Safeguarding Collateral Happens Between Audits

Published on

October 9, 2026

Blog Thumbnail

Recently we read "A Lender's Guide To Fraud: Safeguarding Collateral," a Law360 piece by Zachary Smith and Christopher Tomlinson of Moore & Van Allen. It's the second installment of their series on fraud in lending, published September 15, and its case is that a secured lender protects its collateral with two tools: carefully negotiated credit and security agreements, and periodic collateral audits. We agree with both recommendations. We'd add that both work in intervals. The contract does its work at signing and again at default, and the audit does its work on the day someone visits. A dealer's situation changes in the weeks between, and the article's own examples show what that gap costs.

A security agreement is the document a lender reads after something has gone wrong. Covenants define the default, the default gives the lender the right to act, and acting means enforcing against collateral. That whole sequence assumes the collateral is still there. In a floor plan fraud, by the time anyone is enforcing covenants, the units are gone, either sold with the proceeds kept or financed a second time on another lender's line.

If you need the contract, you're already in trouble.

The contract is a recovery tool

None of this argues for weaker documents. Reporting obligations, inspection rights, insurance requirements and limits on transactions outside the ordinary course belong in every floor plan agreement, and a lender without them has fewer options when a dealer fails. But most of them work by handing the lender a right it can exercise later. The one that produces information along the way, borrower reporting, is written by the borrower.

Take the authors' recommendation that borrower reports be certified for accuracy by an officer. It's sound practice, and a dealer committing fraud will sign it. The signature strengthens the lender's claim after the fact. The report it's attached to is exactly as accurate as the dealer decides to make it.

Double-pledging shows the limit most plainly. When the same unit secures two lines, two well-drafted security agreements point at one vehicle. Priority rules decide which lender gets it. They can't produce a second unit, and the lender that loses on priority ends up with a claim against a borrower that has little left.

The documents need watching too. A UCC financing statement generally lapses five years after filing unless a continuation is filed in time, which is why UCC expiration sits in the same VeroOS alert catalog as a dealer's bank balance.

Audits verify a day

Collateral audits are invaluable. Someone has to stand on the lot and match a VIN to a physical unit, and no data feed replaces that. The OCC's floor plan handbook calls for checks "at least quarterly, but more frequently depending on the repayment terms as well as the dealer's reputation and financial condition." We wouldn't change a word of it.

But a field exam observes one day. On a quarterly cadence that's one day out of roughly ninety, and a unit sold out of trust the week after the auditor leaves stays invisible until the next visit.

Look at the three cases the authors cite.

At Broadband Telecom and Bridgevoice, according to the court filings the article references, the fraud ran for five years while regular audits and customer checks were taking place. The authors write that it appears those audits relied heavily on borrower-supplied documents that had been fabricated or manipulated. It ended when one of the lender's analysts flagged a fake email domain attached to a receivable.

At Tricolor, the authors write that the diligence and audits couldn't establish whether the same collateral had been pledged across multiple credit facilities, and that this appears to have prevented earlier detection. The SEC complaint they cite alleges Tricolor overstated its collateral by roughly $800 million.

Pride Group cuts the other way, and the audit deserves the credit. There, the double-pledged vehicles surfaced during a collateral audit run by one of its lenders.

So in two of the three, audits ran and missed it. The Broadband catch came from one of the lender's analysts noticing that an email domain was wrong, and we'd call that monitoring, done by hand. None of the three was a floor plan book, and Tricolor's problem, collateral pledged across separate facilities, isn't one a single lender's monitoring solves either. We come back to that below.

A pulse between audits

The authors make a point we'd underline. Their answer to fabricated collateral is a well-designed audit, because this kind of fraud "often can go undetected if lenders or auditors rely strictly on borrower-supplied documentation." The same principle holds in the months between audits: watch data the borrower doesn't author.

A dealer can keep a second set of books for one lender's benefit. Keeping bank deposits, payoff timing, title custody and audit history consistent with those books week after week is much harder, because someone else produces each of those records: the bank, the lender's own payment ledger, the title vault, the auditor.

