{{item.title}}
{{item.text}}
{{item.text}}
Read "our take" on the latest developments and what they mean.
What happened? On July 23rd, Brian Johnson, the nominee to lead the CFPB on a permanent basis, had a confirmation hearing before the Senate Banking Committee. The prior week, on July 15th and 16th, Acting CFPB Director Vought testified before the House Financial Services Committee and Senate Banking Committee regarding the Bureau's activities, priorities, and future direction. The hearings followed the release of the CFPB’s 2026 rulemaking agenda covering planned regulatory actions and reconsiderations across several consumer financial services topics.
What were key themes of the hearings? The hearings covered a range of topics related to the CFPB's current operations, future direction, and statutory authorities:
What is in the CFPB’s 2026 agenda? Key items on the agenda include:
Rulemaking |
Agenda Status |
Context |
Personal Financial Data Rights (Section 1033 / Open Banking) |
Proposed Rule |
The CFPB is reconsidering its 2024 open banking rule after it faced litigation. During the hearings, Vought said the CFPB remains supportive of open banking and is "very close" to issuing a revised proposal. |
Small Business Lending Data Collection (Section 1071) |
Final Rule |
The CFPB finalized a revised rule on May 1st, 2026 that significantly narrowed a framework finalized in 2023, including raising reporting thresholds and reducing required data collection. Vought highlighted these changes during the hearings as a return to the statutory requirements. |
Amendments to Dodd-Frank Act Sections 1031 and 1036 (UDAAP) |
Prerule |
This item follows ongoing debate regarding the prior administration's use of UDAAP to address discrimination and other practices not expressly addressed in statute. |
Procedures for Guidance Documents |
Proposed Rule |
The CFPB rescinded more than 70 guidance documents in 2025 and is considering formal procedures governing the future use and issuance of guidance. |
Procedures for Periodic Review of Bureau Regulations |
Proposed Rule |
The CFPB plans to establish a formal process for reviewing existing regulations to determine whether they should be amended, streamlined, or rescinded. |
Legal Standard Applicable to Supervisory Designation Proceedings |
Final Rule |
The rule would establish the legal standard the CFPB will use when determining whether certain nonbank companies should be designated for supervision. |
Larger Participant Rulemakings |
Proposed Rule |
The CFPB plans to reconsider the definitions used to determine which nonbank firms are subject to CFPB supervision across four markets (Auto Finance, Consumer Reporting, Debt Collection, International Money Transfers). Proposed rules are expected during August and September 2026. |
Equal Credit Opportunity Act (Regulation B) |
Final Rule |
The CFPBalized amendments to Regulation B in April 2026 that removed the effects test, narrowed the discouragement standard, and revised requirements for special purpose credit programs. |
Ability-to-Repay / Qualified Mortgage Requirements |
Prerule |
The CFPB has returned the ATR/QM framework to the prerule stage as part of a broader review of mortgage regulations. |
Payday, Vehicle Title, and Certain High-Cost Installment Loans Reconsideration |
Proposed Rule |
The CFPB continues to reconsider its payday lending framework. During the hearings, Vought indicated that a small-dollar lending rule remains on the Bureau's agenda and is a near-term priority. |
Consumer Financial Civil Penalty Fund Rule Amendment |
Final Rule |
The rule would amend regulations governing administration of the Civil Penalty Fund, which is used to provide compensation to consumers harmed by violations of federal consumer financial laws. |
What's next? The Senate Banking Committee will vote on Brian Johnson’s nomination before it is considered by the full Senate.
