Feature Regulatory Compliance
Financial Data Transparency Act: What the June 2026 Joint Data Standards Final Rule Means for Banks and Fintechs
Nine federal agencies published the FDTA joint data standards final rule, effective October 1, 2026. No reporting requirements change yet — but the LEI is now the cross-agency entity identifier of record, and Phase 2 rulemakings that will change actual data submissions must be completed within two years. Here's what to track and do now.
Table of Contents
TL;DR:
- Nine federal agencies published the FDTA joint data standards final rule in June 2026 — effective October 1, 2026 — establishing seven common identifiers across all regulatory reporting.
- No reporting requirements change on October 1. The rule is the foundation; agency-specific rulemakings that will change actual data submissions must be completed within approximately two years.
- The Legal Entity Identifier (ISO 17442) is now the cross-agency entity identifier of record — institutions that don’t have LEIs should start the registration process now.
- The Phase 2 rulemaking clock is already running. Nine agencies will each initiate their own rulemakings to embed these standards into their reporting forms within the two-year window.
On June 11, 2026, nine federal financial regulatory agencies issued a joint final rule under the Financial Data Transparency Act of 2022. The rule becomes effective October 1, 2026. It establishes seven common data standards for regulatory reporting. And it changes exactly zero reporting requirements on October 1.
That apparent contradiction is the thing to understand. The FDTA joint rule is infrastructure — a framework agreement among nine agencies to use consistent identifiers when they eventually revise their reporting forms. The October 1 date is real and significant. The immediate compliance implications are smaller than the press releases suggest. The medium-term compliance implications are larger than most institutions have planned for.
Here’s what actually happened, and what you need to track.
What Is the Financial Data Transparency Act?
Congress enacted the Financial Data Transparency Act of 2022 in December of that year, embedded in the National Defense Authorization Act. The core mandate: nine federal financial regulatory agencies must develop and adopt joint data standards for regulatory reporting — standards that are non-proprietary, machine-readable, and based on open international standards rather than commercial identifiers.
The goal is interoperability. Today, financial institutions submit data to multiple agencies using different data structures, identifiers, and formats. The same legal entity might appear in OCC data under one identifier, CFPB data under another, and FDIC data under a third. Aggregating regulatory data across agencies — for systemic risk monitoring, cross-agency supervision, or research — requires expensive reconciliation work. The FDTA is designed to change that by establishing common identifiers that every agency’s reporting forms will eventually use.
“Eventually” is doing significant work in that sentence.
The Nine Agencies and the Seven Standards
The joint final rule was issued jointly by nine agencies:
| Agency | Abbreviation |
|---|---|
| Office of the Comptroller of the Currency | OCC |
| Federal Deposit Insurance Corporation | FDIC |
| Board of Governors of the Federal Reserve System | Federal Reserve |
| Consumer Financial Protection Bureau | CFPB |
| Securities and Exchange Commission | SEC |
| Federal Housing Finance Agency | FHFA |
| National Credit Union Administration | NCUA |
| Commodity Futures Trading Commission | CFTC |
| Department of the Treasury | Treasury |
If your institution reports to any of these nine agencies, the FDTA applies to your regulatory data.
The rule establishes seven common identifiers — all non-proprietary and available under open licenses:
| Standard | Category | What It Identifies |
|---|---|---|
| ISO 17442 | Legal entities | Legal Entity Identifier (LEI) — 20-character alphanumeric code |
| ISO 4914 | Financial products | Unique Product Identifier (UPI) — for swaps and security-based swaps |
| ISO 8601 | Dates | Standard date and time format |
| USPS state abbreviations | Geographic (U.S.) | Standard state, possession, and territory codes |
| GENC | Geographic (international) | Geopolitical Entities, Names, and Codes — countries and subdivisions |
| ISO 4217 | Currencies | Standard currency codes |
| ISO 10962 (CFI) | Financial instruments | Classification of Financial Instruments — instruments other than swaps |
The agencies explicitly excluded CUSIP, ISIN, and similar identifiers. Those are widely used in U.S. markets but licensed under commercial arrangements — which disqualifies them from the FDTA’s open-license requirement. The Global LEI Foundation’s LEI system and ISO’s instrument classification standards meet the open-license threshold.
What October 1 Actually Changes
The short answer: the framework is legally in place; your reports stay the same.
