Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

H2 2026 Compliance Deadline Calendar: The 8 Dates Financial Services Teams Need to Track Before Year-End

NACHA ACH Phase 2 just took effect. CFPB Reg B disparate impact changes hit July 21. EU AI Act transparency rules begin August 2. FFIEC CAMELS revision comments due August 17. Here's every material compliance deadline between now and December 2026 — and how to triage which ones need your attention first.

Table of Contents

TL;DR

  • NACHA ACH Phase 2 fraud monitoring became effective June 22, 2026 — every non-consumer originator, TPSP, and third-party sender is now in scope, no volume threshold
  • The CFPB’s Reg B final rule (effective July 21, 2026) removes ECOA’s disparate impact / effects test for the first time in 50 years — significant fair lending compliance implications before that date
  • EU AI Act transparency rules hit August 2, 2026; the FFIEC CAMELS revision comment window closes August 17 — both need compliance team attention before Labor Day
  • Colorado AI Act enforcement was pushed to January 1, 2027; CFPB Section 1071 single compliance date is January 1, 2028 — two major timeline shifts since Q1 that change your project plans

Halftime is over. If you spent Q1 and Q2 chasing Basel III Endgame re-proposals, FinCEN CDD changes, and OCC examination guidance, you’re not done — but you’re not starting from scratch either.

The second half of 2026 has a specific set of active compliance deadlines: some already in force, some hitting before Labor Day, some tracking into Q4. The problem isn’t that any one of them is catastrophically complex. The problem is that they’re arriving close enough together that compliance teams with full plates are at real risk of letting a material deadline slip through.

Here’s the H2 calendar with what’s verified, what moved, and where your attention belongs.

Two Major Timeline Shifts Since Q1

Before tracking what’s coming, note the two deadlines that changed since January:

Colorado AI Act enforcement pushed to January 1, 2027. Governor Polis signed SB 189 on May 14, 2026 — delaying the original June 30, 2026 effective date and significantly narrowing the law’s scope. The original SB 24-205 would have covered any AI system used in consequential decisions affecting Colorado consumers. SB 189 creates additional carve-outs and modifies deployer obligations. The full analysis of SB 189’s compliance program implications is here. For most financial institutions, the compliance work already in progress toward a June 30 deadline now has until January 1, 2027 — but that’s closer than it sounds if your program isn’t built.

CFPB Section 1071 compliance date moved to January 1, 2028. The CFPB’s May 2026 final rule eliminated the tiered compliance timeline entirely. Previously, Tier 1 lenders — those that originated at least 2,500 covered loans in the relevant lookback period — faced a data collection start date of July 1, 2026. That date is gone. The final rule establishes a single compliance date of January 1, 2028 for all covered financial institutions. The detailed breakdown of what changed in the 2026 final rule is here. Update your project plans accordingly.

Effective Now: NACHA ACH Phase 2

The NACHA ACH fraud monitoring rule became effective June 19, 2026 — with the first banking business day being Monday, June 22, 2026. If you’re reading this after that date, Phase 2 is already in force.

Phase 2’s defining change: it eliminates the origination volume threshold that had limited Phase 1 to high-volume players. The rule now covers every non-consumer originator, every Third-Party Service Provider (TPSP), every Third-Party Sender (TPS), and every RDFI — regardless of ACH volume. If your institution touches ACH and isn’t strictly a consumer originator, you’re in scope.

What the rule actually requires is risk-based processes and procedures “reasonably intended to identify ACH entries initiated due to fraud.” That standard is intentionally flexible, but it does require:

  • Written policies and procedures documenting your fraud monitoring approach
  • Threshold documentation — what triggers review, escalation, or returns
  • Defined scope — which entry categories and channels your monitoring covers
  • Owner assignment — who is responsible for the process and its maintenance

The most common gap at this stage: institutions that assumed Phase 2 would come with specific control mandates similar to Phase 1’s velocity and return-rate rules. It didn’t. The standard is documented risk-calibration, and “we use our core processor’s default settings” does not meet it without documentation of the risk decision behind that choice.

July 21, 2026: The Reg B Disparate Impact Overhaul

The CFPB’s final Reg B rule — published in the Federal Register on April 22, 2026 — is one of the most significant fair lending compliance developments in decades. It takes effect July 21, 2026.

The headline: for the first time since Regulation B’s original implementation roughly 50 years ago, the CFPB is removing ECOA’s disparate impact / effects test. The rule expressly eliminates the “effects test” from Reg B text and commentary, and affirms that ECOA does not authorize disparate-impact liability under the bureau’s current reading.

