On March 31, 2026, the FDIC released its Spring 2026 edition of Consumer Compliance Supervisory Highlights[1]. It is intended to promote transparency and awareness of consumer compliance risks and supervisory priorities identified through their examination and supervision activities. In 2025, FDIC examiners cited 1,155 violations, with just five statutes accounting for 75% of them.
|
Truth in Lending Act (TILA) / Regulation Z
|
462 Violations (40% of all findings)
|
|
Electronic Fund Transfer Act (EFTA) / Regulation E
|
136 Violations (12% of all findings)
|
|
Flood Disaster Protection Act (FDPA)
|
131 Violations (11% of all findings)
|
|
Truth in Savings Act (TISA) / Regulation DD
|
74 Violations (6% of all findings)
|
|
Home Mortgage Disclosure Act (HMDA) / Regulation C
|
72 Violations (6% of all findings)
|
What follows is a breakdown of the most cited violations, the regulatory context driving exam scrutiny, and practical recommendations banks can proactively take to reduce violation exposure.
Truth in Lending Act (TILA) / Regulation Z
TILA and Regulation Z require lenders to provide clear, timely, and accurate disclosures so borrowers understand the true cost of credit. The most frequently cited violations arise when lenders fail to provide required mortgage disclosures correctly or within mandated timeframes, including:
- Failure to provide good‑faith estimates in Loan Estimates.
- Failure to provide required loan cost breakdowns in Closing Disclosures.
- Missing payment summaries, APR, finance charge, and total interest percentage on mortgage disclosures.
These breakdowns often stem from process gaps, system errors, or insufficient quality control during origination and closing. Because mortgage disclosures directly affect consumers’ understanding of financial obligations, TILA violations are viewed as high‑risk and can result in restitution or enforcement actions when consumers are harmed. In addition, TILA failures can increase a bank’s legal exposure under UDAP/UDAAP for misleading or incomplete disclosures.
How Banks Can Reduce TILA/Reg Z Violations
- Strengthen disclosure workflows by implementing system validations for timing rules and running completeness checks.
- Conduct pre‑closing monitoring to detect missing or incorrect disclosures.
- Ensure LOS and doc-prep system configurations are updated and reconciled periodically.
- Enhance training for lending staff that focuses on fee-tolerance rules, timing triggers, and redisclosure requirements.
Electronic Fund Transfer Act (EFTA) / Regulation E
EFTA and Regulation E establish consumer protections for electronic fund transfers, including debit card transactions, ATM withdrawals, and electronic bill payments. Most EFTA violations involved error investigation requirements, particularly:
- Failure to investigate alleged EFT errors within required timeframes.
- Failure to provide required notices when no error is found.
These two sections represented 74% of all EFTA violations. These failures often reflect weak case‑management practices, poor oversight of third‑party processors, or inadequate employee training. Regulators place significant emphasis on these requirements because delays or errors can leave consumers without access to funds and undermine confidence in electronic payment systems. Failure to properly investigate errors can also create large restitution exposure.
How Banks Can Reduce EFTA/Regulation E Violations
- Centralize error dispute processing by having a dedicated Reg E team or unified case‑management workflow.
- Develop standardized investigation protocols.
- Establish mechanisms to ensure timeframes are met. Use SLA dashboards and automated reminders.
- Use templates with that contain required elements.
Flood Disaster Protection Act (FDPA)
The FDPA requires lenders to ensure that appropriate flood insurance coverage is in place when loans are secured by buildings located in designated special flood hazard areas. The most common violation was a failure to ensure flood insurance was in place whenever a loan on a property in a special flood hazard area was made, increased, extended, or renewed. This issue represented 41% of all FDPA violations.
These findings often result from breakdowns in flood determinations, coverage tracking, or insurance lapse monitoring. FDPA violations draw heightened regulatory concern because flood damage can cause severe consumer financial loss, and civil money penalties for noncompliance can be substantial even when actual flood events have not occurred. FDPA failures frequently lead to material violations that result in enforcement actions.
How Banks Can Reduce FDPA Violations
- Integrate flood‑zone lookups into LOS/core systems.
- Implement real‑time monitoring of MIRE (Make, Increase, Renew, Extend) events.
- Use automated lapse monitoring with alerts before policy expiration.
