Feature Compliance Strategy
CFPB's July 2026 Regulatory Agenda: Five Things Compliance Teams Need to Act On Before Year-End
On July 6, the CFPB released its semiannual regulatory agenda — payday NPRM, Section 1033 do-over, mortgage servicing overhaul, and a 64% cut to nonbank exams. Here's what each item actually means and what compliance teams need to do before December.
Table of Contents
The CFPB’s 2026 regulatory agenda landed on July 6 and most compliance teams treated it like a press release. It isn’t. It’s a calendar — and it has H2 deadlines that will materially change what your compliance program needs to look like.
The Bureau described the release as a “surprisingly active rulemaking program” — and it is, particularly given how aggressively the administration has pulled back on examination activity. Sixty-four exams this year, down from 107 in 2024. Nonbank supervision cut by 64% in two years. And still: five significant rulemaking events anticipated between now and December.
Here’s what each item actually means for your program.
TL;DR
- CFPB released its semiannual regulatory agenda July 6, 2026, with multiple H2 rulemakings anticipated
- Payday lending NPRM (deregulatory) and Section 1033 open banking NPRM could both drop this month — neither eliminates current compliance obligations while they’re pending
- Mortgage servicing streamlining final rule anticipated August 2026: operational implications for servicers with loss mitigation programs and sub-servicer agreements
- FDTA joint data standards rule effective October 1 starts a two-year clock for agency-specific reporting changes
- CFPB exam count dropped to 64 total (42 banks, 22 nonbanks) — state AGs are filling the enforcement gap
1. The Payday Lending NPRM Is Coming — and Payday Lenders Shouldn’t Wait for It
The 2017 Payday, Vehicle Title, and Certain High-Cost Installment Loans rule has had a complicated history. Its ability-to-repay provisions were vacated before they ever took effect. What remains are the payment withdrawal restrictions and disclosure requirements most covered lenders have been navigating ever since.
The CFPB’s July 2026 agenda tees up an NPRM to reconsider those remaining provisions, including compliance dates. The rulemaking is formally designated as deregulatory under Executive Order 14192.
The practical problem: an NPRM is not a final rule. Comment period, analysis, and finalization will take months — at minimum — even in a streamlined rulemaking environment. Consumer advocates will challenge whatever deregulatory moves the Bureau makes. Court review is likely.
Covered lenders who freeze existing controls while waiting for relief that may not arrive until 2027 will have a compliance gap if an examiner shows up in the interim. Payment withdrawal restrictions and disclosures are still current law until a final rule says otherwise.
What to do now: Maintain existing controls. Assign someone to watch for the NPRM — when it publishes, the comment period matters. This is a genuine opportunity for industry input on specific requirements that have created operational friction. If your program has compliance burdens that the NPRM addresses, submit comments.
2. Section 1033 Gets a Do-Over — But Open Banking Infrastructure Should Stay
The November 2024 open banking final rule under Section 1033 was enjoined almost immediately by a federal court in the Eastern District of Kentucky. The CFPB has been in an unusual position since: it issued an ANPRM in August 2025 to reconsider the rule, and the July 2026 agenda confirms a proposed rule reconsidering the original final rule is anticipated this month.
The ANPRM flagged specific issues under reconsideration: who qualifies as a “representative” making data access requests on behalf of consumers; whether data providers can charge fees for responding to access requests; and data security requirements. A new NPRM will clarify all of these — but the core structure of consumer-permissioned data sharing isn’t being abandoned.
The risks of treating Section 1033 as off the table: state-level open banking requirements are expanding. Some large data providers have already built robust consumer data access programs. Banks and fintechs who dismantle Section 1033 infrastructure they’ve built may find themselves behind competitors and out of alignment with state requirements when a revised federal rule finalizes.
For background on what the original Section 1033 rule required and which institutions were in scope, see our earlier analysis of the original open banking compliance obligations.
What to do now: Track the NPRM when it publishes. Focus comments on the fee access structure and “representative” definition — these are the points most likely to affect your specific program. Don’t dismantle infrastructure built for Section 1033.
3. Mortgage Servicers: August Final Rule Has Operational Implications
The streamlined mortgage servicing final rule is the agenda item most likely to create concrete, near-term compliance obligations. Anticipated in August 2026, it completes a proposed rule issued in July 2024 and will overhaul the Regulation X loss mitigation procedures used for borrowers experiencing payment difficulties.
The July 2024 NPRM proposed replacing the current sequential loss mitigation waterfall — with its specific sequential steps, deadlines, and borrower notice requirements — with a more standardized streamlined process. The goal was reducing servicer complexity while ensuring borrowers get evaluated for available options. The final rule will specify exactly what the new process looks like, but the operational changes will be real and will require:
- Rewriting loss mitigation procedures and written policies
- Retraining loss mitigation staff on new evaluation sequences
- Updating consumer-facing disclosures and notices for affected borrowers
- Reviewing sub-servicer agreements where loss mitigation obligations flow down
For mortgage servicers already managing exam scrutiny, the August timeline is tight. CFPB examiners reviewing servicers after the rule takes effect will look for compliance with the new procedures, not the old ones.
