The 21st Century ROAD to Housing Act became the biggest piece of financial institution (FI) legislation in years this month, easing supervisory burden on exam cycles and board meetings while adding new formal requirements around appraisal disputes. AML enforcement and rulemaking sent a clear signal: a compliance program that exists on paper doesn't hold up against what's happening inside an account. A $79 million forfeiture case and a $9.7 million BSA/AML settlement both delivered that lesson this month, and the Federal Reserve issued its own AML proposal on top of it.
Want a deeper dive into the latest headlines? Watch the August Reg Update podcast. For additional resources and regulatory analyses, check Ncomply.
The 21st Century ROAD to Housing Act (H.R. 6644) is one of the biggest pieces of financial institution legislation to pass in years, with provisions impacting banks, credit unions, and lenders. Because the applicability varies by institution type, we're splitting coverage by audience throughout this update rather than covering it in one place. Let’s start with what it means for lenders.
The provisions here apply mainly to FIs working with government-backed loan programs. For FHA loans, any borrower who falls 30 or more days delinquent must now be offered the opportunity to participate in housing counseling. Separately, USDA, VA, FHA, and FHFA are all required to establish formal review and resolution procedures for reconsideration of value (ROV) requests and follow-up appraisal appeals. ROV procedures have been permitted for FIs up to this point but not mandated. That's about to change, and formal rulemaking is likely to follow.
The law also requires FHFA to add a disclosure to the Uniform Residential Loan Application, placed just below the military service question, informing applicants that military members may qualify for a VA loan. FHA loan documents will need to show a side-by-side cost comparison against VA-guaranteed loan costs.
None of this is limited to internal policy updates. Loan origination systems and document providers will need to reflect these changes, too, which means vendor conversations should start now rather than closer to implementation deadlines.
Related: For a deeper dive on this development, register for our Mortgage Industry Update Webinar on August 20 at 1:00 pm CT.
The Bureau has gone without a Senate-confirmed director for roughly 18 months, but that’s about to change. Acting Director Russell Vought's authority to continue leading the agency expired on August 1, 2026. Brian Johnson, who served as the CFPB's deputy director during the first Trump administration and currently holds an executive role at Capital One, appeared before the Senate Banking Committee as the nominee to lead the Bureau long term. During the hearing, he named three priorities: protecting consumers from fraud and scams, keeping the Bureau within its statutory authority, and modernizing its operations. Confirmation is expected within the next couple of months.
Even without permanent leadership, the Bureau has stayed active. Its semiannual regulatory agenda lists a substantial amount of pending work across mortgage servicing and ability-to-repay, though some of those priorities could shift once Johnson is confirmed.
Section 1033 open banking rulemaking is also back in motion. The Bureau finalized its original rule in 2024, FIs sued, and a federal court blocked enforcement. The Bureau's own attorneys then asked the court to kill the rule, before reversing course roughly two months later to rewrite it instead. What's under reconsideration now is whether FIs can charge fees for data access, which the original rule prohibited, and who qualifies as an authorized "representative" allowed to pull a consumer's data on their behalf. A proposed rule addressing both questions is expected soon.
In 2024, the CFPB cut the credit card late fee safe harbor from $30 (or $41 for repeat violations) down to $8. The industry sued, and the rule was thrown out by the court. Now the Bureau is requesting information on late fees and late payments. There's no indication this signals a return to the $8 cap specifically, but it confirms late fees haven't dropped off the Bureau's radar.
Build bandwidth in Q3 and Q4 for mortgage servicing, ability-to-repay, and the 1033 proposal. Any rule changes will show up in Ncomply as they land.
Related: Take a tour of Ncomply to see how your FI can get tailored regulatory updates and more.
In June, we flagged Executive Order 14406, "Restoring Integrity to America's Financial System," and its requirement that regulators issue credit risk guidance on borrowers who aren't legally authorized to work in the U.S. That guidance has now landed.
First, the CFPB issued a statement telling creditors that TILA and Regulation Z may require weighing a borrower's immigration status when assessing repayment ability, specifically because removal from the country could disrupt their income. This marks a sharp reversal from statements issued by prior administrations. Then the OCC, FDIC, and NCUA jointly told banks and credit unions to apply their existing safety-and-soundness underwriting practices to this population, treating uncertain income, employment continuity, and financial stability as credit risk factors like any other.