The CFPB's core functions survive
After over a year of uncertainty about whether the CFPB would continue operating in anything close to its historical form, the recent hearings offered the clearest indication yet that a narrower ‒ but still active ‒ CFPB is beginning to emerge. While the final scope of the Bureau's workforce reductions remains uncertain, the hearings suggest that whatever resources ultimately remain will be concentrated on activities that leadership views as core statutory responsibilities. Although Vought's discussion of a supervisory program consisting of roughly 70 examinations this year demonstrates that the CFPB is continuing active supervision, it is a sharp decline from the average 600 examinations per year conducted between 2020 and 2024. The limited exams are likely to focus on priorities articulated throughout the last year, such as fraud, mortgage-related harms, military protections, credit reporting, debt collection, and other matters involving identifiable victims and measurable consumer harm. For financial institutions, a more focused CFPB may create opportunities to reassess controls, governance processes, and compliance activities developed in response to prior priorities. However, firms should not interpret a reduced CFPB footprint as a reduced need for consumer compliance programs. Federal consumer protection statutes remain in effect, and enforcement authority continues to reside not only with the CFPB but also with state attorneys general, state financial regulators, prudential banking agencies, the FTC, and private litigants. In addition, firms should be cautious about assuming today's supervisory priorities will remain fixed, particularly given the CFPB's history of significant policy shifts across leadership transitions.
An agenda focused on constraint and fulfilling statutory obligations
That said, the 2026 rulemaking agenda points to a broader effort to constrain future CFPB leadership from expanding the Bureau's authority without a thorough rulemaking process. Proposed actions addressing guidance documents, periodic review of regulations, supervisory designation proceedings, larger participant supervision, and a potential narrowing of UDAAP authority all point toward an effort to narrow the mechanisms through which future leadership can establish expectations outside of formal rulemaking. At the same time, the agenda makes clear that current leadership is not abandoning major policy initiatives where it sees a clear statutory mandate. Vought's comments on a forthcoming open banking proposal suggest that the CFPB will preserve consumer-directed access to financial data as a requirement. However, it remains to be seen how the new proposal will balance access rights, liability, data security, competitive concerns, and implementation costs among banks, aggregators, fintechs, and consumers.
What happened? On July 13h, as directed by Executive Order 14406, the OCC, FDIC, and NCUA issued guidance to remind supervised financial institutions of their existing obligations with respect to credit risk management, particularly as it relates to borrowers who are not legally authorized to work in the United States (“non-work authorized borrowers”).
What does the guidance say? The guidance highlights a number of credit risk concerns, including:
What's next? The EO directs Treasury to issue new rules on customer due diligence (CDD) by August 17th, 2026 and to update requirements for customer information programs (CIP) by November 15, 2026.
A portfolio perspective, not an individual screening one.
While the credit risk guidance does not create any new prescriptive obligations, the Administration’s focus on non-work authorized borrowers means that it will likely find its way into examiner expectations quickly. This presents challenges for lenders on multiple fronts: (1) operational questions of data collection, analysis and use across multiple risk assessments; (2) consumer compliance expectations of fair treatment; and (3) potential conflicts with state protections around immigration status and national origin. Deciding which borrowers lack legal status or work authorization is difficult because immigration status is fluid, and all credit applicants – regardless of work authorization – risk some sort of potential work interruption.
The clearest path for financial institutions to address these issues may be to boil the guidance to its actual asks. Assessing income stability and repayment capacity under multiple scenarios, documenting income verification, monitoring portfolio concentration risk are largely status-neutral risk-management practices rather than a call to underwrite on immigration status directly. While firms should certainly revalidate that their underwriting practices are sound and that their customers have the ability to repay, they should largely view the guidance with a portfolio perspective, treating exposure to non-work authorized customers as a variable similar to sector or geographic concentration limits. Managed at the portfolio level, this risk becomes measurable and monitorable without forcing a status determination on any single applicant.
This distinction also addresses potential conflicts with consumer protection and conflicting state laws, with the practical remaining challenge an implementation one: building risk assessment processes that capture legitimate income-stability and repayment-capacity concerns without treating immigration or citizenship status itself as an adverse underwriting factor.
