Deep dives
How the Holder Rule carries seller-related claims into covered financing, why the contract matters, and how lenders should distinguish recovery limits from merchant indemnities.
Published: Sep 27, 2026Why deferred interest differs from a true zero-percent offer, how Regulation Z allocates excess payments, and how to test promotions through payoff and expiration.
Published: Sep 27, 2026A practical reading of covered debt-collector communications, call-frequency presumptions and validation controls, with a focus on consent and channel coordination.
Published: Sep 27, 2026How insurance follows beneficial ownership in qualifying custodial deposits, why balances aggregate across channels, and why insurance does not guarantee uninterrupted access.
Published: Sep 27, 2026The OCC’s 2024 order connects financial-crime controls to balance-sheet growth. A current-status review separates management’s remediation milestones from regulatory release.
Published: Sep 27, 2026A terminated CFPB order provides a durable lesson about payment permissions, loan-extension execution and remediation population controls.
Published: Sep 27, 2026The terminated 2023 CFPB order shows why a valid data code can still describe an event that never happened, and how source-level controls differ from file validation.
Published: Sep 27, 2026The terminated CFPB unemployment-benefit-card order illustrates false-positive harm, identity-verification bottlenecks and the need to preserve error-resolution rights.
Published: Sep 27, 2026A successful login does not settle who authorized a transfer. Regulation E requires a documented investigation, separate liability analysis and timely access to provisional funds.
Published: Sep 27, 2026The 36% military APR limit reaches beyond the stated interest rate. Covered-borrower evidence, fee treatment and contract terms must stay connected through origination and servicing.
Published: Sep 27, 2026The April 17, 2026 interagency guidance supersedes SR 11-7 and SR 21-8, emphasizes materiality and excludes generative and agentic AI from its formal scope without removing broader governance responsibilities.
Published: Sep 27, 2026General QM uses a price-based eligibility framework, while income verification, payment mechanics and product restrictions still matter. QM status is neither a guarantee of affordability nor the only lawful path.
Published: Sep 27, 2026Citi’s record distinguishes the 2020 governance order, the 2024 amendment and the December 2025 termination of that amendment. The practical lesson is to prove control performance, not merely project completion.
Published: Sep 27, 2026The December 18, 2023 Choice Financial Group order connects board oversight, partner customer data, monitoring, lookbacks and staffing. It is a case study in proving that outsourced activity remains visible to the bank.
Published: Sep 27, 2026The June 2024 Evolve order links fintech oversight to AML, consumer compliance, credit, liquidity and board reporting. Its restrictions show why partner growth and exit both require a bank-wide risk assessment.
Published: Sep 27, 2026The May 2024 Chime Financial settlement shows how account closure can leave a customer-money obligation unfinished. Refund controls need to follow funds through issuance, delivery, exceptions and reconciliation.
Published: Sep 27, 2026CAMELS is a confidential supervisory assessment, not a public credit score or a mechanical average. The May 2026 proposal would emphasize material financial risk; strong current earnings still need to be tested against emerging credit and liquidity weakness.
Published: Sep 27, 2026Part 30 links OCC safety-and-soundness guidelines to a compliance-plan and enforcement process. Its relevance to credit is concrete: repayment evidence, independent review, information security, controlled growth and credible remediation.
Published: Sep 27, 2026The OCC/FDIC final rule takes effect November 2, 2026. It distinguishes unsafe or unsound practices, matters requiring attention and informal observations; the new thresholds do not erase violations of law or make weak controls harmless.
Published: Sep 27, 2026The Consumer Financial Protection Accountability and Reform Act of 2026 advanced from House Financial Services in September. It remains proposed legislation; its supervisory election and enforcement provisions are more consequential than the headline funding reform alone.
Published: Sep 27, 2026The March 2026 order directs consideration of mortgage, capital and liquidity reforms. It does not itself rewrite Regulation Z. The lending opportunity depends on actual agency action, lower operating cost and preserved repayment discipline.
Published: Sep 27, 2026The OCC’s April 2026 clarification preserves the existing scope of national trust-bank authority. For any charter applicant, the real questions remain permissible activities, sustainable capital, management, controls and the permissions needed beyond the charter.
Published: Sep 27, 2026The Federal Reserve has removed reputation risk from its examination approach and proposed codifying that policy. This does not remove financial, operational, compliance or credit risk, and it does not require a bank to approve every lawful applicant.
Published: Sep 27, 2026The July 2026 housing law spans supply, mortgage access and bank funding. Its credit effects depend on section-level implementation, local constraints and available funding. Enactment alone does not make every program operational or every project financeable.
Published: Sep 27, 2026The April 2026 Regulation J proposal would permit additional intermediaries in FedNow payment chains, including the domestic leg of cross-border payments. It does not itself open Federal Reserve access to every fintech or make the whole cross-border transaction instantaneous.
