36 AMFriday, July 05, 2019 9:48:36 AMTime Spent:Time Spent: 00:05:5200:05:52IP Address:IP Address:

Page 1

Page 26: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

26 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

COO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

12

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

4

Page 27: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

27 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Basic communications and status updates. Prohibited from conducting Text Communications with any PII.

Q20

12b. Does your company use an API that captures those text messages?

Yes, we used Ringcentral

Page 28: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

28 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

The company provides desktops.

Q2

1a. How are patches or security updates pushed out to remote devices?

All machines are set to automatically update all softwares. The users are not allowed access to change this feature.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The company records the equipment when issued to an employee. Upon termination the equipment is to be returned (shipping paid by company). Failure to return the equipment, the terminated employee is charged for the replacement of all equipment issued and it is deducted from their final check.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#10#10COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:43:10 AMFriday, July 05, 2019 9:43:10 AMLast Modified:Last Modified: Friday, July 05, 2019 9:51:41 AMFriday, July 05, 2019 9:51:41 AMTime Spent:Time Spent: 00:08:3100:08:31IP Address:IP Address:

Page 1

Page 29: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

29 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The company Compliance Officer fulfills this role.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

9

Q12

8. How many of your MLOs conduct business from a branch location?

9

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

2

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Page 30: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

30 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

The MLO's are allowed to use texting for simple communications, confirming appointments, sending reminders. All PII and negotiations are to occur either in person, via telephone or via email.

Q20

12b. Does your company use an API that captures those text messages?

No.

Page 31: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

31 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop computer, phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Updates are sent directly to the remote device via secure e-mail.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Equipment is picked up immediately when a remote employee is terminated.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#11#11COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 9:47:26 AMFriday, July 05, 2019 9:47:26 AMLast Modified:Last Modified: Friday, July 05, 2019 10:12:23 AMFriday, July 05, 2019 10:12:23 AMTime Spent:Time Spent: 00:24:5600:24:56IP Address:IP Address:

Page 1

Page 32: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

32 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

, State Farm Agent

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Only once a year.

Q11

7. How many MLOs do you employ?

None

Q12

8. How many of your MLOs conduct business from a branch location?

N/A

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

N/A

Q14

9. How many of your MLOs conduct business otherwise remotely?

N/A

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Respondent skipped this question

Page 33: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

33 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Respondent skipped this question

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Respondent skipped this question

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

N/A

Q20

12b. Does your company use an API that captures those text messages?

No MLO in office

Page 34: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

34 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Tablet.

Q2

1a. How are patches or security updates pushed out to remote devices?

Security patches automatically updated.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Tablets are retrieved from employee.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#12#12COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:09:11 AMFriday, July 05, 2019 10:09:11 AMLast Modified:Last Modified: Friday, July 05, 2019 10:14:07 AMFriday, July 05, 2019 10:14:07 AMTime Spent:Time Spent: 00:04:5500:04:55IP Address:IP Address:

Page 1

Page 35: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

35 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CEO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Ongoing

Q11

7. How many MLOs do you employ?

5

Q12

8. How many of your MLOs conduct business from a branch location?

5

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 36: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

36 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Text is limited to communication with clients. Documents are sent and received via email - encrypted Sharefile.

Q20

12b. Does your company use an API that captures those text messages?

Yes.

Page 37: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

37 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

All remote employees receive a company issues and monitored laptop and some will also receive a company phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Via our IT department

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

When an employee is terminated, a shipping label is sent and tracked. They will not receive their final pay until all items are received. Access to those devices are deactivated and cannot be accessed

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#13#13COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:15:06 AMFriday, July 05, 2019 10:15:06 AMLast Modified:Last Modified: Friday, July 05, 2019 10:23:04 AMFriday, July 05, 2019 10:23:04 AMTime Spent:Time Spent: 00:07:5800:07:58IP Address:IP Address:

Page 1

Page 38: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

38 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Our Chief Information Officer and their team

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Very often and random

Q11

7. How many MLOs do you employ?

28

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

13

Page 39: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

39 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 40: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

40 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

none of the above

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#14#14COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:33:53 AMFriday, July 05, 2019 10:33:53 AMLast Modified:Last Modified: Friday, July 05, 2019 10:37:26 AMFriday, July 05, 2019 10:37:26 AMTime Spent:Time Spent: 00:03:3200:03:32IP Address:IP Address:

Page 1

Page 41: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

41 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Security consultants

Q11

7. How many MLOs do you employ?

none

Q12

8. How many of your MLOs conduct business from a branch location?

n/a

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

n/a

Q14

9. How many of your MLOs conduct business otherwise remotely?

n/a

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 42: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

42 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 43: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

43 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Via email and automatic program push updates

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Equipment is returned to company

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#15#15COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:39:30 AMFriday, July 05, 2019 10:39:30 AMLast Modified:Last Modified: Friday, July 05, 2019 10:42:44 AMFriday, July 05, 2019 10:42:44 AMTime Spent:Time Spent: 00:03:1400:03:14IP Address:IP Address:

Page 1

Page 44: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

44 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Broker/owner is CIO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Twice a year thru compliance consultants

Q11

7. How many MLOs do you employ?

6

Q12

8. How many of your MLOs conduct business from a branch location?

3

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

3

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 45: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

45 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Regular communication with borrowers

Q20

12b. Does your company use an API that captures those text messages?

No

Page 46: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

46 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None, they provide their own tech.

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

#16#16COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:44:09 AMFriday, July 05, 2019 10:44:09 AMLast Modified:Last Modified: Friday, July 05, 2019 10:47:51 AMFriday, July 05, 2019 10:47:51 AMTime Spent:Time Spent: 00:03:4200:03:42IP Address:IP Address:

Page 1

Page 47: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

47 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a risk assessment of its information security systems?

informally

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 48: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

48 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

routine communication with main office and clients

Q20

12b. Does your company use an API that captures those text messages?

No

Page 49: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

49 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

The company does not provide any device

Q2

1a. How are patches or security updates pushed out to remote devices?

All tech is pw protected and the admin and distribution of software and pw's is controlled by corp office

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

There are no devices given out

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#17#17COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 10:53:26 AMFriday, July 05, 2019 10:53:26 AMLast Modified:Last Modified: Friday, July 05, 2019 10:58:43 AMFriday, July 05, 2019 10:58:43 AMTime Spent:Time Spent: 00:05:1700:05:17IP Address:IP Address:

Page 1

Page 50: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

50 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

always as tech changes

Q11

7. How many MLOs do you employ?

45

Q12

8. How many of your MLOs conduct business from a branch location?

most

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

some

Q14

9. How many of your MLOs conduct business otherwise remotely?

?

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 51: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

51 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

law requires to keep copy of file

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

We have no policy regarding this

Q20

12b. Does your company use an API that captures those text messages?

no

Page 52: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

52 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

They are updated on site

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

They are returned to the office and wiped

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#18#18COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 11:03:33 AMFriday, July 05, 2019 11:03:33 AMLast Modified:Last Modified: Friday, July 05, 2019 11:07:15 AMFriday, July 05, 2019 11:07:15 AMTime Spent:Time Spent: 00:03:4200:03:42IP Address:IP Address:

Page 1

Page 53: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

53 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

- I am a one man shop

Q10

6. How often does the company conduct a risk assessment of its information security systems?

constantly

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

1

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 54: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

54 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

We keep physical files on site

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

If a borrower texts me I reply

Q20

12b. Does your company use an API that captures those text messages?

I do not know what an API is?

Page 55: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

55 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop, laptop/tablet, phone/pda

Q2

1a. How are patches or security updates pushed out to remote devices?

These devices are automatically updated, or receive notification when an update is available.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All company equipment is accounted for and remains company equipment upon termination of employees.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#19#19COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 12:02:12 PMFriday, July 05, 2019 12:02:12 PMLast Modified:Last Modified: Friday, July 05, 2019 12:13:13 PMFriday, July 05, 2019 12:13:13 PMTime Spent:Time Spent: 00:11:0000:11:00IP Address:IP Address:

Page 1

Page 56: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

56 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The Designated Broker, along with our contract IT personnel.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually, or as otherwise needed.

