Last Week, This Morning

September 14, 2026

Below you will find several key developments in the financial services industry, including related developments in information privacy and data security, from the past week. We add an "Amicus Brief(ly)1" comment to each item, where we briefly (see what we did there?) note for friends (and again?) of CounselorLibrary the important takeaways from the developments outlined in the email. Our legal reporters - CARLAW, HouseLaw, InstallmentLaw, PrivacyLaw, and BizFinLaw - provide more comprehensive, real-time updates of federal and state laws, regulations, litigation, and other industry items of interest. For a personal guided tour and free trial of any of these legal reporters, please contact Michael Willer at 614-855-0505 or mwiller@counselorlibrary.com.

FTC's Bureau of Consumer Protection Launches Guidance Program

On September 10, Christopher Mufarriage, the director of the FTC's Bureau of Consumer Protection, announced that the BCP launched a new guidance program that will allow interested stakeholders "to identify genuine ambiguities in the Commission's rules, substantive conflicts between a rule and an existing statute or other rule, and other significant issues that may exist within Commission rules." The BCP Rule Guidance Program webpage explains the process for submitting stakeholder questions through an online form. If the BCP determines that an issue concerning an FTC rule should be addressed, it will provide guidance on that issue.

The BCP notes that "questions that simply ask staff to restate what the rule says - or that attempt to diminish a business's own legal or compliance responsibilities - do not fit the parameters of the new program. For example, staff will not interpret performance based standards like 'clear and conspicuous,' which have established meaning in case law and must be applied by businesses and their legal counsel. Nor will staff respond to questions that can be readily answered by reviewing the FTC's existing plain-language guidance for a rule."

Amicus Brief(ly): This program from the FTC sounds promising. The FTC has always been good at publishing resources for consumers and businesses to help them understand the laws and regulations it enforces. Under the new guidance program, providers will be able to pose questions about difficult compliance issues that arise but that the FTC did not anticipate or questions about issues that providers identified in comments during the administrative rulemaking process but that did not end up being addressed by the FTC in final rules. By the sound of it, the FTC will respond (as long as the provider's question does not ask the FTC to weigh in on how well the provider is doing to comply with an FTC rule). On behalf of our readers and our colleagues with regulatory compliance responsibilities, we consistently express our appreciation for government transparency. We do so again this morning, hoping and expecting that this FTC guidance program will bring clarity to compliance obligations.

Federal Agencies and FinCEN Address Use of Verifiable Digital Credentials Under Customer Identification Program Rule

On September 8, the Department of the Treasury's Financial Crimes Enforcement Network, jointly with the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency, issued two new frequently asked questions that address the use of state-issued mobile driver's licenses ("mDLs") and other government-issued verifiable digital credentials ("VDCs") to verify identities of natural person customers under the Customer Identification Program ("CIP") Rule (31 C.F.R. § 1020.220).

The new FAQs state that a bank or credit union can use a government-issued VDC, such as a state-issued mDL, to verify the identity of a customer who opens an account, either in person, over the Internet, or through some other digital or virtual channel. The agencies state that an mDL "is a VDC format for a driver's license or identity card that is issued by a state government and contains all of the same information as a physical driver's license. As such, a bank or credit union may consider accepting such a credential provided that the bank or credit union can meet the requirements of the CIP Rule. The CIP Rule neither requires nor prohibits reliance on such government-issued VDCs as a means of verifying a customer's identity. For the purposes of 31 C.F.R. § 1020.220(a)(2)(ii)(A)(1), an unexpired, government-issued VDC, such as an mDL, would qualify as a 'government-issued identification,' though it must also 'evidence nationality or residence and bear a photograph or similar safeguard.' Accordingly, if the bank or credit union maintains the appropriate technology or systems to extract the relevant information from a government-issued VDC and it is allowable under the bank's or credit union's CIP, it may consider unexpired state-issued mDLs or other unexpired government-issued VDCs that 'evidenc[e] nationality or residence and bear a photograph or similar safeguard' as one of the documentary methods it uses to verify a customer's identity." "[H]owever, if a government-issued VDC shows indications of fraud, the bank or credit union must consider that factor in determining whether it can form a reasonable belief that it knows the customer's true identity."