Published: Sep 27, 2026The policy moved from H.R. 3234 into the enacted ROAD to Housing Act, with a different upper liability tier. The resulting reciprocal-deposit capacity can matter for funding, but nonbrokered treatment does not make deposits permanent or increase the basic insurance limit.
Published: Sep 27, 2026The Supreme Court’s June 2026 decision invalidated the FTC commissioners’ removal protection and overruled Humphrey’s Executor. It changes leadership accountability; it does not erase the underlying consumer-protection statutes. The same-day Federal Reserve case shows why agency-specific analysis matters.
Published: Sep 27, 2026The 2024 personal financial data rights rule remains the reference text, but its compliance dates are stayed. What lenders should build now, what remains unsettled and how to evaluate cash-flow underwriting without overstating its benefits.
Published: Sep 27, 2026June 2026 guidance expands the practical use of voluntary information sharing against fraud and money laundering. The safe harbor still depends on participant eligibility, notice, verification, purpose and security; SAR confidentiality remains separate.
Published: Sep 27, 2026GENIUS is enacted law, with important implementation proposals still developing. The credit questions are reserve quality, redemption capacity, deposit migration and whether payment economics survive lower interest rates.
Published: Sep 27, 2026The Senate failed to advance H.R. 3633 on September 15, 2026. The latest sponsor draft remains a proposal: examine token classification, intermediary oversight and deposit competition without treating the bill as operating authority.
Published: Sep 27, 2026The March 2026 package is three proposals, not a final capital reset. Aggregate estimates combine different components; the lending impact depends on each bank’s exposures, stress requirements, leverage constraint and management buffer.
Published: Sep 27, 2026The Fed ended its 2018 Wells Fargo action in March 2026, after lifting the asset cap in June 2025. The two milestones explain why remediation needs separate tests for growth permissions, control effectiveness and final closure.
Published: Sep 27, 2026SouthPoint’s August 2026 written agreement shows how parent-company capital, cash flow and distributions interact with a bank subsidiary’s remediation. The analysis separates holding-company obligations from the bank’s own FDIC order.
Published: Sep 27, 2026Apple Card’s dispute-routing and installment-enrollment findings show how a polished interface can still break an essential control. Apple’s order ended in September 2025; the separate Goldman Sachs record must be assessed independently.
Published: Sep 27, 2026The CFPB closed its Bilt matter on September 21, 2026 after voluntary remediation. The case offers a practical framework for finding transition-related fees, reaching affected customers and demonstrating that repayment actually arrived.
Published: Sep 27, 2026A decision-trace framework for adverse-action explanations, now including an evaluation checklist for hybrid underwriting systems.
Published: Sep 27, 2026How to interpret the proposed shift toward proportionate oversight, distinguish it from the core-provider statement, and build a defensible risk assessment.
Published: Sep 27, 2026The September 25 closure, the Utah acquirer’s role, and the distinction between deposit continuity, asset recovery and creditor outcomes.
Published: Sep 27, 2026How a furnisher can connect evidence, investigation, corrections and recurring data defects under Regulation V.
Published: Sep 26, 2026The March 2023 FDIC order shows why partner lending requires usable data, capacity planning and bank-level accountability.
Published: Sep 26, 2026A study of the February 2024 consent order, prepaid-program oversight and the gap between delegated work and verified controls.
Published: Sep 26, 2026Consent, purpose, number hygiene and opt-out controls across servicing, collections, fraud and marketing.
Published: Sep 26, 2026A historical control map for fintech onboarding, BSA/AML, capital, liquidity and board accountability.
Published: Sep 26, 2026Official policy
September proposals covering substantive requirements and application procedures.
Source date: Sep 24, 2026Updates the structure and references of the Cybersecurity Supervision Work Program and rescinds the 2023 bulletin. The OCC says the update adds no procedures and establishes no new regulatory expectations.
Source date: Sep 21, 2026BARR_154 substitute adopted September 16; proposed changes are not current law.
Source date: Sep 16, 2026Official floor record of the unsuccessful cloture vote on proceeding.
Source date: Sep 15, 2026Proposes tailored interagency guidance and replacement of existing guidance if finalized. Comments are due November 16, 2026; the proposal itself does not replace the current framework.
Source date: Sep 15, 2026September 14 proposed substitute EHF26724; not enacted law.
Source date: Sep 14, 2026Final definitions and related supervisory standards; future effective date.
Source date: Sep 1, 2026Introduced text; compare with the subsequently adopted committee substitute.
Source date: Aug 31, 2026Housing, mortgage and bank-funding provisions; includes Keeping Deposits Local in section 902.
Source date: Jul 11, 2026FTC commissioner removal protection and presidential control of executive officials.