What to do now: Pull the July 2024 NPRM now and do your preliminary impact assessment before the final rule publishes in August. Identify which of your procedures will change and which sub-servicer agreements need revision. Starting the assessment now versus after August publication buys four to six weeks of runway.
4. FDTA Data Standards: October 1 Starts a Two-Year Implementation Clock
The Financial Data Transparency Act joint data standards final rule was published June 25, 2026, and is effective October 1, 2026. Eight federal financial agencies jointly established seven common data identifiers — for entities, financial instruments, dates, geographic locations, and currencies — plus principles-based standards for data transmission formats.
The nuance most institutions are missing: the October effective date doesn’t change any existing reporting requirement. Agency-specific rulemakings implementing these standards in actual regulatory reporting forms must follow within two years of the June 25 publication. What October 1 does is start that clock.
The compliance implication is longer-term but material: within two years, agencies will begin updating their specific regulatory reporting requirements to align with these common standards. That means XBRL tagging conventions, identifier formats in call reports and other regulatory filings, and vendor data integrations will eventually need to conform. Institutions that wait for agency-specific rules to arrive before beginning scoping will find themselves with compressed implementation timelines.
What to do now: Brief your regulatory reporting and technology teams on the FDTA rule and its timeline. Begin inventorying which regulatory reporting workflows could be affected as agency-specific rules land. This is a two-year horizon — not an immediate action item — but the scoping work is worth starting now.
5. The Exam Reduction Isn’t the Story — What Replaced It Is
The headline number from the Bureau’s updated supervision posture is stark: 64 total exams planned for 2026 (42 banks, 22 nonbanks), down from 107 in 2024 (46 banks, 61 nonbanks). Nonbank examination is down 64% in two years.
Fintech compliance teams often read this as pressure relief. It isn’t — it’s a channel shift.
The May 2026 enforcement priorities that drove this change are narrow but real: actual harm with identifiable victims and measurable damages, FCRA/Regulation V data furnishing violations, FDCPA compliance, mortgage products, servicemember protections, and fraudulent overcharges. When the CFPB does examine a nonbank in 2026, it’s going directly to those areas.
And as we’ve covered in our state AG enforcement analysis, the federal pullback has directly amplified state attorney general activity. California, New York, Illinois, and Washington have all expanded consumer financial enforcement capabilities. The federal ceiling dropped; the state floor rose. For the details on how the CFPB’s enforcement principles shift changes risk calculations, see our June 2026 analysis.
What to do now: Don’t thin your compliance program because you’re unlikely to be examined. Redirect it toward areas that match current priorities: FCRA furnishing accuracy if you report to credit bureaus, FDCPA compliance if you have collections, mortgage and loss mitigation if you touch residential loans. Add state-level monitoring to your regulatory tracking if you haven’t already.
The Compliance Calendar You Need to Build
| Regulatory Event | Timing | Action Required |
|---|---|---|
| Payday lending NPRM | July 2026 (anticipated) | Monitor, prepare comment strategy |
| Section 1033 open banking NPRM | July 2026 (anticipated) | Monitor, maintain existing infrastructure |
| Mortgage servicing final rule | August 2026 (anticipated) | Begin operational impact assessment now |
| FDTA joint standards effective date | October 1, 2026 | Brief technology/reporting teams |
| Mortgage servicing implementation | After August effective date | Retrain staff, update procedures, revise vendor contracts |
| Agency-specific FDTA rules | Within 2 years of June 25, 2026 | Begin scoping regulatory reporting workflows |
So What?
The CFPB’s July 2026 regulatory agenda is the clearest signal yet about what H2 2026 looks like for consumer financial compliance. The Bureau is actively reconsidering requirements in some areas (payday, open banking) while pressing forward with concrete new obligations in others (mortgage servicing, FDTA). Examination activity is down but focused on specific harm categories.
The compliance teams that will struggle are the ones that read “the CFPB isn’t coming as hard” as permission to thin their programs. Current requirements stay in place until final rules say otherwise. The areas that remain priorities are actively supervised. State regulators are filling gaps the federal pullback created.
The teams that will be positioned well at year-end are the ones that mapped the agenda to their specific product lines, started the mortgage servicing operational assessment before August, and updated their regulatory tracking to include state-level enforcement.
If you’re rebuilding your H2 2026 compliance calendar or updating core compliance documentation ahead of these regulatory changes, the Compliance Essentials bundle gives you the policy and procedure templates to anchor your program while the rulemaking landscape evolves.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the CFPB's 2026 regulatory agenda?
When is the CFPB's payday lending NPRM expected and what will it change?
Does the Section 1033 NPRM mean open banking compliance is suspended?
What does the mortgage servicing final rule change and when does it take effect?
What does the FDTA joint data standards rule's October 2026 effective date actually mean for compliance teams?
How are CFPB exam priorities different for nonbanks versus banks in 2026?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026