The Regulatory Context

For Nondepository Lenders, the Audit Happens After the Complaint

Compass analyzes 100% of your origination, servicing, and collections calls and ties Reg B adverse action, Reg Z disclosures, TCPA consent, and UDAAP language to the consumer, the file, and the originator. The evidence exists before a CID, a state AG demand, or a class complaint forces you to go looking for it.

The problem

You run compliance at a nondepository lender. Maybe an independent mortgage bank licensed in 40 states through NMLS. Maybe an online installment shop with automated decisioning. Maybe a captive auto finance company on dealer-originated retail installment contracts. You do not have OCC or FDIC examiners walking the floor twice a year. What you have is the CFPB, state AGs, the state regulators that issued your licenses, secondary market investors who can demand repurchase, and a plaintiffs' bar that reads the consent order docket like a shopping catalog. You are exam-eligible without ever being on an exam cycle. The audit happens after the complaint.

Your week is a stack of things that started as phone calls. A denied applicant filed a CFPB complaint claiming the agent told her she "wouldn't qualify because she's on disability income," which if true is a Reg B violation. You pull the recording. The agent didn't say exactly that but said something close, and you don't know how many other calls sound like that. Another applicant claims she never received her adverse action notice in the 30 days ECOA requires, and your LOS shows day 31. A TCPA demand letter says a consumer revoked consent in March and the dialer kept calling through July. A state AG sends a CID for outbound calls into their state with the consent record for each.

What you have to work with is a QA team scoring 25 calls per agent per month against a checklist from 2019. The metrics that grade you are call-level: adverse action timing against the verbal completion event, whether the spoken denial reason matched the written notice, steering language on referrals, F&I add-on presentation, mini-Miranda and third-party disclosure on collections, and consent and revocation on every outbound campaign. A CFPB enforcement attorney does not grade on a curve and does not sample. When they ask for every denial call between Q1 and Q3 for applicants in a protected class, they mean every one. You can produce the audio. You cannot produce the analysis.

What sampling misses

A 2 to 5 percent QA sample on a denial line gives you almost no statistical visibility into Reg B exposure. Adverse action conversations are the highest-risk calls in the operation and the lowest-volume per agent. Your worst originator on denial language might handle four denials a month. If QA samples two of them, the odds neither is the bad one are close to coin-flip. Three quarters in, you find the pattern from a complaint, not QA. The same shape repeats on RESPA referrals, F&I add-on calls, and collections campaigns pulling from lists that should have been suppressed.

Sampling misses the timing problem. ECOA gives you 30 days after a completed application to deliver adverse action, and the completion event is often verbal. An originator either took the last piece that made the application complete, or said something suggesting it was already complete weeks earlier than the LOS thinks. The clock you didn't know was running ran out.

Then there is the language problem. ECOA discouragement and steering almost never sound like discrimination. They sound like an agent being helpful. "Are you sure you want to apply with just your income? Your husband's name isn't on this." "We see a lot of folks your age go with the shorter term." "You'd qualify if you took GAP with it." Each is a Reg B or UDAAP problem. A scorecard built for politeness rates them a 5 out of 5. A CFPB exam team or state AG will not.

