A deal jacket audit checks four separate things most checklists mash into one list: federal disclosure rules (Used Car Rule, odometer), federal data-security rules (Safeguards Rule, GLBA), lender stipulations, and state DMV title requirements. Each has a different checker, a different failure mode, and a different definition of “complete.” This checklist organizes by regulator, not by form name.
Why organizing by form name doesn’t work
Most deal jacket checklists read like a table of contents: Buyers Guide, odometer statement, credit application, privacy notice, proof of insurance, title application, bill of sale. It’s accurate, and it’s also close to useless during an actual audit, because it tells you what’s in the folder without telling you what “correct” means for each piece or who’s going to be the one who finds it wrong.
A missing signature on a Buyers Guide is an FTC matter. A missing MFA control on the system that stores the credit application is a Safeguards Rule matter. A missing stip is a lender matter that can freeze funding on that specific deal. A wrong VIN digit on the title application is a state DMV matter that bounces the whole package back. Four different reviewers, four different consequences, four different definitions of “done.” A checklist organized by form name treats them as one undifferentiated pile, which is exactly how a jacket that looks complete on the surface fails when the right person actually opens it.
The worst findings rarely show up as a blank field. Say an expired license that slipped through, a red-flag report that was pulled but never uploaded, a disclosure filed under the wrong deal entirely: none of those are missing documents. They’re documents that exist somewhere in the operation but weren’t verified, weren’t attached to the right deal, or weren’t checked against what else was in the jacket. The FTC’s own enforcement history backs up why that distinction matters: in an August 2024 case against a dealer group, regulators specifically criticized the scope and adequacy of the group’s existing audit program, not a single missing form (ComplyAuto).
The Used Car Rule layer: what the FTC checks
The FTC’s Used Car Rule (16 CFR Part 455) has been in effect since 1985 and requires a Buyers Guide window sticker on every used vehicle offered for sale, disclosing whether the vehicle carries a warranty (and its terms) or is sold “as is.” The 2023 update added a QR-code option that links to the same disclosures online, but the underlying requirement didn’t change: the disclosure has to exist, has to be accurate, and has to match what the customer actually signed at delivery (FTC, Dealer’s Guide to the Used Car Rule).
What an auditor checking this layer looks for:
- A Buyers Guide present for every used unit, with warranty terms (or "as is" language) filled in, not blank
- The signed copy in the jacket matching the window-sticker version, not a generic template
- No conflict between the Buyers Guide warranty language and what F&I actually sold (a service contract sold after the fact should be reflected, not contradicted)
This is enforced under FTC Act Section 5 as an unfair-or-deceptive-practice matter, which means the exposure isn’t just a bounced form, it’s a federal consumer-protection violation (FTC Used Car Rule, Legal Library).
The odometer disclosure sits in this same federal layer but under a separate statute: 49 CFR Part 580, implementing the Truth in Mileage Act. Every ownership transfer requires an odometer disclosure at the time of transfer, dealers must retain records for five years, and discrepancies have to be flagged rather than smoothed over. Violations carry civil penalties that scale per violation, which is a different math than “one bad form” (eCFR, 49 CFR Part 580).
The Safeguards Rule layer: what actually gets audited isn’t the paper
This is the layer most deal jacket checklists skip entirely, because it isn’t about a document in the folder, it’s about the system the folder lives in.
Because most dealers extend or arrange financing, they qualify as “financial institutions” under GLBA and fall under the FTC Safeguards Rule (16 CFR Part 314). The rule requires a written information security program, and a 2021 amendment specified controls that apply directly to how a deal jacket is built and stored: encryption, multi-factor authentication, access controls, monitoring, and a designated Qualified Individual responsible for the program (FTC, Safeguards Rule FAQs for Auto Dealers). A 2023 amendment added a breach-notification requirement to the FTC for incidents affecting 500 or more consumers.
What an auditor checking this layer actually looks for isn’t in the jacket itself:
- Who has access to the credit application, SSN, and bank statements inside that jacket, and whether access is logged
- Whether the digital storage system enforces MFA and encryption, not just a locked filing cabinet
- Whether a privacy notice under GLBA's companion Privacy Rule (16 CFR Part 313) was actually given to the customer, and whether opt-outs were honored (FTC, GLBA overview)
This is the layer most likely to be invisible to a clerk running through a paper checklist, because the failure isn’t a missing signature, it’s an access log nobody ever set up. It’s also why the FTC Safeguards Rule and your back office deserves its own read separate from a jacket checklist: the control lives at the system level, not the folder level.
