Feature Compliance Strategy
After the CFPB Stepped Back: Who's Supervising Your Fintech in 2026 — and What They're Actually Looking For
The CFPB's 2025 enforcement pullback didn't reduce regulatory risk for fintechs — it redistributed it. New York sued EWA providers. California expanded DFPI UDAAP authority. New Jersey issued a junk fees enforcement statement. Here's the new enforcement map and what your compliance program needs to address.
Table of Contents
The CFPB’s enforcement pullback in 2025 wasn’t a reprieve for fintechs. It was a handoff.
And the state attorneys general who caught the baton are, in many cases, more aggressive, better coordinated, and more specifically focused on fintech products than the federal bureau they replaced. If your compliance program was built around CFPB supervision as the primary risk and state enforcement as a secondary concern, that model is now backwards.
TL;DR
- The CFPB withdrew its repeat offender registry (October 2025) and BNPL interpretive rule (May 2025), but state AGs filled the gap aggressively and immediately
- New York AG sued DailyPay and MoneyLion over EWA; a multistate coalition led by Connecticut and North Carolina is investigating BNPL providers
- Rohit Chopra — the CFPB director who pioneered junk fee enforcement — is now running California’s new consumer protection agency
- California SB 825, effective January 1, 2026, extended DFPI UDAAP authority to previously exempt licensees including finance lenders and investment advisers
What the CFPB Actually Pulled Back
Let’s start with what actually happened, because some of the coverage has conflated “CFPB pulled back” with “no more risk.” That’s not what occurred.
Repeat offender registry — rescinded. The CFPB had finalized a rule in 2024 requiring nonbank financial companies subject to government enforcement orders to register those orders with the bureau. In April 2025, the CFPB announced it would not prioritize enforcement for missed registration deadlines. On October 29, 2025, the bureau formally withdrew the rule, citing compliance costs and lack of quantifiable consumer benefit.
BNPL interpretive rule — rescinded. The CFPB had issued a 2024 interpretive rule classifying BNPL products as credit cards under Regulation Z — triggering chargeback protections, periodic statement requirements, and billing dispute procedures. The bureau withdrew that rule in May 2025.
EWA guidance — reversed. In December 2025, the CFPB published an advisory opinion stating that qualifying earned wage access services are not “credit” under the Truth in Lending Act and Regulation Z. This reversed the CFPB’s prior position.
Nonbank supervision — deprioritized. The bureau has significantly reduced examination activity for nonbank financial companies, including fintechs, mortgage servicers, and debt collectors.
None of this means the CFPB ceased to exist. The agency retains enforcement authority and could shift priorities under a future director. But for most fintechs operating today, the practical reality is that state regulators are now your primary supervisors.
Who Filled the Gap
New York: AG Enforcement and New Legislation
New York moved fastest and most aggressively. In April 2025, AG Letitia James sued DailyPay and MoneyLion, asserting that their EWA products operate as illegal payday lenders under New York’s criminal usury law. The suits allege that fees and “tips” charged on early wage access advances constitute interest that exceeds New York’s 25 percent criminal usury cap when annualized.
This enforcement theory directly contradicts the CFPB’s December 2025 position that qualifying EWA products aren’t loans at all. The conflict isn’t theoretical — DailyPay and MoneyLion were complying with what they understood to be the federal framework. State enforcement said that wasn’t enough.
New York also enacted legislation in 2025 treating BNPL arrangements as loans under state law — requiring providers to obtain state licenses, make TILA-like disclosures about terms, comply with UDAAP standards, and provide consumer data protections. The law effectively fills the regulatory gap created by the CFPB’s BNPL rule withdrawal.
California: DFPI Expansion and Rohit Chopra
California’s enforcement trajectory is more significant than any single enforcement action.