What 100% understanding surfaces

  • Adverse action timing tied to the verbal completion event. Compass detects when an applicant has provided the last piece of information that makes the application complete under ECOA and traces forward to notice generation in your LOS. On automated underwriting, it ties the model decline to the verbal explanation and flags calls where the verbal reason diverged from the written notice.
  • ECOA discouragement, steering, and prohibited inquiries. Spousal-signature suggestion, age-coded language, source-of-income skepticism, ZIP-anchored steering, questions touching marital status or childbearing intent. Each is tied to originator, branch, and product. Patterns surface before they become a fair lending finding.
  • Reg Z disclosure drift and LO compensation steering. Verbal APR or payment quotes that diverged from disclosed numbers, finance charge omissions, trigger-term presence on advertising. On TRID transactions, Compass detects when an applicant has provided all six pieces defining an application under 12 CFR 1026.2(a)(3) and traces forward to the LE and CD timing under 1026.19(f). LO compensation steering under 1026.36(d) is flagged across originators and product mix.
  • TCPA consent capture and revocation. Consent grants are scored against the prior express written consent standard for prerecorded or artificial voice marketing to wireless numbers. Every call where a consumer said anything a reasonable factfinder would treat as revocation ("stop calling me," "take me off your list," softer variants) is flagged in English and Spanish and tied to the consumer record. Ambiguous consent or consent from someone other than the called party is also flagged.
  • UDAAP language across origination, servicing, and collections. Verbal misrepresentation of APR, payment, fees, fitness for the product, ability to refinance, or ability to settle. Mandatory-feeling presentation of optional products. False urgency on closing or payoff. The CFPB resolves many fact patterns that used to be Reg B, Reg Z, or RESPA cases under UDAAP, and Compass produces the language-level evidence.
  • Auto exposure: Holder Rule, MLA, state rate caps, F&I add-ons. Under the FTC Holder Rule at 16 CFR 433, dealer-side statements follow the contract to the assignee. Where dealer recordings are accessible, Compass flags verbal misrepresentation, mandatory-feeling add-on bundling, APR above the state cap, and missing MLA checks or MAPR disclosures.
  • Collections exposure: Reg F, mini-Miranda, third-party disclosure, SCRA. Most TCPA class risk lives on the collections dialer. Compass surfaces call-frequency against Reg F's 7-in-7 default, mini-Miranda on first contact, third-party disclosure, SCRA active-duty references before repossession, and contact after a verbal cease.

The Regulatory Context

Enforcement against a nondepository lender is shaped by the absence of a primary prudential regulator. A depository defends exam findings with a QA program and written supervision. You do not get exam findings on a cycle. You get civil investigative demands from the CFPB or a state AG, complaint-driven investigations, repurchase requests from investors, NMLS renewal scrutiny, and class action discovery. Each is a request for evidence you cannot create after the fact. The recordings exist. The analysis usually does not.

The rules sit on top of each other. Reg B (12 CFR Part 1002) governs application handling, prohibited inquiries, adverse action, and the discouragement standard at 1002.4(b). Reg Z (12 CFR Part 1026) implements TILA disclosures and LO compensation rules at 1026.36(d), and on TRID transactions sets the LE and CD windows. Reg X (12 CFR Part 1024) implements RESPA on mortgage, including the ABA disclosure at 1024.15. TCPA and the FCC rules at 47 CFR 64.1200 require prior express written consent for prerecorded or artificial voice marketing to wireless numbers, and survived the narrowing of the autodialer definition in Facebook, Inc. v. Duguid. State mini-TCPAs in Florida, Oklahoma, Washington, and others define automated systems more broadly than Duguid and create private rights of action. For auto, the MLA caps MAPR at 36 percent for covered borrowers, and the FTC Holder Rule pulls dealer-side statements onto the assignee's balance sheet. UDAAP sits above everything as the CFPB's preferred theory when a technical rule does not quite fit.

100 percent coverage is a defensible posture. Sampling gets cross-examined for selection bias because it deserves to be. Contemporaneous detection matters too. A pattern flagged in March and coached in April is different from one found in November because a complaint forced you to look. Compass changes the date you first knew.

How Compass works

Compass replaces the QA scorecard with structured understanding of what actually happened on the call. Every application, denial, closing call, outbound dial, and collections contact is analyzed against the framework that applies. The primary pillar is Conversation Compliance, with Conversation Insights, Conversation Quality, and Conversation Coaching close behind.

Compass is built on Contextual Entity Resolution (CER): consumers, numbers, campaigns, loan files, originators, dealers, states, and product types are first-class entities, not strings in a transcript. A call referencing "the application," "her file," or "the contract" resolves to the right consumer and file. When you need every call for applicant 47XXXX, or every consumer who revoked consent and was contacted again within 30 days, the answer comes from the entity graph, not a keyword search.

