Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Compliance Strategy

Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.

The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.

By Rebecca Leung · August 18, 2026 ·
Table of Contents

TL;DR

  • The FDIC’s 2026 Consumer Compliance Supervisory Highlights covers 2025 exam findings: 1,155 total violations across 825 institutions
  • Five statutes drove 75% of all violations: TILA/Reg Z (462), EFTA/Reg E (136), Flood Disaster Protection Act (131), TISA/Reg DD (74), and HMDA/Reg C (72)
  • 16 formal enforcement actions generated ~$150M in orders and $1.2B in required restitution
  • The five-statute pattern holds year over year — if your compliance testing doesn’t cover these areas explicitly, that’s your gap

Every year, compliance teams brace for the FDIC’s Consumer Compliance Supervisory Highlights. Every year, the same five statutes appear at the top of the violation list. And every year, institutions that got dinged are surprised — because the violations weren’t exotic. They were disclosure formatting, error investigation timelines, flood insurance gaps, account advertising accuracy, and HMDA data quality.

The FDIC’s 2026 Consumer Compliance Supervisory Highlights covers exams conducted in 2025. FDIC-supervised institutions had 1,155 violations cited across approximately 825 consumer compliance exams. Five statutes generated 75% of them. If your compliance program isn’t actively testing against these five areas, you’re not managing your exam risk — you’re hoping the examiner doesn’t look too closely.

The Five Statutes and What the Violations Actually Look Like

1. Truth in Lending Act (TILA) / Regulation Z — 462 Violations

TILA/Reg Z leads the list by a wide margin: 462 citations, roughly 40% of all consumer compliance violations in 2025. The statute requires accurate, standardized disclosure of credit terms — APR, finance charge, amount financed, total of payments — in a format borrowers can understand before they sign.

The most common violations involve institutions failing to provide required information in their cost-of-credit disclosures. That sounds narrow. It isn’t. Regulation Z applies to mortgage loans, home equity products, auto loans, credit cards, BNPL structures, and many fintech credit products. Each product type has its own format, timing, and content requirements. The more product lines an institution runs, the more disclosure touchpoints there are — and the more places a disclosure template can quietly drift out of compliance.

For fintechs operating through bank partners: if your bank partner originates credit products on your platform, your disclosure templates are what the FDIC examiner will review. A Reg Z finding at the bank level traces directly to your disclosure design. The 462 violations in 2025 are a signal that this is an area where even compliant-looking programs have gaps.

What to test: Pull 25 credit disclosures across your product types and verify that every required element is present, accurate, and in the right format. Focus on TILA disclosures for closed-end credit, periodic statement requirements for credit cards, and change-in-terms notice requirements for variable-rate products.

2. Electronic Fund Transfer Act (EFTA) / Regulation E — 136 Violations

Regulation E governs electronic fund transfers — debit card transactions, ACH payments, peer-to-peer transfers, and similar products. The second most common violation category in 2025 was EFTA, with 136 citations.

The bulk of Regulation E violations came from how institutions handled error investigations. The regulation sets specific timelines: provisional credit generally must be given within 10 business days if you need more time to investigate; investigations must be completed within 45 business days (90 days for some international transfers and new accounts); and the consumer must be notified of the result within three business days of completing the investigation.

These aren’t complex standards. They fail in practice because error investigation processes often involve multiple teams (fraud, operations, customer service), and no one has clear ownership of the timeline. Provisional credit gets skipped or delayed. Investigation results don’t generate the required consumer notice. Disputed transactions get coded incorrectly and fall out of the investigation workflow entirely.

For neobanks and payments fintechs: Regulation E error resolution is frequently where bank partner examinations find fintech-driven violations. If your customer service team is handling dispute resolution, they’re handling Regulation E compliance — whether they know it or not.

What to test: Pull the last 30 disputed transaction investigations and map each one against the provisional credit timeline, investigation completion timeline, and consumer notification requirement. The timeline failures will be immediately visible.

3. Flood Disaster Protection Act (FDPA) — 131 Violations

The Flood Disaster Protection Act requires financial institutions to obtain flood insurance for loans secured by improved real property in a Special Flood Hazard Area (SFHA). The FDIC consistently cites flood violations because flood insurance gaps are a structural monitoring problem, not a knowledge problem.

