Feature Compliance Strategy
H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.
The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.
Table of Contents
TL;DR
- H.R. 10184, introduced August 31, 2026, proposes to restructure the CFPB through five major changes: raising the supervision threshold from $10B to $30B, cutting maximum daily penalties from $1M to $50,120 for knowing violations, narrowing the UDAAP “abusive” standard, subjecting the bureau to congressional appropriations, and creating a small-dollar credit safe harbor
- No Democratic cosponsors; the bill faces significant Senate hurdles
- Even if it doesn’t pass, the provisions signal the direction of CFPB enforcement and supervisory posture under the current administration
- State enforcement fills the gap when federal enforcement recedes — and has been doing so actively in 2026
The CFPB has faced structural reform proposals in every Congress since 2011. Most didn’t pass. H.R. 10184, the Consumer Financial Protection Accountability and Reform Act of 2026, is more credible than most — introduced by the chairs of the House Financial Services Committee and its Financial Institutions Subcommittee, with 29 cosponsors and an HFSC roundtable already in the books.
Whether it becomes law is a separate question. What matters for compliance teams right now is what the bill’s provisions reveal about where CFPB supervision and enforcement are heading — and how to position your program for a regulatory environment that’s already shifted significantly from 2023.
This follows the discussion draft we analyzed in July, but H.R. 10184 is a formal bill with sharper provisions. The supervision threshold jumped from $21 billion in the discussion draft to $30 billion. The penalty structure is more specific. The UDAAP changes are more explicit. The roundtable signals committee movement.
The Five Structural Changes in H.R. 10184
1. The $30 Billion Supervision Threshold
The current CFPB supervision threshold is $10 billion in total assets. Any bank or credit union above $10 billion is subject to CFPB examination in addition to its prudential regulator. H.R. 10184 would raise that threshold to $30 billion, with adjustments starting in 2031 based on nominal GDP growth.
The practical effect: institutions between $10B and $30B — mid-sized regional banks, credit unions, and some fintech bank partners — would lose CFPB supervisory jurisdiction. Consumer compliance supervision would revert to the OCC, FDIC, NCUA, or state regulators depending on charter type.
Institutions above $30B could also elect to have their prudential regulator conduct consumer compliance supervision, even though they’d remain above the threshold. The exception: GSIBs stay under CFPB regardless. And the CFPB retains the ability to intervene when it finds heightened consumer risk or inadequate prudential supervision above the threshold.
For fintechs operating through BaaS sponsor banks that fall in the $10B–$30B range, this would change who supervises your bank partner’s consumer compliance program. The OCC and FDIC are not weaker supervisors on consumer protection — but they operate differently from the CFPB, and your bank partner’s exam priorities and remediation timelines may shift.
2. Civil Money Penalty Reduction
The CFPB’s current civil money penalty structure has three tiers: up to $5,000 per day for unknowing violations, up to $25,000 per day for reckless violations, and up to $1,000,000 per day for knowing violations. Those daily caps have historically enabled the CFPB to impose penalties measured in the tens or hundreds of millions for multi-year violations.
H.R. 10184 would cut the maximum daily penalty for knowing violations from $1,000,000 to $50,120. That’s a 95% reduction in the ceiling. Section 501 of the bill also removes the bureau’s authority to impose civil money penalties for violations that were not committed knowingly or recklessly — eliminating the lowest tier for unknowing violations entirely.
The practical effect of the $50,120 cap is context-dependent. For a one-week violation, $50,120 per day produces a $350,840 penalty. For a three-year violation, even at $50,120 per day, the total is over $55 million. The ceiling matters most when violation duration is short and the CFPB is using the daily cap as a deterrent against large institutions.
3. Narrowing the UDAAP “Abusive” Standard
UDAAP — unfair, deceptive, or abusive acts or practices — is the CFPB’s broadest enforcement authority. The “abusive” prong has been particularly contested because the Dodd-Frank Act defined it in ways that gave the CFPB significant interpretive flexibility.
