Dealership Compliance Software

Dealership compliance software tracks a store's obligations under the FTC Safeguards Rule, OSHA, EPA, and F&I regulations in one system, with audit findings, employee training, vendor attestations, and cybersecurity monitoring tied to a single record. The distinction that matters when buying is whether the platform also performs the physical on-site audit or only stores what someone else found.

By Terry Dortch President, Automotive Risk Management Partners Last reviewed

What does dealership compliance software actually do?

A dealership carries obligations from at least four directions at once: the FTC Safeguards Rule for customer data, OSHA for workplace safety, EPA for waste and emissions, and the consumer finance rules governing the F&I office. Each generates its own paperwork, its own training requirement, and its own record retention expectation.

Compliance software exists to hold all of that in one record instead of four filing cabinets and a spreadsheet. In practice it should do five things: score where the store currently stands, track findings through to remediation, assign and expire employee training, hold vendor and document evidence, and produce the reports that regulators, lenders, and insurers ask for.

What separates real coverage from a checklist app?

Most of this category divides on one question: does the vendor come to the store?

A self-assessment tool sends a questionnaire. A general manager, usually on a busy day, answers it from memory. The platform scores the answers and produces a green dashboard. Nothing in that loop involves anyone looking at the shop floor, and a green score assembled that way is worth very little when a lender asks for evidence or an OSHA inspector arrives.

An assessment-led platform sends an auditor who walks the building, photographs findings, and records violations against a defined framework. The software is then the system of record for real findings rather than self-reported ones. That distinction is the single biggest determinant of whether the compliance record holds up under outside scrutiny.

Which regulations should a dealership platform cover?

AreaWhat has to be tracked
FTC Safeguards Rule (16 CFR 314)Written information security program, Qualified Individual, risk assessment, MFA, encryption, disposal schedule, incident response plan, annual report.
OSHA (29 CFR 1910, 1904)Hazard communication and SDS access, lockout/tagout, electrical safety, PPE, respiratory protection, emergency action plan, powered industrial truck certification, injury recordkeeping.
EPABody shop coating rules, used oil and hazardous waste handling, stormwater, spill prevention where oil storage thresholds are met, refrigerant handling certification.
F&I and consumer financeDeal file review against TILA/Regulation Z, ECOA/Regulation B adverse action, FCRA and Red Flags, Regulation M for leases, OFAC screening, and IRS Form 8300 cash reporting.
Employment and trainingRole-based training assignment, completion tracking, expiry and reassignment, plus state-specific requirements such as the Illinois and California harassment training rules.
CybersecurityVulnerability scanning, external exposure and open port visibility, continuous monitoring, and an archived report history.

What does a compliance score need to be worth reading?

Most platforms present a single number. A single number is only useful if you can see what it is made of and what moves it.

ARMP scores across five pillars — audit findings, cybersecurity, documentation, training, and vendor oversight — and snapshots the result over time so a store can see whether it is improving or drifting. That structure matters because the remedies are different. A store failing on training needs courses assigned and chased. A store failing on vendors needs attestations collected. Rolling both into one number tells the general manager that something is wrong without telling them what to do on Monday.

What should a dealership group expect that a single store does not?

Groups have a scoping problem before they have a compliance problem. A platform used across rooftops needs to answer three questions cleanly:

  • Who sees what. A store manager should see their rooftop. A general manager over three stores should see three. Ownership should see all of them without switching accounts.
  • Is the framework the same everywhere. Comparing rooftops is meaningless if each one was audited against a different checklist.
  • Can the group report as a group. Ownership and lenders ask about the group, not about store four.

ARMP handles this with store-level scoping and per-location grading inside a single tenant, so the group view and the store view come from the same underlying audit data.

What questions should you ask a vendor before signing?

  1. Do your own auditors come on site, and how often after the initial assessment?
  2. Is the initial assessment a physical walkthrough or a questionnaire?
  3. Which of the nine Safeguards Rule elements does the platform produce evidence for, and which does it assume we already have?
  4. Do you supply the written information security program document, or only a template?
  5. Does the cybersecurity component satisfy 314.4(d) through continuous monitoring, or do we still owe an annual penetration test?
  6. How do vendor attestations get collected, and what happens when a vendor ignores the request?
  7. Can we export our own audit history and training records if we leave?
  8. Who is liable if your assessment misses something?

Question three separates the field faster than any other. Many platforms in this space are strong on training and weak on everything the Safeguards Rule asks for outside training.

How ARMP is put together

ARMP is a single-vendor program rather than a software subscription with services attached. The parts are:

  • On-site assessment. An auditor performs the initial physical compliance assessment, typically one to two days depending on store size, then returns for shorter reviews through the year.
  • Audit frameworks. Separate OSHA, GLBA, and body shop audit types, each scored against its own violation library, with findings tracked to remediation and overdue items escalated.
  • Generated manuals. The information security program, OSHA manual, compliance management system, and Red Flags program produced as maintained documents rather than blank templates.
  • Training. Course assignment by role and department, quizzes, certificates, expiry, and automatic reminders.
  • Vendor oversight. A hosted attestation form, signature capture, and automated follow-up for vendors who have not responded.
  • Cybersecurity. Ridgeback continuous network monitoring plus vulnerability, external IP exposure, and open port scanning with an archived report history.
  • Deal jacket review. Structured F&I file audits by purchase type and vehicle type, scored server-side.

Related guides

Frequently asked questions

What should dealership compliance software cover?

At minimum: the FTC Safeguards Rule information security program, OSHA general industry requirements, EPA obligations including body shop and waste rules, F&I deal file review, employee training with expiry tracking, vendor oversight, and either continuous network monitoring or scheduled penetration testing. A platform covering only one of these leaves the dealership assembling the rest from other vendors and reconciling the results by hand.

Is compliance software enough on its own, or is an on-site audit still needed?

Software alone cannot see the shop. Blocked exits, missing eyewash stations, unlabelled secondary containers, an open deal jacket on an unattended desk, and an unsecured server closet are physical findings. A platform that only collects self-reported answers records what staff believe is true. An assessment performed on site by an auditor records what is actually true, which is the version that matters after an incident.

How much does dealership compliance software cost?

Pricing in this market is normally quoted per rooftop and varies with which modules are included, how many employees need training seats, and whether on-site audits and network monitoring hardware are bundled. Because scope differs so widely between vendors, per-rooftop list prices are rarely comparable without mapping exactly what each quote covers. ARMP quotes after an initial assessment scope call rather than publishing a list price.

Can one platform handle a multi-rooftop dealership group?

It should. A group needs per-store scoping so a manager sees only their rooftop, consolidated reporting so ownership sees every store at once, and the ability to run the same audit framework consistently across locations. Groups that run separate single-store tools per rooftop end up unable to answer a simple question from the board about how the group as a whole is doing.

Does compliance software replace the Qualified Individual?

No. 16 CFR 314.4(a) requires a named person, and software is not a person. What a platform can do is give that individual the evidence they need to do the job and to produce the annual written report: current audit findings, open remediations, training completion, vendor attestations, and monitoring results in one place instead of five.