search

New CFPB Rules for 2027: Impact on Community Banks and Credit Unions

6/26/2026

The post covers the durable structure — how CFPB authority reaches institutions of different sizes, which rules apply regardless, and how to track developments. Before publishing: verify every named rule's current status against the Bureau's own regulatory agenda and the Federal Register, add a visible last-reviewed date, and consider retitling away from a specific year. Do not publish this from a content calendar without that verification.

---

Community bankers frequently believe the CFPB is somebody else's regulator, because their examinations are conducted by the OCC, the Federal Reserve, the FDIC, or the NCUA. That belief is half right in a way that produces real compliance gaps.

The Distinction That Matters

Rule-writing authority reaches everyone. The CFPB writes the rules implementing most federal consumer financial protection statutes — Truth in Lending, RESPA, Equal Credit Opportunity, Electronic Fund Transfers, Truth in Savings, Fair Credit Reporting in part, and others. Those rules apply to institutions of every size. A $200 million bank complies with Regulation Z as written by the CFPB.

Supervisory authority is threshold-based. The Bureau supervises and examines depository institutions above an asset threshold. Below it, the institution's own prudential regulator examines for compliance with the same CFPB-written rules.

So the accurate framing for a community bank is: the CFPB writes your consumer compliance rules, and your prudential regulator grades you on them. Both halves have consequences — the rules matter regardless of size, and the examination relationship, expectations, and findings language come from the prudential agency.

Enforcement authority is a third thing again, and the Bureau's enforcement reach is not identical to its supervisory reach.

Which Rules Apply Regardless of Size

The practical inventory for a community institution:

Regulation Z — Truth in Lending, including the TRID integrated disclosures, ability-to-repay and qualified mortgage requirements, high-cost mortgage rules, credit card provisions, and advertising requirements.

Regulation X — RESPA, including the anti-kickback provisions, escrow limits, and the mortgage servicing rules.

Regulation B — ECOA, including adverse action notice requirements and the prohibited bases.

Regulation E — electronic fund transfers, error resolution, liability limits, overdraft opt-in, and remittance transfers.

Regulation DD — Truth in Savings, for consumer deposit accounts.

Regulation C — HMDA reporting.

Regulation P — privacy notices.

Regulation V — Fair Credit Reporting Act provisions including risk-based pricing notices and the identity theft red flags requirements.

Regulation F — debt collection, which principally reaches third-party collectors rather than a bank collecting its own debts, though the distinction requires care where collection is outsourced.

UDAAP — the standard with no checklist, applied to everything above.

An institution that cannot produce that list quickly has a gap in its regulatory inventory, which is the foundation of the compliance risk assessment.

What Was in Motion at Drafting

Named as threads to verify rather than as current requirements:

Small business lending data collection under Dodd-Frank section 1071. A rule finalized in 2023 requiring collection and reporting of data on credit applications from small businesses, subject to litigation and to compliance dates that were extended, with tiered dates by originations volume. For community banks with meaningful small business lending, this is the largest new data collection obligation since HMDA's expansion, and its status must be confirmed.

Personal financial data rights under section 1033. A rule addressing consumer access to their financial data and third-party sharing, finalized and then litigated.

Overdraft and non-sufficient funds fee rulemaking, which had been an active area of both rulemaking and enforcement attention.

The Bureau's own operating position, which was subject to significant change and litigation during 2025 and 2026 — affecting the pace of rulemaking, supervision, and enforcement in ways that were unresolved.

That last item is why this topic carries more uncertainty than any other in this content series, and why the verification instruction above is not boilerplate.

The Compliance Reality Below the Threshold

Three practical points that community institutions get wrong.

A pause in supervision is not a pause in obligation. Whatever the Bureau's supervisory posture, the rules remain in force and the prudential regulator examines for them. Institutions that relaxed consumer compliance attention on the basis of news about the Bureau have created exposure with their actual examiner.

Private litigation is unaffected. Many of these statutes carry private rights of action. TILA, RESPA, ECOA, and the FCRA can all be enforced by consumers regardless of any agency's enforcement priorities, and plaintiff's counsel does not wait for a regulatory agenda.

State enforcement exists independently. State attorneys general have authority to enforce certain federal consumer financial laws, and states have their own consumer protection statutes. A quieter federal posture has historically been accompanied by more active state enforcement rather than less enforcement overall.

How to Track This Properly

Read the Bureau's regulatory agenda, published periodically, which states what it intends to propose and finalize. This is the closest thing to a forward calendar that exists.

Watch the Federal Register rather than trade coverage for the actual text and effective dates.

Distinguish four states for every rule, and record which one applies: proposed, finalized-with-future-compliance-date, effective, and stayed-or-vacated. Institutions routinely implement proposals and ignore finalized rules with distant dates, which is the wrong error in both directions.

Read your prudential regulator's issuances too, because that is who examines you, and their bulletins tell you how the rules will be assessed.

Record an applicability decision for each development, including "not applicable," in the regulatory change log.

Structured coverage is available through our banking regulations reference, bank compliance training, and CFPB Laws: Preventing UDAAP and Other Violations.