The most frequently cited FDPA violation: institutions extending loans secured by properties in designated flood zones without verifying or requiring flood insurance. This happens because flood zone determinations are made at origination — but properties can be remapped into SFHAs after closing. Institutions that don’t have ongoing monitoring for collateral in remapped flood zones end up with coverage gaps they can’t see until an examiner runs the geographic check.

The $150 million in formal enforcement orders the FDIC issued in 2025 were primarily for flood insurance violations and FTC Act unfair practices. Flood violations generate civil money penalties, not just remediation requirements. And the civil money penalties for flood violations are assessed per loan, per day — they scale with the number of uninsured properties and the length of the gap.

What to test: Run a portfolio-level flood zone check for all real-estate-secured loans against current FEMA SFHA maps. Confirm that insurance is in place and adequate (not just obtained at origination). Flag any property that was remapped after closing and document your remediation plan.

4. Truth in Savings Act (TISA) / Regulation DD — 74 Violations

Regulation DD governs how deposit accounts are marketed and what disclosures must accompany interest rate advertising. The 74 TISA violations in 2025 cluster around two issues: account advertising that fails to include required disclosures (particularly for bonus rates, promotional APYs, and tier-based rates), and periodic statement or account opening disclosure deficiencies.

For community banks and digital banks running deposit products: the APY calculation and advertising requirements are where errors concentrate. When marketing teams promote interest rates without including required disclosures — or when the advertised rate applies only to specific balance tiers and that’s not disclosed — the Reg DD violation is in the marketing artifact itself, not in the back-office operations.

What to test: Pull every active marketing piece that references deposit interest rates. For each one, verify the required Reg DD disclosures are present and that the advertised rate matches the rate in the account agreement.

5. Home Mortgage Disclosure Act (HMDA) / Regulation C — 72 Violations

HMDA requires financial institutions to collect, report, and disclose data about mortgage lending activity. The 72 violations in 2025 fall into two categories: data integrity problems (incorrect or missing HMDA data fields) and coverage issues (not reporting all required applications and originations).

HMDA data quality is an area where the FDIC is coordinating with the CFPB — HMDA data is publicly available and used for fair lending analysis, so accuracy matters beyond the examination context. A HMDA data quality finding can also surface a fair lending follow-up review if the examiner determines that the inaccuracies mask a pattern worth investigating.

What to test: Run a pre-submission HMDA data audit comparing your LAR to your loan origination system. Focus on application date, action taken date, ethnicity/race/sex data completeness, loan purpose coding, and denial reasons.

The Examination Pattern and What It Means

The 97% satisfactory-or-better overall rating in 2025 is the headline most institutions cite when this report drops. But 75% of violations concentrated in five statutes is a different signal. It means these aren’t obscure regulatory requirements — they’re foundational consumer protections with established, documented compliance frameworks. Institutions that get cited are usually missing something operational: a disclosure template that wasn’t updated, an error investigation process that wasn’t tested, a flood monitoring workflow that was never built.

The 16 formal enforcement actions in 2025 are also worth noting. Informal actions (11 of them) get resolved without public visibility. Formal actions — consent orders, civil money penalties — create public records and require board-level commitment to remediation timelines. The $1.2 billion in required restitution is the aggregate cost of violations that went undetected long enough to build up across thousands of affected customers.

So What?

The FDIC publishes its supervisory highlights so that institutions can adjust their compliance programs before the next exam cycle. The five-statute pattern is a direct signal about where examiner attention concentrates. If your compliance testing calendar doesn’t include explicit annual reviews of TILA disclosure accuracy, Reg E investigation timelines, flood portfolio monitoring, Reg DD advertising accuracy, and HMDA data quality — it should.

This isn’t advanced compliance work. It’s the table stakes that 25% of examined institutions didn’t have right in 2025.

For compliance officers building or maintaining a testing program: the KRI Library has pre-built compliance monitoring metrics including Regulation E error investigation rates, HMDA data error rates, and flood insurance coverage tracking — the kind of ongoing visibility that lets you catch these issues before the examiner does.

If you already have a compliance testing program but aren’t tracking violations to remediation systematically, the fintech consumer compliance roadmap covers how to build the regulatory mapping underlying this work. And the Q2 2026 enforcement trends post shows how these exam findings connect to the formal enforcement actions that follow when they aren’t addressed.

