Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Compliance Strategy

H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.

The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.

By Rebecca Leung · September 5, 2026 ·
Table of Contents

TL;DR

  • H.R. 10184, introduced August 31, 2026, proposes to restructure the CFPB through five major changes: raising the supervision threshold from $10B to $30B, cutting maximum daily penalties from $1M to $50,120 for knowing violations, narrowing the UDAAP “abusive” standard, subjecting the bureau to congressional appropriations, and creating a small-dollar credit safe harbor
  • No Democratic cosponsors; the bill faces significant Senate hurdles
  • Even if it doesn’t pass, the provisions signal the direction of CFPB enforcement and supervisory posture under the current administration
  • State enforcement fills the gap when federal enforcement recedes — and has been doing so actively in 2026

The CFPB has faced structural reform proposals in every Congress since 2011. Most didn’t pass. H.R. 10184, the Consumer Financial Protection Accountability and Reform Act of 2026, is more credible than most — introduced by the chairs of the House Financial Services Committee and its Financial Institutions Subcommittee, with 29 cosponsors and an HFSC roundtable already in the books.

Whether it becomes law is a separate question. What matters for compliance teams right now is what the bill’s provisions reveal about where CFPB supervision and enforcement are heading — and how to position your program for a regulatory environment that’s already shifted significantly from 2023.

This follows the discussion draft we analyzed in July, but H.R. 10184 is a formal bill with sharper provisions. The supervision threshold jumped from $21 billion in the discussion draft to $30 billion. The penalty structure is more specific. The UDAAP changes are more explicit. The roundtable signals committee movement.

The Five Structural Changes in H.R. 10184

1. The $30 Billion Supervision Threshold

The current CFPB supervision threshold is $10 billion in total assets. Any bank or credit union above $10 billion is subject to CFPB examination in addition to its prudential regulator. H.R. 10184 would raise that threshold to $30 billion, with adjustments starting in 2031 based on nominal GDP growth.

The practical effect: institutions between $10B and $30B — mid-sized regional banks, credit unions, and some fintech bank partners — would lose CFPB supervisory jurisdiction. Consumer compliance supervision would revert to the OCC, FDIC, NCUA, or state regulators depending on charter type.

Institutions above $30B could also elect to have their prudential regulator conduct consumer compliance supervision, even though they’d remain above the threshold. The exception: GSIBs stay under CFPB regardless. And the CFPB retains the ability to intervene when it finds heightened consumer risk or inadequate prudential supervision above the threshold.

For fintechs operating through BaaS sponsor banks that fall in the $10B–$30B range, this would change who supervises your bank partner’s consumer compliance program. The OCC and FDIC are not weaker supervisors on consumer protection — but they operate differently from the CFPB, and your bank partner’s exam priorities and remediation timelines may shift.

2. Civil Money Penalty Reduction

The CFPB’s current civil money penalty structure has three tiers: up to $5,000 per day for unknowing violations, up to $25,000 per day for reckless violations, and up to $1,000,000 per day for knowing violations. Those daily caps have historically enabled the CFPB to impose penalties measured in the tens or hundreds of millions for multi-year violations.

H.R. 10184 would cut the maximum daily penalty for knowing violations from $1,000,000 to $50,120. That’s a 95% reduction in the ceiling. Section 501 of the bill also removes the bureau’s authority to impose civil money penalties for violations that were not committed knowingly or recklessly — eliminating the lowest tier for unknowing violations entirely.

The practical effect of the $50,120 cap is context-dependent. For a one-week violation, $50,120 per day produces a $350,840 penalty. For a three-year violation, even at $50,120 per day, the total is over $55 million. The ceiling matters most when violation duration is short and the CFPB is using the daily cap as a deterrent against large institutions.

3. Narrowing the UDAAP “Abusive” Standard

UDAAP — unfair, deceptive, or abusive acts or practices — is the CFPB’s broadest enforcement authority. The “abusive” prong has been particularly contested because the Dodd-Frank Act defined it in ways that gave the CFPB significant interpretive flexibility.

H.R. 10184 would codify a narrower standard: a practice may be deemed abusive only where there is risk of substantial injury not outweighed by countervailing benefits. This mirrors the standard for “unfair” practices under FTC Act section 5 and effectively harmonizes the two standards.

More significantly, the bill would prohibit the CFPB from interpreting UDAAP to include discriminatory practices. This reverses the March 2022 UDAAP examination manual update, which the Biden-era CFPB used to extend UDAAP authority to fair lending enforcement in a way that bypassed the more specific requirements of ECOA and HMDA. The reversal would effectively end the CFPB’s ability to bring UDAAP claims based on disparate impact or discriminatory effect without a separate ECOA hook.

