Dealership F&I Compliance Audit

An F&I compliance audit reviews a sample of completed deal jackets against the consumer finance rules that govern them: Truth in Lending and Regulation Z, ECOA and Regulation B adverse action, FCRA and Red Flags, Regulation M for leases, OFAC screening, and IRS Form 8300 cash reporting. It is a file review, sampled by purchase type and vehicle type, not a questionnaire.

By Terry Dortch President, Automotive Risk Management Partners Last reviewed

What is an F&I compliance audit?

It is a review of completed deal files against the rules that governed them at the moment they were written. Unlike a safety audit, nothing about it is observable by walking the building: the evidence is entirely in the jackets, physical or digital.

The purpose is twofold. First, it finds process failures while they are still cheap — a missing adverse action notice found in a review costs nothing, the same gap found in litigation does not. Second, it produces the record that lenders, manufacturers, and insurers increasingly ask to see when they want to know whether a store polices its own F&I office.

Which regulations does an F&I audit test against?

RuleWhat the file must show
Truth in Lending Act / Regulation ZAccurate credit disclosures on retail installment transactions — amount financed, finance charge, APR, payment schedule, total of payments.
Consumer Leasing Act / Regulation MLease disclosures, including amount due at signing, payment schedule, and early termination terms.
ECOA / Regulation BAdverse action notice where credit was declined, withdrawn, or granted on terms other than those requested, delivered within the required timeframe.
FCRAPermissible purpose for pulling credit, and the risk-based pricing notice or credit score disclosure exception notice.
FCRA Red FlagsIdentity verification performed and documented under the store's written identity theft prevention program.
GLBA privacyPrivacy notice provided, and the file handled under the store's information security program.
OFACScreening against the Specially Designated Nationals list, with evidence retained.
IRS Form 8300Filed where cash received exceeded the reporting threshold, including related structured payments.
FTC Act Section 5 and state UDAPNo deceptive advertising of price or payment; add-ons charged only with informed consent.

Why sample by deal type rather than at random?

Because the required documents differ by deal type, and so do the failures. A cash deal has no Regulation Z disclosure but may well have a Form 8300 obligation. A lease is governed by Regulation M rather than Z. A declined finance application triggers adverse action duties that never arise on a cash sale.

A random sample from a store that writes mostly finance deals will be mostly finance deals, and a broken lease process can sit undetected for a year. Structuring the sample across purchase type — cash, finance, lease — and vehicle type — new, used — forces coverage of every combination the store actually writes.

ARMP builds deal jacket review this way, showing only the questions tagged to the selected purchase and vehicle type, and scoring server-side so the weighting cannot be adjusted at the point of entry.

What does the audit produce?

Three outputs, and the third is the one that changes behaviour:

  1. A score by deal type, so a store can see that finance is clean and lease is not.
  2. A findings list tied to specific files and specific requirements.
  3. Assigned remediation with a due date and escalation when it goes overdue.

Reviews that stop at the first two get filed and forgotten. The remediation loop is what turns a quarterly file review into a process change in the F&I office.

How does F&I compliance connect to the Safeguards Rule?

The F&I office holds the densest concentration of customer nonpublic personal information in the building: full credit applications with Social Security numbers, dates of birth, and income. That makes it simultaneously the highest-value target for the Safeguards Rule risk assessment and the department most likely to fail on physical controls.

The recurring physical findings are deal jackets stored in an unlocked room, jackets left on desks overnight, workstations left signed in, and retention well beyond the two-year disposal expectation at 16 CFR 314.4(c)(6). None of these are F&I regulatory failures in the consumer finance sense, and all of them are Safeguards failures, which is why the two reviews belong in the same program.

An F&I audit checklist

  1. Pull a sample covering cash, finance, and lease, across new and used.
  2. Confirm each file has the disclosures its deal type requires, signed and dated.
  3. Check every declined or counter-offered application for a timely adverse action notice.
  4. Verify the risk-based pricing or credit score disclosure was provided.
  5. Confirm OFAC screening evidence is in the file, not merely performed.
  6. Confirm Red Flags identity verification is documented.
  7. Check menu presentation is evidenced so every customer was offered the same products on the same terms.
  8. Review cash transactions for Form 8300 obligations, including structured payments.
  9. Confirm the privacy notice was provided.
  10. Inspect where jackets are physically stored and who can reach them.
  11. Check retention against the disposal schedule.
  12. Assign remediation with owners and dates, then verify closure at the next review.

Related guides

Frequently asked questions

What does an F&I audit actually look at?

Completed deal jackets. An auditor pulls a sample spanning cash, finance, and lease deals across new and used vehicles, then checks each file for the documents and disclosures that deal type requires: the credit application, the retail installment contract or lease agreement, required federal disclosures, the adverse action notice where credit was declined or terms were worsened, the risk-based pricing or credit score disclosure, the privacy notice, OFAC screening evidence, Red Flags identity verification, and Form 8300 where cash exceeded the reporting threshold.

How many deals should be reviewed?

Enough to cover every deal type the store actually writes, because the failure modes differ. A file review that samples twenty finance deals and no leases proves nothing about the lease process. ARMP structures deal jacket review by purchase type — cash, finance, lease — crossed with new and used, so each combination is represented and scored rather than averaged into a single number that hides a broken lease workflow.

Is the FTC CARS Rule still in effect?

No. The FTC's Combating Auto Retail Scams Rule was vacated by the US Court of Appeals for the Fifth Circuit in January 2025, so it does not currently impose obligations on dealers. The underlying conduct it targeted — deceptive advertising of price and payment, charges for add-ons without consent, and misrepresenting the cost of optional products — remains actionable under Section 5 of the FTC Act and state UDAP statutes. Confirm the current status before relying on this, as it has changed before.

Who should perform the F&I audit?

Someone other than the person who wrote the deals. A finance manager reviewing their own jackets reproduces the same blind spots that created the gaps. The review needs independence, whether that means a compliance officer at a group, a rotation between rooftops, or an outside auditor. Independence is also what makes the result credible to a lender asking how the store polices itself.

What are the most common F&I file findings?

Missing or late adverse action notices when an application was declined or counter-offered. Incomplete OFAC screening evidence. Red Flags identity verification performed but not documented in the file. Menu presentation not evidenced, so there is no record every customer was offered products on the same terms. Form 8300 not filed where structured cash payments crossed the threshold. And signature and date gaps that make an otherwise correct file unprovable.