Regulatory Calendar 2026-2027 for LOS Buyers
Published on: 2026-05-12 · Updated: 2026-09-30
Keeping track of the regulatory landscape is a critical function for any lending institution. For those evaluating a new Loan Origination System (LOS), understanding the compliance roadmap for the next 18-24 months is essential. A new LOS is a significant investment in both capital and time; choosing a platform that isn’t prepared for upcoming deadlines is a recipe for disaster.
This guide provides a clear, operator-focused calendar of key regulatory deadlines and changes through 2028. We cover what each rule change means, when it takes effect, what it implies for your LOS architecture, and what you need to ask vendors during your evaluation.
Status check, September 30, 2026: 2026 rewrote most of this calendar. The CFPB replaced the Section 1071 rule with a narrower version and a single January 1, 2028 compliance date. Section 1033 compliance dates are stayed by a federal court, and the Bureau's reconsideration proposal has been under OIRA review since August 4, 2026. The OCC and FDIC did not finalize the rescission of the 2023 CRA modernization rule and on July 31, 2026 proposed amendments to the 1995 framework instead. The EU moved its AI Act high-risk application dates by 16 months for standalone systems and 12 months for AI embedded in regulated products. The federal banking agencies replaced SR 11-7 with revised model risk guidance on April 17, 2026, and the CFPB's amendments to Regulation B took effect July 21, 2026. Every date below reflects the current state, not the original rulebook. The practical takeaway for buyers: the deadlines moved, but every one of these rules still defines the data and API capabilities your next LOS needs, and the runway is the cheapest time to build them.
Key Compliance Deadlines & Rule Changes
CRA Modernization
Status: 2023 rule enjoined and never applied. An OCC and FDIC proposal to amend the 1995 framework is open for comment through October 13, 2026. Exams continue under the 1995 framework.
The 2023 CRA modernization rule from the Federal Reserve, OCC, and FDIC was nominally applicable January 1, 2026, but a federal court enjoined it before it went into effect and it never took hold. On July 16, 2025 the three agencies proposed rescinding the 2023 rule (published July 18, 2025) and reinstating the framework that existed before it; the comment period closed August 18, 2025. The OCC and FDIC did not finalize that rescission. On July 31, 2026 they issued a new proposal, published August 12, 2026, that keeps the framework adopted in 1995 and amends it. According to the FDIC's summary, the proposal would set the asset tiers at below $1 billion for a small bank, $1 billion to $10 billion for an intermediate bank, and above $10 billion for a large bank, and it does not propose significant changes to the assessment area framework. Comments are due October 13, 2026. The Federal Reserve did not join the proposal. Also on July 31, 2026, the OCC and FDIC asked the court to vacate the portions of the 2023 rule that apply to them. Institutions are being examined under the 1995 framework in the meantime.
LOS Impact: Do not buy CRA modules against the 2023 rule's assessment-area math; the OCC and FDIC have asked the court to vacate it. Geocoding, lending-activity reporting, and clean data extracts remain table stakes under the 1995 framework that exams currently use. Under the proposal, banks with $10 billion or less in assets would be subject to fewer data collection, maintenance, and reporting requirements, so ask vendors how their CRA reporting handles a change of size tier, and be skeptical of any roadmap slide still selling "new CRA framework readiness."
CFPB 1033 (Open Banking / Personal Financial Data Rights)
Status: Compliance dates stayed by court order; reconsideration proposal under OIRA review since August 4, 2026 and not yet published.
The CFPB's Section 1033 rule mandates that financial institutions make consumer data available to consumers and authorized third parties through secure APIs. The original phased compliance dates started April 1, 2026 for the largest providers, but the court in Forcht Bank v. CFPB stayed those dates on October 29, 2025 (CFPB compliance page), and the Bureau opened a reconsideration in August 2025 with plans to substantially revise the rule. OIRA received the CFPB's reconsideration proposal for review on August 4, 2026. As of September 30, 2026 no proposed rule had been published in the Federal Register, so the revised requirements and compliance dates are not yet public. The April 1, 2026 date passed without functioning as an enforcement trigger. Our Section 1033 guide covers what this pause does and does not change.
LOS Impact: Treat this as a pause, not a cancellation. Consumer-directed data sharing is still the direction of travel, and the work that survives any rewrite is the boring kind: secure, well-documented APIs, clear consent management, and named data-access ownership across vendors. During diligence, focus on the platform's API strategy rather than a specific 1033 checkbox.
