Our Newsletter Is Moving to LinkedIn
To keep receiving your weekly insights, all you need to do is subscribe to our new Consumer Financial Services Weekly Newsletter — it’s quick and easy.
We’ll see you there!
To keep you informed of recent activities, below are several of the most significant federal events that have influenced the Consumer Financial Services industry over the past week.
Federal Activities:
On September 11, the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve Board, the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) jointly requested comment on proposed guidance to help financial institutions manage risks associated with third-party relationships, intended to replace the agencies’ 2023 Interagency Guidance on Third-Party Relationships: Risk Management (the 2023 Guidance) and related supplemental third-party risk management (TPRM) resources once finalized, with comments due 60 days after Federal Register publication. The proposal responds to supervisory experience and stakeholder feedback indicating the 2023 Guidance was frequently interpreted too broadly and prescriptively leading to one-size-fits-all checklist approaches, heightened scrutiny applied without regard to actual risk magnitude, and a chilling effect on partnerships with innovative fintech third parties-and instead emphasizes a principles-based, tailored approach centered on risk identification and assessment, consistent with Executive Order 14405, “Integrating Financial Technology Innovation into Regulatory Frameworks.” Separately, the agencies issued a statement addressing factors they will consider in supervisory and enforcement decisions regarding community banks’ engagement with core service providers, and the Federal Reserve Board independently requested comment on a companion third-party risk management guide tailored specifically for Federal Reserve-supervised community banks. For more information, click here.
On September 10, the OCC, the Federal Reserve Board, and the Federal Deposit Insurance Corporation (FDIC) jointly issued an interim final rule that doubles the asset threshold for qualifying small insured depository institutions (IDIs) to be eligible for an extended 18-month on-site examination cycle. Prior to this rule, only IDIs with less than $3 billion in total assets could qualify for an 18-month examination cycle in lieu of the standard annual examination. Effective immediately upon Federal Register publication, the threshold has been raised to less than $6 billion in total assets, implementing § 903 of the 21st Century ROAD to Housing Act, which became law on July 11, 2026. To qualify, an IDI with less than $6 billion in total assets must also: be well capitalized under the prompt corrective action framework; have received a CAMELS management component rating of 1 or 2 at its most recent examination; have received at its most recent examination a composite rating of 1 or, if the IDI has $200 million or less in total assets, 1 or 2; not be subject to a formal enforcement proceeding or order; and not have undergone a change in control during the prior 12-month period. The rule also makes parallel changes to the examination cycle regulations governing U.S. branches and agencies of foreign banks, consistent with the International Banking Act of 1978. For more information, click here.
On September 10, the Federal Trade Commission’s (FTC) Bureau of Consumer Protection (BCP), under Director Christopher Mufarrige, announced the launch of a new BCP Rule Guidance Program allowing stakeholders to submit questions via an online form on the BCP Rule Guidance Program webpage-identifying genuine ambiguities in Commission rules, substantive conflicts between a rule and an existing statute or other rule, or other significant issues within Commission rules. Staff will review submitted questions and, where the Bureau determines a response is warranted, publish guidance publicly to promote transparency and help businesses comply with the law. The program excludes questions that merely ask staff to restate a rule’s text, seek to diminish a business’s own compliance obligations, request interpretation of performance-based standards like “clear and conspicuous” (which have established meanings under case law), or can be answered through the FTC’s existing plain-language guidance. The Bureau intends to refine the process over time based on experience. For more information, click here.
On September 10, Securities and Exchange Commission (SEC) Chairman Paul S. Atkins delivered pre-recorded virtual remarks to the Investor Advisory Committee. Addressing the first panel’s focus on artificial intelligence (AI) and corporate disclosures, Atkins cautioned that while AI may help distill information in SEC filings, it does not give the Commission latitude to depart from its longstanding materiality principle, and emphasized that AI should complement rather than replace human judgment given its continued susceptibility to errors and hallucinations, its opacity, and the risk that widespread reliance on similar tools could cause errors to cascade across markets. He reiterated that the SEC will not prescribe specific AI models or act as a merit regulator, but will focus on its statutory role of setting rules and ensuring fair play. Turning to the second panel on potential reforms to Regulation NMS, Atkins criticized Rule 611 (the Trade-Through Rule) as a longstanding policy misstep dating to his tenure as Commissioner, arguing it fragmented liquidity and increased complexity and cost by substituting regulatory judgment for market competition, and noted that the Commission’s June proposal to rescind Rules 611 and 610(e) has drawn substantial public comment that staff are now reviewing, with the panel’s input intended to further inform the Commission’s approach. For more information, click here.
