FFIEC Social Media Guidance for Mortgage Lenders and Banks
When the Federal Financial Institutions Examination Council (FFIEC) issued its FFIEC guidance on social media in 2013, it didn’t invent new regulations. It did something more important for your compliance program: it confirmed that the Truth in Lending Act, the Real Estate Settlement Procedures Act, the Equal Credit Opportunity Act, and the dozen other laws already governing your institution apply directly to Facebook, LinkedIn, TikTok, and every other platform your institution uses. There’s no separate rulebook for social media. There’s only the law, applied everywhere, and examiners have their own expectations for rule application to digital advertising like social media.
What This Guidance Actually Says
The FFIEC issued this guidance on behalf of its five member agencies: the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve, the FDIC, the National Credit Union Administration, and the Consumer Financial Protection Bureau. Examiners use it to assess your institution’s social media program. Your compliance program should account for it before they ask.
The guidance itself doesn’t rewrite the rules. Instead, it clarifies something institutions had been asking for years: which existing laws apply to social media activity, and how? The answer is straightforward. If a regulation applies to a printed brochure, a radio spot, or an email, it applies to the post your marketing team publishes on Instagram. There’s no medium exception in the regulatory framework.
Key Takeaways
- The FFIEC guidance confirms that existing regulations apply to social media platforms like Facebook and LinkedIn.
- It clarifies that if a law applies to traditional advertising, it applies to social media posts as well.
- Institutions need a robust risk management program proportional to their social media usage, addressing governance, policies, and training.
- Compliance risks concentrate in legal areas and reputational impact; institutions must manage both effectively.
- Establishing clear documentation and monitoring processes is crucial for compliance with FFIEC expectations.
The FFIEC defines social media broadly: any interactive online channel where users generate and share content through text, images, audio, or video. This covers short-form platforms like TikTok and Instagram, micro-blogging sites like X, professional networks like LinkedIn, industry forums, customer review sites, and blogs with public comments sections. If your institution posts to it, comments on it, or permits customers to post on it, this guidance treats it as social media subject to compliance review.
Why This Guidance Appeared
For years, institutions muddled through. Some compliance teams treated social media as a separate domain. Others waited for specific regulatory direction that never came. Financial institutions asked the regulators directly: What are the rules here? The FFIEC’s response wasn’t new rules. It was clarity: the existing rules already apply.
That clarity arrived because social media adoption accelerated faster than institutional compliance programs could adjust. By 2013, when the guidance was released, institutions were running customer acquisition campaigns on Facebook, publishing lending disclosures on LinkedIn, and watching employee posts create reputational risk on X. Yet many compliance teams still treated social media as something fundamentally different from traditional advertising. The guidance closed that gap.
What Your Risk Management Program Needs
The FFIEC doesn’t prescribe a one-size-fits-all compliance checklist. Instead, it expects your risk management program to be sized proportionately to how heavily your institution relies on social media. An institution driving customer acquisition through video content needs more robust controls than one maintaining a static corporate page. Even an institution that has chosen not to use social media at all should still monitor what customers are posting about your brand on public consumer review platforms.
At minimum, your program should address these components:
- Governance structure: Your board of directors or senior management should direct how social media supports your strategic goals and set in place controls to assess risk on an ongoing basis. This isn’t a task force tucked somewhere in marketing. It requires board-level awareness and explicit authorization.
- Written policies and procedures: Document how your institution uses social media, who may post, what approval process applies, how edited or deleted posts are handled, and how records are retained. These policies matter only if someone is confirming your accounts actually follow them day to day.
- Third-party oversight: If external vendors or agencies manage your social media accounts, your risk management process should include how those vendors are selected, monitored, and held accountable for compliance.
- Audit and testing: An independent function should confirm that your institution’s social accounts are operating in accordance with your written policies and applicable law.
- Employee training: Staff who post on behalf of your institution should understand which laws apply to their activity. This isn’t generic “social media best practices” training. It should be specific to your institution’s products, your regulatory environment, and the compliance risks your institution faces.
Where Compliance Risk Actually Concentrate
The FFIEC groups social media risk into categories: compliance and legal risk, and reputation and operational risk.
- Compliance and legal risk: This is where the FFIEC’s core message lands. Eleven specific areas of federal law apply to social media activity, from TILA (lending disclosures and APR accuracy) to the Community Reinvestment Act. When you advertise rates, terms, or credit products on social media, advertising rules apply. When you collect consumer information through a social media contest or sweepstakes, state consumer protection laws apply. When you post about loan qualifications or pricing, fair lending rules apply. The regulatory surface area is significant.
- Reputation and operational risk: Public perception, platform policy changes, and the speed of social media amplification create risk independent of any specific regulation. An employee post that appears discriminatory might trigger no legal violation but serious reputational damage. A platform’s algorithm change might unexpectedly amplify your institution’s messaging to an unintended audience. A third-party vendor’s account compromise could expose customer data. These risks don’t fit neatly into a compliance checkbox, but they require governance just the same.
Building a Sustainable Program
- Start by documenting what your institution is actually doing on social media right now. The FFIEC outlines expectations that your monitoring program should be of substantially similar size to the amount of marketing activities you have. Many institutions can’t answer the question: What accounts does your institution operate, who has access, what is posted, and how often? That inventory is foundational. Without it, you can’t assess risk.
- Align your written policies with the FFIEC’s expectations and your regulatory environment. Policies should specify approval workflows before posting, clear rules on what products or claims can be mentioned, how customer service inquiries through social media are handled, and what records must be retained. Policies should also address employee behavior: what loan officers can post from personal accounts that reference your institution.
- Build the monitoring infrastructure. Many compliance teams rely on spreadsheets or informal processes. As your social media footprint grows, this becomes untenable. Structured monitoring, whether through a dedicated tool or a formalized review schedule, ensures consistency.
- Refresh your training annually. Social media compliance isn’t a once-and-done conversation. Platforms change. Regulations evolve. Your institution’s product mix may shift. Staff turnover happens. A sustained compliance program includes sustained education.
The Bottom Line
Your institution’s social media activity isn’t a separate compliance domain. It is subject to the same regulatory framework that governs every other communication your institution makes. Done right, this is manageable. It requires intentional governance, clear written policy, and consistent oversight. Your regulators will expect evidence of all three during examination. Building that evidence now, while social media remains a relative priority for compliance teams, is far better than scrambling to reconstruct it during a review.
ActiveComply Social monitors your institution’s social media activity against this guidance continuously, instead of relying on a periodic manual review.
See how ActiveComply Social works, or talk to our team.

Melissa Grindel
Head of Compliance & Industry Strategy
Melissa helps institutions develop and execute compliance policies and procedures while providing support through regulatory examinations. Melissa has acted as a content expert for The American Bankers Association, the National Mortgage Bankers Association, The Mortgage Collaborative, HousingWire, MGIC, numerous state MBAs, and other financial industry groups & publications.