Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Trump's Fintech Executive Order: What the August and November 2026 Regulatory Deadlines Mean for Your Charter, Partnership, and Payment Strategy

The May 2026 executive order on fintech innovation set hard deadlines for every major federal financial regulator. The 90-day review window closes August 17. Here's what compliance teams at banks and fintechs need to track — and what won't change regardless of what regulators produce.

By Rebecca Leung · July 13, 2026 ·
Table of Contents

If you followed fintech regulatory news in May 2026, you saw the executive order. What you may not have done is mark your calendar.

On May 19, 2026, President Trump signed “Integrating Financial Technology Innovation Into Regulatory Frameworks” — an executive order directing nearly every major federal financial regulator to review its rules with a specific question: what’s blocking fintech firms from partnering with banks, obtaining charters, and accessing the federal payment system?

The EO set three hard deadlines. The first one — August 17, 2026 — is now less than five weeks away.

TL;DR

  • The May 19, 2026 executive order directed the CFPB, CFTC, FDIC, OCC, NCUA, and SEC to complete a regulatory review by August 17, 2026 targeting rules that impede fintech-bank partnerships and charter applications
  • The Federal Reserve was separately directed to evaluate payment account access for non-bank firms by September 17, 2026 — and has already proposed rules in response
  • The 180-day implementation deadline (November 15, 2026) is when regulatory change actually starts to materialize
  • AML, KYC, cybersecurity, and consumer protection obligations are explicitly preserved in the EO — this isn’t a deregulation of core compliance
  • Banks and fintechs should be mapping potential regulatory changes now, not waiting until November to adjust strategy

What the Executive Order Actually Says

The EO has three operational components, each with a different set of agencies and timelines.

The 90-Day Regulatory Review (Deadline: August 17, 2026)

Six agencies — the CFPB, CFTC, FDIC, OCC, NCUA, and SEC — were directed to review within 90 days:

  • Existing regulations, guidance documents, orders, no-action letters, and supervisory practices
  • Specifically, items that “unduly impede fintech firms from entering into partnerships with federally regulated institutions”
  • Whether regulations “could be amended to streamline application processes for eligible fintech firms seeking bank charters, credit union charters, deposit insurance”

Note who’s on the list and who’s not. The Federal Reserve is conspicuously excluded from the 90-day mandate — it has a separate and slightly longer timeline under the payment account component.

The agencies were also directed to evaluate whether uninsured depositories and non-bank financial companies can satisfy existing regulatory requirements to be treated comparably to insured depository institutions in certain contexts.

The 120-Day Federal Reserve Report (Deadline: September 17, 2026)

The Federal Reserve Board received a separate directive: within 120 days, submit a report to the President on:

  • Whether and how uninsured depositories and non-bank financial companies can obtain direct access to Federal Reserve payment accounts and services
  • If access is permitted under existing law, establish transparent application procedures and commit to deciding on complete applications within 90 days

This is the “Fed master account access” question that has been litigated and debated since Custodia Bank’s 2023 lawsuit against the Federal Reserve. The EO didn’t give a direct answer — it told the Fed to produce one.

The Federal Reserve didn’t wait for the September deadline. In June 2026, the FRB published a proposed rule establishing procedures for eligible non-bank financial companies to apply for payment account access. That proposed rule is the most concrete regulatory output from the EO so far.

The 180-Day Implementation Mandate (Deadline: November 15, 2026)

Within 180 days — November 15, 2026 — the leaders of each named regulatory agency must “work with [the White House] to implement the changes” identified in the 90-day review.

This is when regulatory change actually materializes: revised guidance documents, updated supervisory frameworks, streamlined charter application procedures, or formal rule amendments. What happens in August (the reports) determines what happens in November (the implementation).


