39.2 Sampling Objectives, Workpapers and Testing Reports

Key Takeaways

  • Probability sampling requires a defined population and a defensible selection method.

  • Workpapers should connect evidence, criteria, exceptions and conclusions.

  • A zero-exception sample supports only the conclusion justified by its assumptions and statistical design.

Last updated: October 2026

Judgmental / Targeted Sampling: Non-Statistical Precision

Judgmental sampling deliberately selects files based on specific risk indicators, operational anomalies, or suspected control breakdown points, rather than random probability.

  • Core Purpose: To test the outer boundaries of internal controls, probe known operational vulnerabilities, and conduct diagnostic investigations into root causes.
  • Primary Risk Triggers for Targeted Selection:
    • Mortgage Overrides & Pricing Concessions: Selecting loans where loan originators granted discretionary interest rate discounts, fee waivers, or underwriting guideline exceptions.
    • Near-Cutoff Adverse Action Denials: Selecting credit applications denied where the applicant's credit score or debt-to-income (DTI) ratio fell within 5 to 10 points of the approval threshold.
    • High-Fee / Overdraft Accounts: Targeting checking accounts that incurred four or more overdraft or non-sufficient funds (NSF) charges within a single statement cycle.
    • Denied Regulation E Electronic Fund Transfer Claims: Selecting all consumer fraud or unauthorized debit claims that were denied due to alleged consumer negligence, failure to report within 60 days, or lack of timely written confirmation.
    • Beneficial Ownership Exemptions: Reviewing commercial entity deposit files where commercial customers claimed an exemption from FinCEN beneficial ownership certification.

Sample-size calculation

Do not assign confidence from a convenient file count. For independent randomly selected binary outcomes, with zero exceptions and a very large population, a one-sided 95% upper bound no greater than 5% requires at least 59 files: 0.95 to the 59th power is approximately 0.0485. This is an illustrative attribute-detection calculation. Estimating a rate with a chosen margin of error, observing exceptions, stratifying, or sampling a finite population requires different calculations. Document the objective, population and assumptions before setting sample size.


4. Testing Workpapers, Documentation, and Reporting

A compliance review is only as credible as its underlying documentation. Under federal examination guidelines, workpapers and monitoring reports should withstand independent scrutiny by regulatory examiners.

Standards for Auditable Compliance Workpapers

Every compliance review should be supported by complete, well-organized workpapers containing:

  1. Testing Scope & Objectives: Explicit statement of the regulatory requirements tested (with specific regulatory citations, e.g., 12 CFR § 1026.19(e)(3)), review timeframes, and business lines covered.
  2. Population Reconciliation: Detailed records demonstrating how the target population was generated, including system query logic and reconciliation against general ledger trial balances to ensure completeness.
  3. Sampling Methodology & Selection Logs: Documentation explaining whether statistical or judgmental sampling was utilized, parameters applied, and the complete inventory of selected account numbers.
  4. Standardized Testing Checklists: Structured test steps detailing specific compliance questions, verification criteria, and evidence inspected (e.g., date-stamped LE delivery logs, escrow analysis worksheets).
  5. Granular Exception Logs: Item-by-item recording of each identified deficiency, including account identifier, regulatory section violated, monetary impact, consumer harm, and initial frontline operational rationale.
  6. Root Cause Analysis (RCA): Objective determination of whether exceptions represent isolated human error, systemic programming defects, inadequate training, or flawed policies.

