FCRA Compliance Management & Risk Mitigation 2 — Questions and Answers
Question 1: Under FCRA, how long must a CRA retain documentation of its reasonable procedures for assuring maximum possible accuracy?
- Until the next audit cycle
- No retention period is specified, but records must be available upon regulatory request (Correct answer)
- At least 5 years from the date of creation
- For the duration of any related litigation only
Correct answer: No retention period is specified, but records must be available upon regulatory request
FCRA does not specify a precise retention period for compliance documentation, but regulators expect records to be producible on demand.
Question 2: A furnisher discovers it reported a consumer's Chapter 7 bankruptcy discharge date incorrectly to all three major CRAs. Under an effective compliance management system, what is the FIRST corrective step?
- Send an adverse action notice to the consumer immediately
- Dispute the tradeline internally and pause all furnishing until resolved
- Send corrections to all affected CRAs promptly and document the root cause (Correct answer)
- Notify the CFPB within 30 days of discovery
Correct answer: Send corrections to all affected CRAs promptly and document the root cause
Furnishers must correct inaccurate information sent to CRAs promptly and investigate the root cause to prevent recurrence.
Question 3: Which risk mitigation control is MOST effective for preventing FCRA violations arising from employee use of consumer reports for impermissible purposes?
- Annual FCRA training videos
- Role-based access controls that restrict report retrieval to permissible-purpose job functions (Correct answer)
- A written policy prohibiting misuse posted in the break room
- Random audits of consumer report usage once per year
Correct answer: Role-based access controls that restrict report retrieval to permissible-purpose job functions
Technical access controls prevent impermissible access at the system level, reducing reliance on human compliance alone.
Question 4: A compliance officer is designing a dispute-handling workflow. Which metric BEST signals whether the process meets FCRA's 30-day investigation requirement?
- Average cost per dispute resolved
- Percentage of disputes resolved within 25 business days to allow buffer time (Correct answer)
- Number of disputes escalated to legal counsel
- Ratio of disputes that result in consumer file updates
Correct answer: Percentage of disputes resolved within 25 business days to allow buffer time
Tracking resolution within 25 days (5 days before the statutory deadline) provides an operational buffer and early warning of capacity problems.
Question 5: Under FCRA Section 609, a consumer requests all information in their file from a CRA. Which item is the CRA NOT required to disclose?
- The sources of the information
- The identity of each person that procured a consumer report in the prior two years for employment purposes
- The proprietary scoring algorithm weights used to generate a credit score (Correct answer)
- All information in the consumer's file at the time of the request
Correct answer: The proprietary scoring algorithm weights used to generate a credit score
CRAs must disclose file contents and inquiry sources but are not required to reveal the proprietary algorithms underlying credit scores.
Question 6: A bank's FCRA compliance program lacks a written policy on prescreened solicitation opt-outs. Which regulatory risk does this gap MOST directly create?
- Liability under FCRA Section 615 for failing to provide adverse action notices
- Liability under FCRA Section 604(c) for conducting prescreened lists without honoring opt-outs (Correct answer)
- Violation of the Equal Credit Opportunity Act only
- Risk under FCRA Section 623 for inaccurate furnishing
Correct answer: Liability under FCRA Section 604(c) for conducting prescreened lists without honoring opt-outs
Section 604(c) governs prescreened solicitations and requires creditors to honor opt-out elections made through the national opt-out system.
Question 7: When conducting a vendor risk assessment for a third-party that accesses consumer reports on behalf of a creditor, which FCRA obligation does the creditor RETAIN regardless of the vendor relationship?
- The vendor assumes all FCRA liability once a contract is signed
- The creditor retains responsibility for ensuring the vendor has a permissible purpose for each access (Correct answer)
- Only the CRA bears liability for permissible purpose violations involving vendors
- The creditor is fully indemnified by the vendor contract
Correct answer: The creditor retains responsibility for ensuring the vendor has a permissible purpose for each access
A creditor cannot outsource its permissible-purpose obligation; it remains liable for ensuring its vendors access reports only for legitimate reasons.
Under FCRA, how long must a CRA retain documentation of its reasonable procedures for assuring maximum possible accuracy?