Source date: Jun 29, 2026Federal Reserve governor removal, statutory process and the limits of the stay ruling.
Source date: Jun 29, 2026Introduces the updated Comptroller’s Handbook booklet and identifies superseded materials. Use the linked booklet for portfolio oversight and lending-risk examination practices, alongside product-specific guidance.
Source date: Jun 25, 2026Links to the June 12, 2026 fact sheet and current participation resources.
Source date: Jun 12, 2026Removes additional reputation-risk references from interagency documents.
Source date: Jun 2, 2026Proposed changes to the Uniform Financial Institutions Rating System.
Source date: May 19, 2026Official implementation page links the May 1, 2026 final rule revising coverage, data collection and other provisions, with compliance extended to January 1, 2028. The CFPB notes that supporting implementation materials will be updated later.
Source date: May 1, 2026Replaces SR 11-7 and SR 21-8; emphasizes a tailored, risk-based approach.
Source date: Apr 17, 2026Treasury proposal for stablecoin issuer AML and sanctions compliance programs.
Source date: Apr 8, 2026Would allow additional intermediaries in FedNow transfer chains.
Source date: Apr 8, 2026Proposed standards for FDIC-supervised permitted payment stablecoin issuers.
Source date: Apr 7, 2026Separate OCC/FDIC action; does not establish finality of the Fed proposal.
Source date: Apr 7, 2026Clarifies trust-company and related activities under Part 5.
Source date: Feb 27, 2026OCC proposal and links to implementing regulatory text.
Source date: Feb 25, 2026Proposal to codify removal of reputation risk from Fed supervisory programs.
Source date: Feb 23, 2026Amends Part 328 requirements for digital deposit-taking channels, ATMs and related signs. Effective March 2, 2026, with an April 1, 2027 compliance date for these amendments; distinguish this timetable from other Part 328 obligations.
Source date: Jan 29, 2026CFPB status page notes the October 29, 2025 stay of compliance dates.
Source date: Oct 29, 2025Final guidance on identity proofing, authentication and federation, replacing SP 800-63-3. Useful for evaluating assurance levels and vendor controls; it does not independently establish compliance with bank CIP requirements.
Source date: Jul 31, 2025Public Law 119-27. General effectiveness depends on the statutory timing trigger.
Source date: Jul 18, 2025Planning, diligence, contracts, monitoring and termination; tailored to risk.
Source date: Jun 6, 2023AI governance and risk-management framework; not a banking regulation.
Source date: Jan 26, 2023Retail lending strategy, underwriting, portfolio monitoring, collections and controls; useful context for roll rates and risk-adjusted pricing.
Source date: Oct 28, 2021Credit analysis, documentation, monitoring and counterparty considerations for purchased loans and participations. The posted text removes reputation-risk references as of March 20, 2025.
Source date: Sep 10, 2020Interagency guidance on independent, ongoing credit review and communication of portfolio performance to management and the board. Discusses tailoring review systems to the institution’s size, complexity and risk profile.
Source date: May 8, 2020Credit decisions, fair lending, adverse action and record retention.
Mortgage data collection, reporting and disclosure.
Consumer transfers, error resolution, unauthorized payments and remittances.
Debt-collection communications, validation information and prohibited practices.
Federal registration requirements for covered residential mortgage loan originators.
State mortgage licensing and registration framework.
Consumer lease disclosures and advertising requirements.
Privacy notices and limits on disclosure of nonpublic personal information.
Consumer reporting, furnishing information, disputes and related obligations.
Mortgage settlement, servicing, escrow and loss-mitigation requirements.
Consumer-credit disclosures, cards, mortgages and ability-to-repay provisions.
Deposit-account disclosures, interest calculations and advertising.
The mortgage ATR/QM provisions in Regulation Z.
Section 39 authority for operational and managerial standards and compliance plans.
Interest-rate protections for qualifying obligations incurred before military service.
Consumer-credit protections for covered service members and dependents.
Discriminatory housing practices, including relevant residential lending provisions.
Applications, notices and corporate activities for OCC-supervised institutions.
Standards, compliance-plan procedures and appendices.
Safety-and-soundness standards for covered FDIC-supervised institutions.
Regulatory capital and risk-weighted asset requirements.
Capital adequacy requirements for covered Federal Reserve-regulated organizations.
Capital requirements for covered FDIC-supervised institutions.
Loans to executive officers, directors and principal shareholders.
Restrictions and requirements governing covered affiliate transactions.
Bank holding companies and changes in bank control.
Availability, collection and return of checks and related disclosures.
Check collection, Fedwire funds transfers and FedNow transfers.
Official signs, advertising and representations about deposit insurance.
OCC notification requirements for covered incidents and bank service providers.
General definitions, reporting, records and information-sharing requirements.
