Feature Compliance Strategy
Trump's Fintech Executive Order: What the August and November 2026 Regulatory Deadlines Mean for Your Charter, Partnership, and Payment Strategy
The May 2026 executive order on fintech innovation set hard deadlines for every major federal financial regulator. The 90-day review window closes August 17. Here's what compliance teams at banks and fintechs need to track — and what won't change regardless of what regulators produce.
Table of Contents
If you followed fintech regulatory news in May 2026, you saw the executive order. What you may not have done is mark your calendar.
On May 19, 2026, President Trump signed “Integrating Financial Technology Innovation Into Regulatory Frameworks” — an executive order directing nearly every major federal financial regulator to review its rules with a specific question: what’s blocking fintech firms from partnering with banks, obtaining charters, and accessing the federal payment system?
The EO set three hard deadlines. The first one — August 17, 2026 — is now less than five weeks away.
TL;DR
- The May 19, 2026 executive order directed the CFPB, CFTC, FDIC, OCC, NCUA, and SEC to complete a regulatory review by August 17, 2026 targeting rules that impede fintech-bank partnerships and charter applications
- The Federal Reserve was separately directed to evaluate payment account access for non-bank firms by September 17, 2026 — and has already proposed rules in response
- The 180-day implementation deadline (November 15, 2026) is when regulatory change actually starts to materialize
- AML, KYC, cybersecurity, and consumer protection obligations are explicitly preserved in the EO — this isn’t a deregulation of core compliance
- Banks and fintechs should be mapping potential regulatory changes now, not waiting until November to adjust strategy
What the Executive Order Actually Says
The EO has three operational components, each with a different set of agencies and timelines.
The 90-Day Regulatory Review (Deadline: August 17, 2026)
Six agencies — the CFPB, CFTC, FDIC, OCC, NCUA, and SEC — were directed to review within 90 days:
- Existing regulations, guidance documents, orders, no-action letters, and supervisory practices
- Specifically, items that “unduly impede fintech firms from entering into partnerships with federally regulated institutions”
- Whether regulations “could be amended to streamline application processes for eligible fintech firms seeking bank charters, credit union charters, deposit insurance”
Note who’s on the list and who’s not. The Federal Reserve is conspicuously excluded from the 90-day mandate — it has a separate and slightly longer timeline under the payment account component.
The agencies were also directed to evaluate whether uninsured depositories and non-bank financial companies can satisfy existing regulatory requirements to be treated comparably to insured depository institutions in certain contexts.
The 120-Day Federal Reserve Report (Deadline: September 17, 2026)
The Federal Reserve Board received a separate directive: within 120 days, submit a report to the President on:
- Whether and how uninsured depositories and non-bank financial companies can obtain direct access to Federal Reserve payment accounts and services
- If access is permitted under existing law, establish transparent application procedures and commit to deciding on complete applications within 90 days
This is the “Fed master account access” question that has been litigated and debated since Custodia Bank’s 2023 lawsuit against the Federal Reserve. The EO didn’t give a direct answer — it told the Fed to produce one.
The Federal Reserve didn’t wait for the September deadline. In June 2026, the FRB published a proposed rule establishing procedures for eligible non-bank financial companies to apply for payment account access. That proposed rule is the most concrete regulatory output from the EO so far.
The 180-Day Implementation Mandate (Deadline: November 15, 2026)
Within 180 days — November 15, 2026 — the leaders of each named regulatory agency must “work with [the White House] to implement the changes” identified in the 90-day review.
This is when regulatory change actually materializes: revised guidance documents, updated supervisory frameworks, streamlined charter application procedures, or formal rule amendments. What happens in August (the reports) determines what happens in November (the implementation).
Who the “Covered Firms” Are
The EO defines “covered firms” in a way that captures a specific subset of fintech and payments companies — not all non-banks:
| Firm Type | Covered? |
|---|---|
| OCC-chartered national trust banks (digital asset custody) | Yes |
| Payment stablecoin issuers | Yes |
| State-chartered special purpose depository institutions (WY SPDI, etc.) | Yes |
| Non-bank payment processors | Yes |
| Direct participants in real-time payment networks | Yes |
| Non-bank fintech companies engaged in digital assets or “novel activities” | Yes |
| Traditional BNPL or EWA fintech lenders (no payment system participation) | Depends on activities |
| Standard insured depository institutions (traditional banks) | No — but affected indirectly |
If you’re a stablecoin issuer navigating the GENIUS Act framework, a non-bank payment processor trying to access FedNow directly, or a digital asset firm that recently received (or applied for) an OCC national trust bank charter, the EO was written with your business model in mind.
What Banks Need to Track
Traditional banks are not directly regulated by the EO, but they’re affected by what happens next. The regulatory reviews will generate updated guidance on how banks can structure fintech partnerships — which affects your BaaS relationships, your third-party risk management framework, and your examination exposure.
