FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Section 1071: small-business credit data, underwriting boundaries and the revised reporting framework

6 min read · estimatedAI-generated analysis · Methodology
Current version · 1 version · Publication details

First published . This version published .

Initial full research explaining the mechanism, current regulatory context, customer and business consequences, worked hypothetical examples, competing interpretations and limitations. Primary sources checked October 3, 2026 (America/Denver).

Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
The May 2026 Section 1071 revision narrows the small-business lending dataset and sets January 2028 compliance. The framework separates demographic reporting from underwriting while balancing transparency, privacy and collection costs.
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

The current framework begins with the 2026 revision

Section 1071 of the Dodd-Frank Act added small-business lending data provisions to the Equal Credit Opportunity Act. Its implementing framework changed materially after the original 2023 rule. On May 1, 2026, the CFPB finalized reconsideration covering lenders, transactions, the small-business definition, data fields and timing. An explanation built solely around the original thresholds or phased deadlines would therefore describe an outdated framework. [1]

The rule concerns the visibility of credit applications and outcomes. It does not create a general promise that an applicant will receive financing, nor does a reporting category establish creditworthiness. The economic aim of collecting comparable information differs from the commercial task of deciding whether a particular business can repay a particular obligation.

The account here describes the revised federal rule and current regulatory text checked in October 2026. Rule requirements and institution-specific effects of litigation are separate questions. The cited rule chronology establishes the regulatory framework; it is not a representation that every possible court order affecting every party has been independently resolved.

Three coverage questions precede a report

Under current §1002.105, a covered financial institution generally must have originated at least 1,000 covered credit transactions for small businesses in each of the two preceding calendar years; Farm Credit System lenders are excluded. The rule’s institution concept includes more than insured banks. [2]

Current §1002.106 uses gross annual revenue of $1 million or less in the preceding fiscal year for the relevant small-business size threshold, alongside the definition’s other provisions. It provides for subsequent inflation adjustments. The number is a reporting boundary, not a universal definition that replaces every other program’s use of the term small business. [3]

A third question concerns the transaction. Loans, lines and business credit cards can be covered, while specified exclusions include HMDA-reportable transactions, trade credit, merchant cash advances, agricultural lending and transactions of $1,000 or less. The regulation also explains the treatment of factoring, leases and consumer-designated credit. [4] Product labels alone do not provide a reliable census of what falls inside the framework.

A threshold changes the sample as well as the workload

Consider a hypothetical institution originating 1,100 business transactions in a year. If 180 are outside the covered definition, only 920 remain for the relevant count. The headline number of business loans does not establish coverage. A second institution with 1,020 qualifying originations in one year and 990 in the next does not satisfy an at-least-1,000 test in each of those years merely because its two-year total exceeds 2,000.

These examples are intentionally simplified. They isolate the distinction between a product count, a covered-originations count and a two-year condition. Actual application of the framework involves definitions and transitional rules, including which businesses and products qualify. A reporting perimeter is constructed from several filters, not read directly from a balance-sheet total.

The same filters affect research. A dataset concentrated in larger-volume lenders can describe substantial transaction activity while saying less about small local providers. Broad national coverage and representative coverage of every neighborhood or business niche are different properties. Reducing collection burden and preserving local detail can pull in opposite directions even when both objectives are legitimate.

January 2028 replaces the old phased start

Current §1002.114 establishes January 1, 2028 as the initial compliance date for institutions meeting the specified threshold in 2026 and 2027. A special transition permits use of 2025 and 2026 instead for determining initial coverage. Subsequent entrants follow the continuing coverage provisions. These are explicit rule provisions, rather than an inference from a litigation pause or an assumption that the original 2023 schedule still applies. [5]

A delayed start has two opposing economic effects. It provides time to adapt forms, systems and responsibilities, but also postpones the production of comparable information. More preparation time is not equivalent to zero implementation cost: institutions that built around an earlier specification may face rework, while those outside revised coverage may no longer need the same infrastructure.

