Our Newsletter Is Moving to LinkedIn
To keep receiving your weekly insights, all you need to do is subscribe to our new Consumer Financial Services Weekly Newsletter — it’s quick and easy.
We’ll see you there!
To keep you informed of recent activities, below are several of the most significant federal events that have influenced the Consumer Financial Services industry over the past week.
Federal Activities:
On September 18, the U.S. House Committee on Financial Services favorably reported eight bills to the full House. These included H.R. 7030, the Securing Facilities for Mental Health Services Act (49-0), expanding Federal Housing Administration hospital mortgage insurance eligibility; H.R. 4936, the TRAPS Act (49-0), establishing a federal task force to combat payment scams; H.R. 10234, the CLEAR Forms Act (42-7), directing the U.S. Securities and Exchange Commission (SEC) to develop tailored registration forms for certain annuity and insurance products; H.R. 7866, the American Lending Fairness Act (31-18), clarifying the opt-out provision under the Depository Institutions Deregulation and Monetary Control Act of 1980 for state-chartered lenders; H.R. 1653, the Civil Investigative Demand Reform Act (29-20), reforming the Consumer Financial Protection Bureau’s (CFPB) civil investigative demand process; H.R. 10184, the Consumer Financial Protection Accountability and Reform Act (28-21), reforming CFPB governance, rulemaking, supervision, and enforcement authorities; H.R. 8957, the American Reserve Modernization Act (28-21), establishing a Strategic Bitcoin Reserve and Digital Asset Stockpile within Treasury; and H.R. 5889, the Eviction Helpline Act (47-2), creating a Department of Housing and Urban Development (HUD) hotline to assist tenants in federally assisted housing facing eviction. Chairman French Hill (R-AR) described the bills as reflecting “a practical, common-sense approach to expanding opportunity, protecting consumers, preserving choice and competition, and demanding accountability from the institutions that serve the American people.” For more information, click here.
On September 17, the U.S. House of Representatives passed four bills originating from the House Committee on Financial Services. H.R. 10167, the Common Cents Act, passed by voice vote and would end penny production while authorizing a more cost-effective nickel to reduce taxpayer costs and provide consistent cash-handling guidance for retailers, banks, and consumers. H.R. 2978, the GUARD Act, passed 414-7 and strengthens efforts against financial fraud and scams targeting seniors by allowing federal grant funds to be used for financial crime investigations and improving interagency fraud coordination and reporting. H.R. 8278, the FUTURES Act, passed 417-7 and requires financial regulators to assess and modernize their technological capabilities to make examinations more efficient and responsive to a rapidly evolving financial system. Finally, H.R. 4646, the Whistleblower Protection Act of 2025, passed 424-0 and extends whistleblower protections to individuals working on contracts previously funded by HUD. For more information, click here.
On September 17, the U.S. Senate Banking, Housing, and Urban Affairs Committee, chaired by Senator Tim Scott (R-SC), held an executive session to consider S. 4395, the Terrorism Risk Insurance Program Reauthorization Act of 2026 (TRIA), alongside four of President Trump’s nominees, including Brian Johnson to serve as director of the CFPB, Abby Warren as assistant secretary of Commerce, and Irving Dennis and Jeffrey Ledbetter for CFO and inspector general of HUD, respectively. Scott, invoking the 25th anniversary of September 11, urged swift, bipartisan reauthorization of TRIA to provide long-term certainty for businesses and taxpayers, and voiced support for all four nominees, expressing hope that Johnson, if confirmed, would fight fraud and abuse while preserving access to affordable credit. Ranking Member Elizabeth Warren (D-MA) joined in supporting TRIA’s reauthorization but strongly opposed the nominee slate, arguing that the Trump administration has weakened CFPB enforcement of consumer protection laws at a cost of more than $26 billion to Americans, and specifically criticizing Johnson for what she characterized as a conflict of interest, ultimately announcing she would vote no on all four nominees. For more information, click here, here, and here.