Formal Compliance Monitoring Reports

Upon concluding a review, the compliance department issues a formal monitoring report structured as follows:

  • Executive Summary: High-level summary of review scope, overall findings, systemic themes, and an assigned Risk Rating (e.g., Low / Satisfactory, Moderate / Needs Improvement, High / Unsatisfactory).
  • Scope & Methodology: Detailed explanation of the testing window, population size, sample count, and selection criteria.
  • Detailed Findings & Regulatory Analysis: Factual narrative of each identified deficiency, citing governing federal regulations, error frequency rates, and potential exposure to civil money penalties or restitution.
  • Corrective Action Plan (CAP): The operational business unit's formal written response, detailing:
    • Specific operational steps to remediate identified exceptions;
    • Structural fixes to prevent recurrence (e.g., system logic reconfiguration, updated procedures, re-training staff);
    • Customer restitution plans for monetary harm;
    • Named responsible manager (by title) accountable for implementation;
    • Firm, auditable target implementation completion dates.
  • Post-Review Validation: Compliance logs all agreed CAPs in an enterprise tracking ledger and performs post-implementation validation testing prior to closing any finding.

5. Compliance Monitoring vs. Independent Audit Testing

The following matrix delineates the regulatory distinctions between second-line compliance monitoring and third-line independent audit testing:

DimensionCompliance Monitoring (2nd Line)Independent Testing / Compliance Audit (3rd Line)
Primary PurposeValidates daily operational adherence to consumer regulations, detects operational glitches, and evaluates first-line controls.Provides objective, comprehensive assurance to executive leadership and the Board on the effectiveness of both 1st line controls and the 2nd line CMS.
Responsible PartyCompliance Department officers and regulatory specialists under the direction of the Chief Compliance Officer.Internal Audit Department or independent external compliance audit firm.
Independence LevelFunctionally separate from first-line loan and deposit operations, but actively involved in compliance advisory, policy writing, and training.Strictly independent from all operational, advisory, and administrative compliance functions; cannot evaluate self-created systems.
Scope & FocusTransactional testing, procedure execution, daily operational workflows, and specific product-level compliance.Holistic evaluation of transactional compliance AND the overarching CMS (policies, board oversight, risk assessments, training, complaint programs).
Frequency & CadenceOngoing and frequent (continuous, monthly, or quarterly); dynamically adjusted as operational risks evolve.Periodic and cyclical (annual, 18-month, or risk-based multi-year cycle approved by the Board Audit Committee).
Primary Reporting LineSenior Management, Chief Compliance Officer, Chief Risk Officer, and Executive Compliance Committee.Directly to the Audit Committee of the Board of Directors, with informational copies to senior leadership.
Remediation RoleAssists business units in crafting corrective action plans, drafting updated procedures, and tracking operational closure.Evaluates the adequacy and timeliness of management's remediation, but does not design or implement corrective controls.

FDIC CMS examination framework.

The monthly, semiannual and annual monitoring tiers above illustrate one plan. Select actual schedules and methods from risk and applicable requirements rather than categorically labeling every Regulation CC review moderate or every COPPA review low risk. An audit function should preserve independence; outside assurance is one solution to missing expertise, not the only required organizational arrangement.

Test Your Knowledge

A mid-sized commercial bank is restructuring its compliance management system to satisfy supervisory expectations regarding the Three Lines of Defense model. During an internal review, questions arise concerning the functional boundaries between the Compliance Department's periodic monitoring reviews and the Internal Audit Department's independent compliance audits. Which of the following statements correctly distinguishes compliance monitoring from independent testing?

A

Compliance monitoring is performed exclusively by external consultants reporting to the Chief Risk Officer, whereas independent testing is conducted on a monthly basis by frontline loan officers to verify their own loan originations.

B

Compliance monitoring is an ongoing second-line surveillance activity performed by compliance staff that reports to senior management to validate daily control execution, whereas independent testing is an objective third-line examination performed by internal audit reporting directly to the Board Audit Committee to evaluate both business line controls and the compliance management system itself.

C

Compliance monitoring evaluates the adequacy of board governance and executive oversight, whereas independent testing focuses strictly on daily transaction testing of individual loan files.

D

Independent testing is conducted under the direct supervision of the Chief Compliance Officer, whereas compliance monitoring reports directly to the Board of Directors without senior management involvement.

Sections you finish are checked off in the contents.