CFPB Audits
Notice: No webinar is currently available in this series.
This webinar is not currently available, new dates coming soon.
Frequently Asked Questions
The Consumer Financial Protection Bureau (CFPB) is a U.S. federal regulatory agency established by the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 with the mission of protecting consumers in the financial marketplace by preventing unfair, deceptive, or abusive acts and practices (UDAAP). The CFPB has supervisory authority over a broad range of entities that offer consumer financial products and services. Large depository institutions—banks, credit unions, and thrifts with assets over $10 billion—are subject to direct CFPB examination. Nonbank financial entities in designated markets are also subject to supervision regardless of size, including mortgage servicers and originators, private student lenders, payday lenders, larger participants in consumer debt collection and consumer reporting markets, and remittance transfer providers. The CFPB also has enforcement authority over all entities subject to federal consumer financial protection laws, regardless of whether they are subject to regular examination. For finance professionals at covered institutions, understanding which consumer financial protection laws the CFPB enforces—including TILA, RESPA, ECOA, FCRA, FDCPA, and UDAAP—and how CFPB examination procedures are structured is essential preparation for supervisory engagement and proactive compliance program management.
A CFPB examination is a structured supervisory process through which CFPB examiners review a financial institution's compliance with federal consumer financial protection laws. The examination process typically begins with a pre-examination information request: the CFPB sends a detailed document request covering policies and procedures, sample loan or account files, complaint logs, training materials, organizational charts, and prior examination findings. Institutions should expect to provide responsive, organized documentation that demonstrates a functioning compliance management system (CMS)—the CFPB's primary evaluation framework. During the on-site phase, examiners conduct interviews with compliance and operations staff, review transaction samples for regulatory compliance, test disclosures against applicable standards, and evaluate the institution's complaint management process. The CFPB's examination process focuses heavily on UDAAP risk—evaluating not just whether the institution has complied with specific disclosure requirements but whether its overall practices, marketing, and servicing could be considered unfair, deceptive, or abusive to consumers. Following the examination, the CFPB provides a report of examination outlining findings. Serious deficiencies may result in a matter requiring attention (MRA), a memorandum of understanding (MOU), or an enforcement action with potential civil money penalties. Proactive preparation—particularly a strong, documented compliance management system—significantly influences examination outcomes.
A Compliance Management System (CMS) is the framework through which a financial institution identifies, assesses, controls, and monitors its compliance with consumer financial protection laws. The CFPB's examination framework evaluates the quality of an institution's CMS as the primary indicator of compliance risk—an institution with a strong CMS that promptly identifies and corrects compliance issues is viewed more favorably than one that is technically compliant at a point in time but lacks the systemic controls to sustain compliance over time. The CFPB's CMS framework evaluates four components: Board and management oversight—the governance structure, tone at the top, and accountability mechanisms for compliance; Compliance program—written policies and procedures, staff training, compliance monitoring and testing, and product review processes; Consumer complaint response—how the institution captures, investigates, resolves, and tracks consumer complaints and uses complaint data to identify systemic issues; and Compliance audit—the independent audit function's scope, methodology, and follow-up on findings. An institution whose CMS demonstrates that compliance is actively managed, not just periodically checked, and that issues are identified and corrected before they result in consumer harm, is in the strongest position to achieve favorable examination outcomes and minimize the risk of formal enforcement action.
CFPB examination findings cluster around several recurring themes that financial institutions can proactively address through their compliance programs. UDAAP violations—unfair, deceptive, or abusive acts and practices—are the broadest and most consequential finding category, often arising from marketing materials that overstate benefits or obscure material terms, servicing practices that put consumers at a disadvantage, or fee structures that consumers could not reasonably anticipate. Fair lending violations under ECOA and HMDA arise from disparate treatment or disparate impact in underwriting, pricing, or marketing that disadvantages protected class borrowers, often surfaced through statistical analysis of application and origination data. Weak complaint management—failing to capture, investigate, and resolve consumer complaints systematically—is a frequent finding that the CFPB views as a proxy for overall compliance program quality. Disclosure accuracy violations under TILA, RESPA, and other specific statutes are identified through transaction file testing. Insufficient training programs, outdated policies not reflecting regulatory changes, and inadequate compliance monitoring are systemic findings that lead to broader corrective action requirements. Financial institutions can prepare by conducting regular self-assessments against these categories, performing statistical fair lending analyses, auditing disclosure accuracy, and ensuring their complaint management system produces actionable compliance insights rather than simply tracking resolution of individual complaints.
CFPB enforcement actions carry significant financial and reputational consequences for covered institutions, and understanding the range of potential outcomes motivates the proactive compliance investment that prevents them. Civil money penalties are the most direct monetary consequence: the CFPB's civil penalty authority under Dodd-Frank is tiered by culpability—up to $5,000 per day for violations of federal consumer financial law, up to $25,000 per day for reckless violations, and up to $1,000,000 per day for knowing violations. In addition to penalties, enforcement orders typically require consumer redress—reimbursement to consumers harmed by the violation—which can be the largest component of total financial exposure if the affected practice was widespread or long-running. Consent orders and administrative orders impose ongoing compliance obligations, reporting requirements, enhanced monitoring, and program remediation mandates that consume significant management and compliance resources over their multi-year terms. Reputational damage from public enforcement actions—which are publicly announced and widely covered in trade media—affects customer and partner relationships, talent recruitment, and regulatory relationships with other supervisory agencies. For publicly traded institutions, enforcement actions can affect stock price and analyst coverage. The CFPB's pattern of pursuing high-profile, precedent-setting enforcement actions makes proactive compliance investment clearly more cost-effective than reactive remediation after enforcement.