Most software evaluations do not test for the complexity of multi-branch compliance management. This begs the question of how a platform’s capabilities behave when the same programme must operate across different branches, states and charters.
This article covers what changes, including the regulatory baseline for a distributed network, the evidence a branch has to produce, how monitoring samples should be allocated across locations, policy attestation and version control, the jurisdictional overlay, and how to structure the evaluation itself.
See our resource on unifying financial data for more related to this topic.

The Regulatory Baseline the Software Has to Serve
Anchoring evaluation criteria to supervisory expectations keeps the exercise transparent and makes the resulting requirements defensible to a board.
The FDIC describes a compliance management system as board and management oversight combined with a consumer compliance programme. That programme has four components:
- Policies and procedures
- Training
- Monitoring
- Consumer complaint response
Independent audit sits over the top, providing assurance through risk-based independent review. Every criterion in a software evaluation should trace back to one of those compliance management system elements.
In its March 2026 Consumer Compliance Supervisory Highlights, the FDIC reported roughly 825 consumer compliance examinations conducted in 2025 across its supervised institutions, with 1,155 violations cited. Five regulations accounted for about 75% of them.
Truth in Lending and Regulation Z produced 462 violations, or 40% of the total, largely disclosure failures. Electronic Fund Transfer Act and Regulation E accounted for 136, mostly error investigation failures. Flood insurance requirements under 12 CFR part 339 produced 131. Truth in Savings and HMDA reporting made up most of the remainder.
Those are transaction-level, execution-level failures that happen where the account is opened and the loan is closed, which in a branch network means they happen at locations the compliance function does not sit in.
The FDIC also recorded a 48% increase in complaints involving non-bank service providers, reaching 6,356 cases, a reminder that the evidence chain extends past the bank's own staff.
Branch-Level Evidence: What to Ask a Vendor
A useful test is to take each capability a vendor demonstrates at institution level and restate it as a question about a single location. Effective compliance management software should answer both versions with the same data, and produce evidence rather than a percentage.
Six core capabilities are translated below, from the institution-level question to the branch-level one.
| Capability | Institution-level question | Multi-branch question | Evidence it must produce |
|---|---|---|---|
| Policy attestation | What percentage of staff acknowledged the policy | Which locations have gaps, and for how long | Acknowledgement record by person, location and policy version |
| Monitoring and testing | How many reviews were completed | How was the sample distributed across locations | Sampling frame and coverage by location over a rolling period |
| Issue management | How many issues are open | Which issues were closed locally without escalation | Issue record with originating location, owner and escalation path |
| Training | What is the completion rate | Which roles at which locations are overdue | Assignment and completion by role and location |
| Risk assessment | What is the inherent risk rating | How does branch profile change the residual rating | Assessment with location-level factors documented |
| Complaint intake | How many complaints were received | Which channel and location did they arrive through | Complaint record with source location and resolution timing |
Monitoring, Testing and Sampling Across Locations
Monitoring is generally more frequent and less formal than the independent review performed by the audit function, and it may sit within business lines. Audit provides reasonable assurance through risk-based independent review. It also notes that monitoring performed by various groups should be complementary.
A sample drawn at institution level will systematically under-cover small and recently acquired locations, because volume-weighted sampling sends the reviewer where the transactions are.
Ask a vendor the following questions:
- Can the sampling frame be defined by location as well as by product.?
- Can coverage by location be viewed over a rolling twelve or twenty-four months?
- Does the system flag a location whose coverage has lapsed, without someone having to notice?
The Acquired-Branch Problem
An acquired location arrives with a second policy set, local procedures written for a different institution, staff trained on someone else's programme, and often a different core system.
Ask any vendor how the platform represents a location during conversion, and whether historical evidence from before the acquisition can be attached to the location record.
Policy Distribution, Attestation and Version Control
Attestation coverage has to be visible by location because an average of 94% conceals whether the missing 6% is spread evenly or concentrated in two branches. Policies need effective dating, so the question "what did this location's procedure say in April" has an answer.
Compliance tracking at this level helps support the numbers being reported to the board. When an examiner asks how the bank knows a procedure was in force at a specific branch on a specific date, the answer is a record.
Running the Evaluation
Turn the criteria into a scored test by using the following lines of questioning to your selected vendor candidates:
- Use the bank's own locations. Ask the vendor to configure two, one large and one small or recently acquired, and run the same questions against both.
- Ask what failure looks like. Request the report the system produces when a location is out of compliance.
- Test the rollup. Enter an issue at one location, escalate it, and follow it into board-level reporting.
Platforms differ in how they implement this. Predict360, for example, carries risk control self-assessments, issues management, compliance monitoring and testing, policy and procedure management, certifications and attestations, and complaints management on a single platform.
How any given platform represents location within those records is a question to put to the vendor directly, because it is the difference between reporting at branch level and reporting only in total.
Frequently Asked Questions
How do multi-branch banks manage compliance across locations?
They treat location as an attribute on compliance records. Policies carry effective dates and attestation records by location. Monitoring samples are allocated so that small and recently acquired branches receive coverage. Issues raised locally follow a defined escalation path. Risk assessments account for location-specific factors such as staff tenure, product mix and local regulatory requirements.
What features should bank compliance software have for a branch network?
Location-level attribution on every record, sampling that can be defined and monitored by location, attestation coverage visible by location, policy version history with effective dating, an issue escalation path from branch to enterprise, and reporting that aggregates. Jurisdiction should also be an attribute on requirements for banks operating across state lines.
Does every branch need its own risk assessment?
Not necessarily a separate document. What supervisory expectations point toward is that the enterprise risk assessment reflects factors that differ by location, including product mix, transaction volume, staff experience, recent acquisition status and applicable state requirements. Branches with materially different risk profiles warrant separate treatment within the bank risk assessment.
The companion explainer on compliance management software capabilities sets out how these requirements sit within the wider programme structure, including audit, training and board reporting.
The Predict360 Compliance Management Suite modernizes compliance monitoring, regulatory change management and document management.
Request Demo- Activity Management
- Document Management
- Compliance Monitoring
- Integrated Platform