The lender stipulation layer: what the funding desk checks
Stipulations, proof of income, proof of residence, ID, insurance, are the layer most operations teams already feel every day, because a missing stip is the single fastest way to freeze funding on a specific deal. Some lenders are now using AI-driven data verification to remove the need for certain stips entirely rather than just processing the same paperwork faster, which says something about how much of this friction is a documentation-collection problem and not a customer-cooperation one (AutoSuccess, “Skip the Stip”).
What makes this layer different from the federal disclosure layer: the lender defines what “complete” means, and that definition varies lender to lender and sometimes deal to deal. A stip package that satisfies one funding source can be incomplete for another. An audit against this layer has to check the jacket against the specific lender’s stip sheet for that deal, not a generic list, which is the step most internal audits skip because it requires cross-referencing outside the jacket itself.
The state DMV layer: what actually bounces a package
This is the layer with the most concrete, most frequently cited failure data. In order of frequency, the top reasons state DMVs reject dealer paperwork are: missing signature or notarization (described as “the top rejection reason by far”), an incorrect or incomplete VIN (a single digit typo is enough), a wrong fee or tax calculation (which varies state by state), lienholder errors (especially common on dealer-financed deals), and outdated state forms (Allstate Tags / Barry Risk Management).
None of those five require the DMV to catch anything subtle. They’re mechanical: a field is blank, a number is transposed, a form version is one revision behind. Which is exactly why they’re the highest-volume rejection category and the easiest one to actually eliminate with a consistent pre-submission check, rather than the hardest.
Putting the four layers together
| Layer | Who checks it | What “complete” means | Typical failure |
|---|---|---|---|
| Used Car Rule / odometer | FTC | Buyers Guide present, accurate, matches delivery; odometer disclosure filed at transfer | Blank warranty field, unflagged mileage discrepancy |
| Safeguards Rule / GLBA | FTC (system-level) | Access controls, encryption, MFA, privacy notice given | No access log, no MFA on the storage system |
| Lender stipulations | The funding source | Every stip on that lender’s specific list is resolved | Missing proof of income/insurance, deal-specific stip skipped |
| State DMV title | State DMV | Signature/notarization present, VIN and fee correct, current form version | Missing notarization, VIN typo, outdated form |
An audit that walks the jacket once against all four layers, rather than four separate reviewers each checking their own slice weeks apart, catches the internal-consistency failures that single-layer reviews miss: a Buyers Guide that says one thing and a service contract that says another, or a title application with a name format that doesn’t match the credit application on file. Production data from document review at scale backs this up: in one sample, 24 out of 24 rejections traced back to the same root cause, name or suffix mismatches (Jr./Sr., middle names, “Last, First” order) paired with an un-notarized affidavit.
Failure mode
A single-layer check would have passed the notarization field and missed the name mismatch, or caught the name issue and missed the notarization. It took checking both at once to catch either.
FAQ
What should a deal jacket audit specifically verify?
That every required disclosure (Buyers Guide, odometer statement, privacy notice), signature, and lender stipulation is present, correctly filed under the right deal, and internally consistent with the other documents in the jacket. Consistency across documents catches more real problems than checking each document in isolation.
How often should deal jackets be audited?
Best practice is a rolling spot-check on a sample of recent deals continuously, not a reactive audit that only happens after a lender or OEM flags a problem. By the time an external party catches the gap, the exposure window (funding delay, chargeback, compliance penalty) has already opened. A continuous sample surfaces the same pattern of errors while it’s still cheap to fix.
Where this fits in the compliance stack
A single deal jacket checklist is one piece of a larger compliance picture. For the full picture of what a dealership’s compliance stack needs to cover in 2026, see The Auto Dealer Compliance Stack. For the Used Car Rule specifically, what the Buyers Guide actually requires goes deeper on that single layer. And because deal jackets almost always contain a title, how NMVTIS title-brand checks should fit your buying workflow covers a check that belongs earlier in the process, before the jacket is even assembled.
Running this four-layer check by hand on every deal doesn’t scale much past a handful of units a week, which is why the operations teams who’ve stopped treating audit prep as a fire drill have moved the cross-referencing itself into an AI-operated workflow that checks disclosures, access logs, stips, and DMV fields against each other on every deal, not just the ones that get sampled.
This article summarizes public information for operations teams and is not legal advice. Requirements change; always confirm with the linked official state source or your compliance counsel.