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

Main office is an MLO's residence, 2

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 57: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

57 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

No 'shadow' files. All documentation is retained at the main office.

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Because of the difficulty in capturing text messages we discourage its use, but occasionally we receive and have to respond to a client or RE agent's text message.

Q20

12b. Does your company use an API that captures those text messages?

No. Have to transpose in a different medium for filing purposes.

Page 58: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

58 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop desktop

Q2

1a. How are patches or security updates pushed out to remote devices?

none. everything on cloud server.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

by mail

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#20#20COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 12:12:07 PMFriday, July 05, 2019 12:12:07 PMLast Modified:Last Modified: Friday, July 05, 2019 12:15:19 PMFriday, July 05, 2019 12:15:19 PMTime Spent:Time Spent: 00:03:1100:03:11IP Address:IP Address:

Page 1

Page 59: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

59 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Owner

Q10

6. How often does the company conduct a riskassessment of its information security systems?

Respondent skipped this question

Q11

7. How many MLOs do you employ?

4

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

4

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 60: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

60 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

general questions, gathering of docs.

Q20

12b. Does your company use an API that captures those text messages?

no

Page 61: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

61 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None but we do provide access to Calyx Point to designated laptops for originators

Q2

1a. How are patches or security updates pushed out to remote devices?

We use Sonic Wall Net extender which is double encrypted with a changing pass word on every sign in.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Access to the sever is removed by the IT company that use.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#21#21COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 12:37:42 PMFriday, July 05, 2019 12:37:42 PMLast Modified:Last Modified: Friday, July 05, 2019 12:56:43 PMFriday, July 05, 2019 12:56:43 PMTime Spent:Time Spent: 00:19:0100:19:01IP Address:IP Address:

Page 1

Page 62: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

62 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Broker

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Our system is monitored by an IT company monthly.

Q11

7. How many MLOs do you employ?

4 including the owner / broker

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

1 almost exclusively (is out of state)

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 63: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

63 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 64: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

64 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop Computers

Q2

1a. How are patches or security updates pushed out to remote devices?

Through our IT Company that handles this on all of our computers at set times as needed.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Employee returns them, they are wiped and setup for new and future employees, all data archived from each wipe.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#22#22COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 1:58:35 PMFriday, July 05, 2019 1:58:35 PMLast Modified:Last Modified: Friday, July 05, 2019 2:01:08 PMFriday, July 05, 2019 2:01:08 PMTime Spent:Time Spent: 00:02:3300:02:33IP Address:IP Address:

Page 1

Page 65: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

65 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Access Business Technology the third party company we hire.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Monthly

Q11

7. How many MLOs do you employ?

13

Q12

8. How many of your MLOs conduct business from a branch location?

13

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

6

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 66: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

66 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 67: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

67 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None except we have one laptop that can be used for someone needs it. They have a desktop in the office.

Q2

1a. How are patches or security updates pushed out to remote devices?

We have hired an outside IT dept to watch over firewalls and all devices.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All employees have an exit interview. At that time we get all company property back and lock them out of all company systems.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#23#23COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 05, 2019 2:27:41 PMFriday, July 05, 2019 2:27:41 PMLast Modified:Last Modified: Friday, July 05, 2019 2:39:39 PMFriday, July 05, 2019 2:39:39 PMTime Spent:Time Spent: 00:11:5800:11:58IP Address:IP Address:

Page 1

Page 68: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

68 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Yearly - It is the hired IT that does it

Q11

7. How many MLOs do you employ?

7

Q12

8. How many of your MLOs conduct business from a branch location?

Main Branch - 6 / 2nd branch - 1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

5

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 69: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

69 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

No personal information is allowed. Example: Credit Card info, SSN, Addresses. Usually if borrower asks question, we will answer if not any personal info. Otherwise we call.

Q20

12b. Does your company use an API that captures those text messages?

No.

Page 70: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

70 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptops

Q2

1a. How are patches or security updates pushed out to remote devices?

From IT department, no employee involvement/choice

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

must be logged back to IT dept by supervisor

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#24#24COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Saturday, July 06, 2019 1:16:33 PMSaturday, July 06, 2019 1:16:33 PMLast Modified:Last Modified: Saturday, July 06, 2019 1:19:15 PMSaturday, July 06, 2019 1:19:15 PMTime Spent:Time Spent: 00:02:4200:02:42IP Address:IP Address:

Page 1

Page 71: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

71 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

IT and IT Security is outsourced

Q10

6. How often does the company conduct a riskassessment of its information security systems?

Respondent skipped this question

Q11

7. How many MLOs do you employ?

35

Q12

8. How many of your MLOs conduct business from a branch location?

35

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 72: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

72 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

updates on process

Q20

12b. Does your company use an API that captures those text messages?

no

Page 73: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

73 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

I do not provide any devices to work remotely. All employees work at my office.

Q2

1a. How are patches or security updates pushed out to remote devices?

N/A

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

N/A

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#25#25COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Saturday, July 06, 2019 8:16:21 PMSaturday, July 06, 2019 8:16:21 PMLast Modified:Last Modified: Saturday, July 06, 2019 8:23:03 PMSaturday, July 06, 2019 8:23:03 PMTime Spent:Time Spent: 00:06:4100:06:41IP Address:IP Address:

Page 1

Page 74: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

74 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Monthly. I am always updating our security software when updates are needing. I also haves massive filters on our email via go daddy and Mcafee

Q11

7. How many MLOs do you employ?

2. 3 including me (Craig Pribyl)

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

N/A

Q14

9. How many of your MLOs conduct business otherwise remotely?

N/A

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 75: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

75 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

All records and documents are kept at the office and not individually by LOs

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 76: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

76 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop or desktop with VOIP phone setup

Q2

1a. How are patches or security updates pushed out to remote devices?

They are pushed as needed by our IT department, IT has remote access to all company equipment and can push as needed or through a monthly update.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The employee is required to return the equipment, we have an agreement with fedex where they can just drop the equipment and fedex will package, ship and bill the company.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Respondent skipped this question

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#26#26COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Sunday, July 07, 2019 6:09:20 PMSunday, July 07, 2019 6:09:20 PMLast Modified:Last Modified: Sunday, July 07, 2019 6:13:12 PMSunday, July 07, 2019 6:13:12 PMTime Spent:Time Spent: 00:03:5100:03:51IP Address:IP Address:

Page 1

Page 77: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

77 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Th CIO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

650

Q12

8. How many of your MLOs conduct business from a branch location?

50%

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

10%

Q14

9. How many of your MLOs conduct business otherwise remotely?

70%

Page 78: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

78 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 79: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

79 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

yes

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All Co. equipment is returned on the employees last day of employment. If for some reason the equipment is not returned on the last day of employment it is remotely wiped and all login credentials are locked.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

#27#27COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 5:10:06 AMMonday, July 08, 2019 5:10:06 AMLast Modified:Last Modified: Monday, July 08, 2019 5:16:03 AMMonday, July 08, 2019 5:16:03 AMTime Spent:Time Spent: 00:05:5600:05:56IP Address:IP Address:

Page 1

Page 80: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

80 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

EVP, Chief Information Officer & Chief Technology Office

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

12

Q12

8. How many of your MLOs conduct business from a branch location?

10

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

on an as needed basis

Page 81: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

81 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 82: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

82 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

desktop, laptop, cell phone, landline

Q2

1a. How are patches or security updates pushed out to remote devices?