Bank-specific AML, customer identification, reporting and recordkeeping rules.
Sanctions-related reporting, procedures and enforcement guidelines.
Regulation RR requirements for asset-backed securitizations.
Law-enforcement requests and the separate mandatory information-sharing process.
Coverage basics and ownership-category rules; complements the regulatory text.
Utah banking, financial-institution and related charter authorities.
Deposit definitions, reserve-account requirements and interest on reserve balances. Useful for distinguishing deposit classification from the rates a bank pays customers; consult current amendments before applying a numerical threshold.
Debit-card interchange standards, exemptions, fraud-prevention adjustments and network-routing restrictions. Relevant to issuer economics and merchant acceptance; coverage differs across issuers and provisions.
Liquidity coverage ratio and net stable funding ratio provisions for covered institutions. Provides the regulatory treatment of liquid assets, outflows and funding stability; applicability and tailoring matter.
Single-borrower lending limits, combination rules and exceptions for covered OCC-supervised institutions. A useful starting point for concentration controls and connected-borrower analysis.
Independent audit, management reporting and audit-committee requirements for covered insured institutions. Check the applicable asset thresholds and effective dates rather than assuming one requirement applies to every bank.
Includes brokered-deposit acceptance restrictions, waivers and related funding provisions. Read the regulatory text alongside statutory amendments and the institution’s capital category.
Rules addressing FDIC resolutions and receiverships, including claims and selected contractual and securitization issues. Useful for separating the failed bank, the receivership and an acquiring institution.
Covered-loan definitions, payment-transfer restrictions, consumer notices and recordkeeping. The text identifies reserved provisions; read it with current implementation and enforcement materials rather than applying removed underwriting requirements.
Notification timing, incomplete applications, specific reasons and business-credit variations under Regulation B. Relevant to automated underwriting and the evidence supporting the reasons given to an applicant.
Validation information, itemization and delivery requirements for covered debt collectors. Applicability turns on the FDCPA and Regulation F definitions; originating creditors are not automatically covered debt collectors.
Bank CIP examination guidance covering identification, verification, recordkeeping and reliance arrangements. Links the operating controls to their BSA regulatory authority; using a vendor does not by itself satisfy the bank’s program obligations.
Regulatory framework for SBA business-loan programs, including 7(a) and 504 requirements and lender oversight. Business lending is distinct from consumer credit; program eligibility and guaranty conditions require separate review.
DFI’s official implementation resource for Title 7, Chapter 27, including registration, transaction disclosures and links to statutory requirements. Relevant to business financing and merchant finance; review the Act’s exemptions.
Official explanation of consumer data rights, covered-business thresholds and privacy responsibilities, with a link to the Act. Check statutory exclusions and financial-services exemptions before applying the general requirements.
Official access point for Utah AI policy, regulatory-relief work and the supervised AI Sandbox. Program participation and proposed policy changes should not be treated as general exemptions from financial-services law.
Official regulation, coverage guidance, exemptions, incident reporting and compliance resources for DFS-covered entities. State licensing and the applicable exemption determine coverage; a federal bank charter alone is not the test.
Official examination modules for BSA/AML programs, regulatory requirements and selected products and customer risks. Sections carry their own update dates; the manual explains examination procedures and does not replace the underlying rules.
Examiner guidance on card-bank operations, associated risks, risk management and regulatory requirements. Useful for reviewing underwriting, account management and credit-card portfolio governance.
Guidance on closed-end consumer lending risks and controls. The booklet distinguishes installment credit from open-end cards and complements the OCC’s broader portfolio and supervision materials.
Examiner guidance on card-payment merchant processing and related risk management. Merchant acquiring and processing differ from card issuance, making this a useful companion to issuer and POS-lending controls.
Allocation of payments above the required minimum on covered credit-card accounts, including special treatment of deferred-interest balances.
Advertising requirements for open-end credit, including promotional and deferred-interest disclosures.
Periodic-statement content, including deferred-interest payoff information and other account disclosures.
Covered debt-collector communications, inconvenient times and places, third-party disclosure procedures and electronic opt-outs.
Telephone-frequency presumptions and the broader prohibition on harassing, oppressive or abusive collection conduct across channels.
Treatment of timely disputes and original-creditor information requests, including when collection must pause.
Ownership evidence, fiduciary disclosure and records supporting beneficial interests, including multilevel custodial relationships.
Aggregation by depositor, ownership right and capacity, and insured institution; distinguishes separate banks from branches of one bank.
General and alternative recordkeeping requirements supporting deposit-insurance determinations at institutions within Part 370’s scope.
Authorization, consumer copies, stop-payment rights and other requirements for preauthorized electronic transfers.
Instructions for collecting and reporting applicant ethnicity, race and sex, including treatment across application methods.