Compliance Guide · 2026 · 01 · 8 min read

Bank Compliance Gap Analysis: A Complete Guide

A compliance gap analysis is a systematic comparison of what your bank's policies and disclosures actually say against what current regulation requires them to say. It answers a simple question with expensive consequences: if an examiner read this document tomorrow, what would they find?

Why gaps accumulate

Policies drift. Regulations are amended, guidance is rescinded and replaced, and bank documents written years ago quietly fall out of alignment. Community banks feel this hardest: a three-person compliance department cannot re-read every policy against every applicable part of the CFR on an annual cycle. The result is predictable — examiners find the drift first, and a finding that could have been a quiet internal fix becomes an MRA with board-level tracking.

A single MRA response — drafted by outside compliance counsel — typically costs $25,000 to $75,000 in professional fees, depending on complexity. A gap found and fixed before the exam costs a policy revision.

What a thorough gap analysis covers

Deposit account agreements

Mapped against Regulation E (12 CFR Part 1005) for electronic fund transfer disclosures, error resolution, and liability provisions, and Regulation DD (12 CFR Part 1030) for account disclosures, fees, and advertising accuracy. Deposit agreements are public documents — which means your gaps are visible to anyone who reads carefully, including examiners preparing for your next cycle.

Lending policies

Reviewed against fair lending requirements, Regulation Z and Regulation B disclosure obligations, and the bank's own stated underwriting standards — internal inconsistency between policy and practice is itself a finding.

Vendor management

Assessed against the Interagency Guidance on Third-Party Relationships (OCC Bulletin 2023-17, issued jointly with the Federal Reserve and FDIC in June 2023), which sets expectations across the full third-party lifecycle from planning through termination.

BSA/AML program documents

Compared against the program requirements of 31 CFR 1020.210 — internal controls, independent testing, a designated BSA officer, training, and customer due diligence — and against the finding patterns that recur in public BSA enforcement actions.

Privacy notices

Checked against Regulation P (12 CFR Part 1016): the required content of initial and annual notices, opt-out mechanics where sharing triggers them, and delivery requirements.

Method: map, cite, prioritize

A useful gap analysis produces three things for every gap: the specific regulatory requirement with its CFR citation, the exact policy language (or absence) that falls short, and a severity judgment that reflects examination consequence rather than theoretical risk. Findings without citations are opinions; findings with citations are work orders. The output should be specific enough that counsel can review it and a policy owner can act on it without further research.

Cadence

At minimum, run a full gap analysis annually and after any material regulatory change affecting your product set. Banks under an examination cycle's shadow — or operating under existing supervisory findings — should verify remediated documents again before the next exam begins, because the fastest way to extend supervisory attention is to re-present a document the examiner already cited.

See how your own public documents read.

The free RegentForge diagnostic analyzes a bank's published documents — no account, no internal uploads — and returns findings with CFR citations for your counsel to review.

Start the free diagnostic