How to Prepare for a CFPB UDAAP Examination: A Step-by-Step Checklist for Community Banks

How to Prepare for a CFPB UDAAP Examination: A Step-by-Step Checklist for Community Banks

Community banks can cut UDAAP exam risk by following a 10-step pre-exam checklist that aligns governance, policies, testing, and vendor oversight. The CFPB evaluates unfair, deceptive, and abusive acts or practices using a fact-intensive standard that often turns on documentation and execution. This article provides a step-by-step, examination-ready roadmap—plus examples, common pitfalls, and a practical file-by-file preparation plan.

CFPB UDAAP examinations are rarely about a single “bad” document. They typically focus on whether a bank’s end-to-end consumer experience—marketing, disclosures, servicing, collections, and complaint handling—creates consumer harm, unreasonable risk of harm, or misleading impressions. For community banks, the most effective approach is to prepare like examiners prepare: map products, identify consumer touchpoints, validate what customers are told, and prove controls work in practice.

Below is a step-by-step checklist designed for community banks and credit-focused institutions preparing for a UDAAP-focused review (whether led by the CFPB directly, a prudential regulator, or a state authority applying similar standards). Use it as a structured workplan in the 60–120 days before an anticipated exam, and as a standing program framework if no exam is scheduled.

1) Confirm the UDAAP legal standard and define “UDAAP risk” for your bank

UDAAP is a facts-and-circumstances standard. Your preparation should start by aligning internal stakeholders on how UDAAP is evaluated and what evidence matters.

Key UDAAP concepts to align internally

Unfair: Likely to cause substantial consumer injury that is not reasonably avoidable and not outweighed by countervailing benefits.

Deceptive: A representation, omission, or practice that is likely to mislead a reasonable consumer, and is material.

Abusive: Interferes with a consumer’s ability to understand a term/condition, or takes unreasonable advantage of a consumer’s lack of understanding, inability to protect interests, or reasonable reliance on the bank.

Deliverable

Create a one-page internal “UDAAP Risk Definition” memo that includes (i) your product lines, (ii) highest-risk consumer touchpoints, and (iii) the documents and systems that demonstrate control (policies, training, testing, change management, vendor oversight, and complaint analytics).

2) Build an exam-ready governance file (board to frontline)

Examiners look for clear ownership, consistent reporting, and proof that leadership acts on risk. Your governance file should be ready to send within 24–48 hours of a request.

Checklist: governance artifacts to compile

Board and committee oversight: minutes, compliance reports, approval of policies, tracking of corrective actions, and escalation protocols.

UDAAP policy and standards: current version, prior versions, and effective dates; cross-references to marketing, complaints, servicing, collections, and vendor management.

Management reporting: KPIs/KRIs for complaints, disputes, charge-offs, fee reversals, exceptions, and marketing review throughput.

Issue management: logs showing identified issues, root cause analysis, remediation, and validation.

Common pitfall

A bank has “good policies” but cannot show they are implemented—no tracking of exceptions, no trend reporting, and no evidence that the board is informed of repeat problems (e.g., recurring fee disputes).

3) Perform a product and fee inventory—with a UDAAP lens

UDAAP exams often zero in on fees, add-ons, and “surprise” outcomes. A product inventory should identify what consumers pay, when they pay it, and how it is communicated.

What to inventory

Products: deposits, consumer loans, credit cards (if any), overdraft/NSF programs, debt protection, and any third-party add-ons.

Fee universe: overdraft/NSF, late fees, convenience fees, payoff statement fees, stop payment, account research, wire/ACH, dormancy/inactivity, and returned item fees.

Trigger logic: how the fee is assessed (system rule, manual process, vendor calculation, timing cutoffs).

Testing tip

Pull 30–50 real transactions per high-risk fee type and recreate the fee assessment using system logs and account notes. Examiners like to see that the fee charged matches your account agreement, your disclosures, and your system configuration.

4) Review marketing and disclosures for “net impression” consistency

Many deceptive practice findings are based on the overall net impression—not a single sentence. Marketing, branch scripts, call center practices, and digital UX should all align with disclosures and actual servicing behavior.

Marketing/disclosure checklist

Substantiation: rate/fee claims, “no fee” claims, and “instant/guaranteed” approval language supported by documented criteria.

