Our Newsletter Is Moving to LinkedIn

To keep receiving your weekly insights, all you need to do is subscribe to our new Consumer Financial Services Weekly Newsletter — it’s quick and easy.

We’ll see you there!

Click here to subscribe


To keep you informed of recent activities, below are several of the most significant federal events that have influenced the Consumer Financial Services industry over the past week.

Federal Activities

State Activities


Federal Activities:

On August 14, the Consumer Financial Protection Bureau (CFPB) announced that it is ceasing the discretionary publication of unverified consumer complaint narratives and related data visualizations in its Consumer Complaint Database. The CFPB’s Consumer Complaint Database has long included both aggregate complaint data and the narrative descriptions that individual consumers submit about their experiences with financial products and services. The Bureau has now concluded that the publication of these narratives and associated data visualizations is discretionary, not statutorily required, and that years of experience have demonstrated that their utility is minimal while the potential for consumer confusion and company reputational harm is significant. The announcement drew sharp criticism from Senator Elizabeth Warren (D-MA), ranking member of the Senate Banking, Housing, and Urban Affairs Committee, who characterized the action as Donald Trump and Russell Vought “burying the evidence of corporate abuses against American consumers,” arguing the move makes it easier for banks and corporations to harm families while rewarding Wall Street donors. For more information, click here and here.

On August 14, the CFPB published its regulatory agenda as part of the 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, reflecting the Bureau’s anticipated regulatory matters for the period from January to November 2026. The Bureau, which is currently operating under interim leadership pending confirmation of a permanent director, indicated that this agenda largely focuses on updating projects from the Spring 2025 Agenda, reconsidering certain recently completed rulemakings, and limited new additions. Specifically, the CFPB plans to pursue: (1) a rulemaking to reconsider certain aspects of its May 2023 final rule implementing § 1071 of the Dodd-Frank Act regarding small business lending data collection; (2) a rulemaking to reconsider certain aspects of its November 2024 personal financial data rights rule implementing § 1033 of the Dodd-Frank Act; and (3) a rulemaking to clarify obligations under the Equal Credit Opportunity Act (ECOA). The Bureau’s active agenda is organized into five sections (pre-rule, proposed rule, final rule, long-term actions, and completed actions), and the CFPB noted it expects to continue refining its priorities and provide additional information in future Unified Agenda publications. For more information, click here.

On August 14, the Department of the Treasury published its regulatory agenda as part of the 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, covering planned and completed rulemaking activities across the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) and the Office of the Comptroller of the Currency (OCC). On the FinCEN side, proposed rules include: revisions to customer due diligence requirements for financial institutions under the Corporate Transparency Act (a notice of proposed rulemaking (NPRM) expected March 2027); a reissued joint NPRM with the Securities and Exchange Commission (SEC) on customer identification program requirements for registered investment advisers and exempt reporting advisers (NPRM expected September 2026); a new anti-money laundering (AML)/countering the financing of terrorism (CFT) Programs rule to modernize Bank Secrecy Act (BSA) requirements (NPRM issued April 10, 2026, comment period closed June 9, 2026); and two rulemakings implementing the GENIUS Act for permitted payment stablecoin issuers (PPSIs) — one jointly with the Office of Foreign Assets Control (OFAC) addressing AML/CFT program and sanctions compliance requirements, and one jointly with the OCC, Federal Reserve, Federal Deposit Insurance Corporation (FDIC), and National Credit Union Administration (NCUA) addressing customer identification program requirements (both NPRMs issued April 10, 2026). On the OCC side, proposed rules include a joint NPRM with the FDIC on extensions of credit to insiders and transactions with affiliates to reduce burden and focus supervisory attention on material financial risk, and a joint NPRM with the Federal Reserve and FDIC to revise risk-based capital rules for non-Category I and II banking organizations; at the final rule stage, the OCC is moving forward with an interim final rule to rescind or amend regulations consistent with Executive Order 14219 to streamline Title 12 of the Code of Federal Regulations. For more information, click here.