Tech company sends out an email and conducts updates remotely

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Equipment is requested and self addressed, self stamped packaging is provided.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#28#28COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 6:00:25 AMMonday, July 08, 2019 6:00:25 AMLast Modified:Last Modified: Monday, July 08, 2019 6:05:19 AMMonday, July 08, 2019 6:05:19 AMTime Spent:Time Spent: 00:04:5300:04:53IP Address:IP Address:

Page 1

Page 83: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

83 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Technology Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Yearly

Q11

7. How many MLOs do you employ?

25

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

25

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 84: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

84 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 85: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

85 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop, Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Through our VPN that they log into every day

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Before they receive their last check everything must be turned in.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#29#29COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 6:19:41 AMMonday, July 08, 2019 6:19:41 AMLast Modified:Last Modified: Monday, July 08, 2019 6:21:28 AMMonday, July 08, 2019 6:21:28 AMTime Spent:Time Spent: 00:01:4600:01:46IP Address:IP Address:

Page 1

Page 86: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

86 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Yearly

Q11

7. How many MLOs do you employ?

150

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 87: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

87 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 88: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

88 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Automatic uploads

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Access to the network is terminated immediately upon employee separation from employment, the equipment is collected shortly thereafter.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#30#30COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 6:23:14 AMMonday, July 08, 2019 6:23:14 AMLast Modified:Last Modified: Monday, July 08, 2019 6:30:38 AMMonday, July 08, 2019 6:30:38 AMTime Spent:Time Spent: 00:07:2400:07:24IP Address:IP Address:

Page 1

Page 89: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

89 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CISO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

We have an ongoing program

Q11

7. How many MLOs do you employ?

15

Q12

8. How many of your MLOs conduct business from a branch location?

All

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

None

Q14

9. How many of your MLOs conduct business otherwise remotely?

None

Page 90: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

90 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 91: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

91 / 237

Q1

1. Describe what type of devices the Company providesemployees to use for remote work. (laptop, phone,desktop, tablet, etc.)

Respondent skipped this question

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

Respondent skipped this question

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Respondent skipped this question

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Respondent skipped this question

#31#31INCOMPLETEINCOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 6:50:01 AMMonday, July 08, 2019 6:50:01 AMLast Modified:Last Modified: Monday, July 08, 2019 6:51:31 AMMonday, July 08, 2019 6:51:31 AMTime Spent:Time Spent: 00:01:3000:01:30IP Address:IP Address:

Page 1

Page 92: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

92 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Respondent skipped this question

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a riskassessment of its information security systems?

Respondent skipped this question

Q11

7. How many MLOs do you employ?

Respondent skipped this question

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Respondent skipped this question

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Page 93: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

93 / 237

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Respondent skipped this question

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 94: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

94 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

LOs provide their own laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

LOs are reminded to install security and do weekly and monthly updates and virus scans with computers scanned nightly

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

no company issued equipment

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#32#32COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 7:38:31 AMMonday, July 08, 2019 7:38:31 AMLast Modified:Last Modified: Monday, July 08, 2019 7:43:10 AMMonday, July 08, 2019 7:43:10 AMTime Spent:Time Spent: 00:04:3800:04:38IP Address:IP Address:

Page 1

Page 95: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

95 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

broker and LO trained in tech

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

5

Q12

8. How many of your MLOs conduct business from a branch location?

5

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

5

Q14

9. How many of your MLOs conduct business otherwise remotely?

5 - if you mean meeting customers offsite - ALL LOs do that

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 96: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

96 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 97: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

97 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

All of the above, laptops, desktops, phone, and tablets

Q2

1a. How are patches or security updates pushed out to remote devices?

yes

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Yes resources are returned a specific department is responsible for retrieval

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#33#33COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 8:06:48 AMMonday, July 08, 2019 8:06:48 AMLast Modified:Last Modified: Monday, July 08, 2019 8:09:46 AMMonday, July 08, 2019 8:09:46 AMTime Spent:Time Spent: 00:02:5700:02:57IP Address:IP Address:

Page 1

Page 98: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

98 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CISO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

1500

Q12

8. How many of your MLOs conduct business from a branch location?

all

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

none

Q14

9. How many of your MLOs conduct business otherwise remotely?

varies they have laptops so they have the ability to work remotely

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 99: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

99 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

we have milestone texts set up if the borrower opts in..and LO's can send text messages through our CRM

Q20

12b. Does your company use an API that captures those text messages?

yes

Page 100: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

100 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Logmein.comlaptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Dont understand patches

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Never terminated anyone yet Explain company resources Ee loan no equipment

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

#34#34COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 8:27:45 AMMonday, July 08, 2019 8:27:45 AMLast Modified:Last Modified: Monday, July 08, 2019 8:33:15 AMMonday, July 08, 2019 8:33:15 AMTime Spent:Time Spent: 00:05:3000:05:30IP Address:IP Address:

Page 1

Page 101: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

101 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Me

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Never

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

1 only as needed =vacaton etc

Page 102: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

102 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

when and where to meetNever rates, locks or fees

Q20

12b. Does your company use an API that captures those text messages?

What is an API

Page 103: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

103 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Phone

Q2

1a. How are patches or security updates pushed out to remote devices?

No mortgage apps used on phones, but security patches updated on demand

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Owner broker with no other devices outstanding

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

#35#35COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 8:27:20 AMMonday, July 08, 2019 8:27:20 AMLast Modified:Last Modified: Monday, July 08, 2019 8:33:53 AMMonday, July 08, 2019 8:33:53 AMTime Spent:Time Spent: 00:06:3200:06:32IP Address:IP Address:

Page 1

Page 104: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

104 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Owner broker

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Monthly

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 105: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

105 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Requests for information or updated status. No quotes, etc Mostly nagging or followup

Q20

12b. Does your company use an API that captures those text messages?

No but if details are in the messages they are followed up by email as regular policy.

Page 106: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

106 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

with ongoing updates

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

returned before final paycheck is issued

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#36#36COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 10:02:16 AMMonday, July 08, 2019 10:02:16 AMLast Modified:Last Modified: Monday, July 08, 2019 10:11:19 AMMonday, July 08, 2019 10:11:19 AMTime Spent:Time Spent: 00:09:0200:09:02IP Address:IP Address:

Page 1

Page 107: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

107 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

semi annually

Q11

7. How many MLOs do you employ?

4

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 108: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

108 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

paper records are kept in locked room and in locked cabinets

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

conversational information, clarifying information, many clients use text as a main means of communications.

Q20

12b. Does your company use an API that captures those text messages?

no we dont

Page 109: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

109 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

desktop "thin client" devices for select employees

Q2

1a. How are patches or security updates pushed out to remote devices?

remotely from the corporate office automatically and/or as needed

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

shipped to the corporate office or returned in person; devices must be returned (cannot be kept or purchased)

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#37#37COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 10:21:13 AMMonday, July 08, 2019 10:21:13 AMLast Modified:Last Modified: Monday, July 08, 2019 10:24:52 AMMonday, July 08, 2019 10:24:52 AMTime Spent:Time Spent: 00:03:3800:03:38IP Address:IP Address:

Page 1

Page 110: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

110 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a risk assessment of its information security systems?

frequency as required

Q11

7. How many MLOs do you employ?

0

Q12

8. How many of your MLOs conduct business from a branch location?

N/A

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

N/A

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Respondent skipped this question

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Respondent skipped this question

Page 111: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

111 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Respondent skipped this question

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 112: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

112 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

nothing

Q2

1a. How are patches or security updates pushed out to remote devices?

N/a

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

n/a

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#38#38COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 10:46:22 AMMonday, July 08, 2019 10:46:22 AMLast Modified:Last Modified: Monday, July 08, 2019 10:48:01 AMMonday, July 08, 2019 10:48:01 AMTime Spent:Time Spent: 00:01:3900:01:39IP Address:IP Address:

Page 1

Page 113: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

113 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Owner

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 114: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

114 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 115: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

115 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Computers, laptops, phones, scanners, and fax machines (still).

Q2

1a. How are patches or security updates pushed out to remote devices?

They are forced out at the time of the update. The user must download and install before proceeding.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The company sends out a packing & shipping firm by appointment and gathers the company's equipment for delivery to the corporate offices.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#39#39COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 12:29:54 PMMonday, July 08, 2019 12:29:54 PMLast Modified:Last Modified: Monday, July 08, 2019 12:42:10 PMMonday, July 08, 2019 12:42:10 PMTime Spent:Time Spent: 00:12:1600:12:16IP Address:IP Address:

Page 1

Page 116: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

116 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

IT/Legal

Q10

6. How often does the company conduct a risk assessment of its information security systems?

every six months

Q11

7. How many MLOs do you employ?

80, 2 licensed in WA

Q12

8. How many of your MLOs conduct business from a branch location?

69

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

3

Q14

9. How many of your MLOs conduct business otherwise remotely?

At times, 100% (80). They can and do take apps and meet with clientel at a coffee shop.

