Feature Compliance Strategy
Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.
The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.
Table of Contents
TL;DR
- The FDIC’s 2026 Consumer Compliance Supervisory Highlights covers 2025 exam findings: 1,155 total violations across 825 institutions
- Five statutes drove 75% of all violations: TILA/Reg Z (462), EFTA/Reg E (136), Flood Disaster Protection Act (131), TISA/Reg DD (74), and HMDA/Reg C (72)
- 16 formal enforcement actions generated ~$150M in orders and $1.2B in required restitution
- The five-statute pattern holds year over year — if your compliance testing doesn’t cover these areas explicitly, that’s your gap
Every year, compliance teams brace for the FDIC’s Consumer Compliance Supervisory Highlights. Every year, the same five statutes appear at the top of the violation list. And every year, institutions that got dinged are surprised — because the violations weren’t exotic. They were disclosure formatting, error investigation timelines, flood insurance gaps, account advertising accuracy, and HMDA data quality.
The FDIC’s 2026 Consumer Compliance Supervisory Highlights covers exams conducted in 2025. FDIC-supervised institutions had 1,155 violations cited across approximately 825 consumer compliance exams. Five statutes generated 75% of them. If your compliance program isn’t actively testing against these five areas, you’re not managing your exam risk — you’re hoping the examiner doesn’t look too closely.
The Five Statutes and What the Violations Actually Look Like
1. Truth in Lending Act (TILA) / Regulation Z — 462 Violations
TILA/Reg Z leads the list by a wide margin: 462 citations, roughly 40% of all consumer compliance violations in 2025. The statute requires accurate, standardized disclosure of credit terms — APR, finance charge, amount financed, total of payments — in a format borrowers can understand before they sign.
The most common violations involve institutions failing to provide required information in their cost-of-credit disclosures. That sounds narrow. It isn’t. Regulation Z applies to mortgage loans, home equity products, auto loans, credit cards, BNPL structures, and many fintech credit products. Each product type has its own format, timing, and content requirements. The more product lines an institution runs, the more disclosure touchpoints there are — and the more places a disclosure template can quietly drift out of compliance.
For fintechs operating through bank partners: if your bank partner originates credit products on your platform, your disclosure templates are what the FDIC examiner will review. A Reg Z finding at the bank level traces directly to your disclosure design. The 462 violations in 2025 are a signal that this is an area where even compliant-looking programs have gaps.
What to test: Pull 25 credit disclosures across your product types and verify that every required element is present, accurate, and in the right format. Focus on TILA disclosures for closed-end credit, periodic statement requirements for credit cards, and change-in-terms notice requirements for variable-rate products.
2. Electronic Fund Transfer Act (EFTA) / Regulation E — 136 Violations
Regulation E governs electronic fund transfers — debit card transactions, ACH payments, peer-to-peer transfers, and similar products. The second most common violation category in 2025 was EFTA, with 136 citations.
The bulk of Regulation E violations came from how institutions handled error investigations. The regulation sets specific timelines: provisional credit generally must be given within 10 business days if you need more time to investigate; investigations must be completed within 45 business days (90 days for some international transfers and new accounts); and the consumer must be notified of the result within three business days of completing the investigation.
These aren’t complex standards. They fail in practice because error investigation processes often involve multiple teams (fraud, operations, customer service), and no one has clear ownership of the timeline. Provisional credit gets skipped or delayed. Investigation results don’t generate the required consumer notice. Disputed transactions get coded incorrectly and fall out of the investigation workflow entirely.
For neobanks and payments fintechs: Regulation E error resolution is frequently where bank partner examinations find fintech-driven violations. If your customer service team is handling dispute resolution, they’re handling Regulation E compliance — whether they know it or not.
What to test: Pull the last 30 disputed transaction investigations and map each one against the provisional credit timeline, investigation completion timeline, and consumer notification requirement. The timeline failures will be immediately visible.
3. Flood Disaster Protection Act (FDPA) — 131 Violations
The Flood Disaster Protection Act requires financial institutions to obtain flood insurance for loans secured by improved real property in a Special Flood Hazard Area (SFHA). The FDIC consistently cites flood violations because flood insurance gaps are a structural monitoring problem, not a knowledge problem.
The most frequently cited FDPA violation: institutions extending loans secured by properties in designated flood zones without verifying or requiring flood insurance. This happens because flood zone determinations are made at origination — but properties can be remapped into SFHAs after closing. Institutions that don’t have ongoing monitoring for collateral in remapped flood zones end up with coverage gaps they can’t see until an examiner runs the geographic check.
The $150 million in formal enforcement orders the FDIC issued in 2025 were primarily for flood insurance violations and FTC Act unfair practices. Flood violations generate civil money penalties, not just remediation requirements. And the civil money penalties for flood violations are assessed per loan, per day — they scale with the number of uninsured properties and the length of the gap.
What to test: Run a portfolio-level flood zone check for all real-estate-secured loans against current FEMA SFHA maps. Confirm that insurance is in place and adequate (not just obtained at origination). Flag any property that was remapped after closing and document your remediation plan.
4. Truth in Savings Act (TISA) / Regulation DD — 74 Violations
Regulation DD governs how deposit accounts are marketed and what disclosures must accompany interest rate advertising. The 74 TISA violations in 2025 cluster around two issues: account advertising that fails to include required disclosures (particularly for bonus rates, promotional APYs, and tier-based rates), and periodic statement or account opening disclosure deficiencies.
