(Updated )
CFPB Digital Payment App Oversight Rule: Nullified by Congress in 2025
A fractional CTO guide to the CFPB larger-participant rule for digital payment apps, which Congress nullified in 2025. What the rule would have required, and the examination-readiness practices it pointed toward.
By Craig Hunt
Fractional CTO, Sagecrest Solutions
Corrected September 10, 2026. An earlier version of this guide presented the rule below as finalized in 2026 and in force. Congress nullified it in 2025, and I revised the guide to match.
The CFPB issued a final rule defining larger participants in a market for general-use digital consumer payment applications, published in the Federal Register on December 10, 2024 (89 FR 99582). Congress disapproved it under the Congressional Review Act. S.J.Res.28, enacted as Public Law 119-11 on May 9, 2025, provides that “such rule shall have no force or effect.”
The rule binds no payment platform. The sections below describe what it would have required and the examination practices it pointed toward. Read them as background rather than as current obligations, and confirm your own supervisory status with counsel.
What the Rule Would Have Required
The rule would have extended the CFPB’s supervisory authority under Section 1024(a)(1)(B) of the Consumer Financial Protection Act to nonbank covered persons that qualify as “larger participants” in the consumer financial products or services market. The final rule set the larger-participant threshold for digital payment apps at 50 million or more annual covered consumer payment transactions.
Covered activities included general-purpose funds transfers, wallet-based payment services, and peer-to-peer payment services provided to consumers for personal, family, or household purposes. The scope covered transactions initiated through the app regardless of the underlying settlement rail (bank ACH, card network, RTP, or on-us balance transfers).
Had the rule stood, a platform above the 50 million transaction threshold would have faced three consequences.
CFPB examination authority would have activated. Federal examiners could have conducted on-site examinations of platform policies, procedures, data-handling practices, fraud controls, complaint-handling processes, and consumer notification workflows. The examination scope mirrors what bank examiners exercise over state-chartered and federally chartered banks.
Consumer data privacy standards would have applied at federal scope. Platforms would have needed data governance that satisfies federal consumer financial protection requirements. Data retention policies, third-party data sharing agreements, and consumer disclosure practices would all have sat inside the examination perimeter.
Account termination and “debanking” practices would have faced scrutiny. Platforms would have needed documented policies for suspending or closing user accounts, and arbitrary or discriminatory termination practices would have carried direct enforcement risk.
How CFPB Examinations Actually Work
Examinations follow a predictable structure that platforms can prepare for. The CFPB Supervision manual defines the examination phases, the document requests examiners issue, and the risk assessment framework examiners apply.
Phase 1: Pre-examination scoping. The CFPB issues an Examination First Day Letter that requests baseline documents (policies and procedures, organizational charts, board minutes, compliance management system documentation, transaction volume reports, consumer complaint logs, account closure logs).
Phase 2: On-site examination. A team of examiners conducts on-site work covering the areas the pre-examination scoping identified as risk priorities. Interviews with compliance leadership, technology leadership, product leadership, and operational staff run alongside documentation review and transaction sampling.
Phase 3: Findings and remediation. The examination produces a report of examination that documents findings, categorizes them by severity, and specifies required remediation actions. Matters Requiring Attention direct the platform to address specific issues on a defined timeline. Matters Requiring Immediate Attention require faster remediation and carry higher escalation risk.
Phase 4: Follow-up examinations. Subsequent examinations verify that prior findings closed and assess whether new issues emerged since the last examination. Platforms with strong compliance management systems typically see the examination cycle stabilize into predictable annual or biennial reviews. Platforms with weaker programs face more frequent and more intensive examinations until findings close.
The Compliance Architecture Payment Platforms Build to Prepare
Preparation for CFPB supervision requires architecture decisions across five operational domains.
Compliance management system (CMS). A documented, board-approved compliance management system covers policies and procedures, training, monitoring and testing, consumer complaint response, and vendor management. The CMS provides the framework examiners evaluate. A missing or weak CMS becomes the first finding examiners issue.