The joint rule’s plain language is unambiguous: “At the effective date, the joint rule will not change any reporting requirements without further action by the agencies.” Each agency must separately incorporate the seven standards into its specific reporting forms through individual rulemakings. That process — Phase 2 — hasn’t happened yet.
What changes on October 1, 2026:
- The joint data standards are formally adopted and legally in effect
- Agencies are now required to use these standards when revising reporting requirements
- The two-year Phase 2 clock is running (from publication date)
What does not change on October 1:
- Current regulatory reporting forms
- Current data submission formats and timelines
- Existing LEI requirements (status unchanged if you already have one)
- Any existing exemptions or reporting thresholds
If you expected October 1 to bring a new filing requirement or form change, it won’t. The rule is infrastructure, not immediate compliance action.
The LEI: The Standard With the Most Immediate Implications
Of the seven standards, ISO 17442 — the Legal Entity Identifier — has the broadest practical implications, and the most preparation work to do before Phase 2 arrives.
The LEI is a 20-character alphanumeric code that uniquely identifies a legal entity participating in financial transactions. It’s issued by organizations accredited by the Global LEI Foundation (GLEIF). In the U.S., primary LEI issuers include DTCC, Bloomberg, and the London Stock Exchange Group. LEIs are relatively inexpensive — issuance and annual renewal typically runs $65–130 per entity — but they require an identity verification process and annual renewal.
LEI adoption in U.S. financial markets has been uneven. Large banks have had LEIs for years — the CFTC mandated LEI use for derivatives counterparties under Dodd-Frank, and the SEC incorporated LEI requirements into certain broker-dealer and investment adviser filings. But community banks, credit unions, insurance companies, and many non-bank financial institutions have no LEI because they’ve never been required to obtain one.
That’s the gap the FDTA is designed to close. When the FDIC, OCC, and Federal Reserve begin Phase 2 rulemakings to embed LEI into call reports and bank holding company reports, institutions without LEIs will face a compliance gap on a compressed implementation timeline. Starting the LEI registration process now — before any Phase 2 NPRM hits — avoids that problem entirely.
The registration process involves submitting legal entity data to a GLEIF-accredited Local Operating Unit (LOU), which verifies the information and publishes it in the GLEIF Global LEI Repository, a public searchable database. Plan for a 2–4 week verification period for first-time filers. For holding company structures with multiple regulated subsidiaries, each subsidiary is a separate legal entity that may need its own LEI.
Phase 2: The Rulemaking Wave That Will Change Reporting
The FDTA statute requires each of the nine agencies to complete agency-specific rulemakings incorporating the joint data standards within two years of the joint rule’s publication — by approximately June 2028. That’s not a distant horizon, and the agencies won’t coordinate their timing with each other.
Each Phase 2 rulemaking follows the standard notice-and-comment process: proposed rule (NPRM), public comment period, final rule, implementation deadline. For a bank reporting to three or four of the nine agencies, that’s potentially three or four separate comment periods and implementation windows to manage simultaneously.
What to watch by agency:
Banking agencies (OCC, FDIC, Federal Reserve): Phase 2 will almost certainly include call report revisions (FFIEC 031/041/051 series) and bank holding company reports (FR Y-series). These are the highest-volume regulatory reports in U.S. banking. LEI adoption into call reports would represent the largest scope change in Phase 2, since call report requirements cover virtually every bank in the country.
CFPB: HMDA data and other consumer financial data collections are candidates for LEI integration. HMDA already collects entity-level data — LEI would replace or supplement current identifiers.
SEC: Broker-dealer, investment adviser, and fund reporting forms are likely Phase 2 targets. The SEC has already incorporated LEI into some filings; Phase 2 may expand that footprint.
NCUA: Call reports for credit unions (the 5300 series) are the primary Phase 2 target for NCUA-regulated institutions. Credit unions with no current LEI requirement should treat Phase 2 as the trigger event.
CFTC: Already heavily LEI-dependent through swap reporting under Dodd-Frank — Phase 2 is likely more incremental for CFTC-regulated entities that are already compliant.
FHFA and Treasury: Less visible in early FDTA commentary, but both are bound by the two-year deadline. Institutions with FHFA reporting obligations (mortgage servicers, GSE counterparties) should monitor FHFA’s rulemaking docket specifically.
What to Do Right Now
None of this requires emergency action this week. But it requires building Phase 2 monitoring into your compliance structure before the NPRMs start dropping — because once an NPRM is published, the implementation window compresses fast.
