Q

Conference & Expo: September 22-23, 2026
DealerPoint: April 5-7, 2027

Q

Compliance Considerations Are Becoming a Larger Part of the Technology Modernization Discussion for Dealers & Lenders

Published: September 10, 2026

For many years, platform migration in auto lending was framed mostly as an efficiency question: faster origination, lower operating costs, better borrower experience. That framing is shifting. Regulatory change, audit expectations, calculation complexity, and the need for better documentation are increasingly part of the modernization discussion.

For many dealers and lender partners, compliance may not be the only reason to evaluate legacy systems, but it is becoming harder to separate technology decisions from the ability to implement, test, and document compliant lending logic.

Regulatory Expectations Are Moving Faster Than Legacy Systems Can Follow

Auto lending compliance has always required monitoring federal and state law changes, but the operational burden of implementing those changes is becoming more visible as products, channels, data practices, and technology integrations become more complex.

New requirements are converging, and each one touches the technology responsible for enforcing it. The CFPB’s Personal Financial Data Rights Rule originally included phased compliance dates running from 2026 through 2030, but those dates have since been stayed, and the rule is under reconsideration. Even so, the rulemaking illustrates the broader trend: consumer financial data access, third-party connectivity, data security, and documentation are becoming increasingly important technology and compliance considerations.

Organizations are taking notice, with compliance-related risks ranking as the most commonly cited operational challenge today at 35.4%, ahead of security risks and aging technology according to a recent survey of lending professionals across banking, auto finance, and fintech.

Regulatory changes are rarely written with a specific loan origination system, servicing platform, or calculation engine in mind. However, lenders must ultimately operationalize those requirements somewhere within their technology stack, whether through system configuration, calculation logic, workflow controls, reporting, or supporting documentation.

For institutions operating on legacy core platforms, including AS/400 and COBOL-based environments that remain common throughout parts of the lending industry, implementing and testing changes can require significant development effort. Even where the required logic is ultimately achievable, highly customized or aging systems may increase the time and resources needed to implement, validate, and document updates.

That gap becomes especially visible when an institution expands into a new state or asset class, since expansion often brings compliance obligations it has never faced before, and a platform that cannot be reconfigured quickly leaves compliance teams reacting to gaps rather than anticipating them.

The Calculation Accuracy Risk Hiding Inside Aging Platforms

Compliance exposure is not only about keeping pace with new rules. It is also about whether current systems are correctly executing the rules already in place. Calculation logic for interest, fees, APRs, refunds, payment schedules, and state usury limits cannot be treated as a one-time implementation item. When laws change, interpretations evolve, product structures change, or system updates are released, lenders need a process for determining whether calculation logic must be reviewed, tested, documented, or updated. Without that discipline, issues may remain hidden until an audit, examination, complaint, or portfolio review brings them forward. Consider that calculation accuracy was cited by 23.2% of survey respondents as the area in their platform most in need of modernization, a significant share given the downstream compliance implication of inaccurate consumer lending calculations.

This risk can be difficult to detect because calculation issues may repeat across transactions and remain unnoticed until the portfolio is reviewed.  For calculation compliance, the key issue is not only whether an output appears correct on a single transaction. Lenders also need to be able to explain the logic, show the legal or business rule being applied, demonstrate testing, and maintain evidence that updates were reviewed and implemented when appropriate. That burden becomes harder when critical calculation logic is poorly documented, highly customized, or dependent on institutional knowledge that is no longer readily available.

Modernization Is Becoming a Compliance Strategy, Not Just a Technology Upgrade

The regulatory picture extends beyond U.S. borders. In the European Union, the AI Act became fully enforceable for certain high-risk systems in August 2026, including some applications involving creditworthiness and automated credit decisioning. That development reflects a broader trend: as technology plays a larger role in lending decisions, institutions are increasingly expected to maintain appropriate governance, documentation, oversight, and auditability around the systems they use.

For that reason, modernization decisions should not be treated as IT-only projects. Compliance, legal, risk, operations, and business teams should be involved early enough to identify the rules, calculations, controls, and documentation requirements the platform must support.  A platform that can adapt to new documentation, monitoring, and reporting demands without lengthy custom development cycles gives an institution a materially different risk profile than one that cannot.

At the same time, integrating new regulatory technology into decades old cores remains a genuine technical challenge, not a simple decision. Many institutions still rely on legacy systems that were never designed to talk to modern compliance tooling, and compatibility between old and new remains one of the central obstacles to adopting stronger monitoring and reporting capabilities. That is precisely why the migration conversation and the compliance conversation are converging into one, rather than competing for the same budget.

What This Means for Institutions Weighing a Migration Decision

For institutions still deciding whether to modernize, the calculus has changed. The question is no longer only whether a legacy platform can keep functioning. It is whether that platform can demonstrate, on demand, that its calculations are accurate, its models are explainable, and its data practices meet requirements that did not exist when the system was built.

Institutions evaluating this tradeoff are well served by asking a narrower set of questions:  How quickly can the current platform implement a required calculation or disclosure change? Who can explain the logic being applied? What regression testing is performed before and after updates? What documentation would be available if an examiner, auditor, client, or regulator asked how the result was produced?

As regulatory expectations expand across data rights, AI governance, and consumer protection, the institutions best positioned are not necessarily the ones that migrated first, but the ones whose technology can adapt as quickly as the rules do.

Related Stories:

Sarah Milovich is General Counsel and VP of Compliance for Carleton, the country’s leading provider of financial calculation software, loan origination compliance support, and document generation software. For more information, please visit www.carletoninc.com.