On August 14, the SEC published its Regulatory Flexibility Agenda as part of the 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, reflecting the Chairman’s rulemaking priorities for the period ahead across three divisions. The Division of Corporation Finance has 10 items in the proposed rule stage, including: a reproposal of Rule 144 safe harbor amendments to expand resale availability for restricted and control securities (second NPRM expected October 2026); foreign private issuer eligibility enhancements; crypto assets disclosure; emerging growth company accommodation enhancements and filer status simplification; registered offerings reform; updating exempt offering pathways including potential amendments to the accredited investor definition; rationalization of disclosure practices; shareholder proposal modernization under Exchange Act Rule 14a-8; executive compensation disclosure reform under Regulation S-K Item 402; and rescission of the climate-related disclosure rules adopted in March 2024 (NPRM issued June 3, 2026, comment period closed August 3, 2026). The Division of Investment Management has seven proposed rule items, including amendments to Form N-PORT to reduce disclosure burdens, amendments to Rule 17a-7 to modernize affiliated transaction exemptions, amendments to the custody rules, electronic delivery of information under federal securities laws, enhanced retail exposure to private markets, Form PF reporting requirement amendments for hedge fund advisers, and pay-to-play reform under Investment Advisers Act Rule 206(4)-5; customer identification programs for registered investment advisers and exempt reporting advisers is listed as a long-term action. The Division of Trading and Markets has three proposed rule items: modernization of the transfer agent regulatory regime including crypto asset and distributed ledger technology considerations, amendments to Rule 17Ab2-1 and Form CA-1 to streamline clearing agency registration, and amendments to the Treasury Clearing Rule to exclude certain inter-affiliate and non-U.S. activity and reduce implementation burdens. For more information, click here.

On August 14, Freddie Mac publicly disclosed the results of its 2026 Dodd-Frank Act stress test under the severely adverse scenario, as required by the Federal Housing Finance Agency’s (FHFA) implementation of the Dodd-Frank Act. Conducted annually to assess capital adequacy, the stress test evaluated Freddie Mac’s performance under two hypothetical scenarios — a Baseline scenario and a Severely Adverse scenario — each projected over a nine-quarter horizon. The Severely Adverse scenario modeled a 30% decline in house prices, a 39% drop in commercial real estate prices, and a severe global market shock including the default of Freddie Mac’s largest counterparty. Freddie Mac emphasized that the results are modeled projections based on hypothetical economic conditions and are not expected outcomes, noting that actual results may differ materially, and that its business remains focused exclusively on the U.S. residential mortgage market consistent with its statutory mission to provide liquidity, stability, and affordability to the housing market. For more information, click here.

On August 14, the OCC released its annual update to the Bank Accounting Advisory Series (BAAS), a publication containing OCC staff responses to frequently asked questions from the banking industry and bank examiners on a variety of accounting topics, designed to promote consistent application of accounting standards and regulatory reporting among national banks and federal savings associations. This edition reflects updates to accounting standards issued by the Financial Accounting Standards Board (FASB) on topics including purchased loans, government grants, and internal-use software. The OCC noted that the BAAS does not constitute rules or regulations, but rather represents the OCC Office of the Chief Accountant’s interpretations of generally accepted accounting principles and regulatory guidance based on the facts and circumstances presented. For more information, click here.

On August 13, the Federal Reserve’s Division of Supervision and Regulation issued SR 26-4, guidance reminding all Federal Reserve-supervised banking organizations of their existing credit risk management obligations when lending to individuals not legally authorized to work in the United States. The guidance, which does not amend or expand existing regulations, identifies four key underwriting considerations: (1) source of repayment — noting that income derived from unauthorized employment may be less reliable due to risks of employment termination, suspension, or the borrower’s removal from the U.S.; (2) collateral — highlighting that banking organizations may face added challenges enforcing security interests or locating and repossessing unaffixed collateral such as automobiles or boats when borrowers are not legally authorized to be in the country; (3) documentation and verification — encouraging banks to review paystubs, W-2s, tax returns, employer verifications, bank statements, or evidence of continuing work authorization, and to consider whether such loans exhibit signs of credit weakness for classification and allowance for credit loss purposes regardless of delinquency status; and (4) portfolio and concentration risk — warning that significant lending exposure to borrowers concentrated in geographic markets, employers, or industries disproportionately affected by changes in immigration enforcement or workforce disruptions could result in correlated credit deterioration across affected portfolio segments rather than isolated borrower-level stress. For more information, click here.