For compliance programs, this matters in two directions. If the bill passes, the most aggressive UDAAP theory — discrimination as unfair or abusive practice — goes away at the federal level. But state UDAP laws remain active, state AGs remain aggressive, and the ECOA/Regulation B framework still applies to any creditor making credit decisions. The state enforcement wave we documented in July doesn’t slow down because the CFPB’s UDAAP scope narrows.

4. Congressional Appropriations

The CFPB’s independence from the appropriations process — funding through Federal Reserve transfers — was central to its design as an agency insulated from political budget pressure. H.R. 10184 ends that: the bureau would be funded through annual congressional appropriations, like the OCC or any other executive agency.

This is a structural change with an uncertain timeline for impact. If the bill passes, the CFPB’s budget in fiscal year 2028 would be set by Congress, not by the Fed’s earnings. Years of divided-government budgeting demonstrate what that can mean for agency staffing, enforcement capacity, and rulemaking bandwidth.

For compliance teams, the relevant implication isn’t the dollar amount of the CFPB’s budget — it’s the volatility. An agency whose funding depends on the annual appropriations cycle can experience significant staffing and capacity swings based on elections, budget negotiations, and continuing resolution politics. The new enforcement principles the CFPB adopted earlier this year already reflect a more restrained posture; appropriations dependence would entrench that posture in a way that’s harder to reverse quickly.

5. Small-Dollar Credit Safe Harbor

The bill would create a safe harbor from CFPB enforcement for products classified as small-dollar credit. This is a direct response to years of CFPB attention to payday lending, earned wage access, installment credit, and other short-term consumer credit products.

The safe harbor provision matters for fintech compliance teams in a specific way: it signals that the current administration and House Republican majority view short-term consumer credit as a category deserving protection from CFPB enforcement — not aggressive supervision. But as the Colorado EarnIn case demonstrates, federal enforcement posture doesn’t determine state enforcement posture. A CFPB safe harbor wouldn’t have changed Colorado AG Phil Weiser’s decision to file suit for $16 million in tips and fees.

What This Bill Reveals About the 2026 Regulatory Environment

The bill’s specific provisions are less important than what they reveal about the regulatory philosophy behind them. Three patterns emerge:

Materiality as the governing standard. Every major regulatory reform initiative of 2026 — the OCC/FDIC unsafe or unsound final rule, the OCC violations NPRM, and now H.R. 10184 — is built around the same idea: enforcement and supervision should focus on material risk to consumers and financial institutions, not on procedural compliance for its own sake. The $30B threshold, the penalty reduction, and the UDAAP narrowing are all applications of that principle. Whether or not H.R. 10184 passes, compliance programs that are built around documentation-first, process-completeness frameworks will face increasing pressure to demonstrate actual risk outcomes.

State enforcement is the backstop. Every provision in H.R. 10184 that reduces federal enforcement exposure for a product or institution has a parallel state enforcement gap it does not fill. The UDAAP discrimination prohibition doesn’t touch ECOA. The small-dollar credit safe harbor doesn’t touch state UCCC statutes. The supervision threshold change doesn’t touch state-chartered examination. The last two years of state AG enforcement — against EarnIn, Block, various EWA providers, and others — has been conducted under state law frameworks that are entirely independent of whatever the CFPB does.

Regulatory uncertainty creates compliance program design risk. If your compliance program was designed around the assumption of CFPB examination for institutions between $10B and $30B, and that assumption changes, you need to understand what the prudential regulator’s consumer compliance exam looks like and how it differs. If your UDAAP risk assessment was built around the expanded discrimination-as-UDAAP theory, you need to know which risks survive a narrowed UDAAP standard. Building a compliance program to a moving regulatory target is harder than building to a stable one — which means the compliance planning horizon matters as much as the current rule.

How to Adapt Your Compliance Strategy for the Current Environment

Regardless of whether H.R. 10184 becomes law, three program adjustments are worth making now:

Stress-test your UDAAP risk framework for state exposure. Map every UDAAP-adjacent risk in your program against state UDAP statutes in your operational footprint. Which risks survive a narrowed federal UDAAP standard at the state level? Fair lending disparate impact, fee disclosure opacity, and deceptive marketing claims are all actively pursued by state AGs under state statutes — your program should be tracking them under those frameworks, not just federal ones.

