
Dealerships have one of the highest employee turnover rates of any industry. According to many studies, it ranges from 34 percent to 80 percent annually depending on the role.
In fact, the average tenure of a car salesperson is under two years. Finance and insurance managers, desk managers and even general sales managers cycle through stores at a pace that would alarm most business owners.
For most operational challenges, turnover is expensive but manageable. For compliance, it’s a liability time bomb.
The problem: Your process leaves when your people do
Most dealerships rely on training to maintain compliance. Onboarding sessions, policy walkthroughs, the occasional refresher all are well-intentioned — and all temporary.
When your trained salesperson walks out the door and takes a job across the street, they take with them your compliance process.
The new hire doesn’t know personal phones aren’t allowed for ID photos. They don’t know the dead deal jacket goes in a specific place and has to be retained for five years. They don’t know pulling credit without documented permissible purpose is a direct violation of the Fair Credit Reporting Act.
They’ll find out eventually. Unfortunately, so will your attorney.
Access control is one of the most important parts of cybersecurity. Unfortunately, it’s also one of the most overlooked. Employees accessing more information than what’s necessary places the entire dealership in danger.
This isn’t a hypothetical. In 2026 with the Federal Trade Commission’s Safeguards Rule fully in force and plaintiffs’ attorneys actively hunting for compliance gaps, the cost of a single misstep never has been higher.
One Dallas-area dealership recently paid $270,000 to settle a case involving a single missing dead deal jacket. Not a fraud scheme, not a data breach. One deal. One missing document.
What compliance actually requires at a dealership
The FTC Safeguards Rule expanded recently from two pages to 145 pages of requirements. The technical side — penetration testing, multi-factor authentication, vendor management — gets the most attention. But the administrative and physical obligations are where dealers get exposed every single day.
Here’s what compliance requires on every transaction from the moment a customer enters the funnel.
- Showroom: Driver’s license scanned and validated — not photographed on a cellphone. Same with insurance and other documents;
- Credit application: Customer’s information collected securely;
- Credit pull: Red Flags Rule, Office of Foreign Assets Control and Credit Score Disclosure notice provided;
- Desk: Deal structured with accurate payment calculations before presenting to the customer, and clear documentation of complete details of the first offer (an incoming regulation);
- F&I: Adverse action letters issued if required; deal jacket complete and accounted for;
- Post-sale: Dead deal jackets collected, organized and retained for five years per Fair Credit Reporting Act requirements.
That’s not a training checklist. That’s a process that must be executed correctly on deal number one and deal number 500, on a slow Tuesday and a packed Saturday afternoon.
Turnover doesn’t pause compliance requirements. But it absolutely disrupts compliance execution.
Why training alone doesn’t work
Here’s the hard truth about compliance training in a high-turnover environment: you can’t train your way out of a staffing problem.
Training is a snapshot. It reflects what employees knew on the day they went through onboarding. It assumes they’ll remember it six months later during a chaotic Saturday when a customer is standing at the desk.
It also assumes they’re still working for you.
The dealers who stay consistently compliant aren’t the ones with the best training programs. They’re the ones who’ve built compliance into the workflow itself so that doing the job correctly and staying compliant are the same thing. The guardrails are in the system, not in the employee’s memory.
This is no different than calculating payments, making journal entries or generating a stock order. All these tasks started as manual and have been standardized and improved with technology. Yet the most regulated, most expensive, most variable process and transaction is still largely reliant on people!
The airport model for dealership compliance
Think about the last time you flew. The airport doesn’t rely on travelers remembering the security process. It builds the process into the environment.
You stand in a line. Your identity is verified. You put your bag on the belt. You walk through the scanner. None of it is optional, regardless of how many times you’ve flown or whether you have TSA Pre-Check.
A dealership’s compliance process should work the same way.
Every customer, whether they walked in off the street, submitted an online lead or started a deal remotely should move through the same steps. The process should be consistent, repeatable and enforceable regardless of who’s working that day.
That last part is the key. Enforceable — not dependent on the right employee being in the building.
Doug Fusco is managing partner of compliance at Informativ.
Recent Posts
- Permissible Purpose vs. Consumer Permission: What Every Dealer Needs to Know Before Pulling Credit
- Do You Need an SSN to Run a Credit Check?
- Soft Pulls Aren’t a Compliance-Free Zone
- Not All Borrowers Are Created Equal & the Law Requires You to Say So: Risk-Based Pricing & Credit Score Disclosure Notices Explained
- When AI Tries to Buy a Car