- Enhance training for lending and servicing teams.
Truth in Savings Act (TISA) / Regulation DD
TISA and Regulation DD focus on transparency and accuracy in deposit account disclosures. Violations commonly involve inaccurate or incomplete disclosures regarding interest rates, annual percentage yield, fees, transaction limitations, or bonus terms. Violations of this nature accounted for 61% of all TISA violations.
These issues may occur when product terms are updated but disclosures are not revised consistently across channels, including branch materials, websites, and digital account opening platforms. Regulators view TISA violations as consumer‑impacting because misleading or incomplete information can affect consumers’ decisions about where and how to hold their funds and lead to unexpected fees or reduced earnings. Deposit account disclosures are central to consumer transparency. Inaccuracies can lead to misleading advertising claims and increase UDAP/UDAAP exposure.
How Banks CanReduce TISA/Regulation DD Violations
- Standardize deposit disclosures across digital, branch, and call center channels.
- Validate rate and fee tables at each change.
- Perform a compliance review of marketing materials.
- Enhance digital banking oversight to ensure consistency.
Home Mortgage Disclosure Act (HMDA) / Regulation C
HMDA and Regulation C require financial institutions to collect, report, and publicly disclose detailed data about mortgage lending activity. The most cited violations involve missing, inaccurate, or incomplete data fields in loan application records, such as borrower demographics, loan purpose, action taken, or property information, vital information required by Regulation C. These issues represented 82% of HMDA violations.
These errors often occur due to weak data governance, misconfigured loan origination systems, or insufficient validation controls. Because HMDA data supports fair lending analysis, community investment oversight, and public transparency, regulators scrutinize data accuracy closely and expect strong internal controls throughout the data lifecycle.
HMDA is fundamental to fair lending oversight. Data inaccuracies can signal potential discrimination risks and inaccurate public disclosures.
How Banks Can Reduce HMDA/Reg C Violations
- Strengthen data capture controls at origination and validate before application submission.
- Conduct quarterly HMDA scrubs of key fields.
- Ensure HMDA data mapping sources are clearly defined.
Strengthening CMS to Reduce Regulatory Risk
The FDIC’s most frequently cited violations are not new, but their persistence signals a deeper challenge: regulatory risk often stems less from a lack of rules knowledge and more from weaknesses in execution, oversight, and governance. Disclosure inaccuracies, error‑resolution breakdowns, flood insurance gaps, and data integrity issues typically arise where processes intersect, across systems, vendors, and responsibility levels.
Beyond the most cited violations, the FDIC’s report highlights several broader supervisory themes that elevate overall compliance risk, including robust enforcement activity, with 16 formal and 11 informal actions resulting in approximately $150 million in civil money penalties, as well as significant restitution, totaling $1.2 billion ordered and an additional $4.7 million in voluntary refunds to consumers. The report also points to growing third‑party provider (TPP) risk, with consumer complaints involving TPPs increasing 48 percent year over year, reinforcing regulatory expectations for stronger vendor oversight, accountability, and overall compliance management system (CMS) maturity.
Managing these risks effectively requires more than periodic testing or point‑in‑time fixes. Institutions need compliance programs that are risk‑based, operationally embedded, and resilient to change, especially as digital delivery models and third‑party relationships expand.
Whether preparing for an upcoming exam, responding to supervisory findings, or modernizing compliance infrastructure, we partner with institutions to reduce regulatory risk while supporting operational efficiency. Guidepost experts focus on helping banks move from reactive remediation to sustainable compliance management, by:
- Assessing CMS maturity across governance, monitoring, testing, and issue management.
- Identifying root causes behind recurring regulatory findings.
- Strengthening disclosure controls, data governance, and compliance workflows.
- Enhancing third‑party oversight aligned with regulatory expectations.
- Designing practical, regulator‑ready remediation plans that align with business operations.
The consistency of these findings across examination cycles suggests that the underlying risk is structural, not incidental. Disclosure failures, error resolution gaps, flood coverage lapses, and data integrity issues tend to recur where compliance oversight is fragmented or where accountability for cross-functional processes is unclear. That is the problem worth solving before the next exam cycle begins.
[1] Consumer Compliance Supervisory Highlights Spring 2026