On September 17, the U.S. House Committee on Financial Services held a hearing titled “The Annual Testimony of the Secretary of the Treasury on the State of the International Financial System,” featuring testimony from Treasury Secretary Scott Bessent. Members explored a range of issues affecting the international financial system, including America’s competitiveness and influence within institutions like the IMF and World Bank, concerns about China’s opaque lending practices and exchange rate management, accounting inconsistencies between U.S. GAAP and IFRS affecting Treasury market clearing and liquidity, and the growing intersection of artificial intelligence with financial services, including cybersecurity resilience efforts following the Mythos incident and Treasury’s ongoing work through Project Gold Eagle to establish baseline AI standards in partnership with the banking sector. Bessent highlighted recent international consensus, representing more than two-thirds of global GDP, on addressing global economic imbalances, improving sovereign debt architecture, and reorienting the IMF and World Bank toward their core mandates in a manner consistent with American interests. For more information, click here.
On September 17, the Commodity Futures Trading Commission’s (CFTC) Market Participants Division (MPD) issued CFTC Letter No. 26-25, a no-action position broadly extending relief previously granted only to a single software developer under Staff Letter 26-09 to all similarly situated providers of “passive software” (PSPs) that enable users to trade Commission-regulated derivatives through registered futures commission merchants, introducing brokers, or designated contract markets. Under the letter, MPD will not recommend enforcement action against PSPs or their personnel for failing to register as an introducing broker or associated person under §§ 4d(g) and 4k(1) of the Commodity Exchange Act, provided the PSP satisfies a series of conditions, including avoiding statutory disqualification, providing conflict-of-interest and risk disclosures to users, ensuring users are onboarded directly with and can independently access the relevant registrant, adopting compliance policies consistent with NFA marketing rules, executing joint-and-several liability undertakings with each registrant, maintaining required records, and filing a notice of compliance with the MPD. The relief is limited to “Covered Activities,” namely passively providing front-end interface software that lets users view market data and submit orders directly to registrants without the PSP exercising discretion, generating buy/sell signals, or taking custody of user assets, and applies broadly, not just to providers of crypto-related software, until the CFTC issues formal rulemaking or guidance addressing software developers’ registration obligations. For more information, click here.
On September 17, the Federal Deposit Insurance Corporation (FDIC) Board of Directors approved a notice of proposed rulemaking that would amend the agency’s regulations to promote parity between out-of-state state banks and national banks with respect to the application of host state laws. Under the proposal, when a host state’s laws do not apply to a national bank operating in that state, those same laws would not apply to certain out-of-state, state banks providing services in that host state, regardless of whether the state bank maintains a branch there. Instead, consistent with § 24(j) of the Federal Deposit Insurance Act (FDI Act), the law of the state bank’s chartering state would govern. Specifically, the amendments would provide that, for purposes of § 24(j), host state laws apply to a branch in the host state of, or services provided in the host state by, an out-of-state state bank only to the same extent those laws apply to a branch in the host state of, or services provided in the host state by, an out-of-state national bank. The proposed rule would not alter the interest rates state banks are permitted to charge on their loans, which remain governed separately by § 27 of the FDI Act. For more information, click here.
On September 17, the FDIC Board of Directors approved a notice of proposed rulemaking aimed at modernizing and reforming the agency’s framework for reviewing bank merger transactions under the Bank Merger Act (BMA). Key reforms include accounting for credit unions and centrally booked deposits in the competitive effects analysis, establishing a letter filing process with “deemed approval” for de minimis merger transactions, tailoring other filing requirements to reduce burden and processing times, limiting and clarifying the FDIC’s discretion to remove filings from expedited processing, and reforming the agency’s approach to evaluating the BMA’s statutory factors. Collectively, the proposal is intended to impose greater discipline around review timelines and substantially reduce regulatory burden, making the FDIC’s merger review process faster, more predictable, and better tailored to the size, type, and complexity of risks posed by a given transaction. Comments on the proposed rule are due 60 days after its publication in the Federal Register. For more information, click here.
