Back to Resources
OPERATIONS By The Shore Group Team

Why a 10% QC Sample Is Not a Quality Control Program

Reviewing a fraction of your portfolio feels like due diligence. Here is what it actually leaves exposed, and what a better model looks like for community banks and credit unions.

TL;DR

Having a quality control process is not the same as having quality control. A 10% manual sample tells you something went wrong in the accounts you reviewed. It tells you nothing about the 90% you didn't. The errors sitting in that unreviewed majority don't disappear. They accumulate, compound, and surface later: during an examiner visit, a member complaint, or an internal audit that finds the same error pattern repeating across accounts nobody touched in years. The real cost of a sample-based QC program isn't the regulatory risk, though that's real. It's the hours your team spends on the review itself: doing stare-and-compare admin work instead of fixing the breaks they find. This post explains why the 10% ceiling exists, what it actually leaves exposed, and what a better model looks like.

Ask a credit union or community bank operations leader whether they have a quality control program for deposit accounts, and the answer is almost always yes. Ask what percentage of accounts that program covers, and the number is usually somewhere around 10-20 percent. Ask whether they're confident that the errors in the other 80-90 percent aren't a problem, and the conversation changes.

The 10 percent figure is not a regulatory threshold. It's not a studied judgment about statistical sufficiency. In most institutions, it's the ceiling that the team could realistically hit given how many people are available, how many hours they can allocate before everything else on their plate takes over, and how long a manual account review actually takes. The sample is 10 percent because that's what fits. And somewhere along the way, something that was never designed to be sufficient became normalized as the standard.

This article is about what that leaves exposed, and why the ceiling itself is the problem worth solving.


The Math Nobody Does Out Loud

Take a credit union running 35,000 deposit accounts through its QC process annually. At 10 percent, the team reviews roughly 3,500 accounts per year. That leaves 31,500 accounts unreviewed. If even two percent of those accounts have a documentation error, a missing beneficiary designation, a signature that didn't get captured, or a discrepancy between what the core system shows and what the physical file contains, that's over 600 accounts with known-unknown errors sitting in the portfolio.

Known-unknown is the right framing. The team isn't unaware that errors exist in the unreviewed population. They know the error rate from the sample. What they don't know is which specific accounts are affected. That's the part that creates risk. An examiner pulling a random account from the unreviewed 90 percent isn't asking whether the sample was reasonable, they're asking what they found.

The errors in the unreviewed population also don't stay static. They compound. An account opened with a missing beneficial ownership document in Year 1 gets maintained, modified, and relied upon through Year 2 and Year 3 while the documentation gap persists. When it surfaces, the remediation isn't just fixing one error. It's reconstructing a record that should have been clean from the start, often under time pressure and sometimes with regulatory attention attached.


Five Things a 10% Sample Cannot Catch

Each of the following risks is a real, specific exposure that a randomly selected 10 percent sample is structurally unable to address. The problem isn't that the team is reviewing the wrong accounts. It's that random sampling is blind to the patterns that matter most.

1. Reputational damage from errors that surface publicly

Errors in the unreviewed 90 percent don't stay invisible. They surface when a member discovers a missing beneficiary designation after a loss in the family and the institution has to explain why the document wasn't verified at account opening. They surface when a customer asks for a copy of their account agreement and the document in the file doesn't match what they signed. They surface in complaints that trigger follow-on examiner attention.

⚠️

The reputational cost of a single visible error that was in the unreviewed 90 percent frequently exceeds the cost of the QC automation that would have caught it. And unlike an examiner finding, which stays internal, a member-facing error has a way of becoming the story that follows the institution in the community it serves.

2. Examination exposure from errors the institution didn't find first

The NCUA's 2026 supervisory priorities explicitly include credit administration sufficiency and portfolio monitoring as examination focus areas. When an examiner finds an error the institution's own QC program missed because it was in the unreviewed 90 percent, the finding isn't just about the error. It becomes a finding about the QC process itself. That's a materially worse outcome: instead of a correctable operational mistake, the institution now has a supervisory concern about its quality oversight design.

⚠️

Institutions that find their own errors, document them, and demonstrate a remediation track record are in a fundamentally different examination conversation than institutions that discover errors for the first time when an examiner pulls a file. The difference between those two conversations is directly correlated to QC coverage.

3. The backlog that never gets cleared

The errors in this year's unreviewed 90 percent become next year's inherited problem. A community bank or credit union running 10 percent QC annually is not just leaving accounts unreviewed this cycle. It's building a compounding backlog of documentation gaps, policy exceptions, and compliance discrepancies that accumulate year over year.

⚠️

At some point, that backlog gets discovered. Sometimes it happens during a routine examination. Sometimes it happens during a merger or acquisition when the acquiring institution reviews the portfolio and finds that the documentation infrastructure doesn't support what the core system shows. When it does, the remediation cost is orders of magnitude higher than it would have been if the errors had been caught and corrected in real time.

4. The clusters that random sampling misses

This is the most counterintuitive risk, and the most important. QC errors don't distribute randomly across a portfolio. They cluster. They concentrate around specific account types processed during a system transition. They concentrate around new staff members who haven't yet internalized the exceptions that experienced reviewers catch by habit. They concentrate around process changes where the new checklist didn't quite capture all the scenarios the old one handled. They concentrate in high-volume periods when the front line was moving fast and documentation slipped.

