CFPB 1071 Small Business Lending Data: 2027 Compliance
The 1071 rule is no longer a distant deadline. Here's what small business lenders must collect, report, and build before regulators come knocking.

The CFPB's Section 1071 rule has survived a Supreme Court challenge, weathered Congressional scrutiny, and emerged with revised compliance dates that give most lenders less runway than they think. If your institution originates small business loans and has not yet audited your data-collection infrastructure, the clock is not just ticking — it is already in the red.\n\nThis post breaks down exactly what the rule requires, who is covered and when, and the engineering and compliance decisions you need to make before your go-live date. We are not going to tell you to "consult your legal counsel" and leave it there. We are going to give you the specifics.\n\n## What Section 1071 Actually Requires\n\nSection 1071 of the Dodd-Frank Act amended the Equal Credit Opportunity Act (ECOA) to require financial institutions to collect, maintain, and report data on credit applications from small businesses — including women-owned and minority-owned firms. The CFPB issued its final rule in March 2023 (Federal Register, Vol. 88, No. 72), and after a series of court-ordered stays, revised implementation dates took effect in 2024 and now extend through 2027.\n\nAt its core, the rule mandates collection of 26 data points per covered application, including:\n\n- Credit type, purpose, and amount applied for\n- Action taken and date of action\n- Census tract of the principal place of business\n- Gross annual revenue of the applicant\n- NAICS code\n- Number of workers\n- Time in business\n- Minority-owned, women-owned, and LGBTQI+-owned business status\n- Race, sex, and ethnicity of principal owners (up to four)\n- Pricing information: interest rate, total origination charges, broker fees, and initial annual charges\n\nThe firewall requirement — separating underwriters from demographic data — is one of the most operationally demanding pieces. It is not optional. Your system architecture must enforce it, not just your policy handbook.\n\n## The Phase-In Schedule: Who Goes Live and When\n\nThe CFPB structured compliance around origination volume. After the revised timeline confirmed in 2024, the tiers look like this:\n\n1. Tier 1 — 2,500+ covered originations in each of 2022 and 2023: Initial compliance date was July 18, 2025. These institutions are already in production.\n2. Tier 2 — 500–2,499 covered originations in each of 2022 and 2023: Compliance date of January 16, 2026.\n3. Tier 3 — 100–499 covered originations in each of 2022 and 2023: Compliance date of October 18, 2026.\n4. Tier 4 — Institutions that cross the 100-origination threshold after the rule's effective date: Must comply beginning with the calendar year after they hit the threshold — which means some lenders will be entering scope for the first time in 2027.\n\n> Key clarification: "Covered originations" counts only loans that meet the rule's definition of a covered credit transaction to a small business — defined as a business with gross annual revenue of $5 million or less in its preceding fiscal year. Lines of credit, term loans, merchant cash advances structured as credit, and business credit cards all potentially qualify. SBA-guaranteed loans are covered. HMDA-reportable transactions on dwellings are excluded.\n\nIf you are a community bank or credit union that has been growing your small business portfolio since 2023, run your origination count now. You may be closer to a tier boundary than your compliance team assumes.\n\n## Data Points That Will Break Legacy Systems\n\nMost of the operational pain in 1071 compliance does not come from the easy fields — loan amount, action taken, census tract. It comes from four categories that legacy loan origination systems (LOS) were simply not built to handle.\n\n### Pricing Data at the Application Level\n\nThe rule requires lenders to report the interest rate or rate spread at the time of origination, total origination charges, broker fees, and initial annual charges. For variable-rate products, you report the index and margin. For many LOS platforms built before 2015, pricing data lives in the rate lock or closing module — not in the application record. Retrofitting a data pipeline from closing tables back to application IDs is not trivial.\n\n### Disaggregated Demographic Data\n\nUnlike HMDA, which aggregates race and ethnicity into broad categories, 1071 requires collection of disaggregated race data (for example, distinguishing Vietnamese from Filipino from Korean under the Asian umbrella). The CFPB modeled this on the 2010 OMB Statistical Policy Directive No. 15 revision proposals. Your intake forms, digital applications, and banker-assisted workflows all need updating.\n\n### The Firewall\n\nThe rule prohibits underwriters and others involved in credit decisions from accessing applicant demographic data before the credit decision is made, unless the financial institution uses the data for a self-testing program. This requires either physical separation in your LOS or role-based access controls that prevent the demographic record from surfacing in the underwriter's view. Document your controls — the CFPB has flagged this as a likely examination focus.\n\n### Principal Owner Identification\n\nYou must collect demographic data for up to four principal owners (defined as those holding 25% or more equity). If a business has three principals at 30%, 30%, and 40%, you collect data on all three. If it has five principals each at 20%, none qualifies under the 25% threshold and no demographic data is required — but you still must document why. Your application workflow needs branching logic that most current systems cannot handle natively.\n\n## Building the Reporting Infrastructure\n\nThe CFPB requires covered institutions to compile their small business lending data into a Loan/Application Register (LAR) and submit it annually. The first submission deadline for Tier 1 institutions was June 1, 2026, covering calendar year 2025 data. For institutions entering compliance in 2026 and 2027, their first LAR submissions will follow accordingly.\n\nThe CFPB's FFIEC has published a filing platform, but the data quality validation happens before you hit submit. The CFPB's 2023 final rule estimated that a mid-size institution with 1,000 covered applications per year would spend approximately 3,200 staff hours in year one building and validating its LAR — and that estimate assumed a reasonably modern LOS. Institutions still on on-premise origination software from the 2000s should double that figure.