Clear qualifications: material limits (e.g., “no overdraft fees” but a separate NSF fee exists; “0% APR” but only for a short promo window).

Digital journeys: screenshots of web and mobile flows showing where material terms appear and whether they are easy to find and understand.

Consistency: scripts and FAQs match account agreements and servicing rules.

Example red flag

An ad says “Get paid 2 days early” but the deposit timing depends on employer file submission and the bank’s posting window; the qualification is buried or absent. That can create a misleading net impression if consumers reasonably interpret the claim as guaranteed.

5) Audit servicing, collections, and error-resolution workflows

UDAAP risk increases when a bank’s back-office processes produce repeat consumer harm—especially when consumers cannot reasonably avoid the injury due to system design or operational constraints.

Servicing and collections areas to test

Payment processing: cutoffs, posting order, partial payments, and how payments are allocated among principal, interest, and fees.

Force-placed or collateral-related processes (if applicable): notices, timing, refunds, and vendor controls.

Loss mitigation and hardship: consistent criteria, clear communications, and tracking of approvals/denials.

Collections communications: scripts, call monitoring, frequency caps, and dispute handling.

Error resolution: how disputes are logged, investigated, and closed; communication templates; re-aging practices where relevant.

Practical sample plan

For each high-risk workflow, select a small but defensible sample (e.g., 25 accounts) including: (i) the highest fees, (ii) repeat complaints, (iii) manual overrides, and (iv) vulnerable-customer indicators where identified (e.g., seniors, limited English proficiency, disability accommodation requests).

6) Stress-test your complaint management program

Complaints are one of the fastest ways examiners identify UDAAP themes. Your program must capture, categorize, investigate, remediate, and trend—not just close tickets.

Complaint program checklist

Intake coverage: branch, call center, email, online forms, social media, BBB, attorney letters, and regulator referrals.

Taxonomy: consistent categories (fees, payments, credit reporting, marketing, servicing, fraud, account closures).

Timelines: SLAs for acknowledgment and resolution; escalation triggers for repeat or severe harm.

Root cause and trend: monthly analysis with documented actions and follow-ups.

Remediation: fee reversals, account corrections, negative reporting corrections, and customer communications—tracked and validated.

Examiner expectation

Be prepared to show a “complaint-to-control” link: how a complaint trend changed a script, a system rule, a disclosure, a training module, or a vendor SLA.

7) Validate third-party and fintech oversight end-to-end

Community banks often face UDAAP exposure through service providers: marketing firms, lead generators, core processors, payment platforms, BNPL-like partners, debt protection vendors, and call center vendors. Examiners typically view the bank as responsible for outcomes.

Vendor oversight checklist

Due diligence: licensing, compliance history, complaint history, and UDAAP controls.

Contract terms: audit rights, data access, complaint sharing, performance standards, and approval rights for marketing and consumer communications.

Ongoing monitoring: call monitoring results, QA sampling, complaint metrics, and remediation SLAs.

Change management: a process for approving new campaigns, scripts, fees, or servicing changes before launch.

Example red flag

A lead generator uses comparison charts that omit material conditions (e.g., minimum balance, monthly maintenance fees, eligibility criteria). If the bank cannot evidence review and approval, the bank may inherit the deceptive practice risk.

8) Implement UDAAP testing: transaction-level and “consumer journey” testing

Testing should mimic how consumers experience the product, not just whether disclosures exist. Combine two methods:

Transaction testing

Validate whether the fee/charge/interest was assessed correctly and consistently with agreements and system logic. Document exceptions and root causes.

Consumer journey testing

Walk through the product as a customer would: advertisement → application → approval/denial → account opening → first statement → common servicing events (payment, overdraft, dispute, closure). Capture screenshots, call recordings, emails, and letters.

Deliverable

Create a “UDAAP Testing Binder” with sampling methodology, results, exception tracking, and remediation validation. This becomes exam-ready evidence that your compliance management system is proactive.

9) Prepare your exam response package (what you can produce fast)

Exams move quickly when the bank can produce clean, organized materials. Your goal is speed, completeness, and consistency.

Core exam package documents

Scroll to Top