Nor is a future collection start the same thing as an immediately available public research file. Application intake, completion, reporting, validation and privacy treatment are different stages. An expectation of eventual public information cannot justify presenting simulated data as observed lending activity before that information exists.

The data describe a credit process

The revised §1002.107 retains application identifiers and dates, product and purpose, amounts requested and approved or originated, action taken, geography, revenue, industry, time in business and specified ownership information. Its current text reserves several former fields, including pricing and denial reasons. Minority-owned and women-owned status and principal owners’ ethnicity, race and sex remain within the collection framework, with applicants’ right to refuse the specified demographic information. [6]

Those choices influence what future analysis can explain. Requested and approved amounts can distinguish some demand from supplied credit. If a hypothetical business requests $80,000 and receives $50,000, the approval does not mean its original financing need was fully met. Equally, the $30,000 difference does not prove the original request was economically justified or that the lender acted improperly.

Removing a field can reduce reporting complexity while eliminating a dimension researchers might otherwise use. This is not a claim that every possible field should be collected. It is a reminder that a dataset’s explanatory power follows its contents, and that the absence of pricing or denial-reason information cannot be repaired by treating the remaining variables as perfect substitutes.

The demographic firewall is a boundary on access

Section 1002.108 generally restricts access to the specified demographic responses by employees or officers involved in decisions on the application. It includes a feasibility exception and an applicant notice when the exception is used. The 2026 reconsideration retained the substantive firewall framework. [7][1]

The distinction between collection and decision-making is central. Information can be useful for evaluating patterns across many applications without being appropriate as an input to an individual decision. A reporting database and an underwriting workspace serve different purposes even when both relate to the same transaction. Combining them for operational convenience can blur the intended separation.

In a hypothetical workflow, a relationship manager enters business revenue and the applicant separately submits ownership-demographic information. Whether the latter appears in a credit memorandum depends on access design and any applicable exception, not merely on whether both entries share an application identifier. Technology can implement a boundary, but an attractive interface alone does not establish that the boundary works.

Privacy and nonresponse shape the eventual public picture

Section 1002.110 permits the Bureau to modify or delete collected information before public release to protect privacy. [8] The public record therefore cannot simply be assumed to reproduce every submitted field at full precision. Small businesses can be closely associated with identifiable owners, making combinations of geography, industry and financing details potentially revealing.

Nonresponse creates another interpretive limit. If two hypothetical applicant groups have different rates of voluntarily supplied demographic information, observed outcomes among respondents may not represent all applicants in the same way. A missing response cannot reasonably be assigned a demographic identity merely to make a chart complete. Nor does a low response rate alone explain why respondents chose not to answer.

The revised framework’s enduring tradeoff is between useful visibility and the costs and sensitivities of producing it. More data can illuminate access and demand, but rules determine which activity becomes visible and which remains outside the sample. Section 1071’s future value will depend on accurate collection and careful interpretation, not simply the arrival of a larger spreadsheet.

Sources

  1. CFPB, May 1, 2026 final reconsideration and Federal Register final textOfficial sourceBack to text: ↑1↑2
  2. CFPB, Regulation B §1002.105, current institutional coverageOfficial textBack to text: ↑
  3. CFPB, Regulation B §1002.106, current business definitionOfficial textBack to text: ↑
  4. CFPB, Regulation B §1002.104, covered and excluded transactionsOfficial textBack to text: ↑
  5. CFPB, Regulation B §1002.114, current compliance and transition provisionsOfficial textBack to text: ↑
  6. CFPB, Regulation B §1002.107, current data fields and applicant responsesOfficial textBack to text: ↑
  7. CFPB, Regulation B §1002.108, firewall and feasibility exceptionOfficial textBack to text: ↑
  8. CFPB, Regulation B §1002.110, publication and privacy modificationOfficial textBack to text: ↑

Flag an error or suggest a correction →Public corrections log →