Page 117: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

117 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Presuming the client consents; Arrange meetings/calls. Inform them of their loan status.

Q20

12b. Does your company use an API that captures those text messages?

No, the company does not control individual's phones. The MLO can, using an app, have those texts sent to the loan file for memorializing.

Page 118: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

118 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

desktop

Q2

1a. How are patches or security updates pushed out to remote devices?

vpn

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

returned by employee

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#40#40COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 12:43:07 PMMonday, July 08, 2019 12:43:07 PMLast Modified:Last Modified: Monday, July 08, 2019 12:59:51 PMMonday, July 08, 2019 12:59:51 PMTime Spent:Time Spent: 00:16:4300:16:43IP Address:IP Address:

Page 1

Page 119: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

119 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

president

Q10

6. How often does the company conduct a risk assessment of its information security systems?

1

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

2

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 120: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

120 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

all but sensitive

Q20

12b. Does your company use an API that captures those text messages?

no

Page 121: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

121 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop.

Q2

1a. How are patches or security updates pushed out to remote devices?

We use a device called KACE that pushes out updates and security updates to our computers and servers for Parallels 2x remote.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The branch manager collects the equipment and returns it to home office as part of the termination procedures which include termination of all remote access by IT immediately following employee separation.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#41#41COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 12:20:53 PMMonday, July 08, 2019 12:20:53 PMLast Modified:Last Modified: Monday, July 08, 2019 1:26:25 PMMonday, July 08, 2019 1:26:25 PMTime Spent:Time Spent: 01:05:3101:05:31IP Address:IP Address:

Page 1

Page 122: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

122 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Information Security falls under our Chief Risk Officer.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

It is completed annually by a third party, Richey May. In addition we conduct annual penetration testing.

Q11

7. How many MLOs do you employ?

270

Q12

8. How many of your MLOs conduct business from a branch location?

250

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

None

Q14

9. How many of your MLOs conduct business otherwise remotely?

20

Page 123: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

123 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

We operate on an entirely paperless system

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Texting is not specifically addressed in the policy, but MLO's are NOT allowed to send any PII or NPI through unencrypted means such as email or text.

Q20

12b. Does your company use an API that captures those text messages?

No, not currently

Page 124: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

124 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop, IP phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Pushed out through mandated software updates, emails or new program downloads

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Returned to main office via UPS shipment. User account is disabled prior to return, so no information should be accessible.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#42#42COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 2:57:13 PMMonday, July 08, 2019 2:57:13 PMLast Modified:Last Modified: Monday, July 08, 2019 3:10:31 PMMonday, July 08, 2019 3:10:31 PMTime Spent:Time Spent: 00:13:1700:13:17IP Address:IP Address:

Page 1

Page 125: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

125 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Operations Director

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

16

Q12

8. How many of your MLOs conduct business from a branch location?

4

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

4

Q14

9. How many of your MLOs conduct business otherwise remotely?

4

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 126: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

126 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Through an SMS app via the company CRM. Only accessible from the CRM on a desktop. Primarily initial sales or quick updates on a loan status.

Q20

12b. Does your company use an API that captures those text messages?

Yes

Page 127: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

127 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Phone and Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Updates are pushed to laptops and instructions are provided to update phones when necessary.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Managers are responsible for collecting equipment upon termination of an employee. We don't have any associates that only work remote. Most associates work from the office and occasionally work offset.

Q4

2. Does your company keep physical records at anybranch?

Respondent skipped this question

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#43#43COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 3:53:11 PMMonday, July 08, 2019 3:53:11 PMLast Modified:Last Modified: Monday, July 08, 2019 3:59:12 PMMonday, July 08, 2019 3:59:12 PMTime Spent:Time Spent: 00:06:0000:06:00IP Address:IP Address:

Page 1

Page 128: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

128 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Security Officer

Q10

6. How often does the company conduct a riskassessment of its information security systems?

Respondent skipped this question

Q11

7. How many MLOs do you employ?

NA - we don't originate or have any branch offices

Q12

8. How many of your MLOs conduct business from a branch location?

NA

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

NA

Q14

9. How many of your MLOs conduct business otherwise remotely?

NA

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 129: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

129 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Respondent skipped this question

Q17

11a. If yes, describe what types of records MLOs keep

NA for MLOs, but all servicing documents are images. No physical records are allowed outside of the office.

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 130: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

130 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None

Q2

1a. How are patches or security updates pushed out to remote devices?

n/a

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

n/a

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#44#44COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 6:41:37 PMMonday, July 08, 2019 6:41:37 PMLast Modified:Last Modified: Monday, July 08, 2019 6:45:30 PMMonday, July 08, 2019 6:45:30 PMTime Spent:Time Spent: 00:03:5200:03:52IP Address:IP Address:

Page 1

Page 131: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

131 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

President

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Monthly

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 132: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

132 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

All paper files are kept in the main office. No documents are produced or stored outside of the main office.

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 133: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

133 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Remote employees are issued a laptop and docking station with 2 monitors. Phone is a digital version of Cisco IP Phone and is only accessible on the laptop.

Q2

1a. How are patches or security updates pushed out to remote devices?

IT Help Desk rolls out updates constantly, I do not believe remote employees experience any of these differently than on-site employees.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All issued equipment is logged before an individual is allowed to work remote. All of the logged equipment must be returned.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

#45#45COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 5:24:50 AMTuesday, July 09, 2019 5:24:50 AMLast Modified:Last Modified: Tuesday, July 09, 2019 5:35:53 AMTuesday, July 09, 2019 5:35:53 AMTime Spent:Time Spent: 00:11:0200:11:02IP Address:IP Address:

Page 1

Page 134: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

134 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Compliance Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annual internal audits for everything

Q11

7. How many MLOs do you employ?

50 licensed individuals, 23 WA-specific MLOs

Q12

8. How many of your MLOs conduct business from a branch location?

8

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

All

Q14

9. How many of your MLOs conduct business otherwise remotely?

None

Page 135: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

135 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 136: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

136 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop, phone.

Q2

1a. How are patches or security updates pushed out to remote devices?

VPN and on-premises updates.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Employees are responsible for returning equipment.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#46#46COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 9:27:09 AMTuesday, July 09, 2019 9:27:09 AMLast Modified:Last Modified: Tuesday, July 09, 2019 9:30:10 AMTuesday, July 09, 2019 9:30:10 AMTime Spent:Time Spent: 00:03:0100:03:01IP Address:IP Address:

Page 1

Page 137: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

137 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Information Security VP

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

15

Q12

8. How many of your MLOs conduct business from a branch location?

12

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

3

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 138: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

138 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 139: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

139 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop, phone, and tablets

Q2

1a. How are patches or security updates pushed out to remote devices?

They are pushed out with our RMM tool which is N-Central by Solarwinds

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

They are given to the immediate supervisor upon termination. The credentials and any sites used are blocked from access.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#47#47COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 12:51:58 PMTuesday, July 09, 2019 12:51:58 PMLast Modified:Last Modified: Tuesday, July 09, 2019 2:54:27 PMTuesday, July 09, 2019 2:54:27 PMTime Spent:Time Spent: 02:02:2902:02:29IP Address:IP Address:

Page 1

Page 140: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

140 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

President and Uptime Solutions our IT company

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

0

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 141: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

141 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 142: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

142 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop only

Q2

1a. How are patches or security updates pushed out to remote devices?

Through parent company IT Department

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

They are handed back to the respective branch manager.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#48#48COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 4:43:21 PMTuesday, July 09, 2019 4:43:21 PMLast Modified:Last Modified: Tuesday, July 09, 2019 4:52:08 PMTuesday, July 09, 2019 4:52:08 PMTime Spent:Time Spent: 00:08:4600:08:46IP Address:IP Address:

Page 1

Page 143: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

143 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CIO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

36

Q12

8. How many of your MLOs conduct business from a branch location?

20

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 144: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

144 / 237

Q17

11a. If yes, describe what types of records MLOs keep

N/A

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

N/A

Q20

12b. Does your company use an API that captures those text messages?

