Study the CCBCO domains as a decision workflow rather than a rule list: identify the trigger (who the borrower is, what the product does, where the data flows), name the governing requirement, state the required action, and document the reasoning. The sections below cover insider lending under Regulation O, the UDAAP and fair lending distinction, CRA versus HMDA, suspicious-activity decision points, third-party risk accountability, a case-analysis method with two worked scenarios, and a preparation sequence with readiness checks. Administrative details such as eligibility, scheduling, and fees belong to the credential issuer; confirm those directly with the ICBA rather than relying on secondhand summaries.
Regulation O insider loans: what changes when the borrower is an insider
When a loan applicant is a director, executive officer, principal shareholder, or an institution-affiliated party, Regulation O adds requirements on top of ordinary underwriting: the loan must meet standards on terms, and certain extensions require prior board approval and reporting.
The first decision point is classification, not terms. A person who appears to be an ordinary customer may in fact be a director, a related interest of a director, or a political organization controlled by an insider, and each category carries different obligations. Practice by taking your institution's org chart and listing which roles count as insiders, then tracing how a related-interest relationship, such as a company an executive controls, extends the rules to a business borrower.
The second decision point is what to do once classification is confirmed. Compare the proposed loan's terms against what the bank offers unsecured borrowers generally, check whether the extension type requires board approval beforehand, and confirm the documentation records both the classification analysis and the approval trail. In a scenario, a plausible mistake is treating a sizable insider request as a routine rate exception handled in the loan file alone; the better decision runs the Regulation O checklist first and documents the insider determination before underwriting continues.
UDAAP versus fair lending: two different consumer-protection lenses
UDAAP asks whether a product or practice is unfair, deceptive, or abusive in how it treats consumers generally; fair lending asks whether similarly situated applicants are treated differently on prohibited bases such as race, sex, or age. One addresses the practice itself, the other the distribution of outcomes.
Keep the lenses separate when analyzing a fact pattern because the evidence you look for differs. A UDAAP review examines disclosures, marketing claims, fee mechanics, and whether consumers can reasonably avoid harm. A fair lending review examines underwriting discretion, pricing variance, steering, and comparisons of treatment or outcomes across protected classes. A fee structure can be fully disclosed and still raise a UDAAP question if it is burdensome without offsetting benefit, while an identical fee applied uniformly could still raise a fair lending question if exceptions flow unevenly.
Work a marketing scenario to see the split. Suppose a promotional mailer highlights a low teaser rate in large type while the ongoing rate and fees appear only in dense fine print, and suppose branch referrals for that product skew heavily toward one neighborhood. The UDAAP analysis focuses on whether the presentation creates a deceptive net impression; the fair lending analysis focuses on whether access and steering differ by prohibited basis. Writing both analyses separately, even in two sentences each, is the habit that exam-style case questions reward.
CRA and HMDA: what each framework measures and where they diverge
CRA evaluates how a depository institution serves its entire assessment area, including low- and moderate-income communities, across lending, investment, and services. HMDA is a data reporting regime for covered mortgage applications. They overlap in geography and subject matter but differ in scope, purpose, and output.
A productive comparison exercise: map each framework's trigger, scope, and deliverable. HMDA attaches to specific covered loan types and produces reportable data points about applications and originations. CRA attaches to the institution and produces an evaluation of community-borrower service in a defined assessment area, considering retail lending plus community development activity and service availability. A bank can be diligent on HMDA data quality yet thin on CRA-qualifying community development activity, and vice versa; the two findings do not substitute for each other.
In case scenarios, the trap is borrowing an answer from the wrong framework. If a question describes a branch closing in a rural part of the assessment area, the relevant CRA lens is service performance and how the bank meets community needs, not HMDA reporting accuracy. If a question describes inconsistent recording of applicant ethnicity on mortgage applications, the HMDA lens governs, though fair lending may follow. Practice tagging each fact in a scenario with the framework it belongs to before drafting any conclusion.
BSA/AML decision points: what you do at each escalation step
Bank secrecy framework decisions follow a sequence: know your customer through due diligence, monitor for unusual activity, investigate anomalies, decide whether activity is suspicious, and if so file the required report while keeping the decision confidential and documented.
The decisions most worth drilling are the ones between monitoring and reporting. Unusual is not the same as suspicious: an anomaly may resolve with an ordinary business explanation, and the investigation record should show what you asked, what the customer said, and why you concluded the activity was or was not suspicious. Practice writing both outcomes for the same fact pattern, because the file must support either path. Also practice the confidentiality rule: a decision to file, or even an internal inquiry, must not be disclosed to the customer involved.
A paper scenario to rehearse: a business account shows a series of cash deposits just under a round-number reporting threshold, followed by a large outgoing transfer. A plausible mistake in the scenario is quietly closing the account to make the problem disappear without completing the review or considering whether a suspicious activity report is required, which both loses the documentation trail and risks tipping off the customer. The better decision is to complete the investigation, apply your institution's decision standard, file if the standard is met, and retain the analysis. Your bank's own procedures govern the specifics; learn the sequence and the reasoning requirements rather than memorizing amounts.