1. Inventory your LEI status. Map every legal entity in your organizational structure against its regulatory reporting obligations. Which entities have LEIs? Which don’t? For holding company structures, the entity count may surprise you. Identify gaps before a Phase 2 rulemaking requires you to close them on a 90-day clock.
2. Register for LEIs now if you don’t have them. The GLEIF website maintains the list of accredited LOUs. Initiate registration for any entity without an LEI that reports to any of the nine covered agencies. Plan for a multi-week verification process and annual renewal going forward. An entity that registers now has time; one that waits for an NPRM may not.
3. Assign Phase 2 ownership. Someone in your compliance or regulatory reporting function needs to own FDTA Phase 2 monitoring. That means subscriptions to each covered agency’s regulatory update feeds, a flag process for any NPRM referencing FDTA or data standards, and a system to route those NPRMs to both your comment team and your reporting systems team at the same time. Six months into a comment period is too late to assess technology implications.
4. Assess your data infrastructure. The seven standards include date formats (ISO 8601), currency codes (ISO 4217), geographic codes (GENC and USPS), and instrument classification (ISO 10962) — not just entity identifiers. Your reporting systems may already be partially compliant. Others, like ISO 10962 CFI codes for instrument classification, may require data enrichment work. A baseline assessment now prevents a systems sprint when Phase 2 final rules arrive with implementation deadlines.
5. Engage on proposed rules. The comment periods on Phase 2 NPRMs will be the point at which the practical compliance burden becomes visible. Trade associations and industry groups will file comments — coordinate through your primary trade association so your institution’s specific reporting complexities are reflected. Regulators do read comment letters, and Phase 2 implementation timelines are exactly the kind of thing that gets adjusted based on industry feedback.
So What?
The FDTA joint rule is not a compliance sprint. It’s the starting gun for a two-year rulemaking cycle that will eventually touch every regulatory report every financial institution files with the nine covered agencies. The October 1 effective date means the framework is legally adopted. The June 2028 Phase 2 deadline means individual reporting changes are coming — agency by agency, on a timeline no single institution controls.
The practical priorities are clear: get your LEI situation mapped and resolved now, before a Phase 2 NPRM arrives with a compressed implementation window. Assign someone to watch each covered agency’s rulemaking docket. And assess your regulatory data infrastructure — because the question Phase 2 NPRMs will ask is whether you can submit this data using ISO 17442, ISO 8601, and the rest of the seven standards — not whether you understand what those identifiers mean.
The institutions that will struggle in Phase 2 are the ones that treated October 1, 2026 as a non-event. The ones that won’t struggle are the ones that used the two-year window to close the LEI gap and build Phase 2 tracking into their compliance calendars before the NPRMs hit.
The Compliance Essentials Bundle includes a regulatory tracking calendar, exam preparation checklists, and compliance program templates mapped to major banking regulatory frameworks — so your team has the structure to manage multi-agency rulemakings like FDTA Phase 2 without building it from scratch.
Related Reading
- FDIC IT Examinations in 2026: What the End of URSIT and the New Single IT Rating Mean for Your Technology Risk Program
- OCC Bulletin 2026-13: What Changed from SR 11-7 and the 7-Item Update Checklist for Your MRM Program
- FTC Safeguards Rule in 2026: The 9-Element Security Program Every Non-Bank Financial Institution Now Has to Prove It Has
Sources:
- Joint Rule Establishing Data Standards under the Financial Data Transparency Act of 2022 — FDIC Financial Institution Letter (June 2026)
- Financial Data Transparency Act of 2022: Final Rule — OCC Bulletin 2026-25
- SEC Establishes Joint Data Standards as Required Under the Financial Data Transparency Act of 2022 — SEC Press Release (June 2026)
- FDTA Final Rule Fact Sheet — Data Foundation (June 2026)
- Federal Reserve Board announces final rule that establishes data standards for certain information collections (June 11, 2026)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the FDTA joint data standards final rule change my reporting requirements on October 1, 2026?
What is the Legal Entity Identifier (LEI) and do I need one?
Which agencies are covered by the FDTA joint rule?
Why was CUSIP excluded from the FDTA data standards?
What is Phase 2 of FDTA implementation and when does it happen?
Does the FDTA apply to community banks and credit unions, or just large institutions?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026