Who the “Covered Firms” Are

The EO defines “covered firms” in a way that captures a specific subset of fintech and payments companies — not all non-banks:

Firm TypeCovered?
OCC-chartered national trust banks (digital asset custody)Yes
Payment stablecoin issuersYes
State-chartered special purpose depository institutions (WY SPDI, etc.)Yes
Non-bank payment processorsYes
Direct participants in real-time payment networksYes
Non-bank fintech companies engaged in digital assets or “novel activities”Yes
Traditional BNPL or EWA fintech lenders (no payment system participation)Depends on activities
Standard insured depository institutions (traditional banks)No — but affected indirectly

If you’re a stablecoin issuer navigating the GENIUS Act framework, a non-bank payment processor trying to access FedNow directly, or a digital asset firm that recently received (or applied for) an OCC national trust bank charter, the EO was written with your business model in mind.


What Banks Need to Track

Traditional banks are not directly regulated by the EO, but they’re affected by what happens next. The regulatory reviews will generate updated guidance on how banks can structure fintech partnerships — which affects your BaaS relationships, your third-party risk management framework, and your examination exposure.

Recent consent orders against Evolve Bank, Cross River, and Community Federal Savings Bank all centered on inadequate oversight of fintech partner activities. If the OCC and FDIC use the 90-day review to update fintech partnership guidance — clarifying what “adequate oversight” looks like — that guidance will matter for every bank with fintech relationships.

It also matters for vendor exit planning. If partner fintechs gain easier access to bank charters or Federal Reserve accounts, your current concentration risk picture may shift. Some partners may transition from needing a bank sponsor to operating independently. Your contingency planning should account for that possibility.


What Fintechs Need to Track

For fintech compliance teams, the EO creates a short-term question (track the August and November outputs) and a medium-term question (revise your regulatory strategy based on what actually changes).

Charter strategy. The OCC has been actively issuing national trust bank charters to digital asset firms — Circle’s final approval came July 10, and applications from Ripple, Paxos, Fidelity Digital Assets, Bridge (Stripe), and others are in process. If the 90-day review produces streamlined OCC charter application procedures, firms currently in the application queue should understand what changes and what doesn’t.

Payment account access. The Federal Reserve’s June 2026 proposed rule on payment account access is the most significant near-term development. If finalized in something close to its proposed form, it creates a pathway for stablecoin issuers and non-bank payment processors to access Federal Reserve payment services directly — eliminating some of the structural dependence on bank partnerships. Track the Federal Reserve’s proposed rule and its comment period.

Bank partnership compliance. The CFPB, OCC, and FDIC reviews may produce updated guidance on how bank-fintech partnerships must be structured — which supervisory expectations apply, what documentation banks must maintain, what fintechs must provide to their bank partners. Your current bank partnership compliance posture should be audited against whatever guidance emerges.

New product launches. Fintechs launching new products in a shifting regulatory environment need structured risk assessments before go-live — not after an examiner asks why you didn’t have one. The timing of the EO implementation (November 2026) coincides with many 2027 product launch timelines.


What Won’t Change: Core Compliance Is Non-Negotiable

The executive order is explicit. Section 5 directs agencies to balance innovation with “safety, consumer and investor protection, market integrity, financial stability and oversight.” The EO specifically calls out:

  • Anti-money laundering (AML) compliance
  • Know Your Customer (KYC) requirements
  • Cybersecurity controls
  • Consumer protection obligations

This isn’t window dressing. The agencies interpreting and implementing the EO will not create pathways that eliminate these requirements — the political and legal exposure would be too high. Consumer advocacy organizations have already filed comments warning against weakening UDAAP, fair lending, and data protection standards.

What the EO might streamline: application processes, duplicative reporting requirements across agencies, and guidance that reflects 2014 risk management frameworks applied to 2026 business models. What it won’t touch: your BSA/AML program, your cybersecurity controls, or your consumer protection compliance.

For state enforcement, the calculus is similar. State AGs and state financial regulators have their own mandates that don’t track federal EOs. State enforcement of fintech compliance obligations has been accelerating in 2026 regardless of the federal deregulatory posture — that dynamic continues.


So What? The Compliance Calendar Through November 2026

The action items aren’t complex, but they require deliberate tracking:

Now through August 17: Map the specific regulations, guidance documents, and supervisory practices that create friction in your business model. If you have relationships with bank partners, identify which elements of those relationships are governed by guidance that the OCC, FDIC, or CFPB reviews could affect. Document your current regulatory dependencies — charter status, payment system access, key guidance you rely on.