Amicus Brief(ly): As financial services transactions become increasingly digital, guidance like these FAQs, which make clear how banks and credit unions can rely on digital credentials, is very valuable. Faced with escalating fraud risk as the use of artificial intelligence becomes more widespread, banks and credit unions are justified in their reticence to rely on non-traditional consumer identification materials, like mDLs, to verify a customer's identity. But as the market evolves, so must the providers in that market. These FAQs help banks and credit unions know the guardrails they need to incorporate as they evolve, especially in light of the financial investment it will take to adopt technology that can evaluate mDLs and other VDCs, along with other complementary resources that help those financial institutions confirm the identities of their customers and potential customers.

Federal Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers

On September 11, the Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration, and the Office of the Comptroller of the Currency requested comment on proposed third-party risk management guidance. The guidance is intended to assist financial institutions with identifying and managing risks associated with third-party relationships and complying with applicable laws and regulations. In June 2023, the FRB, the FDIC, and the OCC published third-party risk management guidance. However, based on feedback from stakeholders and supervisory experience, the agencies believe that the 2023 guidance has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles. The current proposed guidance addresses the concerns about the 2023 guidance. The proposed guidance encourages banking organizations to tailor the level and detail of oversight of third parties to the risks actually posed by each relationship and encourages innovation by removing impediments to fintech partnerships.

When the guidance is finalized, the agencies plan to rescind the existing 2023 third-party risk management guidance. Comments are due within 60 days after the proposed guidance is published in the Federal Register, which is expected shortly.

In addition, the agencies issued a joint statement on community banks' relationships with core service providers. The statement addresses certain aspects of how community banks engage with core providers, the extent to which the agencies will take these aspects into consideration when determining the level of supervisory oversight of core provider services, and certain factors the agencies will consider in making supervisory and enforcement decisions related to core providers.

Amicus Brief(ly): Third-party risk management has become a full-time job in many banks since the Dodd-Frank Act. The Consumer Financial Protection Bureau made third-party risk management a component of a healthy compliance management system, requiring regulated companies to oversee their vendors in an effort to head off potential consumer harm at every turn. As a result, companies that once relied on commercial contracts that allocated responsibilities between the parties and called for indemnification if something went wrong now have to develop processes that more closely manage third parties through compliance monitoring and audit functions. But one size does not necessarily fit all, and the agencies are looking for some feedback about how to better empower banks and credit unions to identify where to spend time and money on third-party risk management. We anticipate that banks and credit unions will have plenty of comments for the agencies to consider before issuing final guidance.

IRS Publishes Final Rules for Qualified Passenger Vehicle Loan Interest Deduction

Public Law No. 119-21, otherwise known as the "One Big Beautiful Bill Act," became effective on July 4, 2025. The law includes a new income tax interest deduction for tax years 2025 through 2028, which permits taxpayers to deduct up to $10,000 of "qualified passenger vehicle loan interest" from taxable income for indebtedness incurred after December 31, 2024. On September 8, the Internal Revenue Service published its final rules regarding the deduction, including new reporting requirements for those who receive $600 or more in interest on qualifying vehicle loans in any calendar year. The regulations are effective on November 9, 2026.

The final rules clarify that interest is "qualified passenger vehicle loan interest" only if the indebtedness is a "specified passenger vehicle loan" (defined as purchase money indebtedness) secured by a first lien on an "applicable passenger vehicle." Applicable passenger vehicles are those that are manufactured primarily for road use, have at least two wheels, are treated as motor vehicles under Title II of the Clean Air Act, have a gross weight rating of less than 14,000 pounds, are finally assembled in the United States, and are of the following types: car, minivan, van, sport utility vehicle, pickup truck, or motorcycle. The new regulations provide additional guidance on these qualifications, including when a security interest is deemed to be a first lien, whether interest on ancillary products qualifies for the deduction, how to treat refinancing of a specified passenger vehicle loan, and how to determine whether final assembly of the vehicle occurs within the U.S.