H.R. 10184 would codify a narrower standard: a practice may be deemed abusive only where there is risk of substantial injury not outweighed by countervailing benefits. This mirrors the standard for “unfair” practices under FTC Act section 5 and effectively harmonizes the two standards.
More significantly, the bill would prohibit the CFPB from interpreting UDAAP to include discriminatory practices. This reverses the March 2022 UDAAP examination manual update, which the Biden-era CFPB used to extend UDAAP authority to fair lending enforcement in a way that bypassed the more specific requirements of ECOA and HMDA. The reversal would effectively end the CFPB’s ability to bring UDAAP claims based on disparate impact or discriminatory effect without a separate ECOA hook.
For compliance programs, this matters in two directions. If the bill passes, the most aggressive UDAAP theory — discrimination as unfair or abusive practice — goes away at the federal level. But state UDAP laws remain active, state AGs remain aggressive, and the ECOA/Regulation B framework still applies to any creditor making credit decisions. The state enforcement wave we documented in July doesn’t slow down because the CFPB’s UDAAP scope narrows.
4. Congressional Appropriations
The CFPB’s independence from the appropriations process — funding through Federal Reserve transfers — was central to its design as an agency insulated from political budget pressure. H.R. 10184 ends that: the bureau would be funded through annual congressional appropriations, like the OCC or any other executive agency.
This is a structural change with an uncertain timeline for impact. If the bill passes, the CFPB’s budget in fiscal year 2028 would be set by Congress, not by the Fed’s earnings. Years of divided-government budgeting demonstrate what that can mean for agency staffing, enforcement capacity, and rulemaking bandwidth.
For compliance teams, the relevant implication isn’t the dollar amount of the CFPB’s budget — it’s the volatility. An agency whose funding depends on the annual appropriations cycle can experience significant staffing and capacity swings based on elections, budget negotiations, and continuing resolution politics. The new enforcement principles the CFPB adopted earlier this year already reflect a more restrained posture; appropriations dependence would entrench that posture in a way that’s harder to reverse quickly.
5. Small-Dollar Credit Safe Harbor
The bill would create a safe harbor from CFPB enforcement for products classified as small-dollar credit. This is a direct response to years of CFPB attention to payday lending, earned wage access, installment credit, and other short-term consumer credit products.
The safe harbor provision matters for fintech compliance teams in a specific way: it signals that the current administration and House Republican majority view short-term consumer credit as a category deserving protection from CFPB enforcement — not aggressive supervision. But as the Colorado EarnIn case demonstrates, federal enforcement posture doesn’t determine state enforcement posture. A CFPB safe harbor wouldn’t have changed Colorado AG Phil Weiser’s decision to file suit for $16 million in tips and fees.
What This Bill Reveals About the 2026 Regulatory Environment
The bill’s specific provisions are less important than what they reveal about the regulatory philosophy behind them. Three patterns emerge:
Materiality as the governing standard. Every major regulatory reform initiative of 2026 — the OCC/FDIC unsafe or unsound final rule, the OCC violations NPRM, and now H.R. 10184 — is built around the same idea: enforcement and supervision should focus on material risk to consumers and financial institutions, not on procedural compliance for its own sake. The $30B threshold, the penalty reduction, and the UDAAP narrowing are all applications of that principle. Whether or not H.R. 10184 passes, compliance programs that are built around documentation-first, process-completeness frameworks will face increasing pressure to demonstrate actual risk outcomes.
State enforcement is the backstop. Every provision in H.R. 10184 that reduces federal enforcement exposure for a product or institution has a parallel state enforcement gap it does not fill. The UDAAP discrimination prohibition doesn’t touch ECOA. The small-dollar credit safe harbor doesn’t touch state UCCC statutes. The supervision threshold change doesn’t touch state-chartered examination. The last two years of state AG enforcement — against EarnIn, Block, various EWA providers, and others — has been conducted under state law frameworks that are entirely independent of whatever the CFPB does.