\n\nHere is what a compliant reporting stack minimally requires:\n\n- Application data capture layer: Collects all 26 fields at or near the time of application, not reconstructed post-close\n- Firewall enforcement layer: Role-based access control separating demographic data from underwriting workflows\n- Census tract geocoding: Automated geocoding of principal business address to 2020 Census tract boundaries (the rule uses 2020 tracts, not 2010)\n- LAR compilation engine: Aggregates application records, applies CFPB validation rules, flags errors before submission\n- Audit log: Every field edit, user action, and system change must be logged with timestamps for examination readiness\n- Annual submission module: Formats the LAR to CFPB's technical specifications and supports FFIEC filing platform authentication\n\nIf you are building this in-house, budget 9 to 18 months of engineering time for a greenfield implementation. If you are buying or integrating, demand a live demo of the firewall controls and a sample LAR export before you sign.\n\n## Fair Lending Exposure Is Bidirectional\n\nMost compliance conversations about 1071 focus on the burden of collection. They miss the strategic risk on the other side: the data you collect will be public.\n\nThe CFPB will publish LAR data — redacted to protect applicant privacy, but detailed enough for advocacy groups, competitors, and plaintiffs' attorneys to conduct disparate impact analysis. Bloomberg Law reported in late 2024 that at least four major civil rights organizations have stated they intend to use 1071 public data as the basis for fair lending complaints within 12 months of the first publication cycle.\n\nThis is not a reason to avoid compliance. It is a reason to get your fair lending house in order before you start collecting data. If your denial rates for minority-owned businesses are significantly higher than for comparable non-minority applicants, you want to understand that now — and address it through underwriting criteria review, credit policy analysis, and model validation — not when the CFPB's public dataset makes it visible to everyone.\n\nThe CFPB's fair lending supervision framework explicitly lists 1071 data as a future input into its prioritization model for lender examinations. If your public LAR looks anomalous, expect a phone call.\n\n## What Community Banks and Credit Unions Get Wrong\n\nThe rule includes a limited exemption for institutions with fewer than 100 covered originations in each of the two preceding calendar years. But many community institutions are misreading this as a permanent safe harbor. It is not — it is an annual look-back test. An institution that originates 85 small business loans in 2025 and 110 in 2026 does not trigger coverage until it exceeds the threshold in both of two consecutive years. However, as small business lending volumes continue rising — the Federal Reserve's 2026 Small Business Credit Survey showed a 14% year-over-year increase in loan application volume among firms with fewer than 500 employees — previously exempt institutions are crossing the threshold faster than expected.\n\nCredit unions face an additional complexity: NCUA-chartered institutions are subject to CFPB 1071 rule requirements, but NCUA has separate examination authority. The interplay between the two agencies' expectations on data quality is not fully settled, and credit unions should not assume NCUA examination leniency will substitute for CFPB rule compliance.\n\nFor institutions near the 100-origination boundary, the compliance calculus is this: build the infrastructure now when you have time, or scramble to build it in six months when you cross the threshold mid-year and realize your first LAR is due the following June.\n\n## The Strategic Opportunity Inside the Compliance Cost\n\nEvery institution that builds a clean, validated 1071 data pipeline also gains something it probably did not have before: a structured, standardized dataset on its own small business lending portfolio.\n\nThat data — origination volume by NAICS code, average loan size by census tract, revenue distribution of applicants, denial rates by product type — is genuinely valuable for portfolio management, product design, and community reinvestment planning. Lenders who treat 1071 compliance as purely a cost center will spend the money and get nothing back. Lenders who use it as a forcing function to modernize their data infrastructure will come out ahead.\n\nThe CFPB's own research, cited in the 2023 final rule preamble, estimated the rule would bring transparency to a market representing approximately $1.4 trillion in annual small business credit — a market that has historically lacked the granular public data that makes the mortgage market so analytically rich. The institutions that understand their position in that market earliest will have a competitive advantage in underwriting, pricing, and product development.\n\n## Get Ready Before the Examiners Do\n\nIf your institution is approaching a phase-in deadline in 2026 or 2027, the window for a comfortable implementation is narrow. The CFPB has been clear that it will not grant individual extension requests outside of formally documented natural disaster or extraordinary circumstance exceptions — and the post-stay regulatory environment has only increased enforcement focus on the largest Tier 2 and Tier 3 institutions.\n\nStart with a gap analysis: map your current LOS fields against the 26 required data points, test your geocoding pipeline against 2020 Census tract boundaries, and audit your role-based access controls against the firewall requirement. If you find gaps — and you will — prioritize the data capture layer and the firewall before anything else, because those two failures are the most likely to generate findings on examination.\n\nAtlasForge Financial's AtlasForge Financial API is purpose-built for exactly this kind of compliance data infrastructure — structured data capture, role-scoped access controls, and LAR-ready export pipelines that connect to your existing loan origination system without a full-stack replacement. Our platform also integrates directly with Safe to Spend 365, giving lending teams a unified view of compliance state and customer financial health in a single dashboard. If you want to see how other institutions in your tier are structuring their 1071 builds, start with our compliance resources on the blog or reach out directly — we have seen enough implementations to know where the edge cases are.\n\nThe 1071 rule is not going away. The institutions that treat it as a data infrastructure investment — not just a regulatory checkbox — will be better lenders, not just compliant ones.
Further reading
Ready to build on AtlasForge?
Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.