On September 9, the Federal Communications Commission (FCC) released a fact sheet outlining a Report and Order and Further Notice of Proposed Rulemaking (FNPRM) in CG Docket No. 02-278, aimed at modernizing rules under the Telephone Consumer Protection Act of 1991 (TCPA) to make it easier for consumers to revoke consent to receive robocalls while streamlining callers’ processing of such requests. The Report and Order would allow callers to interpret a revocation request as limited to the specific category of informational robocalls to which it was directed rather than all consented-to robocalls, permit callers to designate an exclusive means for consumers to revoke consent, modify the financial institution exemption from the consent requirement to make it easier for banks to alert customers to fraudulent account activity, and delegate authority to the Consumer and Governmental Affairs Bureau to review and clarify the TCPA implementing rules. The accompanying FNPRM would seek comment on further updates, including revisiting the timeframe for honoring revocation requests, requiring two-way texting functionality so consumers can revoke consent via reply text, requiring callers to provide a method to revoke consent to all robocalls, and the treatment of affiliates. The fact sheet also notes the item is released under “permit-but-disclose” procedures, meaning any outside presentations to the Commission on the matter must be filed in the docket via the FCC’s Electronic Comment Filing System (ECFS). For more information, click here.
On September 8, the FTC entered into a stipulated order for permanent injunction against 5967 Ventures, LLC, doing business as Humboldt Merchant Services, resolving allegations that the payment processor facilitated fraud by opening and maintaining payment processing accounts for shell companies and merchants engaged in deceptive practices. The FTC’s complaint charged that Humboldt Merchant Services violated § 5 of the FTC Act by engaging in unfair acts or practices. Specifically, the complaint alleged that the processor onboarded merchants that were either shell companies or actively engaged in fraud. The case highlights the FTC’s continued focus on upstream payment processors as enforcement targets, not just the fraudulent merchants themselves. Key terms of the order include: the defendant is required to pay $12 million to the FTC; the defendant is barred from engaging in or assisting with credit card laundering, including processing transactions through merchant accounts held by entities other than the actual merchant; and the defendant must maintain a formal oversight program for all sales agents, including monthly risk metric reviews, background checks, MATCH list screening, and Office of Foreign Assets Control checks. For more information, click here.
On September 8, the Financial Crimes Enforcement Network (FinCEN), Federal Reserve Board, FDIC, NCUA, and OCC jointly issued supervisory guidance in the form of two new frequently asked questions (FAQs), along with an amendment to a previously issued FAQ updating terminology, addressing the treatment of verifiable digital credentials (VDCs)-including state-issued mobile driver’s licenses (mDLs) and other government-issued digital credentials-under the Customer Identification Program (CIP) rule, applicable to all FDIC-insured financial institutions. The guidance clarifies that an mDL, a state-issued driver’s license or identity card containing the same information as its physical counterpart, is a type of VDC, and that the CIP rule neither requires nor prohibits reliance on government-issued VDCs to verify a customer’s identity. It further explains that an unexpired, government-issued VDC such as an mDL qualifies as a “government-issued identification” under the CIP rule so long as it evidences nationality or residence and bears a photograph or similar safeguard, and that a bank or credit union may use such a VDC to verify identity to the extent permitted by its CIP, provided it maintains the appropriate technology or systems to extract the relevant information from the credential. For more information, click here.
On September 3, U.S. Federal Housing Finance Agency (FHFA) Director Bill Pulte announced that he directed Fannie Mae and Freddie Mac, the government-sponsored enterprises created by Congress to support the housing market, to immediately approve all lenders to use the VantageScore credit scoring system. Pulte stated on X that the initial rollout of VantageScore had proven successful, with 50 lenders already delivering loans under it, prompting him to instruct Fannie Mae and Freddie Mac to expand approval to all lenders effective immediately. For more information, click here.