ChangePre-July 21Post-July 21
ECOA effects testReferenced in Reg B and official commentaryRemoved
Statistical disparity aloneCould establish ECOA violationInsufficient for ECOA violation
Intentional discrimination / proxy theoriesProhibitedStill prohibited
Discouragement prohibitionBroader scopeNarrowed
Special purpose credit programs (SPCPs)Existing standardsNew conditions and prohibitions

Three compliance caveats that matter before you update your program:

1. Intentional discrimination remains fully prohibited. The rule does not eliminate all disparate impact inquiry — it eliminates the theory that statistical disparity alone establishes an ECOA violation. Evidence of discriminatory intent, including through proxy use, is still actionable under both ECOA and Reg B.

2. State fair lending laws are untouched. California, New York, Illinois, and several other states have independent fair lending statutes that impose disparate impact liability. Institutions operating in those states remain subject to those standards regardless of the federal Reg B change.

3. The Fair Housing Act still imposes disparate impact liability for mortgage lending. The HUD disparate impact regulation was not amended. Mortgage lenders face ECOA changes under Reg B but still answer to FHA disparate impact standards.

The compliance program work before July 21: review your fair lending monitoring framework with legal counsel to determine what changes to analysis methodology and documentation are warranted. The biggest risk is not the rule itself — it’s representing to a bank partner or investor that your fair lending program is unchanged when a material legal standard shifted.

August 2, 2026: EU AI Act Transparency Rules

The EU AI Act’s Annex III high-risk AI system obligations were pushed to December 2027 — a 16-month delay from the originally scheduled August 2026 date. That headline often leads compliance teams to assume nothing is happening in August. That’s wrong.

What is taking effect August 2, 2026:

  • General Purpose AI (GPAI) transparency obligations under Article 53: Providers of GPAI models must publish technical documentation, maintain training data summaries, and comply with EU copyright law
  • AI system labeling requirements: AI-generated content in certain categories must be disclosed
  • Prohibited AI systems enforcement in earnest: The Article 5 prohibitions (social scoring, real-time biometric surveillance in public spaces, etc.) entered force February 2, 2026; enforcement mechanisms are fully operational from August 2026

For US-based financial institutions with EU customer exposure, the August 2 date matters primarily at the vendor layer. If your AI vendors are operating in the EU as GPAI model providers, they face new documentation and transparency requirements this quarter. That affects your due diligence obligations and vendor questionnaires.

The direct August 2 exposure for most US fintechs is limited, but the vendor chain implication is real.

August 17, 2026: FFIEC CAMELS Revision Comments Due

On May 19, 2026, the FFIEC proposed the first material revision to the Uniform Financial Institutions Rating System (UFIRS) in 30 years. The detailed breakdown of what’s proposed is here.

The comment deadline is August 17, 2026 — 90 days from the Federal Register publication. The proposal would:

  • Refocus CAMELS component and composite ratings on factors that materially affect financial condition and risk profile
  • Explicitly reduce the weight given to documentation, policies, and procedures in component ratings
  • Apply to all FDIC-supervised institutions, national banks, federal savings associations, and federally insured credit unions

This is not a compliance deadline in the traditional sense — the proposal isn’t finalized law. But it matters for two reasons:

It signals where examiner attention is heading. The proposal’s shift away from documentation-focused criteria and toward financially material factors is a preview of how examiners will calibrate their evaluations under the revised system. Understanding the direction helps you orient your exam preparation for the next 12-24 months.

The comment window is the influence opportunity. If your institution has experience with Management (M) component ratings, C or S component variability, or composite rating transitions that you believe reflected documentation gaps rather than actual financial risk, this is the appropriate forum. Industry comment in the 90-day window shapes the final rule.

October 1, 2026: FDTA Joint Data Standards Effective Date

The Financial Data Transparency Act joint data standards final rule takes effect October 1, 2026. Nine federal financial regulators — including the OCC, Federal Reserve, FDIC, SEC, CFPB, CFTC, FHFA, HUD, and NCUA — jointly designated the Legal Entity Identifier (LEI) as the cross-agency standard for entity identification. Full implementation details are here.

Important clarification: no new reporting requirements change on October 1. The October effective date establishes the LEI as the standard going forward; Phase 2 rulemakings that change what institutions actually report won’t be completed until 2028. The October date does not require any new data submissions.