The Most Common Mistake: Testing at Origination, Not at Scale

Compliance programs typically test disclosure accuracy at origination — they review a new product launch, validate the disclosure template, and sign off. What they don’t test is whether the disclosure template drifted over the subsequent 18 months as marketing updated the website, product teams changed the fee structure, and IT updated the loan origination system.

TILA and Reg DD violations are often not in the original template. They’re in the version that went live six months later when someone made a change without compliance review. Building a disclosure change management process that routes product and marketing changes through compliance is as important as the initial review.

For Regulation E and HMDA, the equivalent issue is data pipeline drift. The error investigation process that worked correctly in 2024 may have broken when the customer service platform was migrated. The HMDA data feed that was accurate in Q1 may have started producing errors after a system update. Ongoing monitoring — not just annual review — is what catches these before they accumulate.


Relevant regulatory source: FDIC Consumer Compliance Supervisory Highlights (2026)

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What were the five most frequently cited consumer compliance violations in FDIC exams in 2025?
The five most frequently cited violations were: (1) Truth in Lending Act (TILA)/Regulation Z — 462 violations, most commonly around cost of credit disclosure requirements; (2) Electronic Fund Transfer Act (EFTA)/Regulation E — 136 violations, mostly error investigation failures; (3) Flood Disaster Protection Act (FDPA) — 131 violations, most commonly failing to obtain flood insurance on collateral in designated flood zones; (4) Truth in Savings Act (TISA)/Regulation DD — 74 violations; and (5) Home Mortgage Disclosure Act (HMDA)/Regulation C — 72 violations. Together these five statutes represented 75% of all 1,155 violations cited in FDIC consumer compliance exams in 2025.
How serious were the FDIC's enforcement actions in 2025?
Significant. The FDIC brought 16 formal enforcement actions and 11 informal enforcement actions to address examination findings. Formal orders totaled approximately $150 million — primarily addressing flood insurance violations under the Flood Disaster Protection Act and unfair acts or practices under Section 5 of the FTC Act. Additionally, the FDIC required approximately $1.2 billion in restitution through formal orders, while supervised institutions also provided $4.7 million in voluntary restitution to 47,902 consumers.
What specific TILA/Reg Z failures is the FDIC citing most often?
The most common TILA/Regulation Z violations involve institutions failing to provide required information in credit cost disclosures — the disclosure of APR, finance charges, amount financed, and total payments in a form borrowers can understand. FDIC examiners also cite deficiencies in periodic statements, credit card disclosures, and HELOC change-in-terms notices. The volume (462 citations in 2025) reflects how many disclosure touchpoints Reg Z creates across different product types, each with its own format requirements.
Are these FDIC compliance findings relevant for fintechs, or just banks?
Relevant for both. Fintechs with bank partners are effectively operating under the same statutory framework — the bank partner is examined, but findings often trace to the fintech's product design, disclosure templates, error resolution processes, and data reporting. If your bank partner gets a TILA or Reg E finding traced to your product, you will be asked to remediate it. Fintechs operating under state licenses face analogous state consumer protection statutes that mirror the federal regimes.
Why do flood insurance violations keep appearing in FDIC exams year after year?
Flood insurance violations are persistent for a structural reason: they are triggered by geography (a collateral property in a Special Flood Hazard Area) rather than borrower choice, and they require cross-checking between loan origination, servicing, and insurance data at multiple points in the loan lifecycle. Most institutions that fail the Flood Disaster Protection Act don't know they're out of compliance — they have coverage gaps in their monitoring, not intentional evasion. The violation is also easy for examiners to document because it's binary: flood insurance was either obtained or it wasn't.
What should my compliance program do with the FDIC's top violation list?
Use it as an exam prep checklist. Walk through each of the five statutes: test whether your TILA disclosures are accurate and complete for every product type; run a sample of your Reg E error investigations to confirm you're meeting the 45/90-day investigation timeline and provisional credit requirements; audit your loan portfolio for collateral in Special Flood Hazard Areas with verified insurance; and pull a HMDA data quality report before your next exam. These five areas are where FDIC examiners will focus — documenting your testing and findings in advance gives you a defensible record.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.