On September 2, the OCC issued two separate letters granting preliminary conditional approval to charter new de novo national banks, together with waivers of the director residency requirements. One conditional approval was to Revolut Bank US, N.A., a proposed Stamford, Connecticut-based subsidiary of Revolut Holdings US, Inc. (itself owned by UK-regulated Revolut Group Holdings Ltd.), which would offer deposit, credit, payments, and digital asset custody services (excluding, for now, retail foreign exchange business, which remains subject to a future Supervisory Non-Objection) and facilitate stablecoin-based remittances through affiliate TechCo, subject to a minimum $95 million in initial paid-in capital and a 10% tier 1 leverage ratio. The other conditional approval was to OpenReserve Bank, N.A., Na proposed Salt Lake City, UT-based bank that would offer deposit and lending products with tokenized capabilities, payments and treasury services, digital asset custody, and foreign correspondent banking, and plans to form a wholly-owned stablecoin subsidiary (not yet separately applied for) to issue, custody, convert, and process U.S. dollar-denominated reserve-backed stablecoins, subject to a minimum $210 million in initial paid-in capital, a 12% tier 1 leverage ratio, and future compliance with the GENIUS Act. Both approvals remain preliminary and conditional pending satisfaction of standard pre-opening requirements, including independent audits, security reviews, adequate capitalization, and OCC nonobjection to senior officers and directors, and will expire if capital is not raised within 12 months or the banks do not open within 18 months of approval, with the OCC retaining full authority to modify, suspend, or rescind either approval based on material changes in circumstances. For more information, click here and here.
State Activities:
On September 14, Massachusetts Attorney General Andrea Joy Campbell announced a consent judgment resolving her office’s lawsuit against Avon-based debt collection and debt buying companies Judgment Acquisitions Unlimited, Champion Funding, Inc., and their owner Andrew Metcalf, over allegations that they engaged in unfair and deceptive debt collection practices under the Massachusetts Consumer Protection Act, including seizing consumers’ vehicles unrelated to any car loan — even vehicles legally exempt from seizure and serving as consumers’ only means of transportation to work — to coerce payment. The settlement prohibits the defendants from buying, selling, transferring, assigning, or collecting on debts allegedly owed by Massachusetts consumers, effectively providing more than 6,000 consumers with approximately $52 million in debt relief, permanently bars them from seeking a Massachusetts debt collector license or engaging in any collection activity from or within the Commonwealth (even for non-Massachusetts consumers’ debts), and subjects them to a $650,000 suspended penalty if they violate the settlement or are found to have misrepresented their ability to pay. For more information, click here.
On September 9, Minnesota Attorney General (AG) Keith Ellison filed a lawsuit in Hennepin County against C4D, LLC, its owners Travis Benoit and Steven Legatt, and related entity Five Points Properties, LLC, alleging 18 counts of violating the Minnesota Human Rights Act, the federal Truth in Lending Act (TILA), Equal Credit Opportunity Act (ECOA), and Consumer Financial Protection Act (CFPA), Minnesota consumer fraud and deceptive trade practices laws, and Minnesota contract for deed requirements, through a predatory scheme in which the defendants purchased homes, resold them at dramatically inflated prices via contracts for deed with large down payments, artificially low monthly payments, and steep annual balloon payments (in one case, a $2,000 monthly payment paired with a $77,475 annual balloon), leaving purchasers immediately underwater and prone to losing the home and all payments made upon a single missed payment, after which the defendants could resell the property at a further profit. The complaint further alleges that the C4D defendants specifically targeted Somali-American Muslims through “reverse redlining,” exploiting religious beliefs that may discourage interest-based mortgages to steer them into these abusive contracts, including one instance where a Somali-speaking customer with limited English proficiency was misled into believing she was signing a foreclosure-protected mortgage before being evicted with her children after missing payments. Ellison is seeking a court order halting the defendants’ practices, civil penalties, and cancellation or reformation of existing contracts to remedy consumer injuries. For more information, click here.