August 17: Read the reports. Each named agency must publish its review findings. These reports will signal what actually changes in November and what doesn’t. For fintechs with pending charter applications, the OCC report will matter most. For payment companies, the CFPB and OCC reports on partnership guidance matter most.

September 17: The Federal Reserve’s payment account access report is due. Combined with the June 2026 proposed rule, this will clarify whether direct Fed account access is a realistic option for your business category and on what timeline.

November 15: Implementation deadline. Some changes will be immediate (updated guidance, streamlined application procedures). Others will require formal rulemaking with comment periods extending into 2027. Track which is which — rulemaking changes aren’t effective until finalized.

For OCC-chartered stablecoin issuers and firms pursuing the GENIUS Act PPSI pathway, the EO creates a potential acceleration of the federal charter process that matters for January 2027 deadline planning. But “potential” isn’t “certain” — the August reports will tell you more.


External Resources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the Trump fintech executive order actually direct regulators to do?
The May 19, 2026 executive order — titled 'Integrating Financial Technology Innovation Into Regulatory Frameworks' — directed the CFPB, CFTC, FDIC, OCC, NCUA, and SEC (but notably not the Federal Reserve) to review existing regulations, guidance, orders, no-action letters, and supervisory practices within 90 days. The specific focus: identify rules that impede fintech-bank partnerships, and assess whether bank and credit union charter application processes can be streamlined for eligible fintech firms. The Federal Reserve received a separate 120-day mandate to evaluate whether non-bank firms can access Federal Reserve payment accounts and services.
What are the actual deadlines from the executive order?
Three key dates: August 17, 2026 (90 days from the May 19 signing) — the six named regulators must complete their review and identify regulations to update or eliminate. September 17, 2026 (120 days) — the Federal Reserve must submit its report on payment account access options and recommendations. November 15, 2026 (180 days) — each regulator must work with the White House to implement changes identified in the 90-day review. The EO's comment period was open through July 27, 2026.
Which fintech firms does the executive order target — who are 'covered firms'?
The EO defines 'covered firms' broadly: uninsured depository institutions (like OCC-chartered national trust banks), non-bank financial companies engaged in digital asset activities and other novel activities, direct participants in real-time payment networks, payment stablecoin issuers, and non-bank payment processors. State-chartered special purpose depository institutions (like Wyoming SPDI banks) are explicitly captured. Traditional fintech lenders, EWA providers, and BNPL platforms are covered depending on their activities.
What does the executive order say about AML, KYC, and consumer protection compliance?
The EO explicitly preserves core compliance obligations. It directs regulators to balance innovation with 'safety, consumer and investor protection, market integrity, financial stability and oversight.' AML, KYC, cybersecurity, and consumer protection are called out as areas that will continue to require strong controls even in an innovation-friendly environment. This is not a compliance holiday — it's a regulatory posture review with core obligations intact.
What has actually happened since the executive order was signed?
The Federal Reserve moved quickly: in June 2026, the FRB published a proposed rule establishing procedures for non-bank financial companies to apply for Federal Reserve payment accounts and services — the most concrete regulatory response to the EO to date. The OCC has signaled it is reviewing its fintech charter application processes as part of the 90-day review. Multiple agencies have opened comment periods on fintech-specific guidance updates. The August and November deadlines will determine what actually changes.
Should banks and fintechs be changing their compliance programs now in response to the executive order?
Not yet — wait for the agency reports due August 17 before modifying programs. What you should do now: map which regulations the EO review could affect for your business model, identify where current guidance creates friction in your bank partnership or charter strategy, and prepare to engage in any comment periods that open as agencies implement changes. Do not reduce AML, KYC, or cybersecurity controls in anticipation of relaxed guidance — the EO is explicit that these remain non-negotiable.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

New Product Risk Assessment

Structured risk review process for new products, services, and business initiatives.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.