On August 13, Commodity Futures Trading Commission (CFTC) Chairman Michael S. Selig announced the agenda for the inaugural meeting of the agency’s Innovation Advisory Committee (IAC), scheduled for August 20, 2026, from 1:00 to 4:00 p.m. ET in Washington. The meeting, chaired by Walt Lukken and sponsored by Selig, will feature three substantive sessions covering the regulatory evolution of crypto assets (including the history of state licensing patchworks, the impact of regulatory uncertainty on innovation, and the road ahead for a federal market structure framework), the rise of AI in derivatives markets (including agentic finance, autonomous trading, and how existing regulatory principles apply to AI-enabled participants), and the future of prediction markets (including federal and state jurisdictional questions, product design principles, and market surveillance considerations). The meeting will be streamed live on CFTC.gov, members of the public may submit comments through Regulations.gov by August 27, and individuals with questions may contact IAC Designated Federal Officer Michael Passalacqua. For more information, click here.

On August 12, the OCC and FDIC jointly issued a NPRM to amend their Community Reinvestment Act (CRA) regulations, with comments due by October 13, 2026. The proposal, which builds on decades of regulatory experience dating back to the agencies’ current framework rooted in 1995 rules and follows the enjoinment and eventual dismissal of the 2023 CRA rules after litigation in the Northern District of Texas, seeks targeted changes in four main areas: (1) increasing the focus on lending by narrowing the range of services considered under CRA evaluations and clarifying how “responsiveness” and “complexity” are assessed; (2) ensuring community development grants directly benefit local communities, including a proposed 15% cap on indirect costs for grant recipients applicable to large banks; (3) reducing regulatory burden, particularly for community banks, by establishing new simplified asset-size thresholds (below $1 billion for small banks, $1 billion to $10 billion for intermediate banks, and above $10 billion for large banks), limiting the lending test to major product lines, and modernizing public file and notice requirements to allow website-based disclosures; and (4) increasing clarity and objectivity by codifying the definition of community development, establishing a formal process for banks to seek agency confirmation of CRA-qualifying activities, and streamlining the strategic plan option. For more information, click here.

On August 12, the CFTC’s Division of Market Oversight (DMO) issued Staff Advisory Letter No. 26-23 to remind designated contract markets (DCMs) of their regulatory obligations under the Commodity Exchange Act and Part 40 of CFTC regulations when self-certifying incentive programs — including market-maker, liquidity, and trading programs — particularly those related to prediction markets and event contracts. The advisory outlines both procedural and substantive expectations for Rule 40.6 submissions, requiring that filings explicitly detail all material economic, structural, and operational terms, and that all material amendments be submitted as new certifications rather than modifications to existing filings. On the substantive side, DMO staff identified several recurring compliance concerns, including volume-based reward structures with steep tiers that may incentivize wash-trading, market-maker programs that guarantee profits or cover losses, and randomized or sweepstakes-style rewards that violate Core Principle 2’s impartial access requirements; the advisory also flags conflict-of-interest risks when a DCM administers incentive programs benefiting an affiliated market-maker, and antitrust considerations under Core Principle 18. DCMs with previously certified incentive programs are encouraged to review them for compliance and submit any necessary amendments by September 14, 2026. For more information, click here.

On August 11, the U.S. Department of the Treasury announced guidance establishing the framework for employer-sponsored contribution programs to Trump Accounts — tax-advantaged savings accounts designed to help American families build long-term wealth for their children. Under the Working Families Tax Cuts Act, employers may contribute up to $2,500 tax-free annually to the Trump Account of an employee’s dependent, and employees may also make pre-tax contributions through an employer cafeteria plan; to establish such a program, employers must maintain a separate written plan document, follow certification procedures, provide employee notices and annual statements, and report to the Trump Account trustee. Treasury Secretary Scott Bessent and Internal Revenue Service CEO Frank Bisignano highlighted the program’s potential to serve as a low-cost, tax-preferred benefit for businesses of all sizes, noting that more than 50 major companies have already committed to making employer contributions. For more information, click here.