Recent consent orders against Evolve Bank, Cross River, and Community Federal Savings Bank all centered on inadequate oversight of fintech partner activities. If the OCC and FDIC use the 90-day review to update fintech partnership guidance — clarifying what “adequate oversight” looks like — that guidance will matter for every bank with fintech relationships.
It also matters for vendor exit planning. If partner fintechs gain easier access to bank charters or Federal Reserve accounts, your current concentration risk picture may shift. Some partners may transition from needing a bank sponsor to operating independently. Your contingency planning should account for that possibility.
What Fintechs Need to Track
For fintech compliance teams, the EO creates a short-term question (track the August and November outputs) and a medium-term question (revise your regulatory strategy based on what actually changes).
Charter strategy. The OCC has been actively issuing national trust bank charters to digital asset firms — Circle’s final approval came July 10, and applications from Ripple, Paxos, Fidelity Digital Assets, Bridge (Stripe), and others are in process. If the 90-day review produces streamlined OCC charter application procedures, firms currently in the application queue should understand what changes and what doesn’t.
Payment account access. The Federal Reserve’s June 2026 proposed rule on payment account access is the most significant near-term development. If finalized in something close to its proposed form, it creates a pathway for stablecoin issuers and non-bank payment processors to access Federal Reserve payment services directly — eliminating some of the structural dependence on bank partnerships. Track the Federal Reserve’s proposed rule and its comment period.
Bank partnership compliance. The CFPB, OCC, and FDIC reviews may produce updated guidance on how bank-fintech partnerships must be structured — which supervisory expectations apply, what documentation banks must maintain, what fintechs must provide to their bank partners. Your current bank partnership compliance posture should be audited against whatever guidance emerges.
New product launches. Fintechs launching new products in a shifting regulatory environment need structured risk assessments before go-live — not after an examiner asks why you didn’t have one. The timing of the EO implementation (November 2026) coincides with many 2027 product launch timelines.
What Won’t Change: Core Compliance Is Non-Negotiable
The executive order is explicit. Section 5 directs agencies to balance innovation with “safety, consumer and investor protection, market integrity, financial stability and oversight.” The EO specifically calls out:
- Anti-money laundering (AML) compliance
- Know Your Customer (KYC) requirements
- Cybersecurity controls
- Consumer protection obligations
This isn’t window dressing. The agencies interpreting and implementing the EO will not create pathways that eliminate these requirements — the political and legal exposure would be too high. Consumer advocacy organizations have already filed comments warning against weakening UDAAP, fair lending, and data protection standards.
What the EO might streamline: application processes, duplicative reporting requirements across agencies, and guidance that reflects 2014 risk management frameworks applied to 2026 business models. What it won’t touch: your BSA/AML program, your cybersecurity controls, or your consumer protection compliance.
For state enforcement, the calculus is similar. State AGs and state financial regulators have their own mandates that don’t track federal EOs. State enforcement of fintech compliance obligations has been accelerating in 2026 regardless of the federal deregulatory posture — that dynamic continues.
So What? The Compliance Calendar Through November 2026
The action items aren’t complex, but they require deliberate tracking:
Now through August 17: Map the specific regulations, guidance documents, and supervisory practices that create friction in your business model. If you have relationships with bank partners, identify which elements of those relationships are governed by guidance that the OCC, FDIC, or CFPB reviews could affect. Document your current regulatory dependencies — charter status, payment system access, key guidance you rely on.
August 17: Read the reports. Each named agency must publish its review findings. These reports will signal what actually changes in November and what doesn’t. For fintechs with pending charter applications, the OCC report will matter most. For payment companies, the CFPB and OCC reports on partnership guidance matter most.
September 17: The Federal Reserve’s payment account access report is due. Combined with the June 2026 proposed rule, this will clarify whether direct Fed account access is a realistic option for your business category and on what timeline.
November 15: Implementation deadline. Some changes will be immediate (updated guidance, streamlined application procedures). Others will require formal rulemaking with comment periods extending into 2027. Track which is which — rulemaking changes aren’t effective until finalized.
For OCC-chartered stablecoin issuers and firms pursuing the GENIUS Act PPSI pathway, the EO creates a potential acceleration of the federal charter process that matters for January 2027 deadline planning. But “potential” isn’t “certain” — the August reports will tell you more.
External Resources
- White House Executive Order (May 19, 2026) — Full Text
- White House Fact Sheet — Key Provisions of the Fintech EO
- Sullivan & Cromwell — Executive Order on Fintech Innovation and Federal Reserve Payment Accounts
- Consumer Finance Monitor — Executive Order Signals Major Shift in Federal Policy
- Norton Rose Fulbright — Trump Executive Order Directs Federal Regulators to Open Doors for FinTech
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the Trump fintech executive order actually direct regulators to do?
What are the actual deadlines from the executive order?
Which fintech firms does the executive order target — who are 'covered firms'?
What does the executive order say about AML, KYC, and consumer protection compliance?
What has actually happened since the executive order was signed?
Should banks and fintechs be changing their compliance programs now in response to the executive order?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026