CFPB 1071 Rule Timeline: What Every Lender Must Do by 2027
The CFPB's small business lending data rule is no longer hypothetical. Here's the exact compliance calendar — and what your tech stack needs to survive it.

The CFPB's Section 1071 rule has survived legal challenge, political headwinds, and a pandemic-era backlog to arrive at your doorstep with enforceable deadlines. As of mid-2025, the revised phase-in schedule stands — and for the highest-volume lenders, the first reporting window is already open. If your institution is still treating 1071 as a future problem, the calendar disagrees with you.
This post breaks down every critical date, the full list of 21 data points you must collect, and the infrastructure decisions that will determine whether your compliance program is a competitive asset or a last-minute scramble.
Why Section 1071 Matters More Than Most Compliance Rules
Section 1071 of the Dodd-Frank Act amended the Equal Credit Opportunity Act (ECOA) to require financial institutions to collect and report data on credit applications from small businesses, women-owned businesses, and minority-owned businesses. The CFPB issued its final rule in March 2023, with a compliance date structure tied to origination volume.
The rule is not a reporting checkbox. It is the most significant expansion of small-business lending transparency since HMDA was extended in 2015. The Federal Reserve's 2024 Small Business Credit Survey found that minority-owned small businesses were approved at rates 18 percentage points lower than white-owned businesses with comparable financials. Section 1071 is the mechanism regulators intend to use to scrutinize exactly those gaps — in public, annually.
"Section 1071 will shine a light on lending patterns the way HMDA illuminated mortgage markets. Lenders who build honest, well-documented processes will be differentiated. Those who don't will be investigated." — former CFPB Deputy Director, speaking at the 2024 Fintech Policy Forum
The Three-Tier Compliance Timeline
The CFPB structured the rule with a tiered rollout based on covered originations — the number of small-business credit originations in each of the two preceding calendar years. Here are the exact thresholds and deadlines as confirmed in the final rule and subsequent guidance:
- Tier 1 — 2,500+ originations: Data collection began October 18, 2024. First submission to the CFPB is due June 1, 2025.
- Tier 2 — 500–2,499 originations: Data collection deadline is April 1, 2025. First submission due June 1, 2026.
- Tier 3 — 100–499 originations: Data collection deadline is January 1, 2026. First submission due June 1, 2027.
If you're a Tier 3 lender reading this in 2026, your collection clock is already running. The June 1, 2027 submission date is not a soft deadline — failure to report triggers civil money penalties under ECOA, which the CFPB has authority to assess at up to $10,000 per day per violation under certain conditions.
One critical nuance: the "covered originations" count includes loans, lines of credit, and credit cards extended to businesses with gross annual revenues of $5 million or less. Many community banks and credit unions underestimate their covered volume because they exclude credit cards or equipment financing from their mental model of "small business lending." Audit your entire product set before assuming your tier.
The 21 Required Data Points
The rule mandates collection of 21 specific data fields for each covered application. These fall into three functional categories:
Application and Credit Decision Fields
- Unique identifier (lender-assigned)
- Application date
- Credit product type (term loan, line of credit, credit card, etc.)
- Credit purpose
- Amount applied for
- Amount approved or originated
- Action taken (approved, denied, withdrawn, incomplete)
- Action taken date
- Denial reason(s) — up to 4
- Pricing information (interest rate, total origination charges, broker fees, initial annual charges)
- Census tract of the principal place of business
Business Demographic Fields
- Gross annual revenue
- NAICS code (North American Industry Classification System)
- Number of workers
- Time in business
- Whether the business is minority-owned
- Whether the business is women-owned
- Whether the business is LGBTQI+-owned
Applicant-Provided Demographic Fields
- Principal owner 1–4 ethnicity, race, and sex
That last category is where most lenders hit operational friction. The rule requires you to ask applicants for demographic information — and to record it even if the applicant declines to provide it. You must also note whether the information was provided by the applicant, visually observed by staff, or inferred from a surname. The firewall requirements between underwriting staff and demographic data collection are strict and must be documented in your compliance policies.
For a full annotated breakdown of each field's technical specification, the CFPB's official 1071 small business lending data filing instructions are the authoritative source.
Infrastructure You Need Before Your Compliance Date
Data collection is only the first layer. Getting from application intake to a clean, submittable file requires infrastructure most lenders don't have out of the box.