The practical action for October 1 readiness: confirm that your institution has an active, maintained LEI. Obtaining a new LEI costs roughly $65-$130/year from a recognized GLEIF-accredited issuer. If your institution already has one, confirm it’s current and your legal entity name matches the registration. As regulators standardize entity identification, an outdated or missing LEI creates unnecessary friction.

The Triage Framework: Not All of These Are Equally Urgent

When everything is labeled urgent, nothing gets prioritized. A risk-based triage approach segments H2 deadlines into three categories:

Act Now — You’re Already Behind: NACHA ACH Phase 2 is effective. If you’re a non-consumer originator and your documentation isn’t in place, the gap is live. Prioritize this first: write the policy, document your monitoring thresholds, assign the owner.

Substantive Review Before the Effective Date: Reg B disparate impact changes July 21. This requires legal and compliance collaboration — you need to understand what changes to your fair lending program’s documentation, methodology, and communications are warranted before the effective date, not after.

Track and Monitor: EU AI Act transparency (assess vendor chain exposure), FFIEC CAMELS revision (review proposal, determine whether to comment by August 17), FDTA (confirm LEI status).

So What?

Two things most likely to produce “we didn’t realize that changed” moments in your next exam cycle: the Reg B disparate impact shift (because it runs counter to where compliance assumed fair lending regulation was going) and NACHA Phase 2 documentation (because “in force as of June 22” doesn’t feel as pressing as a November deadline on a calendar).

The most defensible posture for H2: map every open regulatory obligation against an assigned owner and a documented due date. If your issues management system is where you capture compliance remediation tasks, this is the moment to populate it for the next six months — with evidence fields ready for when the examiner asks how you tracked readiness.


The Issues Management Tracker & Template includes a regulatory tracking module built for exactly this: assigning owners to open obligations, setting due dates, capturing evidence of completion, and producing the documentation record that satisfies examiners when they ask how your compliance team managed the H2 regulatory pipeline.



Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is the Colorado AI Act compliance deadline still June 30, 2026?
No. Governor Polis signed SB 189 on May 14, 2026, delaying the effective date from June 30, 2026 to January 1, 2027 and significantly scaling back the law's scope. Financial institutions that built Colorado AI Act compliance programs under the original SB 24-205 framework should review SB 189's narrowed requirements, but the January 2027 deadline is the binding date now.
Does the CFPB Reg B disparate impact rule change mean our fair lending monitoring program is obsolete?
Not quite. The July 21, 2026 rule removes the ECOA effects test and eliminates federal disparate impact liability under Reg B — but intentional discrimination (including proxy theories) remains prohibited. More importantly, state fair lending laws remain fully in force, and the Fair Housing Act continues to impose disparate impact liability for mortgage lenders. Your monitoring outputs may have different legal weight, but running disparity analysis still reveals risk.
What does the NACHA ACH Phase 2 rule actually require?
Phase 2, effective June 22, 2026, requires all non-consumer originators, Third-Party Service Providers (TPSPs), Third-Party Senders (TPSs), and RDFIs to establish risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud. Unlike Phase 1, there's no volume threshold — the requirement applies regardless of ACH volume. The standard is documented, risk-calibrated monitoring, not a specific control set.
Does the CFPB Section 1071 rule still require Tier 1 lenders to start collecting data in July 2026?
No. The CFPB's May 2026 final rule replaced the tiered compliance timeline with a single compliance date: January 1, 2028. Previously, Tier 1 lenders (2,500+ small business loan originations) faced a July 2026 start. That date is gone. All covered institutions now have one deadline: January 1, 2028 for data collection to begin.
Should our institution submit comments on the FFIEC CAMELS revision proposal?
That depends on whether the proposed changes affect you materially. The proposal shifts CAMELS ratings to focus on factors that materially affect financial condition and risk profile, explicitly reducing the weight given to documentation and policies. If your institution has experienced Management (M) component ratings that you believe were disproportionately driven by documentation gaps rather than actual risk, the comment period — open through August 17, 2026 — is the right forum. Institutions with history under the current framework have credible standing to comment.
What does the FDTA data standards effective date in October 2026 actually require?
The Financial Data Transparency Act joint data standards final rule takes effect October 1, 2026. This establishes the LEI as the cross-agency entity identifier standard across nine federal regulators. But no new reporting submissions change on October 1 — Phase 2 rulemakings that will change actual data collection requirements won't be completed until 2028. The practical action for now: confirm your institution has an active LEI. Obtaining one is low-cost and avoids friction as agencies standardize entity identification.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.