CFPB Section 1071 (Small Business Lending Data)
Compliance Date: January 1, 2028, uniform for all covered lenders under the revised final rule.
This rule requires lenders to collect and report data on credit applications for small businesses. On May 1, 2026 the CFPB issued a revised final rule that replaced the old tiered rollout (which would have started data collection July 1, 2026 for the highest-volume lenders) with a single compliance date of January 1, 2028. Coverage narrowed sharply: only lenders originating at least 1,000 covered small business credit transactions in each of the two preceding calendar years are covered, between approximately 172 and 181 depository institutions by the CFPB's own estimate. The revision also lowered the small business definition from $5 million to $1 million in gross annual revenue, excluded merchant cash advances, agricultural lending, and loans of $1,000 or less, removed LGBTQI+-owned business status and the disaggregated race and ethnicity categories, and dropped five data points, including pricing and denial reasons. The rule took effect June 30, 2026. Litigation over the rule continues in several courts, so treat even the 2028 date as subject to movement. Our 1071 readiness guide tracks how the major LOS vendors line up against the revised rule.
LOS Impact: If you clear the 1,000-origination threshold, this is still a real data collection and reporting build: application-time capture, demographic-data firewall, and Small Business Lending Application Register (SBLAR) generation. If you are under the threshold, the calculus changed; you may still want the data discipline, but the regulatory forcing function is gone. Either way, ask vendors to demonstrate their 1071 workflow against the revised rule, not the 2023 version their slides were built on.
EU AI Act
Compliance Dates: December 2, 2027 for standalone high-risk systems (including credit scoring); August 2, 2028 for AI embedded in regulated products.
While an EU regulation, the AI Act has extraterritorial reach. If your institution or LOS vendor uses AI or machine learning for credit decisioning (a "high-risk" use case) and serves customers in the EU, you must comply. The original dates moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, received final Council approval on June 29, 2026 and was published in the Official Journal on July 24, 2026. It postponed high-risk obligations from August 2, 2026 to December 2, 2027 for standalone systems (16 months) and from August 2, 2027 to August 2, 2028 for AI embedded in regulated products (12 months), and simplified parts of the compliance regime. The Act's core requirements for transparency, risk management, and human oversight are unchanged.
LOS Impact: If your LOS uses an AI-powered underwriting engine, your vendor must be able to provide the documentation and controls required by the Act. This includes details on the model's logic, data sources, and performance. The delay adds time and leaves the obligations in place. US model risk guidance changed in the same period: see the SR 26-2 entry below. Ask vendors about their AI governance framework and their strategy for complying with the EU AI Act if you have any European operations.
Model Risk Management Guidance (SR 26-2 / OCC Bulletin 2026-13)
Status: Issued April 17, 2026. Supersedes SR 11-7 and OCC Bulletin 2011-12.
On April 17, 2026 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance as SR 26-2 and OCC Bulletin 2026-13. It supersedes SR 11-7, issued in 2011, and the 2021 interagency statement on models used for BSA/AML compliance. The guidance carries scope limits that matter for LOS buyers. Generative AI and agentic AI models are outside its scope. The agencies expect it to be most relevant to banking organizations with more than $30 billion in total assets. The OCC bulletin states that the guidance does not set enforceable standards and that non-compliance "will not result in supervisory criticism against a banking organization." The agencies also said they plan to issue a request for information on banks' use of AI, including generative and agentic AI.
LOS Impact: An LOS or underwriting tool built on generative AI is outside this guidance, and vendor materials that cite SR 11-7 refer to superseded guidance. Ask vendors which guidance their model documentation is written against. Examiners can still review a bank's use of AI under third-party risk management guidance, fair lending law, and general safety and soundness authority, so model documentation, validation evidence, and audit trails remain worth requiring.
Reputation Risk in Supervision
Effective Dates: June 9, 2026 for the OCC and FDIC; July 27, 2026 for the NCUA.
The OCC and FDIC adopted a final rule (91 FR 18279) that removes reputation risk from their supervisory programs and prohibits the agencies from criticizing or taking adverse action against an institution on the basis of reputation risk. The NCUA's final rule (91 FR 38270) took effect July 27, 2026. The Federal Reserve proposed its own rule on February 26, 2026 and had not published a final rule in the Federal Register as of September 30, 2026.
