A complaint program is not a complaints table
Regulators require a program. Most platforms ship a list with a status column.
Including the questions we would rather you did not ask us. Ask them anyway.
Buying compliance infrastructure from a young company is a real risk, and the usual advice — buy from the incumbent — is often wrong in a market where the incumbents are the subject of the enforcement actions. So here is how to run the evaluation properly, including the parts that are uncomfortable for us.
Every claim in this category is a behavior, so every claim can be shown. Ask them to attempt the thing their platform forbids while you watch. Ask them to produce a complete file for a loan you pick. Ask what happens when a required credential expires, and then watch it happen in a test account.
A vendor who reaches for a slide when you ask for a demonstration is telling you something.
The single most useful question, and the answer is diagnostic either way. A vendor with a specific, unprompted list is a vendor whose other claims you can weigh. A vendor who says everything is complete is either not listening or not telling you the truth, and you will find out which during implementation.
"What have you not built?" is the highest-information question in a vendor evaluation. Vagueness is the answer, not the absence of one.
The risk of a young vendor is real. So is the risk of continuing to originate against a record that cannot answer an examiner's questions. Both belong in the comparison, and only one of them is usually written down.
Run the evaluation on demonstrations, not descriptions — and give the most weight to what a vendor volunteers about its own gaps.
Pick a closed project. We will show you the document you would hand a regulator. If it does not answer the question, nothing else matters.