On September 17, FDIC staff, led by Ryan Billingsley, director of the Division of Risk Management Supervision, presented to the FDIC Board of Directors a resolution to rescind the Board’s 2016 Statement on the Development and Communication of Supervisory Recommendations, which had established principles guiding examination staff in issuing supervisory recommendations and matters requiring board attention (MRBAs) to supervised financial institutions. The rescission follows the September 1, 2026, publication of a final rule revising the supervisory framework for issuing matters requiring attention (MRAs), other violations of law, and supervisory observations, under which the FDIC will end its use of supervisory recommendations and MRBAs in favor of the new MRA framework, rendering the 2016 statement obsolete. Staff accordingly recommended, and presented for Board approval, a resolution formally rescinding the 2016 statement as superseded by the final rule. For more information, click here.
On September 17, SEC Chairman Paul S. Atkins delivered remarks at the agency’s 24-Hour Trading Roundtable, expressing his personal support for expanding U.S. equities trading beyond traditional hours to better serve investors responding to real-time global events, attract international capital, align U.S. markets with overseas trading venues, and improve price discovery and market efficiency. Atkins noted that preparatory infrastructure is already underway, including the Depository Trust and Clearing Corporation’s live 23-by-5 trade-capture system, an industry plan establishing overnight price bands and related written policies for overnight trading centers, and ongoing work to prepare the Securities Information Processor (SIP) plans for overnight price dissemination. He also highlighted operational challenges, such as intermediaries’ commercial decisions about overnight services, expanded prime brokerage and securities lending support, and firms’ difficulties obtaining locates for market making, and suggested tokenization could help address these issues through real-time inventory management that reduces settlement failures and mitigates abusive naked short selling. Atkins closed by inviting feedback from market participants and public companies, particularly on how 24-hour trading might affect corporate actions, material disclosure obligations, and SEC EDGAR filing requirements, before turning the roundtable over to Jamie Selway, director of the Division of Trading and Markets, and encouraging public comment through the SEC’s website. For more information, click here.
On September 15, Federal Trade Commission (FTC) staff published a detailed FAQ on price transparency in auto advertising. The headline principle isn’t new: the price a dealer advertises has to be the price any consumer can actually walk in and pay. But the FAQ gets specific about what that means in practice, and a few of the details could trip up even careful dealers and their finance partners. For example, government-required charges (think taxes) can be excluded from the advertised price. Everything else (document fees, dealer-required add-ons, anything the dealer requires any consumer to pay) has to be folded into that single advertised number, not disclosed separately. That includes fees the government requires the dealer to pay but that get passed on to the consumer, and it includes government-authorized (but not mandated) dealer fees too. Doc fees get their own callout: if the mandatory doc fee varies by customer, the advertised price has to reflect the highest fee any consumer would actually be charged. Dealers can’t advertise off the discounted version and surprise someone with the full fee later. Negotiating with individual customers is fine, but the advertised price still has to be a number every consumer could actually get — not a promotional rate quietly extended to a handful of past buyers. The same logic applies to optional add-ons: protection packages and accessories are fine to offer, but dealers can’t imply they are mandatory, misstate their cost, or slip in charges a consumer never agreed to. For more information, click here.
On September 14, the Small Business Administration (SBA), joined by Vice President JD Vance, Attorney General Todd Blanche, Federal Bureau of Investigation Director Kash Patel, and Assistant Attorney General Colin McDonald in Kansas City, MO, announced its largest-ever fraud action to date: the suspension of 870,000 U.S. borrowers connected to an estimated $39 billion in suspected fraudulent pandemic-era Paycheck Protection Program (PPP) and Economic Injury Disaster Loan (EIDL) activity, extending the crackdown to 45 new states, six territories, and the District of Columbia (building on prior suspensions of over 150,000 borrowers tied to roughly $10 billion in fraud across five states). Suspended borrowers are barred from future SBA loans and programs, including the 8(a) Business Development Program, while the Department of Justice simultaneously announced a slate of enforcement actions and indictments under Operation Heartland Surge against alleged PPP and EIDL fraudsters. In a related action, the SBA and its Office of Inspector General, led by William Kirk, launched “Operation No Doze,” under which the agency will send final 30-day repayment demand letters to suspected fraudulent borrowers, beginning with approximately 8,000 in Kansas and Missouri, warning that noncompliance could result in liability under the Administrative False Claims Act (up to double damages plus penalties), DOJ referral, transfer to Treasury’s Cross Servicing Program (with added interest and collection fees up to 28%), and offset against federal payments including tax refunds and Social Security benefits, building on the SBA’s earlier referral of more than 560,000 suspected fraudulent borrowers tied to $22 billion in loans to Treasury for collection. For more information, click here.