Understand your bank partner’s supervisor. If you operate through a BaaS sponsor bank in the $10B–$30B range, know who would supervise its consumer compliance program if CFPB jurisdiction shifts to the prudential regulator. OCC and FDIC consumer compliance examinations are substantive — but they have different emphasis, timing, and remediation culture than CFPB examinations. Your bank oversight and third-party risk program should reflect that.

Use a risk control self-assessment framework to identify material-risk exposures. The regulatory shift toward materiality-based supervision means your RCSA needs to surface which consumer compliance risks have the most potential for consumer harm, financial impact, or systemic exposure — those are the ones that will draw examiner attention regardless of the CFPB’s jurisdiction. A well-structured RCSA maps your control environment to your actual risk exposures, not to a regulatory checklist, and it’s the tool that holds up when the regulatory checklist changes.

What to Watch Before Year-End

H.R. 10184 will move or not based on two variables: Senate dynamics and the appropriations calendar. The bill has no Democratic cosponsors, which means Senate passage would require 60 votes under the filibuster or nuclear option use. Neither is on a clear timeline.

What is on a clear timeline: the OCC/FDIC final rule on unsafe/unsound practices takes effect November 2, 2026. The OCC violations NPRM closes for comment October 1. The Fed’s LFI supervisory posture continues to prioritize private credit and NDFI exposure. Whatever happens to H.R. 10184 legislatively, the supervisory environment your compliance program operates in is already materially different from 12 months ago.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is H.R. 10184 and where does it stand in the legislative process?
H.R. 10184, the Consumer Financial Protection Accountability and Reform Act of 2026, was introduced August 31, 2026 by House Financial Services Committee Chairman French Hill (R-AR) and Financial Institutions Subcommittee Chairman Andy Barr (R-KY), with 29 Republican cosponsors and no Democratic cosponsors. The bill had an HFSC roundtable on September 3 and is in committee as of September 2026. Given the partisan divide, the bill would need to navigate Senate passage to become law. Its provisions reflect the direction of the current regulatory environment regardless of whether it passes as written.
Which institutions would lose CFPB supervisory jurisdiction under the proposed $30 billion threshold?
Depository institutions — banks and credit unions — with between $10 billion and $30 billion in total assets would no longer be subject to CFPB supervisory examinations under the bill. Supervisory jurisdiction would revert to their prudential regulators: the OCC for national banks in that range, the FDIC for state nonmember banks, state regulators for state member banks, and NCUA for credit unions. Institutions above $30 billion could also elect to have their prudential regulator conduct consumer compliance supervision. Global systemically important banks (GSIBs) would remain under CFPB jurisdiction regardless.
How does the UDAAP change affect financial services companies that are not banks?
The UDAAP changes would apply broadly to any entity under CFPB enforcement jurisdiction, not just banks. The key changes: (1) the 'abusive' prong would require substantial injury not outweighed by countervailing benefits — raising the standard for finding a practice abusive; (2) the CFPB would be prohibited from treating discrimination as a UDAAP violation, reversing the March 2022 UDAAP exam manual update. Nonbank fintechs, payment companies, and consumer lenders would all be affected. UDAAP is one of the CFPB's most heavily used enforcement authorities, so narrowing the standard has broad practical effects.
What does 'small-dollar credit safe harbor' mean in the bill?
The bill would add a safe harbor from CFPB enforcement for products characterized as 'small-dollar credit.' The bill text does not provide a final definition in the summary available, but the intent is to protect short-term, small-dollar products like payday loans and installment credit from CFPB enforcement actions. This does not immunize those products from state enforcement — the EarnIn lawsuit Colorado filed on August 27 is a state action and would be unaffected.
What happens to the CFPB's funding under H.R. 10184?
Currently, the CFPB is funded through transfers from the Federal Reserve's earnings — up to 12% of the Fed's total operating expenses — giving the bureau independent funding outside the annual appropriations process. H.R. 10184 would eliminate Fed funding and subject the CFPB to annual congressional appropriations. This would give Congress direct control over the bureau's budget each fiscal year, the most significant structural change proposed by the bill.
Should companies below the $30 billion threshold stop investing in CFPB compliance programs?
No. Even if H.R. 10184 passes exactly as written, state enforcement agencies, state attorneys general, and prudential regulators would still enforce consumer protection laws against institutions of any size. State AGs have been increasingly active — the Colorado EarnIn case is one example, and similar actions are pending in multiple states. The CFPB's civil money penalty authority also wouldn't disappear for institutions that remain under enforcement jurisdiction even if supervisory examination jurisdiction shifts.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

◆ Keep reading

Related posts.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.