What should banks do now? Steps to consider include:
What happened? On July 16th, the Fed, OCC, and FDIC issued a joint statement establishing a coordinated approach for identifying and handling highly sensitive information (HSI) collected during examinations of supervised banks. Separately, on July 22nd, the Fed’s Office of Inspector General (OIG) released a report on how examiners followed up on safety-and-soundness findings at large and foreign banking organizations.
What does the information handling statement say? The statement establishes a coordinated interagency approach for handling highly sensitive information (HSI) or information that carries heightened disclosure risks, for example technology and network diagrams, detailed penetration-testing results, technical details of information technology control weaknesses, and succession-planning documents.
What did the Fed OIG report say? The report highlighted issues with the Fed’s process for validating remediation of supervisory findings and discussed several changes intended to address them:
What's next? The agencies will issue written guidance and training to examiners to implement the HSI approach, and examiners will begin communicating the new identification and escalation processes at the outset of examinations.
The agencies are listening ‒ but implementation will be the real test.
Together, the publications signal a willingness to address longstanding bank concerns regarding information security and excessive delays in the administration of supervisory activities. The HSI statement comes more than a year after an OCC data breach prompted many institutions to sharply pull back the types of information shared with supervisors and how it is transmitted. In fact, it describes many of the approaches institutions have already developed independently in response to the breach, including restricted-access environments, onsite reviews of particularly sensitive materials, and differentiated handling of cybersecurity and technology information. The agencies stop short of prescribing specific approaches or handling requirements and continue to leave significant discretion to institutions and examination teams. As a result, the guidance may not fully address banks’ concerns regarding transparency into the changes agencies have made to strengthen their information security practices or consistency in how sensitive information is treated across institutions and supervisory portfolios.
Similarly, the Fed OIG report arrives after years of industry complaints that findings often remain open long after remediation efforts have been completed. While many of the changes highlighted in the report ‒ including greater reliance on internal audit and a more selective approach to horizontal reviews ‒ have already been incorporated into the Fed's revised SOPs, questions remain as to how quickly and consistently those changes will be implemented across examination teams and portfolios. It takes time for policy changes to translate into examination practice, but the revised SOPs notably include an invitation for institutions to escalate supervisory practices that appear inconsistent with the new framework.
More broadly, these developments reflect an agency environment that is increasingly willing to reconsider how supervision is conducted. Institutions may view this period as an opportunity to engage constructively on process improvements, particularly where supervisory activities consume significant resources without materially improving risk management outcomes.
What happened? On June 12th, the California Department of Insurance proposed its long-term solvency planning rule.
What would be required? The proposal is largely consistent with a draft rule released last fall and would require California-domiciled insurers to document and maintain analyses supporting their long-term capital resilience and solvency planning efforts. Key requirements would include:
What has changed from the draft rule? Following public meetings and input last fall, the proposal makes several changes:
What’s next? The Department of Insurance will hold a virtual public hearing on the Long-Term Solvency Planning Regulation on July 28th.
California is redefining what it means to be solvent, long-term
By requiring insurers to analyze how climate, technology, transition, cybersecurity, and other emerging risks, the proposal expands solvency oversight beyond traditional capital measures and toward the quality of an insurer's forward-looking risk management, governance, and resilience planning. The proposal also places greater weight on an insurer's ability to identify, assess, and adapt to risks that may emerge gradually over decades rather than over a typical planning cycle. While many of the potential requirements (e.g., climate risk assessments, scenario analysis, cybersecurity planning, technology risk governance, and identification of emerging risks) are not new, the proposal intentionally brings these elements together under a solvency-focused framework that directly links emerging risks to future capital planning and regulatory examination readiness. By linking long-term solvency planning to formal supervisory expectations, finalization of this proposal would raise the bar for data, modeling, and analytical capabilities needed to support these assessments. Evaluating risks across 2030, 2040, and 2050 time horizons may require insurers to rely on external datasets, assumptions, and projections that are difficult to obtain or validate, not yet available at the necessary level of granularity, or inherently subject to significant uncertainty.