On August 11, FinCEN issued a final rule, effective August 14, 2026, permanently removing the requirement for U.S. companies and U.S. persons to report beneficial ownership information (BOI) to FinCEN under the Corporate Transparency Act (CTA). The final rule makes permanent the exemptions originally introduced in the March 2025 interim final rule, and additionally exempts U.S. persons holding FinCEN IDs from any obligation to update or correct previously submitted information, eliminates the requirement for foreign companies to report U.S. person “company applicants,” and exempts foreign pooled investment vehicles registered in the U.S. from reporting BOI for any U.S. person in control. Notably, FinCEN also announced it will delete from its BOI database all previously reported information linked to U.S. persons (including company applicants, beneficial owners, and FinCEN ID recipients) identified through documents such as U.S. passports or driver’s licenses, while foreign entities that are reporting companies will still be required to report BOI for foreign individuals. For more information, click here.

On August 11, the OCC issued a statement commending the FDIC’s newly announced two-phase process for reviewing deposit insurance applications, noting that it aligns with the OCC’s own priority of reinvigorating de novo chartering to build a more robust, diverse, and competitive banking system. Comptroller Jonathan V. Gould highlighted that de novo chartering declined significantly over the past 15 years (with the OCC receiving an average of fewer than four charter applications per year between 2011 and 2014, and zero in some years), but noted that momentum has shifted, with the OCC receiving 40 de novo applications in the last 18 months alone, including applications for national trust banks, and, for the first time in five years, a full-service national bank receiving final OCC approval and opening. Gould emphasized that entities engaged in legally permissible activities, including those involving digital assets and novel technologies, should have a clear path to obtaining a national bank charter, and reaffirmed that the OCC will continue encouraging new bank formation to drive innovation, expand consumer choice, and strengthen the resilience of the federal banking system. For more information, click here.

On August 10, the FDIC announced a new two-phase process for reviewing deposit insurance applications, aimed at encouraging new bank formation, speeding up review timelines, and improving overall efficiency. Under the new approach, qualifying de novo applicants will receive a contingent authorization within 120 days of application submission, followed by full approval within the subsequent 12 months after additional information is provided and key organizational steps are completed. This structure is designed to give organizing groups early clarity before they commit significant capital, staffing, and infrastructure resources, and the FDIC generally expects applicants to be able to file concurrently with both the FDIC and their chartering authority. The streamlined procedures align with the 21st Century ROAD to Housing Act, which directs federal banking agencies to modernize the de novo application process, and the FDIC indicated it will continue coordinating with state and federal counterparts to ensure a transparent, consistent, and timely deposit insurance application process. For more information, click here.

On August 5, the SOLO Network announced a FinCEN-observed bank reliance pilot developed in coordination with the Treasury, FinCEN, the OCC, and the FDIC. The pilot represents the first coordinated engagement across all four agencies to operationalize bank reliance at scale and could significantly reshape how financial institutions approach customer due diligence and identity verification. Financial institutions have long been required to independently verify the identity and background of customers before onboarding them. That process has historically meant repeating the same verification work every time a customer opens a new financial relationship, regardless of whether another institution has already completed the same work to an acceptable standard. The redundancy stems not from any lack of verification, but from three structural problems: no common way to represent completed verification work across institutions, little economic incentive to share work already performed, and no operational framework for evidencing reliance in a consistent, auditable way. The pilot was launched to address these structural barriers by standardizing not how institutions perform verification, but how completed verification is represented, evidenced, and independently evaluated by financial institution members of the network. Participating institutions generate standardized, auditable verification artifacts that document the work performed, methods used, timing, and personnel involved. Other institutions in the network can then independently evaluate those artifacts to determine whether they satisfy their own compliance and risk requirements without requiring the consumer or business to start over with the identity verification process whenever onboarding with a new financial institution. If any qualifying factors for a particular financial institution’s verification process are missing from the information shared among the network members, that financial institution can perform just the missing verification steps itself. The model is being described as analogous to TSA PreCheck: trusted verification travels with the consumer rather than being restarted at every new financial institution, while each institution retains independent compliance responsibility and decision-making authority. One important caveat bears noting: regulatory observation of the pilot does not constitute a no-action letter, safe harbor, or endorsement of the SOLO model. For more information, click here.