Regulatory uncertainty creates compliance program design risk. If your compliance program was designed around the assumption of CFPB examination for institutions between $10B and $30B, and that assumption changes, you need to understand what the prudential regulator’s consumer compliance exam looks like and how it differs. If your UDAAP risk assessment was built around the expanded discrimination-as-UDAAP theory, you need to know which risks survive a narrowed UDAAP standard. Building a compliance program to a moving regulatory target is harder than building to a stable one — which means the compliance planning horizon matters as much as the current rule.
How to Adapt Your Compliance Strategy for the Current Environment
Regardless of whether H.R. 10184 becomes law, three program adjustments are worth making now:
Stress-test your UDAAP risk framework for state exposure. Map every UDAAP-adjacent risk in your program against state UDAP statutes in your operational footprint. Which risks survive a narrowed federal UDAAP standard at the state level? Fair lending disparate impact, fee disclosure opacity, and deceptive marketing claims are all actively pursued by state AGs under state statutes — your program should be tracking them under those frameworks, not just federal ones.
Understand your bank partner’s supervisor. If you operate through a BaaS sponsor bank in the $10B–$30B range, know who would supervise its consumer compliance program if CFPB jurisdiction shifts to the prudential regulator. OCC and FDIC consumer compliance examinations are substantive — but they have different emphasis, timing, and remediation culture than CFPB examinations. Your bank oversight and third-party risk program should reflect that.
Use a risk control self-assessment framework to identify material-risk exposures. The regulatory shift toward materiality-based supervision means your RCSA needs to surface which consumer compliance risks have the most potential for consumer harm, financial impact, or systemic exposure — those are the ones that will draw examiner attention regardless of the CFPB’s jurisdiction. A well-structured RCSA maps your control environment to your actual risk exposures, not to a regulatory checklist, and it’s the tool that holds up when the regulatory checklist changes.
What to Watch Before Year-End
H.R. 10184 will move or not based on two variables: Senate dynamics and the appropriations calendar. The bill has no Democratic cosponsors, which means Senate passage would require 60 votes under the filibuster or nuclear option use. Neither is on a clear timeline.
What is on a clear timeline: the OCC/FDIC final rule on unsafe/unsound practices takes effect November 2, 2026. The OCC violations NPRM closes for comment October 1. The Fed’s LFI supervisory posture continues to prioritize private credit and NDFI exposure. Whatever happens to H.R. 10184 legislatively, the supervisory environment your compliance program operates in is already materially different from 12 months ago.
Sources:
- H.R.10184 — Consumer Financial Protection Accountability and Reform Act of 2026 (Congress.gov)
- HFSC: House Financial Services Committee Unveils CFPB Reform Package
- Consumer Finance Monitor: HFSC Roundtable Discusses CFPB Reform Act of 2026 (September 3, 2026)
- PYMNTS: House Bill Would Rewrite CFPB Supervision and Enforcement Rules
- Realty Wire: CFPB Reform Bill Would Slash Penalties, End Fed Funding
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is H.R. 10184 and where does it stand in the legislative process?
Which institutions would lose CFPB supervisory jurisdiction under the proposed $30 billion threshold?
How does the UDAAP change affect financial services companies that are not banks?
What does 'small-dollar credit safe harbor' mean in the bill?
What happens to the CFPB's funding under H.R. 10184?
Should companies below the $30 billion threshold stop investing in CFPB compliance programs?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Compliance Strategy
DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.
The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.
Sep 9, 2026
Compliance Strategy
FinCEN's Scam Center Alert: What BSA Officers Need to Do with FIN-2026-Alert005
FinCEN's September 3, 2026 alert identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency confidence schemes. Here's what the red flags are, who needs to file SARs, and how to update your transaction monitoring program.
Sep 6, 2026
Compliance Strategy
FinCEN Just Permanently Ended BOI Reporting for US Companies. Here's What Your Compliance Program Needs to Update Before Q4.
FinCEN's August 14, 2026 final rule permanently exempts all domestic US entities from Corporate Transparency Act beneficial ownership reporting. Here's what compliance programs need to change — and what the exemption doesn't touch.
Sep 2, 2026