On September 3, the Mortgage Bankers Association (MBA) filed a complaint in the U.S. District Court for the District of New Jersey against New Jersey AG Jennifer Davenport and New Jersey’s Division on Civil Rights (DCR) Director Yolanda Melville in their official capacities. The MBA seeks a declaration that New Jersey’s disparate impact rule violates the Equal Protection Clause of the Fourteenth Amendment and is preempted by federal law, along with an injunction against its enforcement. The disparate impact rules, effective December 15, 2025, codify a broad burden-shifting framework for disparate impact claims across housing, lending, employment, public accommodations, and contracting, and include specific guidance on liability arising from the use of artificial intelligence and automated decision-making tools. The MBA advances two causes of action. First, it contends the rule violates the Equal Protection Clause by stripping away the constitutional safeguards and compelling private parties to engage in racial balancing on the state’s behalf. Second, it argues the rule is preempted by federal law. The Fair Housing Act expressly invalidates any state law that “purports to require or permit” conduct that would constitute a discriminatory housing practice. 42 U.S.C. § 3615. Because the only reliable path to compliance with the New Jersey rule runs through race-conscious policymaking, which the Equal Credit Opportunity Act, Regulation B, and the Fair Housing Act each independently forbid, the MBA argues that simultaneous compliance with state and federal law is impossible. Of note, although the MBA requests that the rule be invalidated in its entirety, the MBA’s complaint focuses exclusively on the rule’s application in the context of disparate impacts on the basis of race. For more information, click here.
On September 3, the California Privacy Protection Agency (CalPrivacy) issued Enforcement Advisory 2026-01, targeting data brokers that provide incorrect information in their annual registration with California’s data broker registry under the state’s Delete Act, which requires businesses that operated as data brokers in the prior year to register annually and disclose information such as data collection metrics, types of data collected, and data recipients. The advisory warns that data brokers are liable for a $200 daily fine for failing to register correctly as required, and notes that the Enforcement Division has already brought multiple enforcement actions over such reporting errors to protect the integrity of the registry, which underpins the newly launched Delete Request and Opt-Out Platform (DROP). For more information, click here.
On September 3, Connecticut AG William Tong issued a comprehensive consumer alert warning residents about the significant financial and security risks posed by unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges-including GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid, which operate outside state and federal regulatory frameworks and expose investors to predatory leverage, opaque centralized control, and little to no recourse if something goes wrong. The Office of the AG reports it is already aware of at least one Connecticut consumer who lost $200,000 depositing funds into such a platform. Joined by Connecticut Banking Commissioner Jorge Perez, Tong explained that although these platforms market themselves as decentralized and governed by smart contracts, many are actually centralized corporate operations registered offshore in jurisdictions like Singapore and the Cayman Islands to evade oversight, allow anonymous trading without Know Your Customer (KYC) verification (creating risks for money laundering, sanctions evasion, and use by state-backed actors such as North Korean hackers), circumvent U.S.-user restrictions through VPNs (with roughly 22.6% of Hyperliquid’s traffic reportedly originating from the U.S.), offer leverage as high as 100x to 250x that would be prohibited for U.S. retail investors, and provide synthetic “perpetual contracts” that can mislead investors into thinking they own actual shares, all while centralized owners retain the ability to alter prices or halt trading and withdrawals. The alert also notes that global regulators have already taken action against Hyperliquid, and it urges Connecticut consumers to research any platform’s regulatory status before investing, keep transaction records, beware of “recovery specialist” scams, and report suspected fraud to the Office of the AG. For more information, click here.
On August 28, the Connecticut Banking Commissioner, Jorge L. Perez, issued a consent order resolving allegations against Tapcheck Inc., a Delaware corporation providing employer-integrated earned wage access (EWA) advances, that between January 1, 2024, and January 29, 2026, it made, offered, and advertised small loans to Connecticut borrowers and received related payments without the small loan company license required under § 36a-556(a) of the Connecticut General Statutes, in violation of subsections (1), (2), (4), and (6) of that section. Without admitting or denying the allegations, Tapcheck, which has since ceased such activity in Connecticut and has a licensing application pending, agreed to comply with the licensing requirement going forward, pay a $200,000 civil penalty in four $50,000 installments, remit $400 in back-licensing fees, and reimburse all fees collected from affected Connecticut borrowers. In exchange, the commissioner agreed not to pursue further enforcement for the pre-Effective Date conduct, and the order does not preclude Tapcheck from obtaining a Connecticut small loan license so long as it complies with applicable requirements and the order’s terms. For more information, click here.