SB 825 — enacted October 2025, effective January 1, 2026 — amended California’s Consumer Financial Protection Law to extend DFPI’s UDAAP enforcement authority to categories previously exempt from those provisions: licensed finance lenders, escrow agents, residential mortgage lenders, broker-dealers, and investment advisers. If you’re California-licensed and historically excluded CCFPL UDAAP analysis from your compliance program, that exclusion expired at the start of this year.
California DFPI EWA regulations, effective February 15, 2025, require direct-to-consumer EWA providers to register with DFPI, comply with supervision and reporting requirements, and file annual reports. First annual reports were due March 15, 2026.
The Rohit Chopra appointment is the most consequential development. Chopra — who served as CFPB Director from 2021 until being fired in February 2025 — was appointed by Governor Gavin Newsom in May 2026 to lead California’s new Business and Consumer Services Agency. Chopra is the person who built the CFPB’s junk fee enforcement campaign, pioneered aggressive nonbank supervision, and expanded CFPB authority over medical debt, credit reporting, and digital payments. Those priorities are now California’s. That’s not speculation — it’s the resume of the person running the agency.
DFPI enforcement in 2025 included a $1 million penalty against Apoyo Financiero for allegedly charging excessive interest and fees, and a $2.3 million settlement with Caliber Home Loans for overcharging California borrowers. These weren’t massive enforcement actions, but they established the enforcement pattern before the SB 825 expansion.
New Jersey: Junk Fees
In June 2026, the New Jersey AG issued a sweeping enforcement statement targeting “junk fees” — broadly defined to include undisclosed or insufficiently disclosed fees in consumer financial products. Legal commentators flagged the NJ statement as potentially serving as a roadmap for multistate enforcement efforts, given New Jersey’s history of coordinating with other state AGs.
The “junk fee” framing covers a wide range of fintech revenue practices: convenience fees, expedited processing fees, subscription fees that don’t clearly disclose auto-renewal, and late fees that exceed actual loss. If your fee disclosures were designed around CFPB’s junk fee guidance (which has been substantially deprioritized federally), review them against state UDAAP and consumer protection law standards.
The Multistate Coalition
Connecticut and North Carolina AGs are leading a multistate coalition that has sent information requests to BNPL providers — essentially the precursor to enforcement action. Multistate AG coalitions are a deliberate enforcement amplification strategy: by coordinating jurisdiction, they can pursue larger settlements, broader injunctive relief, and more expensive corrective action than any single state could demand alone.
The coalition structure also means that a BNPL enforcement action in Connecticut has precedential weight in North Carolina, New York, California, and any other state whose AG has joined the inquiry. Your BNPL compliance documentation needs to hold up in all of those states, not just the one where you’re headquartered.
The Products Being Targeted
| Product | Federal Status (2026) | State Enforcement Status |
|---|---|---|
| Earned Wage Access | CFPB: not credit under TILA (Dec 2025 advisory opinion) | NY AG: suing DailyPay, MoneyLion as illegal payday lenders; CA: registration required since Feb 2025 |
| BNPL | CFPB: interpretive rule rescinded (May 2025) | NY: new legislation treats BNPL as loans; CT/NC: multistate coalition investigation |
| Junk Fees | CFPB: enforcement deprioritized | NJ: sweeping enforcement statement (June 2026); CA: DFPI authority expanded under SB 825 |
| Fintech Lending | CFPB: reduced nonbank supervision | CA: DFPI SB 825 expands UDAAP reach to licensed finance lenders |
The pattern is consistent: where federal guidance pulled back, state law moved in to fill the definition gap. Products designed for federal compliance aren’t automatically state-compliant.
The “CFPB Diaspora” — Why State Enforcement Is Getting More Sophisticated
One underappreciated consequence of the CFPB pullback is where the talent went. States actively recruited former CFPB staff — people who built the bureau’s exam and enforcement infrastructure.
New York hired Gabriel O’Malley, a former CFPB deputy enforcement director, and Chris D’Angelo, who served as chief of staff under former CFPB Director Richard Cordray, as New York’s chief deputy attorney general for economic justice.
