What Did the FTC Actually Allege Against Corpay?
The headline number is $100 million. FleetCor Technologies, now operating as Corpay, agreed to pay $100 million to settle a Federal Trade Commission administrative action alleging that the company charged its business customers a broad array of unauthorized fees they never agreed to pay. The complaint was first filed in federal court in December 2019. The settlement was announced in September 2026, more than six years after the first filing.
The allegations were not exotic. The FTC alleged that FleetCor falsely told its business customers they would save money on fuel, be protected from unauthorized charges, and pay no setup, transaction, or membership fees, while in reality customers were charged hundreds of millions of dollars in hidden fees that were never disclosed at the point of sale. In plain language: what marketing promised and what the business actually delivered were two different things, and the difference ran for years before regulators pulled the documentation and put a number on it.
According to the FTC, FleetCor's own internal records showed that customers generally had not achieved the advertised per-gallon savings. The gap between the marketing claim and the internal record existed in writing, inside the company, before any enforcement action began. The audit trail was there. It just said the wrong thing.
Why Does a 2019 Complaint Produce a 2026 Settlement?
Because enforcement does not move at the speed of a news cycle. The FTC filed its federal court complaint in 2019. The agency filed a separate administrative complaint against FleetCor and its CEO Ronald Clarke in 2021. The settlement arrived in 2026. Between those dates, litigation wound through discovery, appeals, and court findings.
This timeline is not a Corpay anomaly. Regulatory enforcement in financial services and consumer-facing industries routinely spans five to seven years from complaint to resolution. The Credit Acceptance settlement, which we covered as a case study in advertising exposure, followed a similar arc: the conduct that drove the settlement had been running for years before the complaint; the legal process added more years on top of that. By the time a settlement number appears, the underlying conduct is ancient history to everyone inside the company except the lawyers.
The practical consequence for any business running a marketing program: the documentation you produce today is not evaluated in the context of today. It will be evaluated, if it is ever evaluated at all, years from now, by people who were not in the room when the decisions were made, working from whatever records exist at that moment. If a decision was made and not recorded, it did not happen. If copy ran without a compliance review, that review cannot be reconstructed after the fact.
What Does a Compliance Failure Actually Look Like Before It Surfaces?
Not like a failure. That is the problem.

In the Corpay case, the company was not operating in secret. It was marketing commercially available payment cards to fleet operators. It was running campaigns, producing offers, making savings claims. The claims were reviewed by someone, at some level, on some cadence, or they would not have shipped. The compliance gap was not that nobody cared. The compliance gap was that what marketing was saying and what the product was actually delivering were diverging, incrementally, over time, and no record connected those two facts.
A compliance failure at a dealership looks like this: an ad runs that states a lease payment. That payment was accurate when the ad was composed. The manufacturer's offer changed two weeks later. The ad kept running. Nobody recorded when the offer changed, or confirmed that the copy was updated, or noted who made the call to leave it live. If a regulator asks about that ad six months later, the answer is a folder of screenshots with no timestamps, no decision record, and no documented review. Whether or not a violation occurred, the absence of documentation makes the liability calculation look the same as if one did.
The FTC's warning to 97 dealer groups earlier this year underscored the point. As we noted when that warning landed, the dealers most exposed are not always the ones running the most aggressive campaigns. They are the ones who cannot prove, ad by ad and dollar by dollar, what ran, when, what it said, and who approved it.
Is a Dealership's Ad Campaign the Same Compliance Exposure?
Not identical, but structurally similar. Corpay was running a financial product. Dealership advertising is governed by Regulation Z and Regulation M, the FTC Act's prohibition on unfair or deceptive practices, OEM brand guidelines, and a patchwork of state-level advertising rules that vary by jurisdiction. The specific violation shapes are different. The enforcement mechanics are the same.
An ad that states a lease payment without the required trigger disclosures is a Reg M exposure. An ad that states a financing rate without the required additional terms is a Reg Z exposure. An ad that makes a savings claim for a financing product in language the FTC Act treats as deceptive is a Section 5 exposure. These are not theoretical risks. They are the categories that drove settlements in the cases we have covered here.
What makes the Corpay settlement instructive for a dealership is not the fuel card. It is the mechanism. The FTC's theory was that a gap existed between what the company's marketing claimed and what the product actually delivered, and that gap was documentable from the company's own records. In dealership advertising, that gap appears when a campaign says one thing and the offer has changed, when a compliance review happened but was not recorded, when someone made a judgment call about copy and the call was not captured anywhere. The gap is not always a violation. But the absence of a record is the same whether the underlying conduct was compliant or not.