N/A

Page 145: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

145 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop computers and cell phones

Q2

1a. How are patches or security updates pushed out to remote devices?

Laptops are Windows 10 based and updates are downloaded and installed directly from Microsoft on a regular basis. Third party application patches like Flash and Java are updated on a monthly basis

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Company owned resources are returned to Company when employment is terminated

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#49#49COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 9:43:02 AMWednesday, July 10, 2019 9:43:02 AMLast Modified:Last Modified: Wednesday, July 10, 2019 10:06:16 AMWednesday, July 10, 2019 10:06:16 AMTime Spent:Time Spent: 00:23:1400:23:14IP Address:IP Address:

Page 1

Page 146: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

146 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Continually

Q11

7. How many MLOs do you employ?

4, 2 of which are licensed in Washington

Q12

8. How many of your MLOs conduct business from a branch location?

None

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

N/A

Q14

9. How many of your MLOs conduct business otherwise remotely?

4, 2 are licensed in WA. All applications are taking in main office

Page 147: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

147 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

all records are kept with physical file at main office or stored in Encompass our LOS

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Borrowers sometimes initiate text conversations which MLO's are allowed to engage in so communicating via text with borrowers is theactivity

Q20

12b. Does your company use an API that captures those text messages?

no

Page 148: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

148 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop, monitor, keyboard, mouse

Q2

1a. How are patches or security updates pushed out to remote devices?

I don't know

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

employee returns equipment

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#50#50COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 10:03:00 AMWednesday, July 10, 2019 10:03:00 AMLast Modified:Last Modified: Wednesday, July 10, 2019 10:10:22 AMWednesday, July 10, 2019 10:10:22 AMTime Spent:Time Spent: 00:07:2200:07:22IP Address:IP Address:

Page 1

Page 149: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

149 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Director of Infrastructure

Q10

6. How often does the company conduct a risk assessment of its information security systems?

I don't know

Q11

7. How many MLOs do you employ?

1032

Q12

8. How many of your MLOs conduct business from a branch location?

799

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 150: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

150 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 151: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

151 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop computer, scanner, printer

Q2

1a. How are patches or security updates pushed out to remote devices?

Weekly scheduled updates

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Account access is disabled and the equipment is required to be returned to the IT Department at the corporate office.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#51#51COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 10:12:10 AMTuesday, July 09, 2019 10:12:10 AMLast Modified:Last Modified: Wednesday, July 10, 2019 10:57:18 AMWednesday, July 10, 2019 10:57:18 AMTime Spent:Time Spent: Over a dayOver a dayIP Address:IP Address:

Page 1

Page 152: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

152 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Compliance Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Quarterly scans are performed on public-facing servers

Q11

7. How many MLOs do you employ?

238

Q12

8. How many of your MLOs conduct business from a branch location?

235

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

3

Q14

9. How many of your MLOs conduct business otherwise remotely?

None

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 153: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

153 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

MLOs do not individually keep records.

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

MLOs communicate status updates, pose questions, and communicate other administrative information to applicants and borrowers bytext.

Q20

12b. Does your company use an API that captures those text messages?

No

Page 154: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

154 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Only my laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

I update software whenever I use my laptop

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

not applicable

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#52#52COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 11:22:21 AMWednesday, July 10, 2019 11:22:21 AMLast Modified:Last Modified: Wednesday, July 10, 2019 11:27:47 AMWednesday, July 10, 2019 11:27:47 AMTime Spent:Time Spent: 00:05:2600:05:26IP Address:IP Address:

Page 1

Page 155: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

155 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

myself

Q10

6. How often does the company conduct a risk assessment of its information security systems?

I regularly consult with an IT specialist regarding technology updates

Q11

7. How many MLOs do you employ?

none, only myself

Q12

8. How many of your MLOs conduct business from a branch location?

none

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

none

Q14

9. How many of your MLOs conduct business otherwise remotely?

none

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 156: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

156 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

I inform the customers when I have sent emails to them that are important.

Q20

12b. Does your company use an API that captures those text messages?

we do not.

Page 157: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

157 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop or desktop

Q2

1a. How are patches or security updates pushed out to remote devices?

Via Citrix VPN

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Employees ship all equipment back to company

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#53#53COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 11:27:38 AMWednesday, July 10, 2019 11:27:38 AMLast Modified:Last Modified: Wednesday, July 10, 2019 11:29:57 AMWednesday, July 10, 2019 11:29:57 AMTime Spent:Time Spent: 00:02:1800:02:18IP Address:IP Address:

Page 1

Page 158: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

158 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CIO/CFO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

0 - we're 100% wholesale

Q12

8. How many of your MLOs conduct business from a branch location?

n/a

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

n/a

Q14

9. How many of your MLOs conduct business otherwise remotely?

n/a

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 159: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

159 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 160: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

160 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

We do not work remotely.

Q2

1a. How are patches or security updates pushed out to remote devices?

N/A

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

N/A

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#54#54COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 11:33:23 AMWednesday, July 10, 2019 11:33:23 AMLast Modified:Last Modified: Wednesday, July 10, 2019 11:38:01 AMWednesday, July 10, 2019 11:38:01 AMTime Spent:Time Spent: 00:04:3700:04:37IP Address:IP Address:

Page 1

Page 161: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

161 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

We are part of a larger company. Their technology staff covers our needs

Q10

6. How often does the company conduct a risk assessment of its information security systems?

quarterly

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Page 162: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

162 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Our loan document files are locked in files cabinets inside a locked file room

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 163: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

163 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop, Phones

Q2

1a. How are patches or security updates pushed out to remote devices?

In our current environment of Configuration Manager 2012 ("CM12"), software updates automatic synchronization to one day from Microsoft Update to the Central Administration Server ("CAS"). Manual synchronization can also be triggered by initiating the Synchronize Software Updates action in the Configuration Manager ("CM") console. All remote devices that are active and logged in to the domain have patches and security devices installed on them. Processes/standards are documented and approved. Deployments/updates are documented, scheduled and approved via Change Management standards.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

During termination, as per process employees need to return their allotted systems/resources and obtain signoff from Local End User Services team. Returned equipments are then reassigned to new employee after cleanup. In case of Legal Hold cases, Hard drives are retained by the End User Services team. Termination activities are automated via HR feed entry. Returning of assets are tracked via request tickets in Service Now.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

#55#55COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 12:40:16 PMWednesday, July 10, 2019 12:40:16 PMLast Modified:Last Modified: Wednesday, July 10, 2019 1:04:45 PMWednesday, July 10, 2019 1:04:45 PMTime Spent:Time Spent: 00:24:2800:24:28IP Address:IP Address:

Page 1

Page 164: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

164 / 237

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Information Security Officer (CISO)

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

109

Q12

8. How many of your MLOs conduct business from a branch location?

43

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

4

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Page 165: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

165 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 166: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

166 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop, Phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Google, Dell

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Immediately picked up in person

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#56#56COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 6:38:16 PMWednesday, July 10, 2019 6:38:16 PMLast Modified:Last Modified: Wednesday, July 10, 2019 6:40:40 PMWednesday, July 10, 2019 6:40:40 PMTime Spent:Time Spent: 00:02:2400:02:24IP Address:IP Address:

Page 1

Page 167: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

167 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Owner

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annualy

Q11

7. How many MLOs do you employ?

2

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

2

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 168: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

168 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

General follow up. No private financial information

Q20

12b. Does your company use an API that captures those text messages?

no

Page 169: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

169 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Don't do remote work.

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#57#57COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 7:34:43 PMWednesday, July 10, 2019 7:34:43 PMLast Modified:Last Modified: Wednesday, July 10, 2019 7:37:54 PMWednesday, July 10, 2019 7:37:54 PMTime Spent:Time Spent: 00:03:1100:03:11IP Address:IP Address:

Page 1

Page 170: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

170 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Broker

Q10

6. How often does the company conduct a risk assessment of its information security systems?

1

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 171: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

171 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 172: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

172 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop with remote access to office desktop, and phone.