⚠️

A random 10 percent sample has roughly a 10 percent chance of hitting any one of those clusters. It has a near-zero chance of finding a cluster that represents two percent of the portfolio but 80 percent of the actual compliance risk. Automated full-population review catches all of them, because it doesn't sample. It reviews.

5. Staff hours spent on the wrong work

The people running a manual QC process are typically not QC specialists. They're operations staff, compliance coordinators, or branch managers who have QC as one of several responsibilities and who allocate time to it until something more urgent arrives. When a member needs help, when an examiner calls, when a reporting deadline lands, the QC review gets compressed.

⚠️

Every hour spent on manual document comparison, error logging, and ticket creation is an hour not spent on fixing the errors that were found, improving the processes that created them, or serving the members and customers whose relationships are the whole point of the institution. The real cost of a manual QC program is not primarily the risk it fails to catch. It's the work it keeps the team from doing.


What 10% vs. Full-Population Review Actually Looks Like

10% Manual Sample vs. Automated Full-Population QC

The Questions Worth Asking Before the Examiner Does

Three questions that any operations leader or board member can ask about their current QC program, and that an examiner is increasingly likely to ask during a review of credit administration sufficiency.

  • What percentage of accounts did we review in the last QC cycle, and what is our documented rationale for that coverage level?

  • Of the errors our QC process found in the last cycle, how many were discovered another way first: through a member complaint, an internal audit, or an examiner comment?

  • If an examiner pulled a random account from the population we didn't review last cycle, what would they find, and what is our answer for why we didn't catch it?

These aren't trick questions. They're the natural extension of what NCUA and FDIC examiners have been asking about credit administration and quality oversight for years, now being applied to deposit operations with increasing frequency. The institutions that can answer all three with confidence are the ones that already know what's in their portfolio because they reviewed it, not the ones who know what's in their sample.


Frequently Asked Questions

Is there a regulatory requirement for what percentage of accounts a QC program must cover?

No specific coverage percentage is mandated for deposit account QC by NCUA or the FDIC for most institutions. The requirement is for an effective quality control program that identifies and addresses errors in a timely way. The challenge with a 10 percent sample is demonstrating that the program is effective when the institution has no visibility into the 90 percent it hasn't reviewed. Examiners assess program effectiveness based on outcomes: whether errors are being found, remediated, and tracked over time, and whether the program design is capable of detecting meaningful problems. A sample-based program that consistently misses error clusters because they fall outside the reviewed population will have difficulty demonstrating effectiveness on that basis.

What account types carry the most documentation risk in a deposit QC program?

The account types that generate the highest proportion of QC breaks in most deposit portfolios are IRAs and other tax-advantaged accounts (where beneficiary designation and election documentation must be precise and current), joint accounts opened during high-volume branch periods where signature documentation is most frequently incomplete, accounts with power of attorney or trust designations where the underlying legal documentation has to match exactly what the core system reflects, and accounts affected by system migrations or product transitions where data mapping introduced discrepancies between the core record and the physical file.

If our QC team is already stretched thin, how does adding automation help rather than adding complexity?

The point of QC automation is not to add a system the team has to manage. It's to shift what the team spends its time on. In a manual QC process, the majority of staff hours go to pulling files, comparing documents, and logging breaks: the administrative mechanics of the review. In an automated model, those mechanics are handled by the system. The team's time shifts to reviewing the exceptions the system identifies, validating that the automated rules are working as intended, and managing the remediation of breaks found. The same team that currently reviews 10 percent of accounts manually can cover 100 percent of accounts under an automated model because they're no longer doing the extraction and comparison work that consumes most of the current cycle.

How do the metrics from a sample-based QC program compare to what we'd see with full-population coverage?

Most institutions running sample-based QC report error rates calculated as a percentage of the sample reviewed. A two percent error rate in the sample sounds manageable. The same two percent applied to the full unreviewed population represents a significantly larger number of actual accounts with actual errors. Institutions that move to full-population automated QC consistently find in the initial full review cycle that their actual error rate is higher than their sample suggested, because the sample was not capturing the clustered errors in the remainder. After two to three cycles of full-population review with consistent remediation, the true error rate drops measurably because the errors are being found and fixed rather than accumulating.

What does a realistic starting point look like for moving away from a manual sample?

The most practical entry point is a pilot scoped to one account type: IRAs, standard deposit accounts, or whichever product type has the highest volume and the most consistent documentation requirements. Running the automated review on that account type in parallel with the existing manual process for one cycle allows a direct comparison: did the automated review find breaks the manual review missed, and does the manual review find anything the automated system didn't? Shore's Pilot-to-Partnership model is designed specifically for this kind of scoped, low-commitment validation. The pilot produces a result the team can evaluate before the engagement scales.

Ready to Transform Your Operations?

Shore's CORE Assessment evaluates operational readiness across five categories including data quality, process coverage, and regulatory compliance posture. Free, takes 20 minutes, and identifies where your documentation and process gaps are concentrated before an examiner does.

Take the Free CORE Assessment