What Is a Hash-Chained Audit Trail, and Why Does It Matter?
A hash-chained audit trail is a record where each entry is cryptographically tied to the entries before it. The practical consequence is that you cannot go back and edit an earlier entry without breaking the chain in a way that is detectable. The record is, in the meaningful sense, tamper-evident: a later edit creates a visible discontinuity in the chain, so the record's integrity can be verified without trusting anyone who had access to the system.

This matters in an enforcement context because the value of a compliance record is directly tied to its credibility. A spreadsheet someone could have edited last week is worth less than a record that can demonstrate it has not been altered since the event was logged. Discovery is adversarial. The opposing party's job is to find reasons not to credit your documentation. A record that cannot be silently altered is harder to discredit.
The question most dealer groups cannot answer today is: if a regulator asked for every decision made about a specific campaign, on a specific date, including who reviewed the copy, what offer data was in effect, and what compliance determination was reached, could you produce that record? Not a reconstruction. Not a best-effort account from memory and email threads. An actual, dated, unedited record of what happened.
For most dealerships running campaigns through a mix of agencies, internal staff, and platform automations, the honest answer is no. The decisions were made. They were simply never recorded in a form that survives intact when someone outside the organization asks for them.
How AUTONOMi Addresses This
AXIOM, AUTONOMi's governance and policy engine, hash-chains every dealer-impacting decision into a durable audit trail, and the dealer can read this audit trail. Every spend action, every copy change, every compliance review determination, and every allocation shift is recorded in an append-only chain that cannot be silently altered after the fact. An entry that is modified after writing breaks the chain and the break is detectable. The record is not a log that someone with admin access can clean up before an inquiry. It is a chain where any alteration is visible.
The three-stage compliance triad runs before any ad copy reaches a platform. AEGIS runs a strategist-composer-verifier sequence on every ad copy and landing-page assertion before spend is approved, with each stage tracked as a distinct review record. That sequence is not a checkbox. It is a documented determination: what was reviewed, when, what the copy said, and whether it cleared the review. If a regulator asks what compliance review happened on a specific ad, the answer is not a reconstruction. It is a read from the chain.
On OEM offers specifically: AUTONOMi maintains its own byte-level evidence record for every OEM offer it acts on, storing the manufacturer's own response exactly as served, the timestamp of the read, what the data parsed to, and which stored offer rows it backs, in an append-only, hash-chained ledger. This is AUTONOMi's own evidence ledger. What it provides is traceability: when a lease payment appeared in an ad, the record can show which OEM scrape produced it, when that scrape ran, and what the manufacturer's source data said. If an offer changed and the ad copy was updated, that update is in the chain. If the update did not happen, that absence is visible too.
The Corpay case turned, in part, on what the company's own records showed. AXIOM records every allocation lock, budget shift, and per-channel decision with dated reasoning history, so the audit trail covers not just what was approved but what the reasoning was at each decision point. When documentation exists, the conversation with regulators is about facts. When it does not, the conversation is about what might have happened, which is a worse position to argue from.
The Audit Trail Has to Exist Before the Inquiry
The Corpay settlement was seven years in the making. The conduct that generated it was already years old by the time the first complaint was filed. The decisions that created the liability were made by people who were probably not thinking about a $100 million settlement when they approved a fuel savings claim for a fleet card marketing campaign. They were thinking about the quarter. The documentation, or its absence, was a secondary concern at the time and became the primary concern later.
Dealership advertising does not typically involve the dollar volumes that drive a $100 million FTC settlement. But the structural lesson transfers at any scale. A compliance record that was not created at the time of the decision cannot be created credibly later. A copy change that was not logged when it happened cannot be reconstructed accurately under adversarial conditions. An offer that ran after it should have been pulled leaves an exposure that is not cleared by the fact that the people involved had good intentions.
The dealers who are building durable positions are the ones treating their advertising record as a compliance asset, not an afterthought. Every decision that goes into the chain is one fewer conversation to reconstruct from memory when the inquiry arrives. The inquiry may never arrive. But the architecture should assume it will, because the Corpay case is a reminder that the gap between what marketing promised and what a business delivered can sit undocumented for years before anyone is required to produce the receipts. Build your advertising on a documented foundation through AUTONOMi before the question is asked, not after.
Sources: FTC press release, September 2026. FTC complaint, December 2019. FTC administrative complaint, August 2021.