VeroOS is built around that. With the dealer's bank account connected through Plaid, alerts fire when the balance drops by half inside a week or falls below a set share of the credit limit. Payoff behavior is tracked too, with an alert when the four-week payoff ratio falls below a set threshold. Audit results arrive at the item level, so a unit unverified on consecutive audits, or a newly floored unit that hasn't been audited within 30 days, raises its own flag. Missing titles and outstanding early title releases are counted per dealer. Those numbers are defaults, and the lender sets every threshold.

The alerts that matter most combine conditions. Deposits climbing while a dealer reports no sold units for several days is the pattern that points toward proceeds held out of trust, and VeroOS supports rules on exactly that mismatch between bank activity and reported sales. The mismatch shows up between site visits, in the stretch a periodic audit can't see.

An alert nobody owns is just a report, so in VeroOS a triggered condition becomes work. It's assigned to a risk manager, annotated, escalated or used to freeze the account, and each step stays on the record. Thresholds attach to dealer groups, which lets a lender hold a new dealer to tighter tolerances than a ten-year relationship.

One of the simplest alerts fires when a dealer's Plaid connection drops. Sometimes that's a changed password. Somebody should call either way.

Fewer routine audits, a better pulse

The authors acknowledge that lenders skip collateral audits "to avoid the time and expense," and allow that skipping one "can be a justifiable decision depending on the circumstances of a particular credit." We'd go a step further. The expense is the strongest argument for letting those circumstances, visible week to week, set the audit schedule.

On a fixed calendar, the dealer whose signals have been clean for three years gets the same visit as the dealer whose payoffs slowed last month. The lender pays for both, and the good dealer gives up a day of its staff's time for a check that confirms what everyone already knew. Good dealers notice.

A lender that can't tell its dealers apart between visits has to audit all of them as if they were its riskiest. Continuous signals let it tell them apart. A dealer whose signals stay steady between clean audits can move to a longer interval, within whatever floor the lender's own policy and its examiners set. A dealer whose signals drift gets an auditor this week instead of next quarter. Fewer routine visits cost less, and the visits that remain go where the data says something has changed.

On a floor plan book, proactive risk management means calling the dealer about a slowing payoff ratio while there's still collateral to protect, long before anyone reaches for the security agreement.

Where monitoring stops

One lender's monitoring sees its own dealer. It doesn't see another lender's ledger.

Floor plan had its own reminder of that this spring. In March 2026, Stellantis Financial Services and Ford Credit sued the same Iowa dealer group three days apart, and Ford Credit's filing identified 81 vehicles that appeared to be financed by both lenders. According to Ford Credit's petition, Stellantis flagged irregularities in February and told Ford Credit, and Ford's own review then turned up the 81 units.

The authors are right that catching collateral pledged to multiple creditors "typically requires reconciling pledged assets across creditors or credit facilities," and no single lender's system does that on its own. One lender can still see a mark double-pledging tends to leave in its own data: a title that never arrives. A rising missing-title count on a dealer is a reason to pick up the phone early.

Monitoring doesn't replace the field exam or the judgment of the people reading the alerts. It gives a risk team a reason to send the auditor somewhere specific, and a short list of questions for when they get there.

Where we'd end the guide

The authors close by noting that fraud schemes keep getting more sophisticated, and they say the next piece in their series will cover detection. We'll read it closely. Detection is where collateral gets protected. The contract is what a lender has left when detection fails.

The best outcome for a well-negotiated security agreement is that nobody ever has to enforce it.

See how VeroOS monitors dealers between audits. Request a walkthrough.

Latest from our blogs

Explore perspectives from the Vero team on wholesale lending, title workflows, risk management, and the operational future of asset-backed finance.

Blog Thumbnail

AI in Wholesale Finance: What's Actually Happening on the Ground

Floor plan lending is one of the few corners of financial services where 2005-era workflows are still considered normal. Spreadsheets. Manual audits.

Blog Thumbnail

Why Lending Infrastructure Is the Real Fintech Story Now

Over the past decade, most of the attention in fintech has gone to sleek apps, neobanks, and frictionless payment experiences.

See VeroOS on your book of business

A 30-minute walkthrough with people who've run the workflows you're modernizing.