Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Compliance Strategy

The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program

On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.

By Rebecca Leung · July 28, 2026 ·
Table of Contents

TL;DR

  • On July 24, 2026, the House Financial Services Committee released a 70-page CFPB restructuring discussion draft — public comment due August 21, 2026
  • Five titles: congressional appropriations, UDAAP clarity, innovation support, $21B supervisory threshold, and enforcement reforms — none of which take immediate legal effect
  • The $21B threshold change would remove certain mid-size banks from direct CFPB supervision; it does not affect fintech or non-bank oversight, which operates under separate authority
  • The compliance programs that survive any version of this reform will be the ones built around actual legal obligations — not the exam schedules of whoever happens to be running the CFPB this year

A 70-Page Draft, Five Titles, and a $21B Number Making Headlines

The House Financial Services Committee published a discussion draft proposing a structural overhaul of the CFPB on July 24, 2026, and opened a public comment period through August 21. The full 70-page text is available from the House.

The headline number is $21 billion — the proposed new threshold for “very large financial institution” supervisory status, up from the current $10 billion. Acting CFPB Director Vought has signaled support for the threshold change, telling Senate Banking Committee members this week that he backs the overhaul.

Before you decide how much this matters to your program, it’s worth being precise about what the draft actually proposes, what would be in scope and out of scope for each change, and what the realistic path to enactment looks like. The answer to the last question is: uncertain enough that no compliance team should be restructuring programs in response to a draft.

But the direction of travel it represents is worth understanding — because the structural pressure on CFPB authority has been building for two years, and some of these provisions have real compliance implications if they pass in any form.

What’s in the Five Titles

TitleCore ProposalCompliance Implication
I — GovernanceCongressional appropriations; dedicated Inspector GeneralBudget uncertainty; exam frequency could vary with political cycles
II — UDAAP ClarityLegal certainty on “abusive” standard; procedural safeguards for enforcementReduces rulemaking-by-enforcement risk; clarifies guidance vs. enforceable rules
III — Innovation SupportClarity for small-dollar bank products; guidance/rule distinctionMostly upstream — affects how future guidance is written
IV — Supervisory Threshold$10B → $21B for “very large” bank supervision; prudential regulator electionDepository institutions between $10B–$21B could shift to prudential regulator exams
V — EnforcementReduces enforcement-as-policymaking; civil penalty improvementsAligns with June 2026 Enforcement Principles already in effect

Title I — Congressional Appropriations and Governance

Since 2011, the CFPB has drawn its budget from the Federal Reserve System — up to a statutory percentage of the Fed’s total operating expenses. This funding structure was designed specifically to insulate the Bureau from annual appropriations battles. The draft ends that arrangement.

Under congressional appropriations, the CFPB’s budget would compete with other agency priorities, become subject to continuing resolutions and government shutdowns, and potentially shrink or expand based on which party controls the House, Senate, and White House. A dedicated Inspector General (currently shared with the Fed) would also be established.

The operational implications: examination staffing, enforcement capacity, and rulemaking pace would all become more variable. Institutions under direct CFPB supervision could see examination frequency fluctuate with funding cycles. Institutions not under direct CFPB supervision would feel this less directly — but a less-resourced CFPB typically means more supervisory space for state regulators to operate.

Title II — UDAAP Clarity and Procedural Safeguards

This is the provision most compliance teams have been waiting for since 2021.

The draft provides “greater legal certainty” around UDAAP, specifically addressing the Bureau’s authority to define “abusive” practices. The “unfair” and “deceptive” standards have decades of case law and FTC guidance behind them. “Abusive” has largely been defined through CFPB enforcement actions rather than clear statutory criteria — meaning the compliance standard for any given conduct has depended substantially on who was running the Bureau.

The draft would require clearer rulemaking before conduct can be actionable as abusive. It also:

  • Adds procedural safeguards for enforcement actions
  • Clarifies statutes of limitations
  • Addresses jurisdictional overlap with state regulators
  • Requires agencies to explicitly distinguish non-binding guidance from legally enforceable requirements

That last point matters in practice. If you’ve built compliance program procedures around CFPB supervisory letters, FAQs, or informal guidance — which millions of financial institutions have — those aren’t legally enforceable rules. The draft would require the Bureau to say that explicitly. Whether that changes your practical compliance exposure depends on what state regulators and private plaintiffs do with the same underlying conduct.

Title IV — The $21B Supervisory Threshold

This is the provision generating the most attention and the most misunderstanding.

What it does: The current threshold for “very large financial institution” status — triggering direct CFPB supervisory authority over depository institutions — is $10 billion in assets. The draft would raise that to $21 billion. It also allows institutions to elect examination by their primary prudential regulator (OCC, Fed, FDIC) rather than the CFPB.

What it doesn’t do: It doesn’t affect non-bank supervision. The CFPB’s authority over non-bank entities — payday lenders, mortgage companies, student loan servicers, debt collectors, consumer reporting agencies, and (through larger-participant rulemaking) certain fintechs — operates through entirely separate statutory authority. That authority is not on the table in this draft.

If you’re a fintech without a bank charter, or a non-bank lender operating under CFPB’s non-bank supervision framework, the $21B threshold is essentially irrelevant to your direct regulatory exposure.

What Changes Today: Nothing

The CFPB reform discussion draft is a discussion draft. It carries no legal weight. The comment period through August 21 is an invitation for stakeholder input before any legislative process begins. From draft to enacted law, the steps include committee markup, House floor passage (including any floor amendments), Senate consideration and potential cloture, conference committee if House and Senate versions differ, and presidential signature.