State Activities:

On August 14, the District of Columbia enacted B26-0661, the Fiscal Year 2027 Budget Support Act of 2026, as D.C. Act 26-418 without the signature of Mayor Muriel Bowser, creating D.C. Code § 42-3505.01 to authorize the mayor to establish a rent-payment reporting program. Under the program, rental housing providers must offer tenants the option to have their rent payments reported to one or more credit reporting agencies, with the offer required to be in writing and to disclose that participation is optional, identify the reporting agencies, explain which payments will be reported and when payments are considered timely, late, or missed, and explain how tenants may stop reporting. Tenant acceptance must be evidenced by a dated signature, and participating tenants may withdraw at any time, though a tenant who withdraws may not resume participation for at least six months. Providers must stop reporting within 30 days of a tenant’s withdrawal request and must also pause reporting when a tenant provides written notice of intent to withhold rent due to an alleged habitability failure, until rent payments resume. The law also permits the mayor to condition specified District financial assistance on a provider’s participation in the rent-payment reporting program or provision of rent-payment data to credit reporting agencies, subject to tenant consent. For more information, click here.

On August 13, the New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow issued new guidance and a proposed draft regulation to strengthen New York’s Independent Dispute Resolution (IDR) process, which protects patients from surprise medical bills arising from disputes between out-of-network health care providers and health insurers. The guidance implements amendments to Financial Services Law Article 6 signed by Governor Kathy Hochul on May 28, 2026, as part of the FY27 Budget, which exclude Medicaid Managed Care coverage from the IDR process, add the Empire Plan and Student Employee Health Plan to the process with unique dispute criteria, increase the time IDR entities have to issue decisions, and require health care providers and health insurers to pay IDR entities upfront before dispute review begins. The draft regulation is subject to a 10-day preproposal comment period beginning August 13, followed by a 60-day public comment period upon publication in the State Register. Because the new law takes effect August 26, 2026, the regulation will be temporarily adopted on an emergency basis on that date to address conflicts between the new law and existing regulations while the formal rulemaking process proceeds. For more information, click here.

On August 11, the Colorado Department of Law (DOL) filed proposed rules implementing two significant Colorado artificial intelligence laws, the Automated Decision-Making Technology in Consequential Decisions Act (ADMT Act) and the Conversational Artificial Intelligence Services Act (Chatbot Safety Act), both of which take effect January 1, 2027. The ADMT Act (Senate Bill 26-189, signed May 2026) creates obligations for both developers and deployers of ADMT used to materially influence “consequential decisions” — defined to include decisions affecting employment, education, financial services, housing, insurance, and other significant areas of consumer life. As discussed in our prior post, the law imposes disclosure, consumer rights, and human review obligations on deployers, and documentation and notification obligations on developers, while removing many of the governance, bias assessment, and public reporting requirements from the 2024 version. The Chatbot Safety Act (House Bill 26-1263, signed July 1, 2026) imposes obligations on operators of conversational AI services accessible to the general public, including requirements to disclose that users are interacting with AI, estimate user age, protect minors from sexually explicit content and simulated emotional dependence, implement suicide and self-harm response protocols, and submit annual reports to the Colorado Attorney General. The law also prohibits chatbot outputs from being presented as equivalent to services provided by licensed health care, legal, or mental health professionals. Public comments about any proposed revisions to the rules to be presented during the hearing must be submitted by October 5, but all public comments submitted through October 26 will be considered for the final set of rules. For more information, click here.

On August 11, the New York State DFS issued a cybersecurity threat alert to all DFS-regulated entities warning of an active campaign targeting a known exploited vulnerability in N-central, a remote monitoring and management (RMM) system developed by N-able and used by some managed service providers (MSPs) to remotely monitor, patch, and access customer systems. Threat actors exploiting this vulnerability are compromising MSP environments, creating persistent access points that survive credential revocation, and leveraging that foothold to move laterally into MSP customers’ networks with administrator-level privileges. DFS directed regulated entities to promptly determine whether N-central is used in their own environment or by any third-party service provider, and where it is, to work with those providers to review N-central activity for unauthorized or persistent access, verify that applicable patches and mitigation steps have been implemented, and assess whether any systems or credentials were compromised. The alert further reminded regulated entities that senior governing bodies and senior officers must actively engage in cybersecurity risk management and third-party oversight, and that all cybersecurity incidents, including those originating at third-party service providers, must be reported to DFS as required by 23 NYCRR § 500.17. For more information, click here.