Persons who receive from any individual interest aggregating $600 or more for any calendar year on a specified passenger vehicle loan must file an information return reporting the receipt of interest (on a form prescribed by the IRS). The information return must include the name and address of the payee, the amount of interest received for the calendar year, the outstanding principal balance of the obligation as of the beginning of the calendar year, the date of origination of the loan, and information about the vehicle securing the loan.

Those persons who are required to file an information return must also provide to each individual whose name is required to be included in the return a written statement that includes certain information prescribed by law.

Any person who fails to file information returns or furnish payee statements as required is subject to the penalties under Sections 6721 and 6722 of the Internal Revenue Code.

Amicus Brief(ly): Companies that finance vehicle purchases - from banks and credit unions to non-bank finance companies, buy-here-pay-here dealers, and servicers - should spend some time with these new rules. Preparing and delivering the IRS interest form is pretty straightforward, but the requirement to do so is new. (However, the requirement is not brand new. Fun fact for readers: until 1986, all consumer-paid interest, including credit cards, was tax deductible.) Companies must ensure that their systems are prepared to identify the vehicle collateral and categorize it as an "applicable passenger vehicle" or otherwise calculate the finance charges or interest that accrues during the calendar year on vehicles subject to the rules and then generate and send the IRS forms as required. Certain providers, like banks, are accustomed to at least some of this process if they engage in mortgage lending and servicing because the interest deduction for mortgage loans has been in place for years. But for others, this is an important new process to program and test over the next couple of months.

Court Reverses Dismissal of Complaint Alleging Buyer of Mortgages in Foreclosure Was Subject to Illinois Collection Agency Act

The Appellate Court of Illinois recently decided a case in which the State of Illinois sued a company, alleging that it operated as an unlicensed collection agency in violation of the state's Collection Agency Act. Specifically, the state argued that the company stated in its application to transact business in Illinois "that it would engage in 'debt collection and debt purchasing'" and that it purchased three mortgage notes when the mortgages were in foreclosure. The trial court dismissed the complaint, and the Illinois appellate court reversed and remanded.

On appeal, the company argued that the CAA does not apply to purchasers of secured debt that enforce their security interests through foreclosure but instead only applies to entities engaged in third-party debt collection. The appellate court rejected that argument, relying on the plain language of the CAA, which, at the time the complaint was filed, defined "collection agency" to include any person who, in the ordinary course of business, engages in debt collection on behalf of himself or herself, including a debt buyer that purchases delinquent or charged-off consumer loans, credit accounts, or other consumer debt and collects the debt itself. The appellate court also rejected the company's argument that the court should consider the language of the federal Fair Debt Collection Practices Act when determining who is a debt collector, noting that the CAA and the FDCPA contain different language when addressing the parties and practices to which the statutes apply. The appellate court noted that it was possible that the state legislature did not intend for the purchase of mortgage debt and the enforcement of that debt through foreclosure to be covered by the CAA but concluded that it is up to the legislature to amend the language of the CAA, not the court.

Amicus Brief(ly): The court correctly decided this case based on the language of the CAA. We understand the company's arguments, given that its business model does not appear to be focused on money collection; rather, the company enforces security interests through the defaulted mortgage loans it buys. While the FDCPA appreciates the difference between a "collection agency" model and this company's model by largely limiting the applicability of the statute when an apparent debt collector confines its work to the enforcement of security interests, Illinois updated its CAA a couple of years ago to specifically require licensing for debt buyers (without regard to their collection strategies for those purchased debts). This decision underscores the importance of understanding the scope of state licensing laws as they evolve to ensure that a company's license portfolio matches its business model, consistent with the way states regulate the model.


1 For the unfamiliar, an “Amicus Brief” is a legal brief submitted by an amicus curiae (friend of the court) in a case where the person or organization (the “friend”) submitting the brief is not a party to the case, but is allowed by the court to file the brief to share information or expertise that bears on the issues in the case.