FI showroom red and grey logo
MenuMENU
SearchSEARCH

How to Implement a Compliance Management System

Agents can and should help dealers design, install, and enforce their federally mandated CMS. Luckily for everyone involved, the instructions are freely available.

February 28, 2020
How to Implement a Compliance Management System

Agents can and should help dealers design, install, and enforce their federally mandated CMS. Luckily for everyone involved, the instructions are freely available. 

Image by TarikVision via Getty Images

4 min to read


The term “compliance management system” raced into our consciousness when the Consumer Financial Protection Bureau formalized a Compliance 101 program and required all the financial institutions it oversees to have a formal CMS in place. Many in our industry believe the Federal Trade Commission, which has oversight of the auto industry, will eventually require that auto retailers implement a CMS in all aspects of dealership operations.

The day may be coming soon when documenting will be as important as doing.

Ad Loading...

The first exposure many in the industry had to a CMS was when the Safeguards Rule was implemented by most dealerships. The steps required to properly develop a Safeguards program are like the steps required to develop and to implement a CMS.

Most of our shared dealer clients have implemented a CMS, although ironically these dealers do not necessarily recognize their compliance efforts as implementing a CMS. Eventually, your dealer client may ask for your help to implement a CMS, for product sales or menu execution.

A CMS is simply a structured approach to developing and implementing processes in each phase of dealership operations that are compliant with any state, federal, or industry-standard requirements.

Overview of a CMS

A compliance management system is the method by which a dealer manages the entire consumer compliance process. It includes both the compliance program and the compliance audit function. 

Ad Loading...

The compliance program consists of the policies and procedures, which guide employees’ compliance with laws, regulations, and potential litigation defense.

The compliance audit function is an independent testing of the dealer’s transactions and processes to determine its level of compliance with consumer protection laws and internal policies and procedures.

The process to develop and implement a CMS is consistent with the required components outlined by the FTC in its guidance with the Safeguards Rule and the Red Flags Rule. These components are:

  • Appoint a compliance officer.

  • Conduct a risk assessment to gauge current practices vis-a-vis requirement.

  • Develop a policy and procedure to address the compliance requirements.

  • Provide and document employee training on the policy and procedure manual. 

  • Perform periodic audits to confirm compliance with the policy and procedure manual.

How to Implement a CMS in the Dealership

Ad Loading...

Let’s use the Monroney Rule, a rather simple federal requirement, as an example of how the CMS compliance model would work at a dealership.

The first task is to understand the compliance requirement. The Monroney Rule requires that all new vehicles offered for sale have a Monroney label affixed to a window.

Now that the requirement is understood, a dealer must conduct an assessment to see how the dealership is complying with this requirement. The logical approach would be to do a lot walk and review the placement of the Monroney label on each vehicle.

Next, the dealer would create a written procedure that explains how the dealership will comply with the requirement to have a Monroney label on every new vehicle. Salient points would include requiring an employee to confirm each new vehicle received from the factory has a Monroney label properly affixed to the vehicle before it is offered for sale. 

Another requirement would be to assign an employee to conduct periodic lot walks to ensure Monroneys are properly affixed and visible on all vehicles available for sale. Dealers may want to also include required training of all salespeople who oversee test drives to confirm the Monroney is still affixed after a test drive.

Ad Loading...

Once the procedure is written, it becomes a policy. The fourth step in implementing a CMS is to train the employees on the policy and instruction on the procedures required to implement the policy. Employees should acknowledge the training, their understanding of the topic, and agreement to adhere to the policy.

The final step to implement a CMS is to schedule periodic inspections of the vehicle available for sale to ensure that each one has a Monroney label affixed to a window. In this audit step, a separate employee should conduct periodic lot walks to verify compliance with the policy. These periodic audits should be documented and retained.

Most successful dealers intuitively use the CMS model to manage compliant processes in the dealership, they may not be documenting the approach. The day may be coming soon when documenting will be as important as doing.

Good luck and good selling.  

Gil Van Over is the executive director of Automotive Compliance Education (ACE), the founder and president of gvo3 & Associates, and author of “Automotive Compliance in a Digital World.”

Ad Loading...

Originally posted on Agent Entrepreneur

Subscribe to Our Newsletter

More Compliance

Photo of a man signing a paper at a desk while a man in a suit looks on

NADA and the Miracle on 34th Street

Automotive dealers should follow the National Automobile Dealers Association's consumer-friendly guidelines in order to minimize their legal risks.

Read More →
ComplianceFebruary 6, 2026

Another Look at a Recent Data Breach

Get caught up on the most pressing legal and regulatory matters facing dealers and F&I professionals, including data security, shotgun purchases, and inconsistent payment quotes.

Read More →
ComplianceNovember 26, 2025

Turnover and Compliance

Why ongoing training is a necessity

Read More →
Ad Loading...
ComplianceNovember 10, 2025

Singing a Gospel Song Backward

Crime and punishment in auto retail and how to avoid them

Read More →
ComplianceSeptember 26, 2025

The Best Thing a Dealer Can Do to Avoid Legal Problems

Citing the issue is a strategy borrowed from the legal field itself.

Read More →
ComplianceSeptember 15, 2025

Fines of the Times

Civil penalties for noncompliance with federal auto retail and finance rules and regulations can add up quickly. Use this checklist to cover your bases.

Read More →
Ad Loading...
ComplianceAugust 26, 2025

Goodwill and Car Dealers

A dealer goodwill tale is a cautionary tale worth paying attention to.

Read More →
ComplianceJune 30, 2025

The Regulatory Empire Is Striking Back

President Trump - entropist and corporate disruptor in consumer law

Read More →
ComplianceJune 26, 2025

How to Clear a Red Flag

Refine and enforce your dealership’s FTC-mandated ID theft-prevention program to ensure no transaction goes awry.

Read More →
Ad Loading...
ComplianceMay 22, 2025

So You Want a Compliance Audit

Be careful what you ask for … or what you get! Here are three critical components to review with your next compliance partner.

Read More →