The Three Core Components of a Dealership Compliance Program
Key takeaways
- A dealership compliance program needs three core components: education, auditing, and cybersecurity.
- Employee education should cover OSHA, DOT certifications, forklift safety, customer data handling, and Title VII HR training.
- Internal self-auditing is not effective; a compliance program needs someone who physically visits the store to audit it.
- Cybersecurity compliance requires more than just a penetration test and a vulnerability scan.
- Dealerships lacking these three components should consider other compliance program options.
Summary
A workable compliance program rests on three core components, not a single checklist item. Employee education has to cover multiple areas at once: OSHA requirements, DOT certifications, forklift safety, proper handling of customer data, and the Title VII series of HR courses. Beyond training, the store needs an ongoing auditing process, and it cannot be handled purely in-house, since staff reviewing their own work will not catch what an outside, independent audit would find. A compliance program that never physically visits the store to check its work is not a solid one.
The third leg is cyber security, treated as its own serious discipline rather than a formality. A periodic pen test and vulnerability scan check a couple of boxes but do not add up to real protection on their own. For a dealership principal, GM, or F&I director, the takeaway is direct: if your current program is missing education, independent auditing, or genuine cyber security, it has a gap. Dealerships lacking any of these three pieces are encouraged to contact ARMP to discuss stronger options.
Transcript
Introduction to compliance program essentials
Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners. I want to talk to you today about what it takes to create a compliance program. And I don't mean — I'm not going to get into all the intricacies and the elaborate pieces of it, but I want to lay down a couple of things that you have to have in order to have a good compliance program.
Employee education requirements
Number one, you have to have education. You got to make sure that you're educating your employees, and that education is around a number of different things. You have education that needs to be done in the OSHA environment, with the DOT certifications, forklift safety, I mean I can go on and on. You also need to make sure that you're training your staff on how to handle customer data. You want to make sure that you have Title VII, you know, the whole Title VII series of courses that you need to do for your HR programs. So there's a host of educational processes, or educational things, that you need to do, or that you have to have in place.
The need for an auditing process
You also need to have an auditing process. You need to audit, and if you're going to do it internally, God knock your socks off, I guess. It's so important to understand that the fox guarding the hen house isn't going to work in this environment. You can't internally audit yourself effectively. And you have to understand that if you don't have a compliance program that physically walks into your store, then you don't have a solid compliance program. You really don't.
Cybersecurity as a core component
The third piece that you need to have in all of this is you need to have a solid, solid cyber security piece of all of this. So there's three different, there's three different real strong components that have to be in your compliance arsenal. That cyber security piece, it needs to be more than just a pen test and a vulnerability scan. I get it, that's a couple of boxes you can check off, but there's more to it than that.
Closing call to action
I'm telling you right now, if you don't have those components with your current compliance program, then you need to look at some other options. Please give us a call. Information is right here on the screen. Thanks, take care.
Questions this video answers
What are the core pieces every dealership compliance program needs?
A solid compliance program needs three core components: employee education, an auditing process, and a strong cybersecurity piece. Without all three in place, the speaker says you don't have a solid compliance program and should look at other options.
What kind of employee education should a compliance program include?
Education should cover OSHA requirements, DOT certifications, forklift safety, handling of customer data, and Title VII courses for HR programs, among other topics, according to the transcript.
Can a dealership audit its own compliance program internally?
The speaker says internal auditing isn't effective because the fox guarding the hen house doesn't work in this environment. A compliance program needs someone who physically walks into the store to audit it.
Is a penetration test enough for dealership cybersecurity compliance?
No, the speaker states the cybersecurity piece needs to be more than just a pen test and a vulnerability scan. Those are a couple of boxes you can check off, but there is more to it than that.
Read more on this
-
Dealership F&I Compliance Audit
An F&I compliance audit reviews a sample of completed deal jackets against the consumer finance rules that govern them: Truth in Lending and Regulation Z, ECOA...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- OSHA
- DOT certifications
- Title VII
- cybersecurity
- penetration testing
- compliance auditing