For community banks and digital banks running deposit products: the APY calculation and advertising requirements are where errors concentrate. When marketing teams promote interest rates without including required disclosures — or when the advertised rate applies only to specific balance tiers and that’s not disclosed — the Reg DD violation is in the marketing artifact itself, not in the back-office operations.
What to test: Pull every active marketing piece that references deposit interest rates. For each one, verify the required Reg DD disclosures are present and that the advertised rate matches the rate in the account agreement.
5. Home Mortgage Disclosure Act (HMDA) / Regulation C — 72 Violations
HMDA requires financial institutions to collect, report, and disclose data about mortgage lending activity. The 72 violations in 2025 fall into two categories: data integrity problems (incorrect or missing HMDA data fields) and coverage issues (not reporting all required applications and originations).
HMDA data quality is an area where the FDIC is coordinating with the CFPB — HMDA data is publicly available and used for fair lending analysis, so accuracy matters beyond the examination context. A HMDA data quality finding can also surface a fair lending follow-up review if the examiner determines that the inaccuracies mask a pattern worth investigating.
What to test: Run a pre-submission HMDA data audit comparing your LAR to your loan origination system. Focus on application date, action taken date, ethnicity/race/sex data completeness, loan purpose coding, and denial reasons.
The Examination Pattern and What It Means
The 97% satisfactory-or-better overall rating in 2025 is the headline most institutions cite when this report drops. But 75% of violations concentrated in five statutes is a different signal. It means these aren’t obscure regulatory requirements — they’re foundational consumer protections with established, documented compliance frameworks. Institutions that get cited are usually missing something operational: a disclosure template that wasn’t updated, an error investigation process that wasn’t tested, a flood monitoring workflow that was never built.
The 16 formal enforcement actions in 2025 are also worth noting. Informal actions (11 of them) get resolved without public visibility. Formal actions — consent orders, civil money penalties — create public records and require board-level commitment to remediation timelines. The $1.2 billion in required restitution is the aggregate cost of violations that went undetected long enough to build up across thousands of affected customers.
So What?
The FDIC publishes its supervisory highlights so that institutions can adjust their compliance programs before the next exam cycle. The five-statute pattern is a direct signal about where examiner attention concentrates. If your compliance testing calendar doesn’t include explicit annual reviews of TILA disclosure accuracy, Reg E investigation timelines, flood portfolio monitoring, Reg DD advertising accuracy, and HMDA data quality — it should.
This isn’t advanced compliance work. It’s the table stakes that 25% of examined institutions didn’t have right in 2025.
For compliance officers building or maintaining a testing program: the KRI Library has pre-built compliance monitoring metrics including Regulation E error investigation rates, HMDA data error rates, and flood insurance coverage tracking — the kind of ongoing visibility that lets you catch these issues before the examiner does.
If you already have a compliance testing program but aren’t tracking violations to remediation systematically, the fintech consumer compliance roadmap covers how to build the regulatory mapping underlying this work. And the Q2 2026 enforcement trends post shows how these exam findings connect to the formal enforcement actions that follow when they aren’t addressed.
The Most Common Mistake: Testing at Origination, Not at Scale
Compliance programs typically test disclosure accuracy at origination — they review a new product launch, validate the disclosure template, and sign off. What they don’t test is whether the disclosure template drifted over the subsequent 18 months as marketing updated the website, product teams changed the fee structure, and IT updated the loan origination system.
TILA and Reg DD violations are often not in the original template. They’re in the version that went live six months later when someone made a change without compliance review. Building a disclosure change management process that routes product and marketing changes through compliance is as important as the initial review.
For Regulation E and HMDA, the equivalent issue is data pipeline drift. The error investigation process that worked correctly in 2024 may have broken when the customer service platform was migrated. The HMDA data feed that was accurate in Q1 may have started producing errors after a system update. Ongoing monitoring — not just annual review — is what catches these before they accumulate.
Relevant regulatory source: FDIC Consumer Compliance Supervisory Highlights (2026)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What were the five most frequently cited consumer compliance violations in FDIC exams in 2025?
How serious were the FDIC's enforcement actions in 2025?
What specific TILA/Reg Z failures is the FDIC citing most often?
Are these FDIC compliance findings relevant for fintechs, or just banks?
Why do flood insurance violations keep appearing in FDIC exams year after year?
What should my compliance program do with the FDIC's top violation list?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Compliance Strategy
CFPB and CFTC Self-Reporting Policies: A 2026 Decision Guide
Compare the CFPB and CFTC self-reporting policies, penalty-credit rules, and evidence needed for a defensible disclosure decision.
Aug 17, 2026
Compliance Strategy
FTC Debanking Warning Letters: What PayPal and Stripe Were—and Were Not—Told
The FTC Chair sent warning letters to PayPal, Stripe, Visa, and Mastercard. They flag potential Section 5 risk but do not adjudicate a violation.
Aug 12, 2026
Compliance Strategy
FINRA Is Still Barring Brokers Over Text Messages. Here's What the Off-Channel Enforcement Split Means for Your Records Program.
The SEC ended its off-channel enforcement wave after 95 cases and $2.3 billion in penalties. FINRA didn't follow. While the SEC pivoted to fraud and fiduciary cases, FINRA fined BTIG $600,000 and started barring individuals from the industry. Here's what the divergence means for broker-dealer compliance programs.
Aug 7, 2026