Consumer compliance
The Compliance group of the sidebar holds the surfaces a consumer-compliance officer is examined on: the CMS scorecard, Complaints, Disclosures and Marketing reviews, with HMDA and CRA under their own heading, Fair lending & CRA. Each one is an oversight register. Zovos watches the program and produces the evidence, while the systems of record for case handling, filing and origination stay where they are.
The CMS scorecard
The CMS scorecard reads your compliance management system the way the CFPB's compliance management review does, in four pillars: board and management oversight, the compliance program, consumer complaint response, and compliance audit. Every score is computed from your registers, and there is no field anyone can type a score into. Each pillar is shown with the metric table behind it, each metric states which registers it reads and by what rule, and a metric whose inputs you have not populated is shown as a gap rather than hidden. A pillar's score is the plain average of its scored metrics, with no weighting. Each metric links through to the records behind it.
Exam binder (PDF) exports the scorecard sealed. Consumer-compliance exam package assembles one sealed ZIP from the scorecard and the complaint, marketing review, training, HMDA and CRA exports, so the first-day letter for a consumer examination is one download. The copy served to an examiner withholds the complaint register, which holds consumer personal information, and its manifest lists that section as withheld.
Complaint oversight
Complaints arrive by import from your system of record. Import complaints takes a CSV or an Excel workbook, and a validate only checkbox previews exactly what would land without saving any of it. Tick it on the first pass, because an unticked import lands immediately. Each complaint carries a category, the regulation implicated, a status, and links out to a Finding, Control, Policy or Citation. Its root cause is picked from your institution's root-cause list rather than typed free, so the distribution counts like with like.
Complaints that reach you through a portal or referral carry that channel's response clocks, and the screen publishes the timeline table it uses. CFPB company-portal complaints owe an initial response within fifteen calendar days of routing and a final response within sixty. A prudential-regulator referral owes one written response, customarily within thirty calendar days. A BBB referral owes an answer within fourteen days and closure within thirty, and the screen labels that as a reputational deadline rather than a regulatory one. Each clock reads on track, due soon, missed or met, on the register, in the complaint drawer, in the analytics headline, on the obligations calendar and in the exam binder. Recording the response stops that clock. Closing the case does not, because the portal deadline is not yours to close. A complaint that arrived by phone or on your website owes no clock and honestly shows none.
The value is in the pattern rather than the individual case. Zovos surfaces systemic clusters, meaning a category and regulation combination at or above a threshold, because that pattern is the signal a CFPB examiner looks for. Promote cluster opens a remediation finding from a cluster, with an owner and a required rationale, linked to the complaints behind it. Distribution views break the population down by category, regulation, root cause, status and month, an exam binder PDF exports the whole picture, and the board pack carries a complaint-patterns section.
Where a complaint pattern produces a finding, the finding carries the redress side of the story: how much was refunded, how many consumers were affected, over what lookback period, and where the restitution stands. Self-identification and voluntary remediation is credit an examiner can give you, and it has to be on the record before it can be given. Zovos ingests complaints for oversight. It is not the system of record, and it runs no case-handling workflow.
HMDA
The HMDA screen is a data-integrity tool. Upload LAR takes your loan/application register file, and Validate checks it against the FFIEC positional layout using a curated set of edits. Edits fall into syntactical, validity, quality and macro classes. You work the failures in bulk, setting each one to assigned with an assignee, resolved, or, for quality and macro edits only, verified as correct, and every disposition takes a note. The submission reads filing-ready once every failure has an answer. A re-upload for the same filing year is compared with the previous upload edit code by edit code, and you can promote an edit-code cluster straight into a finding.
Descriptive fair-lending screens count, for each group the applicant reported, the applications and the actions taken, and how often a reported rate spread crossed the Regulation Z higher-priced threshold. They are screening, not analysis. Nothing compares one group with another, benchmarks a figure or calls a difference significant, and the tables are computed when you supply the file and never stored.
A fair-lending extract produces a CSV for an external analytics partner, and a fair-lending review register tracks that engagement through not started, in progress, partner submitted, results received and complete. The partner's results are recorded as structured Partner focal points, so they trend from one review to the next. A review also carries a scheduled date, which publishes to the obligations calendar, so a review cycle that quietly stopped surfaces as overdue. A completed review can be promoted straight into a remediation finding.