The proposal reflects an important trade-off that policymakers increasingly face.
More rigorous long-term solvency expectations may increase pressure for risk-based pricing and stronger capital positions, contributing to higher premiums in some markets over the near term. However, those same measures may reduce the risk of insurers continuing to write business at prices or concentrations that later prove unsustainable, leading to sudden non-renewals, market withdrawals, or sharp contractions in underwriting capacity. From a policy perspective, the objective is not simply lower prices today, but a market in which insurers remain financially able, and willing, to provide coverage over the long run.
Whether other U.S. jurisdictions adopt similar approaches remains to be seen, but insurers outside of California should monitor this rulemaking process and consider possible implications. It is worth noting that similar requirements have long been in place internationally, with supervisory regimes such as the EU's Solvency II framework and the UK's Solvency UK regime placing greater emphasis on forward-looking solvency and capital resilience, rather than a narrower focus on current financial condition alone.
While the regulation is not yet final, California insurers should consider:
CFTC sunsets routine large trader reporting for physical commodity swaps. On July 17th, the CFTC issued a final order sunsetting the routine position-reporting requirements of Part 20, ending the daily and event-based large trader reports that clearing organizations, clearing members, and swap dealers have filed for physical commodity swaps since 2011. The Commission is retaining related recordkeeping and special-call provisions as a transitional measure (parts 43, 45, and 150).
GENIUS Act implementation continues at state and federal levels. On July 17th, the FDIC requested comment on reporting forms for FDIC-supervised Permitted Payment Stablecoin Issuers. Separately, NYDFS proposed 23 NYCRR Part 202, aligning its stablecoin framework with the GENIUS Act and establishing reserve, capital, redemption, deposit, and cybersecurity requirements. The OCC stablecoin licensing information-collection notice was placed on public inspection and is scheduled for publication July 27. Banks and applicants should expect application forms to require detailed information about governance, financial resources, business plans, risk management, compliance and ownership.
Fed Vice Chair for Supervision speaks. On July 13th, Fed Vice Chair for Supervision Bowman outlined principles for modernizing financial regulation and supervision across material financial risk, tailoring, transparency, accountability, and emerging risks.
Fed, FDIC, and OCC publish 2026 regulatory agendas. In early July, The FDIC, Fed, and OCC published their portions of the 2026 Unified Agenda of Regulatory and Deregulatory Actions.
CFPB issues credit card late-fee RFI. On July 6th, the CFPB submitted a request for information (RFI) to OIRA regarding credit card late fees and late-payment practices. The item remains in the prerule stage and joins broader agendas published by the CFPB, Federal Reserve, FDIC, and OCC.
SEC proposes Reg E delivery. On July 16th, the SEC proposed Regulation E-Delivery, a rule that would allow issuers, broker-dealers, investment advisers, and other market intermediaries to use electronic delivery to satisfy information delivery requirements under federal securities laws. Comments are due by September 21st, 2026.
NYDFS proposes formal rule on BNPL lenders. On July 15th, the New York Department of Financial Services published a formal proposed regulation implementing the state's BNPL Act, which would require BNPL lenders and qualifying platforms doing business in New York to obtain state authorization or licensure and comply with credit-card-style disclosure, fee, underwriting, and dispute-resolution requirements. Comments must be received by September 14th, 2026.
House passes Main Street Capital Access Act. On July 21st, the House of Representatives passed the Main Street Capital Access Act, which aims to restore tailoring to community and mid-sized bank regulation, ease new bank formation through phased-in capital requirements, add predictability to merger/acquisition approvals, and expand small and mid-sized banks' access to funding and liquidity.
Senate committee advances nomination to NCUA board. On July 23rd, the Senate Banking Committee voted to advance the nomination of John Crews to serve on the National Credit Union Administration (NCUA) board. If confirmed, Crews could lead the agency as the sole board member.
{{item.text}}
{{item.text}}