These aren’t people who have to learn fintech enforcement from scratch. They built the playbook. When they show up at your door with a state AG civil investigative demand, they know exactly what documentation to ask for, what documentation should exist but doesn’t, and how to build a consumer harm case from transaction data.
What This Means for Your Compliance Program
The structural shift requires several practical adjustments:
Remap your regulatory universe by state. If your compliance program maps obligations to federal law and assumes federal regulators are the primary enforcement risk, that map is outdated. Run a state-by-state analysis: where do you operate, what licenses do you hold, what state consumer protection laws apply, and which state regulators have jurisdiction over your products?
Review your EWA and BNPL product terms against state usury laws. The federal/state conflict on EWA is real and active. A product structured to comply with the CFPB’s December 2025 advisory opinion may still violate New York’s criminal usury cap when fees are annualized as interest. Get outside counsel who practice in your operating states to review this specifically.
Audit your fee disclosures for junk fee exposure. The NJ enforcement statement and DFPI’s expanded authority mean you need disclosures that would survive UDAAP scrutiny in multiple states simultaneously. “Convenience fee,” “processing fee,” and “subscription fee” aren’t self-explanatory to regulators enforcing state UDAAP standards — each needs a disclosure that makes the amount, timing, and purpose clear before the transaction.
Run a new product risk assessment before launching fintech products in 2026. The EWA and BNPL enforcement actions share a common pattern: products launched under one regulatory framework (federal) that got caught by a different one (state). A structured new product risk assessment — including state law analysis as a required component — closes that gap before launch, not after an AG civil investigative demand arrives.
Update your TPRM program for state-level vendor oversight requirements. California’s DFPI and New York’s DFS both have vendor oversight expectations built into their licensing and examination frameworks. If your vendor oversight program is calibrated only for federal TPRM guidance (OCC 2023-17, FFIEC), you may be missing state-specific requirements in your largest operating states. See what OCC examiners actually test in vendor exit plan reviews as a baseline — state requirements often parallel and exceed federal guidance.
So What?
The CFPB pullback made national news. The state enforcement response has been quieter, more specific, and more dangerous for fintechs that missed the shift.
New York and California together represent roughly a third of U.S. fintech customers. Both states now have aggressive, experienced enforcement teams focused specifically on the products — EWA, BNPL, embedded lending, junk fees — that fintechs built. The multistate coalition structure means enforcement activity in one state creates legal exposure in others.
The compliance programs built to satisfy CFPB examiners need to be updated for a different enforcement reality: one where state AGs are the first call you get, and they arrive prepared.
The practical floor for compliance in 2026 is understanding, on a state-by-state basis, what your product looks like under state consumer protection law — not just federal guidance that may have already been rescinded.
For two state-specific examples of how compliance programs need to adapt to new state law requirements, see what Connecticut’s expanded CDPA means for fintech data handling and what FDIC examiners flagged in 1,155 consumer compliance violations in 2025.
Sources:
- Morgan Lewis — State Attorneys General Step Up Consumer Financial Services Enforcement
- Skadden — Consumer Financial Enforcement: States to Watch in 2026
- Consumer Finance Blog — CFPB Withdraws Repeat Offender and Form Contract Registry Proposals
- Forbes — Rohit Chopra Takes Over California’s New Consumer Protection Agency
- American Banker — As CFPB Retreats, State AGs and Bank Regulators Step Up
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Did the CFPB actually stop enforcing consumer protection laws against fintechs?
What enforcement actions have state AGs taken against fintechs in 2025–2026?
What is California SB 825 and who does it affect?
What does the multistate EWA and BNPL enforcement mean for product compliance?
Who is Rohit Chopra and why does his California role matter for fintech compliance?
Does the CFPB's withdrawal of the repeat offender registry mean I no longer need to worry about a prior enforcement action?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026