CRA
CRA does not appear in a credit union's sidebar, and a direct link explains that the Community Reinvestment Act applies to banks and savings associations, not credit unions. The CRA program register has five tabs: Readiness, Modernization, Assessment areas, Performance context and Public file.
Delineate area creates an assessment area and requires three attestations under §__.41. They confirm that the area consists of whole geographies, that it includes your main office, branches and deposit-taking ATMs, and that it does not arbitrarily exclude low- and moderate-income geographies. The area is then submitted for approval and becomes active only once an approver signs. An area can be edited while it is still a draft. Once submitted it is fixed, and retiring an approved one as your footprint changes is a recorded status change rather than a deletion. Start performance-context file opens the §__.21(b) performance-context file, and Attach evidence adds to it for the program as a whole or for a single assessment area. The public-file tab is a §__.43 checklist where each item is verified rather than assumed. Export readiness PDF produces the summary.
The program profile records your total assets with their as-of date and how you keep the public file, physically or electronic-only. An electronic-only file needs a published location for each item. The Modernization tab is read-only and unscored. It shows the asset-size tiers with the basis for each, the August 2026 OCC and FDIC proposal to replace them, which the Federal Reserve did not join, and the citation crosswalk. Nothing on it moves your readiness percentage or sets your exam type.
Disclosures and marketing reviews
The Disclosure inventory records each disclosure with its product line, delivery channel, owner and review cadence of annual, semiannual, quarterly, biennial or none. Its governing text is bound to the document version that holds it, shown in a Governing text panel. The last-reviewed date cannot be typed. It comes from Record review, which names the reviewer, the date, the rationale and the version read. Zovos derives the next review date and its status, flags a disclosure whose review has gone stale, and publishes both to the obligations calendar. Each disclosure is linked to the citations it satisfies, and reg-change impact analysis traverses those links, so when a rule moves the disclosures affected surface without anyone having to remember which ones they were.
Marketing review is pre-use review of advertising, scripts and disclosure copy through a UDAAP lens. Log review starts one and freezes the review checklist at creation, so a later change to the template cannot alter what was reviewed. You work each checklist item as pass, fail or not applicable, and a review can be tagged to a partner program so it counts in that program's advertising oversight. Run AI first-pass puts the Ad Screener over the material. It flags trigger terms and suggests checklist dispositions, each with a confidence score, and every suggestion has to be accepted or dismissed by a person. Attach the materials, then Submit for approval with an Approved until date. The outcome is approved, approved with conditions, or rejected. An approval with conditions is not in force until someone uses Record conditions met, which stamps who, when and what the conditions were verified against.
That expiry date is the point. As it nears, the review is badged expiring soon and then expired, and it becomes a reminder source in the obligations calendar with a re-review action. A re-review shows the earlier decision and its checklist beside the new one. Advertising sign-off carries a date and is never permanent. Export review file (PDF) produces the packet for the exam binder.
Dates the rule fixes
Most compliance deadlines recur on a cadence your institution sets. Some are pinned to the wall calendar by the rule itself, and those ship as seeded obligations rather than as something you have to remember to create. Among them are the March 1 HMDA loan/application register submission and CRA loan data, quarterly HMDA reporting for the larger filers it reaches, the April 1 currency date for the CRA public file, small-business lending data under Regulation B, and the annual privacy notice under Regulation P. The same catalogue carries the fixed-date items belonging to other programs, including the AML/CFT program's board approval and independent testing.
Each entry says whether the date is statutory, meaning fixed by the rule, or institution-set, where the rule fixes the frequency and your own calendar fixes the date. Keeping those apart matters, because a board-cycle date presented to an examiner as a statutory one is a problem you created yourself. Each entry also carries an applicability switch, so a requirement that does not reach your charter stays visible and silent rather than vanishing from the list.
Notes and limits
None of these screens originate consumer transactions or file regulatory reports. HMDA validation uses a curated edit subset, so it complements rather than replaces your filing tool's own edit checks. Fair-lending and disparate-impact analysis is a partner seam. Zovos captures the methodology, the segments and the results your partner produced, and does not compute them.
Assessment content ships for this lane too. It includes marketing and UDAAP by product, a CRA self-assessment, and per-regulation packs covering Regulations E, Z, DD and CC, RESPA, the fair-credit-reporting rules and the servicemember rules. They run in the assessments register described in Risk management.