Conversation Compliance. Disclosure tracking against Reg B, Reg Z, Reg X, TCPA, state mini-TCPAs, MLA, the FTC Holder Rule, Reg F, and SCRA. Timestamped evidence of consent, revocation, LE/CD timing, adverse action reasoning, prohibited inquiries, and UDAAP language. Exports tied to consumer and loan records.

Conversation Insights. 100 percent coverage of origination, servicing, and collections. Pattern detection across originators, branches, dealers, products, states, and campaigns. Drift analysis that shows when consent posture or disclosure consistency slips.

Conversation Coaching. Evidence-backed coaching on the specific calls and phrases that drove a signal. Specific call, specific minute, specific phrase.

Conversation Quality. Conditions on the call resolve into Signals measured against Outcome Lift. You see which originator behaviors actually move denial-rate disparity, complaint rate, repurchase demand frequency, and TCPA dispute volume.

Common questions

Q: We do not originate mortgage. Is this still for us? A: Yes. TRID and RESPA examples appear because mortgage IMBs are part of the persona, but the architecture covers consumer installment, fintech, auto, BNPL, and private student. Reg B, Reg Z, TCPA, UDAAP, Reg F, MLA, and Holder Rule signals run independently. Turn on what applies to your book.

Q: We already have a QA team. What changes? A: They stop sampling and start reviewing flagged conversations on the calls that carry actual risk. The work shifts from clerical scoring to investigation and coaching. We do not pitch this as a headcount-cut tool.

Q: We have a consent management platform. What does Compass add? A: Consent platforms record the grant as a checkbox. Compass confirms what was actually said on the call, in what language, by whom, and whether anything in a later call constituted revocation. Revocation events write back to your consent platform or dialer suppression through a connector. Aktify, Convoso, LiveVox, Five9, and similar are connector work, not a rebuild.

Q: How do you handle InfoSec, vendor risk, and model risk review? A: We sign standard paperwork: NDA, MSA, DPA, and a BAA where applicable. SOC 2 is in progress. Security documentation, including the subprocessor list, is available on request during your vendor review. No customer data is used to train models that serve other customers. On model risk, Compass fits into the MRM framework your team already uses; we work through your review process with you rather than handing over a pre-packaged artifact. Plan in months, not weeks, when InfoSec and model risk reviews are required.

Q: Anything Compass produces is discoverable in a CID. How do you think about that? A: It is, and that is the point. The alternative is recordings without analysis, which still get produced and look worse. Lenders we work with want contemporaneous evidence that they detected and addressed patterns before enforcement arrived. Privilege is for outside counsel.

Q: How is Compass different from Gong, NICE, Verint, Observe.AI, or CallMiner? A: Sales-coaching tools optimize for revenue moments. Legacy speech analytics optimizes for keyword detection and rubric scoring. Compass is built around CER and structured Signals tied to outcomes. Keyword spotting catches "30 days" being said. It does not catch whether the clock was running, whether the verbal reason matched the written notice, or whether a discouragement pattern is forming across a team or dealer network.

Q: How does Compass perform on Spanish and bilingual calls? A: Compass processes Spanish natively. Signal libraries run in both languages, and we track recall and precision separately by language because the verbal cues differ. We share those metrics during evaluation.

Q: For captive auto, how do you handle dealer-originated calls we do not record directly? A: Where dealer agreements allow ingestion of dealer-side recordings, Compass flags Holder Rule exposure, MLA checks, F&I add-on presentation, and APR against the state cap. Where dealer recordings are not available, the signals still run on every recorded inbound call your team handles, plus collections.

For Nondepository Lenders, the Audit Happens After the Complaint

The first session runs on our demo audio and a published reference dataset, so you can see the Reg B, Reg Z, TCPA, UDAAP, auto, and collections signal libraries on real conversations without moving any of your data. If your own audio comes in later, NDA and DPA come first, and a BAA where it applies. Bring the question your current QA program cannot answer, and we will work it together.