What your tech stack must handle:
- Unique identifier generation at application initiation, persistent across the full credit lifecycle
- NAICS code lookup integrated into your application flow — applicant self-report is acceptable, but you need a validation layer
- Census tract geocoding for the principal place of business address, accurate to the 2020 Census boundaries
- Firewall enforcement between loan officers who see demographic data and underwriters who must not
- Denial reason capture in a structured field (not a free-text note) mapped to the CFPB's enumerated list
- Pricing calculation logic that correctly computes total origination charges at the time of approval, not disbursement
- Annual file assembly in the CFPB's required CSV schema, validated against the Bureau's published edits before submission
The last point is where many lenders underestimate complexity. The CFPB's filing system will reject submissions that fail its automated edit checks — similar to HMDA's LAR validation — and resubmission after a failed check still counts against your deadline. Build your validation pipeline early and test it with synthetic data before your actual collection period closes.
For institutions evaluating API-driven compliance infrastructure, the AtlasForge Financial API includes structured endpoints for origination event capture, geocoding, and CFPB-schema file generation — designed specifically for lenders who want compliance logic embedded in their loan origination system rather than bolted on at year-end.
Examiner Priorities: What the CFPB Will Actually Look For
The CFPB has signaled, in supervisory guidance and public testimony, that its 1071 examination priorities will center on three areas:
- Data accuracy and completeness. Examiners will compare your submitted data against your loan origination system records. Discrepancies in denial reasons, pricing fields, or demographic capture rates will trigger deeper review.
- Firewall integrity. Can you demonstrate that underwriters did not have access to applicant-provided demographic information during the decisioning process? This requires documented system controls, not just a policy statement.
- Disparity analysis. Examiners will run their own statistical models on your data. If your denial rates or pricing show statistically significant disparities along race or sex lines that aren't explained by legitimate credit factors, you will receive a supervisory finding.
The third point is the one that should focus your attention beyond compliance and into fair lending analytics. Building an internal ECOA reporting dashboard — one that runs disparity models on your own data before the examiner does — is no longer optional for any lender above 500 originations.
The CFPB's fair lending examination procedures are public and worth reading in full. They describe the exact regression models examiners use. If your data can't survive your own version of that analysis, it won't survive theirs.
Common Mistakes Lenders Are Already Making
Based on early Tier 1 implementation experience documented in industry comment letters and compliance conference sessions through Q1 2025, the most common operational failures are:
- Miscounting covered originations for tier determination — particularly by excluding SBA lines of credit or business credit cards
- Collecting demographic data too late in the application process, after a credit decision has already been communicated to the applicant
- Using free-text denial reasons that can't be reliably mapped to the CFPB's enumerated reason codes at year-end
- Relying on manual geocoding for census tract assignment, which produces error rates of 8–12% on commercial addresses compared to automated USPS-certified geocoding engines
- Conflating gross annual revenue capture for 1071 eligibility screening with the revenue data used for underwriting — they must be tracked as separate data points to avoid firewall issues
None of these are exotic edge cases. They are structural gaps in loan origination workflows that were designed before 1071 existed.
What Lenders Who Get This Right Will Gain
Compliance-focused framing can obscure a genuine strategic opportunity. Lenders who build clean, well-structured 1071 data pipelines will have a proprietary dataset that tells them something most of their competitors won't know: where underserved small business credit demand actually exists in their geographic footprint, broken down by industry, owner demographics, and deal size.
Public HMDA data transformed mortgage market strategy for lenders who used it analytically. CFPB 1071 small business lending data will do the same — but the first mover advantage accrues to lenders who build the collection infrastructure correctly from day one, not those who clean up messy data after their first submission.
The institutions that will struggle are those treating 1071 as a pure compliance cost. The ones that will benefit are treating it as the most structured market research dataset their business lending team has ever had access to.
For community banks and credit unions building out their collection workflows, our lending compliance resources on the AtlasForge blog include implementation checklists and sample policy language updated for the 2025 guidance cycle. If you're evaluating platforms to manage the full data lifecycle — from application intake through annual submission — Ember360 was built with CFPB schema validation and firewall-enforced data architecture as core features, not add-ons. Reach out through our contact page to see a workflow walkthrough specific to your origination volume and core system.
Ready to build on AtlasForge?
Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.
