Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Most Compliance Teams Are Auditing the Wrong ScreenRegulatory Bodies
5 min readFor Compliance Officers

Most Compliance Teams Are Auditing the Wrong Screen

The Conventional Approach

Your compliance team audits checkout flows by clicking through as if they were customers. They confirm that fee disclosures exist, terms of service links work, and the total price calculation is correct. They document the flow in a testing matrix and close the ticket. The legal team signs off. You've verified transparency.

This is how most organizations approach fee disclosure compliance. The assumption: if the information is technically present somewhere in the interface, you've met your obligation.

Why This Approach Is Incomplete

The Hopper settlement exposes a gap in this approach. The Federal Trade Commission (FTC) didn't allege that Hopper failed to disclose fees. It alleged the company charged consumers for fees they didn't consent to, even though those fees were "disclosed" on the screen. Hopper paid $35 million to settle allegations that included charging users for "Tip" and VIP Support fees that were technically optional but pre-selected and required scrolling to see.

Here's what matters: Hopper's internal testing showed that when fees were adequately disclosed and unselected by default, most consumers declined them. The fees generated millions in revenue because the disclosure pattern suppressed informed choice.

Your compliance audit that confirms "the fee is disclosed on the checkout screen" misses the enforcement risk entirely. The question isn't whether the disclosure exists. It's whether the interface pattern allows meaningful consent.

The Evidence

Internal communications at Hopper reveal employees expressing concern about "tricking users." One employee noted: "To me, the problem here is that we're tricking users." This wasn't a rogue team ignoring compliance. This was a pattern that passed through design review, product management, and presumably some form of compliance sign-off, because the disclosure was technically present.

The FTC's complaint details the specific mechanisms:

  • The "total price" and Swipe to Book button appeared before consumers saw the optional fees.
  • The optional fees were pre-selected.
  • The fees only appeared on a screen visible after scrolling.
  • Even after mid-2023 changes, Hopper continued to fail to disclose that Tip fees were optional.

Consumer complaints reinforced the pattern. One user wrote: "I did not intend to buy the VIP support. Honestly, it feels like ya'll snuck that in on the final screen at the bottom and opted me in."

The FTC alleged violations of the FTC Act and, for short-term lodging bookings since May 12, 2025, the Unfair and Deceptive Fees Rule. The settlement requires Hopper to clearly and conspicuously disclose fees and charges, and prohibits misrepresenting any fees.

What to Do Instead

Stop auditing for disclosure presence. Start auditing for consent validity.

Run your own A/B test during compliance review. Before approving a fee disclosure pattern, test it with a sample of actual users or employees unfamiliar with the product. Show them the flow. Ask them to complete a booking. Then ask: "Did you notice you were charged for [service]? Did you intend to purchase it?" If many didn't realize they consented, your disclosure pattern fails, regardless of what your screenshots show.

Document interface friction as a control. Your ISO/IEC 27001 Statement of Applicability or SOC 2 control descriptions should include specific requirements about default states for optional charges. "Pre-selected optional fees require executive approval and quarterly attestation that A/B testing shows no material difference in opt-in rates compared to unselected defaults" is a control. "Fees are disclosed on the checkout page" is not.

Involve your internal audit team in design reviews, not just post-launch audits. The Hopper case shows that by the time a pattern is generating millions in revenue, it's embedded in forecasts and roadmaps. Changing it becomes a business negotiation, not a compliance fix. Internal audit should review wireframes and prototypes for patterns that suppress informed choice, just like they review code for security vulnerabilities.

Create a "reasonable consumer" test protocol. Define what "clearly and conspicuously" means in your context before the FTC does it for you in a complaint. Your protocol should specify: font size relative to surrounding text, color contrast requirements, placement on screen (above the fold, before primary action button), default selection states, and the number of clicks or scrolls required to see the disclosure. Make this protocol part of your design system, not a Word document in the compliance folder.

Map dark patterns to FTC Act violations in your risk register. Your GRC platform probably has "deceptive trade practices" as a compliance obligation. Translate that into specific interface patterns: pre-selected checkboxes for optional services, "total price" labels that exclude mandatory fees, confirmshaming (making the opt-out choice sound negative), urgency messaging that misrepresents availability. Rate each pattern by likelihood of enforcement and potential penalty, then audit your properties against that taxonomy.

When the Conventional Approach Is Right

Disclosure audits aren't useless. They're necessary but insufficient.

You still need to verify that fee disclosures exist, that they're accurate, and that they appear before the point of purchase. The FTC's Unfair and Deceptive Fees Rule establishes baseline requirements for how fees must be presented. Your compliance team should absolutely confirm you meet those baselines.

The conventional audit approach also works when you're dealing with truly mandatory fees that can't be declined. If every customer pays the fee regardless of their choice, the disclosure standard is different. You're not testing for consent validity because consent isn't part of the transaction. You're testing for accurate price representation.

And if your organization genuinely wants customers to understand what they're buying, the conventional approach aligns business incentives with compliance obligations. The problem arises when revenue depends on customers not fully understanding or not noticing optional charges. That's when your compliance audit needs to shift from "is the disclosure present?" to "does this pattern allow informed choice?"

The Hopper settlement should prompt a specific question for your next compliance committee meeting: "If we ran our own internal test showing that adequate disclosure would cause most customers to decline an optional service we currently offer, would we change the disclosure or keep the revenue?" Your answer to that question determines whether you're auditing the right screen.

Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."

You Might Also Like