LOS Impact: These rules change what examiners may cite and leave LOS data, disclosure, and reporting requirements as they were.
Regulation B: Disparate Impact, Discouragement, and Special Purpose Credit Programs
Effective Date: July 21, 2026.
The CFPB's final rule (91 FR 21620, published April 22, 2026) amended the Regulation B provisions on disparate impact, discouragement of applicants and prospective applicants, and special purpose credit programs. The rule provides that ECOA does not authorize disparate-impact liability, which Regulation B had called the effects test. It took effect July 21, 2026. A challenge to the rule, National Fair Housing Alliance v. CFPB, No. 1:26-cv-01820, is pending in the U.S. District Court for the District of Columbia (complaint).
LOS Impact: The prohibition on disparate treatment and the adverse action notice requirements in 12 CFR 1002.9 are unchanged. Keep reason-code and decision-documentation requirements in your LOS evaluation. Check with counsel before removing disparate-impact testing from a fair lending program, because the rule is in litigation and mortgage lending is also subject to the Fair Housing Act.
Third-Party Risk Management Guidance (Proposed)
Status: Proposed September 15, 2026. Comments due November 16, 2026.
The OCC, Federal Reserve, FDIC, and NCUA published proposed third-party risk management guidance (91 FR 58536) on September 15, 2026. The notice states that any finalized guidance would replace the 2023 Interagency Guidance on Third-Party Relationships and its supplemental resources. The proposal discusses matching third-party risk management practices to the assessed risk of each relationship and tailoring them to the organization's size, complexity, and risk profile. The Federal Reserve published a separate proposed guide for traditional community banking organizations the same day. The 2023 guidance stays in effect while the proposal is open.
LOS Impact: An LOS purchase is a third-party relationship, so vendor due diligence, contract terms, and ongoing monitoring fall under this guidance. Build diligence files to the 2023 guidance for now, and wait for the final version before rewriting vendor-management policy.
Colorado SB 26-189 (Automated Decision-Making Technology)
Effective Date: January 1, 2027.
Colorado's SB 26-189 repealed and reenacted the consumer protections for artificial intelligence systems that SB 24-205 created in 2024. The act covers automated decision-making technology used to materially influence a consequential decision, a category that includes decisions on an individual's access to financial or lending services. Starting January 1, 2027, developers must give deployers technical documentation describing intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Deployers must give consumers notice at the point of interaction and, within 30 days after a consequential decision that results in an adverse outcome, a plain language description of the technology's role.
LOS Impact: If you lend to Colorado consumers and your LOS or decisioning vendor uses automated decision-making technology in credit decisions, ask the vendor for the developer documentation the act requires and confirm which system produces the consumer notice and the adverse-outcome description. Confirm with counsel whether the act applies to your institution.
Ongoing Compliance: Stable but Critical Rules
Not every regulation has a looming deadline. The following rules are largely stable, but their proper implementation in an LOS remains a critical evaluation point.
HMDA (Home Mortgage Disclosure Act)
For 2026, the primary update to HMDA is the routine annual adjustment of the asset-size exemption threshold, which rose to $59 million effective January 7, 2026. No major changes to data fields or submission processes are expected. However, robust HMDA data collection and LAR generation remain a core competency for any mortgage LOS. Your evaluation should confirm the platform is up-to-date with the latest Filing Instructions Guide (FIG).
TRID (TILA-RESPA Integrated Disclosure)
The TRID rule, which governs the Loan Estimate and Closing Disclosure, has no rule changes scheduled for 2026-2027. The CFPB did publish a request for information on July 9, 2026 asking about industry and consumer burdens from the integrated disclosures, with comments due August 10, 2026. As of September 30, 2026 the Bureau had not published a proposed rule. Compliance hinges on using the correct forms and accurately populating them. Your LOS must ensure pixel-perfect generation of these critical disclosures and handle the timing and delivery requirements flawlessly.
State-Level Commercial Financing Disclosures
States like California, New York, and Utah have enacted their own "TILA-like" disclosure requirements for commercial financing. These laws have been in effect for several years but are a key consideration for lenders operating in those states. An LOS serving commercial clients must be able to generate these state-specific disclosures accurately.