One more consideration worth flagging: portfolio concentration risk. If your book is concentrated in industries, geographies, or employers disproportionately affected by immigration enforcement, agencies want that evaluated like any other concentration risk. But none of the guidance explains how to perform that analysis or where a legitimate credit judgment ends, and a disparate impact on national origin begins. That gray area is worth flagging to fair lending counsel before touching underwriting policy language.
Related: June 2026 Regulatory Update: Fair Lending Shifts & a Supervisory Reset
Federal prosecutors are seeking forfeiture of roughly $79 million tied to a Wells Fargo Securities account, in a case centered on Capstone Ltd., a company the complaint says ran an unlicensed money-transmitting operation. Capstone had registered with FinCEN as a money services business, but told Wells Fargo, Citi, and Chase that it was an IT company, sidestepping the enhanced scrutiny its actual business type should have triggered.
According to the complaint, the company moved funds for a foreign bank, for a stablecoin issuer's customers, and laundered proceeds from a government-impersonation fraud scheme by converting victim deposits into USDT and transferring them overseas. None of that resembled a legitimate IT company's banking profile: hundreds of millions of dollars cycled between checking and securities accounts on behalf of foreign counterparties, with same-day conversion and outflow of funds tied to fraud victims.
Citi closed its accounts with Capstone in mid-2025 over AML concerns. The complaint doesn't say whether that closure triggered a referral to other banks holding the same relationship, and the money kept moving through Wells Fargo without interruption.
A stated business purpose is only as good as your ability to detect it drifting from actual account activity. Onboarding gets a customer in the door; ongoing monitoring, along with periodic and activity-triggered reviews, is what tells you whether the story still holds.
Related: TPRM 101: What is Vendor Monitoring for Financial Institutions?
A regional bank reached a non-prosecution agreement with the DOJ, admitting to willful failures in its BSA/AML program between 2010 and 2021. According to the agreement, the bank knowingly permitted a decade-long check-kiting scheme run by a father-and-son customer relationship, resulting in roughly $6.3 million in losses to another FI.
Compliance staff moved to shut the accounts down more than once, but bank executives overrode them each time. The father was a friend and former business partner of the bank's chairman and CEO, who resigned in 2019. The bank also backdated loan payments for roughly two years to keep the relationship off delinquency reporting in its call reports, a separate issue layered on top of the AML failure.
This wasn't the bank's only run-in with regulators over this period. It separately settled with the SEC and Federal Reserve in 2022 over deficient internal controls tied to insider lending during the same general timeframe. The bank will pay a fine of $9,057,821.62 plus forfeiture of $736,515, for a total of just over $9.7 million.
A control that leadership can override without consequence isn't really a control. The real test of a strong compliance program is whether escalation authority survives someone senior wanting to look away.
Related: How to Create Dynamic BSA/AML/CFT Risk Assessments
The Federal Reserve issued a proposed rule requiring Board-supervised banks to maintain AML/CFT programs that are risk-based and reasonably designed, aligned with the joint rule FinCEN, the OCC, FDIC, and NCUA proposed together on April 10th. The Fed didn't join that joint proposal, consistent with a pattern of sitting out multi-agency rulemaking.
The Fed's version closely mirrors the April proposal but omits a provision requiring agencies to notify FinCEN 30 days before a "significant" enforcement or supervisory action, and the Fed is asking for comment on whether that notice requirement should be restored. At least one Fed governor has publicly raised concerns about the proposal's standard, suggesting disagreement over FinCEN's role rather than a scheduling gap. A visible split like this between the Fed and the other banking agencies is rare. Comments close September 8th.
Picking the ROAD Act back up from earlier in this update, here's what changes for banks.
The biggest shift is to exam cycles. FIs under $3 billion in assets that are well-capitalized and well-managed currently qualify for an 18-month exam cycle instead of the standard 12 months. That threshold is rising to $6 billion, putting many more community banks into less frequent exam territory.
