Feature Compliance Strategy
The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program
On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.
Table of Contents
TL;DR
- On July 24, 2026, the House Financial Services Committee released a 70-page CFPB restructuring discussion draft — public comment due August 21, 2026
- Five titles: congressional appropriations, UDAAP clarity, innovation support, $21B supervisory threshold, and enforcement reforms — none of which take immediate legal effect
- The $21B threshold change would remove certain mid-size banks from direct CFPB supervision; it does not affect fintech or non-bank oversight, which operates under separate authority
- The compliance programs that survive any version of this reform will be the ones built around actual legal obligations — not the exam schedules of whoever happens to be running the CFPB this year
A 70-Page Draft, Five Titles, and a $21B Number Making Headlines
The House Financial Services Committee published a discussion draft proposing a structural overhaul of the CFPB on July 24, 2026, and opened a public comment period through August 21. The full 70-page text is available from the House.
The headline number is $21 billion — the proposed new threshold for “very large financial institution” supervisory status, up from the current $10 billion. Acting CFPB Director Vought has signaled support for the threshold change, telling Senate Banking Committee members this week that he backs the overhaul.
Before you decide how much this matters to your program, it’s worth being precise about what the draft actually proposes, what would be in scope and out of scope for each change, and what the realistic path to enactment looks like. The answer to the last question is: uncertain enough that no compliance team should be restructuring programs in response to a draft.
But the direction of travel it represents is worth understanding — because the structural pressure on CFPB authority has been building for two years, and some of these provisions have real compliance implications if they pass in any form.
What’s in the Five Titles
| Title | Core Proposal | Compliance Implication |
|---|---|---|
| I — Governance | Congressional appropriations; dedicated Inspector General | Budget uncertainty; exam frequency could vary with political cycles |
| II — UDAAP Clarity | Legal certainty on “abusive” standard; procedural safeguards for enforcement | Reduces rulemaking-by-enforcement risk; clarifies guidance vs. enforceable rules |
| III — Innovation Support | Clarity for small-dollar bank products; guidance/rule distinction | Mostly upstream — affects how future guidance is written |
| IV — Supervisory Threshold | $10B → $21B for “very large” bank supervision; prudential regulator election | Depository institutions between $10B–$21B could shift to prudential regulator exams |
| V — Enforcement | Reduces enforcement-as-policymaking; civil penalty improvements | Aligns with June 2026 Enforcement Principles already in effect |
Title I — Congressional Appropriations and Governance
Since 2011, the CFPB has drawn its budget from the Federal Reserve System — up to a statutory percentage of the Fed’s total operating expenses. This funding structure was designed specifically to insulate the Bureau from annual appropriations battles. The draft ends that arrangement.
Under congressional appropriations, the CFPB’s budget would compete with other agency priorities, become subject to continuing resolutions and government shutdowns, and potentially shrink or expand based on which party controls the House, Senate, and White House. A dedicated Inspector General (currently shared with the Fed) would also be established.
The operational implications: examination staffing, enforcement capacity, and rulemaking pace would all become more variable. Institutions under direct CFPB supervision could see examination frequency fluctuate with funding cycles. Institutions not under direct CFPB supervision would feel this less directly — but a less-resourced CFPB typically means more supervisory space for state regulators to operate.
Title II — UDAAP Clarity and Procedural Safeguards
This is the provision most compliance teams have been waiting for since 2021.
The draft provides “greater legal certainty” around UDAAP, specifically addressing the Bureau’s authority to define “abusive” practices. The “unfair” and “deceptive” standards have decades of case law and FTC guidance behind them. “Abusive” has largely been defined through CFPB enforcement actions rather than clear statutory criteria — meaning the compliance standard for any given conduct has depended substantially on who was running the Bureau.
The draft would require clearer rulemaking before conduct can be actionable as abusive. It also:
- Adds procedural safeguards for enforcement actions
- Clarifies statutes of limitations
- Addresses jurisdictional overlap with state regulators
- Requires agencies to explicitly distinguish non-binding guidance from legally enforceable requirements
That last point matters in practice. If you’ve built compliance program procedures around CFPB supervisory letters, FAQs, or informal guidance — which millions of financial institutions have — those aren’t legally enforceable rules. The draft would require the Bureau to say that explicitly. Whether that changes your practical compliance exposure depends on what state regulators and private plaintiffs do with the same underlying conduct.
Title IV — The $21B Supervisory Threshold
This is the provision generating the most attention and the most misunderstanding.
What it does: The current threshold for “very large financial institution” status — triggering direct CFPB supervisory authority over depository institutions — is $10 billion in assets. The draft would raise that to $21 billion. It also allows institutions to elect examination by their primary prudential regulator (OCC, Fed, FDIC) rather than the CFPB.
What it doesn’t do: It doesn’t affect non-bank supervision. The CFPB’s authority over non-bank entities — payday lenders, mortgage companies, student loan servicers, debt collectors, consumer reporting agencies, and (through larger-participant rulemaking) certain fintechs — operates through entirely separate statutory authority. That authority is not on the table in this draft.
