How to Keep Modern Bank Marketing from Creating Major Regulatory Trouble
By Kunal Vankadara, co-founder and CEO at Haast
Simple Subscribe
Subscribe Now!
In spite of the decisive digitalization of banking, at many institutions the compliance teams reviewing digital marketing still work through manual queues and sign-off chains built for yesterday’s quarterly campaigns.
Content stopped arriving in quarterly batches years ago. That mismatch has turned into a supervisory problem.
Key insight: Banks scaled content velocity with technology and digital talent. The review layer governing that content stayed where it was, and examiners are getting better at finding what slips through.
Need to Know:
- Digital banks run marketing continuously across app, email, push and web, while compliance headcount has stayed roughly flat.
- Every push notification and personalized offer is a marketing communication subject to consumer protection standards.
- In April, the Office of the Comptroller of the Currency (OCC) ordered a Chicago bank to pay restitution over deceptive refinance advertising, in a case built entirely on marketing claims.
- FDIC’s digital sign requirements reach every digital channel a bank uses to take deposits, with a Jan. 1, 2027, compliance date.
- However, hiring another reviewer changes little, since the review model itself stopped fitting the work.
A Review Process Built for a Fraction of Today’s Content Volume
A mid-to-large U.S. bank with an active digital marketing function runs content across every channel at once. Push notifications fire weekly. Banners inside the app rotate by lifecycle stage, and underneath all of it an email program runs personalized offer sequences across millions of customers while website rates keep changing.
Every piece of that content makes a claim about a financial product, which puts it inside the same unfair-and-deceptive-practices standard examiners apply to a print ad or a branch brochure. A team built to review quarterly campaigns is now governing a content operation that produces more in a week than it once did in a year. Staffing stayed flat through all of it, and the backlog that creates has a direct commercial cost.
Why this matters: When review capacity and content volume diverge this far, something stops getting reviewed, and the bank loses visibility into which claims reached which customers.
Practical next steps:
- Inventory every channel that can put a product claim in front of a customer, including the ones the marketing function owns without legal sign-off.
- Measure review throughput against actual weekly content volume to size the gap in real numbers.
- Rank content by relative risk tiers, so high-exposure claims get human review and routine copy follows a lighter path.
- Track review turnaround as a business metric with a named owner.
Read more: Your Next AI Failure Will Pass Every Control You Have
Personalization and Notifications: Approved Once, Running at Scale
Widespread personalization is one of the clearest commercial wins of the digital era — and it is where governance most visibly breaks down. Segment A gets one offer. Segment B gets a variation written for a different risk profile, and a balance threshold changes the rate again. Each variant carries its own exposure.
The Federal Trade Commission’s Credit Karma case shows how that scenario can play out. From 2018 to 2021 the company used A/B testing to serve “pre-approved” credit card offers, though nearly a third of the consumers who acted on one were then denied. The FTC’s January 2023 order required $3 million in redress. Regulators objected to the practice of optimizing toward the highest-converting language, which is what a marketing stack typically does by default.
Push notifications sharpen the tension. They are time-sensitive by design, so marketing optimizes for speed and legal review becomes friction the business routes around. However: “You’ve been pre-approved for a credit limit increase” is a representation about a financial product, and sending it as a notification does not lower the bar.
Key insight: Approving a personalization concept once still leaves thousands of individual claims ungoverned as the system generates them in production.
Practical next steps:
- Require the compliance function’s sign-off on the offer logic — and every claim variant it can produce.
- Build guardrails into the personalization engine so claims outside approved language cannot be sent.
- Give push and customer relationship management content a pre-cleared, time-boxed review lane. Log which variant reached which segment.
Read more: AI Can Help Banks Preserve Institutional Knowledge — Or Scale Your Worst Workarounds
Who Enforces This, and What They Have Been Doing
The FTC Act exempts banks from the commission’s own jurisdiction. Its cases still set a standard bankers get measured against, because the Office of the Comptroller of the Currency, the Federal Reserve and the FDIC apply the same unfair-and-deceptive test to the institutions they supervise.
In April, the OCC issued a consent order against The Federal Savings Bank in Chicago for deceptive acts and practices under Section 5 of the Act, tied to cash-out refinance loans guaranteed by the Department of Veterans Affairs. The findings describe claims no reviewer caught: ads telling consumers they had “available funds” that could only be reached by taking a new loan, and an impression that rates or payments would fall on a fixed-rate permanent loan. Under the order, the bank agreed to pay restitution.
Design carries the same exposure as marketing copy. The FTC’s Prime case, which Amazon settled for $2.5 billion in September 2025, turned on billing information collected before the $139 annual cost and automatic renewal were clearly disclosed.
Yet cases like that rarely begin with anyone deciding to deceive.
A product team tunes one element to lift conversion. Somewhere else, UX rebuilds the funnel, the legal team reviews the terms it was handed. No one asks what the finished screen leaves a customer believing.
A critical deadline approaches. The FDIC’s official sign rules require the digital sign across digital deposit-taking channels and ATMs, and prohibit misrepresenting insured status. The rules are in effect now, with mandatory compliance required by April 1, 2027. Meeting it means knowing every digital surface where the bank takes deposits.
Why it matters: Consumer protection obligations reach the design layer, so a page can fail even when each element on it would pass review alone.
Practical next steps:
- Put a compliance checkpoint inside product and UX processes, and judge flows on the impression the full screen creates.
- Audit enrollment, add-on and cancellation flows, and make cancellation at least as easy as sign-up.
- Map every digital deposit channel against the FDIC’s signage rules immediately.
Read more: Can the Martech Ecosystem Survive the Next Wave of AI?
Modernizing the Bank’s Review Layer
Institutions that publish at digital speed without piling up this exposure supplement human review with technology that runs at the speed of the content, covering the full estate instead of a sample and flagging high-risk claims for a person. In this way, someone who once cleared routine copy all day can concentrate on the claims that carry real risk.
Examiners have started to describe what they expect from that shift. In April the OCC, Federal Reserve and FDIC issued updated model risk management guidance that is explicit about validating vendor and third-party products. Generative and agentic AI fall outside its scope — for now — and the agencies have said they plan to seek comment on banks’ use of AI. The OCC’s Spring 2026 Semiannual Risk Perspective report points the same way, favoring human-in-the-loop accountability as adoption spreads.
Key insight: Putting technology into the review layer is a governed activity in its own right, with validation and clear ownership expected alongside it.
Practical next steps:
- Judge a tool on whether it reaches the full content estate before judging how well it reads one asset.
- Start with the highest-volume, highest-exposure channel, prove the model, then extend it.
- Document how any tool in the review path was validated and who owns it, in line with the April guidance.
Read more:
Your Bank Has Two Years, Max, to Become Visible to AI
Marketing Modernization Needs Modern Risk Management
Compliance review has not modernized at the pace of the marketing and product functions it governs, and that is no longer theoretical. The OCC’s April order shows a bank paying restitution over claims that went out through its own marketing channels.
Banks spent more than a decade proving that digital ambition and customer trust can coexist. Compliance review is the last function that has yet to modernize on the same terms. Most teams ask what automation might miss. Yet the harder question is what their manual process is missing right now, with no way to see it.
Read next: Why Digital Leader Chase is Ramping Up Marketing for its Expanding Branch System
