- Overview of the CCO Exam Blueprint
- Domain 1: Credit Union Regulatory Basics
- Domain 2: Deposit and Account Compliance
- Domain 3: Lending Compliance
- Domain 4: BSA/AML and Operational Compliance
- Question Style and Format
- Mapping a Study Schedule to the Domains
- Who Hires CCO-Certified Compliance Officers
- Frequently Asked Questions
- The CCO exam covers four domains: Regulatory Basics, Deposit/Account Compliance, Lending Compliance, and BSA/AML & Operational Compliance.
- Lending Compliance and BSA/AML tend to carry the most day-to-day regulatory complexity, so budget extra review time there.
- Domain 1 builds the regulatory vocabulary and structure you'll need to interpret questions in the other three domains.
- Credit unions, CUSOs, and third-party compliance consultancies all recruit candidates holding this credential.
Overview of the CCO Exam Blueprint
The Credit Union Compliance Officer (CCO) certification exam is organized around four content areas that mirror the actual responsibilities of a compliance professional inside a credit union. Rather than testing trivia, the exam blueprint is designed to confirm that a candidate can identify regulatory requirements, apply them to member-facing products, and recognize red flags in lending and operational activity. Understanding how these four domains fit together - and where the heaviest content concentration lives - is the fastest way to build an efficient study plan.
This guide breaks down each domain in detail: what it covers, why it matters on the job, and the specific topics you should be able to explain without hesitation. If you haven't yet reviewed the fundamentals of what this credential covers, start with What Is CCO Certification? before diving into domain-level detail.
Domain 1: Credit Union Regulatory Basics
Domain 1 establishes the foundation everything else is built on. It covers the regulatory bodies that oversee credit unions, the structure of the National Credit Union Administration (NCUA) versus state-chartered oversight, and the general framework of how compliance obligations flow down from statute to regulation to internal policy.
Domain 1: Credit Union Regulatory Basics
Candidates must be comfortable distinguishing federal versus state regulatory authority and identifying which rules apply to which type of credit union charter.
- NCUA structure, examination authority, and the role of state regulators
- Federal Credit Union Act basics and how it differs from bank-focused statutes
- Board and management responsibilities for maintaining a compliance program
- Distinguishing consumer protection laws from safety-and-soundness regulations
Questions in this domain often ask candidates to identify which regulator has jurisdiction in a given scenario, or to match a regulation to its statutory purpose. It's less about memorizing citation numbers and more about understanding the logic of the regulatory hierarchy - a skill that carries directly into the other three domains.
Domain 2: Deposit and Account Compliance
This domain focuses on the rules governing member deposit accounts - everything from account opening disclosures to funds availability and privacy notices. It's one of the more procedural domains, meaning candidates need to know not just what a regulation requires, but when and how it must be delivered to the member.
Domain 2: Deposit and Account Compliance
Candidates need to understand the mechanics of opening, maintaining, and closing deposit accounts in a regulatorily compliant way.
- Truth in Savings disclosure timing and content requirements
- Funds availability rules and hold policies
- Overdraft program compliance and required member notices
- Privacy notices and information-sharing opt-out mechanics
- Dormant and unclaimed account handling
Expect scenario-based questions that describe a member interaction - opening an account, requesting a hold, or receiving an overdraft - and ask what disclosure or notice is legally required. This domain rewards candidates who practice applying rules to concrete situations rather than reciting them in the abstract.
Key Takeaway
Deposit compliance questions frequently hinge on timing - "within one business day," "before the transaction," "at account opening." Build a timing reference as part of your review instead of trying to memorize rules in isolation.
Domain 3: Lending Compliance
Lending Compliance is typically the densest domain on the exam, since credit unions offer a wide range of loan products - consumer, mortgage, and member business lending - each governed by its own layer of regulation. This domain tests whether candidates can apply fair lending principles, disclosure requirements, and underwriting compliance rules across multiple loan types.
Domain 3: Lending Compliance
Candidates must be able to apply fair lending and disclosure requirements across consumer, mortgage, and business lending scenarios.
- Truth in Lending Act (TILA) disclosure content and timing
- Equal Credit Opportunity Act (ECOA) and fair lending risk indicators
- Mortgage-specific requirements including ability-to-repay considerations
- Adverse action notice requirements and timing
- Flood insurance and appraisal-related compliance checkpoints
Because lending compliance touches so many product lines, this domain rewards candidates who organize their review by loan type rather than trying to memorize regulations as a single undifferentiated list. If you're unsure how much time to allocate here relative to the other domains, the CCO Study Guide walks through a domain-weighted review approach in more depth.
Domain 4: BSA/AML and Operational Compliance
The final domain covers Bank Secrecy Act and anti-money laundering obligations alongside broader operational compliance topics - the areas most closely tied to a credit union's exposure to regulatory enforcement action. This domain tends to feel the most "high-stakes" to candidates because BSA/AML failures carry some of the most serious consequences in the industry.
Domain 4: BSA/AML and Operational Compliance
Candidates must demonstrate a working knowledge of suspicious activity detection, recordkeeping, and the internal controls that support a compliance program.
- Currency Transaction Report (CTR) and Suspicious Activity Report (SAR) triggers
- Customer Identification Program (CIP) and beneficial ownership requirements
- OFAC screening and sanctions compliance basics
- Recordkeeping retention requirements and internal audit expectations
- Vendor and third-party risk management within an operational compliance framework
Expect questions that present a transaction pattern or member behavior and ask what filing or internal escalation is required. This domain also touches on how compliance officers document decisions - an operational skill that examiners look for during actual credit union exams, not just certification exams.
