Regulatory Hot Buttons: What Examiners Are Finding — and How Internal Audit Can Get Ahead of It

I've been performing and managing compliance audits for several years at Brown Edwards, and before that I spent about 15 years working in banking. That dual perspective — seeing things from the banker's side as well as the auditor's side — shapes how I approach these topics. And that context is exactly why I find the consumer compliance regulatory landscape so worth paying attention to right now. At our most recent Spring quarterly banking update, I walked through current regulatory hot buttons and how internal audit can help banks get ahead of them. Here's a summary of what I covered.

Why Regulatory Hot Buttons Matter

These aren't just buzzwords. Regulatory hot buttons represent repeat, systemic exam issues — violations that tend to recur year after year across institutions. When the FDIC releases its Consumer Compliance Supervisory Highlights each year, the top five most-cited regulations look remarkably similar from one year to the next. One regulation might fall off the list and another appear, but the core areas of examiner focus stay relatively consistent.

Why? Because these are the areas most likely to cause consumer harm. They often involve basic regulatory requirements that are frequently misunderstood or inconsistently applied, and they are commonly tied to weak compliance management system execution, vendor oversight gaps, and training breakdowns. Critically, internal audit is expected to identify these risks independently — before examiners walk in the door.

What the FDIC's 2025 Consumer Compliance Exam Results Tell Us

The most recent FDIC Consumer Compliance Supervisory Highlights — the spring 2026 version, covering approximately 825 FDIC consumer compliance exams conducted in 2025 — offered some important data points. The good news: 98% of institutions received satisfactory or outstanding ratings. The not-so-good news: violations remain heavily concentrated in a small number of areas. Just five regulations accounted for approximately 75% of all cited violations across the entire set of exams.

The breakdown among those top five:

  • Truth in Lending Act (TILA): 40% of all cited violations — the single largest category, covering issues with loan estimates, closing disclosures, APR and finance charge accuracy, and required content and timing
  • Regulation E (Electronic Funds Transfer Act): 12% of all cited violations — notably, this moved up from fourth to second most cited since the prior year
  • Flood Disaster Protection Act: 11% of all cited violations — consistently high, and the subject of a dedicated Federal Reserve article
  • HMDA and Truth in Savings Act: 6% each

For internal audit planning purposes, the message is clear: focus testing resources on these five areas, particularly TILA, Regulation E, and Flood, where examiner scrutiny is highest and where the consequences of noncompliance can be significant.

Common Root Causes the FDIC Identified

Across the institutions that had findings, the FDIC identified a consistent set of root causes worth noting:

  • Policies not aligned with actual practices — having written procedures that don't reflect what staff are doing
  • Inadequate training in technical regulatory requirements — training should be role-specific; a teller's fair lending training looks very different from a loan officer's
  • Over-reliance on vendors without adequate controls — the bank remains ultimately responsible for compliance even when a third party is involved, and this includes AI tools that vendors may be using in underwriting or other processes
  • Insufficient monitoring and internal audit coverage
  • Weak change management processes

One point I want to highlight for institutions using vendor-assisted underwriting: if your vendor is using AI in that process, your due diligence obligation extends to ensuring that AI is not introducing discrimination issues. Fair lending risk doesn't disappear just because a third party is doing the work.

Deep Dive: Flood Disaster Protection Act

Flood has remained a top compliance finding for years, and the Federal Reserve's first 2026 Consumer Compliance Outlook dedicated an article specifically to it. There are three primary issue categories noted in the Federal Reserve article.

Issue #1: Insufficient flood insurance at origination. The most common driver of this finding is coverage not being in place at the time of closing — typically because the closing date shifted during the process and no one updated the effective date of the flood insurance policy to match. Banks need a control in the pre-closing process specifically designed to verify that the effective flood insurance date is on or before the closing date. The other main issue is an incorrect insurance amount, usually due to calculation errors.

The required flood insurance amount is the least of three values: the outstanding loan balance, the NFIP building maximum, and the insurable value of the property. If contents are taken as collateral, that must be factored into the calculation as well — an often-overlooked requirement on commercial loans. And insurable value must be based on replacement cost, not market value; confusing the two is a frequent examiner finding. When you have multiple properties or buildings securing a single loan, the calculations become more complex. I'd recommend reviewing the second issue, 2022 Consumer Compliance Outlook article titled 'Commercial Flood Insurance Compliance: Washing Away Common Pitfalls' for detailed guidance on those scenarios.

Issue #2: Failure to provide timely borrower flood notices. When a property is determined to be in a flood zone, the bank must provide a notice to the borrower within a reasonable time before the completion of the transaction. Regulators generally regard 10 calendar days as reasonable, though the regulation itself is silent on an exact number. More importantly, this obligation is triggered not just at loan origination but at every MIRE event — a loan that is Made, Increased, Renewed, or Extended. Flood zones can change, particularly following natural disasters, and every triggering event requires the bank to re-evaluate flood zone status.

