CFPB Section 1071 Small Business Lending Data Collection

The CFPB’s Section 1071 rule reshapes how mortgage lenders collect, store, and report data on credit applications from small businesses. For Tier 1 filers — the largest originators — the compliance date is July 1, 2026. For most mortgage lenders operating in the small business and commercial space, this is the most consequential data collection rule since HMDA.

On October 2, 2025, the CFPB finalized an interim final rule extending compliance dates for Section 1071 of the Dodd-Frank Act. Under the revised schedule, Tier 1 filers — those originating 2,500 or more covered small business credit transactions in each of 2024 and 2025 — must begin collecting and reporting data on or before July 1, 2026, with first filings due June 1, 2027.

For mortgage lenders, this is a meaningful expansion of the data collection perimeter. Until now, HMDA has been the dominant data regime. Section 1071 extends a parallel reporting requirement to small business lending, and the two regimes are designed to work together — examiners will increasingly look for consistency between them.

This guide walks through what Tier 1 status means for mortgage lenders, what counts as a covered application, the data points required, and how to build a Section 1071 program that holds up under CFPB examination.

Who Counts as a Tier 1 Filer

The CFPB’s tier structure is based on originator volume, not portfolio or servicing. Under the 2025 interim final rule, tiers are:

Tier 1: 2,500+ covered transactions in each of 2024 and 2025 — compliance date July 1, 2026 — first filing June 1, 2027.

Tier 2: 500–2,499 covered transactions in each of 2024 and 2025 — compliance date January 1, 2027 — first filing June 1, 2028.

Tier 3: 100–499 covered transactions in each of 2024 and 2025 — compliance date October 1, 2027 — first filing June 1, 2029.

Exempt: Fewer than 100 covered transactions in each year — not required to file.

Volume is measured at the legal entity level, not the holding-company level — though there are aggregation rules for commonly controlled entities. The CFPB has signaled that aggregation will follow Regulation B’s control-person framework, with limited exceptions for certain minority-owned institutions and CDFIs.

The threshold applies to covered credit transactions, not portfolio or servicing. If your institution has any commercial or small business lending activity and your overall originator volume puts you in any tier, you must include that activity in your Section 1071 count. The threshold is firm-wide, not line-of-business.

What Applications and Loans Are Covered

Section 1071 covers applications for credit from a small business. The CFPB’s definition of “small business” is the SBA’s size standard for the applicant’s industry — generally a business with $5 million or less in gross annual revenue (calculated across the applicant’s three most recent fiscal years) and 500 or fewer employees.

A “covered credit transaction” is a closed-end or open-end credit product originated for a small business, including:

  1. Commercial mortgages and refinances
  2. Commercial real estate loans
  3. Working capital lines of credit
  4. SBA-guaranteed loans
  5. Equipment financing
  6. Business credit cards (with limited exceptions for corporate cards)
  7. Merchant cash advances (treated as credit under the rule)

Key exclusions include trade credit (credit extended for the purchase of goods and services from the creditor itself), public utilities, securities transactions, credit to financial institutions, credit to governments, and credit extended to a business with gross revenue above the size standard.

The 19 Data Points You Must Collect

For every covered application, the rule requires collection of 19 data points organized into three categories.

Applicant-Identifying Data

1. Legal name

2. Trade name (if different)

3. Address (physical, not PO Box)

4. Taxpayer Identification Number (TIN / EIN)

5. Application date

6. Application method (in-person, phone, online, mail)

7. Application recipient (where the application was submitted)

Application Characteristics

1. Application type (covered application, prequalification, or incomplete)

2. Action taken (approved, denied, withdrawn, incomplete)

3. Action date

4. Denial reason(s) — enumerated list (main reason + up to four additional)

5. Credit type (closed-end vs. open-end)

6. Credit purpose (working capital, equipment, real estate, etc.)

7. Amount applied for

8. Amount approved or originated

9. Term

Pricing Data

1. Interest rate

2. Total origination charges

3. Broker fees and lender compensation

Demographic data on the applicant’s principal owners (race, ethnicity, sex) is collected on a voluntary basis, consistent with the rule’s fair-lending intent.

Pricing data sensitivity: The pricing fields (interest rate, origination charges, broker fees) are the most contested parts of the rule. For mortgage lenders, these overlap with HMDA rate spread reporting. Treat 1071 pricing data as separate and validate at the loan level — examiners will compare 1071 pricing against HMDA LAR, internal loan files, and the closing disclosure.

Where Section 1071 Meets Mortgage Lending

For most residential mortgage lenders, Section 1071 will be a peripheral obligation. But the rule applies where the lines blur — and for diversified lenders, the overlap is significant.

Residential Mortgages That Touch 1071

  1. Investment property mortgages held in the name of a small business entity (LLC, corporation, partnership) — not in the borrower’s personal name. These are commercial loans, even if secured by 1–4 family residential property.
  2. Mixed-use property loans where the borrower is a small business.
  3. Construction loans to small business developers, including single-purpose entity (SPE) borrowers.
  4. Diversified lenders with both consumer mortgage and commercial / small business lending arms, where total originator volume pushes the institution into a tier.

