Regulatory Calendar 2026-2027 for LOS Buyers

Published on: 2026-05-12 · Updated: 2026-07-19

Keeping track of the regulatory landscape is a critical function for any lending institution. For those evaluating a new Loan Origination System (LOS), understanding the compliance roadmap for the next 18-24 months is essential. A new LOS is a significant investment in both capital and time; choosing a platform that isn’t prepared for upcoming deadlines is a recipe for disaster.

This guide provides a clear, operator-focused calendar of key regulatory deadlines and changes through 2028. We cover what each rule change means, when it takes effect, what it implies for your LOS architecture, and what you need to ask vendors during your evaluation.

Status check, July 2026: the first half of 2026 rewrote most of this calendar. The CFPB replaced the Section 1071 rule with a narrower version and a single January 1, 2028 compliance date. Section 1033 compliance dates are stayed by a federal court while the Bureau rewrites the rule. The banking agencies are rescinding the 2023 CRA modernization rule. And the EU pushed its AI Act high-risk deadlines out by 16-24 months. Every date below reflects the current state, not the original rulebook. The practical takeaway for buyers: the deadlines moved, but every one of these rules still defines the data and API capabilities your next LOS needs, and the runway is the cheapest time to build them.

Key Compliance Deadlines & Rule Changes

CRA Modernization

Status: Being rescinded. Exams continue under the pre-2023 framework.

The 2023 CRA modernization rule from the Federal Reserve, OCC, and FDIC was nominally applicable January 1, 2026, but it never took hold. In June 2025 the three agencies proposed rescinding the 2023 rule and reinstating the framework that existed before it; the comment period closed August 18, 2025 and a final rescission is pending. In the meantime, institutions are being examined under the pre-2023 regulations.

LOS Impact: Do not buy CRA modules against the 2023 rule's assessment-area math; that framework is going away. Geocoding, lending-activity reporting, and clean data extracts remain table stakes under the 1995-era framework that exams currently use. Ask vendors how quickly their CRA reporting adapts when the rescission finalizes, and be skeptical of any roadmap slide still selling "new CRA framework readiness."

CFPB 1033 (Open Banking / Personal Financial Data Rights)

Status: Compliance dates stayed by court order; rule under reconsideration.

The CFPB's Section 1033 rule mandates that financial institutions make consumer data available to consumers and authorized third parties through secure APIs. The original phased compliance dates started April 1, 2026 for the largest providers, but those dates were stayed by the court in Forcht Bank v. CFPB, and the Bureau opened a reconsideration in August 2025 with plans to substantially revise the rule. The first deadline is not functioning as a live enforcement trigger today. Our Section 1033 guide covers what this pause does and does not change.

LOS Impact: Treat this as a pause, not a cancellation. Consumer-directed data sharing is still the direction of travel, and the work that survives any rewrite is the boring kind: secure, well-documented APIs, clear consent management, and named data-access ownership across vendors. During diligence, focus on the platform's API strategy rather than a specific 1033 checkbox.

CFPB Section 1071 (Small Business Lending Data)

Compliance Date: January 1, 2028, uniform for all covered lenders under the revised final rule.

This rule requires lenders to collect and report data on credit applications for small businesses. On May 1, 2026 the CFPB issued a revised final rule that replaced the old tiered rollout (which would have started data collection July 1, 2026 for the highest-volume lenders) with a single compliance date of January 1, 2028. Coverage narrowed sharply: only lenders originating at least 1,000 covered small business credit transactions in each of the two preceding calendar years are covered, roughly 170-180 depository institutions by the CFPB's own estimate. The revision also dropped five data points, including pricing and denial reasons. Litigation over the rule continues in several courts, so treat even the 2028 date as subject to movement. Our 1071 readiness guide tracks how the major LOS vendors line up against the revised rule.

LOS Impact: If you clear the 1,000-origination threshold, this is still a real data collection and reporting build: application-time capture, demographic-data firewall, and Small Business Lending Application Register (SBLAR) generation. If you are under the threshold, the calculus changed; you may still want the data discipline, but the regulatory forcing function is gone. Either way, ask vendors to demonstrate their 1071 workflow against the revised rule, not the 2023 version their slides were built on.

EU AI Act

Compliance Dates: December 2, 2027 for standalone high-risk systems (including credit scoring); August 2, 2028 for AI embedded in regulated products.

While an EU regulation, the AI Act has extraterritorial reach. If your institution or LOS vendor uses AI or machine learning for credit decisioning (a "high-risk" use case) and serves customers in the EU, you must comply. The original August 2, 2026 deadline moved: the EU's Digital Omnibus package, given final approval in June 2026, postponed high-risk obligations by 16-24 months and simplified parts of the compliance regime. The Act's core requirements for transparency, risk management, and human oversight are unchanged.

LOS Impact: If your LOS uses an AI-powered underwriting engine, your vendor must be able to provide the documentation and controls required by the Act. This includes details on the model's logic, data sources, and performance. The delay is breathing room, not a reprieve; US examiners are asking many of the same model-governance questions today under SR 11-7. Ask vendors about their AI governance framework and their strategy for complying with the EU AI Act if you have any European operations.

Ongoing Compliance: Stable but Critical Rules

Not every regulation has a looming deadline. The following rules are largely stable, but their proper implementation in an LOS remains a critical evaluation point.

HMDA (Home Mortgage Disclosure Act)

For 2026, the primary update to HMDA is the routine annual adjustment of the asset-size exemption threshold. No major changes to data fields or submission processes are expected. However, robust HMDA data collection and LAR generation remain a core competency for any mortgage LOS. Your evaluation should confirm the platform is up-to-date with the latest Filing Instructions Guide (FIG).

TRID (TILA-RESPA Integrated Disclosure)

The TRID rule, which governs the Loan Estimate and Closing Disclosure, is also stable. There are no significant updates scheduled for 2026-2027. Compliance hinges on using the correct forms and accurately populating them. Your LOS must ensure pixel-perfect generation of these critical disclosures and handle the timing and delivery requirements flawlessly.

State-Level Commercial Financing Disclosures

States like California, New York, and Utah have enacted their own "TILA-like" disclosure requirements for commercial financing. These laws have been in effect for several years but are a key consideration for lenders operating in those states. An LOS serving commercial clients must be able to generate these state-specific disclosures accurately.