Financial institutions are operating in a changing regulatory environment. The Consumer Financial Protection Bureau’s (CFPB’s) draft strategic plan for fiscal years 2026 through 2030 calls for concentrating enforcement on identifiable victims with material and measurable damages, avoiding novel legal theories, and pursuing a “robust deregulatory agenda.” The Office of the Comptroller of the Currency (OCC) and Federal Deposit Insurance Corporation (FDIC) have likewise adopted a final rule intended to focus supervisory attention on material financial risks instead of less consequential concerns involving policies, processes, and documentation.
These developments give financial institutions an appropriate opportunity to reconsider compliance costs and controls. But they also create a litigation trap: mistaking a change in regulatory priorities for a change in the law.
A regulator’s decision not to examine or enforce a particular issue does not necessarily eliminate the underlying statute, regulation, contractual obligation, or state-law standard. Nor does it prevent state regulators, attorneys general, consumers, commercial customers, or class-action plaintiffs from challenging the same conduct. Before eliminating a compliance control, institutions should not only ask, “Is the regulator still requiring this?” but also, “Why was this control created, and how will its elimination look in litigation?”
A Control May Serve More Than One Purpose
Compliance controls rarely address only regulatory examinations. A control may also prevent customer losses, identify employee misconduct, fulfill contractual commitments, support an institution’s defenses, or create evidence that the institution acted reasonably and in good faith.
Consider controls involving:
- Escalation of recurring consumer complaints;
- Secondary review of potentially discriminatory credit decisions;
- Monitoring for unusual payment activity;
- Verification of changes to customer or vendor information;
- Review of loan-servicing exceptions;
- Oversight of fintech and other service providers;
- Retention of customer communications; and
- Investigation of credit-reporting disputes.
An institution may originally have adopted such a control in response to supervisory guidance that has since been withdrawn or deprioritized. Nevertheless, the control may continue to mitigate exposure under federal consumer-finance statutes, state laws that are unfair, or deceptive trade practices laws, contract law, common-law claims, or other legal requirements.
The first step should therefore be identifying every function the control performs—not merely the regulatory document that prompted its adoption.
The Discovery Record Matters
When litigation follows a customer loss, plaintiffs’ counsel will seek the institution’s risk assessments, audit reports, complaints, prior incidents, committee materials, policies, and communications concerning the challenged practice. If the institution recently eliminated a related control, that decision will likely become a focal point.
A cost-reduction presentation stating that a control was discontinued because the CFPB was “no longer enforcing” the issue could be especially damaging. A plaintiff may characterize that document as evidence that the institution knew of the risk but accepted it to reduce expenses. That characterization may not be legally correct, but it can be difficult and costly to overcome—particularly if the decision was not supported by a documented legal and operational analysis.
The problem becomes greater when the institution previously identified customer harm, received similar complaints, or experienced earlier incidents involving the same risk. In that situation, the eliminated control may become “Exhibit A” in a narrative that the institution had notice of a foreseeable problem and consciously removed the mechanism intended to prevent it.
Internal policies do not automatically establish the legal standard of care, and withdrawn regulatory guidance does not necessarily create a private cause of action. But those principles may not prevent plaintiffs from using the institution’s own documents to support claims concerning knowledge, foreseeability, reasonableness, good faith, or causation.
A Litigation-Prevention Review
Before eliminating or materially reducing a compliance control, a financial institution should conduct a structured review addressing four questions.
First, what legal obligations remain? The institution should distinguish among a change in enforcement priority, withdrawal of informal guidance, amendment of a regulation, and repeal of a statutory requirement. It should also consider applicable state laws, contractual duties, and requirements in jurisdictions that may be more protective than the federal standard.
Second, what harm was the control designed to prevent? The analysis should identify the relevant risk scenario, the frequency and severity of past incidents, related consumer complaints, and whether another control adequately addresses the same risk.
Third, what evidence will remain after the control is removed? The institution should consider how the decision would appear to a regulator, judge, or jury reviewing it without the benefit of the institution’s broader business context.
Fourth, can the institution streamline rather than eliminate the control? Automation, risk-based sampling, revised thresholds, consolidated testing, or improved vendor oversight may reduce costs without leaving the institution unable to detect or defend against foreseeable harm.
The review should involve legal, compliance, operations, risk, internal audit, and relevant business personnel. Where appropriate, counsel should structure the analysis to preserve privilege, while recognizing that the ultimate business decision and resulting operational records may still be discoverable.
Document the Decision, Not Just the Savings
If the institution decides to modify or eliminate a control, its records should explain the entire decision-making process and the rationale for the same. The documentation should identify the governing law, available risk data, existing compensating controls, anticipated effect on customers, implementation responsibilities, and a date for reassessment.
The institution should also monitor what happens afterward. An increase in complaints, exceptions, losses, or service-provider failures may indicate that the decision should be revisited. A defensible process is not complete when the control is eliminated; it includes testing whether the replacement approach works.
The current regulatory environment may permit financial institutions to reduce unnecessary compliance burdens. But deregulation should not become de-risking in name only. A control that no longer responds to a supervisory priority may still prevent customer harm, support a legal defense, or demonstrate responsible decision-making.
Before eliminating it, institutions should assume that the decision—and the documents supporting it—may one day be placed before a judge or jury. The question is whether those documents will show a thoughtful risk assessment or become the plaintiff’s Exhibit A.