If you’re a fintech without a bank charter, or a non-bank lender operating under CFPB’s non-bank supervision framework, the $21B threshold is essentially irrelevant to your direct regulatory exposure.
What Changes Today: Nothing
The CFPB reform discussion draft is a discussion draft. It carries no legal weight. The comment period through August 21 is an invitation for stakeholder input before any legislative process begins. From draft to enacted law, the steps include committee markup, House floor passage (including any floor amendments), Senate consideration and potential cloture, conference committee if House and Senate versions differ, and presidential signature.
Several of those steps have killed less controversial financial legislation. There’s no reason to treat this as imminent.
What your regulatory change log should say: Note received July 29, 2026. Comment period closes August 21. Monitor for committee markup and any reported text. No compliance program changes warranted at this stage.
What Won’t Change Even If Some Version Passes
State AGs Already Filled the Gap
When the CFPB pulled back in 2025, the enforcement gap didn’t stay empty. State attorneys general moved quickly: New York sued earned wage access providers. California’s DFPI expanded UDAAP enforcement authority under SB 825. New Jersey, Illinois, and Massachusetts issued consumer protection statements specifically targeting fintech products. The CFPB’s supervisory threshold affects federal exam authority — it doesn’t touch state enforcement power, which derives from entirely separate statutory authority.
If you’re a mid-size institution that might move out of direct CFPB supervision under the $21B threshold, your examination exposure shifts — it doesn’t disappear. It may become more diffuse and harder to predict, distributed across multiple state regulators rather than a single federal examiner.
Bank Partners Require Compliance Programs Regardless of CFPB Posture
If you operate as a fintech under a bank partnership, your sponsor bank’s third-party risk management requirements don’t relax when the CFPB’s posture changes. The bank is managing its own regulatory risk — OCC, Fed, FDIC, state banking department — and that risk includes your compliance posture. Bank partner oversight requirements are negotiated in your program agreement. Those requirements will reflect the bank’s regulatory exposure, not the CFPB’s enforcement calendar.
Private Litigation Sets the Floor
UDAAP clarity helps reduce regulator-versus-institution uncertainty. It doesn’t affect consumer class actions under state UDAP statutes, which largely parallel the unfair-and-deceptive standard without requiring CFPB action as a trigger. The largest consumer finance settlements in the past decade have often come through private litigation, not CFPB enforcement.
What the Discussion Draft Actually Tells You About Program Design
The most useful takeaway from this draft isn’t any specific provision — it’s the pattern it represents.
Since 2021, the CFPB has operated under at least three meaningfully different enforcement postures depending on administration. Programs optimized for any single posture have required significant rework each time the environment shifted. Programs built around actual legal obligations — statutory text, final rules, court-interpreted standards — have required far less adjustment.
The regulatory change implementation process that matters is the one that distinguishes between legal obligations (statute, final rule, court decision) and the CFPB’s current enforcement interpretation of those obligations. When you build procedures, you should know which category each control is responding to.
The CFPB’s June 2026 Enforcement Principles represent the current Bureau’s interpretation of when enforcement is appropriate. Those principles can shift with leadership. Your statutory obligations under TILA, ECOA, EFTA, and the FTC Act cannot.
So What?
The CFPB reform discussion draft is real, and if something close to its proposals eventually passes, institutions between $10B and $21B in assets may see their primary federal examination source shift. UDAAP clarity would reduce some legal ambiguity that has made compliance program design difficult. Congressional appropriations would introduce budget variability that affects the Bureau’s operational capacity.
But none of that happens before August 21 at the earliest — and realistically, not before late 2026 or 2027 if it happens at all.
What the discussion draft makes concrete is the argument for building compliance programs around legal obligations rather than CFPB enforcement risk. An institution whose procedures are based on statutory requirements doesn’t rewrite its program every time the CFPB shifts posture. It adds a note to its regulatory change log, monitors the legislative calendar, and updates only when something with legal effect is actually enacted.
If that describes your program, this week’s 70-page draft is a monitoring item. If it doesn’t, the path forward is the same regardless of what Congress does with CFPB reform.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the $21B supervisory threshold change apply to fintechs and non-bank lenders?
When could the CFPB reform discussion draft become law?
What does bringing the CFPB under congressional appropriations actually mean?
Does UDAAP clarity in the draft affect current or pending CFPB enforcement actions?
Should we update compliance policies based on the discussion draft?
How does the draft interact with the CFPB's June 2026 Enforcement Principles?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Keep reading
Related posts.
Compliance Strategy
Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven't Accounted For
When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don't address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.
Jul 30, 2026
Compliance Strategy
Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits
The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.
Jul 30, 2026
Compliance Strategy
The First 90 Days as a New Compliance Officer: Inventory Before You Rewrite
A compliance checklist template for your first 90 days: inventory obligations, issues, complaints, commitments, controls, access, and evidence first.
Jul 27, 2026