I've been performing and managing compliance audits for several years at Brown Edwards, and before that I spent about 15 years working in banking. That dual perspective — seeing things from the banker's side as well as the auditor's side — shapes how I approach these topics. And that context is exactly why I find the consumer compliance regulatory landscape so worth paying attention to right now. At our most recent Spring quarterly banking update, I walked through current regulatory hot buttons and how internal audit can help banks get ahead of them. Here's a summary of what I covered.
These aren't just buzzwords. Regulatory hot buttons represent repeat, systemic exam issues — violations that tend to recur year after year across institutions. When the FDIC releases its Consumer Compliance Supervisory Highlights each year, the top five most-cited regulations look remarkably similar from one year to the next. One regulation might fall off the list and another appear, but the core areas of examiner focus stay relatively consistent.
Why? Because these are the areas most likely to cause consumer harm. They often involve basic regulatory requirements that are frequently misunderstood or inconsistently applied, and they are commonly tied to weak compliance management system execution, vendor oversight gaps, and training breakdowns. Critically, internal audit is expected to identify these risks independently — before examiners walk in the door.
The most recent FDIC Consumer Compliance Supervisory Highlights — the spring 2026 version, covering approximately 825 FDIC consumer compliance exams conducted in 2025 — offered some important data points. The good news: 98% of institutions received satisfactory or outstanding ratings. The not-so-good news: violations remain heavily concentrated in a small number of areas. Just five regulations accounted for approximately 75% of all cited violations across the entire set of exams.
The breakdown among those top five:
For internal audit planning purposes, the message is clear: focus testing resources on these five areas, particularly TILA, Regulation E, and Flood, where examiner scrutiny is highest and where the consequences of noncompliance can be significant.
Across the institutions that had findings, the FDIC identified a consistent set of root causes worth noting:
One point I want to highlight for institutions using vendor-assisted underwriting: if your vendor is using AI in that process, your due diligence obligation extends to ensuring that AI is not introducing discrimination issues. Fair lending risk doesn't disappear just because a third party is doing the work.
Flood has remained a top compliance finding for years, and the Federal Reserve's first 2026 Consumer Compliance Outlook dedicated an article specifically to it. There are three primary issue categories noted in the Federal Reserve article.
Issue #1: Insufficient flood insurance at origination. The most common driver of this finding is coverage not being in place at the time of closing — typically because the closing date shifted during the process and no one updated the effective date of the flood insurance policy to match. Banks need a control in the pre-closing process specifically designed to verify that the effective flood insurance date is on or before the closing date. The other main issue is an incorrect insurance amount, usually due to calculation errors.
The required flood insurance amount is the least of three values: the outstanding loan balance, the NFIP building maximum, and the insurable value of the property. If contents are taken as collateral, that must be factored into the calculation as well — an often-overlooked requirement on commercial loans. And insurable value must be based on replacement cost, not market value; confusing the two is a frequent examiner finding. When you have multiple properties or buildings securing a single loan, the calculations become more complex. I'd recommend reviewing the second issue, 2022 Consumer Compliance Outlook article titled 'Commercial Flood Insurance Compliance: Washing Away Common Pitfalls' for detailed guidance on those scenarios.
Issue #2: Failure to provide timely borrower flood notices. When a property is determined to be in a flood zone, the bank must provide a notice to the borrower within a reasonable time before the completion of the transaction. Regulators generally regard 10 calendar days as reasonable, though the regulation itself is silent on an exact number. More importantly, this obligation is triggered not just at loan origination but at every MIRE event — a loan that is Made, Increased, Renewed, or Extended. Flood zones can change, particularly following natural disasters, and every triggering event requires the bank to re-evaluate flood zone status.
Issue #3: Failure to identify coverage lapses and force-place insurance. If flood insurance lapses on a loan in a flood zone, the process is specific: the bank must provide written notice to the borrower giving them 45 days to obtain or increase flood insurance. If they don't, force placement occurs on day 46 or later — not before. Force-placed insurance can be backdated to the lapse date, but it cannot be placed prior to that 46th day. And the bank should be listed as the mortgagee in the flood policy — ensuring this is correct from loan origination is how the bank receives lapse notifications in the first place.
The FDIC and Federal Reserve identify examiner-observed causes. From our own work in the field, I'd add a few more:
Regulation E moved from fourth to second on the FDIC's most-cited list, and the Federal Reserve dedicated a Consumer Compliance Outlook article to error resolution under this regulation as well. The core issue is straightforward but frequently mishandled: when a consumer contacts the bank — orally or in writing — to report an unauthorized transaction or an error, the bank's investigation obligation begins immediately. The bank can request written confirmation of an oral notice, but it cannot delay the investigation pending receipt of that confirmation.
From that first contact, the clock starts ticking. In most cases the bank has 10 business days to complete its investigation. If it cannot finish within 10 business days, it must provide provisional credit to the consumer and then has an extended period to finalize the result. The heavy consumer-complaint exposure here is real: if the bank doesn't resolve an error quickly or to the consumer's satisfaction, the consumer may file a complaint with the CFPB or another agency, which then feeds directly into exam focus.
Common examiner findings under Regulation E include:
Root causes here tend to be staff misunderstanding of the technical timeline requirements, incorrect assumptions about how merchant disputes are handled under Reg E, third-party templates that are missing required disclosures, a lack of secondary review of dispute decisions, and weak compliance review feedback loops overall.
Whether your internal audit function is in-house, outsourced, or a hybrid, there are several practical steps that should be part of any compliance audit program right now:
Most hot button findings involve breakdowns in compliance basics — not exotic or obscure regulatory requirements. Flood and Regulation E remain at high risk and are areas where examiners expect internal audit to have detected issues early. Vendor reliance needs to be actively managed, not assumed. Life-of-loan controls are critical for flood compliance. And strong audit coverage is one of the most effective tools a bank has to reduce exam surprises.
The regulatory landscape is shifting — that's clear from every conversation I have with bank management teams and examiners alike. The direction feels somewhat more bank-friendly than it has in recent years, but that doesn't mean the fundamentals of compliance management have become less important. If anything, staying ahead of known examiner focus areas becomes even more critical as the environment evolves.