Several of those steps have killed less controversial financial legislation. There’s no reason to treat this as imminent.

What your regulatory change log should say: Note received July 29, 2026. Comment period closes August 21. Monitor for committee markup and any reported text. No compliance program changes warranted at this stage.

What Won’t Change Even If Some Version Passes

State AGs Already Filled the Gap

When the CFPB pulled back in 2025, the enforcement gap didn’t stay empty. State attorneys general moved quickly: New York sued earned wage access providers. California’s DFPI expanded UDAAP enforcement authority under SB 825. New Jersey, Illinois, and Massachusetts issued consumer protection statements specifically targeting fintech products. The CFPB’s supervisory threshold affects federal exam authority — it doesn’t touch state enforcement power, which derives from entirely separate statutory authority.

If you’re a mid-size institution that might move out of direct CFPB supervision under the $21B threshold, your examination exposure shifts — it doesn’t disappear. It may become more diffuse and harder to predict, distributed across multiple state regulators rather than a single federal examiner.

Bank Partners Require Compliance Programs Regardless of CFPB Posture

If you operate as a fintech under a bank partnership, your sponsor bank’s third-party risk management requirements don’t relax when the CFPB’s posture changes. The bank is managing its own regulatory risk — OCC, Fed, FDIC, state banking department — and that risk includes your compliance posture. Bank partner oversight requirements are negotiated in your program agreement. Those requirements will reflect the bank’s regulatory exposure, not the CFPB’s enforcement calendar.

Private Litigation Sets the Floor

UDAAP clarity helps reduce regulator-versus-institution uncertainty. It doesn’t affect consumer class actions under state UDAP statutes, which largely parallel the unfair-and-deceptive standard without requiring CFPB action as a trigger. The largest consumer finance settlements in the past decade have often come through private litigation, not CFPB enforcement.

What the Discussion Draft Actually Tells You About Program Design

The most useful takeaway from this draft isn’t any specific provision — it’s the pattern it represents.

Since 2021, the CFPB has operated under at least three meaningfully different enforcement postures depending on administration. Programs optimized for any single posture have required significant rework each time the environment shifted. Programs built around actual legal obligations — statutory text, final rules, court-interpreted standards — have required far less adjustment.

The regulatory change implementation process that matters is the one that distinguishes between legal obligations (statute, final rule, court decision) and the CFPB’s current enforcement interpretation of those obligations. When you build procedures, you should know which category each control is responding to.

The CFPB’s June 2026 Enforcement Principles represent the current Bureau’s interpretation of when enforcement is appropriate. Those principles can shift with leadership. Your statutory obligations under TILA, ECOA, EFTA, and the FTC Act cannot.

So What?

The CFPB reform discussion draft is real, and if something close to its proposals eventually passes, institutions between $10B and $21B in assets may see their primary federal examination source shift. UDAAP clarity would reduce some legal ambiguity that has made compliance program design difficult. Congressional appropriations would introduce budget variability that affects the Bureau’s operational capacity.

But none of that happens before August 21 at the earliest — and realistically, not before late 2026 or 2027 if it happens at all.

What the discussion draft makes concrete is the argument for building compliance programs around legal obligations rather than CFPB enforcement risk. An institution whose procedures are based on statutory requirements doesn’t rewrite its program every time the CFPB shifts posture. It adds a note to its regulatory change log, monitors the legislative calendar, and updates only when something with legal effect is actually enacted.

If that describes your program, this week’s 70-page draft is a monitoring item. If it doesn’t, the path forward is the same regardless of what Congress does with CFPB reform.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the $21B supervisory threshold change apply to fintechs and non-bank lenders?
No. The $21B threshold affects which depository institutions qualify as 'very large financial institutions' subject to direct CFPB supervision. Fintechs and non-banks are supervised under the CFPB's non-bank supervision authority — based on product type or larger-participant rules — not the asset-based threshold. The draft doesn't propose eliminating non-bank supervision.
When could the CFPB reform discussion draft become law?
It's a discussion draft, not a bill. The public comment period runs through August 21, 2026. The path to enactment — committee markup, House floor vote, Senate consideration, conference, presidential signature — is uncertain. Sweeping CFPB structural overhauls have been proposed repeatedly; specific targeted provisions have sometimes passed, but comprehensive reform has not.
What does bringing the CFPB under congressional appropriations actually mean?
Currently, the CFPB draws from the Federal Reserve System — up to a statutory cap — independent of annual congressional budget cycles. Appropriations would require the Bureau's budget to go through the same annual process as every other agency, creating potential funding gaps during government shutdowns or partisan budget disputes. This is the structurally most significant change in the draft.
Does UDAAP clarity in the draft affect current or pending CFPB enforcement actions?
No. The proposed UDAAP changes apply prospectively. Pending enforcement actions proceed under existing law. The UDAAP clarity provisions affect future rulemaking and enforcement standards, not cases already filed.
Should we update compliance policies based on the discussion draft?
Not yet. Discussion drafts carry no legal weight. Log it in your regulatory change tracker, monitor the August 21 comment deadline and any subsequent committee markup, and update policies only when a final rule actually takes effect.
How does the draft interact with the CFPB's June 2026 Enforcement Principles?
The enforcement principles represent the Bureau's current operating posture under existing law. The discussion draft would codify some of those changes structurally, but they're independent mechanisms. Current enforcement principles shift with leadership; the draft would require statutory change — and leadership can shift again.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.