FCRA § 1681e(b) requires a CRA to follow reasonable procedures to assure maximum possible accuracy of the information it reports. The statute does not describe those procedures or require that they be written down.
Written policies, training, and testing help establish that the CRA’s procedures exist, that staff understand them, and that they are followed. They also provide documentation of the CRA’s compliance program when a client, data provider, auditor, or regulator inquires.
Written Policies and Procedures
A policy states what the CRA requires. A procedure states how the work is performed to meet it.
A CRA’s policy set should cover, as applicable:
- Permissible purpose and client credentialing
- Identity matching standards
- Criminal record research and jurisdiction selection
- Verification processing and attempt standards
- Reporting limits, both federal and state
- Report accuracy and review before release
- Dispute handling and reinvestigation
- Vendor selection and oversight
- Records retention, storage, and disposal
- Information security and breach response
- Employee conduct and access to consumer information
In writing and maintaining them:
- Write procedures at the level the work is performed. A policy stating that identity matching will be accurate does not tell a researcher which identifiers are sufficient. The procedure should provide the guidance needed to make that determination.
- Assign ownership. Identify who is responsible for each policy, who approves changes, and who reviews it on a schedule.
- Date and version every document. Version control establishes which policy or procedure was in effect when particular work was performed.
- Retain superseded versions. Prior versions document what procedures and requirements were in effect during earlier periods.
- Review on a schedule and after a change. New services, new jurisdictions, new data sources, and regulatory developments all create gaps in an existing policy set.
Worth Knowing: The FCRA distinguishes between willful and negligent noncompliance. Negligent violations may result in actual damages, while willful violations may result in statutory and punitive damages (FCRA §§ 1681o and 1681n). Written procedures, training records, and compliance testing can help document the steps a CRA took to comply with its obligations.
Employee Training
Written procedures are effective only when the people performing the work understand how to apply them.
- Train before access is granted. An employee should complete training on permissible purpose, consumer information handling, and their own role before working on live files.
- Train to the role. Researchers should understand identity matching and reporting standards. Dispute staff should understand reinvestigation requirements and deadlines. Sales and client service staff should understand the compliance requirements that affect what services can be offered and how they are described.
- Cover the FCRA obligations that apply to the work. Include permissible purpose, accuracy requirements, reporting limits, the public record notice obligation, and dispute handling.
- Retrain when a procedure changes. A revised procedure that nobody was told about is a policy change on paper only.
- Provide refresher training on a schedule. Periodic training reinforces important requirements and provides a record that compliance training is ongoing rather than limited to onboarding.
- Record completion. Document who was trained, on what material, on what date, and what version of the material was used.
Good Practice: Test comprehension rather than recording attendance alone. A signed acknowledgment documents that an employee received the material. A short assessment can help confirm understanding and identify requirements that may need additional explanation.
Compliance Testing
Compliance testing examines whether the work being performed matches what the procedures require.
Compliance testing is related to, but different from, quality control. Quality control focuses primarily on whether the report is accurate. Compliance testing examines whether required procedures were followed, even when the resulting report was accurate.
- Test each procedure against completed files. Select files and confirm that what was done matches what the procedure requires, including the documentation the procedure calls for.
- Include the steps that produce no visible output. Whether a certification was on file before a report was furnished, and whether a review actually occurred, leave no trace in the report itself.
- Test on a defined schedule. Regular testing provides more consistent oversight and makes it easier to compare results over time.
- Look for patterns in testing results. Review findings by employee, client, jurisdiction, service, or other relevant category to identify recurring problems that aggregate results may conceal.
- Record all testing results. Document reviews that found no issues as well as those that produced findings. Both help demonstrate that the testing program is being performed consistently.
- Report results to someone who can act on them. Findings that stay within the team performing the work produce no correction.
See Quality Control Standards for procedures to help ensure report accuracy.
Corrective Action
Compliance findings should lead to appropriate corrective action based on the cause and scope of the problem.
- Identify the cause. Determine whether the procedure was inadequate or unclear, whether additional training is needed, or whether operational conditions contributed to the problem.
- Match the corrective action to the cause. Revise an inadequate procedure, provide additional training when established procedures were not followed, and address operational conditions that contributed to the problem.
- Assign responsibility and a completion date. Each corrective action should identify who is responsible, what must be completed, and when it is due.
- Determine the scope of the problem. A deviation identified in one file may also affect other reports processed under the same procedure. Determine whether additional files or consumers may be affected.
- Correct affected reports where correction is required. Where reports already furnished contain the error, address them rather than limiting the response to future work.
- Verify the correction worked. Test the same procedure again after the change, so the result is measured rather than assumed.
Good Practice: Document significant corrective actions that were considered but not taken, along with the reason. This creates a record of how the finding was evaluated and why a particular response was selected.
External Compliance Audits and Inspections
CRAs may be subject to audits and inspections by data providers, clients, accreditation organizations, and other parties. Some reviews are a condition of continued access to particular data sources or services.
- Social Security Administration, for CBSV. Participation in CBSV includes compliance review requirements established by SSA. Reviews may examine whether verification requests were supported by required consumer consent, whether records were properly maintained, and whether the CRA followed applicable program requirements.
- Data providers. Credit bureaus, drug testing networks, motor vehicle record providers, and other data sources may require credentialing, site inspections, security reviews, end user verification, or periodic recertification as a condition of access. CRAs should understand and track the requirements that apply to each provider relationship.
- End user inspections. Reseller agreements with credit bureaus may require the CRA to credential or inspect its own clients as a condition of access. CRAs should understand which end users require inspection, when reinspection is required, and what documentation must be maintained.
- Clients. Service agreements often reserve audit rights, and larger clients exercise them. A client audit typically examines security controls, permissible purpose handling, and subcontractor oversight.
- Accreditation reviewers. Where a CRA holds an accreditation, the reviewer examines the program against the published standards on the accreditation cycle.
CRAs should maintain a consistent process for managing these reviews:
- Track audit and review requirements. Maintain a schedule of required audits, inspections, recertifications, and renewal dates so that important provider or accreditation requirements are not missed.
- Keep documentation current rather than assembling it for the audit. Policies, training records, testing results, and other compliance documentation should be maintained as part of the regular program rather than recreated when a review begins.
- Address findings promptly. Document the corrective action taken in response to audit findings and verify that identified issues have been resolved before the next review.
Worth Knowing: Provider audits and inspections may be contractual conditions of continued access rather than regulatory examinations. Failure to satisfy a provider’s requirements can result in restricted or suspended access, which may affect the CRA’s ability to deliver services that depend on that source.
See the Audit Services and Compliance Tools directories for providers serving CRAs.
Records to Keep on File
These records help demonstrate that the compliance program is documented, implemented, tested, and updated when problems are identified.
Maintain, as applicable:
- Current policies and procedures, dated and versioned
- Superseded versions, with the dates they were in effect
- Policy review dates, reviewers, and approvals
- Training materials by version
- Training completion records identifying who, what, and when
- Compliance testing schedules, samples, and results
- Findings, corrective actions, owners, and completion dates
- Verification that corrective actions worked
- External audit reports, including CBSV compliance reviews and data provider inspections
- Responses to audit findings and evidence of remediation
Retain audit reports that identified no findings on the same schedule as those that did. Both establish that the review occurred.
See Records & Documentation for retention schedules and secure storage.
Worth Knowing: Written policies are only one part of a compliance program. Effective programs also include training so employees understand the procedures, testing to confirm they are being followed, and corrective action when problems are identified.
Download the Policies and Training Checklist
What to document, what to train on, what to test, and what external audits require.