Consumer complaint operations. Platforms must intake, log, categorize, respond to, and analyze consumer complaints. The CFPB Consumer Complaint Database creates a parallel intake path that examiners cross-reference against internal logs. Discrepancies between internal complaint volume and CFPB complaint volume become examination findings.
Account termination policies. Documented policies must specify the criteria under which the platform suspends or closes user accounts. The criteria must satisfy fair-lending and consumer-protection standards. Every termination decision must trace back to a documented criterion and produce an audit trail examiners can follow.
Data governance and disclosure practices. Data retention schedules, third-party data sharing agreements, consumer disclosure practices, and privacy notices must satisfy CFPB expectations layered on top of state privacy laws and other federal requirements. The examiner’s question typically runs “walk me through the data lifecycle for a consumer who deletes their account” and platforms must produce a defensible walkthrough.
Fraud and error resolution operations. Regulation E error resolution requirements apply to covered payment services. Platforms must handle error notices within statutory timelines, conduct required investigations, and provide required disclosures. The error resolution workflow becomes an examination focus because Reg E findings carry direct consumer-harm implications.
The Operational Framework CTOs Adopt
This framework assumed the rule stood, so read it as background rather than as a compliance plan. It runs in four parts.
Step 1: Compliance management system uplift. Board-approve a CMS that satisfies CFPB expectations. Document policies and procedures across the compliance perimeter. Establish training programs, monitoring processes, and independent testing that examiners will recognize as mature. If the current CMS runs at bank-partner-satisfies-my-obligation maturity, invest in the uplift to independent-federally-examined maturity.
Step 2: Complaint and termination process reengineering. Build the intake, logging, response, analysis, and trending capabilities the CFPB expects. Reconcile internal complaint logs against CFPB Consumer Complaint Database entries monthly. Rebuild account termination workflows to trace every decision back to documented criteria and produce audit trails on demand.
Step 3: Vendor management and third-party risk uplift. Every third party handling covered consumer data or executing covered transactions becomes a vendor management concern. Document the third-party inventory, run due diligence, establish contractual protections, and monitor ongoing performance. Bank-standard vendor management practices become the baseline expectation.
Step 4: Mock examination. Before actual CFPB supervision arrives, run a mock examination using external counsel and consultants who have led CFPB engagements. The mock examination surfaces the gaps that internal review misses. Fix the gaps before the actual examination arrives.
Where Payment Platforms Get Caught
Platforms that miss the preparation window typically get caught in two specific patterns.
Missing the vendor management scope. Every third party in the payment flow enters vendor management scope once CFPB examination arrives. Platforms that operated with minimal vendor management practices face significant catch-up work. The right time to systematize vendor management runs before, not during, the first examination cycle.
Ignoring the consumer complaint reconciliation. The CFPB Consumer Complaint Database captures complaints platforms often never see internally. Reconciling the database against internal logs monthly produces the operational discipline examiners expect. Ignoring the reconciliation until examination begins guarantees findings.
What This Means for Fintechs
The 50 million transaction threshold triggers nothing, because the rule that set it carries no force or effect. Fintechs that built plans around crossing it should revisit those plans with counsel.
Related Guides
- AI Compliance for FinTech in 2026
- AI Compliance for Stablecoin Issuers in 2026
- Best AI Sanctions Screening Tools 2026
- Best AI for Banking Operations in 2026
Frequently Asked Questions
Does the Digital Payment App Oversight rule still apply?
No. Congress disapproved the rule under the Congressional Review Act. Public Law 119-11, enacted May 9, 2025, provides that “such rule shall have no force or effect.” Its 50 million transaction threshold no longer triggers CFPB examination authority.
What did the rule cover?
As issued, it covered general-purpose funds transfers, wallet-based payment services, and peer-to-peer payment services provided to consumers for personal, family, or household purposes, at platforms above the 50 million annual transaction threshold.
How does the nullification interact with state money transmitter licenses?
State licenses continue to apply. The nullified CFPB rule adds no federal supervisory layer on top of them.
Get more like this.
Weekly AI tool reviews and practical implementation guides, delivered straight to your inbox.
No spam. Unsubscribe anytime.