Let's be honest: most commercial lenders tune out when they hear the word "regulation." But ignoring it could cost far more than time or paperwork.
The regulatory landscape is changing fast. Section 1071 introduces new data collection requirements for small businesses. Fair lending enforcement is evolving with increased scrutiny on disparate treatment. State regulators are stepping into perceived gaps left by federal agencies. Also, emerging issues like debanking are creating compliance challenges that didn't exist a few years ago.
With a solid understanding of the fundamentals and what the future holds, you'll be well equipped to explain to your credit committee, your examiner, or your board why compliance is not just a checkbox — it's a critical part of running a safe, sound, and competitive commercial lending business.
Related: Lending Compliance Q&A for Lenders
Table of Contents
Commercial lending regulations are the federal and state rules that govern how financial institutions offer, underwrite, document, and service credit for business purposes. And while commercial loans carry fewer prescriptive requirements than consumer loans, they are still regulated.
A common misconception is that laws like the Equal Credit Opportunity Act (ECOA), the Flood Disaster Protection Act, or the Bank Secrecy Act (BSA) don’t meaningfully apply to commercial lending. In practice, they do — just differently.
These regulations shape how lenders collect applicant data, verify customers, manage collateral in flood zones, monitor transactions, document decisions, and respond to higher-risk activities. Overlooking these obligations can expose an institution to regulatory findings and reputational risk.
Related: What is Fair Lending? Program Essentials, Rules, and More
Too often, commercial lenders set regulations aside in favor of ad hoc, personalized commercial lending activities — only to find that approach costs more in the long run.
Commercial lending regulations do more than mitigate compliance risk. How your institution meets these obligations today can shape safety and soundness, competitive position, and long-term community impact:
Related: Ask the Author: Where Does Risk Management Go Wrong?
Compliance isn’t separate from lending — it’s baked into every step of the loan lifecycle. Understanding where compliance requirements exist helps you identify where violations occur and what they cost your FI in time and resources. Let’s take a look at some examples of how compliance impacts commercial lending.
Related: Is Fair Lending Regression Analysis the Right Fit for Your FI?
To stay compliant, you need to know which regulations apply. Commercial lending is mainly governed by consumer protection and safety and soundness rules. Most consumer protection laws exempt commercial credit, but some address discrimination in any credit situation. Safety and soundness regulations mandate independent appraisals and set limits on loan quantities based on an institution’s capital.
As the regulatory environment changes, so do the risk areas that require focus in 2026 and the years to come.
Section 1071 of the Dodd-Frank Act, which requires FIs to collect and report data on small, women-owned, and minority-owned business applications for businesses with gross annual revenue of $5 million or less, has been in regulatory limbo. In November 2025, the CFPB released a new proposed rule that would move the Section 1071 compliance deadline to January 1, 2028, and broadly adjust the scope of 1071 compliance obligations.
Why It Matters Now: Data-collection expectations around application, approval, and pricing transparency are likely to persist in some form. Use this time to map workflows, formalize application processes, identify data gaps, and test demographic data collection methods. Some states (e.g., New York) have their own Section 1071-like requirements that take effect in 2026.
A 2025 Executive Order directed federal agencies to stop using disparate impact theory to enforce civil rights and fairness laws, shifting the focus to intentional discrimination (or disparate treatment) rather than statistical disparities.
Why It Matters Now: Disparate impact hasn’t disappeared. State regulators, attorneys general, and plaintiffs' attorneys are filling the vacuum with state-level discrimination laws modeled on disparate impact standards. The risk has simply moved jurisdiction. Institutions that abandon their fair lending analytics will find themselves unprepared when state enforcement arrives.
Following another executive order, debanking has become one of the most politically charged issues in financial services. In August, the Small Business Administration (SBA) sent letters to over 5,000 institutions demanding they reinstate customers by December 5, 2025, and compliance reports by January 5, 2026, or face punitive measures.
Why It Matters Now: FIs, including commercial lenders, must be prepared to demonstrate fair banking practices. Review account management policies to ensure decisions are based on measurable risk factors, maintain detailed records to justify account denials or closures, and refresh staff training on the Right to Financial Privacy Act.
There’s no one-size-fits-all approach to compliance management, but institutions focused on commercial lending must stay current on applicable laws and regulations and develop policies and procedures that reinforce their strengths while addressing gaps.
Here are the key elements commercial lenders should prioritize when building their program:
Related: 4 Ways to Streamline Your CMS
Compliance doesn't have to be a barrier to lending — it's the foundation of sustainable growth. When you build processes that get it right the first time, you avoid the drag of post-closing corrections and free your team to focus on long-term relationship development. After all, commercial lending is fundamentally relationship-driven, and consistency, fairness, and transparency are what make you a trusted partner.
Now is the right moment to evaluate your current posture and take proactive steps to strengthen your commercial lending compliance program.
The right compliance software can help you streamline your compliance processes. Learn what to look for in a CMS in our free buyer's guide.