Q2

1a. How are patches or security updates pushed out to remote devices?

System updates come up on devices.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All pertinent information is saved on the cloud. All access would have been taken prior to termination.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#58#58COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 7:51:21 PMWednesday, July 10, 2019 7:51:21 PMLast Modified:Last Modified: Wednesday, July 10, 2019 8:06:55 PMWednesday, July 10, 2019 8:06:55 PMTime Spent:Time Spent: 00:15:3400:15:34IP Address:IP Address:

Page 1

Page 173: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

173 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

MLO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Twice a year.

Q11

7. How many MLOs do you employ?

Two

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

2

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 174: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

174 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Informing the borrower to check emails for important information.

Q20

12b. Does your company use an API that captures those text messages?

Yes

Page 175: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

175 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Automatically with reminders to exit all applications & leave laptop connected to the internet

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#59#59COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, July 10, 2019 7:59:09 PMWednesday, July 10, 2019 7:59:09 PMLast Modified:Last Modified: Wednesday, July 10, 2019 8:07:16 PMWednesday, July 10, 2019 8:07:16 PMTime Spent:Time Spent: 00:08:0700:08:07IP Address:IP Address:

Page 1

Page 176: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

176 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Corporate location has department for security & policy & procedures

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Continuously

Q11

7. How many MLOs do you employ?

Respondent skipped this question

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Page 177: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

177 / 237

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 178: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

178 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None

Q2

1a. How are patches or security updates pushed out to remote devices?

n/a

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

n/a

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#60#60COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 8:28:21 AMThursday, July 11, 2019 8:28:21 AMLast Modified:Last Modified: Thursday, July 11, 2019 8:31:44 AMThursday, July 11, 2019 8:31:44 AMTime Spent:Time Spent: 00:03:2300:03:23IP Address:IP Address:

Page 1

Page 179: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

179 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Mortgage Broker / Owner

Q10

6. How often does the company conduct a risk assessment of its information security systems?

My Computer Company completes it regularly

Q11

7. How many MLOs do you employ?

3

Q12

8. How many of your MLOs conduct business from a branch location?

n/a

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

na

Q14

9. How many of your MLOs conduct business otherwise remotely?

na

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 180: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

180 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Just communication purposes instead of phone calls when the client text's the MLO first

Q20

12b. Does your company use an API that captures those text messages?

No since they are using their personal phones

Page 181: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

181 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

Automated Updates for the Laptop

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

No employees, only owners (2)

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#61#61COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 8:33:48 AMThursday, July 11, 2019 8:33:48 AMLast Modified:Last Modified: Thursday, July 11, 2019 8:38:29 AMThursday, July 11, 2019 8:38:29 AMTime Spent:Time Spent: 00:04:4100:04:41IP Address:IP Address:

Page 1

Page 182: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

182 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Once per week and/or as needed

Q11

7. How many MLOs do you employ?

2, but we are the owners

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 183: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

183 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 184: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

184 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop computers

Q2

1a. How are patches or security updates pushed out to remote devices?

no remote devices deployed

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Third party professional services company provides end-to end compliant overhaul of any equipment from terminated employees

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#62#62COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 7:56:02 AMThursday, July 11, 2019 7:56:02 AMLast Modified:Last Modified: Thursday, July 11, 2019 9:32:10 AMThursday, July 11, 2019 9:32:10 AMTime Spent:Time Spent: 01:36:0701:36:07IP Address:IP Address:

Page 1

Page 185: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

185 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

VP of Technology and Ops

Q10

6. How often does the company conduct a risk assessment of its information security systems?

we are working on implementing a regular risk assessment. In our model we outsource servicing thus limiting risk to begin with.

Q11

7. How many MLOs do you employ?

none

Q12

8. How many of your MLOs conduct business from a branch location?

none

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

none

Q14

9. How many of your MLOs conduct business otherwise remotely?

none

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 186: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

186 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

n/a

Q20

12b. Does your company use an API that captures those text messages?

n/a

Page 187: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

187 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop or Notebook depending on job function

Q2

1a. How are patches or security updates pushed out to remote devices?

Managed through Windows Update Services or Intune/Azure

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Items are reclaimed. Accounts are suspended immediately and access is cut off (essentially 'bricks' the PC until returned to corporate IT)

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#63#63COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 10:49:09 AMThursday, July 11, 2019 10:49:09 AMLast Modified:Last Modified: Thursday, July 11, 2019 10:53:12 AMThursday, July 11, 2019 10:53:12 AMTime Spent:Time Spent: 00:04:0300:04:03IP Address:IP Address:

Page 1

Page 188: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

188 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Information Technology Director

Q10

6. How often does the company conduct a risk assessment of its information security systems?

twice yearly

Q11

7. How many MLOs do you employ?

approx 60

Q12

8. How many of your MLOs conduct business from a branch location?

40

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

maybe 5 or 6

Q14

9. How many of your MLOs conduct business otherwise remotely?

all of them at some point

Page 189: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

189 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

only allowed to use corporate system level SMS notifications

Q20

12b. Does your company use an API that captures those text messages?

no

Page 190: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

190 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops and cell phones.

Q2

1a. How are patches or security updates pushed out to remote devices?

For remote login/access, they are managed/updated by HQ; and, for local access, they are managed/updated by the individual.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Remote access, corporate email, and CRM access is terminated. There is no company issued equipment at this time.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#64#64COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 10:52:51 AMThursday, July 11, 2019 10:52:51 AMLast Modified:Last Modified: Thursday, July 11, 2019 11:00:46 AMThursday, July 11, 2019 11:00:46 AMTime Spent:Time Spent: 00:07:5500:07:55IP Address:IP Address:

Page 1

Page 191: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

191 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Locally, it's the Designated Mortgage Broker; and, at HQ, it's our Franchise Support Director and/or the IT Help Desk.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Not sure.

Q11

7. How many MLOs do you employ?

4

Q12

8. How many of your MLOs conduct business from a branch location?

3

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

2

Q14

9. How many of your MLOs conduct business otherwise remotely?

4

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 192: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

192 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Basic correspondence. Occasionally providing a link to the secure application portal.

Q20

12b. Does your company use an API that captures those text messages?

I encourage it. I use SMSBackUp+ - and, encourage my LO's to do the same.

Page 193: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

193 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops cell pones

Q2

1a. How are patches or security updates pushed out to remote devices?

Through corporate

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Returned

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#65#65COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, July 11, 2019 3:44:49 PMThursday, July 11, 2019 3:44:49 PMLast Modified:Last Modified: Thursday, July 11, 2019 3:48:20 PMThursday, July 11, 2019 3:48:20 PMTime Spent:Time Spent: 00:03:3100:03:31IP Address:IP Address:

Page 1

Page 194: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

194 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief information officer, Compliance officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Quarterly

Q11

7. How many MLOs do you employ?

1

Q12

8. How many of your MLOs conduct business from a branch location?

1

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

1

Q14

9. How many of your MLOs conduct business otherwise remotely?

Not sure

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 195: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

195 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 196: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

196 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

For company deployed assets, we provide a managed Windows laptop. Otherwise we are a BYOD company that provides remote access from any U.S.A. based IP address via our Citrix NetScaler systems to hosted virtual desktops.

Q2

1a. How are patches or security updates pushed out to remote devices?

Patches are deployed to managed windows laptops in the background while connected to the corporate network. Once the patches are received, they apply at the next reboot

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Returning company assets from terminated team members is the responsibility of their management. Our technoloy asset group (TAM) also reviews the weekly termination report and follows up on those assets not returned in a timely manner.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#66#66COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 12, 2019 5:23:57 AMFriday, July 12, 2019 5:23:57 AMLast Modified:Last Modified: Friday, July 12, 2019 5:36:41 AMFriday, July 12, 2019 5:36:41 AMTime Spent:Time Spent: 00:12:4300:12:43IP Address:IP Address:

Page 1

Page 197: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

197 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

y, VP/SMD CISO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

3 total

Q12

8. How many of your MLOs conduct business from a branch location?

None, they sit in centralized/corporate locations - There are two MLO’s in London, KY . There is another MLO in Evansville, IN

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

None

Q14

9. How many of your MLOs conduct business otherwise remotely?

None

Page 198: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

198 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

None

Q20

12b. Does your company use an API that captures those text messages?