Residential Mortgages That Do NOT Touch 1071

  1. Personal mortgages on a borrower’s primary residence (HMDA-only)
  2. Personal second homes and vacation homes (HMDA-only)
  3. Refinances of personal mortgages (HMDA-only)
  4. Reverse mortgages for individuals (HMDA-only)

The test is who the applicant is, not what the property is. Loans to individuals — even on non-owner-occupied investment property — are generally HMDA territory. Loans to small business entities are 1071 territory.

HMDA and 1071: The Overlap You’ll Want to Plan For

This is the part of Section 1071 that gives mortgage compliance officers heartburn — and the part examiners will look at most closely.

HMDA and Section 1071 both collect credit-application data. For the small (but growing) population of loans that could plausibly be reported under either regime, you need a clear written policy on which regime applies and why. Examiners will compare:

  1. Total application counts under HMDA vs. 1071
  2. Volume consistency between HMDA LAR and 1071 data
  3. Denial reason patterns across both regimes
  4. Pricing data, where both regimes capture rate-related fields
  5. Demographic data handling (both are voluntary but collected separately)

The CFPB and prudential regulators have signaled that cross-regime consistency will be a supervisory priority beginning in 2027. Build the policy now, while you have time.

Building a Single Source of Truth

For institutions in scope for both HMDA and 1071, the right architecture is a single application-level data store that feeds both regimes — not two parallel pipelines. This reduces data integrity risk, simplifies examiner requests, and improves your ability to identify and remediate discrepancies.

Building a Defensible Compliance Program

A Section 1071 program that will survive CFPB examination has five moving parts.

1. Written Policies and Procedures

Your 1071 policy should document tier classification and how it was determined; scope (which products, which channels, which entities are included); application intake process; data storage and retention (3 years from application date); reporting process; quality control; exception handling; training requirements; and oversight and audit cadence.

2. Application Intake Controls

Capture the data points at the point of application, not after origination. The intake controls should include LOS / origination system integration that captures the data at submission, validation rules at the field level, required-field enforcement on the controlled fields, and a demographic data collection workflow.

3. Data Quality Controls

Pre-submission QC is the single biggest determinant of exam-readiness. At minimum: reconciliation against origination system totals, reconciliation against HMDA LAR (for any overlap), denial reason accuracy check on a sample basis, pricing data validation against closing disclosures, and edit checks before submission.

4. Filing Platform Readiness

The CFPB is building a dedicated filing platform for Section 1071 (parallel to the HMDA Platform). Confirm your institution’s readiness to integrate with the platform ahead of your first filing deadline.

5. Exam-Readiness Documentation

Maintain an exam binder that includes the Section 1071 written policy, tier classification analysis with supporting data, data lineage documentation (where each field comes from), QC results for the most recent filing, reconciliation against HMDA LAR for overlap period, and any voluntary demographic data collection materials.

Compliance Timeline and What to Do by July 1

If you’re a Tier 1 filer with a July 1, 2026 compliance date, the clock is short. Here’s the practical action sequence:

  1. Now: Confirm tier classification using 2024 and 2025 originator volume.
  2. Now – end of month: Stand up the written policy and get it approved by compliance committee.
  3. Next 60 days: Map current data capture against the 19 data points; identify gaps.
  4. Next 90 days: Update LOS / origination systems to capture missing fields.
  5. Next 120 days: Train intake and operations staff.
  6. By July 1, 2026: Begin collecting all 19 data points on every covered application.
  7. By Q4 2026: Run your first pre-submission QC cycle.
  8. By Q1 2027: Validate the full pipeline end-to-end with test data.
  9. June 1, 2027: First filing due.

Frequently Asked Questions

Do I Have to Collect Demographic Data on the Applicant’s Owners?

No — demographic data (race, ethnicity, sex) is collected on a voluntary basis. You must offer the applicant the opportunity to provide it, but you cannot require it, and you must clearly disclose that providing the information is voluntary.

What If My Institution’s Originator Volume Was Above the Tier 1 Threshold in 2024 but Below in 2025?

You must meet the threshold in both years to qualify for Tier 1. If you drop below in either year, you move down a tier (or become exempt).

How Does Section 1071 Interact With State-Level Small Business Reporting?

Several states have their own small business lending reporting requirements (notably California and New York). Section 1071 is federal and preempts conflicting state requirements. You still need to file state reports, but Section 1071 is the floor, not the ceiling.

Can I Use Third-Party Vendors to Handle Section 1071 Compliance?

Yes — most lenders will use LOS providers, compliance platforms, or specialized 1071 vendors to handle data capture, validation, and filing. Vendor selection and oversight is itself an exam topic, so document your due diligence and ongoing monitoring.

What Records Must I Retain?

Three years from the date of application. Records must be sufficient to reconstruct the application data as it was reported, including the response to any voluntary demographic question.

Ready to review your Section 1071 readiness before July 1? Synergy supports mortgage lenders with policy drafting, data-mapping, QC buildout, and pre-filing readiness reviews. Book a 30-minute readiness call.

Web Statistics