States

Showing: 1 - 10 of 20 Articles

California Law Strengthens Supervision of Mortgage Lenders for Fair Lending Compliance

California Gov. Gavin Newson recently signed the California Fair Lending Examination Act into law. The legislation requires the California Department of Financial Protection and Innovation (DFPI) to periodically examine banks, credit unions, and residential mortgage lenders and servicer licensees for compliance with fair lending laws. The act takes effect on January 1, 2027. The act is a recent example of states expanding their regulatory authority …

FinCEN, Other Regulators Clarify Use of Mobile Driver’s Licenses Under CIP Rule

On September 8, 2026, FinCEN, the Federal Deposit Insurance Corporation (FDIC), Federal Reserve, National Credit Union Administration (NCUA) and Office of the Comptroller of the Currency (OCC) jointly issued two new FAQs addressing how banks and credit unions may treat state-issued mobile driver’s licenses (mDLs) and other forms of government-issued digital credentials under the Customer Identification Program (CIP) Rule. The agencies also updated an existing …

NYDFS Issues Real-Time Alert on Software Exploitation

On August 11, 2026, the New York Department of Financial Services (NYDFS) issued an Industry Letter notifying its covered entities about an ongoing cybersecurity campaign targeting a known vulnerability in a monitoring and management software for managed service providers (MSPs) and IT departments. The vendor that provides the software published an update on August 10 informing its customers of the incident and providing further information …

NYDFS Proposes Rules to Enact Buy Now, Pay Later Statute

On July 15, 2026, the New York Department of Financial Services (NYDFS) issued a formal notice of proposed rulemaking to implement the New York Buy-Now-Pay-Later Act (BNPLA), enacted in May 2025. The first-of-its-kind legislation to regulate buy now, pay later (BNPL) products, the BNPLA will go into effect after the adoption of NYDFS regulations. The proposed rulemaking comes on the heels of a July 2025 …

The New Colorado AI Act: What Financial Institutions Need to Know

Colorado recently upended its landmark artificial intelligence legislation, just a month before the bill’s effective date and with days left in the legislative session. Senate Bill 26-189 (SB 189) repeals and replaces Senate Bill 24-205, the 2024 law that first established Colorado’s AI legislative framework, with a substantially narrowed scope, and pushes back the effective date to January 1, 2027. SB 189 contains a restructured …

Chopra Appointed First Secretary of California’s New Business and Consumer Services Agency

On May 12, 2026, California Gov. Gavin Newsom announced the appointment of former Director of the Consumer Financial Protection Bureau (CFPB) Rohit Chopra as the first secretary of California’s newly created Business and Consumer Services Agency (BCSA). Set to launch on July 1, 2026, the new cabinet-level agency is designed to strengthen consumer protection and fairness through the coordination of licensing, enforcement and rulemaking efforts across …

Part 3: Looking Ahead – Novel Cybersecurity Issues and Department Priorities

In prior posts, we discussed the amendments to 23 NYCRR Part 500 (Part 500) ahead of the April 15 deadline to certify compliance with Part 500 and the increasing focus on multifactor authentication (MFA) as a key cybersecurity control. While Part 500 sets out formal cybersecurity requirements, the New York State Department of Financial Services (NYDFS) regularly uses industry letters and guidance to signal how …

CSBS Interpretive Guidance Clarifies Some Stablecoins May Be Included in Tangible Net Worth Calculations for Money Transmitters

The Conference of State Bank Supervisors (CSBS) recently issued interpretive guidance addressing the accounting treatment of stablecoins in the tangible net worth (TNW) calculation under its Model Money Transmission Modernization Act (MTMA). The guidance clarifies that CSBS intends for the definition of TNW under the MTMA to include, as “tangible financial assets,” stablecoins that meet certain criteria. The guidance is nonbinding, and it is uncertain …

Part 2: NYDFS Sharpens Its Focus on Multifactor Authentication

Financial institutions covered by 23 NYCRR Part 500 (Part 500) (covered entities) must annually certify their compliance with these cybersecurity regulations. As the April 15 date for certifying compliance approaches, the New York Department of Financial Services (NYDFS) has been reinforcing its focus on one particular element of the updated requirements – multifactor authentication (MFA). On February 26, 2026, NYDFS hosted a public cybersecurity presentation …

NYDFS Refresher Series – Part 1: What Companies Need to Know Ahead of Annual Certifications of Compliance

Upcoming compliance certification Every year by April 15, financial entities subject to the New York Department of Financial Services (NYDFS) oversight (covered entities) are required to certify their compliance with the NYDFS’ cybersecurity regulations, 23 NYCRR Part 500 (Part 500). This year’s deadline will be the first time covered entities must certify compliance with all of the amendments to Part 500 that were phased in …