We do not text customers in reference to MLO's.

Page 199: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

199 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

we do not supply equiptment

Q2

1a. How are patches or security updates pushed out toremote devices?

Respondent skipped this question

Q3

1b. How are company resources returned upon employeetermination? (What happens to company issuedequipment?)

Respondent skipped this question

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#67#67COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 12, 2019 9:35:35 AMFriday, July 12, 2019 9:35:35 AMLast Modified:Last Modified: Friday, July 12, 2019 10:00:33 AMFriday, July 12, 2019 10:00:33 AMTime Spent:Time Spent: 00:24:5700:24:57IP Address:IP Address:

Page 1

Page 200: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

200 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’sinformation security policies and procedures?

Respondent skipped this question

Q10

6. How often does the company conduct a risk assessment of its information security systems?

annually

Q11

7. How many MLOs do you employ?

50

Q12

8. How many of your MLOs conduct business from a branch location?

2

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

2

Q14

9. How many of your MLOs conduct business otherwise remotely?

30

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Page 201: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

201 / 237

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

asking to information, status of documentation

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 202: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

202 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Desktop/PCs and phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Remote security client software that checks in with CU systems

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Wiped, reimaged and reassigned

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#68#68COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 12, 2019 10:44:20 AMFriday, July 12, 2019 10:44:20 AMLast Modified:Last Modified: Friday, July 12, 2019 12:00:56 PMFriday, July 12, 2019 12:00:56 PMTime Spent:Time Spent: 01:16:3601:16:36IP Address:IP Address:

Page 1

Page 203: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

203 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Technology Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annual

Q11

7. How many MLOs do you employ?

3

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 204: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

204 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

our POS allows for the member to receive text alerts. These are 1 way messages that direct them to log into their portal. No information is sent via text

Q20

12b. Does your company use an API that captures those text messages?

No

Page 205: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

205 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops

Q2

1a. How are patches or security updates pushed out to remote devices?

Post vendor announcement and release of any security patches; all threats and vulnerabilities are classified, Critical, High, Medium or Low, and prioritized by its amenable timeline in the Threat and Vulnerability Management (TVM) Process Guide and any required patches must be tested, deployed, and monitored post-deployment.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Departing employees return all company issued equipment (i.e., badges, keys, computers, etc.) and proprietary information immediately upon termination. Employees who fail to comply may be deemed as ineligible for rehire and subject to legal proceedings. Each line of business manager follows a Termination Checklist including an automated IT process to terminate all systems and applications access.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Respondent skipped this question

#69#69INCOMPLETEINCOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Friday, July 12, 2019 12:28:29 PMFriday, July 12, 2019 12:28:29 PMLast Modified:Last Modified: Friday, July 12, 2019 12:31:14 PMFriday, July 12, 2019 12:31:14 PMTime Spent:Time Spent: 00:02:4500:02:45IP Address:IP Address:

Page 1

Page 206: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

206 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Information Security Officer(CISO)

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Mr. Cooper conducts annual internal and external risk assessments of controls against industry standard frameworks and best practices. Results of the assessments are managed through corrective action plans (where applicable) and tracked through an issue management process.

Q11

7. How many MLOs do you employ?

429

Q12

8. How many of your MLOs conduct business from a branch location?

429

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

None

Q14

9. How many of your MLOs conduct business otherwise remotely?

None

Page 207: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

207 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 208: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

208 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Company managed laptop and phone

Q2

1a. How are patches or security updates pushed out to remote devices?

We use an automated, centralized management tool

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Access is revoked and it is colleted from the Team Member

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#70#70COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, July 08, 2019 7:48:14 AMMonday, July 08, 2019 7:48:14 AMLast Modified:Last Modified: Friday, July 12, 2019 2:54:51 PMFriday, July 12, 2019 2:54:51 PMTime Spent:Time Spent: Over a dayOver a dayIP Address:IP Address:

Page 1

Page 209: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

209 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Information Security Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Risk assessment is an ongoing process

Q11

7. How many MLOs do you employ?

over 2500

Q12

8. How many of your MLOs conduct business from a branch location?

100%

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 210: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

210 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

All text messages go through a managed platform and not via the MLO's cell phone

Q20

12b. Does your company use an API that captures those text messages?

Yes

Page 211: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

211 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop, mouse and keyboard. Loan officers are permitted to use their personal smartphone's for work purposes, but access to Guild email through the device is controlled by its IT administrator.

Q2

1a. How are patches or security updates pushed out to remote devices?

IBM BigFix Endpoint Management and Microsoft Intune

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Employees must return Guild issued equipment. Guild has a protocol to retrieve company resources upon employee termination.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

#71#71COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, July 09, 2019 12:39:22 PMTuesday, July 09, 2019 12:39:22 PMLast Modified:Last Modified: Friday, July 12, 2019 3:32:41 PMFriday, July 12, 2019 3:32:41 PMTime Spent:Time Spent: Over a dayOver a dayIP Address:IP Address:

Page 1

Page 212: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

212 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annual basis

Q11

7. How many MLOs do you employ?

334

Q12

8. How many of your MLOs conduct business from a branch location?

317

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

2

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Page 213: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

213 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Loan officers are permitted to communicate with borrowers via text message if that is the borrower's preferred method of doing so. Loan officers are to be mindful of the type of information they send via text message to ensure sensitive information is not transmitted in a way that violates Guild's policies

Q20

12b. Does your company use an API that captures those text messages?

No

Page 214: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

214 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop

Q2

1a. How are patches or security updates pushed out to remote devices?

employee can only log in through remote desktop so updates are controlled by headquarters

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

contracts are signed for return of equipment upon termination of employment

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#72#72COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, September 09, 2019 1:04:34 PMMonday, September 09, 2019 1:04:34 PMLast Modified:Last Modified: Monday, September 09, 2019 1:07:28 PMMonday, September 09, 2019 1:07:28 PMTime Spent:Time Spent: 00:02:5300:02:53IP Address:IP Address:

Page 1

Page 215: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

215 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

CIO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

yearly

Q11

7. How many MLOs do you employ?

50

Q12

8. How many of your MLOs conduct business from a branch location?

50

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

50

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 216: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

216 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 217: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

217 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

None

Q2

1a. How are patches or security updates pushed out to remote devices?

None

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

One laptop that stays in the office stayed in the office upon termination.

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

No

#73#73COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, December 31, 2019 4:42:42 PMTuesday, December 31, 2019 4:42:42 PMLast Modified:Last Modified: Tuesday, December 31, 2019 4:47:29 PMTuesday, December 31, 2019 4:47:29 PMTime Spent:Time Spent: 00:04:4700:04:47IP Address:IP Address:

Page 1

Page 218: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

218 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The company is very unorganized, like a teenager's car. Documents are everywhere, even ontop of the coffee creamer box in the storage room.

There are no written policies in the company and there are no security procedures at all. Company records are held in 1. A computer's physical Hard-drive. 2. A system called Point/Calyx which is connected with AUS. 3. On company emails. There is no database server, etc. 4. Hard files in a locked storage room.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

0% of the time.

Q11

7. How many MLOs do you employ?

3

Q12

8. How many of your MLOs conduct business from a branch location?

0

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Page 219: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

219 / 237

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Yes

Q17

11a. If yes, describe what types of records MLOs keep

Page 0-5 of Loan application, all signed docs and Initial disclosures, all underwriting req's and CD's.

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Clients and MLO's text about requirements needed, setting appointments, etc.

Q20

12b. Does your company use an API that captures those text messages?

No.