Preparing for a Data Collection Rule Before It Lands

Section 1071 is worth treating as a case study, because the pattern recurs whenever a rule requires new data rather than a new disclosure — and it is the pattern institutions handle worst.

A disclosure rule is a document change: draft, review, print or configure, deliver on a date. A data collection rule is an origination-process change, and the lead time is much longer than the compliance date suggests.

What such a rule actually requires: new fields captured at application by the people taking applications; system changes to store them; procedure and training changes so they are captured correctly and consistently; demographic information collected under specific rules about how it may be requested and recorded; a submission mechanism; data validation before submission; and — the part institutions discover late — a fair lending analysis capability, because the whole point of collecting the data is that someone will analyze it for disparities.

That last point deserves emphasis. HMDA's history is instructive: the data is collected for transparency, and its practical effect is that lending patterns become publicly analyzable. Any institution facing a small business lending data requirement should assume its small business lending patterns will be examined the same way its mortgage patterns are, and should run that analysis on itself first.

The preparation that does not depend on a rule's final status: know your small business lending volume and whether you would cross any tiered threshold, know whether your origination system can capture new fields at all, and know whether anyone in the institution could analyze the resulting data. Those three answers determine how large the project is, and none of them requires the rule to be settled.

The Small-Institution Exemptions Worth Knowing

A meaningful share of CFPB rulemaking carries exemptions or tailored treatment for smaller institutions, and community banks frequently either miss an exemption they qualify for or assume one that does not exist. Both errors are expensive in different directions.

The general pattern is that exemptions turn on some combination of asset size, origination volume, and geography — and the specific criteria differ by rule, which is why "we're a small bank" is never the answer to whether a rule applies.

Examples of the structure, each requiring verification of current criteria before reliance:

Small creditor and rural or underserved designations under the mortgage rules, which affect qualified mortgage treatment, escrow requirements on higher-priced mortgage loans, and balloon-payment lending. An institution that qualifies as a small creditor operating predominantly in rural or underserved areas has materially different options than one that does not, and the designation depends on published county lists and on origination counts that change annually.

HMDA reporting thresholds, measured separately for closed-end loans and open-end lines over each of the two preceding years, so coverage can change year to year without any change in strategy.

Escrow requirements, where small creditor status can affect the obligation.

Volume-based tiering in newer data collection rules, where compliance dates and obligations differ by originations.

Three practical rules follow. Reassess eligibility annually, because most of these criteria are measured on rolling prior-year data and an institution can drift in or out without noticing. Document the determination with the data supporting it, because an exemption claimed without support is worse than no exemption. And do not build to an exemption you might lose — an institution close to a threshold should understand what compliance looks like on the other side before it crosses.

The broader point for a compliance officer: the exemption analysis is part of the regulatory inventory, not a separate exercise, and it needs a named owner and an annual date like everything else in the calendar.

A closing observation about credit unions, since the title includes them. The structure described above applies, with one substitution: the NCUA is both the prudential regulator and, for federally insured credit unions below the supervisory threshold, the examiner for CFPB-written rules. Credit unions therefore face the same rule set through a single agency relationship rather than two, which simplifies the examination picture without changing a single obligation. Where NCUA guidance and CFPB rules address the same subject, the rule is the requirement and the guidance describes how it will be assessed — the same distinction that applies on the bank side.

Frequently Asked Questions

Do CFPB rules apply to small community banks?

Yes. The CFPB writes the rules implementing most federal consumer financial protection statutes, and those rules apply to institutions of every size. What is threshold-based is supervision: the Bureau examines depositories above an asset threshold, while below it the institution's own prudential regulator examines for compliance with the same rules.

Who examines a community bank for consumer compliance?

Its prudential regulator — the OCC, Federal Reserve, FDIC, or NCUA — for institutions below the CFPB's supervisory asset threshold. The rules being examined are still CFPB-written, but the examination relationship, expectations, and findings language come from the prudential agency.

Which CFPB-written regulations should a community bank inventory?

Regulation Z, Regulation X, Regulation B, Regulation E, Regulation DD, Regulation C, Regulation P, Regulation V, Regulation F where applicable, and UDAAP across all of them. An institution that cannot produce that list quickly has a gap in the regulatory inventory underpinning its compliance risk assessment.

If federal supervision slows, do the obligations change?

No. The rules remain in force, the prudential regulator still examines for them, many of the underlying statutes carry private rights of action that consumers can pursue regardless of agency priorities, and state attorneys general have independent enforcement authority. A quieter federal posture has historically coincided with more active state enforcement rather than less enforcement overall.

What makes a data collection rule harder than a disclosure rule?

A disclosure rule changes a document. A data collection rule changes the origination process — new fields captured by the people taking applications, system changes to store them, procedure and training changes, a submission mechanism, validation, and a fair lending analysis capability, because collected data gets analyzed for disparities. The lead time is far longer than the compliance date implies.

How should a bank track CFPB developments?

Through the Bureau's published regulatory agenda for forward visibility, the Federal Register for actual text and dates, and the prudential regulator's own issuances for how rules will be assessed. Record for each rule which of four states applies — proposed, finalized with a future compliance date, effective, or stayed — and log an applicability decision including "not applicable."

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026