On September 9, the U.S. Department of the Treasury announced that its Financial Crimes Enforcement Network (FinCEN) issued a Financial Trend Analysis identifying approximately $17.5 billion in suspicious financial activity potentially linked to health care fraud, based on more than 5,700 Bank Secrecy Act reports filed by financial institutions between March 1, 2025, and February 28, 2026. The analysis found that depository institutions filed roughly 89% of the reports and accounted for nearly 87% of the flagged suspicious activity amounts; that suspected fraud schemes spanned Medicare, Medicaid, and private insurance funding sources; that the overwhelming majority of subjects were U.S.-based, with only about 1.5% of roughly 13,000 subject addresses located abroad; that home health care businesses were the most frequently identified suspected fraudulent provider type (20% of reports), followed by hospice care, behavioral health and addiction treatment providers, medical equipment providers, and daycares; that suspected proceeds were often used for personal spending, luxury purchases, and international transfers; and that a small subset of filings suggested potential involvement of larger criminal networks or foreign connections. Bessent emphasized that the findings give law enforcement critical financial intelligence to disrupt fraud schemes exploiting taxpayer-funded health care programs, and Treasury noted the analysis, its second health care fraud-related product this year following a March 2026 advisory, will continue to inform coordination with the White House Task Force to Eliminate Fraud and encourage whistleblower reporting to recover taxpayer funds and hold perpetrators accountable. For more information, click here.
On September 8, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), under Operation Economic Outcast, sanctioned 36 targets for supporting Iran’s aviation sector, including 27 Iranian airlines designated pursuant to Executive Order 13902 (leveraging an August 24, 2026 aviation sector determination) as well as covert front companies, foreign intermediaries, and transshipment networks facilitating Mahan Air’s procurement of U.S.-origin aircraft and sensitive technology, including UAE-based ECT Aviation Support LLC, its owner Ibrahim Ali Mohamed Mohamed Mahran, UK-based ECT Aviation Support LTD, UAE-based Aerobravo Airplane Management, Türkiye-based Sky Phoenix, and cargo/general sales agent firms S Sistem, Mes Cargo, Icargo, and Tour Invest, all designated pursuant to Executive Order 13224, as amended. OFAC simultaneously suspended three Iran-related aviation authorizations covering overflights and non-U.S. airline use of U.S.-origin aircraft into Iran, while FinCEN issued a companion alert urging financial institutions to watch for and report red flags tied to Iran’s aircraft and aircraft parts procurement networks. Bessent stated the action fulfills Operation Economic Outcast’s promise of “severe consequences” for those sustaining Iran’s regime, warning that any party facilitating sanctioned Iranian airlines risks being cut off from the global financial system, and Treasury noted the sanctions build on its April and July 2026 actions targeting Mahan Air’s flight operations as well as Mahan Air’s original 2011 designation under Executive Order 13224 for supporting the IRGC-Qods Force. For more information, click here.