Page 220: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

220 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

laptop with virtual VPN enabled desktop

Q2

1a. How are patches or security updates pushed out to remote devices?

remotely from corporate IT department

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

FedEx

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#74#74COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, March 04, 2020 6:06:25 PMWednesday, March 04, 2020 6:06:25 PMLast Modified:Last Modified: Wednesday, March 04, 2020 6:09:36 PMWednesday, March 04, 2020 6:09:36 PMTime Spent:Time Spent: 00:03:1100:03:11IP Address:IP Address:

Page 1

Page 221: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

221 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

The department of the CIO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

all the time

Q11

7. How many MLOs do you employ?

none

Q12

8. How many of your MLOs conduct business from a branch location?

none

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

n/a

Q14

9. How many of your MLOs conduct business otherwise remotely?

n/a

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 222: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

222 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

simple requests that do not involve NPI

Q20

12b. Does your company use an API that captures those text messages?

probably

Page 223: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

223 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop, phone, tablet

Q2

1a. How are patches or security updates pushed out to remote devices?

Associates can generally get them through VPN, but some require the unit to be hard wired to the network in a bank branch or location.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

The employee's direct supervisor gathers it from the employee prior to departing from the company.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#75#75COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Tuesday, April 21, 2020 5:17:25 PMTuesday, April 21, 2020 5:17:25 PMLast Modified:Last Modified: Tuesday, April 21, 2020 5:21:16 PMTuesday, April 21, 2020 5:21:16 PMTime Spent:Time Spent: 00:03:5000:03:50IP Address:IP Address:

Page 1

Page 224: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

224 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Internal

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Constantly

Q11

7. How many MLOs do you employ?

Around 250

Q12

8. How many of your MLOs conduct business from a branch location?

Most - Probably 200

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

50

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 225: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

225 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Basic text communication only. No data, etc.

Q20

12b. Does your company use an API that captures those text messages?

No

Page 226: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

226 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops

Q2

1a. How are patches or security updates pushed out to remote devices?

Remote updates are distributed

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Company has ability to remote wipe and requires the return of all equipment immediately upon termination.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#76#76COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Wednesday, April 22, 2020 8:50:26 AMWednesday, April 22, 2020 8:50:26 AMLast Modified:Last Modified: Wednesday, April 22, 2020 9:28:15 AMWednesday, April 22, 2020 9:28:15 AMTime Spent:Time Spent: 00:37:4900:37:49IP Address:IP Address:

Page 1

Page 227: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

227 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Information Officer with Chief Compliance Officer, COO

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Annually

Q11

7. How many MLOs do you employ?

700

Q12

8. How many of your MLOs conduct business from a branch location?

700

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

10

Q14

9. How many of your MLOs conduct business otherwise remotely?

0

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 228: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

228 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 229: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

229 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptops

Q2

1a. How are patches or security updates pushed out to remote devices?

I believe that is all completed through our corporate IT dept and installs when we log in or out for the day.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Returned to the branch management and then our IT dept will swipe the computers.

Q4

2. Does your company keep physical records at anybranch?

No

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

No

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#77#77COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, April 23, 2020 10:11:50 AMThursday, April 23, 2020 10:11:50 AMLast Modified:Last Modified: Thursday, April 23, 2020 10:19:27 AMThursday, April 23, 2020 10:19:27 AMTime Spent:Time Spent: 00:07:3600:07:36IP Address:IP Address:

Page 1

Page 230: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

230 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Our corporate office has a CIO and we have annual security training like BSA and others that are taken through online learning.

Q10

6. How often does the company conduct a risk assessment of its information security systems?

At least once a year but my thought is that they are constantly monitoring all of our ISS.

Q11

7. How many MLOs do you employ?

14

Q12

8. How many of your MLOs conduct business from a branch location?

14

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

0

Q14

9. How many of your MLOs conduct business otherwise remotely?

14

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

No

Page 231: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

231 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Communication between borrowers, agents and within the office.

Q20

12b. Does your company use an API that captures those text messages?

Yes Google Hangouts.

Page 232: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

232 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

EHL provides Laptop home setups with Mitel phones with either VPN and or Virtual Desktop.

Q2

1a. How are patches or security updates pushed out to remote devices?

All patches are pushed out with EHL's Kace Appliance by Quest.

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

All equipment is requested by IT with options for Fedex shipping and or to bring back to the Manager to ship back to EHL Home Office.

Q4

2. Does your company keep physical records at anybranch?

Respondent skipped this question

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

No

#78#78INCOMPLETEINCOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Thursday, April 23, 2020 12:55:21 PMThursday, April 23, 2020 12:55:21 PMLast Modified:Last Modified: Thursday, April 23, 2020 1:12:58 PMThursday, April 23, 2020 1:12:58 PMTime Spent:Time Spent: 00:17:3700:17:37IP Address:IP Address:

Page 1

Page 233: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

233 / 237

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

Q8

5. Does the company have a Chief Information Officer(CIO)?

No

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Chief Risk Officer

Q10

6. How often does the company conduct a risk assessment of its information security systems?

Once per year

Q11

7. How many MLOs do you employ?

Respondent skipped this question

Q12

8. How many of your MLOs conduct business from abranch location?

Respondent skipped this question

Q13

8a. How many of those MLOs conduct business from abranch location that is the MLO’s resident?

Respondent skipped this question

Q14

9. How many of your MLOs conduct business otherwiseremotely?

Respondent skipped this question

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 234: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

234 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

Respondent skipped this question

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

No

Q19

12a. Describe the activity MLOs are allowed to conductthrough text messaging with borrower.

Respondent skipped this question

Q20

12b. Does your company use an API that captures thosetext messages?

Respondent skipped this question

Page 235: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

235 / 237

Q1

1. Describe what type of devices the Company provides employees to use for remote work. (laptop, phone, desktop,tablet, etc.)

Laptop and phone

Q2

1a. How are patches or security updates pushed out to remote devices?

Though dou

Q3

1b. How are company resources returned upon employee termination? (What happens to company issued equipment?)

Return product via mail and terminate log on creditable

Q4

2. Does your company keep physical records at anybranch?

Yes

Q5

3. Does the company use a cloud-based repository? Ifyes, answer 3a. If no, skip to 4.

Yes

Q6

3a. If yes, do the MLOs conduct business directly into thecloud?

Yes

Q7

4. Does the company have written policies and proceduresgoverning the use of electronic data?

Yes

#79#79COMPLETECOMPLETE

Collector:Collector: Web Link 1 Web Link 1 (Web Link)(Web Link)Started:Started: Monday, March 01, 2021 7:31:19 PMMonday, March 01, 2021 7:31:19 PMLast Modified:Last Modified: Monday, March 01, 2021 7:33:40 PMMonday, March 01, 2021 7:33:40 PMTime Spent:Time Spent: 00:02:2100:02:21IP Address:IP Address:

Page 1

Page 236: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

236 / 237

Q8

5. Does the company have a Chief Information Officer(CIO)?

Yes

Q9

5a. Who in the organization is in charge of the company’s information security policies and procedures?

Compliance

Q10

6. How often does the company conduct a risk assessment of its information security systems?

2 times a month

Q11

7. How many MLOs do you employ?

50

Q12

8. How many of your MLOs conduct business from a branch location?

20

Q13

8a. How many of those MLOs conduct business from a branch location that is the MLO’s resident?

20

Q14

9. How many of your MLOs conduct business otherwise remotely?

20

Q15

10. Must MLOs access the company mainframe via aVPN or similar system when collecting, storing, or workingwith a borrower’s PII or other sensitive information?

Yes

Page 237: Consumer Loan Act and Mortgage Broker Practices Act …

Consumer Loan Act and Mortgage Broker Practices Act Survey on Technology Use

237 / 237

Q16

11. Do your MLOs keep physical records? If yes, answer11a. If no, skip to 12.

No

Q17

11a. If yes, describe what types of records MLOs keep

Respondent skipped this question

Q18

12. Does your company allow MLOs to conduct businessvia text messages? If yes, answer 12a. and 12b.

Yes

Q19

12a. Describe the activity MLOs are allowed to conduct through text messaging with borrower.

Documents

Q20

12b. Does your company use an API that captures those text messages?

No