Question Style and Format
CCO exam questions are scenario-driven rather than definition-driven. Instead of asking "What does TILA stand for?" a typical question describes a member interaction, transaction, or compliance decision point and asks the candidate to identify the correct regulatory response. This format tests applied judgment, not rote recall, which is why candidates who only memorize acronyms tend to underperform relative to their study time invested.
- Multiple-choice format with single best-answer selection
- Scenario stems describing a member, account, loan, or transaction situation
- Distractor answers often reflect a partially correct or outdated rule
- Cross-domain questions that require connecting a Domain 1 concept to a Domain 2, 3, or 4 scenario
Because the exam blends domains within individual questions, isolated flashcard memorization only goes so far. Practicing with realistic scenario questions - the kind found on our full-length CCO practice tests - is the most reliable way to get comfortable with this question style before test day. For a deeper breakdown of how the exam's format affects overall difficulty, see How Hard Is the CCO Exam?
Mapping a Study Schedule to the Domains
Rather than studying all four domains simultaneously, most successful candidates dedicate focused blocks of time to each domain in sequence, then finish with a cross-domain review period that mixes scenario questions from all four areas together.
Domain 1: Regulatory Basics
- Map out NCUA structure and federal vs. state authority
- Build a reference sheet of core statutes and their purpose
Domain 2: Deposit and Account Compliance
- Drill disclosure timing rules with scenario flashcards
- Review overdraft and funds availability edge cases
Domain 3: Lending Compliance
- Organize review by loan type: consumer, mortgage, business
- Practice adverse action and fair lending scenario questions
Domain 4: BSA/AML and Operational Compliance
- Memorize SAR/CTR filing triggers and timeframes
- Review CIP, beneficial ownership, and OFAC basics
Cross-Domain Review
- Take full-length mixed-domain practice tests
- Revisit your weakest domain based on practice results
Notice that Domain 3 gets two full weeks - that reflects its breadth across multiple loan products, not a rigid universal rule. Adjust the schedule based on your own background; a candidate coming from a lending role may need more time in Domain 4 instead. For candidates who want a condensed version of this plan tied to specific milestones and checkpoints, the CCO Study Guide 2026 offers a full first-attempt strategy.
Who Hires CCO-Certified Compliance Officers
The CCO credential is recognized primarily within the credit union industry, but its value extends to several adjacent employer types. Understanding who's actually looking for this credential helps frame why domain mastery matters beyond just passing the exam.
- Credit unions directly: Compliance departments at credit unions of all asset sizes hire for roles ranging from compliance analyst to Chief Compliance Officer, often listing this certification as preferred or required.
- Credit Union Service Organizations (CUSOs): These shared-service entities support multiple credit unions and need staff who understand the same regulatory domains covered on the exam.
- Third-party compliance consultancies: Firms that audit or advise credit unions on regulatory readiness recruit certified compliance officers who can speak to all four domains fluently.
- Examiners and regulatory-adjacent roles: Some candidates use the certification to strengthen a transition into regulatory or examination-support positions.
If you're evaluating whether this career path and credential make sense for your goals, Is the CCO Certification Worth It? walks through the return-on-investment considerations, and CCO Salary Guide 2026 covers how compensation tends to track with role and experience. To see how the certification typically fits into job postings, browse CCO Jobs.
Key Takeaway
Employers care less about which domain you scored highest on and more about whether you can move fluidly between all four - because real compliance work rarely stays confined to a single regulatory area.
Turning Domain Knowledge Into Exam Readiness
Knowing the domain content is only half the equation - the other half is knowing how the material will actually be tested. That's where structured practice becomes essential. Working through full-length practice exams that mirror the real scenario-based question style helps you identify which domain needs more review before test day, rather than guessing based on how confident you feel.
Before you schedule your exam, it's worth confirming you meet the eligibility requirements outlined in CCO Requirements 2026, understanding what score you'll need in CCO Passing Score 2026, and checking current testing windows in CCO Exam Dates 2026. Budgeting for the exam itself is also worth planning ahead - see CCO Certification Cost 2026 for a full pricing breakdown.
| Domain | Primary Focus | Typical Question Style |
|---|---|---|
| Domain 1 | Regulatory structure and authority | Identify jurisdiction/regulation match |
| Domain 2 | Deposit and account rules | Disclosure timing scenarios |
| Domain 3 | Lending across product types | Fair lending and disclosure application |
| Domain 4 | BSA/AML and operational controls | Filing trigger and escalation scenarios |
Frequently Asked Questions
There are four: Credit Union Regulatory Basics, Deposit and Account Compliance, Lending Compliance, and BSA/AML and Operational Compliance.
Lending Compliance and BSA/AML and Operational Compliance are generally considered the most content-dense because they span multiple loan products and regulatory filing requirements, respectively.
Not necessarily. Many candidates have stronger on-the-job exposure to one or two domains and rely on structured study for the others. Check CCO Requirements 2026 for specific eligibility details.
The CCO exam is primarily scenario-based, presenting member, account, or transaction situations and asking candidates to identify the correct compliance response rather than recite a definition.
Most candidates allocate more time to Domain 3 (Lending Compliance) and Domain 4 (BSA/AML and Operational Compliance) given their breadth, while still building a solid Domain 1 foundation first. See the CCO Study Guide for a full weekly breakdown.