Third-party risk: compliance accountability you cannot outsource
When a community bank relies on a vendor for lending support, servicing, deposits, or technology, the bank remains responsible for consumer-protection and compliance outcomes. The regulatory expectation is oversight proportionate to the risk and criticality of the activity, evidenced in writing.
The decision skill here is matching oversight depth to risk. A low-risk, easily substituted service may need lighter due diligence than a vendor that handles consumer loan decisions or customer data, where the bank should be able to show how it selected the provider, reviewed the arrangement, monitored performance, and would respond to deficiencies. Read a service agreement in scenarios with the question 'if this vendor fails, what compliance exposure lands on us?' rather than only 'is this a good price?'
Scenario practice: a fintech partner markets a deposit-adjacent product using the bank's name, and the marketing copy contains a claim your own disclosures would not support. A plausible mistake is concluding the claim is the vendor's responsibility because the agreement assigns marketing duties to them. The better decision treats the consumer-facing statement as the bank's UDAAP exposure, requires correction, and feeds the gap into the vendor monitoring record. That chain, from vendor action back to bank accountability, is the reasoning pattern to internalize.
Case analysis method: turning a fact pattern into a documented decision
For exam-style scenarios, use a fixed four-step response: classify the trigger, name the governing requirement, state the required action, and note the documentation. Practicing the same structure across domains builds speed and prevents gaps.
Worked scenario one, insider lending. Facts: a long-serving director's son applies for a working capital loan for a business the director co-owns. A plausible mistake is evaluating the son as an unrelated customer because he is not himself a board member. The better decision recognizes the related-interest concept, runs the Regulation O analysis for insider-affiliated extensions, verifies the terms against the bank's general standards for comparable credit, checks whether board approval and the applicable notices apply, and documents the relationship finding before underwriting advances. Why it matters: the classification drives everything downstream, and a missed related interest is invisible in the loan file if no one wrote the analysis down.
Worked scenario two, suspicious activity. Facts: a retail customer with modest stated income begins repeated same-day transfers in and out immediately after each deposit arrives. A plausible mistake is flagging the account informally in a shared inbox and waiting for a pattern 'to develop' without a recorded investigation. The better decision opens the internal review, gathers the account history, seeks a business explanation, applies the institution's suspicious-activity standard, files if warranted, and preserves the memo, while ensuring no one contacts the customer about the inquiry. Why it matters: both the escalation and the confidentiality duty are procedural obligations, so the reasoning trail is itself part of compliance, not an afterthought.
| Domain | Trigger to recognize | First governing question | Primary documentation |
|---|---|---|---|
| Regulation O | Applicant is or relates to a director, executive officer, or principal shareholder | Does this extension meet insider-lending standards and approval requirements? | Insider classification analysis and approval record |
| UDAAP | Product, fee, or marketing practice affecting consumers | Is the practice unfair, deceptive, or abusive as presented? | Practice review with net-impression analysis |
| Fair lending | Discretion, pricing, steering, or outcome differences | Are similarly situated applicants treated consistently across prohibited bases? | Treatment or comparative analysis notes |
| CRA | Institutional performance in its assessment area | How does the bank serve low- and moderate-income communities? | Assessment area performance summary |
| HMDA | Covered mortgage applications and originations | Are required data points complete and accurate? | Reporting data and correction log |
| BSA/AML | Unusual activity or transaction patterns | Is the activity suspicious under the institution's standard, and is confidentiality preserved? | Investigation memo and, if applicable, report copy |
| Vendor risk | Third party performs regulated activity or holds data | Does oversight match the activity's risk and criticality? | Due diligence and monitoring record |
Preparation sequence and readiness checks for the CCBCO domains
Structure preparation as rotating passes through the six domain areas, one week per pass: compare two adjacent concepts, complete two paper scenarios, write two decision memos, and score yourself against a rubric before moving on.
A realistic adaptable sequence: week one, map the domain areas to your own bank's policies and list which concepts you can already explain in three sentences. Weeks two through five, rotate through the topic pairs in this guide, insider lending, UDAAP versus fair lending, CRA versus HMDA, BSA/AML decisions, and vendor risk, producing one written decision memo per session. Week six, run mixed scenarios from all domains in random order under time pressure. Week seven, review your memo file and target the domains where your rubric scores dipped. Adjust pacing to your schedule; the sequence matters more than the calendar.
Use this self-check rubric for every memo, scoring each item 0 to 2 (0 absent, 1 partial, 2 complete): trigger correctly identified; governing requirement named; required action stated concretely; documentation noted; adjacent-rule confusion avoided. A total of 8 or more out of 10 across consecutive memos is a reasonable learning milestone that you have internalized the decision structure; treat it as a study signal, not a prediction of any particular exam outcome. Pair the rubric with these readiness checks: you can state the difference between unfair and deceptive without notes; you can explain why a related interest triggers insider rules; you can list the escalation steps in a suspicious-activity review in order; and you can say what bank-level accountability survives a vendor contract.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