Issue #3: Failure to identify coverage lapses and force-place insurance. If flood insurance lapses on a loan in a flood zone, the process is specific: the bank must provide written notice to the borrower giving them 45 days to obtain or increase flood insurance. If they don't, force placement occurs on day 46 or later — not before. Force-placed insurance can be backdated to the lapse date, but it cannot be placed prior to that 46th day. And the bank should be listed as the mortgagee in the flood policy — ensuring this is correct from loan origination is how the bank receives lapse notifications in the first place.

Root Causes We See at Brown Edwards — Beyond the Examiner List

The FDIC and Federal Reserve identify examiner-observed causes. From our own work in the field, I'd add a few more:

  • Little or no training specifically on the Flood Disaster Protection Act — for a regulation this complex, that is a significant gap
  • No backup or succession planning for flood — in smaller banks, often one person holds all the flood knowledge; if that person is out or leaves, the institution is exposed
  • Lack of detailed procedures — the person who has been handling flood for 20 years may not need written procedures, but the rest of the institution does
  • Inadequate tools for calculating minimum flood coverage and poor documentation of how insurable value was determined
  • Force-placing too much flood insurance — when force-placing, the bank is limited to the lesser of the three numbers mentioned above; contractual agreements at origination may allow for more, but force placement does not
  • Third-party vendor errors — we recently encountered a vendor that was sending required notices on day 45 rather than day 46, which constitutes a violation

Deep Dive: Regulation E — Error Resolution

Regulation E moved from fourth to second on the FDIC's most-cited list, and the Federal Reserve dedicated a Consumer Compliance Outlook article to error resolution under this regulation as well. The core issue is straightforward but frequently mishandled: when a consumer contacts the bank — orally or in writing — to report an unauthorized transaction or an error, the bank's investigation obligation begins immediately. The bank can request written confirmation of an oral notice, but it cannot delay the investigation pending receipt of that confirmation.

From that first contact, the clock starts ticking. In most cases the bank has 10 business days to complete its investigation. If it cannot finish within 10 business days, it must provide provisional credit to the consumer and then has an extended period to finalize the result. The heavy consumer-complaint exposure here is real: if the bank doesn't resolve an error quickly or to the consumer's satisfaction, the consumer may file a complaint with the CFPB or another agency, which then feeds directly into exam focus.

Common examiner findings under Regulation E include:

  • Failure to begin the investigation upon oral notice
  • Missing or late provisional credit
  • Failure to complete the investigation within the required timeframe
  • Inadequate written explanations when denying claims — denials need to be thoroughly documented
  • Improper reversal of provisional credit or poor documentation of timeliness

Root causes here tend to be staff misunderstanding of the technical timeline requirements, incorrect assumptions about how merchant disputes are handled under Reg E, third-party templates that are missing required disclosures, a lack of secondary review of dispute decisions, and weak compliance review feedback loops overall.

What Internal Audit Should Be Doing

Whether your internal audit function is in-house, outsourced, or a hybrid, there are several practical steps that should be part of any compliance audit program right now:

  • Make sure your compliance risk assessments treat these five heavily examined regulations as high risk — regardless of what other factors might suggest a lower residual risk score; examiner focus alone justifies elevated monitoring frequency.
  • Use exam manuals when building audit programs — I call this using the opponent's playbook. The FDIC Consumer Compliance Examination Manual and the Federal Reserve Consumer Compliance Handbook are publicly available and directly inform how examiners conduct exams. Why wouldn't you use those same tools?
  • Test actual practices against the regulation itself — not just against the bank's internal policies and procedures. Your policies could themselves be out of compliance. The regulation is the benchmark.
  • Don't rely solely on your bank's prior exam results — subscribe to regulatory updates and review supervisory highlights each year to understand what examiners are seeing across the industry, not just at your institution
  • Focus testing on third-party relationships — validate that vendors are staying in compliance and that the bank has adequate controls in place to catch vendor errors before they become exam findings
  • Consider increased frequency and depth of testing in flood and Regulation E — even if your risk assessment produces a moderate residual risk, the examiner scrutiny on these areas warrants heightened attention

Key Takeaways

Most hot button findings involve breakdowns in compliance basics — not exotic or obscure regulatory requirements. Flood and Regulation E remain at high risk and are areas where examiners expect internal audit to have detected issues early. Vendor reliance needs to be actively managed, not assumed. Life-of-loan controls are critical for flood compliance. And strong audit coverage is one of the most effective tools a bank has to reduce exam surprises.

The regulatory landscape is shifting — that's clear from every conversation I have with bank management teams and examiners alike. The direction feels somewhat more bank-friendly than it has in recent years, but that doesn't mean the fundamentals of compliance management have become less important. If anything, staying ahead of known examiner focus areas becomes even more critical as the environment evolves.

Contact Us

 

Back to Blog