Brokered deposits change, too. Custodial deposits can now make up to 20% of liabilities without being classified as brokered, provided the bank is well-capitalized, under $10 billion in assets, and holds a CAMELS rating of 1, 2, or 3. The reciprocal deposit exemption is also restructured into a tiered formula, scaling from 50% down to 30% as liabilities grow toward $96.3 billion, meaning more reciprocal deposits can stay off the brokered classification.
Public welfare investment caps also rise from 15% to 20% of capital and surplus for national banks and state member banks. Starting two years after enactment, and every two years after, the Fed and OCC will report those investment amounts to Congress by purpose, type, asset size, and location.
Exam relief is a good problem to have, but it's not a reason to let your compliance management system or ERM program slip. Loop your CFO in on the brokered deposit changes specifically.
Related: Enterprise risk management 101: COSO
The Fed, FDIC, and OCC jointly issued guidance on how examiners and banks should handle highly sensitive information during exams. The statement doesn't name a specific trigger, but it follows a 2023 OCC email breach that exposed more than 150,000 messages, including sensitive financial institution data.
The agencies committed to notifying affected banks within 72 hours of confirming a material compromise of confidential supervisory information, longer than the 36-hour window banks themselves have for reporting cyber incidents. Bank management is now expected to flag which requested documents and data they consider highly sensitive, such as network diagrams or penetration test results, since that kind of material carries heightened risk if exposed.
Examiners will notify banks at the start of an exam that they can raise these concerns. From there, the examiner and bank work out together whether the material qualifies and which protective method applies: on-site review instead of copies, direct digital review from the bank's own systems, or redacted or summarized versions. If examiners still need the material for the supervisory record after that, they need sign-off through their own supervisory chain, and redacted or summary versions may still satisfy the record requirement where legal requirements allow.
This creates an avenue to negotiate how sensitive technical exam requests get fulfilled, along with a defined escalation path if a bank disagrees with an examiner's call on what qualifies. One caveat: the statement explicitly creates no enforceable legal right or benefit for banks. It's a supervisory practice commitment, not a binding rule.
TruStage, the insurance and financial services provider serving most credit unions, took its network offline last month after a cybersecurity incident that's still disrupting access to retirement accounts, insurance claims, and payment protection products for some members. We covered the incident and vendor risk lessons in a separate post, linked below, so we'll focus here on what's new: TruStage now faces a lawsuit, and credit unions have a reporting deadline that isn't waiting on TruStage's timeline.
A Pennsylvania credit union filed a proposed nationwide class action against TruStage, arguing the security it marketed to credit union partners never matched what it had. The case will help answer whether a credit union can shift breach costs back onto a vendor when its security promises don't hold up, and litigators watching the case say a claim like this starts with the contract, which is exactly where credit unions should start their own review too.
Separately, don't assume TruStage's investigation timeline buys you time. NCUA's 72-hour cyber incident reporting rule runs on what your institution knew, not when your vendor finishes its own disclosure. If you have a TruStage relationship and haven't assessed whether that window has already passed, do it now.
Related: When a Vendor Goes Dark: Lessons From the TruStage Incident
Closing out our coverage of the ROAD Act, credit unions get a change to board meeting frequency. The blanket monthly requirement is now tiered: de novo credit unions still meet monthly for their first five years, and lower-rated credit unions stay on that monthly track too. Well-rated credit unions, meaning a composite and management score of 1 or 2, can drop to as few as six meetings a year, with a minimum of one per quarter.
As with the exam cycle change for banks, fewer required meetings shouldn't mean less board oversight. If your board plans to take advantage of the drop from twelve meetings a year to six, you still need a way to keep them informed between meetings, whether that's continuing monthly board packets, a board portal tracking KPIs and KRIs, or some other process. A 1 or 2 management rating can slip to a 3 or 4 quickly if the board takes its foot off the gas just because it's technically allowed to.
The ROAD to Housing Act loosened structural requirements across the board this month, but the AML enforcement and rulemaking covered here send the opposite signal: less oversight burden doesn't mean less scrutiny of how institutions behave day to day. Keep that distinction in mind as you work through what's changing and what isn't.
Want a deeper dive into other risk areas facing FIs in 2026? Watch our webinar Emerging Risks in Banking: Q3 2026 Update.