State Activities:
On September 18, New York Attorney General Letitia James announced a settlement with Brooklyn real estate firm Brooklyn High Rise LLC resolving an investigation that found the firm illegally engaged in “tenant blacklisting” by obtaining and using prospective tenants’ housing court records, in violation of the Housing Stability and Tenant Protection Act, resulting in 203 tenants being unlawfully denied housing between July 2019 and September 2025, while also improperly collecting $500 to $750 “good faith deposits” from applicants that were often not refunded, affecting an estimated 300 applicants between January 2020 and December 2025. Under the settlement, Brooklyn High Rise agreed to end its unlawful screening practices (including removing court history and criminal background questions from applications, reassigning applications inadvertently containing such records to leasing agents without prior knowledge of them, publicly affirming compliance with tenant blacklisting and anti-discrimination laws, and training staff), and to pay $202,250 in penalties for the blacklisting violations plus $150,000 in restitution to affected applicants, who will be contacted and may file claims for $500 or $750 payments. For more information, click here.
On September 18, Governor Gavin Newsom issued an executive order directing California’s Government Operations Agency to accelerate implementation timelines for two recently signed AI oversight laws, SB 813, which established a framework for certifying independent verification organizations to assess AI systems for safety and risk, and AB 1405, which created a state registry for AI auditors, while also convening a group of world-leading experts to deliver, within two months, recommendations for further strengthening state law. Proposed reforms under consideration include requiring frontier AI companies to embed onsite independent verification organizations to conduct regular audits, requiring independent verification of companies’ mandated safety frameworks and risk assessments, advancing development of an AI “kill switch” for frontier models with ongoing independent verification of its efficacy, and updating the definition of critical safety incidents to include loss-of-control events such as the recent Hugging Face attack. Framing the action as a response to the federal government’s failure to establish meaningful AI oversight, Newsom called on Congress and the Trump administration to adopt California’s AI regulatory framework, which already spans frontier model safety, independent oversight, child safety standards for AI companion chatbots, social media protections for minors, deepfakes and synthetic content, privacy, workforce impacts, cybersecurity, and AI-enabled fraud, as a national baseline. For more information, click here.
On September 14, the Florida Office of Financial Regulation (OFR) issued a final order approving a Stipulation and Consent Agreement resolving Case Number 138058 against BYDcash, Incorporated (f/k/a BYDcash, LLC). The action stemmed from an OFR examination covering November 1, 2020, through November 30, 2025, which found that BYDcash had engaged in making consumer finance loans without first obtaining the required license, in violation of § 516.02(1), Florida Statutes. Without admitting or denying the finding, BYDcash agreed to cease and desist from future violations of chapter 516 and its implementing rules, pay an administrative fine of $107,250, and, in exchange, the Office agreed to approve BYDcash’s consumer finance license application and issue the license within one business day of the final order’s entry. As part of the settlement, BYDcash waived its rights to a separate hearing, contested findings, or appeal, and both parties released each other from related claims, with the final order constituting the office’s final enforceable agency action in the matter. For more information, click here.
On September 10, the New York State Department of Financial Services (DFS) issued an industry letter to all Covered Entities regulated under its Cybersecurity Regulation (Part 500), providing guidance, without creating new obligations, on how to properly design, conduct, and update the risk assessments required to inform their cybersecurity programs. Drawing on gaps observed during examinations and investigations, including incomplete asset inventories, weak or inconsistent risk methodologies, failure to account for emerging and interconnected risks, insufficient governance, and risk assessments that fail to meaningfully inform the cybersecurity program, DFS outlined five areas of best practice: (1) governance and oversight, including chief information security officer or senior officer involvement and reporting to the Senior Governing Body; (2) adoption of a defined, repeatable risk methodology covering both external and internal threats; (3) comprehensive scope and coverage addressing all assets, emerging risks (such as AI and quantum computing), third-party/supply chain risk, and cyber interdependencies or concentration risk; (4) documentation and traceability linking identified risks to specific controls, compensating measures, or risk-acceptance decisions; and (5) integration of risk assessment results into the broader cybersecurity program, with required review and updates at least annually and whenever a material change in business or technology affects the entity’s cyber risk profile. The department encouraged all covered entities to review their existing risk assessment practices against this guidance to strengthen resilience and better meet Part 500’s requirements. For more information, click here.
Recent Comments